AA26-097A
On April 7, 2026, six U.S. federal cyber agencies co-signed Joint Cybersecurity Advisory AA26-097A. The agencies: the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, the National Security Agency, the Environmental Protection Agency, the Department of Energy, and U.S. Cyber Command. The advisory attributes active disruption of internet-facing Rockwell Automation programmable logic controllers at U.S. water, wastewater, and energy facilities to the Islamic Revolutionary Guard Corps Cyber-Electronic Command's "CyberAv3ngers" cluster.
The advisory explicitly confirms operational disruption and financial loss at named victims. The advisory's structural significance is the EPA inclusion as a co-signer. EPA's water-sector cybersecurity authority has been contested since the 2023 court vacatur of EPA's water-utility cyber rule. The April 7 joint advisory is the most authoritative single document the federal government has published on water-sector cybersecurity since that vacatur.
The "CyberAv3ngers" cluster has been previously attributed by Mandiant and CrowdStrike to the IRGC's Cyber-Electronic Command. Their toolset, per the advisory, includes default-credentials-and-exposed-internet-PLC reconnaissance and the "IOControl" botnet for establishing persistent access on industrial endpoints.
The campaign predates the February 28, 2026 Israel-U.S. strikes on Iran, but has substantially intensified since. Federal-level attribution at the EPA-co-signed level signals the campaign has reached a threshold of impact — operational disruption and financial loss at named victims — that the federal cyber-defense community considers necessary to attribute publicly.
Sixteen hours
On March 14, 2026, the City of Minot, North Dakota suffered SCADA-layer ransomware at its municipal water treatment plant. The compromise reached the supervisory control and data acquisition layer — the operational layer where setpoints, alarms, and process logic live — not just the corporate IT layer.
The water utility ran for sixteen hours on manual operations while engineers restored SCADA. Approximately eighty thousand residents were affected. Manual operations meant valves opened and closed by hand on the operator's instruction; chemical addition controlled by analog meters and the operator's eye; pump activation toggled by physical switch. The utility's drinking-water output remained safe throughout the manual-operation window because operators are trained on manual procedures, even if the digital layer is unavailable.
The architectural lesson is structural. The resilience of a 100,000-person water utility comes from operators who can run manual procedures when the digital layer is unavailable, not from any specific IT or OT system being unhackable. The user-side response: maintain manual fallback procedures; train operators on them; periodically exercise; segment IT from OT; data-diode telemetry where bidirectional access is unnecessary.
110 million meters
On April 13 and 27, 2026, Itron — one of three dominant smart-meter vendors for North American electricity, gas, and water utilities — disclosed two breaches affecting more than 110 million utility meters globally.
Itron meters report consumption telemetry to utility billing and load-management systems. Many Itron meters also include disconnect-relay control, allowing remote utility-driven service disconnection. A breach at the meter-vendor level — that is, at the layer above any specific utility's perimeter — reaches every utility customer who uses that vendor's meter.
The architectural lesson: the smart-meter ecosystem has a vendor-aggregator layer (the meter manufacturer), and that layer is a single perimeter for cross-utility data and cross-utility control. Per Itron's disclosure, the breaches did not result in mass-disconnect activation, but the cross-utility data exposure is permanent.
The user-side response: privacy-preserving telemetry aggregation (differential privacy at the meter level — research-grade implementations exist); customer right-to-disable disconnect-relay (where statutorily permitted); local opt-out from advanced metering infrastructure where regulator policy allows.
139 gigabytes
On April 27, 2026, Pickett USA — a U.S. engineering services firm specializing in utility-side LiDAR and substation engineering — disclosed a 139-gigabyte exfiltration. The data covers Tampa Electric, Duke Energy Florida, and American Electric Power. Three of the largest investor-owned utilities in the eastern United States.
LiDAR and substation engineering data are not consumer-facing. They describe the physical layout, equipment placement, conduit routing, switchgear configuration, and protection-and-control settings of high-voltage substations — the technical specification that an attacker would need to plan precision attacks against the grid's physical assets.
Once exfiltrated, the data is permanent. There is no recall.
The architectural lesson: the engineering-services tier is a vendor-aggregator layer for grid-physical-design data across multiple utilities. The user-side and utility-side response: minimize external sharing of full grid-physical-design data; segment design data by least-privilege; physical-design data should not be aggregable across utilities.
