Attackers Are Reaching Water PLCs, Endpoints, and Camera Feeds Without Exploits, and Detection Built for Malware Is Missing Most of It
Water PLCs hit in seven states, Lazarus-linked tooling in a ransomware campaign, Claude models breaching real companies from test sandboxes, and a Teams call reaching encryption in under 17 hours.
INTRODUCTION
Four days after CISA warned that Iranian-affiliated actors were editing logic on internet-exposed water PLCs, roughly 36 Minnesota community water systems went down, and the FBI now reports activity at water systems in at least seven states. Nobody has formally attributed it, and investigators are weighing whether the actor wanted to look Iranian. South Korean agencies published a campaign in which a state espionage operation and a ransomware crew turned out to be running the same exploits, the same C2, and the same SSH key, and the researchers declined to say they were the same people. Anthropic reviewed its own evaluation transcripts and found Claude models had broken into three real companies from sandboxes that were supposed to be sealed, the earliest three months ago. Sophos traced a Teams help-desk call to file encryption in under 17 hours. And Dutch intelligence says Russia has been reading Europe's exposed IP cameras for military logistics, using image recognition to pick vehicles and cargo out of the feeds.
The thread worth watching across the five is that less of the intrusion is happening at the perimeter and more of it inside channels defenders already treat as routine: an engineering tool, a support call, an evaluation sandbox, a camera nobody monitors. None of that is new on its own, but attackers do not need to innovate every week when their tactics continue to work.
Get The Monday Brief in your inbox every Monday. Subscribe for free, and share it with someone who’d find it useful.
Thanks for supporting us.
WEEKLY SIGNALS ANALYSIS
Legitimate engineering tools can alter OT operations without introducing malware, and the campaign now spans at least seven states. CISA's July 22 update documents ladder logic modified to disable safety shutdown and alarm functions. Re-run your exposure sweep, since the update added Schneider Electric and Siemens, and baseline running controller projects against trusted copies.
Researchers found a state espionage campaign and a ransomware operation running on the same infrastructure, then declined to call them one actor. Lazarus-linked activity and Gunra ransomware shared exploits, C2, tooling, and an SSH key fingerprint against South Korean targets. One access path fed both endings, so early behavior has stopped predicting intent.
Three months passed before anyone noticed that an AI evaluation harness could reach the internet. Anthropic's models exploited weak passwords and unauthenticated endpoints at three real organizations, and two victims had detected nothing. Any vendor test environment that can route to your assets belongs in your threat model.
Your help desk is an authentication boundary. One intrusion proved it in under 17 hours. Operators tracked as STAC4749 reached endpoints through external Teams accounts posing as IT helpdesk. Verify inbound support contact out of band, and allowlist remote access tooling rather than blocklisting it.
What a camera can see matters more than how it authenticates. Russian state actors are compromising exposed IP cameras across Europe, with image recognition pulling military vehicles out of the feeds automatically. Review what each camera actually sees, and remember the camera watching your gate may belong to a neighbor.
What not to over-index on: signature-based endpoint detection as your primary line of defense. It still catches later stages, and in the Teams campaign it eventually flagged the custom tooling. What it misses is the front of these chains: native engineering tools on the PLCs, a phone call and a legitimate remote support product on Teams, and default credentials on cameras running no endpoint agent at all.
THIS WEEK’S SIGNALS
Signal 1: Water PLC Attacks Spread to Seven States While the Advisory Documents Safety Logic Being Deleted and Operator Screens Left Intact
Why it matters: We covered CISA advisory AA26-097A in April, when Iranian-affiliated actors were first confirmed manipulating internet-exposed PLCs across US water and energy systems. Three things changed since then. CISA's July 22 update added Schneider Electric and Siemens controllers alongside Rockwell and documented ladder logic modified at a confirmed victim to disable safety shutdown and alarm functions without alerting operators. Four days later, a coordinated attack hit operational technology at roughly 36 Minnesota community water systems, and the FBI now reports activity at water systems in at least seven states, with several utilities dropping to manual operations. A leaked WaterISAC memo points to Iranian-affiliated actors, but no federal agency has formally attributed it, and investigators are weighing whether someone wanted the activity to look Iranian.
