
The feds flip the script.
The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical Gitea flaw, while malicious pages masquerade as Cloudflare verification screens. Cyber insurance claims get costlier, and AI agents break out of their sandboxes. Boston Scientific battles a cyber incident. Plus, a new standard tracks AI agent activity, criminals target stolen iPhones, and an alleged money mule is charged in a $7.5 million scam. Our guest is Stephen Hilt, Sr. Threat Researcher at TrendAI, on the risks facing data centers. Some breach data doesn’t quite measure up.
Today is Wednesday August 26th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies.
The Justice Department says the U.S. has disrupted a Chinese hacking operation blamed for intrusions at several sensitive government agencies, including the Justice Department, NASA, the Federal Reserve and the U.S. Senate. Authorities seized domains associated with two hacking platforms, known as QScan and QTRouter, that were allegedly used in the campaign. The Chinese Embassy in Washington did not immediately comment. Beijing has routinely denied responsibility for cyberattacks attributed to China.
CISA says more than 100 water and wastewater systems were targeted in cyberattacks in July.
CISA says more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks in July, the first federal accounting of the recent campaign’s scope. The attacks, linked to Iranian threat actors, targeted operational technology, often programmable logic controllers connected directly to cellular modems. At least a dozen states appear to have been affected, though the attacks caused no significant disruption.
CISA is using the campaign to urge critical infrastructure operators to reduce their internet-facing attack surface. The agency recommends identifying exposed systems, removing unnecessary connections, changing default passwords, applying security updates, and routing required remote access through secure gateways with multifactor authentication. CISA says PLCs and other industrial control systems exposed through cellular modems or the public internet have enabled recent malicious activity against the water sector.
Attackers actively exploit a critical Gitea vulnerability.
CISA says attackers are actively exploiting a critical vulnerability in Gitea, the self-hosted software development platform. Tracked as CVE-2026-60004, the flaw allows users with repository write access to execute arbitrary shell commands with the privileges of the Gitea service account. Because Gitea enables self-registration by default, an unauthenticated attacker could register an account, create a repository, and exploit the vulnerability without existing credentials.
Gitea patched the flaw in version 1.27.1, released July 27. Shadowserver currently tracks nearly 5,000 internet-exposed Gitea instances, though it’s unclear how many remain vulnerable. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to remediate it by August 28. Reported attacks have deployed cryptocurrency mining malware on unpatched servers.
Malicious HTML pages are disguised as Cloudflare verification screens.
Threat actors are abusing npm and its mirrors to host malicious HTML pages disguised as Cloudflare verification screens. Researchers at OX Security identified 24 packages using the technique. Unlike traditional npm supply-chain attacks, the packages don’t infect developers who install them. Instead, attackers use npm as storage and services such as UNPKG to render the malicious pages from legitimate domains, potentially helping them evade security controls.
The pages embed Cloudflare’s legitimate Turnstile CAPTCHA, but obfuscated JavaScript redirects visitors regardless of whether verification succeeds. Some versions retrieve encrypted destination URLs from a separate service, allowing attackers to change redirects without republishing the npm package. Researchers warn those destinations could lead to phishing pages or malware, and that malicious files may remain accessible through mirrors even after npm removes the original packages.
Each Wednesday we feature the latest from our T-Minus Space Cyber podcast team. Maria Varmazis is out this week, so Ethan Cook files this report.
Cyber insurance claims are getting more expensive.
Cyber insurance claims are getting more expensive for larger companies, even as fewer claims are being filed. Chubb’s 2026 Cyber Claims Report found that average claim costs in 2025 rose 22% for U.S. middle-market companies and doubled for large firms. The UK and Europe saw similar increases of 34% and 98%, respectively.
Chubb attributes the rising severity largely to data breach and privacy litigation, along with higher business interruption costs. U.S. claims were substantially more expensive, reflecting significant third-party litigation expenses not seen in the UK and Europe. The insurer also warns that expanding privacy laws and ransomware-related data leaks are increasing companies’ litigation exposure. In the U.S., even administrative fees can be substantial: a case involving 10,000 claimants could generate more than $10 million in non-refundable fees before its merits are considered.
AI agents repeatedly escape their sandboxes.
A researcher from Trail of Bits testing GPT 5.6-Cyber found the AI agent could repeatedly escape a QEMU/KVM virtual machine intended to contain it. The agent first exploited recently disclosed host-kernel vulnerabilities, then combined flaws in the libslirp networking library. After the researcher rebuilt QEMU and its dependencies from current upstream code, the agent spent roughly 12 hours autonomously researching the attack surface and ultimately assembled a reliable escape chain involving several previously unknown vulnerabilities in QEMU, Linux KVM, and libslirp.
The experiment suggests conventional VMs may no longer provide sufficient isolation for highly capable cyber agents. The researcher recommends minimizing attack surface, rapidly applying upstream updates, restricting network access and privileges, and closely monitoring agent activity. Firecracker proved substantially more resistant in additional testing, although the agent could still hardlock the host through already-patched Linux kernel flaws.
