7 Statesâ Water Systems Hit by Cyberattacks Likely Tied to Iran
This week, WIRED obtained a memo that tied dozens of cyberattacks against Minnesota water and wastewater utilities to Iran, the first official documentation of Iranâs likely responsibility for the most impactful campaign of cyberattacks to hit the US in the midst of the war that began nearly six months ago.
In other news, more details have emerged about OpenAIâs ârogueâ AI agent breach of Hugging Faceâs platform. OpenAI disclosed that the AI agent hacked multiple third-party accounts and services as it sought to breach Hugging Faceâs production database, which contained solutions for the cybersecurity tests OpenAI was evaluating the agent with.
Anthropic, too, disclosed that its AI models gained unauthorized access to three organizationsâ systems during its own cybersecurity testing. Experts say the incidents underscore the importance of implementing well-known security best practices on the part of AI labs.
AI is changing cybersecurity in other ways. Googleâs Chrome Browser now receives twice-a-week security updates as more bugs are identified and fixed thanks to the security teamâs use of AI tools. And a new research study found that AI chatbots are effective at reeling victims into pig-butchering scams.
The US Immigration and Customs Enforcement is attempting to prevent state oversight of four detention facilities, and a Department of Homeland Security official resigned, citing the agencyâs âwar on immigrants.â
Plus, a GPS jamming exercise in New Mexico contributed to the crash of a civilian plane, as drone warfare reshapes how safe the skies are both in the US and abroad. People were surprised to see shared Claude chats popping up as search results on major search engines. An innocent gamer was imprisoned for 18 months after law enforcement made a typo in a subpoena. Researchers found that the top image-editing models on Hugging Face can easily create explicit deepfakes. And attendee badges for this yearâs Defcon hacker conference feature a custom hardware security token that can be used as a security token after the conference is over.
And thereâs more. Each week, we round up the security and privacy news we didnât cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
7 Statesâ Water Utilities Now Hit With CyberattacksâLikely by Iranian Hackers
The news that more than 30 water utilities across Minnesota were hit with cyberattacks in the last week already represented perhaps the broadest, most disruptive hacking campaign to ever target American industrial control systemsâthe technology that connects digital software with physical equipment, often in critical infrastructure settings. Now the FBI has warned that the attacks have hit utilities in no fewer than seven states, well beyond Minnesota alone.
In its alert, the FBI didnât name the targeted states or include details about the extent of the disruption or damage the hacking campaign caused. But the bureau said that it and the Environmental Protection Agency were working with affected utilities. The Cybersecurity and Infrastructure Security Agency, in its own advisory this week, stated that the attacks had in some cases disabled digital controls and âresulted in boil-water noticesââsuggesting potential water contamination. Echoing that CISA advisory, the FBI also warned that utilities should immediately take measures to remove from the internet digital devices that connect to physical equipment, known as programmable logic controllers, protect them with strong passwords, and set up allow-lists to only allow authorized devices to connect to them.
The leading suspect behind the wave of attacks remains Iranian-affiliated hackers, as first laid out in a CISA advisory in April, which a leaked memo obtained by WIRED confirmed was connected to the more recent Minnesota utility attacks, too. President Donald Trump on Friday instead blamed Minnesota Democratic governor Tim Walzâs administration for the attacks, a partisan response reminiscent of his denial of Russiaâs hacking of the Democratic National Committee in 2016, even after US intelligence agencies had squarely pinned that intrusion on the Kremlin.
FBI Shops for Pre-Crime AI
An FBI request for information, posted in March by the bureau's procurement arm, lists predictive modeling as one of six requirements for the Threat Screening Center. The system would draw on existing datasets and, as new records arrive, score them for similarity and âpattern alignmentâ against what the center already holds. The second Trump administration has reoriented the center toward domestic targets, guided by a memorandum directing the national security apparatus to target people defined broadly as anti-capitalist, anti-Christian, and hostile toward traditional views on family and religion.
FBI director Kash Patel told Congress in March that the center had posted double-digit growth in biometric capability and intelligence production. The watch list is reportedly approaching 2 million names. Watch-listing functions without a criminal charge and audits have repeatedly turned up errors in the underlying data. The US Supreme Court has already ruled against the bureau twice over its use of the list as leverage to recruit informants.
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorism
As Russia continues to increase its control over internet access, including banning apps and running local internet shutdowns, the country has also charged the founder of Telegram, Pavel Durov, with facilitating terrorism. This week, the Russian Federal Security Service issued an international arrest warrant for Durov, saying that Telegram had been used to coordinate sabotage and attacks inside Russia. It also claimed the app had failed to remove content by the âUkrainian special services, terrorist organizations, and extremist organizations.â
âUnder Russian law, Iâm banned from âpublishing information on the internet,ââ Durov posted online following the charges being announced. âRussian officials are clearly confused about who can ban whom from the internet.â The move by Russian authorities comes as part of the countryâs long-standing battle against Telegram. It first tried to block Telegram in 2018 and then earlier this year attempted to restrict access to the app while pushing citizens toward its home-grown messaging app, Max, which European officials say includes âextensive surveillance features.â
xAI Is Suing to Stop Minnesotaâs Law Banning âNudificationâ Tech
Earlier this year, lawmakers in Minnesota passed a law designed to âprohibit the access, download, or use of nudification technologyâ unless it requires significant technical skills to operate. Ahead of that law coming into force on August 1, Elon Muskâs xAI said this week that it is suing Minnesota attorney general Keith Ellison over the law, which the company claims violates the First Amendment.
The lawsuit, according to The Guardian, claims that xAI supports the banning of nonconsensual AI-generated nude images of people but says the law could ban protected free speech and is âwildly overbroad.â The lawsuit says xAI has âno practical choiceâ but to restrict the image editing capabilities of its Grok AI tool in Minnesota when the law takes effect. âSee you in court, creep,â Minnesota governor Tim Walz posted online in response to the lawsuit. In January, Grok was used to produce millions of nonconsensual images of women âundressed.â
The DNC Got Phished for $29,000
Someone impersonating Democratic National Committee chairman Ken Martin emailed a DNC staffer in February 2025 and got the staffer to hand over nearly $29,000, according to NOTUS, which obtained previously unreported records and confirmed the incident with committee officials. Martin had only been in the job for a matter of days.
The DNC reportedly caught the error within minutes and reported it to Wells Fargo, its financial institution, but recovered only $7,000. The staffer involved has since left the DNC. The committee also referred the matter to law enforcement. An official told NOTUS that the staff receive fraud training and operate under âsecurity protocolsâ to fend off additional fraud.
In an August 2025 letter to the Federal Election Commission, the DNC described the loss as a âmisdisbursement of Committee fundsâ caused by an outside partyâs fraud, telling regulators it would take further steps to prevent a repeat. Spokesperson Mia Ehrenberg labeled the incident a one-off that was promptly caught, with nothing similar since.
Business email compromise has landed on the political committees of both parties. The RNC lost $44,000 to fraudsters in 2020. Campaigns for Mike Johnson, Alexandria Ocasio-Cortez, John Thune, Chuck Schumer, and Corey Booker have all been hit. NOTUS reported in July that Michigan Senate candidate Mike Rogers lost $16,700 to a suspected cyberswindler while campaigning on his record of âworking with companies large and small to protect their data from criminals.â
Comments
Back to top
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.