• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

Commonground

Senior Moderator
Wisconsin

NOTIFICATION OF CYBER INCIDENT

AUGUST 6, 2026

This is to inform you that Washburn County is currently responding to a cyber incident that is under investigation. As part of that investigation, the county is working to determine the nature and scope of the activity.

Upon becoming aware of the activity on the morning of August 6, 2026, the county immediately initiated its incident response procedures and took steps to protect county systems and data while beginning a thorough investigation. The county is working closely with qualified cybersecurity professionals and other appropriate partners to investigate the activity, assess any potential impact, and safely restore affected technology services.

To support the county’s response and help ensure the safe operation of county services, the county has made the decision to shut down county technology on August 6, 2026. This decision allows county personnel and incident response specialists to continue assessing affected technology systems while minimizing disruption to county operations.

During this time, staff and the public may experience temporary disruptions to certain county services that rely on internet access or communications via county phone lines. The court system and county offices remain open to the public at this time. The county is actively working to safely restore impacted technology services as they can be appropriately returned to operation. Additional security measures have also been implemented to help reduce the risk of further disruption while the investigation continues.

At this time, the investigation remains ongoing, and we are limited in the information we can provide. While we understand the desire for immediate answers, it is important that any information shared is accurate and based on verified facts. We are committed to providing timely updates as additional information becomes available.At this time, there is no action required by staff or the public. If the investigation determines that personal information was affected, or that additional steps are recommended or required, the county will communicate directly with impacted individuals and provide appropriate guidance.

Please continue to monitor the county’s official communication channels for updates regarding county operations and this investigation. We will be using our website: www.co.washburn.wi.us for updates – notification of any meeting changes will continue to be listed there as well. In addition, we ask that any calls be directed to 911 and they will be routed to the appropriate department until phone service is restored. Updates will also be sent to media outlets as requested.

Protecting the physical and digital safety and security of our staff and constituents remains our highest priority. We recognize the trust that staff and public place in us and appreciate your patience and understanding as we work diligently to investigate this matter, safely restore services, and determine whether any additional actions are necessary. We apologize for any inconvenience this situation may cause and will continue to provide updates as appropriate throughout the investigation.

Lolita Olson, Board Chair
Washburn County

https://co.washburn.wi.us/wp-content/uploads/2026/08/Cyber-Communication-Letter.pdf
 
California city declares state of emergency after cyberattack on computer systems

August 9, 2026 at 3:26 PM EDT
The City Council for Suisun City declared a state of emergency Saturday after a cyberattack forced the municipality to shut down its information technology network.

The attack affected the communication operations of the fire and police departments in the Northern California city, including the routing of 911 calls.

Suisun City officials said in a statement that the attack posed no imminent threat to the public and that all public safety services remained active. The computer network was shut down to contain the threat and preserve evidence for a federal investigation.

Suisun City dispatchers are taking emergency police and fire calls through the Solano County dispatch center. Online city services and internal operations remained temporarily unavailable as of Sunday morning while cybersecurity experts investigated the incident and worked to restore systems.

The attack is believed to be the first of its kind in the city of 30,000 located 55 miles north of San Francisco, as the threat of cybersecurity disruptions of essential services in local communities across the country grows.

continued: https://www.yahoo.com/news/us/articles/california-city-declares-state-emergency-192626638.html
 
Nature - Scientific Reports
10 August 2026
Enhancing botnet attack detection using a hybrid deep learning model combining network flow and DNS query features with explainable AI for cybersecurity

Abstract

The growing dependency on the Internet and the expanding demand for connectivity have led to an increasing threat of botnet-based cyberattacks. Botnets are networks of infected devices managed by a botmaster. The botnets can launch distributed denial of service (DDoS) attacks, financial losses, operational disruptions, and data breaches. Due to the complex and dynamic behavior of botnet activities, existing techniques for botnet identification can be circumvented, resulting in high false negative rates. The proposed research provides a novel deep learning-based hybrid model to enhance botnet identification by leveraging both network flow and Domain Name System (DNS) query features. The two categories of features are processed independently through parallel subnetworks. In each subnetwork, spatial features are extracted using a convolution mechanism. The feature maps obtained from the network and DNS data are then fused to form the final feature vector. A multi-head attention mechanism is applied to focus on relevant features. Further, the features are sequentially processed using a bi-directional Long Short-Term Memory (BiLSTM) layer to capture temporal patterns. The proposed model achieved 99.10% accuracy in detecting botnets, and 98.90% accuracy, 98.95% precision, 99.10% recall, and 98.10% F1-score in identifying the categories of attacks. The comparative analysis carried out highlights the efficiency of the proposed method, resulting in significant improvements over existing methods. Additionally, explainable AI methods, SHapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME) are used to explain the predictions, demonstrating the interpretability and transparency of the predictions made by the proposed model.

https://www.nature.com/articles/s41598-026-65732-w

 
Cotton calls on Treasury to reshape tax guidance to support cybersecurity investment in critical infrastructure OT systems
AUGUST 10, 2026

A U.S. Senator has asked Treasury Secretary Scott Bessent to ensure federal tax guidance encourages investment in, and modernization of, the nation’s OT (operational technology) systems, which vastly control and secure critical infrastructure installations. Tom Cotton, an Arkansas Republican, noted that outdated and underfunded OT infrastructure is leaving water systems, power facilities and industrial plants, especially in rural states, vulnerable to adversarial threats and attacks.

He cited recent incidents involving Chinese state-sponsored hackers inside a New England utility, Iranian actors exploiting PLCs (programmable logic controllers) across U.S. critical infrastructure, and a coordinated cyberattack that disrupted OT at more than 30 community water systems in Minnesota.

Continued: https://industrialcyber.co/critical...stment-in-critical-infrastructure-ot-systems/
 
North Carolina
Cyberattack hits North Carolina ports, raising supply chain risks
August 10, 2026Updated: 14 hours ago

North Carolina State Ports Authority is still recovering after a cyberattack disrupted IT systems across its three port facilities last week, forcing manual operations and delaying cargo processing.

An “operations alert” warning that a “systems-wide outage” would delay gate openings at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port was first posted on the North Carolina Ports website on August 4th.

-snip-

The incident did not affect maritime safety, a spokesperson for the US Coast Guard told CyberScoop over the weekend, adding that it was monitoring the situation and coordinating with state authorities and other federal partners.

Cybernews has reached out to the North Carolina State Ports Authority for clarification.

... https://cybernews.com/news/north-carolina-ports-cyberattack-disrupts-cargo-supply-chain-risk/

Please also see: North Carolina State Budget Makes Historic Investment in Cybersecurity and Digital Readiness









 
Post #2:
August 9, 2026 at 3:26 PM EDT
The City Council for Suisun City declared a state of emergency Saturday after a cyberattack forced the municipality to shut down its information technology network​...

Suisun City leaders to hold another emergency meeting after malware attack
​August 11, 2026

A Northern California city will hold another emergency council meeting Tuesday, days after a malware attack disrupted public safety systems and other city operations.
Suisun City leaders are set to meet at 8 a.m. for a special session that will include a closed-door portion. The city has not publicly detailed what council members will discuss behind closed doors.

... https://www.cbsnews.com/sacramento/news/suisun-city-malware-cyberattack-2nd-emergency-meeting/
 
Blog
Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact

​Released August 11, 2026​
This year marks the 20[SUP]th[/SUP] year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure.

As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise.

Building Partnerships for a More Secure Nation

Cyber Storm began with 500 participants 20 years ago as a national effort to bring government and industry together in one place when our nation needed a way to understand how a major cyber incident could unfold across many sectors at once.

This number has grown, and this fall’s Cyber Storm exercise will bring together 2,000 critical infrastructure owners and operators from around the country, spanning everything from large national companies to local utilities. Participants include legal teams, crisis communication, IT managers, and organizational leaders. For many of them, this exercise is the first time they meet those who they will need to work with during a cybersecurity crisis.

Continued: https://www.cisa.gov/news-events/ne...rs-readiness-resilience-and-real-world-impact
 
CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts
Released August 12, 2026​

WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today released the K-12 Cybersecurity Foundations Resource Package, a comprehensive collection of guides, videos and supplemental materials to help K‑12 schools and districts prevent, mitigate and respond to prevalent cyber threats. Based on current cybersecurity best practices and frameworks, the resource package outlines cost-effective, actionable and customizable steps that K-12 institutions can take to develop and maintain effective cybersecurity programs.

Cyber threats are a significant and growing risk for K-12 schools and districts. These institutions maintain sensitive student and staff data, rely on diverse technologies and systems, have multiple users with varying privileges and levels of access, and often lack resources for robust cybersecurity programs. Cyber incidents can disrupt learning and school operations, compromise student privacy and safety, and expend valuable and limited resources.

