View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA warns of cyberattacks disrupting US water utilities via exposed

๐Ÿšจ ACTIVE EXPLOITATION

  • CISA warns of cyberattacks disrupting US water utilities via exposed PLCs CISA warns of increased cyberattacks targeting internet-exposed programmable logic controllers (PLCs) in US water utilities, causing operational disruptions.

    • Targets: Water and wastewater systems sector in the US, including over 30 Minnesota community water systems
    • Vulnerabilities: Internet-exposed PLCs and operational technology (OT), including undocumented cellular modems
    • Attack methods: Changing PLC passwords to lock out operators, modifying IP addresses to disconnect devices
    • Exposure: Over 4,100 Rockwell Automation/Allen-Bradley, 4,100 Siemens, and 2,000 Schneider Electric hosts exposed online
    • Notable affected devices: Rockwell Automation MicroLogix 1400 PLCs, many running end-of-sale firmware versions ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • Chinese threat actor uses DeepSeek AI for autonomous cyberattacks on exposed servers A Chinese threat actor used DeepSeek AI and Hermes Agent to autonomously attack vulnerable servers running Langflow and n8n workflow automation platforms.

    • Targets: Internet-exposed servers running Langflow and n8n platforms
    • Vulnerabilities: CVE-2026-33017 (Langflow), CVE-2026-21858 and CVE-2025-68613 (n8n), plus Citrix NetScaler CVE-2026-3055
    • Attack method: DeepSeek AI-driven Hermes Agent scanned, selected exploits, and attempted attacks without human feedback
    • Scale: Identified 84 Langflow and 647,000 n8n exposed instances via FOFA search engine
    • Outcome: Autonomous attacks failed to compromise targets, but manual attacks succeeded on 3 Citrix NetScaler systems extracting session cookies ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • pgAdmin 4 OS command injection via MASTER_PASSWORD_HOOK username substitution (CVE-2026-17347) CVE-2026-17347 pgAdmin 4's MASTER_PASSWORD_HOOK setting allows OS command injection via untrusted username substitution from external authentication sources.

    • Applies to pgAdmin 4 versions from 7.2 before 9.17 with MASTER_PASSWORD_HOOK enabled
    • Vulnerability in MASTER_PASSWORD_HOOK executes external commands with %u replaced by username
    • Usernames from OAuth/OIDC, Kerberos, or webserver auth can include shell metacharacters
    • Allows authenticated users to execute arbitrary OS commands as the pgAdmin service account
    • Exploit requires non-default configuration using %u and external identity provider usernames ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A spear-phishing attack used HollowFrame loader to deploy Matryoshka backdoor on law firm endpoints.

    • Targets: Two endpoints at an unspecified law firm
    • Initial vector: Spear-phishing email with link to encrypted archive containing a malicious Windows Shortcut (LNK)
    • Loader: HollowFrame, a Go-based modular loader using DLL side-loading with python.exe and rogue python311.dll
    • Backdoor: Matryoshka, a Rust-based malware with HTTP and GitHub-based C2 variants for command execution and payload delivery
    • Evasion: Anti-analysis checks based on system uptime, memory, file count, and cursor movement; persistence via scheduled tasks ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ”“ CVEs & KEV

  • Other: 19 CVEs (worst 9.9)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check