Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIMultistate Water System Attacks Widen, Iran Suspected
Cyberattacks against water infrastructure have expanded across multiple U.S. states, with Iran suspected as the threat actor. The attacks exploit poorly secured programmable logic controllers (PLCs) that are directly exposed to the Internet, highlighting critical vulnerabilities in operational technology security across water utilities.
Iran Cyberattacks Against Minnesota Water Systems
Preliminary reports indicate Iranian-attributed cyberattacks have targeted water systems in Minnesota and at least six other U.S. states, though no significant damage has been confirmed. The incident has become politicized, with conflicting statements about attribution and state-level cybersecurity competence overshadowing the technical security response.
AIMinnesota Water Utility Attacks Expose Sector's Cyber-Risks
Over 30 community water systems in Minnesota were targeted by a suspected Iran-backed threat actor, highlighting the increasing cybersecurity vulnerabilities facing US critical infrastructure. The attacks underscore the urgent need for water utilities and other essential services to strengthen their security postures against nation-state adversaries.
AISprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection
FishMonger, a China-linked threat actor, has deployed a previously undocumented Windows variant of the SprySOCKS backdoor that leverages kernel drivers to evade detection. The malware campaign has targeted government entities across Honduras, Taiwan, Thailand, and Pakistan, representing a significant evolution from the original Linux-based version.
AIChinese, N. Korean Threat Groups Build on Asia-Pacific Success
North Korean state-linked threat groups are contributing to the nation's GDP growth through targeted cybercrime campaigns against business and financial institutions in the Asia-Pacific region. These attacks represent a significant revenue stream for the isolated nation, demonstrating how nation-state cyber operations are increasingly focused on financial gain rather than solely espionage.
AIIran Signed a Ceasefire — Its Hackers Didn't
Despite Iran signing a ceasefire agreement, cyber operations attributed to Iranian threat actors have continued, highlighting a critical gap in international law. The Geneva Conventions currently lack provisions to explicitly govern cyberwarfare during ceasefire periods, creating a loophole that allows state-sponsored hacking to persist even when kinetic hostilities have ceased. Extending these co
AIPakistan Spies on Afghan Finance Ministry With Xeno RAT
Pakistani intelligence operatives successfully deployed Xeno RAT malware to infiltrate Afghanistan's Finance Ministry, exploiting weak cybersecurity defenses. The attack demonstrates how conventional tactics, techniques, and procedures (TTPs) remain effective against organizations with inadequate security infrastructure, despite having modern digital connectivity.
AITropical Blend: Cyber & Politics Ramp Up Across Latin America
China-linked cyber espionage groups have conducted targeted attacks across at least twelve Latin American nations, focusing on critical infrastructure and strategic sectors. The campaigns have concentrated on gathering intelligence related to maritime shipping operations, oil production facilities, and other geopolitically significant assets in the region.
AIKimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
North Korean state-sponsored threat group Kimsuky has launched targeted cyber attacks against South Korean military and corporate organizations during March-April 2026. The campaign employs sophisticated social engineering techniques including spoofed security software pages and fake Webex meeting interfaces to deliver malware including HTTPSpy, HelloDoor, and VS Code tunnels.