The new resource package was developed in direct response to these needs, helping K-12 school and district personnel better understand cyber risks, make informed decisions and implement cybersecurity best practices. The package includes resources tailored for both K-12 leaders and non-technical school staff, as well as school and district cybersecurity and IT professionals.

“Cyberattacks on K-12 schools and districts jeopardize not only the integrity of our educational mission, but the safety and security of our students and teachers as well. These impacts are often felt well beyond the classroom,” said CISA Acting Director Nicholas Anderson. “The K‑12 Cybersecurity Foundations Resource Package empowers school communities with practical strategies and supports our school safety mission. CISA is helping the K-12 community proactively defend against cyber threats, minimize disruption and better protect the systems our nation’s children, parents and educators depend on every day.”

The K-12 Cybersecurity Foundations Resource Package includes a Getting Started Guide and a more detailed Implementation Guide, along with a six-part video series and quick reference materials to help K-12 leaders and personnel understand key concepts and navigate the package’s various components. The guides outline essential cybersecurity practices organized around eight key objectives:
  • Protecting login credentials,
  • Safeguarding devices and assets,
  • Testing backups,
  • Strengthening incident response capabilities,
  • Improving cybersecurity training,
  • Enacting policies to appropriately manage sensitive data,
  • Aligning investments with recognized cybersecurity frameworks, and
  • Developing long-term, customized plans.
“K-12 cybersecurity has evolved beyond an IT department concern and must now be recognized as a fundamental pillar of school safety and security,” said CISA Acting Executive Assistant Director for Infrastructure Security Scott Breor. “The K-12 Cybersecurity Foundations Resource Package provides a roadmap for schools and districts to increase cyber awareness, evaluate current defenses and strengthen cyber resilience in the face of a growing and evolving threat landscape.”

Informed by K-12 stakeholders and cybersecurity experts, this new guidance aligns with other cybersecurity publications, including:
  • CISA’s Protecting Our Future: Partnering to Safeguard K-12 Organizations from Cybersecurity Threats report,
  • Cross-Sector Cybersecurity Performance Goals, and
  • National Institute of Standards and Technology Cybersecurity Framework.
The K-12 Cybersecurity Foundations Resource Package directly advances Executive Order 14239, Achieving Efficiency through State and Local Preparedness by equipping state and local educational agencies with information and tools to make risk-informed decisions that fit the unique, specific needs of their communities.

CISA’s school safety mission focuses on strengthening the safety, security and resilience of K-12 communities through capacity-building resources and tools. To learn more about CISA’s school safety efforts, visit School Safety. For more K-12 cybersecurity resources, visit Cybersecurity for K-12 Education.

https://www.cisa.gov/news-events/ne...security-resources-k-12-schools-and-districts
 
EXPANDING CAPABILITIES TO COMBAT TRANSNATIONAL CYBER-ENABLED CRIME

​August 12, 2026
Presidential Memoranda


MEMORANDUM FOR THE VICE PRESIDENT

THE SECRETARY OF STATE

THE SECRETARY OF THE TREASURY

THE SECRETARY OF WAR

THE ATTORNEY GENERAL

THE SECRETARY OF COMMERCE

THE SECRETARY OF ENERGY

THE SECRETARY OF HOMELAND SECURITY

THE ASSISTANT TO THE PRESIDENT AND CHIEF OF STAFF

THE DIRECTOR OF NATIONAL INTELLIGENCE

THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY

THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY

THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET

THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS

THE ASSISTANT TO THE PRESIDENT AND DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR

THE NATIONAL CYBER DIRECTOR

THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF

THE DIRECTOR OF THE NATIONAL SECURITY AGENCY

By the authority vested in me as President by the Constitution and the laws of the United States of America, I hereby direct the following:

Section 1. Purpose. Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.

The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime. By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.

Sec. 2. Establishing the Program. (a) The National Coordination Center (NCC), established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion), shall create, manage, and maintain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government. As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall:

(i) be overseen by co-Executive Directors, one from the Department of Justice, designated by the Attorney General, and one from the Department of Homeland Security, designated by the Secretary of Homeland Security (Program Executive Directors). The Program Executive Directors shall be delegated authority to approve, after coordination with each other, cyber operations conducted within the Program by personnel of their respective departments, except that they may not approve operations resulting in Critical Outcomes, as defined in section 4(b) of this memorandum. Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government’s lawful authorities;

(ii) require Participating Companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which shall ensure that Participating Companies undergo rigorous vetting and that their performance adheres to the strict operational procedures outlined in the implementation guidance directed in section 3 of this memorandum; and

(iii) permit Participating Companies to enter into commercial agreements with:

(A) private sector entities, from which the Participating Companies may receive for the purpose of proposing responsive cyber operations to the NCC any threat information collected in the course of those entities’ normal business activities; and

(B) Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats to the Participating Companies in a manner that enables them to propose cyber operations to the NCC that address those threats.

