Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

PoeLLM Campaign Compromises 3,400+ Servers for Crypto Mining

Cryptocurrency mining campaigns have compromised over 3,400 servers since April 2026, with attackers primarily targeting exposed artificial ...

All the recent news you need to know

Southern Company Discloses Data Breach Affecting 400,000 Georgia Power and Alabama Power Customers

 



Southern Company, the Atlanta-based energy holding giant, has confirmed that an unauthorized third party broke into its online customer portal and accessed account information belonging to roughly 400,000 customers across its electric subsidiaries, Georgia Power, Alabama Power, and Mississippi Power.

The company publicly disclosed the breach on October 5, 2026, stating that the intrusion, which occurred in September, was detected through its own monitoring systems. Upon discovery, Southern Company said it moved quickly to shut down the unauthorized access and notified law enforcement.

"Southern Company recently detected suspicious activity involving our online customer portal," the company said in a statement. "An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement."

Of the roughly 400,000 accounts compromised, approximately 300,000 belong to Georgia Power customers. Alabama Power accounts for the remaining 100,000, which represents about 6% of its 1.6 million-customer base. Mississippi Power was named in the company's public notice as affected, but Southern Company has not released a customer count for that subsidiary.

According to the company's published incident notice, the data the attacker accessed includes customers' names, mailing addresses, phone numbers, email addresses, and the last four digits of their Social Security numbers, along with other unspecified basic account details. The company was clear about what was not taken: bank account numbers, payment card numbers, and driver's license numbers were not part of what the attacker pulled from the portal.

The online portal in question is the same platform customers use to pay bills and manage their accounts.

Despite the company's confirmation that it caught and stopped the intrusion, Southern Company has not said when exactly in September the breach occurred, nor has it explained how the attacker got past the portal's defenses in the first place. That absence of technical detail leaves open questions about the attack method, whether it involved stolen credentials, a software vulnerability, or some other approach.

Customers whose information was involved are being notified directly by both mail and email. Southern Company is also offering each affected customer one year of free credit monitoring through Equifax. Those with additional questions were directed to a dedicated assistance line at 1-800-900-6021, available Monday through Friday.

Southern Company, incorporated in 1945 and headquartered in Atlanta, is one of the largest energy holding companies in the United States. It supplies electricity through its subsidiaries to customers across three states and operates natural gas distribution businesses in four more. Its total customer base numbers over 9 million.

The incident sits alongside a string of recent cyberattacks targeting utility companies in North America and beyond. Just weeks earlier, in September 2026, Houston-based CenterPoint Energy disclosed that an unauthorized third party had obtained personal information on a portion of its customers through one of the company's external-facing systems. That disclosure came after a threat actor claimed on a cybercrime forum to have extracted 7.49 million customer records from the utility and ultimately leaked the data after the company failed to respond. In March 2025, Nova Scotia Power, Canada's largest electric utility in that province, suffered a cyberattack that disrupted its customer support line and web portal.

Research published by cybersecurity firm Trustwave in 2025 found that roughly 67% of credential access techniques used against energy and utilities companies involved brute force methods, which are largely automated attacks that cycle through large lists of usernames and passwords. That tactic, known as credential stuffing when it draws on passwords stolen from previous breaches on other platforms, has been used against utility customer portals before. In 2021, UK energy supplier Npower had to shut down its mobile app entirely after attackers used stolen credentials from other websites to access thousands of customer accounts.

The energy sector's digital attack surface has expanded considerably as utilities push more customer services online. Customers log into portals to check bills, set up autopay, and track usage, all of which requires storing personal data behind web-based logins. Security researchers have long pointed out that these portals often receive less security investment than back-end operational systems, even though they handle data that is directly useful for phishing, identity fraud, and social engineering.

Southern Company said it has found no evidence of ongoing unauthorized access following the breach, and noted that it continues to monitor its systems around the clock. The company's public notice also cautioned customers to be alert for fraudulent contact from individuals claiming to be Georgia Power or Alabama Power representatives, reminding them that neither utility will ever threaten immediate service disconnection or demand payment over the phone.

Anyone who believes they may have been affected and has not yet received notification from the company can contact Georgia Power customer service directly through the number listed on their bill.



ASOS Confirms Unauthorised Hack Notification; Customer Data May Be Exposed

 

On 6 October 2026, thousands of ASOS customers across multiple countries received a shocking push notification via the official ASOS app, claiming that hackers had breached the retailer’s systems. The message, which appeared around 10:00 BST, was addressed to ASOS’s data protection officer and IT team and warned that attackers had “fully compromised the Snowflake instance” and would leak data unless the company engaged with them. ASOS swiftly described the alert as an “unauthorised customer notification” and launched an investigation into what appears to be a cyber-extortion attempt routed through a third-party communications platform. 

The notification was headlined “ASOS HACKED” and read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” followed by a link to an external Telegram channel signed by a user called “xuanyewengateway”. Many users reported feeling scared and confused, with some saying they no longer trusted the ASOS app after seeing the message arrive through what should be a secure, brand-controlled channel. Security experts described the incident as a brazen attempt to pressure ASOS publicly by hijacking its own customer-notification system, raising concerns about how attackers gained access to such a sensitive communications tool. 

In response, ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external cybersecurity specialists, as well as relevant authorities. The company confirmed that basic personal information, including names and contact details, may have been accessed during the incident, but it does not believe payment-card information or account passwords were impacted. ASOS stressed that its website and app remain fully operational and urged customers to disregard the unauthorised alert and not click any links contained within it, warning that doing so could expose them to further risks.

ASOS is not currently asking customers to change their passwords or take other specific actions, but it advises anyone who received the notification to ignore it and avoid engaging with the third-party link. The UK’s National Cyber Security Centre has gone further, suggesting that all ASOS customers should consider themselves potentially affected, even if they did not see the alert, and should only access ASOS via its official website or app. Users are also warned to be alert for follow-up scams, such as fake refund or support messages exploiting concern over the incident, and to treat any unexpected communication about the breach with caution. 

ASOS says its investigation into the unauthorised activity involving third-party communication platforms is ongoing, and it will provide updates if the situation changes. While the attackers claimed a Snowflake data-platform breach, Snowflake itself has stated it has found no compromise of its platform at this time. For now, ASOS maintains that push notifications are safe, operations are unaffected, and customers can continue to shop with confidence while the company works with cybersecurity advisers and law enforcement to understand exactly how the unauthorised message was sent and to prevent similar incidents in the future.

Chrome Blocks Unauthorized Certificates After Three ccTLD Hijacks

 

Chrome has taken steps to protect users after attackers compromised three country-code top-level domains and exploited the incidents to acquire unauthorized HTTPS certificates for multiple organizations. The affected namespaces are .gh for Ghana, .sl for Sierra Leone and .as for American Samoa. Attackers targeted the third-party registries which own the ccTLDs rather than Google directly. 

In addition to the country-code top-level domain takeovers, the adversaries also modified the authoritative DNS records to compromise several Google domains and domains of other companies. Chrome reported that it is not evident that Certification Authorities (CAs) that issued the certificates acted in bad faith but instead concluded that the problem stemmed from attackers’ tampering with DNS infrastructure of the country-code domains. 

Chrome’s Secure Web and Networking Team responded to the incidents by utilizing CRLSets to block the unauthorized certificates associated with Google properties and coordinated with the CAs to revoke the certificates, protecting the users of the browsers and other clients. The list of impacted entities grew as Chrome analyzed Certificate Transparency (CT) logs and identified a number of large publicly traded companies and popular internet services. 

The team blocked certificates it suspected to be related to the attacks and reached out to the impacted businesses. Users of Chrome do not need to take any action as the protections are designed to be transparent and work in the background. However, Google warned that organizations should not rely on the browser to protect them against the attacks and that Chrome did not identify all the affected domains. Similarly, protections worked on Google Chrome and may have not triggered in other browsers and clients. 

Organizations are advised to ensure that they monitor the CT logs for all the domains and that they are notified if an unauthorized certificate is issued. This is critical because every certificate that is trusted by the public must be reported to CT logs. For domains that are impacted by the ongoing attacks, it is recommended to look over the most recent certificates to ensure that they have not been issued without authorization. Google recommended the use of restricted Certification Authority Authorization (CAA) records and the use of ACME account bindings when available. 

CAA records dictate which CAs can issue certificates and, while they do not prevent an attacker from using a hijacked domain to issue a certificate, they can help in ensuring that unknown CAs are not utilized. Additionally, the CAA records can prevent attackers from using domain-control validation for certificate issuance through misdirection. Using issuing restrictions and validation method restrictions can prevent attackers from using certificates’ domain validation through cached entries. These protections are only effective after the control of the domain is re-established. 

