Security Wire
A curated security and critical-infrastructure wire, filtered through an Irish and EU lens. It pulls a basket of security-news sources and surfaces the slice touching sovereignty-relevant infrastructure — energy, health, telecom and subsea cable, water, government, finance and transport — dropping the global firehose.
-
Global Telecom & Subsea
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which…
-
Global Government
FTC sues Hims & Hers for allegedly sharing patient information with third-party platforms
Popular telehealth provider Hims & Hers "shared consumers’ sensitive health information with third-party advertising platforms such as Meta and Snap despite promising to protect patient privacy," the federal government alleges.
-
Global Health
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. [...]
-
Global Energy & Grid
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
-
Global Water
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and…
-
Global Telecom & Subsea
Cyberattack hits Angola’s largest telco hours before landmark stock debut
Angola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.
-
Global Telecom & Subsea
2026 Minimum Elements for a Software Bill of Materials (SBOM)
CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM) , that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance…
-
Global Energy & Grid
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek .
-
Global Government
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
-
Global Finance
India’s Bank of Baroda confirms cyber incident after hackers claim data theft
An employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.
-
Global Health
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
-
Global Government
Outdated VPNs should be purged from federal agencies, senator says
Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government.
-
Global Government
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered.
-
Global Government
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it…
-
Global Finance
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more…
-
Global Government
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
-
Global Government
Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry
The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.
-
Global Transport & Ports
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws appeared first on SecurityWeek .
-
Global Energy & Grid
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]
-
Global Government
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access…
-
Global Energy & Grid
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
-
Global Health
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region…
-
Global Government
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian…
-
Global Energy & Grid
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek .
-
Global Transport & Ports
Swiss train maker Stadler refuses Everest $12 million ransomware demand
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform.
-
Global Finance
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
-
Global Government
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.
-
Global Government
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
-
Global Energy & Grid
Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
-
Global Government
French Parliament greenlights social media ban for under-15s
Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.
-
Global Transport & Ports
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]
-
Global Transport & Ports
Japanese food logistics giant recovers as extortion group claims cyberattack
Nichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.
-
Global Government
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]
-
Global Transport & Ports
Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. [...]
-
Global Government
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first on SecurityWeek .
-
Global Government
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender…
-
Global Telecom & Subsea
Taiwan to slow mobile data during national resilience drills
The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military exercises.
-
Global Energy & Grid
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity…
-
Global Energy & Grid
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence…
-
Global Energy & Grid
India says allegedly leaked nuclear plant files pose no safety risk
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.
-
Global Government
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over…
-
Global Government
Hackers were inside South Korea's diplomat training system for 9 months
Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs.
-
Global Transport & Ports
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the…
-
Global Energy & Grid
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain…
-
Global Health
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to…
-
Global Government
Hackers abuse ViPNet software to target Russian govt agencies
ViPNet software update mechanism exploited by threat actors to target Russian government agencies; no Irish or EU infrastructure impact reported.
-
Global Government
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
German naval defence firm TKMS targeted by ransomware; Lidl reports data breach affecting European retail operations.
-
Global Government
Zelensky appoints Ukraine's acting security service chief as acting defense minister
Ukraine's president appoints acting security service chief Yevhenii Khmara, an intelligence and counterterrorism specialist, as acting defense minister amid ongoing conflict.
-
Global Government
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
NATO and allied militaries accelerate autonomous weapons development through faster acquisition processes, raising questions about cybersecurity infrastructure's ability to secure rapidly deployed systems.
-
Global Transport & Ports
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia detained a Russian tourist on a U.S. extradition warrant for an alleged REvil ransomware operative; his lawyers claim authorities arrested the wrong person.
-
Global Government
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Newly discovered GoSerpent malware has targeted Southeast Asian government and diplomatic entities since late 2025 for espionage purposes, Kaspersky researchers reported.
-
Global Government
CISA urges immediate action on actively exploited Fortinet flaws
CISA ordered U.S. government agencies to urgently patch two actively exploited Fortinet FortiSandbox vulnerabilities affecting threat detection systems.
-
Global Government
Ukrainians rally against dismissal of tech-minded defense minister Fedorov
Ukrainian President Zelensky dismissed Defence Minister Mykhailo Fedorov, a technology advocate who promoted drone integration and digital innovation within the armed forces.
-
Global Government
20+ Hijacked Government Websites Became an Attack Channel
Over 20 Brazilian government websites were compromised and repurposed as malware distribution channels in an active PhantomEnigma campaign.
-
Global Government
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
China's military has begun restricting procurement from top domestic cybersecurity firms, though technical failures are not cited as the reason.
-
Global Government
Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities
Trump administration launches Gold Eagle, an AI-powered platform enabling industry and critical infrastructure operators to detect, prioritize and patch cybersecurity vulnerabilities faster.
-
Global Government
Trump’s DNI pick grilled about election security, voter fraud
Trump's director of national intelligence nominee Jay Clayton faced Senate questioning on election security and voter fraud claims during confirmation hearings.
-
Global Government
LAPD sidelines relationship with license-plate reader company Flock Safety
Los Angeles Police Department suspends use of Flock Safety's automatic license-plate readers, joining other U.S. municipalities reassessing the surveillance technology's deployment.
-
Global Energy & Grid
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
Siemens, Schneider Electric, and Rockwell Automation released patches for dozens of industrial control system vulnerabilities; CISA and German VDE CERT issued corresponding advisories.
-
Global Transport & Ports
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Russian state-backed actors are using hacked internet-connected cameras across Europe to surveil NATO logistics and Ukrainian military positions, Dutch intelligence agencies report.
Headlines, short summaries and links only — full articles remain with their publishers, and each item links back to the source. Aggregated automatically; classification is keyword-derived and may miss or mislabel. Independent, no images, no tracking.