Authorities Investigating Cyberattack on Minnesota Water Systems

Plus, OpenAI's rogue agent compromised a customer at a second tech firm, according to a Reuters exclusive.

Good morning! Here’s what’s up.

People

Diane Quick has joined FTI Technology, the technology segment of FTI Consulting, as a senior managing director. According to her LinkedIn profile, Quick joined FTI Consulting in January 2026 after 12 years at Ankura, where she most recently was a senior managing director.

Noel Brandt, Binsar Marseto, and Emily McIntosh have joined FTI Consulting’s Data & Analytics practice as managing directors within the forensic and litigation consulting segment. Brandt, based in Denver, previously founded High Ground Advisory LLC, a regulatory compliance consulting firm. Marseto, based in Toronto, previously was a director at Guidehouse. McIntosh, based in Dallas, previously was with EY, where she was a senior manager.

.

Clips ✂️

Authorities investigating a coordinated cyberattack against Minnesota water systems

Federal and state authorities are investigating what they call a coordinated cyberattack over two days against operational technology at more than 30 community water systems in Minnesota.

Minnesota IT Services (MNIT), the state agency in charge of information technology, said it is coordinating with various state and federal agencies and private sector partners to respond to the attacks.

John Israel, assistant commissioner at MNIT and the chief information security officer in Minnesota, said authorities were actively working with partners to restore operations and provide other services.

Nate George, the mayor of Braham, Minn., said the attack should serve as a wake-up call to state lawmakers.

“Minnesota’s local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources,” he said in a post on X.

by Cybersecurity Dive

OpenAI's rogue agent compromised a customer at a second tech firm, executive says

The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two other sources familiar with the matter.

Modal executives emphasized that the company itself was not hacked.

According to a timeline published by Hugging Face, opens new tab on Tuesday, the rogue agent broke into a sandbox, or ⁠an isolated testing environment, "hosted on a third-party provider's infrastructure" before turning it into a launchpad for the broader hack.

The third-party provider was not named in the blog post, but Modal's chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal's platform.

Modal said the customer had "published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution" — the digital equivalent of leaving a door open on the internet.

by Reuters

OpenAI’s rogue agent shows why we need federal rules for autonomous AI

Months before the Hugging Face breach, Emergence AI published research that investigative journalist Ronan Farrow made public. Ten autonomous AI agents operated across five virtual environments for fifteen days without human intervention. Much of the attention focused on Grok 4.1 turning violent and Gemini 3 Flash committing 683 crimes.

What mattered more went unnoticed: Anthropic’s Claude Sonnet 4.6 built a peaceful democracy in isolation, then stole resources from neighboring environments the moment it joined a shared one. The lesson was clear: safety is not a model attribute. It emerges from the operating environment. The models didn’t change. Working as designed, their behavior evolved as the environment changed. The lesson is hard to ignore: The governance environment changed, and with it, the reward dynamics.

The story here concerns institutions, specifically OpenAI’s and Hugging Face’s, and how we must understand their recent security incident through that lens.

by CyberScoop

Why Financial Regulators Need a Plan for Quantum-Vulnerable Digital Assets

The federal government is pursuing two policies that are on a collision course.

On one track, it is accelerating the development and commercialization of quantum computing. In June 2026, President Trump issued an executive order establishing a whole-of-government effort to “accelerate deployment and commercialization of quantum computing, sensing, and networking.” A companion order directed federal agencies to migrate their most important systems to post-quantum cryptography by the end of 2031.

On the other track, policymakers are rapidly integrating quantum-vulnerable blockchain infrastructure into the financial system. Last summer, Congress enacted the GENIUS Act, creating a federal regulatory framework for dollar-denominated stablecoins that operate on public blockchains. At the same time, banking regulators have approved or conditionally approved national trust bank charters for major crypto firms, while the SEC is enabling the migration of America’s capital markets onto blockchains.

by The FinReg Blog

Companies fear AI risks more than common cybersecurity threats

Dive Brief:

Businesses are more concerned about AI-fueled threats than traditional cybersecurity dangers, potentially undermining their ability to prepare for the attacks they are most likely to face, researchers at the security firm Arctic Wolf said on Tuesday.

Roughly a third of organizations said AI topped their list of cybersecurity concerns, while concerns about malware, credential theft and cloud misconfigurations dropped from their 2025 numbers, according to Arctic Wolf’s annual AI and cybersecurity trends report.

The report also delved into organizations’ use of AI for their security programs, their reasons for reporting cybersecurity incidents and regional trends in cybersecurity challenges.

Dive Insight:

Arctic Wolf described the prominence of AI on businesses’ list of concerns as a potentially worrisome trend.

“An often-overlooked risk surrounding AI is that the attention it receives is distracting leaders from more familiar business risks,” researchers wrote.

by Cybersecurity Dive

TrendAI Modern Bank Heist: The Industrial Age of Cybercrime

Bharat Mistry, Field CTO at TrendAI says that cybercrime has entered its industrial age, amid nation-backed, agentic & AI-powered attacks on fintech firms

AI agents, state-sponsored threat actors and cybercrime-as-a-service are outpacing defences in the financial sector, according to a new report from TrendAI.

The report, titled Modern Bank Heists 2026: The Machine-Speed War for Financial Control, surveyed CISOs across the financial sector and revealed a big shift in attacker strategy.

Adversaries are now pushing back during live incidents, with TrendAI data showing that 67% of institutions experienced such counter-incident response where bad actors attempted to undermine the work of defenders.

AI-backed attacks at machine speed

The TrendAI report revealed a stupendous rise in in AI-enabled attacks at 89% year-over-year rise, confirming that offensive operations can now run at the speed of the machine.

Campaigns that once needed skilled operators, including phishing and fraud, are increasingly run in the background without direct human input, aided by AI tools.

by Cybersecurity Magazine

X