Iran-linked UK power generator attack exposes a cybersecurity blind spot

A suspected Iranian-linked cyberattack took a small UK power generator offline for four days, exposing a potential blind spot: energy assets too small to threaten the grid may also fall below the cybersecurity rules designed to protect it.

Share
Iran-linked UK power generator attack exposes a cybersecurity blind spot
Bristol Proteus power plant. Source: Neil Owen.

A cyberattack believed to be linked to Iran knocked a small British power generator offline for four days last month, prompting warnings about the vulnerability of energy infrastructure.

That incident creates a potentially important paradox, namely that the plant was too small for its loss to threaten Britain's electricity supply, but its size may also have meant that it was subject to less cybersecurity oversight than facilities considered critical to the grid.

Crucial details about the incident — including who carried it out, how the attackers gained access, and whether they actually compromised industrial control systems — remain publicly unconfirmed.

The incident, first reported by The Telegraph, affected a small electricity generator and is believed to be the first Iranian-linked cyberattack to shut down a British power facility successfully.

The Financial Times reported that the facility was well below the threshold at which "important generators" are legally required to notify the government of cyber activity, according to an unnamed UK official, who described the site as "less than a rounding error compared to grid capacity." Nevertheless, the National Cyber Security Centre and Department for Energy Security and Net Zero briefed energy executives. They wrote directly to companies with "advice, direction and next steps" following the incident.

What remains unknown is whether this was an attack on industrial control systems at all. No technical indicators, malware samples, forensic reports or description of the intrusion path have been made public. Nor have British authorities said whether attackers obtained access to operational technology controlling electricity generation, compromised an IT or remote-management system, or caused the operator to shut the facility down as a precaution.

Those scenarios would represent substantially different levels of attacker capability.

UK Energy Minister Michael Shanks said that the affected generator was minimal in scale, that nobody lost power and that the incident posed no threat to Britain's wider electricity grid. "To be clear: there was no threat to the wider grid, and nobody lost power," Shanks wrote on LinkedIn. The British government has also stopped short of publicly attributing the attack to Iran.

For an adversary seeking to demonstrate an ability to disrupt Western infrastructure, smaller facilities could present attractive targets even if their loss has negligible impact on national electricity supply.

There is substantial precedent for Iranian-linked groups targeting operational technology. US authorities have repeatedly warned about attacks on internet-accessible industrial control systems. On Aug. 19, the NSA, FBI, Department of Energy, EPA and Cybersecurity and Infrastructure Security Agency warned of active attempts to compromise Siemens S7-series PLCs used across energy, water, manufacturing and other critical infrastructure sectors.

That warning followed cyber incidents affecting water utilities in multiple US states that cybersecurity experts suspect may be linked to Iran. Federal authorities, however, have not formally attributed those attacks to Tehran.

Iran's Islamic Revolutionary Guard Corps (IRGC) said last month that "any base used for aggression against Iranian territory constitutes a legitimate target for our forces." Moreover, the attacks against US water systems last month were thought to be orchestrated by a group called CyberAv3ngers, operated by the IRGC.

The Telegraph reported that the British generator incident occurred around the same period as attacks affecting water infrastructure in 12 US states. Timing alone does not demonstrate that the same group conducted the incidents, exploited the same technology, or formed part of a coordinated Iranian campaign.

Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, said that Iran "is realizing it can be more successful in its cyber attacks." She said the incidents suggest Iranian attackers are actively searching for weaknesses and finding exposed facilities.

The Guardian reported that the NCSC was understood not to have received outage reports from regulated power station operators. The NCSC and Department for Energy Security and Net Zero briefed energy company executives following the attack. They wrote directly to companies with security advice and recommended next steps, according to the Financial Times. Reuters reported that government, industry and security officials continue to assess the threat and strengthen protections.

Britain's most important generators are subject to mandatory cyber reporting requirements, while the facility targeted in this incident fell well below those thresholds. That raises a broader question about whether smaller energy assets could present adversaries with softer targets for producing visible physical disruption. Individually, the loss of one may barely register on the grid.

For now, the available evidence supports several conclusions: a small British generator suffered a cyber incident serious enough to leave it offline for four days; Iranian-linked hackers are suspected; the facility appears to have fallen below cybersecurity regulatory thresholds; and British security officials considered the incident important enough to warn the wider energy industry.

