JUSTTHENEWS (Kevin Killough) - Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate, others, DOJ says
The group offered tools that allowed malicious actors to engage in computer intrusion activities while concealing the hackers' country of origin, the DOJ said.
CISA (CISA) - A Tale of Two SOCs: Insights From Two Red Team Assessments
Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering…
CISA (CISA) - Defending Against an Active Threat to Siemens S7 Series PLCs
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations - Inventory all Siemens S7 Series programmable logic controllers (PLCs) - Apply critical security patches - Ensure PLCs are not accessible from the Internet - Strengthen access controls - Monitor for unauthorized activity - Harden PLC services, protocols, and ladder logic…
YOUTUBE (Facts Matter with Roman Balmakov) - Apps For US Troops Are Coming Equipped with Chinese and Russian Code
Watch 'Final Hours': https://ept.ms/FinalHoursWatchFullFilm Summary: Are your apps leaking data? A recent study shows military app security risks with foreign code tracking U.S. service members. This breakdown examines the concerning findings regarding mobile applications specifically marketed to U.S. military personnel. A first-of-its-kind report indicates that one out of every eight apps targeting this demographic contains foreign code. Some of these software components originate from China and Russia, raising serious questions about the safety of personal information held by those serving in the armed forces. We review the implications of this foreign code and how it relates to recent reports of U.S. service members being targeted in…
CISA (CISA) - #StopRansomware: Gunra Ransomware
Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra. Key Actions - Prioritize patching known exploited vulnerabilities in…
JUSTTHENEWS (Kevin Killough) - At least 7 states report cyberattacks on water systems, with some having to be shut down
Last month, 30 Minnesota towns and cities were hit by a "coordinated cyberattack." Michigan is now reporting cyberattacks on nine of its water systems.
NEWSNATIONNOW (Josie Fischels) - Water supply cyberattacks: What we know
Michigan says nine of its water systems were hit by cyberattacks, joining Minnesota.
JUSTTHENEWS (Kevin Killough) - Not just Minnesota: Hackers targeted municipal water systems in 7 states, FBI says
The agencies, which didn't say in which states the municipalities are located, said that some of the malicious activity has impacted water operations in those municipalities that were struck.
CISA (CISA) - Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [1 ]. LAUNDRY BEAR’s targeting is…