Category: News

Current, event-driven reporting, announcements and industry developments.

  • Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    Iran-Linked Hackers Disable UK Power Plant for Four Days as US Water Utilities Report Coordinated Attacks

    A small power generation facility in the United Kingdom was disabled for four days after a suspected Iran-linked cyberattack, in a window that overlapped with a wider wave of intrusions against wastewater treatment plants across roughly a dozen US states, according to reporting from Security Affairs and The Register published August 23–24, 2026, citing UK government and industry sources.

    The UK facility, not named publicly for security reasons, was small enough that its outage did not affect the wider national power supply, and staff were able to restore operations without formal notification thresholds being triggered. A UK government source told reporters the plant fell below the legal reporting threshold for “important generators,” while the National Cyber Security Centre declined to comment on the specific incident. NCSC chief Richard Horne said in June that the agency had handled more than 200 attacks on UK critical national infrastructure over the preceding year.

    US Wastewater Plants Hit Across Multiple States

    In parallel, US authorities traced a separate series of intrusions affecting dozens of wastewater treatment facilities, with the earliest reports emerging from Minnesota on July 26 and subsequent incidents confirmed in Michigan, Georgia, South Dakota, New Jersey, and Alabama. Several affected utilities reported flooding and loss of water pressure, and some jurisdictions issued boil-water advisories as a precaution. The FBI has attributed the water-sector intrusions to “malicious cyber actors,” and US government sources cited by Security Affairs indicated the activity likely originated in Iran.

    Researchers characterize both incidents as capability demonstrations rather than attempts to cause lasting damage, consistent with a broader pattern of suspected Iranian probing reported in recent months against infrastructure operators in Germany, Poland, Finland, Belgium, and Albania. UK officials have said the activity has accelerated since February airstrikes involving the United States and Israel against Iranian targets.

    The incidents add to a year in which operational technology at water and wastewater facilities has faced sustained scrutiny, and follow a separate US executive action restricting foreign-made equipment in bulk-power systems over cybersecurity concerns.

  • ProdataKey and Aiphone Launch Integrated Cloud-Based Access Control and Video Intercom Solution

    ProdataKey and Aiphone Launch Integrated Cloud-Based Access Control and Video Intercom Solution

    ProdataKey (PDK) and Aiphone announced on August 26, 2026, a new cloud-based integration designed to unify access control and video intercom management for commercial and multi-tenant properties. The integration connects AiphoneCloud, Aiphone’s cloud-managed intercom platform, with PDK.io, ProdataKey’s mobile-first access control management software.

    “The future of physical security is built on connected, intuitive technologies,” said Dallan Labrum, Executive Vice President of Sales at ProdataKey. “Our integration with Aiphone gives dealers, integrators, and end users a smarter way to manage access control and video intercoms from a unified ecosystem. Together, we’re helping customers improve operational efficiency while delivering a better experience for everyone who enters and manages their buildings.”

    Automatic Tenant Sync Eliminates Duplicate Record-Keeping

    According to the companies, when tenant information is added, updated, or removed in PDK.io, those changes automatically sync to connected Aiphone IXG intercoms, eliminating the need for dealers and property managers to maintain duplicate records or manually coordinate directory updates between two separate systems. Security administrators and property managers can manage both access control and video intercom operations through a single streamlined workflow, which the companies say reduces administrative overhead and helps close security gaps caused by human error in manual record-keeping.

    The launch follows ProdataKey’s earlier preview of the integration at ISC West 2026, where the company showcased new locksets, readers, burglar-panel integrations, and video intercom offerings alongside the incoming Aiphone connection. For multi-tenant and commercial property operators, the combined platform reflects a broader industry shift toward converging previously siloed access control and visitor-verification systems into single-pane-of-glass management, reducing the operational friction that has historically accompanied maintaining separate vendor ecosystems for door access and intercom hardware.

  • Iranian State-Backed Nimbus Manticore Expands Toolset With New Backdoor and SSH Tunneler

    Iranian State-Backed Nimbus Manticore Expands Toolset With New Backdoor and SSH Tunneler

    Cybersecurity researchers at Group-IB have identified additional operational infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps. In an analysis published August 26, 2026, and reported the same day by The Hacker News, Group-IB described the group as among the most active Iranian advanced persistent threat actors of 2026.

