Saturday, August 22, 2026

Saturday Security: Cl0p Ransomware Hits 40+ Companies Through One Vulnerability

 


Your Software Is Your Attack Surface!

This week's Saturday Security Story highlights a growing supply-chain risk: the software your organization relies on can become an attacker’s pathway to your most valuable data.

The Cl0p ransomware group claims to have targeted more than 40 organizations by exploiting CVE-2026-12569, a critical vulnerability in PTC Windchill and FlexPLM product lifecycle management platforms.

The vulnerability reportedly allowed unauthenticated remote code execution and access to sensitive engineering data, with alleged victims including Shell, Philips, GE and Fiserv.

The bigger lesson? Attackers don't necessarily need to breach dozens of companies individually. One vulnerability in widely deployed enterprise software can potentially provide access to many organizations at once.

Third-party software isn't just vendor risk. It's part of your attack surface.

I'm Peter, and that's your Saturday Security Story. Like, subscribe and stay secure!

https://cybermagazine.com/news/plm-zero-day-flaw-exploited-by-clop-in-massive-data-breach

https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/

Saturday, August 15, 2026

Saturday Security: Evil Twin Attack at 30,000 Feet with Fake Wi-Fi on a Delta Flight

 


This week's Saturday Security Story takes us 30,000 feet in the air — and it's a fascinating one. A fake Wi-Fi network appeared on a Delta flight from Las Vegas to Atlanta — and not just any flight. This was a plane leaving the notorious Black Hat conference and DEF CON — two of the world's biggest cybersecurity events. If you're going to pull a stunt like this, that's quite an audience to pick. A passenger had created a network impersonating Delta's onboard Wi-Fi, prompting the airline to shut down legitimate onboard Wi-Fi for approximately 30 minutes while the situation was addressed. The good news: Delta confirmed no aircraft systems or flight safety systems were affected and there was no actual breach of Delta's own infrastructure. But here's why it matters — this is a classic Evil Twin Attack. A fake access point deliberately named to mimic a trusted network — designed to trick unsuspecting users into connecting and potentially exposing their passwords, browsing data, and personal information to whoever controls the rogue hotspot. This week's big takeaway: Never automatically trust the Wi-Fi name you see. Verify the network before you connect — especially in airports, hotels, conference centers, and yes — at 30,000 feet. https://www.theregister.com/security/2026/08/11/def-con-dingus-suspected-of-trying-to-take-over-delta-in-flight-wi-fi/5286331 🗓️ Week ending August 15th, 2026 👤 Hosted by Peter


Saturday, August 8, 2026

Saturday Security: Brinks Breach May Be Just the Beginning

 


This week's Saturday Security Story is a reminder that sometimes the biggest threat after a breach is the attack that comes next. Brinks — yes, the iconic security company — has confirmed unauthorized access to part of its IT systems, saying it quickly activated its incident response process. The good news: alarm monitoring and security systems continued operating normally throughout the incident. The Shiny Hunters group — covered multiple times on this channel — has claimed responsibility, alleging they stole millions of customer and employee records. Brinks has not yet confirmed exactly what information was taken or who may be affected. That uncertainty is itself part of the problem. Brinks is now warning customers to watch for follow-up phishing emails, texts, and phone calls designed to exploit the breach — using stolen personal information to make fraudulent contact appear legitimate. This week's big takeaway: The breach doesn't end when the attackers leave. Stolen data becomes ammunition for the next attack — and the victims of the initial breach become the targets of everything that follows. Stay vigilant. https://brinkshome.com/cybersecurity-update https://www.safestate.com/post/brinks-home-data-breach-confirmed-as-shinyhunters-threatens-leak 🗓️ Week ending August 8th, 2026 👤 Hosted by Peter

Saturday, August 1, 2026

Saturday Security: FBI & EPA Warn Attackers Targeting US Water Systems

 


This week's Saturday Security Story is a sobering reminder that America's water infrastructure remains a prime cyber target. The FBI and EPA are jointly warning that cyber attacks have now been reported at municipal water systems across at least seven states. Iran-linked hackers are the leading suspects in attacks affecting more than 30 Minnesota utilities — though the investigation remains ongoing. The attack method was straightforward but effective: attackers targeted internet-connected industrial control systems (ICS), changing passwords and locking operators out of remote monitoring. The good news — no evidence of drinking water contamination has been found. The bad news — that almost misses the point entirely. This week's big takeaway: Critical infrastructure doesn't have to be physically destroyed to cause serious disruption. Simply forcing utility operators into manual operations creates real-world consequences — slower response times, increased risk of human error, and cascading operational failures. If your OT (Operational Technology) systems are exposed to the internet right now, securing them cannot wait. https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210 🗓️ Week ending August 1st, 2026 — Welcome to August! 👤 Hosted by Peter 00:00:00 - Intro: America's Water Infrastructure Under Attack 00:00:27 - How the Attack Worked — Locked Out of Remote Monitoring 00:00:45 - No Contamination But Real Disruption 00:01:01 - Takeaway: Secure Your OT Systems Now 00:01:01 - Sign-Off & Welcome to August 2026