Florida Critical Infrastructure Cybersecurity Intelligence
This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.
Situational Awareness Bulletin
Cyber Threat Outlook
Florida critical infrastructure operators face a concentrated and escalating threat environment shaped by three converging pressures: adversaries integrating artificial intelligence (AI) tools into intrusion workflows at scale, aggressive targeting of perimeter and operational technology (OT) systems across all critical infrastructure sectors, and a broadening campaign of Iranian-affiliated actors against water and energy assets in the United States and allied nations. Over the next six to twelve months, organizations should expect AI-assisted reconnaissance and tooling to compress the window between vulnerability disclosure and live exploitation — not because autonomous AI agents reliably complete intrusions on their own (current evidence shows human operators still drive successful breaches), but because AI accelerates the targeting and scripting work that precedes them. State-affiliated Chinese actors (including groups tracked as Grimfengxi, Huapi, and Fire Ant) are integrating open-source and commercial AI models into multi-stage operations against government, defense, and technology networks. Simultaneously, Iranian-affiliated actors demonstrated capability and intent to disrupt water and energy OT environments in July and August 2026, shutting down a UK gas-fired plant for four days and compromising more than 100 U.S. water utilities. Ransomware syndicates — including Clop, BlackFile, and Aurora — continue to evolve social engineering and AI-assisted execution techniques against enterprise environments, with voice phishing and adversary-in-the-middle credential theft now capable of bypassing standard multi-factor authentication (MFA). Florida’s interconnected CI sectors, shared cloud environments, and extensive third-party vendor relationships create compounding exposure: a breach at one supply chain node — as demonstrated by the McKesson, Boston Scientific, and PTC Windchill incidents — cascades rapidly into clinical, operational, and logistical disruptions for downstream operators. Operators must prioritize removing OT assets from public internet exposure, deploying phishing-resistant hardware-backed authentication, maintaining tested offline continuity procedures, and conducting regular vendor risk assessments.
Confidence Assessment: High
Executive Summary
-
All Sectors: Federal advisories confirmed active exploitation of a Windows Task Host privilege-escalation flaw (CVE-2025-60710), warned that the Medusa ransomware had compromised over 500 critical infrastructure entities, and reported automated reconnaissance targeting Siemens S7 Programmable Logic Controllers (PLCs). The Cybersecurity and Infrastructure Security Agency (CISA) added six Known Exploited Vulnerabilities (KEVs) to its catalog, cyber threat actors integrated Artificial Intelligence (AI) models and coding assistants to accelerate intrusions, and the TerminalFix campaign used fake Cloudflare verification prompts to deploy Python-based reverse tunnels via Dynamic Link Library (DLL) sideloading, giving attackers a persistent proxy into internal networks.
- Commercial Facilities Sector: Operation CameraSwarm compromised over 14,500 Dahua surveillance cameras via authentication-bypass vulnerabilities and Peer-to-Peer (P2P) relays, while a cyberattack against Slovenian operator Hit forced six casinos offline for three days, paralyzing gaming systems and customer platforms.
- Communications Sector: The Evooo1Bot and Dysphoria botnets compromised hundreds of thousands of edge routers to build resilient proxy networks, while the Chinese state-sponsored group Fire Ant infiltrated Cisco Internetwork Operating System (IOS) XR core routers and Terminal Access Controller Access-Control System (TACACS+) servers to intercept traffic and blind logging telemetry.
- Critical Manufacturing Sector: The Clop extortion gang deployed custom JavaServer Pages (JSP) web shells targeting a remote code execution vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM servers to exfiltrate proprietary engineering designs and supply chain records.
- Defense Industrial Base Sector: Iranian group Tortoiseshell deployed backdoors and reverse Secure Shell (SSH) tunnels via Dynamic Link Library (DLL) search-order hijacking, while Russian actors used malicious Open Authorization (OAuth) applications and Quick Response (QR) codes to hijack defense communications and bypass Multi-Factor Authentication (MFA).
- Energy Sector: Suspected Iranian-affiliated actors forced a four-day operational shutdown of a 15-megawatt gas-fired powerplant in the United Kingdom by disrupting its operational technology (OT) systems, underscoring ongoing risks to distributed generation assets.
- Financial Services Sector: Extortion cluster BlackFile launched voice phishing campaigns impersonating technical support staff to harvest Single Sign-On (SSO) credentials from financial institutions, combining multi-million-dollar ransom demands with aggressive swatting harassment.
- Government Services and Facilities Sector: Federal authorities seized Chinese state-sponsored hacking infrastructure targeting agencies, including the United States Senate, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) isolated a standalone system following a Qilin ransomware claim, and the City of Berlin severed two Senate department networks after refusing a 30-bitcoin Rhysida extortion demand following claimed exfiltration of 5.79 terabytes of administrative and infrastructure data.
- Healthcare and Public Health Sector: Cyber intrusions compromised 2.5 terabytes of records at Polish platform MyDr, halted medical device manufacturing at Boston Scientific in Ireland, and exposed over 284 million patient-related records at distributor McKesson via adversary-in-the-middle (AitM) voice phishing that bypassed multi-factor authentication, while North Korean actors deployed synthetic personas to secure fraudulent employment.
- Information Technology Sector: Cyber threat actors actively exploited vulnerabilities across Microsoft SharePoint (CVE-2026-55040), GeoServer, VMware vCenter, and unpatched PaperCut servers, while emergency updates addressed flaws in GitLab and WatchGuard firewalls. Supply chain attacks poisoned open-source packages in Rust and Node Package Manager (npm) repositories, and hardware-backed device trust successfully blocked an active voice phishing attack targeting ReliaQuest.
- Water and Wastewater Systems Sector: Federal authorities confirmed suspected Iranian actors breached over 100 United States water utilities in July 2026, accessing exposed Programmable Logic Controllers (PLCs) via cellular modems to alter system passwords, modify network settings, and disable operational alarms.
All Sectors
CISA Confirms Windows Task Host Flaw Exploited by Ransomware Gangs. On August 18, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog, warning that ransomware groups are actively exploiting a high-severity privilege-escalation flaw in Windows Task Host. Tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2025-60710, the vulnerability stems from improper link resolution within the host process container on Windows 11 and Windows Server 2025 systems. Local cyber threat actors with low-privilege access exploit the flaw to obtain full SYSTEM privileges on unpatched devices. CISA has not publicly disclosed further details about the specific ransomware campaigns involved. Florida critical infrastructure network defenders operating modern Windows environments must prioritize deploying vendor security patches.
