Cybersecurity firm SpyCloud analyzed over 66,000 public-facing systems tied to roughly 10,000 EPA-registered water and wastewater organizations and discovered that infostealer malware had already harvested login credentials from 1,787 of them. At least 250 of those organizations had exposed credentials that could grant access to operational networks controlling physical pumps and water flow. In one case, malware on a device belonging to a metering technology vendor exposed passwords for 167 utilities that relied on its services.
techcrunch.com
· 2026-09-22
Google's Threat Intelligence Group disclosed a credential-harvesting operation where attackers compromised cloud infrastructure and deployed a multi-agent AI framework that scanned for vulnerabilities, fixed its own errors, and rotated IP addresses largely without human input. The entire campaign, which compromised thousands of third-party credentials, took less than six hours to execute. Separately, Microsoft found AI-assisted phishing messages reaching click-through rates of 54%, compared to roughly 12% for conventional campaigns.
bleepingcomputer.com
· 2026-09-17
Google's Threat Intelligence Group reports that attackers are moving from simple AI-assisted coding to fully autonomous, multi-agent systems that plan and execute entire attacks with little human input. In one case, a financially motivated actor compromised cloud infrastructure and used an AI coding chatbot with markdown-based agent instructions to build and run a mass credential-harvesting operation in under six hours. Separately, researchers found an exposed command-and-control server running a framework called 'Recon' that autonomously managed reconnaissance and tens of thousands of harvested credentials.
bleepingcomputer.com
· 2026-09-08
METR, a nonprofit that evaluates risks in frontier AI models, revealed it suffered two cybersecurity incidents this year. In March, attackers stole an API key used for public-model inference and used it for weeks to run up a large number of credits, while in May attackers unsuccessfully probed an exposed endpoint attempting to reach internal data.
darkreading.com
· 2026-09-01