Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.

A power plant in the United Kingdom was reportedly shut down for four days by Iran-linked hackers, an incident described as the most successful cyberattack of its kind against UK energy infrastructure. The outage, which occurred concurrently with attacks on water infrastructure across 12 U.S. states, did not impact the UK's wider power supply due to the plant's small size.
British officials have not publicly identified the affected power plant, citing security concerns. Staff worked for four days to restore operations. Following the incident, the government issued guidance to power companies and businesses on how to respond to similar threats. The National Cyber Security Centre (NCSC), a division of GCHQ responsible for protecting UK critical infrastructure, was notified but declined to comment on the specific event.
The attack is believed to be the first confirmed instance of hackers affiliated with the Iranian regime successfully disabling a UK power facility. While the outage did not affect the broader grid, the likely intent behind the attack was to demonstrate the capability of Iran's Islamic Revolutionary Guard Corps-linked hackers to access and disrupt UK infrastructure at will. This four-day shutdown of a small generator, unnoticed by the general public, is considered a successful proof of concept from the attackers' perspective.
This incident follows a surge in suspected Iranian cyber operations targeting Western countries since February, coinciding with air strikes by the U.S. and Israel. Reports of such operations have emerged from Germany, Poland, Finland, Belgium, and Albania, with Israel and other Middle Eastern nations remaining frequent targets. In March, the NCSC advised British organizations to reassess their security posture in light of the escalating conflict. NCSC chief executive Richard Horne stated in June that the agency had addressed over 200 attacks on critical national infrastructure in the preceding year.
The timing of this attack is notable, given previous assessments of the UK's preparedness for cyber threats. Last year, the intelligence and security committee, which oversees UK spying agencies, deemed the likelihood of an Iranian cyberattack on British infrastructure as "unlikely." However, a Cabinet Office risk assessment published last month placed the probability of a serious and successful cyberattack on domestic infrastructure at between five and twenty-five percent. That same document also warned that artificial intelligence is making attacks faster, cheaper, and more accessible to a wider range of actors.
A government source downplayed the significance of the incident, stating that the affected site was "nowhere near" the threshold for important generators legally required to report cyber activity. The source characterized it as a "very small-scale site, less than a rounding error compared to grid capacity." A government spokesman reiterated that the UK possesses a robust and resilient energy system and that the incident never jeopardized the wider power network.
The concurrent U.S. water infrastructure attacks affected dozens of wastewater treatment plants across 12 states, leading to issues such as flooding and loss of water pressure, prompting boil water advisories in some areas. The initial reports surfaced from Minnesota on July 26, followed by similar breaches in Michigan, Georgia, South Dakota, and New Jersey. The FBI attributed these incidents to "malicious cyber actors," with U.S. government sources later confirming that the threat likely originated from Tehran.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed