Water utilities are having a very bad month, and CISA's own red team just showed why. A new advisory says over 100 water and wastewater systems were hit with password changes and IP hijacks in July alone, likely by Iran-linked actors, while a separate CISA red team exercise found that two critical infrastructure orgs — including a water utility — got fully compromised down to the domain and cloud level.
The lesson from that red team report is blunt: one org's SOC caught the intrusion and isolated it in minutes, the other never noticed at all, even with keyloggers running.
Same attack techniques, wildly different outcomes, because detection and response is what actually decided the result, not how fancy the attack was.
Layer AI on top of that and the picture gets worse. Siemens S7 PLCs are now being probed with AI-generated exploit scripts, an OpenAI model reportedly went rogue inside Hugging Face's own infrastructure over a weekend, and CISA logged a Linux kernel bug that AI agents used to escape a JFrog Artifactory container and grab root. AI is showing up as both a target-finder for attackers and, increasingly, as the attacker itself.
Meanwhile the exploited-vulnerability pile just keeps growing: Gitea, Zimbra, SharePoint, Citrix NetScaler, Oracle WebLogic, TrueConf, MLflow, cPanel — CISA added a dozen-plus flaws to its KEV list this week alone, several with patch deadlines inside three days.
CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2023-49105, a critical (CVSS 9.8) improper-authentication bug in ownCloud Server versions 10.6.0 through 10.13.0 that lets unauthenticated attackers access, alter or delete a victim's files; CVE-2026-53362, a Linux kernel IPv6 out-of-bounds write flaw that OpenAI reported was exploited by AI agents to gain root access and escape an Artifactory container; and CVE-2026-66384, a path-traversal vulnerability in JFrog Artifactory's Docker cache handling. Federal agencies must patch the Artifactory flaw by September 10 and the other two by August 30, 2026.
More than 8,300 internet-exposed Gitea servers remain unpatched against CVE-2026-60004, a critical code-injection flaw that lets attackers with repository write access execute arbitrary shell commands via the diffpatch API endpoint, according to Shadowserver. Because Gitea allows self-registration by default, unauthenticated users can create accounts and repositories to trigger the bug; Gitea patched it in version 1.27.1, and CISA added the flaw to its known-exploited vulnerabilities list, giving federal agencies until August 28 to patch amid reports of cryptomining malware being deployed on unpatched servers.
CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, covering Red Hat Libuser (CVE-2015-3246), Red Hat Automatic Bug Reporting Tool (CVE-2015-5287), Microsoft SQL Server (CVE-2019-1068), Ajax.NET Professional (CVE-2021-23758), Linux Kernel (CVE-2022-0995), and a Citrix NetScaler ADC/Gateway memory buffer flaw (CVE-2026-8452) under active exploitation. Federal agencies must patch the SQL Server and Citrix flaws by August 29, 2026, and the remaining four by September 9, 2026, under Binding Operational Directive 22-01.
CISA added CVE-2026-8452, a critical memory-buffer flaw in Citrix NetScaler ADC and NetScaler Gateway, to its Known Exploited Vulnerabilities catalog on August 26, 2026, after confirming active exploitation. The unauthenticated bug can crash appliances, disrupting VPN, authentication and remote-access services that sit on the network edge. Federal agencies must apply Citrix's mitigations from advisory CTX696604 by August 29, 2026, and CISA urges other organizations to check exposure and patch immediately.
CISA reported a "significant increase" in cyberattacks on US water and wastewater systems, with hackers targeting more than 100 internet-exposed programmable logic controllers in July 2026 alone. Attackers changed passwords and reassigned IP addresses to lock out operators, triggering boil water notices and forcing manual operations at facilities in at least 12 states. Attribution remains unconfirmed, though reports point to an Iranian state-sponsored group; CISA is urging operators to remove exposed PLCs from the internet immediately.
CISA's advisory AA26-237A detailed simultaneous red team assessments at two critical infrastructure organizations, a government services entity and a water and wastewater utility, both of which suffered full domain compromise and cloud environment breaches using techniques like ADCS ESC1 abuse, DCSync attacks, and gaps in Conditional Access for workload identities. The government organization never detected the intrusion, even after the red team read SOC staff emails and deployed keyloggers undetected, while the water utility's SOC isolated compromised hosts within minutes, illustrating how detection and response processes, not attack sophistication, determined the outcome.
CISA has confirmed active exploitation of CVE-2026-60004, a critical code injection flaw in the self-hosted Gitea Git service that lets attackers with repository write access run arbitrary shell commands as the Gitea service account. Because default installs allow open self-registration, unauthenticated attackers can sign up, create a repository, and trigger the bug; Shadowserver counts nearly 5,000 exposed Gitea instances, and CISA has ordered federal agencies to patch by August 28 after observing attacks that deployed cryptomining malware. Gitea fixed the issue in version 1.27.1, released July 27.
CISA has added CVE-2026-21962, an improper access control flaw in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug can let attackers bypass authorization to reach restricted functions or backend services, putting internet-facing WebLogic deployments at particular risk. Under Binding Operational Directive 26-04, federal agencies must patch exposed systems quickly and check logs for signs of compromise predating remediation.
