As a Disney content creator, Toni Kulusich posts meet-and-greet videos with lots of different Disneyland theme park characters. But her favorite is Peter Pan.
A hugely popular character in the Disney parks, Peter Pan has a large internet fan base and is beloved for his spontaneity and playful interactions with guests as well as his sharp-tongued, often bratty personality. Kulusich, a 27-year-old Los Angeles native who goes to Disneyland about once a week on her annual pass, loves making videos of herself with Peter, posting videos of herself playing tag with him or skipping around the parks.
Kulusich, who uses her middle name online for privacy reasons, never thought there was anything problematic about her Peter Pan content until August 2, when she saw that a video in which she’d gifted Peter a crocheted duck keychain was getting a lot of attention. As the views grew from 10,000 to a million, the negative comments started to pile up. “Slice that duck open and make sure there’s no AirTag inside,” one commenter wrote. “Imagine being known for being the creep that follows Peter Pan around,” another said. As the controversy unfolded, her TikTok following more than doubled, from about 50,000 followers to 125,000.
Kulusich was surprised. She knows about the internet’s antipathy toward so-called “Disney adults,” or people obsessed with the Disney movies and theme parks, with many accusing them of being self-indulgent, overgrown children. But she also doesn’t think her Disney fandom has crept into the rest of her life in an unhealthy way. She has a husband of four years and a full-time job as the manager of a big-box retail store. She has no formal affiliation with the brand and just makes Disney content as a hobby. “It’s not like I’m going to the store or to my job and thinking about Peter Pan,” she says. “It’s just that when I’m inside Disney, I’m able to release my inner child and the kid who doesn’t want to grow up. And that’s what [Peter Pan] stands for.”
Advertisement
But that’s not what the people combing through her Instagram and TikTok accounts thought. They unearthed 10-year-old videos of her meeting Peter at Disneyland as supposed evidence of her obsession, even circulating a Change.org petition to have her banned from the parks. They analyzed Peter Pan’s body language in the videos, saying it reflected his discomfort with her; they commented on her wedding video and expressed sympathy for her husband, accusing Kulusich of secretly being in love with Peter Pan. (Kulusich’s husband, a marine, is a more casual Disney fan but is “really supportive” of her content, she says, though he prefers Cars’ Lightning McQueen to Peter Pan.)
Worst of all, Kulusich says, someone figured out where she works and posted the address, prompting her manager to change her hours for security reasons.
“It’s definitely taken a toll on my mental health,” she says. “Imagine waking up to thousands of comments saying you’re a crazy stalker lady every single day.”
By the end of last week, Kulusich was known worldwide as the deranged “Peter Pan Girl,” the Baby Reindeer of the Disney influencer ecosystem (a reference to Netflix’s 2024 black comedy series about a Scottish comedian’s stalker). “People really just took a five-second video of me with Peter Pan out of context and ran with it,” she says.
Advertisement
The internet obsession with “Peter Pan Girl” touches on a few different internet culture flash points: the rapid spread of social media misinformation, the hysterical nature of TikTok armchair analysis and dogpiling, and of course, the widespread loathing of Disney adults.
from the millions-gone-just-because-no-adults-were-in-the-room dept
Sure, the town’s insurance will pay most of this, but it’s probably fair to say most of this small county’s population (11,823 at last count) wasn’t supportive of local law enforcement’s decision to violate as much of the First Amendment and Fourth Amendment as possible in the apparent hopes of making one local business owner happy.
The backstory is long and convoluted. It involves a local business owner who wanted a liquor license (but had been cited/arrested from drunk driving), her estranged spouse (who shared some documents with Marion County Record reporters), a local attorney who just wasn’t up to the job, a police chief who was far too friendly with the business owner, and a bunch of other law enforcement agencies that pitched in with the constitutional violations just because. And all of that is on top of then-police chief Cody’s animus towards the paper, due to its reporting on his past misconduct.
There’s Kari Newell, a local business person who was seeking a liquor license for a new business when her previous drunk-driving record became public. There’s County Attorney Joel Ensey, who claimed to have no knowledge of the raid until public records showed he actually knew plenty about it beforehand. There’s the Kansas Bureau of Investigation, which also disavowed all knowledge, until it became clear it had knowledge as well, at which point it began publicly condemning Chief Cody and his department. There’s the mayor who didn’t like his deputy mayor and seemed to be all too willing to indulge the police chief. There’s the judge who signed off on the search warrants without reading them and then tried to distance herself from actions — a judge who apparently had some drunk driving problems of her own. There are the communications Chief Cody made to Kari Newell, informing her he was going to raid the newspaper to shut down its coverage of her and, presumably, any further investigation into his law enforcement past. In the middle of all of this, there’s some bullshit computer crime charges, which were invoked despite the newspaper accessing driver record data legally through a third party.
