LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.

zeroday.news ·

Polish cybersecurity authorities have disclosed a previously unacknowledged cyberattack that impacted a combined heat and power plant last winter, coinciding with a period of severe cold. This incident occurred on the same day in December as a series of coordinated cyberattacks that targeted over 30 other renewable energy installations and a larger heat plant, which Poland publicly acknowledged in January. The earlier attacks were described by a senior minister as having nearly caused a blackout for approximately 500,000 people.

While the broader wave of attacks was formally attributed to Russia’s Federal Security Service in July, CERT Polska, the national computer emergency response team, did not attribute the newly revealed attack. This incident affected a smaller combined heat and power plant that supplies heat to about 50,000 residents. According to Marcin Dudek, head of CERT Polska, the attack went unrecognized as a cyberattack at the time.

Dudek, speaking at the DEF CON cybersecurity conference in Las Vegas, explained that the incident took place during routine maintenance over the Christmas period. Plant operators initially attributed the shutdown of the steam turbine and water treatment system to a contractor error, rather than malicious activity. The disruption was contained quickly, preventing any interruption to customer heating, and was initially reported only for informational purposes. However, due to its timing relative to the other attacks, CERT Polska initiated a comprehensive investigation into the low-priority report.

The investigation, which spanned over three months, uncovered what CERT Polska described as the first known instance of a private cellular data network being used as an ingress point into an industrial control system. The agency highlighted the importance of reporting not only confirmed incidents but also unexplained failures and operational disruptions, contrasting this with the more limited reporting requirements under the European Union’s NIS2 law.

In the newly revealed incident, attackers leveraged firewalls that had already been compromised at wind farm substations. From there, they accessed a cellular router connected to one of these private networks. They then used this router to pivot to a controller at the heat plant that was still configured with factory-default login credentials. This allowed the hackers to establish a tunnel into the plant’s industrial control systems. The attack chain involved movement across facilities—from a wind farm to the cellular network and then to the heat plant—that had no direct operational relationship beyond their shared presence on the same private network.

Once inside the heat plant, the attackers conducted reconnaissance for 11 days. They probed industrial equipment, tested credentials against the plant’s firewall, and connected to controllers on Christmas Day to map their targets. Before dawn on December 29, they disabled the Siemens controllers managing the steam turbine and water treatment system. They then locked operators out of these controllers by setting new passwords. The hackers subsequently used automated scripts to wipe the configurations of network equipment and set device addresses to unreachable values to impede recovery efforts.

Plant staff began restoring systems approximately two hours later, even while the attackers were still active, successfully limiting the disruption to a brief outage. The attackers then attempted to destroy forensic evidence along their entire path, corrupting the device used as a gateway into the plant beyond repair and resetting the firewalls and routers behind them. Investigators were only able to reconstruct the attack because one router was running older software that preserved its event logs through a factory reset.

CERT Polska issued a warning that the network misconfiguration enabling the attack—allowing any device on a private cellular network to communicate freely with any other—was prevalent across Poland at the time and is believed to be widespread internationally. The agency is urging energy operators to cease treating private cellular networks as inherently trusted infrastructure and instead apply the same security controls used for internet-facing connections. It called for immediate audits of network configurations, the removal of default passwords from connected devices, and the inclusion of these networks in security testing programs.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

security

UK man tied to The Com sentenced for abusing 117 victims

Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

security

Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

Cisco is proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

breach

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to custome

breach

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses,