Grok, Cisco and AWS: UK power plant hack, AI zero click, children’s hospital breach

Grok, Cisco and AWS: UK power plant hack, AI zero click, children’s hospital breach

Cybersecurity Roundup: Major Incidents and Emerging Threats

Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and warnings across critical infrastructure, AI systems, and enterprise software.

UK Power Plant Hit by Iran-Linked Hackers
A previously unidentified UK power plant was disabled for four days in what The Telegraph called "the most successful cyberattack of its kind against UK energy infrastructure." While the outage did not disrupt the national grid, the government has issued warnings to power companies, framing the attack as a demonstration of Iran-linked hackers' capabilities. The incident underscores growing threats to energy sector resilience.

Zero-Click AI Chat Data Theft via Cryptographic Exploit
Security researcher Rony Utevsky of Adversa revealed a novel attack technique that bypasses AI safety filters by embedding malicious instructions in AES-encrypted data. Demonstrated against Grok and Gemini, the exploit allows threat actors to steal chat histories without user interaction in Grok and generate restricted content in Gemini. The method exploits gaps in how AI models process encrypted inputs, highlighting vulnerabilities in production AI systems.

OpenAI Warns of Persistent AI-Driven Cyber Threats
Chris Lehane, OpenAI’s chief global affairs officer, cautioned that advanced AI models are increasingly capable of launching "ongoing, persistent cyber-attacks," with offensive capabilities outpacing defensive measures. The warning follows OpenAI’s decision to pause development of its most advanced internal models amid safety concerns. Lehane reiterated calls for U.S. government regulation to address frontier AI risks.

Canada’s SickKids Hospital Suffers Second Cyberattack
Toronto’s Hospital for Sick Children, Canada’s largest pediatric health center, experienced a data breach exposing current and former employees' personal information. The incident, linked to a third-party software vulnerability, follows a 2022 ransomware attack. While no clinical systems or patient data were compromised, the breach raises concerns about third-party supply chain risks in healthcare.

Critical Flaws in Cisco Secure Workload Software
Cisco disclosed four high-severity vulnerabilities in its Secure Workload (formerly Tetration) micro-segmentation tool, including two CVSS 10.0 flaws (CVE-2026-20315, CVE-2026-20317) tied to improper access control. Additional vulnerabilities (CVE-2026-20231, CVE-2026-20318) involve input validation and neutralization issues. While SaaS fixes are available, users must manually upgrade Agent and Connector tools to mitigate risks.

Congress Probes CISA Staffing Cuts
Democratic lawmakers, led by Rep. Bennie Thompson, have requested a Government Accountability Office (GAO) investigation into how staffing reductions nearly one-third of CISA’s workforce impact the agency’s ability to protect critical infrastructure. The inquiry reflects growing concerns over resource constraints in federal cybersecurity efforts.

Leaked AWS Keys Grant Full Corporate Account Control
Researchers at Truffle Security identified over 9,300 active and valid AWS access keys exposed between 2022 and 2026, including 526 root keys and 242 admin-level IAM keys. The findings underscore persistent risks from misconfigured cloud credentials, with many keys linked to high-privilege accounts capable of full resource manipulation.

Time-Sensitive Networking (TSN) Protocols Vulnerable to OT Manipulation
Nozomi Networks, owned by Mitsubishi Electric, revealed critical weaknesses in TSN protocols designed for industrial reliability that could allow attackers to inject commands or alter timing signals in operational technology (OT). While patches exist for some flaws, underlying protocol limitations make comprehensive fixes challenging. Network segmentation and firmware updates remain key defenses against potential disruptions to machinery and industrial processes.

