Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an intrusion ShinyHunters claims it carried out to steal millions of records from the security provider's Salesforce instance. Brinks Home hasn’t named the intruder or identified the affected system, but said the responsible party has threatened to leak information it claims to have taken. “Brinks Home is working diligently to determine what information was involved and who may be affected,” the company statement said. “If the Company determines that personal information has been affected, it will notify those individuals as required and as appropriate.” An FAQ page for the incident said that Brinks Home products and services weren’t affected, as far as the company knows at this point, so alarms and other security tools should be working without issue. While Brinks may not have been very forthcoming with information, and lacks any sort of official way for media to communicate with it outside of sending a LinkedIn message it didn’t answer, the party that’s claimed responsibility has gone public with some details, and it’s none other than ShinyHunters with another claimed Salesforce breach. According to leak site monitoring outfit Ransomware.live, ShinyHunters claimed to have obtained more than 4.9 million Salesforce records from Brinks Home “containing some PII.” The group threatened this week to leak the data along with causing “several annoying digital problems” if Brinks Home didn’t reach out by Thursday, July 30, to negotiate a ransom payment. It’s not clear if Brinks Home has contacted ShinyHunters; Brinks Home didn’t respond to messages, and contacts The Register has for ShinyHunters appear to have changed, causing message and email rejections. ShinyHunters has been a prolific Salesforce intruder of late, with the group claiming earlier this year to have stolen data from around 100 high-profile companies’ Salesforce instances. Salesforce has previously warned that an unnamed known threat actor group was actively scanning for public-facing Salesforce instances and abusing misconfigured guest accounts to break in. Brinks Home is no longer part of the larger Brinks brand, with The Brinks Company telling us it sold the home security arm in 2010. Brinks Home’s parent company, Monitronics, has filed for bankruptcy twice since 2019; for customers’ sake, we hope its physical security services are better than its financial management and infosec. ®
One company's inventive campaign for an unreleased product has become a contest between Anthropic and OpenAI to see which can shout the loudest about its own failures. Readers who tuned in earlier today saw the latest episode in the drama – or sitcom – as Anthropic tried to outdo OpenAI's appropriation of the Mythos marketing playbook and made itself the punchline. Since first teasing Mythos in April, Anthropic has marketed the model through fear – declaring its cybersecurity models too dangerous for public release and offering access only to a select few trusted organizations via Project Glasswing. To its credit, the strategy has paid off. Anthropic has closely associated the Mythos name with cybersecurity, which may explain why OpenAI appeared to borrow its competitor's proven PR strategy last week. OpenAI agents exploited a zero-day to escape their sandbox, leading to the autonomous cyberattack on Hugging Face. The episode duly secured sensational headlines playing on the long-held fear that AI will one day go rogue and take over the world. Anthropic responded this week by lathering on even more clown makeup, squandering an opportunity in the process. The Claude maker sent its models into a testing environment to capture a flag. Their prompts said they had no internet access, but because of what Anthropic called "a misunderstanding" with evaluation partner Irregular, the connection was live. Anthropic's models then followed OpenAI's script: they reached the public internet and attacked systems belonging to outside organizations. This time, three were affected rather than one, the company admitted. In one scenario, Mythos 5 persuaded developers to download a poisoned PyPI package. It was installed on 15 machines, including one at a cybersecurity company that routinely scans such packages for malware. In Anthropic's words: "When that company's scanner installed the package, Claude's hidden code executed. We believe the company's security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point it had set up. Claude then used these credentials to access further infrastructure from this company." Worse still, the first of the three incidents occurred in April. Anthropic discovered them only months later, during a retrospective manual review prompted by OpenAI's disclosure. Had it not gone looking, they might never have been discovered, let alone disclosed. There are some caveats. Opus 4.7, the oldest model tested, attacked production systems despite apparently recognizing what it was doing. Mythos 5 recognized that accessing the internet violated its instructions, then reasoned its way into continuing anyway. It was also responsible for publishing the poisoned PyPI package. Only an unnamed research model stopped itself from attacking external organizations. Anthropic also said the models were not running with the production safeguards and monitoring that would normally surround a deployment. Most damningly, Anthropic ran Mythos 5 – the model it had deemed too dangerous for public release – without safeguards in an environment that unexpectedly had internet access. Following OpenAI's admission that it failed so badly in its responsibility to control its technology, Anthropic could have easily spun the story in its favor. You don't have to be fictional tapdancing political PR antihero Malcolm Tucker to see how Anthropic could have