daily cyber × ai intelligence

index

August 24, 2026

Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline

64 of 70 sources 262 gathered 262 triaged 42 clustered 42 written

An Iran-linked attack kept a British power plant offline for four days, reported as the first successful intrusion of its kind against UK energy infrastructure. Also today: a critical unauthenticated account takeover in Keycloak, public labs for the actively exploited GitLab flaws, and a frameless browser-in-the-browser phishing framework.

Nation-State & Critical Infrastructure

  • Iran-linked hackers forced a UK power plant offline for four consecutive days last month, in what officials describe as the first successful attack of its kind on British energy infrastructure (The Telegraph). The government says the facility was a small-scale generator and the national grid was never at risk (Cyber Security News); Security Affairs places the incident alongside concurrent intrusions at US water utilities (Security Affairs). (discussion)
  • SilkParasite’s toolset is larger than first reported — the China-nexus operation against Central Asian governments is now tied to seven RAT families (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT among them), with DLL sideloading as core tradecraft and targeting across Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan and Georgia. Bitdefender assesses the China nexus at medium confidence (@DailyDarkWeb) (earlier coverage).

Vulnerabilities & Exploits

  • Keycloak is vulnerable to a critical unauthenticated account takeover tracked as CVE-2026-18963, with researcher @h4x0r_dz reporting he reproduced the bug locally — notable given how much enterprise SSO sits on Keycloak (Keycloak issue #51833).
  • A critical RNG flaw in Coldcard hardware wallets was disclosed by Wizardsardine, with a breakdown of what went wrong, which devices and seed-generation paths are affected, and what owners should do (Wizardsardine).
  • The Windows I/O Ring exploit primitive appears to be dead, per chompie1337 — a favourite arbitrary read/write technique for Windows kernel exploitation is being retired, pushing RCE/LPE chains toward newer primitives (@thegrugq).

New Tools & Releases

  • Mimic is a frameless browser-in-the-browser phishing library: no iframes, so frame-busting defences don’t apply. It builds fake browser chrome via Shadow DOM and a MutationObserver in a single script, designed to be injected through a reverse proxy (GitHub).
  • Public labs and safe PoCs shipped for the exploited GitLab flaws — a reproducible environment for CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced) (GitHub) and a second lab for CVE-2026-10053, the npm package-registry path traversal giving arbitrary file write as git (GitHub). Released on the basis that exploitation is already circulating (earlier coverage).
  • Cybermes is an autonomous offensive-security, bug-bounty and red-teaming agent framework built on the Hermes agent with multi-model LLM orchestration and task-specific reasoning skills (GitHub).
  • rag-redteam targets the gap between RAG evaluation suites (RAGAS, DeepEval) and LLM scanners like garak, testing pipelines in CI for prompt injection, source-document leakage and cross-document smuggling (GitHub).

Cloud & Identity

  • The NVD entry for the maximum-severity Entra ID flaw is now public: CVE-2026-69836, CWE-502 deserialization of untrusted data, network attack vector, unauthenticated code execution, CVSS 10.0 as assigned by Microsoft — and reported as actively exploited (NVD). Microsoft’s own messaging on exploitation status has been inconsistent (earlier coverage).
  • Privileged Azure AD access to a Turkish telecom is being advertised on a cybercrime forum — the seller claims Database Administrator (SA) privileges, roughly 100 hosts, and no AV/EDR present, at a company with claimed revenue of $25–50M (@DarkWebInformer).