Chrome announced its intent to keep working on long-term projects to improve security and reduce the risks associated with the use of certificates. The proposed changes include shortening the lifespan of certificates and limiting the re-use of domain validation. They will continue to work to improve the Chrome Root Program with the Chrome Quantum-resistant Root Program as the Chrome ecosystem seeks to mitigate the risks posed by DNS and routing compromises.

Japan Arrests Suspected Qilin Ransomware Hacker, Extradites Him to Germany


A suspected member of the Qilin ransomware group has been arrested in Japan and extradited to Germany, where he is expected to face charges related to cyberattacks and ransomware extortion. The case is important as it reveals a growing international effort to identify and prosecute individuals involved in major ransomware operations.

According to a report by SecurityWeek, the suspect is a 28-year-old Russian national who was arrested in Osaka, Japan, in May 2026. German authorities accuse him of playing a role in the Qilin ransomware operation, which has targeted organizations in several countries.

The suspect was extradited to Germany on October 2, 2026, following legal proceedings in Japan. German investigators allege that he was involved in an attack against a logistics company in September 2024.

Ransomware attack

Investigators say the targeted logistics company had its computer systems encrypted during the attack. The attackers allegedly demanded more than $160,000 in cryptocurrency in exchange for restoring access to the affected systems.

The incident is believed to have been connected to the Qilin ransomware operation, also known as Agenda. Qilin emerged as a ransomware-as-a-service (RaaS) operation in 2022. Under this model, ransomware developers provide malware and infrastructure to affiliates, who conduct attacks against victims and share the proceeds with the operators.

This business model has allowed ransomware groups to expand their operations without every attacker needing to develop their own malware or infrastructure.

Qilin's global activity

Qilin has become one of the more active ransomware groups in recent years. It has targeted organizations across different industries, including healthcare, manufacturing, professional services and other critical sectors.

The group attracted international attention after attacks linked to it disrupted healthcare services in the United Kingdom. It was associated with the 2024 attack against Synnovis, a medical services provider whose systems were used by several London hospitals. The incident caused significant disruption to healthcare operations.

Qilin has also been linked to attacks against major companies in other countries, demonstrating the international reach of the ransomware operation.

Experts have continued to track the group's activities and techniques. In 2026, Qilin was also reported to have exploited a critical vulnerability affecting Check Point security products as part of its attack activity.

AI Watermarking Meant to Protect Against Misuse Could Actually Enable It

 



A security feature designed to make AI text traceable appears to have an unintended side effect: it can change how a language model behaves, in some cases making it more willing to follow instructions it was built to refuse.

That is the core finding from new research by Lasso Security, published on September 17 by researcher Andrea Siposova under the title "The Provenance Tax: Understanding the Impact of LLM Watermarking on AI Agent Behavior." The study tested Google DeepMind's SynthID-Text watermarking system across six open-weight language models and found that enabling watermarking changed how those models responded to harmful requests, particularly when attackers used prompt-injection techniques designed to override a model's instructions.


What SynthID-Text Actually Does

To understand why that matters, it helps to understand what SynthID-Text actually changes inside a model.

When a language model generates text, it does not write the way a human does. It builds sentences one token at a time, each step producing a probability distribution over thousands of possible next tokens and then sampling from that distribution. SynthID-Text does not attach a label to the finished output or hide characters in whitespace. It intervenes at the sampling step itself.

The system uses a process called tournament sampling, first described in a 2024 Nature paper by Google DeepMind researchers Sumanth Dathathri, Abigail See, and colleagues. Instead of the standard randomness used in token selection, the watermark substitutes pseudorandom values generated from a secret key and the context of tokens already produced. The result is a statistically detectable pattern woven through the text at the level of individual word choices, invisible to readers but recoverable by anyone holding the key. The technique is refined enough that it does not degrade text quality in any measurable way, which is a large part of what made it attractive as a compliance tool.


The Regulatory Push Behind It

Article 50 of the EU AI Act requires providers of generative AI systems to mark their text, image, audio, and video outputs in a way that is machine-readable and detectable as AI-generated. The Code of Practice the European Commission finalized on July 20, 2026, requires at least two marking layers for audio, images and video, plus watermarking of free-form text longer than 200 tokens. Google signed the Code on July 24, 2026, citing SynthID partnerships as its route to the interoperable detection requirement due on February 2, 2027.

