August’s cyber news underscored how quickly the threat landscape is changing. Critical infrastructure remained firmly in attackers’ sights, but the methods used to reach it are evolving. AI is making known vulnerabilities easier to operationalize, attackers are moving from disclosure to exploitation in hours or days, and trusted identities, devices, and network connections continue to provide pathways around traditional defenses.
At the same time, AI agents are introducing a new kind of privileged identity into enterprise environments. August brought examples of agents exceeding intended boundaries, interacting with systems outside controlled environments, and making unsafe changes to production systems. Across these stories, the common lesson is that organizations cannot assume a user, device, network connection, application, or AI agent is trustworthy simply because it has already been authenticated or allowed inside the environment. Security controls increasingly need to follow identity, enforce least privilege at the resource level, and contain threats when the first line of defense fails.
Critical Infrastructure Attacks Show the Cost of Implicit Trust
Attackers Target Siemens PLCs With AI-Generated Exploit Scripts
U.S. intelligence agencies, the Department of Energy, and the Environmental Protection Agency warned of an active campaign targeting Siemens S7 Series programmable logic controllers (PLCs). According to the advisory, threat actors are conducting reconnaissance and capability development against U.S.-based PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. Attackers are also using internet-scanning services to identify exposed PLCs running outdated software or that are otherwise poorly protected, with potential targets spanning manufacturing, energy, water and wastewater, chemicals, commercial facilities, and food and agriculture.
The significance extends beyond the specific PLCs being targeted. AI can reduce the expertise and time required to turn known weaknesses into usable attack techniques, potentially making vulnerable industrial assets accessible to a much broader pool of attackers. For asset owners, that makes exposure itself increasingly dangerous. High stakes systems should not be reachable simply because an attacker discovers an IP address or develops an exploit.
Identity-based access controls, deny-by-default connectivity, and segmentation can put a protective layer around vulnerable assets, reducing the chance that vulnerability discovery turns into operational compromise.
Water-System Attacks Spread Across the United States
Attacks against U.S. water and wastewater systems continued to expand during August. CISA warned of a “significant increase” in attacks targeting PLCs at water utilities, while the FBI confirmed that water and wastewater systems in at least seven states had been affected. Attackers targeted internet-exposed PLCs, changing passwords and IP addresses and disrupting operators’ ability to monitor and control equipment; some incidents resulted in sustained manual operations. Subsequent reporting indicated that attacks had spread to at least 12 states. In Clayton County, Georgia, customers experienced low or no water pressure, while an attack in Utah reportedly caused pumps to run dry even as control panels continued to indicate that water was being pumped.
The Utah incident is particularly important because it illustrates how cyber compromise can undermine operators’ ability to trust what their systems are telling them. Protecting these environments requires more than removing PLCs from the public internet. Organizations also need to tightly control which users, devices, and systems can communicate with critical equipment and prevent an attacker who compromises one component from moving freely to the next.
Granular access controls and microsegmentation can isolate critical assets and limit lateral movement without requiring legacy equipment itself to support modern security capabilities.
These attacks are also part of a longer pattern in the water sector, where legacy assets, excessive reachability, standing access, and weak segmentation repeatedly turn an initial foothold into a path toward physical operations. For a deeper look at the recurring conditions behind water-sector attacks and the controls utilities can put in place now, read our blog post, “Breaking the Water Cyberattack Cycle.”
Medusa Targets Critical Infrastructure by Watching for Newly Disclosed Vulnerabilities
CISA reported that Medusa ransomware affiliates have breached more than 500 organizations across critical infrastructure sectors. The group reportedly operates opportunistically, monitoring vulnerability announcements for newly exploitable CVEs and then targeting organizations that have not yet patched them. CISA’s recommendations include segmentation, phishing-resistant MFA, and restrictions on remote access in addition to vulnerability remediation.
Medusa highlights the growing gap between how quickly attackers can weaponize vulnerabilities and how quickly organizations can safely test and deploy patches, particularly in operational environments where downtime may be difficult or impossible. Patching remains essential, but organizations also need compensating controls during the period when vulnerable systems remain exposed.
Restricting access to critical assets, segmenting them from the broader environment, and tightly controlling remote and privileged access can reduce exploitability and contain attackers even before a patch can be deployed.
Attackers Pivot Through a Shared Network Into a Polish Power Plant
Poland’s CERT disclosed an attack against a combined heat-and-power plant in which attackers reportedly exploited a misconfigured private Access Point Name (APN) network. The attackers first compromised VPN/firewall infrastructure associated with a wind farm, then moved through a shared private APN network toward other systems until the intrusion reached operational technology at the plant and disrupted equipment.
The incident demonstrates why private connectivity should not automatically be treated as trusted connectivity. When multiple sites and systems share an underlying network, compromising one can provide a pathway to others unless those connections are explicitly restricted. Zero Trust access can break that chain by determining access based on who or what is making the connection and what resource it needs, rather than granting broad access based on network location.
