RSS Amplifier

Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique · Aug 24, 2026

TechLetters ☕️ AI accelerates attacks on industrial control systems. Pro-Russian hackers expose Spanish security personnel. Data of 68% Latvian and 50% Poland (medical records) population leaked.

0
Sign in to vote or save

Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique · Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique

Cyber threat actors are using AI to accelerate attacks on industrial control systems, targeting of Siemens S7 PLCs. Attackers are scanning the internet for exposed controllers. Campaign is focused on critical manufacturing, energy, water and wastewater, chemical, food & agriculture, commercial facilities; defense industrial base potentially exposed. The immediate risk is disruption, equipment damage and downtime. Malicious PLC writes might eventually alter process or safety logic, move equipment outside safe operating limits, or even cause danger to humans https://media.defense.gov/2026/Aug/18/2003983494/-1/-1/0/CSA_Active_Threat_to_Siemens_S7_Series_PLCs.PDF

Spain investigating a major data exposure linked to the pro-Russian hacker group NoName057, which released a 499-page document containing sensitive personal information on around 1,000 police officers, Civil Guard members, military personnel, and other security-related individuals. The data included names, photographs, phone numbers, email addresses, home addresses, contacts, and, in some cases, details about their units or roles. It is unclear whether the group hacked official systems or compiled the data from previously leaked, compromised, or publicly available sources. https://elpais.com/espana/2026-08-17/la-policia-investiga-el-acceso-del-grupo-hacker-prorruso-noname057-a-datos-sensibles-de-medio-millar-de-policias-y-militares.html

Hackers stole personal data on 68% of Latvia’s population! The target was a state agency responsible for vehicle registration, driving licences and other services for drivers. The breach affected 1.2 million people and 200,000 companies, exposing names, personal ID numbers, addresses, vehicle registration numbers and payment details, with records dating back to 2008. Latvia’s president called the attack a threat to national security and demanded that the agency’s leadership resign. Its supervisory board has already stepped down, while the agency’s director has said he will leave his post.

… and medical data of 19 000 000 people of Poland. https://therecord.media/poland-probes-mydr-healthcare-software-breach

Chinese-speaking cyber threat actor used DeepSeek, Qwen, Kimi and MiniMax to automate attacks on internet-facing infrastructure. AI agents handled target discovery, searched GitHub for tools, assessed CVEs, narrowed targets, launched exploitation attempts. Autonomous attacks had limited success. Still, they decreases hundreds of hours of targeting analysis into minutes. Separate manual campaigns exfiltrated data from a few targets. https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/

In case you feel it's worth it to forward this content further:

Subscribed

If you’d like to share:

Share

No posts

Read the original on techletters.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.