Weekly Cybersecurity Report | Week 31, 2026

As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.

Weekly Cybersecurity Report | Week 31, 2026

Information security updates and events from the past week

1. Minnesota Municipal Water System Attacks (July 26–27)

A coordinated cyberattack targeted over 30 municipal water systems across Minnesota, U.S. The attacks disrupted automated utility controls in cities including Plymouth and South St. Paul, forcing some systems to switch to manual operations. Preliminary investigations by U.S. authorities pointed toward Iranian-affiliated hackers.

2. Origin Energy Data Breach

On July 28, the Australian energy provider confirmed a major data breach affecting approximately 900,000 current and former customers. Stolen information included PII such as names, addresses, dates of birth, and partial financial details (e.g., last four digits of credit cards or partial bank account numbers).

3. IBM 2026 Cost of a Data Breach Report

Released at the end of July, the report revealed that the global average cost of a data breach reached a record $4.99 million. The study notably found that breaches involving AI-enabled malicious activity cost roughly $1 million more than non-AI incidents and that AI-assisted attacks increased by 56% compared to the previous year.

4. Microsoft Entra ID Authentication Shift

Microsoft announced that starting September 1, 2026, passkeys will become the default authentication method for Entra ID enterprise users. As part of this push for phishing-resistant security, Microsoft will fully retire support for SMS and voice-based multi-factor authentication on February 1, 2027.

5. GitLab Remote Code Execution Vulnerability

Public exploits surfaced for a critical vulnerability in self-managed GitLab instances. Security teams were urged to prioritize upgrading their self-managed environments to patch the flaw, which allows unauthorized code execution.

6. BlueNoroff Phishing Campaign

The North Korean-linked threat group BlueNoroff launched an advanced campaign using a “ClickFix” payload to deliver malware. The attackers impersonated Zoom and Microsoft Teams meeting invitations via compromised Telegram accounts to target high-value individuals and cryptocurrency firms, often utilizing social engineering to push malicious extensions or files.

7. Hotel Wi-Fi DNS Poisoning Campaign

A widespread espionage campaign was identified targeting business travelers via hotel Wi-Fi networks. Attackers compromised hotel router infrastructure to perform DNS poisoning, redirecting guests to malicious portals designed to harvest corporate login credentials, passwords, and MFA tokens before a VPN connection could be established.

The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.