• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

Trump administration launches new program to secure water systems​

August 31, 2026
The Trump administration debuted a new pilot program Monday to bring free cybersecurity and AI tools to under-resourced water systems, starting in Texas.

Why it matters: Water systems have long been considered among the country's most vulnerable critical infrastructure, and the program arrives as at least 12 states respond to suspected Iranian cyberattacks.

Zoom in: Project Watershed 250 will connect Texas water utilities with U.S. cybersecuritycompanies to identify vulnerabilities and strengthen their defenses during a six-month pilot.

Continued: https://www.axios.com/2026/08/31/white-house-texas-water-cyberattacks
 
Attorney General Todd Blanche

@AGToddBlanche
·
15h
This week, sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users. X disrupted the attack to prevent user accounts from being captured. But, as we’ve shown, the Justice Department will stop at nothing in its pursuit of cyber fraudsters and scammers. We are working closely with @X to track down the criminals behind this week’s attack. There is no refuge for those that perpetrate their criminal schemes from behind computer screens.

4:36 PM · Sep 2, 2026
 
Attorney General Todd Blanche

@AGToddBlanche
·
15h
This week, sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users. X disrupted the attack to prevent user accounts from being captured. But, as we’ve shown, the Justice Department will stop at nothing in its pursuit of cyber fraudsters and scammers. We are working closely with @X to track down the criminals behind this week’s attack. There is no refuge for those that perpetrate their criminal schemes from behind computer screens.

4:36 PM · Sep 2, 2026

A couple of weeks ago we received a realistic looking phishing attempt from a fake X email. I did not take the bait. It is getting more difficult to protect against all of the hack attempts systemwide. imho
 
Screenshot 2026-09-03 125509.webp



edited to add:


Screenshot 2026-09-03 130034.webp
 
Communicating Under Pressure: Best Practices for Service Providers
September 2, 2026

U.S. Cybersecurity and Infrastructure Security Agency
U.S. Federal Bureau of Investigation
Australian Cyber Security Centre
Canadian Centre for Cyber Security
New Zealand National Cyber Security Centre
U.K. National Cyber Security Centre

This document is distributed as TLP:CLEAR. Disclosure is not limited. Sources may use TLP:CLEAR when information
carries minimal or no foreseeable risk of misuse, in accordance with applicable rules and procedures for public release.

Subject to standard copyright rules, TLP:CLEAR information may be distributed without restriction. For more information on the Traffic Light Protocol, see Traffic Light Protocol (TLP) Definitions and Usage.

Executive Summary
Service outages impacting IT and operational technology (OT) systems can be

damaging and disruptive for customers, network defenders, critical infrastructure

owners and operators, and the general public. During incidents that reach or

exceed established thresholds, whether caused by malicious activity or a non-

malicious event, service providers must communicate effectively so end users can

minimize operational impact. This guide outlines how to prepare for effective

outage communications and key elements of clear, actionable messaging.

Effective communication begins with a factual summary tailored to predefined

audiences, avoids PR spin, and adheres to regulatory requirements. Service

providers should be transparent by sharing what is known, unknown, and under

investigation, while providing frequent, iterative updates as new information

emerges or circumstances change.

Key Actions:
 Develop a communications plan with defined incident thresholds and target

audiences for communications.

 Practice transparency and avoid PR/marketing language.

 Provide technical information and a root cause analysis for end users.

 Align all messaging with legal and regulatory requirements.

Intended Audience
Organizations: Government; Federal Civilian Executive Branch (FCEB); State,

Local, Tribal, and Territorial (SLTT); Critical Infrastructure.

Sectors: Critical Manufacturing, Information Technology, Energy, Water and

Wastewater, Transportation, Communications.

This publication was prepared by the CISA with contributions from the FBI, NCSC-UK, Cyber Centre, NCSC-NZ,

and ASD’s ACSC. It reflects best practice within the United States, not Australia. This document was not

prepared in consideration of Australian law and does not reflect the reporting obligations placed on Australian

companies.

For more information on Australian cyber incident reporting requirements, consider guidance on Australian

incident reporting obligations. For example:

 Report | Cyber.gov.au

 SOCI Act regulatory obligations

https://www.cisc.gov.au/resources-s...er-security-obligations-corporate-leaders.pdf

Information provided to the Australian Signal Directorate’s Australian Cyber Security Centre regarding a cyber

incident may be protected by the Limited Use regime, which protects how the information is used within the
Australian Government.

Roles: Defensive Cybersecurity Analysts, Executive Cybersecurity Leadership, Cybersecurity Legal Advisors, Technical Support Staff, Incident Responders, Public Relations Specialists.

Introduction...
Why It Matters...
Preparing Your Organization to Communicate Effectively...
Key Elements of Effective Messaging...
Key Takeaways...
Resources...
Disclaimer...

Continued: https://www.ic3.gov/CSA/2026/260902.pdf
 
FBI
Alert Number: I-090126-PSA | 01 September 2026

Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing​

Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing."

Threat Landscape​

OAuth is a commonly used authorization framework which enables websites and Web applications to request access to a user's account on another application without the user exposing their login credentials to the requesting application.
Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor's control. Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control.

