Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
Article Link: https://therecord.media/iran-cyberattacks-water-treatment
- Water utilities in at least 12 states have reported cyberattacks on their operational technology, with the campaign expanding from an initial cluster in Minnesota to now include incidents in Michigan, Georgia, and South Dakota.
- The attackers gain remote access to internet connected programmable logic controllers, or PLCs, then change the device passwords and lock out the utility’s own staff from monitoring or controlling the equipment. CISA and the FBI describe this as a consistent pattern across the affected facilities rather than isolated incidents.
- While federal agencies have not formally attributed the campaign, multiple sources point to Iran, which has targeted this same category of water sector operational technology since 2023. CISA is urging utilities to remove PLCs from public internet exposure, apply firewalls, and enforce unique credentials.
- Additional information: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
What does this mean for me?
- Even critical services like water utilities are being targeted through internet-connected equipment. This is a reminder to avoid reusing passwords, use multi-factor authentication when available, and report suspicious activity quickly, since attackers often look for easy ways into connected systems.
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Article Link: https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
- Unit 42 researchers disclosed three attacks, collectively named Pass-ta-key, that allow malware already running on a compromised Windows device to abuse Google Password Manager’s synced passkeys. None of the attacks break passkey cryptography itself; they exploit weaknesses in how Chrome and Google’s cloud authenticator handle device trust, onboarding, and recovery.
- The first technique lets unprivileged malware impersonate the victim’s trusted device and request a valid login response without administrator rights, biometrics, or the device being unlocked. This response includes a flag indicating whether the user actually verified their identity, so the attack only succeeds against services that fail to properly check that flag. For example, eBay was found vulnerable and has since fixed the issue.
- The second technique goes further by letting the attacker register their own verification key with Google’s cloud authenticator during a forced re-registration, since the authenticator does not confirm that the new key came from trusted hardware. Once registered, the attacker can authenticate from an entirely different system without needing further access to the victim’s device.
- The most severe technique allows malware to extract the master key that encrypts all of a victim’s synced passkeys directly from Chrome’s process memory during device re-registration. Google currently provides no way to rotate or revoke this key, meaning any passkeys synced to the account, past or future, remain protected by the same compromised secret.
What does this mean for me?
- Passkeys are still much safer than passwords, but if malware infects your computer, attackers may be able to abuse your saved credentials. Keep your device updated, avoid downloading untrusted software, and be cautious of unexpected links, files, and browser extensions.
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
Article Link: https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
- SOCRadar disclosed a Russian loader-as-a-service platform named DOUBLECUP, active since June 2026, which uses ClickFix style lures to deliver two malware families, CountLoader and a previously undocumented remote access trojan called DeviceManager.
- Victims land on fake CRM login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, where they are prompted to run a copied command through ClickFix. That command searches the browser’s own cache for a planted PNG image, extracts hidden script code from it, and uses that code to launch the next stage, all without writing an obvious malicious file to disk.
- The final payload is encrypted using the victim’s public IP address as part of the decryption key, so the malware only unpacks correctly on the intended target’s machine and fails to run in a researcher’s sandbox or on any other system.
- DOUBLECUP is sold as a subscription service, giving customers a licensed client and control panel to build campaigns, along with a Telegram bot to track infections and issue commands. This lowers the technical barrier for less skilled operators to run a full delivery chain that was previously the work of a dedicated developer.
What does this mean for me?
- Be extremely wary of websites that instruct you to copy and run commands on your computer to “fix” an issue, complete a login, or verify your identity. Legitimate companies almost never require users to paste commands into system tools as part of normal business processes.
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Article Link: https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html
- Okta researchers identified more than half a dozen underground services selling discounted access to AI models, including one called Poison Claude, which advertises rates as low as 5 to 15 percent of Anthropic’s official per-token pricing for models including Opus 4.8 and Sonnet 4.6.
- The service achieves this pricing by abusing free bonus credits, such as the 100 dollar signup credit AWS offers for Bedrock accounts, then pooling those accounts and silently routing paying customers’ API requests through them. Customers are issued a working API key and instructed to point tools such as Claude Code at Poison Claude’s endpoint instead of Anthropic’s.
- Because the service sits as a proxy between the customer and Anthropic, every prompt a customer sends passes through infrastructure the operator controls before it ever reaches the model. Okta noted this gives the operator full visibility into customer prompts, creating a real risk of data being logged, leaked, or sold without the customer’s knowledge.
- Okta also found bad actors abusing free trial signups on AI services to mass produce fake identities, using disposable domains like dakaka.org and emailinbo.live to register accounts.
What does this mean for me?
- If an AI service seems unusually cheap or unofficial, assume anything you type into it could be viewed by someone else. Never enter company confidential information, customer data, passwords, or sensitive business details into unapproved AI tools.
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Article Link: https://www.infosecurity-magazine.com/news/chinalinked-threat-actors/
- CrowdStrike’s 2026 Threat Hunting Report found that China-nexus groups Vault Panda and Genesis Panda began exploiting the critical React2Shell vulnerability within 24 hours of its public disclosure, deploying remote access trojans to harvest credentials and carry out follow-on activity.
- This speed was not an isolated case. CrowdStrike found that 88 percent of publicly disclosed vulnerabilities exploited in the first half of 2026 were compromised within 48 hours of release, alongside a 42 percent year over year increase in zero day exploitation.
- These trends predate the use of frontier AI in vulnerability research, and CrowdStrike expects the gap between disclosure and active exploitation to keep shrinking as tools built to find and fix vulnerabilities at scale become more widely used by attackers as well as defenders.
- The report also flagged a sharp rise in identity based attacks, including LLMjacking, where attackers steal access to a victim’s AI platform and overload it with requests, in one case sending nearly 200,000 API calls in two minutes.
- Additional information: https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/
What does this mean for me?
- Attackers are exploiting newly discovered security flaws faster than ever. When your organization requires software updates, browser updates, device restarts, or patching, completing them promptly helps protect both you and the company from known threats.
Brinks Home Discloses Data Breach as Hackers Leak Files
Article Link: https://www.securityweek.com/brinks-home-discloses-data-breach-as-hackers-leak-files
- Home security firm Brinks Home confirmed that attackers accessed a portion of its IT systems, after the extortion group ShinyHunters added the company to its leak site and began publishing stolen files.
- According to ShinyHunters, more than 4.9 million records were taken from Brinks Home’s Salesforce instance, and the group claims some of the stolen data includes personally identifiable information. Brinks Home has not confirmed these specifics and says it is still determining what information was affected.
- Because Brinks Home did not pay the ransom, ShinyHunters has since leaked more than 41 gigabytes of the stolen files publicly. The company maintains that its alarm monitoring and system functionality were not affected, since the attackers did not gain access to its actual products or services.
What does this mean for me?
- Data breaches can expose personal information even when the affected company’s core services continue operating normally. Stay alert for phishing emails, text messages, or phone calls that use personal details to appear legitimate, and monitor important accounts for unusual activity.