Source: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/

Grok TPRM report: https://www.rankiteo.com/company/heygrok

Cisco TPRM report: https://www.rankiteo.com/company/cisco

AWS TPRM report: https://www.rankiteo.com/company/aws-ai

"id": "heyawscis1787567547",
"linkid": "heygrok, aws-ai, cisco",
"type": "Vulnerability",
"date": "8/2022",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Energy',
                        'location': 'United Kingdom',
                        'name': 'Unnamed UK Power Plant',
                        'type': 'Critical Infrastructure'},
                       {'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Grok, Gemini',
                        'type': 'AI Systems'},
                       {'industry': 'Technology',
                        'location': 'United States',
                        'name': 'OpenAI',
                        'type': 'AI Research/Development'},
                       {'customers_affected': 'Current and former employees',
                        'industry': 'Healthcare',
                        'location': 'Canada',
                        'name': 'Hospital for Sick Children (SickKids)',
                        'size': 'Large (Canada’s largest pediatric health '
                                'center)',
                        'type': 'Healthcare Provider'},
                       {'customers_affected': 'Secure Workload (Tetration) '
                                              'users',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Cisco',
                        'type': 'Technology Vendor'},
                       {'industry': 'Multiple',
                        'location': 'Global',
                        'name': 'Multiple Corporations (AWS Users)',
                        'type': 'Various'},
                       {'industry': 'Manufacturing/Industrial',
                        'location': 'Global',
                        'name': 'Industrial OT Systems (TSN Protocol Users)',
                        'type': 'Critical Infrastructure'}],
 'attack_vector': ['Unknown',
                   'Cryptographic Exploit (AES-encrypted data)',
                   'Third-Party Software Vulnerability',
                   'Exposed Cloud Credentials',
                   'Protocol Manipulation'],
 'customer_advisories': ['Public disclosure to affected employees.'],
 'data_breach': {'data_encryption': [None,
                                     'Exploited (AES-encrypted data)',
                                     None,
                                     None,
                                     None,
                                     None,
                                     None],
                 'data_exfiltration': [None,
                                       'Yes (Chat Histories)',
                                       None,
                                       None,
                                       None,
                                       None,
                                       None],
                 'file_types_exposed': [None,
                                        None,
                                        None,
                                        None,
                                        None,
                                        None,
                                        None],
                 'number_of_records_exposed': [None,
                                               None,
                                               None,
                                               None,
                                               None,
                                               '9,300+ active keys (526 root, '
                                               '242 admin-level)',
                                               None],
                 'personally_identifiable_information': [None,
                                                         None,
                                                         None,
                                                         'Yes (Employee PII)',
                                                         None,
                                                         None,
                                                         None],
                 'sensitivity_of_data': [None,
                                         'High (Chat Histories)',
                                         None,
                                         'High (PII)',
                                         None,
                                         'Critical (Root/Admin-Level AWS Keys)',
                                         None],
                 'type_of_data_compromised': [None,
                                              'AI Chat Histories',
                                              None,
                                              'Employee Personal Information',
                                              None,
                                              'AWS Access Keys',
                                              None]},
 'description': ['A UK power plant was disabled for four days in a cyberattack '
                 'linked to Iran, marking one of the most successful attacks '
                 'against UK energy infrastructure. The incident did not '
                 'disrupt the national grid but highlighted vulnerabilities in '
                 'the energy sector.',
                 'Security researcher Rony Utevsky demonstrated a zero-click '
                 'attack exploiting AES-encrypted data to bypass AI safety '
                 'filters, enabling theft of chat histories from Grok and '
                 'generation of restricted content in Gemini. The method '
                 'exposes gaps in AI model processing of encrypted inputs.',
                 'OpenAI warned that advanced AI models are increasingly '
                 'capable of launching persistent cyber-attacks, with '
                 'offensive capabilities outpacing defensive measures. The '
                 'warning follows OpenAI’s pause in developing its most '
                 'advanced internal models due to safety concerns.',
                 'Toronto’s Hospital for Sick Children (SickKids) suffered a '
                 "data breach exposing current and former employees' personal "
                 'information due to a third-party software vulnerability. No '
                 'clinical systems or patient data were compromised.',
                 'Cisco disclosed four high-severity vulnerabilities in its '
                 'Secure Workload software, including two CVSS 10.0 flaws tied '
                 'to improper access control. Users must manually upgrade '
                 'Agent and Connector tools to mitigate risks.',
                 'Researchers at Truffle Security identified over 9,300 active '
                 'and valid AWS access keys exposed between 2022 and 2026, '
                 'including 526 root keys and 242 admin-level IAM keys, posing '
                 'risks of full corporate account control.',
                 'Nozomi Networks revealed critical weaknesses in '
                 'Time-Sensitive Networking (TSN) protocols, which could allow '
                 'attackers to inject commands or alter timing signals in '
                 'operational technology (OT). Patches exist for some flaws, '
                 'but underlying protocol limitations remain.'],
 'impact': {'brand_reputation_impact': ['High (Energy Sector Resilience '
                                        'Concerns)',
                                        'High (AI Safety Concerns)',
                                        'High (AI Security Reputation)',
                                        'Medium (Healthcare Trust)',
                                        'Medium (Enterprise Security '
                                        'Reputation)',
                                        'High (Cloud Security Reputation)',
                                        'High (Industrial Security '
                                        'Reputation)'],
            'conversion_rate_impact': [None,
                                       None,
                                       None,
                                       None,
                                       None,
                                       None,
                                       None],
            'customer_complaints': [None, None, None, None, None, None, None],
            'data_compromised': [None,
                                 'AI Chat Histories',
                                 None,
