Coordinated “cyberattack” on Minnesota water utilities: What you need to know
2026-07-29T20:52:11Z•303bab951fc571e5fc108a26c5f59a64dda8db0c71c83b459103f519b4e935ab
CVE-2021-22681CVE-2026-15409CVE-2026-15410CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030AI coding assistantsCISA KEVCyberAv3ngersIranian-affiliated actorsMicrosoft SharePointOracle Critical Patch UpdatePLCsPyPIRockwell AutomationSchneider ElectricSiemensSonicWall SMA 1000WordPressactive exploitationcritical infrastructureindustrial control systemsnpmremote code executionsoftware supply chainwater utilitieszero-day
What happened
Tenable’s July 2026 security intelligence covers multiple high-impact threats: active exploitation of WordPress Core vulnerabilities enabling unauthenticated remote code execution, actively exploited on-premises Microsoft SharePoint flaws, SonicWall SMA 1000 zero-days, and critical exploitation of Rockwell PLC authentication bypasses affecting water utilities. It also discusses Oracle’s July 2026 CPU, AI coding-assistant configuration poisoning and worm-based supply-chain attacks, and emerging risks to internet-exposed industrial control systems.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 303bab951fc571e5fc108a26c5f59a64dda8db0c71c83b459103f519b4e935ab
- Enrichment time
- 2026-07-29T20:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.