SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsFollowing cyberattacks that disrupted the control systems of 30+ water utilities in Minnesota on July 26 & 27, the FBI published a public service announcement on July 30 stating that seven US states in total had reported incidents affecting the Water and Wastewater Sector (WWS). Both the FBI statement and a simultaneous alert from the US Cybersecurity and Infrastructure Security Agency (CISA) urge that programmable logic controllers (PLCs) be removed from public internet exposure, especially Rockwell Automation MicroLogix 1100 and 1400 series that have been specifically targeted. The FBI explains that attackers remotely accessed internet-accessible PLCs before changing the IP addresses and passwords, which "result[ed] in a loss of monitoring and control functionality," as well as "loss of pressure and flooding;" CISA notes that the attacks led to "boil water notices and sustained manual operations." CISA also warns that "this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans," and the FBI notes that vulnerable third-party network setups applied across multiple sites can put them all at risk. The agencies recommend that organizations disconnect PLCs from the internet and strictly mediate and monitor all network access with VPNs, gateways, and firewalls; harden and restrict access to cellular modems; rotate and strengthen passwords; switch devices into run mode; practice and prepare for manual operation of OT systems; check PLC project files; and plan the replacement of EOL devices. Neither agency has confirmed attribution of the attacks, nor specified which six states beyond Minnesota have been impacted, but SecurityWeek and The Register note reports that indicate Michigan, South Dakota, and Georgia may be among those recently targeted.

With all the focus on network connectivity it’s easy to overlook cellular modem connectivity. You need to know where it is in use, and how. There will be use cases where it is required, but find an alternative in cases where it is for convenience only. Note that cellular providers have the ability to provide public or private IP space to make it harder to access these devices; I found that a useful option where external access isn’t needed.
The FBI and CISA guidance highlights a clear security imperative: eliminate external access to operational technology (OT) systems whenever possible. When operational requirements make external connections unavoidable, organizations must formally document the risk acceptance and enforce continuous monitoring within their cybersecurity programs.
FBI
CISA
SecurityWeek
The Register
Dark Reading
Bleeping Computer
Nextgov/FCW
The Record
WIRED
In March 2026, New York introduced minimum cybersecurity standards for the state's wastewater and drinking water systems. The standards, which were developed by the NY Departments of Environmental Conservation (DEC) and Health (DOH), include mandatory cybersecurity training for certified operators, cybersecurity incident reporting requirements, risk-based tiered standards to protect critical operations and sensitive information, and designation of a cybersecurity lead role at larger drinking water systems. On Monday, August 3, New York Governor Kathy Hochul announced more than $9 million in grants to 153 state drinking water and wastewater systems to help them bolster cybersecurity defenses. The funds come from New York's Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program. The money will be used to help the utilities conduct cybersecurity assessments and implement cybersecurity improvements. The utilities will also receive technical assistance from the New York State Environmental Facilities Corporation (EFC) at no cost.
Minimum cybersecurity standards for water and wastewater are a start, but frankly, states should adopt proven frameworks like the CIS Controls or NIST CSF instead. Implementing a unified cybersecurity baseline across every critical infrastructure sector would give regulators and officials a much clearer picture of overall risk and of where to put limited taxpayer dollars.

New guidelines, with funding in the form of grants to help them be implemented, is a win-win. Talk to your state about how they could do something similar, if they haven’t already. Those in the critical infrastructure business likely want all the help they can get, not only in securing their systems (to stay ahead of current threats) but also in keeping up with emerging requirements. Don’t forget to talk to your peers to find tricks and lessons learned to help you win.

In light of recent reports of attacks against water systems, one would hope that this initiative would include strong authentication and dual party controls on all connections to the public networks, and hiding vulnerable PLCs and sensors. Given the culture of the industry, one would expect there is some connection of controls to the public networks of which management is not even aware. Hiding takes less time than identifying and patching.
A critical vulnerability in Azure Cosmos DB could be exploited to compromise all databases on the service. Wiz Research detected the flaw, dubbed CosmosEscape, which could allow attackers to obtain a platform-wide secret that the researchers have called the Cosmos Master Key, which could in turn be used to "retriev[e] the primary key of any Cosmos DB account on demand, resulting in full read & write access; ... [and] list all databases on the service with the ability to filter by specific organization identifiers like subscription and tenant IDs." Multiple Microsoft services, such as Microsoft Entra ID, Microsoft Teams, and Microsoft Copilot store data in Cosmos DB. Wiz reported the vulnerability to Microsoft on November 20, 2025. Microsoft deployed a hotfix on November 22, and in July, Microsoft rolled out an architectural update to address the issue.

