Trump launches Texas test bed for nationwide water cyber defense

Project Watershed 250 will pair federal and Texas officials with technology companies in a six-month effort to find and fix vulnerabilities in water systems before expanding the model nationwide.

Share
Trump launches Texas test bed for nationwide water cyber defense
Photo by Iain / Unsplash
a satellite satellite dish is shown in this aerial photo
Photo by Iain / Unsplash

The Trump administration is formally launching a new water sector cybersecurity program Monday in San Antonio that will bring together the Office of the National Cyber Director, Texas Cyber Command, the office of Texas Gov. Greg Abbott, and private industry partners.

The initiative, dubbed Project Watershed 250, will use Texas as the testing ground for a six-month pilot aimed at finding vulnerabilities in water systems and helping utilities address them with private sector cybersecurity and artificial intelligence tools. The administration ultimately plans to expand the model nationwide.

Fox News first disclosed the program’s details Monday after receiving advance materials from the Trump administration and participating companies. The rollout follows Politico and Nextgov/FCW reporting on the plans last week.

“President Trump has cemented America’s leadership in AI security and innovation and is now bringing those exquisite tools to local communities and utilities in Texas and ultimately, across the nation,” National Cyber Director Sean Cairncross said in a statement to Fox.

The EPA and the Cybersecurity and Infrastructure Security Agency will serve as federal partners for the program. Firms including Microsoft, Reflection AI, Palo Alto Networks and industrial cybersecurity company Dragos will participate alongside ONCD and Texas Cyber Command. The utilities will receive the assistance at no cost, according to Abbott’s office. (David DiMolfetta / NextGov/FCW)

Related: CyberScoop, Axios, Click2Houston.com, Washington Examiner, Robert M. Lee on LinkedIn, Austin American-Statesman, Fox News


Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


Anthropic temporarily paused some AI training and cybersecurity evaluations, the company said in a blog post detailing changes made after unauthorized actions by its agents earlier this year.

Anthropic said it paused external cyber evaluations of pre-release models after three incidents it disclosed in July, and also briefly paused its own in-house tests of pre-release models.

The company also paused higher-risk reinforcement-learning environments on pre-release models for several weeks after the incidents.

Most reinforcement learning has resumed, but some high-risk environments remain paused pending manual review or updated monitoring tools, according to Anthropic's blog post.

Rival OpenAI said it had paused some model work due to safety concerns. Now, we know Anthropic did the same — and they're reiterating the need for a broader pacing of frontier AI development.

Anthropic will work with METR, one of the groups that OpenAI worked with, on an independent review. (Madison Mills, Sam Sabin / Axios)

Related: Anthropic, Tech Insider, The Cryptonomist, Blockchain News

METR, a research non-profit that evaluates frontier AI models for their ability to carry out long-horizon tasks, reports that external attackers exploited weaknesses around the AI evaluator's public infrastructure in two incidents earlier this year.

Following a thorough investigation in collaboration with its security consultants, METR believes no sensitive information was accessed in either of these incidents. Nonetheless, the company believes it is valuable to share information about how these incidents look in practice and the steps we took as a result.

In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits.

In May 2026, METR observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. Although these incidents had limited consequences, we considered them near-misses and increased our security investment in response. (METR)

Institutional blockchain Cronos took the unusual step of halting its entire blockchain on Sunday, Aug. 30, after a suspected price manipulation attack targeted Tectonic, its largest decentralized lending protocol.

The attack affected an estimated $75 million, although neither Tectonic nor Cronos has confirmed the final loss or published a complete post-mortem.

Most of the suspected proceeds remained trapped on Cronos after validators stopped the network.

Before the incident, Tectonic held roughly $121.7 million in total value locked and $82.7 million in active loans. By Monday, its TVL had fallen to around $3 million, according to DefiLlama data.

The apparent weakness was not a conventional smart contract drain.

Onchain researcher Weilin Li said the attacker targeted TONIC, Tectonic’s thinly traded governance token, and pushed its price roughly 100 times higher within about 20 minutes.

The attacker then deposited the artificially inflated TONIC into Tectonic as collateral and borrowed higher-value assets against it. (Dr. Guneet Kaur / CCN)

Related: The Record, Protos

Losses from the hack of Solana-based neobank Avici have now exceeded $1 million, with the attacker laundering the stolen funds through Tornado Cash, a crypto mixing service often used to obscure transaction trails.

Blockchain security firm Onchain Lens tracked the movement of funds, revealing that the hacker address beginning with FVNFzq converted 10,000 SOL into 1.02 million USDC, then bridged the assets into 418 ETH before depositing them into Tornado Cash.

The exploit is believed to have stemmed from vulnerabilities in smart contract permissions and signature verification, though the exact method has not been fully disclosed.

Security experts point to weaknesses in Avici’s smart contract permission controls and signature verification processes as likely entry points. Such vulnerabilities allow attackers to manipulate transaction parameters or forge signatures, enabling unauthorized withdrawals. (DHAVAL / Bitcoin World)

Related: Incrypted, The Defiant Team, AMB Crypto, CoinDesk, ChosunBiz

Wallets tied to North Korea’s Lazarus Group moved more than $30 million in Bitcoin (BTC) through Hyperliquid over three weeks. The activity raises sanctions questions as the exchange pursues US market access.

Emmett Gallic, an analyst at blockchain intelligence firm Arkham, identified the wallets. He cited a 2024 attribution by investigator ZachXBT. The funds converted to Ether (ETH) and Solana (SOL) before reaching centralized exchanges including Kraken, LBank, and KuCoin.

Donald Trump named Hyperliquid directly at an August White House event. He credited Commodity Futures Trading Commission (CFTC) Chairman Michael Selig with leading the effort. (Darryn Pollock / BeInCrypto)

Related: CoinDesk, Cryptopolitan, BeInCrypto, Yellow, Crypto Briefing, Politico

Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.

Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.

PaperCut Software released three sets of emergency patches to address the vulnerabilities on Thursday, Friday, and Tuesday, "to rush mitigations to customers who might not be able to remove their servers from the internet."

"The first release was an emergency mitigation. The next release added further hardening as we understood more," explained PaperCut CEO Chris Dance today. "We have additional work in hand, and there may be further Emergency Patch releases if required, and of course, a final fully QA and regression-tested official release soon." (Sergiu Gatlan / Bleeping Computer)

Related: PaperCut, Security Week, eSecurity Planet, Security Affairs, Security Week, GBHackers, Help Net Security

The Foreign Ministry on Tuesday established the Cyber Security Policy Division within its Foreign Policy Bureau in response to the growing risk of cyberattacks driven by advances in artificial intelligence.

The division will be responsible for further strengthening coordination with allied and like-minded countries, as well as other partners, while also contributing to international rule-making, the ministry said.

The unit was first created in 2016 under the bureau but was later merged into the National Security Policy Division as part of an organizational reform.

Amid increasing cyber threats, however, the ministry determined that a dedicated division is necessary. (Japan Times)

Related: Ministry of Foreign Affairs Japan, Nippon.com

Researchers at Sygnia report that an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router could not be explained by a running configuration or commit history.

They discovered Fire Ant's new tactic after finding on a Cisco IOS XR router an active GRE (Generic Routing Encapsulation) tunnel interface that could not be explained by a running configuration or commit history.

Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that ran the implant only during alternating hours.

The malware selectively suppressed syslog messages to hide tunnel-related information from legitimate administrators, established outbound Telnet connections to Fire Ant infrastructure, and supported interactive shell access with no logging.

The attackers also used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers.

These captures could expose internal topology, administrative connections, authentication flows, routing relationships, and traffic exchanged with connected networks.