(b) The NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government.

Sec. 3. Implementing Guidance. (a) Within 60 days of the date of this memorandum, the Program Executive Directors shall, in coordination with the Homeland Security Council, establish consensus operating procedures for the Program that ensure the Federal Government’s complete oversight and control of Participating Companies’ performance. No operation may be approved unless it complies with these operating procedures. The procedures shall:

(i) establish minimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully in the Program;

(ii) ensure that the Program’s eligibility criteria enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks;

(iii) mandate that Participating Companies disclose to the NCC all contractual relationships entered into pursuant to section 2(a)(iii) of this memorandum;

(iv) authorize the Department of Justice and the Department of Homeland Security to mandate as a condition of their contractual agreements with Participating Companies under section 2(a)(ii) of this memorandum that such companies maintain a bond or escrow in an amount not less than $1 million, to be forfeited should the Participating Company enter non‑compliance with its contractual agreement described in section 2(a)(ii) of this memorandum;

(v) in conformance with the classified annex to this memorandum, set forth the operational workflow of the Program, which shall include operational deconfliction across Federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice, and the United States Intelligence Community;

(vi) in conformance with the classified annex to this memorandum, provide an adjudicatory framework to ensure operational activity targets only CE-TCOs and accounts for other United States Government equities;

(vii) set forth standardized rubrics and templates for target identification and the creation and processing of Cyber Surveillance and Cyber Effects Operations packages;

(viii) include reporting requirements for Participating Companies that will advance a greater understanding of the activities and impact of foreign CE-TCOs, especially as they relate to the American people and economy, and that will ensure the NCC is fully apprised of the Participating Companies’ operational activities;

(ix) include procedures, including a review by the Department of Justice, that ensure any Program activity that is directed at a United States person or otherwise implicates the United States Government’s obligations under the Constitution, Federal law, or international law receives any necessary authorization, judicial or otherwise, prior to approval of the operation;

(x) include procedures to ensure that a Participating Company that discovers operational activity exceeding the parameters and restrictions of the cyber operation approved by the Program Executive Directors — such as unintentional targeting of (1) a United States person, (2) an information system residing in the United States, or (3) an information system under the control of a United States person — shall cease such operation, conduct minimization procedures, and immediately notify the NCC, which shall notify the Department of Justice;

(xi) include procedures mandating that Participating Companies immediately notify the NCC, which shall notify the Department of Justice, if they discover an imminent cyber-attack against United States critical infrastructure or develop a reasonable belief that an approved Cyber Effects Operation or Cyber Surveillance Operation may result in Critical Outcomes;

(xii) clarify that Participating Companies may still engage in other lawful defensive cyber operations otherwise permitted to them, but that any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government;

(xiii) include procedures for evaluating each Participating Company for continued participation in the Program on at least an annual basis; and

(xiv) mandate that the Program Executive Directors review every cyber operations package and provide written approval and direction to the Participating Company before action may be taken.

(b) The Program Executive Directors shall regularly assess and continuously improve the Program’s operational procedures to maintain effective and efficient execution of the objectives outlined in this memorandum. The NCC shall likewise utilize automation to streamline Program elements wherever appropriate, in accordance with applicable law and the requirements of this memorandum.

(c) The Program Executive Directors shall, within 180 days of the date of this memorandum and annually thereafter, produce a report detailing the status of the Program and submit it to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and the National Cyber Director.

Sec. 4. Definitions. For purposes of this memorandum:

(a) “Cyber Effects Operation” means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.

(b) “Critical Outcomes.” An action will be considered to generate a Critical Outcome if it is likely that it will:

(i) result in the loss of life or serious injury; or

(ii) rise to the level of use of force or armed attack under international law.

(c) “Cyber-Enabled Transnational Criminal Organization (CE-TCO)” means any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction. For the purposes of this memorandum, a foreign group will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government’s direction unless clear intelligence exists establishing such connection.

