Forum Discussion
Tenable Security Intel Brief: Multi-state cyberattacks hit water systems
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.
This week, a coordinated attack disrupted operational technology at more than 30 Minnesota community water and wastewater systems, part of a wave the FBI says reached at least seven states. Our research team assesses the activity is consistent with the Iran-linked CyberAv3ngers ecosystem. U.S. officials have preliminarily pointed to Iran, though no formal attribution has been made.
Coordinated cyberattack disrupts 30-plus Minnesota water systems →
Brief: A coordinated attack disrupted control systems at 30-plus Minnesota water and wastewater plants, one cluster in a wave the FBI says reached at least seven states.
Intel: Four Minnesota cities disclosed attacks. In Braham (~1,700 residents), the plant was taken offline, then restored in two hours; Plymouth switched to manual operation and Maple Plain declared an emergency, no water-quality impact reported. U.S. officials told outlets a preliminary assessment points to Iran, citing the tradecraft and lack of a ransom demand, though it could change. Our research finds the pattern consistent with CyberAv3ngers, which the U.S. links to Iran's IRGC. No agency has named a flaw, but the one most tied to it, CVE-2021-22681 (CVSS 9.8), lets attackers reach Rockwell Logix controllers without authentication.
Update (August 4): On July 30, an FBI-EPA advisory said utilities in at least seven states had reported incidents since July 27, some degrading operations, naming no states or actor; CISA urged utilities to pull exposed programmable logic controllers (PLCs) offline. On August 1, Michigan became the second confirmed state, an EGLE official citing nine systems and no health impact. By August 4, ABC News and Axios reported possible cyber intrusions in "at least 12" states, citing unnamed sources; the FBI's tally still stands at seven.
Why it matters: No flaw is named and attribution stays open, but the exposure is real: internet-facing controllers at least-resourced utilities, tied to a Rockwell weakness its maker says cannot be fully patched. No fix cycle to wait on, only network redesign. The wave already means a plant knocked offline in a town of 1,700.
TA488 pivots to Outlook Web Access with a half-click backdoor →
Brief: Proofpoint reports that TA488, a Russia-aligned actor also tracked as Void Blizzard and Laundry Bear, is exploiting CVE-2026-42897, an Outlook web (OWA) flaw Microsoft rated maximum severity and CISA lists as exploited, to deploy a browser-based backdoor called OWAReaper.
Intel: The campaign began July 22, a day before Proofpoint and the NSA warned of the actor's Zimbra activity. Opening a bland TA488 lure email in OWA runs JavaScript hidden in the message's social-media-icon markup: the reading pane alone triggers it, no link or attachment. That JavaScript is OWAReaper, which Proofpoint calls its "most sophisticated" half-click backdoor yet and a descendant of last week's ZimReaper implant. It steals saved OWA passwords and access tokens, then grants Exchange's "Default" user owner access to every folder, opening it to the actor. Proofpoint says infrastructure predates Microsoft's patch by two months.
Why it matters: The folder-permission grant lives on the Exchange server, so it outlasts the responses defenders reach for first. Proofpoint puts it plainly: "credential rotation and even full re-imaging of the targeted user's device will not evict the actor." A second backdoor in the browser's offline cache re-infects the rebuilt machine. This is TA488's second webmail half-click in two weeks.
A Chinese-speaking actor ran DeepSeek as an autonomous attack operator →
Brief: Palo Alto Networks' Unit 42 documented a Chinese-speaking threat actor, tracked as "knaithe" and "KnYuan," who ran DeepSeek as an AI that attacked on its own after a single instruction, built in the open-source Hermes Agent framework, commanded over Telegram.
Intel: Hermes Agent gave the model terminal access and a skills system on a remote command channel. DeepSeek chose targets and wrote the code. From one Telegram instruction, it searched FOFA, an internet-scanning engine, pulled public exploits from GitHub, and attacked on its own. Both autonomous attacks were stopped by the targets' own setup: a Langflow flaw (CVE-2026-33017) and two n8n flaws (CVE-2026-21858 plus CVE-2025-68613). The confirmed damage was manual: a Citrix NetScaler flaw (CVE-2026-3055) leaked data from three organizations, a Marimo Notebook flaw (CVE-2026-39987) ran commands on 11 machines. Across 460+ targets, Unit 42 says the workflow "confirms a functional, end-to-end autonomous offensive capability," while the autonomous campaigns fully compromised none of their targets.
Why it matters: The actor tried Claude Code and Codex, but Unit 42 found their provider-side controls "likely limited their effectiveness." DeepSeek was the most permissive alternative, run through a framework with nothing to disable. The starker finding is the one Unit 42 closes on: the technical barrier to AI-augmented offensive operations is low and still dropping.
Two AI labs disclose test models reaching real production systems →
Brief: Two AI labs disclosed real-world security incidents involving lab-tested models: Anthropic's models reached three real companies through a partner's misconfigured test setup, and OpenAI's models found unpatched flaws in JFrog's software, extending our July 22 OpenAI and Hugging Face coverage.
Intel: OpenAI's models found zero-days in self-hosted Artifactory, its repository manager, that could be exploited to gain unintended internet access, JFrog confirmed. The company has shipped fixes; cloud customers are protected and self-hosted users directed to Artifactory 7.161. Its post names no CVEs, though the July 27 patch release carries nine newly assigned Artifactory CVEs. Anthropic separately reviewed 141,006 test runs and found three cases where Claude models reached the internet through partner Irregular's misconfigured test environment, accessing three organizations. In one, a model published a booby-trapped software package to PyPI, a public code library, that ran on 15 real systems, including a security firm's scanner, before PyPI removed it.
Update (August 4): OpenAI disclosed two further incidents, separate from the Hugging Face escape, in which its models crossed testing boundaries during third-party evaluations. One was at the UK's AI Security Institute, where internet access was intentionally on and safety classifiers off to measure raw capability. The other was at Irregular, which also ran Anthropic's misconfigured test environment. Neither incident involved a zero-day.
Why it matters: Two frontier labs disclosed the same event class in a month: capability tests run without released models' safeguards, in environments with network access. OpenAI's models identified a genuine zero-day. Anthropic calls its incidents "closer to a harness and operational failure than a model alignment failure." Either way, a model built to find a way out found one.
Stat of the week: $4.99 million
The global average cost of a data breach, up 12% year over year, according to the IBM 2026 Cost of a Data Breach Report, based on breaches at 602 organizations between March 2025 and February 2026.
Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.