ZeroHour

Search: “911”

35 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Local governments in four states dealing with cyberattacks that have shut down services

Ransomware and cyberattacks disrupted local governments in California, Oklahoma, South Dakota, Texas and Wisconsin, taking Suisun City's 911 offline.

Suisun City, California (population 30,000) shut down its IT network after malicious software hit 911 routing, police and fire dispatch; the city declared a state of emergency and the FBI is investigating. Coweta, Oklahoma confirmed a ransomware attack affecting all computers and digital services, with off-site backups slated for restoration. Mitchell (South Dakota), Coryell County (Texas) and Washburn County (Wisconsin) also disclosed cyberattacks that shut down networks and disrupted phone and payment systems.

The Record · Aug 11, 2026Ransomware in the wild

CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

CISA and partners issue a joint advisory pressing organizations toward transparent breach notification and incident response as cyber outages escalate.

Dark Reading reports on a new joint government advisory led by CISA that signals a regulatory shift. The advisory presses organizations to adopt more transparent breach notification protocols and incident response practices. The guidance comes as cyber outages escalate and reflects growing government expectation of disclosure over spin.

Dark Reading · 4d agoPolicy & legal1

HoneyRoute: Honeypot-Model Routing for Adversarial LLM Serving

HoneyRoute detects malicious LLM serving requests and diverts them to a honeypot model, reaching F1 0.911 with 38 ms median added latency.

HoneyRoute is an inference-serving layer pairing a streaming router (a frozen 0.8B embedding backbone with per-domain MLP heads) with a dual-implementation honeypot and an analysis loop that converts trapped interactions into attacker fingerprints for router retraining. On a production trace plus a seven-domain attack corpus it matches 96% of a two-tier guard-LLM cascade's F1 at 1/385th of its latency with 0% evasion under 13 adversarial transformations. Diverting malicious traffic cuts production token consumption under GCG-suffix flooding by 97.8%, and loop training raises detection F1 to 0.933.

arXiv cs.CR · 8d agoAI safety & security

Communicating Under Pressure: Best Practices for Service Providers

CISA, FBI, and international partners issued guidance on crisis communications for service providers during IT and OT outages, emphasizing clarity, transparency, and backup channels.

CISA, the FBI, and international partners published guidance on planning and executing clear, timely, audience-appropriate communications during IT and OT service outages, whether caused by cyber threat actors, human error, or natural hazards. The guidance stresses clarity, accountability, and transparency, and warns that outages at one organization can cascade across interconnected systems. It recommends critical infrastructure owners assume telecommunications may be unreliable and integrate backup communication methods into crisis plans, and points to CISA's CI Fortify initiative for OT isolation and recovery resources.

CISA Advisories · 14d agoAdvisory

CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)

Attackers actively exploit Spring Framework RCE CVE-2022-22965 (SpringShell, CVSS 9.8) to deploy webshells; patches 5.3.18/5.2.20 shipped March 31, 2022.

CVE-2022-22965 enables unauthenticated remote code execution in the widely used Spring Framework (CVSS 9.8), which Unit 42 has observed being exploited in the wild. The flaw stems from getCachedIntrospectionResults exposing the class object during parameter binding, letting attackers manipulate the class loader to modify Tomcat logging and upload a JSP webshell. Public PoCs require JDK 9+, Tomcat, WAR packaging, and spring-webmvc or spring-webflux dependencies on Spring 5.3.0-5.3.17, 5.2.0-5.2.19, or older. Fixes shipped in Spring Framework 5.3.18 and 5.2.20; the related Spring Cloud Function flaw CVE-2022-22963 was patched March 29, 2022.

Palo Alto Unit 42 · Aug 17, 2026Exploit / PoC in the wildCVE-2022-22965CVE-2022-22963CVE-2010-16221

25 Years of Mass Surveillance Is Enough

Bruce Schneier and Cindy Cohn argue post-9/11 mass surveillance expanded far beyond its counterterrorism justification and should be reevaluated for costs to rights.

An essay by Bruce Schneier and Cindy Cohn (originally in Lawfare) traces the post-9/11 shift from targeted surveillance to mass collection of telephone and internet metadata. It cites the Section 215 bulk phone records program, struck down in interpretation by the Second Circuit in 2015 and curtailed by the USA Freedom Act, and the NSA's Upstream program under Section 702 of the 2008 FISA Amendments Act, which ended content searches in 2017. The authors note mass surveillance now serves routine law enforcement and immigration actions, with FBI Director Kash Patel confirming purchases of Americans' data from brokers, and private systems like Flock license plate readers and venue facial recognition feeding government access.

