Cyber Briefing, Sep 21: Colorado water OT attacks, Three Linux CVEs exploited

A digital illustration representing cybersecurity news, featuring a shield with a lock, various icons like email and warning signs, and a computer in the background, all set against a blue tech-themed backdrop.

10 stories · 6 sources · 3 high · ~9 min read

Coverage: Last 72 hours

Today’s Highlights

This cycle underscores the convergence of AI-driven operational risk, real-world OT disruption, and the speed at which attackers exploit new vulnerabilities. Notably, attacks on Colorado water utilities highlight that operational technology (OT) systems are primary targets for foreign-aligned threat actors seeking to disrupt critical infrastructure. The urgency of Linux kernel patching increases as new CVEs are exploited in the wild. Defenders must recognize that both attacker dwell times and exploit ramp-up windows continue to shrink, leaving little tolerance for delays in detection and response.

Table of Contents

  1. Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
  2. Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
  3. Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
  4. Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
  5. Friday Squid Blogging: On Squid Egg Sacs

Critical   High   Medium   Low

Top Stories


Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Source: SecurityWeek | Published: Sep 21 | Risk: HIGH | Impacted: small water utilities, OT/ICS operators, municipal IT-OT teams | Topics: Ics Ot / Vulnerability

What happened: In late August 2026, hackers targeted operational technology systems at two small Colorado water utilities, altering equipment settings, disabling remote access and alarms, and modifying pumping cycles. These disruptions were brief and did not impact water services or public safety. The attackers were described as “foreign actors,” with potential links to Iranian-backed groups.

Why it matters: Compromises of operational technology at critical infrastructure providers can undermine public trust and safety by exposing the organization to destructive or disruptive attacks, even if immediate impact is limited.

How it works: Industrial control systems (ICS) and operational technology (OT) control physical processes such as water treatment equipment. These systems often lack modern security controls, making them vulnerable to remote attackers who can directly alter operational parameters if they gain access.

Practitioner Perspective

Small and rural utilities are prime targets for actors seeking to influence or disrupt critical services with limited detection or incident response capabilities. This trend fits the larger pattern of foreign-aligned groups focusing on vulnerable OT/ICS assets. Utilities relying on vendor-managed remote access and legacy SCADA systems need urgent visibility and robust containment plans due to limited segmentation. Even short-lived changes to OT parameters or alarm systems may mask deeper persistent threat activity. Assume your OT environment is low-hanging fruit if you lack real-time monitoring and regular out-of-band configuration backups.

Recommended Actions

  • Review audit trails for unauthorized changes to HMI and PLC settings following August 2026 activity
  • Implement continuous monitoring or sensor-based alerting on SCADA and OT-side network links

Exploits & CVEs


Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

Source: The Hacker News UPDATED | Published: Sep 19 | Risk: HIGH | Impacted: vulnerability management teams, threat research teams, software security leads | Topics: Vulnerability / Exploit

What happened: A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer

Why it matters: With AI-driven tooling dramatically reducing the gap between vulnerability disclosure and working exploits, organizations face an increased risk window before patching can be applied, making previous response cycles inadequate.

How it works: Adversarial automation and advanced proof-of-concept exploit generators, fueled by AI, can rapidly validate and weaponize vulnerabilities as soon as public details become available, often outpacing manual response by security teams tasked with triage and patch rollout.

Practitioner Perspective

Security programs must evolve from manual or scheduled validation to near-real-time monitoring for exploitability in their unique environment. Waiting for traditional vulnerability scanners or quarterly internal reviews will miss the critical period when adversaries are most active. Investing in both rapid triage automation and tailored proof-of-concept testing within your infrastructure will close the dangerous window between initial CVE disclosure and practical adversary exploitation.

Recommended Actions

  • Integrate dynamic exploitability analysis tools into your vulnerability management pipeline
  • Automate internal PoC exploit tests for newly published CVEs within isolated lab environments

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Source: SecurityWeek | Published: Sep 21 | Risk: HIGH | Impacted: Linux server operators, cloud infrastructure teams, hybrid and on-prem datacenters | Topics: Vulnerability / Threat Intel

What happened: The Cybersecurity and Infrastructure Security Agency (CISA) has added three critical Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them immediately. These flaws could allow attackers to cause denial-of-service conditions, disclose memory, or modify memory.

Why it matters: Kernel-level flaws with known exploitation give adversaries reliable paths to memory attacks, denial-of-service, and unauthorized access that can escalate to infrastructure-wide compromise if left unpatched.

How it works: The Linux kernel manages hardware, memory, and system calls for the entire operating system. Vulnerabilities at this level can allow attackers to crash systems, read or overwrite protected memory, and bypass key security boundaries.

