Tag: critical infrastructure
574 articles

China-Linked Hackers Deploy TinyRCT Backdoor in Southeast Asian Infrastructure Attacks
For years, a stealthy China-linked hacking group has been quietly targeting critical infrastructure in Southeast Asia, with a clear strategic interest in disrupting or monitoring key regional industries. Their sophisticated attacks have zeroed in on state-owned energy and government sectors, using a potent tool called the TinyRCT backdoor.

FCC Tightens Cybersecurity Rules for Emergency Alert Systems, Undersea Cables
The FCC has just tightened cybersecurity rules for emergency alert systems and undersea cables to prevent vulnerabilities that could be exploited by rogue actors, foreign governments, or cybercriminals to spread chaos and misinformation. This move aims to safeguard the nation's primary public-warning platforms, including the Emergency Alert System and Wireless Emergency Alerts.

Iranian Hackers Exploit Credentials in Cal Water Breach
Cal Water swiftly sprang into action when an Iranian-linked group, Handala, claimed to have hacked their system, activating their cybersecurity response plan and launching a thorough investigation. Thankfully, experts from Mandiant found that the breach was limited to third-party accounts, containing no evidence of a larger-scale attack.

Australia's Security Threats Converge as AI Compresses Risk Timeline
When Australia's critical infrastructure is disrupted, it will be a shock, but not a surprise - and with AI supercharging threats, that disruption may come sooner than we think. The warning signs are clear: AI is rapidly expanding the offensive toolkit, making threats more immediate, concurrent, and devastating.

ASIO Disrupts Nation-State Cyber Sabotage Targeting Australian Infrastructure
ASIO director general Mike Burgess revealed that nation-state hackers had infiltrated a critical Australian infrastructure provider's network, gaining login credentials to sabotage it at will. The alarming breach was thwarted thanks to ASIO's swift action and dedicated response.

CISA Warns of Active Exploitation of Lantronix EDS5000 Flaw
A critical code-injection flaw, CVE-2025-67038, has been discovered in Lantronix EDS5000 Series devices, allowing attackers to inject arbitrary OS commands with root privileges due to a lack of input sanitization in the HTTP RPC module. This vulnerability has a CVSS score of 9.8, indicating a high severity level.

Scattered Spider hackers plead guilty to TfL cyberattack
Two young hackers, part of the notorious Scattered Spider group, have pleaded guilty to orchestrating a devastating cyberattack on Transport for London, causing millions in losses and disrupting the lives of countless commuters. The breach, which lasted several days in September 2024, forced TfL to acknowledge that sensitive customer data had been stolen.

US Accelerates Post-Quantum Cryptography Migration with 2030 Deadline
The White House is taking a major step to protect America's sensitive data and digital economy by mandating a rapid migration to quantum-safe encryption, with a deadline of 2030 for key establishment and 2031 for digital signatures. This move aims to safeguard critical infrastructure, jobs, and growth by future-proofing the nation's cybersecurity.

Hacktivism Surges as Geopolitical Crises Expose Cybersecurity Gaps
Hacktivist attacks have skyrocketed amid rising geopolitical tensions, with over 149 incidents reported in just three days - a stark reminder of the growing cybersecurity gaps. This alarming surge is part of a larger trend that began in February 2022, with hacktivist groups increasingly targeting critical infrastructure during times of conflict.

Australia's Food Security Prepares for Stress Test
A year of global turmoil has put Australia's food security to the test, proving that ensuring a steady food supply is crucial to national resilience. Recent events, from the Iran-Israel missile exchange to Strait of Hormuz pressures, have highlighted the need for governments to address vulnerabilities in the country's food system before it's too late.

Brazil Probes Hack of Emergency Alert System After Rogue Alert
A bogus emergency alert sent shockwaves across Brazil, pinging mobile devices in multiple states with a mysterious message reading "Alerta extremo - Defesa Civil:misantropi4". The authorities are now scrambling to investigate the hack, with SEDEC and Federal Police on the case.

Australia Urged to Rapidly Develop Cheap Drone Interceptors
In a chilling display of modern warfare, Russia's 900-strong drone assault on Ukraine in 2026 has sounded alarm bells - will Australia be prepared to counter the threat of cheap, destructive drones? Shahed-class drones, with their 50kg high-explosive warheads, have proven capable of devastating effects, from leveling apartment blocks to crippling critical infrastructure.

