• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents - International 2026-27

Commonground

Senior Moderator
UAE
UAE thwarts cyber-attacks on aviation, energy and education sectors

Emirati authorities described the attacks as “advanced, coordinated” but did not give any clues on who might have been behind them.
Monday 10/08/2026​
Excerpt:

The CSC explained that “the attacks involved multiple vectors and techniques, including attempts to breach systems and digital infrastructure, target accounts and operational data, as well as targeted ‘phishing’ campaigns and attempts to exploit users as an entry point into the targeted environments”.​

Continued: https://thearabweekly.com/uae-thwarts-cyber-attacks-aviation-energy-and-education-sectors
 
OpenAI tightens controls on its new model over cybersecurity risks, as AI security debate intensifies
AUG 10 2026​

KEY POINTS
  • OpenAI paused some “internal activities” on its new Astra model, saying it was concerned the model could be capable of launching cyberattacks autonomously.
  • The company said it cannot yet rule out that the model had reached its “Critical” cybersecurity threshold.
  • Other AI evaluation incidents and new U.S. and EU oversight efforts are increasing scrutiny of frontier-model security.
​-snip-
On Friday, OpenAI revealed concerns about its unreleased model Astra, saying it could not rule out it had reached “Critical” capability, meaning it could launch cyberattacks against sophisticated cyber defenses autonomously, without prompts specifying how to do it.​

... https://www.cnbc.com/2026/08/10/openai-astra-cybersecurity-risks.html
 
World Economic Forum

AI organizations reveal agents hacked other companies, and other cybersecurity news
Published Aug 10, 2026 · Updated Aug 10, 2026​

Excerpt:

1. Leading AI organizations reveal agents went rogue during testing

Industry-leading AI organizations have revealed that their models escaped sandbox testing environments and hacked other businesses.

Anthropic and OpenAI have both reported that agents accessed other companies during cybersecurity tests.

OpenAI said advanced models had spent “a substantial amount of inference compute finding a way to obtain open internet access” in order to solve an evaluation problem set by testers.​

... https://www.weforum.org/stories/cyb...other-companies-and-other-cybersecurity-news/

 
CERT Polska
Follow-Up Report of the December 2025 Energy Sector Incident
08 August 2026


This was a first cyberattack against Poland's energy sector in which the objective was purely destructive. It also proved to be considerably more complex than initially believed, involving an additional event that had not previously been disclosed publicly and that likewise took place in December 2025. The analysis of what occurred at the second CHP plant targeted during that campaign is presented in the report published today. The investigation, which lasted more than three months, led to the discovery of a previously unobserved attack vector involving a private APN. During DEF CON in Las Vegas, the world's largest cybersecurity conference currently taking place, Marcin Dudek, Head of CERT Polska, is presenting the details of the incident.

On 29 December 2025, coordinated attacks targeted Poland's energy infrastructure, including 30 wind and solar power installations and a large combined heat and power (CHP) plant. We described these attacks in detail in our initial report. However, another incident took place in parallel: an attack on a smaller CHP plant supplying heat to 50,000 residents.

As a result of the attack described in this report, a steam turbine and the water treatment system used to produce process water were shut down, interrupting the cogeneration process, in which electricity and heat are generated simultaneously. Thanks to the prompt response of the CHP plant's operators, the incident resulted only in a short-term outage and did not disrupt heat supplies to consumers. It did, however, leave one key question unanswered: how had the attackers managed to achieve this?

Based on the analysis of the collected evidence, we identified the device from which the attacker conducted their operations and reconstructed the attack path. To the best of our knowledge, the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack. The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another. Surveys conducted among organizations using similar solutions indicated that this configuration was commonly encountered in Poland. To the best of our knowledge, it is also widely used in other countries around the world. For this reason, the report concludes with CERT Polska's recommendations for organizations using private APN-based solutions. We encourage readers to read the follow-up report.

https://cert.pl/en/posts/2026/08/incident-follow-up-report-energy-sector-2025/
 
#StopRansomware: Gunra Ransomware

Publication: August 10, 2026

U.S. Federal Bureau of Investigation
U.S. Cybersecurity and Infrastructure Security Agency
U.S. Department of Defense Cyber Crime Center
U.S. National Security Agency
U.S. Secret Service

Republic of Korea’s National Police Agency

To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact the FBI’s Internet

Crime Complaint Center (IC3), your local FBI field office, your local USSS field office, and/or CISA’s 24/7 Operations Center at

contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). When available, please include the following information regarding

the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the

activity; the name of the submitting company or organization; and a designated point of contact. For NSA-client cybersecurity

guidance inquiries, contact CybersecurityReports@nsa.gov.