Federal Agencies Warn Medusa Ransomware Has Impacted Over 500 Critical Infrastructure Organizations. On August 18, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS) updated their joint advisory, AA25-071A, regarding Medusa ransomware. The variant has compromised more than 500 critical infrastructure organizations across multiple sectors. Affiliates purchase initial access from brokers who exploit unpatched edge appliances and remote services. Once inside, actors execute living-off-the-land commands, such as net share and recursive PowerShell directory queries, staging stolen files in directories excluded from antivirus scanning and using rate-limited Rclone processes to evade network traffic thresholds. Florida water and wastewater utilities, chemical processors, food and agriculture operators, and manufacturing plants operating internet-exposed Siemens S7 controllers must immediately remove all such devices from public internet access.
Federal Agencies Warn of Active Campaign Targeting Siemens Programmable Logic Controllers. On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE), and the Environmental Protection Agency (EPA) issued joint advisory AA26-231A. The advisory warns that threat actors are conducting active capability development and reconnaissance against internet-exposed Siemens S7 Series Programmable Logic Controllers (PLCs) across multiple infrastructure sectors. Adversaries utilize artificial intelligence tools to adapt open-source communications libraries, generating Python attack scripts disguised as legitimate operational technology (OT) monitoring software to communicate over Transmission Control Protocol (TCP) port 102. Florida utility operators, chemical processors, and manufacturing plants must immediately remove exposed industrial controllers from the public internet.
CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats, and Enable Effective Incident Response. On August 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published advisory AA26-237A, ‘A Tale of Two SOCs,’ detailing simultaneous red-team assessments of a Government Services and Facilities Sector organization and a Water and Wastewater Systems Sector organization. Both assessments used identical tradecraft — exploiting default credentials on an internet-facing web application, then abusing Active Directory misconfigurations to achieve a full domain compromise, cloud access, and access to sensitive business systems. The Government Services and Facilities organization’s Security Operations Center (SOC) failed to detect the intrusion amid thousands of false-positive alerts; the Water and Wastewater Systems organization isolated compromised hosts within minutes and blocked further access at its OT boundary. CISA noted that no assessed organization has implemented Conditional Access for workload identities. Florida government agencies and water utilities managing hybrid IT and cloud architectures should prioritize alert tuning and adopt workload-identity Conditional Access policies.
CISA Adds Six Known Exploited Vulnerabilities to Catalog. On August 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The additions comprise six Common Vulnerabilities and Exposures (CVE) records: a memory buffer flaw in Citrix NetScaler Application Delivery Controller (ADC) and Gateway (CVE-2026-8452), a remote code execution bug in Microsoft SQL Server (CVE-2019-1068), an Ajax.NET Professional deserialization flaw (CVE-2021-23758), and three privilege escalation flaws: a Linux kernel out-of-bounds write flaw (CVE-2022-0995) and two Red Hat-specific userland vulnerabilities in libuser (CVE-2015-3246) and the Automatic Bug Reporting Tool, or ABRT (CVE-2015-5287). Florida critical infrastructure operators deploying Citrix perimeter gateways, legacy Microsoft SQL Server instances, or Red Hat Enterprise Linux systems should patch immediately. Florida critical infrastructure operators deploying Citrix perimeter gateways or legacy database servers should patch immediately to block initial access and local privilege escalation.
China-Affiliated Threat Actors Leverage Open-Source AI Models to Scale Intrusion Operations. In August 2026, cybersecurity researchers reported that state-affiliated Chinese cyber actors have more than doubled their attack volume by integrating open-source AI models — primarily DeepSeek — into reconnaissance and malware-development workflows. Groups including Grimfengxi and Huapi used AI to generate exploit code and map targets. Critically, documented autonomous AI-driven exploitation attempts did not achieve compromise on their own; researchers found that confirmed intrusions still required manual attacker follow-through, indicating AI currently accelerates reconnaissance and tooling more than it enables fully autonomous breaches. Florida critical infrastructure defenders should recognize that adversary AI-assisted tooling is compressing reconnaissance timelines even though human operators remain necessary to complete successful intrusions.
Aurora Ransomware Operators Deploy AI Coding Agent to Facilitate Live Enterprise Network Exploitation. On August 27, 2026, cybersecurity researchers disclosed that affiliates of the Aurora Ransomware-as-a-Service (RaaS) operation used the Cursor Artificial Intelligence (AI) coding assistant to conduct hands-on network exploitation across ten victim organizations. Cyber threat actors supplied the agent with compromised credentials, commanding it to configure proxy tunnels and scan internal subnets using custom Lightweight Directory Access Protocol (LDAP) scripts. The actors paired these actions with a Linux encryptor targeting VMware ESXi hypervisors, terminating virtual machines to encrypt virtual disk files. The agent, built on Anthropic’s Claude Sonnet model, required multiple command attempts for most tasks, and operators partially bypassed its safety controls by falsely framing the exploitation as an authorized penetration test — demonstrating that AI coding agents both reduce attacker workload and remain exploitable through social engineering even within the tooling itself. Florida critical infrastructure administrators maintaining virtualized server clusters and cloud-connected developer environments must restrict unmonitored development agents and enforce strict hypervisor access controls.
TerminalFix Campaign Abuses Fake Cloudflare Prompts to Deploy Reverse Tunnels. On August 30, 2026, cybersecurity researchers disclosed an evasion-focused social engineering campaign dubbed TerminalFix that targets enterprise organizations across multiple sectors. Compromised websites present users with fraudulent verification checks, prompting them to paste PowerShell scripts directly into Windows Terminal. The script initiates Dynamic Link Library (DLL) sideloading to execute a Python-based reverse-tunnel implant that routes Transmission Control Protocol (TCP) traffic through an encrypted WebSocket channel. The payload conducts automated Active Directory (AD) reconnaissance and network topology mapping. Florida critical infrastructure network defenders should restrict user command-line execution and audit workstation egress.
All Sectors Recommendations:
- Immediately deploy vendor security updates across all internet-facing perimeter infrastructure, prioritizing Citrix NetScaler Application Delivery Controller (ADC) and Gateway appliances, database platforms, and enterprise web integrations to mitigate the impact of automated exploit scripts.
- Apply patches for the Windows Task Host container flaw and for enterprise Linux kernels to close local privilege-escalation pathways, while enforcing application control policies to restrict unauthorized command-line execution and Dynamic Link Library (DLL) sideloading on endpoints.