Operation Endgame Disrupts SocGholish Malware Network
In a major win for global cybersecurity, Operation Endgame has successfully dismantled a significant portion of the SocGholish malware network, depriving cybercriminals of access to thousands of infected computer systems and preventing further damage to citizens, businesses, and organizations worldwide. This decisive action has already remediated 15,000 compromised websites and taken down 106 key infrastructure nodes.

Ukraine Escalates Aerial Attacks on Moscow
Ukraine ramped up its aerial assault on Moscow, unleashing a barrage of drones and cruise missiles that struck the city's Kapotnya oil refinery, sparking massive fireballs and black plumes that were captured on dramatic resident-shot footage. The daring attack, acknowledged by President Volodymyr Zelenskyy, marks the second hit on the Moscow oil refinery this week.

Accenture Bolsters Industrial Cybersecurity with $4.18B Acquisition Spree
As Robert M. Lee aptly puts it, our critical infrastructure, from energy and water systems to manufacturing plants, is crying out for robust cybersecurity that can stay one step ahead of evolving threats - and failing to deliver it could have disastrous societal consequences. Accenture is answering the call with a whopping $4.18 billion investment to bolster industrial cybersecurity.

Pentagon Bolsters Rare Earth Supply with $1.2 Billion in Loans
The Pentagon is investing $1.2 billion to boost the US rare earth supply, with $725 million going to Energy Fuels and $500 million to Phoenix Tailings to enhance domestic processing and magnet production. This significant move aims to strengthen America's foothold in the critical rare earths sector.

Cyberattack Disrupts Australian Sugar Production
Mackay Sugar is making a sweet recovery after a cyberattack halted operations, with significant progress made over the weekend in restoring systems and a staged restart of crushing operations on the horizon. The company is getting back on track, with manual crushing already underway at its Farleigh Mill and harvesting expected to resume soon.

Chinese Hackers Maintain Decade-Long Spy Operation in Isolated Network
Chinese hackers pulled off a stunning 10-year cyber-espionage heist, infiltrating a supposedly airtight network and gaining unfettered access to every login, command, and secret. The masterminds behind Operation Highland, linked to the Velvet Ant cluster, expertly embedded their digital fingerprints into the network's authentication process.

Pentagon Explores Small Nuclear Reactors for Military Base Power
Radiant Nuclear is on the verge of a breakthrough, with plans to deploy its innovative one-megawatt microreactors at Buckley Space Force Base in Colorado, providing a reliable and secure energy source for military operations. The company is just 18 months away from delivering its first reactor, with testing set to begin this summer at the Idaho National Laboratory.

Nations Scramble to Build Critical Mineral Supply Chain Resilience
The conversation about critical minerals is no longer about "if" but "how" - and the Darwin Dialogue 2026 brought together global leaders to shift the focus from diagnosis to delivery. The big question now is why democratic economies struggle to build resilient supply chains at scale and speed.

Microsoft Patch Tuesday Release Sets Record with 206 CVEs Addressed
Microsoft just dropped a record-breaking Patch Tuesday update, fixing a whopping 206 vulnerabilities across its products - including 38 critical ones. This massive release surpasses previous months and confirms a trend towards larger updates, raising both relief and concern among security experts.

CISA Overhauls Risk Prioritization Approach for Federal Agencies, Private Sector
CISA is shaking up its approach to risk prioritization, urging a smarter strategy for applying patches and tackling vulnerabilities. Acting director Nick Andersen emphasizes the need to focus on what matters most, rather than rushing to apply every patch as soon as it's released.

US Gas Station Tank Gauge Systems Vulnerable to Ongoing Attacks
US gas stations are under cyberattack, with hackers exploiting vulnerable tank gauge systems to gain control and wreak havoc. A joint advisory from top US agencies is urging critical infrastructure organizations to secure their internet-exposed systems ASAP.

Pentagon Fortifies Cyber Defenses for Critical Infrastructure
The Pentagon is bolstering its cyber defenses for critical infrastructure, with a key focus on building a unified response framework to tackle cyberattacks on vital US systems. Col. Adolph Rodriguez is leading the charge, prioritizing not just technical solutions but also organizational clarity and control.