Practitioner Perspective

Any Linux infrastructure not patched for these KEV-listed kernel bugs effectively invites opportunistic attackers and botnet operators leveraging public exploit kits. Because CISA flagged these CVEs, exploit attempts are likely ongoing and detectable in the wild. Standard vulnerability scans may not detect exploitation in memory or log clear forensic evidence. The biggest mistake is to treat these as deferred patching items; prioritize even if you run heterogenous Linux versions across hybrid environments. Kernel updates should be coordinated and followed by integrity checks to catch post-exploitation artifacts.

Recommended Actions

  • Patch all Linux kernels for CVEs referenced in the latest CISA KEV catalog on a rolling but expedited schedule
  • Conduct targeted memory and privilege escalation artifact hunting for signs of these kernel flaws in production

Emerging Signals


Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

Source: The Hacker News | Published: Sep 21 | Risk: MEDIUM | Impacted: Indian IT service providers, macOS developer endpoints, clients of outsourced IT contractors | Topics: Vulnerability / Data Breach

What happened: North Korean threat actor Jade Sleet compromised an Indian IT services provider using macOS backdoors FLATROOF and ROOFDECK, employing social engineering tactics like job interview lures to target developers.

Why it matters: Sophisticated backdoors with macOS support extend threat actor reach beyond typical Windows targets, amplifying supply-chain and contractor risk for IT service customers.

How it works: FLATROOF and ROOFDECK are backdoors designed for macOS systems, enabling remote attacker control. They are deployed via spear-phishing campaigns targeted at technical staff, using lures like fake job interviews to bypass conventional defenses.

Practitioner Perspective

North Korean actors are actively targeting IT and software vendors as pivot points for further operations, not just as direct victims. The use of FLATROOF and ROOFDECK macOS backdoors, delivered via job-related social engineering, demonstrates that developer and technical staff endpoints are high-value targets regardless of platform. IT service providers with multinational clients face unique risks from these tailored implants, which bypass threat detection common on Windows fleets. Intensify endpoint monitoring and threat hunting on macOS, especially for personnel with privileged access to infrastructure or source code. Prioritize detection engineering for these specific implant families and continually raise staff awareness of targeted phishing.

Recommended Actions

  • Deploy threat hunting rules for FLATROOF and ROOFDECK IOCs on all macOS endpoints in developer and IT admin fleets
  • Conduct phishing simulation and targeted awareness campaigns for technical staff on job interview-themed lures

Friday Squid Blogging: On Squid Egg Sacs

Source: Schneier on Security | Published: Sep 18 | Risk: LOW | Impacted: policy and cryptography enthusiasts | Topics: Cryptography / Policy

What happened: Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Why it matters: Security blogs like this provide an informal forum for industry discussion and relaxation, which can help community members stay grounded amid cybersecurity’s rapid news cycle.

How it works: Schneier’s regular Friday squid features serve as discussion points for the security community, offering a lighter intermission to harder technical and policy news.

Practitioner Perspective

Staying engaged in the wider professional cybersecurity community outside headline breaches and threat advisories helps practitioners keep perspective and exchange practical insights. Occasional ‘off-topic’ discussions can foster resilience and creativity in high-intensity incident response environments.

Recommended Actions

  • Participate in security community discussion threads to share context and decompress
  • Monitor Schneier’s security blog for occasional expert curation of overlooked news

Also Today

Defensive Actions

  • Patch all Linux kernels for the KEV-listed CVEs highlighted by CISA; prioritize even heterogenous or hybrid cloud environments
  • Review audit trails on OT and ICS systems for any unauthorized changes to HMI and PLC settings after the August 2026 activity
  • Deploy threat hunting rules for FLATROOF and ROOFDECK backdoor indicators on all macOS endpoints managed by developer or IT staff
  • Implement continuous OT monitoring or deploy sensor-based alerting on SCADA and related networks
  • Restrict and audit all vendor and third-party remote access pathways on OT systems, enforcing multi-factor authentication where feasible
  • Conduct phishing simulations and targeted awareness training for technical staff using job-themed lures as templates
  • Integrate dynamic exploitability testing tools for new CVEs into vulnerability assessment workflows
  • Institute incident notification procedures for AI-driven security testing that might reach unintended production assets

What We’re Watching

  • Ongoing exploitation attempts against unpatched Linux kernel vulnerabilities added to the CISA KEV list
  • ChainScript RAT leveraging Polygon blockchain for C2 rotation, especially in organizations using ClickFix
  • Adoption of FLATROOF and ROOFDECK macOS backdoors by North Korean actors, with increased targeting of IT contractors
  • Development and maturity of US-China notification frameworks for AI incidents with national security implications
  • Emerging double-extortion, AI-accelerated ransomware campaigns focusing on APAC, especially from the Qilin group

Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.



Categories: Cybersecurity Blog, Cybersecurity News

Tags: , , , , ,

Leave a Reply

Discover more from TECHMANIACS.com

Subscribe now to keep reading and get access to the full archive.

Continue reading