PUBLISHED ON

AAuugg  99,,  22002266
EEDDIITTIIOONN  001199

Password Resets Failed as Management Planes and Mailboxes Fell Open

Edge appliances RMM paths agentic scanners water systems and webmail shared one calendar

WEEKLY OPENING

Good evening. This week the perimeter did not fail politely it failed in products that sit between you and everything else and also at the taps. CISA moved a cluster of actively exploited flaws into KEV while Microsoft tracked a financially motivated crew shifting ransomware tooling onto the same remote management surface. In parallel Unit42 documented a Chinese speaking operator wiring DeepSeek into an open agent framework and letting it pick targets without a second human prompt. Iran linked operators put more than thirty Minnesota water utilities offline using default credentials nobody changed. Russia linked Void Blizzard found a way to read Outlook mail that survives a password reset. Ransomware crews kept doing what ransomware crews do this time riding a maximum severity SonicWall bug that was patched in July but is apparently still very much alive in August. Six new entries hit the CISA KEV catalog this week which is either a productive week for defenders or a productive week for attackers depending on which side of the patch cycle you are standing on. Patch queues got longer. Trust boundaries got thinner. The lights stay on.

EXECUTIVE TAKE

The defining risk this week was not a single nation state spectacle. It was confirmed exploitation against internet facing management and developer infrastructure load balancers RMM platforms CI servers AI workflow tools and Tomcat cluster paths at a pace that compresses remediation windows to hours not weeks. CISA KEV additions for Progress LoadMaster Nable Ncentral IBM Langflow Apache Tomcat and JetBrains TeamCity establish exploitation as fact for federal and enterprise prioritization under BOD style urgency. Leadership should treat identity and remote access abuse as co equal to CVE work. CrowdStrike 2026 Threat Hunting Report released into Black Hat week quantified a fifteen fold rise in device code phishing and a doubled vishing rate while Microsoft observed Storm1175 resume operations with a new ransomware family after months of quiet. Cloud hosted PHI exposure at Amgen and continued opportunistic China nexus scanning against global government and commercial estates reinforce that third party and edge compromise remains a board level continuity issue not only a SOC ticket backlog.

The defining pattern this week was also persistence attackers building access that survives standard remediation. Void Blizzard tracked by Microsoft Proofpoint tracks the same activity as TA488 Laundry Bear deployed a backdoor that reportedly retains mailbox access through password resets and device re imaging which changes the incident response calculus for any organization exposed on Outlook Web Access. Separately the Iran linked CyberAv3ngers campaign against Minnesota water utilities is a reminder that operational technology exposure at the municipal level remains an unresolved policy gap not just a technical one. For leadership the more immediate signal is the CISA Known Exploited Vulnerabilities catalog which added six entries this week spanning IBM Langflow Apache Tomcat Nable Ncentral JetBrains TeamCity and Progress LoadMaster a cluster that touches identity DevOps tooling and remote management surfaces simultaneously. None of these are exotic they are widely deployed enterprise products with short remediation windows which means patch cadence not novel defense is this week real test. Ransomware activity continues to track closely behind vulnerability disclosure. INC ransomware exploitation of previously patched SonicWall SMA1000 flaws reported in fresh detail this week is a case study in how a three week gap between advisory and full patch adoption becomes an active breach window. Attribution for the SonicWall chaining is treated as corroborated but not government confirmed based on consulted sources.

KEY FINDINGS

  • CVE-2026-8037 Progress Kemp LoadMaster CISA added unauthenticated command injection CVSS 9.6 to KEV after active exploitation telemetry cited hundreds of attempts across dozens of source IPs with FCEB remediation due 10 August 2026

  • CVE-2026-18556 and CVE-2026-18577 Nable Ncentral authentication bypass and incomplete fix follow on both entered KEV path enables admin takeover and RMM style pivot into managed endpoints

  • Storm1175 StormEncryptor Microsoft Threat Intelligence observed new C++ ransomware from 2 August 2026 shifting off prior Medusa use Nable link is assessed likely not confirmed

  • CVE-2026-9198 IBM Langflow unauthenticated code injection on default deployments CVSS 9.8 added to KEV hundreds of exploitation attempts reported in supporting telemetry

  • CVE-2026-34486 Apache Tomcat EncryptInterceptor bypass KEV listed tied in reporting to China nexus activity delivering SNOWLIGHT and to separate AI assisted opportunistic campaigns

