This week

- Default creds used in Polish power grid attack
- CISA chief accidentally uploaded sensitive docs to ChatGPT
- 100 Orgs targeted in latest ShinyHunters campaign
- Calls for UK offensive cyber investment
- MoltBot security considerations abound
Interesting stats
31.4 Tbps record DDoS attack, according to Cloudflare, from the Aisuru/Kimwolf botnet
(<)1/1,000 conversations with Claude.ai had potential for “severe forms of disempowerment” of the human user, according to analysis of harm by Anthropic (paper (PDF)) … 0.1% strikes me as a pretty high rate for human harm at the hands of AI.
Five things
-
Poland power grid: Poland’s Computer Emergency Response Team has published a technical report (PDF) from its investigation into an attack against the country’s grid at the end of 2025, attributed to Russia’s Sandworm government hackers. The remarkably speedy investigation may be a product of the ease with which Russia’s Sandworm group gained access: default usernames, passwords, and no multi-factor authentication. The attackers also deployed wiper malware — a common Russian tactic — in an attempt to disable and destroy the ability to manage and operate the infrastructure. A combined heat-and-power plant, along with wind and solar farms, was targeted. Defenders prevented the wiper attack at the CHP plant, but it was successful against the renewable generation sites. At least 12 affected sites have been confirmed, though OT cyber outfit Dragos says the number is approximately 30. The disruption, amounting to 1.2GW, or 5% of Poland’s energy supply, didn’t disrupt the overall grid.
-
CISA: The acting director of CISA, Madhu Gottumukkala, triggered alarms at his agency when he accidentally uploaded sensitive files to the public version of ChatGPT. While none of the documents were classified, they were marked “for official use,” and access to ChatGPT itself was restricted: Gottumukkala had requested special access for himself upon arrival at the agency. The public version of ChatGPT may use user input to train the model. Other conflicts mark his time at the helm of America’s cyber agency, leaving many feeling he doesn’t have widespread support from the organisation, which is struggling following significant layoffs in the last 12 months.
-
ShinyHunters has targeted ~100 organisations in its latest campaign. The cybercriminal group, known for its social engineering, set its sights on Okta single sign-on accounts at “high-value enterprises”. Some of these may have resulted in incidents (see below). The campaign appears to use a new vishing (voice phishing) kit, in which attackers guide the victim to a web page they control and can manipulate to display, for example, the correct form of multi-factor authentication the user expects. Phishing-resistant forms of MFA — think FIDO2 YubiKeys or passkeys — are the solution to this problem, rather than one-time codes.
-
Offence is the best defence? Former national security advisor and member of the Joint Committee on the National Security Strategy, Lord Sedwill, warned a parliamentary hearing that the UK needs offensive capability to act as a deterrence in cyber and hybrid conflicts. Sedwill says, “There needs to be essentially an offensive element to deterrence, as well as simply a defensive element”. The argument is that many cyber intrusions or attacks (for example, see Poland’s power grid above) do not elicit the same response as a physical or kinetic attack would, and that adversaries are exploiting this to inflict “strategically consequential effects,” according to NATO allies. Europe’s cyber agency, ENISA, describes a “loophole” created by not investing in cyber security, while telling Politico, “We just don’t need an upgrade. We need a rethink,” he said. “Doubling the capacity is the absolute minimum.”
-
MoltBot (neé ClawdBot): An open source, locally hosted “AI personal assistant” has exploded in popularity in 2026. Originally known as ClawdBot, MoltBot allows users to hook up a personal AI to their preferred messaging channel, like WhatsApp, Discord, or Teams, and have it carry out actions on their devices, like replying to emails, managing calendars, and other ‘skills’ that you can plug into the system. Beyond concerns about handing over credentials for all your accounts, there are specific threats to be aware of. Firstly, as with most AI automation, is the prospect of prompt injection due to the shared control/content channel, from emails, invites, or other inputs, or straight up poor configurations or missing authentication. Another is not unique to AI, but the unforeseen or unexpected threat vectors from fast-moving, growing technology projects. This week saw researchers demo a proof-of-concept exploiting the supply chain of a popular ‘skill’ on a package management platform. Typosquatting skills wouldn’t surprise me either, something still affecting many more mature ecosystems, let alone ones facing such meteoric rises. Mature security functions are rarely baked into projects in less than a month.
