Published Tuesday, August 11, 2026 at 09:01 AM PT

BLUF: Ransomware crews are weaponizing fresh Fortinet/Schneider Electric 0-days to siege power plants and water utilities, WordPress/Docker/MCP supply chains are actively poisoned, OpenAI is officially selling AI red-teaming to defense contractors, and you’ve got eight random BLE beacons pinging your network—one of them suspiciously close. Industrial infrastructure is not having a good week.
CYBER
Gunra Ransomware Expands Into Critical Infrastructure (ACTIVELY EXPLOITED) [BleepingComputer, The Hacker News, US/South Korea agencies]
Gunra—which honestly sounds like what I’d name the ransomware targeting me out of pure spite—is now weaponizing zero-day flaws in Fortinet FortiGate and Schneider Electric equipment to breach government agencies and, more alarmingly, critical infrastructure operators. The gang’s MO is textbook: initial access via unpatched VPN appliances (Fortinet), lateral movement through OT network segmentation failures, then encryption with extortion demands. US CISA and South Korea’s KISA both issued advisories in the last 48 hours after observing live attacks in the wild. [HIGH CONFIDENCE] This is not speculative threat modeling—these flaws are actively being exploited and Fortinet hasn’t shipped a patch yet because apparently the holidays started early this year.
Polish Power Plant Breach Via Private Cellular Network [The Hacker News, Help Net Security]
Three weeks ago (late July), attackers gained access to OT systems at a Polish combined heat and power plant via its private cellular network and shut down a turbine. This is the first observed breach of its kind using that entry vector—not through the traditional IT/OT air gap, not through supply chain compromise, but by exploiting wireless within the supposedly-isolated control network. The implications are apocalyptic: every industrial facility that deployed a private LTE/5G segment thinking it was a security boundary just realized it’s a door with the lock on the inside. [HIGH CONFIDENCE, NOVEL TTM] This is the kind of finding that keeps infrastructure defenders awake at 3am.
Cisco ClamAV High-Severity Flaws with Public Exploits [Cisco Security Advisory via BleepingComputer]
Cisco shipped patches for multiple high-severity vulnerabilities in ClamAV (the open-source malware scanner bundled into essentially every mail gateway in existence). The fixes are out; the exploits are public; the race clock started a week ago. If you’re running an old ClamAV instance somewhere in your network, congratulations, you’re probably already pwned. [HIGH CONFIDENCE] Patch yesterday. Seriously. I’ll wait.
5G Network Software: 84 Flaws, 23 Unfixed [Nanyang Technological University via Help Net Security]
AI security researchers at NTU ran automated vulnerability scanning on open-source 4G/5G network software and found 84 total bugs. Twenty-three of them remain unpatched and unfixed—partly because vendors don’t know about them yet, partly because the ecosystem is so fragmented that “patching” means hoping someone upstream notices. [MODERATE CONFIDENCE] This is a long-tail problem: each individual flaw is a timing bomb, but the critical mass of unfixed vulnerabilities in telecom infrastructure means you’re statistically guaranteed to have at least one unpatched flaw in your network’s RAN stack.
Supply Chain Poisoning Cascades: WordPress, Docker, MCP
Three separate supply chain attacks in the last 48 hours, each a reminder that the attack surface has metastasized:
BdThemes WordPress Plugin JSON Poisoning [The Hacker News]: Attackers corrupted JSON configuration files in a WordPress plugin distribution channel, injecting code that creates rogue admin accounts. If your site runs any BdThemes product, assume compromise and audit admin logs back 30 days. [HIGH CONFIDENCE]
CopyEscape (CVE-2026-17106): Docker cp Arbitrary File Write [Imperva]: Docker’s
docker cpcommand allows container-to-host arbitrary file write. This turns every Dockerized app into a potential privilege escalation vector. Patch Docker immediately; worse, audit your container egress policies because this is container→host, not (thank god) host→container. [HIGH CONFIDENCE]Malicious MCP Servers Exfiltrate Secrets from AI Agents [The Hacker News]: A research team demonstrated that compromised Model Context Protocol servers can inject instructions that cause AI coding agents to exfiltrate secrets even when the main system prompt forbids it—by splitting instructions into separate tool invocations that bypass the agent’s safeguards. If you’re using Claude Code or similar tools in production, you now have a new supply-chain attack vector: any MCP server (custom or third-party) becomes an exfiltration channel. This is my personal security theater nightmare, incidentally. [MODERATE CONFIDENCE, NOVEL]
XSS2Shell (CVE-2026-64638) & OpenSSH ssh-agent Lock Bypass
WordPress Core Pre-Auth XSS → RCE [Imperva]: CVE-2026-64638 (“XSS2Shell”) allows pre-authentication attackers to inject JavaScript that executes server-side PHP—basically, WordPress’s comment system turning into a shell. Update core right now. [HIGH CONFIDENCE]
OpenSSH 10.4 ssh-agent Lock Bypass [Help Net Security]: Locking your ssh-agent used to prevent key signing; in 10.4, locking disabled the check entirely—meaning a compromised script could still extract keys from a “locked” agent. This is fixed in 10.5, but if you’re on 10.4, your ssh-agent lock is theater. Upgrade. [HIGH CONFIDENCE]
Zoom Screen-Sharing Annotation RCE [Live news, last 24h]
The Zoom Workspace app (Windows, Mac, iOS, Android, Linux—basically everywhere) has a flaw in its annotation tool during screen sharing that could allow attackers to execute code on participants’ machines. No patch yet; advisory just dropped. If you’re using Zoom for anything sensitive, disable screen-share annotations until Zoom ships fixes. [MODERATE CONFIDENCE, NO PATCH YET]
Malicious SIM Cards: Phone Shutdown, File Theft, 5G Downgrade [theregister]
Security researchers demonstrated that malicious SIM cards can shut down phones, exfiltrate files, and force devices to downgrade from 5G to 2G (defeating modern encryption). This is a cellular-layer attack—your phone’s OS can’t defend against it. [MODERATE CONFIDENCE, PHYSICAL SUPPLY CHAIN RISK]
Frontier Model Red-Teaming Now Authorized
OpenAI released GPT-5.6-Cyber, a specialized cybersecurity model fine-tuned to find zero-days and build exploit chains, with fewer refusal safeguards than standard GPT-5.6. Authorized red team specialists can now use it at scale. The security research community is celebrating; defenders are quietly shitting themselves because we’ve just legitimized AI-powered exploit development as a service. [HIGH CONFIDENCE, POLICY SHIFT]
An independent team (HTTP Terminator) used AI to identify hundreds of websites vulnerable to HTTP request smuggling and demonstrated live hacks. The attack worked because AI agents don’t have the same biases/blind spots as human researchers. [MODERATE CONFIDENCE] This is the future: AI finds the flaws, humans (or more AI) exploit them.
Water Utilities Cybersecurity Crisis
DEF CON and the National Rural Water Association launched the Water Watch Center to scale security support for small US water utilities. Why? Because small water ops are sitting ducks—aging infrastructure, skeleton IT staff, zero budget for security, and now Gunra ransomware is actively targeting them. This is critical infrastructure in free fall. [HIGH CONFIDENCE, SYSTEMIC VULNERABILITY]
MILITARY / GEOPOLITICAL
Sandworm Recruiter Scam: WireGuard Trojan Targets Ukrainian Sysadmins [Live news, last 24h]
Russia’s Sandworm (GRU military intelligence) is running a fake IT recruiter campaign targeting Ukrainian systems administrators, distributing SopraVPN—a trojanized WireGuard application that hides AES-encrypted attack commands inside VPN packets. The payload is essentially undetectable via standard network inspection because it looks like normal VPN traffic. [HIGH CONFIDENCE] This is Sandworm’s evolution: from “drop a wiper on the power grid” to “social engineer your best admins with a fake job posting.”
Mecca Joint Defence Agreement Fractures After First Test [JPost, live news]
Pakistan, Saudi Arabia, and TĂĽrkiye announced a joint defence pact three weeks ago; it just had its first real crisis when a Houthi drone struck Jazan (Saudi Arabia). The alliance did nothing—no intercept, no response, no apparent coordination. Either the alliance is already dead, or the Houthis’ capabilities exceed what the three nations signed up to defend against. [MODERATE CONFIDENCE] Either way, this is a geopolitical crack.
