• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity​

Provides Practical Approaches to Implementing Cyber Decoy Strategies Aligned to MITRE Engage and ATT&CK Frameworks
Released September 16, 2026

WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) released guidance that helps critical infrastructure owners and operators implement realistic decoy systems and information assets to quickly detect and disrupt malicious activity occurring in their networks, which will ultimately improve their cyber defenses. Using Cyber Decoys to Strengthen Detection and Response is the first guide from CISA that offers a detailed explanation of the defensive cyber decoy process.

Continued: https://www.cisa.gov/news-events/ne...t-observe-and-impede-malicious-cyber-activity
 

[please see post #79. https://flutrackers.com/threads/cyber-incidents-usa-2026-27.1039752/post-1041306]

Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks: Sources​

September 16, 2026,
U.S. authorities said there were no reports of "operational disruptions."

The Coast Guard and FBI are investigating after two oil tankers bound for the U.S. were hit with suspected cyberattacks last month, prompting American authorities to launch investigations into both incidents, sources told ABC News.

Continued: https://abcnews.com/Politics/coast-guard-fbi-investigating-after-2-oil-tankers/story?id=136482324
 

USCG, FBI assess OT and IT systems aboard two oil tankers following suspected foreign cyberattacks​

SEPTEMBER 17, 2026
Excerpt:

...This disclosure comes as American utility company CenterPoint Energy said it became aware in September of an online post by a third party claiming to have obtained a dataset containing certain customer information, prompting the company to activate its cybersecurity incident response protocols and launch an investigation with third-party cybersecurity experts.

“The Company’s delivery of electric and gas services has not been impacted and remains operational and undisrupted,” CenterPoint detailed in an SEC filing this week. “As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company’s financial condition or results of operations.”...

...https://industrialcyber.co/industrial-cyber-attacks/uscg-fbi-assess-ot-and-it-systems-aboard-two-oil-tankers-following-suspected-foreign-cyberattacks/
 

Using Cyber Decoys to Strengthen Detection and Response​

Publish Date September 16, 2026
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.

Cyber decoys complement Zero Trust by:

continued: https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
 

Cybersecurity Exercise to Strengthen Resilience​

Released September 18, 2026
Washington, DC – The Cybersecurity and Infrastructure Security Agency (CISA) hosted Cyber Storm X this week, a four-day national cybersecurity exercise designed to test and ultimately strengthen the nation’s resilience. This year’s exercise included 2,000 participants from across the public and private sectors and marks the tenth exercise in the 20-year history of Cyber Storm. The biennial exercise brings together the people who manage the services our nation relies on, including water, energy, and other vital sectors. During the exercise, participants practice how they would respond to a major cyber incident affecting critical infrastructure.

“Cyber Storm helps critical infrastructure owners and operators understand how we would manage a large-scale cyber incident,” said Acting CISA Director Nick Andersen. “Exercises strengthen our national resilience by making sure our plans, policies, and partnerships are ready when we need them. As a nation, we need the ability to respond swiftly and effectively to critical threats. That’s exactly what Cyber Storm does and why it’s a vital exercise for our nation’s security.”

This year’s exercise focused on a scenario involving a nation-state adversary targeting the transportation systems sector, including rail and ports, along with the water and wastewater systems sector. The exercise allowed participants to test response plans, practice coordination, and strengthen information sharing in a safe environment. Cyber Storm X included over two hundred organizations across all levels of government and the private sector.

CISA will now collaborate with participating organizations to identify lessons learned from the exercise. We will use these findings in a public after-action report that captures observations, analyses, and recommendations. CISA is committed to providing access to a wide range of cybersecurity tools and training opportunities, with exercises being a critical part of that toolkit to enhance our nation’s cyber preparedness.

For more information, please visit Cyber Storm X: National Cyber Exercise
 

[please see https://flutrackers.com/threads/cyber-incidents-usa-2026-27.1039752/post-1041350]

Another Tanker Suffers Failure as Crew Suspect Cyber Attack​

September 18, 2026
(Bloomberg) — A liquefied natural gas tanker bringing fuel from the US to Europe suffered a systems failure that the crew reported as a suspected cyber attack, according to people familiar with the matter.
-snip-
The suspected hacking of the Vivit Africa LNG follows other incidents in late August, when two oil and gas tankers off the US coast were boarded by the Coast Guard and Federal Bureau of Investigation due to potential cyberattacks.

 

Gemini hacked three companies in first known breakout by Google's AI​

Posted about 9h ago
Google's Gemini AI model has accessed the internet and hacked other companies during a test of its cybersecurity capabilities, in the first known example of the company's artificial intelligence systems autonomously committing such an act.

The hacks occurred in May during a test conducted by Irregular, an independent company that conducts cybersecurity evaluations.
-snip-
Google told the WSJ it didn't consider it necessary to disclose the incidents earlier because its model stopped the hacking upon learning the companies were real and did not cause harm to them.


Continued: https://www.abc.net.au/news/2026-09-19/gemini-google-ai-hacks-three-companies/107172128
 
Colorado

Foreign hackers breach two more US water utilities, threaten safety of Colorado residents​

Published September 18, 2026
Foreign actors hacked two Colorado water utilities' computer systems last month, changing pumping cycles, disabling alarms and altering equipment settings before operators regained control, state officials said Thursday.

"These were brief incidents, and the risks were quickly addressed by the providers themselves, who subsequently alerted the state," Polis spokeswoman Eric Maruyama said in a statement.

The hackers altered equipment settings, disabled remote access and alarms and changed pumping cycles, according to the governor's office

The water utility systems that were impacted provide drinking water to approximately 400 people.

Continued: https://www.foxnews.com/politics/fo...-utilities-threaten-safety-colorado-residents
 
Colorado
‘Foreign actors’ briefly hacked two small Colorado water utilities last month, state says

Foreign actors gained access to two small water utility systems in Colorado late last month, state officials confirmed, just weeks after hackers with suspected links to Iran had attempted to access similar systems elsewhere in the United States.

continued: https://www.denverpost.com/2026/09/18/colorado-water-systems-hacking-iran-concerns/
 
Kansas

Ransomware attack on Kansas county will affect some services​

Posted: Sep 18, 2026 / 12:23 PM CDT
Updated: Sep 18, 2026 / 05:30 PM CDT

WICHITA, Kan. (KSNW) — A Kansas county’s government says it has been hit by a ransomware attack.

Ellis County discovered the attack on parts of its information technology systems Thursday morning.

Officials said they “immediately took steps to contain the disruption” by isolating the affected systems and enlisting the help of cybersecurity experts.

Continued: https://www.ksn.com/news/state-regi...k-on-kansas-county-will-affect-some-services/
 
Back
Top Bottom