Author: Osiris

  • UK Moves to Give Ministers Power to Block High-Risk Tech Suppliers From Critical Infrastructure

    UK Moves to Give Ministers Power to Block High-Risk Tech Suppliers From Critical Infrastructure

    The UK government has tabled late amendments to its Cyber Security and Resilience Bill that would give ministers new powers to block critical-sector organizations from using technology suppliers considered a national security risk, as concern grows over supply-chain vulnerabilities feeding attacks on critical infrastructure.

    A Response to a Recent Energy Sector Attack

    The government tabled the amendments on August 24, 2026, underscoring what officials describe as an urgent need to give ministers explicit authority to prevent critical infrastructure operators from engaging technology suppliers deemed high risk. The move follows a cyberattack, reportedly linked to a nation-state actor, that took a UK energy generator offline for four days, an incident that industry commentators say sharpened political attention on supply-chain exposure across the country’s critical infrastructure. Once passed, the legislation is expected to be referred to as the Cyber Security and Resilience Act.

    Targeting the Supply Chain, With SMEs in the Middle

    The Cyber Security and Resilience Bill is designed to give the UK stronger enforcement tools against the weak points that enable supply-chain attacks, extending obligations further down the vendor chain than earlier UK cybersecurity legislation. Security industry commentators have noted that while the bill’s blocking power targets specific high-risk suppliers, the practical burden falls heavily on smaller technology vendors serving critical infrastructure operators, who will need to demonstrate stronger security practices or risk being excluded from the market entirely once the provisions take effect.

    Scrutiny Alone Is Not a Complete Fix, Critics Say

    Industry reaction has been mixed: while cybersecurity professionals broadly welcomed greater scrutiny of high-risk suppliers, some cautioned that blocking individual vendors cannot substitute for broader supply-chain security improvements across the sector. Commentators pointed to the energy sector incident as evidence that nation-state-linked attacks on critical infrastructure increasingly exploit third-party and supply-chain relationships rather than targeting operators directly, a pattern the new ministerial powers are intended to address but cannot fully eliminate on their own.

  • Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

    Schneider Electric, Siemens and AVEVA Patch Critical Industrial Control System Flaws in September Patch Cycle

    Industrial automation vendors Schneider Electric, Siemens and AVEVA published their September 2026 Patch Tuesday advisories, disclosing and fixing a batch of vulnerabilities across products used to run and monitor industrial and critical infrastructure operations.

    A Critical Flaw in Widely Deployed Safety Controllers

    The most severe issue disclosed, tracked as CVE-2026-3869 with a CVSS score of 9.2, is a critical authentication vulnerability affecting Schneider Electric’s Modicon M580 and Modicon M580 Safety programmable controllers, hardware widely used to control physical processes in manufacturing and critical infrastructure environments. Schneider Electric published four new security advisories and updated four others, including one originally issued in 2019, and separately resolved high-severity flaws in its PowerLogic T300 platform (formerly Easergy T300) and EcoStruxure IT Data Center Expert product, along with a medium-severity issue in its SCADAPack x70 line.

    Denial-of-Service Risk in Rockwell’s Historian Software

    Rockwell Automation separately disclosed CVE-2026-12661, a high-severity denial-of-service vulnerability in FactoryTalk Historian Machine Edition, in which a network-adjacent, authenticated attacker can send crafted requests to the web interface to trigger a buffer overflow that crashes the device. AVEVA’s FactoryTalk Historian SE product, which is built on the AVEVA PI Server, carries a related issue that lets an unauthenticated attacker remotely crash or exhaust memory on the PI Message Subsystem, requiring a power cycle to recover affected systems.

    Part of a Broader Monthly Cadence Across the Sector

    Since the previous month’s patch cycle, CISA has separately published advisories covering additional industrial and IoT vulnerabilities from vendors including Inductive Automation, Hitachi Energy, Furuno, Johnson Controls and others, underscoring how large and continuous the flow of disclosed operational technology vulnerabilities has become. None of the newly disclosed Schneider, Siemens, AVEVA or Rockwell flaws in this cycle have been reported as under active exploitation, but organizations running the affected controllers and historian software are advised to apply vendor patches and review network segmentation between control systems and general IT networks.

  • Four Espionage Groups Used the Same New Exploit Kit Against Chrome and Windows Within a Week

    Four Espionage Groups Used the Same New Exploit Kit Against Chrome and Windows Within a Week

    At least four separate espionage-motivated threat groups, most with suspected links to Chinese state intelligence, deployed a previously undocumented exploit kit within the same week to break into government, defense, NGO and financial-sector targets across the United States and Southeast Asia, according to research published by security firm Proofpoint.

