Coordinated “cyberattack” on Minnesota water utilities: What you need to know

2026-07-29T20:52:11Z303bab951fc571e5fc108a26c5f59a64dda8db0c71c83b459103f519b4e935ab
CVE-2021-22681CVE-2026-15409CVE-2026-15410CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030AI coding assistantsCISA KEVCyberAv3ngersIranian-affiliated actorsMicrosoft SharePointOracle Critical Patch UpdatePLCsPyPIRockwell AutomationSchneider ElectricSiemensSonicWall SMA 1000WordPressactive exploitationcritical infrastructureindustrial control systemsnpmremote code executionsoftware supply chainwater utilitieszero-day

What happened

Tenable’s July 2026 security intelligence covers multiple high-impact threats: active exploitation of WordPress Core vulnerabilities enabling unauthenticated remote code execution, actively exploited on-premises Microsoft SharePoint flaws, SonicWall SMA 1000 zero-days, and critical exploitation of Rockwell PLC authentication bypasses affecting water utilities. It also discusses Oracle’s July 2026 CPU, AI coding-assistant configuration poisoning and worm-based supply-chain attacks, and emerging risks to internet-exposed industrial control systems.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
303bab951fc571e5fc108a26c5f59a64dda8db0c71c83b459103f519b4e935ab
Enrichment time
2026-07-29T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Coordinated “cyberattack” on Minnesota water utilities: What you need to know · Baitaphish