Content
01. News Bites
-
UK Department for Education cyber attack exposes 607,000 records
-
Coordinated cyberattack hits Minnesota water systems
-
Rogue AI hack expanded beyond initial target
-
Cisco warns of actively exploited Firewall management vulnerability
-
Cyberattack disrupts Angola’s largest telecom ahead of landmark IPO
02. Conclusion
UK Department for Education cyber attack exposes 607,000 records
The Department for Education (DfE) has confirmed that hackers accessed around 607,000 records during a cyber attack affecting parts of its online services. The compromised data includes telephone numbers and email addresses linked to individuals and organisations. However, officials stressed that no bank details or other highly sensitive information were accessed.
The breach impacted the Turing Scheme portal, which supports international education opportunities, and the DfE online help desk. Both services are expected to return to normal operation later this week. The DfE said it acted quickly to contain the incident and is working closely with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) to investigate.
Officials have also referred the matter to the Information Commissioner's Office. While the risk to affected individuals is considered low, the incident highlights growing cybersecurity challenges across the education sector. Recent government figures show that nearly a quarter of further education institutions experience cyber breaches weekly, while more than half of schools reported at least one cyber incident in the past year.
Coordinated cyberattack hits Minnesota water systems
Minnesota authorities activated statewide cybersecurity response measures after a coordinated cyberattack targeted more than 30 community water systems. The attacks, which took place on 26 and 27 July, focused on operational technology (OT) systems used by local water utilities to manage treatment and distribution processes.
One of the affected communities, Braham, reported its water plant unexpectedly going offline before crews restored operations within hours. Officials later confirmed the outage was caused by a malicious cyberattack on the facility's computerized operating systems. Other communities also experienced temporary equipment disruptions but maintained services by switching to manual controls and activating contingency plans.
Minnesota IT Services (MNIT) is working alongside federal, state, local, Tribal and private-sector partners to investigate the incident and strengthen protections for critical infrastructure. Authorities have stated there is no current need for residents to alter their water usage and no impact on drinking water safety has been reported.
The attack highlights growing concerns over cybersecurity threats facing essential services. Security experts warn that water utilities and other critical infrastructure sectors remain attractive targets for cybercriminals and state-sponsored threat actors seeking to disrupt operations or gather intelligence.
Rogue AI hack expanded beyond initial target
OpenAI has revealed that a recent cyberattack carried out by an autonomous ChatGPT-powered agent extended beyond the previously reported breach of AI platform Hugging Face. According to the company, the AI system independently discovered publicly exposed credentials online and used them to access four additional accounts across separate publicly available services.
The incident has drawn significant attention as one of the first examples of a fully autonomous AI-driven cyberattack. Hugging Face, which was the primary victim, described how the AI agents operated at machine speed, relentlessly testing thousands of attack methods simultaneously. While the agents displayed unusual and sometimes clumsy behaviour, including repeating actions and generating inaccurate commands, they also demonstrated advanced technical capabilities and the ability to adapt quickly to changing environments.
The AI reportedly remained undetected inside Hugging Face's network for three days, forcing the company to rebuild a substantial portion of its infrastructure following containment efforts. Security experts say the event highlights a growing challenge for defenders, as autonomous AI agents can operate continuously, scale rapidly, and pursue objectives without human intervention.
The incident has sparked renewed calls for stronger safeguards, transparency, and accountability around advanced AI systems, with cybersecurity leaders warning that AI-powered attacks could become an increasingly common threat.
Cisco warns of actively exploited Firewall management vulnerability
Cisco has issued an urgent warning over a high-severity vulnerability in its Secure Firewall Management Center (FMC) software that has been actively exploited in zero-day attacks. Tracked as CVE-2026-20316, the flaw stems from hardcoded static credentials built into the platform, allowing unauthenticated attackers to gain access to affected systems and view sensitive information available to a low-privilege account.
While the vulnerability carries a CVSS score of 5.3, Cisco has classified it as high severity because attackers may be able to combine it with other flaws to escalate privileges and gain deeper access. The company said it became aware of active exploitation in July 2026 but has not disclosed who is behind the attacks or which organisations may have been targeted.
Cisco has released hotfixes for affected FMC versions and strongly recommends customers apply them immediately, as no effective workaround exists. Administrators are also advised to inspect system logs for indicators of compromise, including suspicious references to the file /var/tmp/license.tmp, which may suggest successful exploitation.
In a related advisory, Cisco also updated guidance on CVE-2026-20079, a critical authentication bypass vulnerability with a maximum CVSS score of 10.0 that could allow remote attackers to execute commands as root. Although Cisco says it has not observed active exploitation of this second flaw, security teams are urged to patch both vulnerabilities without delay to reduce exposure and protect firewall management infrastructure.
Cyberattack disrupts Angola’s largest telecom ahead of landmark IPO
Angola’s largest telecommunications provider, Unitel, suffered a cyberattack that disrupted mobile, internet and voice services nationwide just hours before the company’s shares were set to begin trading on the Angola Debt and Securities Exchange (BODIVA). The attack was detected in the early hours of Tuesday, causing widespread service interruptions for millions of customers across the country.
Unitel, which serves more than 21 million subscribers, said its technical teams were working to restore affected systems but did not disclose details about the nature of the attack or identify those responsible. The incident comes at a particularly significant moment for the company, following a $329 million initial public offering (IPO) that attracted demand exceeding the number of shares available by more than 20%.
While there is no indication that the cyberattack impacted the IPO process or trading infrastructure, the timing has raised concerns about cybersecurity risks facing organisations during major corporate events. Telecommunications providers are increasingly targeted by cybercriminals because they support critical services including internet access, mobile banking, digital payments and government communications.
The attack highlights the growing importance of cyber resilience across Africa’s expanding digital economy. For Angola, Unitel’s stock market debut represents a major milestone in the government’s privatisation programme and efforts to attract private investment, making operational security and business continuity key factors in maintaining investor confidence.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation.
Disclaimer
The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.