    Chaining a Patch Gap Into a Working Exploit

    Proofpoint named the kit BlueMoon, describing it as a chain combining two zero-day flaws in Chromium-based browsers with a Microsoft Windows privilege-escalation bug, letting an attacker escape Chrome’s V8 sandbox and gain elevated access on a victim’s machine. The underlying Chrome flaw, CVE-2026-85046, was fixed in Chromium’s source code on August 7 but did not reach the stable Chrome release until September 3, nearly four weeks later; researchers say that gap between the public fix and the downstream browser update gave attackers a window to reverse-engineer the patch and build a working exploit before most users were protected. The companion Windows flaw, CVE-2026-85880, was addressed as part of Microsoft’s September 2026 Patch Tuesday updates.

    Four Campaigns, Multiple Payloads, One Shared Toolkit

    The first confirmed use came from TA412, a China-nexus group also tracked as APT31 or Violet Typhoon, which began targeting US NGOs, mining companies and physical commodity trading firms on August 28 using phishing emails posing as university outreach. Proofpoint identified three additional clusters using the same kit in the following days, including a group tracked as UNK_DoubleCheck that targeted a Vietnamese manufacturing firm from a compromised Southeast Asian government email account, and UNK_QuietRacket, which used lures referencing Indonesian conferences to target government, consulting and financial organizations in Indonesia and Singapore. Payloads delivered through the kit included the GemStone and ShadowPad malware families.

    Patching Alone Does Not Remove Existing Footholds

    CISA added the exploited Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, giving US federal civilian agencies until September 18 to patch. Researchers caution that updating the browser closes the initial infection route but does not remove malicious components, such as the GemStone extension or scheduled tasks, that earlier-compromised systems may already be running, meaning organizations that may have been targeted need to actively check for signs of persistence rather than relying on patching alone.

  • Cisco Warns of Firewall Management Zero-Day Exploited With Built-In Static Credentials

    Cisco Warns of Firewall Management Zero-Day Exploited With Built-In Static Credentials

    Cisco is warning customers that a vulnerability in its Secure Firewall Management Center (FMC) software, caused by static credentials built into a low-privilege account, was actively exploited in zero-day attacks before a fix was available.

    Hard-Coded Credentials in a Low-Privilege Account

    The flaw, tracked as CVE-2026-20316, stems from static credentials embedded in a low-privilege account within Cisco Secure FMC Software, the centralized platform organizations use to manage and monitor their Cisco firewall deployments. An unauthenticated remote attacker who knows or discovers those credentials can log in to an affected device using that account, gaining a foothold on infrastructure that is meant to be tightly restricted. Cisco says the attack surface is reduced when the FMC management interface is not exposed directly to the public internet, though the company has not disclosed how many organizations had internet-facing management interfaces at the time of exploitation.

    Cisco Learned of Active Exploitation in July, Disclosed in September

    Cisco said it became aware of active exploitation of the flaw in July 2026 but has not shared when the attacks actually began, who is behind them, or which organizations were targeted. The vulnerability was reported by Jimi Sebree of Horizon3.ai. Cisco has released hot fixes addressing CVE-2026-20316, alongside a related flaw tracked as CVE-2026-20079 that the company says can achieve root access on affected devices without relying on the static credentials at all. No workarounds fully address either vulnerability short of applying the fixed software, and Cisco is urging FMC administrators to patch immediately and review whether their management interfaces are unnecessarily exposed to the internet.

  • Startup Bluecore Energy Raises $50 Million to Build Floating Nuclear Reactors for Ports and Data Centers

    Startup Bluecore Energy Raises $50 Million to Build Floating Nuclear Reactors for Ports and Data Centers

    California-based startup Bluecore Energy has raised $50 million in seed funding to develop compact nuclear reactors mounted on floating barges, targeting ports, AI data centers and other coastal facilities with rapidly growing power demands that outstrip what local electrical grids can reliably supply.

    A Reactor You Can Tow Rather Than Build

    The round, led by Silverton Partners and announced September 8, 2026, brings in several new investors and builds on $10 million in previously announced pre-seed funding. Bluecore’s approach centers on a compact, water-cooled small modular reactor design mounted on a floating platform, an architecture the company argues can reach a site far faster than permitting and constructing a fixed land-based nuclear plant, which typically takes the better part of a decade. The company plans to use the new capital to engineer and test its reactor system and pursue regulatory approval and maritime classification, working out of the Port of Long Beach, California.

