Water Utilities Hit in a Dozen States, an npm Worm Keeps Spreading, and Arctic Wolf Doubles Down on Agentic SOC
A look at the last 24-48 hours in cybersecurity: critical infrastructure under pressure, a supply-chain worm widening its reach through the npm ecosystem, and a wave of MDR industry moves led by Arctic Wolf.
Water utilities in at least a dozen U.S. states have reported disruptions in recent days, according to SecurityWeek, with Georgia among the confirmed states after Clayton County reported an outage at a pump station. Details on the scope and method of the intrusions remain limited, but the pattern points to coordinated targeting of water-sector operational technology rather than an isolated incident.
For utilities, that distinction matters. A disrupted pump station is disruptive on its own, but incidents like these typically signal something broader: gaps in segmentation between business IT and plant-floor OT networks, and the possibility that an attacker retains access well beyond whatever was initially detected. Security teams at affected utilities are being urged to treat this as evidence of active, multi-state targeting of critical infrastructure rather than a contained event, and to prioritize isolating affected control systems and hunting for lateral movement rather than simply cleaning up the immediate disruption.
On the software supply chain side, a credential-stealing worm that first surfaced in the Keyv and Cacheable npm namespaces has continued to spread. By August 4, researchers at SafeDep had verified 353 poisoned package versions across 79 package names, while separate monitoring from Aikido put the broader footprint at more than 800 affected packages. The worm is designed to propagate automatically through the npm ecosystem and has reportedly been found planting hooks targeting developer tools, including Claude Code and VS Code, raising the stakes for engineering teams who pull in transitive dependencies without close scrutiny. Organizations with any exposure to the affected namespaces are being advised to audit lockfiles, purge and rebuild any artifacts built from poisoned versions, and treat developer credential rotation as a serious option rather than a last resort.
Two more items are worth a SOC's attention this week. cPanel shipped a targeted security release patching a critical flaw, tracked as CVE-2026-58048 with a CVSS score of 9.4, that let an authenticated hosting customer execute SQL with database-root privileges — a serious problem for any shared hosting environment where tenant isolation is load-bearing. Separately, the commercial phishing-as-a-service kit Greatness has added support for device-code phishing, a technique that abuses the legitimate OAuth 2.0 device authorization flow to sidestep multi-factor authentication and hijack sessions on Microsoft 365 and Google Workspace tenants. Both are reminders that patch cadence and MFA alone are no longer sufficient controls on their own.
On the vendor side, Black Hat USA 2026 wrapped up in Las Vegas this week, and Arctic Wolf was among the MDR players with the most to announce. The company introduced a new Cyber Resilience offering that pairs its existing security operations coverage with an incident-response service — Aurora IR360 — and up to $3 million in warranty coverage, positioning it as a single package spanning prevention, response, and financial backstop rather than three separate purchases. Arctic Wolf also announced new milestones for its Aurora Agentic SOC and Aurora Superintelligence Platform, aimed at making agentic security operations viable for organizations that don't want to build the equivalent in-house, and launched a Cyber AI Readiness Accelerator partner program that pairs its Aurora Attack Surface Management product with partner-delivered consulting and remediation services. The company also picked up a 2026 CRN Tech Innovator Award for its Aurora Endpoint Security product.
The announcements arrive alongside Arctic Wolf's 2026 AI & Cybersecurity Trends Report, which found that 63% of organizations experienced a significant cybersecurity incident in the past year, with nearly half of those affected reporting productivity disruptions lasting two weeks or longer. Those numbers track closely with what's playing out in this week's news: water utilities losing control of physical infrastructure, a worm working its way through the software supply chain largely unnoticed until it wasn't, and a critical privilege-escalation bug sitting in hosting infrastructure millions of websites depend on. For SOC and MDR teams, the takeaway is consistent with recent weeks: assume the perimeter has already been probed, and prioritize detection and segmentation over prevention alone.
- SecurityWeek — Water Sector Cyberattacks Reportedly Hit at Least 12 States
- The Hacker News — Keyv-Linked npm Worm Poisons Hundreds of Packages
- The Hacker News — New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- The Hacker News — Greatness PhaaS Adds Device Code Phishing to Bypass MFA
- Arctic Wolf — Press Releases
