Water-system attacks widen into Michigan as OT campaign crosses state…EU AI Act transparency enforcement begins, shifting AI inventory…OpenAI–Hugging Face incident makes AI evaluation containment…Actively exploited SharePoint flaw demands compromise evidence…
Monday flagship · Weekend decision brief
Water-system attacks widen into Michigan as OT campaign crosses state lines over the weekend
Michigan disclosed attacks affecting nine water systems on Saturday after more than 30 Minnesota systems reported malicious operational-technology activity, moving the decision from local incident response to multi-state exposure validation.
Security.io Intelligence Desk · Monday, 3 August 2026
Executive consequence
Saturday’s Michigan disclosure changed the risk picture from a Minnesota cluster into a multi-state operational-technology event.
Decision today
Inventory internet-reachable PLCs, HMIs, engineering workstations and cellular modems.
Read the full decision briefPrimary reporting: FBI, CISA, NSA, EPA, DOE and US Cyber Command Joint Cybersecurity Advisory AA26-097A · Michigan Department of Environment, Great Lakes, and Energy · American Hospital Association summary of updated AA26-097A · Associated Press
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
The majority of applicable EU AI Act rules entered enforcement on Sunday, including Article 50 transparency duties. Security leaders need evidence that AI systems, synthetic-content paths and machine interactions are inventoried, owned and technically capable of meeting approved disclosure controls.
Do today
Identify AI systems subject to Article 50 transparency duties.
The Friday extortion deadline sharpened an already disclosed third-party incident, but public evidence still does not identify the service provider, affected population or complete data scope. Customers should demand scoped assurance rather than relying on EY’s remediation statement alone.
Do today
Identify data submitted through EY support and tax workflows.
CISA records active exploitation of CVE-2026-50522, an unauthenticated SharePoint Server remote-code-execution flaw. Monday closure must combine verified build state, exposure history, credential protection and forensic review rather than recording a completed update alone.
Do today
Find every on-premises SharePoint Server instance and owner.
Scores from 0–100 reflect Security.io’s editorial assessment of the selected edition across reachable exposure, required decision speed and plausible operational consequence. They are comparative decision aids, not external incident metrics. Source: Security.io editorial scoring based on selected primary and corroborating sources.
Back page
Daily comic · Circuit Chuckles
A brief pause after the intelligence
Cloud Support
Rusty treats cloud operations as literal weather support while Glitch questions the job description.