Security Wire
A curated security and critical-infrastructure wire, filtered through an Irish and EU lens. It pulls a basket of security-news sources and surfaces the slice touching sovereignty-relevant infrastructure — energy, health, telecom and subsea cable, water, government, finance and transport — dropping the global firehose.
-
Global Energy & Grid
Microsoft PowerToys adds Alt+Tab-style switching for an app's windows
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
-
Global Energy & Grid
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first on SecurityWeek .
-
Global Energy & Grid
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
-
Global Energy & Grid
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks. The post Iran-Linked Hackers Shut Down UK Power Plant for Four Days appeared first on SecurityWeek .
-
Global Energy & Grid
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached…
-
Global Energy & Grid
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the…
-
Global Energy & Grid
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
-
Global Energy & Grid
AVEVA Enterprise SCADA
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCADA >=2024| Enterprise SCADA >=2023| Enterprise SCADA >=2022|…
-
Global Energy & Grid
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek .
-
Global Energy & Grid
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers. The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek .
-
Global Energy & Grid
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the…
-
Global Energy & Grid
Hackers breached a small Polish energy plant via private APN last year
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]
-
Global Energy & Grid
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states. The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek .
-
Global Energy & Grid
Water utilities group partners with DEF CON offshoot for Water Watch Center
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.
-
Global Energy & Grid
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were…
-
Global Energy & Grid
Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.
-
Global Energy & Grid
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been…
-
Global Energy & Grid
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
-
Global Energy & Grid
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek .
-
Global Energy & Grid
DataBahn Raises $40 Million for Agentic Data Pipeline Management
The company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared first on SecurityWeek .
-
Global Energy & Grid
Schneider Electric IGSS
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component…
-
Global Energy & Grid
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
-
Global Energy & Grid
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek .
-
Global Energy & Grid
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]
-
Global Energy & Grid
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
-
Global Energy & Grid
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek .
-
Global Energy & Grid
Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
-
Global Energy & Grid
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity…
-
Global Energy & Grid
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence…
-
Global Energy & Grid
India says allegedly leaked nuclear plant files pose no safety risk
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.
-
Global Energy & Grid
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain…
-
Global Energy & Grid
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
Siemens, Schneider Electric, and Rockwell Automation released patches for dozens of industrial control system vulnerabilities; CISA and German VDE CERT issued corresponding advisories.
-
EU Energy & Grid Lead
Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
UK and EU impose first joint cyber sanctions against Russia's FSB unit for attacks on Poland's energy and water infrastructure, plus broader malicious activities.
-
Global Energy & Grid
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric disclosed a vulnerability in its Easergy MiCOM Px40 Series protection relays used in medium and high voltage grid infrastructure across Europe.
-
Global Energy & Grid
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
GitHub Actions workflows can evade traditional CI security scanners, leaving development pipelines vulnerable despite passing security checks.
-
Global Energy & Grid
Siemens Mendix Studio Pro
Siemens released patches for Mendix Studio Pro vulnerability allowing arbitrary code execution through malicious project files during build processes.
-
Global Energy & Grid
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
AI-generated code in software supply chains creates new security risks alongside traditional dependency vulnerabilities, complicating verification processes for enterprises.
-
Global Energy & Grid
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
China-linked hackers deployed malware disguised as an Indian tax utility to target taxpayers and finance professionals, attempting to steal sensitive data via remote access trojan.
-
Global Energy & Grid
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
Threat actor Armored Likho deployed BusySnake stealer against government agencies and power sector entities in Russia, Brazil, and Kazakhstan, combining financial fraud with espionage operations.
-
Global Energy & Grid
Frangoteam FUXA SCADA/HMI
Frangoteam FUXA SCADA/HMI contains a vulnerability allowing unauthenticated remote attackers to enumerate user accounts and role assignments on industrial control systems.
-
Global Energy & Grid
DynoWiper update: Technical analysis and attribution
ESET researchers provide technical analysis of DynoWiper malware used in a data destruction attack against a Polish energy sector company.
-
Global Energy & Grid
ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025
ESET researchers attribute a cyberattack on Poland's power grid in late 2025 to Russian state-sponsored group Sandworm, involving previously undocumented data-wiping malware.
Headlines, short summaries and links only — full articles remain with their publishers, and each item links back to the source. Aggregated automatically; classification is keyword-derived and may miss or mislabel. Independent, no images, no tracking.