A cybersecurity incident disrupts global operations for Boston Scientific.
Boston Scientific says a cybersecurity incident is disrupting global operations, including information systems used to process and ship customer orders. The medical device maker detected the incident August 25 and brought in third-party cybersecurity specialists to investigate and contain the threat. Some business operations are expected to remain affected during recovery. Boston Scientific says it has not determined whether the incident is likely to have a material impact. The full scope and nature of the attack remain under investigation.
A new open standard provides tamper-resistant evidence of what AI agents actually do.
The Linux Foundation is backing TRACE, a new open standard designed to provide tamper-resistant evidence of what AI agents actually do. Developed by confidential computing vendor OPAQUE with support from AMD, Intel, Microsoft and the Technology Innovation Institute, TRACE creates hardware-backed, cryptographically verifiable records of an agent’s runtime environment, software, policies, data classifications and tool use.
The specification combines existing internet standards with confidential computing technologies, including AMD’s Secure Encrypted Virtualization, to produce portable evidence that organizations can independently verify across infrastructure providers. The Linux Foundation will provide vendor-neutral governance, with technical work hosted by the Coalition for Secure AI. TRACE addresses a growing concern as autonomous agents enter production: policies and sandbox configurations can define intended behavior, but don’t necessarily prove which controls remained active or what an agent actually did.
A phishing-as-a-service platform helps criminals unlock stolen Apple devices.
Researchers at SOCRadar have uncovered AnonyMousKIT, a phishing-as-a-service platform designed to help criminals unlock stolen Apple devices and bypass Activation Lock. Active since early 2024, the service is linked to 506 domains and 168 reseller storefronts.
AnonyMousKIT extracts owner contact information from stolen devices and targets victims through email, SMS, WhatsApp and AI-generated phone calls. Messages impersonate Apple, using accurate device details to convince victims their missing iPhone has been found. Fake Apple pages then solicit device passcodes, Apple Account credentials and two-factor authentication codes. In some cases, an AI voice agent posing as Apple Support assists with the deception. Successful attacks can allow criminals to access personal data, remove devices from Find My, and resell them. Compromised accounts could also expose iCloud backups, Keychain passwords and corporate information.
A man faces federal charges for allegedly helping overseas scammers steal more than $7.5 million.
A 21-year-old Indian national is facing federal charges for allegedly helping overseas scammers steal more than $7.5 million from at least nine elderly victims in New York and New Jersey. Prosecutors say Jay Sunilbharthi Goswami served as a money mule, collecting cash, gold and gift cards from victims deceived by scammers impersonating law enforcement or government officials.
Authorities allege Goswami received victim addresses and code words, collected the assets, and transported them for eventual transfer to India, earning about $90,000. After an earlier arrest in December 2025, prosecutors say he continued participating in the scheme. Following another arrest in August, Goswami allegedly fled to Canada and attempted to fly from Toronto to Doha. Canadian authorities arrested him at the airport, and he is awaiting extradition to the United States.
Ethan Cook is N2K’s lead analyst and joins us on behalf of the T-Minus space cyber podcast to share the latest news from the wild blue yonder. Today he files this report on a recent presidential memo to increase commercial space activity in the US.
Trump targets 1,000 annual U.S. space launches.
Last Friday, President Trump signed a new memo that looks to dramatically increase support for commercial space launches. The White House signals that it wants to enable at least 1,000 launches and re-entries annually by 2030, a significant increase from the 178 launches conducted in 2025. The memo also directs NASA to facilitate commercial transportation to the moon and commercial robotic access to Mars. The memo called on agencies to incentivize co-development for space transportation infrastructure, expedite permitting and environmental reviews, and ensure necessary wireless spectrum for space launches. Lastly, the administration tasks agencies with identifying a new federal re-entry site within ninety days.
Some breach data doesn’t quite measure up.
Troy Hunt’s analysis of an alleged Carhartt breach began with an eye-catching number: nearly 25 million unique email addresses. Other reporting cited similar figures, which seemed reassuring. Then the data started behaving strangely.
Using AI-assisted analysis and some decidedly old-fashioned eyeballing, Hunt found millions of synthetic records from the TPC-DS benchmarking dataset mixed with apparently genuine Carhartt customer data. Gibberish email domains, suspiciously uniform birth countries and perfectly flat birth-year distributions were among the giveaways. Removing benchmark data, Microsoft aliases, deactivated accounts and test records eventually cut the total to about 12.9 million addresses.
Hunt found strong evidence the remaining data genuinely originated from Carhartt, including employee addresses and Carhartt-specific email sub-addresses. His larger point: breach claims require verification. Criminals may dump the data, analysts may count it, and suddenly synthetic test records have acquired victims, lawyers and a headline.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

