Loading summary
A
A cyber attack has disrupted water utilities in more than 30 communities in Minnesota. Denmark tests a secondary banking system in case of a cyber attack, North Korea arrests bank hackers and a new Chinese cyber contractor has been identified. This is the Risky bulletin prepared by Catalyn Kim Panu and read by me, Claire Aird 10 today is the 29th of July and this podcast episode is brought to you by Airlock Digital. In today's top story, a cyber attack has disrupted water and wastewater utilities in more than 30 communities in Minnesota. Disruptions were reported in cities including Bram, Maple plain, Plymouth and St Paul. Water remained safe to drink, but some towns reported brief outages. Officials have activated a statewide cybersecurity response. The the state's IT Bureau has not attributed the attack. Meantime, a cyber attack has shut down a US healthcare provider's clinics and hospitals. The non profit Anmed Group operates four hospitals and more than 60 physician clinics in Georgia and South Carolina. Patients that don't need urgent medical care are being redirected to nearby hospitals. The Danish central bank is building a backup payment system that will activate in case of a crippling cyber attack against the banking sector. The secondary system will be able to support payment cards, salary payments and money transfers. It will be tested at grocery chains and pharmacies by the end of 2026. Oregon Senator Ron Wyden has urged the US government to phase out old, insecure VPN gateway devices. Wyden asked the heads of cisa, NIST and the OMB to set mandatory security standards for the use of VPN devices. Under the new standards, federal agencies would have to replace old devices and be banned from buying outdated devices. Senator Wyden cited the increase in adversary attacks targeting outdated VPN gear. The UK Supreme Court has ruled that Bahrain cannot claim state immunity and must stand trial. In a lawsuit filed by two dissidents on over the government's use of spyware, Saeed Shahabi and Moussa Mohammed claimed that the Bahrain government hacked their laptops in 2011 with the FinSpy spyware. The two had worked for an organisation that provided assistance to political prisoners in Bahrain. They were later physically beaten and had their citizenships revoked. The government of Bahrain has denied the allegations. North Korean authorities have arrested members of a cybercrime group that hacked two of the country's banks. The group was led by discharged veterans from North Korea's intelligence Service and included students recruited from two Pyongyang universities. They allegedly hacked the Chosun Central bank and the Foreign Trade bank and siphoned off funds to Chinese accounts. The Stolen money was laundered and sent back to North Korea. Police in Hong Kong have arrested a 25 year old man for SMS blasting. The suspect is accused of driving around the city with an SMS blaster and and sending messages impersonating an online investment company. At least one victim lost $141,000. Russian authorities have arrested a 20 year old man over a smishing and hacking campaign. He's accused of gaining access to online banking and government accounts. He then used that access to take out loans and steal funds. He raked in up to $6,000 a day. Two of his accomplices have also been arrested. Pop star Ariana Grande is suing two hackers for stealing and leaking unreleased music and studio footage. The material was allegedly stolen from her photographers and producers. The suit seeks to identify the hackers as well as anyone who helped distribute the stolen data. Three individuals are suing Apple after losing $1.8 million to a malicious iOS app. The plaintiffs claim the company failed to remove a malicious crypto wallet from its app store despite user reports the app posed as the legitimate Sparrow Wallet, which only has official versions for Windows, macOS and Linux. The plaintiffs are seeking reimbursement of the stolen funds. Cyber sleuths have uncovered a new cyber contractor for Chinese government hackers. According to Intrusion Truth, the Guangdong Chen Ming Co. Is behind a major proxy botnet due to known as Red Relay and orbweaver. The company's customers allegedly include the Chinese army and the Ministry of Public Security. The proxy network has been used by almost a dozen APT groups to hide their attacks, including APT15, Red Vulture, KE3 Chang and Vixen Panda. Cryptocurrency platform Binance has updated internal policies to make it more difficult for law enforcement to obtain information about customers and transactions. The new policy entered into effect in April. It forces law enforcement agencies to route data requests to UAE government agencies, which is delaying responses and investigations. Police officers from five European countries say the process is hindering their efforts to identify scammers and money launderers. The new policy doesn't apply for serious