|
⚡ Hackers shut down UK power plant
LINK
|
- Iranian-linked hackers forced a small British electricity generator completely offline for four consecutive days in July, in what is reported as the first successful cyberattack to fully disrupt a UK energy-generation facility.
- The UK government said the attack hit only a small-scale generator below the reporting threshold for major operators, did not threaten the national grid, and caused no outages at regulated major power stations, with negligible impact on national capacity.
- Analysts view the shutdown as a proof-of-concept by groups tied to Iran's Islamic Revolutionary Guard Corps to show they can penetrate operational technology environments; afterward, DESNZ briefed energy chief executives, sent written cybersecurity guidance, and is updating sector regulations.
|
🏦 Hackers breach Apollo
LINK
|
- Private equity firm Apollo Global Management has confirmed hackers broke into its cloud systems and stole personal data, including names, birth dates, home addresses, and Social Security numbers, in an intrusion between July 6 and July 10.
- The attackers used a social engineering attack to reach Apollo's cloud environment, part of a wider extortion campaign in which a hacking group calls employees pretending to be IT helpdesk staff to trick them into entering passwords and multi-factor authentication codes on spoofed login portals.
- The same group, which also targeted Blackstone, Bridgewater, and Bain Capital, steals data then extorts companies to avoid publication on its leak site, netting ransoms as high as $750,000; Apollo did not say whether it paid or who was affected.
|
📦 npm packages plant Linux backdoor
LINK
|
- Malicious npm packages posing as calendar and streak-calculation date utilities are secretly deploying RedShell, a Linux backdoor tied to the RedC2 command-and-control framework, TrendAI researchers found in an active software supply chain campaign.
- When a developer imports an affected module, the entry file runs automatically, makes a bundled Linux binary executable and starts it as a detached background process, so the standard --ignore-scripts protection does not block execution.
- Once running, RedShell can steal SSH keys, browser-stored credentials and database files, open reverse shells and set up SOCKS5 proxying to move traffic through the host, letting attackers reach source code, cloud tokens and production networks.
|
🔑 768 leaked AWS keys still grant admin
LINK
|
- Truffle Security found 768 publicly leaked AWS access keys that are still active and grant full administrator control over corporate cloud environments, exposing organizations to account takeover, data theft, infrastructure abuse, and cloud billing fraud.
- Researchers analyzed exposed AWS credentials from August 2022 to August 2026 and re-validated 10,616 key pairs on August 10, finding 88% still authenticated, with keys pulled from public Git histories, Hugging Face datasets, Docker images, package registries, and CI/CD logs.
- Of 817 active keys tied to business accounts, 768 kept full admin capabilities and 130 live root keys were linked to AWS Organizations management accounts; Truffle recommends eliminating root keys, rotating exposed credentials immediately, and treating any publicly exposed secret as permanently compromised.
|
📌 Phishing kit survives your password reset
LINK
|
- A new phishing toolkit called iAuthFlow V2, sold for $10,000 on a Russian-language cybercrime forum, keeps attackers inside a victim's account even after a password reset, according to analysis by Abnormal.
- The kit runs a second browser on the attacker's server that relays the victim's real-time credentials and authentication responses, silently registering an attacker-controlled passkey to a Gmail account while the target authenticates through the phishing page.
- Because a passkey is a credential registered to the account rather than a password-derived token, the standard fix of resetting the password and revoking sessions does not remove it, letting the attacker log back in via "try another way" without the password.
|
|