Schneier on Security · 1d agoPolicy & legal

[AINews] Andrew Ng gets into AI Engineering

Andrew Ng relaunches DeepLearning.AI around AI Engineering, defining four core skills from an analysis of 10,000+ job postings and expert interviews.

Andrew Ng, cofounder of Google Brain and Coursera, relaunched DeepLearning.AI with a focus on AI Engineering, basing the curriculum direction on an analysis of over 10,000 job postings plus interviews and surveys. He identifies four key skills: building and deploying AI applications, software engineering fundamentals, effective use of coding agents, and shaping the build with product sense. The Latent Space AI News issue also recaps agent ecosystem developments, including NVIDIA's 'Skill Lift' evaluation proposal showing skill scan scores correlate only weakly (Spearman rho = 0.14) with judged quality, and Konwinski's open-source persistent-agent 'microharness' Headlong, which achieved an unattended self-debugging repair in 48 minutes.

Latent Space · 22d agoAI industry1

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump's Executive Order 14420 declares a national emergency to restrict foreign-made bulk-power grid equipment over cyber, sabotage and supply-chain risks.

Executive Order 14420, signed August 26, declares a national emergency regarding the foreign supply of bulk-power system electric equipment to the United States. It empowers the Energy Secretary to restrict transactions with designated Covered Foreign Entities involving equipment, software, firmware, digital services, maintenance services, and remote-access capabilities. Covered equipment includes transformers, generators, inverters, RTUs, PLCs, intelligent electronic devices, and protective relays, with transmission rated 69 kV or higher in scope while local distribution is excluded. Already-installed foreign equipment may be subject to identification, isolation, monitoring, or replacement requirements, with phased compliance and pre-qualified vendor exemptions permitted.

Security Affairs · 18d agoPolicy & legal

In most cities, nobody owns the whole network

Former Waco CIO argues cellular-connected water controllers sit outside scanned networks, and accountability plus operating-budget funding—not technology—block segmentation.

Writing as Waco, Texas's former CIO, the author describes July water-sector intrusions that CISA linked to over 100 compromised systems, typically controllers on public cellular links absent from asset lists. The FBI and EPA reported incidents at utilities in at least seven states since July 27, and a Clayton County, Georgia pump station failure triggered a boil-water advisory. He argues accountability and funding—using mechanisms like the Texas Water Development Board's new cybersecurity scoring criteria—are the binding constraints, citing Waco's 43-day segmentation of five treatment plants with operating funds.

CyberScoop · 8d agoIndustry in the wild

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

A cyber-attack attributed to Iran shut down a UK power plant, exposing the frailty of critical national infrastructure, security experts warn.

Security experts say an Iranian cyber-attack forced a UK power plant offline, describing the incident as a wake-up call for critical national infrastructure operators. The attack caused physical operational disruption at an energy facility. Technical details about the intrusion path and the affected operator remain limited in initial reporting.

Infosecurity Magazine · 23d agoThreat actor in the wild

Unit 42 Incident Response Archives

Palo Alto Networks Unit 42 markets its paid incident response services backed by threat intelligence and methodology from thousands of investigations.

This is a vendor product page describing Unit 42's incident response offering rather than a news article. It emphasizes containing, remediating and eradicating attacks using threat intelligence and a methodology developed from real-world incident casework. No new incident, vulnerability, or actor activity is reported.

Palo Alto Unit 42 · 8d agoIndustry 6 sources

“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samples

A ransomware group posted stolen data samples after a districtwide network outage disrupted Westfield Public Schools in New Jersey.

Westfield Public Schools in New Jersey experienced a districtwide network outage during the first week of school, disrupting communications and digital instruction while classrooms stayed open. The district initially attributed the disruption to networking hardware failure across all schools and offices. A ransomware group has since posted data samples, indicating extortion activity tied to the incident.

DataBreaches.net · 7d agoRansomware

CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages

CISA and FBI issued guidance urging service providers to deliver timely, transparent communications during major IT and OT outages.

CISA, with the FBI and international partners, released 'Communicating Under Pressure: Best Practices for Service Providers', urging providers to prepare crisis-communication procedures, provide timely status updates during IT/OT outages, and maintain out-of-band communication channels. The guidance warns that disruptions to telecom, cloud, energy, and water services can cascade across critical infrastructure. It aligns with CISA's CI Fortify initiative supporting IT/OT isolation and recovery.

