Cyber security developments for Tuesday the 4th of August 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 4 articles to cover. All attribution is by the article authors. All article analysis is automated.
Dataminr report on how Iranian threat actor CyberAv3ngers has significantly escalated their operational technology targeting. They've moved beyond simple disruption of Rockwell Automation PLCs to now pulling project files and uploading malicious code to Schneider Electric and Siemens controllers across water, wastewater, energy, and government facilities. This one develops the operational technology targeting story from the first of August when we covered the FBI advisory on PLC attacks.
The European Telecommunications Standards Institute has released a draft standard establishing five incremental assurance levels for memory safety. ETSI TS 104 198 affects everything from C and C++ developers through to hardware manufacturers working on capability hardware like CHERI and Arm MTE, finally giving the industry measurable benchmarks rather than just aspirational statements about memory safety.
Uber has open-sourced ADR, their agentic AI detection and response framework that's currently protecting their internal coding assistants and customer-facing support agents in production. The system includes telemetry capture, a benchmark suite with over three hundred security tasks covering seventeen agent attack techniques, and a two-tier threat detection system for catching prompt injection and compromised workflows. Particularly relevant given the number of AI agent incidents we've been tracking this week.
And a pre-authentication remote code execution vulnerability in Apple's screen sharing daemon affecting macOS versions up to 26.5. The flaw stems from inadequate frame-length validation that causes error-handling logic to return authentication success rather than dropping malformed connections, giving unauthenticated attackers root-level file access. Apple patched it in macOS 26.6 on the twenty-seventh of July.
That concludes today's briefing.