Daily Security Intel

Archives
Log in
Subscribe
August 25, 2026

[SecurityIntel] 25 Aug | Iranian Hackers Shut Down UK Power Plant

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, August 25, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Iranian Hackers Shut Down UK Power Plant

CRITICAL

5

C2 IPs

21

OTX IOCs

38

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by critical infrastructure disruption, with Iranian nation-state actors shutting down a UK power plant for four days, and active exploitation of a Zimbra Collaboration Suite vulnerability. Additionally, security firm ReliaQuest confirmed a social engineering breach by the ShinyHunters group, while critical authentication bypass flaws target Keycloak and WordPress miniOrange plugins.

■ CRITICAL STORIES

CRITICAL#1

Iran-Linked Hackers Shut Down UK Power Plant for Four Days

Iranian cyber actors caused real-world operational disruption at a small UK power plant, highlighting growing threats to distributed energy infrastructure and the potential for repeatable physical impacts.

INFO#2

CISA orders urgent patching of actively exploited Zimbra flaw

CISA has added an actively exploited Zimbra Collaboration Suite vulnerability to its KEV catalog, ordering federal agencies to patch it within three days due to immediate exploitation risk.

INFO#3

ReliaQuest Confirms ShinyHunters Hack via Social Engineering

A ReliaQuest employee fell victim to a sophisticated social engineering attack where threat actors impersonated a security team member to gain dashboard access, though the company claims the data-theft attempt ultimately failed.

CRITICAL#4

Critical Keycloak Password Reset Flaw Allows Account Takeover

A critical flaw in the open-source Keycloak identity and access management server allows unauthenticated remote attackers to force password resets and take over any user account.

■ CVEs IDENTIFIED

[CVE-TBD] Zimbra

Zimbra Collaboration Suite — Active exploitation leading to remote code execution or unauthorized access

Critical

[CVE-TBD] Keycloak

Keycloak Identity and Access Management — Unauthenticated remote account takeover via password reset bypass

Critical

[CVE-TBD] Calix GS7 XGS

Calix GS7 XGS (GS5239XG) Router — Remote unauthenticated NAT bypass and port-forwarding rule creation

High

[CVE-TBD] miniOrange SAML 2.0 SSO

miniOrange SAML 2.0 Single Sign On plugin for WordPress — Authentication bypass via forged SAML responses

Critical

■ THREAT ACTORS

ShinyHunters

Cybercrime Group

Targeted ReliaQuest employee using social engineering/impersonation to gain dashboard access.

UAT-10147

Chinese-speaking Cybercrime Group

Targeted Windows and Linux web servers globally using SPECTRE malware, EDR bypass, and Linux rootkits.

Iran-linked Hackers

Nation-State

Conducted a cyberattack on a UK power plant causing a four-day operational shutdown.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploiting vulnerabilities in Zimbra, Keycloak, and miniOrange.
T1566
Phishing | Used by ShinyHunters against ReliaQuest and in fake GTA 6/Minecraft downloads.
T1021.001
Remote Desktop Protocol | Used by scammers to access systems.
T1014
Rootkit | Used by UAT-10147 on Linux servers.
T1562.001
Impair Defenses: Disable or Modify Tools | UAT-10147 EDR bypass; fake Microsoft scans tricking users to uninstall AV.
T1114
Email Collection | AI agents granted permission to read emails.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Zimbra — Actively exploited vulnerability on CISA KEV — [BC]

[P1 PATCH NOW]≤24h

Keycloak — Unauthenticated account takeover via password reset [CVE-TBD] — [THN]

[P1 PATCH NOW]≤24h

miniOrange — SAML 2.0 SSO plugin auth bypass allowing admin login [CVE-TBD] — [BC]

[P2 PATCH NOW]≤72h

Spring — 91 vulnerabilities patched in Application Framework [CVE-TBD] — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch the actively exploited Zimbra Collaboration Suite [CVE-TBD] vulnerability immediately, especially for federal and critical infrastructure entities.
2[P1] Apply the latest security updates released by Red Hat for Keycloak [CVE-TBD] to prevent unauthenticated remote account takeovers.
3[P1] Update the miniOrange SAML 2.0 Single Sign On plugin for WordPress [CVE-TBD] to the latest version to block SAML authentication bypass attacks.
4[P2] Implement network segmentation and firewall rules to mitigate the unpatched NAT bypass vulnerability in Calix GS7 XGS (GS5239XG) [CVE-TBD] residential routers.
5[P2] Review and apply patches for the 91 vulnerabilities identified in the Spring Application Framework [CVE-TBD].
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 26 Aug | MiniOrange SSO Flaws Target WordPress Websites Older → [SecurityIntel] 24 Aug | ToxicPanda Android Malware Abuses VPN Permissions
Powered by Buttondown, the easiest way to start and grow your newsletter.