
A private route to public risk.
Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US and South Korea warn of “Gunra” ransomware gang with North Korean ties. OpenAI mandates strict security controls for its new cybersecurity model. Record-breaking DDoS attacks surge in H1 2026. Data-scraping AI extension returns to the Chrome Web Store. Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI at Black Hat USA to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization.
Today is August 11th, 2026. I’m Maria Varmazis. And this is your CyberWire Intel Briefing.
Poland’s CERT describes winter cyberattack against heat-and-power plant.
Poland’s Computer Emergency Response Team has disclosed that hackers breached a Polish combined heat-and-power plant by exploiting a misconfigured private Access Point Name (APN) network. The attackers initially compromised a wind farm's firewall, then tunneled into the shared APN to locate an exposed controller at the power plant, secured only by default credentials. They used this access to get into the plant's OT network, temporarily shutting down a steam turbine and water treatment system. Polish authorities quickly restored the systems before there was any impact to the public, but said this marks the first known real-world cyberattack using a private APN for lateral movement into an OT network.
The attack took place on December 29th, 2025, the same day that hackers tied to Russia’s Electrum APT targeted dozens of heat and power facilities across Poland. Though the attacks failed to cause significant disruptions, experts emphasized that the hackers tried to cut off heat from civilian populations in the dead of winter.
Russian military hackers target Ukrainian IT workers in fake recruitment scheme.
Hackers linked to Sandworm, a threat actor attributed to Russia's GRU military intelligence agency, are posing as recruiters to target Ukrainian IT workers, according to Ukraine's computer emergency response team. The campaign, active since at least May, involves hackers finding potential victims on legitimate job sites, conducting fake interviews on Telegram and Zoom, and eventually tricking candidates into downloading a malicious VPN app called "SopraVPN." This app, disguised as a legitimate tool needed for a technical interview assignment, executes covert, malicious commands on the victim's device.
Chinese IP connections spark security review in UK Navy drones.
A UK cybersecurity assessment found that cameras aboard Royal Navy drone boats were contacting Chinese IP addresses. The issues were discovered in cameras on Kraken Unmanned Surface Vessel sub-systems, and involved non-sensitive "heartbeat communications" rather than operational imagery or sensitive intelligence.
The UK’s Ministry of Defence disconnected the cameras from the internet, and emphasized that no classified systems were breached. Still, the discovery has heightened ongoing security concerns about Chinese-made components embedded in Western military hardware.
US and South Korea warn of “Gunra” ransomware gang with North Korean ties.
US and South Korean cybersecurity agencies have issued a joint alert regarding “Gunra,” an expanding ransomware-as-a-service group targeting critical infrastructure sectors globally. Built on leaked Conti ransomware code, Gunra has been recruiting ethical hackers and penetration testers to serve as initial access brokers in exchange for a cut of the ransom profits.
Notably, researchers have found overlaps between Gunra's operations and those of North Korean state-sponsored hackers, suggesting collaboration or shared infrastructure between the cybercriminal gang and nation-state actors.
OpenAI mandates strict security controls for its new cybersecurity model.
OpenAI has paused internal development of projects that lack sufficient security controls after determining that its upcoming AI model, "Astra," demonstrates a significant jump in cybersecurity capabilities. Astra has met OpenAI's 'critical' risk threshold—surpassing the 'high' rating of previous models like GPT-5.6-Sol—because it can autonomously develop zero-day exploits against real-world systems and execute end-to-end cyberattacks based solely on high-level objectives.
The company has mandated isolated testing environments, enhanced model weight protections, and strict network restrictions for all projects involving Astra.
Record-breaking DDoS attacks surge in H1 2026.
Cloudflare’s DDoS Threat Report for the first half of 2026 highlights a sixfold increase in attacks exceeding 1 terabit per second, which skyrocketed from one-hundred-thirty incidents in Q1 to more than eight-hundred in Q2. While the vast majority of DDoS attacks remain relatively small and last less than 10 minutes, attackers are increasingly weaponizing DNS-based amplification and flood techniques. The researchers also note that these smaller attacks can still overwhelm most websites.
Data-scraping AI extension returns to the Chrome Web Store.
A popular Chrome extension called “AI Sidebar with DeepSeek, ChatGPT, Claude and more” has returned to the Chrome Web Store and resumed malicious activities. The app was initially banned by Google in January 2026 for secretly scraping users' AI conversations. Although the developers temporarily removed the chat-stealing behavior, likely to get back into the store, a recent update slyly introduced a new monetization scheme. The extension now hijacks update and uninstall events to force-open affiliate links for an AI video-generation platform. Security firm Netskope discovered this deceptive behavior and advises organizations to remove the extension.
Stick with us after the break, Dave Bittner recently sat down at Black Hat with Stephen Harrison, VP of Product at Abnormal AI to discuss "The Identities Your Security Stack Is Ignoring." And no pain, no gain, no authorization.
At Black Hat USA, Dave Bittner sat down with Stephen Harrison, VP of Product at Abnormal AI to discuss "The Identities Your Security Stack Is Ignoring." Here’s their conversation.
That was Dave Bittner and Stephen Harrison discussing "The Identities Your Security Stack Is Ignoring." If you want to learn more, be sure to check out the links in our show notes.
No pain, no gain, no authorization.
A Melbourne man inadvertently hacked his gym’s booking system after asking his AI personal assistant to secure a spot in a popular class. The agent, powered by Anthropic's Claude via OpenClaw software, analyzed the gym's API, discovered it lacked basic authorization checks, and exploited the vulnerability to book classes months before the allowed window. Additionally, when the user asked if he could be moved higher up on the waitlist, the AI canceled the reservation of the person in the number one spot as a test, then bumped the person in the number three spot to make room for its user. The AI was unable to add the members back to the waitlist, and apologized for not being more careful.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
