🟠 High  |  Source: The Register — Security


Researchers have identified a threat scenario in which malicious cloud tenants could deliberately design workloads to maximise power consumption, potentially destabilising the electrical grid infrastructure that serves data centres. Because data centres already place significant and variable demand on power utilities, adversarially crafted compute workloads could amplify this effect to cause localised or regional power disruption. This represents an emerging cross-domain risk at the intersection of cloud computing, physical infrastructure, and critical national infrastructure security.

Security Architect’s Take: Cloud security architects should engage with their cloud providers to understand what resource consumption controls and anomaly detection exist at the hypervisor and tenant level; advocate internally for workload power-consumption baselines and alerting, and factor grid-stability risks into business continuity and third-party risk assessments for data centre dependencies.

Original advisory: Malicious cloud customers can bring down the power grid