How OAuth Consent Phishing Works​

Historically, spear phishing efforts focused on social engineering ruses with links or access to malicious credential harvesting sites or malware deployment to gain access to target accounts or devices. OAuth consent phishing provides actors with persistent access to a target's account because once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings; not by changing the password.

OAuth consent phishing is a deceptive, sophisticated approach to access user accounts without requiring a password. It typically begins with a phishing email or direct message through a CMA and, when the user clicks the malicious link, they are redirected to a legitimate communication provider permission request screen. If the user approves the request, they unwittingly grant high-level access to a malicious application controlled by the cyber actor. From that moment, the cyber actor can act on behalf of the user, including reading and sending emails, and accessing sensitive data without having access to the user's credentials. By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous

OAuth consent phishing is a deceptive, sophisticated approach to access user accounts without requiring a password. It typically begins with a phishing email or direct message through a CMA and, when the user clicks the malicious link, they are redirected to a legitimate communication provider permission request screen. If the user approves the request, they unwittingly grant high-level access to a malicious application controlled by the cyber actor. From that moment, the cyber actor can act on behalf of the user, including reading and sending emails, and accessing sensitive data without having access to the user's credentials. By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous.

Continued: https://www.ic3.gov/PSA/2026/PSA260901
 

Preparing for the Post-Quantum Era: A Call to Action​

September 03, 2026
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.

The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:

  • Raising awareness of quantum risks and the importance of PQC;
  • Developing national strategies that support PQC adoption and integration;
  • Advancing research and development for quantum-safe technologies;
  • Fostering public-private partnerships to share expertise and resources; and
  • Integrating PQC into cybersecurity requirements and procurement processes.

 

(TLP CLEAR) Weekly Vulnerabilities to Prioritize – September 3, 2026​

he below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

SonicWall SMA 1000 Appliances Chained Vulnerabilities

See WaterISAC’s notification regarding these vulnerabilities

JFrog Artifactory Improper Authentication Vulnerability

CVSS v3.1: 9.8
CVEs: CVE-2026-8452
Description: JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://docs.jfrog.com/releases/docs/jfrog-security-advisories

Sangoma Switchvox SQL Injection Vulnerability

CVSS v4.0: 9.3
CVEs: CVE-2026-9586
Description: An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://labs.sra.io/posts/switchvox/

Windchill PDMlink RCE Vulnerability

CVSS v4.0: 9.3
CVEs: CVE-2026-12569
Description: A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030.
Source: https://www.ptc.com/en/support/article/CS473270

PaperCut NG/MF Vulnerabilities

CVSS v4.0: 8.8, 9.4
CVEs: CVE-2026-81578, CVE-2026-82078
Description: An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG, and an unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. These vulnerabilities could allow an unauthenticated remote attacker to modify certain system configurations and potentially enable the execution of arbitrary Java code. CISA added these vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

 

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated September 3, 2026)​

Thursday, September 3, 2026 - 14:55

Access Restricted​

Access to the page you were trying to reach is restricted.

If you are a WaterISAC member and you are already logged in, you may not have access to certain restricted material. If you believe your access permissions are incorrect or if you have any questions, please contact us.

If you are not yet a member, please consider joining and becoming a member.
Please log in to view this content.

 

(TLP:AMBER+STRICT) Recent IOCs Shared in the WaterISAC Slack Workspace (September 3, 2026)​

Thursday, September 3, 2026 - 15:02
Access to the page you were trying to reach is restricted.

If you are a WaterISAC member and you are already logged in, you may not have access to certain restricted material. If you believe your access permissions are incorrect or if you have any questions, please contact us.

If you are not yet a member, please consider joining and becoming a member.
Please log in to view this content.

 

[underlining is mine]​

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)​

September 03, 2026

Summary​

Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. The Easergy MiCOM C264 is a modular and compact substation or bay controller, smart RTU and MV one box solution The EcoStruxure Power Automation System Gateway (EPAS=GTW) is a scalable, interoperable, and rugged communication gateway that helps to remotely monitor and operate electrical processes The EcoStruxure Power Automation System User Interface (EPAS-UI) product is an HMI SCADA designed for electrical networks and substations operations. The EcoStruxure Power Automation System Intelligent Power Management System and Fast Load Shedding (iPMFLS) is a range of solutions designed to overcome size and performances constraints. The EcoStruxure Power Operation (EPO) are an on-premises software offers that provides a single platform to monitor and control medium and lower power systems. The PowerLogic P5 is a medium voltage protection relay. The PowerLogic P7 is a protection and control platform designed for complex and advanced electrical network applications. The PowerLogic T300 is a modular platform for medium voltage and low voltage public distribution network management. The PowerLogic T500 is a control unit and RTU for substation automation. The Saitel DP RTU is a modular platform for medium voltage and low voltage public distribution and transmission network management. The EasyLogic T150 (formerly Saitel DR RTU) is a field device, offering a solid and powerful platform for data acquisition, communication, automation and IED integration for distribution and transmission networks, generation sector and railway. Failure to apply the fix provided below may risk session hijacking, which could result in malicious actors performing unauthorized operations within the affected system.

The following versions of Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A) are affected:

Continued: https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-07
 
Back
Top Bottom