The Signal
The priority set separates threats to industrial operations and business credentials from institutional security governance and AI-assisted capabilities. That distinction matters operationally: these clusters concern different assets, actors, and decision contexts rather than one shared mechanism. [1][2][3][4][5]
Must Know
Federal warning on AI-assisted infrastructure attacks
What happened
U.S. agencies warned that attackers are targeting Siemens S7-series PLCs used in industrial processes across water, food, energy, chemical, manufacturing and commercial facilities, and characterized the attacks as an active threat. [1]
The agencies said the attacks could disrupt industrial processes, cause safety incidents or compromise sensitive data. [1]
Why it matters
The alert states that AI-generated scripts reduce the technical expertise and time needed to develop working industrial-control-system exploitation scripts and malicious tools, while enabling adaptation to defensive measures. [1]
Stripe secret exposure in public code
What happened
Ransomnews researchers reported finding over 50,000 unique exposed Stripe merchant API keys in public repositories, GitHub Actions logs, and misconfigured web servers; testing found a meaningful portion still active. [2]
The report said a dataset containing live keys for 659 merchant accounts included roughly 35 GB of customer and payment data, while stating that Stripe itself was not compromised and the keys belonged to merchants. [2]
Why it matters
Researchers said an active key enabled access to a merchant’s customer list, creation of a fraudulent payment link, and a $1 test charge within 17 hours. [2]
CISA advisory on Medusa ransomware
What happened
An updated joint advisory from the FBI, CISA, and HHS says Medusa ransomware has breached more than 500 organizations since appearing in June 2021. [4]
The advisory says Medusa developers and affiliates have impacted over 500 victims across a variety of critical-infrastructure sectors. [4]
Why it matters
The advisory is a useful current reference point for ransomware risk discussions in affected environments. [4]
Proposed election-office role for Tina Peters
What happened
Shasta County Registrar Clint Curtis said he plans to hire former Mesa County election official Tina Peters as an assistant registrar next month, according to local outlets citing text exchanges with Curtis. [3]
Peters was serving a nine-year sentence for seven felonies, including identity theft, breaking into an election office, disabling surveillance cameras, and stealing voting-system software; Colorado’s governor later commuted her sentence. [3]
Why it matters
Election experts described Peters’ theft of voting-system software as one of the most serious election-system breaches in history, and the stolen code was shared with conservative activists before appearing online. [3]
Mandiant agent-assisted vulnerability research
What happened
Mandiant disclosed an internal multi-agent tool, the Agentic Vulnerability Discovery Harness (AVDH), that hunts for vulnerabilities in source code. [5]
During a live investigation into stolen corporate repositories, Mandiant said AVDH found more than 100 verified, high-severity flaws in two days. [5]
Why it matters
AVDH had been running inside Mandiant for ten months and had scanned tens of millions of lines of code. [5]
Also Worth Knowing
UT San Antonio cyberattack disruption
What happened
A cyberattack targeted the University of Texas at San Antonio’s academic network over the weekend, prompting the university to delay the start of its fall semester. [6]
ChatGPT macOS activity feature and infostealer concerns
What happened
OpenAI’s Computer History feature turns recent Mac computer activity into memories that ChatGPT and Codex can use. [7]
F5 AI Gateway enhancements
What happened
F5 introduced enhancements to its AI Gateway and integrated it into the F5 AI Security Platform. [8]