By Nemuel Cruz, Incognito CyberSecurity(TM)
Three things landed this week that matter to small and mid-sized businesses in Southern Arizona, and none of them are exotic. A firewall management appliance shipped with a built-in password. A build server that lets anyone on the internet run commands. And industrial controllers sitting wide open on the public internet at water utilities. The common thread is boring on purpose: default credentials and things exposed to the internet that never should have been. As a Tucson MSP company, we spent this week checking client environments for exactly these three conditions. Here’s what happened and what to do about it.
1. Cisco Patched an Actively Exploited Zero-Day in Secure Firewall Management Center (CVE-2026-20316)
On Wednesday, July 29, 2026, Cisco released patches for CVE-2026-20316, a flaw in Cisco Secure Firewall Management Center (FMC) that attackers were already exploiting. The problem is static credentials — a hardcoded, low-privilege account baked into the FMC web interface. An unauthenticated attacker on the network can simply log in with those credentials and read sensitive data. The CVSS score is only 5.3, but Cisco rated it High severity because that foothold can be chained with other FMC vulnerabilities to escalate privileges. Cisco confirmed it detected exploitation in July and published indicators of compromise, including checking /var/log/messages for license-related entries referencing /var/tmp/license.tmp. The flaw was reported by Jimi Sebree of Horizon3.ai. Cloud-delivered FMC and Firewall Device Manager are not affected. Cisco’s guidance is blunt: if you suspect exploitation, patching alone isn’t enough — rotate every user credential, cryptographic key, and certificate stored on the appliance, because they may already be gone.
What to do: If you run on-premises Cisco Secure FMC, patch it this week, then confirm the management interface is not reachable from the public internet. If you can’t tell whether it is, that’s the real finding. After patching, rotate credentials and certificates on the box — assume anything stored there was readable. Most small businesses don’t run FMC directly, but if a vendor manages your firewall, ask them today whether they’ve applied this fix and whether the management interface is exposed. Our network solutions work always starts with that inventory question, because you cannot patch equipment you’ve forgotten you own.
2. JetBrains TeamCity Hit With a CVSS 9.8 Unauthenticated Remote Code Execution Flaw (CVE-2026-63077)
JetBrains published an advisory on July 27, 2026 for CVE-2026-63077, a critical vulnerability affecting every version of TeamCity On-Premises before 2026.1.3 and 2025.11.7. It scores 9.8 out of 10. The root cause is insecure deserialization of untrusted data in the agent polling protocol — the channel build agents use to check in with the server. Anyone with HTTP or HTTPS access to the server can send a crafted request, bypass authentication entirely, and run operating system commands with the privileges of the TeamCity server process. No credentials, no user interaction. JetBrains noted that a successful attacker can read stored credentials and compromise the integrity of the CI/CD pipeline, which means poisoned build artifacts flowing downstream to whatever that pipeline deploys. The flaw was reported privately by researcher Antoni Tremblay. Fix versions are 2026.1.3 or 2025.11.7, with a security patch plugin available for older installs from v2017.1 forward.
What to do: If your dev shop or a contractor runs TeamCity on your network, upgrade or apply the patch plugin now, and get that server off the public internet. Then rotate the secrets it held — API keys, deploy credentials, signing keys — because patching doesn’t un-steal a password. This is also a reminder that build servers, jump boxes, and “temporary” internal tools are exactly the assets that never make it onto a formal asset list. A network penetration test is the cheapest way to find out what of yours is actually answering from the internet, rather than what you believe is answering.
3. CISA Warns Water Utilities to Pull Internet-Exposed PLCs Offline After More Than 30 Minnesota Systems Were Disrupted
CISA issued an urgent alert this week warning of a significant increase in attacks against internet-exposed programmable logic controllers in the water and wastewater sector. It follows a coordinated campaign that hit more than 30 community water systems across Minnesota beginning Sunday, July 26 and continuing through Monday, July 27, 2026. Affected communities included Braham, Plymouth, South St. Paul, and Maple Plain. Attackers changed PLC passwords to lock operators out of their own equipment and modified IP addresses to knock devices offline, forcing utilities into manual operations. Braham reported that computerized operating controls were disabled, temporarily affecting water treatment. Minnesota IT Services called it a coordinated cyberattack and activated a statewide response. Attribution is unsettled — the Minnesota Fusion Center said the activity is “aligned” with a campaign CISA described in April involving Iran-linked actors targeting internet-connected PLCs, documented in advisory AA26-097A and updated July 22, 2026, but no direct link to Iran has been presented publicly. CISA’s instruction to owners and operators of all sizes: remove publicly exposed PLCs and other operational technology from the internet as soon as possible, replace default passwords, and restrict remote access to trusted devices only.
What to do: You may not run a water plant, but if you have building HVAC controls, cameras, badge readers, well pumps, irrigation timers, refrigeration monitoring, or shop-floor equipment reachable from outside, you have the same exposure — often installed by a vendor with a default password and a port forward nobody documented. Ask every vendor with equipment on your network for a written list of what they’ve exposed and how they reach it, then put that access behind a VPN with unique credentials and multifactor. And decide now who you call at 2 a.m. when you’re locked out of your own systems; our 24/7 emergency IT services page walks through what that response actually looks like.
The bottom line
Nothing this week required a nation-state budget. A hardcoded password, an unauthenticated endpoint, and controllers left facing the open internet — that’s the whole story. The defense is unglamorous and it’s the same every time: know what you own, know what’s reachable from outside, kill default credentials, patch the things that are exposed first, and rotate secrets after a compromise instead of assuming a patch cleaned up the mess. Layered basics carry most of the weight here, which is why our small business cybersecurity solutions lead with visibility and hardening before anything else. Add endpoint protection that actually reports back, spam and virus filtering to cut off the easiest delivery route, and tested secure data backups so a bad week stays a bad week instead of becoming a closed business.
If you’re not certain what of yours is currently reachable from the internet, that’s the one question worth answering before next week’s advisories land. Contact us and we’ll walk your environment with you — no pitch, just a straight answer about where you stand.


