Tag

Cyberattack

All articles tagged with #cyberattack

Autonomous AI Agents Threaten to Scale Global Cyberattacks
technology13 days ago

Autonomous AI Agents Threaten to Scale Global Cyberattacks

Autonomous AI agents capable of thinking, acting, and adapting without human intervention are being described as a hacker’s dream, potentially enabling scalable, relentless cyberattacks on corporate and government systems. Fortune highlights Anthropic’s Mythos as far ahead in cyber capabilities, signaling a new wave of AI-driven exploitation, while ‘shadow AI’ risks grow as employees run agents remotely. A Dark Reading poll shows nearly half of cybersecurity professionals view agentic AI as the top attack vector for 2026, underscoring the urgent need for safe, controlled AI environments and heightened organizational awareness.

Iranian Hackers Leak Kash Patel’s Personal Emails in Retaliation Campaign
technology14 days ago

Iranian Hackers Leak Kash Patel’s Personal Emails in Retaliation Campaign

Pro‑Iranian group Handala published more than 300 emails and photos from Kash Patel’s personal Gmail, mostly dating from 2010–2012 with some items from 2022, claiming retaliation after FBI/DOJ actions against Iranian hacking operations. NBC News could not verify all emails; the material includes Patel’s family correspondence and a Cuba trip, with metadata indicating the breach predates his government work. The FBI says the information is historical and contains no government information. The incident occurs amid broader Iranian cyber activity targeting U.S. figures, with the State Department offering up to $10 million for information on Iranian hackers.

Stryker breach spotlights risk of weaponized device-management tools
technology25 days ago

Stryker breach spotlights risk of weaponized device-management tools

A March 2026 Stryker cyberattack allegedly used Microsoft Intune to remotely wipe thousands of devices, with Iran-linked Handala claiming credit and up to 50 terabytes of data stolen. Researchers say the attack leveraged living-off-the-land techniques rather than a flaw in Intune, highlighting how MDM/UEM platforms can be abused. MFA and multi-account approvals for destructive actions are advised as Stryker works with forensic experts and the CISA investigates the incident.

Stryker’s Intune wipe hits 80,000 devices; no malware used
technology25 days ago

Stryker’s Intune wipe hits 80,000 devices; no malware used

Last week’s Stryker cyberattack, linked to the Handala hacktivist group, targeted its internal Microsoft environment and used the Intune wipe command to remotely erase data on about 80,000 devices after an admin account was compromised; attackers claimed wiping 200,000 devices and stealing 50 TB, but investigators found no data exfiltration and no malware was deployed. Medical devices remain safe, while electronic ordering systems are offline and orders must be placed via sales reps as restoration proceeds. Microsoft’s DART and Unit 42 are leading the investigation, with full operations and shipping expected to resume as systems recover.

Stryker Faces Uncertain Recovery Timeline After Global Cyberattack
business29 days ago

Stryker Faces Uncertain Recovery Timeline After Global Cyberattack

Stryker disclosed a global cyberattack that disrupted its Microsoft environment and wiped devices via Intune, affecting about 5,500 employees across several regions; while restoration efforts are ongoing, the full timeline and potential financial impact remain unclear, with security researchers pointing to Handala/IRGC-linked APT34 activity though Microsoft has not commented.

Iranian Hacktivists Strike Stryker in Retaliation for Minab School Bombing
technology29 days ago

Iranian Hacktivists Strike Stryker in Retaliation for Minab School Bombing

An Iran-linked hacktivist group, Handala, claims it hacked U.S. medical-device maker Stryker in retaliation for the Minab school bombing, saying it caused global disruption to Microsoft-based systems; Stryker says there is no ransomware evidence and the incident is contained, with a full restoration timeline unclear. Analysts warn more cyber actions may follow as Middle East tensions spill into the cyber realm.

Iran-linked Hackers Hit U.S. MedTech Stryker, Disrupting Global Operations
technology1 month ago

Iran-linked Hackers Hit U.S. MedTech Stryker, Disrupting Global Operations

Iran-backed Handala claimed responsibility for a global cyberattack on U.S. medical-technology company Stryker, crippling its Microsoft environment, wiping data on many computers, and forcing offices to close; Stryker says there is no ransomware and is assessing the impact as Handala frames the strike as retaliation for an Iranian school bombing.

Iran-linked hackers cripple Stryker in retaliatory cyberattack
world1 month ago

Iran-linked hackers cripple Stryker in retaliatory cyberattack

Iran-connected group Handala disrupted Stryker’s global networks and claimed to have stolen about 50 terabytes of data in retaliation for US-Israeli strikes on Iran. Stryker reported a global Microsoft environment disruption with no evidence of ransomware and said the incident is under investigation; Handala also claimed an attack on Verifone amid broader tensions and threats against Western targets.

world2 months ago

Russia escalates cyber sabotage of Europe’s energy grid with Polish plants under attack

Russia’s hybrid warfare appears to be escalating as cyberattacks hit about 30 energy facilities in Poland, threatening a major blackout during a cold snap and signaling broader European subversion beyond Ukraine. The incidents reportedly point to the involvement of Russia’s security services (FSB), highlighting a bold expansion of Moscow’s clandestine strikes against critical infrastructure.

Coordinated Wiper Attacks Hit 30+ Renewable Farms, Sparking Grid Security Concerns
technology2 months ago

Coordinated Wiper Attacks Hit 30+ Renewable Farms, Sparking Grid Security Concerns

CERT Polska disclosed a coordinated, destructive cyber campaign on Dec 29, 2025 that hit more than 30 wind/solar farms and a CHP plant, disrupting substation communications but not stopping electricity or heat delivery. The attackers deployed wipers (DynoWiper, LazyWiper) via compromised Fortinet devices and Active Directory, used multiple accounts with no two-factor authentication, and leveraged Tor/IPs to access energy networks, with several variants and likely LLM involvement; data was also exfiltrated from OT/cloud services. Attribution to Static Tundra tied to Russia's FSB is stated by CERT Polska, though some researchers link activity to Sandworm.

Russia-linked wiper targets Poland’s grid but power stays on
technology2 months ago

Russia-linked wiper targets Poland’s grid but power stays on

Poland’s electric grid was targeted by a new wiper malware, allegedly from Russia’s Sandworm group, on the late-December anniversary of a Ukraine grid attack. The payload, dubbed DynoWiper, aimed to disrupt communications between renewables and grid operators but did not cause a blackout. Attribution is at medium confidence and researchers say there’s no evidence of disruption, with several possible reasons the attack failed.

Verizon Outage Traced to Software Glitch, Not a Cyberattack
technology2 months ago

Verizon Outage Traced to Software Glitch, Not a Cyberattack

Verizon says a January 2026 nationwide outage that left many customers in SOS mode was caused by a software issue rather than a cyberattack; while the company hasn’t disclosed specifics, analysts speculate a faulty feature update. The disruption affected major cities, hindered emergency calls and GPS, and disrupted healthcare communications; Verizon is conducting a full review, with NY Assembly member Anil Beephan Jr. urging FCC scrutiny. A $20 account credit via the MyVerizon app has been offered to affected customers.