No-frills tech news

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That said, the ongoing PLC targeting activity is assessed to be broader in scope than Siemens PLCs. "The actors leverage internet scanning services like Censys and ZoomEye to identify internet-exposed PLCs running outdated software or that are otherwise poorly protected," according to the advisory published by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA). Targets of the activity include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies did not attribute the attacks to a known threat actor or group. The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, not to mention have cascading impacts across interconnected systems. The activity has been found to have singled out the following Siemens PLC models - - S7-200 Series (all CPU variants) - S7-300 Series (all CPU variants including 314, 315, 317 models) - S7-400 Series (all CPU variants) - S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants) - S7-1500 Series (all CPU variants, including F-series safety controllers) "Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives," the agencies said. "If these PLCs are exposed to the internet or insufficiently segmented, then threat actors can exploit various critical and high severity

CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement ...

CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture, an outcome-driven guide for federal civilian executive branch (FCEB) agencies to establish logging, visibility and operational standards in an Agency Logging Plan, as required in Office of Management and Budget (OMB) Memorandum M-26-14. Developed in collaboration with OMB and the Chief Information Security Officers (CISO) Council, this guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring. In alignment with the objectives of M-26-14, CISA’s Logging Reference Architecture guidance directly helps agencies achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response, and forensics. Agencies will be able to utilize this guidance to update enterprise logging strategies, which will inform an Agency Logging Plan that agencies are required to submit to OMB and CISA by November 18, 2026. The M-26-14 Agency Logging Plan Template, provided by CISA, offers a structured format to streamline planning. “Cyber defense begins with insight. Robust logs provide the critical visibility needed to counter daily threats targeting federal systems. CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “The Logging Reference Architecture guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data.” Within the Logging Reference Architecture, CISA provides operational checklists to help federal agencies inform their logging architecture design and organizational strategies, achieve baseline logging fidelity, and ensure logging plans are operationally ready to support necessary security outcomes. The guidance will also inform agency decisions on integrating artificial intelligence (AI) into logging processes in ways that enhance operational value while

Penn State Beaver alumna turns IT degree into <b>cybersecurity</b> career

MONACA, Pa. — For Penn State Beaver alumna Ava-Li Baker, a small campus, big opportunities and real connections with professors helped transform her choice to stay close to home into a rewarding cybersecurity career. Baker, who graduated in 2022 with a degree in information technology, is a cybersecurity analyst for the Naval Nuclear Propulsion Program. The Hopewell Area High School graduate said she wanted to stay close to home, and when she took a tour of the Beaver campus, she liked the more intimate feel of a small campus and knew that “Penn State had a great IT program.” “My experience there was great,” she said, adding that even through the COVID-19 lockdown, she didn’t feel like the pivot to online learning affected her education. “It was interesting to transition to virtual classes, and when we came back, I was still connected to my classmates and remembered people from Zoom classes.” Baker said she was trying to decide between information technology or studying drafting at a technical school. She said her mom always thought she was good with computers, so she decided to go that route. “I like to work with computers and figure out how to do things with computers. What can I do? What can I make? she said. “The degree in information technology appealed to me because it was broad. The world was my oyster. I could do anything with it.” Baker added a minor in security and risk analysis and applied for an information technology internship with the Bettis Atomic Power Laboratory a year in advance because of the clearance process necessary to work there. “I did my internship during the summer of 2021, and then they offered me a chance to return for the next summer in cybersecurity,” she said. “My manager from the previous

