Cybercriminals went after America itself this week, targeting the critical systems that help power the entire state of Nevada.
Meanwhile, Cloudflare thwarted the most significant DDoS attack on record, and thirteen allied nations have warned that China-backed hackers continue to infiltrate telecommunications networks worldwide.
Here's what happened and why these attacks signal a darker turn in the cyber war.
Nevada's state government remains hobbled twelve days after a massive ransomware attack first detected on Sunday, August 24. State offices from Las Vegas to Reno are still struggling, leaving residents unable to access many basics like DMV renewals, marriage certificates, and some benefits. While emergency services (including 911) and core programs such as payroll and unemployment continue to function, numerous websites, phone lines, and in-person counters remain disrupted as recovery continues.
Key Insights
Federal investigators, the FBI alongside CISA, are actively probing the incident with Nevada officials. State leaders have confirmed it was a ransomware attack and acknowledged that some data was exfiltrated, though the scope is still being assessed. Authorities have not disclosed any ransom demand or payment. Governor Joe Lombardo has cautioned that restoration must proceed methodically to avoid further damage, with teams working "around the clock" to bring services back online in stages.
Why This Matters For You:
This incident marks one of the first statewide ransomware shutdowns in U.S. history, highlighting the profound vulnerabilities of local and state governments. Nevada's ordeal is a stark wake-up call for the rest of the country: as more states shift services online, they are also creating broader attack surfaces for cybercriminals. The immediate test is restoring Nevada's systems, but the larger question is whether other states will invest in the cybersecurity infrastructure necessary to prevent their own digital disasters.
Read More on the Nevada Office Of Emergency Management.
Cloudflare says it stopped the most significant DDoS attack ever recorded! This monstrous DDoS attack peaked at a staggering 11.5 terabits per second. The assault targeted financial services, gaming, and cloud platforms, aiming to knock them offline by flooding servers with junk traffic. For comparison, that is like trying to squeeze every movie on Netflix through a single Wi-Fi router at once.
Key Insights:
DDoS attacks are not new. But their scale is escalating rapidly. This 11.5 Tbps attack, a UDP flood lasting 35 seconds, was ~1.6x larger than the previous record of 7.3 Tbps in May 2025 and ~3x larger than the 3.8 Tbps record from October 2024. It leveraged a botnet of compromised IoT devices (e.g., webcams, routers) and cloud servers. (This is a reminder to secure your home devices! Otherwise, your home network might end up on a zombie botnet.)
Why It Matters For You:
Almost everything we do, from banking and gaming to even Zoom calls, relies on cloud services. A successful strike of this size could grind daily life to a halt, not just for one company but for millions of people. The takeaway is simple. Internet security must scale as quickly as attackers do.
Read More on The Hacker News.
Thirteen countries just issued a rare joint warning that China-backed hackers are still actively targeting critical infrastructure worldwide, with telecommunications networks in their crosshairs. The advisory reveals these state-sponsored groups aren't just collecting intelligence, they're allegedly positioning themselves for something bigger. According to FBI officials, Chinese hackers have gained deep access to major communication carriers across 80 countries.
Key Insights:
The hackers focus on "large backbone routers of major telecommunications providers," but also penetrate smaller devices to make the final leap into their targets. Think of it like digital sleeper agents, quietly embedding themselves in the systems that power our phone calls, internet connections, and emergency services. The campaign, known as Salt Typhoon, has breached at least nine U.S. telecommunications networks.
Why This Matters For You:
A widespread, looming digital attack could impact everyone in the U.S. What makes this particularly concerning is the scale and patience involved. U.S. intelligence agencies assess that Chinese actors are "positioning themselves within information technology networks, enabling lateral movement" rather than just stealing data and leaving. This strategy suggests preparing for future disruptions during a crisis, when shutting down communications could harm response efforts and exacerbate chaos.
Read More on Cybersecurity Dive.
Before the guns, exile, pirate ships, and jungle escapes, John McAfee built the world's first commercial antivirus. In the 1980s, he watched the Brain virus spread from Pakistan to California on floppy disks. He realized the age of digital contagion had begun. He didn't wait for permission. He built a defense and a company before most people knew what a virus was.
But success warped into spectacle. After cashing out, McAfee turned into a wandering prophet of cyber paranoia. He claimed that your smart TV was spying on you. That the NSA could own your phone, that digital privacy was dead. In hindsight, maybe he wasn't wrong. Beneath the chaos and conspiracy, McAfee was warning us: if you don't control your data, someone else will.
McAfee's legacy is part tech, part myth. However, his most potent lesson remains. Security is never just software. It's a mindset of distrust and the refusal to assume the system has your back. Rest in peace, sir.
These are my go-to privacy + security tools. Some links are affiliate links. (They support this newsletter at no extra cost to you!)
Proton Mail - One of the more private and secure email services. Basic accounts are free.
Proton VPN – Keep your internet, browsing history, and connection secure with servers in over 120 countries.
Proton Pass - Protect passwords with an elite encrypted password manager. Supports 2FA codes, device sync, multiple vaults, notes, and more.
Proton Drive - Store your data safely. Get 5GB for free and enjoy peace of mind, knowing your files are safe.
Please read my two newsletters:
# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun and battle-tested AI prompt in each issue.
# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security that helps you spot scams and stay safe without needing to become an expert.
Follow for extra insights:
Bluesky | X (Twitter) | LinkedIn | YouTube
PS: Do you have questions? Reply to this email!
Thanks for reading. More cutting-edge cybersecurity insights coming soon.
You're receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.