MEDIUMVulnerability
Global

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

·Source: The Hacker News

Updated:

Executive Summary

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat

Analysis

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat
Source Attribution

Originally published by The Hacker News on Aug 11, 2026.

Related Threats

MEDIUMVulnerability

NC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposed

Caroline Yaffa reports: The Wake County Board of Elections is suspending its use of a software vendor after it reported a possible cyberattack. There’s no evidence that voting machines, ballots, voter registration records or systems used to count votes were affected, according to the county board. But the incident could have exposed information about people... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th...

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

CVE-2026-73053
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and...

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

CVE-2026-73052
NIST NVD