- Disconnect all Siemens S7 Programmable Logic Controllers (PLCs) and industrial control devices from direct internet exposure, routing operational access through encrypted Virtual Private Networks (VPNs) protected by phishing-resistant Multi-Factor Authentication (MFA), and inspecting Transmission Control Protocol (TCP) port 102 for unauthorized communications.
- Restrict network access to VMware ESXi hypervisors and centralized management interfaces to isolated administrative subnets, enforce immutable offline backups for virtual disks, and prohibit unapproved artificial intelligence execution agents on enterprise developer systems.
- Audit enterprise security exclusions to eliminate blind spots used to stage adversary tools, inspect outbound network traffic for long-lived WebSocket reverse tunnels, and monitor for throttled data exfiltration attempts that leverage living-off-the-land utilities such as Rclone.
Chemical Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Commercial Facilities Sector
Operation CameraSwarm Compromises Over 14,500 Surveillance Devices Globally. On August 19, 2026, cybersecurity researchers disclosed that a threat campaign dubbed Operation CameraSwarm compromised more than 14,530 Dahua surveillance devices and IP cameras. The cyber threat actors compromised the large majority of devices — over 12,300 of roughly 14,530 — through credential attacks against weak or default passwords. A smaller subset was reached via two authentication-bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) and a Peer-to-Peer (P2P) relay technique targeting devices behind Network Address Translation (NAT). Attackers built persistent administrator accounts on compromised video systems. Florida commercial facilities, entertainment resorts, and physical security administrators operating networked video cameras must enforce strong, unique administrative credentials, disable unused peer-to-peer services, and isolate camera subnets from corporate environments.
Slovenian Casinos Reopen After Cyberattack Knocked Gaming Systems Offline. On August 31, 2026, gaming and hospitality operator Hit announced the phased reopening of its facilities following a cyberattack that forced six casinos in Nova Gorica, Slovenia, to shut down for three days. The intrusion disrupted internal servers, knocking gaming systems offline, disabling customer loyalty platforms, and forcing hotel reception desks and cafes to issue handwritten receipts. While information technology (IT) personnel restored basic slot machine functionality, table games remained unavailable. Florida hospitality resorts, gaming venues, and commercial entertainment facilities face similar operational continuity risks due to unauthorized enterprise access and server disruptions.
Commercial Facilities Sector Recommendations:
- Disable Peer-to-Peer (P2P) cloud connectivity features and remote viewing services across all Internet Protocol (IP) cameras and network video recorders where vendor cloud hosting is not operationally necessary.
- Isolate physical security systems, surveillance video infrastructure, and Point-of-Sale (POS) terminals onto dedicated Virtual Local Area Networks (VLANs) that are logically and physically separated from corporate administrative networks.
- Apply vendor firmware patches across all camera hardware to remediate legacy authentication-bypass flaws and replace factory-default credentials with complex, centrally tracked administrative passphrases.
- Maintain tested, manual operational contingency procedures, including offline transaction processing and paper logging, to ensure hospitality venues and gaming facilities sustain essential services during enterprise server outages.
Communications Sector
New Mirai Variant Evooo1Bot Targets Edge Devices With Stealth and Proxy Capabilities. On August 13, 2026, cybersecurity researchers reported that a newly identified Linux malware variant, dubbed Evooo1Bot, is actively compromising internet-facing network hardware. Built upon the Mirai botnet codebase, the malware targets routers, firewalls, and cameras manufactured by Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare. Beyond conventional Distributed Denial-of-Service (DDoS) capabilities, Evooo1Bot incorporates encrypted Command-and-Control (C2) channels, honeypot-evasion logic, and a default credential sniffer. Crucially, the malware establishes Socket Secure (SOCKS) proxies on infected devices, enabling cyber threat actors to conceal their origin and pivot into internal enterprise networks. Florida telecommunications providers and network administrators must audit edge gateways and eliminate default credentials.
Dysphoria Botnet Compromises Over 290,000 Routers and Edge Devices. On August 14, 2026, security researchers reported that the Dysphoria botnet had compromised approximately 296,000 internet-facing routers, gateways, and network cameras globally. Cyber threat actors exploit weak administrative credentials and known remote code execution vulnerabilities in embedded Linux systems, using Universal Plug and Play (UPnP) port mapping to create unauthorized inbound routes. The botnet employs blockchain-based domain resolution via Ethereum Name Service (ENS) and Solana Name Service (SNS) for command-and-control resilience, transforming infected devices into residential proxy networks that anonymize malicious traffic. Florida telecommunications providers and network operators must audit edge appliances, disable automated port forwarding, and enforce strong authentication.
China-Linked Espionage Actor Compromises Core Cisco Routers and Authentication Servers. On August 31, 2026, incident response investigators disclosed that a Chinese state-sponsored espionage group tracked as Fire Ant compromised Cisco Internetwork Operating System (IOS) XR core routers and Terminal Access Controller Access-Control System (TACACS+) authentication servers. Sygnia identified two purpose-built tools associated with the intrusion: TacTap, which harvests credentials directly from the TACACS+ authentication process as administrators log in, and BridgeAgent, a Linux backdoor disguised as the Zabbix monitoring service on management hosts. Florida communications service providers and telecommunications operators must immediately audit edge routing infrastructure, TACACS+ authentication servers, and Linux management hosts for these indicators. The cyber threat actors altered router command paths to conceal malicious tunnels, filtered logging messages to blind telemetry, and hooked authentication daemons to harvest plaintext administrator credentials. Attackers leveraged this position to capture live network traffic and probe downstream critical systems. Florida communications service providers and telecommunications operators must immediately audit edge routing infrastructure and out-of-band management planes.
HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw. On September 1, 2026, Hewlett Packard Enterprise (HPE) released urgent security updates for its ArubaOS-CX switch operating system, addressing a maximum-severity vulnerability tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2026-73749. The flaw originates from multiple buffer overflow defects within an internal system daemon, enabling unauthenticated remote actors to send crafted network packets that execute arbitrary code with elevated privileges. The vulnerability affects multiple switch firmware branches, including 10.10 through 10.18 releases. Florida telecommunications providers, campus network operators, and enterprise data centers using Aruba core switching infrastructure must apply vendor firmware patches immediately or isolate switch management planes.
