news.mlab.sh
Back to the feed
threat-intel

This month in security with Tony Anscombe – May 2026 edition

Medium
Summary

In May 2026, Poland experienced cyberattacks targeting industrial control systems at water treatment facilities, mirroring attacks against the Polish energy sector. Simultaneously, a previously unknown group conducted a sophisticated AI-driven attack against Mexico, while Google discovered a novel AI-developed zero-day exploit. Cryptocurrency scams continued to be a major problem, with Americans losing millions to crypto kiosks.

In May 2026, cybersecurity expert Tony Anscombe highlighted several significant security events in his monthly roundup. Poland’s Internal Security Agency (ABW) revealed that cyberattacks targeting industrial control systems (ICS) at five water treatment facilities occurred between 2024 and 2025. These attacks utilized weak passwords and direct internet exposure – tactics similar to those employed against the Polish energy sector, which were previously attributed to the DynoWiper malware, identified by ESET researchers.

Furthermore, a previously unknown group successfully exfiltrated substantial data from the Mexican government, marking what is considered one of the world’s first truly AI-directed attacks. Despite this initial success, a subsequent attempt to exploit vulnerabilities within a water utility plant failed to transition from IT systems to operational technology (OT) systems.

Google researchers have identified a novel zero-day exploit developed using artificial intelligence, representing a significant advancement in attack techniques. Finally, the FBI reported that Americans lost over $388 million in 2025 to scams utilizing cryptocurrency kiosks. These scams often involve deceptive interfaces and pressure tactics to encourage users to invest in fraudulent digital assets.

Read the full article at WeLiveSecurity