Article Read Time

1. Coordinated Cyberattack Hits More Than 30 Minnesota Water Systems
Minnesota IT Services confirmed that a coordinated cyberattack struck over 30 community water systems across roughly 48 hours beginning July 26. Braham’s treatment plant went offline entirely, while Plymouth, South St. Paul, and Maple Plain reported failures in cellular communications and automated utility controls, with Maple Plain declaring a local state of emergency. Federal investigators are examining a possible Iranian nexus, though officials stress that attribution remains preliminary.
Source: BleepingComputer URL: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/
2. Adform Ad Platform Poisoned to Steal Cryptocurrency Across Customer Sites
Attackers appended obfuscated malicious code to Adform’s widely embedded trackpoint-async.js tracking script, turning a trusted advertising library into a clipboard hijacker. The code monitored visitor clipboards for Bitcoin, Ethereum, and TRON wallet addresses and silently swapped them for attacker-controlled ones. Adform detected the compromise on July 27, removed the code, and notified clients, but is urging users to clear browser caches because the poisoned file may persist locally.
Source: The Hacker News URL: https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
3. CISA Flags Actively Exploited Cisco Firewall Management Center Flaw
CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities Catalog on July 29 after confirming exploitation in the wild. The flaw is a hard-coded password in Cisco Secure Firewall Management Center, rated CVSS 8.9, allowing an unauthenticated remote attacker to log in with a low-privilege account. Federal civilian agencies were given an August 1 remediation deadline, and because FMC holds firewall rules, VPN configurations, and device inventories, even limited access is a serious reconnaissance win for attackers.
Source: CISA URL: https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
4. UK Department for Education Breach Exposes 607,000 Records
A threat group calling itself ExfilSquad claimed responsibility for stealing roughly 607,000 records from England’s Department for Education, one of the largest UK public sector breaches this year. The attack targeted the department’s online help desk and the Turing Scheme portal, exposing names, job titles, work email addresses, and phone numbers belonging to school leaders, university staff, and government officials. The DfE says no bank details were involved and is working with the National Cyber Security Centre and the National Crime Agency.
Source: International Business Times UK URL: https://www.ibtimes.co.uk/dfe-cyber-attack-exposes-607000-records-1811392
5. Analog Devices Confirms Data Exfiltration in SEC Disclosure
Semiconductor manufacturer Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files, an incident first detected on June 23. The company says business operations were unaffected and it does not expect a material financial impact, but has brought in external responders and notified law enforcement. Analog Devices is separately assessing a second, apparently unrelated claim that surfaced publicly on July 26.
Source: Security Affairs URL: https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html
