Category: News

Current, event-driven reporting, announcements and industry developments.

  • Civilian Drones Have Grounded Wildfire Aircraft Dozens of Times in 2026, Officials Say

    Civilian Drones Have Grounded Wildfire Aircraft Dozens of Times in 2026, Officials Say

    67 Reported Incursions So Far This Year

    The U.S. Forest Service says there have been 67 unauthorized drone incursions into wildfire airspace so far in 2026, a pattern officials say repeatedly forces firefighting aircraft out of the sky. In an August 2026 public safety post, the Forest Service and the National Interagency Fire Center said temporary flight restrictions are put in place over active wildfires specifically to protect aerial firefighting crews flying air tankers and helicopters, and that every incursion by an unauthorized drone forces those aircraft to stand down until the airspace is confirmed clear. Thirty-nine of the 67 reported incursions this year occurred in Washington state, according to the agencies. Individuals caught flying drones into these restricted zones can face significant fines and potential prison time.

    Spokane Complex Fires: A Concrete Example of the Risk

    The scale of the disruption was illustrated during the Spokane Complex wildfires in Washington in early August 2026. According to FireRescue1, citing a Spokane County Sheriff’s Office news conference, 26 drone incursions were reported on August 2, four of which flew directly into the path of firefighting aircraft. The following evening, aircraft were grounded for roughly 30 minutes after another unauthorized drone entered the restricted airspace, the outlet reported, citing The Seattle Times; the operator in that case was not located. Spokane County Sheriff John Nowels said his office had identified multiple drone operators from the earlier incidents and referred citations to the Federal Aviation Administration, noting each operator could face penalties up to $100,000.

    Washington Department of Natural Resources spokesperson Ryan Rodruck told FireRescue1 that grounding aircraft even briefly has real operational costs: “We’re utilizing all units at our disposal right now, but we can’t do that effectively if the airspace isn’t clear.” He said the temporary flight restriction over the Spokane fires protected airspace up to 5,000 feet, and that wildland firefighting aircraft often operate at altitudes similar to many civilian drones, raising collision risk for pilots and ground crews alike. Thirty-five aircraft, including assets from DNR and the National Guard, were assigned to the Spokane fires on August 3. “Vital seconds, minutes, are lost” with every grounding, Rodruck said.

    Legal Exposure and Public Messaging

    Interfering with firefighting operations on public lands is a federal crime that can carry up to a year in prison, and flying a drone inside a wildfire-related temporary flight restriction can also trigger a civil penalty of $20,000 or more, according to FireRescue1’s reporting. The Forest Service has run a public-awareness campaign, “If You Fly, We Can’t,” aimed at recreational drone operators, warning that even a very small drone can damage a helicopter’s tail rotor or disable an aircraft engine. Both agencies encourage anyone who spots a drone inside restricted wildfire airspace to call 911 or report it directly to the FAA.

    Sources

  • XPeng’s Robotics Unit Raises $900 Million at $6.3 Billion Valuation

    XPeng’s Robotics Unit Raises $900 Million at $6.3 Billion Valuation

    Chinese automaker XPeng said on Monday, August 24, 2026, that its robotics business had raised more than $900 million in its first funding round, valuing the unit at over $6.3 billion and setting a record for a single private financing in China’s embodied AI sector, according to Reuters.

    Record Round for a Standalone Robotics Business

    The round was led by IDG Capital, with Tencent and Alibaba participating as strategic investors, XPeng said in a statement. The financing establishes a standalone market valuation for XPeng’s robotics operation, separate from its automotive business, and will fund robotics hardware and software development, training and refinement of XPeng’s Physical AI models, collection of high-quality training data, construction of mass-production infrastructure, and international expansion, according to the company.

