
10 stories · 6 sources · 3 high · ~9 min read
Coverage: Last 72 hours
Today’s Highlights
This cycle underscores the convergence of AI-driven operational risk, real-world OT disruption, and the speed at which attackers exploit new vulnerabilities. Notably, attacks on Colorado water utilities highlight that operational technology (OT) systems are primary targets for foreign-aligned threat actors seeking to disrupt critical infrastructure. The urgency of Linux kernel patching increases as new CVEs are exploited in the wild. Defenders must recognize that both attacker dwell times and exploit ramp-up windows continue to shrink, leaving little tolerance for delays in detection and response.
Table of Contents
- Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
- Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
- Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
- Friday Squid Blogging: On Squid Egg Sacs
Critical High Medium Low
Top Stories
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Source: SecurityWeek | Published: Sep 21 | Risk: HIGH | Impacted: small water utilities, OT/ICS operators, municipal IT-OT teams | Topics: Ics Ot / Vulnerability
What happened: In late August 2026, hackers targeted operational technology systems at two small Colorado water utilities, altering equipment settings, disabling remote access and alarms, and modifying pumping cycles. These disruptions were brief and did not impact water services or public safety. The attackers were described as “foreign actors,” with potential links to Iranian-backed groups.
Why it matters: Compromises of operational technology at critical infrastructure providers can undermine public trust and safety by exposing the organization to destructive or disruptive attacks, even if immediate impact is limited.
How it works: Industrial control systems (ICS) and operational technology (OT) control physical processes such as water treatment equipment. These systems often lack modern security controls, making them vulnerable to remote attackers who can directly alter operational parameters if they gain access.
Practitioner Perspective
Small and rural utilities are prime targets for actors seeking to influence or disrupt critical services with limited detection or incident response capabilities. This trend fits the larger pattern of foreign-aligned groups focusing on vulnerable OT/ICS assets. Utilities relying on vendor-managed remote access and legacy SCADA systems need urgent visibility and robust containment plans due to limited segmentation. Even short-lived changes to OT parameters or alarm systems may mask deeper persistent threat activity. Assume your OT environment is low-hanging fruit if you lack real-time monitoring and regular out-of-band configuration backups.
Recommended Actions
- Review audit trails for unauthorized changes to HMI and PLC settings following August 2026 activity
- Implement continuous monitoring or sensor-based alerting on SCADA and OT-side network links
Exploits & CVEs
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
Source: The Hacker News UPDATED | Published: Sep 19 | Risk: HIGH | Impacted: vulnerability management teams, threat research teams, software security leads | Topics: Vulnerability / Exploit
What happened: A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer
Why it matters: With AI-driven tooling dramatically reducing the gap between vulnerability disclosure and working exploits, organizations face an increased risk window before patching can be applied, making previous response cycles inadequate.
How it works: Adversarial automation and advanced proof-of-concept exploit generators, fueled by AI, can rapidly validate and weaponize vulnerabilities as soon as public details become available, often outpacing manual response by security teams tasked with triage and patch rollout.
Practitioner Perspective
Security programs must evolve from manual or scheduled validation to near-real-time monitoring for exploitability in their unique environment. Waiting for traditional vulnerability scanners or quarterly internal reviews will miss the critical period when adversaries are most active. Investing in both rapid triage automation and tailored proof-of-concept testing within your infrastructure will close the dangerous window between initial CVE disclosure and practical adversary exploitation.
Recommended Actions
- Integrate dynamic exploitability analysis tools into your vulnerability management pipeline
- Automate internal PoC exploit tests for newly published CVEs within isolated lab environments
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Source: SecurityWeek | Published: Sep 21 | Risk: HIGH | Impacted: Linux server operators, cloud infrastructure teams, hybrid and on-prem datacenters | Topics: Vulnerability / Threat Intel
What happened: The Cybersecurity and Infrastructure Security Agency (CISA) has added three critical Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them immediately. These flaws could allow attackers to cause denial-of-service conditions, disclose memory, or modify memory.
Why it matters: Kernel-level flaws with known exploitation give adversaries reliable paths to memory attacks, denial-of-service, and unauthorized access that can escalate to infrastructure-wide compromise if left unpatched.
How it works: The Linux kernel manages hardware, memory, and system calls for the entire operating system. Vulnerabilities at this level can allow attackers to crash systems, read or overwrite protected memory, and bypass key security boundaries.
Practitioner Perspective
Any Linux infrastructure not patched for these KEV-listed kernel bugs effectively invites opportunistic attackers and botnet operators leveraging public exploit kits. Because CISA flagged these CVEs, exploit attempts are likely ongoing and detectable in the wild. Standard vulnerability scans may not detect exploitation in memory or log clear forensic evidence. The biggest mistake is to treat these as deferred patching items; prioritize even if you run heterogenous Linux versions across hybrid environments. Kernel updates should be coordinated and followed by integrity checks to catch post-exploitation artifacts.
Recommended Actions
- Patch all Linux kernels for CVEs referenced in the latest CISA KEV catalog on a rolling but expedited schedule
- Conduct targeted memory and privilege escalation artifact hunting for signs of these kernel flaws in production
Emerging Signals
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Source: The Hacker News | Published: Sep 21 | Risk: MEDIUM | Impacted: Indian IT service providers, macOS developer endpoints, clients of outsourced IT contractors | Topics: Vulnerability / Data Breach
What happened: North Korean threat actor Jade Sleet compromised an Indian IT services provider using macOS backdoors FLATROOF and ROOFDECK, employing social engineering tactics like job interview lures to target developers.
Why it matters: Sophisticated backdoors with macOS support extend threat actor reach beyond typical Windows targets, amplifying supply-chain and contractor risk for IT service customers.
How it works: FLATROOF and ROOFDECK are backdoors designed for macOS systems, enabling remote attacker control. They are deployed via spear-phishing campaigns targeted at technical staff, using lures like fake job interviews to bypass conventional defenses.
Practitioner Perspective
North Korean actors are actively targeting IT and software vendors as pivot points for further operations, not just as direct victims. The use of FLATROOF and ROOFDECK macOS backdoors, delivered via job-related social engineering, demonstrates that developer and technical staff endpoints are high-value targets regardless of platform. IT service providers with multinational clients face unique risks from these tailored implants, which bypass threat detection common on Windows fleets. Intensify endpoint monitoring and threat hunting on macOS, especially for personnel with privileged access to infrastructure or source code. Prioritize detection engineering for these specific implant families and continually raise staff awareness of targeted phishing.
Recommended Actions
- Deploy threat hunting rules for FLATROOF and ROOFDECK IOCs on all macOS endpoints in developer and IT admin fleets
- Conduct phishing simulation and targeted awareness campaigns for technical staff on job interview-themed lures
Friday Squid Blogging: On Squid Egg Sacs
Source: Schneier on Security | Published: Sep 18 | Risk: LOW | Impacted: policy and cryptography enthusiasts | Topics: Cryptography / Policy
What happened: Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Why it matters: Security blogs like this provide an informal forum for industry discussion and relaxation, which can help community members stay grounded amid cybersecurity’s rapid news cycle.
How it works: Schneier’s regular Friday squid features serve as discussion points for the security community, offering a lighter intermission to harder technical and policy news.
Practitioner Perspective
Staying engaged in the wider professional cybersecurity community outside headline breaches and threat advisories helps practitioners keep perspective and exchange practical insights. Occasional ‘off-topic’ discussions can foster resilience and creativity in high-intensity incident response environments.
Recommended Actions
- Participate in security community discussion threads to share context and decompress
- Monitor Schneier’s security blog for occasional expert curation of overlooked news
Also Today
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure: Threat actors are deploying ChainScript RAT via ClickFix lures with infrastructure rotation powered by Polygon blockchain smart contracts, complicating detection and persistence removal.
- Google Confirms Gemini AI Breached Three Firms: Google’s Gemini AI model inadvertently accessed real company systems in a red team exercise, raising concerns about AI guardrails.
- US and China Discuss Alerting Each Other to AI National Security Threats: US and Chinese officials begin dialogue on mutual notification of AI-driven incidents that could threaten national security.
- An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang: Google’s threat intelligence group placed an analyst inside the TeamPCP hacking gang, which was responsible for a major supply-chain breach.
- In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw: Highlights include a ransomware dev sentencing, Plugin4Shell attacks via AI, and exploitation of a critical SAP vulnerability.
Defensive Actions
- Patch all Linux kernels for the KEV-listed CVEs highlighted by CISA; prioritize even heterogenous or hybrid cloud environments
- Review audit trails on OT and ICS systems for any unauthorized changes to HMI and PLC settings after the August 2026 activity
- Deploy threat hunting rules for FLATROOF and ROOFDECK backdoor indicators on all macOS endpoints managed by developer or IT staff
- Implement continuous OT monitoring or deploy sensor-based alerting on SCADA and related networks
- Restrict and audit all vendor and third-party remote access pathways on OT systems, enforcing multi-factor authentication where feasible
- Conduct phishing simulations and targeted awareness training for technical staff using job-themed lures as templates
- Integrate dynamic exploitability testing tools for new CVEs into vulnerability assessment workflows
- Institute incident notification procedures for AI-driven security testing that might reach unintended production assets
What We’re Watching
- Ongoing exploitation attempts against unpatched Linux kernel vulnerabilities added to the CISA KEV list
- ChainScript RAT leveraging Polygon blockchain for C2 rotation, especially in organizations using ClickFix
- Adoption of FLATROOF and ROOFDECK macOS backdoors by North Korean actors, with increased targeting of IT contractors
- Development and maturity of US-China notification frameworks for AI incidents with national security implications
- Emerging double-extortion, AI-accelerated ransomware campaigns focusing on APAC, especially from the Qilin group
Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply