• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

August 18, 2026
Mapping Iranian Cyberattacks on U.S. Water Systems

In late July, Minnesota authorities disclosed that hackers had attacked not one or two water systems—but more than 30 across the state. The following weeks saw additional revelations in other states. Officials are beginning to understand the scope of what is likely an Iranian cyber campaign months in the making. Although the U.S. government has not publicly attributed the attacks, an Iranian actor linked to the Islamic Revolutionary Guard Corps (IRGC) known as the CyberAv3ngers has claimed responsibility, stating their intention was to “warn America to back down.”

The following set of charts brings together existing press reporting and CSIS expert analysis to provide a picture of what is known about the cyberattacks on the U.S. water sector so far. It is important to acknowledge that the reporting is thus far incomplete; the current understanding of the scope and scale of the attacks is reliant on states self-reporting incidents as they search their technical logs from recent weeks, and reporting requirements are inconsistent at best.

This style of attack is not new for Iran; water facilities have become something of an Iranian specialty. Actors linked to Iran attacked water facilities in the United States as far back as 2013 in New York and Pennsylvania in 2023; they also attacked water systems in Israelin 2020 and 2023. But these earlier attacks went after only one or a handful of targets, whereas the 2026 attacks simultaneously hit at least 12 states and multiple targets.​

Continued: https://www.csis.org/analysis/mapping-iranian-cyberattacks-us-water-systems




 
FBI Press Release
August 18, 2026

17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities

Mabna Institute Hackers Attacked Systems Belonging to Hundreds of Universities, Companies, and Other Victims to Steal Research, Academic and Proprietary Data, and Intellectual Property

A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. The defendants conducted many of these intrusions on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), one of several entities within the government of Iran responsible for gathering intelligence, as well as other Iranian government and university clients. Nine of the 17 defendants charged in the S2 indictment were previously charged in a 7-count indictment announced in March 2018. The case is assigned to U.S. District Judge Jesse M. Furman.

Continued: https://www.justice.gov/opa/pr/17-i...r-theft-campaign-behalf-islamic-revolutionary

 
[emphasis is mine]

August 19, 2026
Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary

Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them. The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs. could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.

The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:

• are properly protected with all applicable security patches and updates,

• are isolated from the Internet wherever possible,

• have strong access controls, and

• employ security tooling to monitor ICS environments for anomalous or malicious activity.

These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.

Technical details


Top Mitigations

Inventory all Siemens S7 Series programmable logic controllers (PLCs)

Apply critical security patches

Ensure PLCs are not accessible from the Internet

Strengthen access controls

Monitor for unauthorized activity

Harden PLC services, protocols, and ladder logic integrity

Hunt for anomalies that may indicate a compromise

Continued: https://www.ic3.gov/CSA/2026/260819.pdf



 
Tip of the Week – August 20, 2026

Review Network Segmentation

Separating operational technology (OT) from business IT networks can help limit the impact of a cyberattack. Water utilities should periodically review firewall rules, network connections, and pathways between IT and OT environments to confirm that only necessary communications are permitted. Strong network segmentation can prevent an attacker who compromises an IT system from easily reaching critical control systems and PLCs.

https://www.waterisac.org/tip-of-the-week-august-20-2026
 
(TLP:CLEAR) Supplemental General Security & Resilience Highlights – August 20, 2026
August 20, 2026​

The following posts are useful for general awareness of current physical security threats, natural disaster resilience, preparedness resources, mitigation guidance, and other security-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Continued: https://www.waterisac.org/tlpclear-...security-resilience-highlights-august-20-2026
 
August 20, 2026

CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards

WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture, an outcome-driven guide for federal civilian executive branch (FCEB) agencies to establish logging, visibility and operational standards in an Agency Logging Plan, as required in Office of Management and Budget (OMB) Memorandum M-26-14. Developed in collaboration with OMB and the Chief Information Security Officers (CISO) Council, this guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring.​

Continued: https://www.cisa.gov/news-events/ne...-federal-agencies-implement-effective-logging

 
Massachusetts, Andover
August 22, 2026

ANDOVER, MA — A cyberattack was responsible for a four-day network outage earlier this month that disrupted Town departments, delayed the release of teacher assignments to Andover Public Schools families and frustrated residents trying to access some municipal services.

Town Manager Andrew Flanagan confirmed in an email Friday that the disruption, first detected Aug. 13, was the result of a cyberattack. An investigation into the incident remains ongoing. The disclosure provides the first public explanation for an outage that Town officials initially described only as a temporary internet connectivity problem.

Continued: https://andovermanews.com/cyberattack-caused-four-day-network-outage-for-town-aps/
 

CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response​

Key Findings: Ensure Robust Baselines and Alert Filtering; Eliminate Organizational Silos and Bureaucratic Hurdles; and Apply Proper Security Controls and Processes for Cloud Environments
Released
August 25, 2026

WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory about lessons learned from red team assessments performed at the request of two critical infrastructure organizations to help organizations strengthen detection, response and protections in information technology (IT), cloud, and operational technology (OT) environments.