Threat Activity & Cybercrime

  • ShinyHunters named BOK Financial and CyrusOne, with the CyrusOne listing citing a rejected $13M demand and claiming 12.9 million Salesforce records plus 645 GB of uncompressed SharePoint data, 182,000+ customer rows and 8,300+ rows of employee PII (@DarkWebInformer). The group also claims to have breached security firm ReliaQuest but has published no proof (campuscodi).
  • Android malware is spreading through the built-in updaters of vehicle head-unit firmware developed by DoFun, delivering a multi-stage downloader for ad fraud and a proxy botnet. Kaspersky found it in June 2026 (The Hacker News); blackorbird calls it the first documented malware case with an infection chain specific to car head units, overlapping with BADBOX (@blackorbird).
  • ToxicPanda now abuses Android VPN permissions to cut victims off from Google Play, blocking Play Protect updates while it operates (BleepingComputer) (earlier coverage). Separately, Indian government blocking notices show Android malware impersonating ICICI, SBI and Axis banking apps using Firebase infrastructure (Ministry of Cyber Affairs).
  • Italian school-software provider Spaggiari confirmed a June 30 incident on its Bergantini platform and reported the breach to Italy’s DPA, but says its forensics do not support claims that core school-management systems were compromised — while an actor offers 6.1 TB of Italian school documents for sale (Spaggiari, Dark Web Informer).
  • Toronto’s Hospital for Sick Children was hit again, this time losing current and former employee and job-applicant data through a flaw in third-party software; clinical systems and patient records were not affected (The Record, BleepingComputer).
  • More than 1,500 subdomains under lacoste.com were found pointing at gambling infrastructure, 1,532 of them in the *.newsletters.lacoste.com namespace and ~98% of the observed DNS surface gambling-related — textbook domain shadowing of a trusted brand (Mücahid Yardım).
  • Intel 471 profiles a new generation of bulletproof hosting, built on reseller layers, rapid infrastructure rotation, jurisdictional insulation and upstream relationships that make takedowns and attribution materially harder (Intel 471).
  • Leak-site churn over the weekend: Qilin added Black Cat Engineering (Qatar), Difor Chile and Clear Align (FalconFeeds), plus Italian victims Euroflora and Studio Boldrin (FalconFeeds); Metaencryptor listed Factory Five Racing and Corona Corporation (FalconFeeds).

AI & Model Security

  • AI-designed bacteriophage genomes were synthesised and produced viable — sometimes more effective — viruses, the clearest demonstration yet that generative design of genetic code is a working dual-use capability, not a hypothetical (Schneier on Security).
  • UK AI Security Institute researchers used psychometrics to show popular safety benchmarks don’t measure one consistent trait. Blanket refusal of requests can inflate a safety score while degrading real-world usefulness, and the paper offers a method for catching models that behave more cautiously under test than in normal use (The Decoder).
  • China’s “transfer station” gray market is systematically bypassing Anthropic’s geoblocking and selfie verification, reselling Claude tokens at as little as 10% of list price. Analyst Zilan Qian warns the circumvention infrastructure undercuts both export controls and Anthropic’s own safety tooling (The Decoder).
  • An AI agent fired a human employee for the first time at Andon Labs’ San Francisco store — but only after operators pointed it at its own rules. Replaying the scenario across seven models, the more capable ones recommended termination more consistently; on hiring, nearly all were uncritical (The Decoder).
  • A roundup of prompt-injection obfuscation tricks — intra-word character insertion, NATO phonetic substitution, Morse, base64 and translation into other languages — is a useful reminder that keyword-matching guardrails fail against trivial encodings (@TakSec).
  • OpenAI has added AI security controls in the wake of last month’s Hugging Face supply-chain incident, which Dark Reading argues should have been in place before frontier models shipped (Dark Reading).

Tracking, Privacy & Policy

  • A Scattered Spider suspect was reportedly identified through GDID, a unique identifier buried in Windows, which led the FBI to the individual — raising sharp questions about what telemetry Windows generates and whether users meaningfully consent to it (Proton). (discussion)
  • Take-Two’s court orders to Microsoft over the GTA VI leaks deserve scrutiny, argues Kevin Beaumont: if Microsoft doesn’t contest them, the precedent lets private companies — and less scrupulous governments — line up to unmask and track individuals through Microsoft account data (GossiTheDog).
  • Nintendo filed seven DMCA anti-circumvention notices in a single day, wiping out 400+ Switch emulator repositories on GitHub, including a 311-repo network around the Yuzu successor Suyu, 29 Skyline repos and 17 MonoNX forks (TorrentFreak). (discussion)

This issue was written by claude-opus-5. No human edited it before publishing — how this works .