In partnership with

~7 MIN READ
Fact A CISA contractor's public GitHub repo exposed 844 MB of the agency's own credentials, including admin logins to three AWS GovCloud servers, for nearly six months, even after nine automated alerts went unread. (Krebs on Security, July 2026)
The Signal
 
This week the machines started doing more of the hacking themselves, and the humans in charge are still catching up. Here's what changed, what got worse, and one thing you can fix before lunch.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
CRITICAL INFRASTRUCTURE
🤖 AI Is Now Writing the Exploit Code for Attacks on Power and Water Plants
Intro
Five federal agencies just confirmed what researchers have been dreading for two years: attackers are using AI to write working exploit code against the equipment that keeps the lights and water running.
What Happened
NSA, CISA, FBI, DOE, and EPA issued a joint advisory (AA26-231A) warning that unidentified attackers are using AI-generated scripts, disguised as monitoring tools, to gain read-write access to Siemens S7 programmable logic controllers across water, energy, manufacturing, and agriculture. The agencies call it "an evolution in threat actor capabilities" that slashes the skill needed to build a working ICS exploit.
Why It Matters
PLCs run the physical machinery behind critical infrastructure, and AI just erased the expertise barrier that used to protect them. Officials call this an active threat happening now, not a future risk.
The Other Side
No attribution to a specific nation or group yet, and no confirmed disruption, just reconnaissance and capability-building against exposed Siemens S7 gear specifically.
 
👉 Takeaway
If your org runs internet-facing OT, get it off the public internet and onto a segmented network today. This is exactly the exposure AI-assisted attackers are now built to find fast.
TL;DR: Feds warn AI is writing real exploit code against power and water plant controllers; no attribution yet, but the threat is active now.
Further reading: The Record
🚨 Can't Miss
 
 
THIRD-PARTY BREACH
Quest Apartment Hotels confirmed a breach after a third-party database operator's vulnerability exposed guest names, contact details, and some birth dates across 120+ properties in Australia, New Zealand, and Fiji. Quest hasn't disclosed how many guests were affected.
Ask your vendors what "third-party database operator" means for your own exposure. Most companies can't answer that.
 
HEALTHCARE BREACH
Toronto's Hospital for Sick Children disclosed a second major incident, this one tied to a third-party software vulnerability. Stolen data covers current and former employees and job applicants; no clinical systems or patient records were touched. The hospital was previously hit by ransomware in 2022.
Healthcare vendor risk assessments need to cover the software your vendors use, not just the vendors themselves.
 
HIGHER ED
UT San Antonio pushed back the first day of classes by three days after catching intrusion activity on its academic network. The activity was stopped at the network edge before reaching core systems; officials found no evidence data was taken. Phones and password resets went dark for thousands of its 42,000 students during the delay.
Fast edge detection turned this into a three-day delay instead of a semester-ending disaster.

Stop making AI decisions in the dark.

Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.

You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.

You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.

CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.

🤖 AI in Cyber
 
 
AI SECURITY
Varonis researchers used "meta-hacking," repeatedly asking Copilot why an exploit "couldn't" work until it disclosed the exact parameter that made it possible. That let them build a one-click attack, CoSnitch, that steals session data, connected Gmail and Drive content, and poisons the AI's memory via a single link.
Treat AI assistants like any attack surface: they can be socially engineered too, just by asking the right leading questions.
 
AI-ASSISTED MALWARE
Researchers uncovered SilkParasite, a China-linked espionage campaign targeting governments across Central Asia since late 2025. The group deployed five previously unseen remote access trojans with "traces of AI-assisted development" in otherwise expert-written code, not fully AI-generated, but a real signal.
AI-assisted malware development doesn't need to be dramatic to matter, it just needs to make skilled attackers faster.
🏛️ Privacy, Power & Policy
 
 
SURVEILLANCE
EFF is calling out tech companies for privately pushing back on unlawful ICE data subpoenas instead of refusing publicly. The group argues quiet resistance protects a company's reputation more than it protects users, and public refusals would set a stronger precedent.
If a platform publishes a transparency report on government data requests, that's worth checking before you trust it with anything sensitive.
 
FACIAL RECOGNITION
EFF joined seven other groups, including Big Brother Watch and Liberty, demanding Nottinghamshire Police halt its planned live facial recognition rollout, aimed partly at "anti-social" youth as young as 11 under a program called Operation View. Polling cited found 48% of the public opposes suspicionless facial scanning on public streets.
Watch where facial recognition gets piloted first: rarely on the people who can afford to fight back.
🛠️ Tools & Tactics
 
 
Practical play
CISA added two actively exploited TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog, one an unauthenticated remote code execution bug, and gave federal agencies until August 23 to patch. Kaspersky traces exploitation to Head Mare, a hacktivist group trojanizing TrueConf client installers since July to slip in backdoors, a supply-chain move that takes patience over sophistication. If your org runs TrueConf, patch immediately and audit client installers for tampering, not just the server. Treat the federal deadline as yours too.

Stop Paying for 6 Tools. One AI Does It All.

Most e-commerce sellers juggle 6–8 tools and pay hundreds monthly to keep operations running. StoreClaw replaces the stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks profit 24/7. Connect your store and let AI handle the work — no prompts, no complex setup, no credit card required.

🧪 Strange Cyber
 
Strange but real
🔓 CISA Spent Six Months Ignoring Alerts About Its Own Leaked Passwords
Intro
Back in July, a CISA contractor accidentally proved the agency's own advice wrong in the most on-the-nose way possible.
What Happened
A public GitHub repository titled "Private CISA" sat exposed for nearly six months, containing 844 MB of the agency's data, including admin credentials to three AWS GovCloud servers and a spreadsheet of plaintext passwords. Security firm GitGuardian sent nine automated alerts. CISA read none of them.
Why It Matters
This is the agency that tells the country to patch fast and monitor alerts. The gap between that guidance and its own response says something uncomfortable about how hard this is, even for the people who write the rulebook.
The Other Side
No evidence the exposed credentials were exploited before the leak was closed, and CISA moved to fix it once Krebs on Security reached out directly.
 
👉 Takeaway
Automated alerts are only useful if someone's reading them. If your team is drowning in security noise, that's the actual vulnerability.
TL;DR: CISA's own contractor leaked the agency's AWS passwords on GitHub for six months, and nobody read the nine alerts warning them.
Further reading: Krebs on Security

The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.