Showing posts with label cyber attacks. Show all posts
Showing posts with label cyber attacks. Show all posts

Thursday, September 24, 2026

Australia to investigate if OpenAI hack of government health website broke the law

Possible trouble for OpenAI from down under? We are learning more about how OpenAI may have obtained data.

"An OpenAI model hacked into an Australian government website, the country’s prime minister Anthony Albanese said Wednesday, in the first publicly reported case of an AI model hacking into a government’s systems. 

Albanese said that there would “obviously be legal consequences” following the breach, and that OpenAI faces a government investigation into how its unreleased models gained access to reams of bulk health data information. ..."

Australia to investigate if OpenAI hack of government health website broke the law | TechCrunch

Thursday, September 10, 2026

For North Korea, AI is a cybercrime force/crime multiplier increasing the already large scale of its cyber crimes

Recommendable overview article! Is not a way shut down these massive criminal activities by North Korea? This has been going on for decades using ever changing technologies.

"AI is changing how states operationalise their cyber capabilities. In North Korea’s case, it’s transforming the country into a bigger cyber power by helping Pyongyang expand what it already does: generate revenue, obtain trusted access and collect intelligence at extraordinary scale.

North Korea has built one of the world’s most unusual state cyber programs, treating hacking not only as an instrument of statecraft but as an industry.
Its operations combine cryptocurrency theft, fraudulent overseas IT employment and other forms of cybercrime with longstanding espionage against foreign defence, aerospace, government and policy targets. AI fits naturally into this model because its greatest value is in lowering the cost of running existing fraudulent models.

The scale of North Korea’s malicious cyber activity is already remarkable.
In the first half of 2026, blockchain intelligence firm TRM Labs assessed that North Korean hackers stole around US$643 million (A$900 million) in cryptocurrency, accounting for roughly 66 percent of tracked global crypto theft. Pyongyang has effectively industrialised cyber-enabled revenue generation, from large-scale cryptocurrency theft to bank heist operations. It’s turning capabilities once associated with intelligence services and transnational criminal organisations into a reliable source of hard currency. ...

This is most prominent in North Korea’s fraudulent IT-worker operations, in which nationals win legitimate remote IT jobs using fabricated or stolen identities, drawing salaries that benefit the regime while gaining trusted access to the systems they are hired to build.
One estimate has found that as many as 22 operatives submitted at least 166,893 applications to US companies across 2024 and 2025, sat more than 21,000 interviews and secured at least 76 job offers. ..."

For North Korea, AI is a cybercrime force multiplier | The Strategist

Wednesday, September 09, 2026

Three bipartisan lawmakers ask US government to ban three Indian hack-for-hire firms. This is huge!

Concerning! Serious allegations! What is PM Modi doing about it?

The scale of activities of these three hacking for hire companies is mind boggling! They don't operate in the shadows!

"A bipartisan group of U.S. lawmakers has asked the U.S. government to ban several hack-for-hire firms — companies that carry out cyberattacks on behalf of paying clients. The lawmakers accuse the firms of targeting Americans and abusing foreign courts to silence U.S. reporting on their activities. ..."

"... Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them. Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.

These hackers have systematically subverted the U.S. legal and financial sectors, targeting private equity firms, pharmaceutical companies, and more than 1,000 attorneys across major U.S. law firms to manipulate ongoing litigation. The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence. While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.

Simultaneously, these actors have mounted an aggressive censorship campaign to suppress public awareness of their illicit activities, directly threatening American free speech and press freedom.
Executives connected to one hack-for-hire group secured an Indian court order enforcing a global takedown of an investigative report by Reuters, including a copy of the report hosted by the Internet Archive. To force further censorship, these foreign hackers have launched ongoing lawsuits against major American media institutions and technology companies,including Google, Meta, Microsoft, and The New Yorker. ...

To hold these illicit actors accountable, we request that the Commerce Department’s Bureau of Industry and Security add the following companies—identified by Reuters and Citizen Lab as the perpetrators of the hacking operations outlined above— to the Entity List to cut off their access to American software, cloud infrastructure,and cybersecurity tools:
Sunkissed Organic Farms Pvt. Ltd. (formerly known as “Appin Technology Pvt. Ltd.”) and subsidiaries, including: ...
BellTroX Pvt. Ltd.
CyberRoot Pvt. Ltd.
..."

Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms | TechCrunch

Tuesday, September 08, 2026

A white hat hacker stole $340M or about 4,000 bitcoins in a crypto heist on Liquid Network, then he returned most of it after

I guess, he proved he could do it! This was not a theoretical attack approach!

"A hacker stole thousands of bitcoins worth about $340 million in a heist at a settlement exchange used by several cryptocurrency exchanges, representing one of the largest known thefts of crypto this year.

Liquid Network, launched in 2018 by crypto firm Blockstream, said in a post on X on Sunday that a “white hat” hacker stole the funds from the network’s wallet, and that it has paused operations until the incident is resolved. ...

The hacker said they would return the funds if Blockstream fixed the bug. ...

Former Blockstream executive Samson Mow said in a post on X on Monday that the company had fixed the bug, and around 3,400 of the roughly 4,000 stolen bitcoins had been returned. The remaining about 600 bitcoins (about $47 million) were still under the hacker’s control. ..."

A hacker stole $340M in a crypto heist, then returned most of it | TechCrunch

Sunday, August 30, 2026

National Emergency: Protecting America’s Power Grid from foreign sabotage and cyber attacks

It seems the reported cyber attacks on water treatment plants and electric power system were more serious!

"On August 26, President Trump declared a national emergency under the International Emergency Economic Powers Act [of 1977] to secure the United States bulk-power system from foreign sabotage and cyberattack. The executive order cites foreign actors — including state-sponsored adversaries — creating and exploiting cybersecurity vulnerabilities across America’s electricity infrastructure, threatening national defense, emergency services, and economic stability.
The order generally prohibits foreign-produced bulk-power equipment and associated software, and directs the Secretary of Energy to publish implementing rules.
A prior complementary order already preserved an estimated 17,000 megawatts of generating capacity — enough to power 12.75 million American homes. The emergency declaration extends that protection across the full bulk-power supply chain, complementing other administration orders targeting AI cybersecurity, defense supply chains, and drone imports."

White House Weekly Briefing | August 24–30, 2026

Thursday, August 27, 2026

The FBI disrupted a massive China-linked hacking network that broke into government systems.

Good news! What took so long!

"The operation targeted networks at the Federal Reserve, the Energy Department, NASA and the Senate, the FBI said in a court filing. Dubbed QTFY by U.S. officials, the campaign has been run since 2018 by a private company based in China that sells access to hacked networks and stolen information to China’s foreign and military intelligence services, the FBI said."

"U.S. officials say they have disrupted a China-linked hacking operation that broke into U.S. government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.

The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing. ..."

The Wall Street Journal What's news

FBI Shuts Down Sprawling China-Linked Hacking Network (behind paywall) "Spy operation targeted NASA, the Federal Reserve and other areas, hiding within normal internet traffic to avoid detection"

Wednesday, August 26, 2026

Cyber security by antiquity. Really!

AKA "security by obsolescence". What a dangerous delusion or is it junk journalism by BBC!

Maybe many of those believing in and applying cyber security by antiquity are of little relevance/value to cyber hackers or are no targets of criminals anyway.

Perhaps this "top cybersecurity expert" is antiquity himself or herself and nobody bothers anymore to hack him or her! 😊

Why are militaries still using old software? Perhaps, they have too much old software to be replaced.

Notice the article below is only about the long obsolete email client software Eudora (discontinued in 2006)!

"A top cybersecurity expert ran obsolete email software for years because hackers had stopped bothering with it. The strategy is called “security by antiquity,” and militaries swear by it too."

"... "The vast majority of attackers are criminals trying to make money and it doesn't make any sense for them to target systems being run by 50 people," [the cybersecurity expert] explains. ..." Maybe this cybersecurity expert from Finland is poor! 😊

Tuesday, August 25, 2026 - Join The Flyover

'Security by antiquity': Why older tech is sometimes safer from hackers "The fear of hacking has made some people turn to other forms of technology ignored by new generations of cyber criminals."

