APTIranian Attack Shuts Down British Power Plant for Four Days
Iranian hackers linked to IRGC shut down a small British power plant for four days, highlighting vulnerabilities in UK critical infrastructure security.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
APTIranian hackers linked to IRGC shut down a small British power plant for four days, highlighting vulnerabilities in UK critical infrastructure security.
MalwareDiscover how Manic Android malware uses accessibility services and a store-and-forward mechanism to steal data offline via device-to-device mesh networks.
MalwareE4del and PINHOLE RATs use FTP banners as hidden channels to distribute Windows malware. Campaign active since July 2026, using phishing and dead-drop resolvers.
MalwareOn August 22, 2026, Zimperium zLabs detailed ToxicPanda 2.0, a new version of the Android malware that dramatically expands its financial targets. The
MalwareThree new banking trojans—Manic, Grandoreiro, and ToxicPanda 2.0—threaten Android and Windows users with sophisticated fraud techniques.
MalwareMalware exploits Android car head unit updates for ad fraud and proxy botnets, turning vehicles into compromised network nodes.
MalwareMalicious npm calendar packages hide RedShell Linux beacon for RedC2 4.0, enabling remote command execution and posing supply-chain risks to developers and infrastructure.
MalwareSynkLoader: Microsoft Teams malware that steals credentials and enables remote control. Poses as IT tools. Learn how to defend against it.
APTExplore three Russia-linked cyber-espionage clusters using OAuth, WhatsApp, and malware against Western researchers, officials, and analysts in phishing campaigns.
MalwareThree compromised Rust crates infected software builds with malware during compilation, bypassing security measures and affecting dependencies.
RansomwareDiscover how Ransom Busters, a fake recovery service, contacts ransomware victims before public disclosure to divert payments and steal data.
APTU.S. agencies report an active threat using AI-generated scripts to target Siemens S7 PLCs via internet scanning, risking industrial facilities. Recommendations included.