Issue #017 · August 26, 2026
Cyber Threat Brief — Issue #017
What's active. What matters. What to do about it.
Priority Actions This Week
- 01If your organization operates water, wastewater, energy, or any industrial control systems, disconnect programmable logic controllers and human-machine interfaces from the public internet today. Iranian-linked actors have disrupted operations at water utilities across more than a dozen US states since late July, including over 30 Minnesota communities. The primary entry point is control equipment left reachable from the internet, often with default or unchanged passwords. Network isolation is the required control, because some of the affected equipment has no available patch.
- 02If your development teams run self-hosted Gitea, patch to version 1.27.1 or later today. CVE-2026-60004 is now being actively exploited in the wild, and CISA added it to its Known Exploited Vulnerabilities catalog on August 25 with a federal deadline of August 28. Attackers are registering accounts on exposed servers that allow open registration, then running code to install cryptocurrency miners. If your Gitea instance allows open registration and is reachable from the internet, treat it as a potential incident, not just a patch.
- 03Review the Adobe and Nvidia advisories published this week and patch any affected products. Both vendors released fixes for critical vulnerabilities. Nvidia's affect widely deployed GPU and AI infrastructure components, which matters for any organization running AI or high-performance computing workloads.
- 04If you run Samsung Galaxy devices in your organization, ensure they have the August 2026 security update. It fixes 56 vulnerabilities, including eight critical Android flaws. Mobile devices with access to corporate email and applications are part of your attack surface, and unpatched flaws in them are a path into your environment.
- 05Reassess how you prioritize patching. Rapid7 warned this month that traditional patch cycles can no longer keep pace with the volume of disclosed vulnerabilities and the speed of exploitation. The practical shift is to prioritize by exposure rather than by severity score alone. A medium-severity flaw on an internet-facing system you depend on may need attention before a critical flaw on an isolated internal one.
Active Campaigns
A wave of intrusions has disrupted water and wastewater utilities across at least 12 US states between late July and August 2026, including more than 30 communities in Minnesota. Several utilities reverted to manual control to maintain operations, and one Georgia authority issued a boil-water notice. Federal officials have not formally attributed the campaign, but the operational pattern is consistent with CyberAv3ngers, an Iranian state-directed group tied to the IRGC Cyber-Electronic Command that has been active since at least 2020. The attacks target programmable logic controllers and human-machine interfaces, the industrial computers that automate water treatment, that were left reachable from the internet. In many cases the entry method involves default or unchanged passwords and exposed remote access software. The Minnesota attacks began just four days after CISA updated its advisory warning of active Iranian targeting of water sector control systems. The campaign is significant for two reasons. First, it targets physical infrastructure that communities depend on for safe drinking water. Second, the affected control equipment is often difficult or impossible to patch, which means the defensive burden falls entirely on network isolation, access control, and removing these systems from the public internet. Small and rural utilities are the primary targets precisely because they are the least likely to have dedicated security staff.
A critical remote code execution vulnerability in Gitea, the widely used self-hosted platform for managing source code, has moved from disclosure to active exploitation in under a month. Tracked as CVE-2026-60004 and rated a critical 9.8, the flaw lets an attacker with ordinary repository write access abuse the diffpatch API endpoint to plant an executable Git hook and run arbitrary shell commands as the Gitea service account. Gitea patched it in late July with version 1.27.1, and CISA added it to the Known Exploited Vulnerabilities catalog on August 25, confirming attacks are occurring in the wild, with a federal remediation deadline of August 28. The danger is amplified by a default Gitea setting: open registration. Although exploitation technically requires an authenticated account with repository write access, an exposed server that allows open registration lets an external attacker simply create an account, create a repository, and trigger the exploit. Confirmed attacks have deployed cryptocurrency mining malware, with at least one documented case where a self-hosted instance was compromised after an automated scanner registered an account on a server with no email confirmation or CAPTCHA. Shadowserver is tracking nearly 5,000 Gitea instances exposed online. A compromised code server can expose configuration secrets, database credentials, and the OAuth and integration credentials that connect it to production.
