Author: Osiris

  • CISA Flags New Industrial Control System Vulnerabilities Across Energy and Water Sector Vendors

    CISA Flags New Industrial Control System Vulnerabilities Across Energy and Water Sector Vendors

    The US Cybersecurity and Infrastructure Security Agency’s industrial-control-systems division published five new security advisories and updated two existing ones on August 27, 2026, covering vulnerabilities in equipment from Ebyte, Applied Systems Engineering, Rockwell Automation, All-Line Equipment, and Xiiaozet, alongside updates to prior Mitsubishi Electric advisories, according to CISA’s own advisory feed and tracking by WaterISAC and independent ICS-security researcher Patrick Coyle.

    The affected products span control and monitoring equipment used across multiple critical-infrastructure sectors, including energy and water utilities. CISA advisories of this kind typically detail vulnerability type, affected product versions, and vendor-issued mitigations, and are used by asset owners to prioritize patching across operational-technology environments that are often harder to update than conventional IT systems.

    Part of a Steady Weekly Cadence of ICS Disclosures

    CISA has issued ICS advisories at a near-weekly pace throughout August, including a batch of 15 advisories on August 13 and a separate advisory for a Johnson Controls product on August 20, reflecting both increased vendor disclosure activity and continued research attention on operational-technology security. The agency encourages asset owners and operators to review each advisory for applicability and apply recommended mitigations, particularly where affected systems are internet-accessible.

    No advisory in this batch indicates active exploitation, distinguishing it from the actively exploited flaws disclosed elsewhere this week, including the Gitea remote-code-execution vulnerability already being used to deploy cryptomining malware.

  • Meta to Pay Up to $18 Billion in Multistate Settlement Over Child Safety and Data Collection Claims

    Meta to Pay Up to $18 Billion in Multistate Settlement Over Child Safety and Data Collection Claims

    Meta agreed to pay up to $18 billion and implement a series of platform changes to settle a multistate lawsuit alleging the company knowingly designed Instagram and Facebook to be addictive to children and collected data from young users without parental consent, according to court filings and reporting from TechCrunch, The Washington Post, and Bloomberg published August 26, 2026.

    US District Judge Yvonne Gonzalez Rogers approved the settlement, which resolves claims brought by attorneys general representing 47 states, the District of Columbia, and three US territories, plus a separate $1 billion agreement with Texas. Meta will pay roughly $11.7 billion to the broader state coalition in ten annual installments; a further $5.3 billion becomes payable only if TikTok, YouTube, and Snap agree to comparable settlement terms of their own.

    Age-Verification and Nighttime-Use Limits Among Required Changes

    The states alleged Meta’s platforms were engineered to maximize engagement among minors despite internal awareness of resulting harms, and that the company collected children’s data in violation of the Children’s Online Privacy Protection Act. As part of the settlement, Meta has committed to daily time limits and nighttime-use blocks for teenage accounts, along with enhanced age-assurance measures intended to keep underage users off the platforms in the first place. Meta did not admit wrongdoing as part of the agreement.

    The settlement is among the largest ever reached over child-safety allegations against a technology company and is expected to intensify pressure on rival platforms facing similar litigation.

  • FBI Investigates Ransomware Breach at Water-Sector Control-System Maker Micro-Comm

    FBI Investigates Ransomware Breach at Water-Sector Control-System Maker Micro-Comm

    The FBI is investigating a ransomware attack and data theft at Micro-Comm, a Kansas-based manufacturer of programmable logic controllers used across US water and wastewater utilities, according to an exclusive Reuters report published August 26, 2026, and corroborated by BrinzTech and IBTimes.

    Micro-Comm, based in Olathe, discovered the breach on July 31, 2026. A relatively new ransomware group calling itself Barracuda claimed responsibility on August 6, posting what it said was roughly 850,000 company files totaling about 644 gigabytes of data. Dixon Land, a spokesperson for the FBI’s Kansas City field office, confirmed the bureau is in contact with Micro-Comm and coordinating with other law enforcement agencies.