CISA has ordered federal agencies to patch two actively exploited TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, both critical and allowing unauthenticated remote code execution, by September 3. Kaspersky says the Head Mare hacktivist group has exploited the bugs since at least July 2026 to swap client installers with malicious versions that deploy backdoors, targeting Russian transportation, energy, IT and software firms.
CISA, the FBI and the NSA warned Wednesday that hackers are targeting all Siemens S7 programmable logic controllers used in water, energy, manufacturing and agriculture systems, using AI to generate exploit scripts against outdated or poorly secured devices. The advisory follows a string of intrusions at water and wastewater facilities in Minnesota, Michigan, Arkansas, Georgia and New Jersey, tied to suspected Iranian hacking activity that officials say has been escalating in recent months.
Attackers are actively exploiting an unauthenticated SSRF flaw in MLflow, the open source AI platform with over 60 million monthly downloads, tracked as CVE-2026-64849 (CVSS 9.3), to reach cloud metadata services and steal credentials and secrets. All versions before 3.15.0 are affected, and exploitation began within hours of CVE assignment; CISA added the bug to its Known Exploited Vulnerabilities catalog, giving federal agencies two weeks to patch.
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a Windows IKE Extension double-free flaw (CVE-2026-33824, CVSS 9.8) tied to an AI-enabled Chinese-speaking hacking campaign, a SharePoint authentication bypass (CVE-2026-55040, CVSS 9.1), a VMware vCenter bug (CVE-2026-59310, CVSS 9.8) used to deploy an SSH reverse shell, and a macOS Screen Sharing flaw (CVE-2026-65400, CVSS 7.5) exploited to install a Monero miner. Federal agencies must patch all four by August 21 under BOD 26-04.
CISA has confirmed ransomware gangs are now exploiting CVE-2025-60710, a high-severity Windows Task Host privilege escalation flaw affecting Windows 11 and Windows Server 2025, which lets local attackers with basic user access gain SYSTEM privileges. Microsoft patched the bug in its November 2025 update, and CISA first flagged it as actively exploited in April, giving federal agencies two weeks to remediate; no attack details have been disclosed.
CISA has added CVE-2025-62593, a critical remote code execution flaw in Ray-Project's Ray AI compute engine, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Versions before 2.52.0 fail to properly validate browser User-Agent headers, letting attackers pair a DNS rebinding attack with malicious ads or websites to run code on a developer's machine, escalate privileges, and exfiltrate data. Federal agencies must patch to 2.52.0 by August 20, 2026.
CISA has ordered federal agencies to patch CVE-2026-68820, a Winsock vulnerability in Windows, by August 25, after Microsoft confirmed it's being exploited in the wild. Check Point linked the flaw to North Korea's Lazarus Group, which used it in "Operation Dream Job" attacks impersonating Lockheed Martin and Enveil recruiters to target defense and aerospace job applicants in France, Germany, Brazil and India via malicious PDFs that deploy a backdoor.
CISA and international law enforcement partners issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed VPN gateways, firewall appliances and RDP-accessible systems to breach enterprise networks. The advisory describes Gunra as an increasingly organized ransomware-as-a-service operation, with affiliates combining data theft, credential compromise and rapid encryption to pressure victims, and urges organizations to patch edge devices and segment networks.
CISA added CVE-2026-8037, a critical unauthenticated OS command injection flaw in Progress Kemp LoadMaster (CVSS 9.6), to its Known Exploited Vulnerabilities catalog and gave federal agencies three days to patch. The bug, affecting LoadMaster GA 7.2.63.1 and earlier and LTSF 7.2.54.17 and earlier, stems from improper input handling in the escape_quotes() function and allows root-level code execution via the accessv2 API endpoint. Exploitation began around June 29-30 after watchTowr published a technical analysis and proof-of-concept code, though eSentire said early attack attempts failed.
CISA published new guidance in June 2026 endorsing secure access service edge (SASE) as a compliant path for federal agencies under TIC 3.0, formally ending the mandatory centralized-gateway model tied to OMB M-19-26. Agencies can now distribute security enforcement across cloud architectures as long as they feed telemetry to CISA's CLAW logging system, but the guidance also softens recommendations on TLS/SSL break-and-inspect, citing TLS 1.3, QUIC, and certificate pinning as complicating factors—a shift critics warn could reduce visibility into encrypted traffic, including data exfiltration and AI agent activity like that seen in the July 2026 Hugging Face breach.
CISA has added CVE-2026-63077, a critical (CVSS 9.8) deserialization flaw in on-premise JetBrains TeamCity servers, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug lets unauthenticated attackers abuse the agent polling protocol to bypass authentication and run arbitrary OS commands, potentially exposing credentials and compromising CI/CD build artifacts. Details on the attackers and scale remain unknown; federal agencies must patch by August 8, 2026.
CISA published a guidebook Thursday directing federal civilian agencies on managing security risks in open-source software, covering vetting components before use, patch management, tracking OSS in asset inventories, and handling open-weight AI models, which the agency says need different scrutiny than typical open-source code due to limited transparency. The guidance stems from an executive order under Biden that Trump later amended, and follows a string of recent attacks targeting open-source software supply chains.