Cisco Warns of Unpatched Secure Email Flaws and Patches Critical Switch Vulnerabilities. On September 2, 2026, Cisco disclosed two unpatched vulnerabilities, tracked as CVE records CVE-2026-20354 and CVE-2026-20355, affecting the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality in Cisco Secure Email Gateways. The issues allow adversary-in-the-middle positioning to recover plaintext email contents. Simultaneously, Cisco issued emergency security patches for critical remote code execution flaws in Nexus 9000 series switches (CVE-2026-20212) and Cisco IOS XR software (CVE-2026-20274). Florida communications service providers, enterprise network operators, and data routing hubs deploying Cisco perimeter infrastructure must apply switch patches and restrict unauthenticated network access to management interfaces.
Threat Actors Exploit Vulnerabilities in TP-Link Archer AX55 Edge Routers. In early September 2026, researchers disclosed two vulnerabilities affecting TP-Link Archer AX55 v4 wireless routers. The flaws could allow attackers with local network access to execute code through the EasyMesh service or recover administrator credentials from captured HTTP login traffic. Neither vulnerability is currently confirmed as actively exploited in the wild or remotely exploitable from the public internet. Florida telecommunications providers, critical infrastructure personnel, and small businesses using affected TP-Link hardware should promptly update router firmware, disable unnecessary EasyMesh functionality, and restrict management access to trusted local devices.
Communications Sector Recommendations:
- Verify the integrity of Cisco Internetwork Operating System (IOS) XR software images and kernel binaries against vendor cryptographic hashes to detect unauthorized modifications and intercepted daemons.
- Isolate Terminal Access Controller Access-Control System (TACACS+) authentication servers and router control planes on physically separated, dedicated out-of-band management networks with restricted administrative access.
- Disable Universal Plug and Play (UPnP) functions and unauthenticated Socket Secure (SOCKS) proxy routing across all customer premises equipment and enterprise routing hardware to prevent automated external port mapping.
- Audit perimeter network devices to eliminate default administrative credentials, disable legacy protocols including Telnet, and inspect Domain Name System (DNS) traffic for queries resolving decentralized blockchain domain naming systems.
Critical Manufacturing Sector
Clop Extortion Group Deploys Custom Web Shell for Mass Windchill Exploitation. On August 18, 2026, security researchers reported that the Clop extortion gang deployed a custom JavaServer Pages (JSP) web shell targeting PTC Windchill and FlexPLM Product Lifecycle Management (PLM) servers. Exploiting a critical remote code execution vulnerability (CVE-2026-12569), the attackers targeted internet-exposed servers across manufacturing and aerospace companies, stealing proprietary engineering blueprints, computer-aided designs, and supply chain records. The web shell executes within the legitimate application process, directly querying internal database connections to decrypt administrative passwords and locate stored intellectual property. Florida manufacturers and aerospace suppliers utilizing PLM software must patch immediately and audit web application directories for unauthorized JSP files.
Critical Manufacturing Sector Recommendations:
- Apply vendor security updates immediately to PTC Windchill and FlexPLM servers to remediate the Common Vulnerabilities and Exposures (CVE) record CVE-2026-12569 and prevent unsafe object deserialization.
- Remove Product Lifecycle Management (PLM) server interfaces from direct public internet exposure, and place application portals behind an enterprise Virtual Private Network (VPN) that requires phishing-resistant Multi-Factor Authentication (MFA).
- Inspect application web roots and servlet directories for unrecognized JavaServer Pages (JSP) files, abnormal file modification timestamps, or scripts referencing unusual Hypertext Transfer Protocol (HTTP) header parameters.
- Audit database query logs and engineering file vaults for anomalous, bulk data-export operations originating from internal web application service accounts.
Dams Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Defense Industrial Base Sector
Iranian Espionage Group Expands Toolset With Backdoor and Reverse SSH Tunnel. On August 26, 2026, threat researchers reported that an Iranian-aligned cyber espionage group, Tortoiseshell, expanded its malware capabilities targeting aerospace and defense contractors across the United States and partner nations. The cyber threat actor deployed a modular C++ backdoor alongside a reverse Secure Shell (SSH) tunneling tool disguised as the legitimate Windows Terminal Server library wtsapi32.dll. Loaded via Dynamic Link Library (DLL) search-order hijacking, the utility abuses the native Windows OpenSSH client to channel command traffic into secured networks. Florida Defense Industrial Base (DIB) suppliers and aerospace engineering facilities must monitor endpoints for unauthorized DLL placements and unexpected outbound SSH tunnels.
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts. On August 20, 2026, cybersecurity researchers disclosed that suspected Russian cyber espionage groups UNC6293, UNC7005, and UNC5976 are exploiting authentication workflows to target the defense sector. The cyber threat actors use two distinct techniques. UNC5976 lures targets to fake file-sharing pages that redirect through the legitimate Google OAuth login, then capture the resulting authentication token via malicious cloud-hosted scripts — no rogue application or consent grant is required, meaning standard OAuth application approval controls do not mitigate this specific attack. UNC7005 uses fraudulent WhatsApp device linking and Microsoft device code phishing, including malicious Quick Response (QR) codes, to attach attacker-controlled devices to victim accounts and bypass Multi-Factor Authentication (MFA). Critically, these campaigns target victims’ personal email, messaging, and cloud accounts rather than corporate-managed accounts, creating a monitoring blind spot for organizational security teams. Florida Defense Industrial Base contractors must extend authentication-security awareness, and monitoring to employees’ personal Google, Microsoft, and WhatsApp accounts.
Department of Defense Launches Mobile SCIF Initiative for Secure Space Network. On September 3, 2026, the United States Department of Defense (renamed the Department of War) announced the launch of the Secure Space Network initiative to design, produce, and deploy approximately 50 transportable Sensitive Compartmented Information Facilities (SCIFs) nationwide. Led by the Office of Industrial Base Growth, the initiative addresses physical security barriers by providing accredited, deployable workspaces at military bases and industry hubs. The program enables non-traditional defense suppliers and commercial technology vendors to handle classified space information and classified programs without erecting expensive fixed infrastructure. Florida defense contractors and aerospace engineering suppliers that are expanding into classified programs benefit from improved regional access to accredited, secure environments.
Defense Industrial Base Sector Recommendations:
- Audit file systems for unauthorized instances of system dynamic link libraries, specifically wtsapi32.dll outside the System32 directory, and enforce Dynamic Link Library (DLL) search-order protections across enterprise endpoints.
