Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Russian Hackers Use Exchange Zero-Day in Email Attacks

  Russia-aligned cyberespionage group Laundry Bear, also tracked as Void Blizzard and TA488, is exploiting a Microsoft Exchange Outlook Web ...

All the recent news you need to know

Iran-Linked Hackers Suspected in Cyberattacks Targeting Minnesota Water Systems

 

Several water systems in Minnesota were under attack from cyber intruders over the weekend. Investigators believe the attacks were launched from an Iranian hacking group called CyberAv3ngers. The attacks targeted approximately 30 water systems in Minnesota on Sunday and Monday and caused a brief interruption in the water supply for one community. 

The most significant attack was in the small town of Braham, located in the Minneapolis area, which was without water for two hours due to a cyberattack. The water supply was cut off, but it was quickly restored. Cybersecurity firm Tenable indicated that the attack methods used were similar to those previously used by the Iranian hacking group. US authorities are investigating whether Iran was behind the cyberattack on the water systems in Minnesota. 

However, officials do not believe that the attacks in Minnesota were carried out by Iran or that the attacks were orchestrated by the group CyberAv3ngers. The attacks in Minnesota occurred shortly after the US Cybersecurity and Infrastructure Security Agency issued an alert about attacks launched by Iran’s proxies on internet-connected systems controlled by infrastructure operators. This warning highlighted the potential for such groups to target critical infrastructure. Water utilities may be particularly vulnerable to such attacks since they use internet-connected machines to control and monitor operations. 

A relatively small amount of protection of these machines can allow hackers to intervene in the functioning of critical infrastructure, even if they cannot access the main corporate IT system. CyberAv3ngers has been accused of targeting industrial control systems by various companies, including water utilities, in the past. This hacking group has attracted increased attention from US authorities due to its suspected Iranian origin and potential access to critical infrastructure. The attack on Minnesota water utilities is part of a wave of cyberattacks launched against the US and its allies. 

Another hacking group, Handala, claimed to have attacked the medical equipment company Stryker and the payment processing company Verifone. Stryker confirmed that it was a victim of a cyberattack, while Verifone rejected the accusations. The group Handala claimed that it carried out these attacks in retaliation for the US-Israeli military operation against Iran. The attack by Handala was reportedly in response to the assassination of an Iranian military commander and the bombing of a school in Iran, which resulted in the death of more than 150 people. 

The US military investigation concluded that the attack on the school in Minab was due to the “inadvertent engagement” of the school by US aircraft, which was targeting a military installation. The attacks on the water utilities in Minnesota illustrate the potential for geopolitical tensions to spill over into attacks on critical infrastructure. Even though it is unclear whether the attacks in Minnesota were launched by Iran, the fact that they were able to occur highlights the need for increased protection of internet-connected infrastructure equipment, as well as monitoring and rapid response systems.

Apple Warns of Supply Crunch as Demand Surges

 

Apple’s issue is a supply crunch: strong demand for iPhones and Macs is outpacing the company’s ability to secure key components, especially advanced chips and memory. The BBC report says Apple warned this could hit revenue in the coming months and that supply constraints are already limiting flexibility in the chain. 

What is happening 

Apple said the core problem is not weak demand but the opposite — sales are running hotter than expected, particularly for iPhone and Mac products. The company described the supply situation as “very significant,” with little room to quickly fix it. That means Apple can sell more devices than it can comfortably produce, which creates delays, pressure on inventory, and a risk of missed sales. 

The shortage affects some of Apple’s most important products, so even a strong quarter can come with a weaker outlook. Apple’s shares fell after the warning because investors tend to react sharply when a company says future growth may slow. The BBC also noted that Apple has already raised prices on some products, showing how supply costs are beginning to affect customers.

A major part of the problem is the cost and availability of memory chips, which have surged in price due to broader industry demand, including AI-related hardware needs. Reuters reported that Apple is also dealing with bottlenecks in advanced chipmaking technology used in its Apple silicon chips. In practical terms, this means Apple may have to pay more for parts, accept tighter margins, or pass costs on to buyers. 

Financial impact 

Despite the warning, Apple’s recent results were still strong, with iPhone and Mac sales rising sharply. But the company signaled that the next quarter may not keep pace if component shortages persist. That is why the story is less about a current collapse and more about a future squeeze on growth. 

