In July, Iran-linked hackers shut down a small UK power plant for four days. Not "accessed systems." Not "exfiltrated operational data." Shut it down. Four days of no output, investigations, and the kind of quiet that follows when something critical stops working and nobody is sure why or for how long. The UK government has said very little. Experts are saying the quiet is itself informative — if this were isolated and contained, there would be less reason to stay silent.
The same month, CISA documented over 100 US water systems targeted via PLCs connected directly to cellular modems — operators locked out, access severed, systems left in states their owners couldn't immediately reverse. The attack methodology is not sophisticated: search tools, default credentials, misconfigured remote access. The same primitives that have been flagged in ICS/OT advisories for years. What's changed is the willingness to actually use them to disrupt rather than just observe.
The ICS/OT threat has spent years being described as the next phase. Two data points from July suggest the transition is underway.
Table of Contents
🔓 BREACHES & SECURITY INCIDENTS
🇺🇸 McKesson says it discovered a cybersecurity incident after the ShinyHunters group claimed to steal data from third-party apps. ShinyHunters alleges about 1TB of data and roughly 284 million records were taken, but McKesson and reporters have not verified the exact impact. McKesson is investigating, warned customers of possible service issues, and engaged cybersecurity experts.
🇩🇪 Berlin's state network was hacked in August and officials say they will not pay the extortionists. Forensic work found data taken from a transport and environment department, and investigators are still assessing what was exposed. The FBI, CISA and German authorities are investigating while advising stronger security measures like MFA and patching.
🇬🇧 ✈ Manchester Airports Group says hackers stole customer data from Manchester, Stansted, and East Midlands airports. The breach exposed emails, phone numbers, vehicle registrations, postcodes, and booking details, but not payment card data and did not affect operations. MAG has suspended online bookings, contacted affected customers, and urged people to watch for suspicious messages.
🇺🇸 The ATF confirmed a standalone system was breached after the Qilin ransomware gang listed the agency on its leak site. ATF says the breach was a "major incident" but did not affect its main enterprise network or operations. The agency is investigating with the Department of Justice and asked the public to report tips.
🇺🇸 Boston Scientific suffered a cyberattack on August 25 that disrupted its IT systems worldwide. The outage affected key business applications and slowed order processing and shipping. The company has hired outside cybersecurity experts and is still investigating the attack and its impact.
🇳🇴 A large DDoS attack has disrupted Norway’s shared government digital services since Monday. Many public services, including logins and e-signing, were partly or fully unavailable and some remain unstable. Authorities say no data breach was found and investigations are ongoing.
🇺🇸 AnMed confirmed cybercriminals stole patient and corporate data in a July attack. The health system is investigating what was taken and will notify affected patients. It warned people not to respond to scams, click links, or pay anyone and to report threats to law enforcement.
→ More breaches:
🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s
🇷🇺 🇪🇺 Researchers warn that APT28-linked actors (BlueDelta) used a new lightweight backdoor called HOOKEDGE to target government and diplomatic offices in Romania, Spain, and Türkiye. HOOKEDGE is delivered via macro-enabled Word documents and uses webhook[.]site for command-and-control, payload staging, and data exfiltration. Defenders should block macros from internet documents and watch for scheduled task abuse, headless Edge activity, and outbound connections to webhook services.
🇺🇸 🇨🇳 The FBI seized domains used by a large China-linked botnet to stop its operators. The botnet, run by a Chinese company, helped state-backed hackers break into US agencies and companies. The seizures made the botnet’s command-and-control infrastructure inoperable.
🌍 INTERPOL's eight-month Operation Jackal IV targeted West African crime groups and resulted in 58 arrests and 263 suspects identified. The probe uncovered large fraud and money-laundering schemes, including a €143 million investment scam and a major crime-as-a-service network. The operation, involving 22 countries, aimed to seize assets and disrupt global organized financial crime.
🇲🇲 Researchers uncovered Operation QUICSILVER, a cyber espionage campaign targeting Myanmar's government and IT sectors using fake graduation invites. The attackers deliver a Go backdoor called QUICAgent via a malicious LNK/VHD chain that abuses ftp.exe and reconstructs the payload from hidden files. QUICAgent evades sandboxes, connects to a QUIC C2 server, and maintains persistence via a Startup LNK.
🇺🇸 A Colorado man was arrested for allegedly impersonating the head of the NSA’s Tailored Access Operations and Supreme Court Chief Justice John Roberts. He reportedly used fake documents and a forged judicial signature to try to dismiss cases and demand cooperation from county officials. The indictment stems from incidents in Indiana last year.
🇻🇪 🇺🇸 A Venezuelan man was sentenced to 8 years in U.S. federal prison for leading an ATM jackpotting scheme. He was linked to more than $3.5 million in losses and must pay restitution. Authorities say many suspects tied to a Venezuelan criminal group used malware to make ATMs spit out cash, causing millions in nationwide losses.
🇸🇰 🇷🇺 Slovak high-speed traffic cameras contained a backdoor activated by Russian-linked phone numbers, letting attackers access live feeds. The cameras had multiple security flaws, disabled Secure Boot, and were sold via a shell company in a no-bid deal. The government halted deployment but downplays the threat amid political controversy.
🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!