    At the center of the robotics unit’s strategy is IRON, XPeng’s next-generation general-purpose humanoid robot, which the company says combines a human-like physical design with an internally developed AI and control architecture spanning hardware, software, processors and motion systems. XPeng has said IRON features 76 degrees of freedom across its body, including 21 in each hand. The company plans to begin mass production of IRON by the end of 2026, with initial deployments at its retail stores and industrial campuses, followed by commercial sales and deliveries in China and overseas markets in 2027. XPeng CEO He Xiaopeng said in June he would personally lead the robotics business as the company pushes toward mass production.

    Funding Comes Amid Pressure on XPeng’s Core Business

    The robotics financing arrives as XPeng’s automotive business faces intensifying competition from domestic Chinese manufacturers and from Tesla in both overseas and domestic markets. According to AI News, XPeng’s publicly traded shares were down more than 7 percent on the day the funding was announced, with a roughly 51 percent decline over the preceding 12 months — underscoring that investors are pricing the robotics division well ahead of, and somewhat independently from, the parent company’s struggling share price. The split suggests investors see China’s embodied-AI and humanoid-robotics race as a distinct growth story from XPeng’s core electric-vehicle competition.

    Sources

  • Denver International Airport Logged Six Perimeter Fence Breaches in Three Years, Records Show

    Denver International Airport Logged Six Perimeter Fence Breaches in Three Years, Records Show

    A Pattern of Breaches Preceding a Fatal Incident

    Denver police have responded to six cases of people breaching the perimeter fence at Denver International Airport since January 2023, according to police records reported by The Denver Post on August 17, 2026. The most serious was a fatal incident on May 8, 2026, when 41-year-old Michael Mott scaled the airport’s eight-foot, barbed-wire-topped security fence and walked onto a runway shortly before 11:20 p.m. He was struck and killed by a Frontier Airlines aircraft that was accelerating for takeoff. Denver’s chief medical examiner, Dr. Sterling McLaren, ruled Mott’s death a suicide, according to the Post.

    Of the other five recorded breaches, one involved a man who crashed through a perimeter fence gate and drove onto the airfield, causing more than $2,000 in damage; another involved a man who jumped the fence after crashing his car nearby and was later found sitting on an active taxiway around 6:40 a.m.; and a third involved a man who told police he was trying to walk to Texas. Two additional trespassing cases involved people jumping the boundary fence into the airport’s warehouse area. At least two of the eight individuals involved in these incidents had active arrest warrants at the time of their breach, the Post reported, citing probable-cause statements.

    How the Numbers Compare Nationally

    There is no national database that tracks airport perimeter breaches specifically, and airports report trespassing incidents inconsistently, according to Annmarie Heth, an assistant professor of aviation and aerospace sciences at Metropolitan State University of Denver who was interviewed by the Post. The Federal Aviation Administration does separately track runway incursions — a broader category covering air traffic control errors, pilot violations, and unauthorized pedestrians or vehicles on runways and taxiways — at airports with control towers, including DIA. The FAA’s database recorded roughly 5,890 runway incursions nationwide between January 2023 and June 2026, of which 1,022 involved unauthorized pedestrians or vehicles. Only two of the six DIA police-documented perimeter breaches during that period appear in the FAA’s database, which lists a total of 37 incidents involving unauthorized vehicles and pedestrians at DIA dating back to April 2006, per Post reporting.

    Officials Say the Uptick May Reflect Better Detection, Not Worse Security

    Heth told the Post that fatal breaches like the one that killed Mott are extremely rare and that advanced perimeter technology usually allows security personnel to intercept trespassers before an incident escalates. “Fences are there to keep honest people out,” she said. “If somebody is really intent on getting through a fence, they’re going to get through.” She added that improved sensors, cameras, analytics and staff training may explain why more incidents are being detected and reported today compared with when she worked as an airport operations manager in Florida between 2009 and 2015, when even wind gusts could trigger perimeter alarms and prompt an investigation.

    A Denver Police Department spokesman, Doug Schepman, said the department’s dedicated Airport Police Bureau at DIA works closely with airport operations staff, monitors data on breach trends, and adjusts resources accordingly. DIA officials declined to comment on the individual trespassing incidents when contacted by the Post. The FAA and the National Transportation Safety Board also declined to comment specifically on DIA’s perimeter breaches.

