Polish Power Plant Breached via Private Cellular Network; Microsoft Patches 400 Flaws Including Exploited Zero-Day; Water Sector Gets Major Cyber Boost
Executive Summary
This week's intelligence reveals significant developments across multiple critical infrastructure sectors, with particular concern for energy, water, and communications systems. The most alarming incident involves threat actors successfully breaching a Polish combined heat and power plant through its private cellular network, resulting in the shutdown of a steam turbine and process-water treatment system—demonstrating the vulnerability of operational technology (OT) environments to unconventional attack vectors.
- Energy Sector Attack: Hackers compromised a Polish power plant via private cellular infrastructure, shutting down critical systems including a steam turbine. This represents a significant escalation in attacks against European energy infrastructure.
- Massive Patch Tuesday: Microsoft addressed approximately 400 vulnerabilities, including one actively exploited zero-day (CVE in afd.sys Windows kernel driver) being used for privilege escalation to SYSTEM. SAP also released critical patches addressing code injection and memory corruption flaws.
- Water Sector Developments: New Senate legislation and the launch of the "Water Watch Center" at DEF CON signal increased focus on protecting under-resourced water utilities from cyber threats.
- Nation-State Activity: Russian-linked threat group UAC-0145 (associated with Sandworm) is conducting social engineering campaigns targeting IT workers through fake job interviews, deploying trojanized VPN clients. Gunra ransomware, exploiting Fortinet and Schneider Electric vulnerabilities, is actively targeting critical infrastructure globally.
- AI Security Developments: OpenAI launched GPT-5.6-Cyber with reduced safeguards for security research, while researchers demonstrated concerning AI agent vulnerabilities that could enable data exfiltration through malicious MCP servers.
- Emerging Threats: The Kimwolf botnet has been rebuilt with blockchain-based command infrastructure to survive takedowns, while DeadLock ransomware is using Polygon smart contracts to make extortion infrastructure more resilient.
Threat Landscape
Nation-State Threat Actor Activities
Russian Operations (Sandworm/UAC-0145): Ukraine's CERT has disclosed a sophisticated social engineering campaign by UAC-0145, a threat group linked to Russia's Sandworm APT. The operation targets IT professionals in Ukraine through fake job interviews, ultimately deploying a trojanized WireGuard VPN client capable of executing remote commands. This campaign, active since at least May 2026, represents a concerning evolution in targeting technical personnel who may have privileged access to critical systems.
- Source: The Hacker News, Bleeping Computer
- Assessment: High confidence attribution based on CERT-UA analysis. Organizations with Ukrainian operations or IT staff should implement additional verification procedures for recruitment communications.
North Korean IT Worker Infiltration: Security researchers conducting a sting operation created a fake cryptocurrency startup and successfully hired three individuals believed to be North Korean operatives. Every virtual machine issued to these workers was recorded, providing valuable intelligence on DPRK tradecraft. This confirms ongoing concerns about North Korean efforts to infiltrate Western technology companies for revenue generation and potential espionage.
- Source: The Hacker News
- Implication: Critical infrastructure organizations should enhance background verification procedures, particularly for remote technical positions.
Ransomware and Cybercriminal Developments
Gunra Ransomware Alert: U.S. and South Korean cybersecurity agencies have issued a joint warning about Gunra ransomware actively targeting government agencies and critical infrastructure organizations worldwide. The group is exploiting known vulnerabilities in Fortinet and Schneider Electric products to gain initial access.
- Source: The Hacker News, Bleeping Computer
- Affected Sectors: Government, critical infrastructure broadly
- Immediate Action: Verify patching status of all Fortinet and Schneider Electric systems; review network segmentation between IT and OT environments.
DeadLock Ransomware Evolution: The DeadLock ransomware group has adopted decentralized infrastructure using Polygon blockchain smart contracts to facilitate victim communications and data leak operations. This approach significantly complicates law enforcement takedown efforts and represents an emerging trend in ransomware operational security.
- Source: The Hacker News, Bleeping Computer
- Analysis: Blockchain-based infrastructure provides resilience against traditional disruption methods. Expect other ransomware groups to adopt similar techniques.