Sunday, August 23, 2026

Iranian cyberattack shuts down British power plant for four days

Bad news! Is this dawn of the age of cyber wars!

I blogged here recently about what could be a similar attack on water treatment plants in Minnesota and 11 other US states. ...

Though British officials have not named the targeted power plant, citing security concerns, the outlet noted that it is "relatively small" and, as such, the attack did not affect the UK's national power supply or its ability to generate power. ..."

"Iran shut down a British power plant for four days in an unprecedented cyber attack, The Telegraph can disclose.

It is thought to be the first time that hackers affiliated to the Iranian regime have succeeded in closing down such a facility in the UK, and is believed to be the most successful cyber attack of its kind. ..."

Iranian cyberattack shuts down British power plant for four days | The Jerusalem Post "The attack occured during the reported Iranian cyberattack that targeted over 30 municipal water systems in Minnesota and several other states in the US, according to the Telegraph."

Iranian hackers shut down UK power plant "Unprecedented cyber attack believed to be most successful of its kind"

Thursday, August 13, 2026

In a first, US will allow some private firms to carry out cyberattacks and disruptive operation against Transnational Criminal Organizations

Concerning! This could potentially have international ramifications! As a minimum these operations would have to be closely monitored and supervised.

"The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday.

In a newly published presidential memorandum, the Trump administration said the move will allow the federal government to use “innovative capabilities of the private sector” to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams, and sextortion.

The memorandum allows private companies participating in the government’s program to conduct surveillance, like using spyware to collect intelligence, as well as make disruptive attacks aimed at the destruction of criminals’ data or systems.

The policy change marks a seismic shift in the U.S. government’s long-standing position under U.S. federal computer hacking laws, which broadly prohibit private companies from conducting cyberattacks or disruption operations without a court-authorized approval. ..."

In a first, US will allow some private firms to carry out cyberattacks | TechCrunch

Wednesday, August 12, 2026

China’s Escalating Cyberattacks Threaten Taiwan’s National Security

Serious stuff! China is a bully! 

Hong Kong was already invaded/taken over illegally by the Communist Party of China after the Basic Law became effective in 1997!

Why does Taiwan not offer reunification under the condition that China becomes  like a Western democracy?

"Amid intensifying cross-Strait tensions, Taiwan is among the world’s most frequent targets of cyberattacks, predominantly attributed to Chinese state-backed hackers. Taiwan’s National Security Bureau (NSB)  has assessed that infrastructure on the island experienced a daily average of 2.63 million cyberattacks in 2025, more than double that of 2023. Energy, emergency rescue, hospitals, and communications infrastructure were the sectors that faced the most significant increases in the number of attacks in 2025, as compared to the previous year.  ..."

China’s Escalating Cyberattacks Threaten Taiwan’s National Security | Global Taiwan Institute

Sunday, August 09, 2026

The AI safety test is becoming a safety risk

Headline of the day! Is the genie out of the bottle? 😊 Probably not! 

"The phrase "the genie is out of the bottle" comes from Middle Eastern folklore popularized in the West by One Thousand and One Nights" (Google Search)

Two days ago, I blogged here about a similar incident regarding the Chinese Kimi mode.

"Over the past few months, AI agents undergoing cybersecurity evaluations have escaped their boundaries, accessed the internet, and, in some cases, hacked into real-world systems. The incidents have involved models from OpenAI, Anthropic, Meta, and most recently, Chinese AI lab Moonshot AI, with testing conducted by several different organizations including a cyber evaluation startup called Irregular. ...

The episodes expose a growing problem for the AI industry: As autonomous agents become more capable, the environments designed to safely test their limits are failing to contain them. ..."

The AI safety test is becoming a safety risk | TechCrunch

Friday, August 07, 2026

Well known Hackers with ties to Iran Hit Water Systems in 12 US States since March 2026

Bad news! Very concerning!

Maybe future wars will not be so bloody anymore as far as the military is concerned, but more devastating if not dangerous to the civilian population.

"Cyberattacks have hit water and wastewater systems in at least 12 states, officials say, with an Iran-linked hacking group suspected of trying to disrupt American infrastructure as the war drags on.

