Category: Energy

  • Startup Bluecore Energy Raises $50 Million to Build Floating Nuclear Reactors for Ports and Data Centers

    Startup Bluecore Energy Raises $50 Million to Build Floating Nuclear Reactors for Ports and Data Centers

    California-based startup Bluecore Energy has raised $50 million in seed funding to develop compact nuclear reactors mounted on floating barges, targeting ports, AI data centers and other coastal facilities with rapidly growing power demands that outstrip what local electrical grids can reliably supply.

    A Reactor You Can Tow Rather Than Build

    The round, led by Silverton Partners and announced September 8, 2026, brings in several new investors and builds on $10 million in previously announced pre-seed funding. Bluecore’s approach centers on a compact, water-cooled small modular reactor design mounted on a floating platform, an architecture the company argues can reach a site far faster than permitting and constructing a fixed land-based nuclear plant, which typically takes the better part of a decade. The company plans to use the new capital to engineer and test its reactor system and pursue regulatory approval and maritime classification, working out of the Port of Long Beach, California.

    Targeting Ports, Data Centers and Disconnected Coastal Sites

    Bluecore is positioning its floating reactors to serve ports, AI data centers and coastal infrastructure, with units potentially deployed offshore and connected to onshore customers by subsea cable, and sees a secondary market in remote islands and coastal settlements that lack a practical connection to a wider electricity grid. The pitch follows a broader push by the US Department of Energy and the International Atomic Energy Agency to expand nuclear generating capacity for AI infrastructure and other energy-intensive industries, including the IAEA’s recent launch of an initiative focused on licensing nuclear technology for maritime applications.

    Regulatory Path Remains the Key Unknown

    Whether a mobile, barge-mounted reactor design can move through a meaningfully faster regulatory and licensing pathway than a conventional fixed nuclear plant remains untested, and industry observers have flagged that question, rather than the underlying reactor engineering, as the main risk to Bluecore’s timeline. The company was founded less than a year ago by former Uber Freight executive Kofi Asante, and its rapid progression from founding to a funded, physical hardware program has drawn attention from investors as data centers compete for gigawatt-scale power commitments faster than traditional grid expansion can deliver them.

  • Nuclear Power Plant Security Technology

    Nuclear Power Plant Security Technology

    Nuclear power plants operate under the strictest physical and cyber-physical security requirements of any commercial facility class, governed by dedicated regulatory frameworks that treat security as inseparable from safety. The technology stack protecting a nuclear generating station reflects that reality: multiple redundant, independently monitored layers designed so that no single failure, whether mechanical, electronic or human, can compromise the protection of reactor systems, spent fuel and special nuclear material.

    Layered Physical Protection

    Nuclear facilities are typically organized around concentric security zones, moving from an owner-controlled area through a protected area to vital areas immediately surrounding reactor and safety systems. Each boundary is reinforced with hardened barriers, vehicle arrest systems capable of stopping a loaded truck, and intrusion detection that combines microwave, infrared and fiber-optic perimeter sensors to minimize single-technology blind spots. Armed, highly trained security officers supplement these systems, with response times and staffing levels dictated by regulatory design-basis threat requirements rather than site-specific risk tolerance alone.

    Access Control and Insider Threat Programs

    Access to vital areas requires multi-factor identity verification, typically combining biometric authentication with credentialed access control and continuous personnel reliability screening. Because insider access represents one of the most difficult threat vectors to detect through perimeter security alone, nuclear operators maintain dedicated insider threat programs that monitor behavioral indicators, enforce two-person rules for access to the most sensitive areas, and require ongoing psychological and background reassessment of cleared personnel.

    Video Surveillance and Command Integration

    Video surveillance at nuclear sites integrates with access control, intrusion detection and radiological monitoring within a unified command-and-control platform, giving security operations centers a consolidated operational picture rather than a collection of disconnected feeds. Redundant power supplies and hardened communications ensure that surveillance and detection systems remain operational even during grid disturbances or attempted sabotage of supporting infrastructure.

    Cyber-Physical Convergence

    Modern nuclear security programs increasingly treat cybersecurity as inseparable from physical protection, given that digital instrumentation and control systems now govern safety-critical functions once managed by purely analog equipment. Regulatory frameworks require nuclear operators to secure both operational technology networks and the physical pathways — cabling, network closets, remote terminals — through which those systems could be accessed, reflecting the recognition that a determined adversary may target the weaker of the two domains rather than confronting the stronger one directly.

    Counter-Drone and Airspace Monitoring

    Growing concern over small unmanned aircraft has pushed nuclear operators to add counter-UAS detection layers, combining radar, radio-frequency and electro-optical sensors to identify and track drones approaching restricted airspace above and around generating stations, an area where regulatory guidance continues to evolve as the underlying technology matures.

  • Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    A small power generation facility in the United Kingdom was disabled for four days after a suspected Iran-linked cyberattack, in a window that overlapped with a wider wave of intrusions against wastewater treatment plants across roughly a dozen US states, according to reporting from Security Affairs and The Register published August 23–24, 2026, citing UK government and industry sources.

    The UK facility, not named publicly for security reasons, was small enough that its outage did not affect the wider national power supply, and staff were able to restore operations without formal notification thresholds being triggered. A UK government source told reporters the plant fell below the legal reporting threshold for “important generators,” while the National Cyber Security Centre declined to comment on the specific incident. NCSC chief Richard Horne said in June that the agency had handled more than 200 attacks on UK critical national infrastructure over the preceding year.

    US Wastewater Plants Hit Across Multiple States

    In parallel, US authorities traced a separate series of intrusions affecting dozens of wastewater treatment facilities, with the earliest reports emerging from Minnesota on July 26 and subsequent incidents confirmed in Michigan, Georgia, South Dakota, New Jersey, and Alabama. Several affected utilities reported flooding and loss of water pressure, and some jurisdictions issued boil-water advisories as a precaution. The FBI has attributed the water-sector intrusions to “malicious cyber actors,” and US government sources cited by Security Affairs indicated the activity likely originated in Iran.

    Researchers characterize both incidents as capability demonstrations rather than attempts to cause lasting damage, consistent with a broader pattern of suspected Iranian probing reported in recent months against infrastructure operators in Germany, Poland, Finland, Belgium, and Albania. UK officials have said the activity has accelerated since February airstrikes involving the United States and Israel against Iranian targets.

    The incidents add to a year in which operational technology at water and wastewater facilities has faced sustained scrutiny, and follow a separate US executive action restricting foreign-made equipment in bulk-power systems over cybersecurity concerns.

  • White House Bans Foreign-Made Bulk-Power System Equipment Over Cyber Backdoor Concerns

    White House Bans Foreign-Made Bulk-Power System Equipment Over Cyber Backdoor Concerns

    President Trump signed an executive order on August 26, 2026 declaring a national emergency over the security of the U.S. bulk-power system and banning the acquisition or installation of foreign-made equipment used to manage electricity transmission and generation, according to the order published by the White House and reporting by The Record. The order covers technology tied to transmission lines rated at 69,000 volts or higher, along with substations, control rooms, power generating stations and reactors, as well as associated software and firmware that could be remotely accessed or updated by foreign governments.

    The administration said the action responds to a pattern of foreign actors “creating and exploiting vulnerabilities” in bulk-power system technology that could enable remote access or supply-chain disruptions. The order directs the Departments of Defense, Commerce and Energy to review transactions involving bulk-power equipment and calls for a published list of pre-qualified vendors and components that federal agencies and utilities can rely on going forward.

    The order follows a string of confirmed intrusions into critical infrastructure operators this year, including cyberattacks affecting water utilities in multiple U.S. states and a reported multi-day shutdown of a small power plant in the United Kingdom, incidents that researchers have variously linked to Iranian, Russian and Chinese-linked hacking groups. For operators of power generation and transmission facilities, the order effectively elevates supply-chain vetting of grid control and monitoring equipment to the same priority long applied to physical perimeter security and access control systems protecting the same sites.

  • Texas Governor Orders Pause on New Data Center Approvals Amid Grid Interconnection Strain

    Texas Governor Orders Pause on New Data Center Approvals Amid Grid Interconnection Strain

    Texas Governor Greg Abbott has ordered a pause on approvals for new large data center projects seeking to connect to the state’s power grid, a move that Houston Public Media reported on August 27, 2026 could delay roughly 300 large data center projects, though not every planned facility in the state is covered by the pause.

