GreenCyber / Light reading / Week ending 2 August 2026
The Global Debrief, week ending 2 August 2026
Water utilities in at least seven American states lost the ability to monitor and control their plants, and no security flaw was exploited to do it.
Water and wastewater utilities in at least seven American states lost the ability to monitor and control their treatment plants. Some ran by hand for days. Some issued notices telling residents to boil their water. No security flaw was exploited to cause any of it. The equipment was reachable from the public internet, and whoever reached it changed the addresses and the passwords. The operators were locked out of their own plants by someone who simply set a new password. At least one utility found the instructions governing its pumps and valves had been altered, and an altered instruction outlives the password reset. It has to be compared against a known good copy before the plant goes back into automatic operation.
That shape repeated all week, across industries with nothing else in common. An advertising supplier's code, running on other companies' websites with their permission, was used to interfere with payments made by their visitors. An Australian manufacturer of drone flight control hardware lost control of its internet address for a day, long enough for somebody else to present a genuine looking secure connection under its name and collect whatever customers typed into it. A global professional services firm's client documents were taken through a support platform operated by another company. In none of these did an attacker defeat a control. In each, they used a connection or a permission the organisation had already granted, to a supplier it had already approved.
Then the disclosures. An energy retailer completed the initial phase of its review and told the market that roughly 900,000 current and former customers had information accessed, weeks after an extortion claim naming a far larger number reached a newsroom. A semiconductor manufacturer told its regulator that files had been taken in an intrusion detected in June, and that it is not aware of the data being released or misused. Both of those are creditable pieces of work. Both also show where the exposure now sits, which is the interval between an incident and the moment management can say what actually happened. Reporting obligations start on suspicion rather than on certainty, and an attacker's number becomes the public number by default whenever a company cannot yet produce its own.
Then the artificial intelligence story most boards will have seen in a headline, framed as an autonomous attack campaign. The research it came from says the autonomous phase did not achieve full compromise of any intended target. The damage that was confirmed came from a person working by hand, against systems already exposed through known and unpatched weaknesses. That is not a reason to relax, and it is not a reason to restructure a security programme either. What has genuinely changed is the price of an attacker's labour, and that shortens the useful part of every window an organisation has to fix something after it becomes public knowledge.
Three questions for Thursday.
- Which of our equipment and systems can be reached from the public internet? Ask for the list, with a name against it and a date on it, rather than an assurance that there is nothing.
- If we learned tonight that customer information had been taken, how long before management could tell this board how many people and which information? And who here is permitted to decide that a claim of a breach is not credible?
- Which of our suppliers can change what appears on our website, or reach inside our systems, without asking us? Who assessed them, and when?
The week for a security leader
Water and wastewater
Utilities in at least seven American states lost monitoring and control
- The FBI and the Environmental Protection Agency published a joint public service announcement on 30 July. Since 27 July, water and wastewater utilities in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.
- The devices are Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers reachable from the public internet. After remotely accessing them the actors changed the IP addresses and passwords, costing operators "monitoring and control functionality". No agency has named a vulnerability and no agency has named an actor.
- The FBI records operational effects including loss of pressure and flooding, and notes that pressure loss could potentially allow untreated ground water to seep into pipes. CISA's alert of 30 July describes activity "resulting in boil water notices and the necessity for ongoing manual operations".
- More than 30 Minnesota community water systems were affected, according to Minnesota IT Services on 28 July, which could not determine whether a single actor was responsible. Braham's plant went offline and the city asked residents to minimise water use for a few hours, which was not a boil water notice. Plymouth continued operating manually and kept supplying water. South St Paul maintained service. Maple Plain declared a local state of emergency.
- At least one organisation reported modified PLC project files after noticing ladder logic discrepancies across several sites. The FBI also records that similarities in network setups provided by third parties across several victims could let an attacker "multiply successes", naming no integrator or architecture. Censys observed that mobile carriers account for 59 per cent of the exposed Rockwell devices it saw. Rockwell published a MicroLogix 1400 password recovery notice on 30 July.
Sources: FBI and EPA joint public service announcement, 30 July 2026; CISA alert, 30 July 2026; Minnesota IT Services, 28 July 2026; Rockwell Automation customer notice, 30 July 2026; Censys.
