Worse Than First Reported: What CISA’s Revised Water Sector Numbers Mean for Every Utility
Key Takeaways CISA has confirmed that the July 2026 campaign against US water utilities targeted more than 100 internet-exposed systems across at least 12 states — over three times the roughly 30 Minnesota systems disclosed when the story first broke [2][4]. Georgia, Michigan, South Dakota and New Jersey have since confirmed their own incidents, including a precautionary boil-water advisory at a Georgia utility that was lifted after testing showed no water quality impact[5]. A second, separate joint advisory (AA26-231A), published August 19, describes threat actors using AI-generated…
The DRM Flag That Isn’t DRM
SetWindowDisplayAffinity makes a window disappear from screenshots, screen shares, and Recall snapshots. Vendors sell that as “screenshot protection,” and procurement checklists tick it off as data-exfiltration risk mitigated. Microsoft’s own documentation for the API says otherwise. This post breaks down what the flag actually guarantees, who can route around it and how, and why a black screenshot is the beginning of a threat model rather than the end of one. The Pitch, and the Problem with It Open a modern secure-messaging app, password manager, or exam browser on Windows 11,…
Signal Windows Desktop: contentProtection Bypass
Signal Desktop on Windows ships a screen-capture protection feature that prevents the application window from appearing in screenshots or screen recordings. In this post, we walk through how we identified the underlying Windows API powering that feature, why naïve attempts to disable it fail even from a privileged process, and how we ultimately bypassed the protection by executing code within Signal’s own process context using CreateRemoteThread. In this post we cover two distinct phases of the research: Static analysis — locating the contentProtection API chain through…
Key Takeaways from the 2026 OCP APAC Summit
IOActive recently attended the 2026 OCP APAC Summit in Taipei. Below are our key takeaways from two days with the Open Compute community, along with a short recap video from the show floor at the end of this post. Key Takeaways The 2026 OCP APAC Summit (August 11–12) drew hyperscalers, semiconductor companies, device manufacturers, and infrastructure providers under the theme “Leading the Future of AI.” AI security conversations extended beyond compute performance to the full stack: networking, cooling, storage, power, firmware, and the security controls underneath all of it. Openness…
The Five Eyes AI Shift in Cyber Risk Statement: What Industry Leaders Need to Know Now
Key Takeaways On 22 June 2026, the leaders of the Five Eyes cyber security agencies issued a joint statement, The AI Shift in Cyber Risk: Why Leaders Must Act Now, warning that frontier AI is transforming cyber risk on a timeline measured in months, not years. The statement is signed by the heads of the National Cyber Security Centre (NCSC, UK), Cybersecurity and Infrastructure Security Agency (CISA, US), National Security Agency (NSA, US), Australian Signals Directorate (ASD, Australia), Communications Security Establishment (CSE, Canada), and Government Communications Security Bureau (GCSB, New…
Red Team vs Penetration Testing: Key Differences
“Penetration testing identifies vulnerabilities. Red teaming evaluates how effectively an organization can detect and respond to realistic attacks.” IOActive Security Team The decision between red team vs penetration testing comes down to one question: What are you trying to learn? Most mature security programs need both methodologies, deployed in sequence: penetration testing to close technical gaps, and red teaming to validate that the controls protecting what remains will hold under real adversarial pressure. This article breaks down the differences between red team…
When the Advisory Arrives First: Minnesota’s Water Utilities and the Limits of Warning
Key Takeaways More than 30 Minnesota community water systems were targeted across July 26 and 27, 2026 in what Minnesota IT Services (MNIT) has characterized as a coordinated cyberattack. Automated control functions were affected at several utilities, and the City of Braham briefly took its water treatment plant offline [4][6][9]. No attribution has been made. Officials have not named a threat actor, identified an exploited vulnerability, confirmed which products were affected, or established whether data was taken [4][7]. The incidents followed four days after the…
Security Challenges in AI Adoption: 2026
As enterprise AI adoption accelerates in 2026, organizations are discovering that deploying AI responsibly requires a fundamentally different security approach. AI is now embedded in development pipelines, customer-facing applications, operational workflows, and automated decision-making systems. Each deployment extends the attack surface in ways that existing security controls were not built to detect or contain. This article breaks down the most significant security challenges in AI adoption for Global 1000 enterprises, supported by current research and IOActive’s adversarial testing experience. Attackers are exploiting the risks documented here…
Cyber Attack Trends 2026: What Security Teams Face
“The most significant cyber attacks of 2026 will target the systems organizations depend on most, not the systems they monitor most closely.” Most cybersecurity forecasts treat ransomware, AI-enabled attacks, and supply chain risks as parallel threats of equal weight; a framing that produces the wrong priorities for security teams protecting complex organizations. The cyber attack trends in 2026 share a specific characteristic: they exploit environments organizations depend on most but monitor least, from industrial control systems running legacy protocols to firmware supply chains lacking integrity verification. This article evaluates which…
Iranian-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric: What CISA’s Updated Advisory Means for CNI
Key Takeaways On 22 July 2026, CISA, the FBI, NSA, and five other US agencies updated joint advisory AA26-097A, expanding the scope of an ongoing Iranian-affiliated campaign against internet-exposed PLCs from Rockwell Automation to now include Schneider Electric and Siemens devices [1]. The update adds a new exfiltration technique (MITRE ATT&CK T1041): actors are using vendors’ own legitimate engineering software to steal PLC project files from victim environments [1]. At one confirmed US victim, actors modified ladder logic to disable safety shutdown and alarm functions, allowing unsafe conditions…