    Attack Described as Opportunistic, Not Targeted

    Micro-Comm told Reuters the FBI characterized the intrusion as an opportunistic attack rather than one specifically aimed at the company, and that the leaked files did not include customer credentials or data related to the company’s ability to remotely access its devices. Roughly 200 of Micro-Comm’s SCADAview CSX systems — used to monitor and control equipment at customer sites — are reachable from the public internet, a configuration security researchers have flagged as a broader risk across the water sector.

    The disclosure comes amid heightened federal scrutiny of Iran-linked cyber activity against water infrastructure, following a wave of intrusions this summer affecting wastewater treatment plants across a dozen US states, though officials say the Micro-Comm incident and the earlier nation-state activity are being tracked as separate matters.

  • Army Laser Weapon Downs Cartel-Linked Drones on Texas Border in System’s First Confirmed Use

    Army Laser Weapon Downs Cartel-Linked Drones on Texas Border in System’s First Confirmed Use

    The US Army’s Multipurpose High Energy Laser destroyed three cartel-linked drones along the Texas border over two nights, August 25 and 26, 2026, in what officials describe as the system’s first confirmed operational engagement, according to reporting from DroneXL, Unmanned Airspace, and NORTHCOM’s own statement, corroborated by AeroVironment, which confirmed one of its AMP-HEL units was involved.

    The engagements took place in airspace over or near the Rio Grande Valley in southern Texas and were carried out by Joint Task Force-Southern Border, a roughly 8,000-strong US Northern Command unit. The drones were assessed as hostile because they were operating in direct support of activity posing a physical threat to US military personnel and Customs and Border Protection partners working the area.

    Vehicle-Mounted System Produces 20 Kilowatts of Laser Power

    AMP-HEL is a vehicle-mounted directed-energy weapon capable of producing 20 kilowatts of laser power, designed for precision engagement of small unmanned aerial threats at a fraction of the cost of a traditional interceptor missile. The military did not specify the exact model variant used in the border engagements.

    The successful engagement marks a turnaround for the program, which drew criticism in February after an AMP-HEL unit mistakenly targeted the wrong drone and briefly froze operations at a commercial airport. Border-area counter-drone activity has intensified this year as cartel organizations increasingly use small unmanned aircraft for smuggling and surveillance, prompting expanded federal investment in counter-UAS testing and detection infrastructure.

  • Asheville City Council Votes to End Flock Safety Camera Contract, Remove All 11 License-Plate Readers

    Asheville City Council Votes to End Flock Safety Camera Contract, Remove All 11 License-Plate Readers

    The Asheville, North Carolina City Council voted on Tuesday, August 25, 2026, to terminate the city’s contract with license-plate reader vendor Flock Safety and remove all 11 of its cameras from city streets, according to local reporting from WLOS.

    Mayor Esther Manheimer said the decision reflected growing concerns about how Flock manages the data its cameras collect and who can access it, framing the vote as an attempt to balance public-safety utility against privacy risk. Rondell Lance, president of the local Fraternal Order of Police chapter, opposed the removal, arguing the system had given investigators an efficient way to narrow suspect vehicles by characteristics rather than manually checking every potential match.

    Part of a Wider Pattern of Contract Reviews

    Asheville’s vote follows a period of intensifying scrutiny of automated license-plate reader networks nationally, after Flock Safety itself cut its default data-retention window to seven days earlier this month in response to similar pressure. Other jurisdictions, including communities in the Chicago suburbs, have faced comparable public fights over whether to keep, expand, or cancel Flock deployments amid concerns that plate-reader data could be accessed for purposes such as immigration enforcement or unauthorized personal tracking by officers.

    Asheville’s existing contract with rival vendor Axon includes provisions for stationary license-plate readers, though none are currently installed; city officials said any future deployment would require new privacy policies to be established first.