Adobe and Nvidia each published multiple security advisories this week, including fixes for critical vulnerabilities in their products. Nvidia's advisories are particularly relevant given how widely its GPU and AI infrastructure components are deployed across cloud providers, research institutions, and any organization running AI or high-performance computing workloads. A vulnerability in this layer can affect the shared infrastructure that many organizations depend on. Notably, a significant share of the vulnerabilities being disclosed by major vendors this year, including many in Google Chrome, were discovered using AI. This is reshaping the disclosure landscape in two ways at once. Vendors are finding and fixing more flaws faster than ever, which is good, but the same capability lowers the barrier for attackers to discover flaws too, and it is part of why the volume of patches organizations must apply keeps rising. The practical consequence for defenders is that the patch backlog is growing structurally, not temporarily, and prioritization discipline matters more than it ever has.
CVE Watch
PRODUCT: Rockwell Automation Studio 5000 Logix Designer / Logix controllers
WHAT IT MEANS:
This is a critical vulnerability in Rockwell Automation control systems that lets an attacker bypass authentication and connect to a programmable logic controller, the industrial computer that automates physical processes like water treatment. It is a striking example of the industrial control system patching problem. The vulnerability was disclosed in 2021 and remained largely unexploited for years because industrial systems are extremely difficult to patch without disrupting essential services. Since March 2026, Iranian affiliated actors have been actively exploiting it, and CISA added it to the Known Exploited Vulnerabilities catalog. Rockwell has confirmed there is no security patch available, which means the only defense is to isolate the affected controllers from the internet and restrict access to them. A critical, no-patch, actively exploited flaw in equipment that runs public water infrastructure is exactly the scenario the current water utility campaign is exploiting.
ACTION:Isolate all Rockwell Logix controllers from the public internet immediately. Restrict controller access to authorized engineering systems only, change any default or unchanged passwords, log cellular modem and remote access connections, and inspect controller project files for unauthorized changes.
PRODUCT: Gitea (versions 1.17 through the fix in 1.27.1)
WHAT IT MEANS:
A critical remote code execution vulnerability in Gitea, the self-hosted source code management platform, allows an attacker with repository write access to abuse the diffpatch API endpoint, plant an executable Git hook, and run arbitrary shell commands as the Gitea service account. CISA confirmed active exploitation and added it to the Known Exploited Vulnerabilities catalog on August 25 with a federal deadline of August 28. The practical severity is higher than "authenticated RCE" suggests, because Gitea's default open registration lets an external attacker create their own account and repository to obtain the required write access. Confirmed attacks have deployed cryptocurrency miners, and a compromised server can expose configuration secrets, database credentials, and the OAuth and integration credentials that connect it to production. Nearly 5,000 Gitea instances are exposed online.
ACTION:Upgrade Gitea to version 1.27.1 or later immediately. Disable open registration, remove anonymous access, and place the server behind a VPN or zero-trust gateway rather than leaving it broadly reachable. Treat any internet-exposed instance that allowed open registration as a potential incident: search for unexpected Git hooks, Gitea-spawned shell processes, unfamiliar account creation, and anomalous CPU or outbound network activity.
PRODUCT: Microsoft Windows Ancillary Function Driver for WinSock (afd.sys)
WHAT IT MEANS:
Covered in Issue 016 as ACTIVE. This use-after-free vulnerability in the Windows kernel networking driver allows privilege escalation to SYSTEM level and was added to the CISA Known Exploited Vulnerabilities catalog on August 11. It remains an active concern because it is present on every Windows machine and is the kind of flaw an attacker chains after gaining an initial foothold. Moving to MONITORING because the August Patch Tuesday fix has been available for two weeks. Organizations that have completed August patching are protected; those that have not should treat it as overdue.
ACTION:Confirm the August 2026 Windows security update is deployed across all Windows endpoints and servers. If August patching is not complete, prioritize it now.
Threat Actor Activity
Operational pattern consistent with the group behind disruptions at water utilities across at least 12 US states since late July, including more than 30 Minnesota communities, with some utilities reverting to manual control. Targets internet-exposed PLCs and HMIs at small water systems. Active since 2020, US-sanctioned, formally tied to Iran's IRGC. No patch exists for the primary Rockwell flaw being exploited, making isolation the only defense.
Actively exploiting CVE-2026-60004 against internet-exposed Gitea servers with open registration, deploying cryptocurrency mining payloads. CISA confirmed exploitation via KEV listing on August 25. No named threat actor attributed yet. Nearly 5,000 Gitea instances are exposed online according to Shadowserver.