The self-proclaimed “CyberAv3ngers,” which cybersecurity experts tie to Iran’s Revolutionary Guard, locked administrators out of more than 30 systems in Minnesota alone and blocked water from being pumped into towers. No supplies were harmed, but sources say hackers could have reached chemical dosing controls.

President Trump doubted Iran’s involvement, instead blaming “grossly incompetent” Minnesota leaders after an attack shut down a water plant there. ..."

"... The Federal Bureau of Investigation (FBI) and U.S. Environmental Protection Agency (EPA) stated in their July 30 joint public service announcement (Alert: I-073026-PSA) that since July 27, 2026, water and wastewater utilities in at least seven states had reported incidents, and that some of that activity had "degraded water operations." The FBI stated that reported operational effects have included pressure loss and flooding, and identified Rockwell Automation MicroLogix 1100 and 1400 series PLCs as the targeted devices. The PSA does not attribute the activity to any specific actor, referring only to "malicious cyber actors." ...

How has CyberAv3ngers evolved over time?

CyberAv3ngers has demonstrated a deliberate capability escalation across four documented phases:

In Phase One (2020–2022), the group operated as a propaganda persona, claiming responsibility for infrastructure disruptions in Israel that were later assessed as fabricated. DomainTools Investigations demonstrated that several claims reused imagery from earlier data leaks.

In Phase Two (October 2023–January 2024), the group compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland by exploiting default passwords on internet-exposed devices. The Municipal Water Authority of Aliquippa, Pennsylvania, was the highest-profile victim.

In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices. OpenAI disclosed in October 2024 that CyberAv3ngers had used ChatGPT to assist with target reconnaissance and code debugging.

In Phase Four (March 2026 to present), the group pivoted to exploiting CVE-2021-22681, a critical authentication bypass in Rockwell Automation Logix controllers. Actors connected to internet-facing PLCs from foreign hosting providers using the same manufacturer engineering software (Studio 5000 Logix Designer) that legitimate operators use. Once connected, they downloaded and modified controller project files and altered operator display data. The July 22 advisory update expanded the manufacturer scope to include Schneider Electric and Siemens PLCs alongside Rockwell Automation. ..."

Wednesday, August 5, 2026 - Join The Flyover



Monday, July 27, 2026

'Unprecedented' Self-Directed CyberAttack on Hugging Face by OpenAI's Rogue Model Was Repelled by Chinese Defensive AI

I had intended to publish this blog post earlier! I procrastinated! Mea culpa!

I have just blogged here about this complex and very sophisticated cyber attack.

'Unprecedented' Self-Directed CyberAttack by OpenAI's Rogue Model Was Repelled by Chinese Defensive AI "AI startup Hugging Face deployed a Chinese-developed AI model to counter an unprecedented cyberattack launched by a rogue OpenAI system, highlighting both the emerging threat of autonomous AI attacks and the growing capabilities of Chinese AI technology."

OpenAI used the ExploitGym to cyber attack Hugging Face

What an irony! 😊 There is even a research paper published in May as a preprint on arXiv about ExploitGym with the title containing "Turn Security Vulnerabilities into Real Attacks"! 

As they say reality is stranger than fiction! 😊

I blogged here and here about this incidence before.

"... OpenAI pitted its models against a benchmark called ExploitGym, released in May, which challenges LLMs to find ways to exploit real-world vulnerabilities found in commonly used software. ...

On July 9, according to reporting by Reuters, OpenAI’s models started trying to break through the proxy. They found an unknown bug in the proxy’s software and used it to access the internet. From there, they broke into Hugging Face’s computer systems on July 11, apparently looking for data sets and solutions that would help them complete their task. Hugging Face announced the hack on July 16. ..."

The Hugging Face AI hack is scary—but unsurprising

Tuesday, July 21, 2026

The cyber attack on Hugging Face was quite complex and sophisticated


Bad news!

