Europe’s wind and solar farms leave controls exposed, raising the risk of sabotage
Dutch researchers identified 8,547 internet-facing systems across 35 countries, with potential full control at roughly 181 sites

Check out my latest piece for CSO on how AI is turning offensive security into a continuous necessity, even as human pentesting skills remain invaluable.
Dutch researchers warned that rhousands of administrative systems at wind and solar power parks in Europe are exposed to the internet, potentially giving attackers access to interfaces that can stop turbines and raising the risk of sabotage.
The exposed systems included administrative and login interfaces as well as operational interfaces showing data and controls.
However, one of the researchers, Soufian El Yadmani, from internet-scanning company Modat, said that researchers believed full control would have been possible in the case of around 181 sites.
One turbine's web page showed live data, "Start, Stop and Reset" buttons and the turbine's location, the research said. Some systems controlled several turbines or a whole farm."What we can map in hours, an attacker can map in hours too," the report said. The researchers urged operators to take admin interfaces off the internet immediately.
El Yadmani and Bouke van Laethem of the Dutch National Cyber Security Centre presented their findings at the ONE Conference in The Hague.
Turbines or arrays closely linked to public infrastructure were a special concern, El Yadmani said. "If you can turn off the energy within the city or the airport, imagine that at a larger scale."Using machine learning to sort and cluster data, the pair said they identified 8,547 internet-facing systems they could link to at specific solar parks (7,942) and wind farms (605) in 35 European countries, which should not have been exposed to the internet.
Most of the systems found were admin pages with login screens.
Spain had the most exposed solar systems, with 2,766, followed by Greece with 1,860, they said.
Germany has Europe's most installed solar capacity, and 672 exposed solar systems. However it had the most exposed wind systems with 212, with Italy close behind at 192. The researchers said the rankings partly reflected where they had been able to link systems to specific sites. (Stephanie van der Berg and Toby Sterling / Reuters)
Related: Modat, mpakter, Ocean News and Technology, energynews.pro

Anthropic is expanding a program that allows vetted cybersecurity professionals to test its most powerful AI models with fewer safeguards, after its Project Glasswing initiative helped uncover more than 100,000 software vulnerabilities this year.
Its partners under Glasswing, an initiative aimed at securing the world's most critical software, found at least 129,000 verified vulnerabilities between April and July. Anthropic's own open-source scanning found 5,500 more between April and October.
More than 33,000 have so far been rated critical or high severity.
Anthropic said the figures are likely an undercount and expects the true impact to be at least five times higher, as the data comes from a survey of a limited number of partners.
The revamped Cyber Verification Program, or CVP, announced on Tuesday combines two programs Anthropic has run for the past six months.
The first, Glasswing, gave organizations securing critical software access to Claude Mythos, Anthropic's most cyber-capable family of models. The second, the original CVP, gave vetted security teams reduced safeguards on Claude Opus and Sonnet models.
The company's April unveiling of Claude Mythos Preview raised fears that AI could hack software before it had been secured.
The new program has three tiers, each with its own verification requirements and security controls. All three include access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models.
The Defense tier covers work such as incident response and malware analysis. Security teams, critical infrastructure operators, open-source maintainers, and researchers with a record of reported vulnerabilities can apply.
The Red Team tier adds authorized penetration testing and red-teaming, but only organizations can apply.
The Specialized tier has the fewest restrictions and is reserved for a small group of organizations authorized to test safety-critical systems such as power grids, flight systems and interbank transfer infrastructure.
Anthropic announced an expansion of its Claude for Startups program, offering subsidized access to its AI models and a variety of other benefits to qualifying companies.
The new version of the program, which launched as part of Anthropic’s SF Tech Week event, provides a free year of Claude Team, Anthropic’s paid plan for groups, with up to five premium seats, as well as $1,000 in API credits for building with Claude. Companies will also get access to Claude Marketplace, which lets them build plug-ins for the service. Companies can also book virtual office hours with Anthropic’s Applied AI team. (Anzar Mehraj and Jeffrey Dastin / Reuters and Russell Brandom / TechCrunch)
Related: Anthropic, Claude Support, Bloomberg, The Information, Unite.AI, Quartz, Help Net Security

Mistral said it would soon release a new open-weight AI model that it claimed would rank among the best globally, part of efforts to grow its appeal, lock in more customers and better compete with US rivals.
The French artificial-intelligence startup said it was launching a public preview of Mistral Large 4, dubbed Le Chonk, so it could work with developers, cybersecurity experts and state authorities to evaluate how the model behaves. It plans to release the weights, or the trained parameters of the model, on Oct. 27.