  • CVE-2026-63077 JetBrains TeamCity unauthenticated RCE via agent polling protocol deserialization permissive XStream path added to KEV on prem only Cloud not affected per vendor scope

  • knaithe KnYuan Unit42 Chinese speaking operator used DeepSeek via Hermes Agent over Telegram for autonomous FOFA enumeration and PoC driven exploitation across 460 plus targets confirmed impact concentrated on manual Citrix NetScaler and Marimo paths

  • CVE-2026-64638 WordPress XSS2Shell emergency core fix in 7.0.3 for pre authentication login XSS chainable toward PHP execution under admin interaction no confirmed mass in the wild exploitation as of mid week reporting

  • Device code phishing CrowdStrike reported roughly 15 times monthly attempt growth in H1 2026 APT29 Cozy Bear cited among prominent users of OAuth device authorization abuse against cloud identities

  • Amgen material cloud incident with exfiltrated proprietary data and patient PHI from third party hosted storage disclosed via SEC filing full blast radius still under investigation

  • Connor Riley Moucka Krebs reported guilty plea tied to 2024 Snowflake related extortion affecting 165 plus organizations and large scale AT&T call text history theft

  • VMware Broadcom CVE-2026-59309 CVE-2026-59310 related critical vCenter authentication bypass and syslog path RCE with no published workarounds remained early week patch priority after late July advisory

  • CyberAv3ngers Iran linked Under Attribution disrupted more than 30 Minnesota community water utilities using default Unitronics Vision Series credentials and CVE-2021-22681 briefly taking a Braham treatment plant offline CISA updated advisory AA26 097A to reflect expanded targeting

  • Void Blizzard Microsoft naming Proofpoint tracks the same activity as TA488 Laundry Bear Under Attribution single vendor sourced is exploiting CVE-2026-42897 a persistent XSS in Microsoft Outlook Web Access to deploy the OWAReaper JavaScript implant which survives credential resets and re imaging

  • INC Ransomware is reported chaining CVE-2026-15409 CVSS 10.0 SSRF and CVE-2026-15410 CVSS 7.2 RCE in SonicWall SMA1000 appliances to steal credentials and TOTP seeds both CVEs remain on CISA KEV

  • Cisco Talos published research this week 6 August documenting adversaries weaponizing consumer AI coding tools Claude Code Codex Cursor Gemini for malware development credential harvesting and DDoS tooling finding safety guardrails inconsistently effective

  • Brinks Home confirmed a data breach following a claim by extortion group ShinyHunters which also added Questel Alcon and Lumenis to its leak site this week

  • Bank of Baroda disclosed an email account compromise with claimed exposure of internal communications and loan documents core banking systems were reported unaffected

  • A Ruby on Rails Active Storage vulnerability CVE-2026-66066 KindaRails2Shell CVSS roughly 9.5 allowing unauthenticated file read and potential RCE was patched by Akamai researchers disclosure this week

  • A Chinese threat actor reportedly used a leaked DarkSword phishing kit to deliver GHOSTBLADE malware targeting iOS devices

  • A hardware RNG flaw in COLDCARD cryptocurrency wallets is reportedly linked to an 88.6 million Bitcoin theft per consulted sources

WEEKLY THREAT NARRATIVE

Management Planes Became the Breach The week highest confidence signal was exploitation of systems that administer other systems. LoadMaster Ncentral TeamCity and Langflow share a property defenders undervalue until KEV makes it unavoidable a single unauthenticated or weakly authenticated foothold yields network position build secrets or endpoint reach without a classic phishing chain. Microsoft Storm1175 timeline new StormEncryptor activity the same day CVE-2026-18577 surfaced fits the established pattern of high velocity ransomware crews racing disclosure to patch gaps on RMM and edge gear. That Nable linkage remains Microsoft assessed rather than forensically confirmed is not comfort it is a reminder to hunt the post access toolset AnyDesk SimpleHelp Advanced IP Scanner Mimikatz LSASS access !!!README_FIRST!!!.txt regardless of root CVE proof.

Agentic Recon Is Operational Not Theoretical Unit42 reconstruction of the knaithe KnYuan workspace matters less for the modest confirmed compromise count than for the workflow. DeepSeek inside Hermes Agent driven from Telegram independently pulled public PoCs ranked CVEs by FOFA footprint abandoned hard targets and pivoted toward larger attack surfaces such as n8n. Autonomous phases largely failed where defaults were hardened manual phases succeeded against CVE-2026-3055 Citrix NetScaler memory disclosure and CVE-2026-39987 Marimo. The operator own agent exposed the lab by serving the home directory over HTTP an opsec failure that also produced unusually complete session evidence. Treat this as confirmed proof of concept of agentic offense at scale not as confirmed APT grade national tasking. Attribution stays Chinese speaking opportunistic operator Zhuhai associated in Unit42 assessment under continuing evaluation for any broader nexus.

Identity Abuse Outran Password Controls CrowdStrike Black Hat timed hunting report reframed convenience protocols as primary initial access. Device code phishing does not steal a password it obtains a legitimate grant after the user types a code somewhere they should not. A fifteen fold attempt increase doubled vishing sub 48 hour PoC exploitation for most observed cases and continued npm centric supply chain pressure describe a landscape where trusted flow is the payload delivery system. Parallel commodity activity Bank of America themed lures installing hardened ScreenConnect Fastjson 1.x CVE-2026-16723 exploitation without a 1.x patch path shows financially motivated actors still win on familiar social and library debt. WordPress XSS2Shell sits in the same thematic bucket the login page is reachable by design and a parser differential turned that inevitability into a core platform emergency.

Persistence Is the Theme Not the Exploit Two of the week most significant reports the OWA campaign attributed to Void Blizzard and the ongoing exploitation tied to Iran linked operators against water infrastructure share a common thread that matters more than either individual CVE both are built around access that outlives the standard remediation response. Password resets device re imaging and even patching do not reliably evict an implant designed to persist server side or in browser storage. That reframes incident response guidance containment scoped only to credential rotation is treating a symptom not the access.

The KEV Catalog Is Doing the Talking This week technical story is less about a single headline vulnerability and more about volume and diversity of confirmed exploitation. Six KEV additions across identity platforms Nable developer tooling JetBrains Apache Tomcat AI infrastructure IBM Langflow and load balancing Progress in a single week signals that attackers are not concentrating on one category of software they are opportunistically working whatever has a fresh weaponizable disclosure. Reporting concentration around these entries reflects wide press coverage of the same CISA feed rather than independently confirmed separate campaigns the individual exploitation events should be treated as discrete unless a source explicitly links them.

Ransomware Still Runs on Old News The INC Ransomware reporting on SonicWall SMA1000 is a reminder that patched and remediated are not the same word in practice. The underlying CVEs were disclosed and added to KEV in mid July the fresh reporting this week describes exploitation and ransomware deployment continuing into August implying either delayed patch adoption or a population of appliances that were never fully current. This is inference from the reporting timeline not a confirmed patch failure rate no vendor source this week quantified how many appliances remain vulnerable.

NOTABLE TECHNICAL SIGNALS

Top CVEs CVE-2026-8037 Progress LoadMaster unauthenticated command injection CVSS 9.6 CISA KEV active exploitation confirmed patch by 10 August 2026 for FCEB CVE-2026-9198 IBM Langflow unauthenticated code injection RCE on default deployments CVSS 9.8 CISA KEV fixed in 1.10.1 CVE-2026-63077 JetBrains TeamCity unauthenticated RCE via agent polling deserialization path CVSS 9.8 class reporting CISA KEV fixed in 2026.1.3 and 2025.11.7 CVE-2026-18577 and CVE-2026-18556 Nable Ncentral authentication bypass CVSS 8.2 both KEV incomplete fix narrative between the pair CVE-2026-34486 Apache Tomcat EncryptInterceptor bypass cluster message protection failure CVSS 7.5 CISA KEV fixed in 11.0.21 10.1.54 9.0.117 CVE-2026-64638 WordPress Core pre authentication reflected XSS on login XSS2Shell CVSS 8.9 fixed in 7.0.3 and backports RCE chain requires additional conditions user interaction in the wild mass exploitation not confirmed CVE-2026-59309 and CVE-2026-59310 VMware vCenter critical authentication bypass and syslog directory traversal RCE CVSS 9.8 class Broadcom emergency patches no workarounds exploitation in the wild not confirmed in early week coverage CVE-2026-16723 Fastjson 1.x RCE class issue under active attack per secondary research no 1.x fix path migrate to 2.x CVE-2026-3055 and CVE-2026-39987 Citrix NetScaler memory disclosure and Marimo notebook command execution used in Unit42 observed manual campaign impact CVE-2026-42897 Outlook Web Access persistent XSS exploited to deploy OWAReaper implant patched by Microsoft in mid May exploitation reported ongoing CVE-2026-15409 and CVE-2026-15410 SonicWall SMA1000 SSRF and RCE chain CISA KEV since 14 July reported active use by INC ransomware this week CVE-2021-22681 Unitronics Vision Series default credential flaw reused in the Minnesota water utility incident despite being years old not confirmed whether this specific CVE was the sole vector versus default credential access alone CVE-2026-66066 KindaRails2Shell Ruby on Rails Active Storage unauthenticated file read RCE patched this week

