Daily brief at 7am Melbourne. Unsubscribe any time.

Tuesday 25 August 2026

Lights Out in Britain: Iran-Linked Hackers Knocked a Power Plant Offline for Four Days

Iran-linked hackers shut down a UK power plant for four days — and the US just sanctioned the crew responsible while a bipartisan Senate bill races to quantum-proof the energy grid.

Lead story

Lights Out in Britain: Iran-Linked Hackers Knocked a Power Plant Offline for Four Days

An Iran-linked threat actor managed to shut down a UK power plant for four consecutive days in what security researchers are calling one of the most consequential cyberattacks on European energy infrastructure in years. The plant was knocked offline entirely — not degraded, not partially disrupted — and the outage lasted long enough to raise serious questions about the resilience of Britain's distributed energy network.

The UK government moved quickly to contain the narrative, telling The Register there was "no risk to the wider energy system." That's technically reassuring but strategically uncomfortable: a single plant going dark for four days is a proof-of-concept, not a one-off accident. Attackers now have confirmation that this kind of disruption is achievable.

The timing is pointed. Across the Atlantic, the US Treasury simultaneously announced sanctions against alleged Iranian hackers as part of what officials labelled "economic D-Day" — a coordinated pressure campaign targeting individuals affiliated with Iran's Mabna Institute, a group with a long history of IP theft and infrastructure probing. The sanctions follow a Justice Department indictment unsealed last week, suggesting a deliberate sequencing: indict, then sanction, then watch what Iran does next.

Why this matters beyond Britain

Nation-state attacks on energy infrastructure are nothing new, but this incident has a few characteristics worth watching. First, it involved a distributed energy asset — not a massive centralised grid hub but a smaller plant typical of the kind proliferating across Europe and Australia as grids decarbonise. Smaller, more distributed assets often mean smaller security budgets and less mature operational technology (OT) defences.

Second, the attack caused real operational disruption, not just a data breach or a ransom demand. That puts it in a different category to most incidents — closer to the 2015 Ukraine power grid attack in terms of intent and effect.

Third, it landed the same week a bipartisan US Senate bill — the Quantum Guard Act — called for the Federal Energy Regulatory Commission (FERC) to factor quantum computing threats into its reliability standards. The juxtaposition isn't lost on anyone: nation-states are already disrupting power grids with today's tools, and legislators are already trying to future-proof against tomorrow's.

The Australian angle

Australia's energy grid is undergoing a similar distributed transition, with the AEMO managing an increasingly fragmented mix of renewables, storage, and legacy assets. The SOCI Act (Security of Critical Infrastructure Act) applies directly to electricity assets, and the Australian Signals Directorate has been vocal about OT security gaps in the sector. An incident of this scale in Britain will almost certainly prompt fresh conversations between ACSC and Australian energy operators about OT network segmentation and incident response readiness.

What to watch

Iran's response to the US sanctions is the immediate unknown — escalatory moves against US or allied infrastructure are a well-worn playbook. The UK's National Cyber Security Centre hasn't yet attributed the attack publicly, so the full technical picture remains murky. But the operational reality is already clear: distributed energy assets are attractive targets, and four days of downtime proves the concept works.

Also today

US Treasury Sanctions Iranian Hackers in Coordinated 'Economic D-Day' Push

The US Treasury has sanctioned a group of alleged Iranian hackers linked to the Mabna Institute, following a Justice Department indictment unsealed last week. Officials described the action as part of a coordinated 'economic D-Day' campaign designed to apply maximum pressure on Iran's cyber apparatus. The Mabna Institute has previously been associated with large-scale intellectual property theft targeting universities and technology companies. The sanctions freeze any US-held assets and prohibit Americans from doing business with the named individuals. The move runs in parallel with the UK power plant attack attributed to Iran-linked actors, suggesting a broader escalation in the Iran cyber-threat landscape this week.

CyberScoop

Bipartisan Senate Bill Wants to Quantum-Proof the US Energy Grid

A bipartisan US Senate bill dubbed the Quantum Guard Act would require the Federal Energy Regulatory Commission to incorporate quantum computing threats and post-quantum cryptography standards into its reliability frameworks for the energy sector. The bill arrives as cryptographically relevant quantum computers inch closer to viability and nation-state adversaries are suspected of harvesting encrypted communications now to decrypt later. The energy grid is considered particularly exposed given the long operational lifespans of industrial control systems, many of which can't be quickly patched or replaced. Australia's energy sector faces a comparable challenge — AEMO and critical infrastructure operators will eventually need to migrate OT communications to post-quantum standards under ASD guidance.

CyberScoop

Critical Keycloak Flaw Lets Unauthenticated Attackers Hijack Any Account

Red Hat and the Keycloak open-source identity project have patched a critical vulnerability — CVE-2026-18963, CVSS 9.1 — that could allow a completely unauthenticated remote attacker to force a password reset and take over any user account on an affected server. Keycloak is widely used as a single sign-on and identity broker in enterprise and government environments, meaning a successful exploit could cascade across every application sitting behind it. Red Hat has released patches and organisations running Keycloak should treat this as an emergency update. Given Keycloak's prevalence in Australian government and enterprise deployments, the ASD's patch priority guidance is likely to flag this quickly.

