Threat Brief — 2026-08-06 — Russian Net Wobbles, PLCs Still Naked
Executive summary: A massive outage is destabilising major Russian internet services including Ozon, Telegram, and banking platforms, with thousands of complaints filed within an hour. Forescout has published fresh scan data showing 4,407 exposed Rockwell PLCs online — 22 located in US cities recently hit by water-utility cyberattacks. A new deep-dive into LD_PRELOAD-based persistence techniques revives attention to a classic but underappreciated Linux rootkit vector.
Top items
- Massive outage hits Russian internet services. Ozon, Telegram, and dozens of Russian services are experiencing widespread instability, with thousands of user complaints logged within a single hour. The scope — spanning marketplaces, banks, and messaging — suggests infrastructure-level disruption rather than isolated provider issues. Root cause not yet attributed. (src: SecurityLab.ru)
- 4,400+ Rockwell PLCs exposed online; 22 in water-utility attack cities — new scan data. Forescout's August 3 scan identified 4,407 internet-facing Rockwell Automation PLCs. Critically, 22 are located in cities hit by recent US water-utility cyberattacks, and 19 of those share the same mobile carrier network — suggesting a common attack vector. This is a genuine development in the ongoing water-utility PLC story first reported 2026-07-31 by BleepingComputer. (src: The Hacker News) — (first reported: BleepingComputer)
- LD_PRELOAD persistence techniques detailed — from function interception to BEURK rootkit. An in-depth technical analysis covers how attackers use LD_PRELOAD to intercept libc functions, hide processes, files, and network connections, and establish persistent rootkit-level access on compromised Linux hosts. The BEURK rootkit is highlighted as a practical implementation. Relevant for incident-response teams that rely on standard tools (ls, ps, netstat) which can be fully subverted. (src: Xakep)
- AI exposed a long-ignorable browser security gap for enterprises. Skyhigh Security analysis argues that AI adoption has surfaced a pre-existing enterprise blind spot: browsers are now the primary control point for data movement and AI interactions, yet most organisations lack adequate browser-layer data governance. Not a new vulnerability, but a forcing function for reassessing browser security posture. (src: BleepingComputer)
Themes
OT exposure remains a live crisis. The Forescout scan quantifies what CISA warned about five days ago: thousands of PLCs are still internet-facing, and attackers are actively exploiting that exposure in the water sector. The shared mobile carrier detail hints at a repeatable attack chain that defenders should prioritise hunting for.
Classic Linux persistence gets fresh attention. The LD_PRELOAD deep-dive is a reminder that commodity rootkit techniques remain effective against default Linux tooling — relevant as attackers increasingly target infrastructure and cloud-hosted Linux systems.
===
