Venkat Mangudi

Writing on cybersecurity, AI, resilience, leadership, and risk.

Follow

Signal Watchtower Edition 015: The Utility Breach Nobody Saw Coming

The Signal Watchtower: Security, Privacy, AI
Edition 015

A Texas power utility lost 7.5 million customer records. Nearly a thousand Windows patches shipped in one cycle. And an AI company opened an investigation into its own agents.

FocusSecurity · Privacy · AI

Coverage window1 – 15 September 2026

AuthorVenkat Mangudi, Founder & CEO, Elytra Security

What happened, and why it matters to your business

STORY 01 · 7.5 MILLION RECORDS, ONE UTILITY

CenterPoint Energy confirms a breach after a hacker leaks customer data

CenterPoint Energy, a Texas power and gas utility serving millions of homes and businesses, confirmed that customer data was stolen after a hacker publicly leaked records they claimed to have taken from the company’s systems. The company has not disclosed exactly how the attacker got in. The 7.5 million records puts this among the larger utility breaches on record, and utilities hold the kind of billing, address and account data that fuels further scams against the same customers.

STORY 02 · A RECORD-SIZED MONTHLY FIX, THEN EMERGENCY FOLLOW-UPS

Microsoft’s biggest Patch Tuesday of the year needed emergency fixes days later

Microsoft’s monthly security update this cycle addressed close to a thousand individual vulnerabilities, an unusually large number even by recent standards. Within days, the company had to issue emergency follow-up fixes because some of the original patches caused problems of their own. Vulnerabilities are surfacing faster than any single monthly cycle can cleanly absorb, and even the fixes now need fixing.

STORY 03 · WHEN THE HELPER MIGHT HAVE BEEN THE PROBLEM

OpenAI investigates whether its own AI agents were linked to an attack on a code repository

OpenAI confirmed it is looking into a report connecting its AI agents to an incident earlier this year at RubyGems, a repository developers use to share code, where suspicious activity forced administrators to temporarily stop new account signups. If confirmed, an AI system built to help people write and manage code was itself, directly or indirectly, part of an attack on the infrastructure developers rely on daily. Every organization deploying AI agents will eventually have to answer who is accountable when the agent, not a person, does the damage.

A breach at a power company affects the same customers who trust it to keep the lights on. A patch cycle that ships nearly a thousand fixes at once means IT teams everywhere are triaging faster than they can verify. A leading AI company publicly investigating its own agents shows the tools your teams are adopting can act in ways nobody explicitly told them to.

What this means for you, in practice

  • Ask whether your organization uses any utility, energy or infrastructure provider that has recently disclosed a breach, and whether your account details were part of it.
  • Ask how your IT team prioritizes a monthly patch batch when hundreds of fixes arrive at once, and whether they wait for vendor confirmation before applying critical ones.
  • Ask which AI coding assistants or agents your developers use, and whether anyone reviews what those agents actually do with repository or package-manager access.
  • If your organization is a utility, energy provider or handles similarly sensitive customer records, ask when your incident response plan was last tested against a large-scale data theft scenario.
  • Treat a breach notification from any service provider, utility included, as seriously as a breach of your own systems.

Read the full edition: the complete technical briefing follows on the pages after this preface, and is also available as a downloadable PDF at wp.me/ag5Z8Q-2So.

The Technical Briefing

What the first half of September revealed

A near-thousand-CVE Patch Tuesday, a wave of no-patch-window exploitation across VPN and network security appliances, and mounting evidence that AI agents are now directly implicated in attacks on developer infrastructure. Confirmed facts are separated from claims throughout.

Nine security flaws crossed from disclosure to active exploitation in this window alone, several within hours of a patch or proof-of-concept becoming public.

01Executive Overview

A record patch cycle met a record exploitation pace

The first half of September was dominated by two forces moving in the same direction: an unusually large Microsoft Patch Tuesday requiring emergency follow-up fixes, and a run of network and identity infrastructure flaws, Cisco Secure Email Gateway, Cisco Secure FMC, SonicWall SMA1000, Check Point VPN, Citrix NetScaler and JFrog Artifactory, that moved from disclosure to active exploitation within days. CenterPoint Energy confirmed a breach affecting 7.5 million customer records, one of the period’s largest disclosed incidents. OpenAI opened an investigation into whether its own AI agents were connected to a RubyGems supply-chain incident from earlier this year, while separate research showed Anthropic’s Claude used to port a working exploit between two different industrial PLC models. Adobe shipped an emergency fix for an actively exploited maximum-severity Commerce zero-day, and GitLab patched a maximum-severity path traversal flaw that saw in-the-wild probing within hours of disclosure.

