News Summary:
Avertium is tracking STAC4749, a financially motivated intrusion campaign leveraging Microsoft Teams-based voice phishing (vishing) and IT support impersonation to gain initial access to target environments, which has led to credential theft, unauthorized remote access, and the deployment of Chaos ransomware across multiple industries. Earlier, on August 10, 2026, a coordinated cyberattack was reported to have targeted operational technology (OT) at water utilities across at least seven states, disrupting over 30 Minnesota community water systems on July 26–27, 2026. The FBI and EPA stated attackers specifically targeted internet-facing Rockwell Automation MicroLogix 1100/1400 programmable logic controllers (PLCs) by modifying their IP addresses and passwords. Previously, on August 5, 2026, the company discussed the CMMC Phase II suspension, clarifying for defense contractors that cybersecurity requirements, including CMMC compliance, CUI protection, and NIST SP 800-171 readiness, remain despite the uncertainty it created within the Defense Industrial Base (DIB). On July 30, 2026, Avertium achieved Elite status in the SentinelOne MSSP Partner Program, enhancing its ability to deliver managed security services through SentinelOne’s Singularity Platform, Purple AI, and Cloud Security.