Weekly Wire #4: Justice and Negligence
This week brought two long-delayed reckonings for major cybercrime figures: Connor Moucka pleaded guilty for the Snowflake extortion spree, and Maksim Silnikau was sentenced to 16 years for running Ransom Cartel. Both cases took years to reach resolution, and both arrived during a week when Forescout researchers found over 4,000 industrial controllers still sitting naked on the public internet, many of them in the same cities recently hit by water-system attacks. There is a quiet absurdity in watching justice catch up with individual operators while the conditions that made their attacks possible remain stubbornly unchanged. The same week also gave us a new Spectre-class CPU attack that bypasses years of mitigations, a reminder that some classes of vulnerability are simply never fully closed: they are managed, mitigated, and occasionally rediscovered by someone with enough patience.

In brief
- Connor Moucka pleaded guilty for his role in the 2024 Snowflake data-theft campaign that extorted 165 organizations, while Belarusian Maksim Silnikau received 16 years for creating and operating the Ransom Cartel ransomware strain.
- Forescout found 4,400 Rockwell/Allen-Bradley industrial controllers exposed online, including 22 in cities recently targeted by water-system attacks, despite years of federal guidance.
- A new CPU side-channel attack dubbed TONTOU bypasses Spectre v2 mitigations and was demonstrated leaking Linux password hashes.
- Researchers linked TeamPCP’s supply-chain attacks back to 2020, far earlier than previously known, with evidence of AI-assisted payload evolution.
- Italian defense legislation introduced a formal military cyber domain (spazio cibernetico militare), establishing a new Cyber Intel Command within the armed forces.
- Threat actors breached TrueConf’s update infrastructure to trojanize client installers with backdoors, and a Metabase SQLi zero-day was exploited for customer data theft.
Digital forensics & DFIR
- An analysis of incidents at Brazilian educational institutions — Kaspersky’s GERT team delivered a thorough postmortem on IR cases at Brazilian schools and universities. The standout detail is forensic: even when attackers wiped system logs, Prefetch files and Amcache.hve still preserved execution timestamps and SHA-1 hashes. Useful if you are working cases where the attacker remembered to clean up but forgot that Windows never really forgets.
- A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide — Researcher Vangelis Stykas maintained access to DPRK-operated servers for nearly two years, mapping intrusions across the globe. The forensic value here is not just the scale of compromise but the window into how these operators organize their infrastructure: the same servers, tools, and patterns repeating across hundreds of victims.
Threat intelligence & APT
- Canadian Man Pleads Guilty in Snowflake Extortions — Krebs on Security reconstructs the full arc of Connor Moucka’s guilty plea, including his connections to co-conspirators Cameron Wagenius (the U.S. Army soldier who pleaded guilty in 2025) and John Binns (who recently obtained Turkish citizenship, making extradition unlikely). The detail about Moucka re-extorting a victim using a government official’s stolen family data is the kind of predatory escalation that separates this case from garden-variety ransomware.
- Hackers breach TrueConf to trojanize client installers with backdoors — The Head Mare hacktivist group exploited vulnerabilities in unpatched TrueConf servers to replace legitimate client installers with weaponized versions. Supply-chain compromises via videoconferencing software are not new, but the targeting of Russian-developed TrueConf suggests this is hacktivism with a geographic agenda rather than financially motivated crime.
- ClickFix attack pushes macOS infostealer for crypto theft attacks — A Go-based malware delivered via ClickFix social engineering targets macOS users specifically for cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. The macOS threat landscape has been catching up to Windows for years, and the combination of infostealer capabilities with Keychain access is a reminder that Apple’s walled garden has gates that users can be tricked into opening.
- Open-source software’s archenemy TeamPCP goes back further than anyone thought — Oligo Security traced TeamPCP’s infrastructure back to campaigns from 2020, including a ShadowRay exploitation chain that produced the first self-propagating botnet running on hijacked AI infrastructure. The finding that this actor operated for years under multiple aliases before branding itself publicly in late 2025 is less an attribution breakthrough than a sobering reminder of how long threat actors can operate before the industry gives them a name.
Privacy & surveillance
- ICE Is Buying Access to Credit Card Records — Schneier highlights reporting that ICE is purchasing credit header data through commercial brokers, which includes names, addresses, and other information provided when opening a credit card. The mechanism is legal, and that is precisely the problem: what you disclose to a bank for a credit application is now apparently fair game for immigration enforcement.
- Apple WebKit vulnerabilities reveal your IP address, despite Private Relay — Three separate WebKit mechanisms (DNS prefetching, WebAuthn/passkeys, and WebTransport) bypass iCloud Private Relay and expose the user’s real IP address. The researchers expect patches by fall, but the architectural problem is worth noting: Private Relay operates at the WebKit proxy level, not the system level, so anything that runs outside the standard page-loading path simply ignores it.
Policy & legislation
- Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online — Forescout’s Vedere Labs scanned Shodan and found 2,844 exposed Rockwell/Allen-Bradley controllers in the U.S. alone, with 22 in cities recently targeted by water-system attacks. Nineteen of those 22 had firmware versions vulnerable to a 2017 RCE flaw. The advisory says “remove them from the internet.” The scan says they are still there. The gap between those two statements is where the next incident will happen.
- Ransom Cartel ransomware creator sentenced to 16 years in prison — Belarusian national Maksim Silnikau ran Ransom Cartel from 2021 to 2023, extorting at least $5.2 million from 18 companies. He fled Spain while awaiting extradition and was caught in Poland trying to return to Belarus. Between this and the Snowflake guilty plea, it has been a rare week where some of the people behind major cybercrime operations actually faced concrete consequences.
- DDL Difesa: nasce lo spazio cibernetico militare, cosa cambia per le aziende — The Italian Council of Ministers approved defense legislation creating a formal military cyber domain, including a new Cyber Intel Command and cyber-specific military specialist roles. ACN and DIS remain unchanged, so the civilian cyber apparatus stays separate. The timing is interesting: Italy is building out military cyber structures just as NIS2 compliance deadlines approach for the private sector, creating a parallel architecture that may generate friction as much as coordination.
Tools & research
- New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes — Researchers demonstrated a speculative execution attack that sidesteps recent Spectre v2 mitigations and successfully leaks secrets from Linux machines. The fact that this class of vulnerability is still yielding new bypasses eight years after the original Spectre disclosure should not surprise anyone, but the practical demonstration of password hash exfiltration makes the risk concrete rather than theoretical.
- Metabase SQLi zero-day exploited in customer data-theft attacks — A critical SQL injection vulnerability in Metabase was exploited as a zero-day to breach customer instances, with Framework and Tally among the confirmed victims. The practical takeaway is not about Metabase specifically: it is that analytics platforms sitting on top of production databases are an increasingly attractive target, because compromising them gives you the data without having to touch the database server directly.
- July 2026 CVE Landscape — Recorded Future identified 85 high-impact vulnerabilities exploited in July, a 44% increase from June. The most commonly exploited weakness classes remain OS command injection and unrestricted file upload, which says something about where defenders should be spending their patching energy. Fourteen of the 85 exploited CVEs are at least five years old, with the oldest dating to 2008.
The pick of the week is the Krebs on Security piece on Connor Moucka’s guilty plea, not because the outcome is surprising, but because Krebs reconstructs the full network of co-conspirators and their divergent fates in a way that reads like the closing chapter of a story that is still being written. Two of the three alleged conspirators have now pleaded guilty; the third is a Turkish citizen who cannot be extradited. Justice, it turns out, is as jurisdictional as the internet itself. Next week, watch for further fallout from the water-system attacks as attribution firms up and the scope of affected utilities continues to expand.
FAQ
Why are U.S. water systems still vulnerable to cyberattacks in 2026?
Most of the roughly 50,000 U.S. community water systems are small and publicly funded, with cybersecurity far below water safety in priority. PLCs often sit internet-exposed for years because operators are unaware or lack resources to segment them, and cybersecurity rules for the water sector remain mostly voluntary despite repeated FBI and EPA warnings.
What are the most important cybersecurity events of the week of August 2?
Connor Moucka pleaded guilty to the 2024 Snowflake customer data extortion spree; Belarusian national Maksim Silnikau was sentenced to 16 years for creating Ransom Cartel; Forescout found over 4,000 internet-exposed industrial controllers in the U.S.; a new TONTOU CPU attack bypassed Spectre v2 mitigations to leak Linux password hashes; and Italian defense legislation introduced a formal military cyber domain.
How are articles selected for the Weekly Wire?
Articles are curated from a fixed set of RSS feeds weighted by source reliability and relevance to DFIR, threat intelligence, privacy, policy, and security research. Vendor marketing and press releases are discarded.