The five lead signals

Signal 01 · Critical Infrastructure

CenterPoint Energy confirms a breach affecting 7.5 million customers

A hacker leaked data allegedly stolen from the Texas utility, and CenterPoint confirmed personal information was compromised. The company has not detailed the initial access vector. Utilities hold billing and account data that fuels downstream fraud against the same customer base, making disclosure speed and customer notification as important as the technical response.

Signal 02 · Patch Velocity

Microsoft’s largest Patch Tuesday of the year required emergency follow-up fixes

Microsoft’s monthly release addressed close to 1,000 vulnerabilities, prompting emergency out-of-band fixes days later after some patches introduced their own issues. When a single cycle grows this large, validation and rollback planning matter as much as patch deployment speed.

Signal 03 · Network & Identity Infrastructure

Six separate VPN, firewall and identity platforms saw active exploitation in two weeks

Cisco Secure Email Gateway, Cisco Secure FMC, SonicWall SMA1000, Check Point VPN, Citrix NetScaler and JFrog Artifactory all had flaws actively exploited within this window, several added to CISA KEV. Remote-access and identity infrastructure remains the highest-leverage target class for attackers seeking a foothold.

Signal 04 · AI Accountability

OpenAI investigates its own agents’ possible role in the RubyGems incident

OpenAI confirmed it is examining a report linking its AI agents to suspicious activity at RubyGems that forced a temporary halt to new account registrations earlier this year. Separately, researchers used Claude to port a working exploit between two industrial PLC models. Both point to the same open question: who is accountable when an AI agent’s actions, not a human operator’s, cause the damage.

Signal 05 · Maximum-Severity Enterprise Software

Adobe, GitLab and SAP all shipped maximum-severity fixes this period

Adobe’s emergency StyleSmuggler fix for an actively exploited Commerce zero-day, GitLab’s maximum-severity path traversal patch, and SAP’s critical Extended Passport Processing flaw all landed within the same fortnight. Enterprise platform vendors continue to compress the time organizations have to validate exposure before exploitation begins.

02AI Agents & Development Infrastructure

AI agents and the platforms used to build them featured on both sides of the security ledger this period: as investigated participants in an attack, as tools used to accelerate exploit development, and as continued targets in their own right.

Under InvestigationHighAI Agent Accountability

OpenAI investigates report linking its AI agents to the RubyGems attack

OpenAI confirmed it is looking into a report connecting its AI agents to suspicious activity at RubyGems in May, when maintainers suspended new account registrations in response to what appeared to be malicious automated activity. Nothing is confirmed yet, but the investigation itself signals that AI vendors are being asked to account for what their agents do on infrastructure they were never explicitly authorized to touch. Organizations running agentic AI against package registries or code repositories should log and review agent actions with the same rigor as human administrative access.

Researchers use Claude to port a PLC exploit between vendors

ConfirmedHigh

Forescout’s Vedere Labs used Anthropic’s Claude to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller to a different model, and confirms that AI-assisted exploit adaptation now reaches industrial control systems as well as conventional IT.

Langflow RCE actively exploited to steal credentials and tokens

ConfirmedHighCVE-2026-0768

Threat actors are exploiting an unauthenticated remote code execution flaw in Langflow, an open-source framework for building AI applications, to steal credentials and tokens from exposed instances, continuing a pattern of AI development platforms drawing sustained attacker interest.

Attacker reaches SSH bastion eight seconds after a Marimo notebook RCE

ConfirmedMed-High

Sysdig documented a human attacker moving from a vulnerable Marimo notebook to an SSH bastion host in eight seconds, matching the speed AI tooling has brought to automated exploitation once initial access is gained.

Mass-scanning campaign harvests cloud credentials from exposed Vite servers

ConfirmedMed-High

F5 Labs identified an automated campaign scanning for internet-exposed Vite development servers to steal AWS and Azure credentials, configuration data and infrastructure state files, and exposed development tooling is carrying production-grade consequences.

Black Hat session to reconstruct the OpenAI–Hugging Face incident

ConfirmedMed-High

OpenAI security engineers are set to present a technical reconstruction of the earlier OpenAI–Hugging Face incident at Black Hat USA 2026, covering how frontier models are sandboxed during evaluation and how the attack path exploited a zero-day to gain internet access.

