This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

In the last ~48 hours, key cybersecurity developments require executive attention: coordinated cyberattacks disrupted operational technology across more than 30 Minnesota water systems, JetBrains disclosed a critical TeamCity authentication bypass leading to remote code execution, Cisco confirmed active exploitation of a Secure Firewall Management Center zero-day, and Russian-linked actors used an Outlook Web Access flaw to maintain long-term mailbox access through a browser implant.

These developments reinforce priority themes for the weekend: critical infrastructure remains exposed through internet-accessible operational controls, software development platforms are becoming privileged intrusion paths, security management systems continue to attract active exploitation, and email compromise is evolving beyond stolen passwords into persistent access that can survive credential rotation.

Speak naturally. Send without fixing.

Wispr Flow turns your voice into clean, professional text you can send the moment you stop talking. Not rough transcription you have to clean up. Actual polished text — ready for email, Slack, or any app.

Speak the way you think. Go on tangents. Change your mind mid-sentence. Flow strips the filler, fixes the grammar, and gives you text that reads like you spent five minutes writing it.

89% of messages sent with zero edits. Millions of professionals use Flow daily, including teams at OpenAI, Vercel, and Clay. Works on Mac, Windows, and iPhone.

📊 Executive Threat Heatmap 📊

Category shifts this week:

  • Critical Infrastructure / Water Operations ↑ — Coordinated attacks affected operational controls across dozens of water systems and forced some utilities into manual recovery.

  • Developer and CI/CD Infrastructure ↑ — The TeamCity flaw can bypass authentication and execute commands with the TeamCity server process privileges.

  • Security Management Platforms ↑ — Cisco FMC exploitation demonstrates continued pressure against the platforms that configure and monitor defensive controls.

  • Email and Identity Persistence ↑ — OWA browser implants can preserve mailbox access beyond ordinary password resets and device remediation.

🚨 Late-Breaking Threats (last 7-10 days) 🚨

Coordinated cyberattack targets more than 30 Minnesota water systems — High

What changed: CISA warned water and wastewater operators to remove vulnerable operational technology from the internet after coordinated attacks against water systems affected utilities in Minnesota and several other states. Reported impacts included password changes that locked out operators, systems being taken offline, pressure loss, flooding, and sustained manual operations. U.S. officials are investigating likely Iranian-linked involvement.

Why this matters: Water-sector attacks cross the line from information security into public safety and operational continuity. When operators lose remote control or visibility, the fallback is not a ticket queue. It is manual operation of physical infrastructure while federal investigators determine who changed the password.

Critical TeamCity flaw enables unauthenticated remote code execution — High

What changed: JetBrains warned that all on-premises versions of TeamCity are affected by a critical authentication bypass tracked as CVE-2026-63077. An attacker with HTTPS access to the server can abuse the agent polling protocol to bypass authentication and execute operating-system commands with the privileges of the TeamCity server process. TeamCity Cloud has already received protective measures.

Why this matters: TeamCity sits inside the software delivery chain with access to repositories, build agents, signing processes, secrets, and deployment environments. Compromise the build platform and attackers may inherit a trusted route into everything engineering deploys next.

Cisco Secure FMC zero-day actively exploited using static credentials — High

What changed: Cisco confirmed active exploitation of a Secure Firewall Management Center zero-day tracked as CVE-2026-20316. The flaw exists because affected systems contain static credentials for a low-privileged account, allowing an unauthenticated remote attacker to log in and access sensitive information.

Why this matters: FMC manages firewall policy, visibility, and network enforcement. Even low-privilege access to a security control plane can expose configuration data, topology, operational details, and the information needed to develop a more damaging follow-on attack. Apparently static credentials remain immortal until an incident report finally kills them.

Russian actors exploit OWA flaw for persistent mailbox access — Medium-High

What changed: Russian-linked threat actors exploited an Outlook Web Access vulnerability tracked as CVE-2026-42897 to deploy OWAReaper, a browser implant capable of maintaining mailbox access through credential rotation and device changes. The exploitation chain can trigger when a user opens a specially crafted email, without requiring a malicious attachment or embedded link.

Why this matters: This is not ordinary mailbox theft. A browser-level implant inside OWA can preserve access to sensitive communications, recovery messages, internal directories, and executive context even after defenders reset passwords and clean endpoints. The account looks fixed while the attacker keeps reading.

🛠️ Pattern & TTP Summary 🛠️

Stage

Vector

What We’re Seeing

Initial Access / Operational Impact

Internet-exposed OT and remote controls

Coordinated access to water-system technology causing lockouts, outages, pressure loss, flooding, and manual operations

Privilege / Supply Chain Access

CI/CD server authentication bypass

TeamCity exploitation enabling command execution within a privileged software delivery environment

Control-Plane Reconnaissance

Firewall management access

Static credentials allowing unauthenticated access to sensitive Cisco FMC information

Persistence / Intelligence Collection

OWA browser implantation

Malicious JavaScript maintaining mailbox access beyond password rotation and endpoint cleanup

What is an EOR—and why are companies using it?

