In partnership with

~8 MIN READ
Fact A single unauthenticated endpoint in Ruflo, an open source AI agent platform with 67,000+ GitHub stars, exposed 233 tools, letting anyone execute shell commands, steal API keys, and spawn unauthorized agent swarms with no login required. CVSS 10.0. (SecurityWeek, July 2026)
The Signal
 
Nothing says "critical infrastructure is still an afterthought" like 30 water utilities getting hit in the same 48 hours with nobody, including the utilities themselves, having a clear answer for who did it or why. This week's stories share one thread: the danger isn't always a sophisticated attacker, it's a system nobody was watching closely enough, whether that's an OT network, an AI agent's permission settings, or a rival ransomware gang's own operational security.

PS — Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
CRITICAL INFRASTRUCTURE
💧 A Coordinated Cyberattack Hit 30+ Minnesota Water Utilities. One Plant Went Dark.
Intro
Somebody targeted operational technology at more than 30 Minnesota community water systems at once, and more than a week later, nobody's said who or why.
What Happened
Malicious actors hit OT systems across 30+ water utilities statewide on July 26 and 27, knocking the City of Braham's water plant fully offline and disrupting communications and automated controls at Maple Plain and other communities. Minnesota IT Services (MNIT) activated the state's cybersecurity incident response capabilities, coordinating with federal, state, local, and Tribal partners to help utilities contain and investigate the damage.
Why It Matters
Water treatment is about as basic-services as critical infrastructure gets, and a coordinated hit across 30+ separate utilities in a 48 hour window suggests either a shared vulnerability being mass exploited or a genuinely organized campaign, not opportunistic scanning.
The Other Side
Braham's plant was back online within hours, treating water normally, and MNIT says it isn't currently aware of any active requests for residents to change their water usage. No attacker has claimed responsibility, and officials haven't attributed it to a specific group.
 
👉 Takeaway
If your organization runs OT alongside IT, this is the week to confirm that segmentation actually holds and that your incident response plan covers "we don't know who did this or why" as a starting state, not an edge case.
TL;DR: Unknown attackers hit OT systems at 30+ Minnesota water utilities in 48 hours, knocking one plant offline; the investigation is ongoing and nobody's claimed credit.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
DATA BREACH
ShinyHunters says it vished its way into Brinks Home's Microsoft Entra environment on July 13, convincing an employee to complete an authentication step that handed over account access. The group claims roughly 4.9 million Salesforce records, including 1.1 million customer contact rows, 3.8 million support chat logs, and over 4,000 employee PII records. Brinks Home, which generates roughly $830 million in annual revenue and serves over a million customers, discovered the intrusion July 20 and says alarm monitoring and system functionality weren't affected. The company has not yet confirmed exactly whose data was involved and is warning customers about potential fraudulent messages impersonating the brand.
Vishing works because it targets what MFA can't automate: a person's judgment under pressure. Retrain, don't just deploy.
 
HEALTHCARE BREACH
CareCloud, which handles records for over 45,000 providers nationwide, is notifying at least 345,000 people that hackers accessed one of its AWS-hosted health record databases for at least six days back in March. Stolen data includes names, Social Security numbers, government IDs, bank account and payment card details, and medical information. CareCloud disclosed the breach in March but only recently filed the fuller details with state attorneys general, and the number is expected to keep climbing as more state disclosures are filed. The breach is part of a broader 2026 pattern of major healthcare-sector incidents, including separate breaches at TriZetto and NYC Health + Hospitals this year.
Check notification letter dates closely. Disclosure timelines keep getting longer, not shorter.
 
DATA BREACH
Suno, the AI song generator, suffered a breach back in November 2025 that exposed names, addresses, emails, phone numbers, purchase history, and partial card details for 55.3 million users, but never disclosed it. The public only learned through Have I Been Pwned after 404 Media obtained the leaked data. The same leak exposed Suno's source code, which reportedly confirms the company scraped millions of songs and lyrics from streaming platforms, now the subject of ongoing copyright litigation by major record labels. Suno co-founder Mikey Shulman did not respond to requests for comment before the breach became public.
An undisclosed nine month old breach is its own story. A validated copyright case is a bonus nobody at Suno wanted.

Try the AI that knows your customers. No commitment.

Most platform evaluations start with a demo request and end three weeks later in a conference room. This one takes 15 minutes and puts you directly inside Gladly's interface — navigating it on your own terms.

See how AI surfaces real-time customer context before a conversation starts. Watch how a single conversation thread pulls in purchase history, channel history, and account details without a handoff.

No installation. No commitment. Start the interactive demo and see the platform for yourself.

🤖 AI in Cyber
 
 
AI SECURITY
Ruflo, an open source AI agent orchestration platform with over 67,000 GitHub stars, shipped an MCP bridge exposing 233 tools through an unauthenticated endpoint that let anyone execute the terminal_execute command and get shell access as the node user inside the container. CVSS 10.0. Attackers could pull provider API keys, spin up unauthorized agent swarms on the victim's own credentials, and inject corrupted patterns into the platform's shared AgentDB learning store, poisoning outputs across every user. It's patched now in version 3.16.3, but the bug lived for an unknown period in a tool built specifically to run autonomous multi-agent swarms with persistent memory.
Running agent orchestration tooling? Audit auth on every exposed endpoint, not just the ones you remember configuring.
 
