CenterPoint Energy, a Texas-based utility provider, has confirmed a data breach following claims by an unnamed hacker of having stolen 7.49 million customer records. The company acknowledged the incident but did not immediately provide details on the scope or nature of the compromised data.
The confirmation from CenterPoint Energy comes amidst a broader landscape of cybersecurity incidents affecting critical infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Acronis Backup, Cisco ISE, Google Pixel, and Cisco Secure Email Gateway. These additions highlight ongoing threats to various systems, from enterprise solutions to mobile devices.
Other recent attacks include a supply-chain compromise targeting Brevo, which reportedly infected over 100,000 websites with WordPress backdoors and Clickfix malware. Separately, the Gyazo image-sharing service experienced a data breach exposing 23 million user records. Financial institutions have also been targeted, with Revolut reporting a data leak potentially linked to compromised Italian government accounts.
Malware developments continue to pose significant risks. Researchers have identified "RatHat," a new AI-powered mobile threat that leverages Android accessibility features to target credentials and bank accounts. Another notable discovery is "BambooToken," malware that utilizes the MQTT protocol to evade detection. Additionally, the "SilkParasite" infrastructure has been linked to the "SpiceRAT" malware, which has been observed targeting energy and government entities across Central Asia.
The threat landscape also includes state-sponsored activities, such as "Chosen Brick," identified as Iranian surveillance malware. Iranian cyber operations have also been noted for targeting dissidents, activists, and journalists.
In response to these evolving threats, security researchers are developing new detection methods. These include "Delphi Scanner" for static malware detection via API sequence modeling, "ALIBI" for adversarial legitimacy injection against large language model (LLM) malware analyzers, and frameworks for metamorphic malware detection and uncertainty-aware zero-day botnet detection for IoT networks.
Law enforcement efforts are also underway, with the "NightmareStresser" DDoS-for-hire service recently taken offline as part of a global crackdown. Despite these efforts, the continuous emergence of new vulnerabilities and sophisticated attack techniques underscores the persistent challenges in cybersecurity.





