Daily Drop (1346)
08-15-26
Saturday, Aug 15, 2026 // Buy Bob a Coffee // Ghostwire
Iran Elevates Water and Desalination Infrastructure to a Primary Coercion Target in the Gulf
Bottom Line Up Front (BLUF): A War on the Rocks analysis argues that Iran has made Gulf water and energy infrastructure—particularly desalination plants—a central instrument of deterrence against the United States and its regional partners, backed by six months of demonstrated strikes during Operation Epic Fury. Cheap long-range drones (roughly $50,000–$75,000 each, per BBC figures cited) and widely proliferated ballistic and cruise missiles now let a small force disable water systems serving hundreds of thousands to millions of people from hundreds of kilometers away. The operational significance for infrastructure defenders: water is uniquely time-sensitive as a coercion lever—unlike oil or food, disruption can produce a crisis within days, especially when kinetic strikes are combined with cyber operations that Iran credibly possesses.
Analyst Comments: This is strategic infrastructure-risk analysis rather than incident reporting, and the authors are explicit that their storage/endurance figures are order-of-magnitude assessments constrained by limited public disclosure—that hedging should be preserved rather than treated as hard intelligence. For OT/ICS and infrastructure-security readers, the most relevant thread is the explicit pairing of physical strikes with cyber-attacks against mapped water systems; a thoroughly reconnoitered SCADA environment amplifies the impact of a kinetic campaign and compresses response time. The interceptor-inventory argument is the sharpest operational point: with U.S. forces globally estimated at fewer than 1,000 Patriot and roughly 250 THAAD rounds, a sustained Iranian campaign (the authors’ illustrative figure is ~50 drones plus missiles daily against specific plant complexes) could exhaust allied air defenses—the “going Winchester” scenario—leaving hardening, dispersion, and storage as the fallback rather than interception. The power-water interdependence is the underappreciated systemic risk: because large reverse-osmosis and legacy thermal desalination plants are tightly coupled to power generation (100 MW+, comparable to a hyperscale datacenter), a strike on electrical infrastructure disables water production as a second-order effect, and restoration depends on globally scarce turbines, transformers, and switchgear already strained by datacenter demand. Treat specific incident claims as reported-not-confirmed; several rest on Iranian or single-source claims.
READ THE STORY: War on the Rocks
Suspected Iranian Cyber Campaign Hits U.S. Water Sector Across 12 States
Bottom Line Up Front (BLUF): A coordinated wave of cyberattacks has reportedly affected water utilities across at least 12 U.S. states and 100 municipalities, with indicators pointing toward Iranian-linked actors, including CyberAv3ngers, a group associated with the Islamic Revolutionary Guard Corps. The incidents targeted internet-exposed operational technology, including programmable logic controllers, and appear to rely on weak security controls such as default credentials, poor authentication, and direct internet exposure. CSIS assesses the activity as opportunistic disruption rather than a major escalation, with psychological impact and public fear serving as key objectives.
Analyst Comments: The scale of the campaign is notable, but the technical sophistication appears limited. The attackers are not demonstrating novel ICS tradecraft so much as exploiting predictable weaknesses in under-secured water systems. That matters because it shifts the core lesson away from “Iran has a new capability” and toward “U.S. critical infrastructure remains too easy to touch.” The campaign also fits a long-running Iranian pattern. Tehran-linked actors have repeatedly targeted water, energy, transportation, and local government infrastructure using accessible OT systems and basic intrusion paths, then amplified the incidents publicly to maximize psychological and political impact. In that sense, the disruption itself may be secondary to the messaging value: proving that actors aligned with Iran can reach systems inside the U.S. homeland.
READ THE STORY: CSIS
Puerto Rico Water Rationing Exposes Infrastructure Gaps as Rainwater Harvesting Goes Underused
Bottom Line Up Front (BLUF): Puerto Rico is rationing water to roughly 180,000 households in the northeast after the driest July on record compounded longstanding failures in the island’s water infrastructure. Despite receiving between 30 and 169 inches of rain annually, Puerto Rico has made limited use of household rainwater-harvesting systems. Experts estimate that equipping 1 million homes with collection systems could capture roughly 30 billion gallons annually, providing a significant decentralized reserve during droughts and infrastructure failures.
Analyst Comments: Puerto Rico’s Aqueduct and Sewer Authority reportedly loses around 60 percent of treated drinking water before it reaches customers, meaning scarcity is being amplified by distribution failures rather than rainfall alone. Recent ruptures in the 72-inch Super aqueduct underscore how dependent the island remains on centralized infrastructure with limited redundancy. Rainwater harvesting would not replace the public water system, but it could reduce pressure during outages and drought conditions by supplying water for sanitation, cleaning, and other non-potable uses. The model is already common elsewhere in the Caribbean: roughly 90 percent of homes in the U.S. Virgin Islands reportedly use cisterns, while jurisdictions including Barbados have incorporated collection requirements into building codes. Puerto Rico has legislation requiring rainwater systems on government buildings, but implementation and enforcement have lagged.
READ THE STORY: Wired
Chinese Open-Weight AI Models Near U.S. Frontier Cyber Capabilities as Washington Weighs Restrictions
Bottom Line Up Front (BLUF): Chinese AI lab Z.ai says its new GLM-5.3 model is approaching the cyber capabilities of leading U.S. frontier models, scoring 84.5% on CyberGym and ranking just behind top U.S. systems on exploit-development benchmarks. Z.ai delayed release of the model weights for two weeks and introduced controlled access for security partners, citing concerns about misuse. The development is intensifying a parallel U.S. policy debate over whether Chinese open-weight models should face procurement restrictions, Entity List controls, or other measures that would reduce their use inside American companies.
Analyst Comments: The issue is no longer whether Chinese open models can compete on general reasoning or coding; the question is whether freely downloadable models can also perform high-end vulnerability research and exploit development at a level close to closed U.S. systems. That distinction matters because open-weight releases are fundamentally harder to govern after publication. Once weights are public, vendors cannot meaningfully revoke access, enforce moderation, or prevent users from fine-tuning the model for offensive tasks. Z.ai acknowledged that problem directly by delaying GLM-5.3’s public release while it tests additional safeguards.
READ THE STORY: Axios
DPRK Expands Military Role in Russia as Missile Units Move Toward Direct Combat Support
Bottom Line Up Front (BLUF): North Korea’s military role in Russia is moving beyond ammunition shipments and conventional troop deployments toward direct operational support. Ukrainian intelligence says roughly 90 North Korean missile personnel are deploying to Russia’s Voronezh region alongside a new batch of KN-23/KN-24 ballistic missiles, with the force potentially operating up to 120 missiles and six launchers. Ukrainian President Volodymyr Zelenskyy separately claims Moscow could receive another 30,000–50,000 North Korean troops. The deployments would deepen Pyongyang’s exposure to modern combat while giving Russia additional manpower and ballistic-strike capacity against an already strained Ukrainian air-defense network.
Analyst Comments: The missile deployment matters more than the raw personnel count. Embedding North Korean specialists inside Russia’s 112th Missile Brigade would give Pyongyang direct experience with targeting cycles, launcher operations, maintenance, battle-damage assessment, and Ukrainian interception tactics. That is a significant step beyond simply supplying weapons. A broader DPRK deployment could eventually free Russian personnel for combat by assigning North Korean forces to security, logistics, infrastructure restoration, or other rear-area functions. Expansion into sophisticated air-defense or electronic-warfare roles is plausible but remains less firmly established by the reporting provided. Operating systems such as the S-350 or S-400 would require extensive training and integration into Russian radar, identification, and command-and-control networks. Likewise, any employment of North Korea’s Il-76-based airborne early-warning capability alongside Russian forces would represent a much deeper level of interoperability. Those possibilities should therefore be treated as indicators to watch rather than confirmed elements of the current deployment.
READ THE STORY: Telegram // Defense Matters
Pyongyang Uses AI to Scale Cybercrime and Remote IT Worker Operations Against Canada
Bottom Line Up Front (BLUF): North Korea is increasingly integrating artificial intelligence into cyber operations to automate analysis of stolen data, improve phishing, accelerate malware development, and make fraudulent remote-worker identities more convincing. The Asia Pacific Foundation of Canada warns that this evolution raises the risk to Canadian financial, technology, research, and critical-infrastructure sectors, particularly as DPRK-linked actors continue targeting cryptocurrency and using fake employment schemes to generate revenue and gain insider access.
