Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The Gunra ransomware gang is successfully targeting critical infrastructure by exploiting known vulnerabilities in Fortinet firewalls and VPN appliances while bypassing multi-factor authentication. The group operates as a ransomware-as-a-service (RaaS) model and leverages leaked Conti ransomware code to execute their attacks. This highlights the ongoing risk posed by unpatched legacy vulnerabiliti
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, FBI, and international partners have issued a joint advisory warning about the Gunra ransomware-as-a-service operation targeting healthcare organizations and critical infrastructure globally. The group, which transitioned to a RaaS model in 2026, offers affiliates an 80% ransom cut and exploits known vulnerabilities in VPNs and firewalls to gain network access, conducting double extortion at
AIA Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Security researchers from the University of Birmingham and Fuzzware have discovered that malicious SIM cards can execute attacker-controlled commands on cellular modems, potentially compromising IoT devices including EV chargers, industrial routers, and vehicle telematics systems. Testing across 26 phones and cellular modules confirmed this vulnerability exists in critical infrastructure component
Iran Cyberattacks Against Minnesota Water Systems
Preliminary reports indicate Iranian-attributed cyberattacks have targeted water systems in Minnesota and at least six other U.S. states, though no significant damage has been confirmed. The incident has become politicized, with conflicting statements about attribution and state-level cybersecurity competence overshadowing the technical security response.
AI⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week's cybersecurity incidents centered on permission and access control failures across multiple domains. Breaches included an AI model boundary violation, an $88M Bitcoin theft exploiting weak randomness, water-system attacks, and DNS hijacking—most stemming from misconfigured access, legacy vulnerabilities, exposed infrastructure, and inadequate default security settings rather than sophis
AIMinnesota Water Utility Attacks Expose Sector's Cyber-Risks
Over 30 community water systems in Minnesota were targeted by a suspected Iran-backed threat actor, highlighting the increasing cybersecurity vulnerabilities facing US critical infrastructure. The attacks underscore the urgent need for water utilities and other essential services to strengthen their security postures against nation-state adversaries.
AICoordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack compromised operational technology systems at over 30 Minnesota community water utilities on July 26-27, 2024, forcing at least one facility offline and disrupting automated controls at multiple sites. The incident triggered a statewide cybersecurity emergency response, with affected municipalities including Braham, Plymouth, South St. Paul, and Maple Plain reporting vari
AICritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains has disclosed a critical security vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On-Premises that enables unauthenticated attackers to execute arbitrary operating system commands. The flaw affects all on-premise versions and has been patched in versions 2025.11.7 and 2026.1.3, while cloud instances are already secured. Organizations using on-premise TeamCity deployments should prio
AIThe Invisible Battlefield: How Cyber War Is Reshaping Everyday Life
Former National Cyber Director Chris Inglis highlights the escalating threat of cyber attacks targeting critical infrastructure including hospitals, utilities, and essential services. These attacks represent an invisible battlefield that increasingly impacts everyday operations and public safety, requiring heightened awareness and defensive measures from enterprise organizations.
AITropical Blend: Cyber & Politics Ramp Up Across Latin America
China-linked cyber espionage groups have conducted targeted attacks across at least twelve Latin American nations, focusing on critical infrastructure and strategic sectors. The campaigns have concentrated on gathering intelligence related to maritime shipping operations, oil production facilities, and other geopolitically significant assets in the region.
Vulnerability Disclosure in the Age of AI
AI models are now capable of autonomously discovering software vulnerabilities at unprecedented speed, creating a critical inflection point that exposes decades of technical debt from insecure development practices. The article argues that vulnerability disclosure must evolve from a reactive process to a coordinated national and international effort involving governments, vendors, and infrastructu
CISA Announces Rescheduled CIRCIA Virtual Town Hall Meetings
CISA has rescheduled virtual town hall meetings for CIRCIA rulemaking to June 2026 following a 76-day DHS partial shutdown that reduced staff to 38% capacity. The meetings will gather stakeholder feedback on proposed regulations requiring critical infrastructure entities to report significant cyber incidents within 72 hours and ransomware payments within 24 hours. Four virtual sessions will be hel