Let’s start with the good news: Microsoft deployed a hotfix within two days of the notification and after analyzing their environment found no other activity than the researcher’s actions. Which means no action required on your part. The flaw could be used for command injection as well as primary key recovery due to a common signing key being used. This is what an effective VDP looks like. Make sure you’ve stacked the deck on your VDP so you can achieve similar results.
This is a textbook example of successful vulnerability disclosure: responsible reporting from Wiz paired with a swift resolution by Redmond. Outstanding job by Wiz.
Last week, Adobe published three security bulletins to address critical vulnerabilities in Adobe Campaign Classic, Adobe Bridge, and Adobe Format Plugins. On Wednesday, July 29, Adobe published a security bulletin to address two critical vulnerabilities in Adobe Campaign Classic: CVE-2026-48449, CVSS score 10.0, is a critical incorrect authorization vulnerability that could lead to arbitrary code execution; CVE-2026-48448, CVSS score 8.6 is a critical improper neutralization of special elements flaw used in an SQL injection that could lead to arbitrary file system read. The Campaign Classic advisory includes a note advising users that "Effective August 11, 2026, Adobe may assign a single CVE identifier to internally discovered vulnerabilities with the same severity rating and CWE category when a release includes systemic fixes." On Tuesday, July 28, Adobe published a security advisory to address eight critical vulnerabilities in Adobe Bridge, all of which could lead to arbitrary code execution or privilege escalation. Adobe credits external researchers for finding and reporting the vulnerabilities. Also on Tuesday, July 28, Adobe published an advisory addressing one critical vulnerability in Adobe Format Plugins. CVE-2026-48372, CVSS score 7.8, is a critical heap-based buffer overflow vulnerability in Adobe Format Plugins that could lead to arbitrary code execution. Adobe credits an external researcher for finding and reporting the vulnerability.

As these are desktop app updates, I don’t focus so much on the CVSS score as on how we are going to get these updated in a timely fashion. A silver lining here is Adobe Creative Cloud will deploy all these updates. You just need to monitor that it’s been done, which may require some prodding of users to restart their desktop apps for the updates to be applied.
Heise
The Hacker News
Adobe
Adobe
Adobe
Thermo Fisher Scientific has published a security bulletin regarding a high-severity vulnerability in its widely used DNA analysis software for crime labs that could allow "nearly undetectable modification of .fsa/.hid file types generated by select Applied Biosystems™ Human Identification software." Thermo Fisher has made updates available to address the vulnerability, which include "the use of digital signatures to add an extra layer of protection that, moving forward, will help customers verify that data files have not been modified." If customers are unable to apply the updates or switch to a different analysis platform, Thermo Fisher recommends that customers maintain a secure chain of custody for files generated by the HID instrumentation throughout the analysis workflow; store generated files on encrypted, password-protected storage media; restrict access to generated files to authorized personnel in accordance with laboratory’s access control policies; apply the principle of least privilege; and leverage firewall rules and network access control lists (NACLs) to restrict internet connectivity to only trusted sources.

One would like to assume crime lab software automatically employs good chain of custody/evidence controls. Time to verify that there wasn’t something left as an exercise for the user. Don’t beat yourself up for wishful thinking; update and improve your process (and software), then keep moving forward.
The Next Web
The Hacker News
Chemistry World
Thermo Fisher
The Arch Linux DevOps team has disabled users' ability to adopt abandoned packages in the community-maintained Arch User Repository (AUR), in response to recent campaigns to poison AUR packages with malware. Michael Taggart at IFIN noted that "openconnect-sso" was the first of several packages poisoned in a campaign beginning July 29. Arch Linux engineer Robin Candau announced on July 30 that AUR package adoption had been disabled, and on August 1 that AUR pushes were also temporarily disabled "due to the current influx of malicious package adoptions and follow-up commits made via the AUR." Taggart notes that "many of the [malware] behaviors (especially Tor exfil) look similar to the last campaign," which took place in mid-June and infected about 1,500 package build files; the previous campaign was described in NewsBites 28.45, and the payloads of both campaigns deliver infostealers. Taggart recommends users mitigate the attack by denying Tor outbound on their networks, and also check their installed packages against the results of the AUR Audit tool.

This makes me sad. AUR is an effective app store for Arch users, and I’d hate to see it lose momentum or see users adopt a less legitimate option. As part of disabling TOR outbound (if you haven’t already disabled it) make sure that you don’t have legitimate (approved) use cases that need exceptions. Work with your Arch users to make sure they are checking those packages to ensure they are legit non-doctored copies. Consider writing up (and publishing) a short procedure anyone can follow.
BleepingComputer
Arch Linux
IFIN
California-based biotech firm Amgen has disclosed a data breach that resulted in the exfiltration of "some of its data, including proprietary data, patient protected health information, and other information." In a filing with the US Securities and Exchange Commission (SEC), Amgen said that in July 2026, it became aware of "unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers." At that time, Amgen "activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts." The company's ongoing investigation is "assess[ing] whether, and/or the extent to which, patient, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated." Amgen develops and manufactures medications for oncological, hematological, and cardiovascular diseases. Massachusetts-based semiconductor chip maker Analog Devices has disclosed an IT security breach that resulted in the exfiltration of "certain files." Analog detected unauthorized access to some of its systems on June 23, 2026, at which time the company "activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities." Analog is also coordinating with law enforcement authorities. The Analog SEC filing also notes that "Separately and unrelated, on July 26, 2026, [Analog Devices] was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact."

I keep expecting to see a larger surge in attacks against chipmakers to get a leg up on the technology supporting AI. The ExfilSquad ransomware gang is taking credit for this attack. It’s not clear if Analog Devices is only missing customer data or was IP also captured. Take the position that customer data is grabbed in any breach reported and protect yourself accordingly.

There does not appear to be any information out yet on how/why this attack succeeded, and no reports on impacted customers being notified. All the news reports are based on Amgen’s 8K SEC filing where the first sentence says the data exposed was "…stored in cloud environments hosted by third-party cloud service providers." The cloud aspect became the headline for most of the follow-on coverage, but it does not change the fact that Amgen failed to protect its customers' information — quite often cloud breaches are due to user admin failure and are not the fault of the provider. The financial impact of this incident may be reduced if Amgen can receive damage compensation payments if the cloud provider was at fault, but the damage to Amgen's customers does not change.
HIPAA Journal
The Record
BleepingComputer
Amgen
The Record
SEC
UK Government Investments (UKGI), a holding company responsible for the financial interests of the UK government, disclosed in its Annual Report and Accounts publication that a data breach took place within the 2025-2026 fiscal year. UKGI did not specify the exact timing of the incident, but stated that "an internal file containing high-level management information and the names and work email addresses of 51 government officials was publicly accessible for c. 40 hours, following the actions of a member of staff who did not follow established information security policies." Once aware of the exposure, the UKGI made a report to the Information Commissioner's Office (ICO) and to an internal Audit and Risk committee, and engaged a cybersecurity firm to review the incident response, recommend security measures, and strengthen future incident preparedness. "The overwhelming majority" of the third-party firm's recommendations have already been implemented or will be within months. UKGI also notes that its report to ICO was voluntary, despite the incident not meeting the threshold for mandatory notification.

Our users remain our greatest asset and greatest liability. As the saying goes: for want of a nail the kingdom was lost. Make sure that you’ve got not only sufficient technical controls to offset users creating end-arounds but also a friendly & timely process to handle exceptions so you’re not the problem users are solving. Make sure that you’ve got monitoring and alerting to catch any attempts at an end-around. It really hurts to hear that your security is broken, dumb, or easily bypassed, so seek to understand those use cases.
The US Federal Trade Commission (FTC), along with the US states of Utah and California, is suing telehealth provider Hims & Hers, alleging that the company shared customers' sensitive health information with third-party advertising platforms like Meta, Snap, Microsoft, Pinterest, Reddit, and X, despite the company's claims that they protect customers' privacy. The complaint alleges that Hims & Hers has shared consumers’ health information with advertising platforms by sharing its customer lists and using pixel tracking. Hims & Hers allegedly used Meta Pixel and the Meta Conversions API tracking technologies to gather and transmit customer information. The company also allegedly used advertising tools from other companies that harvested customer information and provided it to third party entities to be used for advertising purposes. The complaint also alleges that Hims & Hers is deceiving consumers about billing and cancellation policies. The FTC is seeking a permanent injunction, monetary relief, and civil penalties.

Be really careful with analytics and tracking cookies on sites. They can leak information inadvertently. While I could see advertising on a public site, I can’t figure out why that would exist on the private secure site in any fashion, particularly now with the increasing number of privacy laws. Advertising is a revenue source and it is also working to extract as much telemetry and information from your users as it can for their benefit (revenue). Spin up a team to check where you have tracking and advertising and verify that you’re not set to be the next on with this type of lawsuit.
HIPAA Journal
TechCrunch
SFGate
The Register
FTC
FTC
SANS Internet Storm Center StormCast Tuesday, August 4, 2026
More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey
https://isc.sans.edu/podcastdetail/10036
AUR packages adoption disabled
Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
SANS Internet Storm Center StormCast Monday, August 3, 2026
zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability
https://isc.sans.edu/podcastdetail/10034
zipdump.py Metadata Encoding
https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
Atomic MacOS (AMOS) stealer infection
https://isc.sans.edu/diary/Atomic+MacOS+AMOS+stealer+infection/33208
Phishing Campaigns Targeting AI Solutions Providers
https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
My Upcoming Classes
Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.
Frontier AI is accelerating vulnerability discovery, adaptive attack chains, and attack volume at unprecedented scale. A new era of attacks demands a new model of prevention. Join Cato Networks for the launch of Cato Agentic Threat Prevention and see how specialized defensive agents predict attack paths, personalize protections, and adapt enforcement as threats evolve.
Webinar | From Framework to Action: Applying the SANS AI Security Maturity Model | Wednesday, September 16 | Kyriakos "Rock" Lambros
Webinar | How to Reduce Connectivity Tickets and Accelerate Application Changes
Webinar | SANS 2026 Cloud Security Exchange | Monday, August 17 | The agenda is now live. Explore expert-led sessions led by AWS, Google & Microsoft. Register to attend live or watch on demand.