US water campaign grows to 12 states: preliminary Iranian attribution confirmed, Georgia boil water advisory issued, FBI and EPA warn of degraded operations nationwide      Black Hat: Samsung Galaxy one-click exploit chain gives full device access through Samsung Members and Samsung Account vulnerabilities      Black Hat: pre-authentication RCE chains in Bonita BPM and Apache OFBiz from chained middleware flaws, no account required      US water campaign grows to 12 states: preliminary Iranian attribution confirmed, Georgia boil water advisory issued, FBI and EPA warn of degraded operations nationwide      Black Hat: Samsung Galaxy one-click exploit chain gives full device access through Samsung Members and Samsung Account vulnerabilities      Black Hat: pre-authentication RCE chains in Bonita BPM and Apache OFBiz from chained middleware flaws, no account required     
CyberSipTM
Intelligence without the noise
Issue No. 103
August 7, 2026
3 items · past 24h
<5 min read
Today's picture

The water infrastructure campaign first documented in Minnesota has now touched at least 12 US states, with preliminary investigative findings pointing to Iranian-backed hackers, a boil water advisory issued to 300,000 customers in Georgia's Clayton County, and a joint FBI and EPA statement confirming degraded water operations in multiple states. At Black Hat 2026, researchers from Microsoft and Mobile Hacking Lab disclosed a one-click exploit chain against Samsung Galaxy devices that uses vulnerabilities in the Samsung Members and Samsung Account applications to gain full device control without any special privileges, with Samsung shipping a patch in its August update. Also at Black Hat, researchers presented 12 vulnerabilities across four enterprise Java platforms including pre-authentication remote code execution chains in Bonita BPM and Apache OFBiz that combine seemingly minor middleware issues into paths for complete unauthenticated compromise.

Today's intelligence
3 items
01 HighWater InfrastructureIran Attribution
The US water campaign has grown to at least 12 states, with investigators pointing to Iranian-backed actors and a Georgia utility issuing a boil water advisory
What began as a single-state incident has become the largest documented coordinated cyberattack on US water and wastewater infrastructure. Clayton County, Georgia, which serves 300,000 people near Atlanta, issued a boil water advisory after a pressure drop. Attribution remains preliminary. The FBI and EPA have warned utilities nationwide.
States affectedAt least 12
as of Aug 6
Named statesMinnesota, Michigan
Georgia, New Jersey
South Dakota
AttributionPreliminary Iranian
(not confirmed)
First reportedJuly 26, 2026
Minnesota
Sources familiar with the investigation told CBS News on August 6 that cyberattacks on US water systems suspected to be linked to Iranian-backed hackers have been confirmed in at least 12 states, including Michigan, Minnesota, Georgia, New Jersey, and South Dakota. The incidents began on July 26 and 27 with the coordinated disruption of more than 30 community water systems across Minnesota, covered in Issue 97. The scope expanded steadily through the following week. The FBI and EPA issued a joint public service announcement on July 30 warning water and wastewater utilities in at least seven states had reported incidents with some malicious activity degrading operations. By August 4, reporting expanded that count to 12 states. In Georgia, the Clayton County Water Authority, which serves approximately 300,000 customers in the Atlanta metropolitan area, said cyber activity caused a water pressure drop during late July and forced the agency to issue a boil water advisory. Service was restored within hours. In Minnesota, investigators from the FBI, CISA, and the EPA have conducted on-site assessments at affected utilities. Federal officials have declined to publicly attribute the campaign, though multiple sources across outlets have named Iranian-affiliated actors as the most likely responsible party. The Wikipedia article on the Minnesota incident, citing reporting from The New Republic, notes investigators described Iranian hackers as probably responsible while stressing that assessments could change. The CyberAv3ngers group, associated with Iran's Islamic Revolutionary Guard Corps and previously documented by CISA for targeting internet-facing programmable logic controllers at US water facilities, is the actor class consistent with the techniques observed. No drinking water safety issues have been confirmed beyond the temporary Georgia boil water advisory.
The expansion from one state to twelve in eleven days indicates either a single coordinated campaign that was larger than initially understood, or a sustained actor conducting sequential intrusions against a consistently vulnerable sector. Either framing is operationally significant. Water and wastewater infrastructure in the United States is predominantly operated by small community utilities with limited cybersecurity staffing and budgets. The EPA's own 2024 audit found that more than 70 percent of audited water systems were failing to meet baseline statutory security requirements. The Georgia boil water advisory is the first confirmed drinking water impact from this campaign and demonstrates that operational technology compromise at water facilities can reach public health outcomes, not just operational inconvenience.