CI Fortify, Australian led guidance on isolating operational technology
- Published 28 July, led by the Australian Signals Directorate and co-sealed by ASD's ACSC, CISA, the FBI, the Canadian Centre for Cyber Security and the National Cyber Security Centres of the United Kingdom and New Zealand.
- The subject is isolating vital operational technology from all other networks. Its stated purpose is that owners and operators "can provide continuity of their critical services in instances of crisis or service disruption".
- It was published two days after the American incidents began and two days before the FBI warning, and it references neither, because it was written before either was public. It is not a response to those events.
- The design assumption is continuity rather than prevention: that something will be lost and the plant still has to run. That matches the one control that demonstrably worked in the American incidents, which was manual operation.
Sources: CI Fortify guidance, ASD and co-sealing agencies, 28 July 2026.
Network and security infrastructure
Arista VeloCloud Orchestrator, CVE-2026-16812, exploited
- Advisory published 27 July. Operating system command injection, CVSS 10.0. Arista's own words: "This issue was discovered externally and is known to be actively exploited."
- On-Prem deployments only. Hosted and dedicated services are not affected and were patched before publication.
- Fixed in 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1.
- CISA added it to the Known Exploited Vulnerabilities catalogue on 27 July with a remediation deadline of 30 July, three days.
- Arista's interim measure: "Restrict access to the VCO web interface to trusted administrative networks." Nobody has published attribution.
Sources: Arista security advisory, 27 July 2026; CISA Known Exploited Vulnerabilities catalogue, 27 July 2026.
Check Point SmartConsole, CVE-2026-16232, weaponised in window
- The advisory itself sits outside this window. Check Point published on 19 July and updated on 22 July. The in window development is the public proof of concept.
- Authentication bypass in the SmartConsole login process, affecting Security Management Server and Multi-Domain Security Management Server. An unauthenticated attacker can obtain an application login token, log in with full administrator privileges and modify security policy or configuration. Rapid7 gives the root cause as a broken trust boundary in the application authentication path, with the server accepting an attacker supplied SIC distinguished name.
- Exploited as a zero day at the time of disclosure. Check Point's own wording: "Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers."
- Rapid7 published a root cause technical analysis on 28 July and a proof of concept script on 29 July. Exploitation requires network access to the management server and a Trusted Clients configuration that does not restrict GUI clients, which Rapid7 found to be the default in its testing.
- Affected releases run from R77.30 through R82.10. Fixes are in R82.10 Jumbo Hotfix Take 36, R82 Take 118 and R81.20 Take 158 and later. Check Point's own advisory assigns no CVSS score, and reported scores diverge, with both 9.1 and 9.3 in circulation.
Sources: Check Point advisory sk185169, published 19 July 2026 and updated 22 July 2026; Rapid7 technical analysis, 28 July 2026; Rapid7 proof of concept, 29 July 2026; The Hacker News, 29 July 2026.
Cisco Secure Firewall Management Center, CVE-2026-20316, exploited
- Advisory published 29 July. A static credential shipped in the product lets an unauthenticated remote attacker log in using a low privileged account and reach sensitive data.
- Cisco's wording: "In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability."
- CVSS 3.1 base score of 5.3, published by Cisco and matched by the National Vulnerability Database. Cisco separately assigns a Security Impact Rating of High, deliberately above its own score, because the access can be chained with other flaws in the same product to escalate. Higher scores circulating this week trace to no primary source.
- Cisco says the flaw could be chained. Cisco has not said chaining is occurring, and at least one outlet is explicit about the difference.
- No workarounds. Hot fixes have been available since 30 July across the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 trains. CISA added it on 29 July with a deadline of 1 August. Cloud delivered FMC, FDM, ASA and FTD are not affected. Credit to Jimi Sebree of Horizon3.ai as discoverer, noting Horizon3 is an interested party in its own finding.
Sources: Cisco security advisory, 29 July 2026; National Vulnerability Database; CISA Known Exploited Vulnerabilities catalogue, 29 July 2026.
Fortinet FortiOS SSL-VPN, CVE-2025-68686, added to the exploited catalogue
- CISA added it to the Known Exploited Vulnerabilities catalogue on 27 July with a remediation deadline of 10 August.
- Fortinet describes an exposure of sensitive information in FortiOS SSL-VPN that may allow a remote unauthenticated attacker to "bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases". The precondition, in Fortinet's words: "An attacker would need first to have compromised the product via another vulnerability, at filesystem level." It restores persistence rather than granting entry.
- Devices without SSL VPN enabled are not affected. Affected versions are 7.6.0 to 7.6.1, 7.4.0 to 7.4.6, and all of 7.2, 7.0 and 6.4.
- Vendor and regulator are in open disagreement as at 3 August. Fortinet's advisory still records the flaw as not known to be exploited and has not been updated since 12 March 2026, while CISA added it to the exploited catalogue on 27 July on evidence nobody has published.
- Reporting names CVE-2022-42475, CVE-2023-27997 and CVE-2024-21762 as plausible original entry points, which Fortinet's advisory does not enumerate. The researcher who found the bug sampled 3,503 FortiGate units and reported 144 still compromised, which is single source and unreproduced. Nobody has published attribution, and no source distinguishes opportunistic sweeping of already compromised devices from a targeted return to known victims.
Sources: Fortinet PSIRT advisory, last updated 12 March 2026; CISA Known Exploited Vulnerabilities catalogue, 27 July 2026.
Software and build infrastructure
JetBrains TeamCity, CVE-2026-63077
- Advisory published 27 July. Deserialisation of untrusted data in the agent polling protocol, CVSS 9.8, unauthenticated remote code execution. All TeamCity On-Premises versions are affected.
- An unauthenticated attacker with HTTP or HTTPS access to the server can bypass authentication checks and execute operating system commands with the privileges of the TeamCity server process, exposing stored credentials, build environments and the software supply chain beneath them.
- Fixed in 2025.11.7 and 2026.1.3. A security patch plugin is available for TeamCity 2017.1 and later where upgrading is not possible.
- TeamCity Cloud customers need take no action. JetBrains states it has verified there is no evidence of Cloud environments being exploited through this vulnerability.
- Reported privately on 10 July by Antoni Tremblay. JetBrains' wording is preserved rather than softened: "At the time of publishing this advisory, we are not aware of any active exploitation of this vulnerability."
Sources: JetBrains security advisory and blog, 27 July 2026; Rapid7, 29 July 2026; Help Net Security, 28 July 2026; Qualys ThreatPROTECT, 31 July 2026.
Energy and utilities
Origin Energy customer data security incident
- On 28 July Origin said the initial phase of its review was complete and that approximately 900,000 current and former customers had information accessed. Origin calls this a customer data security incident and has not characterised it as ransomware.
- The fields are names and addresses, phone numbers, dates of birth, account details, and either the last four digits of a credit card or the last three digits of a bank account. Chief executive Frank Calabria: "At this point in time, we believe the information of approximately 900,000 current and former customers was accessed."
- On 22 July a person using the alias "John Doe" emailed 7NEWS claiming over two million customer records with a fourteen day countdown, and gave a sample of 50 records to The Australian. That volume is claim only and nobody has stood it up. On 22 July Origin told the ASX it did not believe the impacted data included credit card or bank details, and on 23 July it confirmed unauthorised access and disclosure and listed the partial card and bank digits.
- The claimant says they contacted Origin on 2 July through the board, the security teams and customer service without response, which is the claimant's own account and Origin has not confirmed it. Origin has said it had been reviewing a potential security threat since early July and did not assess it as credible.
- On 24 July a person using the alias "Edison Walthour" told The Australian the matter had been settled privately, which is claim only, single sourced, and Origin declined to comment and has not addressed it since. Reporting treats the two aliases as one actor and nobody has confirmed that. Origin has notified the ACSC, the National Office of Cyber Security, the AFP and the OAIC, and has offered a twelve month Equifax Protect subscription and IDCARE support.
Sources: Origin Energy ASX announcements of 22, 23 and 28 July 2026 as reproduced by three outlets, graded confirmed rather than primary; 7NEWS, 22 July 2026; The Australian, 24 July 2026.
Professional services
EY listed by ShinyHunters
- EY disclosed an incident in early July involving an IT service management platform used by internal staff supporting tax related client work. An unauthorised third party had access from 28 March to 12 April 2026, and EY detected anomalous activity on 23 April.