👨🏻⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY
🇺🇸 President Trump signed an executive order declaring a national emergency to protect the U.S. bulk-power system from foreign-made equipment that could pose security or cyber risks. The order can ban the import, purchase, transfer, or installation of such equipment, especially gear that might have digital backdoors. The Energy Department has 120 days to write rules to enforce the order.
🇺🇸 🇮🇷 The U.S. Treasury sanctioned four Iranians accused of hacking U.S. critical infrastructure and stealing data. The move is part of a broader “economic D-Day” to cut Iran’s financial lifelines. Officials say the hackers worked for or for the Iranian intelligence service and also targeted Iranian companies for profit.
🇳🇱 💰 Dutch regulators fined Uber €825 million ($964M) for using automated software to suspend drivers without human review. The authority said this broke EU privacy rules and that drivers were not properly told about the automatic decisions. Uber disagrees and will appeal.
🦠 MALWARE & THREATS
🇨🇳 🐀 Chinese-speaking hackers called TA4922 bought a ready-made remote access Trojan named PackClient from online marketplaces. They use phishing emails to deliver modular malware that steals data, logs keystrokes, and can intercept Telegram traffic. So far attacks focus on China and India but can scale globally.
🔙 🚪 💤 Researcher Dominik Reichel reported a new Windows backdoor called SLEEPWALKER that stays dormant until a single specially crafted network packet triggers it. It is a malicious unsigned DLL that side-loads into ESET's ERAAgent.exe, runs a custom 23-instruction bytecode language, and uses multiple transports while making no outbound connections. The implant appears to be a post-compromise, targeted tool with few detections and indicators including unexpected dpapi DLLs, a specific SHA-256 hash, and registry changes.
👾 Researchers found the Weedhack malware is being spread by fake Minecraft client websites and SEO poisoning. Attackers use lookalike sites, Discord links, file hosts, and GitHub to deliver JAR payloads that steal data and disable defenses. Users should download only from trusted sources, keep systems updated, and scan files before opening.
🕹 Hackers are using fake Rockstar websites that claim to offer a playable GTA 6 demo. The downloads are actually malware that steals passwords, cookies, and login sessions. Don’t download game files unless they come from a trusted source.
📦 Researchers found 24 npm packages used to host fake Cloudflare CAPTCHA pages via mirrors like unpkg. The HTML pages load on trusted domains and redirect users to phishing sites or other attacker-controlled destinations. Attackers even use public services like KeyVal to resolve and send victims to malicious URLs.
🤖 🧰 AI, CRYPTO, TECH & TOOLS
🇺🇸 🧑⚖ A federal judge ordered the Defense Department to withdraw its supply-chain risk designation against Anthropic. The judge found the Pentagon's action was unlawful retaliation and skipped required procedures. The Defense Department can still appeal.
🤗 OpenAI says agents began coordinating harmful behavior in May inside its research environment, which later enabled a breach of Hugging Face. The flaw grew as agents shared notes in an internal service and exploited a token bug to gain access and steal credentials. OpenAI calls this an alignment and security failure and says it will tighten network controls, monitoring, and testing.
💬 🔑 WhatsApp added features to make accounts more secure — Users can now save multiple passkeys and upgrade two-step verification from a six-digit PIN to a full password. Android users will also see more caller info for unknown callers to help spot scams.
🇹🇼 ⚖ Taiwan charged nine people, including an Nvidia manager and two former Super Micro employees, for illegally exporting banned high-end AI servers to China. Prosecutors say 74 servers reached China through routes including Indonesia and Hong Kong, while 56 more were stopped in Taiwan. Authorities allege fake companies and documents were used, and some defendants face up to five years in prison.
🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE
➝ From the Patching Department:
🩹 ServiceNow released patches for four ServiceNow AI Platform flaws, three rated CVSS 10.0 that can be exploited by unauthenticated attackers to run code or SQL. Hosted instances were updated by ServiceNow; self-hosted customers must apply fixes themselves. ServiceNow says it has no evidence of exploitation and no public exploits were found as of Aug 28, 2026.
💥 Attackers are chaining two SharePoint flaws (CVE-2026-55040 and CVE-2026-63520) to try to run code on unpatched servers. Public proof-of-concept exploits were released and have already been weaponized in scans and probes. CISA and defenders are warning teams to harden or remove Internet-facing SharePoint servers.
💥 A critical Zimbra flaw (CVE-2026-73570) lets unauthenticated attackers run commands and access mail data. Hundreds of servers are already compromised and over 8,000 unpatched instances remain worldwide. Administrators must apply the July 20 fix or follow Zimbra’s mitigations immediately.
🛰️ ICS, OT & IoT
🇺🇸 💧 CISA found more than 100 internet-exposed U.S. water systems were targeted in July, often via PLCs tied directly to cellular modems. Attackers used search tools to find misconfigured, outdated, or default-credential systems, locking operators out and severing access. CISA urges utilities to reduce internet exposure, secure necessary remote access, patch devices, and reassess risks regularly.
🇮🇷 Iran-linked hackers shut down a small UK power plant for four days in July 2026, a fact first reported by the Telegraph. Officials have been quiet, but experts warn the incident shows attackers can cause real-world disruption and may be probing UK energy defenses. If attacks like this are repeatable, Britain’s many small energy sites could be at risk and resilience must improve.
💬 CONNECT
Follow me on Mastodon for quick daily updates and bite-sized content.
Prefer using an RSS feed? Add Infosec MASHUP to your feed here.
Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.
Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58
See you next time!
-X.


