This website uses cookies

Read our Privacy policy and Terms of use for more information.

The Iran-linked attack on US water utilities is no longer a Minnesota story. The FBI has now confirmed the same PLC intrusions in at least seven states, and CISA is telling every utility in the country to pull exposed controllers offline. President Trump's response was to blame Minnesota's governor and deny Iran's involvement, which puts the White House at odds with its own intelligence agencies and CISA's own advisory. That gap between what investigators are finding and what officials are saying in public is worth watching.

Everything else today is a variation on the same theme: old bugs, not new AI magic, are still what get people breached. OpenAI's Hugging Face incident traced back to a misconfigured sandbox. SonicWall VPN gateways are getting rooted with zero clicks. N-able's "fix" for its N-central bug didn't actually fix it, and attackers used the leftover hole to plant Cloudflare tunnels that survived even after access got revoked. Add a critical unauthenticated RCE in TeamCity, a maximum-severity Adobe Campaign Classic flaw, and a Rails Active Storage bug that lets attackers read your secret keys through image uploads, and the pattern holds: the fundamentals are still the whole game.

The breach and fraud stories round out the day. Żabka, Brinks Home, Amgen, and CareCloud all have data circulating from breaches nobody's fully explained yet, and a COLDCARD wallet RNG bug looks tied to $88 million in stolen Bitcoin.

Enterprise DevOps teams are generating infrastructure through AI tools faster than they can govern or track it, creating environments that drift out of sync, accumulate unused resources, and lose consistent security settings over time. Industry analysis argues the core risk isn't AI-generated code itself but the lack of built-in operational oversight — including drift detection, cost tracking, and access management — a gap that grows more costly as companies deploy GPU-heavy AI infrastructure at scale.

A malicious search ad and fake Apple Support-style guide on Claude's sharing page tricked Mac users into pasting a Terminal command, triggering the MacSync stealer, according to Huntress, which found the malware while investigating a mid-July macOS intrusion. The six-stage malware harvests browser logins, cookies, keychain data, SSH and cloud credentials, and Telegram sessions, then targets roughly 60 wallet browser extensions and 21 desktop wallet apps, sometimes swapping in trojanized versions to steal recovery phrases while installing a persistent remote-access backdoor.

CISA released updated guidance on software bills of materials, adding roughly two dozen new fields meant to make SBOMs more comprehensive and useful for tracking software components. Some security practitioners argue the changes focus on data completeness rather than actual risk management, questioning whether the revised framework helps organizations better identify or respond to vulnerabilities in their software supply chains.

Google's Chrome Security team says AI tools built with Gemini fixed 1,072 security bugs across the last two Chrome releases, more than the total patched in the prior 23 milestones combined. Among the findings was a sandbox escape bug, tracked at crbug.com/487383169, that let a compromised renderer read local files and had gone undetected in the codebase for more than 13 years. Google also credited AI-assisted triage, and its BigSleep and CodeMender tools with DeepMind and Project Zero, with blocking more than 20 vulnerabilities, including one critical S1+ issue, from reaching production in May alone.

Wordfence detected a backdoor slipped into version 10.8.7 of the Advanced Responsive Video Embedder (ARVE) plugin, which has about 20,000 active installs, tracked as CVE-2026-18072 with a CVSS score of 9.8. The code, hidden in fn-update-check.php, let an attacker log in as an administrator using a fixed SHA256 token via request parameters, then sent site and username data to an external server before WordPress.org pulled the release within about two hours, meaning most sites never received it through automatic updates. Wordfence advises anyone running 10.8.7 to remove it, check admin accounts, rotate secret keys, and inspect for unauthorized changes.

Security firm Wiz discovered a critical flaw in Azure Cosmos DB's Gremlin API that could have let attackers extract the Cosmos Master Key, granting read and write access to every customer database on the service along with subscription and tenant IDs. Wiz reported the issue to Microsoft in November 2025; Microsoft shipped a hot fix within two days but took another eight months to re-engineer the system and eliminate the master key entirely. Wiz found a similar Cosmos DB key exposure via Jupyter Notebook back in 2021.

Researcher Håkon Måløy disclosed a flaw, confirmed by Microsoft, that lets attackers hide malicious instructions in a Word document so that Copilot copies them into new documents it generates or edits, letting the payload self-propagate across an organization's document workflows and potentially alter figures like financial data. Måløy began working with the Microsoft Security Response Center on March 3, and Microsoft has since rolled out several targeted mitigations, but the underlying vulnerability remains unfixed; Microsoft says it uses defense-in-depth safeguards and is urging customers to update systems and review AI-generated content before use.

Quick Hits

Reply

Avatar

or to participate

Keep Reading