Cyber threat actors are using AI to accelerate attacks on industrial control systems, targeting of Siemens S7 PLCs. Attackers are scanning the internet for exposed controllers. Campaign is focused on critical manufacturing, energy, water and wastewater, chemical, food & agriculture, commercial facilities; defense industrial base potentially exposed. The immediate risk is disruption, equipment damage and downtime. Malicious PLC writes might eventually alter process or safety logic, move equipment outside safe operating limits, or even cause danger to humans https://media.defense.gov/2026/Aug/18/2003983494/-1/-1/0/CSA_Active_Threat_to_Siemens_S7_Series_PLCs.PDF
Spain investigating a major data exposure linked to the pro-Russian hacker group NoName057, which released a 499-page document containing sensitive personal information on around 1,000 police officers, Civil Guard members, military personnel, and other security-related individuals. The data included names, photographs, phone numbers, email addresses, home addresses, contacts, and, in some cases, details about their units or roles. It is unclear whether the group hacked official systems or compiled the data from previously leaked, compromised, or publicly available sources. https://elpais.com/espana/2026-08-17/la-policia-investiga-el-acceso-del-grupo-hacker-prorruso-noname057-a-datos-sensibles-de-medio-millar-de-policias-y-militares.html
Hackers stole personal data on 68% of Latvia’s population! The target was a state agency responsible for vehicle registration, driving licences and other services for drivers. The breach affected 1.2 million people and 200,000 companies, exposing names, personal ID numbers, addresses, vehicle registration numbers and payment details, with records dating back to 2008. Latvia’s president called the attack a threat to national security and demanded that the agency’s leadership resign. Its supervisory board has already stepped down, while the agency’s director has said he will leave his post.
… and medical data of 19 000 000 people of Poland. https://therecord.media/poland-probes-mydr-healthcare-software-breach
Chinese-speaking cyber threat actor used DeepSeek, Qwen, Kimi and MiniMax to automate attacks on internet-facing infrastructure. AI agents handled target discovery, searched GitHub for tools, assessed CVEs, narrowed targets, launched exploitation attempts. Autonomous attacks had limited success. Still, they decreases hundreds of hours of targeting analysis into minutes. Separate manual campaigns exfiltrated data from a few targets. https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
In case you feel it's worth it to forward this content further:
Subscribed
If you’d like to share:
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.