    Sources

  • Nvidia in Talks to Invest in Perplexity at $30 Billion-Plus Valuation

    Nvidia in Talks to Invest in Perplexity at $30 Billion-Plus Valuation

    Nvidia is discussing an equity investment in Perplexity as part of a new funding round that would value the AI search startup at more than $30 billion, The Information reported on August 23, 2026, citing people familiar with the discussions. Reuters also reported the talks but said it could not independently verify the details.

    A Fast-Rising Valuation

    The prospective round would put Perplexity’s valuation more than 50 percent above the $20 billion mark it reached in a September 2025 round, and above the $23 billion valuation reported in a subsequent January 2026 financing, according to the reporting. Perplexity’s annualized revenue has roughly tripled this year, climbing from about $250 million to more than $750 million, a jump largely attributed to “Perplexity Computer,” an AI agent product that automates multi-step professional tasks and drives significantly higher token consumption than conventional search queries. At $750 million in annualized revenue, a $30 billion valuation would price the company at roughly 40 times sales.

    Nvidia is not a new backer: it previously participated in Perplexity’s Series B in January 2024, its unicorn round the same year, and an $18 billion extension round in July 2025 alongside SoftBank Vision Fund 2, NEA and IVP. Per The Information, Nvidia had also weighed a technology-licensing arrangement and hiring some of Perplexity’s staff before the conversation shifted toward a straight equity stake.

    Search as AI-Agent Infrastructure

    Nvidia CEO Jensen Huang has previously said in interviews that Perplexity is his personal go-to AI assistant, and Nvidia has functioned as something of a financial backstop for AI startups in recent years, investing in companies that in turn spend heavily on its chips. Perplexity CEO Aravind Srinivas has said he is considering a public listing around 2028. The talks come as Perplexity competes not only with Google and OpenAI’s distribution advantages but with agent-native search challengers such as Exa, which Nvidia’s venture arm has also backed.

    As of publication, neither Nvidia nor Perplexity has confirmed the terms of the discussions publicly, and the reported valuation and structure could still change before any deal is finalized.

    Sources

  • CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

    CISA, NSA and FBI Warn of Active AI-Assisted Reconnaissance Against Siemens S7 PLCs

    Joint Advisory Warns of Active Targeting

    The National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency released a joint cybersecurity advisory on August 19, 2026, warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The advisory, designated AA26-231A, covers the S7-200, S7-300, S7-400, S7-1200 and S7-1500 controller families, including the F-series safety variants.

    According to the agencies, the activity spans several critical infrastructure sectors, with Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities named as the most-targeted. Siemens S7 controllers are also used in the Defense Industrial Base, which the advisory says could be affected as well. CISA describes the threat as “not a theoretical risk” and says exploitation of poorly protected PLCs could disrupt industrial processes, damage equipment, trigger safety incidents through manipulation of interlocks or emergency shutdown systems, and cause cascading effects across interconnected systems.

    AI-Generated Scripts and the Snap7 Library

    The advisory says the threat actors are combining publicly available industrial automation tooling with AI-assisted scripting to build custom software that mimics legitimate operational-technology monitoring tools. Specifically, the agencies describe adversaries using internet-scanning services such as Censys and ZoomEye to locate exposed S7 controllers, then deploying AI-generated Python scripts built on the open-source snap7 library to read and write PLC memory, configuration data and ladder-logic programs over the S7comm protocol on TCP port 102. CISA characterizes the use of AI to generate this exploitation code as “an evolution in threat actor capabilities” that lowers the technical bar for building working industrial-control exploitation tools and speeds adversaries’ ability to adapt to defenses.

    The agencies assess the pattern observed so far as consistent with reconnaissance and capability development — testing techniques against specific PLC models and using read access to understand target environments — rather than a confirmed disruptive attack. The advisory maps the observed techniques to the MITRE ATT&CK for ICS and Enterprise frameworks and to MITRE D3FEND countermeasures.

    A Distinct Threat From the Iran-Linked Water Sector Warning

    AA26-231A is separate from an earlier joint advisory, AA26-097A, which described confirmed Iran-linked exploitation of PLCs at a U.S. water-sector victim, including modification of ladder logic that disabled safety shutdown and alarm functions. The new Siemens-specific advisory does not attribute the reconnaissance activity it describes to any named nation-state or group, and it explicitly frames the observed activity as pre-attack staging rather than a confirmed disruptive incident. CISA also cautions that PLC targeting more broadly extends beyond Siemens equipment, and that the Siemens-specific guidance in the advisory should be treated as one subset of a wider threat landscape facing internet-exposed industrial controllers.

    Mitigations Recommended by the Authoring Agencies

    The agencies are urging asset owners to inventory all Siemens S7 controllers in their environments, apply available firmware and engineering-software patches, verify that PLCs are not reachable from the internet, and block TCP port 102 at perimeter firewalls. Additional recommendations include restricting engineering-workstation access through IP or MAC allowlisting, enabling PLC password protection and configurable read/write protection levels, deploying ICS-aware intrusion detection, and monitoring for anomalous S7comm traffic patterns, unauthorized write operations, and use of the snap7 library outside approved engineering systems. The advisory also recommends organizations that rely on third-party systems integrators or managed service providers share the guidance with those parties directly, since asset owners may not always be aware that PLCs accessible to vendors are also exposed to the wider internet.

    Sources

  • Anthropic Investors Reportedly Target $2 Trillion Valuation for October IPO

    Anthropic Investors Reportedly Target $2 Trillion Valuation for October IPO

    Anthropic investors are pushing for a valuation of at least $2 trillion for the AI company’s planned initial public offering, which could launch as soon as October 2026, according to the Financial Times. If it materializes at that level, the listing would be the largest IPO in history, surpassing SpaceX’s $1.77 trillion debut in June 2026.

    A Valuation Built on Projected Growth

    Six Anthropic backers told the Financial Times that the $2 trillion figure comes from investors and bankers circling the deal rather than from Anthropic itself; senior executives have not confirmed an IPO valuation target even in private conversations, per the FT’s reporting. Anthropic was last valued at roughly $965 billion following a private round in May 2026, meaning a $2 trillion debut would roughly double that mark in under half a year.

    The case rests heavily on revenue trajectory. Anthropic said in May that annualized revenue had exceeded $47 billion, and backers now expect that figure to reach between $100 billion and $120 billion by the end of 2026. “If Anthropic is growing 800 per cent a year, you’d think at the incredibly low end they would trade at 30 times [revenue],” one investor told the FT — a multiple that would actually imply a $3 trillion valuation. Investors have pointed to AI-adjacent public companies such as Palantir and Nebius, which have traded near 55 times revenue this year, as rough comparables in the absence of a direct publicly listed rival. Morgan Stanley, Goldman Sachs and JPMorgan are reported to be leading the offering.

    Risks Facing the Record Bid

    Anthropic’s path to a record-setting debut carries acknowledged risks. The company’s flagship model costs more than two and a half times as much to use as OpenAI’s leading product, according to data from AI analysis firm Artificial Analysis cited in the reporting, while lower-cost Chinese open-weight models continue to close the capability gap. Revenue growth also slowed in June after the U.S. Commerce Department imposed a temporary export control on Anthropic’s top models, though investors told the FT that business rebounded afterward. Nearly $100 billion in venture capital, sovereign wealth and institutional money has flowed into Anthropic during 2026 alone, underscoring how much investor appetite already assumes continued hypergrowth.

    Because the valuation target originates with investors and bankers rather than an official filing or company confirmation, it should be read as a market expectation rather than a settled figure. Anthropic has not publicly disclosed IPO plans, pricing, or timing as of this writing.

    Sources

  • DOJ and FBI Seize Domains Behind Chinese State-Sponsored QScan and QTRouter Hacking Platforms

    DOJ and FBI Seize Domains Behind Chinese State-Sponsored QScan and QTRouter Hacking Platforms

    The U.S. Department of Justice and FBI announced August 26, 2026 that they had executed court-authorized domain seizures to disable two linked hacking platforms, known as QScan and QTRouter, used by a China-based, state-sponsored group the department identified as QTFY. According to the DOJ’s press release, court documents unsealed in the Southern District of California name Nanjing Xinjiuwei Network Technology Company as the operator of QTFY, which the department said sells hacking services to clients including the Chinese Ministry of State Security and the People’s Liberation Army.

    Court filings describe QScan and QTRouter as complementary tools: QScan searches the internet and automatically infects vulnerable internet-of-things devices, such as home routers and security cameras, while QTRouter forms an obfuscation network from those compromised devices that lets operators route attack traffic through infected machines in more than 130 countries, concealing the true origin of intrusions, FBI Cyber Assistant Director Brett Leatherman said in a video statement released by the bureau.

    The DOJ said the disruption made both platforms inoperable because the seized domains were hard-coded into their communication and authentication functions, a technique reported by The Record based on court documents. According to the department, victims of QTFY’s activity since at least 2018 include NASA, the Federal Reserve, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate, as well as power companies, telecommunications providers, hospitals, financial institutions and defense contractors.

    Leatherman described the action as the disruption of “a global botnet used by a Chinese state-sponsored group … to target U.S. critical infrastructure,” adding that QTFY had “exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies, telcos, and major hospital systems” for nearly a decade. The FBI said QTFY’s services were also sold to customers beyond the Chinese government, though it did not name additional clients.

    The takedown is the latest in a series of U.S. actions targeting Chinese state-linked infrastructure-scanning and botnet operations, and underscores continuing concern among federal agencies about the use of compromised consumer and small-business IoT devices, including routers and security cameras, as staging infrastructure for espionage-linked intrusions into critical infrastructure networks.

  • Pro-Russian Hacker Group Claims Multi-Day DDoS Attack on Norway’s Digital Government Services

    Pro-Russian Hacker Group Claims Multi-Day DDoS Attack on Norway’s Digital Government Services

    A pro-Russian hacking group calling itself Server Killers claimed responsibility on Wednesday, August 26, 2026 for a distributed denial-of-service attack that disrupted Norwegian government digital services for several days, according to the Associated Press and multiple cybersecurity outlets including BleepingComputer and The Record. The group said in a Telegram post, widely reported by Norwegian media, that it had “declared cyber war” on Norway after the country renewed its security cooperation with Ukraine on August 23.

    Are Kvistad, a spokesperson for the Norwegian Digitalization Agency (Digdir), told the AP that the attack began Monday, August 24, and had affected multiple government digital services over three days. BleepingComputer reported that the attack started at 03:38 CEST that morning and targeted infrastructure supporting services operated by Digdir and its operations provider, Vivicta.

    The Record reported that the incident disrupted roughly ten digital services used for identity verification, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access. Among the affected systems was ID-porten, Norway’s digital identification gateway, which the outlet said has more than 4.5 million users and provides access to services including BankID and MinID.

    Security Affairs, which first reported the incident on August 25, characterized it as a DDoS attack rather than an intrusion resulting in data theft. The Server Killers group’s Telegram claim, cited by ABC News, tied the timing directly to Norwegian Prime Minister Jonas Gahr Støre’s meeting with Ukrainian President Volodymyr Zelenskyy around Ukraine’s National Flag Day on August 23.

    Norwegian officials had not, as of the claim’s publication, independently confirmed Server Killers as the responsible party, and cybersecurity researchers caution that DDoS attribution based solely on a threat actor’s own claims should be treated carefully. The incident nonetheless illustrates how European governments’ digital-identity infrastructure has become a recurring target for politically motivated disruption tied to support for Ukraine.

  • Cyberattack Disrupts Boston Scientific’s Global Order Processing and Shipping

    Cyberattack Disrupts Boston Scientific’s Global Order Processing and Shipping

    Boston Scientific, the Massachusetts-based medical device manufacturer, disclosed on August 26, 2026 that a cyberattack identified the previous day had disrupted its global operations, including its ability to process and ship customer orders. According to a filing with the U.S. Securities and Exchange Commission reported by Cybersecurity Dive, the company said the incident affected its IT network and “certain operating systems and business applications” beginning August 25.

    In a statement posted to its newsroom, Boston Scientific said it activated its incident response plan upon detection and is working with third-party cybersecurity experts to investigate, contain and remediate the threat. The company said it could not immediately estimate how long full restoration of affected systems would take, according to reporting from SecurityWeek and pharmaphorum.

    The disruption has drawn attention because of Boston Scientific’s role as a major supplier of cardiovascular, endoscopy and neuromodulation devices to hospitals and clinics worldwide. Dray Agha, senior manager of security operations at the security platform Huntress, told pharmaphorum that “the attack on Boston Scientific demonstrates that cyber incidents in the MedTech sector extend far beyond IT and actively threaten the global healthcare supply chain,” warning that an inability to process or ship medical orders “creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line.”

    Boston Scientific has not publicly attributed the attack to a specific threat actor or confirmed whether patient or customer data was exposed. Medical Device Network, citing the company’s own account, reported that the incident has continued to affect access to operating systems and business applications supporting order processing days after it was first detected.

    The incident adds to what industry outlets describe as a continuing pattern of cybersecurity incidents affecting medical technology manufacturers in 2026, underscoring the exposure that device makers face when enterprise IT outages ripple into physical supply chains for hospitals and clinicians who depend on timely equipment and consumable shipments.

  • CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    The US Cybersecurity and Infrastructure Security Agency published A Tale of Two SOCs: Insights From Two Red Team Assessments on August 25, 2026. The advisory compares assessments conducted at two critical-infrastructure organizations and shows how similar adversary techniques produced very different defensive outcomes.

    Two assessments, two outcomes

    At the first organization, CISA’s red team gained access to multiple workstations, elevated privileges across the domain and moved laterally without being detected by the security operations center. The assessment identified gaps in monitoring, cloud visibility, identity protection and communication between separate security teams.

    At the second organization, the SOC detected and quarantined the red team’s initial access. That response forced the assessors to move to an assumed-breach scenario. Defenders also detected and contained portions of the follow-on activity, limiting the red team’s freedom of movement.

    What made the difference

    CISA’s comparison emphasizes operational fundamentals rather than a single security product. Tuned alerts, established network and identity baselines, documented escalation procedures, communication between SOC teams and system owners, and visibility across IT, cloud and operational-technology environments all affected the result.

    The advisory also highlights the risk created by fragmented tooling. Multiple SOCs or endpoint-detection platforms do not automatically improve security when teams cannot see one another’s alerts or coordinate investigations. Cloud identity and application controls require the same operational ownership as traditional endpoint and network monitoring.

    Why it matters for critical infrastructure

    Critical-infrastructure operators increasingly manage connected IT, cloud and OT environments. An attacker who begins on a workstation may use identity systems, remote administration paths or cloud services to move toward operationally important resources. Detection quality therefore depends on whether defenders can correlate events across those boundaries before activity becomes a domain-wide compromise.

    Red-team assessments do not predict every real intrusion, but they provide controlled evidence of how existing people, procedures and technology perform against realistic adversary behavior. CISA’s findings support a practical priority: organizations should test whether their SOC can detect and coordinate a response across the complete environment, rather than assuming that deployed tools are functioning as an integrated defense.

    Sources

    Follow additional developments on Technology News.