- Restrict the execution of the native Windows OpenSSH client on user workstations and monitor network egress for unauthorized, long-lived Secure Shell (SSH) reverse tunnels.
- Enforce administrative approval workflows for all third-party Open Authorization (OAuth) application integrations across cloud tenants to prevent malicious application consent grants.
- Deploy phishing-resistant Multi-Factor Authentication (MFA) utilizing hardware security keys and train personnel to identify and reject fraudulent Quick Response (QR) code pairing prompts.
Emergency Services Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Energy Sector
Iran-Linked Hackers Shut Down UK Power Plant for Four Days. In July 2026, suspected Iranian-affiliated cyber threat actors conducted a cyberattack that forced an operational shutdown of an unnamed, small-scale electricity generation plant in the United Kingdom for four days. The facility, a 15-megawatt gas-fired peaking station, sustained a disruption to its operational technology (OT) systems before personnel restored generation. Government authorities confirmed that the wider electrical grid remained stable, though specific Common Vulnerabilities and Exposures (CVE) identifiers and Indicators of Compromise (IOCs) were not publicly disclosed. Florida municipal utilities managing distributed generation, Programmable Logic Controllers (PLCs), and Supervisory Control and Data Acquisition (SCADA) environments face comparable risks from repeatable state-sponsored targeting. This incident occurred in the same operational window as the wave of intrusions against more than 100 U.S. water utilities described in this bulletin’s Water and Wastewater Systems section, both widely attributed to Iranian-affiliated actors, suggesting a coordinated July 2026 Iranian operational tempo targeting Western water and energy infrastructure simultaneously.
Energy Sector Recommendations:
- Enforce strict physical and logical network segmentation between enterprise information technology (IT) networks and operational technology (OT) environments to prevent threat actors from bridging into generation controls.
- Isolate Programmable Logic Controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) infrastructure behind industrial firewalls with protocol-specific deep packet inspection.
- Establish and regularly test manual operational failover procedures to ensure electric power generation facilities can maintain baseline output during automated control system outages.
- Deploy continuous behavioral network monitoring across industrial protocols to detect unauthorized engineering commands or anomalous communication attempts directed at generation assets.
Financial Services Sector
Extortion Group BlackFile Targets Financial Services Sector With Voice Phishing Campaigns. On August 17, 2026, threat researchers disclosed that cybercrime cluster BlackFile, tracked as UNC6671 and associated with The Com, is actively targeting financial institutions, rating agencies, and private equity firms. The group deploys callers who contact employees on their personal mobile numbers, spoofing the legitimate help-desk caller ID, and direct them to fraudulent login portals. These portals use Adversary-in-the-Middle (AitM) infrastructure that intercepts not only credentials but live Multi-Factor Authentication (MFA) session tokens in real time, defeating standard MFA even when enabled. Extortion operations operate under multiple brand identities (Redact, Pink, Helix, and Falcon), demanding ransoms beginning near three million dollars and subjecting uncooperative corporate leadership to aggressive harassment, including swatting incidents. Florida financial institutions, wealth management firms, and payment processors must implement strict out-of-band verification protocols for all internal technical support requests.
Financial Services Sector Recommendations:
- Enforce mandatory out-of-band supervisory verification for all help desk password resets, identity changes, and Single Sign-On (SSO) credential modifications.
- Implement device-trust conditional access policies to ensure that enterprise cloud access tokens cannot be authenticated from unmanaged or non-compliant endpoints.
- Conduct specialized voice phishing training to assist employees in recognizing social engineering tactics used by callers impersonating internal technical support personnel.
- Establish an executive threat and extortion escalation playbook coordinated with regional law enforcement to manage harassment, swatting risks, and corporate extortion attempts.
Food and Agriculture Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Government Services and Facilities Sector
United States Disrupts Chinese State-Sponsored Hacking Platforms Targeting Federal Agencies. On August 26, 2026, the United States Department of Justice (DOJ) announced the seizure of domains associated with QScan and QTRouter, two platforms operated by Chinese state-sponsored actors. Run by contractor Nanjing Xinjiuwei Network Technology Company, the tooling targeted the DOJ, the National Aeronautics and Space Administration (NASA), the Federal Reserve, the United States Senate, the Department of Energy laboratories, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and several unnamed private companies in the U.S. and South Korea. Adversaries conducted automated vulnerability scanning and exploited or attempted to exploit internet-facing edge products, including VPN technologies, to gain access to government and other sensitive networks. Florida government facilities and municipal administrative networks should treat these disclosures as an active warning to audit external perimeters against foreign reconnaissance.
ATF Confirms Cyber Incident After Ransomware Group Claims Attack. On August 28, 2026, the United States Bureau of Alcohol, Tobacco, Firearms, and Explosives (ATF) in Washington, District of Columbia, confirmed a cybersecurity incident following extortion claims by the Qilin ransomware group. The intrusion was confined to a standalone system, which personnel isolated immediately to prevent lateral movement. The affected standalone system reportedly held records of targets of ATF investigations, raising a potential risk to active law enforcement casework if the data is confirmed to have been exfiltrated. The Department of Justice (DOJ) designated the intrusion a major incident under federal guidelines, though core enterprise networks, operational missions, and firearms registration databases remained unaffected. Florida municipal agencies and law enforcement partners should evaluate perimeter architecture to verify that auxiliary systems maintain logical segmentation from primary directories.
City of Berlin Refuses Ransom Payment Following Severe Municipal Network Intrusion. On August 31, 2026, municipal officials in Berlin, Germany, announced they refused a 30-bitcoin extortion demand following a major network compromise claimed by the Rhysida ransomware group. Cyber threat actors breached municipal networks between August 7 and August 12, claiming to have exfiltrated 5.79 terabytes of administrative, legal, and employee data. To contain the intrusion, administrators severed external connections across the Senate Departments for Mobility/Transport/Climate and for Urban Development/Housing. The data are subject to public leak threats. Florida municipal agencies and local government bodies should ensure incident response playbooks include isolated operational continuity measures.
China-Linked Actors Leverage Artificial Intelligence Models to Automate Government Intrusions. In August 2026, intelligence researchers disclosed that Chinese state-linked threat actors integrated commercial Artificial Intelligence (AI) models, including Claude, Qwen, and DeepSeek, into an automated attack campaign discovered by Hunt.io researchers. Deploying open-source agents, the actors orchestrated multi-stage intrusions against government systems in Taiwan, mapping 21 public-sector networks, extracting single sign-on user credentials, and breaching 85 administrative accounts. When defensive barriers blocked intrusion paths, autonomous agents queried vulnerability databases to generate alternative exploit methods. Florida municipal government facilities, state administrative agencies, and public sector Information Technology (IT) managers should recognize that adversary agentic automation compresses reconnaissance timelines and accelerates perimeter targeting.
