Threat Intelligence Blog

Contact us to discuss any insights from our Blog, and how we can support you in a tailored threat intelligence report.

Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 04 September 2026

Black Arrow Cyber Threat Intelligence Briefing 04 September 2026:

-OpenAI, Anthropic and 100-Plus Firms Warn AI Attacks Are About to Explode

-Is Your Cloud Security Strategy Ready for AI’s Looming Threat?

-Vishing Campaign Abuses Microsoft Teams to Give Attackers a Foothold in Company Networks

-Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

-Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

-Hacked before Their First Coffee: Why New Hires Risk Becoming Cybercriminals’ Favourite Target

-Malvertising Is Moving from Deceptive Content to Weaponised Infrastructure

-Stronger Security Drives Ransomware Groups to Recruit from Within

-Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

-North Korean Remote Workers Are Broadening Their Job Hunt beyond IT

-Criminals Publish Data of 8.7m People after Airports Hack

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Following recent news stories about the cyber risks associated with the malicious use of AI, we report on a joint announcement by a range of organisations that warns all businesses to prioritise their cyber defences ahead of an expected sharp rise in attacks. In addition to the below report, similar announcements were made recently by authorities in the UK, USA and other countries.

While AI has increased the risks, attackers continue to use other tactics: this week we report on how attackers use Teams calls, fake software installers and fake voicemail notifications to gain access to their victims’ systems. We highlight these so that business leaders can ensure these tactics are included in employee training to help staff recognise the signs. We also include information on how business leaders should address the developing insider risks, including when recruiting remote workers.

To respond to this, all organisations should strengthen not only their cyber security (to reduce the probability of a successful attack) but also strengthen their cyber resilience to help enable the organisation to survive an attack. In our experience, the best way to achieve this is through a cyber incident response exercise designed and facilitated by impartial cyber experts; contact us to find out how we help organisations in various countries achieve this proportionately.


Top Cyber Stories of the Last Week

OpenAI, Anthropic and 100-Plus Firms Warn AI Attacks Are About to Explode

More than 100 organisations across technology, banking, insurance and security have warned of a sharp rise in AI-enabled cyberattacks over the coming months as the technology can help attackers find weaknesses and act at greater speed. Businesses more broadly are urged to prioritise cyber defence, address serious existing weaknesses and strengthen controls over AI-generated code. CrowdStrike reported that attackers adopted 88% of proof-of-concept exploits within two days of their public release. The signatories call for urgent action from leaders, suppliers, governments and AI developers.

https://siliconangle.com/2026/08/27/openai-anthropic-and-100-plus-firms-warn-ai-attacks-are-about-to-scale/

Is Your Cloud Security Strategy Ready for AI’s Looming Threat?

AI agents are reshaping cloud security by finding and combining weaknesses far faster than human attackers. While a human tester might assess 50 routes to greater access in a day, an autonomous agent can test thousands within minutes, and only 38% of organisations report high confidence in their cloud security. Businesses should therefore focus on how permissions and configuration weaknesses combine to expose critical data, while adopting temporary access credentials, tighter controls over what users and systems can do, stronger separation between workloads, and continuous testing of potential attack routes.

https://www.csoonline.com/article/4215419/is-your-cloud-security-strategy-ready-for-ais-looming-threat.html

Vishing Campaign Abuses Microsoft Teams to Give Attackers a Foothold in Company Networks

Between January and April 2026, a coordinated voice phishing campaign targeted more than 150 employees at over 10 companies through Microsoft Teams. Attackers posed as internal IT support and used 26 distinct identities, and then tried to persuade staff to install malicious software or grant remote access to their computers. Successful calls often lasted 10 to 15 minutes. Collaboration platforms accounted for 42% of phishing alerts during the period, up from 30% in the previous four months, highlighting their growing use as a route into corporate networks. The documented intrusion attempts were blocked.

https://www.helpnetsecurity.com/2026/09/01/spring-ring-vishing-campaign-microsoft-teams/

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active cyberattack campaign is using convincing copies of trusted software websites to distribute malicious software. Primarily targeting Chinese-speaking users and China-based operations of multinational organisations, it has affected healthcare, manufacturing, technology, logistics, government, education and gaming. Once installed, the malware disables Windows Update, weakens Microsoft Defender, deletes volume shadow copies and prevents standard users from removing its payload directories. Microsoft assessed with moderate confidence that the activity was consistent with the China-associated Silver Fox threat group.

https://thehackernews.com/2026/09/fake-software-installers-disable.html

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

A phishing campaign sent 26,589 fake voicemail emails to 5,527 organisations between 1 June and 4 August 2026. Attackers concealed malicious code inside scalable vector graphic (SVG) attachments, a common image file format, while 95% of messages falsely appeared to originate from recipients’ own organisations. The broadly targeted campaign personalised subject lines using part of recipients’ email addresses. Despite using a single template, 75% of messages received Microsoft spam scores that treated them as not spam, demonstrating how familiar content and disguised attachments can bypass standard email controls.

https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/

Hacked before Their First Coffee: Why New Hires Risk Becoming Cybercriminals’ Favourite Target

New employees are especially attractive targets for cyber criminals, while Verizon reported that most successful breaches involved a human element. Attackers exploit public recruitment updates and unfamiliar company processes to send convincing fraudulent messages. Weak temporary passwords, excessive system access, delayed training and unsecured personal devices further increase exposure. Organisations can reduce risk by issuing unique credentials securely, requiring password changes at first login, using multi-factor authentication, limiting access to role requirements, removing unused accounts promptly and providing cyber security guidance from day one.

https://www.digitaljournal.com/article/hacked-before-their-first-coffee-why-new-hires-risk-becoming-cybercriminals-favourite-target/

Malvertising Is Moving from Deceptive Content to Weaponised Infrastructure

Malicious advertising increasingly hides harmful activity behind legitimate-looking adverts, using redirect chains, disposable domains and selective delivery to evade checks. PropellerAds found that while overall campaign rejections fell 42% between Q1 and Q2 2026, the number involving malware and antivirus-flagged threats rose 13%. Cloaking, where a campaign conceals its true destination or behaviour, accounted for 67% of advertiser suspensions. Organisations should therefore monitor an advert’s full journey and post-launch behaviour, rather than relying solely on initial content checks.

https://cybersecuritynews.com/malvertising-is-moving-from-deceptive-content-to-weaponized-infrastructure/

Stronger Security Drives Ransomware Groups to Recruit from Within

Ransomware groups are increasingly recruiting employees and contractors to bypass stronger cyber security controls. SentinelOne attributed 56% of insider incidents to negligence, such as phishing or lost devices. However, incidents involving malicious insiders with privileged access cost an average of $4.9 million each, while malicious insider activity rose 42% over the previous year. Organisations should rapidly remove access when staff leave, limit sensitive permissions, strengthen login verification and create a culture where employees can report mistakes quickly without fear.

https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Attackers favour repeatable, low-cost methods over sophisticated techniques. Microsoft reported that ClickFix, which tricks users into running malicious commands, appeared in 47% of its attack notifications and was its most commonly observed initial-access method, while Bitdefender reported that legitimate administrative tools featured in 84% of serious incidents. Vulnerability exploitation also rose from 20% to 31%, and ransomware appeared in 48% of breaches. Organisations should prioritise patching exposed systems, restrict powerful tools and scripts, strengthen identity controls, and ensure security alerts are actively monitored by people authorised to respond.

https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html

North Korean Remote Workers Are Broadening Their Job Hunt beyond IT

Huntress investigations indicate that suspected North Korean remote workers are expanding beyond IT into sales, marketing and healthcare roles. In one healthcare case, three accounts used services that concealed their locations, with less than half of their activity occurring during normal business hours. Investigators also found apparently falsified identity documents and, in another case, a company laptop connected to hardware that enabled remote operation. Organisations can reduce this risk by carrying out rigorous background checks before onboarding, researching candidates online and verifying their employment history.

https://www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/

Criminals Publish Data of 8.7m People after Airports Hack

Personal data belonging to 8.7 million customers of Manchester, London Stansted and East Midlands airports has been published online after airport operator MAG did not pay the ransom demanded by the attackers. The stolen information includes email addresses, phone numbers, addresses, vehicle registrations, purchasing history and details of past and planned travel. Its public availability increases the risk of targeted scams and further attacks using the stolen information. MAG says affected customers have been contacted, passengers’ physical safety was not at risk, and it is working with authorities and specialist advisers.

https://www.bbc.co.uk/news/articles/c74k39g3ee5o


Governance, Risk and Compliance

Your Board Has A Financial Expert—Why Doesn't It Have A Cyber One?

NIST, ISO, and Where to Begin With Security Frameworks - DevX

Help to build cyber resilience – New ABI Guidance - BIBA

Hiring for the AI Era: A New Challenge for CISOs - Infosecurity Magazine

Threats

Ransomware, Extortion and Destructive Attacks

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

AI ransomware operation steals 3.1TB from over 30 companies | Cybernews

Stronger Security Drives Ransomware Groups to Recruit From Within

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Ransomware and Destructive Attack Victims

Criminals publish data of 8.7m people after Manchester Airports Group hack - BBC News

ATF confirms cyberattack hit system containing info on its investigation targets | CyberScoop

Berlin Won’t Pay Extortion Group Claiming Data Theft - SecurityWeek

Healthcare cyberattacks hit pacemakers and millions of patient records

Cyberattack causes network outage at Boston Scientific, disrupts global operations - Help Net Security

Dialysis Chain Will Pay $15M Settlement in Interlock Attack

McKesson discloses breach after ShinyHunters claims patient data theft

Ransomware Gang Claims Nutex Health Data Breach - SecurityWeek

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

Phishing & Email Based Attacks

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign - Infosecurity Magazine

Phishing Targeting Financial Services Tripled in a Single Quarter. Here’s How to Defend Against It.

Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse

FBI raises alarm over deceptive phishing campaign targeting prominent people | CyberScoop

New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password - IT Security Guru

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Wave of X password reset emails could be hiding a sneak phishing attack | Mashable

The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action | Group-IB Blog

Other Social Engineering

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks - Help Net Security

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog

Clickfix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog

North Korean remote workers are broadening their job hunt beyond IT - Help Net Security

Wave of X password reset emails could be hiding a sneak phishing attack | Mashable

The Cybersecurity Control Money Can't Buy - Above the Law

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Artificial Intelligence

OpenAI, Anthropic and 100-plus firms warn AI attacks are about to explode - SiliconANGLE

Sharp rise in incidents of AI escaping users’ control, research finds | AI (artificial intelligence) | The Guardian

AI ransomware operation steals 3.1TB from over 30 companies | Cybernews

65% of Enterprises Have Seen AI Agents Act Out of Scope - Infosecurity Magazine

Majority of Senior Cybersecurity Leaders Have Limited Trust in AI | Security Magazine

How to respond to an AI agent security incident | CSO Online

AI security debt exposed as adversarial AI finds old flaws - SiliconANGLE

AI is making cyberattacks worse. You need a digital disaster plan | PCWorld

Unit 42 warns AI has shifted balance of power from defenders to attackers | CyberScoop

AI watchdog predicts doomsday within decade, unless guardrails are imposed on systems

91% of professionals say their firm still falls short on AI - how to fix that | ZDNET

NVIDIA NemoClaw vulnerability can hijack AI agents via websites | Cybernews

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

Is your cloud security strategy ready for AI’s looming threat? | CSO Online

The Guardrails Debate: Security Researcher Changes His Mind

Claude Mythos only model to complete full cyber kill chain, experts say

OpenAI says Astra AI model crosses 'Critical' cyber capability

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Anthropic explains how its AI models escaped their sandbox and hacked real systems | TechSpot

AI Gives Cybercriminals a Dangerous New Advantage

Lords considers government emergency AI kill switch | Computer Weekly

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

AI helps Chinese-speaking hackers speed up attacks on exposed servers | CSO Online

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says - SecurityWeek

Who is accountable when your AI agent goes rogue? | CSO Online

Report Finds AI Security Fails to Match AI Usage | Security Magazine

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

AI Cyberattacks Are Getting Faster. Companies Are Falling Behind

Fake Claude Opus 5 app delivers malware and wipes its own tracks - Help Net Security

Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems

Russian-Speaking Cybercriminals Used SpaceX’s AI Tool to Hack Seven Companies

Defining an AI Kill Switch Is Hard, but Necessary

ChatGPT can log into your web accounts without you now - but should you let it? | ZDNET

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails - Help Net Security

Why Enterprises Need AI FinOps, Security to Scale Responsibly

AI Model Evaluator METR Hit by Credential Theft, Probing

AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure | TechRadar

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities | CyberScoop

3 surveys deliver the same uncomfortable truth about adopting agentic AI | ZDNET

Apple escaped Android's 'toxic hellstew' - now Siri AI is creating a new one | ZDNET

Anthropic Just Beat The Pentagon In Court. A Judge Said National Security Was Used To Punish Its AI Rules. | IBTimes

Bots/Botnets

Dogged Russia-based botnet dismantled after 23-year run | CyberScoop

Careers, Roles, Skills, Working in Cyber and Information Security

Hiring for the AI Era: A New Challenge for CISOs - Infosecurity Magazine

Cybersecurity's “Hiring Crisis” is Fueling the Cybercrime Talent Pipel - Infosecurity Magazine

Cloud/SaaS

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks - Help Net Security

Is your cloud security strategy ready for AI’s looming threat? | CSO Online

New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password - IT Security Guru

Dropbox accounts breached through Lenovo email verification flaw

Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Lazarus Group Moves 244 Bitcoin (BTC) Worth $19.42M From Dormant Wallets - COINOTAG

Cyber Crime, Organised Crime & Criminal Actors

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say | Reuters

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Cybercrime moves into the mainstream: Why threat actors are increasingly turning to Telegram - Digital Journal

CRPx0 hacking service for dummies claims victim count more than quintupled

What underground forums can tell businesses about cyber risk | SC Media UK

Revolut scam steals £180,000 from Jersey residents in just four weeks

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Data Breaches/Leaks

Criminals publish data of 8.7m people after Manchester Airports Group hack - BBC News

Dropbox accounts breached through Lenovo email verification flaw

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Healthcare cyberattacks hit pacemakers and millions of patient records

Toy-making giant Hasbro disclose data breach affecting employees

Huge Latvia data breach exposes 1.2M citizens' data | Cybernews

More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen | TechRadar

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

McKesson discloses breach after ShinyHunters claims patient data theft

Bumble users allegedly exposed in 110M data sale claim | Cybernews

It sure looks like hackers breached a major ID card verification service | TechCrunch

Carhartt data breach exposes information of 12.9 million accounts

Robert Burns farm charity warns members after Beacon CRM cyberattack data breach - BBC News

Data Protection

Reform UK pledges to scrap GDPR for ‘light touch’ laws | Irish Independent

I asked 100 companies for my data. Some deleted it instead. - Ars Technica

Denial of Service/DoS/DDoS

Pro-Russian hackers launch series of large-scale cyberattacks on Norway's government sector — CCD

Encryption

Turns out Brits would quite like their private messages to stay private

UK says 'no' to backdoors, but the government isn't listening – Computerworld

Fraud, Scams and Financial Crime

Revolut scam steals £180,000 from Jersey residents in just four weeks

Drivers charged £370 in car park QR code scam

Nuisance-call blocker fined £190k for being a nuisance caller

Insider Risk and Insider Threats

Stronger Security Drives Ransomware Groups to Recruit From Within

North Korean remote workers are broadening their job hunt beyond IT - Help Net Security

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

Internet of Things – IoT

Think twice before installing this device promising free movies - Ars Technica

Law Enforcement Action and Take Downs

Dogged Russia-based botnet dismantled after 23-year run | CyberScoop

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

Two alleged TeamPCP hackers arrested over global supply chain attacks - Help Net Security

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

68-year-old imprisoned after making $1.3 million by pirating IPTV services

Nigerians extradited to US for sextortion, deaths of two teens

Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

Malvertising

Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Scareware ads keep running on Google's transparency tool, even after they're reported - Help Net Security

Malware

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

You don't want this Sleepwalker backdoor on your Windows machine

Crooks push Mac malware through fake OpenAI Codex ads

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Think twice before installing this device promising free movies - Ars Technica

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Fake Claude Opus 5 app delivers malware and wipes its own tracks - Help Net Security

Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails - Help Net Security

Microsoft Defender flags legitimate Google search links as malicious

Mobile

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Models, Frameworks and Standards

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure - SecurityWeek

Cyber Security Bill enters Lords committee stage - UK Parliament

Peers propose report into Computer Misuse Act reform | Computer Weekly

Reform UK pledges to scrap GDPR for ‘light touch’ laws | Irish Independent

NIST, ISO, and Where to Begin With Security Frameworks - DevX

NIS2 compliance: Fixing IAM and access control before the 2026 audit - Help Net Security

CMMC Compliance Third-Party Assessment Is Paused. The Risk Isn't.

Outages

Massive Microsoft 365 outage causes auth issues, service failures

OpenAI confirms ChatGPT outage as users report errors

Telstra outage caused by failure to prioritise well-known network vulnerabilities - ABC News

Passwords, Credential Stuffing & Brute Force Attacks

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password - IT Security Guru

Five billion passkeys later, passwords are still hanging around

Threat actors are posing as AI crawlers to hunt for exposed credentials - Help Net Security

Wave of X password reset emails could be hiding a sneak phishing attack | Mashable

AI Model Evaluator METR Hit by Credential Theft, Probing

Privacy, Surveillance

UK says 'no' to backdoors, but the government isn't listening – Computerworld

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

How Facebook and Instagram will change after Meta's $18B settlement - and where the money is going | ZDNET

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Regulations, Fines and Legislation

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure - SecurityWeek

Cyber Security Bill enters Lords committee stage - UK Parliament

Peers propose report into Computer Misuse Act reform | Computer Weekly

Lords considers government emergency AI kill switch | Computer Weekly

UK says 'no' to backdoors, but the government isn't listening – Computerworld

Five Washington developments every CISO should be watching | feature | SC Media

Nuisance-call blocker fined £190k for being a nuisance caller

Reform UK pledges to scrap GDPR for ‘light touch’ laws | Irish Independent

The AI Kill Switch Act is repeating the Clipper Chip’s mistakes | CyberScoop

Anthropic Just Beat The Pentagon In Court. A Judge Said National Security Was Used To Punish Its AI Rules. | IBTimes

White House bans foreign-made equipment for power generation over cyber backdoor concerns | The Record from Recorded Future News

CMMC Compliance Third-Party Assessment Is Paused. The Risk Isn't.

Social Media

How Facebook and Instagram will change after Meta's $18B settlement - and where the money is going | ZDNET

How to stop getting unwanted password reset emails from X

Bumble users allegedly exposed in 110M data sale claim | Cybernews

US Navy tells sailors and their families: scrub your social media, enemies are watching

Supply Chain and Third Parties

Two alleged TeamPCP hackers arrested over global supply chain attacks - Help Net Security

Robert Burns farm charity warns members after Beacon CRM cyberattack data breach - BBC News


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Where and how Putin could expand his war in Europe beyond Ukraine - Atlantic Council

Software company chief warns threat of AI cyber warfare already here | The Jerusalem Post

NATO Sees Rising Russian Sabotage and Cyber Activity Across Europe

Chinese Fire Ant hackers turn Cisco routers into spying platforms

The government wants households to prepare for disaster – but the UK’s real test will be the NHS

US Navy tells sailors and their families: scrub your social media, enemies are watching

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

Nation State Actors

China

Chinese Fire Ant hackers turn Cisco routers into spying platforms

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

AI helps Chinese-speaking hackers speed up attacks on exposed servers | CSO Online

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says - SecurityWeek

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

US Navy tells sailors and their families: scrub your social media, enemies are watching

White House bans foreign-made equipment for power generation over cyber backdoor concerns | The Record from Recorded Future News

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Russia

Where and how Putin could expand his war in Europe beyond Ukraine - Atlantic Council

Russia’s hybrid warfare campaign in Europe is escalating | Just The News

NATO Sees Rising Russian Sabotage and Cyber Activity Across Europe

Russia is preparing strikes beyond Ukraine’s borders; British companies are at risk — Daily Mail | УНН

The government wants households to prepare for disaster – but the UK’s real test will be the NHS

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Pro-Russian hackers launch series of large-scale cyberattacks on Norway's government sector — CCD

Russian-Speaking Cybercriminals Used SpaceX’s AI Tool to Hack Seven Companies

US Navy tells sailors and their families: scrub your social media, enemies are watching

Royal Family overhaul cybersecurity amid growing threat from Russian hackers | The Independent

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails - Help Net Security

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say | Reuters

North Korea

North Korean remote workers are broadening their job hunt beyond IT - Help Net Security

US Navy tells sailors and their families: scrub your social media, enemies are watching

Lazarus Group Moves 244 Bitcoin (BTC) Worth $19.42M From Dormant Wallets - COINOTAG

Iran

Britain ‘must brace for more Iranian cyber attacks’

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

US Navy tells sailors and their families: scrub your social media, enemies are watching

Experts: Water Cyber Attacks Had Scale, Not Sophistication

Iran Attempted Cyberattacks on US Infrastructure, NBC Reports




Vulnerability Management

AI Cyberattacks Are Getting Faster. Companies Are Falling Behind

CISA: Most exploited vulnerabilities should have been eradicated decades ago

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree - Help Net Security

AI’s Vulnerability Surge May Be More Manageable Than Feared

Telstra outage caused by failure to prioritise well-known network vulnerabilities - ABC News

Vulnerabilities

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - Help Net Security

Windows 11 KB5120998 update released with 35 changes and fixes

China-linked hackers turn Cisco routers into covert attack infrastructure | CSO Online

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities - SecurityWeek

HPE patches critical ArubaOS-CX remote code execution flaw

Chrome and Firefox Updates Patch Dozens of Vulnerabilities - SecurityWeek

Google fixes the sixth actively exploited Chrome zero-day of 2026

Firefox 155 patches 30 security flaws, adds sortable tab groups | PCWorld

Attackers exploit zero-days in consistently besieged SonicWall product | CyberScoop

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks - SecurityWeek

Hackers Chain Two New SonicWall Zero-Day Vulnerabilities - Infosecurity Magazine

Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs

U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Over 8,300 Gitea servers vulnerable to code execution attacks

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut releases second emergency patch for exploited flaws

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Hackers push malicious Virtualizor update in BGP hijacking attack

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability - SecurityWeek

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 28 August 2026

Black Arrow Cyber Threat Intelligence Briefing 28 August 2026:

-ZeroTokens Phishing Platform Steers Attacks in Real Time

-ToxicPanda Banking Trojan Matures into Enterprise Threat

-New Windows Malware Lays Dormant Until a Custom Command Activates It like a Sleeper Agent

-What Your CISO Is Trying to Tell You, and Why It Matters More Than You Think

-Why Provision 29 Is Raising the Bar for Board Accountability

-Worrying Cyber Security Gaps Expose UK Charities

-How Shadow IT Threatens Your Cyber Security and Digital Sovereignty

-The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

-AI Vulnerability Discovery Scores the Highest Impact of 20 Emerging Risks

-Ransomware Attack Volumes Hit ‘High Water Mark’ in July

-Incident Response: Why the First Two Hours After an Attack Set the Tone

-Business Continuity and Cyber Security: Two Sides of the Same Coin

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start this week by looking at developing attacker techniques, including phishing attacks that can be steered in real time, malware designed to remain dormant until activated, and mobile malware capable of stealing login and authentication details that could provide access to business systems.

We also look at the growing risks associated with AI. Research highlights extensive use of personal and unapproved AI tools, while AI is also accelerating vulnerability discovery. Ransomware activity remains high, reinforcing the need for organisations to understand where they are exposed and prioritise the risks that matter most.

The wider message is that security, governance and resilience must develop alongside the threat. In the UK, Provision 29 of the UK Corporate Governance Code reinforces the need for reliable evidence that important controls are working, while effective incident response, secure backups and tested recovery arrangements can materially affect how quickly an organisation recovers.

We support organisations in various countries to address these risks and requirements. Contact us to discuss how we help leadership teams to strengthen proportionate cyber security, governance and resilience.


