LIVE · cybersecurity feed
Live wire
Fake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk
iranmedium

Iran-linked cyberattack shut down a UK power plant

A suspected Iran-linked cyberattack recently disrupted a small-scale UK power plant, causing it to shut down for four days. While the government confirmed the incident, it emphasized that the wider energy system remained unaffected and highly resilient. This event follows a series of similar cyber intrusions targeting water utilities in the United States, which cybersecurity analysts also suspect are linked to Iran.

zeroday.news ·

A small-scale power plant in the United Kingdom was shut down for four days due to a suspected cyberattack, which government officials confirmed on Monday. While the UK government has not formally attributed the incident, it is believed to be linked to Iran. Authorities emphasized that the wider energy system was never at risk, describing it as "highly resilient."

UK Energy Minister Michael Shanks stated that following the incident, his department briefed energy CEOs and provided additional security advice to companies. The specific power station affected was not disclosed by government officials.

This incident is believed to be the first disruptive Iranian cyberattack of its kind in the UK. It occurred around the same time as a series of digital intrusions targeting American water utilities across 12 states. In late July, suspected Iranian cyber operatives disrupted over 30 water facilities in Minnesota, with similar reports emerging from at least 11 other US states.

While US state and federal officials have not formally attributed these water system hacks, private-sector threat analysts strongly suspect Iran is responsible. These breaches are seen as a direct response to the ongoing conflict in the Middle East.

The American utility cyberattacks primarily involved internet-connected programmable logic controllers (PLCs). Federal agencies recently issued a warning that attackers are now employing AI-generated exploitation scripts to breach internet-exposed Siemens S7 Series PLCs in various critical facilities, including those in water, manufacturing, and energy sectors.

Experts suggest that this activity appears to be a continuation of the same pattern of Iran-affiliated actors targeting PLCs. These devices are fundamental to essential health, safety, and critical infrastructure across society, making them attractive targets for adversaries. The use of AI-generated scripts represents an active and evolving threat, not merely a theoretical risk.

irancyberattackpower plantcritical infrastructureplc
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.

gta 6high

Fake GTA 6 Extended Look and demo sites deliver an infostealer

Cybercriminals are exploiting the hype surrounding the upcoming Grand Theft Auto VI release by distributing fake demo websites that deliver an information-stealing malware. These sites impersonate Rockstar Games and trick users into downloading a malicious executable disguised as a game installer. The malware, identified as belonging to the Vidar family, is designed to steal passwords, session cookies, and other sensitive data from browsers and applications, potentially bypassing two-factor authentication through the reuse of stolen session tokens.

cloud

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions

breach

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

ransomware

Tricky 'SynkLoader' Multitool May Herald Ransomware

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

security

Your data doesn’t die when you do (Lock and Code S07E17)

This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.