(d) “Cyber Surveillance Operation” means activities conducted in or through the interdependent network of information systems that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers for the primary purpose of collecting information or intelligence — including information that can be used for future Cyber Effects Operations — from information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon, with the intent to remain undetected. Cyber Surveillance Operations entail accessing such information systems without authorization from the owner or operator or by exceeding authorized access. Cyber Surveillance Operations include those actions essential and inherent to enabling Cyber Surveillance Operations, such as manipulation or temporary disruption that is not intended to cause physical effects or impact the usability of physical or virtual infrastructure.

(e) “Information system” has the same meaning as it has in section 3502 of title 44, United States Code.

(f) “Participating Companies” means private United States companies that have been accepted into the Program and will be authorized to conduct cyber operations under the direction of the United States Government.

(g) “United States person” has the same meaning as it has in Executive Order 12333.

Sec. 5. General Provisions. (a) Nothing in this memorandum shall be construed to impair or otherwise affect:

(i) the authority granted by law to an executive department or agency, or the head thereof; or

(ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.

(b) This memorandum shall be implemented consistent with applicable law and subject to the availability of appropriations.

(c) This memorandum is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.

DONALD J. TRUMP
https://www.whitehouse.gov/presiden...-to-combat-transnational-cyber-enabled-crime/
 
Tip of the Week -August 13, 2026 Insider Threat Management

Insider threats are an enduring risk to the water and wastewater sector. Given that, an insider threat management program is essential for water and wastewater utilities aiming to strengthen their security and operational resilience. A proficient insider threat awareness program consists of two key components. First, awareness training should incorporate recognizing potential indicators of insider threats and suspicious activity behavior. Second, organizations should institute clearly defined policies for employees to report suspicious behaviors to human resources or senior management.

https://www.waterisac.org/tip-of-the-week-august-13-2026
 
(TLP:CLEAR) Ransomware Groups Now Targeting Recently Disclosed SharePoint and SonicWall Vulnerabilities
August 13, 2026

Summary: CISA has confirmed ransomware operators are now exploiting vulnerabilities in Microsoft SharePoint and SonicWall SMA1000 appliances, adding updates to its Known Exploited Vulnerabilities catalog. WaterISAC sent vulnerability notifications to members in July for these vulnerabilities.​

Continued: https://www.waterisac.org/tlpclear-...osed-sharepoint-and-sonicwall-vulnerabilities
 
Uber Freight launches cyber attack investigation following Helix claims
13 Aug 2026

Excerpt:

“We are investigating a data security incident involving unauthorised access to a portion of Uber Freight’s systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement,” the spokesperson said. “There has been no impact to Uber Freight’s business operations, which continue in the normal course without disruption. Our systems are secure and fully operational.”

The cyber incident was claimed by the Helix hacking group, which posted data it claims was stolen from Uber Freight.

Helix claimed cyber attacks on a number of Wall Street firms this month, including Blackstone, the firm looking to buy HSBC’s Australian lending portfolio.​

... https://www.cyberdaily.au/security/...r-attack-investigation-following-helix-claims
 
Terabytes of credentials leaked in massive supply-chain attack


The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
Dan Goodin – Aug 12, 2026 5:43 PM​

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes

​more.... https://arstechnica.com/security/20...dia_url>&utm_medium=social&utm_source=twitter
 
Massachusetts, Plymouth County
Jail visits suspended after cyber attack
08/15/2026

The Plymouth County Correctional Facility’s computer system was shut down Thursday and in-person inmate visits suspended after a cyber intruder bypassed the jail’s security system and accessed its servers, an official said.

State police, the FBI and the Department of Homeland Security are investigating the apparent breach, which was detected by the jail’s information technology employees early Thursday morning, according to a spokesperson for Plymouth County Sheriff Joseph D. McDonald Jr.

It was unclear what information the person accessed, if any, according to the spokesperson. The investigation will attempt to determine what the intruder was seeking. The system was immediately shut down and will remain inaccessible until the investigation is complete.