    The order responds to mounting pressure on the Electric Reliability Council of Texas (ERCOT) interconnection queue, as AI-driven data center demand has produced a wave of large-load requests competing for grid capacity and connection timelines. According to the report, Beth Garza, who previously served as ERCOT’s independent market monitor, said the interconnection process could take significantly longer than originally projected, whether because of the governor’s pause or because the initial timeline itself was unrealistic; Garza said she “will be pleasantly surprised” if by April 2027 the industry has a clear picture of which data center loads will ultimately be able to move forward.

    Texas has emerged as one of the largest hubs for hyperscale and AI-focused data center construction in the country, drawing investment from major cloud and AI infrastructure providers seeking access to relatively fast permitting and available land, but also straining grid planning as operators request power commitments that can rival the demand of entire cities. The pause reflects a broader tension states are navigating between courting large-scale data center investment and protecting grid reliability and consumer electricity costs for existing residential and industrial customers.

    For the physical security and critical infrastructure sector, large-scale data center buildouts have significant downstream implications beyond power supply: campus perimeter security, access control, and fire and life-safety systems are typically scoped and budgeted alongside the underlying facility and power infrastructure, meaning delays or restructuring of a project’s grid interconnection timeline can directly affect the pace of associated physical security procurement and installation work tied to new builds.

  • CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

    CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

    Joint Advisory Warns of Active Targeting

    The National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency released a joint cybersecurity advisory on August 19, 2026, warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The advisory, designated AA26-231A, covers the S7-200, S7-300, S7-400, S7-1200 and S7-1500 controller families, including the F-series safety variants.

    According to the agencies, the activity spans several critical infrastructure sectors, with Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities named as the most-targeted. Siemens S7 controllers are also used in the Defense Industrial Base, which the advisory says could be affected as well. CISA describes the threat as “not a theoretical risk” and says exploitation of poorly protected PLCs could disrupt industrial processes, damage equipment, trigger safety incidents through manipulation of interlocks or emergency shutdown systems, and cause cascading effects across interconnected systems.

    AI-Generated Scripts and the Snap7 Library

    The advisory says the threat actors are combining publicly available industrial automation tooling with AI-assisted scripting to build custom software that mimics legitimate operational-technology monitoring tools. Specifically, the agencies describe adversaries using internet-scanning services such as Censys and ZoomEye to locate exposed S7 controllers, then deploying AI-generated Python scripts built on the open-source snap7 library to read and write PLC memory, configuration data and ladder-logic programs over the S7comm protocol on TCP port 102. CISA characterizes the use of AI to generate this exploitation code as “an evolution in threat actor capabilities” that lowers the technical bar for building working industrial-control exploitation tools and speeds adversaries’ ability to adapt to defenses.

    The agencies assess the pattern observed so far as consistent with reconnaissance and capability development — testing techniques against specific PLC models and using read access to understand target environments — rather than a confirmed disruptive attack. The advisory maps the observed techniques to the MITRE ATT&CK for ICS and Enterprise frameworks and to MITRE D3FEND countermeasures.

    A Distinct Threat From the Iran-Linked Water Sector Warning

    AA26-231A is separate from an earlier joint advisory, AA26-097A, which described confirmed Iran-linked exploitation of PLCs at a U.S. water-sector victim, including modification of ladder logic that disabled safety shutdown and alarm functions. The new Siemens-specific advisory does not attribute the reconnaissance activity it describes to any named nation-state or group, and it explicitly frames the observed activity as pre-attack staging rather than a confirmed disruptive incident. CISA also cautions that PLC targeting more broadly extends beyond Siemens equipment, and that the Siemens-specific guidance in the advisory should be treated as one subset of a wider threat landscape facing internet-exposed industrial controllers.

