Weekly Security Sprint EP 171. Cyber Conflicts and Critical Infrastructure, New Reports, and Crime Statistics

August 25, 2026

Please enjoy our latest podcast, the weekly Security Sprint, on Spotify, Apple, as well as other locations accessible via the Spotify for Podcasters link or wherever you listen to your favorite podcasts.

In this week’s Security Sprint, Dave and Andy discuss the above topics and quarterly reports, ransomware, the weather, and much more.

Opening:

Main Topics

Iran-linked hackers blamed for cyber-attack that shut down UK power plant — The Guardian — 23 Aug 2026. Hackers linked to Iran have been blamed for a cyberattack that temporarily shut down a small-scale power generator in the United Kingdom. The UK government said the incident did not threaten the wider energy system, but reporting characterized it as an apparent escalation amid tensions between Tehran and London following UK support for U.S. military operations. The incident demonstrates how geopolitical conflict can extend into cyber operations against civilian infrastructure without requiring effects at national scale. Energy operators and other critical infrastructure organizations should consider the potential for politically motivated cyber activity to target individual facilities as part of broader state-linked pressure campaigns. 

Cyber Threats in Times of Conflict — Emsisoft — 17 Aug 2026. Emsisoft assesses that events in Ukraine, Venezuela, and the continuing Iran conflict demonstrate that cyber operations have become a routine component of modern conflict, but cautions against assuming every disruption represents a sophisticated state cyberattack or that cyber operations will replace conventional warfare. The Iran experience is particularly instructive, with Iranian-linked actors conducting disruptive operations against companies and infrastructure while targeting internet-facing operational technology, illustrating how cyber activity can broaden a conventional conflict geographically and operationally without producing a single decisive cyber event. 

What if America Went Completely Dark? — The New York Times Magazine — 18 Aug 2026. The New York Times examines the potential consequences of a prolonged nationwide electric-grid failure and emphasizes how quickly an electricity crisis would cascade into communications, water and wastewater, fuel distribution, healthcare, transportation, food supply, finance, public safety, and other essential services. Modern infrastructure is deeply interdependent, meaning backup generators and individual continuity plans can provide temporary resilience but eventually fail when fuel, telecommunications, logistics, staffing, and supply chains are themselves disrupted. A sufficiently prolonged outage would therefore become far more than a utility incident, producing cascading failures that could overwhelm normal emergency-management structures and require difficult decisions about prioritizing limited resources and restoring interconnected systems in the correct sequence. The scenario is an exceptional example of convergence and potential Blended Threat consequences because the initiating event could be cyber, physical, technological, natural, or deliberate while its effects rapidly propagate across virtually every operational domain. The central preparedness implication is that organizations should examine not simply whether they possess backup power, but how long they can sustain mission-essential functions when electricity, communications, fuel, water, transportation, vendors, personnel, and public services fail simultaneously or sequentially. Senators introduce bipartisan Quantum-GUARD Act to boost US electric grid against emerging quantum cyber threats

Quarterly Threat Report: Second Quarter, 2026 — Beazley Security — 18 Aug 2026. Beazley Security reports that vulnerability disclosures increased dramatically during the second quarter as agentic AI accelerated vulnerability research, yet confirmed exploitation grew at a substantially slower rate and the fundamental paths attackers used to enter organizations changed very little. The report finds that compromised credentials against exposed VPN and remote desktop services remained the dominant ransomware entry method, while supply-chain attacks, infostealers, device-code abuse, and data-theft-only extortion continued to complicate defense. 

CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa RansomwareThe Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) released an update to the joint Cybersecurity Advisory #StopRansomware: Medusa Ransomware. The advisory is part of an ongoing series detailing ransomware variants and threat actors. It provides technical details on Medusa ransomware activity, along with detection and mitigation guidance to help protect at-risk government and critical infrastructure organizations. Medusa is a ransomware-as-a-service variant first identified in June 2021. As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Other victims include organizations in the medical, education, legal, insurance, technology, and manufacturing industries. 

FBI: 2025 had biggest violent-crime drop in 90 years — Axios — 18 Aug 2026. FBI data shows that U.S. violent crime fell sharply in 2025, producing the largest annual decline since the bureau began publishing national estimates in 1936. The decline was broad across communities of different sizes and was accompanied by substantial reductions in property crime, motor vehicle theft, burglary, and larceny. The national figures remain statistical estimates because the FBI accounts for incomplete reporting, and the breadth of the decline makes attributing the trend to any single administration, policing strategy, or policy difficult. The data provides important context for public-safety planning and threat assessments by showing that high-profile incidents and localized problems can coexist with a substantially improving national crime environment. Alcohol, AI and aging: Theories on why violent crime is down

Severe Weather: And Get Ready for Winter Weather!

Quick Hits:

Read more about Gate 15’s full podcast menu at our Podcast page. You can subscribe and enjoy all the Gate 15 Podcasts on Spotify for PodcastersAppleSpotify, as well as other locations accessible from the Spotify for Podcasters link. Week-to-week, you can hear and learn more about our all-hazards threats, risks, mitigation and other issues impacting homeland security risk management from our team as well as our regular and special guests. The full podcast menu includes:

  • The Security Sprint is our weekly rundown of the week’s notable all-hazards security news, risks and threats and some of the key focus areas for organizations to consider behind the headlines. Gate 15 team members discuss physical security, cybersecurity, natural hazards, health threats and other issues across our environment.
  • Nerd Out! Security Panel Discussion, moderated by Dave Pounder, focuses on physical security topics including terrorism, extremism, hostile events, and other pertinent topics.
  • The Gate 15 Interview, is a monthly interview between Gate 15’s founder and Managing Director, Andy Jabbour and guests from throughout the homeland security risk management community addressing a wide range of all-hazards topics and issues.
  • The Cybersecurity Evangelist, with Jennifer Lyn Walker, is a cybersecurity-focused discussion with Jen and invited guests. This is presently a Gate 15 special podcast and occasionally is updated on our Gate 15 podcast channel.
  • Venue Security, The IAVM Podcast Series was a 2024 limited series podcast as Gate 15’s founder and Managing Director, Andy Jabbour hosted a series of short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
  • The Risk Roundtable, was a monthly discussion among our team and occasional guests exploring the all-hazards threats and risks impacting the United States and internationally. This was suspended in September 2023.

We hope you’ll subscribe, listen and share your ideas and other feedback! Reach out to us on BlueskyLinkedIn, via email at Gate15@gate15.global.

Previous Podcasts