This document is distributed as TLP:CLEAR. Disclosure is not limited. Sources may use TLP:CLEAR when information carries

minimal or no forseeable risk of misuse, in accordance with applicable rules and procedures for public release. Subject to

standard copyright rules, TLP:CLEAR information may be distributed without restriction. For more information on the Traffic Light

Protocol, see Traffic Light Protocol (TLP) Definitions and Usage.

Executive Summary

Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government,

critical infrastructure, and other organizations. The Gunra ransomware variant first

appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a

double-extortion model, both encrypting data and threatening to publish exfiltrated

data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides

technical details of the activity, as well as tailored detection and mitigation guidance

to protect at-risk organizations from Gunra.

Key Actions

 Prioritize patching known exploited vulnerabilities in internet-facing systems,

including virtual private network (VPN) gateways and remote desktop protocol

(RDP)-exposed infrastructure.

 Implement and test offline, immutable backups stored in a physically separate,

segmented location to ensure recoverability without ransom payment.

 Segment networks to restrict lateral movement from an initially compromised

device to other systems in the organization.

Indicators of Compromise

For a downloadable copy of indicators of compromise, see:

 AA26-222A STIX XML (55KB)

 AA26-222A STIX JSON (62 KB)

Intended Audience Organizations: Government, Critical Infrastructure

Sectors: Healthcare and public health, financial services and insurance, critical

manufacturing and construction, transportation systems and logistics, government

services and facilities, utilities, academia, media and communications, retail, and

professional and nonprofit services.

Roles: Cybersecurity architects, defensive cybersecurity analysts, vulnerability

analysts, systems administrators, and security systems managers.

https://media.defense.gov/2026/Aug/...tical infrastructure, and other organizations.


 
Translation, emphasis is mine
Taiwan

Overseas hackers have launched AI agent-based attacks against government agencies; the Ministry of Digital Affairs has activated a joint emergency response mechanism to strengthen cybersecurity defenses
115年8月13日​

The Ministry of Digital Affairs (MODA) stated that cybersecurity monitoring units detected anomalous attacks targeting government agencies as early as July. The National Institute of Cyber ​​Security began issuing alerts on July 20, while investigations and emergency response measures were immediately initiated. Investigations into the sources, methods, and scope of the attacks have been completed, and the affected agencies have addressed the issues.

Investigation results indicate that this wave of attacks exhibited clear characteristics of foreign origin and involved a hybrid approach combining manual hacking with AI agent-assisted attacks (such as "Open Claw"). AI agents enable the rapid chaining of multiple attack techniques and utilize secondary systems—such as backup or testing environments—as launchpads, resulting in attacks that are fast, low-cost, and large-scale.

To address emerging AI-driven cybersecurity threats, the government has established protection guidelines and strengthened system monitoring across agencies, as well as inter-agency intelligence sharing and joint defense. Through multi-layered protection and rapid response, the government aims to block attacks early and minimize potential damage.

MODA stated that, in addition to concluding the investigation and remediation of this incident, it will continue to bolster the government's overall defense capabilities based on the attack characteristics identified and maintain vigilance against other potential attack vectors.​

https://moda.gov.tw/ACS/press/news/press/20394
 
France
Update: 16.08.2026​

French Prime Minister calls emergency meeting in wake of cyberattack crisis

In June, French tax authorities discovered that someone had gained access to the system and immediately cut off that access. At the time, however, it was not clear that the attacker had already stolen data. The perpetrator had repeatedly extracted small quantities of data, allowing the activity to go unnoticed by security services.

It was only after responsibility for the attack was claimed and the stolen data offered for sale on a dark web platform that the authorities reported the incident to France’s national data protection authority.​

continued: https://today.rtl.lu/news/world/fre...eting-in-wake-of-cyberattack-crisis-187110530
 
France
18 August 2026​

French tax authority announces new cyberattacks targeting cadastral records, unclaimed estates
Cadastral breach alone reportedly estimated to affect nearly 2M accounts


France's Directorate General of Public Finances (DGFiP) confirmed Tuesday that a cyberattack affecting millions of pieces of data related to cadastral information and unclaimed estates occurred a few weeks ago, broadcaster BFMTV reported.

DGFiP confirmed the cybersecurity incidents involving two new types of data that took place but are only now contained.

The first concerned cadastral records, targeting a set of administrative documents and maps that list, describe and identify all real estate properties within a municipality. The second involved unclaimed estates, meaning an inheritance that has not been claimed or accepted by the heirs following a person’s death.

Continued: https://www.aa.com.tr/en/europe/fre...g-cadastral-records-unclaimed-estates/4030891


 
Germany

Cyberattack hits Berlin state ministries
17 August 2026•Update: 17 August 2026​

Several Berlin state ministries have been cut off from the government’s IT network following a security breach, the premier’s office said Monday, as investigators work to contain the incident and determine its scope.