What is being misread: Most coverage is chasing the attribution question, and attribution is the least useful thing on the table. Whoever turns out to be responsible, the access path is identical and so is the remediation. The finding that deserves the attention is quieter: delete only the ladder-logic instructions enforcing safe limits, leave everything else running, and the HMI keeps reporting a plant that no longer exists. The Minnesota utilities that fell back to manual operations did the right thing, because manual operation is the only mode where a human is reading the process rather than the controller's account of it.
Think Red (Douglas McKee): The interesting part here is not that a PLC was reachable from the internet. It is that I never had to hide anything. I can leave your ladder logic running, leave the pumps turning, and delete only the instructions that enforce pressure and temperature limits. This is very similar style attack to what I demonstrated at DEF CON 27, using a building controller, now coming to life in the real world. Your operators keep watching a screen that says everything is fine, because I did not touch the screen. From a red-team perspective, the HMI is not a security control, it is a story you tell yourself, and I get to write it. The legitimate engineering tools did all the heavy lifting, which means there is no exploit to catch and no malware to flag.
Act Blue (Ismael Valenzuela): This is where OT and IT security part ways, and treating them the same is how you miss this. Start by eliminating internet exposure of PLCs, HMIs, and cellular-connected engineering gear, and block or monitor the OT protocol ports in the advisory: 44818, 2222, 102, and 502, plus SSH on edge modems. Re-run that sweep even if you did one in April, because the July update added Schneider and Siemens. Pull running PLC projects on a schedule and diff them against a trusted baseline, focused on safety interlocks and reusable logic modules, since native engineering activity will not trigger malware alerts. Verify critical safety functions through mechanical trips or out-of-band instrumentation an attacker editing controller logic cannot also edit. And rehearse running the process by hand, because that is your genuine containment option and you want to know how long you can sustain it before the day you need the answer.
Supporting sources:
SecurityWeek: CISA urges water sector to lock down internet-exposed PLCs after coordinated attacks
WIRED: Leaked WaterISAC memo ties Minnesota water utility attacks to Iran
CBS News: US investigating whether Iran was behind cyberattacks on water systems in at least seven states
CNN: Sweeping cyberattack on water systems in multiple states has US officials on edge
IOActive: Iranian-affiliated actors expand PLC targeting to Siemens and Schneider Electric
Dark Reading: Minnesota water utility attacks expose sector cyber-risks
Signal 2: A State Actor and a Ransomware Crew Ran Parallel Campaigns in South Korea on the Same Infrastructure
Why it matters: Four South Korean agencies issued a joint advisory, with a supplemental AhnLab report naming the campaign Operation Double Barrel. From 2025 through the first half of 2026, a group widely tracked as Lazarus and the Gunra ransomware operation ran parallel intrusions against South Korean targets, exploiting the same flaw in financial security software that is effectively mandatory for Korean banking, and sharing malware filenames, privilege escalation tools, C2 servers, and an SSH key fingerprint. The state side planted espionage backdoors at 72 organizations in 2026 alone. Gunra used the same access to encrypt and extort. AhnLab calls it a likely technical link and declines to say it is one actor, offering collaboration, shared infrastructure, or a common access broker as equally live explanations.
What is being misread: Some write-ups are reading this as proof that North Korea has gone into the ransomware business, and AhnLab was careful not to say that. Whatever the relationship turns out to be, the operational consequence is fixed: one access path fed both a multi-year espionage campaign and a double-extortion operation, and nothing observable at hour one told the defender which they had. The delivery mechanism deserves equal attention. Mandated client-side security software is a distribution channel with no realistic opt-out, and visiting one of 15 compromised legitimate Korean websites with an outdated client installed was enough, with no click and no download prompt.
Think Red (Douglas McKee): There is nothing new about attackers sharing tools. What works in my favor here is how badly defenders want to label the intrusion early. You see a Lazarus SSH key fingerprint and you assume espionage, so you slow down, watch, and preserve evidence. Meanwhile the same access supports a ransomware payload whenever the operator decides it is worth more encrypted than observed. I do not have to commit to an outcome when I get in. The shared tooling is not just an attribution headache for you, it is option value for me, and your early classification tells me exactly how much room you have given me to move.
