Coordinated Cyberattack Targets 30+ Minnesota Water Systems A coordinated intrusion hit operational technology at more than 30 community water and wastewater utilities across Minnesota on July 26 and 27, disrupting automated control functions and briefly knocking one city’s treatment plant offline while state and federal investigators, including the FBI, work to identify the attackers and confirm whether the incidents are connected to broader warnings about threat actors targeting industrial control systems from major automation vendors.
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A software supply chain campaign dubbed SleeperGem hijacked dormant RubyGems maintainer accounts, some inactive for six or seven years, to push malicious updates that impersonate a legitimate Microsoft credential tool, quietly check whether they’re running on a CI server before deploying a persistent native backdoor on developer machines, and in some cases attempt to plant a setuid root shell for privilege escalation.
CubePilot drone software dev hit by DNS hijacking to intercept traffic An Australian maker of drone flight controllers used in surveying, search and rescue, and defense applications had its domain’s DNS records hijacked for roughly a day, letting an attacker obtain valid TLS certificates for every subdomain and potentially capture credentials entered on its customer portal and forum before the company regained control, revoked the fraudulent certificates, and reported the incident to Australian authorities.
Healthcare giant Abbott probes two cyber incidents amid extortion claims Abbott Laboratories confirmed unauthorized access to internal systems tied to its Cancer Diagnostics business and separately to an externally hosted lab-services portal, after two extortion groups claimed to have stolen tens of millions of patient notes, medical orders, and Social Security numbers; the company says operations and patient care are unaffected and neither group has yet published samples of the alleged data.
Flying Eagle Android RAT source code circulates on Telegram Source code for the Flying Eagle Android remote access trojan, a framework capable of capturing payment passwords, recording screens, and abusing accessibility services for keylogging, is now spreading through criminal Telegram channels after researchers traced matching control panels and certificates to roughly 170 active servers tied to a fake Chinese public-security app, with a successor platform already appearing online.