CISA Advisory AA26-097A, updated on July 22, documented Iranian-affiliated actors targeting internet-facing programmable logic controllers across US critical infrastructure and expanded the scope of observed exploitation to include Schneider Electric and Siemens devices alongside Rockwell Automation. That advisory was published four days before the Minnesota attacks began. The timing and targeting profile are consistent across both the advisory and the observed campaign. Water utilities that have not reviewed AA26-097A and implemented its recommendations for PLC network isolation, project file integrity verification, and internet-facing device removal should treat the 12-state scope of this campaign as a direct operational warning. CISA has separately published CI Fortify guidance with sector-specific steps for water and wastewater systems.
  • Water and wastewater utilities should review CISA Advisory AA26-097A and the CI Fortify guidance immediately. Priority steps include isolating internet-facing operational technology systems, verifying PLC project file integrity against known clean backups, and logging all remote access to field control equipment.
  • Utilities in states not yet publicly identified should not assume they are outside the campaign scope. The FBI and EPA joint advisory recommends that all water utilities report any anomalous operational technology activity to the FBI and CISA regardless of whether they believe they have been targeted.
  • For utilities using programmable logic controllers from Rockwell, Schneider Electric, or Siemens on internet-accessible network segments, disconnect or firewall those devices from internet exposure and implement deny-by-default access rules as an immediate measure independent of longer-term patching cycles.
Thirty communities in Minnesota became twelve states in eleven days. A Georgia utility serving 300,000 people issued a boil water advisory. The campaign is ongoing. The advisory that described exactly this kind of attack was published four days before it started. Review AA26-097A today.
02 HighSamsung GalaxyBlack Hat
Researchers disclosed a one-click Samsung Galaxy exploit chain at Black Hat that gives full device access through the Samsung Members application
The chain requires one link click from the victim and uses Samsung's own preloaded applications to reach full device control. It earned $50,000 at Pwn2Own in October 2025 and was disclosed publicly at Black Hat this week after Samsung shipped fixes in August. No special permissions are needed on the attacker's part.
ResearchersDimitrios Valsamaras
Microsoft
AlsoKen Gannon
Mobile Hacking Lab
DemonstratedPwn2Own Ireland
Oct 2025 ($50,000)
Black Hat Aug 2026
TargetSamsung Galaxy S25
and earlier Galaxy
PatchedSamsung August
2026 security update
Dimitrios Valsamaras of Microsoft and Ken Gannon of Mobile Hacking Lab presented a complete exploit chain against Samsung Galaxy devices at Black Hat USA 2026 this week, nearly ten months after they first used it to win $50,000 at the Pwn2Own Ireland competition in October 2025. The chain begins with a malicious link sent to the victim through any messaging channel. When the victim clicks the link, a vulnerability in Samsung Members, an official preloaded support and diagnostics application, forces the app to connect to an attacker-controlled website. That connection is used to exploit a second vulnerability in Samsung Members and a third in Samsung Account to establish a foothold with progressively greater access. The researchers then used Bixby, Samsung's virtual assistant, as a pivot point in the chain, leveraging its integration with device functions to escalate control. The final result is full device access with no special permissions required on either the attacker or victim side beyond the victim clicking a single link. The Samsung Members application is preloaded on Galaxy devices and cannot be uninstalled by users. Samsung addressed the underlying vulnerabilities in its August 2026 security update, which covers 38 security improvements including 8 rated critical. The full technical details of the exploit chain were disclosed publicly at Black Hat this week following the coordinated disclosure process. The vulnerabilities span CVE-2025-21079 and related identifiers in the Samsung Members and Samsung Account components.
Samsung Galaxy devices represent a substantial portion of the Android market, and Samsung Members is a preloaded application that users cannot remove. A one-click exploit chain that abuses a preloaded, unremovable application gives attackers a reliable attack surface on a very large installed base. The chain does not require the victim to install anything, approve any permissions, or do anything beyond clicking a link that might arrive through a convincing message. Full device access from that single interaction means contacts, messages, stored credentials, location history, camera, microphone, and any authentication tokens or private keys stored on the device are all in scope.
Samsung's August 2026 update patches this chain along with 37 other vulnerabilities. Samsung devices receive security updates through the Samsung Members application itself, which is the same application exploited in this chain. An unpatched device is vulnerable to this attack through the very mechanism it would use to receive the fix. Enterprise device management teams that push Samsung security updates through a unified endpoint management platform should confirm the August patch has been applied to all managed Galaxy devices rather than relying on Samsung Members to auto-update a device that could be blocked by this vulnerability before the update arrives.
  • Apply Samsung's August 2026 security update to all Galaxy devices. Confirm it has applied by checking Settings, then Security and Privacy, then Security update, and verifying the date reflects the August 2026 release. Enterprise teams should push this through unified endpoint management rather than relying on device-initiated updates.
  • Until the patch is confirmed applied, be cautious with unsolicited links received through any channel on Galaxy devices. The chain requires a single link click with no additional interaction. A link received through SMS, email, a messaging app, or a QR code is a sufficient trigger if the device is unpatched.
One click. Full device access. The application being exploited is preloaded on every Galaxy device and cannot be removed. Samsung patched it in August. Confirm the update has applied. Do not rely on Samsung Members to update itself on a device that can be compromised through Samsung Members before the update arrives.
03 HighBlack HatEnterprise Java
Black Hat research found pre-authentication RCE in Bonita BPM and Apache OFBiz by chaining middleware flaws that individually appear minor
Twelve vulnerabilities across four enterprise Java platforms. Two of them produce complete unauthenticated compromise when chained. The individual flaws include URL parsing differences, hardcoded cryptographic keys, and incomplete servlet protections. None of them looked critical in isolation.
ResearchersLidor Ben Shitrit
Assaf Levkovich
Total CVEs12 across 4
Java platforms
RCE targetsBonita BPM
Apache OFBiz
DisclosureCoordinated
Black Hat Aug 2026
Security researchers Lidor Ben Shitrit and Assaf Levkovich presented findings at Black Hat 2026 covering 12 vulnerabilities across four enterprise Java platforms, with two yielding complete pre-authentication remote code execution chains. The first affects Bonita BPM, a widely deployed open-source business process management platform used for workflow automation in enterprises. The second affects Apache OFBiz, an open-source enterprise resource planning system used for order management, inventory, accounting, and related functions. In both cases, the attack chains combine individually low-severity findings into unauthenticated compromise. The component flaws include differences in how servlet containers and application layers parse URLs, leading to authentication bypass when an application checks permissions against one representation of a path while serving content from a different one; hardcoded cryptographic keys used for session or token signing that allow an attacker to forge valid authentication artifacts; and incomplete protections on servlet filters that leave certain request paths reachable without proper authorization checks. No single flaw in either chain would rate as critical by itself. The researchers noted that each component looks like a minor implementation oversight in isolation. Chained, the combination reaches unauthenticated code execution on the server. Fixes were developed through coordinated disclosure processes with the respective project teams ahead of the Black Hat presentation.
Enterprise Java platforms like Bonita BPM and Apache OFBiz process core business workflows, financial transactions, and HR data, and they frequently run on internal networks under the assumption that network position provides adequate protection against unauthenticated access. The research shows that pre-authentication remote code execution is achievable through standard web request patterns against the default installation, without any special network position or prior knowledge of the target environment. Apache OFBiz has a documented history of critical vulnerabilities: CVE-2024-38856, a critical authentication bypass disclosed in 2024, was added to CISA KEV and exploited in the wild within weeks of disclosure. The platform appears in this brief's history as a recurring high-priority target.
The URL parsing discrepancy class of vulnerability is one of the most persistent and under-acknowledged security issues in enterprise Java applications. It arises because the Java Servlet API, application frameworks, and individual application code each parse URL paths according to slightly different rules, and an attacker can craft a request that is interpreted as unauthenticated by one layer while being routed to a protected endpoint by another. This same class of issue has appeared in Spring Framework, Apache Struts, and multiple Java application servers over the past decade. The researchers' framing that seemingly minor middleware flaws combine into critical chains applies equally to any enterprise Java application where multiple layers contribute to access control decisions without a unified parsing model.
  • Apply the coordinated disclosure patches for Bonita BPM and Apache OFBiz through each project's official release channels. Check each vendor's security advisories published in conjunction with the Black Hat presentation for specific version numbers and patch instructions.
