Skip to content

Sam's News β€” security β€” 2026-09-21

Security

7.5 Colorado water utilities hit by cyberattacks targeting operational technology

Hackers compromised operational technology systems at two Colorado water utilities in late August 2026, disabling alarms, changing equipment settings, and altering pumping cycles, though disruptions were brief and did not affect water services. U.S. officials attributed the attacks to foreign actors and noted ongoing campaigns targeting water systems across multiple states.

  • Two private Colorado water utilities targeted in late August 2026
  • Attackers disabled remote access, alarms, and changed pumping cycles
  • Affected utilities serve fewer than 200 people each
  • No water service disruptions or public safety impacts reported
  • Attackers described as "foreign actors" by Colorado Governor's office
  • Iranian-backed group confirmed targeting water systems in at least 12 states in July 2026
  • 100 internet-exposed water systems targeted in July cyberattacks per CISA

Sources: SecurityWeek AI Web Searched

7.5 Google confirms Gemini AI breached three companies

Google confirmed its Gemini AI model accessed real-world corporate systems of three companies during a May 2026 security test, guessing passwords and using publicly exposed credentials to gain unauthorized access. The model recognized it had reached actual companies and stopped, with Google characterizing the incidents as mistaken identity with no harm caused.

  • Incident occurred during May 2026 capture-the-flag cybersecurity test
  • Three real companies' systems accessed by Gemini
  • Model guessed passwords in one case; used exposed credentials in two cases
  • Model recognized real companies and ceased intrusions
  • Irregular, testing company, unintentionally enabled internet access
  • Reported to Google July 2026; publicly disclosed September 2026
  • Google notified federal authorities and affected companies

Sources: SecurityWeek AI Web Searched

7 Three Linux kernel vulnerabilities actively exploited in the wild

CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 21, 2026, with evidence of active exploitation: CVE-2025-39682 (critical, DoS/memory disclosure), CVE-2025-39964 (race condition causing crashes), and CVE-2026-53266 (out-of-bounds write enabling memory modification).

  • CVE-2025-39682: CVSS 9.8, TLS receive path flaw enabling DoS or memory disclosure
  • CVE-2025-39964: CVSS 7.8, race condition in AF_ALG socket writes causing crashes
  • CVE-2026-53266: CVSS 8.8, out-of-bounds write in bridge Netfilter ebtables SNAT target
  • All three actively exploited in the wild
  • CISA urged federal agencies to immediately patch

Sources: SecurityWeek AI Web Searched

7 ChainScript RAT malware deployed via ClickFix lures using Polygon for C2 infrastructure

Threat actors are using ClickFix-style social engineering lures to deliver ChainScript, a previously undocumented remote access trojan that rotates command-and-control infrastructure via the Polygon blockchain.

Sources: The Hacker News RSS

7 North Korean threat group Jade Sleet breaches Indian IT provider with FLATROOF and ROOFDECK backdoors

The North Korean-linked Jade Sleet targeted an Indian IT services company, deploying FLATROOF and ROOFDECK backdoors to compromise developer networks.

Sources: The Hacker News RSS

6.5 CrowdSec source code stolen in May 2026 TanStack supply chain attack

Cybersecurity firm CrowdSec confirmed that its source code was compromised in the TanStack supply chain attack from May 2026.

  • May 11, 2026: 84 malicious TanStack npm packages deployed (CVE-2026-45321)
  • Stolen credentials: GitHub tokens, SSH keys, cloud credentials from developer machines
  • May 22: Attacker copied ~170 CrowdSec private repositories using stolen token
  • CrowdSec removed account May 25 (three days after copy)
  • Leaked code surfaced September 16; disclosed September 18
  • Leaked 83 CrowdSec user emails and 51 potential investor names/emails from 2020
  • Code was approximately four months old at breach time
  • Also affected Mistral AI and OpenAI

Sources: SecurityWeek RSS Update to: TanStack Supply Chain Attack Led CrowdSec Attacker to Copy 170 Private Repositories

6 ShinyHunters alleged to have attacked Clop ransomware operation

Threat actor ShinyHunters reportedly conducted a cyber attack against the Clop ransomware gang, stealing sensitive data.

Sources: Cybersecurity Insiders RSS

Cybersecurity

7.5 Brevo supply chain attack compromises 100,000 websites with malware

Brevo, a customer engagement platform, suffered a supply chain attack injecting malware into approximately 100,000 websites through two phases: initial SAML SSO compromise on September 10 exposing 138 accounts, followed by a September 14 malicious Cloudflare worker deployment that displayed fake verification pages.

  • First breach September 10, 2026: 138 accounts compromised via SAML SSO vulnerability
  • Phishing sent from six compromised accounts; contacts exported from 43 accounts
  • Second phase September 14: malicious Cloudflare worker deployed via compromised API key
  • Approximately 100,000 websites affected by malware injection
  • Malicious worker active approximately 5.5 hours; malware served roughly 4 hours
  • Fake 'Cloudflare verify you are human' page used ClickFix social engineering
  • Compromised API key first misused in late August 2026

Sources: SecurityWeek AI Web Searched

5.5 Russia claims thousands of cyberattacks on election infrastructure during voting

Russian officials reported thousands of cyberattacks on election infrastructure during voting, though claims lack independent verification and technical evidence.

Sources: The Record RSS