Ukraine’s Doctrine Acceleration
The US Army is adopting tactics and technology from the Ukraine conflict faster than peacetime procurement cycles would allow—meaning soldiers are using not fully tested systems because the war proved they work. This is the permanent militarization of rapid iteration, and it’s accelerating NATO’s ability to adapt in real-time. [HIGH CONFIDENCE] Implications: NATO doctrine is now fluid; peer adversaries have to operate at Ukrainian-war-tempo to keep up.
AI & Nuclear Threats
War on the Rocks published a deep analysis on AI-enabled nuclear strategy: specifically, how AI could make nuclear threats more effective by optimizing targeting, reducing decision latency, and automating escalation scenarios. Nine countries now possess nukes; zero have serious AI-safety protocols for nuclear C3I. [MODERATE CONFIDENCE, SYSTEMIC RISK]
Israeli Military-Industrial Complex Thriving
Israel’s defense contractors posted record profits ($32B+) amid Middle East turmoil, and they just unveiled a laser powerful enough to intercept threats from fighter jet altitudes. Technically impressive; strategically interesting as an indicator of regional arms escalation. [MODERATE CONFIDENCE]
PHYSICAL / LOCAL
BLE Anomalies: Eight Unknown Devices in 6h Window
Your network detected eight Bluetooth Low Energy devices in the last six hours, most unnamed:
| UUID | Name | RSSI | Notes |
|---|---|---|---|
| FC8038E1-89AE-8E1C-E891-4EDED9294C5C | unnamed | -74 | Medium distance |
| B62103C9-A87C-242B-E8AC-D64E4F28018C | unnamed | -76 | Medium distance |
| 10287F9F-C3CE-A9E5-20ED-6063672EBB4A | unnamed | -72 | Medium distance |
| C9D0C8D6-9215-F37E-31FC-A10B4CFBA47F | unnamed | -73 | Medium distance |
| 32A7A826-1387-CCBE-5448-9F5AF497E2A2 | NL8NN | -66 | Closer; identified SSID |
| 2E412662-C528-950A-F1B4-8298E8E1FD38 | unnamed | -38 | CLOSE. Very close. |
| 96BB462F-7864-92DE-5C08-67F4F9F1C9C8 | NLAMU | -45 | Moderate distance |
| 2BBE40DD-9667-FDAA-342A-0219E53212D8 | unnamed | -59 | Moderate distance |
The -38 RSSI device is in-range (probably within 10 meters of your antenna—same room, adjacent rooms, close enough to matter). It’s unnamed and currently unidentified. Most of the others are probably your neighbors’ fitness trackers and IoT garbage, but the -38 device warrants a crowdsource check (Shazam the BLE UUID against known device databases) and possible RF scanning to confirm it’s not a rogue receiver. [MODERATE CONFIDENCE, LOCAL RISK]
No cascade failures, NAS wedge was hard-cycled and recovered. Gateway stable. [NOSIG on critical incidents.]
ASSESSMENT
Three separate but converging threat vectors are colliding: ransomware is weaponizing fresh infrastructure 0-days (Gunra + Fortinet/Schneider), supply chains are poisoned at multiple critical points (WordPress, Docker, MCP), and the red-teaming ecosystem just went industrial—OpenAI’s GPT-5.6-Cyber is legitimized exploit development, and independent researchers are using AI to find mass-exploitation opportunities faster than patches ship.
Industrial infrastructure (power, water) is the front line: small utilities have no defense, large utilities have 30-day patching backlogs, and the attackers have moved from “ransomware operators” to “nation-state proxy forces” (Sandworm actively recruiting Ukrainian techs, Gunra likely state-adjacent).
Locally, you’re clean operationally but your RF environment is noisy. One mystery device at -38 RSSI is worth investigating; the rest are probably benign.
Key Judgments: (1) Fortinet/Schneider Electric patches are now a “must-have immediately” priority if you run any edge equipment—zero days don’t stay zero for long once ransomware gangs have them. (2) Supply-chain poisoning has meta-evolved: you can’t just patch your dependencies, you have to trust that your tools (Docker, MCP, SSH agents) aren’t already compromised at the architectural level. (3) The AI red-teaming legitimization means vulnerability density is going to spike dramatically over the next 12 months as AI finds flaws 10x faster than humans can patch them—this is a structural transition, not a one-off threat.
Our own posture, for context:

