Threat Intelligence

Weekly Threat Roundup: Massive IoT Botnet, Water System Attacks, and Fake Software Traps SMBs Should Know About

The Hacker News · 28 Aug 2026
Key Takeaway Train staff to spot fake logins and apps, and patch internet-facing systems promptly, since attackers are exploiting both human trust and technical gaps.

A new round-up of cybersecurity incidents shows attackers continuing to rely on deception as a primary entry point into business systems. Fake login pages, counterfeit security scanning tools, and imitation productivity apps were all used this week to trick users into handing over access or installing malicious software. These simple social engineering tactics remain effective precisely because they look legitimate at first glance.

Beyond these scams, researchers flagged more advanced threats, including a botnet of roughly 296,000 IoT devices, attacks targeting more than 100 water utility systems, and an exploit chain affecting Microsoft SharePoint. Other reported activity included botnets using AI techniques, malicious tools that delay revealing harmful behaviour to avoid detection, command-and-control traffic hidden within legitimate public infrastructure, and attackers scanning the internet for exposed systems. Overall, the report points to a shrinking window between when vulnerabilities are discovered and when they're actively exploited.

For small and medium businesses, this mix of low-tech scams and high-tech infrastructure attacks is a reminder that cybersecurity risks come in many forms — from a single employee clicking a fake login page to internet-connected devices being silently recruited into a botnet. Staying informed and applying updates quickly remains one of the most effective defences.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.