top of page

THE CYBER BRIEF - ISSUE 48

  • Ralph Labarta
  • 15 hours ago
  • 2 min read

T H I S I S S U E - S P O T L I G H T


Iran-Linked Hackers Blamed for Taking Down UK Power Plant


  • Iranian-affiliated hackers shut down a small-scale UK power plant for four days in July 2026, marking the first confirmed instance of Iran-linked hackers disabling such infrastructure in Britain; no group claimed responsibility.

  • Attackers exploited programmable logic controllers (PLCs) using unsophisticated methods - scanning for exposed devices and exploiting default credentials — per CISA; an estimated 12 to 70 million PLCs operate globally, many lacking modern cybersecurity protections.

  • The attack coincided with Iranian-linked operations targeting U.S. water systems across a dozen states; NCSC head Dr. Richard Horne said the UK manages 200+ cyberattacks on critical infrastructure annually, 75% linked to hostile states.

https://www.cbsnews.com/news/iran-linked-hackers-blamed-attack-uk-power-plant-reports/

New Phishing Toolkit Uses Passkeys to Maintain Access After

Password Resets


  • Researchers at Abnormal Security identified iAuthFlow V2, a $10,000 phishing-as-a-service toolkit sold on a Russian-language cybercrime forum, that runs a dual-browser attack: victims interact with an attacker-controlled phishing page while the attacker mirrors the session in a separate connected browser.

  • During credential capture, the toolkit silently registers an attacker-controlled passkey on the victim's account — a credential tied to the account itself rather than derived from the password.

  • Because the passkey persists independently, standard remediation like resetting the password and revoking active sessions fails to remove attacker access.

https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets

T-Mobile 'Chopped a Cable' to Expel Chinese Hackers From Its

Network


  • T-Mobile cybersecurity chief Jeff Simon and three colleagues physically cut a cable at a Bellevue, WAarea data center in 2024 to sever a router compromised by Salt Typhoon, a Chinese governmentbacked hacking group.

  • Salt Typhoon's campaign compromised hundreds of telecom, internet, and data center companies, with documented victims including AT&T, Verizon, Viasat, Charter, and Windstream.

  • Hackers sought customer phone records and intelligence on senior U.S. officials, including presidential candidates; T-Mobile avoided a major breach by detecting the intrusion early and physically disconnecting the compromised equipment.

https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network

Ransomware Disproportionately Targets Medium-Sized

Firms, Straining Customer Relationships


  • Medium-sized businesses ($10M–$1B revenue) accounted for roughly 73% of ransomware incidents between 2023 and mid-2026, per Black Kite's analysis of 13,336 incidents across 120,128 mid-market firms.

  • Manufacturing was the most-targeted sector, representing over 25% of mid-market victims, while nearly 30% of mid-market organizations had at least one known exploited vulnerability.

  • 72% of mid-market attacks hit North American companies, and Black Kite found vendor-risk teams of two or fewer people often responsible for portfolios exceeding 300 suppliers, leaving continuous oversight impossible.


https://www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257

This newsletter is intended for informational purposes only. The content reflects publicly available information and general industry trends as of the date of publication and may not reflect the most current regulatory developments. Newsletter may contain links to vendor supported content which does not represent endorsement or promotion of products or services. Nothing herein constitutes legal, compliance, or professional advice, and should not be relied upon as such.


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.

© 2026 Techmar, LLC

bottom of page