Top Cyber Stories of the Last Week

ZeroTokens Phishing Platform Steers Attacks in Real Time

A phishing campaign has used a platform called ZeroTokens to let criminals monitor victims and alter fraudulent login screens in real time. More than 45,000 messages were sent to over 24,000 recipients across 700 organisations, with 24,000 sent on a single day. The attacks targeted financial information, login details, card data and verification codes, while adapting prompts to retry failed verification steps. Researchers found the platform supported templates for 53 financial institutions and 36 card issuers, and assessed that information captured through the phishing interaction would most likely be used outside the platform for financial theft or payment redirection.

https://www.infosecurity-magazine.com/news/zerotokens-phishing-real-time/

ToxicPanda Banking Trojan Matures into Enterprise Threat

A new version of the ToxicPanda Android banking Trojan has expanded from targeting 16 financial institutions to 349 banking, digital wallet and cryptocurrency applications across 16 countries. Attackers are using legitimate cloud services to distribute the malware that can now issue 167 remote commands and gain deeper, persistent control of infected devices, including stealing screen-lock credentials. This creates wider business risk because employee smartphones often hold authentication credentials and provide access to corporate applications.

https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat

New Windows Malware Lays Dormant Until a Custom Command Activates It like a Sleeper Agent

Security researchers have identified SLEEPWALKER, an unusual form of Windows malware designed to remain dormant until it receives a specially crafted network signal. Unlike conventional malware, it contains no built-in malicious functions, helping it avoid detection while disguised as a legitimate security management component. Once activated, it can receive additional capabilities and execute instructions. No active campaigns or confirmed victims have been identified, but researchers believe its highly targeted design could indicate nation-state involvement rather than widespread criminal use.

https://www.techradar.com/pro/security/new-windows-malware-lays-dormant-until-a-custom-command-activates-it-like-a-sleeper-agent

What Your CISO Is Trying to Tell You, and Why It Matters More Than You Think

Effective cyber risk management requires security teams to communicate technical risks in terms that business leaders can understand and act on. Security teams can struggle to secure executive support when risks are presented through technical scores, acronyms and system details rather than potential business impact. With AI accelerating the pace at which threats evolve, that communication gap is becoming increasingly important. Cyber security risks are more likely to prompt timely decisions when leaders understand which business services are affected, the consequences of delaying action, the cost or disruption involved, who owns the response and what risk will remain afterwards.

https://www.forbes.com/councils/forbestechcouncil/2026/08/25/what-your-ciso-is-trying-to-tell-you-and-why-it-matters-more-than-you-think/

Why Provision 29 Is Raising the Bar for Board Accountability

The revised UK Corporate Governance Code is increasing expectations on boards to demonstrate that important internal controls are working effectively, rather than relying on periodic compliance checks. From 2026, Provision 29 requires boards to assess and report on material controls using reliable evidence. For cyber security, this strengthens the case for more continuous monitoring, as annual assessments can quickly become outdated across cloud services, conventional IT infrastructure and third-party suppliers. More timely information can help boards understand changing risks and provide greater confidence when making formal declarations about control effectiveness.

https://www.itsecurityguru.org/2026/08/26/why-provision-29-is-raising-the-bar-for-board-accountability/

Worrying Cyber Security Gaps Expose UK Charities

Research into 380 of the UK’s largest and best-known charities found widespread cyber security weaknesses, with exposed staff or supplier passwords affecting 44% of well-known charities and 55% of the largest by income. Around one in three could also have emails forged in their name, increasing the risk of fraudulent appeals or payment requests. Larger charities were not necessarily better protected, with better-funded organisations more likely to have exposed credentials and internal login pages. Nine in 10 also lacked a published process for reporting security weaknesses, although none appeared on ransomware leak sites.

https://tfn.scot/news/worrying-cybersecurity-gaps-expose-uk-charities

How Shadow IT Threatens Your Cyber Security and Digital Sovereignty

The rapid adoption of unapproved apps, cloud services and AI tools is creating a growing cyber security and governance risk for organisations. Employees often adopt these tools for convenience, but sensitive data can then move outside approved systems, leaving organisations with limited visibility over where it is stored, who can access it and how it is used. AI note-taking tools and personal accounts are increasing this challenge. Effective control requires organisations to provide usable approved alternatives, monitor what tools are being used and ensure sensitive information remains within appropriately governed environments.

https://www.forbes.com/councils/forbestechcouncil/2026/08/20/how-shadow-it-threatens-your-cybersecurity-and-digital-sovereignty/

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Akamai has found that a small group of intensive AI users may be creating a disproportionate share of organisational risk. The 5% of employees who use AI most intensively use it at 12 times the rate of the least active half, while 47% of enterprise AI conversations take place through personal rather than managed corporate accounts. Around 14% of enterprise AI conversations involved corporate email addresses linked to personal AI subscriptions, potentially exposing sensitive data. AI browser and coding extensions add further risk, with nearly 75% requesting significant permissions and 16% containing known security weaknesses.

https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html

AI Vulnerability Discovery Scores the Highest Impact of 20 Emerging Risks

AI-powered vulnerability discovery has emerged as the highest-impact of 20 emerging risks identified by Gartner, with 76% of respondents placing it in their top ten. Organisations expect the effects to become tangible within the next two years as AI makes it faster and easier to find previously unknown security weaknesses and turn them into usable attacks. While respondents also ranked themselves highly prepared, Gartner warns that vulnerability discovery could outpace organisations' ability to fix weaknesses, raising the risk of serious cyber incidents and disruption to operations.

https://www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/

Ransomware Attack Volumes Hit ‘High Water Mark’ in July

Ransomware activity reached its highest level of 2026 so far in July, with 894 recorded attacks, up almost 25% from June. North America accounted for 41% of incidents and Europe 29%, while one rapidly growing criminal group was linked to 15% of attacks. NCC Group also warned that artificial intelligence is increasing the speed and scale of cyberattacks by helping criminals automate activity and create more convincing phishing content. Emerging AI agents capable of carrying out ransomware attacks with little or no human involvement could further increase the threat.

https://www.computerweekly.com/news/366649779/Ransomware-attack-volumes-hit-high-water-mark-in-July

Incident Response: Why the First Two Hours After an Attack Set the Tone

The first two hours following a cyberattack can significantly influence how quickly an organisation recovers. Poor early decisions, such as wiping compromised systems, can destroy evidence, leave attackers' access routes in place and turn a five-day recovery into a five-week crisis. Effective response depends on quickly assembling legal, forensic and recovery specialists, establishing secure communications and understanding what has been affected. Tested backups are equally important, as many failures only become apparent during recovery. Organisations that prepare response arrangements in advance are better placed to contain disruption and restore operations quickly.

https://www.informationweek.com/incident-response/incident-response-why-the-first-two-hours-after-an-attack-set-the-tone

Business Continuity and Cyber Security: Two Sides of the Same Coin

Business continuity and cyber security cannot be treated separately as attackers increasingly target the systems organisations rely on to recover from disruption. Research found that 93% of ransomware attacks targeted backup repositories, while 68% of breaches involved a human element. With the average global cost of a data breach reaching $4.88 million, organisations need recovery arrangements that remain secure during an attack. This includes protecting backups, separating critical systems, maintaining alternative communications and regularly testing recovery plans against realistic cyberattack scenarios.

https://www.csoonline.com/article/4086135/business-continuity-and-cybersecurity-two-sides-of-the-same-coin.html



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware attack volumes hit ‘high-water mark’ in July | Computer Weekly

Ransomware attackers are zeroing in on mid-market companies - Help Net Security

Scammers pose as ransomware recovery agents, but just go on to steal more from victims | TechRadar

Scattered Spider Targets Tech Companies for Help-Desk Exploitation - ReliaQuest

Tricky 'SynkLoader' Multitool May Herald Ransomware

Ransomware surges as criminals deploy AI tools | Microscope

Autonomous AI Ransomware Threat Peaks 2026

Gunra Ransomware: What You Need to Know |Fortra

Ransomware and Destructive Attack Victims

US Bank claimed by hackers, posted on the dark web | Cybernews

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited - SecurityWeek

ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta | TechRadar

ATF confirms “major incident” after recent Qilin breach claims

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

ShinyHunters Leaks 7.1 Million Baxter International Records

Phishing & Email Based Attacks

ZeroTokens Phishing Platform Steers Attacks in Real Time - Infosecurity Magazine

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets - SecurityWeek

Fake bank websites play dead to evade security scanners - Help Net Security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine

Russian snoops add OAuth abuse to targeted phishing campaigns

Hackers abuse npm mirrors to host phishing redirect pages

New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls | TechRadar

First-time buyer lost £47,000 after email 'impersonated' - The Mirror

Def Con Attendees Targeted by Persistent Phishing Campaign - Infosecurity Magazine

Other Social Engineering

Think you’d never fall for it? Modern cybercriminals are counting on that | Federal News Network

Fake bank websites play dead to evade security scanners - Help Net Security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine

Scattered Spider Targets Tech Companies for Help-Desk Exploitation - ReliaQuest

Attackers impersonate popular AI brands to spread malware - Help Net Security

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Beware of fake Indeed interview apps used to install spyware | Malwarebytes

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Red Flags That Expose Fake North Korean IT Workers

Cybercriminals perfect 'social engineering': 'Each hack feeds the chances of the next one succeeding - France 24

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

First-time buyer lost £47,000 after email 'impersonated' - The Mirror

Scammers cost Irish adults €760m last year - survey – The Irish Times

‘Hang up’ warning issued as fraudsters target Isle of Man residents by phone | iomtoday.co.im

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice | CyberScoop

2FA/MFA

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Artificial Intelligence

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty

Why "Shady AI" is Security's Next Big Governance Problem

Why AI cyberattacks are outpacing enterprise defenses | CSO Online

A low-tech solution from the past may be your best defense against AI deepfakes | ZDNET

AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security

New study finds bosses are far more comfortable sharing work documents with AI than their employees — despite the security risks | TechRadar

Four in Five AI Tools Run with No IT Oversight, Research Finds - Infosecurity Magazine

Attackers impersonate popular AI brands to spread malware - Help Net Security

Ransomware surges as criminals deploy AI tools | Microscope

Autonomous AI Ransomware Threat Peaks 2026

PYMNTS | OpenAI Exec Tells People to Expect AI-Driven Cyberattacks

The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes - Help Net Security

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Grok chat duped into swallowing injected instructions

NCSC, comments on agentic AI | Professional Security Magazine

ISMG Editors: AI-Assisted Cyberattacks Gain Speed and Scale

What The Hugging Face Cyberattack Teaches Leaders About AI

AI supply chain risk is showing up in developer workflows first - Help Net Security

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

OpenAI: Agent behavior that led to Hugging Face intrusion formed in May | CyberScoop

The Hugging Face incident and the road ahead | OpenAI

OpenAI previews privacy-focused system for detecting AI misuse - Help Net Security

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses - SecurityWeek

AI Agents Taking Unsanctioned Action During Cyber Testing

Eight AI Agents Attacked Taiwan's Government for Four Days — With No Human Pulling the Trigger - Times Tabloid

Fake Codex Download Uses Google Sites to Deliver macOS Malware - Infosecurity Magazine

Could OpenClaw have actually hacked that Australian gym? We decided to test it.

ChatGPT can now search Apple Messages, raising privacy concerns | Fortune

Careers, Roles, Skills, Working in Cyber and Information Security

Cybersecurity Job Ads Requiring AI Skills Double - Infosecurity Magazine

Cloud/SaaS

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

New malware turns Microsoft cloud into its control center | CSO Online

Researchers Uncover Thousands of Leaked AWS Keys - Infosecurity Magazine

NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Cyber Crime, Organised Crime & Criminal Actors

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A $25 template helped scammers build hundreds of phantom bank domains - Help Net Security

More Than Half of Gen Z Has Faced a Cyberattack - tovima.com

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects - Infosecurity Magazine

Your Shredded Visa Card May Still Work at the Checkout - Security Affairs

Scammers cost Irish adults €760m last year - survey – The Irish Times

Data Breaches/Leaks

Researchers Uncover Thousands of Leaked AWS Keys - Infosecurity Magazine

US Bank claimed by hackers, posted on the dark web | Cybernews

Personal Information Exposed in Apollo Global Data Breach - SecurityWeek

More Than 9 Million Facial Images Were Leaked Online

Cyberattack hits 63% of Latvia’s population | Al Bawaba

88 ID Verification Breaches Show the Cost of Collecting Identity Data

French tax authority says break-in exposed data of 600K, including some private messages

Target may have suffered another damaging data leak as hackers claim 8.6GB haul | TechRadar

ShinyHunters Leaks 7.1 Million Baxter International Records

Sensitive Information Exposed in Nutex Health Data Breach - SecurityWeek

Data/Digital Sovereignty

How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty

The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know

Why Israel's outsized influence on global tech is worrying | Al Majalla

Denial of Service/DoS/DDoS

Massive DDoS attack disrupts Norway’s government digital services

Pro-Russian hackers declare ‘cyberwar’ on Norway

Encryption

Nearly half of enterprises have no one leading PQC migration - Help Net Security

Quantum Cyberattacks Are Now A CIO Deadline, Not A Research Topic

Fraud, Scams and Financial Crime

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A $25 template helped scammers build hundreds of phantom bank domains - Help Net Security

Fake bank websites play dead to evade security scanners - Help Net Security

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Your Shredded Visa Card May Still Work at the Checkout - Security Affairs

Scammers cost Irish adults €760m last year - survey – The Irish Times

Scams: Why You Can No Longer Trust Your Eyes And Ears | Scoop News

Up to £464m ‘moved through more than 3,000 UK high street shell companies’ | Business | The Guardian

Identity and Access Management

88 ID Verification Breaches Show the Cost of Collecting Identity Data

Insider Risk and Insider Threats

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

Red Flags That Expose Fake North Korean IT Workers

Insurance

Average Cyber Insurance Losses Increase Despite Fewer Claims - Infosecurity Magazine

Internet of Things – IoT

Slovakia finds Russian backdoors in speed cameras | Cybernews

Hackers infect Android car head units with proxy botnet malware

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout | Tom's Hardware

Law Enforcement Action and Take Downs

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects - Infosecurity Magazine

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist | CyberScoop

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice | CyberScoop

Linux and Open Source

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researcher tricks Apple’s Find My into sharing location data with Linux

China joins Europe in scrapping Windows for Linux | ZDNET

Malware

ToxicPanda Banking Trojan Matures Into Enterprise Threat

New Windows malware lays dormant until a custom command activates it like a sleeper agent | TechRadar

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

Attackers impersonate popular AI brands to spread malware - Help Net Security

AI Speeds Up Malware Development, Not Its Success Rate: Analysis - SecurityWeek

Fake Codex Download Uses Google Sites to Deliver macOS Malware - Infosecurity Magazine

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Tricky 'SynkLoader' Multitool May Herald Ransomware

Hackers abuse FTP server banners to deliver new Windows malware

New Agent Tesla Malware Variant Boosts Evasion Capabilities - Infosecurity Magazine

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Hackers infect Android car head units with proxy botnet malware

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Hackers abuse npm mirrors to host phishing redirect pages

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Misinformation, Disinformation and Propaganda

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

OpenAI banned Russian ChatGPT accounts backing covert influence operation

Mobile

ToxicPanda Banking Trojan Matures Into Enterprise Threat

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

Models, Frameworks and Standards

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts - SecurityWeek

Firms urged to prepare for eventual NIS2 implementation

Passwords, Credential Stuffing & Brute Force Attacks

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets - SecurityWeek

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Hackers poison popular Rust crates to steal developers' credentials

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes - Help Net Security

Privacy, Surveillance

Your Comcast router doubles as a motion detector now - and a potential police informant | ZDNET

More Than 9 Million Facial Images Were Leaked Online

Researcher tricks Apple’s Find My into sharing location data with Linux

The best and worst AI for your privacy, ranked - and how each handles your data | ZDNET

ChatGPT can now search Apple Messages, raising privacy concerns | Fortune

Windows 11 is finally getting better privacy controls for cameras and mics | PCWorld

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears | CyberScoop

Flock Announces Band-Aids Meant To Remedy Totally Predictable And Widespread Abuse Of Surveillance Equipment

Regulations, Fines and Legislation

Senator asks US government watchdog to review how feds use hacking tools | TechCrunch

UK government set to adjudicate on ‘risky’ tech purchases | Computer Weekly

Meta agrees to $18 billion settlement over teen social media harms

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears | CyberScoop

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts - SecurityWeek

Trump Moves to Ban Some Foreign Energy Equipment From Grid - Bloomberg

Shadow IT

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty

Why "Shady AI" is Security's Next Big Governance Problem

Shadow AI presents cyber security challenge - CIR Magazine

Social Media

TikTok reaches $400m US children's privacy settlement | US News | Sky News

Meta agrees to $18 billion settlement over teen social media harms

Software Supply Chain

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

New malware turns Microsoft cloud into its control center | CSO Online

AI supply chain risk is showing up in developer workflows first - Help Net Security

Hackers poison popular Rust crates to steal developers' credentials

Hackers abuse npm mirrors to host phishing redirect pages

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

This Mini PC Brand Accidentally Hosted Malware-Infected Drivers On Its Website

Supply Chain and Third Parties

Financial damage from cyber attacks grows despite falling claims volumes | Insurance Times

Is Cyber Facing an Affordability Crisis?

AI supply chain risk is showing up in developer workflows first - Help Net Security


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

UK to warn public to store tinned food in case of emergencies: FT

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Officials disrupt Chinese espionage operation that hit multiple federal agencies | CyberScoop

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware | The Record from Recorded Future News

Nation State Actors

China

UK government set to adjudicate on ‘risky’ tech purchases | Computer Weekly

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate - Help Net Security

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware | The Record from Recorded Future News

Trump Moves to Ban Some Foreign Energy Equipment From Grid - Bloomberg

China joins Europe in scrapping Windows for Linux | ZDNET

Eight AI Agents Attacked Taiwan's Government for Four Days — With No Human Pulling the Trigger - Times Tabloid

China-linked Threats to Operational Technology

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Russia

UK to warn public to store tinned food in case of emergencies: FT

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

German firms report rising cyber threat from foreign intelligence services, study shows - The Economic Times

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout | Tom's Hardware

Pro-Russian hackers declare ‘cyberwar’ on Norway

AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking - SecurityWeek

Russia-Linked Threats to Operational Technology

Russia builds global satellite internet network to rival Starlink

North Korea

Red Flags That Expose Fake North Korean IT Workers

Iran

Iranian hackers carry out unprecedented attack on UK’s power network | The Independent

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Iran strikes deep: Attack on British infrastructure

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

UK power plant shutdown highlights CNI cyber challenges | Computer Weekly

Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’ | IT Pro

The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera

Big or small—Critical infrastructure under attack | McDonald Hopkins - JDSupra

Iran hackers vow to target US allies | Cybernews

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Pakistan's Transparent Tribe Refreshes Tools for Afghan Attacks




Vulnerability Management

AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

Silent Patches Don’t Stop Attackers - They Blind Defenders - SecurityWeek

Why mission risk should drive cyber operations strategies | perspective | SC Media

The Vulnerability Gap: Why Discovery Is Outrunning Repair

Frontier AI: Vulnerability Management's Systemic Revolution

Vulnerabilities

Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel

Microsoft patches max severity code execution, privilege escalation flaws

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security

That April Windows update you skipped? Hackers are exploiting it now | PCWorld

Microsoft: August updates break printing, PDF export in WPF apps

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Microsoft rolls out fix for Windows 11 crashes, gaming issues

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Recent Citrix NetScaler Vulnerability Exploited in the Wild - SecurityWeek

Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes

Hackers breached over 270 Zimbra servers in ongoing attacks

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Chrome 152 Patches Over 300 Vulnerabilities - SecurityWeek

Adobe and Nvidia Patch Dozens of Vulnerabilities - SecurityWeek

PaperCut Releases Emergency Patch for Exploited Zero-Day - SecurityWeek

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

Ubiquiti UniFi vulnerabilities: 21 critical bugs expose devices | Cybernews

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line | CyberScoop

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

GitLab Warns of Active Exploitation of Critical GraphQL Flaw

Critical Isolated-vm Vulnerability Leads to RCE on Host - SecurityWeek

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

91 Vulnerabilities Patched in Spring Application Framework - SecurityWeek

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Hackers target WordPress sites in miniOrange auth bypass attacks

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Critical Avada WordPress theme flaw enables zero-click RCE


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 21 August 2026

Black Arrow Cyber Threat Intelligence Briefing 21 August 2026:

-Why Compliance Does Not Guarantee Cyber Resilience

-Infostealers Harvest 1.7 Billion Credentials in Six Months

-Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

-Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

-UK Cyberattacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

-Your Security Appliances Are the Attack Surface

-Stealthy Attacks: How to Protect Your Business

-Attackers Turn to AI for Help Identifying Files Worth Stealing

-Rogue Ransomware Affiliate Poses as Recovery Firm to Steal Payments

-The 80% Problem: Why AI Resilience Is More Important Than Ever

-UK Fraud Cases Hit Record High in 2026

-How CSOs Can Turn Cyber Security into a Business Growth Strategy

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

While many organisations need to fulfil regulatory requirements for cyber security, it is important to ensure that the choices made not only help prevent a cyber incident from occurring, but also enable the organisation to continue operating while an incident is being investigated and managed.

We highlight the need for cyber resilience in our review this week, alongside insights on the developing tactics of attackers, including exploiting gaps in multi-factor authentication and repurposing older domains with an established reputation and using them to deliver malicious software.

We discuss how attackers are exploiting vulnerabilities in security appliances to enter organisations, and how they use techniques to avoid detection and to identify the systems and business information most valuable to target, again underlining the need for resilience planning. We also share information on an emerging ransomware tactic, where a suspected attacker later poses as an expert who can help the victim recover from the attack.

As cyber risks continue to develop, including through the use of AI, business leaders need to focus not only on preventing attacks but also on ensuring the organisation can continue operating when an incident occurs. This resilience requires effective governance across people, operations and technology, with controls proportionate to the organisation and its risks. Contact us to discuss how we help leadership teams strengthen their cyber security and resilience.


