Three cybersecurity stories shocked experts this week, revealing threats hiding in plain sight across American infrastructure.
Highway solar panels contained secret spy radios, hackers pulled off a massive software attack for pocket change, and a US Senator accused Microsoft of gross negligence in hospital breaches.
Here's what happened and why it matters to you.
Welcome to the September 12, 2025, issue of Pithy Security. Here are this week's three most significant cybersecurity developments.
The Federal Highway Administration has just issued a warning about solar-powered highway infrastructure. Officials say chargers, roadside weather stations, and traffic cameras should be scanned for hidden radios secreted inside batteries and inverters. Federal and state-level reporting revealed "undocumented cellular radios" found inside inverters and batteries used across the US highway systems.
Key Insights:
The undocumented radios discovered in inverters and batteries represent a significant security vulnerability in critical infrastructure. These devices could enable remote tampering and surveillance, giving foreign adversaries backdoor access to America's transportation networks. Security experts warn that compromised highway systems could disrupt traffic flow, manipulate emergency alerts, or steal sensitive location data from millions of daily commuters.
Why This Matters For You:
Your daily commute just became a cybersecurity battleground. Those innocent solar panels powering traffic lights, emergency call boxes, and digital highway signs could be secretly transmitting data or receiving commands from foreign adversaries. When hackers can remotely control traffic systems, weather alerts, and roadside cameras, they're putting millions of drivers at risk during rush hour, emergencies, and severe weather events.
Read More on Reuters.
Hackers pulled off one of the largest supply chain attacks in history by compromising 18 popular npm packages that receive 2 billion weekly downloads. (npm packages are "ready-made" chunks of code that developers share and use.) The attackers phished the account of developer "qix" and poisoned versions of widely-used JavaScript libraries, including chalk and debug. Despite reaching millions of developers and hitting 10% of cloud environments, the sophisticated crypto-draining malware initially stole just 5 cents! A comically small amount that some security researchers have since revised slightly upward, but the irony remains.
Key Insights:
The malicious versions were only live for about 2.5 hours on September 8, 2025, before being removed. The attack targeted cryptocurrency wallets in browsers, designed to hijack transactions from Ethereum and Solana users. Security researchers noted the irony that the most significant financial impact will likely be the millions of dollars companies spend on new security vendor contracts rather than actual theft.
Why This Matters For You:
When the world's most popular coding libraries get hijacked but barely anyone loses money, it reveals something encouraging about modern security defenses. The rapid detection and removal show that supply chain monitoring is working, even if it can't prevent initial compromise. For developers who downloaded these packages during those critical 2.5 hours, their wallets stayed safe thanks to a quick industry response, proving that sometimes the cybersecurity community's immune system works exactly as designed. For once! 🛡️
Read More on Bleeping Computer.
Senator Ron Wyden is demanding the Federal Trade Commission investigate Microsoft for "gross cybersecurity negligence" after a series of high-profile attacks. The Oregon Democrat points to the devastating 2024 Ascension hospital ransomware attack that affected 5.6 million patients. According to Wyden's office, the breach started when a contractor clicked a malicious link on Microsoft's Bing search engine.
Key Insights:
While Microsoft boasts $20 billion yearly in cybersecurity revenue, the Ascension attack caused harrowing lapses, including delayed lab results, medication errors, and absent safety checks. The health system posted a $1.1 billion net loss, partly attributed to the cyberattack. Wyden argues Microsoft's default security settings leave customers vulnerable to ransomware and other threats.
Why This Matters For You:
The investigation demands a shift toward holding Big Tech accountable for security failures in critical infrastructure. When hospitals can't access patient records or pharmacies lose prescription data because of software vulnerabilities, the consequences reach far beyond corporate balance sheets. Healthcare workers had to revert to manual documentation, delaying critical patient care, showing how cybersecurity negligence directly impacts the services people depend on daily.
Read More on PC Mag.
In 2015, hackers calling themselves The Impact Team breached Ashley Madison, a dating site for people seeking affairs. They stole data on 32 million users. Data included names, emails (many from government and military domains), and payment records.
When the company refused to shut down, the hackers dumped the information online. Careers collapsed. Marriages ended. The fallout led to widespread extortion attempts and profound personal devastation.
The chilling truth: not all breaches are about money. Sometimes, the goal is pure destruction.
These are my go-to privacy + security tools. Some links are affiliate links. (They support this newsletter at no extra cost to you!)
Proton Mail - One of the more private and secure email services. Basic accounts are free.
Proton VPN – Keep your internet, browsing history, and connection secure with servers in over 120 countries.
Proton Pass - Protect passwords with an elite encrypted password manager. Supports 2FA codes, device sync, multiple vaults, notes, and more.
Proton Drive - Store your data safely. Get 5GB for free and enjoy peace of mind, knowing your files are safe.
Please read my two newsletters:
# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun AI prompt in each issue.
# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security that lets you spot scams and stay safe without needing to become an expert.
Follow for extra insights:
Bluesky | X (Twitter) | LinkedIn | YouTube
PS: Do you have questions? Reply to this email!
Thanks for reading. More cutting-edge cybersecurity insights coming soon.
You're receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.