A UK Power Plant Went Down for Four Days (08/24/2026)

August 24, 2026
A UK Power Plant Went Down for Four Days (08/24/2026)
Key Intel / TL;DR
  • The Telegraph reports that Iranian actors took a UK power plant offline for four days in July, with the site undisclosed and no official government confirmation.
  • Analysts note the attack ran alongside the large-scale operation against US water plants and mattered for demonstrating feasibility rather than for its scale.
  • Keycloak CVE-2026-18963 scores 9.1 and lets an unauthenticated attacker hijack any account, administrators included, without the email verification token.
  • CISA ordered urgent patching of the actively exploited Zimbra flaw we carried on August 20.
  • UAT-10147 is using AI to scale server attacks and deploying SPECTRE with endpoint detection bypass.

Treat the power plant reporting carefully, because the sourcing is thinner than the headline suggests. The Telegraph says Iranian actors took a UK generating site offline for four days in July, the site has not been named, and no official confirmation has followed. What analysts are reacting to is not the scale, since the facility was small and supply was barely affected, but the demonstration that it can be done at all.

Top 5 Critical Security Alerts

1. A UK Power Plant Was Offline Four Days, Reportedly to Iranian Actors

The Telegraph reported that Iranian hackers shut down a small UK power plant for four days in July, with the account surfacing on August 22. The facility has not been identified and the UK government has not confirmed the attribution. Analysts note the operation ran in parallel with the large-scale campaign against US water plants, and one described the underlying problem as sustained under-investment in national infrastructure running on legacy systems. Infosecurity Magazine

Operator Note: Take the four days rather than the attribution, because the outage duration is the part that holds regardless of who did it. Four days is not a control system that got restarted, it is a control system somebody had to rebuild with confidence that the logic on it was the logic they intended. If you run process control, the question this raises for you is how long your own recovery would take when you cannot trust the running configuration, and most operators have never timed that.

2. A 9.1 in Keycloak Hands Over Any Account

CVE-2026-18963 is an improper state validation flaw in the reset-credentials authentication flow, letting an unauthenticated attacker force a password reset and take over any account, administrators included, without ever holding the email verification token. It affects Keycloak before 26.7.2 and the corresponding Red Hat builds. Version 26.7.2 landed on August 19, and disabling the forgot-password feature across all realms works as a stopgap. No exploitation has been observed as of today. The Hacker News

Operator Note: Keycloak sits underneath a lot of internal single sign-on that nobody outside the platform team thinks about, so the inventory question is which of your applications trust it rather than whether you run it. The stopgap here is unusually good, because turning off forgot-password for a day costs your help desk some calls and closes the hole completely.

3. CISA Orders Urgent Zimbra Patching

The Zimbra flaw we carried on August 20 as under active exploitation now has a federal directive attached, with CISA ordering urgent remediation. Exploitation was already in the wild when we first carried it, so the directive confirms rather than announces the risk. BleepingComputer

Operator Note: Four days from our first note on the exploitation to a directive is a short arc, and it tracks the pattern this month where the interval between disclosure and enforcement keeps compressing. If Zimbra is on your estate and it was not urgent last Thursday, it is now.

4. UAT-10147 Is Using AI to Scale Server Attacks

The group is using AI to increase the volume of its server attacks and deploying SPECTRE with endpoint detection bypass built in. This is the third distinct campaign this month where the notable element is the operator’s tooling rather than the payload. The Hacker News

Operator Note: Scale is the word to sit with. The same crew that could work through a few hundred targets can now work through a few thousand, which changes your odds of being selected without changing anything about how attractive you are. Exposure management stops being a maturity exercise and starts being an arithmetic one.

5. ToxicPanda Grows From Banking Trojan to Enterprise Threat

ToxicPanda has matured past consumer banking fraud into something that belongs on an enterprise threat model, and a separate report has it abusing virtual private network permissions to block Google Play. Dark Reading

Operator Note: Using the VPN permission to prevent Play from updating or removing it is the detail worth carrying, because it turns a legitimate Android capability into persistence. Any mobile device policy that grants VPN permission broadly is granting that too.

Additional Security Alerts

Threat Intelligence

  • Doubloon Dredger is abusing Notion to harvest authentication tokens: Another campaign living inside a service your allowlist already permits. Infosecurity Magazine
  • A fake Codex download uses Google Sites to deliver macOS malware: Developer tooling as the lure, on a hosting domain nobody blocks. Infosecurity Magazine
  • Operation QUICSILVER is targeting Myanmar government and IT with a QUICAgent backdoor: The Hacker News

Security Breaches & Incidents

  • ReliaQuest confirmed a failed data theft attempt after a ShinyHunters breach: A security vendor disclosing an attempt against itself, which is worth more than most vendor blog posts. BleepingComputer
  • A South Korean startup platform breach exposed key management failures: The breach is the symptom and the key handling is the finding. BleepingComputer

Security Standards & Frameworks

  • NIST warns of security risks specific to multi-cloud environments: The gaps sit between providers rather than inside any one of them, which is exactly where nobody owns them. Infosecurity Magazine
  • New guidance helps businesses verify quantum-safe hardware claims: Useful now that every vendor has discovered the word quantum. Infosecurity Magazine

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)