Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious Cloud Computing: The Unintended Consequences on Power Grid Security


Malicious cloud customers can bring down the power grid by launching targeted GPU workloads that exploit vulnerabilities in workload scheduling. The potential threat demands immediate attention from both public and private sectors as it underscores the vulnerability of critical infrastructure to malicious activity.

  • Malicious cloud customers can cause damage to datacenters and supporting electrical systems, posing a threat to national security and infrastructure stability.
  • The attack, dubbed Bit2Watt, exploits vulnerabilities in workload scheduling and demonstrates the need for extended cybersecurity defenses.
  • Attacks can be covert, launched within authorized workload execution paths, and likely missed by cloud-provider monitoring frameworks.
  • Potential attacks could induce voltage excursions, harmonic distortion, and damping degradation, leading to unstable system operation.
  • The attack's potential for cascading failures poses a significant risk to large-scale power systems, with the possibility of blackouts exceeding 80%.
  • Side-channel attacks called Watt2Bit demonstrate the potential for covert data exfiltration via frequency-shift keying (FSK) encoding.
  • The need for coordinated defenses across both cyber and physical layers is highlighted to mitigate these risks.



  • Malicious cloud customers can bring down the power grid, a potential threat to national security and infrastructure stability. Researchers at Zhejiang University in China have devised a method to launch GPU workloads that can cause damage to datacenters and supporting electrical systems. This attack, dubbed Bit2Watt, exploits vulnerabilities in workload scheduling and demonstrates the need for extended cybersecurity defenses across both the cyber and physical layers.

    The researchers' approach involves utilizing an adversary masquerading as a legitimate cloud tenant to launch GPU workloads with the potential to destabilize datacenters and power grids. These attacks can be relatively covert, launched within authorized workload execution paths and likely missed by cloud-provider monitoring frameworks. The attack's impact is substantial, with high-frequency modulations exceeding 6,000 Hz that could induce voltage excursions, harmonic distortion, and damping degradation.

    In a scenario where an adversary utilizes 1,000 GPUs to create a total harmonic distortion of 46.8 percent, the electrical current would be squandered on non-productive work, and heat production would exceed normal levels by approximately 20%. This not only threatens the availability of computing equipment but also introduces an unstable mode into the system.

    The attack's potential for cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems, underscores the need for improved cybersecurity defenses. The researchers propose that infrastructure providers coordinate defenses across both layers to look for malicious computation patterns and emphasize the importance of local energy buffering systems to handle power demand spikes.

    Moreover, this attack opens up the possibility of side-channel attacks called Watt2Bit. Researchers at Zhejiang University demonstrated that an electrical stress created by a malicious workload can enable denial-of-service events and covert data exfiltration via frequency-shift keying (FSK) encoding. The recovery of a 50-bit test sequence using FSK encoding serves as proof of concept for the potential threats posed by such attacks.

    This finding highlights the need for a fundamental shift in security practices, with coordinated defenses requiring consideration of workload behavior, power electronics, and grid dynamics. As datacenter and computing infrastructures converge, security must be addressed across domains to mitigate these risks.

    The researchers' findings underscore the vulnerability of the power grid infrastructure to malicious cloud customers. Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy. The potential for such attacks is a pressing concern that demands immediate attention from both the public and private sectors.

    In summary, malicious cloud computing poses significant risks to national security and critical infrastructure stability. Researchers have devised methods to launch GPU-based attacks that can destabilize datacenters and power grids, highlighting the need for extended cybersecurity defenses across both layers.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malicious-Cloud-Computing-The-Unintended-Consequences-on-Power-Grid-Security-ehn.shtml

  • https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193

  • https://dailysecurityreview.com/security-spotlight/volt-typhoon-energy-grid-cyberattack-exposes-us-infrastructure-vulnerabilities/


  • Published: Mon Jul 20 14:32:56 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us