Sygnia believes that Fire Ant's operation aimed to compromise trusted infrastructure at an initial victim and use it as a covert bridge to explore access paths into connected high-value networks, a tactic which they dub “target behind the target.” (Bill Toulas / Bleeping Computer)

Related: Sygnia, Cyber Security News, CSO Online

Fire Ant's evasion tactics. Source: Sygnia

Researchers at Datadog Security discovered a new password-spraying campaign targeting AWS root user accounts at more than 150 organizations, highlighting the continued value of cloud environments’ most privileged identities to attackers.

A newly disclosed password-spraying campaign targeting AWS root user accounts at more than 150 organizations highlights the continued value of cloud environments’ most privileged identities to attackers.

The activity relied on a broad, proxy-backed infrastructure to tunnel authentication requests.

The source IP addresses were distributed across multiple countries and autonomous systems, with threat intelligence services classifying the infrastructure as hosting providers, residential proxy networks, or similar anonymization services.

This infrastructure makes IP-address blocking less reliable and complicates attribution efforts. Datadog researchers also found no clear victimology pattern.

The affected organizations operated across various industries and geographic regions, indicating that the campaign was likely opportunistic rather than targeted at a particular sector or region.

Although AWS requires multi-factor authentication for root users, attackers may still seek accounts with recently created root credentials, weak recovery processes, incomplete security hardening, or passwords previously exposed in third-party breaches. (Tamilselvan / CyberPress)

Related: Datadog Security Labs, Cyber Security News

AWS Root User Sign in page. Source: Datadog.

Google Threat Intelligence researchers linked a series of intrusions into Brazilian financial institutions to a financially motivated hacking group it calls BREEZE COMET (formerly UNC5669) that uses custom malware and generative AI to manipulate payment systems and execute fraudulent transfers.

BREEZE COMET has targeted banks, payment processors, retailers, cryptocurrency exchanges and financial-technology providers since 2024. Its operations focus on organizations with access to Brazil’s Pix instant-payment network and other banking systems.

The threat actor gains access through methods including password spraying, voice phishing and the installation of remote-management software, Google said. The hackers have also compromised government websites to distribute malware, connected rogue hardware directly to retail networks and searched development environments for credentials, API keys and cloud-access tokens.

Once inside, the attackers use stolen accounts and custom malware to move through networks and reach core financial applications. In one incident, BREEZE COMET carried out two waves of hundreds of fraudulent transactions within 24 to 48 hours of gaining access. Google said the group has successfully stolen at least tens of thousands of dollars.

Google found evidence that BREEZE COMET used large language models to help create scripts for network reconnaissance, credential testing, malware deployment, and data theft. The AI-assisted tools were highly customized and functional but contained hallmarks of machine-generated code, including verbose comments and standardized structures, Google said.

The threat group has also developed backdoors and tunneling tools in several programming languages, including Rust, Nim, Go and Java, allowing it to maintain redundant access and evade security controls. Its infrastructure involving compromised municipal websites in Nigeria, Paraguay, Ghana and Venezuela may indicate plans to expand elsewhere in Latin America and Africa.

Google said the campaign marks a shift in Latin American cybercrime from high-volume fraud against individual banking customers toward direct attacks on the financial infrastructure that processes payments. (Google Threat Intelligence Group)

The US Office of Management and Budget has officially released a memo directing agencies to expand the use of Login.gov for user identity verification in a push to make it the universal sign-on for public services.

In a six-page document dated Monday, OMB Director Russell Vought told agencies the absence of a clear strategy has led to agencies deploying various sign-on solutions and taking different approaches to digital identity management. Per the memo, that means users often need multiple sign-ons, and the government pays more.

“This policy enforces Login.gov as the universal sign-on for accessing public services online, enabling more seamless and efficient service delivery while safeguarding user privacy and supporting resilience against fraud and security threats,” Vought said in the memo.

The official release of the policy comes after OMB recently circulated a draft version of the document to leaders for feedback. FedScoop obtained a copy of that draft and first reported on its contents last week. At the time, current and former officials viewed the policy as an effort to continue a longstanding push to establish a single sign-on for government. (Madison Alder / FedScoop)

Related: The White House, ExecutiveGov, Federal News Network, NextGov/FCW, Biometric Update

Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code execution (RCE) from nearby devices via Bluetooth Low Energy (BLE).