Until technical details emerge, the incident may be more revealing as a warning about the cybersecurity of smaller energy assets — and the gaps in what is known about them — than as evidence of a significant new Iranian capability against Britain's power system. (Tony Diver, Rozina Sabur, Matt Oliver / Telegraph, George Parker, Charles Clover, Tom Wilson and Malcolm Moore / Financial Times, Michael Shanks / LinkedIn, Kate ​Holton and Sam Tabahriti / Reuters, Ronny Reyes / New York Post, Ben Quinn / The Guardian)

Related: BBC, Cyber Security NewsNew York PostJoe.My.God, Security AffairsMetro.co.ukGB NewsThe i PaperThe GuardianThe Irish TimesCNBCTMCnetWashington ExaminerHuman Events, The Sun, Debug Lies News, Security Arsenal, RTE, CNBC, Gigazine, Middle East Eye, Times of India, Times of Israel, Chosun Daily, ABC News, The Times, Security Week, Cyber Security News, IT Pro, iNews, Hacker News, r/DeepStateCentrismr/ukpoliticsr/unitedkingdom, Slashdot


Metacurity is the cybersecurity news you'd need hours to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


A hacker who somehow landed their hands on GTA VI gameplay and the entire map and decided to leak them.

According to gaming creator NikTek on X, Cyberleek allegedly leaked the two clips and the entire map of Leonida as a protest against the publisher’s decision to pre-sell digital copies of the game. They said that they will not stop dropping leaks until the company issues a public apology and commits to doing better.

Various pirating and torrenting sites have been populated with download links to an alleged GTA 6 build that contains malware. According to experts from NordVPN, these downloads have been floating around all year, but have experienced a resurgence with the recent leaks. (Jowi Morales / Tom's Hardware and Cade Onder / IGN)

Related: XDA Developers, ForbesiPhone in CanadaNotebookcheckPC GamerThe IndependentTech4GamersKotakuTechRadarThe Game PostComic Book, Gameranx, Firstpost, TechPowerUp

As first reported by cyber threat monitoring platform Hackmanac, the cybercriminal group xpl0itrs claims to have compromised the infrastructure of Gruppo Spaggiari Parma, a technological provider for the Italian educational system, and to have stolen 6.1 TB of data from over 3,000 schools.

Hackmanac reported the alleged intrusion last Thursday, although the authorship, the real scope of access, and the size of the exfiltration remain unvalidated externally. There is also no public confirmation to ratify the 6.1 TB attributed to the attack.

The affected company develops tools such as ClasseViva, a digital ecosystem used to manage academic and administrative processes. This platform links the daily activity of schools with teachers, students, and families, so an intrusion of this type could affect information distributed across thousands of schools.

Among the data that the attackers claim to have exfiltrated are personal information of students and teachers, medical data, identity information, and contact data. The type of records mentioned matches the kind of sensitive information that educational institutions and their technology providers usually safeguard. (Miguel Gómez / APD)

Related: Spaggiari, Pasquale Pillitteri

Source: HackRisk.io

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability.

MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.

Tracked as CVE-2026-64849, this critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow's outbound webhook delivery was patched in version 3.15.0 and can be used by attackers without privileges to remotely access internal services or cloud metadata configurations on unpatched instances.

"The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and body to the caller," MLflow's security team says in a security advisory issued three weeks ago.

"An unauthenticated attacker who can reach the tracking server makes the server issue HTTP requests to arbitrary internal/loopback/cloud-metadata endpoints and reads the responses via /test: cloud instance-metadata (e.g. AWS IMDS IAM credentials), internal-only admin services behind the network boundary, and internal port/host scanning." (Sergiu Gatlan / Bleeping Computer)

Related: Mlflow on GitHub, CISA, Security Week, Cyber Daily, Security Affairs, HackRead

Chris Lehane, chief global affairs officer of OpenAI, said people should prepare to defend against “ongoing, persistent” cyber-attacks from AIs, as cutting-edge artificial intelligence models gain advanced capabilities to plan and launch offensives.

The leading AI company this week announced a pause in development of its most advanced internal models amid rising safety fears, and Lehane said: “We are hitting a different chapter, a different moment within AI, in terms of what the capabilities of this technology can do.”

OpenAI announced last week it has paused training of some frontier AI models to implement new safeguards, and it is unclear when training will restart after new guardrails have been put in place.

