Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • Pro-Russian Hacker Group Claims Multi-Day DDoS Attack on Norway’s Digital Government Services

    Pro-Russian Hacker Group Claims Multi-Day DDoS Attack on Norway’s Digital Government Services

    A pro-Russian hacking group calling itself Server Killers claimed responsibility on Wednesday, August 26, 2026 for a distributed denial-of-service attack that disrupted Norwegian government digital services for several days, according to the Associated Press and multiple cybersecurity outlets including BleepingComputer and The Record. The group said in a Telegram post, widely reported by Norwegian media, that it had “declared cyber war” on Norway after the country renewed its security cooperation with Ukraine on August 23.

    Are Kvistad, a spokesperson for the Norwegian Digitalization Agency (Digdir), told the AP that the attack began Monday, August 24, and had affected multiple government digital services over three days. BleepingComputer reported that the attack started at 03:38 CEST that morning and targeted infrastructure supporting services operated by Digdir and its operations provider, Vivicta.

    The Record reported that the incident disrupted roughly ten digital services used for identity verification, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access. Among the affected systems was ID-porten, Norway’s digital identification gateway, which the outlet said has more than 4.5 million users and provides access to services including BankID and MinID.

    Security Affairs, which first reported the incident on August 25, characterized it as a DDoS attack rather than an intrusion resulting in data theft. The Server Killers group’s Telegram claim, cited by ABC News, tied the timing directly to Norwegian Prime Minister Jonas Gahr Støre’s meeting with Ukrainian President Volodymyr Zelenskyy around Ukraine’s National Flag Day on August 23.

    Norwegian officials had not, as of the claim’s publication, independently confirmed Server Killers as the responsible party, and cybersecurity researchers caution that DDoS attribution based solely on a threat actor’s own claims should be treated carefully. The incident nonetheless illustrates how European governments’ digital-identity infrastructure has become a recurring target for politically motivated disruption tied to support for Ukraine.

  • Cyberattack Disrupts Boston Scientific’s Global Order Processing and Shipping

    Cyberattack Disrupts Boston Scientific’s Global Order Processing and Shipping

    Boston Scientific, the Massachusetts-based medical device manufacturer, disclosed on August 26, 2026 that a cyberattack identified the previous day had disrupted its global operations, including its ability to process and ship customer orders. According to a filing with the U.S. Securities and Exchange Commission reported by Cybersecurity Dive, the company said the incident affected its IT network and “certain operating systems and business applications” beginning August 25.

    In a statement posted to its newsroom, Boston Scientific said it activated its incident response plan upon detection and is working with third-party cybersecurity experts to investigate, contain and remediate the threat. The company said it could not immediately estimate how long full restoration of affected systems would take, according to reporting from SecurityWeek and pharmaphorum.

    The disruption has drawn attention because of Boston Scientific’s role as a major supplier of cardiovascular, endoscopy and neuromodulation devices to hospitals and clinics worldwide. Dray Agha, senior manager of security operations at the security platform Huntress, told pharmaphorum that “the attack on Boston Scientific demonstrates that cyber incidents in the MedTech sector extend far beyond IT and actively threaten the global healthcare supply chain,” warning that an inability to process or ship medical orders “creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line.”

    Boston Scientific has not publicly attributed the attack to a specific threat actor or confirmed whether patient or customer data was exposed. Medical Device Network, citing the company’s own account, reported that the incident has continued to affect access to operating systems and business applications supporting order processing days after it was first detected.

    The incident adds to what industry outlets describe as a continuing pattern of cybersecurity incidents affecting medical technology manufacturers in 2026, underscoring the exposure that device makers face when enterprise IT outages ripple into physical supply chains for hospitals and clinicians who depend on timely equipment and consumable shipments.

  • CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    The US Cybersecurity and Infrastructure Security Agency published A Tale of Two SOCs: Insights From Two Red Team Assessments on August 25, 2026. The advisory compares assessments conducted at two critical-infrastructure organizations and shows how similar adversary techniques produced very different defensive outcomes.

    Two assessments, two outcomes

    At the first organization, CISA’s red team gained access to multiple workstations, elevated privileges across the domain and moved laterally without being detected by the security operations center. The assessment identified gaps in monitoring, cloud visibility, identity protection and communication between separate security teams.

    At the second organization, the SOC detected and quarantined the red team’s initial access. That response forced the assessors to move to an assumed-breach scenario. Defenders also detected and contained portions of the follow-on activity, limiting the red team’s freedom of movement.

    What made the difference

    CISA’s comparison emphasizes operational fundamentals rather than a single security product. Tuned alerts, established network and identity baselines, documented escalation procedures, communication between SOC teams and system owners, and visibility across IT, cloud and operational-technology environments all affected the result.

    The advisory also highlights the risk created by fragmented tooling. Multiple SOCs or endpoint-detection platforms do not automatically improve security when teams cannot see one another’s alerts or coordinate investigations. Cloud identity and application controls require the same operational ownership as traditional endpoint and network monitoring.

