
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Monday, July 27, 2026. I'm Steve Prentiss. U.S. agencies warn of Iran linked actors targeting water and energy control systems an updated advisory from cisa, the FBI, the NSA and the Department of Energy warns that Iran linked actors are ins inside American water and energy control systems and are actively making changes. This applies to devices such as programmable logic controllers that run pumps, valves and safety alarms. The warning suggests that these actors can alter what operators see on their screens, leading to unanticipated events or unannounced outages. This is not a new practice. It is what happened to Rockwell Automation controllers in April. But this updated advisory now includes Schneider Electric and Siemens. CHATGPT suffered brief global outage on Saturday. This outage started at around 5am Eastern time and prevented users in the US, India, Europe, Japan, Australia and elsewhere from loading chats and loading previous conversations, although it only lasted an hour. It also affected OpenAI's coding platform Codex. And although this was brief and quickly resolved, industry analysts point out that such an event is a reminder of just how ingrained these types of services have become globally. Malvertising sends malware in pieces for an unsuspecting browser to build According to a report from Ad security platform Confiant, I.e. c o n f iant, a malvertising operation called Sour Trade is making victims browsers build the final Windows executable themselves using a legitimate BUN runtime as its base instead of serving one complete malicious file from a fixed URL. This campaign has operated since late 2024 and has impersonated companies such as TradingView, Solana and Luno to target retail traders and cryptocurrency investors across 12 countries in 25 languages. Confiance recommendation, of course, is for users to click on downloadable software from a vendor's own site rather than from an ad. Ontrack suffers data breach the US based parcel delivery company that specializes in last mile e commerce deliveries is informing its customers that hackers breached its corporate network and may have accessed personal details belonging to its customers. This breach occurred between March 20th and 22nd. The company has not stated the type of information that was exposed as it redacted the data elements in the notification sample shared with authorities. According to Bleeping Computer. The wording of the company's statement suggests a possible agreement between the firm and the attackers, typically a ransom payment. Huge thanks to our sponsor Pindrop. Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why they built Pindrop Pulse for meetings, catch deepfakes, AI voices and spoofed locations in real time. Go to pindrop.com that is pindrop.com and start verifying wrench attacks appear to be on the rise A growing number of crypto thefts are now happening as in person strongarm techniques. According to blockchain security audit company Certik, crooks are using face to face coercion to steal digital assets. Incidents of wrench attacks, as they are called, have increased 33% year over year in the first half of 2026. Adversaries use violence, intimidation or credible threats to compel a victim to transfer digital assets, surrender private keys, unlock a wallet, reveal credentials or pressure a third party into compliance. These third party pressures include home invasions, kidnappings and sometimes even murder. Certik warns that attackers do not need direct access to the primary holder if they can threaten a spouse, parent, child, employee, driver, assistant or close friend, adding that such proxy victims often have weaker operational security, more predictable routines and less training than the primary target. End Quote UK's new Prime Minister seeks continuity on cyber policy Newly elected UK Prime Minister Andy Burnham has signaled continuity in the country's cybersecurity strategy by reappointing Liz Lloyd to oversee the cyber portfolio. Despite dismantling the department that previously managed it, Lloyd will continue steering the Cybersecurity and Resilience Bill, which expands cybersecurity regulations to data centers, managed service providers and critical infrastructure, while introducing stricter incident reporting requirements. Burnham split the former Department of Science, Innovation and Technology across three ministries, separating AI security from cybersecurity policy for the first time. While critics warn the reorganization could weaken coordination, Lloyd is expected to continue advancing the legislation and publish the much delayed National Cyber Action Plan later this summer. Rockwell patches flaws in arena simulation software Rockwell Automation has now patched four vulnerabilities in its arena Simulation software, a product that provides organizations with a virtual environment to model, visualize and test complex operational workflows. The four CVE numbered flaws are memory corruption issues stemming from improper validation of user supplied data that can result in an out of bounds, write. Michael Heinzel. The researcher who discovered the vulnerabilities told Security Week that the file types involved arena experiment and model files are opened routinely by users as part of normal workflows, meaning a booby trapped file would not necessarily stand out to an arena user targeted in a social engineering attempt. The Pope's official Prayer App Leaks User Data Click to Pray is the official app of the Pope's worldwide prayer network and has over 700,000 accounts. Unfortunately, it has been also leaking people's names and email addresses for months or perhaps even longer, according to an ethical hacker who found and reported the security vulnerability six months ago to no avail. The hacker, who goes by the handle Bob the Hacker, is known in the cybersecurity community for her previous research exposing a free food flaw in McDonald's ordering system and open controls on Chinese robot manufacturer Pudu Robotics. In short, the Prayer app flaw will return user data for any account, not just in individual members. For anybody who chooses to try, this, of course becomes material for spamming campaigns and other types of social engineering. If you have some thoughts on the news from today or about this show in general, please be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I'm Steve Prentiss reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories. Behind the headlines lines.