Attack Vectors This Week Unauthenticated and alternate path exploitation against internet reachable management APIs dominated confirmed KEV activity especially command injection authentication bypass and unsafe deserialization on appliances and CI CD control planes. Secondary but strategically important vectors included OAuth device code phishing against cloud identities vishing assisted SaaS takeover RMM dual use installation via banking lures and parser differential XSS on ubiquitous CMS login surfaces. Supply chain and dependency risk remained elevated in reporting npm centric patterns in CrowdStrike H1 data unmaintained Java JSON libraries while cloud third party storage exposure drove the week major healthcare adjacent breach disclosure. Exploitation of internet facing management and remote access infrastructure dominated the window SonicWall SMA1000 Nable Ncentral Cisco adjacent remote management and OWA all fit this pattern of attackers targeting the administrative or webmail layer rather than endpoints directly. Credential theft and access persistence featured heavily both in the OWAReaper implant browser storage persistence and in the Minnesota water utilities default credential exposure. Supply chain and third party cloud exposure also surfaced with Amgen breach traced to third party cloud providers rather than Amgen own infrastructure.

Actor and Infrastructure Patterns Storm1175 Microsoft financially motivated StormEncryptor C++ .encrypted extension !!!README_FIRST!!!.txt post compromise use of AnyDesk SimpleHelp Advanced IP Scanner Mimikatz LSASS rapid disclosure to ransomware tempo prior Medusa association. Nable initial access Under Attribution likely per Microsoft not confirmed. knaithe KnYuan Unit42 Chinese speaking opportunistic operator DeepSeek plus Hermes Agent plus Telegram tasking FOFA enumeration public GitHub PoCs accidental workspace exposure via python3 m http.server mixed autonomous failure and manual success. China nexus SNOWLIGHT delivery against Tomcat and broader spray infrastructure reported via consulted sources with UNC style cluster labels in some write ups. Treat multi country government commercial scanning as corroborated theme precise group unification remains Under Attribution where only single commercial telemetry is available. APT29 Cozy Bear cited by CrowdStrike as prominent device code phishing operator against cloud identities technique emphasis not a new full campaign dossier this week. FAMOUS CHOLLIMA STARDUST CHOLLIMA DPRK nexus CrowdStrike report context AI environment and npm supply chain themes in H1 2026 hunting retrospective background pressure not a fresh Week of August 2 exclusive intrusion set. Cybercrime legal closure Connor Riley Moucka guilty plea Krebs on Snowflake era extortion and related theft enforcement signal not active intrusion TTPs for current week operations. Void Blizzard TA488 activity this week showed a maturing infrastructure model GitHub commit search API polling for command and control AES CTR encrypted HTTPS with DNS tunneling fallback and dual persistence across browser localStorage and offline IndexedDB caches a notable evolution from the group earlier Zimbra focused campaign. CyberAv3ngers activity against water utilities relied on low sophistication default credential access rather than novel exploitation consistent with their prior Unitronics focused campaigns per CISA updated AA26 097A. ShinyHunters continued its pattern of converting a single cloud CRM compromise into a rolling multi victim extortion campaign adding three named companies to its leak site this week.