This research, referred to as UniBLEed, indicates that the attack can compromise the robot’s Locomotion PC, the component responsible for essential functions, without requiring any BLE pairing.

The vulnerabilities have been assigned the identifiers CVE-2026-76639 and CVE-2026-76640. The latter refers specifically to the Bluetooth-related chain of exploits.

A GATT characteristic, identified as 0xFFE2, accepted writes only with basic WRITE permission, allowing a nearby device to interact without needing to authenticate or pair.

A cleartext bootstrap command returned an AES-128 key specific to the robot, encapsulated inside an RSA-encrypted response.

Typically, the key-wrapping process should keep it secure. However, the researcher found that Unitree’s cloud API endpoint at /device/bindExtData would decrypt the data and return the plaintext key to any authenticated Unitree account.

Alarmingly, the API did not verify ownership of the serial number submitted with the request, meaning that merely being near the target was enough to recover the unique secret associated with the robot’s BLE version 3 setup and Wi-Fi configuration.

Once the researcher Boschko obtained this key, they could access protected BLE operations. A 121-byte pre-shared key was used to trigger an insecure Wi-Fi fallback in a script called wpa_connect.sh. (Divya / GBHackers)

Related: Boschko.ca, Cyber Security News, SC Media, Security Affairs

Florida is revoking permits for Flock cameras and similar license-plate readers on state roads, dealing a blow to local law enforcement agencies that say they’re a critical crime-fighting tool.

In a memorandum, Florida Department of Transportation Assistant Secretary Will Watts gave agencies 30 days to remove the cameras from state roads, or FDOT will remove them itself.

The agency also no longer intends to issue permits for the cameras.

The controversial cameras — most commonly manufactured by Flock, but numerous other companies make similar devices — photograph every vehicle that passes by, recording details like license plate numbers, make, model, color, and markings like dents and scratches on cars.

Thousands of cameras have been posted on streets across the state — and tens of thousands more nationally — and law enforcement agencies say the cameras are critical tools to solving crimes quickly.

Florida's move follows Texas governor Greg Abbott's order to pause funding for Flock cameras as scrutiny over the AI-powered surveillance devices has mounted. (Ryan Gillespie / Orlando Sentinel) 

Related: Townhall, Business InsiderDecrypt

Microsoft confirmed a widespread, multi-hour outage affecting Outlook users, leading to email delays and failures, authentication issues, and other problems.

In a post on X, Microsoft reported the issue was impacting its Exchange Online service, its cloud-hosted platform for business email, calendar, contacts, and tasks, and then said it had identified the problem.

“We’ve confirmed that users may experience degraded functionality with various Exchange Online functionalities. We’re reviewing service telemetry and diagnostic data to isolate the source of the issue,” Microsoft wrote at 12:43 p.m. ET on Monday, after an earlier message saying it was investigating user reports of Exchange Online problems.

The company said that it identified an issue with an “authentication component” and is testing what it believes will be a remediation strategy with a portion of the infrastructure to determine if it resolves the problem. If so, it will roll out the solution more broadly. Later, it noted that the authentication component was impacting other services beyond Exchange. (Sarah Perez / TechCrunch)

Related: Türkiye Today, MashableCNET, IJR News

Best Thing of the Day: Clothing to Avoid AI Surveillance

Artist Simon Weckert designed digital camouflage clothing as a response to the proliferation of AI-powered surveillance cameras that detect people, vehicles, animals, bicycles, and other objects in their field of view

Worst Thing of the Day: No More Ethnic Cleansing Supporting Password Managers

1Password has committed $300,000 to the Omacom Foundation, which makes Omarchy, a Linux distribution created and controlled by European ethnic cleansing advocate David Heinemeier Hansson.

Closing Thought