New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A newly discovered attack vector, dubbed Bit2Watt, poses a significant threat to cloud infrastructure and power grids worldwide. The alarming aspect of this vulnerability is that it doesn’t require an exploit to cause disruption – simply gaining access to a cloud tenant’s account can be enough to wreak havoc on the grid.

The Bit2Watt attack leverages the fact that many cloud providers use virtualized environments, where multiple tenants share resources on the same physical infrastructure. This setup allows for efficient resource utilization but also creates an avenue for unauthorized access and manipulation. In this case, a malicious actor would need to compromise only one tenant’s account to gain access to the underlying virtualization layer and disrupt power grid operations.

The attack works by targeting the hypervisor – software that manages virtual machines within the cloud provider’s infrastructure. By gaining control of the hypervisor, an attacker can manipulate the flow of energy between different nodes in the power grid, potentially causing blackouts or other disruptions. What’s more concerning is that this vulnerability doesn’t require a zero-day exploit; simply having access to a compromised account can be enough to gain control.

This attack vector matters for several reasons. Firstly, it highlights the interconnectedness of modern infrastructure – one vulnerable tenant in a cloud environment can have far-reaching consequences for entire cities or regions. Secondly, it underscores the need for robust security measures within cloud environments, where multiple tenants often share resources and interact with each other’s applications.

The Bit2Watt attack serves as a stark reminder that cloud security is not just an IT issue but also has real-world implications on public safety and critical infrastructure. As more organizations move their operations to the cloud, they must prioritize robust access controls, regular vulnerability scanning, and thorough penetration testing to identify potential weaknesses before they can be exploited.

In light of this discovery, organizations using cloud services should take immediate action to secure their accounts and infrastructure. This includes implementing multi-factor authentication, monitoring account activity for suspicious behavior, and conducting regular security audits to identify potential vulnerabilities. By staying vigilant and proactive in addressing these types of threats, we can mitigate the risks associated with attacks like Bit2Watt and ensure that our critical infrastructure remains safe from cyber threats.


Source: The Hacker News — 2026-07-21