Analyst Comments: The important shift is from using AI as a content-generation tool to embedding it directly into cyber operations. If groups such as Kimsuky are running local AI systems to process stolen information and tailor follow-on phishing, that reduces analyst workload and lets operators move faster from collection to exploitation. For Canada, the remote IT worker problem may be the more immediate threat. These schemes bypass traditional perimeter security because the attacker is hired, issued credentials, and granted legitimate access. AI-generated résumés, face-swapping, voice alteration, and synthetic interview assistance make identity fraud more scalable and harder for recruiters to catch.
READ THE STORY: Asia Pacific
Crytica Introduces RDAi for In-Device Instruction-Set Integrity Monitoring on OT Endpoints
Bottom Line Up Front (BLUF): Crytica Security has announced RDAi (Rapid Detection, Alert, and isolation), a patented approach that places a sub-100 KB agent—called a “Probe”—inside OT and embedded devices to detect unauthorized changes to their instruction sets and static data such as configuration files. The pitch is a shift from external, inference-based OT/IoT monitoring to deterministic, device-level detection that reports whether a device itself remains in a trusted operating state. For defenders, the intended value is a high-confidence tampering signal that feeds existing SOC, SIEM, and XDR workflows rather than replacing them.
Analyst Comments: This is a vendor product announcement with no independent validation, so the “deterministic,” “high-fidelity,” and “non-disruptive” claims are marketing positioning that buyers should test against their own hardware before accepting. The underlying concept—host-based integrity monitoring of firmware and instruction sets—is sound and addresses a real OT detection gap: legacy controllers can’t run EDR, and passive network monitoring cannot see firmware or configuration tampering that leaves no network signature. The unanswered questions that determine real value: which processor architectures, RTOSes, and legacy PLCs the Probe supports; how it’s provisioned and updated at scale; performance and safety-certification impact on real-time control loops; and how the agent itself is protected from tampering. The IBM statistics cited (56% YoY rise in AI-driven attacks; 50% of SOCs running AI agents) are framing, not product-specific.
READ THE STORY: HNS
Dragos Launches EmberAI, an OT-Native Analyst Assistant Built on Its Intelligence Fabric
Bottom Line Up Front (BLUF): Dragos has released EmberAI, an OT-native AI assistant built on the Dragos Intelligence Fabric and embedded in the existing Dragos Platform deployment. It is pitched as helping analysts of varying experience prioritize threats by operational impact—querying assets, vulnerabilities, and network activity in plain language and mapping detections to known OT threat groups—while keeping customer telemetry inside the customer’s own environment rather than feeding it to a cloud-based general-purpose model. For defenders staffing under-resourced OT security programs, the significance is a purpose-built triage aid that aims to compress alert-to-action time in environments where a wrong or delayed decision carries direct safety and control consequences.
Analyst Comments: This is a vendor product announcement, so the operational claims should be read as marketing rather than independently validated capability—no benchmarks, false-positive rates, or third-party evaluations are provided, and terms like “OT-native” and the “xOT” framing are Dragos positioning. That said, the design choices are the substantive part worth defenders’ attention: keeping data in-environment, retaining a human-in-the-loop with auditable recommendations, and using a domain-specific intelligence engine rather than piping operational telemetry into an opaque external model directly address the data-sovereignty and hallucination concerns that make general LLMs risky in ICS contexts. The realistic value proposition is workflow acceleration—triage, correlation, and reporting—for teams that lack deep OT expertise, not autonomous decision-making. The “expert-built OT skills” workflow library is described as forthcoming (”available soon”), so a meaningful piece of the pitch is not yet shippable. Buyers should treat the petabyte-scale telemetry and 600+ protocol figures as vendor-supplied and evaluate against their own environment before assuming coverage.
READ THE STORY: HNS
OpenAI Cyber Model Reportedly Finds Hundreds of Kernel Flaws as AI Exploit Capability Accelerates
Bottom Line Up Front (BLUF): OpenAI has reportedly created GPT-5.6-Cyber, a restricted-access model designed for vulnerability research and exploit validation with fewer cybersecurity safeguards than its general-purpose systems. According to WION, the model completed 95% of advanced cyber tasks in testing and identified two previously unknown vulnerabilities in Chrome’s V8 engine, three critical database flaws, at least five mobile operating-system vulnerabilities, and more than 400 privilege-escalation flaws in a single operating-system kernel. Access is reportedly limited through OpenAI’s new Daybreak Red program, reflecting growing concern that frontier AI systems capable of finding vulnerabilities can also generate working exploits.
Analyst Comments: Automated vulnerability discovery has been improving for years. What changes the risk calculation is the reported ability to move from discovery into exploit validation and working exploit development at scale. If the reported results are accurate, hundreds of privilege-escalation findings in one kernel would suggest AI-assisted vulnerability research is moving from isolated discoveries toward systematic codebase interrogation. That could compress weeks or months of manual auditing into substantially shorter cycles and materially increase the volume of vulnerabilities defenders must triage. The access model also signals where frontier labs appear to be drawing the line on dual-use cyber capability. A model that can discover vulnerabilities and reliably validate exploitation cannot be cleanly categorized as defensive or offensive; the distinction depends on who controls it and what targets it is pointed at. Restricting access may reduce immediate abuse, but it does not remove the longer-term proliferation problem as comparable capabilities emerge across multiple laboratories and open-weight ecosystems.
READ THE STORY: Wion
Anthropic Watermarks Claude Output as Researchers Test How Easily AI Provenance Can Be Removed
Bottom Line Up Front (BLUF): Anthropic has reportedly begun embedding invisible provenance markers into text generated by newer Claude models, alongside C2PA metadata for supported image and file outputs, as part of its transparency commitments under the EU AI Act. The text watermark is statistical rather than a visible tag: the model subtly biases token selection so sufficiently long outputs carry a detectable pattern. Within days of the rollout, open-source projects claimed they could remove the watermark, but independent analysis cited by Habr found that most currently strip only Unicode artifacts or file metadata—not Anthropic’s underlying statistical signal.
Analyst Comments: A statistical watermark depends on preserving enough of the model’s original token choices. Heavy paraphrasing, translation, or regeneration through another model can disrupt that pattern without requiring an attacker to understand the secret key or detector. That does not make watermarking useless. It can still provide a strong provenance signal for long, substantially unedited outputs, particularly when the detector is controlled by the model provider. But it should not be treated as proof of authorship. A watermark can indicate that text passed through a particular model, not that the model originated the underlying ideas or that a human did not substantially contribute to the final product. The reverse is equally important: absence of a watermark does not prove human authorship. Older models may not support the mechanism, short outputs may not contain enough statistical signal, and extensive editing can naturally weaken or erase detection. Any organization using watermark detection for academic integrity, employment screening, journalism, or compliance should treat it as one evidentiary signal rather than a binary verdict.
READ THE STORY: Xa6p
Apple Sends Spyware Attack Warnings to Users Across More Than 110 Countries and Regions
Bottom Line Up Front (BLUF): Apple has reportedly issued a new round of mercenary spyware threat notifications to users in more than 110 countries and regions, warning selected individuals that they may be targeted by highly sophisticated surveillance operations. These campaigns typically focus on government officials, journalists, activists, human-rights workers, executives, and other high-value targets rather than ordinary consumers. Recipients should treat the alert as a high-priority security event, update affected devices immediately, enable Apple’s strongest available protections, and assume sensitive communications or account data could be at risk until the device is assessed.
Analyst Comments: Mercenary spyware campaigns are expensive, selective, and usually tied to intelligence collection or politically sensitive surveillance. If a user receives one, the correct response is not simply “change your password” and move on. The device, linked accounts, communications history, and potentially other systems used by the target should be treated as part of an incident. The source article overstates one point slightly by suggesting an Apple notification means compromise is already proven. A threat notification is better understood as a high-confidence warning of targeting activity, not definitive proof that malware successfully infected the device. That distinction matters operationally because defenders should investigate for compromise without assuming every alert confirms a completed intrusion.
READ THE STORY: T00ls
Apple macOS Screen Sharing Flaw Exploited in the Wild to Deploy Monero Miner
Bottom Line Up Front (BLUF): A critical macOS Screen Sharing vulnerability, CVE-2026-65400 (CVSS 9.8), is being actively exploited against internet-exposed Macs to gain unauthorized access and install Monero cryptocurrency miners. The flaw affects Apple’s built-in Screen Sharing service and was patched in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Organizations should immediately patch affected systems and restrict or disable Screen Sharing, particularly where TCP/5900 is exposed to the internet.