Opening entities in every country can be slow, expensive, and hard to scale.

That's why more companies are using EOR to hire globally faster.

See how Oyster helps teams hire, pay, and support talent in 180+ countries while staying compliant along the way.

✅ Fail-Safe Checklist (before COB) ✅

🔄 Patch & Hardening

  • Patch TeamCity On-Premises immediately and restrict HTTPS access to approved administrator and build networks.

  • Apply Cisco FMC updates and mitigations and review all affected systems for use of the exposed static account.

  • Remove OT controllers, PLC interfaces, and remote-management systems from direct internet exposure.

  • Patch Exchange and OWA systems for CVE-2026-42897 and review browser-facing access paths.

  • Rotate CI/CD, firewall-management, and email-related secrets where compromise cannot be confidently excluded.

  • Validate manual operating procedures for water, manufacturing, facilities, and other cyber-physical environments.

📊 People & Monitoring

  • Monitor water and OT environments for operator lockouts, password changes, PLC configuration writes, control loss, pressure anomalies, and unexpected remote sessions.

  • Hunt TeamCity servers for suspicious agent polling, new build configurations, command execution, token access, and outbound traffic from the server process.

  • Watch Cisco FMC activity for low-privilege account use, unusual logins, sensitive configuration access, and first-seen management sources.

  • Monitor OWA sessions for anomalous mailbox reads, suspicious browser scripts, unusual session persistence, and access continuing after password resets.

  • Escalate operational effects immediately rather than waiting for full technical attribution.

💼 Process & Validation

  • Enforce change freeze on OT remote access, CI/CD infrastructure, firewall-management systems, and Exchange environments unless CISO-approved.

  • Conduct 30-minute tabletop:
    “Internet-exposed OT compromise → operator lockout → TeamCity intrusion → firewall reconnaissance → persistent mailbox access.”

🤝 Partners & Assurance

  • Require water, facilities, and OT owners to confirm internet exposure, manual fallback procedures, and vendor remote-access controls.

  • Require DevOps teams to attest TeamCity patch status, build-secret rotation, and pipeline integrity.

  • Require network-security teams and MSPs to confirm Cisco FMC remediation, account review, and management-plane restrictions.

  • Require email-platform owners to validate Exchange patching, OWA monitoring, and privileged mailbox review.

🕵️ Detection Opportunities 🕵️

Water / OT: Alert on password or account changes, PLC programming activity, remote-control sessions from unfamiliar sources, loss of telemetry, and sudden movement into manual operations.

TeamCity: Detect anomalous agent polling requests, server-process child commands, unauthorized project changes, new access tokens, and CI/CD secrets used from first-seen hosts.

Cisco FMC: Monitor static-account authentication, sensitive configuration reads, unusual API or GUI access, and management logins from unapproved networks.

OWA / OWAReaper: Hunt unusual JavaScript execution in webmail sessions, persistent mailbox access after credential changes, abnormal browser session duration, and unauthorized message or directory collection.

📈 Risk Outlook 📈

Overall Risk Level: High

This weekend’s highest-risk pattern is trusted control-system compromise:

  • Water and wastewater operational technology

  • CI/CD and build infrastructure

  • Firewall management platforms

  • Email and browser-based identity sessions

Attackers are targeting the systems that control physical processes, build trusted software, configure security policy, and carry executive communications. Compromise in any one of these environments can create impact far beyond the originally affected system.

📌 Key Leadership Takeaways 📌
  1. Internet-exposed OT can turn cyber access into physical disruption.

  2. CI/CD platforms must be treated as privileged production infrastructure.

  3. Security management systems need the same monitoring and hardening as identity platforms.

  4. Mailbox persistence can survive password rotation, so remediation must include the application and session layers.

📋 Immediate Leadership Checklist 📋

🔄 Verify: TeamCity, Cisco FMC, Exchange, and exposed OT remediation status.

📊 Validate: Monitoring coverage for PLC changes, CI/CD command execution, firewall-management access, and persistent OWA sessions.

💼 Confirm: Manual operations, secret rotation, and incident ownership are current for every affected platform class.

🔹 Rehearse: “Control-system compromise → operational disruption → trusted-platform persistence” response.

Final Insight: Attackers are targeting the systems that move water, build software, enforce policy, and carry executive conversations.

This weekend, verify the controls behind the controls before someone else starts operating them.

PRDs by voice. Bug reports by voice. Ship faster.

Dictate acceptance criteria and reproductions inside Cursor or Warp. Wispr Flow auto-tags file names, preserves syntax, and gives you paste-ready text in seconds. 4x faster than typing.

Keep reading