Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy

Researchers in China have identified a novel cyber-physical vulnerability, dubbed Bit2Watt, that could allow malicious cloud tenants to destabilize data centers and the broader electrical grid by manipulating GPU workloads. The attack, detailed in a preprint paper by Zhouhao Ji, Kaikai Pan, and Wenyuan Xu from Zhejiang University, highlights a potential pathway for adversaries to cause blackouts or damage equipment by exploiting the power demands of artificial intelligence (AI) training.
The core of the Bit2Watt attack involves a malicious actor masquerading as a legitimate cloud customer to launch specially crafted GPU workloads. These workloads are designed to induce rapid and significant power fluctuations within data centers. While AI training workloads are known to cause power swings, the researchers demonstrated that malicious GPU loads can achieve modulation frequencies exceeding 6,000 Hz, significantly higher than the few hertz observed in typical household loads. Such high-frequency modulations can lead to substantial voltage excursions, harmonic distortion, and damping degradation in the power system.
The researchers claim that an attack employing 1,000 GPUs on a 1-megawatt local power grid, particularly one reliant on distributed energy resources like photovoltaics, could generate a total harmonic distortion of 46.8 percent. This level of distortion would result in nearly half the electrical current being wasted on non-productive work and an approximate 20 percent increase in heat generation. Furthermore, the attack could produce a negative damping ratio of -0.27, introducing instability into the system. The authors warn that if protective measures are triggered and computing loads are shed, it could initiate cascading failures, potentially leading to blackouts affecting over 80 percent of large-scale power systems.
The attack is described as covert because it operates within authorized workload execution paths, making it difficult for current cloud provider monitoring frameworks to detect. The researchers emphasize the need for infrastructure providers to implement coordinated defenses across both cyber and physical layers, specifically looking for malicious computation patterns. They also recommend the use of local energy buffering systems to manage power demand spikes.
The findings align with observations from major technology companies regarding the power challenges posed by AI training. Microsoft, Nvidia, and OpenAI noted in a 2025 research paper that the transition between GPU computation and data synchronization causes large power swings. They cautioned that if the frequency spectrum of these swings harmonizes with critical utility frequencies, it could physically damage power grid infrastructure. Similarly, Meta's paper on training Llama 3 cited the risk of tens of thousands of GPUs simultaneously increasing or decreasing power consumption, leading to instantaneous fluctuations of tens of megawatts that can strain the power grid.
Beyond causing direct grid instability, the Bit2Watt research also points to a potential side-channel attack called Watt2Bit. The electrical and thermal stress induced by malicious workloads could create denial-of-service events and enable the covert exfiltration of data through power modulation. As a proof of concept, the researchers demonstrated the recovery of a 50-bit test sequence using frequency-shift keying (FSK) encoding.
The researchers conclude that the convergence of power and computing infrastructures necessitates a fundamental shift in security approaches. They advocate for coordinated defenses that comprehensively consider workload behavior, power electronics, and grid dynamics to address these emerging threats.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets