Critical

Sandworm group linked to major attempted cyberattack on Poland's power system

SCM feed for Latest
Actively Exploited

Overview

On December 29, 2025, the Sandworm hacking group attempted a cyberattack on Poland's power infrastructure, deploying a new wiper malware called DynoWiper. This malware is designed to erase data and disrupt operations, posing a significant threat to critical systems. ESET, the cybersecurity firm that reported the incident, noted that the attack could have serious implications for power stability and national security in Poland. As the incident unfolds, it raises concerns about the vulnerabilities in power grids and the potential for similar attacks on other nations. The situation underscores the ongoing risks posed by state-sponsored cyber activities.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Poland's power system
  • Timeline: Newly disclosed

Original Article Summary

The cybersecurity firm ESET reported that Sandworm deployed a new, undocumented wiper malware named DynoWiper in the attempted disruptive attack on December 29, 2025.

Impact

Poland's power system

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Not specified

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware, Critical.

Related Coverage

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News

The Iranian hacking group known as Nimbus Manticore has been linked to two new types of malware that can affect both Linux and macOS systems. These malware families are remote access trojans (RATs) created using Node.js and JavaScript, allowing attackers to gain control over infected devices. Researchers from Kaspersky noted that the group is using a clever tactic of posing as recruiters to deliver malicious code through fake coding tests. This development is concerning as it expands the group's targeting capabilities and indicates a shift in their methods. Users and organizations using Linux or macOS systems should be vigilant and consider enhancing their security measures to prevent potential infections.

Sep 1, 2026

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News

METR, a non-profit focused on evaluating artificial intelligence models, reported that attackers stole an API key and used it to consume AI credits worth approximately $600,000. The organization experienced two significant security incidents aimed at unauthorized access to its systems. Fortunately, METR stated that no sensitive information was compromised during these events. This incident not only impacts METR's financial resources but also raises concerns about the security of AI-related infrastructure, highlighting the vulnerabilities that organizations in this space may face. As AI technology continues to evolve, ensuring robust security measures is crucial to prevent similar incidents in the future.

Sep 1, 2026

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News

Researchers have identified a new technique called GuardBreaker, employed by a Russia-aligned hacker group known as UAC-0099. This group targeted an entity in Ukraine with the goal of disrupting artificial intelligence systems, specifically by triggering safety mechanisms in large language models (LLMs). By doing so, they aim to manipulate AI-assisted analysis, potentially leading to misinformation or faulty decision-making. This incident underscores the growing intersection of cybersecurity and AI, raising concerns about the effectiveness of AI technologies in secure environments. The implications could extend beyond Ukraine, affecting how organizations worldwide integrate AI into their operations.

Sep 1, 2026

Recently patched PaperCut zero-days used in data theft attacks

BleepingComputer

Two recently patched vulnerabilities in the PaperCut NG and MF print management software are now being exploited in data theft attacks. These flaws were initially discovered and addressed last week, but attackers have quickly adapted to use them for unauthorized access to sensitive data. Organizations that rely on PaperCut for managing printing services should be particularly vigilant, as these vulnerabilities could lead to serious data breaches if not properly mitigated. Users are urged to apply the latest security updates immediately to protect their systems from potential exploitation. This situation serves as a reminder of the importance of timely patch management in cybersecurity.

Sep 1, 2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News

Recent research by VulnCheck has revealed that attackers are exploiting two serious vulnerabilities in Langflow and Ruby on Rails. The first vulnerability, CVE-2026-0768, has a CVSS score of 9.8 and allows attackers to execute arbitrary Python code as the root user due to inadequate validation of user input. The second vulnerability, CVE-2026-66066, also poses a significant risk, although specific details were not provided in the report. These flaws could lead to unauthorized access and control over affected systems, making it crucial for organizations using these platforms to take immediate action. Companies and developers should prioritize patching these vulnerabilities to safeguard their applications and data.

Sep 1, 2026

PaperCut Exploitation Escalates to Active Intrusions

SecurityWeek

CISA has flagged two vulnerabilities in PaperCut, identified as CVE-2026-82078 and CVE-2026-81578, which are now being actively exploited. These vulnerabilities have the potential to allow attackers to gain unauthorized access to systems using PaperCut, a popular print management software used by organizations worldwide. This escalation of exploitation means that users of PaperCut should be particularly vigilant about securing their systems. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, signaling the urgency for organizations to take action. Companies relying on PaperCut need to assess their installations and apply any available security patches to mitigate the risk of intrusions.

Sep 1, 2026