Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
2026-08-11T07:24:00Z•0c33c687d27a91b3de1fc456d2ffbe565ffba23bfe4a11cb489a5f4d743ee7ce
CVE-2026-64638CVE-2026-8037China-linked threat actorKimsukyMetabaseN-able N-centralProgress Kemp LoadMasterRATStormEncryptorWordPressactive exploitationadversary-in-the-middlecredential theftcritical infrastructureindustrial control systemsinfostealermalicious VS Code extensionsmalicious npm packagesphishingpower plantprivate cellular networkransomwaresupply-chain attackvishingzero-day
What happened
The document is a cybersecurity news feed covering active exploitation, zero-days, supply-chain compromises, malware campaigns, phishing, identity attacks, and critical infrastructure intrusions. The most severe items include an exploited unauthenticated Metabase flaw enabling administrative access, active exploitation of CVE-2026-8037 in Progress Kemp LoadMaster, a WordPress pre-authentication XSS leading to potential PHP code execution (CVE-2026-64638), attacks against N-able N-central, and a Polish power plant disruption via a private cellular network. It also describes malicious npm and VS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0c33c687d27a91b3de1fc456d2ffbe565ffba23bfe4a11cb489a5f4d743ee7ce
- Enrichment time
- 2026-08-11T07:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.