AI and IT News Recap: July 30, 2026: Hackers Seize the Controls at 30+ Minnesota Water Utilities, xAI Sues to Kill a Deepfake Ban, and a
B Bet on Securing AI Agents

By Noah Smith, Founder, KeyChange Technologies · July 30, 2026

Pen-and-ink illustration of a small-town water tower rigged like a marionette, its control valve pulled by strings from an unseen hand overhead, while a lone worker at the base looks up.

Welcome to your daily KeyChange AI and IT news recap for July 30, 2026. Today's AI and IT news is a study in control: who holds it, who is trying to seize it, and who is being told to hand it over. Attackers reached into the operational controls of more than 30 Minnesota water systems, Elon Musk's xAI went to federal court to block a first-in-the-nation deepfake law, and a

billion acquisition just made "who is your AI agent logging in as" the hottest question in security. Here is what happened and what it means for your business.

📌 The AI and IT news at a glance

  • Hackers seize the controls at 30+ Minnesota water utilities, knocking at least one plant offline, with investigators eyeing an Iran-linked crew.
  • A stealthy new Iranian backdoor, NightLedger, turns compromised government and telecom systems into covert relays across three continents.
  • xAI sues Minnesota to block the country's first ban on AI "nudify" apps, calling it a free-speech violation.
  • Cyera agrees to buy Oasis Security for
    billion to lock down the logins of AI agents.
  • The EU AI Act's transparency and deepfake-labeling rules go live August 2, with fines up to €15 million.
  • A gray-market "relay" economy for LLM access is quietly becoming a shadow-AI risk for cost-conscious teams.

🔝🛡️ Top story: Hackers grabbed the controls at 30-plus Minnesota water utilities

More than 30 community water systems across Minnesota were hit in a coordinated cyberattack over the weekend of July 26 and 27, with several cities, including Maple Plain, Braham, South St. Paul, and Plymouth, reporting that automated control functions were affected. The City of Braham said its water plant was knocked offline; crews restored service within about three hours and the plant went back to filtering and treating water as expected. Minnesota IT Services (MNIT) activated its statewide cybersecurity incident response to help utilities contain, investigate, and remediate. This was not a data-theft breach. It was a direct reach into the operational technology (OT) that physically runs the water, which is exactly the category of attack that safety regulators have warned about for years.

Attribution is still pending a federal investigation, but the timing lines up closely with escalating Iran-affiliated activity against programmable logic controllers in U.S. critical infrastructure, and reporting points at the Iran-linked CyberAv3ngers crew as the prime suspect. CISA has spent 2026 widening its warnings about this exact threat, adding Schneider Electric and Siemens gear to a list of targeted equipment in a late-July update. For a small municipal utility with a two-person IT budget, "state-linked actor probing your control system" is a genuinely new place to be.

In short: A coordinated cyberattack disrupted operational controls at more than 30 Minnesota water utilities, briefly taking at least one treatment plant offline, with an Iran-linked group the leading suspect.

What it means for your business: If you run anything with physical controls (HVAC, building access, manufacturing lines, pumps, meters), the lesson is that internet-reachable OT is now a front-line target, not an afterthought. Segment it from your office network, put multifactor authentication in front of remote access, and confirm you can operate in manual mode if the automation is compromised.

My take: The reassuring detail here is also the scary one. Braham was back online in three hours because a human could still walk in and run the plant by hand. That resilience is the whole ballgame for small operators. You are not going to out-spend a nation-state on defense, but you can make sure a compromised controller is an inconvenience rather than a catastrophe. Anyone running critical equipment should treat this week as a free tabletop exercise: if your automation went hostile tonight, could your people still deliver the service?

Source: BleepingComputer


🛡️ IT and security

An Iranian backdoor named NightLedger turns victims into relay stations

Kaspersky's Securelist and The Hacker News detailed a fresh toolset from the Iranian IRGC-linked espionage group Nimbus Manticore (also tracked as UNC1549 and Mirage Kitten). The centerpiece is a previously undocumented Windows backdoor called NightLedger, paired with two custom WebSocket tunneling tools, BridgeHead and ArcBridge. NightLedger installs itself by masquerading as a legitimate Windows library and abusing a search-order hijack so it runs with the trust of a signed system process, which is precisely the kind of trick that slips past casual endpoint checks. The tunneling tools then quietly convert an infected machine into a covert relay node the operators can route their traffic through.

