this week in security — august 2 2026 edition
THIS WEEK, TL;DR
U.S. government suspects Iranian-backed hackers breached several Minnesota and Michigan water facilities
The New York Times ($): At the start of the week, Minnesota state officials warned that several water facilities serving dozens of communities across the state had been hacked, just days after the feds re-upped warnings that Iranian hackers were breaking into water providers. The water supplies weren't affected but caused widespread disruption. By the end of the week, the water hacks spread to Michigan and other states, per the FBI. It's still early days but all signs and intelligence so far point to Iran, after earlier hacks at Stryker and the leak of the FBI director's emails were linked to Iranian government hacktivists. There's still been no formal attribution, so keep an open mind. All of this comes as the U.S. and Iran remain at war with no end in sight. Pay no attention to Trump's comments, who for some reason blamed the hacks on Minnesota itself. This wasn't the nightmare cyber scenario that Hollywood had played out for decades, but then again, the real cause — decades of underinvesting in cybersecurity — doesn't exactly make for a sexy big-screen storyline.
More: FBI | UPI | Washington Post ($) | Wired ($) | KSTP | Dysruption Hub | Minnesota Star Tribune | Statescoop | Reuters ($) | @wendynather

OpenAI and Anthropic both confirm their AI models hacked other companies
Wired ($): After last week's admission that OpenAI's models hacked Hugging Face and other companies, Anthropic 'fessed up to hacks of its own. The maker of the Claude chatbot said it gained unauthorized access to three other organizations during testing of its AI models. Unlike OpenAI, which didn't secure its sandbox from the internet properly, a miscommunication with a third-party testing company meant that Anthropic's test was running on the internet, allowing it to hack into the other companies. We also learned more about how OpenAI's earlier hack of Hugging Face went down, including the JFrog zero-day that was used to escape its sandbox, plus one of the victim companies that had one of its customer accounts breached. You're probably thinking, how is any of this legal? Well, it's probably not, but only until a judge says so.
More: OpenAI | Anthropic | Bloomberg ($) | Wired ($) | Reuters ($) | Heise | BBC News | CNBC | Tailscale | @briankrebs | @josephhall
A Claude sharing bug exposed people's prompts to Google searches
Garbage Day: In related awkward news, Claude users who hit the "share" button may have had their prompts and conversations with the chatbot indexed in Google and Bing search engines. Reddit users found that anyone could site-search site:claude.ai/share and see a bunch of people's sensitive chats. Anthropic blamed its users for the inadvertent sharing, saying the system was "working as intended." (Which is to say, it was Anthropic's own terrible user interface design to blame.) The search results were quickly pulled offline… so it was a problem. OpenAI had a similar, earlier issue where its users' chats were being indexed by Google and other search engines. It's a good reminder that whatever you submit to a chatbot, it can still be leaked, hacked, or obtained by legal order. I wrote more about this very issue this week.
More: DigitalDigging | 404 Media ($) | Forbes ($) | Android Authority | VentureBeat | Gizmodo | Futurism | Subscribers: this week in security