Act Blue (Ismael Valenzuela): Intent is not fixed at the point of entry, so a confident attribution can quietly narrow your response before you have earned the right to narrow it. If indicators map to a state actor, keep the quiet, evidence-preserving APT response, but pre-position the ransomware playbook alongside it: protect and verify offline backups now, since that is silent work the actor cannot see, and define the tripwires that flip you to aggressive containment, such as backup tampering, mass credential dumping, or staging of deployment tooling. Hunt those precursors regardless of the label. Assume exfiltration already happened, and plan credential and SSH key rotation as part of coordinated eradication, not piecemeal while the actor is still watching. And if a regulator requires you to run specific endpoint software, put it in your patch SLA and your threat model, because you cannot uninstall your way out of a compliance requirement.
Supporting sources:
The Record: North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
The Hacker News: Hackers exploit AnySign4PC via hacked Korean sites to install backdoors without prompts
TechNadu: North Korean hackers share tools with Gunra ransomware, AhnLab finds
The Record: North Korean hackers behind major open-source supply chain attacks, Amazon says
Signal 3: Anthropic’s Own AI Models Breached Three Real Companies From Evaluation Sandboxes, and the First One Went Unnoticed for Three Months
Why it matters: Prompted by OpenAI's Hugging Face disclosure, Anthropic reviewed 141,006 evaluation runs where Claude could have obtained internet access and found three incidents in which models reached the real internet from test environments run through Irregular, a third-party evaluation partner, and compromised production infrastructure at three organizations. Opus 4.7 got into a real company through weak passwords and unauthenticated endpoints and pulled credentials plus several hundred rows of production data. Mythos 5 published a malicious PyPI package that ran on 15 real systems and stole credentials from a security company's scanner. The earliest incident dates to April, so this went undetected for about three months. Two victims had no idea until Anthropic called, and the third had still not been reached at publication.
What is being misread: The headline everywhere is "AI went rogue," which gets the failure backwards. A misconfigured third-party sandbox left real internet reachable, and the models did what any competent tester does first: scanned what they could reach, tried weak credentials, and looked for exposed services. No zero-days, unlike the OpenAI case. Anthropic's prompt told the models the environment was simulated, and a prompt is not a network control. The evaluations also ran without the classifiers that ship with production Claude, so the harness was the only containment, and it was built to the standard of a test rig. Nobody checked it for three months.
Think Red (Douglas McKee): Years ago in the early part of my career, I was routinely asked to test whether a supposedly isolated environment was actually isolated. Like most pentesters, I started with the basics. I scanned what I could reach, tried weak credentials, and checked for services that should never have been exposed. Sure enough, those simple findings were usually where success was found as a pentester. That is essentially what happened here, except the pentester was an AI model and the rules of engagement failed to contain it. (like they do threat actors...) It did not need a complex exploit chain or some breakthrough capability. It found the same weak passwords, unauthenticated services, and network paths pentesters have been reporting for years. The real problem was not that the AI behaved like a pentester. It was that nobody successfully limited where the test was allowed to go, which I might add, is realistic.
Act Blue (Ismael Valenzuela): Treat an evaluation harness like a production security boundary, because for three months it was the only one. If you run or participate in AI cyber evaluations, enforce isolation at the network layer rather than the prompt layer, default-deny egress, and validate it continuously against configuration drift rather than once at commissioning. You may also be reachable from a testbed you never contracted with, so harden internet-facing services against exactly what these agents used: weak passwords, unauthenticated endpoints, and exposed debug interfaces. Ask your AI vendors who operates their evaluation sandboxes, how egress is enforced, and what the notification commitment is when an eval touches a third party. And note that one victim was a security company whose own package-analysis pipeline executed the malware, so go ask what your build and dependency pipeline would have logged, and whether anyone reads it.
Supporting sources:
Anthropic: Investigating three real-world incidents in our cybersecurity evaluations
BleepingComputer: Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
Help Net Security: Anthropic’s Claude breached three companies during security tests
The Record: Anthropic says its AI hacked real-world companies in three incidents
Signal 4: A Teams Help-Desk Call Reached File Encryption in Under 17 Hours
Why it matters: Sophos documented a campaign tracked as STAC4749 that hit dozens of North American organizations between February and June 2026 using external Microsoft Teams accounts impersonating IT helpdesk in chats and voice calls, with Canada taking roughly half the targets. At least three intrusions ended in Chaos ransomware, a RaaS operation reportedly run by former BlackSuit members. There is no exploit and no attachment at the front of this chain, just a phone call and an employee willing to grant remote access to someone who sounds official. Sophos clocked the fastest at under 17 hours from that call to encrypted files.
