BREACHES & INCIDENTS
π¨ 7 | Cyberattack disrupts operations at all three North Carolina ports
A cyberattack disrupted operations across North Carolina Portsβ three facilities.
- North Carolina Portsβ Wilmington, Morehead City and Charlotte Inland Port facilities were affected.
- The Aug. 4 attack struck the North Carolina Ports IT system and caused operational delays.
- Wilmington delayed opening and switched to manual gate processing.
- The breach was contained, but recovery and full system restoration remain ongoing.
- The attacker and access method are unknown; officials reported no indication that sensitive data was compromised.
:paperclip: Coverage: wect.com Β· :eye: via @campuscodi@mastodon.social, @metacurity@infosec.exchange
π΅οΈ RESEARCH & DEEP DIVES
β UPDATE | π¨ 8 | 4,407 Rockwell PLCs Exposed Online, Including 22 in Water-Attack Cities
Forescout found 22 exposed Rockwell PLCs in cities hit by U.S. water-utility attacks.
- Water and wastewater utilities in at least seven U.S. states were affected, including more than 30 Minnesota communities.
- Rockwell/Allen-Bradley MicroLogix 1100 and 1400 PLCs were targeted; 4,407 were internet-exposed worldwide and 2,844 were in the United States.
- Attackers remotely changed PLC IP addresses and passwords, disrupting monitoring and control of connected equipment.
- Exposed EtherNet/IP services on TCP port 44818 provided unauthenticated access paths; 19 of 22 PLCs in affected cities used the same mobile carrier network.
- Nineteen of the 22 PLCs ran firmware susceptible to CVE-2017-16740, affecting MicroLogix 1400 Series B and C firmware 21.002 and earlier.
:page_facing_up: Source: forescout.com Β· :paperclip: Coverage: thehackernews.com Β· :eye: via The Hacker News
π¨ 7 | Zenity finds zero-click hijacking flaws in Claude and ChatGPT Atlas
Zenity found zero-click hijacking flaws in major AI browsers.
- Users of Claude in Chrome, ChatGPT Atlas, Gemini in Chrome, Perplexity Comet and Copilot Edge are affected.
- Hijacked agents can steal Gmail, Google Drive and local data, take over accounts, send phishing messages and make fraudulent purchases.
- Attackers hide indirect prompt injections in emails, X posts, webpages, calendar invitations and other content read by the agent.
- Zenity used invisible email prompts and rogue NPM packages against Claude, and a malicious X comment against ChatGPT Atlas.
- Zenity reported the findings to Anthropic in December 2025 and January 2026 and to OpenAI in January 2026; the reported paths remained unpatched.
:page_facing_up: Source: daily-tribune.com Β· :paperclip: Coverage: securityweek.com Β· :eye: via SecurityWeek
β οΈ 6 | Fake The Odyssey Downloads Deliver Lumma Stealer and Steal Sensitive Data
Fake The Odyssey downloads are delivering Lumma Stealer.
- People downloading pirated copies of The Odyssey (2026) are targeted.
- Lumma Stealer steals browser passwords, payment-card data, and cryptocurrency wallets.
- A single execution of the fake movie download compromises the system.
:paperclip: Coverage: cybersecuritynews.com Β· :eye: via Cyber Security News
π CVEs & KEV
CVE-2026-12605 β CVSS 9.6 β In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServ...
CVE-2026-16731 β CVSS 8.3 β Authentication and authorization bypass via cryptographic timing side-channel...
CVE-2026-16315 β CVSS 8.1 β Authentication and authorization bypass via cryptographic timing side-channel...
CVE-2026-65551 β CVSS 7.5 β WordPress Breakdance plugin before 2.7 - Broken Access Control vulnerabilityMissin...
CVE-2026-64993 β CVSS 6.8 β Dell RVTools versions prior to 4.8.1, contains an improper certificate valida...