Since its early days, Mistral has been a staunch advocate of open-weight models that are publicly available for anyone to download and modify, saying they give users the flexibility to tailor them to their needs while protecting their data and intellectual property.
The company said that closed models—where developers keep the source code, training data, and underlying model weights hidden—could pose security risks for users because they sometimes block responses to useful cyberdefense requests.
A more capable model would allow Mistral to appeal to more consumers and enterprises, grow its customer base and better compete with the likes of ChatGPT maker OpenAI and Anthropic. Mistral said it had trained its new model on about 4,000 Nvidia Grace Blackwell graphics processing units deployed at its own data centers in Europe.
It said Mistral Large 4 would rank among the top open-weight models globally on aggregate benchmark performance, and the strongest open-weight model developed outside China by a substantial margin.
“The model capabilities will further improve as we scale up our training capacity,” Guillaume Lample, Mistral co-founder and chief scientist, said.
The announcement comes about a month after Mistral completed a funding round led by South Korea’s Samsung Electronics that lifted its valuation above $24 billion, giving it additional firepower to invest in model development. (Mauro Orru / The Wall Street Journal)
Related: Artificial Analysis, CNBC Technology, WebProNews, Axios, The New Stack, Digital Journal, TestingCatalog AI News, Slashdot, Tech.eu, CNET, Simon Willison's Weblog, The Register, Tech Insider, shattered.io
A group of companies is coming together to try to simplify the process of bringing AI personal bots such as Muse into the business world.
Meta, Walmart, Stripe and a handful of other companies are publishing what they’re calling a “personal agent protocol.” It’s an open standard meant to dictate how artificial intelligence agents can interact with businesses.
Enterprise AI startup Sierra, co-founded by former Salesforce co-CEO Bret Taylor, is part of the group. Taylor, who’s also chairman of OpenAI and is leading the initiative, told CNBC in an interview that companies have a lot of work to do to figure out how and when personal agents are able to access information.
“Companies will know when it’s a personal agent versus an actual person. For a lot of companies there’s a risk: you don’t want just a random bot that isn’t acting on behalf of a person to have access to this service,” Taylor said. “It is kind of chaos until such a standard exists.”Meta’s Muse has become the most popular and buzzy version of personal AI agents since hitting the market in early September. It soared to the top of Apple’s App Store and remains there, ahead of ChatGPT. However, Amazon is among the companies that have blocked Meta’s agents, citing worries of website scraping.
Amazon also blocked Perplexity’s AI agent and sued the startup in November, alleging the company took steps to “conceal” its AI agents so they could continue to scrape Amazon’s website without approval. Perplexity called the lawsuit a “bully tactic.”For the new standard, Taylor compared it with the experience of logging into other websites with Google or Facebook credentials, technology he worked on when he was tech chief at Facebook. He said the practice will help with authentication so that businesses know if they’re dealing with a bot, and will provide visibility into what personal agents are actually doing through these websites.
David Singleton, vice president of engineering and consumer products at Meta Superintelligence Labs and former technology chief at Stripe, highlighted security. In order for agents to work well, he said, customers need to share credit card and personal information, and the new standard creates some level of visibility and control.
While OpenAI and Anthropic aren’t on board now, Taylor said he expects the AI giants to participate, and indicated he will be “really disappointed” if it’s not being used by competitors. (Kate Rooney / CNBC)
Related: Sierra, Quartz, Silicon Angle, Gizmodo, CMS Wire, Decagon, Facebook, Quartz, Unite.AI, The Verge, Forkast

The US Justice Department announced that Michael Smith, a man who used AI songs to steal millions in music royalties, has been sentenced to 18 months in prison, capping off the first-ever criminal case over streaming fraud.
He pleaded guilty in March to using AI to generate thousands of songs and then streaming them billions of times with bots, generating more than $8 million in royalties. His was the first criminal conviction over a tricky problem that’s plagued the music industry for years.
Ahead of sentencing, his lawyers had asked the judge for no prison time, arguing the harm to any single artist was “insignificant” and “no victim suffered any real harm.” But at a hearing on Tuesday (Oct. 6) in Manhattan federal court, Judge John G. Koeltl ordered him to serve a year and a half in jail, followed by two years of supervised release. (Bill Donahue / Billboard)
Related: Justice Department, Music Business Worldwide, Unite.AI, Bleeping Computer
Spend less time finding cybersecurity news. Get more out of it.
Metacurity delivers the cybersecurity news, analysis, and insight that would take you hours—and sometimes days—to assemble yourself.
