View all sources for this day →

The Signal

Reported PLC targeting carries the clearest operational consequence, while other lead stories address exploited enterprise entry points and assistant-mediated document handling. Together, they emphasize that security boundaries differ sharply by environment and workflow. [1][2][3][4]

Must Know

CISA water-sector controller protection guidance

Security · Incident

What happened

CISA reports a significant increase in threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems Sector, including entities of all sizes. [1]

Against exposed PLCs, threat actors have modified passwords to lock out operators and changed IP addresses to disconnect the PLCs; the activity has resulted in boil water notices and sustained manual operations. [1]

Why it matters

CISA states that internet-exposed OT assets have increased risk of defacement, configuration changes, operational disruption, and, in severe cases, physical damage. [1]

Laundry Bear Exchange email-opening attack

Exploitation · Incident

What happened

Proofpoint reported that Russia-affiliated cyber-espionage group Laundry Bear, also known as Void Blizzard and TA488, is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, through email targeting U.S. and European government entities and various private-sector organizations. [2]

Proofpoint detected emails carrying the concealed exploit reaching targeted users’ inboxes. [2]

Why it matters

The reported inbox delivery places mail handling at the front of the relevant defensive boundary. [2]

Cisco FMC credential exploitation

Exploitation · Vulnerability

What happened

CVE-2026-20316 is a static-credentials vulnerability in Cisco Secure Firewall Management Center (FMC), whose web interface centrally manages multiple Cisco Secure Firewall devices; CISA warned that attackers are leveraging it. [3]

The static credentials belong to a low-privileged account and can be used by attackers to log in to an incompletely described target. [3]

Why it matters

A credential flaw affecting a centralized management interface shifts attention beyond the managed devices themselves. [3]

Microsoft Copilot prompt-injection research

AI & Agents · Research

What happened

A security researcher demonstrated a self-propagating prompt-injection attack against Microsoft Copilot for Word that silently alters documents and embeds hidden instructions into newly created files, without macros or traditional malware. [4]

The attack hides a JSON-formatted prompt as white text on a white background; when Copilot uses the document as source material, it removes the formatting and treats the text as part of the user’s request. [4]

Why it matters

The researcher reportedly reproduced the full worm chain after Microsoft rolled out multiple mitigations, including upgrades to newer GPT-5.5 and 5.6 models. [4]

Vulnerability volume and patch prioritization

Vulnerability · Research

What happened

Ryan Dewhurst of KEVIntel describes how his team confirms exploitation before a vulnerability appears in CISA’s catalog. [5]

The described process uses a global honeypot sensor network, AI triage, and human verification in a lab before vulnerabilities reach the public feed. [5]

Why it matters

The article discusses CISA’s three-day patching deadline under BOD 26-04 and presents virtual patching as a way to buy time. [5]

Pre-catalog confirmation can help practitioners frame prioritization around observed exploitation rather than publication timing. [5]

Also Worth Knowing

Analysis of eSIM Plus and Nicegram code

Identity · Supply Chain

What happened

Analysis found that eSIM Plus and Nicegram share a Belarus-linked codebase; both are presented to EU users as Lithuanian products, while eSIM Plus is signed by “Mobyrix, Minsk.” [6]

Exposed-credential risk analysis

Identity · Security

What happened

Compromised credentials can remain active after passwords are created, requiring organizations to identify exposed accounts before attackers use them. [7]

Data-breach cost survey

AI & Agents · Incident

What happened

More than one in four organizations affected by a malicious attack in the past year said AI drove the attack. [8]

Sources (8)
  1. [1] CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

    cisa ncas current activity · July 30, 2026

  2. [2] Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

    helpnetsecurity · July 30, 2026

  3. [3] Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

    helpnetsecurity · July 30, 2026

  4. [4] Hidden prompt turns Microsoft Copilot into an AI worm

    malwarebytes labs · July 30, 2026

  5. [5] 200 new CVEs a day and no realistic way to patch them all

    helpnetsecurity · July 30, 2026

  6. [6] eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds

    securityaffairs · July 30, 2026

  7. [7] Exposed credentials are giving attackers a head start many organizations don’t see

    helpnetsecurity · July 30, 2026

  8. [8] Data breach cost 2026 averaged $4.99 million, AI attacks ran higher

    helpnetsecurity · July 30, 2026