Analyst Comments: Systems advertising VNC/Screen Sharing directly to the internet are giving attackers a clean path to test authentication flaws at scale, and the reported exploitation shows that threat actors are already doing exactly that. The larger concern is the cluster of vulnerabilities uncovered in Apple’s Screen Sharing implementation. Researchers have described multiple logic and state-management flaws capable of undermining authentication, including separate pre-authentication weaknesses that reportedly require little more than network access to an exposed host. These are not memory-corruption exploits requiring complicated chains or reliability work; several stem from basic authentication-state failures, making weaponization considerably easier.
READ THE STORY: THN
U.S. Courts to Begin Disclosing Government Spyware Use in Wiretap Reports
Bottom Line Up Front (BLUF): Beginning with the 2028 Wiretap Report, published in 2029, the U.S. judiciary will start publicly tracking how often judges authorize the use of spyware and hacking tools to intercept real-time communications. The new reporting category will cover network investigative techniques used for live interception of calls and messages, including communications on services such as Signal and WhatsApp, but it will not include separate search-authority operations where law enforcement remotely hacks a device to extract stored data.
Analyst Comments: The FBI has used network investigative techniques for decades, but the public has had no reliable count of how often those tools were used specifically for real-time surveillance. The scope is important. The new category will cover hacking used as a wiretap, not every instance where authorities remotely compromise a device. That means the resulting statistics will still understate total government use of spyware and exploitation tools, particularly where investigators use malware to retrieve stored files, location data, or other device contents under separate search authorities. From an oversight perspective, even a partial count changes the conversation. If usage is rare, agencies can support claims that spyware is reserved for exceptional cases. If deployment numbers are high, lawmakers and privacy advocates will have stronger grounds to challenge whether these tools are truly being used as narrowly as officials suggest.
READ THE STORY: TC
“Download More RAM” Attack Breaks Windows VBS and Disables EDR Protections
Bottom Line Up Front (BLUF): Researchers disclosed a Windows attack technique dubbed “Download More RAM” that abuses writable Serial Presence Detect (SPD) data on some DDR4 and DDR5 memory modules to undermine Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI). An attacker with local administrator privileges can falsify a DIMM’s reported memory geometry, creating memory aliasing that exposes normally isolated physical memory. Researchers used the technique to weaken Secure Kernel protections, load vulnerable signed drivers, disable Microsoft Defender, and affect third-party EDR and anti-cheat products. Microsoft tracks the issue as CVE-2026-23670 and shipped a mitigation in its April 2026 security update.
Analyst Comments: Windows assumes firmware and physical memory configuration data are trustworthy; writable SPD breaks that assumption. Once the system is convinced that nonexistent memory exists, overlapping physical addresses can expose regions VBS was specifically designed to isolate from even privileged administrators. The attack is not a remote compromise and already requires administrator-level access, so this is not an initial-access vulnerability. Its value comes after compromise. An attacker who already controls a system could use the technique to dismantle security boundaries that normally remain intact even with kernel-level privileges, potentially neutralizing EDR, Credential Guard, Secure Kernel protections, or other Hyper-V-backed isolation mechanisms.
READ THE STORY: Cyber Press
Actively Exploited XSS-to-RCE in Alinto SOGo Webmail via Malicious ICS Invitations (CVE-2026-8496)
Bottom Line Up Front (BLUF): CERT/CC has published VU#487613 for CVE-2026-8496, a cross-site scripting flaw in Alinto SOGo v5.12.7 that lets an attacker execute script in the SOGo webmail context by embedding a malicious SVG payload in the DESCRIPTION field of an ICS (iCalendar) invitation. The vulnerability is under active exploitation in the wild, confirmed via VirusTotal sightings. Critically, the payload fires during normal calendar rendering—when a user opens or previews the calendar tab—without any explicit click, making delivery-to-execution nearly automatic once a malicious invite lands in a victim’s mailbox. Organizations running self-hosted SOGo should upgrade to v5.12.8 immediately.