    Nimbus Manticore — also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549 — is assessed by Group-IB to be linked to the Tortoiseshell cluster (also known as Imperial Kitten and Unyielding Wasp), itself part of the broader Charming Kitten activity cluster. The group has a documented history of using social-engineering campaigns, including fake recruitment and “Dream Job” lures, to deliver malware to targets in aerospace, defense, IT services, and telecommunications.

    New Backdoor and Tunneling Infrastructure Found Across Two Regions

    Group-IB researchers Mansour Alhmoud and Mohamed Emam identified a C++ backdoor with characteristics similar to the group’s existing TWOSTROKE implant, along with an SSH-based tunneling utility, deployed across newly discovered infrastructure spanning both Europe and the Middle East. “The discovered Tortoiseshell infrastructure potentially suggests an expanded targeting profile, focusing on Middle Eastern countries, alongside European countries,” the researchers wrote.

    The findings follow earlier reporting on the group’s NightLedger backdoor and custom WebSocket tunnelers, which Group-IB said have been used to turn compromised systems into covert network relays capable of executing commands, uploading files, and capturing screenshots while tunneling traffic through victim networks. Group-IB said the continued development of new tools alongside the expanding infrastructure footprint “demonstrates a threat actor that is steadily evolving its toolset and adapting its techniques to maintain access across a growing number of targets.”

    Organizations in the aerospace, defense, telecommunications, and critical-infrastructure-adjacent sectors that operate in Europe or the Middle East are advised to review indicators associated with the Tortoiseshell/Nimbus Manticore cluster as part of routine threat-intelligence monitoring.

  • AWS and Nvidia Expand Partnership With 2 Million More GPUs for Agentic and Physical AI

    AWS and Nvidia Expand Partnership With 2 Million More GPUs for Agentic and Physical AI

    Amazon Web Services and Nvidia announced on August 27, 2026, a major expansion of their infrastructure partnership, with plans to deploy 2 million additional Nvidia GPUs across AWS’s global infrastructure during 2027 and 2028. The new capacity will include Nvidia’s Blackwell Ultra, Rubin, and Rubin Ultra platforms, and builds on AWS’s previously announced plan to add more than 1 million Nvidia GPUs beginning in 2026.

    “NVIDIA and AWS have built one of the great growth engines of the AI era, and demand is running ahead of every forecast,” Nvidia founder and CEO Jensen Huang said in the companies’ joint announcement. “For 16 years, we have scaled NVIDIA computing in the cloud together. Now, we are expanding our partnership across the full stack — GPUs, CPUs, networking, open models and software — to make agentic and physical AI real at an unprecedented pace and scale that only AWS and NVIDIA can deliver.”

    Robotics, Federal AI Factories, and CPU Infrastructure

    The expanded collaboration extends beyond GPU deployment. AWS will integrate Nvidia’s Vera CPU-based infrastructure into its cloud, giving customers a CPU option purpose-built for AI agent workloads alongside accelerated compute. The companies also plan to build AI factories for the U.S. government, including deploying 100,000 Nvidia GPUs on AWS infrastructure dedicated to federal and national-security workloads.

    On the physical-AI and robotics side, Amazon Robotics is working with Nvidia to develop next-generation robots using Nvidia’s Jetson platform, Omniverse simulation libraries, and the Isaac open robotics development platform. The collaboration spans simulation, synthetic data generation, robot training, route optimization, functional safety, and real-to-sim validation, running on GPU-accelerated Amazon EC2 instances — work with direct relevance to warehouse automation, logistics security, and the broader push toward AI-driven physical infrastructure that industrial and critical-infrastructure operators are increasingly evaluating.

    The deal also covers data processing and open-model availability, including GPU-accelerated processing on Amazon EMR via new EC2 G7 instances and continued availability of Nvidia’s Nemotron model family on Amazon Bedrock and SageMaker.

  • Critical cPanel Flaw Could Let a Hosting Customer Take Root Control of a Whole Server

    Critical cPanel Flaw Could Let a Hosting Customer Take Root Control of a Whole Server

    cPanel published a security advisory on August 27, 2026, disclosing a critical vulnerability in the domain-parking and addon-domain functionality of cPanel & WHM. Tracked as CVE-2026-65643, the flaw allows an authenticated account holder with permission to add parked or addon domains to create arbitrary files on the server, which can ultimately be abused to achieve code execution as the root user.

    According to cPanel’s own advisory, successful exploitation “leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.” The vulnerability affects all currently supported versions of cPanel & WHM. Patched versions are 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP2 build 11.138.1.7 or later; servers running end-of-life cPanel releases must first upgrade to a supported version before they can receive the fix.