    Mitigations Recommended by the Authoring Agencies

    The agencies are urging asset owners to inventory all Siemens S7 controllers in their environments, apply available firmware and engineering-software patches, verify that PLCs are not reachable from the internet, and block TCP port 102 at perimeter firewalls. Additional recommendations include restricting engineering-workstation access through IP or MAC allowlisting, enabling PLC password protection and configurable read/write protection levels, deploying ICS-aware intrusion detection, and monitoring for anomalous S7comm traffic patterns, unauthorized write operations, and use of the snap7 library outside approved engineering systems. The advisory also recommends organizations that rely on third-party systems integrators or managed service providers share the guidance with those parties directly, since asset owners may not always be aware that PLCs accessible to vendors are also exposed to the wider internet.

    Sources

  • Electrical Substation Security and Condition Monitoring

    Electrical Substation Security and Condition Monitoring

    Substations are compact but high-consequence sites. Physical intrusion, equipment failure, overheating and fire can all disrupt the grid, so security and condition monitoring increasingly converge.

    Layered physical protection

    Fences, gates, access control and intrusion detection form the basic security perimeter. Radar, thermal and video analytics can provide earlier awareness around remote or unmanned substations.

    Thermal condition monitoring

    Transformers, connectors, switchgear and cable terminations can develop abnormal heat before failure. Fixed thermal cameras and temperature-sensing systems help operations teams identify trends before they become outages.

    Fiber sensing opportunities

    DTS can monitor power cables and long routes for thermal anomalies, while DAS can detect vibration, digging or physical disturbance near critical lines. Together they create a continuous sensing layer beyond the fence.

    Cyber-physical integration

    Modern substations contain networked protection and control equipment. Physical security events should therefore be correlated with network and operational alarms rather than handled in a separate silo.

    Resilience as the design goal

    The purpose of substation security is not simply to detect trespass. It is to protect continuity of service. Redundant communications, backup power, secure remote access and tested response procedures are therefore core design requirements.

    Conclusion

    Electrical Substation Security and Condition Monitoring should be evaluated as part of a broader operational architecture. The strongest deployments combine suitable sensing technology, resilient communications, clear procedures and measurable performance rather than relying on a single device or headline specification.

  • Solar Farm Security: Protecting Large Renewable-Energy Sites

    Solar Farm Security: Protecting Large Renewable-Energy Sites

    Utility-scale solar farms combine expensive distributed assets with very large perimeters, remote locations and limited staff presence. Their security architecture must therefore emphasize early detection, reliable communications and low false-alarm rates.

    The perimeter problem

    A solar site may stretch across hundreds of hectares. Traditional guard-intensive protection becomes expensive, so operators increasingly rely on layered detection using fence sensors, radar, thermal imaging and video analytics.

    Remote verification

    Every alarm should be quickly verifiable. Thermal cameras are useful at night and in low-light conditions, while visible cameras provide identification detail. Radar can cue PTZ cameras toward moving targets and reduce dependence on fixed camera coverage.

    Asset and cable protection

    Inverters, transformers, copper cabling, battery systems and communications cabinets require local protection. Access control, cabinet monitoring and tamper alarms create a second layer inside the perimeter.

    Operations and maintenance

    Environmental conditions such as heat, dust, vegetation and wildlife can create nuisance alarms. Analytics and regular tuning are essential. Solar-powered field devices can be useful, but maintenance planning and communications redundancy remain critical.

    Integrated renewable-site security

    The strongest model connects perimeter detection, video, access control, fire monitoring and operational telemetry in one command workflow. For long boundaries, fiber-optic sensing can add continuous linear awareness without thousands of powered field sensors.

    Conclusion

    Solar Farm and Renewable-Energy Site Security should be evaluated as part of a broader operational architecture. The strongest deployments combine suitable sensing technology, resilient communications, clear procedures and measurable performance rather than relying on a single device or headline specification.

  • DTS for High-Voltage Power Cable Monitoring: Technology and Applications

    DTS for High-Voltage Power Cable Monitoring: Technology and Applications

    High-voltage cable systems are increasingly critical to urban grids, renewable-energy connections, offshore wind farms and interconnectors. As power density rises, operators need more than periodic inspections. They need continuous information about where heat is building, whether a cable section is approaching its thermal limit and how loading affects long-term asset health. Distributed Temperature Sensing, or DTS, is one of the most powerful tools for this job.