                                 'Employee Personal Information',
                                 None,
                                 'AWS Access Keys (Root/Admin-Level)',
                                 None],
            'downtime': ['4 Days', None, None, None, None, None, None],
            'financial_loss': [None, None, None, None, None, None, None],
            'identity_theft_risk': [None,
                                    None,
                                    None,
                                    'High (Employee PII)',
                                    None,
                                    None,
                                    None],
            'legal_liabilities': [None,
                                  None,
                                  None,
                                  'Potential (Employee Data Exposure)',
                                  None,
                                  'Potential (Unauthorized Access)',
                                  None],
            'operational_impact': ['Power Plant Disabled',
                                   None,
                                   None,
                                   None,
                                   None,
                                   'Potential Full Account Takeover',
                                   'Potential Machinery/Industrial Process '
                                   'Disruption'],
            'payment_information_risk': [None,
                                         None,
                                         None,
                                         None,
                                         None,
                                         None,
                                         None],
            'revenue_loss': [None, None, None, None, None, None, None],
            'systems_affected': ['UK Power Plant (Disabled for 4 Days)',
                                 'Grok, Gemini AI Systems',
                                 None,
                                 'SickKids Hospital HR Systems',
                                 'Cisco Secure Workload (Tetration)',
                                 'Corporate AWS Accounts',
                                 'Industrial OT Systems (TSN Protocols)']},
 'initial_access_broker': {'backdoors_established': [None,
                                                     None,
                                                     None,
                                                     None,
                                                     None,
                                                     None,
                                                     None],
                           'data_sold_on_dark_web': [None,
                                                     None,
                                                     None,
                                                     None,
                                                     None,
                                                     None,
                                                     None],
                           'entry_point': [None,
                                           None,
                                           None,
                                           None,
                                           None,
                                           None,
                                           None],
                           'high_value_targets': [None,
                                                  None,
                                                  None,
                                                  None,
                                                  None,
                                                  None,
                                                  None],
                           'reconnaissance_period': [None,
                                                     None,
                                                     None,
                                                     None,
                                                     None,
                                                     None,
                                                     None]},
 'investigation_status': ['Demonstrated by Researcher',
                          'Completed (Public Disclosure)',
                          'Disclosed (Patches Available)',
                          'Researcher Disclosure',
                          'Researcher Disclosure'],
 'lessons_learned': ['Energy sector resilience requires enhanced cybersecurity '
                     'measures against state-sponsored threats.',
                     'AI systems must improve handling of encrypted inputs to '
                     'prevent safety filter bypasses.',
                     'AI-driven cyber threats require proactive defensive '
                     'strategies and regulatory oversight.',
                     'Third-party software vulnerabilities pose significant '
                     'risks to healthcare institutions.',
                     'Timely patching and manual upgrades are critical for '
                     'enterprise security tools.',
                     'Exposed cloud credentials remain a persistent and '
                     'high-risk threat to corporate security.',
                     'Industrial protocols like TSN require robust '
                     'segmentation and monitoring to prevent OT manipulation.'],
 'motivation': ['Demonstration of Capability',
                'Data Theft / Exploitation',
                'Unauthorized Access / Data Exfiltration',
                'OT Disruption'],
 'post_incident_analysis': {'corrective_actions': ['Enhanced cybersecurity '
                                                   'measures for energy sector '
                                                   'resilience.',
                                                   'Improved AI model '
                                                   'validation for encrypted '
                                                   'data processing.',
                                                   'Regulatory frameworks for '
                                                   'AI-driven cyber threats.',
                                                   'Stricter third-party risk '
                                                   'management in healthcare.',
                                                   'Timely patching and manual '
                                                   'upgrades for enterprise '
                                                   'security tools.',
                                                   'Strict cloud credential '
                                                   'management and monitoring.',
                                                   'Network segmentation and '
                                                   'enhanced monitoring for '
                                                   'industrial OT systems.'],
                            'root_causes': ['State-sponsored cyber '
                                            'capabilities targeting critical '
                                            'infrastructure.',
                                            'Gaps in AI model processing of '
                                            'encrypted inputs.',
                                            'AI offensive capabilities '
                                            'outpacing defensive measures.',
                                            'Third-party software '
                                            'vulnerability in healthcare '
                                            'systems.',
                                            'Improper access control and input '
                                            'validation in enterprise '
                                            'software.',
                                            'Misconfigured cloud credentials '
                                            'leading to exposure.',
                                            'Underlying weaknesses in '
                                            'industrial TSN protocols.']},
 'recommendations': ['Strengthen cybersecurity defenses in critical '
                     'infrastructure, particularly energy sectors.',
                     'Enhance AI model validation for encrypted inputs to '
                     'prevent exploitation.',
                     'Develop and enforce regulatory frameworks for AI-driven '
                     'cyber threats.',