used the episode to make its case as the safer, more trustworthy AI company. Instead, realizing its own marketing playbook was being used to help a competitor, it went head-to-head with OpenAI, willingly admitted that it made similar sandbox-based blunders, and disclosed that the results were even more calamitous. Three companies hacked, not just one. So, while the AI biz has attempted to eclipse OpenAI's "rogue agent" story with its own, what's left behind is a new reputation for irresponsible handling of technology. Failed superheroes The incident does not instill a great deal of trust in either Anthropic or OpenAi to safeguard the world from its AI. Dr Ilia Kolochenko, founder of ImmuniWeb and practising cybersecurity and data protection lawyer, likened the two companies to failed superheroes. "While making conclusions would be a bit premature at this point in time, the incidents certainly do not increase confidence in the AI vendor's ability to safely deploy AI, let alone to assure their customers that the so-called frontier models are safe to use," he told The Register. "It is akin to hiring a superhero to protect you but being afraid that the superhero may suddenly go rogue and kill you and your family. Nobody needs such a superhero." Likewise, security pro Jake Williams, VP at HunterStrategy and IANS faculty member, said: "I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. "We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents damaging others." By trying to reclaim a marketing trope that served it well, Anthropic has invited scrutiny of its own safety record and accusations that it is chasing attention above all else. Other experts we spoke to shared the concern that both companies are mishandling their agents, with potentially greater consequences as the systems become more capable. The common thread is recklessness, which Anthropic and OpenAI seem oddly eager to advertise. ®
A week after suspending online banking, CAF Bank still has no timetable for restoring access to its 14,000 UK charity customers. The bank updated customers on Thursday about the outage, which has disrupted payments to staff and suppliers. Little had changed. In a message seen by The Register, CAF Bank said it was not yet able to restore the service safely. As it had earlier in the week, the bank said it detected attempted fraud on some accounts and acted quickly to stop it. Its investigation uncovered a previously unknown vulnerability in the connection between its systems and third-party software. CAF Bank said its technical team was working around the clock with suppliers and external experts on a fix. The Register understands that no timetable has been set for restoring online banking. Earlier this week, CAF Bank CEO Alison Taylor apologized for the disruption. "The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved," she said. Since The Register first reported the story earlier this week, the BBC has spoken to charities struggling to make essential payments, including payroll. Kevan Hodges, chief executive of Down's syndrome charity 21 Together, told the BBC the outage was "appalling." "People are concerned that wages won't get paid because of this, and that's just stressful when they have bills to pay. My team have wasted days trying to get through to [CAF Bank], but all in vain," he said. Bali Rodgers, chief executive of Safer Communities Alliance, told the BBC the grassroots organizations it represents were slowly losing trust in the bank. CAF Bank also came under fire last year after the introduction of a new banking platform left customers unable to log in or make transactions. The bank later apologized but has not disclosed how much it spent on the system. CAF Bank held £1.45 billion ($1.93 billion) in customer deposits at the end of its 2024/25 financial year. ®
The two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.
Note to privacy-conscious vandals: If you're going to destroy Flock license plate readers, make sure you also take out the other CCTV cameras in the area that could catch you in your crime. Otherwise, you'll end up like one unlucky Californian. Marcus Bee, 40, was arrested by the Monterey County Sheriff’s Office on Tuesday, accused of joining the ever-growing band of US citizens damaging the controversial cameras popping up across the country. A police report filed this week stated that Bee, of Pismo Beach, was arrested on suspicion of attacking at least three Flock cameras in Lockwood and Bradley. According to the deflock.org website, which maps Flock camera deployments, there are only three of the automated license plate readers (ALPRs) running in the two communities – one in Lockwood and two in Bradley, roughly 25 miles away. Police allege Bee caused thousands of dollars’ worth of damage to “public safety infrastructure.” Monterey County Sheriff’s Office added that Bee was caught after “his actions were captured by other surveillance cameras located nearby,” along with other investigative leads. "This arrest sends a clear message that anyone who intentionally damages public safety equipment will be identified, arrested, and held accountable," said Monterey County Sheriff Tina Nieto. "These cameras have become an invaluable investigative resource that helps us solve crimes, recover stolen vehicles and ag equipment, locate missing persons, and protect our communities. Any attempts to disable these systems will not prevent us from doing our job. “In this case, the suspect's own actions were captured on surveillance cameras, leading directly to his arrest. We will continue to aggressively investigate these crimes and seek prosecution against anyone who targets public safety infrastructure." Bee was jailed with bail set at $30,000. The case follows a similar one in Georgia last week, although local