Critical

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Security Affairs
Actively Exploited

Overview

Iran-linked hackers successfully disabled a power plant in the UK for four days, marking a significant cyberattack on the country's energy sector. This incident is considered the first confirmed attack of its kind in the UK. The timing of the attack coincided with similar incidents targeting water infrastructure across 12 states in the United States, raising concerns about coordinated efforts by these hackers. The impact of such attacks on critical infrastructure is profound, as it not only disrupts services but also poses risks to public safety and national security. As countries increasingly rely on digital systems for essential services, the need for robust cybersecurity measures becomes even more urgent.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: UK power plant, US water infrastructure
  • Timeline: Newly disclosed

Original Article Summary

Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy […]

Impact

UK power plant, US water infrastructure

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Not specified

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Critical.

Related Coverage

When an Agent Fails: Incident Response for AI-Initiated Access Events

SCM feed for Latest

The article discusses the challenges faced by cybersecurity teams when responding to incidents initiated by artificial intelligence. It highlights how AI can create new vulnerabilities, leading to unauthorized access events that traditional security measures might miss. Businesses and organizations are advised to enhance their incident response strategies to account for these AI-driven scenarios, ensuring they can effectively detect and mitigate such threats. The focus is on developing a proactive approach to security that includes monitoring AI activities and implementing robust authentication processes. This is particularly important as AI continues to evolve and become more integrated into various systems.

Aug 23, 2026

Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

A new version of the malware known as ToxicPanda has been reported, now dubbed ToxicPanda 2.0. This upgraded malware is expanding its reach and has been detected in 16 different countries. Researchers have found that it specifically targets Android car head units, hijacking them for malicious purposes. This poses significant risks for drivers as it can compromise vehicle systems and potentially allow attackers to manipulate navigation and other functions. Users and manufacturers of affected devices need to be vigilant and implement security measures to protect against this evolving threat.

Aug 23, 2026

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Security Affairs

Researchers at Adversa AI have developed a new attack method called Cryptographic Context Injection, which allows attackers to bypass safety controls in AI systems. This technique involves sending encrypted instructions as AES-encrypted payloads that trick the AI into decrypting them within its own execution environment. As a result, attackers can potentially access complete chat histories from Grok, a conversational AI platform. This poses a significant risk to user privacy, as sensitive information could be leaked without any user interaction required. The discovery raises concerns about the security of AI systems and the effectiveness of current safety measures designed to protect user data.

Aug 23, 2026

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News

TikTok has agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice, which accused the company of breaching child privacy laws. The lawsuit claimed that TikTok collected personal information from minors without proper consent, violating federal regulations aimed at protecting children's online privacy. As part of the settlement, TikTok will pay $300 million upfront and an additional $100 million once a previous court order is lifted. This case emphasizes ongoing concerns about how social media platforms handle user data, especially when it comes to minors. The settlement could lead to stricter compliance measures for TikTok and other companies in the industry regarding child privacy protections.

Aug 22, 2026

Named Pipes Under Attack: Securing Windows Interprocess Communication

BleepingComputer

Windows named pipes, a method for fast communication between processes, have been identified as a potential security risk due to weak access controls. This vulnerability allows untrusted processes to potentially access privileged services, posing a threat to system integrity. Security experts from ThreatLocker recommend several strategies to mitigate these risks, including endpoint verification, command authorization, strict input validation, and limiting privileges to what is necessary. These measures can help secure named-pipe communications and protect against unauthorized access. Organizations using Windows systems should take these recommendations seriously to safeguard their environments from potential exploitation.

Aug 22, 2026

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

SecurityWeek

Recent reports have spotlighted three banking trojans: Manic, Grandoreiro, and ToxicPanda 2.0. Manic is a spyware variant that has been actively targeting users in Latin America and Europe. The Grandoreiro campaign continues to persist, affecting online banking users by stealing sensitive information. ToxicPanda 2.0 has expanded its capabilities, posing a significant risk to financial institutions and their customers. The presence of these trojans indicates a growing trend of sophisticated cyberattacks aimed at financial theft, making it crucial for users and businesses to remain vigilant and adopt stronger security measures.

Aug 22, 2026