    Targeting Ports, Data Centers and Disconnected Coastal Sites

    Bluecore is positioning its floating reactors to serve ports, AI data centers and coastal infrastructure, with units potentially deployed offshore and connected to onshore customers by subsea cable, and sees a secondary market in remote islands and coastal settlements that lack a practical connection to a wider electricity grid. The pitch follows a broader push by the US Department of Energy and the International Atomic Energy Agency to expand nuclear generating capacity for AI infrastructure and other energy-intensive industries, including the IAEA’s recent launch of an initiative focused on licensing nuclear technology for maritime applications.

    Regulatory Path Remains the Key Unknown

    Whether a mobile, barge-mounted reactor design can move through a meaningfully faster regulatory and licensing pathway than a conventional fixed nuclear plant remains untested, and industry observers have flagged that question, rather than the underlying reactor engineering, as the main risk to Bluecore’s timeline. The company was founded less than a year ago by former Uber Freight executive Kofi Asante, and its rapid progression from founding to a funded, physical hardware program has drawn attention from investors as data centers compete for gigawatt-scale power commitments faster than traditional grid expansion can deliver them.

  • ‘DoppelCart’ Fraud Network Runs 119,000 Fake Online Stores to Steal Payment Card Data

    ‘DoppelCart’ Fraud Network Runs 119,000 Fake Online Stores to Steal Payment Card Data

    German cybersecurity company Nebty has identified a fraud operation dubbed DoppelCart, describing it as the largest publicly documented fake-shop network by domain count, spanning almost 119,000 domains built to mimic real retailers and harvest payment card data from bargain-hunting shoppers.

    A Cluster Built Almost Entirely on One Top-Level Domain

    Nebty’s scans identified 118,787 domains in the cluster, the large majority registered under the .shop top-level domain and accounting for roughly 2.72% of all sites on that TLD. As of the researchers’ latest scans, more than 105,000 of the fake shops remained active. The sites mimic more than 44,000 real brands, with a typical brand cloned around twice, though some brands, including SodaStream, Velasca, CurrentBody, Daniel Wellington and Dreame, were impersonated by more than 30 separate shops each. The fake storefronts typically advertise discounts of up to 65% to lure shoppers searching for deals.

    Shared Infrastructure Behind Thousands of Storefronts

    Despite the scale of the operation, the underlying infrastructure is comparatively narrow: researchers found that 96% of confirmed DoppelCart shops shared identical build files and ran on just 27 distinct e-commerce backends, suggesting a small number of template kits power the vast majority of the cluster. When testing checkout pages across the network, Nebty found code specifically built to collect payment card numbers and cardholder information at the point of sale, rather than simply taking payment through a legitimate processor and never delivering goods.

    The New Largest Fake-Shop Network on Record

    DoppelCart significantly surpasses the previously largest documented fake-shop cluster, “BogusBazaar,” a network of roughly 75,000 sites tied to an estimated 850,000 fraudulent transactions. Researchers advise shoppers to check unfamiliar retail URLs carefully for odd domain extensions, verify a business has visible customer reviews and contact information, and treat unusually steep discounts on well-known brands as a warning sign rather than an opportunity.

  • Extortion Group Claims Breach of Florida DMV Database, Threatens to Leak 200,000 Driver Records

    Extortion Group Claims Breach of Florida DMV Database, Threatens to Leak 200,000 Driver Records

    The extortion group ShinyHunters claims to have breached an online platform used by the Florida Department of Highway Safety and Motor Vehicles, stealing more than 200,000 driver records and threatening to publish the data if the state does not respond by a set deadline.

    A Password-Reset Flaw Allegedly Opened the Door

    The targeted system, known as DAVID (Driver And Vehicle Information Database), is described by the Florida Highway Safety and Motor Vehicles agency as a platform that gives law enforcement and criminal justice officials immediate access to driver and vehicle information, and serves as the state’s primary reporting mechanism for fatalities and serious injuries. ShinyHunters told BleepingComputer the intrusion exploited a password-reset weakness that let the group compromise multiple internal accounts, including ones it claims belonged to DMV employees and an FBI agent. Using that access, the group said it wrote a script to iterate through driver records by ID number, downloading the associated HTML pages and images for each one, collecting over 200,000 records since the breach allegedly began on September 3, 2026.

    Epstein Record Used as Proof, September 11 Deadline Set

    As evidence of the intrusion, the group released a screenshot of a DMV record belonging to Jeffrey Epstein, including his address and registered vehicles. ShinyHunters added the Florida agency to its dark web leak site with a listing giving officials until September 11, 2026, to make contact before the group releases the full dataset, a listing the group has labeled a “final warning.” The claimed 200,000-record figure comes directly from the attackers and has not been independently verified or confirmed by the state as of publication.