                     'Improve third-party risk management in healthcare and '
                     'other sensitive industries.',
                     'Prioritize patching and manual upgrades for enterprise '
                     'security tools like Cisco Secure Workload.',
                     'Implement strict cloud credential management and '
                     'monitoring to prevent exposure.',
                     'Adopt network segmentation and enhanced monitoring for '
                     'industrial OT systems using TSN protocols.'],
 'references': [{'source': 'The Telegraph'},
                {'source': 'Adversa (Rony Utevsky)'},
                {'source': 'OpenAI (Chris Lehane)'},
                {'source': 'Hospital for Sick Children (SickKids)'},
                {'source': 'Cisco Security Advisory'},
                {'source': 'Truffle Security'},
                {'source': 'Nozomi Networks'}],
 'regulatory_compliance': {'fines_imposed': [None,
                                             None,
                                             None,
                                             None,
                                             None,
                                             None,
                                             None],
                           'legal_actions': [None,
                                             None,
                                             None,
                                             None,
                                             None,
                                             None,
                                             None],
                           'regulations_violated': [None,
                                                    None,
                                                    None,
                                                    'Potential (Healthcare '
                                                    'Data Protection Laws)',
                                                    None,
                                                    'Potential (Data '
                                                    'Protection Laws)',
                                                    None],
                           'regulatory_notifications': [None,
                                                        None,
                                                        None,
                                                        'Yes (Public '
                                                        'Disclosure)',
                                                        None,
                                                        None,
                                                        None]},
 'response': {'adaptive_behavioral_waf': [None,
                                          None,
                                          None,
                                          None,
                                          None,
                                          None,
                                          None],
              'communication_strategy': ['Government warnings to power '
                                         'companies',
                                         None,
                                         'Public warning by OpenAI’s chief '
                                         'global affairs officer',
                                         'Public disclosure of breach',
                                         'Security advisory by Cisco',
                                         'Researcher disclosure (Truffle '
                                         'Security)',
                                         'Researcher disclosure (Nozomi '
                                         'Networks)'],
              'containment_measures': [None,
                                       None,
                                       None,
                                       None,
                                       'SaaS fixes available; manual upgrades '
                                       'required for Agent/Connector tools',
                                       None,
                                       'Network segmentation, firmware '
                                       'updates'],
              'enhanced_monitoring': [None,
                                      None,
                                      None,
                                      None,
                                      None,
                                      None,
                                      'Recommended'],
              'incident_response_plan_activated': [None,
                                                   None,
                                                   None,
                                                   'Yes',
                                                   None,
                                                   None,
                                                   None],
              'law_enforcement_notified': [None,
                                           None,
                                           None,
                                           None,
                                           None,
                                           None,
                                           None],
              'network_segmentation': [None,
                                       None,
                                       None,
                                       None,
                                       None,
                                       None,
                                       'Recommended'],
              'on_demand_scrubbing_services': [None,
                                               None,
                                               None,
                                               None,
                                               None,
                                               None,
                                               None],
              'recovery_measures': [None, None, None, None, None, None, None],
              'remediation_measures': [None,
                                       None,
                                       None,
                                       None,
                                       'Patching vulnerabilities '
                                       '(CVE-2026-20315, CVE-2026-20317, '
                                       'CVE-2026-20231, CVE-2026-20318)',
                                       'Revoking exposed AWS keys',
                                       'Patching TSN protocol flaws (where '
                                       'possible)'],
              'third_party_assistance': [None,
                                         None,
                                         None,
                                         None,
                                         None,
                                         None,
                                         None]},
 'stakeholder_advisories': ['Government warnings to UK power companies.',
                            'OpenAI’s public warning on AI-driven threats.',
                            'Public advisory to employees and stakeholders.',
                            'Cisco’s security advisory to Secure Workload '
                            'users.',
                            'Nozomi Networks’ recommendations for TSN protocol '
                            'users.'],
 'threat_actor': ['Iran-Linked Hackers'],
 'title': ['UK Power Plant Cyberattack by Iran-Linked Hackers',
           'Zero-Click AI Chat Data Theft via Cryptographic Exploit',
           'OpenAI Warning on Persistent AI-Driven Cyber Threats',
           'Canada’s SickKids Hospital Data Breach',
           'Critical Flaws in Cisco Secure Workload Software',
           'Leaked AWS Keys Grant Full Corporate Account Control',
           'TSN Protocols Vulnerable to OT Manipulation'],
 'type': ['Cyberattack',
          'Data Theft',
          'AI-Driven Threat',
          'Data Breach',
          'Vulnerability Disclosure',
          'Credential Exposure',
          'Protocol Vulnerability'],
 'vulnerability_exploited': ['AI Safety Filter Bypass via Encrypted Inputs',
                             'Third-Party Software Flaw',
                             'Improper Access Control (CVE-2026-20315, '
                             'CVE-2026-20317), Input Validation '
                             '(CVE-2026-20231, CVE-2026-20318)',
                             'TSN Protocol Weaknesses']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.