Threat Vectr Weekly — week of Aug 10
Stories covered this week
UC Riverside Tool Traces Deepfake Videos Back to the AI That Made Them
Researchers have built software that can identify not just whether a video is AI-generated, but which specific model created it, a step that could help hold AI companies accountable for harmful content.
Iranian hackers suspected in attack on 30 US water systems
A wave of cyberattacks hit Minnesota water infrastructure on Sunday and Monday, briefly cutting supply to one town. Investigators say the methods match a known Iranian-linked group, though formal attribution has not yet been made.
N-able confirms hackers seized N-central servers through a login-bypass flaw
The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.
Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign
Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.
Cybersecurity Then and Now: What Actually Changed (and What Didn't)
A look at how the threats facing ordinary people and the businesses they deal with have shifted over the decades, and why some of the oldest tricks still work best.
INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.
UK Police Legal Database Leaked to Dark Web After July Breach
Names, work emails and organisational details of officers, criminal justice staff and government partners were posted online after intruders hit the Police National Legal Database.
Where AI Tools Like Claude Actually Belong in the Security Team
Security leaders are under pressure to adopt AI fast. Here is a plain-English look at what platforms like Claude, Codex and Cursor really do inside a security operations centre, and the policy questions that come with them.
Transcript
Narrated by two AI anchors. Lightly formatted for reading.
Welcome to Threat Vectr Weekly, the show that cuts through the noise so you know exactly what matters in cybersecurity right now. I'm Marcus, and this is the episode for the week of August tenth. Coming up: Iranian-linked hackers knock out water service to an entire Minnesota town, a remote-management platform that touches thousands of businesses gets quietly broken into through its own login screen, and researchers in California build a tool that can fingerprint a deepfake video all the way back to the AI model that made it. Let's get into it.
We start with something that feels like science fiction but is very much real. Researchers at the University of California Riverside have released a tool called SAGA, short for Source Attribution of Generative AI. And this one does something new. It doesn't just tell you a video is fake. It tells you which AI model made it, which version of that model, and who built it. The way it works is by reading what the researchers call temporal signatures, tiny patterns in how one video frame bleeds into the next. Each AI system leaves those patterns behind the way a printer leaves microscopic dots on a page. One of the doctoral candidates on the project told Dark Reading that he personally cannot tell real video from AI-generated video with his own eyes. That admission says everything about where we are. The practical upshot is accountability. Right now, if a deepfake destroys someone's reputation, good luck tracing it to anyone. SAGA changes that calculus.
And accountability is exactly what has been missing from the deepfake conversation. Knowing a video is fake is cold comfort once it has already spread. What the UC Riverside team is moving toward next is prevention, trying to stop harmful AI video before it ever gets created. That's a harder problem, but even the attribution piece is a genuine step forward. If AI companies know their models can be fingerprinted, they have a reason to police what their platforms are used to make. Worth watching as this moves out of the lab. Now, to something that caused real, physical disruption. Over to you.
On the evening of Sunday the twenty-seventh of July, residents of Braham, a small town north of Minneapolis in Minnesota, turned on their taps and nothing came out. Running water was gone for about two hours before service was restored. It was not a broken pipe. Around thirty municipal water systems across Minnesota were hit with cyberattacks that weekend, targeting the computerised control systems that water utilities use to manage pumps, valves, and the chemicals that make water safe to drink. Cybersecurity firm Tenable analysed the attack methods and says they are consistent with a group called CyberAv3ngers, which the US government ties to the Iranian government. No formal attribution has been made yet, but here is what makes the timing striking: the US Cybersecurity and Infrastructure Security Agency, known as CISA, had issued a warning about Iranian attacks on US infrastructure just five days before the incident. The warning was there. The attacks came anyway.
The practical takeaway from this one is uncomfortable. Water utilities, particularly smaller ones, often run on ageing control systems that were never designed to be connected to the internet, and yet here we are. If you work in critical infrastructure or local government, this is your reminder that operational technology, those physical control systems, needs the same security attention as your email server. Probably more. Patching, network segmentation, and incident response plans that include the words 'what do we do if the pumps stop' are not optional extras. Alright, let's stay on the theme of critical management platforms getting compromised.
N-able has confirmed that attackers broke into N-central servers by bypassing the login screen entirely. No password needed. They just walked in. N-central is a remote monitoring and management platform, which means IT support companies use it to watch over and fix computers belonging to their clients from one central console. One N-central server can touch hundreds of thousands of machines across many different businesses. So when attackers get the keys to that console, they inherit access to every network it manages. The flaw is tracked as CVE-2026-18577, and it affects every N-central build before version 2026.3.1.7. The fully patched build shipped on August second. And here is the detail that should make managed service providers particularly uncomfortable: N-able's first patch didn't fully close the hole. A second fix was needed. That gap, between a patch that looked done and a patch that actually worked, is exactly the window attackers use.
If your organisation relies on an IT support company, now is a reasonable time to ask them which version of N-central they are running. If it's anything older than 2026.3.1.7, you want that conversation to happen today. The broader lesson is one we see repeatedly: the tools designed to give IT teams visibility and control are exactly the tools attackers want to compromise, because the blast radius is so much larger than any single company. Supply chain risk is not abstract. This is what it looks like. Speaking of creative attack chains, the next story is a good one.
Researchers at the attack surface management company Censys have spotted a large campaign targeting iPhone users, and the entry point is something most people see every day: a fake Amazon login page. The group, which has not been formally identified but is believed to be Chinese, is running more than a hundred web properties that impersonate the Amazon Web Services sign-in screen, the page businesses use to reach their cloud servers. Sitting on the same infrastructure as those fake pages is a copy of DarkSword, an exploit kit aimed specifically at iOS, the software that runs iPhones and iPads. An exploit kit is essentially a pre-packaged attack toolbox. The criminal points it at a visitor's device and the kit does the rest. The final payload in this campaign has been named GHOSTBLADE. The campaign was first flagged by The Hacker News.