    Particularly Severe for Shared and Multi-Tenant Hosting

    Security researchers covering the disclosure noted that the flaw’s impact is amplified in shared-hosting environments, where a single low-privilege tenant account with domain-management permissions could serve as a stepping stone to compromising every other customer hosted on the same server — including the ability to deploy persistent backdoors, alter website content, exfiltrate databases, and manipulate server configuration across multiple unrelated hosted accounts.

    cPanel has not disclosed evidence of active exploitation, and as of the August 27, 2026 update to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, CVE-2026-65643 was not listed. The advisory also carries no published CVSS score; as of August 28, 2026, the CVE Program’s own record store had not yet published a formal record for the vulnerability, even though two unrelated cPanel plugin flaws disclosed on July 31 already had entries at the time of the check.

    Given how widely cPanel is deployed across web and hosting infrastructure, administrators are advised to prioritize the update, particularly on multi-tenant servers where the domain-parking feature is exposed to lower-trust account holders.

  • McKesson Confirms Cyberattack as ShinyHunters Claims Theft of 284 Million Patient Records

    McKesson Confirms Cyberattack as ShinyHunters Claims Theft of 284 Million Patient Records

    McKesson Corporation, the pharmaceutical distributor that moves roughly a third of prescription drugs sold in the United States, confirmed on August 28, 2026, that it suffered a cybersecurity incident involving unauthorized access to third-party applications. In a Form 8-K filed with the U.S. Securities and Exchange Commission, McKesson said it discovered the incident on August 25, 2026, and that its investigation “remains in the early stages,” with updates being posted to the company’s website.

    Hours after McKesson’s disclosure, the extortion group ShinyHunters told BleepingComputer it had exfiltrated approximately one terabyte of data from the company’s Salesforce and Snowflake environments over a four-day window between August 21 and August 25, 2026. According to the group, initial access came through vishing attacks that compromised multiple employees’ Okta single sign-on accounts, which were then used to reach the Salesforce and Snowflake platforms.

    ShinyHunters claimed the stolen data includes roughly 284 million patient-related records, and said it contacted McKesson after completing the theft to demand a ransom of $55,236,150, giving the company 72 hours to respond. The group said McKesson did not negotiate or respond to the demand.

    Part of a Broader Pattern Targeting Healthcare and SaaS Platforms

    The McKesson incident is the latest in an ongoing wave of data-theft attacks attributed to ShinyHunters against healthcare and health-technology organizations, several of which have involved compromised third-party SaaS and cloud-data platforms rather than direct breaches of core clinical systems. As with earlier incidents in this pattern, the exposure risk here centers on identity providers and cloud data warehouses that sit adjacent to, but outside, an organization’s primary operational infrastructure — a distinction that matters for how healthcare and pharmaceutical enterprises prioritize identity security and third-party risk monitoring alongside traditional network defenses.

    McKesson has not confirmed the scope of data exposed or verified ShinyHunters’ record-count claim. The company said additional updates would be provided as the investigation progresses.

  • Comelit-PAC Launches Linear Beam Smoke Detector Range for Warehouses and Large Open Spaces

    Comelit-PAC Launches Linear Beam Smoke Detector Range for Warehouses and Large Open Spaces

    Comelit-PAC has launched a new range of linear beam smoke detectors designed for warehouses, atriums, industrial facilities, sports halls and other high-ceiling environments, the company said on August 26, 2026. The detectors use reflective infrared beam technology to monitor for smoke over distances of up to 120 meters, and the range comprises four models split between addressable and conventional variants covering 5 to 60 meters and 50 to 120 meters respectively.

    The addressable models are compatible with Comelit-PAC’s Logifire panels, while conventional variants work with standard fire alarm control panels; all models are certified to EN54-12, and the addressable versions add EN54-17 certified short-circuit isolation. The detectors include smart alignment technology that automatically optimizes signal strength during commissioning, an integrated laser pointer to assist installation, and automatic compensation for environmental drift such as dust buildup, minor structural movement and temperature fluctuation, with maintenance alerts generated when servicing is needed. “As warehouses become larger, industrial facilities more complex and public spaces increasingly multi-purpose, there’s growing demand for technologies to deliver reliable coverage without adding unnecessary complexity,” said Mandy Bowden, Fire Systems Business Manager UK & ROI at Comelit-PAC.