  • TSA Unveils Horizon 25 Strategy to Modernize Checkpoints and Expand Counter-Drone Capabilities

    TSA Unveils Horizon 25 Strategy to Modernize Checkpoints and Expand Counter-Drone Capabilities

    The Transportation Security Administration launched a new strategic plan called Horizon 25 on August 24, 2026, timed to the agency’s 25th anniversary, outlining three priorities: modernizing checkpoint technology, improving the traveler experience, and hardening security across multiple transportation modes, according to TSA’s own press release and reporting from International Airport Review and Federal News Network.

    TSA Administrator David P. Cummins said the plan is intended to streamline how the agency acquires new screening technology, including next-generation scanners and biometric identity-verification systems, as well as expand TSA’s capability to detect and respond to unmanned aircraft near airports and other transportation facilities. The agency has been steadily rolling out Credential Authentication Technology 2 units, which pair document scanning with live facial comparison, as part of a broader $781 million technology-modernization program already underway.

    Gold+ Program to Be Replaced

    As part of Horizon 25, TSA said it will retire its existing Gold+ program and replace it with an evolved Screening Partnership Program, expanding the role private security contractors play in airport checkpoint operations under federal oversight. The agency framed the changes as part of a longer-term effort to reduce checkpoint friction for low-risk travelers while concentrating resources on higher-risk threats, including the small-drone threat vector that has drawn increasing federal attention this year.

    TSA said further implementation details will be worked out with field and headquarters staff in September, with the counter-UAS and technology-acquisition components expected to roll out in phases rather than all at once.

  • IBM Completes Acquisition of HRL Laboratories to Bolster Quantum Hardware Roadmap

    IBM Completes Acquisition of HRL Laboratories to Bolster Quantum Hardware Roadmap

    IBM announced on August 26, 2026, that it has completed its acquisition of HRL Laboratories, a research institution previously jointly owned by Boeing and General Motors, adding capabilities in silicon-spin qubits, quantum sensing, cryogenics, and advanced packaging to IBM’s quantum computing program, according to IBM’s own newsroom announcement and corroborating coverage from The Quantum Insider and Quantum Computing Report.

    HRL’s expertise in silicon-spin qubit fabrication is intended to complement IBM’s existing leadership in superconducting quantum computing, giving the company a second qubit modality to draw on as it pursues a multi-modality hardware roadmap. HRL’s silicon fabrication processes are expected to be integrated into Anderon, IBM’s dedicated quantum wafer foundry established earlier this year.

    Boeing and GM Retain a Role in Quantum Applications

    Boeing and General Motors, HRL’s former joint owners, will continue to partner with IBM and HRL on quantum applications and advanced technology development following the deal’s close, according to IBM’s announcement. The acquisition adds to a broader wave of consolidation and infrastructure investment in quantum computing this year, as government agencies and large technology firms compete to move quantum systems from research labs toward practical, fault-tolerant deployment.

    Financial terms of the acquisition were not disclosed. IBM said HRL’s quantum-sensing and materials-science capabilities, beyond qubit fabrication, are also expected to strengthen its broader hardware development pipeline.

  • Critical Gitea Flaw Under Active Exploitation as Thousands of Servers Remain Unpatched

    Critical Gitea Flaw Under Active Exploitation as Thousands of Servers Remain Unpatched

    A critical vulnerability in Gitea, a widely used self-hosted Git service, is being actively exploited to plant cryptocurrency-mining malware on unpatched servers, according to reporting from The Hacker News and BleepingComputer published August 26 and 28, 2026, and confirmed by vulnerability-tracking service Shadowserver.

    The flaw, tracked as CVE-2026-60004 and carrying a CVSS score of 9.8, allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea service account by submitting a malicious patch through the platform’s diffpatch API endpoint. Because Gitea’s default configuration permits open account registration, an unauthenticated attacker can obtain the necessary write access simply by creating an account and a repository, then trigger code execution — researcher Shai Rod (NightRang3r), who is credited with the discovery, described exploitation as achievable in seconds on a default install with zero prior credentials.