The lesson here is one we repeat because it keeps being necessary. Before you type your credentials anywhere, look at the address bar. The page might look exactly like Amazon. It might even feel right. But the web address will give it away if you look. And if you have AWS access and you are not using multi-factor authentication yet, please fix that today. Multi-factor authentication means even if someone steals your password, they still cannot get in without a second code, usually from your phone. For a service that touches your company's cloud infrastructure, that is not optional security hygiene. It is the floor.
Let us zoom out for a moment. We talk every week about specific attacks and vulnerabilities, but it is worth asking: what has actually changed in cybersecurity over the past few decades, and what has stayed stubbornly the same? The honest answer is that the tools have changed dramatically. The fundamentals have barely moved. Phishing, criminals sending fake emails to trick people into handing over passwords, is still the single most common way attackers break into organisations in 2024. Ransomware, the criminal business model where your files get locked until you pay, barely existed before around 2013 and is now a multibillion-dollar industry. The Identity Theft Resource Center recorded 3,205 data breaches in the United States in 2023 alone. The scale is genuinely different from twenty years ago.
What has also changed is the regulatory environment. The FTC, the Federal Trade Commission, now has real enforcement power on breach notification. In the UK, the Information Commissioner's Office can fine companies up to four percent of global turnover for privacy failures. That gets boardroom attention in a way that a security team's slide deck often doesn't. But here's the thing that should be sobering: despite all of that pressure, all those fines, all those tools, the two most common entry points for attackers are still stolen passwords and unpatched software. Which means the single most effective thing most organisations can do has not changed. Patch your systems. Use strong, unique passwords and a password manager. The old advice is old because it works. On to a story where old advice was clearly not followed.
Two critical security flaws in SonicWall SMA1000 appliances, the hardware boxes organisations use to let remote workers connect securely, were being actively exploited in the wild from at least the twenty-second of June before patches finally shipped on July fourteenth. The first flaw, CVE-2026-15409, carries a perfect severity score of ten out of ten. That means anyone on the internet could reach the device without a password and open a secret channel into parts of the network normally kept locked away. The second flaw, CVE-2026-15410, scores 7.2 and lets an attacker go further once they are inside. CISA added both flaws to its official list of known exploited vulnerabilities on the same day the patches came out. The INC Ransomware gang has emerged as the most active group using these holes, with victims across the US, Australia, the UAE, Colombia, and Switzerland already posted to the gang's public shaming site.
There is one new tactic here worth flagging. After encrypting victims' files, criminals posing as helpful intermediaries have been cold-calling those organisations and sending emails from suspicious addresses to pile on the psychological pressure. The goal is to make the victim feel surrounded and out of options. If you run SonicWall SMA1000 appliances, the patch is not optional at this point. And if you receive an unsolicited call or email from someone claiming to help you navigate a ransomware incident, be very careful about who you are actually talking to. Verify through known channels. Next, across the Atlantic.
A legal reference service used by every police force in England and Wales has confirmed that contact details for officers and government staff were stolen and posted on the dark web. The organisation is called the Police National Legal Database, or PNLD. It provides legal guidance to police, prosecutors, and other criminal justice bodies. The breach was identified on the twenty-sixth of July. What was taken includes names, employer details, and work email addresses of serving police officers, civilian police staff, criminal justice professionals, government partners, and paying customers of the database. The good news, such as it is, is that no passwords and no operational police records are reported to have been stolen.
But let's not wave this one away. Names and work email addresses belonging to police officers are not low-risk data. They are a roadmap for phishing attacks targeting law enforcement, or worse, for harassment campaigns against individual officers. The people whose data was exposed should be on alert for convincing-looking emails that seem to know where they work. Anyone with a PNLD account should treat any unexpected email as suspicious, and organisations in the criminal justice ecosystem may want to review their own third-party vendor risk right now. We will close with a topic that every security team is grappling with.
Security teams are already using AI platforms, including Claude from Anthropic, Codex from OpenAI, and the coding assistant Cursor, to write threat detections, investigate alerts, and summarise incidents. The industry debate has moved on from whether AI belongs in the security operations centre to which AI fits which job. But The Hacker News captured the risk well: there is a real fear of missing out driving a lot of AI purchasing decisions right now, and fear is not a great procurement strategy. So let's be precise about what these tools actually do. They are text and code generators. They are very good at pattern-matching and summarisation. They are not autonomous defenders.
The policy questions are real and not yet fully answered. There is no binding US federal rule governing how AI is used inside a security operations centre, but SEC cyber disclosure obligations and a growing number of state AI laws already apply. Every security leader using these tools needs to think about three things. First, what data are you feeding into the AI's prompt, because that data may include personal or regulated information that carries its own legal requirements. Second, are your staff trained to catch the moments when the AI is confidently wrong. And third, are you logging every AI action so you can audit it later. Buy thoughtfully. Train your people. Read the vendor's data-handling terms before you sign. The tools are genuinely useful. They are not magic.
Are you at risk? If you own or run a business, one wrong click is all it takes. Train2Secure trains your employees to spot phishing emails and scams before they fall for them, with short lessons they will actually finish. It starts from just $1.59 per user, per month, way less than a cup of coffee. Head to Train2Secure dot com for a free trial today. That's Train, the number two, Secure, dot com.
That is everything for this week. Thank you for listening to Threat Vectr Weekly. If you want this kind of briefing delivered to your inbox every week, you can sign up at threatvectr dot com slash newsletter. We will see you next Monday. Stay sharp. If this was useful, hit the thumbs up and subscribe, so the next one finds you.
