:

IRAN-LINKED HACKERS TARGET 100 US WATER UTILITIES

SECURITY DESK1 MIN READ
WED, SEP 2, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.

The cyberattacks represent a significant breach of U.S. critical infrastructure, with hackers gaining access to water treatment and distribution systems across multiple states. The campaign highlights vulnerabilities in aging water utility networks, many of which operate with limited cybersecurity resources. The EPA's $11 million grant program aims to address these gaps by funding security upgrades, threat detection systems, and employee training at water utilities nationwide. The funding supports vulnerability assessments, implementation of security controls, and incident response capabilities. U.S. cybersecurity officials have attributed the attacks to Iranian state-sponsored groups. Water utilities are among the most critical infrastructure sectors, and disruptions could affect millions of Americans' access to clean water. Water systems have historically faced cybersecurity challenges due to aging infrastructure, legacy systems, and budget constraints. The federal funding represents an escalation in efforts to secure these assets against state-sponsored threats.

■ SOURCES

Bloomberg Tech

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.

2H AGOSecurity Desk

A critical authentication bypass vulnerability in JFrog Artifactory is being actively exploited to create administrative access tokens. The flaw (CVE-2026-82329) grants attackers full control over software repositories.

2H AGOSecurity Desk

Spyware was used against Serbian student activists and politicians organizing anti-corruption protests ahead of March local elections, according to a new report. The targeting allegedly focused on opponents of President Aleksandar Vucic.

2H AGOIndustry Desk

The New York Stock Exchange deployed Anthropic's Project Glasswing to identify and remediate cybersecurity vulnerabilities, NYSE President Lynn Martin disclosed to Congress.

2H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.