"An autonomous AI agent breached Hugging Face’s production infrastructure through a malicious dataset, moving laterally across systems for an entire weekend without detection.
When the incident response team tried to analyze the attack using commercial frontier models, safety guardrails blocked every forensic query—treating the defenders’ real exploit data the same way they would treat a live attack.
The agent executed thousands of actions through short-lived sandboxes, harvesting cloud credentials and reaching multiple internal clusters, all without human guidance.
Hugging Face ultimately completed its forensic analysis using GLM 5.2, an open-weight model running on its own infrastructure, because it was the only option that wouldn’t refuse to process attacker artifacts.
The incident exposes a basic asymmetry: Defenders operating under enterprise governance hit safety controls that don’t constrain attackers running uncensored models, turning AI tooling into a potential single point of failure during the exact moment security teams need it most."

"... The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files.
No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset.
Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.

Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion. ..."

Data Points: Kimi K3 marks a big shift in AI development

Wednesday, July 15, 2026

US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from cybercrime victims

How rogue is Russia under Putin the Terrible!

"U.S. prosecutors have charged three Russian nationals and two web hosts with hacking, conspiracy, and money laundering over their alleged roles in hosting cyberattacks that caused tens of millions of dollars in damages to U.S. businesses.

The three Russians, Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova, who reside in St. Petersburg, are accused of owning and running two web hosts, Media Land and ML.Cloud, which allegedly provided criminals and state-backed hackers with web hosting and infrastructure support for carrying out cyberattacks. ..."

US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from cybercrime victims | TechCrunch

Thursday, April 16, 2026

European police agency Europol sends emails and letters to 75,000 people asking them to stop DDoS attacks

What took so long! For the past several decades there should have been more aggressive law enforcement action against cyber crime like DDOS attacks!

"A coalition of global law enforcement agencies have sent emails to more than 75,000 alleged cybercriminals who paid for a service to launch cyberattacks that can knock websites offline.

On Thursday, Europol announced the coordinated operation against several distributed denial-of-service (DDoS) for-hire services, which allow criminals to launch cyberattacks without needing to have any hacking skills, nor the need to run their own infrastructure. 

Part of the law enforcement action — dubbed Operation PowerOFF — included Europol sending warning emails and letters to more than 75,000 people who are suspected of using these DDoS-for-hire services. 

Europol said it obtained information about the alleged cybercriminals by raiding and seizing servers associated with these services, allowing the police to identify their registered users.

The action also resulted in four arrests, the takedown of 53 domains, and police executing 24 search warrants. ..."

European police email 75,000 people asking them to stop DDoS attacks | TechCrunch

Tuesday, April 07, 2026

Russian government hackers broke into thousands of home routers around the world to steal passwords

The megalomaniac and war criminal Putin the Terrible attacks the rest of the  world!

"A group of Russian government hackers have hijacked thousands of home and small business routers around the world as part of an ongoing campaign aimed at redirecting victim’s internet traffic to steal their passwords and access tokens, security researchers and government authorities warned on Tuesday.

This is the latest tactic by the long-running Russian hacking group known as Fancy Bear, or APT 28, known for its high-profile hacks and spying operations, including the breach of the Democratic National Committee in 2016 and the destructive hack that hit satellite provider Viasat in 2022. Fancy Bear is widely believed to be part of Russia’s intelligence agency GRU.

The hacking group targeted unpatched routers made by MikroTik and TP-Link using previously disclosed vulnerabilities according to the U.K. government’s cybersecurity unit NCSC and Lumen’s research arm Black Lotus Labs, which released new details of the campaign Tuesday. ..."

Russian government hackers broke into thousands of home routers to steal passwords | TechCrunch

Iranian hackers are targeting American critical infrastructure, US agencies warn

Was this part of the just agreed upon 14 days cease fire agreement?

"The U.S. government is warning that Iran-backed hackers are escalating their tactics by targeting American critical infrastructure systems with the aim of causing disruption.

In a joint advisory published Tuesday, the FBI, the National Security Agency, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Energy collectively warned that Iranian government hackers have been exploiting internet-facing systems used across a range of sectors. These include water and wastewater utilities, as well as energy and local government facilities. The agencies did not specifically name any of the targets but said that the hacks were aimed at causing “disruptive effects within the United States” and had already resulted in “operational disruption and financial loss.”

The hackers targeted programmable logic controllers and supervisory control and data acquisition (SCADA) products ..."

Iranian hackers are targeting American critical infrastructure, US agencies warn | TechCrunch