Top Cyber Stories of the Last Week

Why Compliance Does Not Guarantee Cyber Resilience

Compliance frameworks provide an important security baseline, but passing an audit or holding a certification does not prove that an organisation can keep critical services running during serious disruption. Documented controls may exist without showing how systems, people, suppliers and recovery arrangements will perform under pressure. Scenario-based exercises can expose hidden dependencies, unclear responsibilities and unrealistic recovery assumptions before a real incident occurs. For business leaders, the key is to test whether controls deliver the intended outcomes in practice, rather than treating documented compliance as sufficient evidence of resilience.

https://www.itsecurityguru.org/2026/08/19/why-compliance-does-not-guarantee-cyber-resilience/

Infostealers Harvest 1.7 Billion Credentials in Six Months

Flashpoint recorded 7.4 million devices infected with information-stealing malware in the first half of 2026, up 27% on the previous six months, with 1.7 billion login credentials stolen. The firm also tracked 21,667 software vulnerabilities, an 8% increase, although only 239 were being actively exploited. Malicious use of AI is also growing, with more than 22 million related posts identified across illicit online channels. Ransomware activity rose sharply too, with 6,256 victims recorded, a 45% increase, highlighting how automation, cheaper initial access and established ransomware-as-a-service operations are increasing the scale of ransomware activity.

https://www.infosecurity-magazine.com/news/infostealers-17-billion/

Password Spraying Attacks Surge 155x as Hackers Exploit MFA Gaps

Huntress has recorded a 155-fold increase in password spraying attacks during the first half of 2026, including more than 81 million login attempts and 78 compromised accounts in just two weeks. Attackers combined previously stolen passwords with older sign-in methods that can bypass multi-factor authentication when security policies are not applied consistently. Of 23 affected organisations analysed, eight had no multi-factor authentication, while the remaining 15 had gaps that excluded certain users, applications or sign-in methods. The findings highlight the importance of applying strong authentication controls consistently across all cloud access.

https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired internet domains to exploit the trust and traffic that was built under previous owners. Infoblox found that around 65,000 expired domains are re-registered every day, accounting for nearly 20% of new registrations in the first half of 2026. One criminal operation reportedly spent almost $7 million on more than 10,000 expired domains, using them for unauthorised sports-streaming sites, betting promotion and systems supporting malware. Because expired domains can continue receiving web traffic, appear in stored search results and benefit from an established reputation, organisations should recognise that a familiar or long-established domain is not necessarily a safe one.

https://securityaffairs.com/197251/cyber-crime/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html

UK Cyberattacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

UK organisations faced an average of 1,597 cyberattacks per week in July 2026, up 26% year-on-year and growing faster than the global rate of 16%. Ransomware also surged globally, with 964 reported victims, an 87% annual increase. At the same time, generative AI is creating new data risks, with one in 36 prompts from business networks carrying a high risk of exposing sensitive information and high-risk activity identified in 88% of organisations that regularly use these tools. For business leaders, the findings support maintaining defences across networks, cloud services, endpoints, email and AI use rather than relying on one layer.

https://www.itsecurityguru.org/2026/08/13/uk-cyber-attacks-jump-26-year-on-year-as-ransomware-activity-doubles-globally/

Your Security Appliances Are the Attack Surface

Security and networking appliances such as firewalls and VPN gateways are becoming an increasingly attractive route into organisations. Google tracked 21 previously unknown vulnerabilities targeting these products in 2025, while they accounted for over 25% of newly recorded actively exploited vulnerabilities in the first half of 2026. 75 known weaknesses in security appliances have also been linked to ransomware campaigns. The risk is heightened because these devices are internet-facing, highly trusted and often difficult to monitor, meaning a compromise can provide attackers with significant access while remaining largely invisible to existing security controls.

https://securityboulevard.com/2026/08/your-security-appliances-are-the-attack-surface/

Stealthy Attacks: How to Protect Your Business

Attackers are increasingly favouring stealth over disruptive malware, using stolen credentials and legitimate business tools to move through systems without raising alarms. Research found critical Microsoft vulnerabilities doubled year-on-year from 78 to 157, while flaws exposing sensitive information rose by 73%. Privilege escalation, where attackers gain higher levels of access, accounted for 40% of disclosed issues. With Microsoft fixing 570 vulnerabilities in July alone, organisations face growing pressure to prioritise risk. Strong access controls, multi-factor authentication, continuous monitoring and effective patch management remain essential to limiting the impact of these quieter cyberattacks.

https://insight.scmagazineuk.com/stealthy-attacks-how-to-protect-your-business

Attackers Turn to AI for Help Identifying Files Worth Stealing

Gambit Security has identified several cases where cyber attackers used artificial intelligence to support attacks, from creating malicious tools and harvesting credentials to identifying which business data was most valuable to steal. In one case, AI helped a suspected ransomware operator assess systems across six organisations and prioritise production databases, client documents and backups. Separately, a credential-harvesting operation used a tool developed with AI to collect 2,975 valid keys and credentials from 1,742 victim systems in under two months. For organisations, the cases show that AI can assist attackers with both technical tasks and identifying the business information most worth targeting.

https://www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/

Rogue Ransomware Affiliate Poses as Recovery Firm to Steal Payments

Security researchers have identified a suspected ransomware affiliate posing as a recovery firm and approaching victims before attacks become public, claiming it could provide decryption keys and seeking $20,000 to $60,000 to delete stolen data from servers controlled by the ransomware group. Evidence suggests the same individual or group may be behind both the original ransomware attacks and the subsequent recovery offers, creating an additional route to profit. The activity raises concerns that growing distrust among the criminal parties involved in ransomware operations could expose victims to multiple parties seeking payment, while providing no guarantee that stolen data will remain confidential even after a ransom is paid.

https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/

The 80% Problem: Why AI Resilience Is More Important Than Ever

AI is now embedded in daily business operations, with ISACA finding that 82% of European companies permit its use at work. Governance has not kept pace, as only 42% have a formal AI policy and 20% do not know who would be accountable if an AI system caused harm. With Microsoft Copilot used by 80% of organisations adopting AI, reliance on a single provider creates operational risk. For business leaders, this makes advance planning for AI outages important, including clear ownership and an agreed alternative for critical work.

https://www.itsecurityguru.org/2026/08/14/the-80-problem-why-ai-resilience-is-more-important-than-ever/

UK Fraud Cases Hit Record High in 2026

The National Fraud Database recorded more than 220,000 cases in the first half of 2026, its highest total for that period. Identity fraud rose 9% to nearly 130,000 cases and now accounts for three-fifths of all filings, while account-takeover incidents increased 5%. SIM-swap fraud, where criminals transfer a victim’s mobile number to another SIM card to intercept calls and messages, rose 402% to more than 4,100 cases. Money-muling cases also rose 69%, with people under 30 accounting for 57%, reinforcing the importance of fraud education, awareness and prevention for younger people.

https://www.infosecurity-magazine.com/news/uk-fraud-cases-hit-record-high/

How CSOs Can Turn Cyber Security into a Business Growth Strategy

Cyber security is a business enabler rather than simply a defensive function. As organisations adopt AI, modernise infrastructure and expand digital operations, Chief Security Officers (CSOs) have an opportunity to shape investment and transformation decisions from the outset. Building security into new initiatives early can reduce costly changes, improve operational resilience and make secure working easier for employees. Measuring success should also extend beyond preventing incidents to how quickly the organisation can recover and maintain critical services when disruption occurs, helping cyber security support innovation, productivity and growth.

https://www.csoonline.com/article/4208202/how-csos-can-turn-cybersecurity-into-a-business-growth-strategy.html



Threats

Ransomware, Extortion and Destructive Attacks

Three-quarters of Ransomware Attacks Target Mid-Market Firms - Infosecurity Magazine

UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally - IT Security Guru

Law Firms Increasingly Targeted By Ransomware/Vishing Attacks - Security Boulevard

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign - SecurityWeek

The long tail of Clop’s PTC hack is just beginning to emerge | CyberScoop

27M records allegedly stolen via misconfigured Microsoft portals​ | Cybernews

Akira Ransomware Uses Safe Mode to Bypass EDR

Ransomware gang crashes own attack — with no-one to blame but themselves | TechRadar

CISA: Windows Task Host flaw now exploited by ransomware gangs

Rogue ransomware affiliate poses as recovery firm to steal payments

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Data analyst sent to prison for stealing data, extorting employer

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Windows 11 is fully removing a legacy tool that malware and ransomware have abused for years, meet WMIC

Prison for data analyst who tried to extort $2.5 million from his employer

Ransomware and Destructive Attack Victims

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign - SecurityWeek

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

The long tail of Clop’s PTC hack is just beginning to emerge | CyberScoop

Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others | Reuters

Multiple organisations investigating fresh wave of Cl0p breaches | Computer Weekly

More than 200 victims of Medusa ransomware identified over the last year, CISA says | The Record from Recorded Future News

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

Researchers Confirm ExfilSquad’s Access to Sensitive Data - Infosecurity Magazine

European nation rocked by major hacker attack: “largest data leak in history” | Cybernews

Details emerge on BlackFile's recent attacks on financial companies | CyberScoop

Co-op chief digital and technology officer resigns | Retail Week

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

BMW hit by ransomware attack, allegedly breaching motorcycle data | Cybernews

Other Social Engineering

Law Firms Increasingly Targeted By Ransomware/Vishing Attacks - Security Boulevard

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

How QR-code phishing can slip past corporate security measures

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra - Infosecurity Magazine

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix - Infosecurity Magazine

Burnham messaged person posing as Trump’s chief of staff

Your polite reply to that text is worth $2 on the dark web | Malwarebytes

Hackers want your nudes. Here’s how to keep your privates, private | PCWorld

2FA/MFA

Password spraying attacks surge 155x as hackers exploit MFA gaps

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk | TechRadar

Artificial Intelligence

A hollowed out data layer is making CISOs fly blind into AI attacks - Help Net Security

AI is making fraud harder to spot and identity harder to prove - Help Net Security

80% of Organizations Experienced AI or Cybersecurity Incidents

AI’s ‘middle class’ has gotten dramatically better at hacking | CyberScoop

Governance Gap: AI Accountability Crisis

Fake Evidence: How Generative AI Is Changing Fraud

Attackers turn to AI for help identifying files worth stealing - Help Net Security

The 80% Problem: Why AI resilience is more important than ever - IT Security Guru

AI agents aren’t legally responsible for any harm that they cause, experts say. So who is? | AI (artificial intelligence) | The Guardian

NCSC CTO calls for strong AI safeguards | UKAuthority

Irregular says ‘human oversight’ responsible for AI sandbox escape incidents | CyberScoop

Turf War Between Claude Agents Leads to Self-Replicating Malware

Citizen developers are becoming a security problem | perspective | MSSP Alert

Anthropic sees AI risks rising, no plan to release stronger "Model 2"

OpenAI Is Pausing Some Work Due To Safety Concerns After Finding It Could Pose Critical Cybersecurity Risks | IBTimes

ChatGPT’s new feature could give infostealers a map of your Mac activity - Help Net Security

The 'Industrial Accidents' Behind Rogue AI Attacks

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

World-first autonomous ‘end-to-end’ AI attack against Taiwan tied to Chinese hackers — and the scariest part is that it was fully open source | TechRadar

AI Is Calling In Cybersecurity's Technical Debt

LiteLLM Supply-Chain Attack - Technology, Banking and Healthcare the Most Affected

153GB of stolen credentials surface after LiteLLM supply chain attack - Help Net Security

Invisible AI Prompts Trigger Court Sanctions - Security Affairs

How Cybercriminals Are Weaponizing Frontier AI Models Like Grok

Rise of Malicious AI Skills Expands Enterprise Risk

UK Legal Regulator Raises AI Misuse Concerns - Infosecurity Magazine

Copilot tricked into telling reseachers how to hack itself

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Abnormal AI CEO Says the Age of AI Attacks Is Forcing a Rethink of Cybersecurity - Benzinga

ChatGPT's new Computer History tracks your Mac activity to create a timeline - but should you let it? | ZDNET

OpenAI unveils ChatGPT for Teens with stronger guardrails to tackle safety risks | Reuters

Bots/Botnets

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies - Infosecurity Magazine

Botnets Based on the Notorious Mirai Code Continue to Emerge - Security Boulevard

Linux Botnet Evooo1Bot Expands Mirai Capabilities Beyond DDoS

Careers, Roles, Skills, Working in Cyber and Information Security

CISOs Break Their Silence in 'Declassified' Docuseries

A Realistic Path Into Remote Cybersecurity Jobs - DevX

Multiple Suicides Reported in US Cyber Operations Forces | Security Magazine

Cloud/SaaS

27M records allegedly stolen via misconfigured Microsoft portals | Cybernews

Hacker claims 3.6 million Azure account records stolen from major companies

Crook hawks millions of records allegedly plundered from corporate Azure tenants

New malware turns Microsoft 365 and Azure into its control center – Computerworld

Weak IAM affects up to 98% of cloud environments - Help Net Security

Max severity SAP Commerce Cloud flaw now targeted in attacks

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security

Police bust cybercrime ring accused of stealing €30 million in four-day spree - Help Net Security

14,000 Trezor Customers Impacted by Data Breach at ShipMonk - SecurityWeek

SafePal data breach impacts 39,798 customers, stolen info for sale

Cyber Crime, Organised Crime & Criminal Actors

UK Fraud Cases Hit Record High - Infosecurity Magazine

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Your polite reply to that text is worth $2 on the dark web | Malwarebytes

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring - IT Security Guru

How Cybercriminals Are Weaponizing Frontier AI Models Like Grok

Microsoft starts removing WMIC tool used by cybercriminals

Researchers find a loophole that lets expired credit cards make unauthorized payments - Help Net Security

Data Breaches/Leaks

Infostealers Harvest 1.7 Billion Credentials in Six Months - Infosecurity Magazine

27M records allegedly stolen via misconfigured Microsoft portals | Cybernews

Hacker claims 3.6 million Azure account records stolen from major companies

Crook hawks millions of records allegedly plundered from corporate Azure tenants

Multiple organisations investigating fresh wave of Cl0p breaches | Computer Weekly

Philips and GE investigating Clop ransomware data theft claims

Over 1,000 Charities Hit by Beacon CRM Data Breach - SecurityWeek

Fortune 500 Companies Hit in Azure Data Theft Campaign - SecurityWeek

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

LiteLLM Supply-Chain Attack - Technology, Banking and Healthcare the Most Affected

153GB of stolen credentials surface after LiteLLM supply chain attack - Help Net Security

Trivy, Not LiteLLM Behind the 2,500 Org Compromise - SecurityWeek

European nation rocked by major hacker attack: “largest data leak in history” | Cybernews

ICO reprimands criminal records body over ‘cybersecurity failings’ that exposed data – PublicTechnology

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

Why Secrets Slip Through Every Layer of Your Security Stack - Security Boulevard

50,000 Stripe Secrets Leaked in Public Code

14,000 Trezor Customers Impacted by Data Breach at ShipMonk - SecurityWeek

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

France investigates tax authority breach after hacker claims 600,000 victims | The Record from Recorded Future News

NHS Blood and Transplant investigate data breach due to pager use - BBC News

RingCentral data breach exposed info of 1.6 million accounts

Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping

McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen - Security Affairs

Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak - gHacks Tech News

Scottish prosecutors cast eye over leaky supplier after staff data exposed

Healthtech firm CareCloud data breach impacts 3.7 million patients

SafePal data breach impacts 39,798 customers, stolen info for sale

Scottish Govt Suffers Potentially Widening Data Breach

Advanced Cyberattacks Target Legal Professionals to Compromise Proceedings - NACABAR Announces CLE to Prepare Lawyers to Respond

Hackers Expose Data of 1.2 Million Heights Finance Customers

Latvian officials resign after cyberattack exposes data on 1.2 million people | The Record from Recorded Future News

Sakura Internet hack exposes data of up to 1.36 million accounts

Data/Digital Sovereignty

Cybersecurity Sovereignty is Having its Moment, but the Channel is Keeping its Head - Security Boulevard

Denial of Service/DoS/DDoS

Linux Botnet Evooo1Bot Expands Mirai Capabilities Beyond DDoS

Why connectivity and cybersecurity can't be treated separately

Large-scale DDoS attacks disrupted Threema secure messaging service

Fraud, Scams and Financial Crime

UK Fraud Cases Hit Record High - Infosecurity Magazine

AI is making fraud harder to spot and identity harder to prove - Help Net Security

Fake Evidence: How Generative AI Is Changing Fraud

Your polite reply to that text is worth $2 on the dark web | Malwarebytes

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

Police bust cybercrime ring accused of stealing €30 million in four-day spree - Help Net Security

Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk | TechRadar

Hackers arrested over €30M bank fraud exploiting service provider flaw

Researchers find a loophole that lets expired credit cards make unauthorized payments - Help Net Security

How Hackers Target Your Retirement Savings | Kiplinger

Banks look for fraud signals in customer behavior - Help Net Security

Identity and Access Management

Weak IAM affects up to 98% of cloud environments - Help Net Security

Microsoft Urges Organizations to Move Beyond Active Directory

Insider Risk and Insider Threats

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack | CyberScoop

Prison for data analyst who tried to extort $2.5 million from his employer

Internet of Things – IoT

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Botnets Based on the Notorious Mirai Code Continue to Emerge - Security Boulevard

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Meta's Ray-Bans are being banned from pubs, restaurants, and theatres

Law Enforcement Action and Take Downs

Police bust cybercrime ring accused of stealing €30 million in four-day spree - Help Net Security

Ukrainian police raid 94 fraudulent call centers, seize $2 million - Help Net Security

Hackers arrested over €30M bank fraud exploiting service provider flaw

Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack | CyberScoop

Prison for data analyst who tried to extort $2.5 million from his employer

Linux and Open Source

Linux Botnet Evooo1Bot Expands Mirai Capabilities Beyond DDoS

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Malware

Infostealers Harvest 1.7 Billion Credentials in Six Months - Infosecurity Magazine

New malware turns Microsoft 365 and Azure into its control center – Computerworld

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra - Infosecurity Magazine

Expired domains are a goldmine for hackers – and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malware | IT Pro

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies - Infosecurity Magazine

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security

Turf War Between Claude Agents Leads to Self-Replicating Malware

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix - Infosecurity Magazine

Fake Chrome update pop-ups may be spreading malware

ChainDrop worm crawls into npm supply chain, evades standard defenses

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

New macOS malware turns stolen browsers into attacker-controlled sessions | CSO Online

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

Windows 11 is fully removing a legacy tool that malware and ransomware have abused for years, meet WMIC

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

Geekom admits to shipping malware-laced network drivers for AMD mini PCs — company responds with guidance, removes malicious package | Tom's Hardware

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign - Infosecurity Magazine

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

Misinformation, Disinformation and Propaganda

Russia’s information warfare after 2022

Researchers publish tool to rate disinformation defense

Mobile

Your polite reply to that text is worth $2 on the dark web | Malwarebytes

New Android malware relays bank cards to fraudsters while victims still hold them - Help Net Security

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

Models, Frameworks and Standards

By the Book: NIST Ransomware Guidelines Provide a Standard for Reasonable Ransomware Response - Security Boulevard

Ice cream makers as ‘critical infrastructure’? EU’s new cybersecurity law suffers wobbly rollout – POLITICO

17 draft Cyber Resilience Act standards are open for comment - Help Net Security

Passwords, Credential Stuffing & Brute Force Attacks

Password spraying attacks surge 155x as hackers exploit MFA gaps

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

I followed password advice for years until I found out it was designed by someone who later regretted it

Why Secrets Slip Through Every Layer of Your Security Stack - Security Boulevard

Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak - gHacks Tech News

Regulations, Fines and Legislation

Donald Trump empowers US private companies to conduct cyber-attacks | Donald Trump | The Guardian

A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo. | CyberScoop

As warfare becomes engineering, the era of the digital mercenary dawns - Defense One

Ice cream makers as ‘critical infrastructure’? EU’s new cybersecurity law suffers wobbly rollout – POLITICO

US courts will start publishing how often the government uses spyware | TechCrunch

Trump’s move to ‘unleash’ private sector hackers raises novel oversight, liability questions | Federal News Network

17 draft Cyber Resilience Act standards are open for comment - Help Net Security

EU introduces strict new security rules for VPNs with the help of industry giants | TechRadar

Multiple Suicides Reported in US Cyber Operations Forces | Security Magazine

Software Supply Chain

ChainDrop worm crawls into npm supply chain, evades standard defenses

Supply Chain and Third Parties

Over 1,000 Charities Hit by Beacon CRM Data Breach - SecurityWeek

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

LiteLLM Supply-Chain Attack - Technology, Banking and Healthcare the Most Affected

153GB of stolen credentials surface after LiteLLM supply chain attack - Help Net Security

Trivy, Not LiteLLM Behind the 2,500 Org Compromise - SecurityWeek

Scottish prosecutors cast eye over leaky supplier after staff data exposed


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Russia’s information warfare after 2022

Researchers publish tool to rate disinformation defense

Non-Nuclear Military AI and the Risk of Misperception for a Nuclear War – CESRAN International

Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes | The Record from Recorded Future News

China

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

World-first autonomous ‘end-to-end’ AI attack against Taiwan tied to Chinese hackers — and the scariest part is that it was fully open source | TechRadar

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Researchers Link Suspected Chinese APT to Hack-for-Hire Operations - Infosecurity Magazine

T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network

Russia

Russia’s information warfare after 2022

Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk | TechRadar

Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others | Reuters

Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes | The Record from Recorded Future News

North Korea

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

Iran

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

What we know about the alleged Iranian hacks on US water utilities | TechCrunch

US charges Iranians for sprawling hacking campaign on government agencies, universities | The Record from Recorded Future News

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

Researchers Link Suspected Chinese APT to Hack-for-Hire Operations - Infosecurity Magazine

US courts will start publishing how often the government uses spyware | TechCrunch

Trump’s move to ‘unleash’ private sector hackers raises novel oversight, liability questions | Federal News Network


Tools and Controls

Your Security Appliances Are the Attack Surface - Security Boulevard

Governance Gap: AI Accountability Crisis

Anthropic sees AI risks rising, no plan to release stronger "Model 2"

The 80% Problem: Why AI resilience is more important than ever - IT Security Guru

The New Currency Of Cybersecurity Is Speed, But Only If The Fix Doesn’t Break Production

Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk | TechRadar

I followed password advice for years until I found out it was designed by someone who later regretted it

By the Book: NIST Ransomware Guidelines Provide a Standard for Reasonable Ransomware Response - Security Boulevard

Weak IAM affects up to 98% of cloud environments - Help Net Security

Irregular says ‘human oversight’ responsible for AI sandbox escape incidents | CyberScoop

Citizen developers are becoming a security problem | perspective | MSSP Alert

Akira Ransomware Uses Safe Mode to Bypass EDR

Google’s AI security agents found 100+ critical software vulnerabilities in just two days - Help Net Security

Microsoft smothers malware by tracking behavior instead of blocking domains | TechRadar

Windows 11 is fully removing a legacy tool that malware and ransomware have abused for years, meet WMIC

Microsoft Urges Organizations to Move Beyond Active Directory

Researchers say OpenAI revoked their access to limited cyber program | TechCrunch

OpenAI Is Pausing Some Work Due To Safety Concerns After Finding It Could Pose Critical Cybersecurity Risks | IBTimes

ChatGPT’s new feature could give infostealers a map of your Mac activity - Help Net Security

Windows 11’s strongest security defenses can be bypassed without a screwdriver - Help Net Security

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model - SecurityWeek

EU introduces strict new security rules for VPNs with the help of industry giants | TechRadar

Banks look for fraud signals in customer behavior - Help Net Security

Copilot tricked into telling reseachers how to hack itself



Vulnerability Management

The New Currency Of Cybersecurity Is Speed, But Only If The Fix Doesn’t Break Production

Most people never update their networking equipment, and cybercriminals know it

8,539 reasons to rethink how vulnerabilities get patched - Help Net Security

‘The economics of vulnerability discovery have changed’: NIST wants to modernize the National Vulnerability Database amid AI advances – cyber experts say it needs to be redesigned with machine-speed in mind | IT Pro

Google’s AI security agents found 100+ critical software vulnerabilities in just two days - Help Net Security

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

How to reduce cybersecurity backlogs and fix vulnerability debt | CSO Online

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model - SecurityWeek

Windows Server 2022 reaches end of mainstream support in 60 days

Vulnerabilities

Microsoft totally breaks Windows Defender virus scans in trying to fix a 0-day flaw - Neowin

CISA: Windows Task Host flaw now exploited by ransomware gangs

Critical RCE flaw in Windows IKE Extension now actively exploited

Microsoft Rolls Out 22 Fresh Security Patches - SecurityWeek

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) - Help Net Security

Max severity SAP Commerce Cloud flaw now targeted in attacks

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure - SecurityWeek

Apple plugs image-processing hole ripe for spyware abuse

Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates - SecurityWeek

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security

Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it | ZDNET

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Apple just patched a critical macOS flaw that let hackers break in without a password | TechSpot

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities - SecurityWeek

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities - SecurityWeek

Hackers Exploiting Unpatched GeoServer Zero-Day - SecurityWeek

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) - Help Net Security

Chrome, Firefox Updates Patch Dozens of Vulnerabilities - SecurityWeek

Google Fixes Two Critical Chrome Flaws in WebGL and Dawn — Update Your Browser

Firefox 154 fixes 58 security bugs, adds Nvidia GeForce Now streaming | PCWorld

Hackers Target Zimbra Servers in Active Exploitation Campaign - SecurityWeek

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

MLflow Vulnerability Exploited for Cloud Credential Theft - SecurityWeek

N-able Bug Exposes Password Vault Master Keys

943 Patches Rolled Out With Oracle's August 2026 Security Update - SecurityWeek

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities - SecurityWeek

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities - SecurityWeek

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls - Infosecurity Magazine

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover - Infosecurity Magazine

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw - SecurityWeek


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 14 August 2026

Black Arrow Cyber Threat Intelligence Briefing 14 August 2026:

-AI Is Changing Cyber Threats. Recovery Is Becoming Just as Important as Prevention

-Why Recovery Readiness Has Become the New Standard for Cyber Resilience

-‘The Easiest Way into a Company Isn’t Always Through a Vulnerability Anymore’: Hackers Are Building a Global Insider Threat Recruitment Network – and They’re Even Offering Referral Bonuses

-Cyber Security Needs a New Operating Model

-The New Mandate for CISOs: Become an Architect of Secure AI

-Ransomware Attacks Spike as World Distracted by AI

-Ransomware Attackers Target Managers to Steal Data and Move Deeper into Corporate Networks

-Ransom-Seeking Hackers Set Their Sights on Wall Street’s Trillion-Dollar Private Equity Firms

-Who Is Liable When AI Goes Rogue? Lawyers See New Risks

-UK Charities Count the Cost of Beacon CRM Cyberattack

-Inside the BBC’s Emergency Plans for a Putin Cyber Attack

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start our review of the specialist and general media this week by looking at the importance of recovery and resilience when responding to a cyberattack. This is essential, as attackers increasingly seek to damage backups and recovery capabilities, requiring organisations to focus not only on preventing attacks but also on recovering from them. Resilience, recovery planning and governance are as important as traditional security controls as cyber threats increase in speed and scale.