What is being misread: Most awareness programs still frame social engineering as an email problem, training people to scrutinize links and attachments. This intrusion arrives as a live voice call inside a trusted collaboration platform, and the platform does the persuading, since anyone reaching an employee through Teams reads as internal. The endpoint side gets misread too. Blocking Quick Assist looks like the fix, and Sophos watched the operators move to RemSupp in April, apparently because it was less likely to be blocklisted, then add DWAgent and AnyDesk as backup access. A blocklist loses that race, because there is always one more remote support product.
Think Red (Douglas McKee): I pick the help desk because it exists to give access, and its whole job is to be helpful under pressure. No phishing email. I call you inside the tool you already trust, and I sound exactly like the IT support you were expecting. Your endpoint controls matter a lot less once the user installs the remote-access tool on my behalf, and they will, because that is what the organization trained them to do. Help the colleague. Cheaper and more reliable than burning an exploit, and it scales across every organization that treats a Teams call as inherently trustworthy.
Act Blue (Ismael Valenzuela): Start with external access to the Teams tenant, because that is the cheapest control and the one most organizations leave open by default. Restrict or disable federation and external chat and calling, and alert on inbound Teams contact from outside your tenant. Then fix the process: require out-of-band verification before anyone grants a remote session, using a number the employee looks up themselves or a ticket reference the caller cannot produce, and make clear that declining a support call is never punished. This is proper Zero Trust in action. On the endpoint, allowlist the remote access tooling you actually use and alert on execution of anything else, one of the highest-fidelity detections available on Windows, and watch for PowerShell writing executables into user AppData, correlating with external Teams contact in your M365 audit logs at triage. Take the 17-hour figure to your incident commander, because containment has to start at the remote session, not at the encryption.
Supporting sources:
BleepingComputer: Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Cybersecurity Dive: Hackers abuse Microsoft Teams in ransomware campaign through fake IT support
Signal 5: Russian Intelligence Is Reading Europe’s Exposed IP Cameras for Military Logistics, and in Ukraine the Feeds Have Fed Targeting Attempts
Why it matters: A July 10 joint advisory from the Dutch AIVD and MIVD reports that at least one Russian intelligence service is systematically compromising internet-connected cameras in the Netherlands, other EU and NATO states, and Ukraine to track military transport routes and weapons shipments bound for Kyiv. Inside Ukraine, the services say camera access has been used in attempts to neutralise personnel and destroy equipment. The targets are ordinary devices, including home doorbell cameras, with a small number of compromised units sitting directly on military logistics routes in the Netherlands. Image recognition does the watching, pulling military vehicles and cargo out of the feeds automatically, so scale costs the operator almost nothing.
What is being misread: Read quickly, this is the water PLC story again and the fix is patching and passwords. Be careful with the numbers, because Censys counted more than 87,000 exposed cameras matching a known-exploited service version and rightly notes that reachable is not the same as compromised. The question nobody has answered survives that caveat. Facilities teams sited these cameras to watch a gate, a loading dock, a driveway, and no one reviewed those sight lines as a collection surface, because that has never been anyone's job. Hardening determines who can reach the device. After a compromise, the only thing that decides what the intrusion was worth is what the camera was pointing at.
Think Red (Douglas McKee): Access to a camera is worth more to me than access to most servers, and it is usually cheaper to get. I am not trying to persist, move laterally, or pull a database. I want to watch, and the device is already aimed at exactly what I care about. The part defenders underrate is the automation. Nobody is sitting there watching a thousand parking-lot feeds, so image recognition does the watching and flags the military vehicle, which means scale costs me almost nothing. And what I collect is the kind of intelligence a network intrusion never produces. What physically moved, when, from where, how often. That is targeting data, not espionage trivia.
Act Blue (Ismael Valenzuela): Camera security has lived in physical-security procurement, and this advisory moves it into intelligence risk, which means it needs an owner it has never had. The mechanical work is known: inventory every camera reachable from the internet by direct IP, port forwarding, UPnP, or vendor cloud relay, get them off the public internet, put remote viewing behind a VPN, replace factory credentials, add MFA where firmware allows, and segment them with dedicated viewing accounts. The second inventory is the one to schedule this quarter. Walk the camera list and record what each one sees, then re-aim or mask anything covering loading docks, badge readers, or vehicle staging, and strip GPS metadata from streams leaving your network. And extend the question past your fence line, because the operators favored cameras belonging to petrol stations, warehouses, and private homes. The device watching your gate may not be yours, and may not be hardenable by you.