    Part of a Broader Pattern of Government Database Targeting

    ShinyHunters has claimed responsibility for a string of high-profile extortion cases against corporate and government targets over the past year, frequently relying on compromised credentials and account takeover rather than novel technical exploits to gain initial access. The alleged Florida incident underscores a recurring weak point in large government record systems: authentication and account-recovery workflows that, once compromised, can expose bulk record access far beyond what a single stolen credential would typically allow.

  • Attackers Used a Three-Year-Old Flaw to Steal Reactor Data From a Philippine Nuclear Agency

    Attackers Used a Three-Year-Old Flaw to Steal Reactor Data From a Philippine Nuclear Agency

    A threat actor exploited a long-patched vulnerability in the file-sharing platform ownCloud to steal reactor data, personnel records and stored credentials from a Philippine nuclear research organization, according to researchers who found the stolen material staged on attacker-controlled infrastructure.

    A Two-Year-Old Bug in a Default Configuration

    Threat-hunting firm Hunt.io published a blog post on August 26, 2026 identifying an ownCloud server hosted in Amsterdam that appeared to function as a staging hub for a suspected Chinese-speaking operator, containing offensive tooling alongside data taken from at least two victims: a Philippine nuclear research agency and a marine engineering and shipbuilding company serving the Philippine Navy. The intrusion exploited CVE-2023-49105, an authentication bypass in ownCloud’s pre-signed URL mechanism disclosed by the vendor in November 2023 and carrying a CVSS score of 9.8. On installations left in ownCloud’s default configuration, with no signing key configured, an attacker who knows a valid username can construct requests the system accepts as authenticated, letting them access, modify or delete files without ever supplying a password.

    Reactor Records, Personnel Files and Stored Credentials

    The material recovered from the nuclear agency’s staging folders, roughly 372 MB across 176 files, included a database of research-reactor core components, historical fuel inventories, radiation-safety documentation, incident records, and a 192 MB database dump from a biometric attendance and personnel system, alongside employee resumes, travel records and financial disclosures. Investigators also found a KeePass password database, AxCrypt-encrypted files and a PDF containing a BitLocker recovery key among the stolen material, credential artifacts that could help an attacker move further into connected systems. A separate recovered inventory suggested roughly 9 GB of data may have been taken from the agency in total, though only a fraction was directly recovered by researchers.

    CISA Adds the Flaw to Its Exploited Catalog

    The US Cybersecurity and Infrastructure Security Agency added CVE-2023-49105 to its Known Exploited Vulnerabilities catalog on August 27, 2026, one day after Hunt.io’s disclosure, formally flagging a nearly three-year-old bug as under active exploitation. The incident illustrates a recurring pattern in intrusions against sensitive government and research infrastructure: the vulnerability exploited was neither novel nor unpatched by the vendor, but a long-available fix that an internet-facing, self-hosted file-sharing system had apparently never received.

  • Nvidia-Backed Zankore Secures $3.1 Billion Loan for Southeast Asia AI/GPU Buildout

    Nvidia-Backed Zankore Secures $3.1 Billion Loan for Southeast Asia AI/GPU Buildout

    Zankore, an AI compute (“neocloud”) platform backed by Indosat Ooredoo Hutchison, Ooredoo Group, Nokia and Nvidia, signed a senior term loan facility of up to $3.1 billion to fund Nvidia GPU and cloud infrastructure deployment across Indonesia and Southeast Asia, Reuters reported. The financing supports an initial 100MW of Nvidia AI infrastructure, with Citi, ING, Natixis, Qatar National Bank and UOB arranging the debt.

    Why it matters: The deal illustrates how AI compute buildout is expanding well beyond the US, Europe and China, with large debt-financed infrastructure projects now targeting Southeast Asia specifically — a region where data center and power infrastructure security is a growing concern for operators and regulators alike.

    Source: Reuters, September 9, 2026.

  • Google to Invest $15.1 Billion in Finland AI Infrastructure, Signs First Nuclear Power Deal Outside the US

    Google to Invest $15.1 Billion in Finland AI Infrastructure, Signs First Nuclear Power Deal Outside the US

    Alphabet’s Google will invest at least €13 billion ($15.1 billion) in AI infrastructure in Finland over 2027–2028, its largest European investment to date, Reuters reported. The funding covers three new data centers plus grid and clean-energy upgrades.

    Google also signed a 22-year power purchase agreement for up to 50% of the output of Fortum’s Loviisa nuclear plant — the company’s first nuclear power deal outside the United States.

    Why it matters: The scale of AI-driven data center buildout is now large enough that hyperscalers are signing multi-decade nuclear power agreements to secure supply, a direct signal of how AI infrastructure growth is reshaping national energy planning and grid investment, including in countries not previously associated with hyperscale data center clusters.

    Source: Reuters, via DW and AFR, September 9, 2026.