Select a theme from the list.
Insights

From our experts

Latest
US Defense Supply-Chain Order Pushes Software Provenance Far Beyond the SBOMBit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid ThreatWindows LegacyHive Flaw Leaves Administrators Weighing Unofficial ProtectionHijacked Security Cameras Become Eyes on NATO Military Supply RoutesEstée Lauder Breach Shows the Long Tail of Oracle Enterprise ExploitationMicrosoft and AMD Build a More Specialized Azure Engine for Enterprise AIFresh SharePoint Exploitation Shrinks the Window Between Patch and AttackHelloNet Campaign Turns Trusted ViPNet Components Into an Espionage LaunchpadCritical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade PathNichirei Cyberattack Sends Digital Disruption Into the Cold ChainNadMesh Botnet Raids Exposed AI Servers for Cloud CredentialsACR Stealer Turns Fake Fixes Into Enterprise Data TheftUS Defense Supply-Chain Order Pushes Software Provenance Far Beyond the SBOMBit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid ThreatWindows LegacyHive Flaw Leaves Administrators Weighing Unofficial ProtectionHijacked Security Cameras Become Eyes on NATO Military Supply RoutesEstée Lauder Breach Shows the Long Tail of Oracle Enterprise ExploitationMicrosoft and AMD Build a More Specialized Azure Engine for Enterprise AIFresh SharePoint Exploitation Shrinks the Window Between Patch and AttackHelloNet Campaign Turns Trusted ViPNet Components Into an Espionage LaunchpadCritical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade PathNichirei Cyberattack Sends Digital Disruption Into the Cold ChainNadMesh Botnet Raids Exposed AI Servers for Cloud CredentialsACR Stealer Turns Fake Fixes Into Enterprise Data Theft
Security Insight

Bit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid Threat

Bit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid Threat
Photo by Ann H on Pexels

Researchers behind Bit2Watt found that carefully controlled GPU workloads can generate rapid power oscillations without exploiting a software vulnerability or breaching industrial systems. Physical tests confirmed that GPUs can produce the modulation, while simulations examined how synchronized activity across large clusters might destabilize electrical infrastructure. ([thehackernews.com](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html?utm_source=openai))

A new research project called Bit2Watt challenges the assumption that cloud workloads are electrically passive. The researchers demonstrated that a tenant with legitimate access to graphics processors could deliberately alternate between intensive computation and near-idle operation, producing high-frequency changes in power consumption.

No malware, administrative privilege or conventional software exploit is required. The attack concept relies on the physical relationship between computational activity and electricity demand.

From GPU scheduling to power modulation

The researchers developed two approaches. One uses a custom CUDA workload that rapidly switches a GPU between high and low utilization. The other hides similar power changes inside a functioning large language model training process by modifying training operations and workload timing.

The second approach is potentially more difficult to identify because it can resemble legitimate artificial intelligence activity. Standard cloud monitoring typically focuses on utilization, temperature, billing and application performance, not high-frequency electrical patterns.

Tests showed that both consumer and data-center GPUs could create measurable oscillations. The researchers then modeled a worst-case scenario in which a large number of physically clustered GPUs operated in close synchronization. Their simulations indicated that such coordination might create harmful distortion or instability in certain grid environments.

Important practical limitations

Bit2Watt should not be interpreted as evidence that attackers can currently shut down a national grid through a cloud account. The most severe results came from simulations using demanding assumptions, including access to many GPUs, tight timing synchronization and favorable electrical conditions. Data-center power conditioning and cloud-provider controls could also weaken the effect.

How operators can respond

  • Correlate GPU scheduling telemetry with rack-level and facility-level power measurements.
  • Detect repeated utilization patterns that have no clear computational purpose.
  • Limit a single tenant's ability to synchronize large numbers of physically adjacent accelerators.
  • Use batteries, supercapacitors and harmonic filtering to absorb rapid load changes.
  • Create information-sharing procedures between cloud security and electrical engineering teams.

In my view, the most valuable lesson is organizational. Cloud security teams and power engineers traditionally monitor different systems, creating a blind spot between logical workloads and physical infrastructure. Bit2Watt suggests that hyperscale AI facilities should treat electrical behavior as part of tenant risk management, even when every instruction being executed is technically permitted. ([thehackernews.com](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html))

Talk to our team →

Latest

US Defense Supply-Chain Order Pushes Software Provenance Far Beyond the SBOMJul 22, 2026Bit2Watt Research Turns Ordinary GPU Workloads Into a Potential Grid ThreatJul 22, 2026Windows LegacyHive Flaw Leaves Administrators Weighing Unofficial ProtectionJul 22, 2026Hijacked Security Cameras Become Eyes on NATO Military Supply RoutesJul 21, 2026Estée Lauder Breach Shows the Long Tail of Oracle Enterprise ExploitationJul 21, 2026Microsoft and AMD Build a More Specialized Azure Engine for Enterprise AIJul 21, 2026

Most read

1Global CMS Exploitation Wave Plants Webshells on Business Websites2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching4Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path5Exposed Attack Server Unmasks Three Microsoft 365 Phishing Operations6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards