Franklin project adds new security providers, employs digital twins and AI

At the annual DEF CON hacker conference, the DEF CON Franklin project and the National Rural Water Association (NRWA) announced a new initiative called the Water Watch Center. This program aims to enhance the cybersecurity of small rural water utilities across the United States, particularly those serving fewer than 10,000 people. The initiative expands on previous volunteer efforts by integrating managed detection and response (MDR) providers, digital twins, and artificial intelligence (AI) agents.
The Water Watch Center will initially fund five security providers: Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies. These providers will assist small water utilities in detecting and mitigating cyber breaches. A key component of the program involves these security providers exchanging threat intelligence and sharing it with the NRWA, which offers technical assistance and operational support to water and wastewater utilities nationwide.
Jake Braun, co-founder of the DEF CON Franklin project, highlighted the need for a scalable cybersecurity delivery mechanism for the approximately 150,000 small water utilities, 98 percent of which operate as small businesses. He noted that while volunteers have been working in the field for two years, the sheer number of utilities necessitates a more structured approach, similar to how managed security service providers (MSSPs) serve small businesses.
Braun described the Water Watch Center as a tiered system. The NRWA sits at the top, overseeing the program. Below that, the MDR providers will deploy sensors to monitor utility networks for vulnerabilities. Franklin project volunteers will then assist in fixing identified issues or responding to alerts. The program plans to expand from an initial five MSSPs to ten, aligning with the ten CISA regions, and will leverage volunteers to connect utilities with MSSPs and deliver cybersecurity solutions based on alerts from CISA and ISACs.
The initiative also addresses the growing threat of AI-powered cyberattacks. The Water Watch Center has partnered with Vanderbilt University to apply research from the DARPA Cyber Agents for Security Testing and Learning Environment (CASTLE) program. This collaboration will involve creating digital twins of selected water and wastewater systems. Researchers will then deploy both red-team (attack) and blue-team (defense) AI agents within these digital replicas.
The red-team agents will attempt to breach the simulated water systems, testing the automated detection and response capabilities of the blue-team defenders. The ultimate goal is to train AI-based defense agents that can eventually be deployed to water and wastewater facilities across the U.S. Braun emphasized that with a significant shortage of cybersecurity professionals, AI-driven defenses are crucial for combating future AI attacks.
Recent weeks have seen suspected Iranian hackers target numerous water systems, predominantly small community systems, by exploiting programmable logic controllers (PLCs) exposed directly to the internet with default or weak passwords. While there is no current indication that these attackers used AI, experts anticipate this will become a factor in future cyber disruptions. The Water Watch Center's AI initiatives are designed to proactively address this evolving threat landscape.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets