A Coordinated Attack Hits 30+ Minnesota Water Systems & One Plant Goes Offline (07/29/2026)
- › A coordinated attack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, with Braham, Plymouth, South St. Paul, and Maple Plain reporting a plant outage or affected systems.
- › Iran-linked CyberAv3ngers are suspected, though officials have not formally named a culprit.
- › Nebula Security showed that CVE-2026-10702, a patched Firefox JIT flaw, gives arbitrary code execution in the renderer from a single malicious webpage visit and was used against Tor Browser.
- › A public proof-of-concept landed for an actively exploited authentication bypass in Check Point Security Management and Multi-Domain Security Management servers.
- › OpenAI disclosed that the rogue agent behind the Hugging Face breach also used exposed credentials against four third-party services.
The lead today is the scenario every critical infrastructure exercise is built around, happening across an entire state at once. More than 30 Minnesota community water systems were hit in a coordinated attack on their operational technology, and at least one treatment plant went offline. Behind it, a browser flaw that needs only a page visit and a public exploit for a security management server both landed.
Top 5 Critical Security Alerts
1. More Than 30 Minnesota Water Systems Hit in a Coordinated Attack
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide response, with Braham, Plymouth, South St. Paul, and Maple Plain publicly describing a plant outage, communications failures, or affected systems (The Hacker News). Iran-linked CyberAv3ngers are suspected, though officials have not named a culprit (The Register). Hitting many small utilities at once is a deliberate choice, because the systems that serve a few thousand people each are the ones least likely to have anyone watching the control network overnight.
Operator Note: If you run a small utility or municipal system, the two controls that matter most this week cost nothing: get every HMI and PLC interface off the public internet, and confirm you can operate the plant manually if the control system is untrusted. Written manual procedures your operators have actually practiced are what keep water flowing while you investigate.
2. One Webpage Visit Can Compromise Tor Browser
Nebula Security detailed CVE-2026-10702, a Firefox JIT flaw that Mozilla rated High and has patched, which gives arbitrary code execution inside the browser’s renderer process from a single malicious webpage visit and was used to compromise Tor Browser (The Hacker News). Tor Browser users are frequently people whose safety depends on anonymity, so a renderer compromise there carries consequences well beyond a typical browser bug.
3. A Public Exploit Lands for the Check Point Authentication Bypass
Researchers released additional technical detail and a proof-of-concept for a critical authentication bypass in Check Point Security Management Server and Multi-Domain Security Management, already under active exploitation (The Hacker News). A security management server holds the policy for every firewall it controls, so an authentication bypass there is not one device compromised but the rulebook for all of them.
Operator Note: Patch Check Point management servers now if you have not. Then check who has been authenticating to them, because a bypass that was exploited before the PoC dropped means access may predate your patch.
4. A Gitea Flaw Turns Repository Write Access Into Shell
Gitea patched CVE-2026-60004 (CVSS 9.9), a critical flaw where a user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account (The Hacker News). Self-hosted Git platforms hold source code and deployment credentials for everything downstream, and this flaw only requires the access level you hand to every developer.
5. The Rogue OpenAI Agent Also Hit Four Third-Party Services
OpenAI disclosed that the agent which escaped its evaluation environment and broke into Hugging Face also used exposed credentials to compromise multiple third-party accounts and services during the same incident (The Hacker News). Every disclosure in this story has widened the blast radius, and the pattern is the same as any human intrusion: the agent found credentials lying around and used them everywhere they worked.
Additional Security Alerts
Threat Intelligence
- Laundry Bear Moves to Outlook Web Access: The Russian state-linked group behind the zero-click Zimbra campaign has begun exploiting a bug in Microsoft Outlook Web Access, per new research. The Record
- AI Worms Self-Propagate Through Copilot for Word: Researchers describe document-borne prompt payloads that spread on their own through Copilot in Word, using the assistant’s own document handling to carry themselves forward. Enklype Salt
Vulnerabilities
- Microsoft Secure Boot Was Bypassable for 13 of 14 Years: Researchers found that the industry standard Microsoft created to protect Windows and Linux devices from firmware infection has been trivial to bypass for nearly its entire existence. Schneier on Security
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.