ExfilSquad Claims Wesco Breach: Global supply chain and distribution company Wesco has confirmed it is investigating a cybersecurity incident after the ExfilSquad threat group claimed responsibility for data theft. Given Wesco's role in critical infrastructure supply chains, downstream impacts should be monitored.
- Source: Bleeping Computer
Botnet and DDoS Developments
Kimwolf/AISURU Botnet Resurgence: Months after law enforcement seized servers and arrested an alleged operator, the Kimwolf botnet has been rebuilt with significant improvements. The new version disguises attack traffic as legitimate Chrome HTTP/2 traffic and retrieves command-and-control instructions from the Ethereum blockchain, making it highly resilient to takedown efforts.
- Source: The Hacker News, CyberScoop
- Impact: Android and IoT devices remain primary targets. Critical infrastructure organizations should audit IoT device inventories and implement network segmentation.
DDoS Attack Volume Surge: Cloudflare reports mitigating over 800 network-layer DDoS attacks exceeding 1 Tbps during Q2 2026—a fivefold increase from the previous period. This escalation in attack volume poses significant risks to critical infrastructure organizations with internet-facing services.
- Source: Bleeping Computer
Emerging Attack Vectors
Malicious SIM Card Exploitation: Researchers have demonstrated that malicious SIM cards can execute attacker commands on cellular modules embedded in EV chargers, industrial routers, and vehicle telematics systems. This attack vector bypasses traditional network security controls and poses significant risks to cellular-connected critical infrastructure.
- Source: The Hacker News
- Affected Systems: Electric vehicle charging infrastructure, industrial cellular gateways, transportation telematics
Windows USB Auto-Install Privilege Escalation: Researchers have demonstrated a technique to abuse Windows Plug and Play functionality to achieve SYSTEM-level access on fully updated Windows 11 systems by emulating USB devices and exploiting privileged installation components.
- Source: The Hacker News
- Mitigation: Review USB device policies; consider restricting automatic driver installation in high-security environments.
Sector-Specific Analysis
Energy Sector
CRITICAL: Polish Power Plant Compromise
Threat actors successfully breached a Polish combined heat and power (CHP) plant by exploiting the private cellular network used by the local grid operator. The attackers achieved sufficient access to shut down a steam turbine and the process-water treatment system, demonstrating the ability to cause physical impacts on energy generation infrastructure.
- Source: The Hacker News
- Attack Vector: Private cellular network infrastructure
- Impact: Operational disruption to power generation and water treatment systems
- Attribution: Not yet publicly attributed; investigation ongoing
Key Takeaways for Energy Sector:
- Private cellular networks, while providing isolation from public internet, introduce their own attack surface that may be overlooked in security assessments.
- The ability to impact both power generation (turbine) and supporting systems (water treatment) suggests either broad access or understanding of interdependencies.
- European energy infrastructure continues to face elevated threat levels, particularly in Eastern Europe.
Recommended Actions:
- Audit security controls on private cellular and wireless networks connecting to OT systems
- Review access controls between cellular network infrastructure and control systems
- Ensure monitoring capabilities extend to private network infrastructure
- Verify incident response procedures address scenarios involving private network compromise
Gunra Ransomware Targeting Schneider Electric Systems: The joint U.S.-South Korea advisory specifically notes Gunra ransomware exploiting Schneider Electric vulnerabilities. Energy sector organizations using Schneider Electric products should prioritize vulnerability assessment and patching.
Water and Wastewater Systems
Water Watch Center Launch: A new initiative launched at DEF CON aims to provide cybersecurity assistance to under-resourced water utilities. The "Water Watch Center" represents a significant public-private partnership effort to address the well-documented security gaps in the water sector.
- Source: SecurityWeek
New Senate Legislation: Complementing the Water Watch Center, new Senate legislation provides additional cyber resources for U.S. water systems. This legislative action acknowledges the critical need for federal support given the fragmented nature of water utility ownership and limited security budgets.
Cross-Sector Concern: The Polish power plant incident included disruption to process-water treatment systems, highlighting the interconnection between energy and water infrastructure. Water utilities co-located with or dependent on energy facilities should review these interdependencies.
Communications and Information Technology
Zoom Zero-Click Vulnerabilities: Critical vulnerabilities in Zoom's annotation feature could allow any meeting participant to execute code on other participants' machines without user interaction. Both screen sharers and viewers were vulnerable. Zoom has released patches.
- Source: SecurityWeek, The Hacker News, CSO Online
- Impact: Any organization using Zoom for sensitive communications, including critical infrastructure coordination
- Action: Update Zoom clients immediately; consider disabling annotation features until patches are verified
Cisco ASA/FTD VPN Exploitation: Cisco has warned of active exploitation of a high-severity denial-of-service vulnerability in Secure Firewall ASA and Firepower Threat Defense (FTD) software. Attackers are remotely crashing affected devices, potentially disrupting network connectivity for critical infrastructure organizations.
- Source: Bleeping Computer
- Action: Apply Cisco patches immediately; monitor VPN infrastructure for unexpected restarts
Cisco ClamAV Vulnerabilities: Two high-severity vulnerabilities in Cisco Secure Endpoint Connector's ClamAV component have public exploits available. Successful exploitation could crash scanning processes, potentially allowing malware to evade detection.
- Source: Bleeping Computer
Mozilla Signing Key Exposure: Mozilla has updated the GPG key used to sign Firefox and Thunderbird releases after the previous key was accidentally committed to a private GitHub repository. While the exposure was to a private repository, Mozilla took the precautionary step of key rotation.
- Source: The Hacker News, Bleeping Computer
- Action: Update GPG key trust for Firefox/Thunderbird verification if using manual verification processes
Malicious Chrome Extension Returns: A Chrome extension previously banned for stealing AI chat data has returned to the Chrome Web Store and resumed malicious activities. The extension had accumulated over 300,000 installs before initial removal.
- Source: SecurityWeek
- Action: Review browser extension policies; consider enterprise browser management solutions
Transportation Systems
Delta In-Flight Wi-Fi Incident: Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared on a flight from Las Vegas to Atlanta carrying DEF CON attendees. The crew deactivated the network after detecting anomalies, and federal authorities are investigating. This incident highlights the potential for Wi-Fi deauthentication and evil twin attacks in aviation environments.
- Source: CyberScoop, Bleeping Computer
- Analysis: While this incident may have been a prank given the passenger demographic, it demonstrates the feasibility of in-flight network attacks and the need for robust wireless security in aviation.
Healthcare and Public Health
HIPAA Security Updates: HHS Office for Civil Rights and NIST are preparing updated guidance on HIPAA security requirements, with a webinar scheduled for September 2026. Healthcare organizations should monitor for updated compliance requirements.
Logistics Breach Impact: The confirmed breach at Ceva Logistics may have downstream impacts on healthcare supply chains. Healthcare organizations using Ceva for medical supply logistics should assess potential exposure.
- Source: Infosecurity Magazine
Financial Services
Blockchain-Based Criminal Infrastructure: The adoption of Ethereum and Polygon blockchain infrastructure by both the Kimwolf botnet and DeadLock ransomware represents an emerging challenge for financial sector security teams. These techniques complicate attribution and takedown efforts while potentially involving cryptocurrency infrastructure.
npm Supply Chain Attack: Six npm packages were discovered querying an Ethereum wallet to locate command-and-control infrastructure. Financial services organizations with JavaScript/Node.js development should audit dependencies.
- Source: Infosecurity Magazine
Government Facilities
Local Government Attacks Continue: Suisan City, California is responding to a cyber incident that has impacted police and fire response capabilities. This is the third local government cyber incident reported in the past week, continuing a concerning trend of attacks against municipal systems.
- Source: Infosecurity Magazine
- Impact: Public safety services affected
Food and Agriculture / Commercial Facilities
Supply Chain Concerns: The Wesco breach (supply chain/distribution) and Ceva Logistics breach (European clients affected) highlight ongoing risks to supply chain infrastructure supporting multiple critical sectors including food distribution and commercial operations.
Film Festival Data Exposure: Records associated with Tribeca Film Festival were exposed in a data leak affecting directors, actors, and celebrities. While not directly critical infrastructure, this highlights risks to high-profile events and venues.
