Top stories.
- Cyberattack on Poland's energy infrastructure compromised around thirty facilities.
- Threat actors continue to exploit months-old WinRAR flaw.
- SoundCloud breach affected nearly 30 million accounts.
Cyberattack on Poland's energy infrastructure compromised around thirty facilities.
A December 29th cyberattack against Poland's power grid breached around thirty sites connected to distributed energy generation, according to researchers at Dragos. The researchers say this is "the first major cyber attack targeting distributed energy resources (DERs), the smaller wind, solar, and [combined heat and power] facilities being added to grids worldwide."
Dragos notes, "While the attack did not result in power outages, adversaries gained access to operational technology systems critical to grid operations and disabled key equipment beyond repair at the site. Due to the lack of electric outages, asset operators and the broader community may be mistaken to think this is not overly concerning. However, what was demonstrated, especially for other countries who currently or will depend more on DERs, should be very alarming."
Dragos blames the attack on the threat group "ELECTRUM," which overlaps with the Russian threat actor Sandworm. ESET also attributed the activity to Sandworm, noting that the GRU-linked threat actor has caused blackouts via cyberattacks in the past.