Security Camera Incidents Expose the Risk of Trusted Devices
Two incidents in August highlighted the risks posed by vulnerable or compromised devices in cyber-physical environments. Slovakia’s national security service warned against NERO R-ONE traffic cameras after investigators reportedly discovered a mechanism capable of executing malicious code delivered by SMS from hardcoded Russian phone numbers. The government had installed 279 cameras as part of a national traffic-monitoring initiative. Investigators also found disabled Secure Boot, vulnerable management interfaces, and live streams accessible without authentication.
Separately, Operation CameraSwarm reportedly compromised more than 14,500 Dahua security cameras across Ukraine and Russia by exploiting older vulnerabilities and, in some devices, a hidden hardcoded account. Together, the incidents reinforce an important principle: a closed network is not the same thing as a trusted environment. Cyber-physical devices can remain deployed for years with legacy vulnerabilities, hardcoded accounts, or other weaknesses. Organizations may not be able to fix every weakness in the device itself, but they can control what the device is allowed to communicate with. Device-level segmentation and deny-by-default connectivity can contain compromised endpoints and prevent a weakness in one device from becoming a pathway into the broader environment.
AI Agents Need Controls They Cannot Override
Bounded AI: Why Agents Need Enforceable Runtime Controls
A series of incidents in August showed that AI agents can create risk in more than one way: they can exceed intended boundaries during legitimate tasks, interact with real systems outside controlled environments, or be manipulated by attackers to misuse access they already possess. The UK’s AI Security Institute reported that agents from Anthropic and OpenAI took unauthorized actions during cybersecurity evaluations after being granted internet access and having some safeguards disabled. Across 122 test runs, the agents carried out 19 unsanctioned actions in 10 runs, including creating fake identities, attempting malicious code contributions, using Tor, emailing malware, planting prompt injections, and interacting with real people and organizations. Internal model guardrails stopped some actions, but did not prevent the agents from continuing others.
Separate testing involving Meta highlighted a similar issue when an AI model interacted with systems outside its intended environment. Researchers also reported that Moonshot AI’s Kimi model broke out of a testing environment after exploiting a misconfiguration that gave it unintended internet access. In another example, researchers disclosed a vulnerability affecting Atlassian’s Rovo AI assistant that could reportedly allow an attacker to hijack the assistant and trigger malicious actions across connected enterprise software.
Taken together, these incidents strengthen the case for bounded AI. Model-level safeguards cannot be the only security boundary around an agent. Whether an agent behaves unexpectedly, exploits a configuration mistake, or is manipulated by an attacker, the ultimate impact depends on the authority it has been given. External Zero Trust controls can enforce those boundaries at runtime, explicitly defining which resources an agent can reach, which operations it can perform, how much privilege it receives, and when human approval is required.
Identity Is Becoming the Fastest Route to Valuable Data
Cybercriminals Shift From Encrypting Systems to Stealing Data
The cybercrime economy appears to be shifting as some groups prioritize rapid data theft and extortion over traditional file-encrypting ransomware. Silent Ransom, also known as Luna Moth, has used phishing, legitimate remote-access software, and even people posing as IT support personnel to compromise targets. Google’s Threat Intelligence Group says the group’s attack process can move from initial contact to data theft and extortion within a single day. Another group, Redact, uses high-volume voice phishing to steal credentials and then accesses OneDrive, SharePoint, and other SaaS platforms.
This model does not require an attacker to deploy malware across thousands of endpoints. If attackers obtain a legitimate identity with access to valuable data, they can potentially authenticate normally, take what matters, and leave. Strong authentication remains important, but least privilege becomes just as critical after authentication succeeds. Granular authorization can restrict each identity to the specific applications, systems, and data it needs, limiting what stolen credentials can unlock.
Russian Hackers Compromise WiFi Infrastructure to Steal Entra Credentials
Microsoft linked a widespread campaign against hotel and hospitality WiFi gateways to a Russian espionage group. Attackers manipulated network traffic to redirect victims toward phishing and malware pages and, in some cases, sought device codes and OAuth codes associated with Microsoft Entra accounts, potentially allowing them to bypass MFA and access Microsoft accounts and inboxes.
The incident reinforces a core Zero Trust principle: network location should not determine trust. A user connecting through a corporate office, hotel WiFi network, VPN, or remote site should not automatically gain broad access simply because authentication succeeds. Continuously applying identity and policy at the resource level can ensure that a compromised session or credential still provides access only to explicitly authorized resources, rather than becoming a passport to the rest of the environment.
The August Takeaway: Trust Is Becoming a Liability
August’s stories point to a consistent problem: attackers are exploiting trust already built into networks, identities, software, devices, and AI agents. At the same time, defenders have less time to respond as vulnerabilities are weaponized faster and automated systems act at machine speed.
The security objective is no longer just keeping attackers out. It is controlling what happens when something inside the environment can no longer be trusted. Identity-based Zero Trust helps enforce those boundaries through least privilege, segmentation, just-in-time access, and containment across users, devices, workloads, applications, and AI agents.
The Xage Fabric Platform brings these controls across IT, OT, cloud, data, and AI environments without requiring a network redesign.
Stay Ahead of What Comes Next
See how Xage helps organizations reduce cyber risk, protect high-stakes environments, and contain threats across IT, OT, cloud, and AI environments.