Following the raids — that’s right, raids — multiple lawsuits were filed. Not only did the Marion County PD (under the leadership of Gideon Cody, whose past misconduct was being examined by the local paper) talk a local court into blessing its raid of the newspaper’s office, it also raided the home of the paper’s owner, 98-year-old Joan Meyer, who died less than 48 hours after the raid.
Advertisement
Pretty much every lawsuit filed by the victims of these raids has paid out. Last November, the county agreed to pay $3 million to three of the affected journalists and one of the town’s city council members, who was also subjected to an illegal raid by local officers.
That large settlement followed a $235,000 settlement the town agreed to pay to Marion County reporter Deb Gruver, whose computer was seized along with her personal cell phone by local law enforcement officers.
That brings the total to $3,235,000 (at minimum!). The latest settlement — one that will be paid to another of the paper’s reporters — now means county residents will be asked to contribute to a tab that has now surpassed the $4 million mark:
Phyllis Zorn, the reporter whose acts of journalism served as an excuse for the August 2023 police raid of the Marion County Record, will get $850,000 from the city of Marion to settle her federal lawsuit over the raid.
This is the sort of thing that should make all good Americans yank on their imaginary suspenders and get their rural lawyer shtick on. We should — as a unified drawl — make it clear that we, as the collective “small town lawyer,” think this is some disturbing bullshit. And we should fervently argue in favor of large settlements, even if we know this just means our fellow Americans will be asked to give a little more the next time the budget’s on the agenda.
Advertisement
While I do think its sucks that the public has to pay the price for government malfeasance, things like this encourage more people to vote with their wallets. That doesn’t mean funneling money into some PAC. That means protecting your earnings by expelling the people who were on board with these blatant violations of constitutional rights. And Marion County residents aren’t done paying for the perverse acts of prosecutors, law enforcement, and the mayor who had the cops’ back all the way through this debacle:
The county government is making things right. That it’s doing this with other people’s money doesn’t mean the settlements are meaningless. We, the people, should simply rejoice in our magnanimous nature. Even though we’re getting fucked, we can at least take heart in the fact that we were invited to the climax.
Peacock is raising prices across all three of its subscription plans.
New customers will pay more immediately, while existing subscribers will see the higher rates on bills from September 17.
The ad-supported Peacock Premium plan is increasing from $11 to $13 per month. Premium Plus is going from $17 to $20. The Select plan, which offers a more limited selection of programming, is also going up from $8 to $9 per month.
Annual subscriptions are getting more expensive too. Peacock Premium will now cost $130 a year, up from $110, while Premium Plus rises from $170 to $200. Select is increasing from $80 to $90 annually.
Advertisement
The latest increase comes after Peacock also raised prices in 2025, though the timing is particularly notable. The new rates are arriving just as Peacock heads into a busy period for live sports.
Advertisement
Peacock carries Sunday Night Football, the full NBA broadcast schedule, MLB and WNBA coverage, alongside the English Premier League. The new prices take effect just before the Premier League season gets underway. The NFL regular season is also fast approaching, and the 2026-2027 NBA season is due to begin in October.
The service is also leaning on its wider entertainment catalogue to justify the higher cost. Subscribers can watch shows including Love Island USA, The Traitors, Yellowstone, The Real Housewives and Law & Order, alongside films such as Wicked, Obsession and The Super Mario Galaxy Movie.
Advertisement
There are also more releases on the way. These include Line of Fire, The Traitors: New Blood and Crystal Lake, a Friday the 13th prequel series.
For anyone already subscribed to Peacock, there is at least some breathing room before the increase appears. Existing customers won’t see the new pricing on their bills until September 17 or later. Meanwhile, new subscribers will pay the higher rates immediately.
Sonos has finally added Live Activities support to its iPhone app.
The new feature, rolling out to iPhone users now, gives users quicker access to playback controls without having to reopen the app. The feature appears on the Lock Screen after you start playing audio on a Sonos device and leave the app.
Once active, the Live Activity shows the room or group that was last playing audio, along with controls for playing, pausing and skipping tracks. This means you can make basic playback changes directly from the Lock Screen.