- Documents tied to numerous EY clients were downloaded during that window, including documents containing client tax information. EY secured systems, notified law enforcement and offered 24 months of identity monitoring through Experian. It has not named the third party platform provider or published a victim count.
- ShinyHunters listed EY on its leak site on 27 July with a deadline of 31 July, alongside other newly listed victims including RingCentral and Brinks Home.
- The group claims the intrusion came through a supply chain attack that yielded credentials to EY internal systems, and claims access to Jira, GitHub and Azure environments, and more data than EY has acknowledged. All of that is claim, and none of it is confirmed.
- EY has not confirmed that ShinyHunters was behind the incident. BleepingComputer records that it has no way to verify the group's claims independently, and no alleged EY data had appeared on underground forums at the time of reporting.
Sources: EY incident disclosure, early July 2026; BleepingComputer, 27 July 2026; Hackread, 27 July 2026; Cybernews.
Semiconductors and manufacturing
Analog Devices confirms exfiltration in an SEC filing
- Analog Devices filed a Form 8-K on 29 July confirming it detected unauthorised activity across certain company systems on 23 June 2026.
- The filing states that "certain files were exfiltrated from the affected systems", with the investigation into their nature and scope ongoing.
- On release of the data, the company's wording is preserved exactly: "To the Company's knowledge, the data has not been publicly released or used for fraudulent purposes." It does not believe the incident is reasonably likely to materially impact its business, operations or financial condition, and says operations were not interrupted at any point.
- It engaged external cybersecurity experts for containment and investigation, and has notified and is coordinating with law enforcement.
- ExfilSquad listed the company on 26 July claiming roughly 570,000 records containing customer personal information, which is claim only. Analog Devices treats that 26 July matter as a separate and unrelated cybersecurity incident which it is assessing for validity and scope, so it should not be read as the June intrusion. The company is no longer listed on that group's leak site.
Sources: Analog Devices Form 8-K, filed 29 July 2026; Security Affairs, 30 July 2026; Cybersecurity News.
Aerospace and unmanned systems
CubePilot DNS hijacking
- On 24 July an attacker took control of the DNS settings for cubepilot.org, the domain of CubePilot, an Australian manufacturer of flight controllers and autopilot hardware for drones used in surveying, search and rescue, agriculture and defence, and redirected traffic to attacker controlled infrastructure.
- The attacker obtained TLS certificates covering all cubepilot.org subdomains, so a visitor would have seen a valid HTTPS connection while reaching attacker infrastructure. CubePilot warned that "credentials entered on any of our services on 24 July may have been captured", naming the portal and the forum.
- CubePilot regained control of its domains the same day, revoked the fraudulently issued certificates, preserved evidence, notified the relevant providers, and reported the incident to ASD's ACSC and to law enforcement. It undertook to notify affected entities directly where impact is confirmed.
- Customers were told not to flash firmware images downloaded on 24 or 25 July until integrity checks are complete. Images obtained before 24 July are considered safe.
- OEM services, the community forum and the documentation portal were taken offline during the investigation. Chief executive Philip Rowse said the ERP portal was also taken offline as a precaution.
Sources: CubePilot customer notice and statements by Philip Rowse; BleepingComputer, 28 July 2026; SC Media; secnews.gr.
Advertising technology
Adform served malicious code through the platform
- On 27 July Adform identified suspicious activity on its systems and, in its own words, "immediately launched an investigation under its incident-response procedures". Malicious code was being served through the platform to websites carrying its tag. Adform says it contained the incident, removed the code, informed impacted clients and reported the matter to relevant authorities.
- Adform confirms the code was designed to "interfere with certain cryptocurrency transactions involving Bitcoin, Ethereum, or Tron by attempting to replace a cryptocurrency wallet address copied to a user's clipboard with a different address", and says it was not designed to install software or establish persistence, and operated only while an affected webpage was open.
- Two accounts stand and neither has been settled. Adform's notice states it found no evidence the code transmitted users' IP addresses or information about the websites they visited to an external party, while acknowledging such transmission may have been possible. Kevin Beaumont documented a beacon to a named IP address and port carrying the visitor's IP address, the referring website and the URL path.
- The duration is contested. Adform scopes the exposure to a website using the affected technology on 27 July 2026. Beaumont observed activity across the preceding week, and an archived sample of the file exists dated 26 July.
- Attributed to reporting rather than to Adform: the file name trackpoint-async.js, a second payload rewriting values in input fields and intercepting copy, cut, paste and input events, and a clean VirusTotal result at the time of detection. On scale, Adform's own 2025 annual report gives roughly 1,800 customers, 1.5 billion ads displayed daily and operations in more than 180 countries. There is no confirmed count of affected sites or of funds diverted.
Sources: Adform incident notice, undated and unversioned; Adform 2025 annual report; Kevin Beaumont's published findings.
Artificial intelligence
Unit 42 research on an autonomously run offensive campaign
- Unit 42 published research on 30 July on an operator running offensive reasoning through an open source agent framework, enumerating targets and their vulnerabilities, sourcing exploit tools and initiating attacks without human intervention, orchestrated over a messaging app. The activity was in May 2026. The publication is the in window event, not the attacks.
- Its own conclusion: "Although these autonomous campaigns did not achieve full compromise of any of their intended targets, the findings carry several implications for defenders." Unit 42 attributes that failure to configuration requirements on the target side and says the margin of failure was narrow.
- The confirmed damage came from the operator working by hand: data exfiltration from three Citrix NetScaler targets and command execution on 11 Marimo notebook endpoints, out of more than 460 attempted targets. Session hijacking attempts against a persistently targeted Malaysian government entity are suspected rather than confirmed. Unit 42 records the system executing "hundreds of hours of manual targeting analysis in mere minutes".
- The offensive reasoning ran on a model with minimal safety controls, reached through an open source framework with no client side restrictions. Unit 42 assesses that the operator tried Western hosted models and that provider side controls likely limited their usefulness for autonomous attacks. Likely is an assessment rather than a finding, and Unit 42 does not rank or compare models. One provider confirmed to Unit 42 that its safeguards refused requests that breached its policies and that it disabled an account it believes is linked to the campaign.
- Unit 42 assesses the operator to be a Chinese speaking individual in Zhuhai, China, using the aliases knaithe and KnYuan, and attributes no further. Whether the actor is state linked or criminal is not established. Investigators gained visibility when the agent framework, responding to a command, started a file server from the home directory rather than a staging directory and exposed the entire workspace.
Sources: Unit 42 research publication, 30 July 2026.
Circulating, and not carried
- A cryptographic fix for the Signal backup recovery key weakness. One outlet reported on 27 July that the weakness state linked actors have been phishing had received a formal cryptographic fix. It is an unreviewed academic preprint proposing an architecture, published by a third party researcher, and Signal has shipped nothing and has not commented. The advisory that named the campaign was published on 26 June, outside this window. There is no in window Signal item.
- Attribution for the American water incidents. Iranian attribution circulated from 30 July, sourced to unnamed officials who explicitly cautioned that responsibility was not definitively determined. One Iranian state publication named a group on 29 July, which is a third party assertion rather than a claim of responsibility. A second group appears in vendor framing alongside that vendor's own statement that the incident has not been officially attributed. The agencies issuing the warnings named nobody.
- A vulnerability behind the American water incidents. Much commentary points at a 2021 controller flaw. No agency has named any vulnerability, and that flaw's published scope does not include either of the two controller models the FBI names.
- Nine further water systems in Michigan, reported on 1 August by a single outlet and not corroborated.
- Three extortion claims, all carried above as claims and none as fact: the volume and content ShinyHunters asserts about EY, the 570,000 record figure ExfilSquad asserts about Analog Devices, and the private settlement asserted in the Origin matter. None is verifiable from outside, and the honest position is that they remain assertions.
- Larger customer counts for the advertising platform, circulating from a single researcher, close to an order of magnitude above the company's own annual report, and unreconciled by anybody.
- Higher severity scores for the Cisco flaw, circulating from outlets and traceable to no primary source. The vendor and the national database both publish 5.3.
Start a conversation
Want this every week?
It goes out to the organisations we work with. Ask and you are on the list, and there is nothing else attached to it.
- Every enquiry is read by a senior leader. There is no sales sequence behind this form.
- Nothing is resold to you and no vendor introduction is waiting at the other end.
- A first conversation is a conversation, not a scoping call with a proposal attached.