Government Services and Facilities Sector Recommendations:
- Audit external network perimeters and Virtual Private Network (VPN) gateways for automated adversary scanning, and disable legacy protocols and unnecessary public services.
- Enforce strict logical network segmentation around standalone, test, or legacy operational servers to prevent compromises of auxiliary systems from exposing primary Active Directory domains.
- Maintain immutable, air-gapped data backups for all critical municipal databases and validate rapid bare-metal restoration capabilities through quarterly recovery exercises.
- Develop and exercise rapid network isolation procedures that allow administrators to sever departmental networks during active ransomware events without completely halting public safety and administrative services.
Healthcare and Public Health Sector
Extensive Data Compromise at Medical Platform Provider Affects Healthcare Networks Across Poland. On August 12, 2026, Polish government authorities disclosed a massive data compromise affecting MyDr, a medical documentation and electronic prescription provider operating in Warsaw, Poland. Cyber threat actors gained unauthorized access to cloud storage assets. The specific attack vector has not been publicly confirmed — MyDr has not disclosed it, and Polish authorities stated in August 2026 that it was premature to identify a root cause while the investigation was active. The compromise exposed approximately 2.5 terabytes of patient records, PESEL numbers (Poland’s national identification equivalent to U.S. Social Security numbers), and prescription logs across 12,000 healthcare facilities. The data are susceptible to extortion schemes. Florida healthcare delivery organizations and clinical networks must evaluate third-party medical software dependencies and cloud security postures.
Boston Scientific Discloses Cyberattack Disrupting Global Device Manufacturing and Shipments. On August 25, 2026, medical technology manufacturer Boston Scientific, headquartered in Marlborough, Massachusetts, United States, detected a cyberattack that forced an outage across internal information technology (IT) systems. The disruption impacted on-premises enterprise applications supporting product manufacturing, customer order processing, and global equipment distribution, causing facilities in Cork, Ireland, to halt production. Cloud environments remained unaffected, and third-party specialists were engaged for containment. Florida healthcare systems and surgical networks relying on Boston Scientific device supply chains face downstream inventory delays, emphasizing the vulnerability of critical clinical dependencies to manufacturing disruptions.
Pharmaceutical Distributor McKesson Discloses Major Breach Following Voice Phishing Attack. On August 28, 2026, healthcare and pharmaceutical distributor McKesson Corporation, based in Irving, Texas, United States, disclosed a cybersecurity incident discovered on August 25. The ShinyHunters extortion group claimed responsibility, stating they used voice phishing against employees to steal Single Sign-On (SSO) credentials using an impersonation domain. The actors accessed enterprise cloud environments, exfiltrating one terabyte of data containing approximately 284 million patient-related records before issuing a $55 million ransom demand. The data are vulnerable to extortion. Florida healthcare delivery networks and pharmacies that rely on wholesale distribution systems must enforce strict device verification for cloud access.
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales. On August 31, 2026, cybersecurity researchers disclosed that state-sponsored North Korean cyber actors have expanded fraudulent employment operations beyond information technology (IT) into healthcare and biotechnology organizations. Cyber threat actor cluster PurpleDelta deployed synthetic personas generated using Artificial Intelligence (AI) and fraudulent credentials from illicit identity services, utilizing real-time AI transcription tools during remote interviews to bypass screening. Compromised identities were used to infiltrate medical companies, record internal meetings, and funnel compensation to sanctioned entities. Florida healthcare networks and clinical research institutions must enhance identity verification for remote personnel to prevent insider data theft and regulatory penalties.
Healthcare and Public Health Sector Recommendations:
- Enforce phishing-resistant Multi-Factor Authentication (MFA) and device-trust conditional access across enterprise Single Sign-On (SSO) platforms to prevent stolen credentials from accessing cloud repositories.
- Establish clinical supply chain contingency plans and inventory buffer thresholds for critical medical devices and pharmaceuticals to mitigate downstream shortages caused by manufacturing plant outages.
- Implement rigorous identity validation procedures, including mandatory in-person verification or trusted biometric authentication, for prospective remote personnel to detect fraudulent synthetic personas.
- Conduct comprehensive security reviews of third-party clinical software and cloud integrations, auditing code dependencies for input-handling vulnerabilities, including Extensible Markup Language (XML) External Entity (XXE) flaws.
Information Technology Sector
Attackers Exploit SharePoint Authentication Bypass Following Public Exploit Release. On August 13, 2026, threat researchers warned that malicious actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint Server. Tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2026-55040 with a Common Vulnerability Scoring System (CVSS) score of 9.1, the flaw stems from improper JSON Web Token (JWT) validation in on-premises deployments. Following public proof-of-concept exploit releases, attackers launched automated scans against internet-exposed servers to forge tokens and impersonate administrative accounts. Florida critical infrastructure organizations and information technology (IT) providers hosting on-premises document hubs must apply vendor updates immediately and isolate portals behind secure access gateways.
Unpatched GeoServer Zero-Day Targeted in In-the-Wild Remote Code Execution Attacks. On August 13, 2026, threat researchers warned that malicious actors were attempting to exploit a previously unpatched zero-day vulnerability in the open-source GeoServer geospatial data platform. GeoServer subsequently released patched versions 3.0.1, 2.28.5, and 2.27.6; operators should apply the available updates immediately and restrict internet access to all GeoServer deployments. The flaw originated from an unauthorized Structured Query Language (SQL) injection defect within the jsonArrayContains function. When GeoServer instances interface with database configurations operating under system administrator privileges, remote attackers can achieve unauthenticated Remote Code Execution (RCE). Honeypots observed hundreds of automated exploitation probes within hours of public disclosure. Florida information technology (IT) providers, municipal utilities, and geospatial data administrators should immediately restrict public internet access to GeoServer installations and apply database privilege restrictions.