    Cryptominer Payloads Observed, CISA Deadline Already Passed

    Shadowserver identified more than 8,300 internet-exposed, vulnerable Gitea instances as of August 27, 2026. The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on August 25 and ordered Federal Civilian Executive Branch agencies to patch by August 28. In at least one documented case, a developer’s Gitea instance was compromised by a dropper that cleared environment variables, killed competing processes, and fetched an architecture-specific cryptominer payload before deleting itself — consistent with opportunistic, automated scanning rather than a targeted campaign.

    The vulnerability affects all Gitea versions from 1.17 onward and is fixed in version 1.27.1. Organizations running self-hosted Gitea instances, particularly those with open registration enabled, are advised to patch immediately and review recent repository and account activity for signs of compromise.

  • Waymo Names Munich as Its Third City Outside the US for Driverless Ride-Hailing

    Waymo Names Munich as Its Third City Outside the US for Driverless Ride-Hailing

    Waymo announced on August 28, 2026, that Munich will become its third international city for autonomous ride-hailing, following earlier expansions to London and Tokyo, according to reporting from Euronews. The company said it is laying the operational and regulatory groundwork for a driverless service in the German city but has not set a specific public launch date.

    Waymo pointed to safety data from its US operations to make the case for expansion, citing internal analysis suggesting its autonomous vehicles are involved in significantly fewer serious-injury and fatal crashes per mile than human-driven taxis in the same markets. The company noted that Europe records roughly 20,000 road fatalities annually, with driver error cited as a factor in a majority of crashes, as part of its rationale for prioritizing European expansion.

    Part of a Broader European Push for Autonomous Driving

    The Munich announcement comes as European regulators show growing openness to autonomous and driver-assistance systems more broadly; a recent Dutch approval of Tesla’s Full Self-Driving Supervised system has been followed by similar regulatory movement in Denmark, Lithuania, and Estonia. Waymo already operates fully driverless commercial service across ten US cities, where the company has said it now completes more than half a million paid trips per week.

    Munich’s position as a major automotive-engineering hub, home to BMW and a dense supplier base, is likely to shape how quickly Waymo can secure local regulatory approval and testing partnerships. The company has not disclosed which German authorities it is engaging with or a target timeline for public rides to begin.

  • Hasbro Notifies Employees That Social Security and Financial Data Was Exposed in Cyberattack

    Hasbro Notifies Employees That Social Security and Financial Data Was Exposed in Cyberattack

    Toy and game maker Hasbro has begun notifying current and former employees that a cyberattack exposed their personal and financial information, according to breach notification letters filed with state regulators, including the Massachusetts Attorney General’s Office on August 28, 2026, and reported by BleepingComputer.

    The exposed data varied by individual but could include Social Security numbers, financial account information, credit and debit card numbers, driver’s license details, names, email addresses, and phone numbers. The Massachusetts filing alone identifies 436 affected employees in that state; the total number of individuals notified nationwide was not disclosed in the filing reviewed by BleepingComputer.

    Response and Unresolved Questions on Scope

    Hasbro said it “implemented containment and remediation measures, including disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards,” and is offering affected individuals complimentary identity-protection services. The company said it has “no indication” the exposed information has been misused.

    Hasbro separately disclosed a cyberattack detected on March 28, 2026, that forced systems offline and contributed to an estimated $25 million in lost revenue during the resulting disruption; the company’s current employee-data notification does not formally confirm whether the two incidents are connected, and BleepingComputer’s reporting treats the link as unconfirmed. The disclosure adds Hasbro to a lengthening list of large employers notifying staff of breach exposure this year, following similar notifications from healthcare and logistics firms including McKesson’s disclosure of a ShinyHunters-linked breach earlier this week.