Apple’s problem reflects a bigger technology trend: demand for chips is rising across consumer devices and AI infrastructure at the same time. When a company as large as Apple struggles to source parts, it often signals pressure across the wider electronics supply chain. In this case, the issue is a mix of extraordinary demand, limited supply flexibility, and rising component prices.

Trump Memo Signals New U.S. Push to Disrupt Foreign Cybercrime Groups


The memo from the White House signed by President Donald Trump will increase the role of cybersecurity companies in fighting foreign criminal organizations that operate across borders. The National Coordination Center will be responsible for developing a program that allows government-approved cyber activities against these groups. 


According to the plan authorized American companies could carry out approved cyber monitoring and cyber impact missions against targets linked to these criminal groups while being watched by the government. 

Information systems and infrastructure might be affected during these activities, including the loss of data. With this effort the government wants to improve how it deals with cybercrime, fraud and other illegal acts that affect American people. Working with the Department of Justice the Department of Homeland Security will set up and run the program through the National Cyber Security Council. 

Companies involved in the program must have an escrow or a bond of least one million dollars and must operate with the required government permissions. The plan encourages sharing information, between businesses and government agencies at every level, including federal, state, local, tribal and territorial authorities to spot possible cyber threats and develop ways to deal with them. The issue of companies being involved in offensive cyber activities is a big deal. This has caused people to worry about things getting out of hand someone getting hurt by mistake and the government and private companies having trouble working together. 

The program is only going after foreign cyber crime groups that want to hurt the United States government, American people or American interests long as these groups do not work for a foreign government. A company has to stop what it is doing if it does something it is not supposed to do, like going after people or systems. 

The company also has to tell the NCC about this so they can send it to the Justice Department. This is part of a program started by the White House in March to deal with criminal groups from other countries that are involved in ransomware, malware, phishing, financial fraud, sextortion, impersonation and pig butchering schemes. 

The White House said that American people have lost a total of $20.8 billion because of cyber crimes. If a company wants to be part of this it has to follow some strict rules. The private sector participation in cyber activities has to be done carefully. Private sector participation, in cyber activities is a serious matter. 

Along with sharing information about threats with businesses and government groups companies that take part might also suggest actions that need permission from the federal government. This policy has started conversations about how much the business world should be involved in taking offensive actions in the cyber world. Someone who supports the program sees it as a chance to use skills from the private sector to fight more powerful criminal groups.

Someone who is against it warns that having more businesses take part in offensive actions could lead to legal problems more chances of things getting worse and results that were not expected. Cyber crime is a problem that affects governments everywhere. 

German intelligence groups have also taken steps to make their own groups stronger so they can stop the cyber networks of enemies. This shows that governments are becoming more ready to use ways to protect themselves and take action. A memo from the time of the Trump administration shows a change in what private cybersecurity companies will do, in the future. 

If the framework can really stop criminal networks without going against the law or making new security problems then how it is watched over and approved will be very important to how well it works. The United States is showing a change in how it deals with cybercrime by doing this. It is clear that the government and private cybersecurity companies need to work to stop cyber threats. 

Several things will decide if this works, such as making sure someone is watching over it following the law and taking steps to avoid things going wrong. The framework needs to be good at stopping criminal networks. The framework will be important to the United States and its plan to deal with cybercrime. The framework and its oversight and authorization processes will be crucial, to its success.

GeoServer Zero Day Being Probed While No Patch Available


A newly found GeoServer zero-day is already receiving active exploitation efforts, while there is no patch ready yet. Firms using the open-source geospatial platform should keep an eye out for their exposure. 

A cybersecurity expert with the handle q1uf3ng found the vulnerability which has not been given any CVE identifier yet.

Zero-day with no patch

The vulnerability exists in the jsonArrayContains functionality and permits illegal SQL injection. In few configurations, particularly where the flaw can reach a privileged database account, that path may result in remote code execution. The vulnerability has not been given any CVE identifier yet. 

The flaw was publicly revealed on 12 August 2026. Soon after, watchTowr said it started noticing exploitation attempts, with hundreds of attempts coming from a few IP addresses. According to WatchTowr’s Jake Knott, “Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses. Yet another example of how quickly attackers move once a vulnerability enters the public domain.”

The timing is crucial here. When enough technical information or proof of concept is public, threat actors don’t have to wait for a well planned exploit. They can compare responses, scan broadly, trigger errors, and make a list of devices to visit later. It is spying with an error message as a compass.

Cyber criminals are probing the flawed GeoServer systems, but no confirmed exploit has been found yet. But experts have warned that exploitation could soon happen. 