At the same time, ransomware remains a significant threat, while criminals continue to exploit familiar weaknesses including compromised credentials, social engineering, insider access and third-party relationships. Reporting this week highlights attackers targeting managers and other employees with valuable business access, alongside growing concerns over AI governance and accountability.

The consistent message for business leaders is that cyber security and resilience must be addressed together, and must consider the risks presented by AI. Contact us to discuss how we help organisations strengthen proportionate cyber security, resilience and governance by understanding and addressing current and evolving cyber risks.


Top Cyber Stories of the Last Week

AI Is Changing Cyber Threats. Recovery Is Becoming Just as Important as Prevention

AI is accelerating software development, but it is also widening the range of systems, identities and data that organisations must protect. Security leaders warn that faster development and increasingly autonomous AI tools can introduce weaknesses more quickly and make attacks harder to contain. This is shifting attention from prevention alone towards cyber resilience, including the ability to identify trusted backups and restore operations quickly after an incident. Organisations are also being encouraged to apply clear access controls to AI systems, regularly test recovery plans and treat resilience as a business continuity priority rather than simply a technical or compliance issue.

https://yourstory.com/2026/08/ai-is-changing-cyber-threats-recovery-is-becoming-just-as-important-as-prevention

Why Recovery Readiness Has Become the New Standard for Cyber Resilience

Ransomware increasingly targets an organisation’s ability to recover, with more than 90% of attacks attempting to delete or tamper with backups and nearly 60% succeeding. This exposes a critical gap between simply storing backup data and being able to restore business operations quickly. The risk is compounded by identity-based attacks, fragmented protection across cloud and on-premises systems, and limited testing of recovery plans. 18% of organisations test recovery monthly, while just one in five report unified backup protection across hybrid environments, increasing the risk of prolonged disruption, financial loss and reputational damage.

https://www.zdnet.com/paid-content/article/why-recovery-readiness-has-become-the-new-standard-for-cyber-resilience/

‘The Easiest Way into a Company Isn’t Always Through a Vulnerability Anymore’: Hackers Are Building a Global Insider Threat Recruitment Network – and They’re Even Offering Referral Bonuses

Cyber criminals are increasingly paying employees to provide access to company systems, approve fraudulent activity or leak sensitive data, creating a growing insider threat across sectors including financial services, telecommunications, logistics and social media. TrendAI found a structured criminal market offering fixed payments, profit sharing and even referral bonuses, with prices ranging from a few hundred dollars for credentials to $1,000 a day for specific internal actions. Organisations should treat unusual staff activity and approval exceptions as potential security concerns, while reducing reliance on single-person authority for high-risk transactions.

https://www.itpro.com/security/the-easiest-way-into-a-company-isnt-always-through-a-vulnerability-anymore-hackers-are-building-a-global-insider-threat-recruitment-network-and-theyre-even-offering-referral-bonuses

Cyber Security Needs a New Operating Model

The European Central Bank has warned that AI is accelerating cyber attacks to the point where traditional security processes may no longer move quickly enough. Europe’s largest banks have been asked to submit plans addressing AI-enabled cyber threats by 31 October 2026, reflecting a wider regulatory shift towards treating AI as an operational risk rather than an emerging concern. As attackers increasingly use AI to identify weaknesses and develop attacks at scale, organisations will need to prioritise risks based on real-world exposure and strengthen their ability to respond before vulnerabilities can be exploited.

https://www.csoonline.com/article/4206138/cybersecurity-needs-a-new-operating-model.html

The New Mandate for CISOs: Become an Architect of Secure AI

AI adoption is accelerating faster than many organisations can govern it, with Netskope reporting that 73% of organisations now use AI but only 7% enforce security policies in real time. Despite 90% of cyber security professionals increasing AI security budgets this year, 29% feel less secure than 12 months ago. The growing use of unapproved AI tools is increasing the risk of sensitive data exposure and inconsistent controls. Effective AI adoption therefore depends on clear governance, appropriate safeguards and strong data protection, enabling organisations to innovate while maintaining oversight and reducing business risk.

https://www.raconteur.net/technology/the-new-mandate-for-cisos-become-an-architect-of-secure-ai

Ransomware Attacks Spike as World Distracted by AI

Comparitech recorded 799 ransomware attacks in July, a 20% rise making it the second busiest month of the year. Finance, technology, pharmaceutical and education organisations saw the sharpest increases. The United States accounted for 322 incidents, far ahead of Germany with 40. Two ransomware groups, The Gentlemen and Qilin, were linked to almost a third of recorded attacks, highlighting that established threats such as stolen login details and unpatched systems remain significant despite growing attention on AI related risks.

https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934

Ransomware Attackers Target Managers to Steal Data and Move Deeper into Corporate Networks

Ransomware groups are increasingly targeting managers and other senior employees because their everyday access can provide a route to sensitive data, financial processes and wider corporate systems. Zscaler tracked 351 victims across 334 organisations in one month, with 62% holding manager-level roles or above and around 75% working in finance, sales, operations, HR or marketing. Industrial organisations accounted for 35.5% of victims. The findings highlight that attackers do not need administrator access to cause significant disruption, making tighter access controls, verification of unusual requests and rapid investigation of compromised accounts increasingly important.

https://cybersecuritynews.com/ransomware-attackers-target-managers/

Ransom-Seeking Hackers Set Their Sights on Wall Street’s Trillion-Dollar Private Equity Firms

Ransom-seeking criminals have targeted dozens of major US financial institutions, private equity firms, law firms and other businesses using convincing phone calls and fake login websites. Google reported on the campaign, while Reuters' analysis of 72 malicious websites listed in Google’s report found that more than 200 organisations had been targeted over a five-week period. Attackers impersonated internal IT support teams and persuaded employees to disclose passwords and multi-factor authentication codes, allowing them to take control of accounts. The campaign highlights how simple manipulation of employees can bypass sophisticated technical security controls, particularly where highly sensitive financial and commercial data could make organisations attractive ransom targets.

https://www.independent.co.uk/tech/google-hackers-wall-street-ransom-b3029209.html

Who Is Liable When AI Goes Rogue? Lawyers See New Risks

As autonomous AI agents become more capable of acting without human oversight, recent incidents involving OpenAI, Anthropic and Meta have raised new questions over legal responsibility when AI systems breach corporate networks. Potential claims could come from affected businesses, customers, employees, shareholders and regulators, with liability potentially extending to both AI developers and organisations deploying the technology. Existing negligence and computer access laws may apply, although courts are still determining how concepts such as intent and foreseeability should be treated when an AI system acts independently. California has also introduced legislation preventing companies from avoiding liability simply by blaming the AI itself.

https://indianexpress.com/article/technology/artificial-intelligence/who-is-liable-when-ai-goes-rogue-lawyers-see-new-risks-10822929/

UK Charities Count the Cost of Beacon CRM Cyberattack

Beacon CRM, a platform used by more than 1,500 organisations, has confirmed a cyberattack in which customer database backups were likely stolen. Customers have been advised to assume all information held on the platform before 27 July was accessed and may have been readable despite encryption. A number of UK charities have confirmed potential exposure of personal information, including names, contact details, dates of birth and donation records. Early evidence suggests compromised login credentials were used to gain access, highlighting the potential impact of a supplier breach on organisations and the people whose data they hold.

https://www.theregister.com/security/2026/08/05/uk-charities-count-the-cost-of-beacon-crm-cyberattack/5283305

Inside the BBC’s Emergency Plans for a Putin Cyber Attack

The BBC is strengthening plans to keep the public informed if a major cyberattack or power outage disrupts critical UK infrastructure. Its contingency planning prioritises radio, particularly FM, as a resilient communications channel when internet, television or mobile services may be unavailable. The UK Government is also preparing to encourage households to keep battery-powered or wind-up radios and other emergency supplies. Recent exercises involving 120 experts from the Cabinet Office, NHS and Ministry of Defence have tested scenarios affecting hospitals and traffic systems, highlighting growing concern over the resilience of essential services and communications.

https://inews.co.uk/news/media/bbc-emergency-putin-cyber-attack-4689896?ITO=newsnow



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware attacks spike as world distracted by AI

Europe Ransomware Attacks Up 29%, TicTac Research Finds

Ransomware Surges in July After Q2 Lull - Infosecurity Magazine

Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks

Why managers are ransomware's top targets now - and 6 ways to stay safe | ZDNET

Ransom-seeking hackers set their sights on Wall Street’s trillion-dollar private equity firms: report | The Independent

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

New StormEncryptor ransomware used by former Medusa affiliate

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

ExfilSquad Targets New Victims, Shares Data via Torrents

DeadLock ransomware uses blockchain to resist infrastructure takedown

Ransomware and Destructive Attack Victims

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

ExfilSquad Targets New Victims, Shares Data via Torrents

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout | The Record from Recorded Future News

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

Major hedge funds targeted in wave of attempted cyberattacks | Fortune

Bay Area city declares state of emergency over malicious cyberattack

Ransomware attack on Health Sciences Centre affects doors, ventilation and air-conditioning | CBC News

Wesco confirms security incident after ExfilSquad claims data theft

French rugby club Stade Français restores systems after cyberattack, probes data leak | The Record from Recorded Future News

Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo - Infosecurity Magazine

Manitoba health minister says cybersecurity priority after hospital attack

Phishing & Email Based Attacks

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

AI Phishing Now Frighteningly Normal, Hard to Detect

Real emails, hijacked payments: Two H1 2026 attack chains

Ofcom UK Blocked 481,521 Malicious Emails Over the Past 3 Years - ISPreview UK

Steam hardware distributor hit by cyberattack, 'expect fake messages,' Valve warns — Europe vendor has personal information and hardware purchase details stolen | Tom's Hardware

Other Social Engineering

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Hackers talked their way into Levi’s, and three computers were enough

Sherlock Holmes was the “OG” Social Engineer

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare | ZDNET

Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix

2FA/MFA

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

New Zealand sanctions Russian hackers, propaganda groups over Ukraine war | The Record from Recorded Future News

Artificial Intelligence

Ransomware attacks spike as world distracted by AI

CISO AI risk management drives business growth - SiliconANGLE

The new mandate for CISOs: become an architect of secure AI - Raconteur

Frontier AI Has a Cybersecurity Expertise Problem - Security Boulevard

Humans in the loop miss a third of dangerous AI coding agent requests

AI agent creates fake personas, plants malware during UK security test | SC Media UK

Three Disclosures, Three Different Unintended Failures (OpenAI, Anthropic, and Now AISI) | Lowenstein Sandler LLP - JDSupra

AI experts are panicking about a terrifying new era of hacking. What can normal people do? | The Independent

UK cyber agency warns over frontier AI behaviour

Who is liable when AI goes rogue? Lawyers see new risks | Technology News - The Indian Express

IBM’s 2026 Cost of a Data Breach Report Signals a New Era of AI-Driven Cyber Risk | Alston & Bird - JDSupra

Cyberattacks are getting faster as AI helps hackers scale | Inquirer Technology

The AI Governance Gap Is a Leadership Problem: Waiting Won't Close It - SecurityWeek

Cyber resilience takes center stage as AI reshapes the CISO role - SiliconANGLE

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Meta becomes the third AI giant in two weeks to admit its model went rogue | TechSpot

Who Is Liable When an AI Agent Hacks a Third Party? | BakerHostetler - JDSupra

Hidden Text in PDFs Is Hijacking This AI Assistant - Decrypt

Innovation or Negligence? What Recent AI Hacks Mean for the Future of Cybersecurity

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks | TechRadar

AI deployments are stretching enterprise security to its limits - Help Net Security

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack - SecurityWeek

AI sandbox escape uncovered in Microsoft Copilot flaw - SiliconANGLE

Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agents | IT Pro

Researcher Claims Control of ChatGPT Secure Sandbox

Prompt injection isn't the bug, AI agent frameworks are

Why your AI orchestration framework is a critical security decision | CSO Online

Advertisers are trying to influence AI bots with secret ads

"GhostJacking" Exposes Identity Governance Gaps in AI Agents

The UK needs better AI governance

The Sandbox Failed: How OpenAI's Experimental AIs Went Rogue and Attacked Hugging Face

OpenAI reveals upcoming Astra model may possess 'critical’ hacking capabilities - SiliconANGLE

Chinese startup Moonshot's AI model breaks out of testing environment, researchers say

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data - SecurityWeek

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

How to report an AI Act violation in the EU - Help Net Security

Senior Derbyshire detective under investigation over use of AI - BBC News

An AI agent was asked to book a gym class, whe none was available, it decided to hack the system and jump the queue | TechSpot

Bots/Botnets

Kimwolf botnet rebuilt to survive takedowns, researchers say | CyberScoop

Careers, Roles, Skills, Working in Cyber and Information Security

What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience | ZDNET

'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today | ZDNET

Cyberattacks drive companies to hire specialised security talent in AI, cloud & threat intelligence - The Economic Times

Cloud/SaaS

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

Violent Physical Crypto Thefts Surge to $30m in Losses - Infosecurity Magazine

Go-Based macOS Malware Steals Crypto and Secrets - Infosecurity Magazine

Six npm Packages Read C2 Addresses From Ethereum Wallet - Infosecurity Magazine

Cyber Crime, Organised Crime & Criminal Actors

'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitment network – and they’re even offering referral bonuses | IT Pro

UK man tied to The Com sentenced for abusing 117 victims | CyberScoop

Looking Beyond the Numbers: Understanding Malicious Domain Registration Data

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Snowflake attacker pleads guilty to hack of 165 companies’ data | CSO Online

Data Breaches/Leaks

UK charities count the cost of Beacon CRM cyberattack

Beacon security incident: Hackers steal details of hundreds of lawyers who used mental health charity LawCare | Law Gazette

Beacon CRM confirms cyberattack exposed UK charity data | SC Media UK

Healthcare and Victim Support Charities Affected by Beacon Cyber Incid - Infosecurity Magazine

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack - SecurityWeek

Mozilla Issues New Firefox GPG Key Following Exposure - SecurityWeek

Hackers talked their way into Levi’s, and three computers were enough

3.8 Million Impacted by Unlimited Technology Systems Data Breach - SecurityWeek

Swiss government SharePoint breach compromised 200 accounts

London cops handed victim's new address and number to her stalker, watchdog says

Framework loses customer data in Metabase zero-day attack

Logistics Giant Ceva Suffers Data Breach Impacting European Clients - Infosecurity Magazine

Steam hardware distributor hit by cyberattack, 'expect fake messages,' Valve warns — Europe vendor has personal information and hardware purchase details stolen | Tom's Hardware

Champions Cup rugby team hacked in ransom attack with player data at risk

9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old

Data/Digital Sovereignty

US kill switch: 74% of European firms fear losing tech | Proton

75% of European businesses fear a US tech kill switch - American companies should, too | ZDNET

Denial of Service/DoS/DDoS

DDoS attacks over 1 Tbps surged fivefold in the second quarter

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common - Help Net Security

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Encryption

HP thin client disk encryption bypassed | Cybernews

Fraud, Scams and Financial Crime

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Identity and Access Management

"GhostJacking" Exposes Identity Governance Gaps in AI Agents

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Insider Risk and Insider Threats

'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitment network – and they’re even offering referral bonuses | IT Pro

North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Internet of Things – IoT

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

Law Enforcement Action and Take Downs

UK man tied to The Com sentenced for abusing 117 victims | CyberScoop

Snowflake attacker pleads guilty to hack of 165 companies’ data | CSO Online

Linux and Open Source

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

How to combat the new threats in open-source libraries - SiliconANGLE

Growing Up The Hard Way

Malware

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Enterprise passkey security under threat from malware | CSO Online

How to combat the new threats in open-source libraries - SiliconANGLE

Go-Based macOS Malware Steals Crypto and Secrets - Infosecurity Magazine

Six npm Packages Read C2 Addresses From Ethereum Wallet - Infosecurity Magazine

Kimwolf botnet rebuilt to survive takedowns, researchers say | CyberScoop

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities - SecurityWeek

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix

Hackers breach TrueConf to trojanize client installers with backdoors

Lumma Stealer Malware Found in Pirated Copies of the “The Odyssey” - Security Boulevard

Misinformation, Disinformation and Propaganda

China launches cybersecurity investigation into Palo Alto Networks products - Global Times

Mobile

Coruna, DarkSword iOS Exploits Proliferate Globally

Android malware combo takes out loans and relays victims' credit cards

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G - Help Net Security

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Models, Frameworks and Standards

How to report an AI Act violation in the EU - Help Net Security

Department of War Suspends CMMC Phase 2 Assessment Requirements: Top Points For Defense Contractors | DLA Piper - JDSupra

HIPAA Security Rule Revamp? | McAfee & Taft - JDSupra

Passwords, Credential Stuffing & Brute Force Attacks

Enterprise passkey security under threat from malware | CSO Online

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Microsoft Removes Picture Password Setup in Windows 11, Pushing PINs, Passwords, and Biometrics - gHacks Tech News

Regulations, Fines and Legislation

How The UK’s Recent Cabinet Changes Could Impact Cybersecurity | SC Media UK

How to report an AI Act violation in the EU - Help Net Security

Outdated Cybercrime Laws Put Security Researchers at Risk

German cabinet approves new spying rules | Semafor

The UK needs better AI governance

HIPAA Security Rule Revamp? | McAfee & Taft - JDSupra

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

House-passed cyber bill for small businesses gets Senate companion | FedScoop

Social Media

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Software Supply Chain

How to combat the new threats in open-source libraries - SiliconANGLE

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Supply Chain and Third Parties

Beacon CRM confirms cyberattack exposed UK charity data | SC Media UK

UK charities count the cost of Beacon CRM cyberattack

Beacon security incident: Hackers steal details of hundreds of lawyers who used mental health charity LawCare | Law Gazette

Framework loses customer data in Metabase zero-day attack

Logistics Giant Ceva Suffers Data Breach Impacting European Clients - Infosecurity Magazine

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack - SecurityWeek


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Inside the BBC’s emergency plans for a Putin cyber attack

The Iran War Hits Home - FPIF

German intelligence services may be allowed to launch pre-emptive cyberattacks against Russia | European Pravda

Nation State Actors

Experts weigh in: Why is state involvement in cyberattacks so difficult to prove? - RTL Today

China

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

Russia

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Inside the BBC’s emergency plans for a Putin cyber attack

German intelligence services may be allowed to launch pre-emptive cyberattacks against Russia | European Pravda

Russian military hackers pose as recruiters to target Ukrainian IT workers | The Record from Recorded Future News

New Zealand sanctions Russian hackers, propaganda groups over Ukraine war | The Record from Recorded Future News

North Korea

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks | TechRadar

North Korean spies are running local LLMs to cause AI mischief

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security

North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Iran

The Iran War Hits Home - FPIF

Attacks on America’s ‘super vulnerable’ water systems should be a wake up call after years of warnings, cybersecurity experts say | The Independent

Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks


Tools and Controls

Why recovery readiness has become the new standard for cyber resilience | ZDNET

New N-able Zero Day Puts MSPs on Defensive - InfoRiskToday

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

The AI Governance Gap Is a Leadership Problem: Waiting Won't Close It - SecurityWeek

AI is changing cyber threats. Recovery is becoming just as important as prevention | YourStory

More than half of AI-generated patches are broken | CyberScoop

Cyber resilience takes center stage as AI reshapes the CISO role - SiliconANGLE

OpenAI Pauses Some Work on New Astra Model on Cyber Concerns

OpenAI launches GPT-5.6-Cyber and expands Daybreak with Red and Blue access tiers - Neowin

Meta Confirms One of Its AI Models Breached a Company During a Misconfigured Cyber Test - gHacks Tech News

Defenders Need to Think in Chains, Not Checklists

Enterprise Defenses Recovered at the Edge and Collapsed Inside

338 million attack simulations reveal the state of enterprise defense - Help Net Security

Meta AI model hacked a company during misconfigured cyber test

AI sandbox escape uncovered in Microsoft Copilot flaw - SiliconANGLE

Researcher Claims Control of ChatGPT Secure Sandbox

CISO principles for navigating cybersecurity incident disclosure

71% of CISOs spend 10+ hours on board reports - Help Net Security

Three in four AI-generated vulnerability patches leave something broken - Help Net Security

AI struggles to patch vulns without adult supervision

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

MSP, MSSP, MDR or MXDR: What are you really buying? | perspective | MSSP Alert

PYMNTS | Cybersecurity M&A Spree Maps the Next Attack Surface

The UK needs better AI governance

The inconvenient truth about AI pentesting: someone has to check all the work



Vulnerability Management

Cybersecurity needs a new operating model | CSO Online

More than half of AI-generated patches are broken | CyberScoop

Defenders Need to Think in Chains, Not Checklists

Three in four AI-generated vulnerability patches leave something broken - Help Net Security

AI struggles to patch vulns without adult supervision

Op-Ed: Are ‘Common Vulnerabilities and Exposures’ the reality of chronic cyber insecurity? - Digital Journal

NIST wants to overhaul its vulnerability database for the AI age | CyberScoop

CISA cautions against rigid rules for future of cyber vulnerability program - Nextgov/FCW

Why patching networks against cyberattacks is 'very scary' in the age of AI - Breaking Defense

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix - Help Net Security

NATO and an AI startup can now name and track software vulnerabilities | CyberScoop

Vulnerabilities

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day - Infosecurity Magazine

Microsoft patches LegacyHive Windows zero-day vulnerability

Nightmare Eclipse Drops Windows Zero-Day Exploit 'ShieldBreak' - SecurityWeek

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) - Help Net Security

ClamAV 1.5.4 Open-Source Antivirus Fixes Eight Security Vulnerabilities

New N-able Zero Day Puts MSPs on Defensive - InfoRiskToday

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

vCenter Flaw Exploited Just Five Days After Disclosure - Infosecurity Magazine

Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Zoom flaw allowed attackers to take control of your iOS and Android devices - PhoneArena

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws - SecurityWeek

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP | ZDNET

Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform - SecurityWeek

Hackers breach TrueConf to trojanize client installers with backdoors

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Ivanti EPM Update Patches Remotely Exploitable Flaws - SecurityWeek

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data - SecurityWeek

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust - Infosecurity Magazine

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager - SecurityWeek

HP thin client disk encryption bypassed | Cybernews

Multiple Flaws in Enterprise Java Platforms Allow Attackers to Execute Remote Code

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Swiss government SharePoint breach compromised 200 accounts

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers - Help Net Security

WordPress 7.0.4 Patches Remote Code Execution Vulnerability - SecurityWeek

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People - SecurityWeek


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 07 August 2026

Black Arrow Cyber Threat Intelligence Briefing 07 August 2026:

-AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

-AI Isn't the Biggest Cyber Security Risk. Yesterday's Security Model Is

-Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions

-AI Is ‘Both the Weapon and the Target’ in Latest Wave of Cyberattacks

-The $5 Million Threat: AI Is Supercharging Phishing Attacks

-Humans, Not AI, Still a Cause of Most Cyber Losses in First Half of Year

-Device Code Phishing Up 1,500% in 2026; Vishing Doubles

-Attackers Are Using Microsoft’s Legitimate Login System to Camouflage Phishing Attacks

-Hackers Can Weaponise Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

-Russian Spies Take Their Half-Click Email Attack from Zimbra to Outlook

-Cloud and SaaS Environments Now Top Targets for Attackers

-The Modern CISO Is Becoming the Next CFO

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Our review of the specialist and general media this week reinforces our consistent message that if organisations want to improve their cyber security and resilience, they must go beyond technology.

While AI is hitting the news again this week with agentic AI taking unauthorised actions, we highlight that the wider risks presented by AI require business leaders to ensure there are appropriate controls to quickly identify and respond to cyber threats.

Nonetheless, this week’s review also highlights that social engineering and human actions remain a major cause of cyber loss. Phishing, including when powered by AI, can enable attackers to take over an employee’s account to access emails and documents, and to hijack conversations for payment fraud. Research also demonstrates how Copilot could be misused to accelerate an attack once an account has been compromised.

Our objective in preparing this review is to help business leaders to understand how the threat landscape is evolving. These threats should be addressed by a leadership team that has a solid understanding of the fundamentals of cyber security and resilience, so that the leadership team can ensure the risks are understood and appropriately managed. As above, this is not an IT issue; it is for the leadership team to ensure that risks are managed across the organisation. Contact us to discuss how we support business leaders to achieve this in a proportionate manner.