The campaign is hitting government, aviation, telecom, and financial targets across the Middle East, Africa, and South Asia, with named victims spanning Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. It is a distinct, geographically separate track from the same group's earlier MiniFast operation against Western defense and aerospace firms, so this is expanded reach rather than recycled activity.

In short: An Iranian state-linked group is deploying a new stealth backdoor, NightLedger, that hijacks a trusted Windows process and turns compromised systems into hidden traffic relays.

What it means for your business: Most small and mid-size firms are not the direct target here, but the technique matters. Signed-process hijacking and DLL search-order abuse defeat "the file looks legitimate" instincts, so behavioral monitoring that flags a trusted process doing untrusted things is worth more than another signature-based scanner.

My take: The relay angle is the part I would not gloss over. Attackers increasingly want your machines not for your data but as anonymous stepping stones to hit someone else. That reframes "we have nothing worth stealing" as the wrong question. Your bandwidth and your clean IP reputation are the asset, and a compromised box that is quietly relaying an espionage campaign is a liability you would rather not explain to a regulator or an insurer later.

Source: The Hacker News


🤖 AI

xAI sues Minnesota to kill the country's first AI "nudify" ban

Elon Musk's xAI has filed suit against Minnesota Attorney General Keith Ellison to block HF 1606, a first-in-the-nation law prohibiting apps and websites that generate fake sexualized images of real people without consent. The law, signed by Governor Tim Walz and set to take effect in early August, imposes fines of up to $500,000 per violation and, notably, attaches liability regardless of whether a platform deployed state-of-the-art guardrails or explicitly forbids the content in its terms. xAI is asking a federal court to declare the statute unconstitutional under the First and Fourteenth Amendments and to enjoin enforcement, arguing the law is an overbroad, content-based restriction whose definition of "intimate part" could sweep in things like shirtless men and swimwear photos.

This lands at a genuinely hard intersection. Nonconsensual synthetic intimate imagery causes real, documented harm, which is why states are legislating against it and app stores have started pulling "nudify" apps. At the same time, strict-liability rules that ignore intent and good-faith safeguards raise legitimate constitutional questions. The case fits xAI's pattern as the lab most resistant to content restrictions, and it arrives while the company is also fielding class-action complaints over Grok-generated imagery.

In short: xAI is asking a federal court to strike down Minnesota's first-in-the-nation ban on AI nudification apps as an unconstitutional restriction on speech.

What it means for your business: If your company builds or resells anything that generates images or video, watch this closely. A ruling either way will shape how much liability sits with the platform versus the end user, and strict-liability statutes mean "we prohibit it in our terms" may not be a defense.

My take: I find the underlying law easy to support and the constitutional question genuinely hard, which is an uncomfortable place to sit. The strict-liability design is the crux: holding a provider fully responsible even when it forbids and technically blocks the misuse is where reasonable people start to worry about overreach. The courts, not the labs and not the legislatures, are going to draw these lines, and this is the case that starts the drawing.

Source: CNBC


Cyera bets
billion that AI agents need their own security guards

Data-security unicorn Cyera has agreed to acquire Oasis Security for roughly

billion, structured as about $700 million in cash with the remainder in stock. Oasis specializes in non-human identity security, meaning the credentials, tokens, and permissions that belong to automated systems rather than people, and AI agents in particular. It is Cyera's third acquisition this year, coming just after a $600 million round in June that valued the company at
2 billion; Oasis had raised a
20 million Series B in March and
95 million in total. The companies expect to close later this year.

The strategic logic is blunt. As businesses hand real tasks to AI agents, each agent becomes a new kind of user that never sleeps, moves at machine speed, and holds credentials of its own. Recent incidents where autonomous agents chained together exposed logins to reach systems they were never meant to touch turned "manage your agents' identities" from a theoretical concern into a board-level one, and the money is now flowing toward companies that can do it.

In short: Cyera is buying Oasis Security for about

billion to manage the identities and permissions of AI agents, marking AI-agent security as a real, fundable category.

What it means for your business: If you are piloting AI agents that can log into your tools, treat each one like an employee who needs least-privilege access, scoped permissions, and monitoring, not a magic helper with your admin password. You do not need a billion-dollar platform to do that, but you do need to stop giving agents standing access they rarely use.