    How DTS Works Along a Power Cable

    A DTS interrogator launches laser pulses into an optical fiber installed alongside or inside the cable system. Temperature changes affect the characteristics of backscattered light, allowing the system to calculate temperature at thousands of points along many kilometers of fiber. Instead of installing thousands of conventional temperature sensors, the fiber itself becomes a continuous sensing line.

    For power transmission operators, this creates a thermal profile of the complete route. Hot spots can be associated with joints, ducts, crossings, soil conditions, cable trays or other installation features. The key benefit is spatial awareness: the operator does not only know that a circuit is hot, but where the thermal constraint is developing.

    Dynamic Cable Rating

    One of the most valuable uses of DTS is dynamic cable rating. Traditional cable ratings are based on conservative assumptions about ambient conditions and heat dissipation. Real-time thermal data allows operators to estimate how much current can safely be carried under actual conditions.

    This can help utilities increase usable capacity without immediately replacing cables. It can also identify sections where poor thermal conditions are limiting the entire circuit. When combined with load data and thermal models, DTS becomes part of a real-time asset-management system rather than a simple alarm sensor.

    Where DTS Is Used

    Common applications include underground high-voltage cables, subsea export cables, tunnel installations, cable bridges, industrial power networks, data-center feeders and renewable-energy connections. It is especially useful on routes where conventional inspection is difficult or where failure would have severe operational consequences.

    Installation quality matters. The sensing fiber must have a known thermal relationship with the monitored cable. Calibration, route mapping, spatial resolution and integration with SCADA or condition-monitoring platforms all affect the quality of the final system.

    DTS vs Point Temperature Sensors

    Point sensors are valuable where a few specific components need monitoring, but they cannot provide a continuous thermal map. DTS is strongest when the asset is long and distributed. It can reveal unexpected heating between known inspection points and can provide historical temperature data for trend analysis.

    The two approaches are not mutually exclusive. Critical joints may use dedicated sensors while DTS monitors the complete route. A layered design often produces the best result.

    The Future: Combined Fiber-Optic Condition Monitoring

    The next step is combining DTS with other distributed fiber-optic sensing technologies. DAS can detect vibration and acoustic events, while distributed strain sensing can provide information about mechanical stress. Together, these technologies can create a multi-parameter view of cable health.

    For modern power networks, the optical fiber running beside a cable is becoming more than a communications channel. It can act as a continuous digital nervous system for the asset, helping operators improve capacity, detect abnormal conditions earlier and make better maintenance decisions.

    SectechMedia Editorial Note

    DTS should not be treated as a standalone thermometer. Its greatest value appears when thermal data is integrated with electrical load, cable models, alarms and maintenance workflows. In high-value cable systems, that integration can turn raw temperature measurements into actionable infrastructure intelligence.

  • Small UK Power Generator Taken Offline After Iran-Linked Cyberattack

    Small UK Power Generator Taken Offline After Iran-Linked Cyberattack

    A small power generation site in the United Kingdom was shut down for four days in July 2026 following a cyberattack that has been linked to hackers associated with Iran, The Telegraph reported on August 23, citing sources familiar with the incident. UK outlets including the Independent, Metro and The Register subsequently confirmed elements of the report with government sources.

    What happened

    The affected facility has not been publicly named. UK officials describe it only as a “small-scale energy generator” — the kind of site that, according to reporting, often runs intermittently to top up the grid rather than providing baseload power. A UK government spokesperson confirmed the incident to multiple outlets, including The Register and CNBC, stating that the attack did not create a risk to the wider energy system.

    Official response

    “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system,” a UK government spokesperson said in a statement provided to several outlets. “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.” The National Cyber Security Centre, part of GCHQ, said it does not routinely comment on individual incidents.

    Why it matters

    Reports describe this as the first time hackers linked to Iran have successfully disrupted a UK energy facility, and note that it occurred around the same time as a wave of cyberattacks attributed to Iran-linked actors against water utilities in the United States. Even when an individual facility is small relative to national grid capacity, incidents like this are a reminder that distributed and smaller energy assets — not just flagship power stations — are part of the critical infrastructure attack surface, and that operational technology segmentation and incident response planning need to extend across the full fleet of generation sites, not only the largest ones.

    Sources

    More coverage like this is available on Technology News.