Cut Lead Review From Hours To Minutes
Sign up for a free trial of Attio, the agentic CRM.
Ask Attio to build a daily workflow that surfaces the deals that need your attention today, like anything with a stage change, a recent reply, or a new signal in the last 24 hours.
Review your pipeline in Claude, synced live from Attio via MCP.
That's it.
Iran-linked hackers just widened a water-utility hacking campaign to a dozen states, a federal patch deadline for a critical LoadMaster bug lands today, and a WordPress bug with a comic-book name hits every install since 2023. Also: an 18-year-old Linux kernel flaw gets weaponized, and Switzerland's IT agency finds out the hard way that "patched last month" isn't the same as "patched everywhere." Coffee first, then patch.
Iran-Linked Hackers Widen Their Water Utility Campaign to 12 States
Water and wastewater utilities in Michigan, Minnesota, Georgia, New Jersey, and South Dakota have all reported operational-technology intrusions since late July, with more than 30 community water systems hit in Minnesota alone. Attackers are gaining remote access to pumps, valves, and pressure controls, forcing some operators onto manual control — though officials say there's been no disruption to actual water supply so far. Federal agencies haven't formally attributed the campaign, but multiple sources point to Iran-linked actors running the same OT-targeting playbook they've used since 2023. If you or your clients touch municipal or utility infrastructure, this is the week to audit remote access into OT/ICS environments — before a pump stops, not after.
CISA's LoadMaster Patch Deadline Is Today
CISA added Progress Kemp LoadMaster's command-injection flaw (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after logging 792 exploitation attempts from 65 IP addresses across 18 countries. Federal civilian agencies had until today, August 10, to patch under Binding Operational Directive 26-04 — a deadline every MSP with a LoadMaster client should be quietly treating as their own. Move any internet-facing appliance with the API enabled onto GA 7.2.63.2 or LTSF 7.2.54.18 now.
One Login-Screen Bug, Every WordPress Site Since 2023
WordPress patched a pre-authentication reflected XSS on its login screen — CVE-2026-64638 (CVSS 8.9), already nicknamed XSS2Shell — that chains straight to PHP code execution with zero credentials required. It hits every version from 6.4 through 7.0.2. The fix shipped in 7.0.3 and was backported across 24 maintenance branches, all the way down to 4.7.34, which tells you exactly how seriously WordPress core is treating it. If clients run self-hosted WordPress, and most do, get them updated this week, not next.
A Linux Bug Older Than the iPhone Just Got a Name
Researchers at Tencent's Zhuque Lab uncovered SCTPhantom (CVE-2026-64564), a use-after-free in the Linux kernel's SCTP networking stack that's been sitting there since 2007-2008. A local attacker can ride it to root privilege escalation and, worse for anyone running multi-tenant infrastructure, escape a default-seccomp container straight to the host — no special capabilities required. Patches are already backported to 6.6.148, 6.12.101, 6.18.42, and 7.1.6. If you run shared hosting, container platforms, or anything multi-tenant for clients, this jumps the patch queue.
Switzerland's IT Agency Learns the July Patch Tuesday Lesson the Hard Way
Switzerland's Federal Office of Information Technology (BIT) confirmed attackers compromised roughly 200 government accounts — both user and technical — after breaching SharePoint servers, likely via one of two SharePoint flaws (CVE-2026-56164 or CVE-2026-50522) Microsoft patched back in July. BIT caught the intrusion within days, cut internet access to the platform, and reset every affected password; so far there's no evidence sensitive data left the building. The reminder for anyone managing M365/SharePoint for clients: "patched last month" and "patched everywhere" are not the same sentence.
That's the stack for today. If you only patch one thing before lunch, make it LoadMaster — the federal deadline was this morning. See you tomorrow.
— The ChannelBytes Team