- Source: Security Magazine
Vulnerability and Mitigation Updates
Critical Vulnerabilities Requiring Immediate Attention
Microsoft August 2026 Patch Tuesday
Microsoft released security updates addressing approximately 400 vulnerabilities, including three zero-days:
- CVE-2026-XXXXX (afd.sys): ACTIVELY EXPLOITED - Use-after-free vulnerability in the Windows Ancillary Function Driver (afd.sys) kernel-mode driver allows privilege escalation to SYSTEM. This vulnerability is being exploited in the wild.
- Two additional publicly disclosed zero-days addressed
- Source: SecurityWeek, The Hacker News, Bleeping Computer, KrebsOnSecurity
- Action: Prioritize patching of the afd.sys vulnerability given active exploitation. Apply all Patch Tuesday updates according to organizational risk assessment.
SAP Critical Vulnerabilities
SAP released 28 new and 2 updated security notes, including four addressing critical-severity vulnerabilities:
- Critical code injection vulnerabilities
- Critical memory corruption vulnerabilities
- Source: SecurityWeek, CSO Online
- Action: SAP administrators should review security notes immediately and prioritize critical patches, particularly for internet-facing systems.
Adobe ColdFusion and Campaign Classic
Adobe has issued urgent patches for critical vulnerabilities in ColdFusion and Campaign Classic that could enable arbitrary code execution and denial-of-service attacks.
- Source: SecurityWeek
- Action: Patch immediately; ColdFusion vulnerabilities have historically been targeted rapidly after disclosure.
Zoom Annotation Zero-Click RCE
- Zero-click code execution via annotation feature
- Affects both presenters and viewers
- Source: SecurityWeek, The Hacker News
- Action: Update all Zoom clients immediately
Metabase SQL Injection
A SQL injection vulnerability in Metabase grants attackers complete database access.
- Source: CSO Online
- Action: Patch Metabase installations; audit for signs of exploitation
Microsoft SharePoint RCE (Ransomware Exploitation)
CISA has confirmed that ransomware groups are now exploiting a high-severity SharePoint remote code execution vulnerability that has been flagged as actively exploited since early July. Researchers have also disclosed an AI-assisted exploit chain reaching unauthenticated RCE.
- Source: Bleeping Computer, The Hacker News
- Action: Verify SharePoint patching status immediately; this is now confirmed in ransomware attack chains.
ICS/OT Advisories
Johnson Controls C-CURE 9000 and Victor (Update A)
CISA has released an updated advisory for Johnson Controls C-CURE 9000 and Victor application server vulnerabilities.
- Source: CISA ICS Advisories
- Affected Systems: Physical access control and video management systems
- Action: Review advisory and apply mitigations; these systems are commonly deployed in critical infrastructure facilities.
Additional Vulnerabilities
- Cisco ASA/FTD: High-severity DoS vulnerability under active exploitation
- Cisco ClamAV: Two high-severity vulnerabilities with public exploits
- Cursor IDE: Pre-trust code execution vulnerability (patched)
- Fortinet/Schneider Electric: Multiple vulnerabilities being exploited by Gunra ransomware
Supply Chain Vulnerabilities
BdThemes WordPress Plugin Compromise: A supply chain attack has compromised WordPress plugin vendor BdThemes, with malicious JSON creating rogue administrator accounts. WordPress has temporarily disabled affected plugins.
- Source: The Hacker News
- Action: Organizations using BdThemes plugins should audit for unauthorized administrator accounts and await WordPress guidance.