Heathrow down
On April 4, 2026, a Collins Aerospace software outage took down Heathrow, Brussels, and Berlin airports. Airline operations were impacted across Europe; Heathrow alone moves approximately 220,000 passengers daily.
Collins Aerospace operates the ARINC airline-passenger-handling software stack used by approximately one third of European airline carriers and dozens of European airports. A software failure at Collins reaches every airport using ARINC simultaneously — a single-point-of-failure software-as-a-service architecture for airline operations.
The architectural lesson: the European airline operations layer has consolidated onto a small number of operations-software vendors, and a software failure at any one of them propagates instantly across multiple sovereign nations' airports. The April 4 outage was not adversarial — it was a software-deployment fault — but the same architectural surface is reachable to adversarial action.
The user-side response is policy-level: airport authorities should mandate vendor diversity for operations software; carriers should maintain manual-passenger-handling fallback procedures; regulators should treat operations-software vendors as critical infrastructure under the EU NIS2 directive and equivalent national regimes.
Sweden's thermal plant
On April 15, 2026, Sweden publicly attributed a destructive thermal-plant intrusion attempt to Russian intelligence. The Swedish Security Service (Säkerhetspolisen) and the Swedish Civil Contingencies Agency (MSB) issued a joint statement. The attack targeted a regional thermal generation facility supplying district heating during late winter.
Sweden's public attribution to Russian intelligence is structurally significant. Public attribution has historically been reserved for the most serious incidents because attribution itself is a diplomatic action. The April 15 statement places Sweden's Russia attribution in the same category as Estonia's 2007, Germany's 2015, and the United States' 2018 public Russia-attribution moments.
The Dragos 2026 Year in Review identifies three new threat groups operating in the OT/ICS space: SYLVANITE, AZURITE, PYROXENE. Dragos warns of "control-loop mapping" — adversary characterization of OT physical processes for precision sabotage. Industrial-organization ransomware is up forty-nine percent year-over-year.
Without a leader
In April 2026, Sean Plankey, the Trump administration's nominee for Director of the Cybersecurity and Infrastructure Security Agency, withdrew his nomination amid Senate confirmation uncertainty. CISA — the federal cyber-defense agency designated as the U.S. national coordinator for critical infrastructure cybersecurity — is operating without a confirmed director during the most acute critical-infrastructure cybersecurity cycle in decades.
The IRGC PLC campaign (AA26-097A April 7); the Itron 110-million-meter breach (April 13, 27); the Pickett USA grid engineering exfiltration (April 27); the Collins Aerospace airline outage (April 4); Sweden's Russia thermal plant attribution (April 15); the City of Minot North Dakota water plant ransomware (March 14); Dragos's 49% YoY industrial-ransomware metric — all are concurrent. Regulator capacity is itself a layer of the dependency stack. When the regulator has no confirmed leader, regulator-side coordination of incident response, threat-intelligence dissemination, and resource allocation is impaired.
The user-side response is policy-level: the Senate should expedite a CISA-director confirmation; the executive branch should appoint a serving career official to act in confirmed-equivalent capacity in the interim.
Anodot
Today, May 5, 2026, the ShinyHunters wave reframes from "Salesforce intrusion" to "third-party SaaS supply chain." Vimeo's 119,000-record dump originated through Anodot — a SaaS analytics integration vendor — not a direct Vimeo intrusion. Concurrently, ShinyHunters drip-released data from Carnival, Mytheresa, Zara, 7-Eleven, Pitney Bowes, and Canada Life.
The pattern, observed today: a single third-party SaaS analytics integration becomes the vector to many customers' data. Salesforce was the carrier-of-trust SaaS aggregator covered in yesterday's edition. Anodot is the third-party-SaaS-of-Salesforce aggregator. The architectural pattern compounds: a Salesforce integration breach reaches every customer of every Salesforce customer using that integration.
The user-side response: third-party SaaS integration audit (which integrations have access to which Salesforce objects? minimum-necessary scope?); per-organization integration segmentation; alternatives to vendor-aggregating analytics platforms (self-hosted Mautic, Listmonk, Plausible Analytics, Matomo, Metabase).
Cushman & Wakefield issued its official statement today, calling the intrusion "limited" and confirming vishing as the vector. Instructure remains silent on the May 6 deadline.
The Friedman NSO
In January 2026, NSO Group came under U.S. investor control. The acquiring group, led by Robert Simonds, named former Trump ambassador to Israel David Friedman as executive chairman. The January 2026 transparency report was stripped of customer-termination figures that had appeared in prior years' reports. NSO is openly lobbying for U.S. Entity-List delisting.
In October 2025, U.S. District Judge Phyllis Hamilton reduced the WhatsApp punitive-damages award against NSO from $167.2 million to approximately $4 million. The case is now in Ninth Circuit appellate posture. The 40-fold reduction substantially diminishes the legal-system price assigned to commercial spyware abuse — the price that the Oakland verdict in spring 2026 had elevated.
In December 2025, the U.S. Treasury quietly delisted three Intellexa Specially Designated Nationals. The delisting reduces the financial-system pressure on the Intellexa cluster.
The architectural significance: the commercial spyware vendor that operated against E2EE messaging at scale is now under U.S. ownership aligned with the executive branch, with the legal-system price for abuse reduced, while previously-listed Intellexa SDNs were quietly delisted. The architectural counter: open-firmware mobile devices (GrapheneOS Lockdown Mode equivalent), continuous Citizen Lab and Amnesty International forensic monitoring, Freedom of Information Act litigation against U.S. agency spyware acquisition, and political pressure to maintain Entity-List sanctions and Treasury SDN designations.
The Athens conviction
On February 26, 2026, an Athens criminal court convicted Tal Dilian — Israeli former IDF intelligence officer and founder of Intellexa — and three additional Intellexa executives for the unlawful interception of Greek civil-society and journalist communications using the company's "Predator" spyware. The conviction is the first criminal conviction of commercial spyware vendor executives anywhere.
The Greek prosecution arose from the 2022 "Predatorgate" scandal in which approximately 100 individuals — journalists, activists, lawyers, and a senior Greek official — were targeted with Intellexa-supplied spyware.
The architectural significance: until February 26, 2026, no jurisdiction had successfully prosecuted commercial spyware vendor executives for the consequences of their product's deployment. The Athens precedent establishes that — at least in Greek jurisdiction — the spyware-vendor industry's "we just sell the product, the customer abuses it" defense does not survive criminal prosecution.
The $2 million contract
Paragon Solutions — sold to AE Industrial Partners for approximately $900 million before final Israeli DECA approval — is now operationally embedded inside U.S. Immigration and Customs Enforcement under a reactivated $2 million contract. ICE acting director Todd Lyons confirmed the deployment in House Homeland Security Committee testimony May 1, 2026. Senator Ron Wyden led 30 lawmakers in an oversight letter on April 24, 2026.
Concurrently, Paragon is openly stonewalling Italian prosecutors investigating the Cancellato / Fanpage hack. The Italian prosecution's first move was to request Paragon's full customer-list disclosure; Paragon's response, per public reporting, was non-cooperation.
The architectural significance: federal agency acquisition of commercial spyware is now publicly confirmed at a specific contract amount and a specific cabinet department, with no public oversight statute applicable to the acquisition or deployment, and no notification-of-target requirement.
Bad Connection — invisible to MVT
Citizen Lab researchers Gary Miller and Swantje Lange's April 23, 2026 "Bad Connection" report — covered in edition 03 — has a structurally significant additional finding: SS7 / Diameter "ghost operator" surveillance is invisible to Mobile Verification Toolkit (MVT), iVerify, and Lookout — the three commercial / open-source forensic detection products that civil society relies on to confirm device compromise.
The user cannot prove they are being SS7-tracked from the device side. The architectural significance: a commercial spyware ecosystem that has migrated to a vector forensic tooling cannot detect leaves users with no architectural recourse at the device layer.
The user-side response shifts to the network layer: FIDO2 hardware authentication that survives SIM compromise; carrier-side SS7/Diameter security audit by GSMA mandate (recently strengthened); regulator-mandated disclosure of carrier inter-operator routing relationships.
518 dead
On April 23, 2026, a Tanzanian commission of inquiry confirmed 518 dead and 2,390 injured in post-October-2025-election violence. The violence was conducted under a five-day complete internet blackout.