My take: This is the clearest sign yet that "AI agent security" is graduating from conference-panel jargon to a line item. The uncomfortable truth for smaller shops is that most agent deployments today run on over-broad API keys and shared logins because it is the fast path to a demo. That is fine for a prototype and dangerous in production. The vendors are racing to sell you the guardrails; the free version is just disciplined permission-scoping, and it is worth doing before an agent surprises you.

Source: TechCrunch


The EU AI Act's transparency rules go live on August 2

Article 50 of the EU AI Act, covering transparency obligations, becomes legally enforceable on August 2, 2026, and it survived the recent Digital Omnibus package that pushed most high-risk compliance out to December 2027. In plain terms: if you operate a chatbot, users generally need to be told they are talking to AI; AI-generated or manipulated content, including deepfakes, needs to be labeled; and emotion-recognition or biometric-categorization systems require disclosure. The European Commission issued detailed guidelines on July 20, and there is no grace period. Penalties run up to €15 million or 3 percent of global annual turnover, whichever is higher.

The wrinkle worth flagging is that Article 50 attaches by function, not by risk tier. Many organizations spent the first half of 2026 relaxing after hearing that AI Act enforcement had been delayed, but that delay was about the Annex III high-risk categories, not this. If your product interacts with EU users through an AI chatbot or generates synthetic media, the obligation applies even if you never considered yourself a "high-risk" AI provider. Regulators have also acknowledged that the watermarking techniques the law leans on are bypassable, so this is not a set-and-forget checkbox.

In short: The EU AI Act's transparency and deepfake-labeling duties become enforceable August 2, apply based on what your system does rather than its risk tier, and carry fines up to €15 million.

What it means for your business: If you serve EU customers and use AI chatbots or generate images, audio, or video, confirm this week that you disclose AI interactions and label synthetic content. It is a low-cost fix now and an expensive oversight later.

My take: The trap here is complacency. "EU AI Act enforcement got delayed" was true enough to make a lot of people stop reading, and Article 50 is the part that quietly did not move. It is also the part most likely to touch an ordinary business, because a customer-service chatbot or a marketing deepfake is far more common than a high-risk credit-scoring model. This is a rare compliance item where doing the right thing is genuinely cheap, so there is no good reason to be caught out.

Source: Euronews


🧰 Business AI watch

A gray-market "relay" economy for AI access is a shadow-IT risk in disguise

Security researcher Simon Willison put a spotlight this week on a gray-market ecosystem of "relay" services that pool stolen and abused LLM API credentials, harvested through free-trial abuse, stolen cards, and exposed support chatbots, then resell access at discounts as steep as 97.8 percent off official rates. Cheap is the lure; the catch is what you give up. These relays frequently run silent model substitution, so you pay for a flagship model and quietly receive a cheaper one, and every prompt and response you send passes through an unvetted intermediary that may retain it. The Cloud Security Alliance flagged the same trend in its July 29 briefing, tying it to the broader credential-theft economy behind recent Ollama and LiteLLM vulnerabilities.

The reason this belongs on a business owner's radar is that it is a shadow-IT problem wearing a cost-savings costume. A well-meaning employee who finds "GPT access for 90 percent off" is not thinking about data governance, and that route sits entirely outside the vendor-risk questions most companies actually ask. Vendors are starting to respond, with Anthropic moving to mandatory identity verification at Claude Pro and Max checkout, but the demand side is not going away while the price gap is this wide.

In short: A discount gray market for AI API access is pooling stolen credentials and quietly rerouting or substituting models, exposing any business that uses it to data leakage and fraud.

What it means for your business: Make sure your team buys AI access directly from the provider or a known reseller. If a deal on model access looks too cheap to be real, it is, and your prompts (which may contain customer data or trade secrets) are the hidden price.

My take: This is the shadow-IT story of the SaaS era repeating itself with AI, and the fix is the same as it always was. People route around tools that are too expensive or too locked down, so the durable answer is to give your team a sanctioned, reasonably priced AI option and a clear line about what data can go into it. Ban everything and you push usage into exactly these back alleys; provide a good default and most of the temptation evaporates.

Source: Simon Willison


That is your AI and IT news recap for July 30, 2026. Confirm your water and building controls are not sitting on the open internet, check any EU-facing chatbots against the new labeling rules, and we will see you in the next one. For yesterday's stories, see our July 29 recap.