Top Cyber Stories of the Last Week

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

The UK AI Security Institute found that advanced AI agents took unauthorised actions on the live internet during controlled cyber tests. Agents were recorded taking 19 unsanctioned actions across 10 of the 122 test runs. Activities included attempting to add malicious code to a public software project, creating false identities, contacting real people and disguising earlier actions. Researchers intervened before the most serious activity succeeded and found no evidence of harm. However, the tests demonstrated that agents could adopt unintended, deceptive methods while pursuing a goal. Organisations testing powerful AI agents should tightly restrict internet access and monitor activity in real time.

https://securityaffairs.com/196695/ai/ai-deception-emerges-in-cyber-tests-as-agents-target-real-people-and-systems.html

AI Isn't the Biggest Cyber Security Risk. Yesterday's Security Model Is

Artificial intelligence is accelerating the speed at which cyber threats develop, exposing weaknesses in security models that rely heavily on manual investigation and decision-making. Attacks that once unfolded over days or weeks can now progress within hours or minutes, reducing the time available to protect operations. Organisations should therefore assess how quickly they can detect unusual activity, make decisions, contain affected systems and restore critical services. Effective cyber security now depends on combining automated response with human judgement, governance and accountability.

https://www.forbes.com/councils/forbestechcouncil/2026/08/03/ai-isnt-the-biggest-cybersecurity-risk-yesterdays-security-model-is/

Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions

Cisco Talos has found that criminals are bypassing safety controls in commercial AI tools by splitting malicious projects across multiple sessions and presenting harmful activity as authorised security testing. The research covered tools including Claude Code, Codex, Cursor and Gemini, and found safeguards offered limited protection across platforms. AI capability largely reflected the operator’s existing skill, with experienced criminals building highly advanced attack tools while less capable users still produced working systems, including one network controlling nearly 2,000 Android TVs. Organisations should expect security weaknesses to be identified more quickly and exploitation to follow sooner.

https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/

AI Is ‘Both the Weapon and the Target’ in Latest Wave of Cyberattacks

CrowdStrike recorded an 89% rise in AI-enabled malicious activity during 2025, with criminals and nation states using AI to accelerate attacks and target organisations’ own AI systems. Attackers are stealing access credentials and compromising trusted software packages to reach wider networks. One attacker abused stolen AI access credentials to generate around 200,000 requests in two minutes, while another campaign compromised more than 300 software dependencies in a single day. CrowdStrike observed that almost nine in ten exploitations involving public proof-of-concept code happened within two days of publication, sharply reducing the time organisations have to patch.

https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534

The $5 Million Threat: AI Is Supercharging Phishing Attacks

Phishing remains the leading entry point for data breaches for the fourth consecutive year, with voice and text message scams costing organisations an average of $5.29 million per incident. AI is making these attacks more convincing and easier to scale, with deepfakes, realistic fake voice or video messages, used in 45% of AI-driven attacks studied. Despite being a well-understood threat, phishing-related breaches still take an average of 251 days to identify and contain, reinforcing the need for stronger technical controls alongside staff awareness training.

https://www.fortra.com/blog/5-million-threat-ai-supercharging-phishing-attacks

Humans, Not AI, Still a Cause of Most Cyber Losses in First Half of Year

Cyber insurance provider Resilience reports that human error remains the leading driver of cyber losses, with more than 85% of incurred losses in the first half of 2026 linked to phishing, social engineering or transfer fraud. Artificial intelligence is increasing the quality and realism of these attacks, including more convincing emails and voice impersonation, but fully autonomous AI attacks have not yet appeared in Resilience’s claims. Ransomware-related extortion accounted for 73% of incurred losses despite making up only 5.8% of claims.

https://www.claimsjournal.com/news/national/2026/07/30/339184.htm

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

CrowdStrike recorded a 15-fold rise in device code phishing during the first half of 2026 and a doubling of voice phishing over the same period. Device code phishing tricks users into approving fraudulent cloud logins, while voice phishing uses phone calls to obtain credentials and security codes. These techniques can bypass established security controls, while voice phishing can exploit mobile devices with fewer protections and leave fewer traces for security teams to investigate. In one case, attackers gained access and registered a new authentication device within four minutes, highlighting how quickly a cyberattack can unfold.

https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles

Attackers Are Using Microsoft’s Legitimate Login System to Camouflage Phishing Attacks

Check Point identified more than 200 phishing emails in a campaign targeting around 120 organisations. The campaign disguised emails as Microsoft Planner notifications about urgent HR updates, then directed victims to genuine Microsoft login pages, reducing some of the usual warning signs of phishing. Victims were asked to approve access for a malicious application, which could then expose Microsoft 365 data including emails, files, Teams chats, calendars, SharePoint and OneDrive. The campaign is no longer active, but the technique is becoming more widespread, reinforcing the need for employees to scrutinise sender details and link destinations even when Microsoft’s genuine authentication pages are used.

https://www.helpnetsecurity.com/2026/07/30/microsoft-authentication-system-phishing/

Hackers Can Weaponise Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Researchers have demonstrated how a compromised Microsoft 365 employee account could allow criminals to misuse Copilot to identify senior targets, imitate trusted writing styles and take over a chief executive’s email account. In the test, attackers quickly found a pending $247,500 wire transfer and sent a convincing request to redirect the payment. They also used automated inbox rules to hide security alerts and finance team responses. The findings show that AI assistants with email access can significantly accelerate fraud, making monitoring of AI-enabled accounts, inbox rule abuse and unusual session activity increasingly important.

https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/

Russian Spies Take Their Half-Click Email Attack from Zimbra to Outlook

A Russian espionage group has expanded an email-based attack from the Zimbra email system to on-premises Microsoft Exchange servers, targeting government bodies and organisations across telecommunications, financial services, hospitality and aerospace. Simply opening a malicious message in Outlook Web Access can allow attackers to run code within an authenticated mailbox session, without requiring a link or download. The resulting browser implant can steal data, leave few traces and remain active after password changes, browser restarts or even a full device rebuild. Microsoft’s cloud-based Exchange Online service is not affected.

https://www.theregister.com/security/2026/07/30/russian-spies-take-their-half-click-email-attack-from-zimbra-to-outlook/5281033

Cloud and SaaS Environments Now Top Targets for Attackers

Cloud and Software-as-a-Service environments have become leading targets for cyber attackers, as attacks increasingly focus on compromising identities and trusted access. Attackers are increasingly exploiting trusted user accounts, email systems and legitimate administration tools rather than relying on traditional malware. Around two-thirds of phishing emails passed email authentication checks, while 39% used novel social engineering techniques and VIP users were targeted in 25% of observed attacks. The growing use of artificial intelligence is also expanding the attack surface and helping criminals generate exploit code and automate cyberattacks.

https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/

The Modern CISO Is Becoming the Next CFO

The CISO role is evolving from a technical function into a strategic executive position as cyber risk becomes inseparable from business risk. Splunk’s 2026 CISO Report found that nearly all CISOs now oversee artificial intelligence governance and risk management, while 78% report concerns about personal liability following security incidents, up from 56% a year earlier. Some organisations are building specialist security leadership teams under a single accountable CISO, similar to the way large finance functions operate.

https://www.csoonline.com/article/4193375/the-modern-ciso-is-becoming-the-next-cfo.html



Threats

Ransomware, Extortion and Destructive Attacks

The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encrypting Your Files

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Ransom Cartel ransomware creator sentenced to 16 years in prison

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks - SecurityWeek

Ransomware and Destructive Attack Victims

The most famous brand in physical security got pwned by ShinyHunters

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Jaguar Land Rover to Cut Jobs After Major Cyber Attack | EasternEye

Phishing & Email Based Attacks

Russian spies take their half-click email attack from Zimbra to Outlook

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Attackers exploit genuine Microsoft login screens to phish users | Cybernews

The $5 Million Threat: AI Is Supercharging Phishing Attacks| Fortra

Russian hackers deploy OWAReaper Exchange backdoor

Fake Bank of America Phishing Scam Installs Remote Access Malware - Infosecurity Magazine

Phishing attacks don't look fake anymore: Watch for these 7 scams | PCWorld

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

COLDCARD security audit phishing attack installs remote access tool

Other Social Engineering

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Why brand impersonation is becoming an initial access vector - Security Affairs

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove - Help Net Security

COLDCARD security audit phishing attack installs remote access tool

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Fake IRS letters direct crypto holders to bogus compliance portal - Help Net Security

2FA/MFA

How MFA gets hacked — and strategies to prevent it | CSO Online

Artificial Intelligence

One-in-five breaches are now AI-related, IBM warns | IT Pro

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

AI models are behaving unexpectedly. Experts warn of "a really bumpy road" ahead. - CBS News

'Rogue' AI posed as human in shock hack as experts warn it may be ‘too late’ to stop it - Daily Star

UK Cyber Test: AI Agent Attempted to Social Engineer Open So...

NCSC concerned over 'unsanctioned actions' of frontier AI models - UKTN

Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says - Nextgov/FCW

The $5 Million Threat: AI Is Supercharging Phishing Attacks| Fortra

Excuses like 'AI did it' don't exist in the eyes of the law

Gartner: Why cybersecurity must shift to outcomes against AI-led attacks | Computer Weekly

AI Isn't The Biggest Cybersecurity Risk. Yesterday's Security Model Is

CrowdStrike: AI is now both the weapon and the target in cyberattacks | CyberScoop

Cybercrime goes subscription: AI, malware and infrastructure on demand - Help Net Security

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

UK firms report rise in AI-driven cyber attacks - CIR Magazine

Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks - Infosecurity Magazine

Sophisticated Cyberattackers Boost Productivity Using AI

OpenAI's models secretly joined forces months ahead of hacking Hugging Face | Tech News - Business Standard

When AI goes rogue — Harvard Gazette

OpenAI's AI models secretly built a message board to coordinate hacking - Digital Trends

The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop | WIRED

Suppliers, logins, and AI tools are all becoming attack paths - Help Net Security

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies - Infosecurity Magazine

The Hugging Face attack shows how fast one breach can spread | perspective | MSSP Alert

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale - SecurityWeek

Hidden prompt turns Microsoft Copilot into an AI worm | Malwarebytes

How OpenAI's and Anthropic’s AI models hacked other companies : NPR

What Claude’s real-world breaches reveal about AI safety tests - The New Stack

OpenAI's Escaped Models Were Allegedly Rampaging More Extensively Than Previously Reported

Why AI has eclipsed cyberattacks as firms' top compliance problem | American Banker

OpenAI is investigating more incidents of AI agents going rogue days after hack - Digital Trends

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers - Help Net Security

Why the Browser is Becoming Security's Front Line in the Age of AI - Infosecurity Magazine

OpenAI reveals how criminals used ChatGPT to run scams - Help Net Security

Your enterprise AI footprint is about three times bigger than your model list - Help Net Security

AI Risks Require Tougher Cyber Defenses, Top US Officials Warn

Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents - Infosecurity Magazine

AI Sends Global Crime Syndicates Into Fraud Nirvana

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels - SecurityWeek

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits - Infosecurity Magazine

Anthropic: Security Gaps, Not Model Issues Led to Claude Attacks

Google dev kit spurs first-ever agent-on-agent violence

Resilience analysis shows AI is strengthening existing cyber attack methods - Reinsurance News

Bypassing AI guardrails is so easy a script kiddie can do it

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Companies push AI, sysadmins keep it on a short leash - Help Net Security

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

AI Now Fuels Over Half of Africa’s Cybercrime, Study Finds

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

New Tool Traces AI Videos Back to Their Source

Careers, Roles, Skills, Working in Cyber and Information Security

AI isn’t closing the skills gap — it’s exposing the validation gap | CSO Online

Center for Cyber Safety and Education Marks 15 Years of Expanding Access to Cybersecurity Careers

Cloud/SaaS

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Russian hackers deploy OWAReaper Exchange backdoor

Cloud and SaaS Environments Now Top Targets for Attackers - Infosecurity Magazine

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Online ad firm Adform’s script compromised to steal cryptocurrency

Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch

Fake IRS letters direct crypto holders to bogus compliance portal - Help Net Security

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Cryptominer Abuses Linux PAM to Hide From SOC Analysts - Infosecurity Magazine

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Cyber Crime, Organised Crime & Criminal Actors

Cybercrime goes subscription: AI, malware and infrastructure on demand - Help Net Security

Foxtrot Network: The shadowy gang recruiting teen killers across Europe - BBC News

Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop

INTERPOL flags AI as the new engine of African cybercrime - Help Net Security

AI Now Fuels Over Half of Africa’s Cybercrime, Study Finds

Teen hackers tell BBC how police are helping them use their skills for good - BBC News

Data Breaches/Leaks

Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says | Euronews

31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected | The Record from Recorded Future News

UK’s Police National Legal Database Reveals Data Breach - Infosecurity Magazine

Experts react as Department for Education cyber attack exposes 607,000 records - IT Security Guru

UK government investment arm cops to 40-hour leak of officials' contact details

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

South Korea fines telco giant KT $39 million for customer data breach

English National Ballet suffers possible data breach following cyber attack | The Standard

150,000 Impacted by Madera Community Hospital Data Breach - SecurityWeek

Polish convenience store chain Żabka hacked through third-party account | The Record from Recorded Future News

Sheffield Hospitals Charity affected by cyber attack - BBC News

Motiv8: Portsmouth charity hacked as CEO explains next steps

Encryption

Apple challenges UK encryption order | Cybernews

The quantum imperative: Why federal cybersecurity cannot wait for tomorrow’s threat | Federal News Network

Fraud, Scams and Financial Crime

AI Sends Global Crime Syndicates Into Fraud Nirvana

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

WhatsApp Scam Hijacks Accounts via Linked Devices Feature - Infosecurity Magazine

Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims | CyberScoop

Interpol Leverages Global System to Curtail Fraud Payments

CAF Bank reopens online service but warns of further outages

Buying TikTok followers can expose users to scams and account theft - Help Net Security

Identity and Access Management

Non-human identities are 91% of everything active in production - Help Net Security

Insider Risk and Insider Threats

Humans, Not AI, Still A Cause of Most Cyber Losses in First Half of Year

Humans remain ‘weakest link’ when it comes to cyber attacks - Insurance Post

Insurance

Underwriters Making Better Cyber Risk Decisions | Kovrr - Security Boulevard

Internet of Things – IoT

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Law Enforcement Action and Take Downs

Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims | CyberScoop

Interpol Leverages Global System to Curtail Fraud Payments

Ransom Cartel ransomware creator sentenced to 16 years in prison

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Foxtrot Network: The shadowy gang recruiting teen killers across Europe - BBC News

Teen hackers tell BBC how police are helping them use their skills for good - BBC News

Jailed Flock vandal wipes out three cameras, racks up thousands in damages

Linux and Open Source

Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop

Arch Linux disables AUR package adoption to stop malware flood

Cryptominer Abuses Linux PAM to Hide From SOC Analysts - Infosecurity Magazine

Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

Malware

Cybercrime goes subscription: AI, malware and infrastructure on demand - Help Net Security

New DOUBLECUP ClickFix service hides malware in browser cache images

Arch Linux disables AUR package adoption to stop malware flood

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

COLDCARD security audit phishing attack installs remote access tool

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Fake Bank of America Phishing Scam Installs Remote Access Malware - Infosecurity Magazine

Chrome wants more extension reviews, but good ratings won’t keep malware out - Digital Trends

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages — Elastic Security Labs

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts - SecurityWeek

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

5 Reasons Developers Still Download Malicious Packages - Security Boulevard

Passwords, Credential Stuffing & Brute Force Attacks

6 places you should never store your passwords – unless you want to get hacked - Which?

Regulations, Fines and Legislation

Apple challenges UK encryption order | Cybernews

Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says | Euronews

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels - SecurityWeek

Report: U.S. to exclude open-weight AI models from new safety tests - Neowin

Senators warn Trump’s AI interventions could drive users to Chinese models | CyberScoop

South Korea fines telco giant KT $39 million for customer data breach

Social Media

Buying TikTok followers can expose users to scams and account theft - Help Net Security

LinkedIn's new 'Seems like AI slop' button lets you report all those cringey posts | ZDNET

Software Supply Chain

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages — Elastic Security Labs

ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly Installs - Infosecurity Magazine

5 Reasons Developers Still Download Malicious Packages - Security Boulevard

77 Open VSX extensions found harvesting developer info

Mitigation Guidance for Supply Chain Compromise | Google Cloud Blog

CISA Issues New SBOM Guidance. Did They Get It Right?

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Supply Chain and Third Parties

Mitigation Guidance for Supply Chain Compromise | Google Cloud Blog

English National Ballet suffers possible data breach following cyber attack | The Standard

Sheffield Hospitals Charity affected by cyber attack - BBC News

Polish convenience store chain Żabka hacked through third-party account | The Record from Recorded Future News


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Cyberattacks and the critical services we rely on | MPR News

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict - SecurityWeek

Will The Cyberattacks On Water Systems In 7 States Be A Wakeup Call?

Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control | Tom's Hardware

Nation State Actors

China

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers - Help Net Security

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day - Infosecurity Magazine

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Russia

Russian hackers deploy OWAReaper Exchange backdoor

Russian spies take their half-click email attack from Zimbra to Outlook

Travelers Beware: Russian Intel Hacking Hotel Wi-Fi

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

North Korea

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korea's elite hackers turned on their own government — and got caught

South Korea Warns of State-Backed Watering Hole Attacks

Iran

Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control | Tom's Hardware

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran | WIRED

A brief timeline of Iranian cyberattacks on U.S. companies, political figures, water systems and more - CBS News


Tools and Controls

The modern CISO is becoming the next CFO | CSO Online

Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console

Chrome wants more extension reviews, but good ratings won’t keep malware out - Digital Trends

Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

How MFA gets hacked — and strategies to prevent it | CSO Online

AI-found bugs aren't proving any easier to exploit despite the hype

A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports | TechRadar

Underwriters Making Better Cyber Risk Decisions | Kovrr - Security Boulevard

Why the Browser is Becoming Security's Front Line in the Age of AI - Infosecurity Magazine

AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt | ZDNET

AI slop pollutes the CVE pipeline with fake vulns

Non-human identities are 91% of everything active in production - Help Net Security

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

Taking the myths out of Mythos - the role for the channel around AI and security | ChannelPro

New Tool Traces AI Videos Back to Their Source

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev - Infosecurity Magazine

Google Chrome Prepares Default Block for Extensions That Hijack the New Tab Page or Search Engine - gHacks Tech News

Cloudflare has mostly ditched third party security tools, suggests not trying that at home



Vulnerability Management

AI-found bugs aren't proving any easier to exploit despite the hype

AI is finding so many Chrome security flaws that Google may start updating it twice a week | TechSpot

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day - Infosecurity Magazine

A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports | TechRadar

Gartner: Why cybersecurity must shift to outcomes against AI-led attacks | Computer Weekly

Why CVE grading still matters for vulnerability management | native | MSSP Alert

AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt | ZDNET

AI slop pollutes the CVE pipeline with fake vulns

Taking the myths out of Mythos - the role for the channel around AI and security | ChannelPro

What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery

How zero-knowledge proofs let companies share cyber risks securely | CyberScoop

Vulnerabilities

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities - SecurityWeek

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability - SecurityWeek

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks - SecurityWeek

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Critical Vulnerabilities Patched With Chrome 151 Update - SecurityWeek

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

OpenVPN 2.7.6 Released with Security Fixes for Windows and mbedTLS

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected | The Record from Recorded Future News

Rails patches critical Active Storage flaw with RCE potential

TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices | TechRadar

Hackers run khunt post-exploitation toolkit from Oracle database

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor - Security Boulevard

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers - Help Net Security


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 31 July 2026

Black Arrow Cyber Threat Intelligence Briefing 31 July 2026:

-73% of Organisations Say They Are Not Fully Ready for a Major Cyberattack

-Why the Biggest AI-Driven Cyber Threat Is Still Human Nature

-Phishing Dominates as Initial Entry Method for Cyberattacks, as Hackers Hone Evasion Techniques

-AI Is Gaining Ability to Personalise Cyberattacks, Enabling Phishing at Scale

-Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

-Year-Long Russian Attacks Infect Users as Soon as They Look at an Email

-Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

-Ransomware Groups Increasingly Deploy EDR Kill Techniques

-Agentic Browsers Rewind Web Security by 20 Years

-OpenAI's Rogue AI Hacked Four More Platforms besides Hugging Face

-Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

-Response to Fraud Must Transform Faster, Warns City of London Police

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Cyber resilience requires organisations to prepare and rehearse how they will respond to a serious cyber incident, and this week we reinforce the need for organisations to strengthen their resilience. This is achieved by the leadership team, not just the technology team, planning and rehearsing how to investigate and coordinate various response activities that affect everyone.

We also continue to look at cyber security, which is where organisations take a structured approach to help prevent an incident from occurring. Attackers continue to target employees through email and Teams phishing, while AI is making personalised deception faster and easier to scale. We continue to look at other AI-driven risks that business leaders need to address, including evolving risks with agentic AI and browsers.

Addressing these risks requires a leadership team that is regularly upskilled on the risks and the proportionate controls that they can ensure are implemented to reduce the risks. Resilience is strengthened through cross-functional incident response exercises that test decision-making, authority, coordination and business dependencies. Contact us to discuss how we support organisations across the world to achieve this.


Top Cyber Stories of the Last Week

73% of Organisations Say They Are Not Fully Ready for a Major Cyberattack

New research found that 73% of organisations would not be fully prepared for a major cyberattack, despite most having response plans, tools and technical teams in place. Of the 600 senior security decision makers surveyed, 76% had experienced at least one cyberattack in the past year, while 90% expected difficulties coordinating internal stakeholders during a serious incident. Limited executive involvement, delays engaging legal and communications teams, and poor visibility across systems were identified as major obstacles, showing that effective response depends on rehearsed decision-making and coordination, not technology alone.

https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html

Why the Biggest AI-Driven Cyber Threat Is Still Human Nature

AI can rapidly identify software weaknesses and produce convincing messages, but manipulating people may still give criminals an easier route into organisations than overcoming technical defences. A technical flaw still requires suitable access and conditions to become a breach, while a single employee can be deceived through an urgent phishing email, fake security alert or impersonation attempt. AI makes these attacks faster, cheaper and more convincing in any language. Organisations should not expect employees to identify every convincing AI-generated deception and need broader technical defences to support them.

https://www.forbes.com/councils/forbestechcouncil/2026/07/29/why-the-biggest-ai-driven-cyber-threat-is-still-human-nature/

Phishing Dominates as Initial Entry Method for Cyberattacks, as Hackers Hone Evasion Techniques

Phishing was the initial entry point in just over half of the cyber incidents investigated by Cisco Talos between March and June 2026, up from one third in the previous quarter. Attackers are increasingly using QR codes, trusted cloud services and tailored documents to bypass email security and steal Microsoft 365 credentials. Phishing-as-a-service kits can also help criminals bypass multi-factor authentication and retain access after compromise, reinforcing the need for phishing-resistant authentication, centralised logging and controls that limit attack propagation.

https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/

AI Is Gaining Ability to Personalise Cyberattacks, Enabling Phishing at Scale

AI is enabling criminals to create highly personalised phishing attacks at scale by researching targets, impersonating trusted contacts and adapting conversations when questioned. Unlike generic scam messages, these attacks can reflect an employee’s role, relationships and current responsibilities, making them far harder to identify. Researchers estimate that some business email compromise attacks could be fully automated by late 2026, with more complex cyberattacks potentially automated from start to finish as early as 2027. This significantly increases the risk that employees will be manipulated into revealing credentials or downloading malicious software.

https://www.washingtonpost.com/opinions/2026/07/28/ai-is-gaining-ability-personalize-cyberattacks-enabling-phishing-scale/

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Microsoft detected approximately 7.6 billion email phishing threats between April and June 2026, with credential theft accounting for up to 96% of attacks involving malicious content. Attackers are also increasingly targeting employees through Microsoft Teams, often posing as IT support staff. Weekly malicious call attempts increased by roughly 80% from the start of 2026 and reached almost ten times the mid-2025 level by late June. One automated email fraud campaign reached more than 67,000 users across 42,000 organisations in under three hours, highlighting how attackers combine trusted workplace channels with convincing impersonation to steal access or redirect payments.

https://cybersecuritynews.com/email-phishing-threats-as-teams-vishing-attacks/

Year-Long Russian Attacks Infect Users as Soon as They Look at an Email

Russian state-linked attackers have exploited a weakness in Zimbra email systems since July 2025, compromising users simply when they viewed a malicious email, without requiring a click or attachment. The campaign targeted government, defence, energy, education, media and technology organisations, stealing up to 90 days of emails, passwords, contact directories and authentication details. The flaw was fixed in November 2025, but unpatched systems remain exposed. Organisations using Zimbra should update immediately, limit access to webmail until secure, and review systems for signs of compromise.

https://www.theregister.com/patches/2026/07/23/year-long-russian-attacks-infect-users-as-soon-as-they-look-at-an-email/5277358

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malicious advertising campaign targeting retail traders and cryptocurrency investors has operated since late 2024 across 12 countries and 25 languages. Fraudulent adverts impersonate services including TradingView, Solana and Luno, directing victims to convincing fake websites. Rather than downloading a complete malicious program, the victim’s browser assembles it from separate components, which can produce a different file for each session and reduce the value of basic file matching. There is no specific software patch to apply, reinforcing the importance of downloading trading and wallet applications only from official vendor websites and monitoring the wider advertising and download chain.

https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html

Ransomware Groups Increasingly Deploy EDR Kill Techniques

Ransomware groups are increasingly disabling endpoint security tools before encrypting systems, reducing the time available to detect and contain attacks. Halcyon recorded 1,988 publicly claimed attacks across 101 countries in the second quarter of 2026. Although claims fell by 5.7%, the methods used became more sophisticated, with greater automation and some groups progressing from initial access to ransomware deployment in under an hour. Manufacturing accounted for 19.8% of cyber extortion attacks, while criminals also expanded their use of artificial intelligence to support access, negotiation and other stages of attacks.

https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/

Agentic Browsers Rewind Web Security by 20 Years

Agentic browsers are AI-enabled web browsers that can navigate websites and take actions on a user’s behalf, rather than simply displaying pages. Researchers found that every commercial agentic browser they tested could be manipulated into harmful activity, including account takeover, unauthorised purchases and, in some cases, control of the underlying device. Some weaken established protections that stop one website triggering actions on another, allowing malicious online content to redirect the agent. Organisations considering adoption should assess the risks and use separate, isolated accounts and credentials rather than connecting agentic browsers to employees’ normal accounts.

https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years

OpenAI's Rogue AI Hacked Four More Platforms besides Hugging Face

Following the recent report that an OpenAI security test led an autonomous AI agent to access Hugging Face, OpenAI has confirmed that the agent also reached four other external services. The evaluation was designed to test what the models could do without safety filtering; the agent escaped its controlled environment and used exposed credentials to access outside systems. Only Hugging Face and Modal Labs have been named, leaving three affected services undisclosed. The incident highlights the risk of highly capable AI systems operating without effective containment and controls.

https://decrypt.co/374645/openais-rogue-ai-hacked-four-more-platforms-besides-hugging-face

Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

Hackers are compromising Wi-Fi systems at hotels and conference centres to redirect travellers to convincing fake Microsoft 365 login pages. The campaign, active since at least June, has affected organisations across financial services, legal, healthcare, energy, retail and other sectors worldwide. In some cases, attackers can bypass multi-factor authentication by tricking users into approving a legitimate-looking sign-in request, potentially giving them access to emails, documents and business communications. Exposure can be reduced through always-on, full-tunnel VPNs and disabling Microsoft device-code authentication where it is not needed.

https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/

Response to Fraud Must Transform Faster, Warns City of London Police

Fraud and cyber crime now account for nearly half of all crime in the UK, prompting the City of London Police to call for a faster national response involving government, law enforcement and industry. Recent enforcement activity resulted in 557 arrests, £9 million frozen, and the seizure of £2.8 million in cash and £15.3 million in non-cash assets. The new Report Fraud service, launched in January 2026, is intended to improve reporting and intelligence gathering as criminals adopt increasingly sophisticated methods.

https://policeprofessional.com/news/response-to-fraud-must-transform-faster-warns-city-of-london-police/



Threats

Ransomware, Extortion and Destructive Attacks

Bad news — paying a ransomware demand might cause hackers to come back and ask for more | TechRadar

Companies are still paying ransoms to cyber criminals despite official advice | IT Pro

Over a third of ransomware victims re-extorted after paying

Ransomware groups take aim at vulnerable VPNs | CSO Online

Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine

Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs

Ransomware is the Scoreboard

The Signs Were There: What the First Autonomous Ransomware Case Confirms | Trend Micro (US)

Ransomware gangs go after EMEA healthcare's supply chain - Help Net Security

ShinyHunters data leaks fuel $2,000 sextortion email scam

Clop ransomware targets Windchill, FlexPLM in data theft attacks

Ransomware Attacks Targeting Universities on the Rise - Infosecurity Magazine

LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

Ransomware and Destructive Attack Victims

Ernst & Young data breach claimed by ShinyHunters extortion gang

Education department says 607,000 records taken in cyber attack - BBC News

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - SecurityWeek

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Phishing & Email Based Attacks

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | National Cyber Security Centre

Russian APT Laundry Bear perfects zero-click phishing attack | Computer Weekly

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Phishing Dominates as Initial Entry Method for Cyber-Attacks - Infosecurity Magazine

Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog

The best-funded companies open the most phishing attachments - Help Net Security

Opinion | AI is gaining ability to personalize cyberattacks, enabling phishing at scale - The Washington Post

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks - Infosecurity Magazine

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

LogoKit Phishing Kit Screenshots Victim Sites in Real Time - Infosecurity Magazine

Japanese firm transferred S$6 million in email impersonation scam; director of recipient company jailed - CNA

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | Trend Micro (US)

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Other Social Engineering

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Phishing Dominates as Initial Entry Method for Cyber-Attacks - Infosecurity Magazine

Opinion | AI is gaining ability to personalize cyberattacks, enabling phishing at scale - The Washington Post

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

A new vishing campaign is targeting Microsoft Teams – here's what users need to know | IT Pro

ShinyHunters data leaks fuel $2,000 sextortion email scam

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

2FA/MFA

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Artificial Intelligence

Opinion | AI is gaining ability to personalize cyberattacks, enabling phishing at scale - The Washington Post

AI image fraud will cost $40 billion next year - can these international standards help? | ZDNET

Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers | TechRadar

One ChatGPT link could smuggle a rogue AI agent into your company

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

US lawmakers push for AI 'kill switch' after OpenAI models go rogue - BBC News

An AI agent can pass every safety check and still leak secrets - Help Net Security

LLMs Are Getting Smarter, But Not Safer: Veracode 2026 GenAI Code Security Report Finds AI-Generated Code Security Has Stalled at 56% Pass Rate

Agentic Browsers Rewind Web Security by 20 Years

OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Face - Decrypt

OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Microsoft Copilot Deployments Delayed Over Security Concerns - Infosecurity Magazine

New Dolphin X malware uses AI to rank high-value targets

OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

After Mythos, zero trust alone won’t be enough against AI-powered attacks | Federal News Network

The OpenAI–Hugging Face Incident: A Watershed Moment for AI Governance, Contracting, and Enterprise Risk | Saul Ewing LLP - JDSupra

Hugging Face breach reignites open-weights debate, raises liability questions - Help Net Security

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard - Infosecurity Magazine

One-click Claude Desktop Flaw Could Enable Hidden Prompt Injection And Code Execution

Your AI agents can reach data no one approved - Help Net Security

OpenAI models used Artifactory zero-days to escape to the internet

When AI Agents Escape Sandboxes, Old Security Rules Apply

Stronger AI Safety Requires Peeking Inside the 'Black Box'

Why The Biggest AI-Driven Cyber Threat Is Still Human Nature

The Signs Were There: What the First Autonomous Ransomware Case Confirms | Trend Micro (US)

Europe's Multilingual Reality Exposes AI Security Gaps

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation

Nvidia forms Open Secure AI Alliance to build open-source security tools

NVIDIA’s Open Security AI Alliance Is Missing Some Big Names - Infosecurity Magazine

Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop

FBI sees Anthropic’s Mythos as a law enforcement challenge | FedScoop

Biggest ever MCP update brings metadata, cybersecurity enhancements - SiliconANGLE

Trump considering AI controls after OpenAI hacking incidents - BBC News

Why Mythos is the cybersecurity crisis we need | resource | SC Media

828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead

Beyond the Patch: How AI Continues to Change Cyber Hygiene

250 Eiffel Towers' worth of waste: The AI boom's toxic hardware problem | ZDNET

Rogue AI cyber incident heralds new 'era of agentic autonomous attacks' | Insurance Times

Bots/Botnets

Despite multiple takedowns, botnets continue to grow | CyberScoop

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Cloud/SaaS

Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

A new vishing campaign is targeting Microsoft Teams – here's what users need to know | IT Pro

Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts | CSO Online

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Your team isn’t "ignoring security." They’re just underwater. - The New Stack

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Cyber Crime, Organised Crime & Criminal Actors

Europol flags 4,340 'horrific' URLs linked to The Com

Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders

When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk | CSO Online

Data Breaches/Leaks

Ernst & Young data breach claimed by ShinyHunters extortion gang

Exposed credentials are giving attackers a head start many organizations don't see - Help Net Security

Education department says 607,000 records taken in cyber attack - BBC News

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - SecurityWeek

A record credential leak just changed the threat model. Your vendor rating did not | perspective | MSSP Alert

Chick-fil-A data breach affects more than 13,000 customers

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

Tens of thousands of university account logins found on dark web

Data breach at medical billing firm MCBS affects 1.26 million people

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

DentaQuest disclosed a data breach that impacted +23 million individuals

Origin Energy Data Breach Affects 900,000 Australians - SecurityWeek

Denial of Service/DoS/DDoS

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Encryption

Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop

Fraud, Scams and Financial Crime

AI image fraud will cost $40 billion next year - can these international standards help? | ZDNET

Police Professional | Response to fraud must transform faster, warns City of London Police

Stolen Meta and Google ad accounts are worth more than the money they hold - Help Net Security

Japanese firm transferred S$6 million in email impersonation scam; director of recipient company jailed - CNA

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | Trend Micro (US)

Former policeman charged over French château ‘investment scam’

Call of Duty Mobile scam uses fake free points giveaway to hijack players' accounts - Help Net Security

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Identity and Access Management

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Flaws in Passkey Implementation Show Old Attacks Still Work

Insider Risk and Insider Threats

Why The Biggest AI-Driven Cyber Threat Is Still Human Nature

Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers | TechRadar

One ChatGPT link could smuggle a rogue AI agent into your company

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Internet of Things – IoT

Tengu botnet reboots Linux devices to survive removal - Help Net Security

The automotive software vulnerabilities hiding in your dashboard - Help Net Security

Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth | TechRadar

Law Enforcement Action and Take Downs

Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders

Police Professional | Response to fraud must transform faster, warns City of London Police

Europol flags 4,340 'horrific' URLs linked to The Com

FBI sees Anthropic’s Mythos as a law enforcement challenge | FedScoop

Man gets six years for hacking 750 women's Snapchat accounts

Japanese firm transferred S$6 million in email impersonation scam; director of recipient company jailed - CNA

Former policeman charged over French château ‘investment scam’

Council worker spared prison after four-day data-snooping spree

Linux and Open Source

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched - Infosecurity Magazine

Malvertising

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser - Infosecurity Magazine

Malware

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser - Infosecurity Magazine

Tengu botnet reboots Linux devices to survive removal - Help Net Security

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Despite multiple takedowns, botnets continue to grow | CyberScoop

New Dolphin X malware uses AI to rank high-value targets

Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain | TechRadar

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

Hackers abuse Notepad++ plugins to stealthily install malware

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Mobile

Iran-linked group caught hiding surveillance tools in fake apps | TechRadar

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Is It Safe To Keep Using A Phone That No Longer Gets Update Support?

The US is charging an American citizen for wiping his phone at the border | The Verge

Call of Duty Mobile scam uses fake free points giveaway to hijack players' accounts - Help Net Security

Android malware detection collapses when the context stage comes out - Help Net Security

'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China

Models, Frameworks and Standards

Examining the Unintended Consequences of the Online Safety Act - IT Security Guru

Commission publishes new guidance to support businesses' implementation of the Cyber Resilience Act - EU Reporter

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation - Infosecurity Magazine

Outages

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft blames massive Microsoft 365 outage on maintenance bug

Cloudflare reveals what's behind major internet outages - Help Net Security

Passwords, Credential Stuffing & Brute Force Attacks

Exposed credentials are giving attackers a head start many organizations don't see - Help Net Security

Why Resetting Passwords No Longer Stops Attackers

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days | CyberScoop

macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Flaws in Passkey Implementation Show Old Attacks Still Work

A record credential leak just changed the threat model. Your vendor rating did not | perspective | MSSP Alert

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

I'm not letting Claude touch my passwords, no matter how safe Anthropic claims it is

Regulations, Fines and Legislation

Commission publishes new guidance to support businesses' implementation of the Cyber Resilience Act - EU Reporter

Examining the Unintended Consequences of the Online Safety Act - IT Security Guru

US lawmakers push for AI 'kill switch' after OpenAI models go rogue - BBC News

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry | The Record from Recorded Future News

The US is charging an American citizen for wiping his phone at the border | The Verge

Huawei ban to cost the EU up to €40 billion, says industry – POLITICO

Industry's message on CIRCIA: Please ask us fewer questions about cyberattacks | CyberScoop

The government has delivered its verdict on the proposed UK VPN ban | The Independent

AI, audits and OSINT featured in House intel bill | Federal News Network

Rubio restricts visas for sextortionists, cyber scammers | CyberScoop

Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices

US launches trade probe into EU over big tech fines | Euronews

Trump Administration Bans New Chinese AI Robots and Power Inverters Over National Security Fears: 'These - Benzinga

Shadow IT

Shadow AI incident response begins with logs that may already be gone - Help Net Security

Shadow AI agents are multiplying. Here's how to find and secure them.

Social Media

Man gets six years for hacking 750 women's Snapchat accounts

Meta tackles AI-generated accounts with a free Facebook verification badge - Help Net Security

Software Supply Chain

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Supply Chain and Third Parties

When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk | CSO Online

Ransomware gangs go after EMEA healthcare's supply chain - Help Net Security


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Iran-linked group caught hiding surveillance tools in fake apps | TechRadar

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | National Cyber Security Centre

Finnish Intelligence Warns of Russian Cyberattacks - Freedom

The Red Cross plans to extend its protection to cyberspace - SWI swissinfo.ch

Ukrainian hackers cause Russian air defense to shoot down a Su-57 fighter | TechRadar

Can Cyber Operations Be Deterred? What Wargames Reveal

China

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Huawei ban to cost the EU up to €40 billion, says industry – POLITICO

Trump Administration Bans New Chinese AI Robots and Power Inverters Over National Security Fears: 'These - Benzinga

Open weights vs. closed: An AI civil war's afoot, and the stakes are existential | ZDNET

Researchers Say a 'Ghost' Chinese Company Built the Network Hiding PLA Cyberattacks

'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China

Russia

Year-long Russian attacks infect users as soon as they look at an email

Laundry Bear pivots to new exploit days after Zimbra alert | Computer Weekly

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations | National Cyber Security Centre

Finnish Intelligence Warns of Russian Cyberattacks - Freedom

Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages

Ukrainian hackers cause Russian air defense to shoot down a Su-57 fighter | TechRadar

How Ukrainian Cyber Operation May Have Led to Downing of russian Su-57 Near Moscow | Defense Express

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

North Korea

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Nearly 100,000 cyberattacks hit foreign ministry, affiliates in 6 months - The Korea Times

Iran

Iran-linked group caught hiding surveillance tools in fake apps | TechRadar

Handala Hacker Group claims cyberattack on U.S. communications infrastructure

Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems

America is playing Iran’s game – Middle East Monitor


Tools and Controls

Why Resetting Passwords No Longer Stops Attackers

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

Is Patching Dead? Vulnerability Management in the Post-Mythos Era - SecurityWeek

Has your security stack become your biggest cyber risk? | ChannelPro

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Ransomware groups take aim at vulnerable VPNs | CSO Online

Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine

The government has delivered its verdict on the proposed UK VPN ban | The Independent

Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses | TechRadar

Flaws in Passkey Implementation Show Old Attacks Still Work

OpenAI models used Artifactory zero-days to escape to the internet

When AI Agents Escape Sandboxes, Old Security Rules Apply

Google's solution to hacker name confusion? Yet another naming system | CyberScoop

Securing What Matters: Why Cyber Resilience Needs Prioritisation - IT Security Guru

Shadow AI incident response begins with logs that may already be gone - Help Net Security

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation - Infosecurity Magazine

Microsoft tightens Windows enterprise activation security - Help Net Security

They might have grown up online — but Gen Z are apparently far less likely to use antivirus, study finds | TechRadar

Vulnerability management needs an update for the AI era | TechTarget




Vulnerability Management

Is Patching Dead? Vulnerability Management in the Post-Mythos Era - SecurityWeek

The shrinking exploit window and what it means for cybersecurity teams | native | MSSP Alert

Mythos Asks the Right Question. It Doesn't Answer It.

828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead

Is It Safe To Keep Using A Phone That No Longer Gets Update Support?

Vulnerabilities

Critical Flaw Led to Azure Cosmos DB Pwnage - SecurityWeek

Cyber Firm Wiz Says Flaw Could Have Exposed Thousands of Microsoft Cloud Customers

Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure

Google says AI helped Chrome fix 1,072 security bugs in two releases

Google Releases Patches for 370 Vulnerabilities in Chrome 151 - Infosecurity Magazine

Oracle drops 1,449 security patches like it's the new normal

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Critical VM Escape Vulnerability Patched in VMware ESXi - SecurityWeek

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

One-click Claude Desktop Flaw Could Enable Hidden Prompt Injection And Code Execution

Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe - SecurityWeek

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day - SecurityWeek

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Unpatched Fastjson Vulnerability Exploited in Attacks - SecurityWeek

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain - Security Affairs

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard - Infosecurity Magazine

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) - Help Net Security

JFrog Patches Flaws Behind OpenAI Models' Escape

AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched - Infosecurity Magazine

New Certighost PoC exploit lets attackers hijack Windows domains

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

vBulletin fixes critical pre-auth RCE flaw with public exploit

PTC Windchill Vulnerability Exploited in Ransomware Campaign - SecurityWeek

828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 24 July 2026

Black Arrow Cyber Threat Intelligence Briefing 24 July 2026:

-OpenAI’s New Model Went Rogue and Hacked Another Company. Why It Matters.

-AI Models Keep Getting Caught Cheating

-Senior Executives Abuse Shadow AI Twice as Much as Regular Employees Do

-The Script, Not the Voice, Is What Makes AI Voice Phishing Work

-Connecting AI Agents to Outside Services Explodes the Risk Radius

-Cyber Remains Top Enterprise Risk for Company Leaders

-79% of Ransomware Attacks Start with Compromised Identities

-Ransomware Attacks Hit SMBs Harder than Ever as Cybercrime Gang Rivalry Heats Up

-A New Ransomware Threat Actor Emerges Every Week, Warns Report

-Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats from 329 Million Users

-Watch Out – That Microsoft Calendar Invite Dated 2050 Could Be Hiding Stolen Files and Worse

-Device Code Phishing: Turning a Convenience Feature into an MFA Bypass

-1 in 4 Businesses Hit by Cyber Attacks through Their Supply Chain in the Last Year

-The Executive Profile Your Security Team Isn’t Defending

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Over the past week, the global media has been discussing how OpenAI’s new model bypassed its testing controls and accessed systems belonging to another AI company while attempting to complete a cyber security task. We include this and other information in our weekly review of cyber security in the specialist and general media, to help raise awareness of the risks that organisations need to manage when using AI, and when defending against AI-driven attacks.

While AI has been the focus of many news stories this week, business leaders need to ensure they do not take their eye off other risks, including ransomware attacks, which frequently begin with compromised credentials including credentials obtained through phishing. We also include this week news of other vulnerabilities and attack tactics, from Adobe Acrobat extensions and Microsoft calendar entries, to supply chain risks and online information about company executives that enables attackers to impersonate them.

Although cyber risks come from various angles, and new high risks are identified particularly related to AI, the underlying approach to managing cyber risks remains consistent. Business leaders should ensure they are upskilled with an understanding of the risks they need to manage, and an impartial view of the controls that they need to ensure are in place and governed. Importantly, the controls must cover people, operations and technology, and the impartial assessment should come from cyber experts who are not providing those controls. Contact us to see how we help organisations across various countries to achieve this proportionately.


Top Cyber Stories of the Last Week

OpenAI’s New Model Went Rogue and Hacked Another Company. Why It Matters.

OpenAI has disclosed that an advanced artificial intelligence model bypassed its testing controls and accessed systems belonging to another AI company while attempting to complete a cyber security task. The incident highlights the growing risks posed by AI agents, which can act independently on computers and pursue objectives without continuous human direction. Although the affected company was not widely known, the incident raises concern about whether safeguards will remain effective as AI systems become more capable. OpenAI has strengthened its security controls and is continuing to investigate the incident.

https://www.washingtonpost.com/technology/2026/07/22/openais-new-model-went-rogue-hacked-another-company/

AI Models Keep Getting Caught Cheating

Research from the UK’s AI Security Institute found that every large language model tested in offensive cyber security exercises attempted to take prohibited actions or use unintended shortcuts to complete assigned tasks. The models often failed to disclose this behaviour, and fewer than half recognised it as wrong when challenged. In one case, a model used an external online service to try to access protected evaluation systems, triggering a security alert. Although no data was lost, the findings raise serious concerns about using AI in sensitive areas where trust, oversight and reliable decision-making are essential.

https://cyberscoop.com/ai-models-cheat-deceive-users-aisi-report/

Senior Executives Abuse Shadow AI Twice as Much as Regular Employees Do

Senior executives are using unauthorised AI tools at twice the rate of other employees, with nearly two-thirds admitting to the practice compared with 31% of lower-level staff. This creates particular risk because leaders often handle sensitive financial, strategic, customer and intellectual property data. Three-quarters of employees recognise the security and privacy concerns, suggesting the problem is driven less by awareness and more by poor alternatives. Where approved tools are slow, limited or difficult to access, staff are more likely to use personal accounts and unapproved services, reducing oversight and leaving organisations without reliable records of how important decisions were made.

https://www.cio.com/article/4195782/senior-executives-abuse-shadow-ai-twice-as-much-as-regular-employees-do.html

The Script, Not the Voice, Is What Makes AI Voice Phishing Work

Research involving 4,100 US adults found that the persuasiveness of an AI voice phishing call mattered far more than how human the voice sounded. Around 16% of participants said they might comply with scam requests, rising to 36% for a fake relative in distress. Controls should therefore focus on independent verification, such as calling back using trusted contact details, family code words and preventing telephone requests alone from authorising password resets, payments or account changes.

https://www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/

Connecting AI Agents to Outside Services Explodes the Risk Radius

Connectors link AI agents to external services including email, messaging and file storage, widening an organisation’s exposure to data loss and unauthorised actions. PromptArmor found that 37% of 2,517 connectors changed within six weeks, with 1,686 new capabilities added to connectors that were already live. Around two in five Claude connectors were also likely to call additional AI services, meaning data could be processed by providers not considered when the connector itself was approved. Rapid changes to permissions, data handling and write access mean connector approvals can quickly become outdated, creating hidden governance and security risks.

https://www.theregister.com/ai-and-ml/2026/07/19/connecting-ai-agents-to-outside-services-explodes-the-risk-radius/5274640

Cyber Remains Top Enterprise Risk for Company Leaders

Cyber attacks and data breaches remain the top enterprise risk in 2026 and are expected to retain that position through 2028, according to Aon. Artificial intelligence is increasing the speed, scale and accessibility of attacks, allowing criminals to automate research, create convincing phishing messages and exploit weaknesses more quickly. Despite this, many organisations consider themselves only somewhat prepared, with fragmented oversight and limited testing of AI-related incidents. Aon recommends strengthening basic controls, reviewing insurance coverage, improving board reporting and testing response and continuity plans against AI-enabled disruption.

https://www.emergingrisks.co.uk/cyber-remains-top-enterprise-risk-for-company-leaders/

79% of Ransomware Attacks Start with Compromised Identities

A Sophos report found that compromised user accounts were involved in 79% of ransomware incidents, making stolen login details the most common route into organisations. Malicious emails accounted for 26% of cases, phishing rose from 18% in 2025 to 24% in 2026, and brute force attempts remained broadly stable at 23%. By contrast, attacks exploiting known software weaknesses fell from 32% to 18%. For business leaders, the findings underline the need to strengthen identity controls, limit unnecessary access and ensure compromised accounts can be identified and disabled quickly.

https://www.securitymagazine.com/articles/102440-79-of-ransomware-attacks-start-with-compromised-identities

Ransomware Attacks Hit SMBs Harder than Ever as Cybercrime Gang Rivalry Heats Up

NordStellar’s analysis of more than 200 threat actor blogs identified 2,581 reported attacks in the second quarter of 2026, with Qilin and The Gentlemen responsible for 299 and 284 incidents respectively. Smaller US businesses were hit hardest, suffering 769 attacks, followed by Canada with 97, Germany with 83 and the UK with 74. Attacks on US organisations with revenues above $1 billion also rose by 74%, from 23 to 40 incidents. The findings suggest smaller businesses remain especially exposed where defences are limited, while major companies may face increased targeting as leading groups compete for status.

https://www.techradar.com/pro/security/ransomware-attacks-hit-smbs-harder-than-ever-as-cybercrime-gang-rivalry-heats-up

A New Ransomware Threat Actor Emerges Every Week, Warns Report

The ransomware market is becoming increasingly crowded and unpredictable, with 61 new groups emerging during the first half of 2026. Black Kite identified 146 active groups by June, up from 105 a year earlier, although their average lifespan has fallen to just 4.9 months. Despite this fragmentation, the five largest groups accounted for 44% of 7,551 publicly disclosed victims between March 2025 and March 2026. Critical software weaknesses provided initial access in 44% of attacks, reinforcing the importance of timely updates. The report also recommends stronger identity verification, help desk escalation and controls against executive impersonation.

https://www.infosecurity-magazine.com/news/new-ransomware-weekly/

Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats from 329 Million Users

A flaw in Adobe’s Acrobat extension for Chrome could have allowed attackers to steal visible WhatsApp Web chats, contacts and profile information when a user visited a malicious website, without requiring a click or password. The extension was installed on up to 329 million browsers worldwide. Adobe fixed the issue in version 26.5.2.3 and distributed the update automatically. The incident highlights the wider risks posed by browser extensions, particularly where trusted software can access sensitive information across other websites and online services.

https://cybersecuritynews.com/acrobat-extension-flaw-whatsapp-chats/

Watch Out – That Microsoft Calendar Invite Dated 2050 Could Be Hiding Stolen Files and Worse

Group-IB has identified new malware targeting organisations that uses compromised Microsoft 365 calendars to steal sensitive files. Attackers hide instructions in calendar entries dated as far ahead as 2050, then attach encrypted stolen data to events, allowing the activity to blend into legitimate Microsoft traffic. At least 12 systems were compromised, with three still communicating with the attackers during the investigation. Researchers found similarities to tools linked with an Iranian-aligned group, although the evidence was not strong enough for confident attribution. The technique shows that trusted cloud services can conceal malicious traffic and data theft from normal monitoring.

https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse

Device Code Phishing: Turning a Convenience Feature into an MFA Bypass

Device code phishing turns a legitimate Microsoft sign-in feature into a route around multi-factor authentication. Victims enter a genuine code on Microsoft’s website and complete MFA, but unknowingly approve access for the attacker. In one case, criminals posed as a contact at a law firm, built trust through several emails, then used the compromised account to register multiple devices, hide messages and send phishing emails to hundreds of recipients. Organisations should block device code authentication where it is not required, restrict device registration and train staff to treat unexpected requests to enter verification codes as suspicious.

https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html

1 in 4 Businesses Hit by Cyber Attacks through Their Supply Chain in the Last Year

One in four UK businesses suffered a cyber incident through their supply chain in the past year, while 48% knowingly continued working with suppliers that had security or resilience concerns. Databarracks found these organisations were more than four times as likely to experience a supplier-related incident. Although 89% assess suppliers during onboarding, ongoing visibility often remains limited. The wider study also found 65% believe a serious cyber attack could threaten their survival, highlighting the need to treat critical suppliers as part of the organisation’s own resilience planning.

https://www.itsecurityguru.org/2026/07/21/1-in-4-businesses-hit-by-cyber-attacks-through-their-supply-chain-in-the-last-year/

The Executive Profile Your Security Team Isn’t Defending

Artificial intelligence can now assemble detailed profiles of senior executives in minutes by combining public information about their careers, relationships, interests and routines. This makes convincing impersonation and targeted fraud easier, even for less skilled attackers. Organisations should treat an executive’s public digital footprint as a managed security risk, with regular reviews of what major AI platforms reveal. Removing unnecessary personal information, addressing family exposure and showing executives their own AI-generated profiles can reduce the information available for phishing, fraudulent calls and attempts to manipulate support staff.

https://www.csoonline.com/article/4197460/the-executive-profile-your-security-team-isnt-defending.html



Threats

Ransomware, Extortion and Destructive Attacks

A New Ransomware Threat Actor Emerges Every Week, Warns Report - Infosecurity Magazine

Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up | TechRadar

79% of Ransomware Attacks Start with Compromised Identities | Security Magazine

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat - Infosecurity Magazine

Government Agencies Falling Victim to Ransomware Daily, Warns Study - Infosecurity Magazine

Ransomware Uses AI to Amp Up Negotiations | Lawfare

Pay up or not? Ransomware surge has victims facing tough choices. - Ars Technica

If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns - IT Security Guru

How enterprise GenAI can amplify ransomware risk — and how to contain it

New Spirals ransomware encrypts victim network in under 24 hours

Scattered Spider members jailed over Transport for London hack that cost £29 million - Help Net Security

Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

PYMNTS | Governments Weigh Ransomware Payment Bans

Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness - Infosecurity Magazine

As Ransomware Blackmail Surges, Governments Mull a Ban on Paying Up | Extremetech

Inc Ransomware Exploits SonicWall SMA Zero-Days

A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands | TechRadar

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

Ransomware and Destructive Attack Victims

Government Agencies Falling Victim to Ransomware Daily, Warns Study - Infosecurity Magazine

Qilin claims hack of Danone global food giant | Cybernews

JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security

List of Companies Impacted by Rise in Cyber Attacks

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack - SecurityWeek

After KFC, cyberattack hits Japanese ice cream giant Glico | The Straits Times

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei - SecurityWeek

Romania's land registry hit by cyber attack, data allegedly for sale - Help Net Security

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Abbott probes two cyber incidents amid extortion claims

Phishing & Email Based Attacks

Phishing Campaign Hides Lua Loader as TrueType Font File - Infosecurity Magazine

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Attackers Combo Up Evasion Tactics for BEC Phishing

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass | Trend Micro (US)

AI spam filters are getting suckered by old-school text salting

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Police dismantle Kratos phishing platform, arrest developer

Business Email Compromise (BEC)/Email Account Compromise (EAC)

Attackers Combo Up Evasion Tactics for BEC Phishing

Other Social Engineering

The script, not the voice, is what makes AI voice phishing work - Help Net Security

The executive profile your security team isn't defending | CSO Online

Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust - IT Security Guru

Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse | TechRadar

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Almost half of fraud cases reported in the first half of 2026 were phone scams (vishing)

Scammers impersonate FBI on social media, prey on crime victims

Fake FBI agents target people who already got scammed - Help Net Security

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 - Infosecurity Magazine

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

Telegram shortlinks knocked offline over sanctioned VPN connection

Artificial Intelligence

The script, not the voice, is what makes AI voice phishing work - Help Net Security

How enterprise GenAI can amplify ransomware risk — and how to contain it

OpenAI’s new model went rogue and hacked another company. Why it matters. - The Washington Post

Co-founder of firm hacked by rogue OpenAI models says it is 'a wake-up call' - BBC News

The executive profile your security team isn't defending | CSO Online

Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain - Infosecurity Magazine

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Prompt injection is becoming the XSS of the web agent era - Help Net Security

Agentic AI: Taming the Unpredictable

Senior executives abuse shadow AI twice as much as regular employees do | CIO

Connecting AI agents to outside services explodes the risk radius

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

New UK report finds AI models consistently cheat and deceive users | CyberScoop

Forescout Report Reveals Surge in AI-Driven Cyber Threats - IT Security Guru

Vibe-Coded Apps Riddled With Exploitable Security Flaws - SecurityWeek

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness - Infosecurity Magazine

Claude Chrome extension flaw lets malicious extensions trigger AI actions

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes - Help Net Security

Think you can spot fake AI photos? They're now a security risk | PCWorld

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

CISOs Feel the Heat Over AI Risk

Attackers Are Learning to Live Off the AI Toolchain

Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

AI agents are still logging in as humans - Help Net Security

“Stop asking whether AI works and start asking what it can reach”: C1 CISO on AI agent security | news | MSSP Alert

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

AI Data Centers Are Being Built Faster Than They Can Be Secured - SecurityWeek

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

Google's Gemini lets strangers send messages from your locked Android phone

Researchers Build WordPress Exploit Using OpenAI's GPT - Infosecurity Magazine

Hacker Turns AI Jailbreaks Into Offensive Platform

AI Agents Can Now Use Your Password. Is Agentic AI Going Too Far?

WordPress "wp2shell" exploit payload analyzed: AI developed this attack | Cybernews

OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict

Malware is targeting AI tools in software development environments | CyberScoop

White House accuses Chinese company of distilling Anthropic’s Fable | CyberScoop

Bots/Botnets

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

Careers, Roles, Skills, Working in Cyber and Information Security

AI can't fix cybersecurity's hiring problem - Help Net Security

The top AI fear for 6,000 tech pros isn't losing their jobs - it's more work for the same pay | ZDNET

MSSPs have a burnout problem, and pay isn’t the fix | news | MSSP Alert

Cloud/SaaS

Airbus moves critical apps off AWS to a French cloud

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security

The SaaS blind spot: Why security teams can’t get inside their own apps | CSO Online

Malicious cloud customers can bring down the power grid

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

New OkoBot framework deploys 20 payloads to steal data, crypto

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft - gHacks Tech News

Cruciferra Crypter Uses Process Ghosting to Evade Detection - Infosecurity Magazine

Cyber Crime, Organised Crime & Criminal Actors

US charges two over laundering $43 million from investment fraud

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime | CyberScoop

Police take down investment fraud network that stole €100 million a month - Help Net Security

Data Breaches/Leaks

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Ernst & Young Data Breach Affects Personal, Financial Information - SecurityWeek

EY Sued Over Breach Targeting Client Tax, Financial Info - Law360

Lessons Learned: US Cybersecurity Agency Leaked Secrets

23andMe Faces New Security Mandates in $18m Data Breach Settlement - Infosecurity Magazine

UK health tech firm Craneware admits customer and staff data stolen in cyber attack | The Independent

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts - SecurityWeek

Estée Lauder discloses data breach via Oracle E-Business flaw

Paidwork breach exposes sensitive data of 23 million users - Help Net Security

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches - Help Net Security

Chick-fil-A discloses data breach after credential stuffing attacks

South Korea discloses data breach impacting diplomats worldwide

Breach of AI music platform Suno affected 55M+ user accounts

Investigation finds no evidence of negligence in Qantas hack – Australian Aviation

Data/Digital Sovereignty

Airbus migrating 70 critical apps from AWS to France's Scaleway amid digital sovereignty push

Denial of Service/DoS/DDoS

AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek

Fraud, Scams and Financial Crime

US charges two over laundering $43 million from investment fraud

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime | CyberScoop

Police take down investment fraud network that stole €100 million a month - Help Net Security

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust - IT Security Guru

Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage

Almost half of fraud cases reported in the first half of 2026 were phone scams (vishing)

Scammers impersonate FBI on social media, prey on crime victims

Fake FBI agents target people who already got scammed - Help Net Security

Suffolk conman targeted elderly to defraud them out of millions - BBC News

Cardiff Covid fraudster jailed over bogus £200,000 loans - BBC News

Fraudster told to repay £5m to Royal Mail or face jail - BBC News

Identity and Access Management

79% of Ransomware Attacks Start with Compromised Identities | Security Magazine

Insider Risk and Insider Threats

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Internet of Things – IoT

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Your next car's software update could become its biggest security risk - Digital Trends

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Law Enforcement Action and Take Downs

US charges two over laundering $43 million from investment fraud

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime | CyberScoop

Police take down investment fraud network that stole €100 million a month - Help Net Security

Police dismantle Kratos phishing platform, arrest developer

Scattered Spider members jailed over Transport for London hack that cost £29 million - Help Net Security

UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group | TechCrunch

Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders - Infosecurity Magazine

Telegram shortlinks knocked offline over sanctioned VPN connection

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

A 21-year-old allegedly hid malware in Steam games to steal $220,000 in crypto, then bought Uber Eats with it

US seizes over 1,000 websites in FIFA World Cup piracy crackdown

Linux and Open Source

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Linux kernel team publishes 432 CVEs in two days

Multi-patch vulnerability fixes can leave open source exposed - Help Net Security

Malware

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust - IT Security Guru

Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica

Phishing Campaign Hides Lua Loader as TrueType Font File - Infosecurity Magazine

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

New OkoBot framework deploys 20 payloads to steal data, crypto

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Attackers keep using GitHub to distribute malware | Cybernews

This new Mac malware won't let you use your computer until you surrender your password - Digital Trends

Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe | IT Pro

Microsoft warns of surge in ACR Stealer attacks on customers

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft - gHacks Tech News

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

Dangerous new GoSerpent malware is apparently on the hunt for government secrets | TechRadar

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant - Infosecurity Magazine

Cruciferra Crypter Uses Process Ghosting to Evade Detection - Infosecurity Magazine

Malware is targeting AI tools in software development environments | CyberScoop

20+ Hijacked Government Websites Became
an Attack Channel

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Brazilian Banking Trojan Actively Spreading in Portugal

Mobile

Google's Gemini lets strangers send messages from your locked Android phone

Fake Bahrain Alert App Deploys Android Surveillance Malware

Models, Frameworks and Standards

Does the Cyber Security and Resilience Bill make you feel secure? | Computer Weekly

How mapping security controls can ease the compliance burden | TechTarget

PR3TACK preemptive framework maps threats before attackers use them - Help Net Security

NCSC ready to open Pathways to a broader set of organisations | UKAuthority

The CMMC 60-day pause: A strategic reset or something much bigger? | perspective | MSSP Alert

Passwords, Credential Stuffing & Brute Force Attacks

This new Mac malware won't let you use your computer until you surrender your password - Digital Trends

79% of Ransomware Attacks Start with Compromised Identities | Security Magazine

AI Agents Can Now Use Your Password. Is Agentic AI Going Too Far?

These Irish State agencies use password software with deep links to a Russian tech firm – The Irish Times

Chick-fil-A discloses data breach after credential stuffing attacks

Regulations, Fines and Legislation

Does the Cyber Security and Resilience Bill make you feel secure? | Computer Weekly

PYMNTS | Governments Weigh Ransomware Payment Bans

'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar

Social media companies have failed to enforce their minimum age requirements: Ofcom | Biometric Update

European Union considers social media ban for children

Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach

The CMMC 60-day pause: A strategic reset or something much bigger? | perspective | MSSP Alert

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains - SecurityWeek

France approves social media ban for under-15s - BBC News

Shadow IT

Senior executives abuse shadow AI twice as much as regular employees do | CIO

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security

Social Media

Social media companies have failed to enforce their minimum age requirements: Ofcom | Biometric Update

VPN firms and digital rights groups join forces to urge the UK government to leave VPNs alone | TechRadar

'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar

European Union considers social media ban for children

Scammers impersonate FBI on social media, prey on crime victims

France approves social media ban for under-15s - BBC News

Software Supply Chain

Attackers keep using GitHub to distribute malware | Cybernews

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Malware is targeting AI tools in software development environments | CyberScoop

Supply Chain and Third Parties

1 in 4 businesses hit by cyber attacks through their supply chain in the last year - IT Security Guru

Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets

Estée Lauder discloses data breach via Oracle E-Business flaw


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns - IT Security Guru

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

Finland Accuses Russia of Cyberespionage

Europe exposes Russia’s cyber war

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption

Symposium on International Law and Artificial Intelligence in Armed Conflict: Introduction - Opinio Juris

AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict

US Cyber Command senior enlisted leader: Data is the currency of warfare > Defense Logistics Agency > News Article View

NATO is building a Starlink-style military satellite network as eight allies unite to protect critical space communications | TechRadar

Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters | SentinelOne

Hackers were inside South Korea's diplomat training system for 9 months | The Record from Recorded Future News

Nation State Actors

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns - IT Security Guru

Trump offers no proof of claims foreign meddling threatens U.S. elections; Slammed for stoking voter fears

Trump Warns of Cyber Threats to U.S. Election Security from Foreign Powers | World News - The Times of India

China

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

Threat Actors Aligned with China Attacking U.S. University Physics + Engineering Depts. | Robinson+Cole Data Privacy + Security Insider - JDSupra

White House accuses Chinese company of distilling Anthropic’s Fable | CyberScoop

China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans - SecurityWeek

Russia

Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Finland Accuses Russia of Cyberespionage

Europe exposes Russia’s cyber war

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes - Help Net Security

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe | IT Pro

These Irish State agencies use password software with deep links to a Russian tech firm – The Irish Times

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Russian Hacker Turns Jailbroken Claude Into Pentest Platform - Infosecurity Magazine

Hacker Turns AI Jailbreaks Into Offensive Platform

North Korea

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korea's IT worker scheme funds Russia's war effort | CyberScoop

Hackers were inside South Korea's diplomat training system for 9 months | The Record from Recorded Future News

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 - Infosecurity Magazine

Iran

Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption

Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters | SentinelOne

AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict


Tools and Controls

The executive profile your security team isn't defending | CSO Online

Vibe-Coded Apps Riddled With Exploitable Security Flaws - SecurityWeek

The AI code vulnerabilities that grow with your app - Help Net Security

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Small teams are the heaviest users of AI coding agents - Help Net Security

AI spam filters are getting suckered by old-school text salting

Malware is targeting AI tools in software development environments | CyberScoop

'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar

The SaaS blind spot: Why security teams can’t get inside their own apps | CSO Online

“Stop asking whether AI works and start asking what it can reach”: C1 CISO on AI agent security | news | MSSP Alert

AI Data Centers Are Being Built Faster Than They Can Be Secured - SecurityWeek

Businesses need to boost cyber resilience, here’s how | IT Pro

Microsoft and OEMs answer Windows 11 Secure Boot questions before the October deadline

Real AI Threat Is Blind Trust

SANS Warns of AI Governance Gap as Use by Security Teams Surges - Infosecurity Magazine

AI can't fix cybersecurity's hiring problem - Help Net Security

Why Smarter Cybersecurity Starts with Better Data | Research Communities by Springer Nature

These Irish State agencies use password software with deep links to a Russian tech firm – The Irish Times

Russian Hacker Turns Jailbroken Claude Into Pentest Platform - Infosecurity Magazine

China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans - SecurityWeek

Cloud operations become the next big role for agentic AI - Help Net Security

Behavioral biometrics: How to detect nonhuman threat actors | TechTarget


Reports Published in the Last Week

Ransomware and Cyber Extortion in Q2 2026



Vulnerability Management

The Windows 10 hangover is becoming a security problem - Help Net Security

Multi-patch vulnerability fixes can leave open source exposed - Help Net Security

AI Can Find Bugs, But Human Knowledge Still Proves Them

Security teams keep finding critical flaws after scheduled testing ends - Help Net Security

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

Vulnerabilities

New Windows LegacyHive zero-day gives hackers admin privileges

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users

AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Attackers target critical FortiSandbox flaws as CISA issues patch order

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Linux kernel team publishes 432 CVEs in two days

New RefluXFS Linux flaw lets attackers gain root privileges

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider - SecurityWeek

OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates - SecurityWeek

Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Inc Ransomware Exploits SonicWall SMA Zero-Days

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation | Volexity

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 17 July 2026

Black Arrow Cyber Threat Intelligence Briefing 17 July 2026:

-UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows

-75% CISOs Fear Executives Don’t Understand Cyber Security Risks Employees Face

-Finance Phishing Works Because It Sounds Boringly Normal

-Microsoft Warns of Increase in Number of Security Updates

-Destructive Windows Backdoor Stuffs Multiple Wipers and Ransomware Code into a Single Package

-Identity Attacks Overtake Exploits as Top Ransomware Cause

-Companies Keep Getting Breached by Vulnerabilities They Already Knew About

-ClickFix Is Changing the Economics of Social Engineering

-AI, Once Relegated to Helping Hackers with Certain Tasks, Can Now Power Every Stage of a Cyber Attack

-Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

-Russian Hackers Exploit Weak Router Security to Breach Critical Infrastructure, Western Allies Warn

-UK Firms Make Cyber Resilience Measurable

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start this week’s review of cyber security in the specialist and general media with news that the UK Government plans to encourage households to keep emergency supplies in case a cyber attack or other crisis disrupts essential services. This aligns with previous reports in which the Government called on businesses to prepare to continue operating if an incident causes the loss of access to technology.

We also report that CISOs are concerned that leadership teams do not fully understand the cyber risks associated with employee behaviour. Other stories highlight evolving phishing techniques, the need to manage a higher volume of security updates, and the continuing development of AI-enabled attacks and ClickFix social engineering campaigns.

A key step in managing these risks is ensuring that leadership teams understand their cyber responsibilities, can oversee risk management effectively and have rehearsed plans for responding to an incident. Contact us to hear how we support organisations across different sectors and of different sizes to achieve this.