    Beam smoke detection is a standard approach for protecting large-volume spaces where point smoke detectors would be impractical to install and maintain in sufficient density, and reducing false alarms from environmental drift has been a persistent integrator complaint with older beam detector generations. The addressable range’s real-time alignment display and dual day/night sensitivity settings target that maintenance burden directly, a common driver of beam detector replacement cycles in large commercial and industrial buildings.

  • Cosmos EVM Flaw Drains $5.72 Million From Six Blockchains After Patch Shipped Without a Security Advisory

    Cosmos EVM Flaw Drains $5.72 Million From Six Blockchains After Patch Shipped Without a Security Advisory

    Cosmos Labs disclosed in a post-mortem published August 28, 2026 that a critical balance-handling flaw in the shared Cosmos EVM module, used by more than 115 known public blockchains, was exploited on six chains between August 20 and August 25, 2026, draining roughly $5.72 million in assets, according to the company’s writeup and reporting by The Hacker News. The vulnerability allowed an attacker to manipulate token balances through a supply-overflow condition on older chain versions and a type-conversion issue on newer ones, both exploitable within a single transaction carrying a net supply change of zero.

    According to The Hacker News, a fix for the flaw was made public in May 2026 but was not distributed as a security release until August 19, and the release notes for the patched versions did not disclose that they contained a security fix. Cosmos Labs has said it does not maintain a complete registry of the networks running its software, meaning some chain operators may not have known a security-relevant update was available. Attackers moved roughly $2.87 million of the stolen funds through decentralized exchanges and an estimated $2.85 million through centralized exchanges, whose accounts have reportedly been frozen pending investigation.

    The incident highlights a recurring weakness in open-source infrastructure that underlies widely used platforms: a patch is only protective if downstream operators know it addresses a security issue, and shared modules used across dozens of independently operated networks can leave a long window of exposure when disclosure practices lag behind development timelines. Cosmos Labs has since urged all EVM chains running unpatched versions to halt operations until they upgrade.

  • Attackers Chain Two PaperCut Flaws to Achieve Unauthenticated Remote Code Execution

    Attackers Chain Two PaperCut Flaws to Achieve Unauthenticated Remote Code Execution

    Malicious actors are exploiting a newly patched vulnerability in PaperCut NG and PaperCut MF print management software to execute arbitrary code on affected servers, according to research from Huntress and reporting by The Hacker News. PaperCut released an emergency fix with additional hardening after the flaw, which does not yet have an assigned CVE identifier, was found being exploited in the wild.

    Huntress researchers John Hammond and Andrew Brandt said the vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which can be used to execute arbitrary Java code inside the application’s process. The flaw stems from how PaperCut’s authorization check handles a specifically crafted request: an attacker can reference one page that gets rendered in the response while a different page actually owns the component or action being executed, allowing the authorization check to trust the rendered page and miss the permission requirements tied to the executed action.

    PaperCut print management software is widely deployed across schools, government agencies, healthcare systems and corporate print environments, making unauthenticated remote code execution a significant exposure wherever an instance is reachable from an untrusted network. Organizations running PaperCut NG or MF are advised to apply the emergency patch immediately and review Huntress’s indicators for signs of prior exploitation.

  • Google Rolls Out Encrypted Client Hello on Android 17 to Hide Browsing Destinations From Networks

    Google Rolls Out Encrypted Client Hello on Android 17 to Hide Browsing Destinations From Networks

    Google said this week that Android 17 now supports Encrypted Client Hello (ECH), a privacy standard that prevents internet service providers and other network operators from seeing which websites and apps a device is connecting to, according to a security post published by Google and its Jigsaw team. Google described the rollout as the first broad deployment of ECH on a major mobile operating system.

    ECH works alongside private DNS to encrypt the hostname sent during the initial stage of a TLS connection, a field historically visible in plaintext even over otherwise-encrypted HTTPS connections and commonly used by networks to profile which sites and services a user visits. With ECH enabled, network providers can see only which content delivery network is handling a connection and how much data is moving, not the specific destination site, for websites and apps that support the standard. Google said Android 17 also adds Local Network Protection, requiring apps to obtain permission before scanning for or connecting to devices on a user’s local network, along with mandatory Certificate Transparency logging for website certificates.

    For organizations managing mobile device fleets, wider ECH adoption reduces the effectiveness of network-level traffic analysis as a security and monitoring technique, since enterprise security tools that rely on inspecting destination hostnames at the network layer will see less metadata for ECH-enabled connections. Google said Android app developers should upgrade to OkHttp 5.5.0 and enable ECH support to take advantage of the new protection.