Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

2026-08-06T13:23:58Z7b00ecb4be12b434a269dd5709396fb18eabe9405597622d385664cb0be47dc8
CVE-2026-59774CVE-2026-63077CVE-2026-64531CVE-2026-9198active-exploitationagent-securityai-securitybackdoorcredential-leakcritical-vulnerabilitydevice-code-phishinggiteaindustrial-control-systemsiotlangflowlinux-kernelmalwarenpmoauth-token-theftphishingplcprompt-injectionransomwarerceroot-shellsupply-chain-attackteamcityvulnerabilitywater-utilities

What happened

The document aggregates major cybersecurity developments reported on August 5–6, 2026, including actively exploited critical vulnerabilities, exposed industrial control systems, supply-chain compromises, malware and phishing campaigns, AI-agent security flaws, credential exposure, and cybercrime activity. Notable items include active exploitation of TeamCity CVE-2026-63077, Gitea CVE-2026-59774, Linux Open vSwitch CVE-2026-64531, and Langflow CVE-2026-9198; factory-backdoored Zbtlink routers; trojanized npm and QuickFox packages; and phishing operations targeting Microsoft tokens and MFA.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
7b00ecb4be12b434a269dd5709396fb18eabe9405597622d385664cb0be47dc8
Enrichment time
2026-08-06T13:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.