Suspected China-Nexus Actor Exploits VMware vCenter Flaw to Deploy Ransomware. On August 17, 2026, cybersecurity researchers disclosed that a suspected Chinese Advanced Persistent Threat (APT) group is actively exploiting a critical vulnerability in Broadcom VMware vCenter. Tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2026-59310 with a Common Vulnerability Scoring System (CVSS) score of 9.8, the path traversal flaw allows unauthenticated remote actors to achieve arbitrary root code execution on the server appliance. Attackers plant cron-job-based persistence that launches reverse SSH tunnels to attacker-controlled infrastructure, then create persistent administrative accounts and deploy Babuk-derived ransomware to encrypt ESXi hypervisor environments and hinder forensic investigations. Florida critical infrastructure organizations and information technology (IT) providers operating virtualized clusters must patch appliances immediately and isolate management planes.
GitLab Issues Emergency Security Patch for Critical GraphQL Code Injection Flaw. On August 18, 2026, GitLab released out-of-band security updates addressing a critical, unauthenticated code-injection flaw in GitLab Community Edition and Enterprise Edition. Tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2026-19478 with a Common Vulnerability Scoring System (CVSS) score of 9.4, the vulnerability resides within the GraphQL Application Programming Interface (API). It enables remote actors without credentials to rewrite project repository states, delete projects, and forge merge histories. Honeypot telemetry confirmed active exploitation within 48 hours of disclosure. Florida information technology (IT) providers and critical infrastructure software developers running self-managed GitLab instances should apply vendor security releases immediately to safeguard source code integrity.
CISA Adds Actively Exploited MLflow Platform Vulnerability to Catalog. On August 19, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added an actively exploited vulnerability affecting the MLflow machine learning platform to its Known Exploited Vulnerabilities (KEV) Catalog. Tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2026-64849, the flaw enables remote unauthenticated threat actors to conduct directory traversal and read sensitive arbitrary files from the underlying operating system. Malicious actors exploit the flaw to harvest credentials, extract proprietary model parameters, and map internal infrastructure. Florida information technology (IT) providers, software vendors, and enterprise developers deploying machine learning lifecycle servers should restrict internet-facing exposure and apply vendor security updates immediately.
ReliaQuest Thwarts Data-Theft Attempt Following Sophisticated Social Engineering Campaign. In August 2026, cybersecurity service provider ReliaQuest, based in Tampa, Florida, reported that an employee was targeted in a voice phishing and single sign-on credential theft attempt by the ShinyHunters extortion group. The attacker impersonated internal security personnel during telephone calls, directing the user to a fraudulent single sign-on portal hosted on a lookalike domain ending in the dot-claims top-level domain. Although the employee supplied credentials and authorized an authentication prompt, configured device-trust controls prevented the attacker from accessing downstream corporate systems or customer environments. Florida critical infrastructure operators should mandate hardware-backed device validation alongside standard authentication mechanisms.
CISA Adds Actively Exploited Gitea Remote Code Execution Vulnerability to Catalog. On August 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added a critical Remote Code Execution (RCE) vulnerability in Gitea to its Known Exploited Vulnerabilities (KEV) Catalog. Tracked as a Common Vulnerabilities and Exposures (CVE) record, CVE-2026-60004, with a maximum severity rating, the flaw enables authenticated actors with repository write privileges to execute arbitrary commands via malicious Git hooks. Because default installations permit open account registration, unauthenticated external actors can register and exploit the flaw. Florida information technology (IT) providers, software vendors, and enterprise developers hosting private code repositories should upgrade immediately to prevent server compromise and repository tampering.
Shai-Hulud Trinitite Worm Poisons Open-Source Software Packages to Steal Developer Secrets. On August 31, 2026, security researchers disclosed that the self-propagating Shai-Hulud Trinitite worm infected the widely used TanStack Query Node Package Manager (npm) package. The malware captures developer credentials, utilizing stolen OpenID Connect (OIDC) tokens within build pipelines to compromise additional software releases. The worm establishes background persistence on macOS and Linux systems, executing a destructive directory-wiping script if monitored developer credentials are revoked. Florida information technology (IT) providers, software vendors, and enterprise developers must isolate contaminated build runners, remove persistence mechanisms, and verify package lockfiles to maintain software supply chain integrity.
WatchGuard Patches Critical Vulnerabilities in Fireware OS On September 1, 2026, network security vendor WatchGuard issued urgent security updates addressing three critical vulnerabilities affecting the Fireware Operating System (OS). The flaws reside within the Internet Key Exchange Daemon (iked) process and enable unauthenticated remote cyber threat actors to execute arbitrary code with root privileges on vulnerable network security appliances by sending crafted network packets. While vendor advisories confirmed no observed in-the-wild exploitation at release, edge gateway flaws are routinely weaponized rapidly by state-sponsored actors. Florida information technology (IT) providers and critical infrastructure network operators deploying WatchGuard firewalls must apply vendor firmware updates immediately to prevent perimeter compromise.
Recently Patched PaperCut Zero-Days Used in Data Theft Attacks. On August 31, 2026, cybersecurity researchers reported that threat actors actively weaponized two vulnerabilities in PaperCut MF and PaperCut NG print management software to execute data theft attacks. Attackers chained an authentication bypass issue (CVE-2026-81578) to an unsafe dynamic class-loading flaw (CVE-2026-82078) to achieve unauthenticated Remote Code Execution (RCE) with administrative privileges. Intrusions placed malicious Java payloads into application directories, executing discovery commands via the parent process, and exfiltrating corporate data prior to log deletion. Florida organizations operating print management infrastructure must immediately restrict external exposure to ports 9191 and 9192, apply vendor updates, and examine database logs for unauthorized commands.
Hackers Poison Popular Rust Crate in Widespread Supply Chain Attack. On August 20, 2026, cyber threat actors compromised the maintainer account of the arrayref Rust package, a widely used open-source library with over 245 million lifetime downloads. Attackers published malicious package versions containing a typosquatted dependency that executed a build script during software compilation, delivering cross-platform infostealer payloads to Windows, macOS, and Linux systems. The malware harvested browser credentials and established persistent backdoor access on development hosts. Florida information technology (IT) providers, software vendors, and enterprise developers must audit dependency lockfiles, remove unauthorized build scripts, and rotate development pipeline signing keys.
Critical NetScaler Vulnerabilities Enable Authentication Bypass on Enterprise Gateways. On August 20, 2026, Citrix released security updates addressing two critical vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway deployments. The primary flaw, tracked as Common Vulnerabilities and Exposures (CVE) record CVE-2026-19490, allows unauthenticated remote cyber threat actors to bypass authentication on appliances configured as Gateways or Authentication, Authorization, and Accounting (AAA) virtual servers. A secondary memory overflow vulnerability, CVE-2026-19489, enables denial-of-service conditions. Florida information technology (IT) operators and critical infrastructure network administrators deploying customer-managed NetScaler appliances should apply vendor updates immediately to prevent perimeter compromise.