police were unable to identify the suspect(s) behind the two attacks, which involved setting two ALPRs on fire. The two attacks were timed fairly close together, although the phenomenon of inflicting criminal damage onto Flock cameras is something of a long-running trend. Several US police forces have been tasked with arresting alleged Flock vandals, including Jeffrey Scott Sovern, 41, who authorities believe was behind a spate of attacks on ALPR cameras in North Suffolk, Virginia, between April and October 2025. He said, at a hearing in June, that he believed the technology was unconstitutional. Flock cameras: A problem or simply misunderstood? The Monterey County Sheriff’s Office said Flock’s cameras “are an important investigative tool” used to help solve various types of crimes, including missing persons cases, car thefts, and violent crimes such as shootings and homicides where suspect vehicles are involved. Contrary to the opinions held by many, it went on to say, the cameras “are used exclusively to support legitimate criminal investigations,” not to support the US government’s anti-immigration efforts. Likewise, Flock has repeatedly denied offering contracts to agencies such as Immigration and Customs Enforcement (ICE), although reports suggest police were instead carrying out searches on ICE's behalf. Customs and Border Protection (CBP) has also allegedly used Flock data in its own immigration investigations. Other critiques of the technology used by thousands of police departments across the US include problematic abuses, such as police officers using it to stalk romantic interests. The Institute of Justice is aware of at least 26 cases of this behavior, it reported earlier this month, with the majority taking place since 2024. Additionally, the American Civil Liberties Union (ACLU) takes issue with the scale of data gathering by ALPRs. It claims that less than 1 percent of the cars scanned are connected to crime, yet they still have details added to a database, such as vehicle manufacturer, model, color, license plate number, bumper stickers, and scratches. Flock CEO Garrett Langley claimed this week in an interview with The Drive that the company’s cameras were used to solve around 1 million crimes across the US last year. Responding to claims such as Sovern’s – that the cameras are unconstitutional, specifically that they violate Americans’ Fourth Amendment rights – Langley said there are no legal issues, and he doesn’t foresee any arising in the future. Flock’s spokespeople have repeatedly condemned the cases of camera vandalism, highlighting the risk of losing evidence that could be crucial to solving ongoing criminal cases. ®
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it's now pulling the same half-click trick against Microsoft Outlook Web Access. Proofpoint says the cyber group it tracks as TA488, or "Laundry Bear," began exploiting CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access (OWA) component of on-premises Exchange Server, a day before researchers and government agencies exposed the group's abuse of a zero-day in Zimbra Collaboration Suite. Unlike conventional phishing attacks, this one doesn't depend on persuading the victim to follow a link or download a file. If a target opens the booby-trapped message in OWA, the browser executes attacker-controlled JavaScript inside the victim's authenticated mail session. Exchange Online is not affected. According to Proofpoint, TA488 abused the OWA flaw to target government organizations in the US and Europe, along with telecommunications, financial services, hospitality, and aerospace companies. The researchers said the unusually broad campaign may have been intended to hide among the background noise of everyday email traffic rather than the tightly focused operations more commonly associated with espionage groups. "TA488 appears to demonstrate interest in a wide range of sectors while maintaining priorities for intelligence collection against government and defense," Proofpoint said. "Lure themes remain generic and unremarkable, so the target is more inclined to open and skim the email but ultimately overlook it." Instead of dropping conventional malware onto the endpoint, the attackers deploy a browser implant dubbed OWAReaper that lives entirely inside OWA. Proofpoint says it leaves virtually no host artifacts, communicates over two command-and-control channels, supports multiple methods of exfiltrating data, and survives browser restarts, password changes, and even a complete device rebuild because the foothold resides in the compromised mailbox rather than on Windows itself. CVE-2026-42897 isn't making its debut on The Register. Microsoft disclosed the bug in May following reports that attackers were using it in the wild. Proofpoint's latest report fills in more of the picture, showing the activity formed part of a broader espionage campaign rather than isolated exploitation. Proofpoint believes TA488 may actually have been exploiting the flaw as a zero-day, citing attacker infrastructure that dates back to March, roughly two months before Microsoft's out-of-band patch. If accurate, that would suggest the campaign was underway well before defenders knew there was a vulnerability to fix. "If this is the case, the combined improvement of the malware and the exploit development against a harder target in Outlook Web Access signal a leap in capability by TA488," Proofpoint said. Microsoft did not immediately respond to The Register's questions, but if Proofpoint's assessment holds up, TA488 isn't just recycling an old trick. It's refining one that has already proven capable of slipping past one of the oldest pieces of security advice in the book: don't click suspicious links. ®
Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.
PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher’s (aka principal’s) laptop. At the bottom of the laptop there was a sticker with the woman’s username and password. Even if they had been complicated, the post-it would have given them away, but in fact, the combination was: Username: headteacher Password: headteacher Using that laptop, a malefactor could have had access to pupils’ personal information, internal conversations, emails, and all kinds of private school files. There could be serious problems for everyone who worked for or attended the school. “A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building. This wasn’t the only instance of poor security Walker saw in his time doing IT for schools. He also saw an institution create an Excel file called Passwords.xlsx, then put it on a shared drive that students could get to. As its name suggests, Passwords.xlsx was filled with login credentials that any bad actor could take advantage of. Walker also saw leaver accounts that remained active, a server that had its backup drive permanently plugged in so hackers could potentially wipe the backup as well, a Wi-Fi password written on a whiteboard in reception, and one critical system that users could only access from an ancient laptop. There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch. And, years after Windows XP was no longer the current platform, the school had a CCTV monitor with that ancient OS running on it. And, a supposedly secure server room doubled as a storage closet for stationery and Christmas decorations. Walker told us that, in his experience, the schools he worked with had priorities other than cybersecurity and they didn’t understand its importance. One boss even denied the importance of keeping data safe at all. “We don’t need to worry about cybersecurity. They're only a primary school,” his manager told him when Walker tried to get them to use cloud backups. The problem, Walker opines, is that schools often have to work with outdated gear and the teachers and school administrators have other concerns. His solution: keep it simple. “Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. Enforce proper passwords and block the ones that have already turned up in data breaches. If a password is already doing the rounds online, it has no business protecting a school system. None of that is as exciting as rolling out a fleet of shiny new iPads, but it works.” ®
UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word’s context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog post Tuesday. Måløy describes the issue in considerable detail while withholding the specific prompt payload, arguing that, because no robust mitigation exists, it would be irresponsible to disclose anything beyond the class of the vulnerability. “To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite,” Måløy noted. Måløy said that he has been working with Microsoft since March 2026 on addressing the vulnerability, but after multiple updates to Copilot, this new class of Copilot worm is still viable. Microsoft mitigated the exploit demonstrated by his original proof-of-concept prompt, but Måløy said rewording the payload allowed him to successfully propagate the worm and alter financial data in a target document. Måløy and Microsoft twice delayed public disclosure of the issue, but, after 144 days, he said in his report that people needed to be made aware. “The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.” How Copilot propagates a Word worm Måløy explained the worm’s execution with an example involving an employee preparing a financial report for their company. The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult. “The attack can therefore continue without further involvement from either the compromised website or the original malicious document,” Måløy said. “The attacker does not need access to the victim’s Microsoft 365 tenant. The attacker only needs to share a malicious document with the victim.” Copilot should use information in documents a user includes in its context for a project without treating instructions embedded in a document as additional prompts, Måløy said, but his research suggests it doesn't always do that. A fundamental flaw Måløy argues that he’s essentially dug up a new type of cross-domain prompt injection attack that abuses a fundamental part of modern LLM architecture. “For AI-assistants to be useful, they often must process emails, documents, webpages, memories, tool outputs, and other information that may be controlled by an attacker,” the researcher said. But if an LLM has to process data in order to determine it contains an attack, the attack could already be influencing that determination. “Relying on the model to detect XPIAs therefore resembles asking an interpreter to execute an untrusted program to determine whether that program is safe to execute,” Måløy asserted. Were Microsoft or some other company to pop another model in front of that model to check for malicious content, it only moves the problem outward, Måløy said, creating a “LLMs all the way down” scenario. “The long-term challenge likely lies in designing systems in which goals and intentions also exist independently of the information being processed,” he said. Until that time, Måløy argues, “any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate.” What can Copilot customers do to reduce the risk? Short of ditching Copilot, there’s not much. “No customer-side remediation fully addresses the issue at the time of publication,” Måløy said, but he does have a few tips. Treat externally sourced documents as untrusted when using them in Copilot, he recommends, and fully review every single document before sending it to Copilot, and fully review any Copilot-generated or edited documents before distributing them. Sheesh - if you’re going to have to actually read that stuff, you might as well just cut Copilot out of the loop and do the thinking yourself. Microsoft has been in touch to confirm the research, but the company's statement doesn't do anything to allay fears this is an unsolved issue. “We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.” We also reached out to Måløy, but didn’t hear back before publication. ® Updated at 1841 GMT on July 29 to add Microsoft's statement.
Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew's previous raids, noting the timing relative to recent government warnings. The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure on July 22, four days before Minnesota said the attacks targeted its systems. The advisory warned that Iran-linked hackers were attempting to disrupt operations using tactics previously associated with CyberAv3ngers. Government facilities, water and wastewater systems, and energy providers were among those urged to remain on high alert. What happened in Minnesota? On July 26 and 27, more than 30 community water systems across Minnesota were disrupted by what officials called "a coordinated cyberattack" targeting operational technology (OT). Minnesota IT Services (MNIT), the state's IT agency, said the Department of Health is working with the affected water facilities to ensure public health is maintained. No cities have yet asked citizens to modify the amount of drinking water they consume, per MNIT's latest update. The agency did not offer many other details about the attacks, other than to mention all the different agencies, organizations, and bodies it is working with as part of the investigation. One of the first cities to report issues, Braham, warned that its water reserves were limited in its initial notice. Citizens were asked not to water their lawns or use water for recreational purposes, although the problems were resolved the same day. No such directives were issued in other affected cities. Maple Plain declared a state of emergency, allowing it greater flexibility to coordinate resources, but did not ask residents to adjust their consumption. The same was true in the Twin Cities suburb of Plymouth and in South St. Paul, which both confirmed cyber-related problems on July 27 but did not ask residents to curb water use. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota CISO. "MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. "This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services." What is CyberAv3ngers? First identified around 2020, CyberAv3ngers is widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), specifically its Cyber-Electronic Command division (IRGC-CEC). For the first two years, the group began as a "propaganda persona," as Tenable puts it, claiming disruptive attacks on Israeli infrastructure – claims that were later debunked as fabrications. Its first sustained campaign came in November 2023, when it compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them anti-Israel messages. Tenable said CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland as part of the campaign. They did so by exploiting default passwords. Between 2024 and 2025, the crew developed the IOCONTROL malware kit, built for attacks on OT and Internet of Things (IoT) devices. OpenAI said in 2024 that the group's members used ChatGPT in the development process. CyberAv3ngers stepped up its activity in 2026, targeting US critical infrastructure through Rockwell Automation/Allen-Bradley PLCs from March onward. CISA's July 22 update added Schneider Electric and Siemens equipment to the list of potential targets. In some cases, the attacks - which targeted multiple critical infrastructure sectors - disrupted operations at affected facilities, federal officials said, though they offered no specifics on what those disruptions entailed. CyberAv3ngers is known for targeting small water and municipal facilities, which experts believe are among the lowest-hanging fruit in US critical infrastructure. Many small and rural facilities lack dedicated cybersecurity resources. Tenable said some operators manage OT environments using remote-access software such as TeamViewer and AnyDesk or leave their PLCs exposed to the web. "These access methods bypass enterprise security controls entirely, creating an attack surface that is invisible to conventional security monitoring," Tenable said. Poor segmentation between IT and OT environments can also allow a single intrusion to spread across much of the network. ®
One day after a federal judge ordered an ICE detention center opened to state health inspectors, the agency posted new contract terms that would void state oversight at four facilities.
The US government has decided to effectively ban the sale of advanced robots made in other nations. The decision trickled out over two days with publication of a National Security Determination [PDF] and an update [PDF] to the list of banned devices set by the Federal Communications Commission (FCC). The national security document observes “Advanced robotic devices will be critical to creating efficiencies in our economy, dominating on the battlefield, and securing our homeland” and notes that modern bots are now constantly connected to networks “which creates broad attack surfaces and leaves them vulnerable to data exfiltration, remote disruption of the physical robot, and dependencies on unsecure over the air updates.” One example of those vulnerabilities mentioned in the document is the UniPwn flaws that made it possible for attackers to take over humanoid robots made by Chinese company Unitree. “If the United States continues to rely on foreign sources of advanced robotic devices and critical components, it will subject the parts of the U.S. economy and national security enterprise that are reliant on these robots to the whims of foreign entities that could disrupt or degrade the supply chains at a time of their choosing,” the document states. To respond to those threats, the FCC decided the foreign-made advanced robotic devices belong on its Covered List of products for which imports are banned because they pose an unacceptable risk to the national security of the United States and its residents. The regulator offered a single exception: if the Department of War vouches for a device, it can have it. Foreign-owned companies that make their bots in America are also exempt, an important exemption because one of the leading robot-makers is Boston Dynamics – a company backed by the USA’s DARPA that is now majority-owned by South Korea’s Hyundai, but continues to manufacture its machines stateside. The decision does, however, apply to all future foreign-made devices. Vendors of clankers already approved for sale in the USA can continue to import them, and users are also free to use any bots they already own. But the intent of the documents is clear: from now on, only robots made in America are welcome in America. One entity that stands to benefit from this decision is Tesla, which Elon Musk claims will one day produce one million humanoid robots a year. In true Muskian style he has also said Tesla will go into “high production” of the bots in 2026, but there’s no evidence of that happening although the occasional trillionaire did recently show off the production line for Tesla’s “Optimus” bot. ®