Threat Brief — 2026-08-11 — OT Breach Vectors and AI Agent Hijacking
Executive summary. Fresh reporting adds technical detail to last year's breach of a Polish CHP plant, revealing the attackers pivoted through a private APN to reach the OT network — a reminder that "private" connectivity is not a security control. Separately, new "GhostJacking" research demonstrates how AI agents can be hijacked by weaponising their own security-alert and blocked-event channels, exposing identity-governance gaps that most organisations haven't begun to address.
Top items
- Polish CHP turbine breach vector detailed — private APN used to reach OT network. BleepingComputer now reports that the attackers who shut down a turbine at a Polish heat-and-power plant (serving ~50,000 residents) gained access by exploiting a private APN connection into the OT network, rather than a traditional internet-exposed system. This is a new technical development in the story first reported on 2026-08-10 by SecurityLab, which attributed the turbine shutdown to Russian hackers. The detail matters because private APNs are widely assumed to provide isolation but often lack authentication or segmentation controls. (src: BleepingComputer)
- "GhostJacking" research exposes identity-governance gaps in AI agents. New research shows attackers can manipulate and hijack AI agents by using security alerts and blocked events as a communication and control channel — effectively turning the agent's own security infrastructure against it. This is a novel attack class that organisations deploying AI agents (customer-service bots, coding assistants, autonomous workflows) are unlikely to have considered. No public exploit noted, but the research implies the technique is reproducible against agents that surface blocked-event details to end-users or logs. (src: DarkReading)
Themes
Expanding attack surface beyond the obvious. Both items highlight threats through channels presumed safe — a private APN for OT access, and security-alert mechanisms for AI agents. Organisations should audit "trusted" connectivity paths and AI agent feedback loops with the same rigour applied to public-facing systems.
