Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Cybercriminals successfully breached a Polish combined heat and power plant serving 50,000 residents by exploiting the private cellular network used for remote equipment management. The attackers shut down critical systems including a steam turbine and water treatment processes, though recovery efforts began while intruders remained active and no service disruption occurred for customers.
AIMultistate Water System Attacks Widen, Iran Suspected
Cyberattacks against water infrastructure have expanded across multiple U.S. states, with Iran suspected as the threat actor. The attacks exploit poorly secured programmable logic controllers (PLCs) that are directly exposed to the Internet, highlighting critical vulnerabilities in operational technology security across water utilities.
AIOver 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout's research revealed 4,407 internet-exposed Rockwell Automation PLCs globally, with 2,844 in the United States. Notably, 22 of these exposed controllers were located in cities recently targeted by cyberattacks on water utilities, with 19 sharing the same mobile carrier network, raising significant concerns about critical infrastructure security.
AIExposed Fuel Tank Gauges Under Attack in the US
Cybersecurity researchers have identified a growing threat where attackers are exploiting Internet-connected fuel tank monitoring systems at gas stations across the United States. These exposed tank gauges, which lack proper security controls, provide threat actors with unauthorized access to critical infrastructure systems, potentially enabling operational disruption at fuel distribution points.