Analyst Comments: The dangerous property here is the zero-interaction trigger: because the SVG executes on calendar view rather than requiring a user to open an attachment or click a link, an attacker only needs to get an ICS invite delivered, and mail systems accept calendar invitations by design. The reporting frames the outcome as “remote code execution,” but the described impact is more precisely full compromise of the victim’s webmail session and mailbox in the browser context—mailbox exfiltration, contact and calendar theft, forced logout/login credential phishing, and password-manager autofill hijacking; whether this extends to code execution beyond the browser is not substantiated in the note, so treat the “RCE” label with some caution. The root cause is textbook—unsanitized rendering of attacker-controlled content combined with missing Content Security Policy—and the SVG-with-event-handler technique (<animate onrepeat='...'>) is a well-known CSP/sanitizer bypass that is seeing renewed use across webmail and browser-rendered contexts. Because exploitation is confirmed, this should be treated as patch-now for any internet-facing SOGo instance; where immediate patching isn’t possible, restricting or filtering inbound ICS content and hunting for anomalous calendar-render activity are reasonable interim measures. Note the advisory itself is flagged as AI-assisted, which is worth keeping in mind when weighing the precision of the impact language.
READ THE STORY: Carnegie Mellon University
PATCHCORD Espionage Campaign Targets Afghan Telecom and South Asian Critical Infrastructure
Bottom Line Up Front (BLUF): Acronis Threat Research Unit (TRU) has detailed an espionage operation against Afghan telecom providers and South Asian critical infrastructure built around a custom Windows backdoor tracked as PATCHCORD, delivered through spoofed portals and sector-specific lures such as a trojanized Afghan Telecom management installer. TRU assesses with moderate confidence that the activity overlaps with the APT36 / Transparent Tribe cluster. The operation’s significance for defenders lies in its diversified C2 (custom HTTP, Google Sheets API, and GitHub Gists), fileless follow-on execution, and browser-shortcut hijacking for persistence—along with staging infrastructure holding regreSSHion (CVE-2024-6387) tooling that suggests internet-facing OpenSSH is a candidate initial-access path into high-value telecom and government targets.
Analyst Comments: The attribution is worth reading precisely: TRU’s link to Transparent Tribe is moderate-confidence, and the separately noted infrastructure overlap with a server Kaspersky previously tied to SilverFox/ValleyRAT is explicitly stated not to establish coordination between the groups—so treat both as investigative leads rather than settled attribution. Operationally, the most useful hunting signals are the least conventional ones: living-off-trusted-services C2 through Google Sheets and GitHub Gists is designed to blend into normal enterprise egress and will not be caught by domain/IP blocklists alone, so detection should lean on anomalous Sheets API and Gist activity from endpoints that have no business reason to use them. The browser-shortcut hijack (replacing the shortcut target while preserving the real browser path and icon, then launching the legitimate app to avoid suspicion) is a durable persistence technique that survives casual inspection and is worth adding to endpoint hunts. The regreSSHion tooling on the staging server is a plausibility indicator, not proof of use—there is no claim in the reporting that CVE-2024-6387 was actually exploited in this campaign—but unpatched internet-facing OpenSSH remains a realistic entry vector regardless. The fileless shellcode chain (decrypt → VirtualAlloc → CreateThread, no disk write) lowers artifacts and argues for memory and behavioral detection over file-based scanning.
READ THE STORY: GBhackers
CISA and Australia’s ACSC Publish “CI Fortify” Guidance on Isolating Vital OT Systems
Bottom Line Up Front (BLUF): CISA and the Australian Cyber Security Centre (ACSC) released joint guidance, CI Fortify – Advice for isolating vital systems, giving critical infrastructure operators a method to isolate essential OT and enabling systems from all other networks and to run them in isolation for extended periods during a disruption or crisis. The intent is resilience and containment: cutting network pathways can disrupt an active adversary’s ability to reach its objective, contain incidents in progress, and allow compromised systems to be rebuilt safely. For OT defenders, this is a planning framework aimed at making “islanding” a deliberate, pre-engineered capability rather than an improvised emergency reaction.
Analyst Comments: This is guidance rather than an incident or vulnerability, and its value is as a preparedness reference—defenders should treat it as a structured playbook for a capability many CI operators assume they have but have never engineered or tested. The most useful and honest part is that CISA and ACSC document the trade-offs isolation introduces: loss of patching, reduced external visibility, and elevated risk of infection via removable media once air-gapped—the same failure modes that historically undermine air-gapped environments. The insistence that physical separation must be built in ahead of time is the operationally hard requirement; retrofitting physical isolation points and manual fallback processes into a running plant is expensive and cannot be improvised mid-incident. The guidance’s emphasis on mapping upstream dependencies and peer connections (other utilities, dispatch/scheduler operators) reflects a realistic understanding that isolation is rarely clean—islanding one operator can cascade into partners. Realistic assessment: this reduces incident blast radius and improves recovery posture, but only for organizations that invest in the physical and procedural groundwork before a crisis.