The Hacker News

ShinyHunters Breaches ReliaQuest via Phishing — Firm Says Damage Was Contained

Managed detection and response firm ReliaQuest has confirmed that the ShinyHunters threat group successfully phished one of its employees and gained access to an internal dashboard. The company is insisting the impact was limited and that no customer environments were compromised, but the optics are uncomfortable for a security vendor whose entire pitch is that they catch exactly this kind of thing. ShinyHunters has a long track record of high-profile breaches — including Ticketmaster and Snowflake customers — and frequently monetises stolen access on criminal forums. Details on exactly which dashboard was accessed and what data it contained remain sparse.

SecurityWeek

Anthropic Opens Mythos 5 to Defenders and Drops $35M Into Open Source Security

Anthropic has expanded access to its Mythos 5 model for cybersecurity defenders, integrating it into its Claude Security codebase-scanning product currently in public beta for Claude Enterprise customers. Simultaneously, the company announced a $35 million open source security fund aimed at shoring up the software supply chain — the same supply chain that AI coding tools are now accelerating faster than security teams can audit. The dual announcement positions Anthropic as both a security vendor and a responsible AI developer, a lane it's been trying to occupy since OpenAI's agent safety incidents earlier this month. Australian enterprises using Claude Enterprise will have access to the Mythos 5 scanning capability.

SecurityWeek

Hugging Face Fielding $13 Billion Acquisition Offers — But Will Its Community Let It Sell?

Hugging Face, the open-source AI platform that hosts more than half a million models and datasets, is reportedly in talks that would value the company at around $13 billion. The catch: Hugging Face has built its identity around being the neutral, community-owned alternative to big-tech AI labs, and its founders are said to have deep reservations about selling that identity along with the company. A sale to any of the obvious suitors — Google, Microsoft, Amazon — would be read by the open-source AI community as a defection. The company was also at the centre of a significant security breach earlier this month, which may complicate due diligence conversations.

TechCrunch

AliExpress Caught Using Inaudible Audio Tones to Fingerprint Shoppers' Browsers

Security researchers have caught AliExpress deploying a covert browser fingerprinting technique that sends inaudible ultrasonic audio tones to visitors' devices, using the way each browser and audio stack processes those tones to build a unique fingerprint — without cookies, without consent, and without users having any obvious way to detect it. As a side effect, at least one developer noticed the technique was muting their Bluetooth headphones. Firefox and Brave have both confirmed they are implementing mitigations. The technique is old in concept but its deployment by a major e-commerce platform at scale is new. Australian users of AliExpress are affected, and the conduct may warrant scrutiny under the Privacy Act's APP 3 and 11 obligations.

Ars Technica

TikTok Pays $400M to Settle US Children's Privacy Case

TikTok has agreed to pay $400 million to settle a US Justice Department case over children's privacy violations — $300 million upfront and another $100 million once an earlier consent decree against its predecessor app Musical.ly is vacated. The settlement covers allegations that TikTok collected data from children under 13 without verifiable parental consent. It's one of the largest children's privacy penalties in US history and lands the same week New Zealand announced it would pursue a social media ban for under-16s. Australia's Online Safety Act and the ongoing eSafety Commissioner review of age assurance obligations make this directly relevant to how platforms operating here may face similar consequences.

SecurityWeek

New Zealand Moves to Ban Social Media for Under-16s

New Zealand's government has introduced legislation that would require high-risk social media platforms — Instagram, TikTok, Snapchat, and Facebook are named explicitly — to take 'reasonable steps' to verify users are at least 16 years old. Proposed verification tools include facial age estimation, digital ID services, and formal identification checks. The bill puts New Zealand on a similar trajectory to Australia, which passed its own under-16 social media legislation last year and is still working through the technical standards for age assurance. How New Zealand's implementation compares to Australia's will be closely watched by both regulators and platforms navigating compliance across the Tasman.

The Record

Security Pros Are Quietly Backing $4 Paper Password Books — and They Have a Point

A growing number of senior security practitioners are publicly endorsing cheap paper password notebooks sold in Australian newsagencies and discount stores for around $4, arguing that for low-tech users — particularly elderly relatives — a physical book stored at home beats a forgotten master password or a recycled PIN any day. The argument isn't that paper is more secure in absolute terms; it's that security has to account for the actual human using it. The trend has sparked a lively debate about whether the industry has overcorrected toward complexity at the expense of usability, and whether 'good enough' security that gets used beats 'perfect' security that doesn't.

The Register

Nvidia Senior Manager Indicted Over AI Server Smuggling Scheme to China

A senior Nvidia manager has been indicted on charges related to a scheme that allegedly used Supermicro as an intermediary to smuggle high-end AI servers to China in violation of US export controls. The indictment follows Jensen Huang publicly rebuking Supermicro over the arrangement. The case is significant because it suggests export control circumvention may be happening from inside the companies making the chips, not just through third-party grey-market brokers. It also adds a new dimension to the ongoing US-China AI hardware dispute at a moment when Washington is tightening export licensing rules and Beijing is accelerating domestic chip development.

Ars Technica

Sources consulted