Podcast: Cybersecurity Headlines (CISO Series)
Host: Steve Prentiss
Main Theme:
A rapid-fire overview of the day’s top cybersecurity stories, exploring urgent infrastructure threats, emerging malware, cyber policy shifts, and headline-grabbing breaches.
[00:14–01:16]
Summary:
Multiple U.S. agencies (CISA, FBI, NSA, DoE) updated advisories to warn that Iran-linked threat actors are actively inside American water and energy control systems and making unauthorized changes.
Details:
Memorable Quote:
“These actors can alter what operators see on their screens, leading to unanticipated events or unannounced outages.”
— Steve Prentiss (00:38)
[01:17–01:55]
Summary:
ChatGPT was unavailable globally for about an hour early Saturday morning, disrupting user access to both ongoing and past conversations.
Details:
Notable Insight:
“Analysts point out... such an event is a reminder of just how ingrained these types of services have become globally.”
— Steve Prentiss (01:50)
[01:56–02:49]
Summary:
New malvertising technique, Sour Trade, tricks browsers into assembling malware piece by piece, evading detection.
Details:
Best Practice Reminder:
“ConfianT’s recommendation, of course, is for users to click on downloadable software from a vendor's own site rather than from an ad.”
— Steve Prentiss (02:41)
[02:50–03:22]
Summary:
Major last-mile US parcel delivery firm OnTrac revealed hackers accessed personal customer data.
Details:
[04:14–05:22]
Summary:
Increase in face-to-face, coercive crypto theft ("wrench attacks") — up 33% so far in 2026.
Details:
Notable Quote:
“Such proxy victims often have weaker operational security, more predictable routines and less training than the primary target.”
— Steve Prentiss quoting Certik (05:10)
[05:23–06:03]
Summary:
New Prime Minister Andy Burnham reappoints Liz Lloyd to lead UK's cyber portfolio, signaling policy continuity even as relevant departments are restructured.
Details:
[06:04–06:57]
Summary:
Four security flaws fixed in Rockwell Arena—simulation software used to model/test operations.
Details:
[06:58–07:55]
Summary:
Major privacy flaw exposed in the Pope’s official prayer app, leaking user names and emails for months.
Details:
On critical infrastructure hacking:
“This is not a new practice… but this updated advisory now includes Schneider Electric and Siemens.”
— Steve Prentiss (00:33)
On malvertising:
“A malvertising operation called Sour Trade is making victims’ browsers build the final Windows executable themselves…”
— Steve Prentiss (02:07)
On physical crypto theft:
“…adversaries use violence, intimidation or credible threats to compel a victim to transfer digital assets, surrender private keys, unlock a wallet, reveal credentials or pressure a third party into compliance.”
— Steve Prentiss (04:22)
Concise, urgent, and matter-of-fact. The host maintains a steady, professional news delivery, punctuated by actionable security advice drawn directly from real incidents.
This episode delivers a brisk yet thorough update on fresh threats and systemic changes shaping today’s cybersecurity landscape, reminding listeners to stay vigilant from both digital and physical vectors.