During red team assessments, CISA uses adversarial tradecraft to simulate malicious cyber operations. The objectives are to observe and evaluate an organization’s ability to detect, investigate and respond to real‑world threat activity. The advisory, A Tale of Two SOCs: Insights From Two Red Team Assessments, details red team activity at both organizations and the organizations’ differing defensive responses.

Continued: https://www.cisa.gov/news-events/ne...rganizations-assess-risk-identify-threats-and
 

[emphasis is mine]​

Aug 25, 2026

Navy instructs troops, families to scrub social media of personal information​

The U.S. Navy directed service members, military families and civilian personnel to remove personal information that reveals their connection with the service in order to protect them and their loved ones from adversaries.

Bad actors are utilizing the online presence of individuals tied to the military to gather intelligence and launch attacks that include doxxing, surveillance, physical attacks and harassment, according to an Aug. 19 Navy administrative message.

“Since the initiation of Operation Epic Fury, the Department of the Navy’s (DON) personnel, assets, and our families face an evolving threat landscape,” the message said. “U.S. military installations and personnel remain under increased vigilance due to recent uncrewed aircraft system (UAS) encounters, suspicious activities, cyber threats, and acts of violence.”

In response to the increased security concern, the Naval Criminal Investigative Service launched Epic Vigilance, an initiative aimed at protecting Navy personnel and families.

Continued: https://www.navytimes.com/news/your...o-scrub-social-media-of-personal-information/
 

AI is supercharging hacks of everyday utilities​

5 hours ago

Years of warnings about the digital vulnerabilities lurking inside basic utilities are colliding with a new reality: AI is making those weaknesses easier for hackers to exploit.
Why it matters: AI is lowering the barrier for state-backed hackers looking to disrupt or manipulate water systems, power plants and other critical infrastructure.
Driving the news: A recent wave of cyberattacks targeting critical infrastructure is raising new questions about the preparedness of U.S. water systems and a British power plant.

Continued: https://www.axios.com/2026/08/25/ai-critical-infrastructure-cyberattacks
 
August 26, 2026

FBI, Department of Justice Announce Disruption of Global Botnet​

The FBI and the U.S. Department of Justice on August 26 announced the disruption of a global botnet disruption used by a Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure. In this video, FBI Cyber Division Assistant Director Brett Leatherman speaks to the significance of the disruption and discusses an associated Joint Cybersecurity Advisory that the Bureau and our partners issued to help defenders protect their networks from the group.


Video Transcript​

FBI Cyber Assistant Director Brett Leatherman: I’m Brett Leatherman, head of the FBI’s Cyber Division.

Today, the FBI and DOJ [U.S. Department of Justice] are announcing the disruption of a global botnet used by a Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure.

For nearly a decade, QTFY has exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies, telcos, and major hospital systems.

QTFY operates within a complex network of hackers-for-hire and government clients in the People’s Republic of China.

Our investigation links the group to Nanjing Xinjiuwei Network Technology—a company that sells stolen data and hacking services to Chinese military and intelligence agencies.

Their services include a scanning platform that scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet, or a network of machines secretly controlled by the adversary.

These tools let QTFY hide the origin of their attacks.

So, instead of appearing to come from China, traffic is routed through everyday devices in more than 130 countries—potentially through systems just down the street from the victim’s own network.

Today—thanks to the work of FBI San Diego, the FBI Cyber Division teams, and our partners at DOJ—we shut these tools down.

We seized multiple domains the platforms relied on for core functions like communication and authentication.

Without those domains, the platforms were rendered inoperable.

We’re also issuing a Joint Cybersecurity Advisory with our partners to help defenders protect their networks from this group.

This action is just the latest technical operation against PRC state-sponsored hacking.

Last year, the FBI removed surveillance malware from thousands of U.S. systems; before that, we disrupted botnets tied to Flax Typhoon and Volt Typhoon.

In line with the new White House National Cyber Strategy, we are ramping up our efforts to shape adversary behavior and defend the homeland in cyberspace.

But lasting deterrence depends on partnerships.

Working with industry is how we deny the adversary easy gains and raise the cost of every attack.

To disrupt at scale, we have to coordinate at scale.

So the mission belongs to all of us.

Welcome to the fight.

Video Download​

Video Source​

 

(TLP:CLEAR) Vulnerability Notification – Oracle HTTP Server & WebLogic Proxy Plug-in Actively Exploited​

Author: Chase Snow
Created: Wednesday, August 26, 2026 - 9:24
Categories: Cybersecurity, Security Preparedness

ACTION MAY BE REQUIRED for utilities using Oracle HTTP Server or the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server or Microsoft IIS. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.