AI data giant Alation confirms cyberattack

Days after reporting an incident affecting a number of its customers, enterprise data giant Alation on Thursday confirmed a cyberattack. Alation makes data software that its enterprise customers use to search for files and data using natural language queries. In recent years, the company has expanded into AI, allowing customers to turn large amounts of messy data into usable content. The company says it services more than 500 global companies, including around half of the Fortune 1000 largest companies in the United States. When reached by TechCrunch about the incident, the company said it was investigating. “Alation recently identified an isolated incident involving unauthorized activity in one of its systems,” the company said in a statement provided to TechCrunch by an external representative, Stephen Russell. “We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate.” Alation did not specify the nature of the cyberattack, mention the root cause of the incident, or say how many customers are affected. The company did not say if it had alerted its customers to the incident or what defensive actions, if any, they should take following the intrusion. On Tuesday, Alation reported an unspecified incident that resulted in “degraded availability” for some of its customers. The company said it had resolved the incident within an hour. Much of the company’s systems are hosted on Amazon Web Services. It’s not immediately clear if any data was stolen or exfiltrated during the incident. This is the latest cybersecurity incident in recent weeks to affect a large-scale technology giant, as hackers increasingly target companies that store large amounts of sensitive or proprietary information for their corporate customers. Earlier this month, several companies reported data thefts following a breach at European shipping giant Ceva Logistics. Hackers are also said to be

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability - CVE-2026-72530 TrueConf Server Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.

Living Security Announces 2026 <b>Cybersecurity</b> Awareness Month Speaker Lineup Focused ...

Living Security Announces 2026 Cybersecurity Awareness Month Speaker Lineup Focused on Trust in an AI World Five cybersecurity experts join Living Security's turnkey Cybersecurity Awareness Month program to help employees navigate AI-driven deception, digital trust, and human risk AUSTIN, Texas, August 20, 2026 (Newswire.com) - Living Security, the global leader in Human Risk Management (HRM), today announced the featured speaker lineup for its 2026 Cybersecurity Awareness Month program, bringing together five experts whose careers span cybercrime prosecution, intelligence operations, online safety advocacy, insider threats, and human behavior risk. The speakers are part of Living Security's turnkey Cybersecurity Awareness Month offering, designed to give security awareness teams the expert-led programming, interactive experiences, ready-to-launch campaign content, employee communications, and planning resources needed to run an engaging October campaign. Built around the theme Navigating Trust in an AI World, this year's Cybersecurity Awareness Month program explores one of the defining security challenges of the AI era: how employees can make informed decisions when deepfakes, voice cloning, synthetic content, misinformation, and increasingly sophisticated social engineering make deception easier to create and harder to detect. Employees are being asked to evaluate information, verify identities, and make security decisions in situations where traditional signals of trust may no longer be reliable. The 2026 speaker lineup brings those challenges to life through firsthand experiences with cybercrime, espionage, manipulation, insider threats, digital safety, and the human behaviors that can either increase or reduce organizational risk. "The security challenge facing organizations today isn't simply awareness; it's trust," said Ashley Rose, CEO and Co-Founder of Living Security. "The experts joining this year's program have spent their careers confronting cybercrime, deception, manipulation, insider threats, and online safety challenges. Their experiences bring this year's theme to life and help employees understand how to build trust, verify information, and make better security decisions."

AI <b>Cybersecurity</b> Risks: Practical Guidance for Leaders | Forvis Mazars US

Frontier artificial intelligence (AI) models, such as Anthropic’s Mythos model family, have drawn attention for their reported ability to find software vulnerabilities, develop exploits, and complete multistep tasks with limited human direction. While the precise extent of those capabilities may be difficult to determine, the direction is apparent: advanced AI can reduce the time and technical skill required to identify and exploit weaknesses. National and international bodies now describe this openly. The European Commission has noted that advanced AI can be misused to identify vulnerabilities, automate attacks, and increase the scale and speed of cyber incidents.1 The National Institute of Standards and Technology (NIST) makes a similar point, framing AI-enabled cyberthreats as a core concern for enterprise risk management.2 The operating conditions for cybersecurity are changing rapidly, placing more pressure on organizations to apply a defense-in-depth strategy. As businesses integrate AI tools into software development, customer service, financial processes, and internal operations, the stakes are high. Some systems retrieve sensitive information, connect to critical business systems, and act through an employee’s or AI agent’s permissions. Organizations also may become dependent on AI models whose availability is controlled by an outside provider or affected by government action.3 Business leaders now face two corresponding questions regarding external and internal risks: - How will AI change threats directed at the organization? - What new exposure will the organization create by embedding AI inside its own operations? Vulnerability Discovery Is Getting Faster AI technology didn’t invent software vulnerabilities or zero-day attacks. Researchers and threat actors have long looked for weaknesses in operating systems, browsers, applications, and infrastructure. What frontier models can escalate is the speed and scale of that work. The European Commission observes that frontier capabilities, once concentrated in a few systems, are becoming more accessible as open-source models improve, including to criminal

<b>Cybersecurity</b> Threat Delays Start of Classes at UT San Antonio

Creative Commons One day before the University of Texas at San Antonio was scheduled to begin its fall semester Wednesday, officials postponed the start by three days after “attempted unauthorized activity against university technology systems” prompted them to shut down many of the university’s digital systems, including some related to email and phone services. The university also pushed back registration and payment deadlines. “We are making this decision to ensure the university systems, technology and services our students, faculty and staff rely upon are operating optimally as we begin the semester. Starting classes on Monday (Aug. 24) gives our teams the necessary time to restore services carefully and position our university community for a strong start,” UT San Antonio President Taylor Eighmy wrote in a statement to the campus community Tuesday. “Out of an abundance of caution, we proactively took systems and services offline to evaluate our technology environment and reinforce safeguards before bringing services back online.” Over the weekend, UT San Antonio detected a potential threat to its systems “at the edge of our network, before it reached core systems and University Technology Solutions,” officials said in an announcement. “Our response has been effective. At this time, our ongoing investigation has found no evidence that university data was accessed or exfiltrated as a result of this activity.” A university spokesperson wrote in an email to Inside Higher Ed that UT San Antonio has identified the source of the attempted unauthorized activity, but didn’t provide further details; they said only that the “university’s investigation remains ongoing in coordination with expert partners” and has no “definitive timeline for completion.” Aside from starting three days late, the semester is expected to carry on as scheduled, with the university “making the necessary academic adjustments within the existing semester calendar,” they wrote. While UT

ReliaQuest Advances Agentic Cyber Defense for Enterprises with Anthropic's Claude

ReliaQuest, the AI cybersecurity company behind GreyMatter, announced expanded AI initiatives with Anthropic, the AI safety company and creator of the Claude family of models, aimed at accelerating the development and deployment of AI for enterprise cyber defense. The collaboration brings Anthropic’s Claude core family of models into the ReliaQuest GreyMatter platform, which is used by some of the world’s largest organizations to detect, investigate, and respond to cyber threats at machine speed. Through the partnership, GreyMatter customers will gain access to advanced AI capabilities designed to strengthen enterprise cyber defenses. ReliaQuest has also joined Anthropic’s Project Glasswing and is using Mythos within its own systems for defensive cybersecurity applications. Through its participation in Project Glasswing, ReliaQuest will gain shared insights into how emerging AI models may be leveraged by threat actors. “We are at a defining moment for cybersecurity,” said ReliaQuest founder and CEO Brian Murphy. “AI is changing what attackers can do. It has to change what defenders can do too. Our work with Anthropic means our customers will have more access to frontier AI models deeply integrated into GreyMatter — so they can move faster and respond with greater confidence than the adversary.” The expanded integration of Claude builds on an existing relationship between the two companies. GreyMatter already uses Claude’s advanced reasoning capabilities for complex security operations tasks, including alert triage, threat investigation, and analysis of sophisticated multi-stage attacks. ReliaQuest was also among an initial group of security vendors recently selected to integrate with Anthropic’s compliance API — enabling authorized Claude activity data to be brought into GreyMatter. This allows enterprise security teams to monitor, detect, and respond to Claude usage in the same manner as other enterprise applications operating within their environments. Claude models have been incorporated into GreyMatter since the platform’s early development. They