READ THE STORY: Security Week
OT/ICS Attack Techniques in 2026: Adversaries Descend the Purdue Model to Reach Controllers
Bottom Line Up Front (BLUF): A red-team analysis published on the Codeby.net forum documents the protocol-level techniques used to compromise OT/ICS environments in 2026, drawing on the author’s OT audit engagements and several claimed—but independently unverified—incidents against Polish water and energy infrastructure and a Russian supply-chain compromise via ViPNet. The core argument for defenders: attackers no longer stop at the IT perimeter. They deliberately traverse the Purdue model from IT down to controllers and field devices, where the impact shifts from data loss to physical process manipulation, equipment damage, and service disruption. The immediate significance is that Levels 1–2 typically lack any endpoint detection, so compromise at the control layer is often visible only through network traffic analysis—if it is visible at all.
Analyst Comments: The technical substance here is credible and matches well-established OT threat modeling; the framing around dual-homed historian servers as the “attacker’s dream” pivot point (IT-DMZ → OT-DMZ) is the most operationally useful takeaway, because it identifies the single architectural weakness that most often bridges corporate email compromise to a Modbus write. The Modbus function-code breakdown is accurate and worth internalizing: FC 6/16 (register writes) and FC 5/15 (coil writes) are the direct paths to setpoint manipulation and discrete-output control, while the author correctly debunks the common myth that FC 8 sub-function 0x0001 “halts the PLC”—it resets the communication event log and is more useful for log-clearing (Indicator Removal, T1070) than for disruption. Treat the incident claims with caution: the Poland water/energy events and the ViPNet compromise are presented by the author himself as unverified or partially attributed, and the vendor statistics (IBM 70%, CrowdStrike +150% China-nexus, RED Security 77%) come from different populations and methodologies that should not be summed or read as a single OT trend. The realistic constraint on protocol attacks is also stated plainly: they require prior lateral movement or physical access to the OT segment, so perimeter and vendor-access controls remain the highest-leverage mitigations.
READ THE STORY: Codeby
Items of interest
DEFCON: Researchers Infiltrate Suspected North Korean IT Worker Scheme Through Fake Crypto Startup
Bottom Line Up Front (BLUF): Security researchers created a fake decentralized-finance startup and hired three individuals they assess were North Korean IT workers, giving the team a rare inside view of how DPRK-linked operatives pass remote hiring checks and establish legitimate access inside Western companies. The suspected workers used inconsistent identity documents, VPN infrastructure, AI-assisted job tools, and remote-access software while operating inside researcher-controlled virtual machines. The campaign highlights a persistent insider-access problem: these actors do not need to exploit a vulnerability if an organization hires them and grants them credentials, source-code access, and trusted employee status.
Analyst Comments: The most important point is that the suspected operatives entered through normal recruiting workflows, passed interviews, signed contracts, and received authorized access. Once inside, their activity could resemble that of any legitimate remote developer unless defenders are specifically looking for identity inconsistencies, unusual access patterns, or infrastructure associated with DPRK IT-worker operations. The onboarding indicators are especially useful for defenders. Researchers observed mismatched states across claimed residences, driver’s licenses, and banking information; one submitted identity image reportedly contained signs of Google Gemini processing and a SynthID watermark. Another used a legitimate Social Security number with unrelated banking details. These are not definitive attribution signals individually, but taken together they reinforce the value of repeated identity verification rather than treating pre-employment checks as a one-time control.
READ THE STORY: THN
How North Korea Hid an IT Workforce Inside US Companies (Video)
FROM THE MEDIA: This is the story of Christina Chapman, a suburban TikTok creator who ran a covert “laptop farm” from her Arizona home. The scheme became a gateway for North Korean IT operatives who infiltrated US companies and, according to the Justice Department, funneled millions of dollars to the North Korean government.
The North Korean Operatives Hiding Inside U.S. Companies (Video)
FROM THE MEDIA: North Korea has built a secret workforce inside American companies. Using stolen identities, AI tools and U.S. accomplices, its operatives have cheated their way into remote jobs in an effort to earn money for Kim Jong Un’s regime. The FBI says there are likely thousands of them applying for jobs across America and hundreds of millions of dollars have been funneled back to the regime.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don’t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


