IT Security Newsletter - 8/5/2026
Water Sector Cyberattacks Reportedly Hit at Least 12 States
The number of US states affected by the recent hacking campaign targeting water and wastewater facilities continues to grow. At least 12 states have been hit, according to ABC News, but the names of only a handful of the affected states are currently known. Minnesota was the first to report attacks, with more than 30 community water systems targeted on July 26 and 27. Michigan has also officially confirmed that a "small number" of communities have seen malicious cyber activity. READ MORE...
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. By claiming the recipient must take specific actions "to avoid account restrictions," the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com, tries to push them to follow the link without thinking. READ MORE...
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). The flaws were uncovered by Forescout's Vedere Labs researchers, who published the full details at the Black Hat USA security conference earlier today. Omada is TP-Link's business networking product line. READ MORE...
Prolific ransomware group behind SonicWall zero-day attacks
Researchers said INC ransomware, one of the most active ransomware groups globally, has been the main attacker exploiting a pair of SonicWall zero-days soon after they were disclosed last month. The prolific ransomware-as-a-service operation wasn't the first group to exploit the flaws, which were actively exploited for three weeks before the vendor disclosed and patched the defects July 14, but it has been the most assertive and concerning group to target and chain both vulnerabilities. READ MORE...
Massive supply-chain attack compromises 440 packages under four hours
In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms. The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, was initially let loose in keyv, a data management interface software package with more than 600 million monthly downloads. READ MORE...
Google's synchronized passkeys can be stolen in 'Pass-ta-key' attacks
Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked. Over time, it's thought that passkeys will replace passwords entirely. But what happens when malware steals the master key? Researchers have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception. READ MORE...
AI researchers let models off the leash - then watched as they tried to add malware to a FOSS project
The UK's AI Security Institute has observed AI models performing what it calls "unsanctioned action" 19 times during security tests. The Institute (AISI) revealed the incidents in a Tuesday post and technical report that details tests it conducted to see if AI models can solve a cyber security challenge. "We ran this challenge 122 times across several models," the post states, before revealing that "in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet." READ MORE...
- ...in 1858, the first transatlantic telegraph cable is completed.
- ...in 1884, the cornerstone for the Statue of Liberty is laid on the former Bedloe's Island (now Liberty Island) in New York Harbor.
- ...in 1914, the first electric traffic signal lights are installed in Cleveland, Ohio.
- ...in 1926, magician and escape artist Harry Houdini performs his greatest feat, apparently spending 91 minutes in a sealed underwater tank before escaping.