Microsoft commits to AI privacy guardrails for student data

ConfirmedLow

Microsoft agreed to adopt AI privacy standards for schools negotiated with the American Federation of Teachers, a step other AI vendors may be pressed to match.

03Network & VPN Exploitation

Remote-access and network security appliances again produced the period’s fastest disclosure-to-exploitation windows, with six separate platforms confirmed under active attack.

ConfirmedHighCISA KEVCVE-2026-76461

Cisco Secure Email Gateway root RCE zero-day exploited in the wild

Cisco warned that CVE-2026-76461, a CVSS 9.8 flaw stemming from insufficient email-parsing validation, allows an unauthenticated remote attacker to execute arbitrary commands with root privileges, and confirmed active exploitation before a patch was broadly deployed. Email security gateways sit directly in the inbound trust path; a root-level bypass here has enterprise-wide reach.

Cisco Secure FMC exploited by three separate threat clusters

ConfirmedHighCVE-2026-20079

Cisco confirmed that a maximum-severity authentication bypass in Secure Firewall Management Center, originally disclosed in March, is being actively exploited by three distinct threat clusters linked to ransomware and state-sponsored activity, and the flaw has remained a live attack path for six months despite an available patch.

SonicWall patches two SMA1000 zero-days chained for RCE

ConfirmedHighCVE-2026-83548 / 83549

SonicWall disclosed two zero-day flaws in its Secure Mobile Access 1000 series VPN appliances that can be chained for unauthenticated remote code execution, both already exploited in the wild before patches were available.

Check Point warns of imminent VPN exploitation

ConfirmedHighCVE-2026-85102 / 85103

The Dutch NCSC and Check Point both warned of imminent exploitation of two critical Check Point VPN flaws that could be exploited for remote code execution, urging emergency patching ahead of confirmed in-the-wild attacks.

Citrix NetScaler authentication bypass exploited since early September

ConfirmedHighCVE-2026-19490

A critical NetScaler authentication bypass flaw has been exploited in the wild since at least September 3, according to reporting, adding another remote-access platform to the period’s active exploitation list.

JFrog Artifactory authentication bypass exploited days after disclosure

ConfirmedHighCVE-2026-82329

Attackers are exploiting a critical authentication bypass in JFrog Artifactory to create tokens granting administrative access, with watchTowr reporting exploitation began merely days after public disclosure.

CISA adds five flaws to KEV across Artifactory, ScreenConnect and MikroTik

ConfirmedHighCISA KEV

CISA added five actively exploited flaws to KEV in one action spanning JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS, alongside a separate three-flaw batch covering Cisco, Citrix and Fortinet the same week.

04Enterprise Software & Patch Tuesday

Microsoft’s largest patch cycle of the year set the tone, followed by maximum-severity fixes across Adobe, GitLab, SAP and a 12-year-old PostgreSQL flaw finally reaching resolution.

Microsoft’s near-1,000-CVE Patch Tuesday needs emergency follow-ups

ConfirmedHigh

Microsoft’s monthly release addressed close to 1,000 vulnerabilities, one of the largest single cycles on record, and required emergency out-of-band fixes days later after some patches introduced their own issues.

Adobe ships emergency fix for actively exploited Commerce zero-day

ConfirmedHighCVE-2026-75650

Adobe released an emergency out-of-cycle fix for CVE-2026-75650, dubbed StyleSmuggler, a maximum-severity flaw in Adobe Commerce and Magento Open Source allowing unauthenticated arbitrary code execution, already under active exploitation. Adobe also patched over 170 vulnerabilities in its regular cycle.

GitLab patches maximum-severity path traversal probed within hours

ConfirmedHighCVE-2026-85706

GitLab urged immediate patching of CVE-2026-85706, a 10.0 CVSS path traversal flaw affecting both Community and Enterprise editions, after in-the-wild probing began within hours of public disclosure.

SAP patches maximum-severity Extended Passport Processing flaw

ConfirmedHigh

SAP addressed multiple vulnerabilities including a maximum-severity flaw in SAP Extended Passport Processing that could severely impact confidentiality, alongside its regular monthly patch batch.

12-year-old PostgreSQL flaw turns replication access into a persistent backdoor

ConfirmedHighCVE-2026-6471

PostgreSQL patched CVE-2026-6471, dubbed PostGREShell, which allows any account holding the REPLICATION attribute to run arbitrary operating-system code, turning low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.