The feature also works when playback is started outside the Sonos app. Sonos says the controls will still appear when audio is initiated through Direct Control from supported services. They also work with Bluetooth or AirPlay. This gives the Live Activity a little more flexibility than simply acting as an extension of the app.
Advertisement
There are some limitations at launch, though. Album artwork isn’t currently displayed in the Live Activity. Sonos says it is looking into other ways to improve the Lock Screen experience, so there is every chance that this could change in a future update.
Advertisement
Sonos also confirmed that Live Activities work with Apple Watch and CarPlay. However, the playback controls aren’t currently supported on either platform. That makes the iPhone Lock Screen the main place where the new feature is useful for now.
Live Activities have become a handy way of keeping information from apps accessible without constantly opening them. Therefore, the addition is a welcome one for Sonos users. It’s also a surprisingly basic feature to be arriving only now, given how useful quick playback controls can be when listening around the house.
Advertisement
Sonos itself described the addition as a “much-requested, anticipated, and needed feature,” so it seems the company is well aware that this has been a long time coming.
Your desk or bench is a work area, so why not make it look the part? That’s the idea behind the miniature blinking traffic barrels that [Glen Akins] recently put together. Of course, just a single blinking light doesn’t really sell the idea of a busy construction zone, so he spent a somewhat surprising amount of time and effort optimizing the design for small-scale production.
The end result is a fascinating write-up that dives into the design decisions [Glen] made. Every aspect of this project, from the overhang of the “handle” on the 3D printed barrel to the number of passive components on the PCB was carefully considered. Critics may say [Glen] put too much thought into something that didn’t need to be so complex, but projects like these are an excellent way to keep your skills sharp — there’s no such thing as practicing too much.
Starting with the design of the barrel itself, we appreciate that [Glen] kept the capabilities of his desktop 3D printer in mind. By breaking the design up into multiple pieces and avoiding overly steep angles, he produced a design that prints cleanly without the need for support material. His step-by-step documentation and screenshots also serve as a great introduction to designing parts in Fusion if that’s something you’re interested in.
From there, things switch over to the electronics. Some in the audience will bemoan that he’s using a PIC12F1612 microcontroller to blink a single LED instead of a 555, but [Glen] brought the receipts on this one. Not only does the PIC offer more flexibility in terms of getting the blinking to look the way he wants, but it requires fewer passive components on the board and is considerably more energy efficient than the iconic timer IC. Even if you ignore all the other advantages, he calculates that going with a 555 would have cut the battery life of the finished product by approximately 15%.
This is one of those projects that’s difficult to summarize in such a terse format, as every time you think the write-up must be about over it takes a new turn on you. We were mildly bemused when the second iteration of the PCB popped up, but by the time he introduced the custom programming adapter board, we knew [Glen] wasn’t messing around.
Public TV channel sues Iron Mountain data center after its cloud storage vendor goes out of business, losing over 70 years of archival materials and programming
Nine PBS in St. Louis sues to recover roughly 50 terabytes of archive spanning seven decades after cloud vendor Open Source Storage went defunct and cut off access on the day its contract expired
Iron Mountain says it never had access to the data, arguing it rents physical space to OSS and that handing over a third party’s hardware would have breached its contracts and exposed other clients’ data
A Denver judge has since ruled that Nine PBS owns the material and ordered cooperation on retrieval within 30 days
Nine PBS, the public television station in St. Louis, has sued Iron Mountain Data Centers in Denver District Court, seeking the return of roughly 50 terabytes of archival material sitting in a Denver facility.
This move was necessitated by its contracted cloud storage provider, Open Source Storage (OSS), which quietly went defunct earlier in 2026.
The legal brief has since prompted District Court Judge Eric Elliff to rule that Nine PBS is the rightful owner of the materials and is entitled to recover them, and to order Iron Mountain to cooperate in every way it can with the retrieval.
Latest Videos FromTechRadar
Advertisement
How did a station lose its own archive of data?
Nine PBS’s relationship with what it calls the predecessor of Open Source Storage began in 2019, when it entered into a contract with the latter to supply hardware, software, and cloud storage services for the station’s archival materials.
The contract was renewed annually, first with its predecessor and then with OSS itself, until recently, when it tried to arrange a meeting to renew the contract for 2026. OSS did not respond, nor did it indicate any intention to end the arrangement.
The agreement was due to expire on March 6th, and the contract essentially allowed PBS an additional 30 days to retrieve its data after termination. However, when access was cut off, PBS received no response or path to access its data. Instead, when looking for an explanation, it found out that the OSS website no longer existed and that the company had a delinquency status with the Colorado Secretary of State.
