Fast Track Bootcamps
 Crafted For Career-Ready Skills

CyberWatch Weekly: Cyber Frontiers Expand as Tankers, AI, and Infrastructure Fall Under Attack

CyberWatch Weekly: Cyber Frontiers Expand as Tankers, AI, and Infrastructure Fall Under Attack

This week’s incidents show attackers operating well beyond the enterprise network. Federal teams boarded oil tankers in the Gulf of Mexico after foreign actors reached vessel systems at sea. A threat intelligence report documented Russian and Chinese state-linked actors using a commercial AI model for espionage and surveillance at a scale that once needed entire teams. UAE disclosed a serious breach of a government-linked supplier, traced to a single missing patch. Here’s a closer look at this week’s top cybersecurity headlines.

Coast Guard and FBI Board Texas-Bound Oil Tankers After Foreign Actors Reach Vessel Networks

US Coast Guard and FBI personnel boarded two foreign-flagged tankers bound for the United States in August, with the Coast Guard confirming the operations only on 15 September in response to press inquiries. The boarding occurred cause indications showed the vessels’ networks were compromised by foreign cyber actors. Iranian reports confirmed the first ship as the VL Prosperity, a 333-metre Liberian-flagged supertanker carrying roughly 2.3 million barrels toward Galveston. Iran’s Mehr News Agency claimed that attackers reached engine room systems on 7 August near the Strait of Gibraltar, reducing cooling flow, increasing engine speed, and cutting communications for over 30 hours. A team including Coast Guard Cyber Protection Team members and FBI Cyber Action Team operators boarded on 21 August and spent four days examining operational technology and IT systems. A second tanker was boarded three days later, on 24 August. Nothing in either inspection pointed to disrupted operations or crews at risk, and officials have named no one responsible so far, though they are looking closely at whether Iran had a hand in it.

The wider problem, as experts describe it, is that a modern tanker steers, sails and loads through systems that all sit on a network reachable from outside. Getting in does not take much: a WiFi link, an HF radio channel, the satellite connection, or somebody plugging in a USB stick that should never have come aboard. Organisations with maritime exposure should segment vessel OT from IT and treat crew endpoints as an access path.

Source: SecurityWeek, CBS News, ABC News, Bloomberg Law, UNN

Anthropic Report Documents Russian Espionage and Chinese Surveillance Running on Claude

Anthropic’s September 2026 threat intelligence report documents state and non-state actors weaponising Claude, with the central finding that sophisticated attacks no longer require sophisticated attackers. Midnight Blizzard, attributed by the US and UK governments to Russia’s Foreign Intelligence Service, scanned email services and remote access systems across more than two dozen Ukrainian government organisations, targeting ministries, embassies, think tanks, and defence industrial firms, with drone supply chains a recurring theme. Targeting extended to Europe, the Middle East, and maritime-related government agencies in Asia. China-based activity was broader. A religious affairs operation produced Chinese-language dossiers and daily digests on Catholic leaders, Tibetan civil society, Falun Gong practitioners, and Taiwanese Christians, collecting birth dates and immigration histories and mapping venues including floor plans. A municipal cyber police unit ran a sentiment monitoring pipeline querying a government surveillance database, and a state security bureau requested pre-operational venue intelligence for protests in Vancouver, Türkiye, and Oslo. Anthropic disrupted all documented operations.

Experts advise removing long-lived credentials from client applications and enforcing short-lived, scoped tokens with continuous monitoring. Anthropic assesses that more actors will adopt AI frameworks to run faster and larger campaigns.

Source: Kyiv Post, Bitter Winter, Cyber Security News

Hacker Breaches UAE Government-Linked Firm and Demands $5 Million

A hacker who breached a private sector organisation supporting a UAE government sector demanded $5 million and threatened to publish stolen data on the dark web. Speaking at the Arab Media Summit, Dr Mohammed Al Kuwaiti, the head of Cyber Security for the UAE Government, called it one of the most serious attacks the country’s critical infrastructure has faced. The breach came through a vulnerability that the latest software updates had left unaddressed. The attacker claimed to have mapped the organisation’s systems and identified how to navigate them. Cooperation between the private sector and local and international bodies contained the attack and prevented any leak. Al Kuwaiti noted the UAE has faced around 640,000 attacks in a single day across critical infrastructure, electricity, water, and the economy.

Experts stress that patch management remains the highest return control in critical infrastructure, particularly across suppliers holding equivalent access but sitting outside direct oversight. Vendor programmes should verify patch cadence contractually rather than assume it.

Source: Gulf News

Conclusion

Each incident this week bypassed the corporate perimeter entirely. Attackers reached ship systems mid-voyage, state actors ran surveillance at a scale that previously required staffed offices, and a government-linked environment fell to one unpatched supplier. Notably, Midnight Blizzard’s target list included maritime-related government agencies in Asia, a reminder that these are not separate threat pictures.

Stay vigilant and informed, tune in next week for more updates in InfosecTrain’s CyberWatch Weekly!

 

TOP