~/greenteam/nerd

Weekly review

Week of August 24-30, 2026

This week's digests were dominated by critical vulnerability disclosures (ServiceNow, PaperCut, Gitea, Zimbra, ownCloud) and CMMC/quantum procurement developments, but missed a wave of high-profile ransomware and breach disclosures (ATF, Carhartt, Boston Scientific, Berlin) and a major CISA warning about AI-assisted attacks on water-sector industrial controllers.

What you might have missed

Stories not surfaced in this week's daily digests.

cybersec BleepingComputer / TechCrunch

ATF Declares 'Major Incident' After Qilin Ransomware Claims Breach

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident on a standalone system containing information about investigation targets, which Justice Department officials designated a formal 'major incident.' The Qilin ransomware gang listed ATF on its dark web leak site the same day, though ATF has not confirmed the attribution or what, if any, data was stolen.

Why it matters: It's the third major U.S. federal law enforcement agency (after the FBI and DHS) to disclose a significant breach in six months, signaling federal agencies are now squarely inside ransomware gangs' opportunistic targeting, not just nation-state espionage.

infrastructure TechCrunch / CISA

CISA Confirms 100+ Water/Wastewater Systems Targeted by AI-Assisted PLC Attacks

CISA disclosed that malicious actors targeted more than 100 internet-exposed systems across the U.S. water and wastewater sector during July, largely by exploiting exposed programmable logic controllers from Rockwell, Schneider Electric, and Siemens. The agency said some intrusions used AI-generated exploitation scripts and, in cases, disabled shutdown processes and alarms without notifying operators.

Why it matters: It quantifies for the first time the scale of an ongoing, suspected Iran-linked campaign against U.S. critical infrastructure and highlights AI as a force-multiplier for OT/ICS attacks.

cybersec SecurityWeek / TechCrunch

Boston Scientific Cyberattack Causes Global Operational Disruption

Medical device maker Boston Scientific disclosed a cybersecurity incident detected on August 25 that disrupted access to operating systems and business applications worldwide, including its ability to process and ship customer orders. The company filed an SEC Form 8-K and sent staff at its Cork, Ireland manufacturing site home while investigating with third-party responders.

Why it matters: It's the latest in a string of 2026 medtech breaches (following Stryker, Abbott, and Medtronic incidents), underscoring how IT outages at device manufacturers can ripple into patient care and supply chains.

cybersec BleepingComputer / The Register

Carhartt Data Breach Exposes 12.9 Million Accounts via ShinyHunters Extortion

ShinyHunters claimed to have stolen over 50GB of Carhartt customer, employee, and corporate data after the apparel giant declined to pay a $3.3 million ransom. Have I Been Pwned's analysis found the real impact was about half the group's claim — roughly 12.9 million unique email addresses — after researcher Troy Hunt discovered the leaked dataset had been padded with millions of synthetic records.

Why it matters: It illustrates both the continuing dominance of ShinyHunters-style extortion-without-encryption attacks and the growing need to independently verify breach-scale claims before acting on them.

cybersec Cybernews

Rhysida Ransomware Threatens to Auction 5.8TB of Berlin Government Data

The Rhysida ransomware group claimed an attack on Berlin city government systems and is threatening to auction 5.8TB of stolen data after the city refused to pay its ransom demand. The incident adds Berlin to a growing list of European municipal governments hit by ransomware this year.

Why it matters: Government refusal to pay combined with a large public-data auction threat raises the stakes for how municipalities balance ransom payment policy against citizen data exposure.

Themes this week

Patterns observed across coverage.

Ransomware and extortion groups are hitting federal agencies and blue-chip brands alike

Qilin (ATF), ShinyHunters (McKesson, Carhartt), and Rhysida (Berlin) all claimed major victims this week, with ATF becoming the third U.S. federal law enforcement agency breached in six months — a sign that ransomware-as-a-service affiliates are treating government and enterprise targets as equally opportunistic.

Critical infrastructure and OT/ICS are under sustained, AI-accelerated attack

CISA's water-sector PLC advisory, the UK power plant shutdown, the executive order banning risky foreign tech from the power grid, and the China-made ZBT router implants all point to a widening, AI-assisted campaign against energy, water, and telecom infrastructure this week.

CMMC remains in regulatory limbo, straining the assessor ecosystem

With Phase II suspended since July and the CMMC Reform Task Force's public comment period closed August 14, third-party assessors are reporting contract cancellations and layoffs while contractors wait for recommendations expected around mid-September; this week's digest items (quantum procurement, foreign-tech grid bans) are downstream ripples of that broader policy uncertainty.

AI is simultaneously the attacker's new tool and the defender's new attack surface

This week's stories span AI-scripted PLC exploitation, AI-scaled malware groups like UAT-10147, warnings about AI coding assistants outpacing dependency vetting, and Akamai's research on risky enterprise 'super-adopters' — alongside a federal court ruling against the Pentagon's Anthropic ban, showing AI policy and AI-enabled threats are now deeply intertwined.

Suggested new sources

Worth considering for your feed list. Review and add manually.

SecurityWeek

Breaking cybersecurity news, breach and vulnerability disclosures

SecurityWeek consistently broke or closely tracked several stories missed this week (ATF, Boston Scientific, Keycloak, Apollo), offering fast, detail-rich coverage that complements the existing feed roster's broader industry angle.

Industrial Cyber

Industrial control systems (ICS), OT, and critical infrastructure security

None of the currently subscribed feeds specialize in OT/ICS, yet this week's biggest infrastructure story (100+ water utilities targeted via exposed PLCs) sits squarely in that domain — Industrial Cyber tracks these threats in far more depth than general IT security outlets.

CyberScoop

Cybersecurity industry and policy news across government and private sector

It offers a broader cybersecurity-industry lens than the strictly federal-agency focus of FedScoop/DefenseScoop/NextGov already in the digest, useful for covering private-sector policy fights like the Anthropic/Pentagon ruling alongside government-specific coverage.