Today’s stories share a common thread: the exposure window is rarely as short as the headline suggests. A power plant knocked offline for days turns out to be a “proof of concept” rather than the main event, a perimeter VPN bug sits unexploited today but won’t stay that way, and a hospital breach traces personal data back nearly a decade. Here’s what’s new since yesterday’s digest.
OT watch: Iran-linked hackers force a small UK power plant offline for four consecutive days
A cyberattack attributed to threat actors linked to Iran forced a small-scale British power generation facility offline for four straight days last month, in what officials describe as the first time an Iran-affiliated group has successfully shut down a piece of UK energy infrastructure. First reported by The Telegraph, the incident did not put the broader national grid at risk — the affected site was a limited-capacity generator, not a transmission-level asset — but officials assess the attackers’ goal wasn’t disruption at scale so much as a demonstration that groups linked to Iran’s Islamic Revolutionary Guard Corps can reach into UK infrastructure and switch it off at will. The timing is notable: the disclosure comes shortly after the UK granted the United States permission to launch defensive military operations against Iran from British bases, raising the likelihood that the intrusion was a calculated signal rather than an opportunistic hit. The Telegraph via RedState · Israel Hayom
A “proof of concept” framing from officials shouldn’t read as reassurance — it means the same access could be aimed at a higher-value target with the same techniques next time. If your organization operates or monitors OT/ICS environments tied to power generation or distribution, even at small scale, this is a fair prompt to confirm remote-access paths into control systems are inventoried and monitored, not just assumed to be air-gapped.
Vulnerability watch: A CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway needs no credentials to exploit
Citrix disclosed CVE-2026-19490 (CWE-288, authentication bypass using an alternate path), a critical flaw affecting NetScaler ADC and NetScaler Gateway when configured as a Gateway — covering SSL VPN, ICA Proxy, CVPN, or RDP Proxy — or as an AAA virtual server. Rather than exploiting a weak password or stolen token, an attacker reaches an alternate authentication path that bypasses the controls the configuration is supposed to enforce, remotely and without any credentials or user interaction. On older vulnerable builds, a Gateway or AAA configuration alone is enough to be exposed; newer vulnerable builds additionally require a configured SAML action. Affected versions include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus the corresponding FIPS and NDcPP builds. As of Rapid7’s latest analysis, no in-the-wild exploitation has been confirmed, but researchers note that Citrix’s remote-access products are consistently high-value, fast-moving targets once a bypass like this becomes public. Help Net Security · The Hacker News
NetScaler appliances sit directly on the perimeter, which is exactly why authentication-bypass bugs in them move from disclosure to mass exploitation faster than almost any other product category. If you run NetScaler ADC or Gateway configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA authentication, patch to 14.1-73.32 / 13.1-63.21 or later now rather than waiting for confirmed exploitation — by the time that shows up, scanning is usually already underway.
Breach watch: A third-party software flaw exposes SickKids Hospital employee and applicant data reaching back to 2016
The Hospital for Sick Children (SickKids) in Toronto disclosed that a vulnerability in a third-party software application — used by SickKids and other unnamed organizations — exposed personal information belonging to current and former staff, job applicants, and employees of Boomerang Health and the SickKids Foundation. Patient data was not affected. The compromised system supported the hospital’s careers website and certain HR functions, including payroll; SickKids says the intrusion was first identified on July 9, and its notification letters indicate individuals who were part of its workforce between December 12, 2016 and August 31, 2018 may have had sensitive personal information exposed on the affected system. The hospital is offering 24 months of complimentary credit monitoring and identity-protection services to those affected. BleepingComputer · The Record
A near-decade-old employment window turning up in a 2026 breach notice is a reminder that HR and recruiting systems tend to retain records far longer than anyone tracks, and third-party vendors managing them inherit that same long tail of exposure. If your organization outsources careers-site or payroll-adjacent HR functions to a third party, it’s worth confirming how long that vendor retains historical employee and applicant records, and whether their breach-notification process would actually catch you if the exposure predates your own current staff.
Also noted: CISA, FBI, and HHS update the Medusa ransomware advisory to 500+ confirmed victims
A joint update from the FBI, CISA, and the Department of Health and Human Services, drawing on investigations conducted as recently as April 2026, confirms the Medusa ransomware-as-a-service operation has now hit more than 500 organizations since it first appeared in June 2021. Victims span healthcare, defense, manufacturing, government services, IT, and financial services, with additional hits in education, insurance, and law. The advisory reiterates Medusa’s now-familiar double-extortion playbook — initial access via known vulnerabilities or compromised credentials, followed by encryption and data theft with payment demanded to avoid both. Help Net Security · Infosecurity Magazine
Medusa’s victim count crossing 500 across five years is less a single incident to react to than a standing reminder to check the advisory’s published indicators and TTPs against your own detection coverage, particularly if you sit in one of the sectors named above.
Final thought
Every story today has a longer tail than its headline: a power plant outage that reads as a warning shot rather than the real target, a perimeter bug still waiting for its first confirmed exploit, and a breach notice reaching back to employment records from 2016. The operational lesson is the same each time — assume the exposure window is wider than the first report suggests, and make sure your own logging and vendor oversight go back far enough to answer for it. If you want help sizing up how far back your own visibility actually reaches, see our how-to guides or book a discovery call.