Summary: A critical improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in is being actively exploited in the wild. Tracked as CVE-2026-21962 (CVSS 10.0), the vulnerability allows an unauthenticated remote attacker with HTTP access to send crafted requests to the affected proxy components and bypass intended access controls, potentially enabling unauthorized creation, deletion, or modification of critical data and access to backend WebLogic systems.

Yesterday, CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation.

Analyst Note: Because the WebLogic Server Proxy Plug-in and Oracle HTTP Server typically sit at the network perimeter—often in DMZ environments front-ending backend application servers—a successful bypass could give attackers a foothold inside trusted network environments, potentially enabling lateral movement, credential theft, or access to systems that support OT environments.

WaterISAC strongly encourages members to determine whether Oracle HTTP Server or the WebLogic Server Proxy Plug-in is deployed within their environment, review Oracle’s January 2026 advisory, and apply the fixes immediately.

Additional Reading

...Continued: https://www.waterisac.org/tlpclear-...ver-weblogic-proxy-plug-in-actively-exploited
 
Massachusetts
August 26, 2027

On August 25, Boston Scientific identified a cybersecurity incident affecting certain information technology systems that resulted in a network outage and disruption to the company’s operations. Once detected, the company activated incident response protocols and began an investigation to assess and contain the threat with the assistance of third-party cybersecurity experts. The incident has impacted access to certain operating systems and business applications, including the ability to process and ship customer orders.

The investigation into the cybersecurity incident is ongoing. While the company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.

The company filed an 8k on this incident and will provide updates on this webpage as appropriate.

 
[emphasis is mine]
August 26, 2026

Qilin gang claims US Bureau of Alcohol, Tobacco, Firearms and Explosives​

Key takeaways:
  • Qilin claims the ATF as its latest victim but has provided no evidence or details.
  • The ATF holds potentially sensitive law enforcement, investigative, firearms, and employee information.
  • Several major federal law enforcement agencies have suffered cyberattacks in 2026.
  • Qilin remains one of the world's most prolific ransomware gangs, claiming thousands of victims since 2022.
Excerpt:

What’s at risk in an ATF breach

Part of the US Department of Justice, the US Bureau of Alcohol, Tobacco, Firearms and Explosives is responsible for investigating and protecting the public from violent crimes involving illegal guns, bombings, weapons smuggling, and arson.
The agency is also responsible for enforcing federal laws governing firearm licenses (FFLs), regulating the commercial storage and use of explosives, and combating tobacco and alcohol bootlegging, according to the ATF website.
-snip-
If Qilin’s claims are legitimate
– and depending on which ATF networks were accessed – potential risks could be enormous, compromising not just agents and case files, but ongoing ATF investigations, potentially impacting prosecutions, and exposing informants and witnesses.
-snip-

Qilin remains a ransomware powerhouse

As for the Russian-linked Qilin gang, the ransomware operators have claimed roughly 1,900 victims in the past 18 months alone, making it one of the most active groups of 2025 and, to date, 2026.

Continued: https://cybernews.com/news/qilin-ransomware-bureau-alcohol-tobacco-firearms-atf-cyberattack/
 
[emphasis is mine]

CISA: Internet Exposure Reduction Guidance
Revision Date August 21, 2026

Identify which systems are accessible from the internet, remove unnecessary remote access, and secure remote access that is necessary.
Many organizations unknowingly leave common vulnerabilities and weaknesses exposed to the internet, making them easy targets for exploitation. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software that they can exploit to gain unauthorized access. By following the guidance below, organizations can proactively identify internet exposures, remove those that are unnecessary, and secure those that are necessary, strengthening their cybersecurity posture.

The range and number of internet-accessible assets—including industrial internet of things (IIoT), supervisory control and data acquisition systems (SCADA), industrial control systems (ICS), and remote access technologies—continues to grow. In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem. Directly connecting PLCs to the internet through cellular modems can create significant security risks. However, internet exposure reduction does not mean disabling necessary remote access; organizations should remove remote access when it is unnecessary and secure it when it is necessary.

Steps to Reduce Internet Exposure​

continued:
 

Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents​

PUBLISHED WED, AUG 26 202611:11 AM EDTUPDATED AN HOUR AGO

The Federal Reserve, the U.S. Senate, the Department of Justice, NASA and other federal agencies were victims of computer intrusions by a Chinese state-sponsored hacking group, the DOJ said Wednesday morning as it announced the court-ordered seizure of internet domains used for hacking platforms.
-snip-

“Other targeted networks include those operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors,” a court filing said.

Other federal agencies that were victims of computer intrusion by the platforms were the Energy Department, the Health and Human Services Department and the National Institutes of Health, according to the DOJ.

Continued: https://www.cnbc.com/2026/08/26/china-hacker-federal-reserve-doj-nasa.html
 
Back
Top Bottom