Critical

New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

The Hacker News

Overview

In late December 2025, the Russian hacking group Sandworm attempted a significant cyber attack on Poland's power sector, described by officials as the largest of its kind targeting the country's energy infrastructure. The attack involved a new type of malware called DynoWiper, which was designed to disrupt power operations. Fortunately, the attack was thwarted, and Poland's energy minister, Milosz Motyka, confirmed that the country's cyberspace forces detected and responded to the threat in time. This incident emphasizes the ongoing risks facing critical infrastructure from state-sponsored actors and highlights the importance of robust cybersecurity measures in protecting essential services. As cyber threats continue to evolve, organizations must remain vigilant to safeguard against potential disruptions.

Key Takeaways

  • Affected Systems: Poland's power sector
  • Timeline: Ongoing since the last week of December 2025

Original Article Summary

The Russian nation-state hacking group known as Sandworm has been attributed to what has been described as the "largest cyber attack" targeting Poland's power system in the last week of December 2025. The attack was unsuccessful, the country's energy minister, Milosz Motyka, said last week. "The command of the cyberspace forces has diagnosed in the last days of the year the strongest attack on

Impact

Poland's power sector

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Ongoing since the last week of December 2025

Remediation

Not specified

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware, Critical.

Related Coverage

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News

The Iranian hacking group known as Nimbus Manticore has been linked to two new types of malware that can affect both Linux and macOS systems. These malware families are remote access trojans (RATs) created using Node.js and JavaScript, allowing attackers to gain control over infected devices. Researchers from Kaspersky noted that the group is using a clever tactic of posing as recruiters to deliver malicious code through fake coding tests. This development is concerning as it expands the group's targeting capabilities and indicates a shift in their methods. Users and organizations using Linux or macOS systems should be vigilant and consider enhancing their security measures to prevent potential infections.

Sep 1, 2026

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News

METR, a non-profit focused on evaluating artificial intelligence models, reported that attackers stole an API key and used it to consume AI credits worth approximately $600,000. The organization experienced two significant security incidents aimed at unauthorized access to its systems. Fortunately, METR stated that no sensitive information was compromised during these events. This incident not only impacts METR's financial resources but also raises concerns about the security of AI-related infrastructure, highlighting the vulnerabilities that organizations in this space may face. As AI technology continues to evolve, ensuring robust security measures is crucial to prevent similar incidents in the future.

Sep 1, 2026

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News

Researchers have identified a new technique called GuardBreaker, employed by a Russia-aligned hacker group known as UAC-0099. This group targeted an entity in Ukraine with the goal of disrupting artificial intelligence systems, specifically by triggering safety mechanisms in large language models (LLMs). By doing so, they aim to manipulate AI-assisted analysis, potentially leading to misinformation or faulty decision-making. This incident underscores the growing intersection of cybersecurity and AI, raising concerns about the effectiveness of AI technologies in secure environments. The implications could extend beyond Ukraine, affecting how organizations worldwide integrate AI into their operations.

Sep 1, 2026

Recently patched PaperCut zero-days used in data theft attacks

BleepingComputer

Two recently patched vulnerabilities in the PaperCut NG and MF print management software are now being exploited in data theft attacks. These flaws were initially discovered and addressed last week, but attackers have quickly adapted to use them for unauthorized access to sensitive data. Organizations that rely on PaperCut for managing printing services should be particularly vigilant, as these vulnerabilities could lead to serious data breaches if not properly mitigated. Users are urged to apply the latest security updates immediately to protect their systems from potential exploitation. This situation serves as a reminder of the importance of timely patch management in cybersecurity.

Sep 1, 2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News

Recent research by VulnCheck has revealed that attackers are exploiting two serious vulnerabilities in Langflow and Ruby on Rails. The first vulnerability, CVE-2026-0768, has a CVSS score of 9.8 and allows attackers to execute arbitrary Python code as the root user due to inadequate validation of user input. The second vulnerability, CVE-2026-66066, also poses a significant risk, although specific details were not provided in the report. These flaws could lead to unauthorized access and control over affected systems, making it crucial for organizations using these platforms to take immediate action. Companies and developers should prioritize patching these vulnerabilities to safeguard their applications and data.

Sep 1, 2026

PaperCut Exploitation Escalates to Active Intrusions

SecurityWeek

CISA has flagged two vulnerabilities in PaperCut, identified as CVE-2026-82078 and CVE-2026-81578, which are now being actively exploited. These vulnerabilities have the potential to allow attackers to gain unauthorized access to systems using PaperCut, a popular print management software used by organizations worldwide. This escalation of exploitation means that users of PaperCut should be particularly vigilant about securing their systems. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, signaling the urgency for organizations to take action. Companies relying on PaperCut need to assess their installations and apply any available security patches to mitigate the risk of intrusions.

Sep 1, 2026