LIVE · cybersecurity feed
Live wire
breach

Hackers breached a small Polish energy plant via private APN last year

Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]

zeroday.news ·

A previously undisclosed cyberattack against a small Polish combined heat-and-power (CHP) plant in December 2025 resulted in the shutdown of its steam turbine and water treatment system. This incident, which occurred concurrently with a broader series of attacks on Poland's energy sector, was facilitated by the exploitation of a private Access Point Name (APN) and a misconfigured network lacking client isolation.

The Polish Computer Emergency Response Team (CERT) confirmed the details of this second attack in a recent follow-up report. While the initial wave of attacks, attributed to the Russian Electrum threat group, targeted 30 wind and solar power installations and a large CHP plant, destroying equipment and wiping Windows systems, the grid's overall energy generation and distribution remained undisrupted. In the newly revealed incident, plant staff were able to quickly restore systems, leading to a short-lived outage with no impact on the local population of approximately 50,000 residents.

Investigators determined the attack path began with the compromise of a FortiGate VPN/firewall at a wind farm. From there, the attackers utilized a Teltonika cellular router to tunnel into a private APN managed by the distribution system operator. The critical vulnerability was the APN's lack of client isolation, which allowed the attackers to scan and communicate with devices across different facilities connected to the same APN.

Starting on December 18, the attackers identified a WAGO PFC200 programmable logic controller (PLC) at the CHP plant with its web interface exposed on the APN and protected only by default administrator credentials. After compromising this controller, they enabled SSH access, using it as a bridge into the plant's operational technology (OT) network.

Over the subsequent week, the threat actors scanned the OT network for SCADA systems and industrial devices. By December 25, they had connected to three Siemens PLCs, likely in preparation for the final assault. At approximately 5:30 a.m. on December 29, the attackers accessed the SCADA interface and the Siemens PLCs, switching them into STOP mode, activating password protection, and consequently shutting down the steam turbine and the process-water treatment system, interrupting cogeneration operations.

In an effort to impede recovery and forensic analysis, the attackers also reset and reconfigured several Moxa devices, destroyed logs, and corrupted or reset the WAGO controller, Teltonika router, and FortiGate firewall used during the intrusion.

CERT Polska believes this incident represents the first documented real-world cyberattack where an attacker gained access to an OT network by moving laterally through a private APN. Subsequent surveys revealed that this type of network configuration was common in Poland at the time, and CERT Polska estimates similar arrangements are likely widespread internationally.

Recommendations from CERT Polska include treating private APNs as untrusted external networks, implementing isolation between connected clients, using allowlists for essential traffic between APN gateways and OT systems, and disabling exposed SSH and Telnet administration services.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.