Poland Confirms Attack on Wind Farms and Solar Plants

In one of the previous Security Sunday issues, we wrote about the Russian attack on the Polish energy grid. The targets included more than 30 wind and solar farms, heating plants, and industrial facilities. The Polish national team CERT Polska has published a detailed report revealing the scope of the attack and its technical details.
The cyberattack occurred on December 29, 2025, and CERT Polska attributes it to a group known as Static Tundra. Security companies ESET and Dragos independently confirmed with moderate confidence that the Russian hacking group Sandworm, also known as ELECTRUM or APT44, is behind the attack. This group operates under Unit 74455 of the Russian military intelligence agency GRU and has a long history of attacks on energy infrastructure, including power outages in Ukraine.
The attackers used destructive software called DynoWiper. This malware has a purely destructive purpose — it overwrites file contents with random data and then deletes them. According to CERT Polska findings, the malware was launched directly on human-machine interfaces (HMI) connected to control units at the compromised energy farms.
Researchers from ESET identified significant similarities between DynoWiper and the earlier ZOV malware, which was deployed against a Ukrainian energy company in November 2025. Both malware families share characteristic features.
“The attacker gained access to the infrastructure using several accounts that were statically defined in the device configuration and did not have two-factor authentication enabled. The malware used in the incident involving wind and solar farms was launched directly on the HMI machine. In contrast, at the cogeneration plant and the manufacturing company, the malware was distributed in the Active Directory domain via a PowerShell script executed on the domain controller. The attacker used credentials obtained from the local environment to attempt to gain access to cloud services. After identifying credentials for which corresponding accounts existed in the M365 service, the attacker downloaded selected data from services such as Exchange, Teams, and SharePoint. The attacker was particularly interested in files and email messages related to OT network modernization, SCADA systems, and technical work performed within the organizations,” stated Polish CERT.
iOS 26.3 Brings Privacy Revolution: Apple Will Limit Location Tracking by Mobile Carriers
Apple is once again pushing the boundaries of personal data protection. With the upcoming iOS 26.3 update, expected to be released in February 2026, the company introduces a new feature called “Limit Precise Location.” This feature aims to reduce the amount of location data that mobile carriers can obtain when your iPhone connects to their network.
How does it actually work? When your phone connects to cell towers, the carrier obtains information about your location based on signals from surrounding towers. Until now, it was possible to determine your position with street-level accuracy. The new feature in iOS 26.3 will change this. Instead of a precise address, the carrier will only have access to an approximate location at the neighborhood or broader area level.
However, there is a significant limitation. The feature will only be available on devices equipped with Apple’s own C-series modem. Currently, this includes only iPhone Air, iPhone 16e, and iPad Pro with the M5 chip. This means that the vast majority of iPhone users, including owners of iPhone 17, 17 Pro, and 17 Pro Max models, will not receive this protection.
Another obstacle is the need for support from mobile carriers. At launch, the feature will only be available with select providers: Boost Mobile in the USA, Deutsche Telekom in Germany, EE and BT in the United Kingdom, and AIS and True operators in Thailand. Apple expects the list of supported carriers to gradually expand throughout 2026.
Researchers Found 175,000 Unsecured Ollama AI Servers
Researchers from SentinelOne and Censys have released a report identifying more than 175,000 publicly accessible servers running on the open-source Ollama platform that are completely unsecured.
This infrastructure is located in 130 countries worldwide. According to the research, the largest share of systems comes from China, which accounts for approximately 30 percent of all discovered instances. The remaining infrastructure is spread across the United States, Germany, France, South Korea, India, Russia, and other countries.
The situation becomes even more dangerous when we consider the capabilities of these systems. Nearly half of all analyzed servers have tool-calling functionality that allows them to execute code, access external APIs, and interact with other systems. Approximately 22 percent support image processing, and a quarter use models optimized for multi-step reasoning. Researchers from GreyNoise also recorded more than 91,000 attack sessions targeting LLM infrastructure during the period from October 2025 to January 2026, identifying systematic campaigns aimed at mapping and exploiting these vulnerable systems.
Researchers from Pillar Security discovered an operation called Bizarre Bazaar, which represents a sophisticated criminal ecosystem. Attackers systematically scan the internet using tools like Shodan and Censys, search for unsecured endpoints with AI systems, verify their functionality, and then resell the obtained access on illegal marketplaces at discounted prices. In just two weeks, research honeypots captured more than 35,000 attack sessions targeting AI infrastructure.
Critical Vulnerability in WinRAR
The popular archiving program WinRAR has once again become a target of massive exploitation by hacking groups linked to Russia and China.
Google Threat Intelligence Group (GTIG) in its recent report highlighted active exploitation of a critical vulnerability designated as CVE-2025–8088, which allows attackers to execute malicious code on victims’ computers. Although the flaw was patched in July 2025 in WinRAR version 7.13, many users have not yet updated and are becoming easy targets for cyberattacks.
The technical nature of the vulnerability lies in a path traversal flaw that exploits so-called Alternate Data Streams (ADS) in the Windows system. Attackers create malicious RAR archives that, when extracted, write files to arbitrary locations on the computer. The most common target is the Windows Startup folder, where files that are automatically launched at user login are stored. The victim typically sees only a harmless document, such as a PDF, while malicious code is installed in the system in the background.
ESET, the company that discovered and reported this security flaw, stated that as early as July 18, 2025, they observed the RomCom group (also known as CIGAR or UNC4895), which engages in financial attacks and espionage, exploiting this flaw as a zero-day to spread a variant of the SnipBot malware (also known as NESTPACKER).
The widespread exploitation of this flaw is estimated to be the result of a thriving black market where WinRAR exploits are sold for thousands of dollars. One of these vendors, “zeroplayer,” was selling the exploit several weeks before CVE-2025–8088 was disclosed.