Access Now's KeepItOn coalition documented 5,448 hours of Tanzania internet shutdowns in 2025 — $889.8 million in 2025 economic loss, Africa's worst.
The architectural significance: the internet shutdown is not merely an information-control mechanism; it is a state-violence enabler. When citizens cannot communicate, organize, or document state violence in real time, the state's accounting of its own violence becomes the only source. The Tanzanian commission's confirmation of 518 deaths only after the shutdown lifted demonstrates the principle.
The same pattern appeared on March 15, 2026, when the Republic of the Congo (Brazzaville) imposed a nation-scale election-day internet blackout. NetBlocks measured connectivity at approximately 3% of normal baseline. The result: Denis Sassou Nguesso's 94.82% fifth-term re-election. Sassou Nguesso has held the presidency since 1997 and previously held it from 1979 to 1992.
The user-side architectural response is mesh networking and satellite uplinks for civic documentation during shutdowns: Briar (Bluetooth and Tor), Bridgefy (mesh), Starlink unofficial dishes (documented in Iran and Sudan), Reticulum, Meshtastic, GoTenna PRO consumer products.
Roblox's settlement
On April 21, 2026, Roblox Corporation paid $35.8 million in simultaneous settlements with Nevada ($12.5 million), Alabama ($12.2 million), and West Virginia ($11.1 million). 146 federal multi-district litigation cases remain pending.
The settlement requires Roblox to remove end-to-end encryption from minor chats. The first U.S. settlement weaponizing child safety against encryption.
The architectural significance: state attorneys general have, for the first time, secured a settlement that requires a major consumer messaging-adjacent platform to roll back end-to-end encryption protections at the protocol level, on child-safety grounds, before any federal regulatory or legislative action requires it. The Meta Instagram E2EE rollback announced for May 8 — covered in edition 03 — was a corporate-voluntary action; the Roblox E2EE rollback is a settlement-mandated state-AG action. The architectural pattern is the same — operator pathway re-introduced at the messaging layer — but the mechanism is regulatory, not corporate.
April 22, 2026, was the amended Children's Online Privacy Protection Act Rule's compliance deadline. New coverage: biometric identifiers (faceprints, voiceprints, iris patterns) and government-issued identifiers. Penalties: $53,088 per violation per child per day. NCMEC reports indicate 21.3 million CyberTipline reports in 2025, including 1.5 million with generative-AI nexus.
Today, May 5, the Pennsylvania Attorney General filed a first-of-its-kind medical-impersonation lawsuit against Character.AI.
Common Crawl
April 29, 2026: the News/Media Alliance — on behalf of NBCUniversal, CNN, Vox Media, Ziff Davis, and hundreds of regional U.S. publishers — sent a formal letter to Common Crawl Foundation Executive Director Rich Skrenta demanding the removal of publisher content from the Common Crawl corpus and the establishment of an opt-out registry.
The letter explicitly invokes the EU AI Act's Article 53 GPAI training-data summary requirement, which becomes legally binding August 2, 2026. Common Crawl is the foundational web-scraped corpus for the majority of large-language-model training datasets.
The same day, seven wrongful-death lawsuits were filed in the Northern District of California against OpenAI and Sam Altman, seeking more than $1 billion. The plaintiffs are families of victims of the Tumbler Ridge mass shooting. The complaints cite OpenAI's documented June 2025 internal flag-and-override of the shooter's account.
The architectural significance: the AI training-data provenance war is no longer a courtroom war fought on copyright theories; it is a corpus-removal war fought on regulatory compliance. And the AI vendor liability surface is no longer just copyright; it is now wrongful-death.
Today (May 5)
This Tuesday afternoon, several developments:
- The Pennsylvania Attorney General filed a first-of-its-kind medical-impersonation lawsuit against Character.AI.
- Cushman & Wakefield issued its official statement on the ShinyHunters intrusion ("limited," vishing-confirmed).
- Instructure remains silent on the May 6 deadline.
- The Department of Homeland Security Office of Inspector General reported that 76 percent of smartphone applications used by intelligence-office personnel posed security risks meeting DHS's own internal classification thresholds.
- RightsCon 2026 Lusaka was officially cancelled under reported People's Republic of China pressure on Zambia over Taiwanese delegate participation.
- ShinyHunters' Anodot reframing extends the May 6 deadline pressure across the third-party-SaaS supply chain.
Tomorrow (May 6): the Instructure ShinyHunters extortion deadline expires. The Cushman & Wakefield ShinyHunters contact deadline expires. The CISA Black-Hammer / BlueHammer / RedSun-class CVE-2026-33825 federal patch deadline. The Trellix May 2 source-code-breach impact assessment continues. May 7: Cloudflare, Coinbase, Lyft earnings.
The unifying pattern
The user's daily-life dependencies — water, electricity, transit, communications, payments, education, healthcare, identity — each layer up through:
- OT/ICS systems (Rockwell PLCs at water/wastewater/energy facilities; SCADA at the Minot water plant; smart meters at residential utility connections).
- Vendor SaaS aggregators (Salesforce; Anodot; Itron; Collins Aerospace ARINC; Pickett USA engineering).
- Third-party-of-third-party data integrations (the Anodot vector that reached Vimeo customers).
- Supply-chain dependencies (Bitwarden-CLI cascade via Checkmarx KICS Docker Hub takeover, April 22).
- Foreign-controlled or domestically-captured spyware vendors (Friedman NSO; Paragon ICE $2 million contract; Athens Intellexa convicted; Treasury Intellexa SDN delisting).
- Regulator capacity (CISA without confirmed leader; EPA water-cyber-rule contested; FERC NERC CIP-015-2 pending).
- Information control (Tanzania 5-day shutdown enabling 518 deaths; Republic of Congo 3% baseline; PRC pressure on Zambia cancelling RightsCon).
- Settlement-mandated encryption rollback (Roblox $35.8 million state-AG settlement requiring E2EE strip from minor chats).
Each layer is a potential attack surface. When the regulator (CISA) has no confirmed leader and the attack volume is increasing 49% YoY, the dependency stack is fragile. The pattern is structural.
The architectural counter
Layer reduction. Minimize the count of vendors / OT-internet exposures / single-point-of-failure aggregators. Maintain regulator capacity. Deploy the user-controlled primitive stack at every layer:
- Network segmentation in OT environments: air-gap where feasible; data-diode for telemetry-only paths; bastion-host access for engineering changes.
- Vendor diversification at the SaaS-aggregator layer: avoid single-Salesforce / single-Anodot / single-Itron / single-ARINC architectures.
- On-premises manual fallback: train operators on manual procedures (Minot ND ran 16 hours manually after the March 14 ransomware); periodically exercise.
- Open-source / open-firmware OT alternatives where mature: OpenPLC, Mosquitto MQTT broker, Apache PLC4X, OPC UA open-source SDKs.
- Regulator capacity maintenance: Senate-confirmed CISA director; NERC CIP enforcement; EU NIS2 implementation; state PUC cybersecurity authority.
- User-side resilience: multi-utility / multi-carrier where economically possible; satellite uplinks for shutdown resilience; mesh networking (Briar, Meshtastic, Reticulum, GoTenna PRO) for civic emergencies.
- Forensic detectability at the device layer: open-firmware mobile devices (GrapheneOS) where the SS7/Diameter / Pegasus / Graphite vector cannot bypass user-inspectable cache and notification-database behavior.
- The user-controlled primitive stack from editions 02-04 — open clients, open firmware, FIDO2, censorship-resistant transports, private coins, local-inference AI, federated identity, self-hosted services — applied at every layer of the dependency stack.
Closing
Tomorrow, May 6, the Instructure ShinyHunters deadline expires. Tomorrow the Cushman & Wakefield contact deadline expires. Tomorrow the CISA federal patch deadlines on multiple KEV-listed CVEs expire. Tomorrow continues today's pattern. The patterns of the past sixty days converge on a single architectural diagnosis: the dependency stack is too tall, too consolidated, and too brittle, while the regulator that should be coordinating defense lacks a confirmed leader, and the spyware vendors that could exploit the brittleness are being captured under domestic ownership and watching their sanctions relax.
Layer reduction is the only generalizable counter. Fewer vendors. Fewer single-point-of-failure aggregators. Fewer integrations. Fewer dependencies. Maintain the regulator. Deploy the user-controlled primitive stack at every layer.
The dependency stack is the pattern. Layer reduction is the response.