Study: DIB Reports Higher <b>Cybersecurity</b> Scores, but Confidence Falls

Defense contractors are reporting their highest cybersecurity compliance scores since tracking began, but confidence in the accuracy of those scores has fallen sharply, according to an annual study conducted by Merrill Research and commissioned by CyberSheath, a cybersecurity compliance services provider. The study, which surveyed 302 defense contractors, found that average Supplier Performance Risk System (SPRS) scores climbed to plus 51 in 2026, up from plus 33 last year. At the same time, just 65% of contractors that submitted an SPRS score said they were extremely or very confident in its accuracy, down from 89% last year and 94% in 2024. SPRS scores measure contractor compliance with National Institute of Standards and Technology (NIST) Special Publication 800-171 security requirements. Those requirements also form the cybersecurity foundation for the Department of Defense’s (DOD) Cybersecurity Maturity Model Certification (CMMC) program. CMMC provides a framework for DOD to verify that defense industrial base (DIB) contractors meet applicable cybersecurity requirements, including through self-assessments and, for some contractors, third-party assessments. According to the report, the latest SPRS results show substantial improvement on paper. The average score had remained negative for three consecutive years, at minus 12 in 2024, minus 15 in 2023, and minus 25 in 2022. SPRS scores can range from minus 203 to a maximum of plus 110. The scores do not represent all respondents, however. Only 67% said they had submitted an SPRS score. The study characterized the disconnect between higher scores and lower confidence as a “central challenge for the DIB,” saying the issue is increasingly about “independently validating whether claimed compliance reflects operational reality.” The report’s findings come as DOD has paused Phase 2 of CMMC, which had been scheduled to take effect on Nov. 10. The department announced a 60-day review of the program on July 13 while keeping

ASU launches new scholarship pipeline to AI-powered <b>cybersecurity</b> careers

Future cybersecurity threats may not look much like past ones. Artificial intelligence is changing how attackers find vulnerabilities, automate attacks and probe digital systems. At the same time, federal agencies, businesses and communities are expanding their use of AI. Related story These factors create a new, urgent question: Who will secure our vulnerable infrastructure and computer security systems? The United States already faces a persistent shortage of skilled cybersecurity professionals, with experts estimating about 500,000 unfilled roles. Now employers need a new kind of professional — one who understands how to use AI to defend digital systems and how adversaries can harness the same technology to attack them. The School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at Arizona State University, will help train that workforce. ASU is one of 14 universities selected to receive inaugural awards from the U.S. National Science Foundation's CyberAICorps Scholarship for Service, or CyberAI SFS, program. The Fulton Schools’ AI-Augmented Cybersecurity Scholars Program will provide students with scholarship support, advanced education and research opportunities at the intersection of AI and cybersecurity. But there is another crucial component: a pathway to a job. CyberAI SFS is a scholarship-for-service program. Its goal is to prepare graduates for cybersecurity careers supporting U.S. government agencies and other eligible public-sector organizations. The scholarship is designed as a pipeline stretching from university classrooms and research labs to the places where some of the nation’s most consequential cybersecurity work happens. A pipeline with a proven track record In the School of Computing and Augmented Intelligence, that pipeline isn’t being built from scratch. The new program builds on existing NSF Scholarship for Service efforts, led in the school by the ASU Center for Cybersecurity and Trusted Foundations. Across two previous iterations of the program, ASU has

Wyden, Warren Demand FINRA Strengthen <b>Cybersecurity</b> Standards to Prevent ACATS ...

