This Week in Cyber - Aug 27 - Sept 02, 2026

This week, Boston Scientific remains disrupted after a cyberattack, OpenAI and Anthropic warned of accelerating AI-driven attacks, the White House launched Project Watershed 250, a cyberattack exposed data tied to 8.7 million airport customers, and TSA updated cybersecurity requirements for surface transportation.


Boston Scientific remains disrupted after cyberattack

Boston Scientific continues recovering this week from the cybersecurity incident that caused a global network outage on August 25.

As of August 30, the company said its investigation remained ongoing and it was working toward partial restoration of product shipping. The incident affected systems used to manufacture products and process and ship customer orders.

Why it matters: Stopping the attack doesn't restore operations. Operators need to quickly establish blast radius, persistence, and which systems can be trusted. Every hour spent answering those questions extends the recovery window.


OpenAI, Anthropic and more than 100 companies warn of AI-driven cyberattacks

On August 27, more than 100 companies including OpenAI, Anthropic, Microsoft, Amazon and Alphabet warned that AI-enabled cyberattacks could soon become significantly more widespread.https://www.reuters.com/legal/litigation/major-tech-companies-call-defensive-surge-defeat-ai-driven-hacks-2026-08-27/

The companies called for governments and industry to strengthen cyber defenses as increasingly capable AI models make advanced cyber capabilities more accessible.

Why it matters: Defenders should always have the advantage. The companies building frontier AI systems are warning that advantage is shifting to adversaries. Operators need the capability to investigate and act fast to keep the fight unfair.

Read our full breakdown: AI Is Compressing the OT Attack Cycle


White House launches Project Watershed 250

On August 31, the White House Office of the National Cyber Director launched Project Watershed 250, selecting Texas as the first state for the water cybersecurity pilot.

Participating utilities will receive cybersecurity assessments, remediation support and emerging defensive capabilities through a partnership between federal agencies, Texas Cyber Command and private-sector providers.

Why it matters: Watershed 250 is a start, not a solution. Assessments and remediation can reduce exposure, but utilities need durable capability to defend after the pilot ends. The real test is whether operators are better off after the program than they were before it.


Cyberattack exposes data tied to 8.7 million airport customers

On August 27, Manchester Airports Group disclosed a cyberattack affecting Manchester, Stansted and East Midlands airports, with data tied to about 8.7 million customers accessed.The exposed information included email addresses, phone numbers, vehicle registrations and postcodes. Manchester Airports Group said airport operations and aviation security weren't disrupted.

Why it matters: The breach stopped short of airport operations. That's the boundary defenders need to prove, not assume. Transportation operators need the visibility and investigative capability to determine whether attacker access is contained to business systems or moving toward systems that can disrupt physical operations.


TSA updates cybersecurity requirements for surface transportation

On September 1, TSA moved forward with a revised cybersecurity information collection covering freight rail, passenger rail and mass transit operators.

The update covers cybersecurity incident reporting, contingency and recovery planning, assessments and additional reporting around cybersecurity implementation plans for covered operators.

Why it matters: TSA is moving the requirement from having a cybersecurity plan to showing the controls behind it actually work. Operators will need repeatable evidence that detection, investigation, response, and recovery capabilities are functioning before an incident becomes the test.


That’s it for this week.

We’ll be back next Thursday with the next Weekly Roundup.

Previous
Previous

This Week in Cyber - Sept 3–9, 2026

Next
Next

More Than 100 U.S. Water Systems Were Targeted in July