Continuing to deploy the upgraded CoolClient backdoor with a signed Windows kernel-mode rootkit for stealth. The China-linked espionage group remains focused on long-term access and evasion against government and enterprise targets.
Remained the most active tracked threat actor in the most recent reporting period with 207 recorded incidents, primarily DDoS attacks aligned with pro-Russian hacktivist objectives against Western targets.
Among the top ransomware operations by victim count, continuing to drive elevated industrial ransomware volume through its ransomware-as-a-service model across manufacturing, healthcare, and professional services.
CVE-2026-65400 exploitation from Issue 016 continues against unpatched internet-exposed Macs. Organizations that applied the August 6 macOS update are protected. Any Mac exposed before patching should still be treated as compromised.
| Actor | Status | Activity |
|---|---|---|
| CyberAv3ngers (IRGC Cyber-Electronic Command) | [ ESCALATING ] | Operational pattern consistent with the group behind disruptions at water utilities across at least 12 US states since late July, including more than 30 Minnesota communities, with some utilities reverting to manual control. Targets internet-exposed PLCs and HMIs at small water systems. Active since 2020, US-sanctioned, formally tied to Iran's IRGC. No patch exists for the primary Rockwell flaw being exploited, making isolation the only defense. |
| Gitea exploitation operators (unattributed) | [ ESCALATING ] | Actively exploiting CVE-2026-60004 against internet-exposed Gitea servers with open registration, deploying cryptocurrency mining payloads. CISA confirmed exploitation via KEV listing on August 25. No named threat actor attributed yet. Nearly 5,000 Gitea instances are exposed online according to Shadowserver. |
| Mustang Panda (HoneyMyte) | [ ACTIVE ] | Continuing to deploy the upgraded CoolClient backdoor with a signed Windows kernel-mode rootkit for stealth. The China-linked espionage group remains focused on long-term access and evasion against government and enterprise targets. |
| NoName057(16) | [ ACTIVE ] | Remained the most active tracked threat actor in the most recent reporting period with 207 recorded incidents, primarily DDoS attacks aligned with pro-Russian hacktivist objectives against Western targets. |
| Qilin (Agenda) | [ ACTIVE ] | Among the top ransomware operations by victim count, continuing to drive elevated industrial ransomware volume through its ransomware-as-a-service model across manufacturing, healthcare, and professional services. |
| Cryptomining operators (macOS Screen Sharing) | [ MONITORING ] | CVE-2026-65400 exploitation from Issue 016 continues against unpatched internet-exposed Macs. Organizations that applied the August 6 macOS update are protected. Any Mac exposed before patching should still be treated as compromised. |
Key Takeaway
The lead story this week is a departure from the software vulnerabilities that usually dominate this brief, and that is precisely why it matters. Iranian-linked actors have spent late July and August disrupting the water utilities that more than a dozen US states depend on for safe drinking water. This is not data theft or ransomware. It is the manipulation of the physical systems that treat and deliver water, and in several cases it forced utility operators to abandon their automated controls and run treatment by hand. Two facts make this campaign especially difficult. The targets are small and rural utilities that rarely have dedicated security staff, and the control equipment being exploited often has no available patch, which means the only defense is to remove these systems from the internet entirely and lock down who can reach them. The through-line connecting this to the rest of the brief is exposure. The water utilities were reachable from the internet. The Gitea servers now being exploited to plant cryptominers were reachable from the internet with open registration left on. The MLflow and Screen Sharing flaws of recent weeks were exploited on internet-exposed systems within hours. Rapid7's warning this week, that patch cycles can no longer keep pace and defenders must prioritize by exposure rather than severity score, is the correct frame for all of it. The single most valuable question a security team can ask right now is not which vulnerability is most severe. It is which of our systems can be reached from the internet, and which of those do we not actually need to expose at all. For water utilities that question is a matter of public safety. For everyone else it is the difference between a vulnerability that gets exploited within hours and one an attacker never reaches.
Sources
- CISA Known Exploited Vulnerabilities Catalog
- Tenable Research Special Operations
- The Hacker News
- SecurityWeek
- Help Net Security
- BleepingComputer
- The Register
- StateScoop
- Security Affairs
- Shadowserver
- Rapid7