ZeroHour

Search: “US water systems”

14 stories

Iran Cyberattacks Against Minnesota Water Systems

Preliminarily attributed to Iran, cyberattacks hit Minnesota water systems as part of a campaign targeting at least seven US states.

A campaign of cyberattacks against water systems in Minnesota and at least six other US states has been preliminarily attributed to Iran, though no real damage has been reported so far. US President Trump publicly disputed the Iranian attribution, blaming Minnesota authorities instead. The incident underscores ongoing nation-state targeting of US water utilities.

Schneier on Security · Aug 15, 2026Threat actor in the wild

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 24d agoThreat actor

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Rapid7 found a new backdoor, ted, compiled into trojanized HAProxy at two South Korean organizations, with medium-confidence attribution to North Korean actors.

Rapid7 documented a previously undocumented Linux toolkit named ted compiled into the HAProxy load balancer binaries of two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, serves altered pages only to filtered visitors, and hides C2 exchanges from backend logs and HAProxy statistics; a companion RAT, curlRAT, beacons on a default 12-hour schedule. The toolkit also trojanizes crond, sshd, agetty, atd, and polkitd binaries and sanitizes logs and bash history. Rapid7 attributes the activity with medium confidence to North Korean state-sponsored actors, with domain infrastructure overlapping APT37 listings in maltrail and delivery resembling the Operation SyncHole campaign.

The Hacker News · 12d agoThreat actor in the wild

xHunt Campaign: New Watering Hole Identified for Credential Harvesting

Unit 42 tied the xHunt campaign to a watering hole on a Kuwait government website used to passively harvest visitors' NTLM credential hashes.

Palo Alto Unit 42 identified a Kuwait government organization's webpage injected with hidden HTML referencing image paths on domains (microsofte-update.com, learn-service.com) tied to xHunt/Hisoka C2 infrastructure. When visitors loaded the page, Windows would attempt SMB/NetBIOS authentication to the remote share, allowing the operators to capture NTLM hashes that could be cracked or relayed. Related DNS redirect activity on xHunt infrastructure in 2019 pointed to additional credential-harvesting interest against Kuwaiti government email servers.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1