AI-ASSISTED EXPLOIT
Security researcher Lee Jia Jie used AI to help discover, build a proof of concept for, and optimize the timing window on a use after free race condition in the Linux kernel's traffic control subsystem (CVE-2026-53264), converting an unprivileged user to root on CentOS Stream 9 in as little as 9 seconds, succeeding in all 10 test runs. The upstream fix landed June 1, 2026, with patches available for kernel versions 5.10.259 through 7.0.13, though distro patch status remains uneven across Debian, Ubuntu, and SUSE. Lee noted AI "still has many blind spots" and human judgment stayed necessary throughout, but the assist clearly sped up the harder parts of the work. Reporter Kyle Zeng disclosed the flaw ahead of the TyphoonPwn 2026 competition.
AI-assisted exploit development is routine enough to get a byline now. Patch faster than the researchers publish.
🏛️ Privacy, Power & Policy
 
 
STATE POLICY
New York's SAFE for Kids Act now has final rules: platforms must default minors to chronological, non-algorithmic feeds and block overnight notifications between midnight and 6 a.m. without parental opt-in, using privacy preserving age verification methods beyond just uploaded government ID. Rules take effect January 25, 2027; violations carry civil penalties up to $5,000 each, and age data must be deleted or de-identified immediately after use. Platforms must also run annual testing of their age assurance methods and retain results for at least 10 years.
If your platform serves New York minors, start scoping the engineering work now, not next quarter.
 
FEDERAL POLICY
Industry groups used recent CISA town halls to push back on the pending CIRCIA rule, which would require critical infrastructure owners, an estimated 300,000+ entities, to report major incidents within 72 hours and ransomware payments within 24. Complaints centered on scope creep and unclear thresholds for what counts as a "covered" incident versus routine recon, with groups like the Auto Care Association and AHIP pushing for narrower scope and data minimization. CISA has already missed two prior deadlines, October 2025 and May 2026; a September 2026 target now looks shaky too.
Start building the internal reporting workflow now. Waiting for the rule to finalize means building it under a deadline instead of your own timeline.
🛠️ Tools & Tactics
 
 
Practical play
CVE-2026-42533 is a heap buffer overflow in nginx's regex based map directive handling that can crash worker processes or potentially allow remote code execution, CVSS 9.2, affecting versions 0.9.6 through 1.31.2. It's been patched since July 15 in nginx 1.30.4 and 1.31.3, but a full chain proof of concept exploit went public in late July, making unpatched instances a live target. Can't patch immediately? A GitHub scanner can flag configs using numbered capture groups alongside affected map variables, a workable but incomplete stopgap until you can upgrade.
Check your nginx version today. Anything before 1.30.4 or 1.31.3 is this week's patch, not next sprint's.

The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.

🧪 Strange Cyber
 
A hacker gloats as a rival ransomware gang's leak site displays a neon orange apology message instead of a ransom demand
Strange but real
🤝 A Ransomware Gang Extorted a Rival Ransomware Gang, Then Apologized on Its Victim's Website
Intro
This one's from April, but "criminals extorting other criminals" doesn't get old fast enough to skip. The 0APT ransomware gang went after a rival outfit called Krybit, and things got petty in a way that only makes sense between two groups who've already given up any claim to a code of honor.
What Happened
0APT threatened to expose Krybit's operators' identities, photos, names, and locations unless paid, posting sample data as proof, all while framing Krybit as a group that "poses significant risks to cybersecurity and data privacy." Security researcher Eric Taylor's team found plaintext credentials for Krybit's own operators and affiliates, plus crypto wallet addresses, in the leaked files. Krybit's site went dark and came back up with an apology message.
Why It Matters
Extortion works because reputational and legal exposure carry real weight, and that leverage evaporates fast when your target is already a criminal enterprise with nothing left to protect. It's a useful reminder that "we'll expose you" only works on people who have something to lose from exposure.
The Other Side
This isn't new behavior. DragonForce hit rival gangs BlackLock and Mamona in 2025 before eventually shutting down RansomHub's operations entirely, so criminal-on-criminal attacks are becoming a recognizable pattern, not a one-off.
 
👉 Takeaway
Even if you'll never negotiate with a ransomware gang, it's worth remembering that these groups have their own operational security failures, internal rivalries, and sloppy credential hygiene. They're not the disciplined monoliths the leak sites make them look like.
TL;DR: Ransomware gang 0APT extorted rival gang Krybit, leaked its operators' credentials, and got a public apology posted on Krybit's own site in return.
Further reading: The Register

You already follow the model launches, benchmarks, and breakthroughs. Now trade on what happens next. Explore real-world AI and tech markets on Kalshi. Trade $25, get up to $500.

Keep Reading