N-able N-central maximum-severity flaw added to KEV

ConfirmedHighCISA KEV

CISA added a maximum-severity N-able N-central flaw to KEV, continuing a pattern of remote monitoring and management platforms remaining a recurring high-leverage target for attackers seeking access across managed customer environments.

05Supply Chain & Web Platforms

WordPress plugin compromises and a VoIP platform under sustained attack drove the period’s web-facing supply-chain risk, while CenterPoint Energy’s disclosure kept vendor and utility breach exposure in focus.

ConfirmedHighCritical Infrastructure Breach

CenterPoint Energy confirms 7.5 million customer records stolen

CenterPoint Energy confirmed that customer personal information was compromised after an attacker leaked data allegedly stolen from the utility’s systems, with the company not yet detailing the initial access method publicly. Utility-sector breaches at this scale carry downstream fraud risk against the same customer base for years after disclosure.

Malicious plugin update backdoors 1,500 WordPress sites

ConfirmedHigh

Malicious versions of the Admin Menu Editor Pro plugin were distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates creating a hidden administrative user account, ultimately affecting 1,500 WordPress sites.

Sangoma Switchvox unauthenticated SQL injection exploited for RCE

ConfirmedHighCVE-2026-9586

Attackers are actively exploiting an unauthenticated SQL injection flaw in the Sangoma Switchvox enterprise VoIP platform that can lead to remote code execution, with exploitation continuing across multiple reporting windows this period.

Elementor Pro and Super Forms plugins exploited for webshell deployment

ConfirmedHighCVE-2026-32475

Threat actors are exploiting critical flaws in the Elementor Pro and Super Forms WordPress plugins, including an arbitrary file upload issue, to deliver webshell payloads and execute arbitrary commands on compromised sites.

3 million WordPress sites affected by migration plugin SQL injection

ConfirmedMed-HighCVE-2026-19949

A high-severity SQL injection flaw in a widely used WordPress migration plugin, installed on over 3 million sites, could allow unauthenticated attackers to achieve remote code execution.

Japan’s Digital Agency breach traced to a VPN vulnerability

ConfirmedHigh

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people from Japan’s Digital Agency, and VPN infrastructure remains a preferred initial-access route into government systems.

06Critical Infrastructure & OT

Industrial control systems drew both attacker and researcher attention this period, with AI-assisted exploit adaptation reaching PLC environments for the first time in this dataset.

ConfirmedHighAI-Assisted OT Exploitation

Claude used to port a working PLC exploit between vendors

Forescout’s Vedere Labs used Anthropic’s Claude to port a pre-authentication remote code execution exploit from one WAGO programmable logic controller to a different model, demonstrating that AI-assisted exploit adaptation now extends into industrial control environments, where patch cycles are typically slower and exposure windows longer than in conventional IT.

Cisco Nexus 9000 flaw allows unauthenticated root code execution

ConfirmedHigh

Cisco patched a critical flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated remote attacker to execute code as root, alongside additional switch-platform advisories the same week.

CISA ICS advisory flags memory-corruption device crash risk

ConfirmedHigh

A CISA ICS advisory this period warned that successful exploitation of an industrial control protocol flaw could result in memory corruption, a device crash, or a remote attack vector that bypasses standard error-reporting mechanisms.

HPE patches nearly two dozen critical AOS-CX flaws

ConfirmedHighCVE-2026-73749

HPE addressed nearly two dozen issues collectively tracked as CVE-2026-73749, carrying a CVSS score of 9.8, in its AOS-CX networking operating system used across enterprise and industrial network deployments.

PaperCut exploitation escalates from credential theft to active intrusions

ConfirmedHighCISA KEV

CISA added two PaperCut vulnerabilities to KEV as exploitation escalated from credential-theft attacks targeting the education sector to full active intrusions, with print-management infrastructure proving a durable target across sectors.

07Nation-State & Threat Actors

State-linked activity this period spanned dissident surveillance, zero-day exploitation against NGOs, and continued exploitation of a regional broadband provider.

Nation-state & espionage activity

Iran-linked Telegram-controlled malware US, UK and Dutch agencies detailed Windows malware, controlled via Telegram, used by Iran’s intelligence service to spy on dissidents, journalists and activists, capable of copying messages, taking screenshots and activating microphones.

UTA0560 / GRIMWEDGE A China-linked actor exploited recently patched Chrome and Windows zero-days in a spear-phishing campaign delivering the GRIMWEDGE backdoor, targeting multiple NGOs beginning September 1.

