SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, August 25, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Iranian Hackers Shut Down UK Power Plant | CRITICAL |
|
5 C2 IPs | 21 OTX IOCs | 38 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by critical infrastructure disruption, with Iranian nation-state actors shutting down a UK power plant for four days, and active exploitation of a Zimbra Collaboration Suite vulnerability. Additionally, security firm ReliaQuest confirmed a social engineering breach by the ShinyHunters group, while critical authentication bypass flaws target Keycloak and WordPress miniOrange plugins. |
|
■ CRITICAL STORIES Iran-Linked Hackers Shut Down UK Power Plant for Four Days Iranian cyber actors caused real-world operational disruption at a small UK power plant, highlighting growing threats to distributed energy infrastructure and the potential for repeatable physical impacts. |
CISA orders urgent patching of actively exploited Zimbra flaw CISA has added an actively exploited Zimbra Collaboration Suite vulnerability to its KEV catalog, ordering federal agencies to patch it within three days due to immediate exploitation risk. |
ReliaQuest Confirms ShinyHunters Hack via Social Engineering A ReliaQuest employee fell victim to a sophisticated social engineering attack where threat actors impersonated a security team member to gain dashboard access, though the company claims the data-theft attempt ultimately failed. |
Critical Keycloak Password Reset Flaw Allows Account Takeover A critical flaw in the open-source Keycloak identity and access management server allows unauthenticated remote attackers to force password resets and take over any user account. |
|
■ CVEs IDENTIFIED [CVE-TBD] Zimbra Zimbra Collaboration Suite — Active exploitation leading to remote code execution or unauthorized access |
[CVE-TBD] Keycloak Keycloak Identity and Access Management — Unauthenticated remote account takeover via password reset bypass |
[CVE-TBD] Calix GS7 XGS Calix GS7 XGS (GS5239XG) Router — Remote unauthenticated NAT bypass and port-forwarding rule creation |
[CVE-TBD] miniOrange SAML 2.0 SSO miniOrange SAML 2.0 Single Sign On plugin for WordPress — Authentication bypass via forged SAML responses |
|
■ THREAT ACTORS ShinyHunters | Cybercrime Group |
Targeted ReliaQuest employee using social engineering/impersonation to gain dashboard access. |
UAT-10147 | Chinese-speaking Cybercrime Group |
Targeted Windows and Linux web servers globally using SPECTRE malware, EDR bypass, and Linux rootkits. |
Iran-linked Hackers | Nation-State |
Conducted a cyberattack on a UK power plant causing a four-day operational shutdown. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploiting vulnerabilities in Zimbra, Keycloak, and miniOrange. |
| T1566 | | Phishing | Used by ShinyHunters against ReliaQuest and in fake GTA 6/Minecraft downloads. |
| T1021.001 | | Remote Desktop Protocol | Used by scammers to access systems. |
| T1014 | | Rootkit | Used by UAT-10147 on Linux servers. |
| T1562.001 | | Impair Defenses: Disable or Modify Tools | UAT-10147 EDR bypass; fake Microsoft scans tricking users to uninstall AV. |
| T1114 | | Email Collection | AI agents granted permission to read emails. |
|
■ PATCH PRIORITY Zimbra — Actively exploited vulnerability on CISA KEV — [BC] |
Keycloak — Unauthenticated account takeover via password reset [CVE-TBD] — [THN] |
miniOrange — SAML 2.0 SSO plugin auth bypass allowing admin login [CVE-TBD] — [BC] |
Spring — 91 vulnerabilities patched in Application Framework [CVE-TBD] — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch the actively exploited Zimbra Collaboration Suite [CVE-TBD] vulnerability immediately, especially for federal and critical infrastructure entities. |
| 2 | [P1] Apply the latest security updates released by Red Hat for Keycloak [CVE-TBD] to prevent unauthenticated remote account takeovers. |
| 3 | [P1] Update the miniOrange SAML 2.0 Single Sign On plugin for WordPress [CVE-TBD] to the latest version to block SAML authentication bypass attacks. |
| 4 | [P2] Implement network segmentation and firewall rules to mitigate the unpatched NAT bypass vulnerability in Calix GS7 XGS (GS5239XG) [CVE-TBD] residential routers. |
| 5 | [P2] Review and apply patches for the 91 vulnerabilities identified in the Spring Application Framework [CVE-TBD]. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |