CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◍ Incident Response & DFIR Jul 30, 2026

Infosec News Nuggets — July 30, 2026

AboutDFIR Archived Jul 30, 2026 ✓ Full text saved

Coordinated Cyberattack Targets 30+ Minnesota Water Systems A coordinated intrusion hit operational technology at more than 30 community water and wastewater utilities across Minnesota on July 26 and 27, disrupting automated control functions and briefly knocking one city’s treatment plant offline while state and federal investigators, including the FBI, work to identify the attackers and […] The post Infosec News Nuggets — July 30, 2026 appeared first on AboutDFIR - The Definitive Compendium Pr

Full text archived locally
✦ AI Summary · Claude Sonnet


    By MaryOn July 30, 2026 Coordinated Cyberattack Targets 30+ Minnesota Water Systems A coordinated intrusion hit operational technology at more than 30 community water and wastewater utilities across Minnesota on July 26 and 27, disrupting automated control functions and briefly knocking one city’s treatment plant offline while state and federal investigators, including the FBI, work to identify the attackers and confirm whether the incidents are connected to broader warnings about threat actors targeting industrial control systems from major automation vendors.   SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A software supply chain campaign dubbed SleeperGem hijacked dormant RubyGems maintainer accounts, some inactive for six or seven years, to push malicious updates that impersonate a legitimate Microsoft credential tool, quietly check whether they’re running on a CI server before deploying a persistent native backdoor on developer machines, and in some cases attempt to plant a setuid root shell for privilege escalation.   CubePilot drone software dev hit by DNS hijacking to intercept traffic An Australian maker of drone flight controllers used in surveying, search and rescue, and defense applications had its domain’s DNS records hijacked for roughly a day, letting an attacker obtain valid TLS certificates for every subdomain and potentially capture credentials entered on its customer portal and forum before the company regained control, revoked the fraudulent certificates, and reported the incident to Australian authorities.   Healthcare giant Abbott probes two cyber incidents amid extortion claims Abbott Laboratories confirmed unauthorized access to internal systems tied to its Cancer Diagnostics business and separately to an externally hosted lab-services portal, after two extortion groups claimed to have stolen tens of millions of patient notes, medical orders, and Social Security numbers; the company says operations and patient care are unaffected and neither group has yet published samples of the alleged data.   Flying Eagle Android RAT source code circulates on Telegram Source code for the Flying Eagle Android remote access trojan, a framework capable of capturing payment passwords, recording screens, and abusing accessibility services for keylogging, is now spreading through criminal Telegram channels after researchers traced matching control panels and certificates to roughly 170 active servers tied to a fake Chinese public-security app, with a successor platform already appearing online. CATEGORIESInfoSec News Nuggets TAGSAboutDFIRCubePilotnews nuggetsSleeperGem SHARE FACEBOOK TWITTER LINKEDIN PINTEREST STUMBLEUPON EMAIL
    💬 Team Notes
    Article Info
    Source
    AboutDFIR
    Category
    ◍ Incident Response & DFIR
    Published
    Jul 30, 2026
    Archived
    Jul 30, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