In brief
-
⚠️ Incidents: Nike says it’s investigating the possible theft of 1.4TB of data by the WorldLeaks cybercriminal gang. TikTok’s new owners say outages over their first week of ownership were caused by a power outage at their data centre. Have I Been Pwned says 29.8 million SoundCloud accounts appear to have been compromised; ShinyHunters are claiming responsibility. Match Group, the company behind dating platforms Tinder, Hinge and OKCupid, is investigating a “recently identified security incident” believed to be the theft of 10 million records, also claimed by ShinyHunters. The Vladimir Bread Factory east of Moscow has suffered a cyberattack that has disrupted food deliveries after IT systems used to arrange transport were taken offline (production was not affected).
-
🕵️ Threat Intel: Microsoft PowerBI is being abused to send scam emails from
[email protected], an address Microsoft encourages customers to allowlist; the mails are sent as part of a notification that the recipient has been added to a Power BI dashboard. CrowdStrike says that North Korea’s Labyrinth Chollima has split into three different groups with distinct missions: Labyrinth Chollima focuses on defence and aerospace espionage, while spin-offs Golden Chollima and Pressure Chollima focus on stealing cryptocurrency (report). -
🪲 Vulnerabilities: WinRAR patched a high-severity path traversal vulnerability (CVE-2025-8088; 8.4/10; advisory) in July last year, however, it’s recently seen exploitation by nation-state and cybercriminal groups. SolarWinds is warning of two critical vulnerabilities (CVE-2025-50552 & CVE-2025-50554; both 9.8; advisory) that allow authentication bypass and remote code execution in its Web Help Desk IT solution. Fortinet customers can’t catch a breather: the firm is warning of yet another authentication bypass vulnerability in its FortiCloud solution (CVE-2026-24858; 9.4/10; advisory). Researchers have discovered two sandbox escape vulnerabilities in open source automation platform n8n (CVE-2026-1470 & CVE-2026-0863; 9.9 & 8.5/10; info). Ivanti’s Endpoint Manager Mobile (EPMM) product has received patches for two actively exploited unauthenticated RCE vulns (CVE-2026-1281 & CVE-2026-1340; both 9.8/10; advisory).
-
🧑💻 End user and consumer: WhatsApp has released Strict Account Settings, a lockdown mode style feature aimed to protect at-risk users from spyware.
-
🧿 Privacy: Apple has introduced a feature that limits cellular geolocation of its latest iPhone models by telcos, law enforcement, spies, and criminals.
-
📜 Policy & Regulation: Japan and the UK have agreed to accelerate cooperation on cybersecurity amidst a flying visit by British Prime Minister Kier Starmer.
-
👮 Law Enforcement: The DOJ has charged 31 people suspected of stealing $5.4 million from 63 ATMs between February 2024 and December 2025 using the ‘Ploutus’ malware. The FBI has seized RAMP; the Russian cybercrime forum is popular with ransomware gangs and initial access brokers.
-
💰 Investments, mergers and acquisitions: Dallas-based MSP LevelBlue is acquiring AlertLogic from Fortra as the latter seeks to split out its software and services businesses.
-
🗞️ Industry news: Darktrace CEO Jill Popelka has stepped down from the post she’s held since September 2024; chair Charles Goodman is filling in temporarily while a permanent replacement is appointed. Two penetration testers have received a $600,000 settlement for a wrongful arrest and defamation suit. Gary DeMercurio and Justin Wynn were arrested in 2019 (vol. 2, iss. 38) while conducting a physical test by local Sheriff Chad Leonard, despite the test being authorised by the Iowa Judicial Branch, and the pair producing a letter showing as much at the time of their detention.
And finally
- Scam compounds: The remarkable story of day-to-day life for enslaved works in a Southeast Asian scam compound. These financial losses and the human cost of these organised criminal enterprises are massive. The conditions, team structures, call scripts, use of AI, and more come from a trove of information, totalling 4,200 pages, supplied to WIRED by a whistleblower. The conditions, team structures, call scripts, use of AI, and more come from a trove of information, totalling 4,200 pages, supplied to WIRED by a whistleblower. It’s well worth your time.