The CyberWire Daily Podcast 8.3.26
Ep 2606 | 8.3.26

Water you waiting for?

Transcript

Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerabilities fool security databases. Monday business briefing. Our guest is Tim Starks from CyberScoop discussing the White House's quantum aspirations. AI is the hottest thing on campus.

Today is Monday August 3rd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Officials warn of broad attacks on U.S. water systems. 

Cyberattacks targeting U.S. water systems have expanded to at least seven states, with officials warning the campaign could be much broader. While no drinking water has been contaminated, hackers have targeted internet-connected industrial control systems used to manage water quality, chemical treatment, and pressure. Minnesota first disclosed the activity, and Michigan later confirmed attacks affecting multiple municipal systems, though officials said there were no public health impacts. Federal investigators consider Iran the leading suspect, citing an increase in Iranian cyberactivity since the U.S. and Israel’s war with Iran began, but they stress the attribution remains preliminary and lacks definitive forensic proof. President Trump publicly disputed Iran’s involvement, while state and federal officials continued to treat Iranian actors as the most likely source. The Cybersecurity and Infrastructure Security Agency (CISA) warned that water utilities of all sizes are at risk and urged operators to disconnect vulnerable controllers from the internet. The incidents underscore longstanding concerns about the cybersecurity of aging, resource-constrained critical infrastructure.

CISA shares guidance to secure open source software. 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance to help federal agencies securely adopt, manage, and contribute to open source software (OSS). The recommendations emphasize evaluating OSS before deployment, maintaining inventories of software components, tracking dependencies, monitoring for vulnerabilities, and applying patches promptly. CISA also encourages agencies to contribute security fixes and improvements back to the open source community while ensuring sensitive information is not exposed. For software developed by federal agencies, CISA recommends planning for open source release where appropriate, following secure development practices, and publishing supporting documentation and software bills of materials (SBOMs). The guidance also addresses open source artificial intelligence, warning that AI models lacking transparency into their training data and development process should be treated as proprietary software with incomplete provenance and subjected to stricter risk management before deployment.

An unsecured Chinese surveillance platform tracks foreigners. 

A cybersecurity researcher uncovered an unsecured Chinese surveillance platform that appears to track thousands of foreigners in Zhangjiakou, revealing the breadth of China’s monitoring capabilities beyond its own citizens. The database contained detailed personal information, including passport data, phone numbers, travel records, camera sightings, hospital visits, and social connections. It categorized individuals by nationality, religion, and other attributes, including foreign journalists, students, and residents from Hong Kong and Taiwan. Evidence reviewed by The New York Times suggests the platform was developed for the Zhangjiakou Public Security Bureau by surveillance technology firm Origin Dynamic. Researchers said the exposed system highlights China’s extensive integration of surveillance data and weak privacy safeguards, with sensitive information left accessible online. Experts warned the incident reflects a broader expansion of China’s surveillance infrastructure and the risks posed by poorly secured government systems.

CaptiveCrunch makes public WiFi questionable. 

Microsoft is warning organizations to treat hotel, airport, conference, and other public Wi-Fi networks as untrusted following the discovery of CaptiveCrunch, a global cyber campaign attributed to the Russian threat group Storm-2945, a subgroup of Midnight Blizzard. Active since May, the campaign compromises hospitality network infrastructure to present fake login pages, software updates, and verification prompts that steal credentials or install malware. In some cases, attackers abuse Microsoft’s legitimate device-code authentication process to gain account access without stealing passwords. Microsoft also found evidence that Android devices are being targeted with malicious app downloads. The company says the attackers used artificial intelligence to support the campaign. To reduce risk, Microsoft recommends using mobile hotspots or cellular connections instead of public Wi-Fi, avoiding software updates through captive portals, adopting phishing-resistant authentication, and disabling device-code authentication where it is not needed.

The timing is hard to miss, with Black Hat and DEF CON just getting underway, it’s a fitting reminder that in Las Vegas, not every suspicious network is part of the conference agenda.

INC ransomware claims stolen data from an Australian healthcare provider. 

Australian healthcare provider Partnered Health is investigating claims by the cyber extortion group INC Ransom that it has stolen and published data from the organization’s network. The group says 11 files containing personal information were posted on its darknet leak site, though Partnered Health has obtained a court injunction restricting access to the data while investigators assess its authenticity, which seems…aspirational. The incident stems from a cyberattack disclosed in July that occurred on June 23, with additional patients and employees now believed to be affected. Partnered Health has notified impacted individuals and reported the incident to Australian authorities. Security experts warn the breach highlights the growing cyber risks facing healthcare organizations and advise patients to be vigilant for phishing attempts and fraudulent communications using potentially stolen personal information.

Crime lab DNA software proves vulnerable. 

Researchers at the University of New Haven have identified a high-severity security vulnerability affecting DNA analysis software widely used in U.S. crime laboratories, potentially exposing digital forensic records dating back to 1995 to undetectable tampering. The flaw could allow an attacker with access to a lab’s systems to alter DNA analysis files without leaving evidence of modification, raising concerns about the integrity of digital forensic evidence. Researchers demonstrated the attack using AI-assisted code and publicly available decryption keys, though there is no evidence the vulnerability has been exploited in real cases. After being notified, Thermo Fisher Scientific acknowledged the issue, worked with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and released a software update that adds digital signatures to help verify file integrity. Experts say the findings highlight the need for stronger cybersecurity protections in forensic laboratories.

Researchers flag fabricated SQLite vulnerability advisories. 

Security researchers at JFrog say dozens of recently published SQLite vulnerability advisories appear to be fabricated, likely generated by large language models (LLMs), despite being assigned CVE identifiers and initially receiving high severity ratings from the National Vulnerability Database (NVD) and other sources. After analyzing six reported SQLite flaws, researchers found the advisories referenced nonexistent functions, incorrect line numbers, invalid proof-of-concept exploits, and fixes that never existed. None of the vulnerabilities appeared on SQLite’s official advisory page, and testing failed to reproduce the claimed issues. JFrog warns the incident exposes weaknesses in the current CVE ecosystem, where unverified submissions can propagate through vulnerability databases and automated security tools. The researchers recommend validating high-impact CVEs against vendor advisories, source code, and reproducible exploits before prioritizing remediation, particularly as AI-generated content becomes more prevalent.

The U.K.’s Police National Legal Database suffers a data breach. 

A cyberattack on the U.K.’s Police National Legal Database (PNLD) has exposed the names and contact details of roughly 100,000 police officers on the dark web, raising serious safety concerns for law enforcement personnel. Authorities believe the hacking group ExfilSquad was responsible, as part of a broader campaign targeting U.K. government agencies, including the Ministry of Defence, Home Office, National Crime Agency, and Crown Prosecution Service. The breach follows a separate attack on the Department for Education that exposed more than 500,000 records. Affected officers say the leak increases personal security risks, particularly for those involved in organized crime investigations.

Monday business briefing.


Cybersecurity and AI companies announced a wave of funding and acquisition activity this week, led by ThreatLocker’s $190 million Series F to expand its Zero Trust platform. Other notable funding rounds included Act Security ($60 million), AegisAI ($36 million), Harmony AI ($34 million), Hush Security ($30 million), Abstract ($25 million), CopySight ($3 million), and Frenos ($1.5 million extension), with investments focused on cloud security, identity management, AI-powered security operations, and enterprise automation. On the mergers and acquisitions front, Cyera agreed to acquire identity security startup Oasis Security for $1 billion to combine data and identity protection. Leonardo DRS announced a $450 million acquisition of mission software provider Raft, while Keyfactor plans to acquire U.K.-based identity security firm Cofide to strengthen AI trust infrastructure. Vena Solutions also announced plans to acquire enterprise AI platform Morpheo AI to enhance its AI capabilities.

AI is the hottest thing on campus. 

Artificial intelligence is reshaping higher education in unexpected ways. As demand for traditional computer science degrees cools and entry-level coding jobs face pressure from AI, colleges are finding growing interest from students who never planned to study computer science in the first place. Psychology majors, musicians, biologists, and business students are adding AI minors, certificates, and courses to build what universities increasingly view as a fundamental workplace skill. Schools are responding with AI literacy requirements, new interdisciplinary programs, and faster course development, reflecting the technology’s rapid evolution. Educators argue that understanding AI is becoming as essential as reading or basic math, even as they caution against overreliance on the technology. The irony is hard to miss: AI may be writing some code that once justified a computer science degree, but it’s also convincing students across nearly every other discipline that they need to learn enough about it to keep up.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

We're recording onsite at Black Hat this Wednesday and Thursday from our podcast studio in the SpecterOps Kennel Club. If you'd like to meet the N2K CyberWire team, make sure you stop by the studio.

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.