MITRE ATT&CK Themes T1190 Exploit Public Facing Application KEV cluster on LoadMaster Langflow TeamCity Tomcat Ncentral and related edge dev tools T1133 External Remote Services RMM and management plane abuse Ncentral Take Control patterns AnyDesk SimpleHelp ScreenConnect T1059 Command and Scripting Interpreter command injection and post exploit scripting across appliance and endpoint stages T1003.001 OS Credential Dumping LSASS Memory Storm1175 Mimikatz LSASS behavior per Microsoft T1486 Data Encrypted for Impact StormEncryptor ransomware deployment T1566 Phishing T1566.002 Spearphishing Link banking lures and broader social delivery vishing growth in CrowdStrike data supports voice led variants T1566.004 where applicable T1528 Steal Application Access Token device code OAuth grant abuse culminating in cloud session theft behavioral basis device authorization flow misuse described by CrowdStrike map refined with org specific IdP telemetry T1078 Valid Accounts post grant and post bypass operation under legitimate sessions and admin contexts Unitronics default credential access in the Minnesota water utility incident T1195 Supply Chain Compromise npm registry and dependency themes in hunting report retrospective Fastjson transitive risk T1048 T1567 Exfiltration Over Alternative Web Services Amgen cloud exfiltration outcome NetScaler memory theft seeking session cookies in Unit42 casework T1102 Web Service Telegram as operator channel for agentic tasking Unit42 T1027 living off the land patterns dual use RMM and scanners blending into admin noise T1505.003 Web Shell T1189 Drive by Compromise OWAReaper browser context execution triggered by opening a crafted email functioning as a client side persistence mechanism within OWA T1550.004 Web Session Cookie OWAReaper stated survival through credential resets implies session or token level persistence rather than credential dependent access T1071.001 Web Protocols GitHub API polling used as command and control channel by the OWA campaign

Threat Detection SIGMA StormEncryptor ransom note and extension


SIGMA Suspicious dual use RMM installation outside change window


YARA StormEncryptor sample family hash anchored plus note string


YARA Hermes DeepSeek agent workspace residue defensive hunting


SIEM logic Device code OAuth grant anomalies IdP agnostic pseudocode


SIEM logic Ncentral RMM admin takeover follow on


SIEM logic LoadMaster accessv2 pre auth exploitation attempts


SIGMA rule anomalous OWA session activity following message open behavioral based on OWAReaper reporting


YARA rule pseudocode for OWAReaper style browser context implant fragments conceptual based on public reporting no confirmed sample hash available

rule Suspected_OWAReaper_Fragment
{
    meta:
        description = "Detects Base64-fragmented JS assembly pattern reported in OWAReaper campaign"
        reference = "Proofpoint reporting, Aug 2026 - unconfirmed sample"
        confidence = "low - behavioral pattern only, no verified IOC hash"
    strings:
        $b64_fragment_marker = /[A-Za-z0-9+\/]

SIEM detection logic vendor agnostic pseudocode default credential access to ICS OT human machine interfaces


DEFENDER PRIORITIES

First urgency is confirmed exploited edge and management software patch or isolate internet facing LoadMaster Nable Ncentral TeamCity on prem Langflow and Tomcat cluster nodes on CISA KEV timelines then validate from an external attack surface scan rather than CMDB wishful thinking. Concurrently assume ransomware operators will chain any RMM foothold into credential theft within days pair CVE work with immediate controls on dual use remote tools and LSASS protection.

Second close identity protocol gaps that malware centric detections miss. Restrict or Conditional Access gate device code flow alert on unfamiliar OAuth client IDs completing device grants and rehearse token revocation. WordPress estates need core 7.0.3 verification at fleet scale VMware vCenter ESXi emergency builds from Broadcom remain non optional where still lagging.

Third prepare detections for agentic noise bursty FOFA like scanning sudden PoC cloning patterns on DMZ honeypots and Telegram orchestrated tooling are no longer research curiosities. Healthcare and life sciences teams should pressure test third party cloud storage controls after the Amgen disclosure pattern volume and sensitivity of exfiltrated objects can make an incident material even when manufacturing stays up.

The most urgent priority this week is also patching the six newly KEV listed vulnerabilities CVE-2026-63077 CVE-2026-9198 CVE-2026-34486 CVE-2026-18556 CVE-2026-18577 and CVE-2026-8037 given CISA confirmation of active exploitation and short federal remediation windows already in force. Organizations running Nable Ncentral should treat the reported incomplete initial fix as reason to verify remediation directly rather than trusting patch status dashboards alone.

Second priority is any organization exposed on Microsoft Outlook Web Access given the reported persistence of the OWAReaper implant through credential resets patching CVE-2026-42897 alone is insufficient mailbox permission audits and browser context telemetry review are necessary to confirm eviction not just remediation.

Third any organization operating internet facing OT ICS human machine interfaces particularly Unitronics Vision Series deployments should treat default credential exposure as an active ongoing risk rather than a historical finding given this week confirmed exploitation against municipal water systems.

Lower but non trivial priority organizations still running unpatched SonicWall SMA1000 appliances from the mid July disclosure window should assume compromise rather than assume they missed the exploitation wave given INC ransomware continued activity reported this week.

RECOMMENDED ACTIONS

Patch CVE-2026-8037 CVE-2026-18556 CVE-2026-18577 CVE-2026-9198 CVE-2026-34486 and CVE-2026-63077 on all reachable instances record external validation evidence

  • Isolate management interfaces for load balancers RMM CI CD and vCenter behind VPN ZTNA with MFA disable public LoadMaster API where not required

  • Hunt for StormEncryptor artifacts .encrypted !!!README_FIRST!!!.txt hash c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054 and unexpected AnyDesk SimpleHelp ScreenConnect installs

  • Restrict OAuth device code flow to compliant devices alert and auto revoke on anomalous device code completions

  • Upgrade all WordPress cores to 7.0.3 or maintained backports audit Application Passwords and admin session anomalies since late July

  • Apply Broadcom VMware emergency updates for CVE-2026-59309 CVE-2026-59310 and related ESXi guest escape issues verify cluster wide PS host compliance

  • Inventory Langflow n8n Marimo and similar AI workflow UIs remove internet exposure enforce auth on all forms and disable unsafe defaults auto login public flow IDs

  • Migrate applications off Fastjson 1.x block known exploit traffic at WAF while migration proceeds

  • Review third party cloud storage entitlements logging and egress controls for PHI IP repositories tabletop an Amgen style materiality decision path

  • Deploy the SIGMA YARA SIEM logic above into staging within 72 hours tune allowlists then promote to production with SOAR revoke isolate playbooks

  • Patch CVE-2026-63077 JetBrains TeamCity CVE-2026-9198 IBM Langflow and CVE-2026-34486 Apache Tomcat immediately per CISA KEV deadlines

  • Verify Nable Ncentral remediation for CVE-2026-18556 CVE-2026-18577 directly against vendor advisory rather than relying on automated patch status alone

  • Audit Outlook Web Access mailbox permissions organization wide for unexpected Owner level grants tied to CVE-2026-42897 exposure

  • Revoke and re issue OAuth tokens for Outlook add ins holding ReadWriteMailbox permissions if OWA exposure is confirmed

  • Identify and remediate any internet facing Unitronics Vision Series or similar PLC HMI interfaces still using vendor default credentials

  • Block outbound GitHub API polling patterns from Exchange OWA server infrastructure where no legitimate integration exists

  • Confirm SonicWall SMA1000 firmware is fully current 12.4.3 03453 12.5.0 02835 or later and hunt for prior compromise if the mid July window was missed

  • Review third party cloud vendor access scopes following the Amgen disclosure particularly for vendors holding sensitive patient or customer data

  • Patch Ruby on Rails deployments against CVE-2026-66066 where Active Storage image upload handling is exposed

CONFIDENCE & LIMITATIONS

Confidence Level | Rationale High | CISA KEV exploitation status Microsoft Storm1175 StormEncryptor behavioral cluster Unit42 agentic campaign reconstruction CrowdStrike quantitative identity abuse trends Krebs legal reporting on Moucka vendor patch facts for WordPress and JetBrains High | KEV additions and SonicWall INC ransomware reporting corroborated across multiple consulted sources Moderate | Storm1175 to Nable initial access hypothesis explicitly unconfirmed by Microsoft unified China nexus clustering around SNOWLIGHT UNC labels where secondary correlators outpace multi vendor joint advisories Moderate | Void Blizzard TA488 attribution and OWAReaper implant details rest primarily on single vendor sourced reporting treated Under Attribution pending independent corroboration Low to Moderate | Specific role of CVE-2021-22681 in the Minnesota water utility incident versus default credential access alone remains not confirmed by consulted sources Sample Notes | Sample breadth this week is strong on vulnerability exploitation and identity trends thinner on OT specific primary publications and on exclusive long form drops inside the exact window. Kaspersky was not used as sole attribution for any nation state claim. Empty or thin areas are marked rather than padded no high confidence ICS sabotage event defined the week in the sources reviewed. No Tier 1 MITRE ATT&CK Group mapping was found for either Void Blizzard or CyberAv3ngers technique mappings are analyst inferred from behavioral reporting not source confirmed group profiles.