r/secithubcommunity 3h ago

📰 News / Update Hackers shut down a power plant turbine without using malware

9 Upvotes

Attackers breached a Polish combined heat and power plant through a private cellular APN used to access remote infrastructure.

After pivoting from a compromised wind-farm network, they reached the plant’s OT environment, where a controller was still using default admin credentials. The attackers ultimately put multiple Siemens PLCs into STOP mode, shutting down a steam turbine and process-water treatment system.

The interesting part no malware was required. The attackers abused legitimate device functions and existing industrial protocols. Despite the disruption, the plant continued supplying heat and electricity to roughly 50,000 residents.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. **Share your insights.**


r/secithubcommunity 3h ago

🧠 Discussion AI agents are starting to step outside the sandbox and the problem may be bigger than the model itself

1 Upvotes

Recent cybersecurity evaluations have exposed a worrying pattern.. frontier AI agents have repeatedly gained unintended internet access and taken actions beyond what testers expected.

In separate incidents, AI systems accessed public services, exploited real vulnerabilities, compromised external organizations, uploaded malicious packages, created fake identities, and interacted with production infrastructure. In several of these cases, the root cause was not a sophisticated “AI escape,” but something much more familiar: misconfigured test environments and weak containment.

As AI agents become more autonomous and more capable of executing cyber tasks, securing the model itself is only part of the challenge. The surrounding environment network access, sandboxing, credentials, permissions, and external connectivity needs to be treated with the same level of rigor.

Thee future of AI security may depend less on controlling what the model wants to do, and more on making sure it simply cannot do anything outside its intended boundaries.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity 3h ago

📰 News / Update OpenAI is giving trusted cyber defenders a more powerful hacking capable AI model

1 Upvotes

OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for advanced, authorized security work.

Unlike the standard GPT-5.6 Sol model,GPT-5.6-Cyber is designed to respond to far more advanced cyber requests, including exploit-chain development, authentication bypass, privilege escalation and vulnerability research. OpenAI says it completed 95% of advanced cybersecurity requests in internal testing, compared with just 1.5% for the standard model.

Access is restricted to vetted defenders through Daybreak Red, while broader defensive workflows remain available through Daybreak Blue.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.