This week

- Small UK power plant offline for 4 days last month following cyber-attack
- AI firms promise better segregation, monitoring, in response to rogue models
- Copilot helpfully told researchers how to hack it
- 3.7M people affected by US electronic health records breach
- Poor expiry date checks may allow ‘zombie card’ contactless payments
Interesting stats
$100 at the lower end, up to $1 million at the top end offered by Medusa ransomware gang for access to 200 victims’ networks last year. (see link in story below).
73% of ransomware attacks between 2023 and mid-2026 were against medium-sized businesses ($10M-$1B revenues), with 25% of those victims being in the manufacturing sector, according to analysis of 13,336 ransomware attacks by Black Kite
$3.4 billion is the estimated financial value of intellectual property stolen by Iranian cyber operations, across 31.5 terabytes of stolen data from 243+ organisations since 2013, according to DOJ charges against Iranian individuals.
9,300 AWS access keys exposed between August 2022 and August 2026 are still active and valid, according to Truffle Security, with 242 of those keys were associated with IAM users that have an AdministratorAccess policy, granting full access to the associated Amazon tenant.
Five things
-
The Telegraph reports that Iranian-affiliated attackers compromised and caused the shutdown of a small UK power plant last month. The plant was offline for four days while the incident was investigated and remediated. Small plants like this are typically used to generate electricity during peak periods, rather than to satisfy base-load demands. Hundreds of them exist across the UK, and they can be entirely automated, firing up in response to signals from grid operators to balance the grid. “In response to this specific incident, the NCSC and Department for Energy Security and Net Zero briefed energy CEOs and directly wrote to companies with advice, direction and next steps,” the government told the FT. The timing of the incident coincides with the Iranian-linked attacks against US water companies. Potentially, there’s overlap between the type of SCADA system and programmable logic controllers in the user, and this is collateral damage from a poorly targeted attack.
-
Irregular, the AI testing outfit responsible for running the unreleased versions of Anthropic and OpenAI’s models, says “human oversight” led to the models having access to the internet and failing to run background checks to ensure test names didn’t match real-world organisations. The unsigned blog post (take some accountability, folks) says the firm is “putting in place new and robust protocols” and will release a whitepaper about the incidents and its lessons learned. OpenAI has announced new security policies to contain models during testing. Unsurprisingly, this includes network segregation and better monitoring. Both of which should have been in place and verified already, frankly, though if you’re wondering why it wasn’t previously, OpenAI added that this would “require meaningful compute,” estimating the overhead at “roughly 20 percent of the inference compute being monitored”. That’s way more than typical security monitoring costs, potentially by an order of magnitude. NCSC has also published some sensible steps for frontier labs, or anyone else testing novel AI models, to follow.
-
Security researchers from Varonis were able to get Microsoft Copilot to ‘hack itself’ and explain to them how to have the AI chatbot automatically execute prompts without user interaction. Microsoft has addressed the issue. Still, it would allow attackers to exfiltrate data from the user’s context if they clicked on a Copilot link with a prompt asking Copilot to, for example, summarise recent email and call a specific website.
-
US healthcare technology provider CareCloud has told regulators that the personal data of 3,756,469 people was stolen after an attacker gained access to one of its electronic health record systems. The data includes personal, ID, payment, medical, and insurance data — quite the haul for the attackers.
-
Some interesting research out of University of Massachusetts Amherst that has found you can get payments out of some expired contactless credit cards. While you would think how an expiry date is checked would be pretty standard, the process isn’t, the data may not be encrypted leaving it open to proximate attacker-in-the-middle, and enforcement isn’t consistent either, meaning some can be turned into ‘zombie cards’. Paper (PDF).
In brief
-
Two Berlin state ministries have been segregated from the main Berlin State Network as a precaution following a compromise by cybercriminals.
-
It’s 2026 and exposed S3 buckets are still a thing: a reverse-image people search tool exposed an estimated 9 million images totalling 450GB. The bucket belongs to ClarityCheck, which promises a “private and secure” search that can “identify anyone in a photo” and their social profiles “in seconds”. I suspect most of the people in the images have no idea their likeness has been uploaded. After all, how many people need to use reverse-lookup services to find people they know?
-
Investment firm Apollo has confirmed a ShinyHunters-sounding breach after attackers used social engineering to gain access to a cloud system and steal personal data. It’s not known if the affected individuals are employees, investors, or other contacts of the private equity firm, which has around 5,000 staff and just under $1 billion in assets under management.
-
New reporting says that T-Mobile ‘chopped a cable’ in response to a 2024 compromise of its systems by the Chinese Salt Typhoon group.
-
CISA has published an advisory on the Medusa ransomware gang, outlining how the group chooses to pay $100-$1M to so-called Initial Access Brokers to sell them access to pre-compromised networks, rather than trying to exploit vulnerabilities.
-
Citrix says that customers should immediately patch two vulnerabilities in its NetScaler Gateway and ADC solutions. The most severe is an authentication bypass in… well, it’s product used to authenticate and govern remote access. Not ideal. (CVE-2026-19490; 8.8/10; advisory).
-
Cisco has patched a bunch of critical vulnerabilities, including five ‘perfect 10s’ in its Crosswork and Secure Workload solutions. (CVE-2026-lots… Advisories: Crosswork, Secure Workload).
And finally
- Reminder that Windows Server 2022 reaches end of mainstream support on 13 October 2026 (<60 days). Microsoft has promised to continue providing security updates for the operating system at no extra cost through 2031, allowing organisations to meet compliance requirements, such as Cyber Essentials, and run supported software.