Lehane renewed calls for the US government to legislate to create rules for frontier AI safety, and said the fact that the most cutting-edge and unreleased AI models appear to be improving cyber offence faster than defence, was “among the reasons why I think it’s absolutely imperative that this country passes a national law that creates mandatory required safety standards, and within that the pause element would be inherent and endemic to that process." (Robert Booth / The Guardian)

Related: PYMNTS, The International News

Anthropic is now running its security scanner Claude Security on Claude Mythos 5.

The tool scans codebases for vulnerabilities and suggests patches, available in public beta for Enterprise customers. Scans count as normal token usage. Each finding includes a CWE category (a standard way to classify software flaws), severity ratings, and a suggested fix. Humans still have to sign off on every patch.

Anthropic is also plugging Mythos 5 into partner security products protecting hospitals, utilities, and banks. End users don't interact with the model directly and only see results like suggested patches. Several partners already use Claude Opus for security tools and are expected to switch to Mythos 5. Security vendors can sign up for partnership access. (Matthias Bastian / The Decoder)

Related: Claude, The New StackUnite.AI, Cyber Security News, MarkTechPostRuntimeWire

Anthropic’s US customers are using cheaper alternatives to its most powerful AI tool, raising questions about the group’s high-spending business model ahead of what is expected to be the biggest IPO of all time.

Spending on Fable 5, Anthropic’s largest and priciest model, has plateaued at only about 11 percent of overall outlay on the company’s tools, more than two months after its release, according to spending data from 70,000 companies collected by payments group Ramp.

This breaks a pattern of corporate users defaulting to the most powerful models. Analysts and investors in Anthropic said the change was primarily driven by Fable’s high price and the fact that older models are capable of handling the bulk of business demands. (George Hammond / Financial Times)

Related: Ramp, Drew Breunig, Capital BriefRuntimeWireSimon Willison's WeblogPYMNTSMarcus on AIImplicator.ai, Martin Alderson, Hacker News

According to researchers at Huntress, a phishing campaign targeting Black Hat and DEF CON attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own trusted certificate authority on compromised PCs.

They uncovered the campaign after one of their own researchers was contacted following Black Hat and DEF CON.  

The attacker approached the researcher via social media platform X, posing as CoinDesk's vice president and head of marketing, and asked for help with an upcoming conference.  

Rather than simply directing the target to a conventional phishing page, the attacker sent a Google Doc containing a custom Google Apps Script sidebar. The document appeared partially encrypted and asked the recipient to enter an "encryption key" supplied by the attacker. 

The key was designed to fail. The sidebar then offered instructions for supposedly decrypting the document, along with a "Manual Update" option. Both were intended to convince the target to download or execute malicious code.  

The campaign used different infection chains depending on the victim's operating system. Mac users were targeted with malware displaying characteristics consistent with Atomic macOS Stealer, or AMOS. (Sean Parker / Redmond Magazine)

Related: Huntress

The @HartmansDoeke X account that messaged the Huntress researcher, posing as CoinDesk's VP and Head of Marketing.

OpenAI urged its home state of California on Friday to “strengthen” its landmark AI law following recent autonomous hacks by its models — a notable step after the ChatGPT maker had previously opposed stricter rules.

The company said it was committed to working with the California Legislature and the governor on the issue, making it the first major AI lab to call for changes to the transparency law — the first of its kind in the country, which includes requirements for when companies must report certain safety issues.

“Recent incidents underscore both the need for these protections and the importance of updating them as new risks and safeguards emerge across the industry,” the company said in a post on LinkedIn.

The post from OpenAI’s global affairs team said it wanted to see the law amended to require monitoring of frontier models still being trained or evaluated for potentially serious incidents, “namely conduct that could bypass a third party’s security controls and compromise the third party’s confidential information.”

OpenAI also said it supported strengthening cybersecurity protections throughout the AI model-development process with an eye to stopping programs from evading security controls. (Chase DiFeliciantonio / Politico)

Related:  OpenAI on LinkedIn, Guardian, The Prompt, Business Insider

In a letter to California's Attorney General, private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems. 

The breach comes a month after security researchers sounded the alarm on a new hacking campaign targeting financial and private equity giants.

Apollo’s human resources chief Matthew Breitfelder said that hackers used a social engineering attack to gain access to the company’s cloud environment between July 6 and July 10. The hackers took names, birth dates, contact information (including home addresses), and Social Security numbers.

The letter does not specifically say who had their personal information stolen, such as Apollo employees or individuals at companies it owns. Apollo is one of the world’s largest private equity firms with $938 billion in assets under its management. (Zack Whittaker / TechCrunch)

Related: OAG.ca.gov, The Register, CyberScoop, Financial Times, The Paypers, Bloomberg, PYMNTS

Irregular, the company at the center of a series of incidents in which AI models compromised real-world computer systems during supposedly contained security evaluation, is facing criticism after publishing a postmortem that security experts say leaves key questions unanswered.

Irregular provides evaluation environments for other companies’ AI models, said Friday it was publishing “key findings” from its internal investigation, but the post provided no new information beyond that included in earlier disclosures and did not specify how many incidents occurred in total.

The company previously declined to say whether additional incidents had occurred beyond those announced by three competing frontier AI labs — OpenAI, Anthropic and Meta. Each said their models reached the public internet during testing by Irregular, blaming some form of “testing-environment misconfiguration” for the subsequent attacks on third-party networks.

A spokesperson for Irregular said at the time the company’s investigation was ongoing and that it could not “go into further details.” They did not respond to questions from Recorded Future News about the findings released on Friday.

In that post, Irregular again did not provide a total count of incidents. Instead, it used terms like “several,” “a handful” and “vast majority” when describing cases in which models “took actions outside their testing environments in ways that impacted the real world.” (Alexander Martin / The Record)

Related:  IrregularForbes Middle EastIrregularCyber Security NewsBloombergCyberScoopThe Cyber Express, SecurityWeek

An August 8 cyberattack on the Latvian Road Traffic Safety Directorate (CSDD) was not reported on time, and the perpetrator had likely tried to enter other state systems as well, Latvian Television's De Facto reported on August 23.

The CSDD had not notified the State Data Inspectorate (DVI) of the data breach within the statutory timeframe of 72 hours, according to information available to De Facto. The cyber incident response agency ‘Cert.lv’ was also notified late. The police launched an investigation on their own initiative.

This is the second-largest data breach in Latvia’s history.

The breach occurred via the CSDD’s ‘Medical’ platform, which around 200 doctors use to submit medical certificates for vehicle drivers. The stolen data belongs to 1.2 million individuals and 200,000 legal entities from the CSDD.

It is highly likely that the same attacker also unsuccessfully attempted to breach other state systems – as suggested by the methods used and the timing of the incident, according to “Cert.lv”. However, the intrusion into the CSDD system took place on the night of Saturday, 7 August to 8 August. The attack went unnoticed at the time, and there was reportedly no warning of a large-scale data breach. (Latvian Public Service Media)

Related: UA.news, The Record, TVP World

Federal cybersecurity agencies warned that troves of new victims of the Medusa ransomware gang have been identified over the last year.

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

The group caused widespread outrage in April when it shut down the University of Mississippi Medical Center — Mississippi’s only children's hospital, only Level I trauma center, only Level IV neonatal intensive care unit, and home to the state’s only organ transplant program.

The advisory warned that the group has focused its efforts on the healthcare sector and has become adept at exploiting “newly announced exploits within 24 hours.”

The ransomware gang has “been observed to use exploits up to a week before public vulnerability disclosure,” the agencies added, citing a recent report from Microsoft about the trend of Medusa actors targeting victims using software that has not been updated to include new patches.

“However, there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching,” the advisory said. (Jonathan Greig / The Record)

Related: CISA, Bleeping Computer, Help Net Security, Cyber Magazine, TechInformed, Cyber Security News, Cyber Press

According to researchers at Truffle Security, more than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

Truffle Security has been tracking this exposure for the past four years and says that 817 of the exposed keys were linked to companies, 526 of them being AWS root keys.

According to the researchers, 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy. This role has full permissions to create, modify, delete, and view virtually all AWS services and resources within an account.

They note that each key of the 768 live keys in the two sets “full control of a company's AWS account.”