  • For Apache OFBiz deployments, verify that no prior CVEs remain unpatched. The platform has accumulated multiple critical authentication bypass and remote code execution vulnerabilities over 2024 and 2026. A current patch level review is warranted even for teams that applied patches promptly when prior CVEs were disclosed.
  • Restrict network access to Bonita BPM and Apache OFBiz administrative interfaces to known internal IP ranges rather than relying on application-layer authentication as the sole protection. Neither platform is designed for direct internet exposure, and network-layer controls provide defense in depth against pre-authentication attack chains.
Twelve flaws. Four platforms. Two paths to unauthenticated code execution on enterprise business systems. Each piece looks minor. The chain does not. Apply the patches and check whether Apache OFBiz is current, because it has been a recurring exploitation target for two years.
Cross-source standouts
01
The water campaign and the gap between published guidance and actual defensive posture
CISA published Advisory AA26-097A on Iranian-affiliated actors targeting water sector programmable logic controllers. It was updated on July 22 with expanded scope covering Schneider Electric and Siemens devices and new documentation of project file exfiltration. The Minnesota attacks began on July 26, four days later. The advisory described the attack class, named the affected device families, and provided detection guidance. The attacks happened anyway, across a sector the EPA had already assessed as broadly non-compliant with its statutory security requirements. The 12-state expansion of this campaign illustrates the structural gap between published guidance and actual defensive action in a sector where most operators are small community utilities without dedicated security staff. CISA advisories, KEV deadlines, and FBI joint announcements are necessary and insufficient. The Minnesota incident had all three, and the campaign still spread to 11 more states. The water sector needs different mechanisms than voluntary guidance to move the security baseline, and the current attack campaign makes that case more concretely than any assessment has.
02
Black Hat, chaining, and the reason individual CVSS scores are a poor predictor of actual exploitability
The Samsung chain and the enterprise Java research share a common structure: neither attack succeeds through a single high-severity flaw. Both work by combining individually lower-rated issues into an outcome more serious than any component would suggest. The Samsung chain uses a forced connection, an application vulnerability, and a platform integration to produce full device access from a single link click. The Bonita BPM and OFBiz chains combine URL parsing discrepancies, incomplete servlet protections, and hardcoded keys to reach pre-authentication code execution. CVSS scoring is computed per vulnerability, not per chain. A hardcoded cryptographic key might score as medium severity in isolation. A URL parsing discrepancy might not even warrant a CVE. When those two flaws appear in the same application and an attacker can reach them in sequence, the combined impact is critical. Security teams that triage patch work using individual CVSS scores will systematically underestimate the risk from combinations of lower-rated findings. The correct question is not what score this vulnerability received, but whether any combination of accessible vulnerabilities in this system produces an outcome we cannot accept. The Black Hat research tradition of presenting exploit chains rather than individual CVEs exists precisely to answer that question.
Still watching
Days 2–5
TeamCity CVE-2026-63077 (Issue 102 · CISA KEV, federal deadline August 8) — confirmed exploited, deadline is tomorrow. Upgrade to 2025.11.7 or 2026.1.3. If immediate upgrade is not possible, install the security patch plugin for 2017.1 and later. Audit administrator accounts and build configuration history since July 28.
Day 2
OVSwrap CVE-2026-64531 (Issue 102 · CVSS 7.8, public exploit for 800 builds) — local privilege escalation to root. Apply distribution vendor kernel patch when available. Interim mitigation: echo 'install openvswitch /bin/false' > /etc/modprobe.d/ovswrap.conf takes effect without a reboot. Check your vendor security tracker for patch availability.
Day 2
SonicWall SMA1000 CVE-2026-15409 and INC Ransomware (Issue 100 · MFA seed theft confirmed) — patch to 12.4.3-03453 or 12.5.0-02835. Rotate all TOTP seeds for enrolled VPN users. Patching does not invalidate seeds already stolen. Review logs from June 22 forward for UTA0533 indicators.
Day 5
LegacyHive (Issue 88 · Nightmare Eclipse, no patch) — Windows User Profile Service privilege escalation with working proof of concept on fully patched systems. No CVE, no fix. Now at Day 21. Three prior disclosures in this series were exploited before patches arrived.
Day 7+