crimes, including child sexual abuse, terrorism or imminent threat to life. A new botnet has infected more than 200,000 routers, security cameras and IoT devices since March, according to Chinese security firm Jianxin. The botnet appears to be the backend of the Dysphoria Network, a new DDoS for hire service. Besides DDoS capabilities, the botnet also includes the ability to work as a giant proxy network. Hackers are exploiting a zero day in Arista VeloCloud orchestrator service. The zero day allows attackers to inject and run commands on on premises servers. All VeloCloud servers reachable over the Internet are vulnerable. The zero day has a 10 out of 10 severity score due to its ease of exploitation. JetBrains has released a security update for TeamCity CI CD servers. The patch fixes an unauthenticated remote code execution bug that allows attackers to take over Internet exposed servers. The bug impacts on premises servers. Previous TeamCity security flaws have seen widespread exploitation. JFrog has patched a zero day in the artifactory Artifact Repository Management server. The bug was exploited by OpenAI models earlier this month to hack the Hugging Face AI platform. JFrog says OpenAI reported the zero day as soon as they learned of it. Microsoft has released its AI model for cybersecurity tasks Mai Cyberone Flash. The model has reportedly achieved a 96% score on the Cyber Gym test. Its operational costs are half that of other popular models. The company has also released Perception, a framework for managing AI agents across enterprise networks. And finally, a coalition of tech companies and open source organisations have founded the OpenSecure AI Alliance. The new industry group will develop and share open source AI tools for defenders. The alliance was formed in response to the recent OpenAI hugging face hack. Hugging face's security team was unable to investigate the incident with Frontier Models due to their strict guardrails. 37 tech companies and open source foundations are part of the new Open Secure AI alliance, including the likes of Nvidia, Microsoft, IBM and Cisco. And that is all for this podcast edition. Today's show was brought to you by Airlock Digital. Find them at airlockdigital. Com thanks to your company.
Podcast: Risky Bulletin (Risky Business Media)
Date: July 29, 2026
Host/Reader: Claire Aird
This episode centers around a significant cyberattack targeting over 30 water and wastewater utilities in Minnesota, along with a rapid-fire roundup of major cybersecurity news worldwide. Topics include North Korean cybercrime, bank backup systems in Denmark, lawsuits related to spyware, new details on Chinese cyber contractors, software vulnerabilities, and global developments in AI-driven security.
“A cyber attack has disrupted water and wastewater utilities in more than 30 communities in Minnesota. Disruptions were reported in cities including Bram, Maple plain, Plymouth and St Paul.” (Claire Aird, 00:09)
Sen. Ron Wyden’s VPN Security Push:
“Wyden asked the heads of CISA, NIST and the OMB to set mandatory security standards for the use of VPN devices.” (00:46)
UK Supreme Court on Spyware & Bahrain:
North Korean Bank Hackers Arrested:
Hong Kong SMS Blaster Arrest:
Russia Smishing/Hacking Ring:
Chinese Cyber Contractor Identified:
Binance Policy Change:
“Police officers from five European countries say the process is hindering their efforts to identify scammers and money launderers.” (02:40)
New Botnet Spreads via IoT:
Zero-Day & Patch Roundup:
Microsoft’s Cybersecurity AI:
OpenSecure AI Alliance:
“The alliance was formed in response to the recent OpenAI Hugging Face hack. Hugging Face's security team was unable to investigate the incident with Frontier Models due to their strict guardrails.” (03:36)
On Minnesota water utilities disruption:
“Officials have activated a statewide cybersecurity response. The the state's IT Bureau has not attributed the attack.” (00:16)
On Denmark’s banking resilience:
“The secondary system will be able to support payment cards, salary payments and money transfers. It will be tested at grocery chains and pharmacies by the end of 2026.” (00:37)
On Chinese APT activity:
“The proxy network has been used by almost a dozen APT groups to hide their attacks, including APT15, Red Vulture, KE3 Chang and Vixen Panda.” (02:27)
On Binance’s new law enforcement policy:
“The new policy entered into effect in April. It forces law enforcement agencies to route data requests to UAE government agencies, which is delaying responses and investigations.” (02:36)
The bulletin is delivered in a brisk, matter-of-fact style, typical for professional cybersecurity reporting. There are no dramatic flourishes, just tightly summarized events and developments, balancing technical depth and accessibility for a broad audience.
This comprehensive update delivers urgent news and vital context for security professionals, policymakers, and anyone tracking global cybersecurity trends.