Further digging helped the TV station find a link to Iron Mountain, and on March 13, Nine PBS sent a demand letter asking the data center operator to preserve and return its material, offering to cover any reasonable costs incurred. Iron Mountain neither confirmed nor denied that it held any of the material.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Nine PBS sued OSS and its president Charles Wells in St. Louis Circuit Court on April 16, then paused the case when a man named James Tramel, described as a managing partner of the group that had acquired OSS’s assets, confirmed the data was safe in Iron Mountain’s Denver facility.
Advertisement
Tramel corresponded with the station for about a month, then stopped. An automatic reply from his account later said he was no longer affiliated with OSS. On a subsequent call, according to the complaint, Tramel said he had been defrauded into buying the company.
A data custody issue with multiple players involved
With no one at OSS responding, Nine PBS returned to the St. Louis court and won a default judgment establishing that it owned the data, had an immediate right to possess it, and that OSS had to return it or facilitate its transfer to a new vendor. This was not particularly effective: asking a company that refuses to pick up the phone to honor a judgment is impractical, and the station was forced to file again in Denver, where the data was hosted.
Iron Mountain told Current it never had access to the data. Its position is that it supplies physical infrastructure, meaning the building, network connectivity, power, and environmental controls, while customers rent space for their own servers and hardware. Those machines are the client’s assets, and in this case the client was OSS, not Nine PBS. The contention is essentially the equivalent of a landlord not being responsible for the contents of a tenant’s filing cabinet, even when the tenant vanishes.
The order Nine PBS secured from a judge in the second case states that it must identify a third-party vendor, potentially a former OSS employee, who can access and retrieve the data from the infrastructure inside Iron Mountain’s facility, and it has 30 days to do so.
The station will pay Iron Mountain current and past-due storage fees dating from when OSS stopped paying its own bills. Return any physical devices holding the data immediately once access is granted, and it must ensure that no other OSS customer’s data is retrieved or compromised as a result.
The material at stake includes the station’s coverage of the history of East St. Louis, the COVID-19 pandemic, and the Great Flood of 1993; Nine PBS vice president and chief content officer Leah Freeman puts the span at approximately 70 years of the organization’s history.
Advertisement
Whether the legal battle that Nine PBS had to endure is worth it, skipping an easy-to-set-up NAS server with relatively inexpensive drives at its own premises is an interesting question and one that it is sure to be asking itself, as it has yet to be provided access to its own archives at the time of writing.
CEO apologizes for police misuse as activists call for vandal action against license plate cameras
Surveillance tech company Flock has struggled with its public image for years, but the problem has become particularly acute in recent weeks.
Its network of ALPRs has long attracted criticism over mass surveillance and the retention of location data belonging to motorists who are not suspected of any offense.
Advertisement
Days after its CEO apologized for documented abuses of the company’s system, The Register contacted the company’s usually responsive media team about an online campaign calling for its automated license plate readers (ALPRs) to be vandalized on Halloween, and received an automated response.
“Thanks for reaching out to Flock. Our media team is currently touching grass and taking a break,” the email said.
“Unlike our cameras, we can’t work 24/7, so we’ll get back to you when we’ve had a snack and regained the ability to form coherent sentences.”
This week, US social media users began promoting Halloween 2026 as a night of action against Flock’s ALPRs, which continue to attract negative coverage.
X grouped posts about the so-called “De-Flock America” campaign into a dedicated trending story, which recorded more than 36,500 posts over two days. Similar calls have appeared on other major social platforms.
Posts encourage participants to wear costumes, leave their smartphones at home, and disable nearby ALPRs while concealing their identities.
The Reg asked Flock whether it was aware of the campaign and planned any countermeasures, but received only the automated response.
Advertisement
Apologies and changes
Last week, Flock CEO Garrett Langley apologized after a woman was stalked using his company’s ALPR system.
“It kills me that she went through that,” he told CBS News in an interview, less than two weeks after The Washington Post published a story highlighting 46 cases involving US police officers abusing their access to Flock’s system. Some allegedly involved officers abusing that power to stalk women.
Langley gave the interview after Flock announced an array of changes, including reducing its standard data retention period from 30 days to seven.
Customers may retain information for longer, however. A new “Evidence Mode” allows law enforcement to retain data beyond that seven-day period if it’s required for ongoing casework.
Advertisement
Flock also introduced controls allowing police agencies to restrict the types of searches that outside forces can run against their data.
For example, City A might request permission to search data belonging to City B as part of an investigation. With the new feature, City B can restrict City A from making searches related to “immigration enforcement,” a nod to ICE agents accessing police Flock systems without a dedicated contract.
Flock will also require customers to enable its existing Audit Assistance feature by year-end. The tool detects unusual search activity and flags it for review. It is currently optional but will become mandatory by year-end, having been “associated with arrests of several law enforcement officers who allegedly abused the system.”
Flock said more than a third of customers have voluntarily opted in to Audit Assistance so far.
Advertisement
Langley’s interview appeared one day after People reported that Haines City police officer Christopher Goodson, 31, allegedly used Flock to search for his estranged wife’s license plate 717 times. The searches took place between September 1, 2024, and June 30, 2026, according to a probable cause affidavit.
Goodson was suspended with pay pending further investigation. ®
Consumer group sees improvements on paper but warns the devil remains in the detail
Apple’s latest attempt to settle its App Store dispute with the European Commission has drawn criticism from Epic Games and a cautious response from a consumer group, which warned that “the devil is in the detail.”
Announced on August 18, the changes introduce new business terms for applications distributed in the European Union. Apple says the changes “reduce complexity by moving every developer that distributes apps in the EU to a single set of business terms” and resolve its long-running spat with the Commission over fees and alternative distribution.
Advertisement
An App Store app using Apple In-App Purchase will attract a 26 percent commission, reduced to 15 percent for developers in qualifying programs and auto-renewing subscriptions after their first year. The rate for apps using alternative payment processing will be 20 percent, or 10 percent for qualifying developers. Apps linking to the web to complete purchases will incur a 15 percent commission, again reduced to 10 percent for qualifying developers. Apps distributed through an alternative marketplace or the web will pay Apple a 5 percent “Core Technology Commission” on digital transactions.
The structure is simpler than Apple’s previous terms, which were revised after the company was slapped with a €500 million fine. Complaints about Apple’s antics continued through the end of 2025 amid accusations that the company was persisting in non-compliance with the Digital Markets Act (DMA).
Apple claims the changes follow “close collaboration with the European Commission” and “resolve Apple’s disagreements with the Commission over business terms and alternative distribution.”
Naturally, there was plenty of hand-wringing and “think of the children” rhetoric from the iPhone slinger. The company would obviously prefer users to stick with Apple In-App Purchase, calling it “the safest, most trusted way for users to purchase and download apps and make seamless and secure payments in those apps.” It also noted that it had worked with the Commission on child safety measures for alternative payments, including parental gates and restrictions on links from apps aimed at children.
Advertisement
Epic Games, a longstanding critic of Apple’s App Store practices, called the scheme “junk fees,” adding that the plan did “nothing to open up the mobile app ecosystem to competition, as required by Digital Markets Act.”
“The law makes it clear that Apple must allow developers to offer link outs to the web for purchases ‘free of charge’ and has to allow ‘effective use’ of competing stores,” the company wrote.
The European Consumer Organisation (BEUC), an umbrella group representing 42 independent consumer organizations across 31 countries, was also cautious.
Sébastien Pant, the group’s senior officer for competition and digital enforcement, wrote: “On paper, there seem to be some improvements with a simpler and lower fee structure. But it remains to be seen if these commitments will satisfy app developers who will, in any case, pass on the fees to consumers.
Advertisement
“We also need to see the full user flow to see if consumers will truly benefit. For example, will consumers be able to easily conclude contracts with app developers on iPhones outside the App Store without having scare screens displayed? Will it be possible to easily download and use alternative app stores on iPhones and iPads without the artificial friction Apple deliberately created?
“Also, we must remember this is not a gift Apple is giving consumers, but something they are required to do so by EU law. It might be a cliché, but the devil is in the detail!”
Developers can sign the new terms immediately, with the changes taking effect on October 1. ®
Nurosym’s report highlights how Irish employees may be struggling to let the stress of the workday go, once the day is done.
Medical device company Nurosym has published data identifying a potential “hidden stress window” for Irish employees, who may find that their daily commute is adding extra strain onto their workday, frequently.
The organisation collected information from 1,000 Ireland-based employees across the month of July and what stood out was that worsening congestion in Dublin is leading to employees losing a significant number of hours each year in the daily commute. Findings suggest that drivers are estimated to have lost an average of 95 hours to traffic during 2025.