Every weekday, we sift through thousands of news articles, press releases, filings, court documents, and research reports, including details that vendor announcements and PR pitches leave out. We tell you what changed, why it matters, and what deserves your attention. Minimal vendor marketing. No outrage bait. No SEO filler.
A paid subscription gives you:
- The full Metacurity archive: Every newsletter, searchable and browsable.
- Our weekly long-reads roundup: The best cybersecurity writing from across the industry, selected and vetted to make your reading time count.
- Specialized reports and analysis: Periodic deep dives that go beyond the daily headlines.
- A direct role in sustaining independent journalism: Your subscription helps keep our editorial priorities focused on readers and the cybersecurity community.
If Metacurity saves you time, helps you spot an important development, or gives you a clearer understanding of the industry, please consider becoming a paid subscriber. Your support keeps that work going.
Subscribe today—and thank you for reading and supporting Metacurity.
Goldman Sachs Group Inc.’s data was exposed earlier this year in a hack of accounting firm EY, according to a person familiar with the matter.
The bank’s systems weren’t affected by the attack, a Goldman spokesperson said in an emailed statement, adding that client assets weren’t impacted and “remain safe.”
“As with other clients we understand were affected, we have been in regular contact with EY and are focused on working with them to support any of our clients impacted by their security incident,” the spokesperson said. (Katherine Chiglinsky / Bloomberg)
Related: Shattered.io, Cyber Security News, Financial Times
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket.
The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory. However, exploitation requires knowing the exact name of the file and path.
“This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the security advisory.
“Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents,” Atlassian says.
Atlassian urges system administrators who manage self-hosted instances to apply the security updates immediately. Cloud customers need to take no action, as the vendor has automatically patched the products.
If immediate patching is not possible, the company recommends restricting external network access, including for internet-facing instances that require user authentication.
Temporary mitigations include adding a web application firewall (WAF) or proxy rule blocking specified traversal patterns across all affected products, Tomcat RewriteValve rules for Confluence, JSM, Jira, Bamboo, and Crowd, or a URL rewrite rule for Bitbucket. (Bill Toulas / Bleeping Computer)
Related: Atlassian, SC Media, The Register, Cyber Security News, Help Net Security, WatchTowr, Cyber Kendra, Reddit - Information Security News, Daily Security Review, Reddit cybersecurity, r/netsec, The CyberSec Guru, SOC Prime
Google said attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday.
The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.”
Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked. (Dan Goodin / Ars Technica)
Related: Google
Hadrian, an agentic AI offensive security platform, has raised $40 million in a funding round co-led by Forgepoint Capital International and Smart Fin.
Existing investors HV Capital, Motive Partners, Picus Capital and Oetker Ventures also participated. The round brings Hadrian's total funding to $65 million. (Tamara Djurickovic / Tech.eu)
Related: SiliconANGLE, The SaaS News, FinSMEs, Startup.eu
AI-native IT service management (ITSM) and enterprise automation platform company Serval has acquired software supply chain security startup Ensignia and named its founder and CEO, Sam Stewart, head of security, strengthening the security infrastructure around the company’s AI-powered enterprise automation platform.
Financial terms of the acquisition were not disclosed.
Stewart will lead Serval’s security organization across detection and response, corporate security, application security, and infrastructure security. His responsibilities will also include the guardrails, permissions and audit trails governing how Serval’s automation agents interact with customer systems. (CityBiz)
Related: Business Wire, Unite.AI
Best Thing of the Day: This Is Why Journalism Matters
Thanks to reporting by Futurism, Google has updated its guidelines to explicitly forbid the use of fake bylines and AI-generated headshots, saying it will no longer “prioritize” sites that engage in those deceptive practices.
Worst Thing of the Day: This Is One Reason Why You Shouldn't Ask Enemies to Take Out Two of Your Top Cities
According to California Governor Gavin Newsom, after Donald Trump suggested that Iran could “take out” Los Angeles and San Diego, he woke up to a call from the head of California’s Office of Emergency Services alerting him that the department had detected an uptick in concerning cybersecurity activity and threat intelligence.
Bonus Worst Thing of the Day: This Meets the Definition of Creepy
Amazon’s “About you” page, which is currently in beta after launching this May, uses data from customers’ activity to generate details about them in categories like Product Preferences, Interests & Hobbies, and Home & Family.
Extra Bonus Worst Thing of the Day: BMW Apparently Doesn't Understand Stalking and Abuse
A woman named Jane reportedly failed to persuade BMW to remove her ex-husband from the location app in her car. Her ex-husband is now in jail for assault with a dangerous weapon with intent to do bodily harm after threatening and pointing a firearm at her.
Closing Thought