GBHackers · 5d agoAdvisory

US and Canadian Court Records Breached Following Thomson Reuters Incident

Thomson Reuters disclosed a breach of its C-Track court software exposing sensitive case records across Ontario courts and 11 US states.

Thomson Reuters detected unauthorized access to its C-Track case management product on June 30 and disclosed the incident on September 2. Files from three Ontario courts and appellate courts in 11 US states plus the US Virgin Islands were affected, potentially exposing names, Social Security numbers, driver's license numbers, medical information, dates of birth and health insurance data. The company said financial transaction systems were not impacted and found no evidence of misuse; the investigation into exact scope is ongoing.

Infosecurity Magazine · 13d agoData breach 2 sources

CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do

CISA urged water utilities to secure internet-exposed PLCs after July 2026 attacks compromised over 100 US water and wastewater systems, suspected Iran-linked.

CISA's exposure-reduction guidance, published August 21, follows July 2026 attacks in which threat actors remotely accessed PLCs connected directly through cellular modems, changed device IP addresses and passwords, and in some cases disabled alarms and shutdown processes without notifying operators. Iran is the suspected actor, though officials stopped short of formal attribution. CISA recommends routing remote access through centrally managed secure gateways, phishing-resistant MFA, unique credentials, and external scanning of industrial protocols such as Modbus, EtherNet/IP, DNP3, BACnet and OPC UA.

Security Affairs · 20d agoExploit / PoC in the wild

‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit

An expert witness hired by 3M used ChatGPT to write portions of his report in a fatal Houston explosion lawsuit, with prompts discoverable.

An expert witness retained by 3M in litigation over the 2020 Watson Grinding explosion in Houston, which killed three people and destroyed roughly 200 homes, used ChatGPT to draft significant portions of his expert report. Discovery records revealed prompts asking ChatGPT to 'show how 3M is 0% at fault' and to defend 3M's standard of care. The case demonstrates that AI prompts used to produce expert testimony can be discoverable during litigation, with hundreds of millions of dollars in liability at stake in the ongoing lawsuits.

404 Media · 29d agoAI safety & security

AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirement

Cyble argues GCC regulators' 6-72 hour breach-notification deadlines make AI-powered detection essential for Gulf enterprises.

Cyble's blog highlights that the UAE Information Assurance Standard v2 requires incident notification within 6 hours of detection, while Saudi Arabia's SAMA cybersecurity framework and NCA Essential Cybersecurity Controls converge on 72-hour reporting. It argues that compliance clocks start at detection, not response, and that IAS v2 mandates 24/7 monitoring with defined SLAs for Tier 1 critical infrastructure entities. The piece promotes Cyble Vision's AI-powered threat intelligence for continuous exposure monitoring and audit-ready detection logs.

Cyble · 12d agoIndustry

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable details ransomware group Storm-0501's Azure tenant-hijacking tactics and how its cloud detection and response identifies them.

Tenable's blog describes how cybercrime group Storm-0501 conducts cloud-first ransomware campaigns against Azure environments. The group has shifted from endpoint encryption to total hijacking of cloud tenants and systematically neutralizes resource locks, immutability policies, and backups. Tenable outlines its One Cloud Exposure detections, using AI-powered threat stories and precision alerts, to expose these TTPs early.

Tenable Blog · Aug 17, 2026Threat actor in the wild

Threat Bulletin

Palo Alto Networks Unit 42 published a threat bulletin, but no article body was available for detailed analysis.

The feed item contained only the title 'threat bulletin' with no article text. No specific incidents, actors, or vulnerabilities could be extracted from the available content.

Palo Alto Unit 42 · 20d agoAdvisory

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 23d agoThreat actor

AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs

Unit 42 reports AI agents compressed a ransomware intrusion from weeks to under 10 hours, using 50+ MITRE ATT&CK techniques against an enterprise network.

Palo Alto Networks Unit 42 investigated a ransomware incident where AI agents moved through an enterprise network in under 10 hours, work that would have taken human operators roughly two weeks. The attacker entered via a public-facing API endpoint, used automated reconnaissance to map microservices, searched source-code repositories for credentials, and accessed a secrets-management system. They hijacked enterprise code workflows to exfiltrate cloud access keys, attempted Terraform backdoors (blocked by branch protections), and used stolen credentials to access the victim's own AI services as attack infrastructure. Over 50 MITRE ATT&CK techniques were observed; the actor confirmed using frontier AI models and agentic frameworks during negotiations.