The company found 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs and extracted 64,024 unique AWS keys that corresponded to 50,654 AWS accounts after removing duplicates. (Bill Toulas / Bleeping Computer)

Related: Truffle Security, Infosecurity Magazine, Techzine, IT Pro, SC Media, The Register, Cyber Press, GBHackers

Unique verified exposed AWS keys. Source: Truffle Security

According to researchers at Kaspersky, a new malware campaign is targeting Android-based automotive head units, abusing the software-update functionality built into affected DoFun head units.

They describe it as the first documented case of malware specifically built to infect such systems. The malware was discovered in June 2026 and attributed with high confidence to MoYu Group, a threat actor associated with the BadBox botnet.

Kaspersky found that a Boolean parameter named installNotExists could allow the application to install software that was not previously present on the device. (Lore Apostol / TechNadu)

Related: Securelist, GBHackers, Pasquale Pillitteri, Help Net Security, PCMag, Bleeping Computer

Head unit infection scheme. Source: Securelist

Researchers at Zimperium report that the ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.

Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users.

After obtaining VPN service permissions, ToxicPanda 2.0 blocks communications to Google Play before extracting and installing its payload, then requests Accessibility Service permissions.

 ToxicPanda 2.0 is being distributed through Amazon AWS-hosted buckets. (Bill Toulas / Bleeping Computer)

Related: Zimperium, Bleeping Computer, Cyber Security News, Cyber Press

Source: Zimperium.

New Zealand plans to ban under-16s from social media, joining a throng of countries worldwide seeking to limit online harm to children.

The government will introduce the Online Safety Bill on Monday that will require high-risk social media platforms like Instagram, TikTok, Snapchat and Facebook to take reasonable steps to check users are over the age of 16, Prime Minister Christopher Luxon told reporters. The law is unlikely to progress before a Nov. 7 election.

Penalties for companies that fail to meet their obligations will be significant — potentially as much as 10% of a platform’s global revenue, Luxon said.

New Zealand has become the latest country to emulate Australia, which barred under-16s from using social media in late 2025. Since then more than two dozen countries have either enacted their own bans or are weighing similar restrictions. They include a number of European states as well as developing nations such as Indonesia, Vietnam and Brazil. (Tracy Withers / Bloomberg)

Related: Associated PressReutersAgence France-PresseOman ObserverStuff.co.nzRNZthepost.co.nz, 1News

Cybersecurity data company Prevalent AI Ltd. said it has raised $22 million in growth funding from Los Angeles-based Integrity Growth Partners (IGP), the first primary capital it has taken since being founded nine years ago.

Prevalent AI’s product is a data fabric that reaches into hundreds of separate enterprise systems. What comes back gets rebuilt as a knowledge graph, and the graph stays current. Security teams can query the graph and ask which assets, controls, and identities exist across an estate and which of those nobody is watching. (Duncan Riley / Silicon Angle)

Related: Tech.euStartup.euTech Funding News, SecurityWeek

Munich Re has agreed to acquire At-Bay, the Israeli-founded insurtech that combines cyber insurance with cybersecurity services, for an enterprise value of $575 million, in a deal that highlights the insurance industry's growing push to move from paying for cyber losses to actively preventing them.

The German insurance giant said the definitive agreement has been signed and that the transaction is expected to close in the first quarter of 2027, subject to regulatory approvals and other customary conditions. (Meir Orbach / CTech)

Related: Munich Re, ReutersInsurance BusinessDow Jones NewswiresGlobesRuntimeWire, Insurance Journal

Best Thing of the Day: A Long Overdue Move

Members of Congress have asked a government watchdog to examine the effect staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA) have had on the agency’s ability to function.

Bonus Best Thing of the Day: More of This, Please

TikTok has reached a $400 million settlement with the US Department of Justice, ending a 2024 lawsuit alleging the company violated federal children’s privacy laws.

Extra Bonus Best Thing of the Day: Let's Hope This Works

Google introduced Backstory, an experimental artificial intelligence (AI) tool that surfaces information and helps people learn more about the context of images seen online.

Worst Thing of the Day: Flock Somehow Manages to Exceed Its Previous Odiousness

Surveillance giant Flock Safety has built a system that is both an artificial intelligence tool for police that can identify drivers and track vehicles by their patterns of movement alone.

Bonus Worst Thing of the Day: Flock Somehow Manages to Exceed Its Previous Duplicity

The country needs to find a “compromise” between privacy and safety, according to Flock Safety CEO Garrett Langley.

Closing Thought

Read more