Hackers breached a small Polish energy plant via private APN last year

A Second Polish Energy Plant Falls Victim to Sophisticated Cyber Attackers, Exposing a Novel Attack Path Last year’s devastating cyber attacks on Poland’s energy sector have revealed an alarming new threat vector. A small combined heat-and-power (CHP) plant in Poland was compromised by hackers who exploited a private Access Point Name (APN) network, demonstrating a … Read more

Multistate Water System Attacks Widen, Iran Suspected

Cyberattacks on US Water Systems Widen, with Iran Suspected Behind the Threats A growing number of states across the US have fallen victim to a wave of cyberattacks targeting their water and wastewater systems. The attacks, which have been linked to Iranian threat actors, have exposed weaknesses in the country’s critical infrastructure, leaving experts warning … Read more

‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents

Security researchers at Tenet have unveiled a new attack technique that exploits identity governance gaps in AI agents, allowing attackers to manipulate and hijack these systems with alarming ease. The technique, dubbed “GhostJacking,” works by tricking AI agents into executing malicious commands using seemingly legitimate instructions hidden within trusted data sources. This can include security … Read more

Member of The Com sent to prison for blackmail, sextortion

A member of the notorious online cybercrime collective “The Com” has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. Justin Swaddle, known by several aliases on social media platforms, was arrested in October 2023 and pleaded guilty to multiple child sexual abuse offenses at Leeds Crown … Read more

BdThemes plugins supply-chain hack creates rogue WordPress admins

A Devastating Supply-Chain Hack Hits WordPress Admins through BdThemes Plugins A sophisticated threat actor has exploited a vulnerability in the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, to create rogue admin accounts on thousands of websites. The attack, which was first detected by WordPress security firm Defiant on August 7, has … Read more

Hackers breached a small Polish energy plant via private APN last year

A Second Polish Energy Plant Compromised via Private APN, Highlighting a Novel Attack Vector In a significant revelation, Poland’s Computer Emergency Response Team (CERT) has disclosed that a second energy plant was breached by hackers last year using an unconventional approach. The attack, which occurred on December 29, 2025, highlights the growing threat of sophisticated … Read more

‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents

**New Research Exposes Identity Governance Gaps in AI Agents** A recent demonstration at DEF CON 34 has highlighted a disturbing vulnerability in artificial intelligence (AI) agents, allowing attackers to manipulate and hijack these systems using seemingly legitimate security alerts and blocked events. This technique, dubbed “GhostJacking,” has left many organizations wondering if their AI-powered defenses … Read more

Valve notifies Steam hardware customers of a data breach

Valve has notified Steam hardware customers in Europe that their personal and order information was stolen by hackers who broke into the shipping partner CEVA Logistics’ servers. The breach occurred between July 29 and August 1, with attackers gaining access to details such as names, addresses, phone numbers, email addresses, and product orders. CEVA Logistics … Read more

LexisNexis shuts down services after suspicious activity on servers

LexisNexis Shuts Down Services After Unusual Activity on Vendor Servers Global data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline as part of a response to suspicious activity detected on servers managed by an unnamed third-party vendor. The move aims to protect customers from potential security risks while the company … Read more

OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

A New Frontier in Cybersecurity: OpenAI’s GPT 5.6 Cyber Model Now Available to Select Partners In a significant development, OpenAI has unveiled its latest model, GPT 5.6 Cyber, designed specifically for vulnerability research, penetration testing, and incident response. However, what sets this model apart from previous versions is that it’s not available to the general … Read more