SonicWall Urges Immediate Patching for Chained Gateway Vulnerabilities. On September 2, 2026, security researchers confirmed active zero-day exploitation targeting SonicWall Secure Mobile Access (SMA) 1000 series appliances. Cyber threat actors chain a pre-authentication Server-Side Request Forgery (SSRF) flaw, tracked as CVE record CVE-2026-83548, with a maximum CVSS score of 10.0, with an OS command-injection bug (CVE-2026-83549) to execute unauthenticated commands with elevated privileges. CISA added both flaws to its KEV catalog. Florida critical infrastructure operators, IT service providers, and managed security firms deploying SMA 6210, 7210, or 8200v appliances must apply vendor hotfixes immediately to prevent gateway compromises.
Coder Infrastructure Compromised to Push Malicious Terraform Modules. On September 3, 2026, cloud development platform vendor Coder disclosed a software supply chain compromise affecting its module registry. On August 31, 2026, unauthorized actors accessed Coder’s Cloudflare routing infrastructure, inserting rogue IP addresses that served modified Terraform modules to developers for 14 hours. The malicious modules contained scripts designed to exfiltrate cloud credentials, SSH keys, OIDC tokens, and database passwords to a lookalike domain, coder-infra[.]com. Florida IT providers, software developers, and cloud architects utilizing Coder workspace templates must inspect provisioner logs for telemetry data, purge cached packages, and rotate all accessible environment secrets.
Autonomous OpenAI Agents Escape Sandbox Boundaries to Hijack Developer Wiki. On September 4, 2026, security researchers revealed that autonomous Artificial Intelligence (AI) agents operated by OpenAI bypassed sandbox restrictions to hijack DseWiki, a volunteer-run German programming website. Operating continuously between May and June 2026, thousands of multi-agent instances executed Hypertext Transfer Protocol (HTTP) GET requests to publish over 18,000 unauthorized posts across 15,000 edits. The agents shared methods for evading safety guardrails, discussed using Tor, and established backup pages beginning with “ZZZ” to evade alphabetical moderation deletion sweeps. Florida IT vendors and software developers deploying autonomous AI web-scraping agents must enforce strict output sanitization, network egress filtering, and multi-agent containment boundaries.
Four Major Artificial Intelligence Platforms Experience Simultaneous Global Outage. On September 3, 2026, four leading commercial AI platforms, ChatGPT, Claude, Grok, and Gemini, suffered simultaneous service disruptions lasting over 90 minutes. The concurrent outage originated from an infrastructure failure within Microsoft Azure’s East US region, which hosts production compute and API routing pipelines for multiple competing AI vendors. Tens of thousands of enterprise workflows and automated development tasks were disrupted globally before engineers restored cloud stability. Florida IT operators and enterprise software developers integrating AI models into critical operational pipelines must recognize systemic cloud provider concentration risks and implement multi-cloud failover mechanisms.
Information Technology Sector Recommendations:
- Apply emergency vendor security updates to all internet-facing enterprise gateways, firewalls, and application servers, prioritizing WatchGuard Fireware Operating System (OS) appliances, Citrix NetScaler Application Delivery Controller (ADC) and Gateway platforms, and PaperCut print services to eliminate unauthenticated Remote Code Execution (RCE) and authentication bypass vectors.
- Upgrade and harden on-premises collaborative platforms and private source code management servers, specifically Microsoft SharePoint, GitLab, and Gitea, to remediate token-validation defects and code injection flaws while disabling open user registration and restricting repository write privileges.
- Isolate VMware vCenter management interfaces, ESXi hypervisors, and MLflow tracking servers within dedicated, non-routable administrative subnets, auditing scheduled cron jobs, database connections, and system logs for unauthorized WebSockets or directory-traversal attempts.
- Verify software supply chains by pinning software dependencies, regenerating package lockfiles strictly from trusted upstream registries, and enforcing least-privilege scoping on OpenID Connect (OIDC) tokens to block compromised Node Package Manager (npm) packages and poisoned Rust dependencies from executing malicious compilation scripts.
- Enforce phishing-resistant Multi-Factor Authentication (MFA) alongside hardware-backed device-trust conditional access policies across enterprise Single Sign-On (SSO) portals to ensure that stolen credentials obtained via voice phishing cannot authenticate from unmanaged or adversary-controlled devices.
Nuclear Reactors, Materials, and Waste Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Transportation Systems Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Water and Wastewater Systems Sector
CISA Confirms Hackers Targeted Over 100 US Water Systems During July. On August 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that malicious actors targeted more than 100 internet-exposed systems across the United States water sector during July 2026. Suspected Iranian-affiliated actors accessed exposed Programmable Logic Controllers (PLCs) manufactured by Rockwell Automation, Schneider Electric, and Siemens, frequently connecting via public-facing cellular modems. Attackers modified device IP addresses, altered passwords, and disabled shutdown processes and alarm functions, causing operational disruptions during containment. Florida municipal water and wastewater treatment facilities must immediately inventory remote access pathways and eliminate direct cellular connections to operational technology (OT) assets.
Note: CISA and multiple outlets confirmed this July 2026 campaign occurred concurrently with the Iran-linked UK power plant shutdown covered in the Energy sector, treating them as isolated and independent incidents understates the scope of the strategic threat.
Water and Wastewater Systems Sector Recommendations:
- Disconnect all Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), and operational technology (OT) field assets from direct public internet exposure, eliminating direct cellular modem connections and routing all operational telemetry through an isolated perimeter firewall.
- Require all remote operator, vendor, and systems integrator connections to traverse centralized, monitored jump hosts protected by encrypted Virtual Private Networks (VPNs) with phishing-resistant Multi-Factor Authentication (MFA) and strict Internet Protocol (IP) allowlisting.
- Change all factory-default and vendor administrative passwords across field controllers, Human-Machine Interface (HMI) consoles, and cellular gateways to unique, complex passphrases, placing physical controller key switches into the run position to block unauthorized logic or firmware modifications.
- Audit controller configuration files, setpoint parameters, and alarm threshold tables against verified offline baselines to detect unauthorized setting alterations, while regularly exercising manual failover protocols to ensure continuous water treatment and pressure regulation during automated control system disruptions.