Security defenders describe chasm between claims of AI hacks and real-world attacks
Despite the very real recent AI hacks and the rising number of bugs, a good number of security folks have been trying to put some of this all into actual perspective. Is the world falling? Far from. A very good level-headed read from @ciaranm (feat. @ProfWoodward) summed it up well, saying there's likely a stormy period coming but creating fears of some kind of cyber AI apocalypse distracts from very real security problems today (ahem!). It's a reminder that the marketing fluff your manager reads about AI hacks and threats, as well as a lot of what you might read in the headlines, is a far cry from what defenders are actually seeing. As discussed online, @GossiTheDog and friends say phishing, social engineering, and ClickFix attacks are actually what's hitting companies hard. Also, cyber insurance giant Resilience notes [PDF] that it saw no customer losses related to AI-specific attack vectors, but a ton related to social engineering attacks. It's because these are the attacks that work!
More: Ciaran Martin | Bloomberg ($) | Claims Journal | Bruce Schneier | @drwhax | @emilymbender | @raphae.li | @eff
~ ~
~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent blogs include: When AI chatbots and LLMs get legal, check your privilege | Most fitness wearables lack end-to-end encryption and don't disclose government data demands | U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents | AI can find bugs and flaws, but don't forget the cybersecurity basics | A beginner's guide to analyzing the network traffic of apps and websites
~ ~
THE STUFF YOU MIGHT'VE MISSED
Soon after Dutch telcos were hacked, the phishing emails appeared
Hackify: In March, two Dutch phone and internet companies were hacked. Security researchers found two of their email addresses used solely for those services (and nowhere else) were taken in the hacks. So they turned it into an opportunity to see what happened with their data in the aftermath. Within about two weeks of the hacks, the phishing emails began, and much of the efforts focused on impersonating banks. This blog shows how personal information is traded after it's been stolen.

Binance allegedly delaying data requests by routing them through UAE's government
The New York Times ($): Law enforcement say Binance now routes their requests for customer data through the UAE, where the world's biggest crypto exchange is regulated. That's frustrating cops and feds who are trying to shut down scammers and money launderers, but are finding massive delays and a slowdown in process. Binance agreed to help police as part of its plea deal with the U.S. DOJ in 2023, then Trump pardoned Binance's founder last year…
Google's big security plan for going beyond zero-trust
Google: For the past decade-plus, Google has prided itself on its zero-trust principles, the company's gold standard policy for keeping its network and data safe. Now, Google has a new set of principles dubbed "beyond zero," which relies on a new contextual and risk-based authorization model that balances speed and security in today's age — which is to say, AI and stuff. Meanwhile: Google also said it fixed more bugs in Chrome during June than in the past two years, which the company cited as the use of AI to find bugs. Microsoft saw a similar trend, but Apple apparently is limiting bug submissions amid a deluge.

Researchers say thousands of data center systems are exposed to remote access
Lava: A bug (CVE-2013-4786) in baseboard management controllers, which are used to control bare-metal systems and servers in data centers (even when they're bricked), allows remote access to tens of thousands of these management interfaces, per new research. At least 30,000 systems are accessible from the web.
Wiz finds "master key" bug in Microsoft's CosmosDB
Wiz: Google-owned cloud security firm Wiz found a "master key" bug in Microsoft's Azure CosmosDB database service that could have been used to raid the accounts of thousands of its customers, and potentially Microsoft itself. (More via Reuters ($).) The platform is used for hosting chatbots, web applications, and reportedly stores Microsoft's own Defender endpoint telemetry.
~ ~
OTHER NEWSY NUGGETS
Buckle up for a bunch o' breaches: Alright, let's blast through some breaches, starting with…. Medical billing firm MCBS was hacked to the tune of 1.26 million people… Coca-Cola's dairy unit Fairlife confirmed hackers stole data after it was earlier forced to halt milk production… Health data giant HealthStream got hacked, with billing and customer data stolen (but no evidence of compromised health data yet)... and not to be outdone, CareCloud began notifying victims after its March data breach that included people's medical data, affecting at least hundreds of thousands — but a source tells me the number is in fact much higher. Pharma giant Amgen reported a breach, which included patients' medical records. And, chipmaker Analog Devices confirmed two breaches, one involving the theft of company information, and another involving an extortion attack related to half-a-million records.
Purge the outdated VPNs! Old, legacy, and outdated VPN technology should be ripped out of the federal enterprise, says Sen. Ron Wyden [PDF]. VPNs allow staff to remotely work, but bugs in VPNs have allowed them to be hacked and abused to compromise organizations and steal data. Look, it's not an exciting topic but it's important. (via The Record, Cyberscoop)
Fed agency demanding ER records: The CPSC, the fun-filled federal department that publicly advises people not to put their infant children in trebuchets, sparked concerns after "discreetly pressuring hospital executives" to share emergency room patients' personally identifiable health data with a contractor. This includes names, addresses, diagnoses, and other personal info to be shared with contractor Konza Health for "analysis," under the guise of a new consumer product injury "surveillance" program. Lawyers say this exceeds the agency's authority. (via KFF Health News, Politico ($))
New Roombas and foreign humanoids banned: The U.S. FCC has banned new imports of foreign-made robots, including humanoid robots, robodogs, and even Roomba vacuums. The FCC cited [PDF] a risk to national security and cyberattacks. Existing devices are fine, but the move is seen as trying to shore up the U.S.' own declining manufacturing position by taking on China's dominant market share, rather than solving any actual cybersecurity issue. (via The Verge ($), Associated Press, PBS, PCMag)
Hacked advertiser serves malware: Digital advertiser Adform was breached and its code altered to interfere with crypto wallets. By serving the malicious ads code instead of just ads, the code was able to swap crypto addresses in the victim's computer clipboard with the wallet address of the hacker's. Need some ad-blocker suggestions? I gotchu. (via DoublePulsar, Adform)
BEC hits the DNC: Democrats lost close to $29,000 in a business email compromise (BEC) email scam. Someone purporting to be a DNC staffer tricked someone into sending the funds (fyi: this is an institutional problem!) The DNC only got a portion of the funds back. The FBI says BEC scams are notoriously popular because they are highly effective. (via NOTUS)
~ ~
THE HAPPY CORNER
*breeeeeeattheeeee out* …ahhh! It's the happy corner, and about time!
It's August and it's blazing hot in Las Vegas, so you know what that means? The world's hackers descend to Black Hat, Def Con, and BSides for a week of cybersecurity learning, meetups, and a sprinkling of mayhem (it wouldn't be hacker summercamp without it).
To make sure everyone has a great time, the good folks at Def Con and BSides LV have banned smart glasses (aka pervert glasses) from the show. These eyeglass wearables are equipped with cameras that can be used to record other people without permission, so banning them keeps everyone safe from surveillance.
Also, @kimzetter has the inside scoop at Wired ($) on this year's new Def Con badges, which contain an open source chip that can also be used as a security key, like a YubiKey. Nice!
Moving on…. Apple's iMessage nudity scanner seems to have gone haywire by classifying some pets as explicit content. The dogs are innocent!
...Aaaaand lastly for this edition. Remember the caption contest of the collapsing robot from last week's newsletter? You had me in absolute stitches with your responses. From the mailbag:
- Kerri: "When the CIO asks 'Do we need a cybersecurity team?' for the third time this year"
- Mario: "...We tested everything multiple times to make it safe and reliable..."
- Per: "We're bending over backwards to serve you!"
- Eric: "When you git-blame the vulnerable code and realize you wrote it."
Got good news to share? Get in touch! this@weekinsecurity.com.
~ ~
CYBER CATS & FRIENDS
This week's cybercat is Judy, who, honestly, seems like a total badass. According to her human, Judy is "docile, but trust me, she likes to eat cardboard for fun, amongst other things. She’s currently trying to eat the blanket as I type this." Absolute legend, Judy. You have the persistence of a well-resourced hacker! Thanks to Cloud for sending in.

🐈 Keep sending in yer' cyber cats! 🐈⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter!
~ ~
SUGGESTION BOX
That's everything for this week! Thank you so much for reading. I hope you enjoyed it. If you liked this newsletter, feel free to share it on your socials or forward to a friend.
Alas, I will not be in Las Vegas this year for Def Con, Black Hat, or anything else fun for that matter (sadness overwhelms me) but please send me tips (or via Signal at zackwhittaker.1337). You can reach out any time; it's always great to hear from you — especially hearing about the cyber things you love and care about!
Otherwise, please get in touch if you have anything else for the newsletter or want to share something for next week's edition.
Floating off into the distant internet,
@zackwhittaker