Anthropic's technical implementation is built directly on SynthID-Text, the same tournament-sampling mechanism from the Nature paper, adapted for their own models and keys. It covers claude.ai, the API, Claude Code, Claude Cowork, Claude Tag, and access through AWS, Google Cloud, and Microsoft Foundry. With the industry's largest players now committed to the same watermarking standard, Siposova's findings arrive at an uncomfortable moment.


What the Research Found

Siposova ran paired experiments on six open-weight models using Hugging Face's unmodified SynthIDTextWatermarkLogitsProcessor, enabling and disabling watermarking while keeping the seed, batch composition, and ordering identical.

Watermarking changed refusal behavior on harmful requests, but the effect was more pronounced when the same requests were paired with prompt-injection techniques. Under those conditions, several watermarked models complied with harmful requests their unwatermarked versions had rejected, with the strongest differences appearing in prompt-injection scenarios.

Siposova told Ars Technica that behavior was clearly different compared with the same model without watermarking, and that the differences were especially pronounced under adversarial conditions or when running an agent calling tools. She put it plainly: "Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it's going to show up somewhere."

Lasso repeated its prompt-injection experiment using 11 different watermark keys and found that changing the key could change both the size and direction of the effect. That means two different deployments of the same watermarking system, on the same model, could produce different safety outcomes depending purely on which key was chosen.


The Agent Problem

The consequences extend beyond what a model says. When a language model powers an AI agent, token selection can determine which tool an agent invokes and which arguments it passes. "Such a watermarking procedure can therefore affect both what the model says and what an agent does," the study stated. Watermarking reduced accuracy on six of seven models, with a substantial decrease on four.

Lasso's conclusions are deliberately careful. The study did not verify how Claude model responses change when watermarking is applied, and critics noted the experiment only validated the SynthID-Text tournament sampling implemented by Hugging Face, which differs from how the Claude model would actually implement it. Siposova stressed that the findings describe patterns in the tested sample, not universal rules about watermarking as a category.

Lasso recommended repeating agent evaluations and red-team testing when watermarking or its configuration changes, particularly under adversarial inputs.

The research surfaces a tension that will only sharpen as regulatory deadlines close in. Watermarking was designed to answer the question of where AI text comes from. What it can also do, under the right adversarial conditions, is change what the AI decides to do next.


Former Engineer Jailed for Ransomware-Style Cyberattack

 

A former employee of a New Jersey-based industrial company has been sentenced to 32 months in federal prison for launching a computer network attack and attempting to extort his former employer. Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced by U.S. District Judge Michael A. Shipp on September 28, 2026, at federal court in Trenton, New Jersey. The sentence followed his guilty plea to charges involving extortion through a threat to damage a protected computer and intentional damage to a protected computer. 

According to court documents and statements made during the proceedings, Rhyne previously worked as a core infrastructure engineer for the U.S.-based industrial company, identified in court records as Victim-1. While he was living in New Jersey in November 2023, he allegedly began preparing a plan to disrupt the company’s computer network and force it to pay a ransom. His position reportedly gave him technical knowledge and access that allowed him to plan the attack against the company’s critical systems. 

As part of the scheme, Rhyne initiated unauthorized remote desktop sessions and scheduled tasks designed to damage the company’s network. The planned actions included deleting network administrator accounts, changing passwords linked to other employee accounts and shutting down several company servers. These steps could have seriously disrupted business operations by preventing authorized staff from accessing systems and interrupting essential digital services. 

On November 25, 2023, Rhyne sent an extortion email to employees of the industrial company. In the message, he threatened to continue shutting down servers unless the company paid approximately 20 bitcoin. At the time, the cryptocurrency demand was valued at about $750,000. The case highlights how former employees with detailed knowledge of internal infrastructure can pose a significant cybersecurity risk, especially when access controls and administrative privileges are not promptly reviewed after employment ends. 

The investigation was conducted by special agents from the FBI’s Newark Field Office, with assistance from the FBI’s Kansas City Field Office. U.S. Attorney Robert Frazer announced the sentence, while Assistant U.S. Attorney Taj Moore of the Cybercrime Unit prosecuted the case. The conviction demonstrates that unauthorized access, deliberate disruption of computer networks and ransom demands can result in substantial federal prison sentences. It also underlines the importance of removing former employees’ access, monitoring remote sessions and protecting administrator accounts against misuse.

Featured