Top stories.
- Poland’s CERT describes winter cyberattack against heat-and-power plant.
- US and South Korea warn of "Gunra" ransomware gang with North Korean ties.
- Chinese IP connections spark security review in UK Navy drones.
Poland’s CERT describes winter cyberattack against heat-and-power plant.
Poland’s Computer Emergency Response Team has disclosed that hackers breached a Polish combined heat-and-power plant by exploiting a misconfigured private Access Point Name (APN) network, BleepingComputer reports. The attackers initially compromised a wind farm's firewall, then tunneled into the shared APN to locate an exposed controller at the power plant, secured only by default credentials. They used this access to get into the plant's OT network, temporarily shutting down a steam turbine and water treatment system. Polish authorities quickly restored the systems before there was any impact to the public, but said this marks the first known real-world cyberattack using a private APN for lateral movement into an OT network.
The attack took place on December 29th, 2025, the same day that hackers tied to Russia’s Electrum APT targeted dozens of heat and power facilities across Poland. Though the attacks failed to cause significant disruptions, experts emphasized that the hackers tried to cut off heat from civilian populations in the dead of winter.

