IEEE Cipher --- Items from security-related news (E193)





Prior news summaries from Cipher



  • Poison Passcodes Do Not Amuse
    US government targets Cop City protester over phone operating system
    Concern over US effort to prosecute Sam Tunick, accused by authorities of wiping his phone using GrapheneOS
    Publisher: The Guardian
    Date: July 23, 2026
    By: Timothy Pratt

    Summary:
    When a US citizen, known for protesting Atlanta's "cop city", returned home to Atlanta after vacationing in Europe, he was detained at the airport before being granted entry. US agents told him that he had to present his phone for examination as part of an investigation into child sexual abuse. After refusing several demands, he gave the agents a "duress" passcode that caused the operating on his Google Pixel phone to delete all his data. Agents in turn charged him with destroying evidence. This case centers on details of federal law regarding the rights of citizens who are seeking to enter the country. The US citizen felt that the detention and search were a fishing expedition about his political activities, not a legitimate inquiry based on evidence. The outcome may help to clarify some little-noticed aspects of US law.


  • Water, Water, Everywhere
    U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems
    Investigators cautioned that the assessment was preliminary. There
    were no indications that any water supply had been rendered unsafe to drink.
    Publisher: The New York Times
    Date: July 30, 2026
    By: Dustin Volz and Ernesto Londoño

    Summary:
    On Sunday, dozens of municipal water systems in Minnesota were subjected to a cyberattack. The report by the state's IT service department did not indicate that any cities experienced outages or harm, but the scope of the attack was concerning. They worked with Federal agencies to investigate the incident, and the general consensus was that entities in Iran or posing as Iranian entities were responsible for the incident. No ransom demands were made, and the investigation is ongoing.



  • CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

    Publisher: CISA News
    Date: July 30, 2026

    Summary:

    In the wake of the Minnesota water system incident, the US Federal Agency CISA (Cybersecurity and Infrastructure Security Agency) issued guidance for people in charge of water and wastewater systems These systems often implement command and control via networks, and these legacy systems sometimes lack protection against sophisticated cyberattacks. The CISA advice focuses on Programmable Logic Controllers because they are the most common device for implementing computer controls of industrial equipment. CISA says:
    Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
    Enable password protection and change default passwords.
    Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.


  • Is our water safe? Cyberattacks targeting US municipal systems on the rise

    Publisher: Deseret News
    Date: Sept. 25, 2026
    By: Art Raymond

    Summary:

    This article states that the Pew Research Center recently issued a report about the increasing number of cyberattacks on US water systems [Ed. The report was evident on the Pew website as of Sep. 28.] In addition to that, an "intelligence note" claimed that in the fall of 2025 there was a concerted effort to attack Utah's water systems, and those attempts emitted from an "internet signature" linked to Iran.

    The Utah Legislative Auditor General issues a report at the beginning of this year center on "drinking water cybersecurity". That report noted the importance of increasing cybersecurity across all of the state's drinking water systems, and it raises possibility of regulation of these entities.


  • Fake Account? What Fake Account?
    Anthropic AI used fake profiles to target people in hack then hid the evidence

    Publisher: BBC
    Date: Aug 6, 2026
    By: Kali Hays and Imran Rahman-Jones

    Summary:
    When the UK's AI Security Institute (AISI) conducted tests of two AI systems (OpenAI and Anthropic's Mythos), they noticed "unusual" activity. Upon investigation they found that the systems were trying to upload malicious code into GitHub by pretending to be humans seeking help. OpenAI and Anthropic said that the testers were at fault for not isolating the tests from the Internet more carefully, but what concerned AISI was the level of deception that the systems pursued. Mythos furthered the deception by taking steps to remove evidence of the fake accounts through which it sent messages asking for assistance accessing GitHub.

    This is not the first time that AI agents have been deceptive and have removed the evidence. One might view the activity as a way of "cleaning up" by removing information that was clearly not wanted by the human user.


  • A Secret Chinese Network Hidden in The Internet

  • FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
    Publisher: The Hacker News
    Date: Aug 26, 2026
    By: Ravie Lakshmanan

    Summary:
    After months of investigation, the FBI disabled a longstanding overlay network that was run by Chinese threat actors for the purpose of evading network traffic controls while finding vulnerable IoT devices and corrupting them. The overlay network also served as a botnet for targeting US institutions, including the Department of Justice (DOJ). There was no information about the victims or damage caused by the botnet, which may have been operating since 2018.. The Chinese group is known as "QTFY" and seems closely associated with the Chinese government.


  • Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure

    Publisher: US Justice Department
    Date: August 26, 2026
    By: Press Release

    Summary:
    This article is also about dismantling the QTFY network. Assistant Attorney General for National Security John A. Eisenberg. "These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation's critical infrastructure." The press release mentioned other similar operations carried out by the FBI over the past several years.



  • FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
    China's hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.
    Publisher: Wired
    Date: Aug 26, 2026
    By: Andy Greenberg

    Summary:
    This article has more information about the QTFY network and its takedown by the FBI. One interesting note concerns the effect of sending QTFY traffic over VPNs used by people within China who are evading the "Great Firewall" censorship. Those networks carry so much traffic that the FBI had trouble finding the QTFY traffic in the deluge.


  • FBI Applicants Exposed
    Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records
    The compromise, if confirmed, would be the latest in a string of
    cybersecurity failures at the F.B.I., which said it was investigating
    the matter.
    Publisher: New York Times
    Date: Sept. 23, 2026
    By: Dustin Volz

    Summary:
    The FBI apparently left a door ajar on its "jobs portal", the ShinyHunters group made off with a few terabytes of sensitive personnel data from applicants, some of whom are presently FBI agents. The records also included data about former FBI agents. The full extent of the breach is not known. The ShinyHunters group has made no financial demand, but it wants the FBI to retract a statement they previously made about the group using violent threats for extortion. They want the FBI to "set the record straight."


  • FBI agents' blood tests and doctors’ notes surface after breach

    Publisher: Malwarebytes
    Date: Sep. 28, 2026
    By: Pieter Arntz

    Summary:
    The ShinyHunters breach of FBI personnel information included a good deal of medical information. This is no ordinary data breach. The FBI has acknowledged that its FBIJobs systems were compromised, but ShinyHunters says that they accessed the systems with medical information and background check reports on employees. The hacker group says that it has information about 60K current and former FBI staff.

    The medical information is particularly concerning because unlike like and email address or password, it cannot be changed and can have lasting effects on how a person is perceived and treated.