According to Knott, “However, this is unlikely to remain the case for long: GeoServer has a track record of being targeted and exploited at scale, with multiple vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog. With no patch currently available and exploitation already underway, organizations running GeoServer should take this vulnerability seriously and, where possible, identify exposed instances, restrict public access, and monitor for a vendor fix.”

Threat actors are triggering errors to find vulnerable targets before active exploitation, and probing GeoServer systems for unpatched zero-day.

About GeoServer

A well-liked framework for exchanging and publishing geographic data via web services is called GeoServer. Public sector portals, environmental platforms, mapping initiatives, utilities, transportation systems, academic institutions, and internal corporate applications are some of the places where it can be found. Because of this, a remotely reachable instance becomes more than just a technical detail; it may provide credentials, backend services, geographic data, or a path to a larger network.

Hackers Steal 607,000 Records in Cyber-Attack on UK Department for Education

 



Hackers have stolen around 607,000 records from England's Department for Education (DfE) after compromising systems used to handle enquiries and administer international education funding.

The department confirmed the cyber incident after attackers accessed data held through the DfE's online help desk and the portal supporting the Turing Scheme. The compromised information includes telephone numbers and email addresses associated with individuals and organisations that had interacted with the department.

Reports have also identified names and job titles among the exposed information, including details belonging to school leaders, university staff and government officials. However, the DfE said the affected information was limited to customer-service contact details and that bank details and other sensitive information were not accessed.

The department has stressed that the figure of 607,000 refers to records rather than the number of individuals affected. A single person or organisation may therefore account for multiple records across the affected systems.


Social Engineering Reportedly Used Against DfE Helpdesk

The breach reportedly involved a social-engineering attack against an external-facing DfE helpdesk used by education-sector organisations and local authorities.

Computer Weekly reported that the attackers targeted the department's helpdesk and obtained more than 600,000 records containing personally identifiable information, while the affected systems were taken offline as the department investigated the incident. The Times also reported that it had verified the authenticity of some of the leaked information.

The incident illustrates why customer-facing systems can represent an attractive target. Helpdesks routinely process legitimate requests from large numbers of users and may contain historical enquiries and account-linked information. If an attacker can manipulate a support process or gain access to an account with sufficient privileges, information held outside an organisation's core systems can become exposed.

The DfE has not publicly disclosed a complete technical account of how the attackers gained access or which specific vulnerability was exploited. It would therefore be premature to attribute the breach to a particular software flaw or compromised credential without further evidence.

A group calling itself ExfilSquad has claimed responsibility for the attack and has reportedly published or advertised stolen information online. The group's claims should be treated as claims by the alleged attackers, although multiple reports have examined samples of the data and reported that some information was authentic.


DfE Moves to Contain the Incident

The DfE said it acted quickly after identifying the incident and has been working with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) to establish what happened and assess the impact.

The department has also referred itself to the Information Commissioner's Office (ICO), the UK's data protection regulator.

A DfE spokesperson said the department had "robust processes" to protect information and had taken swift action to contain the incident. The department maintained that the information involved was restricted to customer-service contact details and that no other data had been accessed.

The NCA separately confirmed that it was aware of the incident and was working with partners to understand the circumstances and its impact.

The DfE has also temporarily affected the operation of the services involved while remediation work is carried out. Reports said the department switched to telephone support while the affected systems were being addressed, with normal operation expected to resume after the disruption.

The department has assessed the data-protection risk to affected individuals as low. However, the exposure of professional contact information can still create opportunities for follow-on attacks, particularly phishing and impersonation campaigns that use legitimate names, job titles, organisations or previous interactions to make fraudulent communications appear credible.


Education Sector Continues Being Prime Target

The DfE breach comes as education organisations across the UK continue to report high levels of cyber incidents.

The latest UK government's Cyber Security Breaches Survey 2025/26 found that 49% of primary schools, 73% of secondary schools, 88% of further-education colleges and 98% of higher-education institutions had identified a breach or cyber attack during the previous 12 months. The comparable figure for UK businesses was 43%.

The frequency of attacks was also high among colleges and universities. Around 24% of further-education colleges and 29% of higher-education institutions reported experiencing a breach or attack at least weekly. The survey found that 14% of primary schools and 20% of secondary schools experienced attacks at least weekly.

Phishing remained the dominant threat. Among institutions that had identified a breach or attack, 90% of primary schools and 96% of secondary schools reported phishing incidents. The same figure was 96% for further- and higher-education institutions combined.

The government survey also identified higher levels of other attack types across further and higher education. These included impersonation, reported by 79% of affected further- and higher-education institutions, viruses, spyware or malware at 51%, and denial-of-service attacks at 49%. Unauthorised access to files or networks by staff was reported by 29%, while 23% reported unauthorised access by students.

The consequences extend beyond the initial compromise. Almost half, or 49%, of further- and higher-education institutions that identified a breach or attack reported at least one negative outcome for their systems. Compromised accounts or systems being used for illicit purposes accounted for 23%, while 16% reported websites, applications or online services being slowed or taken down and 14% reported losing access to files or networks.


Contact Data Can Become a Launchpad for Further Attacks

Although the DfE maintains that highly sensitive information was not accessed, the exposed records still have security implications.

Names, job titles, work email addresses and telephone numbers can provide attackers with the information required to make subsequent phishing or impersonation attempts appear legitimate. A message addressed to a known employee, referencing their role or organisation, can be considerably more convincing than an unsolicited generic email.

This risk is particularly relevant in education, where senior school leaders, university staff and government officials may have access to wider organisational systems or sensitive information.

The latest government survey indicates that impersonation is already a recurring problem in the sector. Among further- and higher-education institutions that identified breaches or attacks, 79% reported attempts involving people impersonating their organisation or staff.

The DfE incident therefore demonstrates that the consequences of a data breach do not necessarily end when the initial intrusion is contained. Exposed contact information can potentially become useful in later social-engineering campaigns, while disruption to public-facing services can continue during investigation and recovery.

For organisations handling large volumes of education-sector data, securing customer support infrastructure is therefore part of protecting the wider attack surface. Access controls, strong identity verification, monitoring and rapid incident response can limit how far an attacker can move after compromising an externally accessible service.

The DfE investigation remains ongoing, with the department working alongside the NCSC and NCA and having notified the ICO. The full circumstances of the intrusion, including how the attackers gained access and the precise extent of the exposed information, are expected to become clearer as the investigation progresses.

Here's How to Secure Your SSO Against Credential Attacks

 

Single sign-on (SSO) has transformed how employees access business applications by allowing one account to authenticate users across multiple services. However, this convenience also creates a concentrated security risk: if attackers compromise the central login, they may gain access to email, VPNs, customer-management platforms, file storage, and other sensitive systems. The 2025 University of Pennsylvania breach demonstrated how a compromised PennKey SSO account could provide access to several internal services and expose information belonging to 1.2 million individuals. SSO is not inherently insecure, but it must be treated as a critical security control rather than a simple convenience feature. 

Strong password policies remain an important foundation for protecting SSO accounts. Current NIST guidance recommends passwords of at least 15 characters when they are used without additional authentication, while passwords used with multi-factor authentication (MFA) may be at least eight characters. Organizations should permit passwords of up to 64 characters and compare new passwords against lists of commonly used or previously compromised credentials. At the same time, businesses should reconsider frequent mandatory resets and rigid complexity rules, which can encourage predictable habits such as adding a number to an old password. 

 MFA should be enforced consistently for every user, application, and access scenario—not only for administrators or accounts considered high risk. SMS codes and basic one-time passwords provide more protection than passwords alone, but phishing-resistant technologies offer stronger defenses against modern credential theft. FIDO2 security keys, WebAuthn, and passkeys can help prevent attackers from capturing authentication data through phishing pages or infostealer malware. These methods are particularly valuable for privileged accounts and systems containing sensitive information. 

Organizations must also protect the infrastructure supporting their SSO environment. Identity-provider administrator accounts should use separate privileged identities, phishing-resistant MFA, just-in-time access, and continuous monitoring. SAML certificates, token-signing keys, OAuth secrets, application credentials, and refresh tokens should be stored securely, rotated regularly, and restricted to authorized personnel. Security teams should review application registrations, delegated permissions, and user-consent grants to remove stale or excessive access that attackers could exploit for persistence. 

When properly implemented, SSO can improve security by reducing password reuse, limiting password exposure across applications, centralizing access policies, and simplifying account deactivation when employees leave. It can also reduce help-desk requests caused by forgotten passwords and make compliance reporting easier. Nevertheless, SSO is not secure by default. Organizations should combine strong password screening, universal phishing-resistant MFA, hardened administrator accounts, controlled recovery procedures, careful application permissions, and regular monitoring to ensure that one compromised credential does not become a gateway to the entire enterprise.

Featured