CSO Online · 13d agoThreat actor in the wild

ATF declares ‘major incident’ as ransomware gang claims hack

The ATF declared a major cybersecurity incident and notified Congress after a ransomware gang claimed responsibility for hacking the federal agency.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) formally declared a major incident involving its cybersecurity and notified Congress, according to the agency. A ransomware gang has publicly claimed responsibility for the attack. ATF is the latest in a series of US federal agencies in recent years to report a major cyber incident, though the gang's identity and the scope of data affected were not specified in initial reporting.

TechCrunch · Security · 19d agoRansomware

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Unit 42 investigated a ransom attack in which frontier AI agents autonomously breached an enterprise network, compressing weeks of tradecraft into under 10 hours.

Unit 42 incident responders documented an intrusion where a single human operator directed frontier AI agents to breach an enterprise network autonomously as part of a ransom attack. The agents executed more than 50 MITRE ATT&CK techniques in under 10 hours, work that would normally require roughly two weeks of human red-team effort. They breached a public-facing web service, mapped internal microservices, scraped hard-coded secrets from code repositories, harvested root credentials from the secrets manager, and hijacked CI/CD builds to exfiltrate cloud access keys. The attacker also used stolen cloud keys to repurpose the victim's AI endpoints as post-compromise infrastructure and left behind an 80-page AI-generated security audit documenting dozens of exploited findings.

Palo Alto Unit 42 · 14d agoThreat actor in the wild

Cybersecurity attention fades within months after a breach

ManageEngine survey of 700 breached organizations finds security attention fades within one to six months, while 91% still trust their posture.

A ManageEngine survey of 700 IT and security leaders in the US and Canada, all of whom had experienced a breach, found that 91% trust their current security posture and only 8% make security a permanent priority after an incident. 80% said post-breach focus lasts just one to six months, and nearly half made no wider changes after their incident. About two in three organizations using AI in security said they act on AI recommendations without additional verification. The report also flagged unclear ownership across security, IT, and business teams as a cause of delayed remediation.

Help Net Security · 2d agoIndustry

Unit 42 - Latest Cyber Security Research

Unit 42 briefing warns frontier AI models compress exploit development timelines and highlights 2026 incident response report findings on AI-accelerated attacks.

Palo Alto Networks Unit 42 published a threat briefing and Global Incident Response Report arguing that frontier AI models enable threat actors to move from initial access to exfiltration in minutes rather than months. The report found attacks are 4x faster, 65% of initial access is driven by identity-based techniques, and 87% of attacks unfold across multiple surfaces. The briefing offers CISO guidance on prioritizing defenses against AI-accelerated, automated attacks.

Palo Alto Unit 42 · 28d agoAI safety & security

Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain

Dark Reading reports AI-driven 'swarm' attacks like the PaperCut incident now span recon, lateral movement and exfiltration, forcing a rethink of the cyber kill chain.

Dark Reading examines how attackers are incorporating AI across the full kill chain, from building lab environments to stage and test agentic attacks through reconnaissance, lateral movement, and exfiltration. It cites a swarm-style AI attack on PaperCut systems as evidence that AI-enabled attackers are changing established defense and detection models.

Dark Reading · 5d agoThreat actor

Kids’ online safety bill faces dim prospects of passage this session despite progress

Kids Online Safety Act clears Senate committee but passage looks unlikely this session amid House-Senate deadlock over the duty-of-care provision.

KOSA advanced out of the Senate Commerce Committee, but the chambers remain split on a duty-of-care provision requiring platforms to act with reasonable caution to prevent foreseeable harm, which House leadership opposes over First Amendment and negligence-lawsuit concerns. The Senate passed KOSA 91-3 last Congress before it died in the House, and the House passed its own version without the duty of care in June as part of a larger package, after stripping a state-law preemption provision. Observers say even Senate passage this year is a struggle given the short calendar, with a lame-duck window between November and January the more plausible path, and Majority Leader John Thune controlling whether a roll-call vote happens.

The Record · 23d agoPolicy & legal

Threat Assessment: Ryuk Ransomware

Unit 42 assesses Ryuk ransomware amid a CISA/FBI/HHS alert on threats to U.S. healthcare, including the UHS attack that disrupted hospital operations.

