1. A UK Power Plant Went Dark for Four Days. Five Agencies Just Confirmed the Bigger Problem.
The Telegraph's report that Iran-linked hackers took a small UK power generator offline for four days in July has since been independently reported by the BBC, The Guardian, and The Independent. UK authorities still haven't confirmed it. Five US agencies just confirmed the broader threat is real.
The Department for Energy Security and Net Zero acknowledges "an incident" at "a small-scale energy generator," with no risk to the wider grid. It does not confirm Iran, the four-day figure, or how the intrusion happened. The National Cyber Security Centre says it hasn't received outage reports through regulated channels, consistent with its standard practice of not discussing individual cases. No facility has been named. What changed since this story first broke isn't official confirmation, it's the byline count: a single exclusive built on anonymous sourcing is now a story three separate national outlets have independently reported. That's a real shift in how seriously to take the claim. It is not the same thing as officials confirming it, and British papers have overstated infrastructure-hack claims before and had officials push back hard.
On August 19, the NSA, CISA, FBI, Department of Energy, and EPA jointly warned, in an advisory they call "not a theoretical risk, an active threat," that attackers are using AI to write exploit code against Siemens S7-series programmable logic controllers, the small industrial computers that run physical equipment inside factories, power plants, and water systems. Attackers scan the open internet with tools like Censys and ZoomEye to find PLCs exposed without protection, then use AI-generated scripts to read and rewrite the controller's own logic, in some cases disguising the tool as ordinary monitoring software. No specific breach has been publicly confirmed. The advisory names six at-risk sectors: critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities.
Whether or not Iran is ever confirmed behind the UK incident, the capability the US government just confirmed, AI writing working exploit code against exposed industrial equipment, doesn't require a nation-state's resources or a zero-day vulnerability. It requires an internet-facing PLC nobody remembered to take offline.