Cyberattacks
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Hackers connected to Iran knocked a UK power plant offline for four days last month, according to the Sunday Telegraph, which broke the story. It comes after Britain allowed the US to launch defensive operations against Tehran from British bases — a policy that stops short of offensive strikes.
The government said the incident hit a small-scale energy generator and that the wider energy system was never at risk. The National Cyber Security Centre is understood not to have logged any outages from regulated power station operators. Still, Iran's IRGC has warned that any base used for aggression against Iranian territory is a "legitimate target."
Britain's new PM Andy Burnham was notified last week that a decision had already been made to extend the US basing agreement.
Source: The Guardian
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.
Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.
ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.
Source: SecurityWeek
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
A Gambit Security report has revealed one of the most detailed real-world cases of AI being weaponized inside an active ransomware operation. A suspected affiliate of The Gentlemen ransomware-as-a-service group used Anthropic's Claude Code to breach VPN appliances, steal domain credentials, and exfiltrate SQL databases across at least eight organizations — including an Australian energy utility and a Mauritius financial firm.
The attacker used Claude Sonnet 4.6, an older, less-restricted model, interactively refining commands based on live output. Claude executed a sophisticated LDAP pass-back attack, created hidden backdoor VPN accounts, and ranked databases by business value before dumping them. At one point, Claude accidentally knocked a firewall offline, then logged: "Yeah, I screwed up."
This marks a clear shift — AI isn't just drafting phishing emails anymore. It's running live attacks.
Source: Cybersecurity News
A Gambit Security report has revealed one of the most detailed real-world cases of AI being weaponized inside an active ransomware operation. A suspected affiliate of The Gentlemen ransomware-as-a-service group used Anthropic's Claude Code to breach VPN appliances, steal domain credentials, and exfiltrate SQL databases across at least eight organizations — including an Australian energy utility and a Mauritius financial firm.
The attacker used Claude Sonnet 4.6, an older, less-restricted model, interactively refining commands based on live output. Claude executed a sophisticated LDAP pass-back attack, created hidden backdoor VPN accounts, and ranked databases by business value before dumping them. At one point, Claude accidentally knocked a firewall offline, then logged: "Yeah, I screwed up."
This marks a clear shift — AI isn't just drafting phishing emails anymore. It's running live attacks.
Source: Cybersecurity News
U.S. agencies including the NSA, CISA, FBI, and the Energy and Environmental Protection Agency issued a joint warning Wednesday about hackers using AI-generated scripts to attack critical infrastructure — water, food, energy, chemical, and manufacturing sectors.
The attackers are targeting Siemens S7 Series programmable logic controllers, using AI to rapidly develop exploitation tools that once required significant technical skill. The agencies called it an "active threat," not a theoretical one. Attacks could disrupt industrial processes, trigger safety incidents, or expose sensitive data.
Experts flagged this as the first known CISA advisory explicitly citing AI-generated scripts targeting operational technology systems.
Source: CyberScoop
U.S. agencies including the NSA, CISA, FBI, and the Energy and Environmental Protection Agency issued a joint warning Wednesday about hackers using AI-generated scripts to attack critical infrastructure — water, food, energy, chemical, and manufacturing sectors.
The attackers are targeting Siemens S7 Series programmable logic controllers, using AI to rapidly develop exploitation tools that once required significant technical skill. The agencies called it an "active threat," not a theoretical one. Attacks could disrupt industrial processes, trigger safety incidents, or expose sensitive data.
Experts flagged this as the first known CISA advisory explicitly citing AI-generated scripts targeting operational technology systems.
Source: CyberScoop
Taiwan's Ministry of Digital Affairs says the attack on government agencies began on 20 July, and Israeli firm Dream, which detected the intrusion, calls it a first-of-a-kind breach. Attackers used open-source AI agents — OpenClaw and Hermes — to build what Dream calls an autonomous hacking tool, one that behaved like a coordinated cyber team.