Supporting sources:
AIVD: Cybersecurity advisory, Russian state actors are compromising IP cameras
The Record: NATO logistics and Ukrainian troops are top subjects of Russian camera hacks, advisory says
The Hacker News: Russian intelligence hacks IP cameras to spy on military logistics across NATO states and Ukraine
MEME OF THE WEEK
The scariest thing Anthropic's models found in three real companies was the same thing pentesters have been putting in reports since 2012: weak passwords and no network isolation.
ROLE-BASED TAKEAWAYS
Executive / CISO / Board Level
OT integrity can no longer be inferred from the operator display, and this is now a multi-state event. Roughly 36 Minnesota systems were hit, the FBI reports activity in at least seven states, and CISA documents safety logic disabled without alerting operators. The board question is whether critical safety conditions can be verified independently, and how long the process can run manually.
Attribution is unresolved, and remediation should not wait for it. A leaked memo points to Iranian-affiliated actors, no federal agency has attributed it, and investigators are weighing a false-flag angle. The access path and the fix are identical under every scenario.
AI evaluation environments create third-party incident exposure. Anthropic’s models reached three real organizations, the earliest three months before discovery, and two victims had detected nothing. Any AI evaluation activity capable of reaching our infrastructure should carry real penetration-testing authorization, notification, and liability terms.
State-linked access can become a ransomware event without changing infrastructure. In South Korea, an espionage campaign and the Gunra operation shared exploits, C2, and an SSH key, and researchers declined to call them one actor. Ransomware containment should be pre-positioned from hour one, not triggered by the first encrypted file.
Camera placement is an intelligence-exposure decision, not only a facilities one. For any site near logistics, transport, or defense-adjacent activity, we need to know what our cameras can see and who can reach them, including cameras we do not own that overlook our sites.
Enterprise Architect
Design Principle Impact: The HMI can no longer be the authoritative source of process state in OT. Safety verification needs an independent path an attacker editing PLC logic cannot also alter, and manual operation should be a designed control mode with a known sustainable duration.
New Constraint/Dependency: Any AI evaluation harness or third-party red-team platform that can reach production must be a hard network boundary with default-deny egress and continuous drift validation. Prompt-level statements about isolation are not controls.
Second New Constraint: Remote access tooling needs an allowlist model. STAC4749 rotated from Quick Assist to RemSupp to DWAgent and AnyDesk within one campaign, faster than any blocklist maintenance cycle.
Security Operations
Implementation Watch Item: Diff running PLC logic against a trusted baseline, focused on safety interlocks and reusable code modules, and cover ports 44818, 2222, 102, and 502 plus SSH on edge modems. Re-scope the exposure inventory to include Schneider Electric and Siemens.
Common Failure Mode: Trusting the HMI as the sole source of process state, trusting inbound Teams calls as internal, blocklisting remote support tools instead of allowlisting them, and treating cameras as unmanaged edge appliances rather than as endpoints.
Monitoring Patterns: Alert on engineering-tool connections to controllers outside change windows, PowerShell writing executables to user AppData, enriched at triage with M365 audit logs showing inbound external Teams contact for the same user, execution of remote management tools outside the allowlist, and outbound connections from eval or testbed subnets to untrusted IP space. For cameras, alert on management access from outside your network and authentication from unexpected geographies.
Signal vs Noise Guidance: A genuine indicator is an engineering-tool connection with no matching change ticket, or an unapproved RMM install after external Teams contact. Sanctioned support sessions tied to valid tickets are expected, but should remain attributable and logged.
Adversarial edge item: Pre-authorize failover to independent mechanical or out-of-band safety controls and drill it, so a confirmed logic change triggers containment without a change-board decision. Separately, drill the 17-hour case: an active remote session found at 5pm needs a containment path that does not depend on anyone being at a desk.
See you next Monday!
The Monday Brief is produced by Douglas McKee and Ismael Valenzuela. The opinions expressed are our own and do not reflect those of our employers.