Wyden, Warren Demand FINRA Strengthen Cybersecurity Standards to Prevent ACATS Brokerage Fraud Millions of Americans’ life savings at risk due to a lack of basic online account holder features by leading brokerages Washington, D.C. – U.S. Senators Ron Wyden and Elizabeth Warren today called for the Financial Industry Regulatory Authority (FINRA) to strengthen consumer protections and prevent Automated Customer Account Transfer Service (ACATS) brokerage fraud. ACATS is an automated system managed by the National Securities Clearing Corporation which allows investors to seamlessly transfer their stocks, bonds, and cash from one brokerage firm to another. Designed to keep brokerages from slowing transfers, ACATS' rapid process also gives fraudsters an opportunity to exploit the system's weak security measures before victims can respond. Under current regulations, brokerages have one business day to validate or object to a transfer request and three business days to complete asset transfers. FINRA recommends, but does not require, that brokerages notify customers before they transfer their assets to another company. Most firms rely on a bare-bones electronic verification process and do not verify the transfer with the outgoing account holder. Some do not even notify customers about the transfer of their assets. As a result, the press has reported that fraudsters can open accounts in victims' names and use the ACATS system to drain their investments before they realize what has happened. “It is unacceptable that major brokerage firms are putting customers’ life savings at risk of being ripped off by criminals because of inadequate account protections,” the senators said in their letter to Robert W. Cook, the President and CEO of FINRA. “FINRA must step in to protect consumers.” An analysis conducted by the senators’ offices revealed an inconsistent security landscape, with only a fraction of brokerages voluntarily providing customers with strong protections. While firms like Fidelity

Will AI Replace Detection Roles in <b>Cybersecurity</b>?

Will AI Replace Detection Roles in Cybersecurity? AI agents are already starting to handle the grunt work of detection engineering, or essentially finding malware. If AI is now doing the job, what's the future of this role? Or will it completely vanish? Check out this post from Caleb Sima of Whiterabbit for the discussion that is the basis of our conversation on this week's episode co-hosted David Spark , the producer of CISO Series, and Yaron Levi , CISO, Dolby Laboratories . Joining is Adrian Ludwig , CSO, Rippling . Thanks to our podcast sponsor, ThreatLocker . The messy middle The challenge facing detection engineering teams goes well beyond writing better rules. "The problem isn't just context and predicting what types of possible threats exist, and it's also not just creating detection rules," said Fred Wilmot of Detecteam . "It means we also have to be able to accurately and completely represent what happens to that contextual value." That scope extends well past detection engineering, he said, into "change management, audit, data provenance, and governance." Meny Har of Spectrum Security described the current model as "entirely unsustainable." The sharpest people on security teams are spending 70% of their time in what he calls the "Messy Middle" — "reconciling threat behaviors with log realities and legacy SIEM logic." Compress that time-to-coverage from weeks to minutes, he said, and the game changes. The 2030 team, in his view, isn't a skeleton crew. "It's a full team of senior practitioners who have transitioned from being mechanics to being conductors. They will direct a fleet of agents to handle the 'Messy Middle' of syntax and tuning, giving them the actual bandwidth to tackle that adversary frontier." The automatable part Cutting detection engineers because AI can handle triage misreads the evidence. Mike McCabe of Cloud

New <b>cybersecurity</b> committee follows years of attacks without preventive requirements

At a time when municipal water systems in seven states have suffered cyberattacks, the need to guard against malicious hacking has taken on greater urgency. Mississippi’s hospitals and other institutions have meanwhile been subjected to their own run of attacks, yet for years the state has not required the facilities to defend against them. Against that backdrop, Lt. Gov. Delbert Hosemann has created a Senate Select Committee on Cybersecurity to study the security of state and local government computer systems and review how Mississippi prosecutes cybercrime. Hosemann points to the most severe recent Mississippi case, in February 2026, when a ransomware group that security researchers link to Russia took the University of Mississippi Medical Center offline for more than a week, which resulted in the closure of its clinics, forced doctors to work with pen and paper, and demanded an $800,000 ransom. The FBI and the Department of Homeland Security joined the recovery in that case. UMMC houses the state’s only children’s hospital, its only Level I trauma center and its only organ transplant program. Hosemann said cybercrime costs the state hundreds of millions of dollars. The medical center was the fourth Mississippi hospital system hit in three years. A 2023 ransomware attack on Singing River Health System in Ocean Springs exposed the health information of nearly a million people. North Mississippi Health Services and OCH Regional Medical Center in Starkville were struck the same year. UMMC had been breached before that. A decade ago, it paid $2.75 million in federal fines after the 2013 theft of a laptop exposed about 10,000 patients’ records, and federal investigators found the center had known of the vulnerability since 2005 and left it unaddressed. Through all of this, Mississippi has had no state law requiring hospitals to guard against cyberattacks. Only the federal

CMMC review: DoD's inconsistent CUI marking continues to plague program

While there are differing opinions about how the Pentagon could improve the Cybersecurity Maturity Model Certification program, most organizations agree the Defense Department’s inconsistent and unclear process for marking controlled unclassified information continues to be a critical problem driving CMMC costs and confusion. In comments filed to the CMMC Reform Task Force, multiple industry groups highlighted CUI identification and marking as one of the main cost drivers of the cyber evaluation program. The Pentagon has paused CMMC third-party assessment requirements to address cost and compliance concerns, especially for small businesses. CUI is sensitive government data that doesn’t meet strict criteria for national security classification, but still requires special protection and handling controls under federal laws or policies. CMMC is intended to verify whether contractors are protecting CUI in line with federal cyber standards. But industry organizations say both DoD and prime contractors often improperly mark CUI or apply blanket CMMC requirements across subcontractors, regardless of whether companies will handle CUI. They say that in turn requires companies, including smaller firms, to unnecessarily comply with costlier CMMC standards. The Office of Advocacy, an independent organization within the Small Business Administration, highlighted CUI uncertainty as the “most frequently cited concern” for small businesses when it comes to CMMC. “This uncertainty has downstream consequences,” Advocacy wrote in reply to the CMMC Reform Task Force’s request for information. “When a contractor cannot confidently determine what information is CUI, they will generally err on the side of including all of it into their compliance boundary. Small businesses expressed numerous times that CUI is being overmarked, inconsistently marked, or improperly flowed down through the supply chain.” The office said DoD in some cases has even treated publicly available information as CUI. Likewise, the National Defense Industrial Association said its members have identified “multiple instances where inconsistencies,

AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

U.S. authorities on Wednesday warned of an AI-fueled campaign that attempts to exploit vulnerable Siemens S7 devices across multiple industries, including energy, water, critical manufacturing, agriculture and, potentially, the defense industry. The FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency said in an advisory that hackers are conducting reconnaissance and gathering other information about Internet-exposed S7 programmable logic controllers. Many of the targeted devices run out-of-service software or are otherwise vulnerable to attack. As part of the campaign, attackers are using AI-generated exploitation scripts disguised as legitimate monitoring software. They employ AI to generate code to gain initial access, pilfer credentials, and execute denial-of-service and other nefarious actions. Depending on the specific circumstances, exploitation of these tools could lead to the “disruption of critical industrial processes, safety incidents, downtime or equipment damage,” among other impacts, according to the advisory. The hackers are targeting variants of Siemens S7-200, S7-200, S7-400, S7-1200 and S7-1500 Series PLC models. Recent Iran-linked cyber activity The advisory follows a wave of recent cyber threat activity linked to Iran-nexus actors against drinking and wastewater facilities. Authorities in July warned about exploitation of vulnerable PLCs from Rockwell Automation, Schneider Electric and Siemens S7-1200 devices. U.S. authorities suspect that Iran-nexus threat actors are behind a wave of cyberattacks against water systems across at least 12 states. Operators at those sites were cut off from their monitoring equipment and locked out of their own password-protected systems. It is not immediately clear whether the latest PLC attacks came from the same Iran-backed threat groups or if other hackers have begun targeting PLCs as well. Security teams should ensure their current firmware versions are updated to the latest versions and apply security patches as well as check for known vulnerabilities, enable multifactor authentication and confirm that PLCs are

University of Memphis AI, <b>cybersecurity</b> conference focuses on Mid-South's future in tech

University of Memphis AI, cybersecurity conference focuses on Mid-South’s future in tech Published: Aug. 19, 2026 at 3:28 PM CDT|Updated: 10 hours ago MEMPHIS, Tenn. (WMC) - Artificial intelligence is rapidly changing the way businesses and organizations operate and creating new cybersecurity challenges. The University of Memphis is hosting the AI and Cybersecurity Conference 2026 on August 27, bringing together leaders to discuss innovation, security and the future of AI in the Mid-South. Parker King spoke with Dr. William Duffy, director of Applied AI at the University of Memphis on the Digital Desk, about what this conference means for the region. Click here for more information. Click here to sign up for our newsletter! Click here to report a spelling or grammar error. Please include the headline. Copyright 2026 WMC. All rights reserved.

T-Mobile 'chopped a cable' to expel Chinese hackers from its network | TechCrunch

New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data. The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon. The campaign compromised hundreds of phone companies, internet giants, and data center providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream. By and large, T-Mobile escaped a widescale breach of its network by catching the activity early — and resorted to physically cutting the cable to a compromised system, per Bloomberg. The publication said T-Mobile’s cyber staff spent months looking for suspected hackers in its network without success. Eventually, the company found unusual behavior on one of its systems coming from another router belonging to a different telecom company, which T-Mobile did not name. After identifying the breach, T-Mobile’s cybersecurity chief, Jeff Simon, told Bloomberg that he and three others drove to the data center nearby to its Bellevue, Washington headquarters, found the compromised system, pulled out a set of scissors, and snipped the cable connecting the box to the outside world. When reached by TechCrunch, T-Mobile did not provide comment.

CrowdStrike Sinks 7% Despite Truist Price Target Raise to $245, Palo Alto Networks Falls 5%

Although the NASDAQ 100 is trading slightly in the green, CrowdStrike (NASDAQ:CRWD | CRWD Price Prediction) stock is down 7% to $198.99 midday Wednesday. The decline comes even after Truist raised its price target on the stock sharply ahead of next week’s earnings. Palo Alto Networks (NASDAQ:PANW) stock is also down 5% to $355.54 in the same session. The selloff pulls in CrowdStrike and Palo Alto Networks on a day with no company-specific catalyst identified. Broad software and technology selling appears to be driving the move, and cybersecurity software is falling with the broader complex rather than acting as an obvious safe haven from AI-hardware rotation. CrowdStrike stock is up 82% year to date through Tuesday’s close. Palo Alto Networks stock is up 103% over the same window. Both names have run hard into a crowded earnings week, and today’s drawdown is happening from elevated multiples that leave little room for disappointment. The Truist note leans into that setup constructively for CrowdStrike, yet the stock is trading as if positioning matters more than fundamentals ahead of earnings. Traders may want to keep an eye on whether the pre-earnings drift extends into next week or resets before the release. Truist Raises Targets but Prefers Smaller Names Truist analyst Junaid Siddiqui raised CrowdStrike’s price target to $245 from $187.50 while keeping a Buy rating. The firm called cybersecurity spending resilient overall and described the CrowdStrike setup as “constructive” heading into earnings. Siddiqui also raised Rubrik’s price target to $135 from $90, and SailPoint’s price target to $23 from $18, both Buy-rated, as part of an off-cycle software earnings preview. Truist named Rubrik and SailPoint its preferred cybersecurity picks, calling both positioned for “beat-and-raise quarters.” The firm’s core thesis is that enterprise cyber budgets are concentrating on identity security, cyber resilience, AI governance,

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims," Check Point Research's Jaromír Hořejší said. The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026. The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders. This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. That said, it's worth noting that the operation does not always result in ransomware deployment. In most cases, the threat actors have been observed covertly stealing lists of files and then specific files from the systems. The operation is supported by a cluster of hacked WordPress sites that serve multiple functions - - Host malware stages - Run as command-and-control (C2) servers to send instructions - Store logs exfiltrated from victims Check Point said it was able to glean more insights into the campaign due to the threat actor's operational security blunders that exposed detailed infection logs and screenshots from victim machines, as well as the tools used to mass-manage compromised websites. As many as close to 2,000 WordPress sites are estimated to have been hacked as part of the campaign. Most of the sites