The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator (DSO), the company running the local electricity grid, sets up with a mobile carrier. The incident happened on the same day as coordinated attacks against Poland's energy sector that affected 30 facilities. READ MORE...
North Korean government snoops are operating LLMs locally and collecting technology to weave AI into their attack operations, according to South Korean security firm Genians. The researchers said they observed Kimsuky setting up and operating local LLM environments using Ollama, GPT4All, and Msty, experimenting with other AI tools such as Cursor, and using retrieval-augmented generation (RAG) for local document searches. READ MORE...
New research once again demonstrates the need strong identity governance and operational guardrails around AI agents to protect against hijacking attacks that leverage their legitimate access and privileges against their very users. At a DEF CON 34 session this week, Tenet Security demonstrated how attackers can poison content in trusted systems such as security alerts, logs, and error reports. READ MORE...
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industrial organizations in the second quarter of 2026, up 12% from 1,020 in Q1. The figures come from publicly disclosed victim data and posts made by ransomware groups on their data leak sites. READ MORE...
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. Compared with the first quarter, when the company recorded just 130 attacks above 1 Tbps, the latest figure represents a more than fivefold increase. Cloudflare is a major web infrastructure and security firm that provides CDN, DNS, reverse-proxy, and DDoS protection services to customers worldwide, protecting roughly 20% of the web. READ MORE...
A website built to look almost exactly like CNN's homepage is telling visitors to download "the new CNN app." But it's not CNN's app, and has nothing to do with the news company. The campaign doesn't stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that's already linked to the attacker's account. READ MORE...
A Chrome extension that Google pulled from its store in January 2026 over conversation-theft allegations is back in circulation and reaching enterprise browsers again through Google's own CRX distribution infrastructure, according to Netskope Threat Labs. The extension is named 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' and is advertised as an AI assistant for Chrome. OX Security flagged it for scraping ChatGPT and DeepSeek conversation content and sending it to external domains. READ MORE...
U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers' tools to target government and critical infrastructure organizations. Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and construction, media, retail, transportation and utilities. READ MORE...
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business analytics, disclosed last week that its Metabase Cloud platform had been compromised by an attacker wielding a zero-day vulnerability that impacts versions 1.58 of the platform and above. READ MORE...
Researchers have found that a malicious SIM card can tell some phones and cellular-connected devices to leak data, drop to 2G, shut themselves down, or even execute code, all thanks to functionality that's supposed to be there. The research [PDF], presented at the USENIX WOOT conference in Baltimore this week, examines proactive SIM functionality, which allows a SIM to issue commands to the device hosting it. READ MORE...
Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. READ MORE...