More than two-thirds (68pc) of those who participated in the research found that they arrive home drained at least once during the week and 56pc explained that it takes at least an hour or longer for them to finally relax. Some find they have to check back into work, with 82pc of contributors stating that they look at work messages after hours.
Advertisement
“Commuting is usually quantified as time lost, but from a physiological standpoint, it is better understood as one contributor to a sustained allostatic load,” explained Dr Elisabetta Burchi, the head of research at Nurosym.
She added: “Urban environments impose near-continuous demand on the autonomic nervous system; noise, crowding, artificial light and the vigilance required by unpredictable conditions all recruit sympathetic activity.
“When a congested journey follows a cognitively demanding day, these inputs summate rather than resolve. The result is that sympathetic tone can remain elevated after arrival home, with the parasympathetic recovery that would normally follow a stressor delayed or incomplete.”
No place like home
Nurosym’s report found that the problem is most pronounced in the Dublin area, where nearly three-quarters (73pc) of employees arrive home feeling stressed or mentally drained at least once a week. This was followed by the south-west at 71pc, the border and midland regions at 68pc and the west at 67pc.
Advertisement
The Dublin-based workforce was also found to be the cohort most likely to be digitally connected after hours, with 87pc admitting that they scan their emails and messages outside of regular working hours. More than 40pc of those who contributed said this is a daily activity.
One in five Dublin respondents said their commute makes it more difficult to unwind, compared with one in six nationally.
Looking more closely at gender-based figures, participating men were found to be more likely to remain connected to their jobs, with 85pc checking work messages outside their normal hours, compared with 78pc of women.
Clear lines
Burchi had a number of suggestions for professionals looking to maximise their time so that there is more of a healthy disconnect between working hours and personal hours.
Advertisement
She stated employees should create a consistent transition between work and home that can help signal to the body that the demands of the day have ended.
“Where you can, deal with final messages before the journey home, then switch off work notifications for the evening,” she said. “After-hours checking keeps attention oriented to the next task and delays the point at which arousal can begin to subside.
“Try not to move straight from the commute into other commitments. Even five or 10 quiet minutes creates the recovery interval that allows autonomic activity to settle before the next demand begins.”
Burchi is also of the opinion that some mindfulness tasks can alleviate pressure and she advised slowing down your breathing, engaging in breathing exercises once safely at home and using movement to release excess energy.
Advertisement
“A short walk or gentle stretching can create a physical transition out of work mode. This may be particularly helpful for people who have spent much of their day sitting at a desk or in a car.”
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
CISA says the Medusa ransomware operation has breached more than 500 U.S. critical infrastructure organizations since 2021, up from more than 300 reported last year. The group has targeted healthcare, government, defense, manufacturing, IT and financial organizations, evolving into a ransomware-as-a-service operation that recruits initial-access brokers and uses stolen data to pressure victims into paying. BleepingComputer reports: The three federal agencies recommended that network defenders secure their networks against the ransomware group’s attacks by mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts. Security teams are also advised to segment networks to block lateral movement after compromise and to block access from untrusted origins to remote services on internal systems.
[…] “Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to potential victims,” the advisory says. “Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa.”
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.
PLCs are industrial computers used to automate and control machinery and physical processes in factories and other critical infrastructure.
The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued the joint advisory Wednesday, saying the attacks are ongoing.
“This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs),” reads the advisory.
“However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems.”
Advertisement
The critical infrastructure sectors most targeted include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies also note that Siemens S7 PLCs are used in the Defense Industrial Base, which could also be targeted.
Threat actors are using internet scanning services, including Censys and ZoomEye, to find exposed Siemens PLCs and exploit critical and high-severity vulnerabilities, outdated software, and weak authentication.
The advisory says the attackers are using artificial intelligence to develop Python exploitation scripts that use the ‘snap7.dll’ and ‘python-snap7’ libraries to communicate with Siemens S7 PLC devices.
These custom tools are disguised as legitimate OT monitoring software and can provide read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol.
Advertisement
The agencies say the activity appears focused on persistent reconnaissance, potentially preparing attackers for disruption to critical infrastructure, including stealing sensitive data, damaging equipment, causing extended downtime, or leading to safety incidents.
The actively targeted devices include Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs.
Organizations are urged to inventory Siemens S7 PLCs, install the latest security updates, block internet access, strengthen access controls, and monitor for unusual activity targeting these devices.
Today’s advisory follows a recent increase in attacks targeting exposed PLCs at U.S. critical infrastructure organizations.
You must be logged in to post a comment Login