It compromised at least 85 government accounts, extracted more than 2,500 personnel records, then expanded to Taiwan's nuclear safety agency and at least seven energy companies. Not everyone is sold on the autonomy: Semgrep's Cris Thomas points out that someone still picked the target and set the objective — "it's not totally 100% autonomous."
While Taiwanese officials stopped short of blaming China, Dream said the use of Simplified Chinese in internal communications meant a high probability the operator was connected to China. China's Taiwan Affairs Office did not respond to a request for comment.
MDA says the attack combined manual operations with AI agents, that sources, methods and scope have been fully investigated, and that affected units have completed their handling. New protective guidelines and strengthened monitoring are now in place.
Source: The Guardian
Taiwan's Ministry of Digital Affairs says the attack on government agencies began on 20 July, and Israeli firm Dream, which detected the intrusion, calls it a first-of-a-kind breach. Attackers used open-source AI agents — OpenClaw and Hermes — to build what Dream calls an autonomous hacking tool, one that behaved like a coordinated cyber team.
It compromised at least 85 government accounts, extracted more than 2,500 personnel records, then expanded to Taiwan's nuclear safety agency and at least seven energy companies. Not everyone is sold on the autonomy: Semgrep's Cris Thomas points out that someone still picked the target and set the objective — "it's not totally 100% autonomous."
While Taiwanese officials stopped short of blaming China, Dream said the use of Simplified Chinese in internal communications meant a high probability the operator was connected to China. China's Taiwan Affairs Office did not respond to a request for comment.
MDA says the attack combined manual operations with AI agents, that sources, methods and scope have been fully investigated, and that affected units have completed their handling. New protective guidelines and strengthened monitoring are now in place.
Source: The Guardian
A supply chain attack that exposed more than 2,000 organizations traces back to a compromised Trivy build — not LiteLLM, as initially reported. SOCRadar identified 2,188 organizations with attributable records and found 95% had their data collected before March 24, when the two poisoned LiteLLM releases appeared on PyPI for just 40 minutes.
The real damage started March 19, when TeamPCP force-pushed malicious commits to 76 of 77 trivy-action version tags, using access it had kept after an incomplete credential rotation — Aqua Security's own systems were never breached. Their Shai-Hulud worm harvested credentials, tokens, and API keys, then used stolen developer secrets to spread itself across accessible packages.
It all falls under CVE-2026-33634 — 8.8 high on CVSS v3.1, 9.4 critical on v4.0 — covering Trivy v0.69.4, trivy-action 0.0.1 through 0.34.2, setup-trivy 0.2.0 through 0.2.6, LiteLLM 1.82.7 to 1.82.8, and telnyx-python 4.87.1 to 4.87.2. CISA added it to KEV on March 26, with an April 9 deadline.
Six CI/CD platforms were hit — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite — with Germany, Brazil, and France most affected. Stolen data is already up for sale on Telegram.
Source: SecurityWeek
A supply chain attack that exposed more than 2,000 organizations traces back to a compromised Trivy build — not LiteLLM, as initially reported. SOCRadar identified 2,188 organizations with attributable records and found 95% had their data collected before March 24, when the two poisoned LiteLLM releases appeared on PyPI for just 40 minutes.
The real damage started March 19, when TeamPCP force-pushed malicious commits to 76 of 77 trivy-action version tags, using access it had kept after an incomplete credential rotation — Aqua Security's own systems were never breached. Their Shai-Hulud worm harvested credentials, tokens, and API keys, then used stolen developer secrets to spread itself across accessible packages.
It all falls under CVE-2026-33634 — 8.8 high on CVSS v3.1, 9.4 critical on v4.0 — covering Trivy v0.69.4, trivy-action 0.0.1 through 0.34.2, setup-trivy 0.2.0 through 0.2.6, LiteLLM 1.82.7 to 1.82.8, and telnyx-python 4.87.1 to 4.87.2. CISA added it to KEV on March 26, with an April 9 deadline.
Six CI/CD platforms were hit — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite — with Germany, Brazil, and France most affected. Stolen data is already up for sale on Telegram.
Source: SecurityWeek