A joint CISA, FBI, and HHS alert on October 28, 2020 warned of an imminent threat to U.S. healthcare from operators deploying Trickbot and Ryuk ransomware. Universal Health Services reported a Ryuk attack that disrupted all U.S. UHS sites for weeks, with similar incidents at hospitals in Oregon and New York. Ryuk typically arrives after Trickbot or BazaLoader infections delivered via malicious email, and operators enumerate networks with PowerShell and WMI before encryption. The Trickbot Anchor_DNS module performs DNS tunneling for C2, using connectivity checks to benign domains like ipinfo.io and checkip.amazonaws.com.

Palo Alto Unit 42 · Aug 17, 2026Ransomware in the wild

Boston Scientific Reveals Global Disruption After Cyber Incident

MedTech giant Boston Scientific disclosed a cyber incident causing IT outages and disruption across its global operations.

Boston Scientific revealed that a cyber incident triggered IT outages disrupting its worldwide operations. The medical device manufacturer has not yet confirmed whether data was accessed or whether ransomware is involved. Details on scope and impact remain limited as the investigation continues.

Infosecurity Magazine · 20d agoData breach

PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers

Guardicore Labs uncovers the PLEASE_READ_ME ransomware campaign targeting MySQL servers, using double extortion and publishing stolen victim data.

Guardicore Labs at Akamai uncovered an opportunistic ransomware campaign dubbed PLEASE_READ_ME that targets MySQL servers. The attackers employ double extortion, publishing stolen data to pressure victims into paying. The campaign is devastating internet-facing MySQL deployments, making exposed database servers the primary at-risk population.

Akamai Blog · 8d agoRansomware in the wild

Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations

Boston Scientific says a cyberattack has caused global disruption to its operations, with no confirmation yet on device impact or data exfiltration.

Boston Scientific, a major medical device manufacturer, disclosed that a cyberattack is causing global disruption to its operations. The company has not confirmed whether medical devices are affected or whether any customer data was exfiltrated. The investigation appears to be ongoing, and healthcare-sector exposure raises patient-safety and supply-chain concerns.

TechCrunch · Security · 20d agoData breach

TCRF taken offline by DDoS attack after Claude user ban

The Cutting Room Floor game wiki was taken offline by a DDoS attack after a user leveraging Claude was banned.

The Cutting Room Floor (TCRF), a wiki documenting unused video game content, was knocked offline by a distributed denial-of-service attack. The attack reportedly followed moderation action banning a user who was using Anthropic's Claude. The incident highlights friction between community sites and AI-assisted users and tools.

Lobsters · security · 18d agoAI safety & security in the wild

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The ATF is responding to a major cybersecurity incident claimed by a ransomware gang, with the US Justice Department investigating the breach.

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) acknowledged a 'major' cybersecurity incident after a ransomware gang claimed responsibility for an attack. The US Justice Department is investigating the breach. Available reporting provides limited technical detail, and the scope of data theft and operational impact remains unclear.

The Register · Security · 20d agoRansomware

A battery storage cyberattack would look exactly like a badly tuned controller

Risk modeling suggests a few hundred compromised grid-scale batteries dispatched through cloud optimizers could trigger blackouts in Texas or Great Britain.

Centrii analysis estimates 1,500 compromised one-megawatt units (5.4% of ERCOT's ~28 GW fleet) or 400 units (about 29% of Great Britain's ~1,400-unit fleet) could destabilize the grids, with modeled damage of $12-65 billion in Texas and a national blackout costing £2-10 billion in Britain. The study puts the probability of a major attack affecting at least one million people by 2031 at 92.1%, dropping to 61.4% with IEC 62443 certification and quarterly drills, based on 10,000 Monte Carlo runs. Because hostile battery swings are phased like legitimate frequency response, control rooms would see nothing unusual; Centrii proposes hunting for a reverse-governor signature where inverter output feeds oscillations. Spain's April 2025 blackout took an expert panel until March 2026 to rule out cyberattack, partly because key plants had no recordings.

Help Net Security · 14d agoResearch

EU Cyber Resilience Act to Enforce New Reporting Requirements

EU Cyber Resilience Act reporting obligations begin Friday, requiring businesses to notify serious product security incidents within 24 hours.

The EU Cyber Resilience Act's new reporting requirements take effect starting Friday. Businesses operating in the EU will have 24 hours to notify the government whenever they discover serious product security incidents.

Dark Reading · 6d agoPolicy & legal