“Investigations have revealed a security breach in the Berlin state network. All relevant agencies are working around the clock to secure the state network,” the office said in a statement.

Authorities disconnected several ministries, including those responsible for climate action and building and housing, from the network on Friday as a precaution.​
-snip-

The affected system, known as BeLa, is a secure high-speed fiber-optic network connecting roughly 600 government and public sites across the city-state. It is operated by ITDZ Berlin.

continued: https://www.aa.com.tr/en/europe/cyberattack-hits-berlin-state-ministries/4029772
 
Europe
Lativa

18 August 2026
Latvia says data of 1.2 million people stolen in cyberattack

​Excerpt:

...
The attack reportedly secured information last week such as first and last names, payment details, vehicle licence plates and the address registered on the day the service was provided.
-snip-

..."I have to say that I am unpleasantly surprised by a certain IT-security infantilism that exists in some regulatory authorities and government institutions," the prime minister said. He referred to a previous hacker attack on the state forestry administration in June.

Two "serious cyber incidents" occurring within a short period were a clear signal that additional security measures were needed, he said. "This is now quite literally a matter of national security," Kulbergs said.

https://www.yahoo.com/news/world/articles/latvia-says-data-1-2-144834453.html
 
India
CG Power flags suspected cyber incident; operations unaffected
August 18, 2026

CG Power and Industrial Solutions disclosed a suspected cyber event affecting IT systems but not core operations, working with cybersecurity experts and notifying CERT-In as per regulations.

Continued:

https://www.financialexpress.com/business/industry-cg-power-flags-suspected-cyber-incident-operations-unaffected-4320564/?utm_term=Autofeed&utm_medium=Echobox&utm_source=F acebook&fbclid=IwY2xjawTxhFdwZG9mAWV4dG4DYWVtAjExA GJyaWQRMTZJVkxncG1jcUVwSzFOQlpzcnRjBmFwcF9pZBAyMjI wMzkxNzg4MjAwODkyAAEeSwNSFiTbFJTwizOAKp_GgCIMxKUFT zU0I_QbY697haSBs0wCbQYpa2BRBVI_aem_HK4dbAApLOffvZI Txd94KQ#Echobox=1787073500



 
Egypt
August 20, 2026

US-bound oil tanker targeted in Cyberattack

On August 7, 2026, the giant tanker “VL PROSPERITY”, with a capacity of 2.3 million barrels of crude oil, which was sailing under the Liberian flag from Egypt’s Sidi Kerir port toward one of the ports of the United States, was targeted by a major cyberattack in the Strait of Gibraltar, and all of its communications were cut off for 30 hours.​

According to one of the ship’s crew members, the attackers infiltrated the engine-room systems, reduced the engine’s cooling flow, increased the engine speed, and disabled the ship’s fuel and engine-oil tank. No group has yet claimed responsibility for the incident.​

Continued: https://en.mehrnews.com/news/247123/US-bound-oil-tanker-targeted-in-Cyberattack

 
ugust 20, 2026
AI data giant Alation confirms cyberattack


Days after reporting an incident affecting a number of its customers, enterprise data giant Alation on Thursday confirmed a cyberattack.

Alation makes data software that its enterprise customers use to search for files and data using natural language queries. In recent years, the company has expanded into AI, allowing customers to turn large amounts of messy data into usable content. The company says it services more than 500 global companies, including around half of the Fortune 1000 largest companies in the United States.

When reached by TechCrunch about the incident, the company said it was investigating.

-snip-
This is the latest cybersecurity incident in recent weeks to affect a large-scale technology giant, as hackers increasingly target companies that store large amounts of sensitive or proprietary information for their corporate customers.

Continued: https://techcrunch.com/2026/08/20/ai-data-giant-alation-confirms-cyberattack/


 
August 20, 2026
Anup Kumar, CEO of Optiv Consulting, warns of software concentration risk as Russian cyber gang Clop exploits a PLM flaw to breach Shell, Philips and GE

The Russian-speaking cybercriminal group Clop launched a large-scale exploit, targeting vulnerabilities in enterprise software and breaching nearly 50 organisations.

In doing so, it has added top global companies like Shell, Philips, GE and Fiserv to its list of targets.

The threat actor has allegedly exfiltrated 89GB of data from Shell, 15.5GB from Philips and 391GB from GE, including critical project documents, blueprints and engineering plans.

All of these three companies have confirmed they have opened formal investigations following the claims.

Continued: https://technologymagazine.com/news/behind-the-russian-clop-hack-breaching-shell-philips-and-ge
 
Back
Top