LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
iranmedium

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.

zeroday.news ·

A power plant in the United Kingdom was reportedly shut down for four days by Iran-linked hackers, an incident described as the most successful cyberattack of its kind against UK energy infrastructure. The outage, which occurred concurrently with attacks on water infrastructure across 12 U.S. states, did not impact the UK's wider power supply due to the plant's small size.

British officials have not publicly identified the affected power plant, citing security concerns. Staff worked for four days to restore operations. Following the incident, the government issued guidance to power companies and businesses on how to respond to similar threats. The National Cyber Security Centre (NCSC), a division of GCHQ responsible for protecting UK critical infrastructure, was notified but declined to comment on the specific event.

The attack is believed to be the first confirmed instance of hackers affiliated with the Iranian regime successfully disabling a UK power facility. While the outage did not affect the broader grid, the likely intent behind the attack was to demonstrate the capability of Iran's Islamic Revolutionary Guard Corps-linked hackers to access and disrupt UK infrastructure at will. This four-day shutdown of a small generator, unnoticed by the general public, is considered a successful proof of concept from the attackers' perspective.

This incident follows a surge in suspected Iranian cyber operations targeting Western countries since February, coinciding with air strikes by the U.S. and Israel. Reports of such operations have emerged from Germany, Poland, Finland, Belgium, and Albania, with Israel and other Middle Eastern nations remaining frequent targets. In March, the NCSC advised British organizations to reassess their security posture in light of the escalating conflict. NCSC chief executive Richard Horne stated in June that the agency had addressed over 200 attacks on critical national infrastructure in the preceding year.

The timing of this attack is notable, given previous assessments of the UK's preparedness for cyber threats. Last year, the intelligence and security committee, which oversees UK spying agencies, deemed the likelihood of an Iranian cyberattack on British infrastructure as "unlikely." However, a Cabinet Office risk assessment published last month placed the probability of a serious and successful cyberattack on domestic infrastructure at between five and twenty-five percent. That same document also warned that artificial intelligence is making attacks faster, cheaper, and more accessible to a wider range of actors.

A government source downplayed the significance of the incident, stating that the affected site was "nowhere near" the threshold for important generators legally required to report cyber activity. The source characterized it as a "very small-scale site, less than a rounding error compared to grid capacity." A government spokesman reiterated that the UK possesses a robust and resilient energy system and that the incident never jeopardized the wider power network.

The concurrent U.S. water infrastructure attacks affected dozens of wastewater treatment plants across 12 states, leading to issues such as flooding and loss of water pressure, prompting boil water advisories in some areas. The initial reports surfaced from Minnesota on July 26, followed by similar breaches in Michigan, Georgia, South Dakota, and New Jersey. The FBI attributed these incidents to "malicious cyber actors," with U.S. government sources later confirming that the threat likely originated from Tehran.

irancyberattackukpower plantus water infrastructure
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assume

aihigh

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Researchers at Adversa AI have developed a novel attack called Cryptographic Context Injection, which bypasses AI safety filters by embedding malicious instructions within AES-encrypted payloads. This technique tricks AI models like xAI's Grok and Google's Gemini into decrypting and executing these hidden commands. In the case of Grok, the attack can lead to zero-click theft of user chat histories and personal data by disguising the malicious payload as a webpage summary request.

breach

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]