    Why it matters for critical infrastructure

    Critical-infrastructure operators increasingly manage connected IT, cloud and OT environments. An attacker who begins on a workstation may use identity systems, remote administration paths or cloud services to move toward operationally important resources. Detection quality therefore depends on whether defenders can correlate events across those boundaries before activity becomes a domain-wide compromise.

    Red-team assessments do not predict every real intrusion, but they provide controlled evidence of how existing people, procedures and technology perform against realistic adversary behavior. CISA’s findings support a practical priority: organizations should test whether their SOC can detect and coordinate a response across the complete environment, rather than assuming that deployed tools are functioning as an integrated defense.

    Sources

    Follow additional developments on Technology News.

  • CISA Deadline Passes for Federal Agencies to Patch Actively Exploited Zimbra Flaw

    CISA Deadline Passes for Federal Agencies to Patch Actively Exploited Zimbra Flaw

    August 24, 2026, was the deadline for US federal civilian executive branch agencies to mitigate or discontinue use of Zimbra Collaboration Suite (ZCS) systems affected by CVE-2026-73570, a critical, actively exploited remote-code-execution flaw, after the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog on August 21, according to reporting from Dark Reading and The Hacker News.

    Background on the flaw

    Zimbra disclosed CVE-2026-73570, a command-injection vulnerability in the optional zimbra-snmp component that can allow unauthenticated remote code execution when SNMP notifications are enabled, and released a patched version, ZCS 10.1.20, on July 20, 2026. Poland’s CERT Polska warned on August 16–17 that the flaw was being actively exploited in the wild, and BleepingComputer reported on the active exploitation campaign on August 20. CISA added the vulnerability to its KEV catalog on August 21 and required federal civilian agencies to remediate by August 24.

    Why it matters

    Zimbra Collaboration Suite is widely used email and collaboration software across businesses and government agencies. An unauthenticated remote-code-execution flaw in internet-facing collaboration infrastructure, already confirmed as being actively exploited before a patch was applied everywhere, is exactly the scenario CISA’s KEV deadlines are designed to force organizations to act on quickly. Security teams running Zimbra Collaboration Suite that have not yet applied version 10.1.20 or later, or disabled the affected SNMP component, should treat this as an active, ongoing exploitation risk rather than a theoretical one.

    Sources

    More coverage like this is available on Technology News.

  • UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    A cybercrime group tracked as UAT-10147 is using artificial intelligence tools to help scale attacks against internet-facing servers, and is deploying a malware toolset called SPECTRE that includes endpoint detection and response (EDR) evasion capabilities and a Linux rootkit component, according to a report published by The Hacker News on August 24, 2026.

    What the campaign involves

    Reporting describes UAT-10147 as using AI-assisted techniques to accelerate reconnaissance and exploitation against server infrastructure, rather than relying solely on manual attack chains. Once inside a target environment, the group is reported to deploy SPECTRE, which combines capabilities to bypass or blind EDR tooling with a Linux-focused rootkit intended to maintain stealthy, persistent access.

    Why it matters

    The use of AI-assisted tooling to scale attacks against server infrastructure reflects a trend that both offensive and defensive researchers have flagged repeatedly through 2026: attackers are using automation and AI assistance to compress the time between reconnaissance and exploitation, while defenders increasingly rely on AI-assisted detection to keep pace. A rootkit paired with EDR-bypass capability is also a reminder that Linux server estates — often assumed to be lower-risk than Windows endpoints — remain a high-value target, particularly where detection tooling coverage is weaker than on the desktop fleet.

    Sources

    More coverage like this is available on Technology News.

  • Operation QUICSILVER: New QUICAgent Backdoor Targets Myanmar Government and IT Networks

    Operation QUICSILVER: New QUICAgent Backdoor Targets Myanmar Government and IT Networks

    Security researchers have disclosed a cyber-espionage campaign, tracked as Operation QUICSILVER, that targets government agencies and IT organizations in Myanmar using a previously undocumented backdoor named QUICAgent, according to a report published by The Hacker News on August 24, 2026.

    What researchers found

    The campaign is described as an active cyber-espionage operation focused on Myanmar government and information-technology sector networks. Reporting characterizes it as consistent with state-linked cyber-espionage tradecraft, deploying the QUICAgent backdoor to establish persistent access inside targeted networks. As is typical for early-stage espionage-malware disclosures, full attribution and complete technical indicators were still being documented publicly at the time of the report.

    Why it matters

    Espionage-focused backdoors like QUICAgent are built to stay hidden inside government and infrastructure-adjacent networks for extended periods rather than cause immediate disruption, which makes early public disclosure by researchers an important part of defenders’ ability to detect them. Campaigns targeting Southeast Asian government and IT-sector networks are also a reminder that nation-state espionage activity extends well beyond the small number of countries that dominate headlines, and that regional government and critical-infrastructure-adjacent IT operators remain a persistent target set.

    Sources

    More coverage like this is available on Technology News.

  • GSX 2026 Preview: Security Leaders Head to Atlanta in September

    GSX 2026 Preview: Security Leaders Head to Atlanta in September

    Global Security Exchange returns to Atlanta in September with an agenda built around the operational and management challenges facing security leaders. The ASIS International event combines a technology exhibition with education on physical protection, information security and organizational resilience.

    Event details

    • Dates: 14–16 September 2026
    • Venue: Georgia World Congress Center
    • Location: Atlanta, Georgia, USA

    Published themes and technology areas

    • Intelligence and organizational resilience
    • Information security and site security
    • Supply-chain and personnel security
    • Investigations, executive protection and governance

    Who should follow the event

    Security directors, enterprise risk leaders, consultants, integrators and practitioners responsible for protecting people, facilities, information and supply chains.

    Why it matters

    GSX is useful for teams comparing technology with policy and operating practice. Its published education tracks span both physical and information-security responsibilities, making it relevant to organizations managing converged risk.

    Registration and visit planning

    Registration is open through the official GSX website. ASIS also lists pre-conference programs for 12–13 September; visitors should check the current registration and program pages before booking.

    Sources

    Security & Fire Exhibitions

  • International Security Expo 2026 Preview: Resilience and Counter-Threat Technology

    International Security Expo 2026 Preview: Resilience and Counter-Threat Technology

    International Security Expo returns to Olympia London with a focus on national and organizational resilience. The official program architecture brings together counter-terrorism, perimeter and border protection, counter-UAS, critical-infrastructure security and the co-located International Cyber Expo.

    Event details

    • Dates: 29–30 September 2026
    • Venue: The Grand Hall, Olympia London
    • Location: London, United Kingdom

    Published themes and technology areas

    • Counter-terrorism and resilience
    • Perimeter, border and counter-UAS security
    • Critical-infrastructure protection
    • Cybersecurity convergence and live demonstrations

    Who should follow the event

    Government and public-sector security teams, critical-infrastructure operators, corporate security leaders, consultants, integrators and technology buyers.

    Why it matters

    The event connects policy and operational security with product evaluation. Specialist zones and demonstrations can help buyers examine how systems perform within wider protective-security programs.

    Registration and visit planning

    The organizer offers registration through the official event site. Olympia publishes the same dates and Grand Hall location; visitors should check both sites for current access and travel guidance.

    Sources

    Security & Fire Exhibitions

  • Cyber-Physical Security Convergence: Why IT and Security Teams Are Merging

    Cyber-Physical Security Convergence: Why IT and Security Teams Are Merging

    Physical security systems increasingly run on IP networks, cloud services and software platforms, while cyber incidents can create physical consequences. This is pushing IT, cybersecurity and physical-security teams toward closer operational convergence.

    Physical devices are cyber assets

    Cameras, door controllers, intercoms, alarm panels and sensors contain processors, firmware and network interfaces. Weak credentials, vulnerable software or unnecessary services can turn protective equipment into a cyber entry point.

    Identity and incident convergence

    Joiner, mover and leaver processes should update both digital and physical permissions. Badge activity, login records, forced doors and camera status can also provide stronger incident context when correlated.

    Architecture and governance

    Security devices should not sit on unmanaged flat networks. Segmentation, secure remote access, logging and vulnerability management require shared ownership across IT, cyber and physical-security functions.

    Cloud and operational technology

    Vendor security posture becomes part of procurement as video and access platforms move to cloud services. Critical infrastructure must also consider OT systems that control physical processes.

    Benefits and limitations

    Convergence can improve asset visibility, investigation and policy consistency, but it does not require every department to merge. Clear responsibilities and escalation paths remain essential.

    Conclusion

    Unified identity, shared data and careful correlation will continue to drive cyber-physical convergence. Isolated facilities systems are increasingly difficult to govern securely.

  • Small UK Power Generator Taken Offline After Iran-Linked Cyberattack

    Small UK Power Generator Taken Offline After Iran-Linked Cyberattack

    A small power generation site in the United Kingdom was shut down for four days in July 2026 following a cyberattack that has been linked to hackers associated with Iran, The Telegraph reported on August 23, citing sources familiar with the incident. UK outlets including the Independent, Metro and The Register subsequently confirmed elements of the report with government sources.

    What happened

    The affected facility has not been publicly named. UK officials describe it only as a “small-scale energy generator” — the kind of site that, according to reporting, often runs intermittently to top up the grid rather than providing baseload power. A UK government spokesperson confirmed the incident to multiple outlets, including The Register and CNBC, stating that the attack did not create a risk to the wider energy system.

    Official response

    “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system,” a UK government spokesperson said in a statement provided to several outlets. “The UK has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards.” The National Cyber Security Centre, part of GCHQ, said it does not routinely comment on individual incidents.

    Why it matters

    Reports describe this as the first time hackers linked to Iran have successfully disrupted a UK energy facility, and note that it occurred around the same time as a wave of cyberattacks attributed to Iran-linked actors against water utilities in the United States. Even when an individual facility is small relative to national grid capacity, incidents like this are a reminder that distributed and smaller energy assets — not just flagship power stations — are part of the critical infrastructure attack surface, and that operational technology segmentation and incident response planning need to extend across the full fleet of generation sites, not only the largest ones.

    Sources

    More coverage like this is available on Technology News.