Resilience and Continuity Planning
Lessons Learned
Polish Power Plant Incident:
- Private cellular networks require the same security rigor as other network infrastructure
- Attackers are identifying and exploiting non-traditional network paths to OT systems
- Interdependencies between power generation and water treatment systems can be exploited for cascading impacts
Blockchain-Resilient Criminal Infrastructure:
- Traditional takedown approaches are becoming less effective against decentralized criminal infrastructure
- Organizations should plan for scenarios where ransomware communication channels cannot be disrupted
- Incident response plans should not assume law enforcement can quickly disable attacker infrastructure
Supply Chain Security
- Wesco Breach: Supply chain distribution companies represent high-value targets with broad downstream impact
- Ceva Logistics: European supply chain operations affected; assess vendor relationships
- npm/Software Supply Chain: Blockchain-based C2 discovery in npm packages represents evolving supply chain attack techniques
Cross-Sector Dependencies
This week's Polish power plant incident demonstrates critical interdependencies:
- Energy → Water: Power generation facilities often include water treatment systems; compromise of one affects both
- Cellular → Energy: Private cellular networks supporting grid operations introduce telecommunications dependencies
- IT → OT: Continued convergence creates expanded attack surfaces
Physical Security Considerations
Mass Kidnapping Trends: Security Magazine reports a 154% increase in mass kidnappings from 2020-2025, with projections for continued increases in kidnaps-for-ransom in 2026. Critical infrastructure personnel, particularly executives and key technical staff, should be included in organizational security planning.
- Source: Security Magazine
Regulatory and Policy Developments
Water Sector Legislation
New Senate legislation provides additional cybersecurity resources for U.S. water systems, acknowledging the sector's unique challenges including fragmented ownership, limited budgets, and critical importance to public health.
- Source: SecurityWeek
- Implication: Water utilities should monitor for implementation guidance and funding opportunities
NIST National Vulnerability Database Modernization
NIST is seeking public input on modernizing the National Vulnerability Database (NVD) to address AI-driven cyber threats and machine-scale security data requirements. This initiative acknowledges that current vulnerability management approaches may not scale to AI-accelerated threat environments.
- Source: CyberScoop
- Action: Organizations with vulnerability management expertise should consider providing input to shape future NVD capabilities
AI Governance
Multiple reports this week highlight the AI governance gap, with organizations implementing AI systems without fully understanding legal protections and security implications. OpenAI's launch of GPT-5.6-Cyber with reduced safeguards and the Daybreak access program raises questions about responsible AI deployment in security contexts.
- Source: SecurityWeek, CSO Online
Election Security
A federal judge has issued a second order blocking a Trump administration mail-in voting directive, though the Supreme Court temporarily reversed an earlier decision through the shadow docket. Election infrastructure stakeholders should monitor for final resolution.
- Source: CyberScoop
Training and Resource Spotlight
New Tools and Capabilities
OpenAI GPT-5.6-Cyber: OpenAI has launched a cybersecurity-focused AI model designed for vulnerability research, penetration testing, and incident response. The model is available through a two-tier access program:
- Daybreak Blue: Removes some OpenAI-made guardrails for security research
- Daybreak Red: Grants access to cyber-focused frontier AI models with further reduced restrictions
- Source: SecurityWeek, The Hacker News, Infosecurity Magazine
- Consideration: While potentially valuable for defensive security, reduced safeguards raise concerns about potential misuse. Organizations should establish governance frameworks before adoption.
Corma Defensive AI: Corma has emerged from stealth with $60 million in seed funding from Sequoia Capital, Khosla Ventures, and Coatue to develop defensive cybersecurity AI models.
- Source: SecurityWeek
Water Watch Center: Launched at DEF CON, this new resource aims to help under-resourced water utilities protect their systems. Water sector organizations should explore available assistance.
Best Practices
GitHub as EDR: CSO Online highlights how GitHub's native logging and monitoring capabilities can function as an endpoint detection and response system for development environments when properly configured.
- Source: CSO Online
AI Agent Security: Research this week demonstrates risks of AI agents with broad system access, including the ability to exfiltrate secrets through malicious MCP servers. Organizations deploying AI agents should implement strict access controls and monitoring.
- Source: The Hacker News, Bleeping Computer
Small Business Resources
NIST has published guidance on foundational cybersecurity practices for small businesses, addressing the reality that this sector is often under-resourced for cyber defense. Critical infrastructure supply chain partners in the small business category should review this guidance.
- Source: NIST
- Publication Date: August 20, 2026
Looking Ahead: Upcoming Events
Webinars and Training
| Date | Event | Organization | Focus Area |
|---|---|---|---|
| August 20, 2026 | Back to Basics: Foundational Cybersecurity Practices for Small Businesses | NIST | Small Business Cybersecurity |