BambooToken A multi-platform malware family active since at least 2023 was found using the MQTT protocol to control compromised Windows and Linux systems across Asia and South America.

Criminal activity & regional impact

Thai broadband provider breach A Thai broadband provider was hacked via a Fortinet vulnerability, with attackers staging reconnaissance scripts, CVE-probing tools, brute-force utilities and privilege-escalation tools on compromised infrastructure.

VectraRAT A full-service malware-as-a-service platform offering a Windows implant, command-and-control infrastructure and an operator panel is being sold for $250 per month, lowering the barrier to entry for enterprise-targeted intrusions.

CenterPoint Energy extortion leak A hacker publicly leaked data allegedly stolen from the Texas utility, later confirmed by the company as affecting 7.5 million customer records.

08Signals & Patterns

Five patterns define the first half of September

1

Remote-access infrastructure remains the fastest path to active exploitation Cisco, SonicWall, Check Point, Citrix and JFrog all had flaws reach active exploitation within days of disclosure. These platforms need pre-authorized emergency patch lanes as standard practice.

2

Patch volume is outpacing validation capacity A near-1,000-CVE Patch Tuesday requiring emergency follow-up fixes shows that even vendor-side quality assurance struggles to keep pace with vulnerability discovery volume.

3

AI agent accountability is moving from theory to open investigation OpenAI’s inquiry into its agents’ possible role in the RubyGems incident is the first instance in this dataset of a major AI vendor formally investigating its own product’s connection to an attack on developer infrastructure.

4

AI-assisted exploit adaptation has reached industrial control systems Claude was used to port a working PLC exploit between two different vendor models, extending the AI-accelerated exploitation pattern from IT into OT environments with typically slower patch cycles.

5

Utility and infrastructure providers remain high-value, under-defended targets CenterPoint Energy’s 7.5-million-record breach and Japan’s Digital Agency breach both trace back to infrastructure providers holding sensitive customer data with less mature security operations than comparable financial-sector organizations.

09Defender Actions

Eight actions for the period ahead

01

Build a same-day patch lane for remote-access appliances VPN, firewall and identity-management platforms should trigger emergency patching the moment exploitation or PoC code is confirmed, not on the next change window.

02

Validate large patch batches before broad deployment A near-1,000-CVE cycle needing emergency follow-up fixes shows staged rollout and rollback planning matter as much as patch speed.

03

Audit and log AI agent actions on code repositories and package registries Treat agentic AI access to developer infrastructure with the same review rigor as human administrative access, given open questions about agent accountability.

04

Extend patch urgency to OT and PLC environments AI-assisted exploit porting has reached industrial control systems; review PLC and SCADA patch cycles against this accelerated threat model.

05

Review utility and infrastructure vendor security posture If your organization depends on a utility or infrastructure provider, ask about their breach history and customer-notification timelines directly.

06

Restrict WordPress plugin auto-updates to verified maintainer accounts The Admin Menu Editor Pro compromise shows maintainer-account takeover remains a viable path to mass site compromise.

07

Close exposure on development servers and AI workflow platforms Langflow and exposed Vite servers both saw active credential-theft campaigns; ensure development infrastructure is not internet-facing without authentication.

08

Keep confirmed breach facts separate from leak-site claims CenterPoint Energy’s confirmation followed an attacker leak claim; treat claims and confirmations as distinct until verified, exactly as this briefing does throughout.

10Closing Note

CenterPoint Energy’s breach became public when a hacker leaked the data, not when the company found the intrusion.

That gap, between compromise and discovery, is the same gap Microsoft’s emergency patches and OpenAI’s agent investigation are both responding to. A record volume of fixes needed a second round of fixes. An AI vendor is now checking what its own product did months after the fact.

The response is the same discipline this briefing repeats every edition. Validate patches before deploying them at scale. Know what your AI agents can touch. Ask your infrastructure providers about their breach history and notification timelines directly.

The full technical edition, with severity tags, CVEs and defender actions, is available as a downloadable PDF at wp.me/ag5Z8Q-2So.

About The Signal Watchtower

Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.

Authored by Venkat Mangudi · Founder & CEO, Elytra Security

Integrity. Trust. Clarity.

An ISO/IEC 27001:2022 Certified Company


Discover more from Venkat Mangudi

Subscribe now to keep reading and get access to the full archive.

Continue reading