Continued: https://www.plymouthindependent.org/jail-visits-suspended-after-cyber-attack/

 
Utah
Report: Utah among 12 states whose water infrastructure was targeted by Iran
Aug. 15, 2026

​KEY TAKEAWAYS
  • Utah's water infrastructure faced cyberattacks, linked to Iran, with 500 intrusion attempts.
  • Federal agencies warn of rising cyber threats to critical water infrastructure in the U.S.
  • Utah's water systems lack foundational cybersecurity protections, increasing vulnerability to future attacks.
continued: https://www.ksl.com/article/article...-infrastructure-was-targeted-by-iran/51609847


 
CISA, FBI, HHS UPDATE JOINT CYBERSECURITY ADVISORY ON MEDUSA RANSOMWARE
Last Revised August 18, 2026​
Original Publication: March 12, 2025
Last Update: Aug. 18, 2026
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.
The update expands details on Medusa actors’ operations, including more specifics about their affiliate model and payment ranges for initial access brokers, as well as a broader list of exploited vulnerabilities. It describes Medusa’s opportunistic targeting and use of Interactsh URLs for exploit verification. It also lists additional tools for network enumeration, persistence, and stealth, including detailed PowerShell obfuscation techniques and command-and-control utilities. Additionally, HHS has been added as a co-sealer, providing their insights into Medusa’s operations against the Healthcare and Public Health Sector.

  • Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date within a risk-informed span of time.
  • Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization.
  • Filter network traffic by preventing unknown or untrusted origins from accessing remote services on internal systems.
For a downloadable copy of IOCs, see:
Organizations: Government; Federal Civilian Executive Branch (FCEB); State, Local, Tribal, and Territorial (SLTT) Governments; Critical Infrastructure.

Sectors: Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services.

Roles: Defensive cybersecurity analysts, vulnerability analysts, security systems managers, systems administrators, infrastructure support, network operators, threat analysts, digital forensics specialists, and incident responders.

Introduction:
-
snip-


(Updated Aug. 18, 2026) Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of April 2026, Medusa developers and affiliates—referred to as “Medusa actors” in this advisory—have impacted over 500 victims from a variety of critical infrastructure sectors. Affected industries include medical, education, legal, insurance, technology, and manufacturing. Per FBI, the Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant.

The authoring agencies encourage organizations to implement the recommendations in the Mitigationssection of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.

Continued...https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
 
Please also see Post #2: California city declares state of emergency after cyberattack on computer systems
Aug 18, 2026​
Signs of recovery emerge after Suisun City cyberattack

Excerpt:

“The Suisun City water counter is now open for in-person service at City Hall,” the update stated.

The water counter’s opening ends an 11-day streak of empty hallways. While this service is available for residents, eight other departments and offices remain closed, including the public works department and the city manager’s office.

An ongoing federal investigation has forced Suisun City officials to remain silent on how the malicious software reached its IT systems in the first place.
The FBI, Department of Homeland Security and California Office of Emergency Services all have a piece of the cybersecurity threat pie, investigating the incident and helping the city restore its systems.

... https://fox40.com/suisun-city/signs-of-recovery-suisun-city/
 
Last edited:
Texas
August 18, 2026Updated: 38 seconds ago

Back-to-school cyberattack locks 42K students out of Texas university systems days before classes begin

Key takeaways:
  • Hackers breached University of Texas at San Antonio over the weekend, forcing critical university systems offline just days before classes begin.
  • All students,faculty, and staff will be required to reset their passwords as the university restores systems.
  • UT San Antonio says it has found no evidence of data theft so far, but the investigation remains ongoing.
Continued: https://cybernews.com/news/university-of-texas-san-antonio-cyberattack-systems-offline/




 
Major genetic-testing firm says hack compromised sensitive patient data
Aug. 17, 2026

The June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector.
Excerpts:

...
Baylor’s investigation — for which it hired third-party cybersecurity experts and worked with law enforcement — concluded on July 30, according to the statement, which did not explain the two-week delay in announcing the hack.​...

...In late July, New Jersey-based diagnostic testing vendor Centers Lab announced that hackers had breached its systems and stolen patient data in August 2025. And two weeks ago, medical-device giant Abbott said a recent cyberattack affected patients’ health data.​

https://www.cybersecuritydive.com/n...mpromise-patient-data-genetic-testing/828019/
 
OpenAI Foundation
August 18, 2026

Pacing model development in an era of cyber-critical capabilities

Over the past several weeks, two developments have underscored the growing risks associated with increasingly capable AI systems: the OpenAI-Hugging Face incident and, separately, preliminary evidence that one of our upcoming models, Astra, may meet the Critical cybersecurity capability threshold under our Preparedness Framework. Together, these developments, combined with rapid progress in our internal research, have added urgency to our work on strengthening our monitoring, alignment, and containment safeguards across all stages of the training process.​

continued: https://openai.com/index/pacing-model-development-cyber-capabilities/

 
Back
Top