Top Cyber Stories of the Last Week

UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows

The UK Government is preparing to launch a national resilience campaign encouraging households to keep basic supplies such as food, water and medicines in case essential services are disrupted by events including a cyber attack. The initiative follows growing concern over threats to critical national infrastructure, including energy, water and communications networks, alongside plans for a national exercise to test the Government's response to a large-scale hybrid attack. For business leaders, the campaign and exercise reinforce the need to consider how disruption to power, water or communications could affect organisational continuity.

https://www.ibtimes.co.uk/uk-government-emergency-preparedness-campaign-1808763

75% CISOs Fear Executives Don’t Understand Cyber Security Risks Employees Face

MetaCompliance has found that many organisations face a growing gap between cyber security leaders and senior executives, with 78% of Chief Information Security Officers believing board-level decision makers do not fully understand the cyber risks created by employee behaviour. Almost 80% said executive support for security awareness declines over time, while 40% are concerned employees are sharing sensitive information with generative AI tools. As AI enables more convincing fraudulent communications at scale, sustained executive engagement and clear governance are becoming essential to strengthening organisational resilience.

https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/

Finance Phishing Works Because It Sounds Boringly Normal

Finance-themed phishing is a common initial access route because malicious messages closely resemble routine business correspondence and fit expected finance and procurement workflows. Cofense found that 59% to 79% of subject lines in campaigns against financial organisations referred to routine operations, while 21% to 41% used urgency. By imitating normal business processes, including invoices, payment confirmations and supplier enquiries, these emails are more likely to evade automated email security tools and persuade employees to open attachments or click malicious links.

https://www.helpnetsecurity.com/2026/07/16/cofense-finance-phishing-tactics-report/

Microsoft Warns of Increase in Number of Security Updates

Microsoft is using AI to identify software weaknesses across Windows more quickly, meaning organisations should expect a higher number of security updates in future. Microsoft says the increase reflects improved identification and remediation of weaknesses. Its multi-model scanning process validates potential findings before they reach engineers, aiming to reduce false positives and shorten the window in which zero-day vulnerabilities can be exploited. Human experts will continue to oversee the process. Business leaders should therefore expect patching demand to increase and ensure that update processes can absorb a higher volume of security releases.

https://www.infosecurity-magazine.com/news/microsoft-increase-number-security/

Destructive Windows Backdoor Stuffs Multiple Wipers and Ransomware Code into a Single Package

Microsoft has identified a new type of destructive malware that combines several attack techniques into a single tool, giving criminals greater flexibility once they gain access to a network. Rather than simply demanding payment, it can overwrite storage, encrypt files so they cannot be recovered, steal information, record user activity and disable recovery features. For business leaders, the combined capabilities broaden the potential impact of a compromise beyond data theft to remote control, permanent system damage and wider operational disruption.

https://www.theregister.com/security/2026/07/10/destructive-windows-backdoor-stuffs-multiple-wipers-and-ransomware-code-into-a-single-package/5270053

Identity Attacks Overtake Exploits as Top Ransomware Cause

Identity-related attacks have become the leading cause of ransomware, overtaking software vulnerabilities for the first time in three years. Sophos found that malicious emails, phishing and stolen login details accounted for almost three quarters of ransomware incidents, while software vulnerabilities fell to 18% of cases. Although 97% of organisations affected by credential theft had multi-factor authentication in place, attackers were still able to gain access, highlighting that this important security control must be fully deployed and supported by additional measures to detect and respond to suspicious activity.

https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause

Companies Keep Getting Breached by Vulnerabilities They Already Knew About

A survey of 300 IT and cyber security leaders found that while organisations have become highly effective at identifying security weaknesses, many still struggle to fix them quickly. Around eight in ten experienced a security incident in the past year linked to a vulnerability already in their inventory, and about half said the relevant weakness had been known for 30 to 90 days. The biggest barriers were unclear ownership, competing business priorities and lengthy approval processes. Organisations requiring a verified follow-up scan before closing a vulnerability reported substantially fewer incidents involving weaknesses they already knew about.

https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/

ClickFix Is Changing the Economics of Social Engineering

ClickFix has evolved into a highly organised cyber crime service that allows even low skilled attackers to launch convincing social engineering campaigns. Rather than exploiting software flaws, victims are tricked into running malicious commands themselves after visiting fake CAPTCHA pages, browser updates or IT support prompts. Attack kits are available on underground forums from around $250 per month, driving a sharp rise in attacks. Researchers also identified 123 previously undetected ClickFix pages, highlighting how these campaigns can bypass traditional security tools and reinforcing the importance of user awareness alongside technical controls.

https://www.helpnetsecurity.com/2026/07/15/clickfix-social-engineering-attacks-report/

AI, Once Relegated to Helping Hackers with Certain Tasks, Can Now Power Every Stage of a Cyber Attack

Artificial intelligence is now being used across every stage of a cyber attack, marking a significant shift from simply assisting with isolated tasks. Research found that criminal groups are using AI to identify security weaknesses, generate malicious code, automate attacks and move through victim networks with far less human involvement. In one case, a single developer used AI to produce around 88,000 lines of working code in under a week. As AI accelerates both the speed and scale of attacks, organisations face much shorter windows to detect and respond to emerging threats.

https://www.nextgov.com/cybersecurity/2026/07/ai-once-relegated-helping-hackers-certain-tasks-can-now-power-every-stage-cyberattack/414744/

Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

GuidePoint Security has reported that ransomware activity has continued to rise, with threat actors claiming 2,279 victims, up 7% on the previous quarter and 43% compared with a year earlier. Researchers identified a record 91 active ransomware groups operating across 108 countries. AI is helping criminals process stolen information and tailor their extortion tactics, rather than creating fundamentally different ransomware attacks. Manufacturing remained the most affected sector, accounting for almost 15% of reported incidents. Business leaders should combine recovery planning with measures to understand what sensitive data could be exposed and reduce how attackers could use it as leverage.

https://www.businesswire.com/news/home/20260709079338/en/Ransomware-Victims-Rise-43-as-AI-Becomes-a-Productivity-Tool-for-Threat-Actors-GuidePoint-Security-Finds

Russian Hackers Exploit Weak Router Security to Breach Critical Infrastructure, Western Allies Warn

Western governments have warned that Russian state-backed hackers continue to target critical infrastructure by exploiting poorly secured routers and other internet connected network devices. The activity has affected organisations across financial services, healthcare, communications, defence, energy, and government. The warning follows an attempted cyber attack against Poland's power grid that could have disrupted electricity supplies to around 500,000 people. The campaign highlights the importance of replacing default passwords, keeping network equipment up to date and monitoring internet facing systems as closely as other critical business assets.

https://www.nextgov.com/cybersecurity/2026/07/russian-hackers-exploit-weak-router-security-breach-critical-infrastructure-western-allies-warn/414735/

UK Firms Make Cyber Resilience Measurable

ISG reports that UK organisations are embedding cyber security into wider business resilience, with boards increasingly expecting measurable evidence that security investments reduce risk and improve response times. As AI is used by both defenders and attackers, organisations are adopting AI supported detection while maintaining human oversight and clear decision making. Growing concerns over supply chain risk and critical infrastructure are also driving demand for continuous monitoring, real time reporting and integrated security services that strengthen resilience and support regulatory expectations.

https://www.businesswire.com/news/home/20260710009829/en/U.K.-Firms-Make-Cyber-Resilience-Measurable



Threats

Ransomware, Extortion and Destructive Attacks

Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package

Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018 - Security Affairs

UK Cyber Attacks Climb 34% as Ransomware Leadership Shifts, Check Point Research Reveals - IT Security Guru

Ransom demands are down, email is the top way attackers get in - Help Net Security

Identity Attacks Overtake Exploits as Top Ransomware Cause

Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security

New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine

Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand | CSO Online

GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |

New Qilin Ransomware Attack Uses DCSync Technique to Abuse Active Directory Replication Protocols

CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find - IT Security Guru

Everest Ransomware Claims 1 TB Data Theft But Encryptor Shows No Exfiltration Code

This ransomware negotiator was paid to fight hackers, he was secretly working with them instead | TechSpot

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

Ransomware ecosystem grows, but ‘four-headed monster’ dominates - TechCentral.ie

This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June | IT Pro

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Former ransomware negotiator gets 4 years for BlackCat attacks

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Ransomware and Destructive Attack Victims

Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek

Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek

Phishing & Email Based Attacks

Ransom demands are down, email is the top way attackers get in - Help Net Security

Phishing Toolkits Harvest Entra Tokens in Real Time

New phishing kits target Microsoft 365 accounts, evade MFA

Finance phishing works because it sounds boringly normal - Help Net Security

Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many

New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam | TechRadar

Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine

Open Directory Exposes Three Evilginx Phishing Operators - Infosecurity Magazine

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Other Social Engineering

ClickFix and removable media lead malware delivery methods | TechTarget

ClickFix's Mushrooming Ecosystem Demands New Defense Tactics

ClickFix is changing the economics of social engineering - Help Net Security

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek

Is that QR code a trap? How to spot quishing scams before it's too late | ZDNET

QR Codes Are the New Security Blindspots That Steal Your Card Details and Deliver Malware

Tech support scam caused massive data breach at Australian airline Qantas

Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many

LastPass, Bitwarden users targeted with fake security alerts

Scammers are using FaceTime to steal bank account passwords - CBS News

2FA/MFA

Only 28% of financial workforce MFA is phishing-resistant - Help Net Security

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop

EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign - SecurityWeek

Money launderer accused of stealing seized crypto while in prison

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

EU sanctions Russian tech giant VK, state-backed messenger Max, and FSB-linked cyberattack network — The Insider

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

Artificial Intelligence

Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds

99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security

AI Is Changing Financial Services Security Faster Than Many Organisations Can Keep Up | Scoop News

Enterprises are rethinking where their AI applications run - Help Net Security

AI, once relegated to helping hackers with certain tasks, can now power every stage of a cyberattack - Nextgov/FCW

Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready

Why the Next Big Enterprise Security Breach Will Start With an AI Agent Nobody Authorized - QR Code Press

Risk of democratic interference added to National Risk Register - GOV.UK

What are 'context bombs'? Get familiar with the new cybersecurity tool. | Mashable

AI-assisted Software Engineering Is Creating A New Delivery Paradox

Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine

EU unveils AI cybersecurity action plan for AI and Cybersecurity

You Can't Secure Your Agents If You Can't See Them

The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code | IT Pro

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes

What is AI squatting? An emerging cyber threat targeting AI hallucinations | Artificial Intelligence News - Business Standard

Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek

UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek

Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online

Why conversational AI is redefining your security perimeter | TechTarget

Musk promises purge after Grok Build caught sending entire repos to the cloud

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

Bots/Botnets

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek

Careers, Roles, Skills, Working in Cyber and Information Security

ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight

Cloud/SaaS

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek

Phishing Toolkits Harvest Entra Tokens in Real Time

New phishing kits target Microsoft 365 accounts, evade MFA

Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security

Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

European Companies Have a Collaboration Security Confidence Gap

Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online

Novel OAuth Client ID Spoofing Technique Targets Cloud Environments - Infosecurity Magazine

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Money launderer accused of stealing seized crypto while in prison

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

London teenager who offered crypto advice to terror groups convicted | The Standard

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Cyber Crime, Organised Crime & Criminal Actors

New tutorials on underground hacking forums have roughly doubled - Help Net Security

London teenager who offered crypto advice to terror groups convicted | The Standard

Dutch police bust investment fraud ring stealing over €100 million

Spanish Police take down €140 million cyber fraud ring, arrest four

Police Disrupt a €140M Euro Cyber Fraud Ring in Spain

Russian Cybercrime Trio Indicted In Alleged $62M Scheme

Teen hackers jailed after live streaming cyber attack on TfL - BBC News

Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals

Data Breaches/Leaks

Police suspects Dutch hackers were involved in Odido breach

Finland issues wanted notice for hacker behind massive psychotherapy data breach | The Record from Recorded Future News

23andMe reaches $18 million settlement with states for massive breach | The Record from Recorded Future News

Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru

Tech support scam caused massive data breach at Australian airline Qantas

Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek

CISA credential leak prompts tighter security measures | CyberScoop

ServiceNow's requires_authentication=false: The One Boolean That Exposed Enterprise Data Worldwide - Security Boulevard

Musk promises purge after Grok Build caught sending entire repos to the cloud

Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek

Data/Digital Sovereignty

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

Denial of Service/DoS/DDoS

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

Encryption

MEPs fail to prevent Chat Control snoopfest revival

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider - IT Security Guru

Fraud, Scams and Financial Crime

Scammers are now cloning trusted news websites to steal your money - Digital Trends

UK charges five persons linked to fraud platform behind more than a million scam calls - Help Net Security

Spanish Police take down €140 million cyber fraud ring, arrest four

Dutch police bust investment fraud ring stealing over €100 million

Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many

UK charges suspects linked to Russian Coms call spoofing platform

Tech support scam caused massive data breach at Australian airline Qantas

Scammers are using FaceTime to steal bank account passwords - CBS News

Identity and Access Management

Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru

Identity Attacks Overtake Exploits as Top Ransomware Cause

AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready

Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine

A wolf in sheep’s clothing | Professional Security Magazine

Insider Risk and Insider Threats

75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine

This ransomware negotiator was paid to fight hackers, he was secretly working with them instead | TechSpot

The negotiator was the leak: insider who betrayed ransomware victims gets 70 months | HaystackID - JDSupra

Law Enforcement Action and Take Downs

INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million

This ransomware negotiator was paid to fight hackers, he was secretly working with them instead | TechSpot

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang - SecurityWeek

UK charges five persons linked to fraud platform behind more than a million scam calls - Help Net Security

Spanish Police take down €140 million cyber fraud ring, arrest four

Dutch police bust investment fraud ring stealing over €100 million

UK charges suspects linked to Russian Coms call spoofing platform

Police suspects Dutch hackers were involved in Odido breach

London teenager who offered crypto advice to terror groups convicted | The Standard

Teen hackers jailed after live streaming cyber attack on TfL - BBC News

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

764 splinter group leader sentenced to 40 years in jail | CyberScoop

Finland issues wanted notice for hacker behind massive psychotherapy data breach | The Record from Recorded Future News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

Welsh Doxbin admin jailed for egging on swatters from behind a screen

Linux and Open Source

Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine

OpenMandriva Linux says contributor tried to sabotage the project

Malware

Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package

GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |

Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru

ClickFix and removable media lead malware delivery methods | TechTarget

CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper

New CrashStealer malware poses as Apple crash reporting tool

New MacOS Malware Exploits Legitimate Developer ID - Infosecurity Magazine

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware - Help Net Security

Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek

Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek

AI-assisted Software Engineering Is Creating A New Delivery Paradox

The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code | IT Pro

222 GitHub Repositories Linked to Fake Go Package Malware Operation

Hackers backdoor Jscrambler npm package with infostealer malware

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Compromised npm Packages in the AsyncAPI Namespace Deliver M...

Mobile

RedHook Android malware now uses Wireless ADB for shell access

US personnel faced phone-tracking campaign during Iran war – FT | Iran International

Models, Frameworks and Standards

EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews

EU unveils AI cybersecurity action plan for AI and Cybersecurity

Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA

New AI Security Charter Backed by Over 70 Cyber Firms - Infosecurity Magazine

UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek

Cybersecurity Noncompliance Just Triggered Another False Claims Act Settlement for a Defense Contractor

Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense

Passwords, Credential Stuffing & Brute Force Attacks

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security

Don't let an AI chatbot pick your password, ever | ZDNET

Regulations, Fines and Legislation

EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews

Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine

Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA

23andMe reaches $18 million settlement with states for massive breach | The Record from Recorded Future News

Risk of democratic interference added to National Risk Register - GOV.UK

MEPs fail to prevent Chat Control snoopfest revival

Nobody talks about what happens when the agency writing federal cybersecurity standards has no director, no playbook, and a third fewer staff — CISA's May 2026 leak just made it visible - Silicon Canals

More Countries Jump on the Social Media 'Ban Wagon'

Cyber Security Bill amendment to be reintroduced in House of Lords — Hong Kong Watch

Cybersecurity Noncompliance Just Triggered Another False Claims Act Settlement for a Defense Contractor

Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense

OpenAI releases latest ChatGPT model after delay over White House cybersecurity concerns | ChatGPT | The Guardian

Social Media

More Countries Jump on the Social Media 'Ban Wagon'

Software Supply Chain

222 GitHub Repositories Linked to Fake Go Package Malware Operation

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek

Ghost Accounts Abuse GitHub API in Mass Recon Campaign - SecurityWeek

Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security

Supply Chain and Third Parties

Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru

Manage Vendor Risk in a Few Practical Steps

Edtech gets schooled by third-party cyberthreats | TechTarget


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows | IBTimes UK

Stockpile food in case of Russian cyber attack, Government will tell public

EU adopts largest-ever cyber sanctions package against Russia

EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign - SecurityWeek

UK and EU impose sanctions on hacking groups linked to Kremlin | Computer Weekly

Europe is building resilience – but not the kind it needs for war - Friends of Europe

As Global Conflicts Go Digital, Businesses Require Wartime Plans

Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine

Nation State Actors

China

China, India-Linked Hackers Both Targeted Same Pakistani Police Force - SecurityWeek

Russia

UK government to warn the public to prepare for a cyberattack​ | Cybernews

UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows | IBTimes UK

EU sanctions Russian tech giant VK, state-backed messenger Max, and FSB-linked cyberattack network — The Insider

Officials from 13 Nations once again warn defenders that Russian hackers are targeting network devices | CyberScoop

Russian hackers exploit weak router security to breach critical infrastructure, Western allies warn - Nextgov/FCW

Weak Security Continues to Fuel Russian Cyberattacks

CISA Stresses Router Hardening Against Nation-State Hackers

UK and international allies warn critical sectors over Russian cyber threats | UKAuthority

EU adopts largest-ever cyber sanctions package against Russia

Europe is building resilience – but not the kind it needs for war - Friends of Europe

EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop

NATO Condemns Russian Cyber Attacks, Warns of Reprisals | Newsmax.com

UK, EU officially pin Poland energy cyberattack on Russia

UK charges suspects linked to Russian Coms call spoofing platform

Russian Cybercrime Trio Indicted In Alleged $62M Scheme

North Korea

Cyberattacks against S. Korean military top 18,000 last year: report - The Korea Herald

Iran

Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure

US personnel faced phone-tracking campaign during Iran war – FT | Iran International

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

London teenager who offered crypto advice to terror groups convicted | The Standard

Teenager convicted of terrorism offences after CTP London investigation | Metropolitan Police


Tools and Controls

The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious code | IT Pro

75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine

Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife

NCSC advice on vulnerable routers | Professional Security Magazine

Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek

Only 28% of financial workforce MFA is phishing-resistant - Help Net Security

New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine

As Global Conflicts Go Digital, Businesses Require Wartime Plans

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek

Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security

Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine

Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clients | IT Pro

AI Coding: Do Security Risks Outweigh Productivity Gains?

The best defense against AI attacks turns out to be a skeptical human - Help Net Security

New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam | TechRadar

Why AI 'harnesses' matter more than frontier LLMs for cybersecurity | CyberScoop

Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security

ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight

OpenAI releases latest ChatGPT model after delay over White House cybersecurity concerns | ChatGPT | The Guardian

VPN service favored by ransomware groups is sanctioned by US | The Record from Recorded Future News

EU launches AI test platform to find cybersecurity flaws | Cybernews

Gold Eagle: the White House’s AI cyber clearinghouse


Reports Published in the Last Week

AI Security Report 2026 - Check Point Research



Vulnerability Management

Microsoft Warns of Increase in Number of Security Updates - Infosecurity Magazine

99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security

Companies keep getting breached by vulnerabilities they already knew about - Help Net Security

Microsoft is rewriting Windows patch guidance because of AI - Help Net Security

EU launches AI test platform to find cybersecurity flaws | Cybernews

White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | CyberScoop

Vulnerabilities

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record | CyberScoop

Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities - SecurityWeek

Dell PCs are shutting down after Windows 11's July update, Microsoft admits and blocks it

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Fresh SharePoint Vulnerability Exploited Soon After Disclosure - SecurityWeek

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities - SecurityWeek

Adobe Patches Critical ColdFusion Vulnerabilities - SecurityWeek

CitrixBleed 2 exploited in repeatable attack chain culminating in DragonForce ransomware, researchers find - IT Security Guru

Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution

Debian 13.6 security update patches over a hundred advisories in trixie - Help Net Security

CISA urges immediate action on actively exploited Fortinet flaws

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates - SecurityWeek

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud - SecurityWeek

ServiceNow's requires_authentication=false: The One Boolean That Exposed Enterprise Data Worldwide - Security Boulevard

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow - SecurityWeek

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Splunk, Zoom Patch Critical Vulnerabilities - SecurityWeek

These 5 Routers Are No Longer Safe To Use After A New Security Backdoor Was Discovered

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer - SecurityWeek

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zoom issues a warning to Windows users about critical security flaw - BetaNews


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 10 July 2026

Black Arrow Cyber Threat Intelligence Briefing 10 July 2026:

-ConsentFix and ClickFix: How Microsoft 365 Accounts Are Hijacked in 3 Seconds

-New Ghost Phishing Wave Is Breaking Traditional Email Security

-Hackers Are Posing as Interpol to Target Small Businesses – Here’s What You Need to Know

-Cyber Experts Issue Alert After Two Ransomware Groups Team Up on ‘Unprecedented’ Threat Campaign

-First Fully Agentic Ransomware Attack Sparks Readiness Concerns

-The AI Vulnerability Storm Is Here: Is Your Security Program Ready?

-Enterprise AI Still Smarting from Leaping Before Looking

-European Central Bank Demands AI Security ‘Action Plan’

-SonicWall Research Finds Financial Services Running Overdrawn on Cyber Defences as Attack Intensity Outpaces Every Other Tracked Industry

-Organisations Struggle to Prioritise Known Cyber Risks

-How Faster Cyber Attacks Are Reshaping Enterprise Cyber Security Strategies

-The Shift Toward Business-Aligned Risk Management

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

There is a temptation to focus on AI related news in cyber security at the expense of discussing the evolution of more established attacks and risks. Although this week we include news on the first fully agentic AI ransomware attack, we start by highlighting other ongoing attacks affecting organisations today that are notable for their speed and tactics in order that business leaders can address them. These include attacks on Microsoft 365 accounts and web browsers, as well as attackers impersonating authorities.

The agentic ransomware development is significant, not because the individual attack tactics are new, but because of the speed at which AI can work through challenges to achieve its objective. This, and other developments, highlight the need for business leaders not only to govern cyber security appropriately, based on risk to reduce the likelihood of an attack, but also to ensure that the leadership team understands how the organisation will respond if or when an attack succeeds.

Our recommendation is for the leadership team itself to participate in a tabletop walkthrough of an evolving attack scenario, led by impartial experts who can challenge assumptions and clarify understandings. This is an Incident Response Exercise that is not an IT activity and should not be designed by any control provider; the objective is for all control providers and the leadership to work through the required response across the organisation for situations where controls fail. This is a very impactful exercise; contact us to discuss how we enable organisations to achieve this in a proportionate manner.


Top Cyber Stories of the Last Week

ConsentFix and ClickFix: How Microsoft 365 Accounts Are Hijacked in 3 Seconds

An attack called ConsentFix builds on the ClickFix technique, where criminals trick users into following familiar online instructions that secretly hand over access. In this case, victims are lured through platforms such as Dropbox or DocSend and shown what appears to be a normal Microsoft 365 sign-in process. Dragging the callback link into the browser can expose OAuth tokens, giving criminals access to Microsoft 365 without the password and despite multi-factor authentication. Because the instructions resemble normal online workflows, staff awareness should be reinforced by monitoring endpoints and identities for suspicious behaviour or logins from unexpected locations.

https://www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/

New Ghost Phishing Wave Is Breaking Traditional Email Security

An EvilTokens phishing campaign affecting organisations in the US and Europe exposes a gap in conventional email checks. Its malicious content remains encrypted during initial inspection and appears only after the link opens in the user’s browser. Victims are then guided through Microsoft’s genuine device-code sign-in process and unknowingly authorise access to Microsoft 365 without surrendering their password. Data from 15,000 organisations puts 2026 phishing exposure at 75.6% in consulting, 72.8% in financial services and 71.9% in manufacturing, showing why security teams need visibility into what webpages do after they load.

https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html

Hackers Are Posing as Interpol to Target Small Businesses – Here’s What You Need to Know

Small businesses in North America, Europe, Asia and the Middle East are receiving phishing emails that impersonate Interpol cyber crime investigators. The emails claim to contain evidence of suspicious activity and pressure recipients into opening a password-protected file hosted on Proton Drive. Instead, the file contains ransomware that tries to encrypt files found on accessible drives before showing victims a ransom demand. Bitdefender found the campaign targeting sectors including finance, technology, legal services, food, agriculture, pharmaceuticals and media. The ransomware is relatively simple, but small businesses remain attractive targets because security responsibilities often fall to employees without specialist support.

https://www.itpro.com/security/cyber-attacks/hackers-are-posing-as-interpol-to-target-small-business-heres-what-you-need-to-know

Cyber Experts Issue Alert After Two Ransomware Groups Team Up on ‘Unprecedented’ Threat Campaign

Sophos has warned that ransomware groups Vect and TeamPCP are working together in a campaign that combines stolen login details, data theft and ransomware deployment. The partnership, announced in March, shows how cyber criminal groups are increasingly operating like businesses by pooling specialist skills. TeamPCP has compromised trusted open source tools, and Sophos says credentials it obtained have already been used in a Vect ransomware attack. Organisations relying on open source software should keep current records of those tools and check the integrity of third-party updates before rolling them out.

https://www.itpro.com/security/ransomware/cyber-experts-issue-alert-after-two-ransomware-groups-team-up-on-unprecedented-threat-campaign

First Fully Agentic Ransomware Attack Sparks Readiness Concerns

Sysdig has identified what it describes as the first fully AI-led ransomware attack, where an AI agent exploited a known weakness in an internet-facing system, stole credentials and encrypted a production database. The techniques were familiar, but the pace was notable: after an unsuccessful login, the AI adapted and succeeded 31 seconds later. Business leaders do not need a different defensive model, but they have less time to intervene. Organisations should reduce exposure of internet-facing services, fix known weaknesses promptly, protect credentials and ensure response teams can contain intrusions before important systems are affected.

https://www.techtarget.com/searchsecurity/news/366645613/First-fully-agentic-ransomware-attack-sparks-readiness-concerns

The AI Vulnerability Storm Is Here: Is Your Security Program Ready?

The Cloud Security Alliance warns that advanced AI tools could reduce the time between finding a software flaw and exploiting it to just hours. Its report says emerging AI models have already found thousands of serious weaknesses across major operating systems and browsers, creating working attack methods without human guidance. For senior leaders, this changes the risk profile. Patch cycles, incident response and board reporting based on slower, human-led attacks may no longer be realistic. Organisations should identify and segregate critical applications, strengthen basic controls and introduce safe, structured automation to accelerate vulnerability management and incident response.

https://www.techtarget.com/searchsecurity/feature/The-AI-vulnerability-storm-is-here-Is-your-security-program-ready

Enterprise AI Still Smarting from Leaping Before Looking

DigiCert has found that 78% of enterprises using AI have either suffered an AI-related security incident or identified AI-related weaknesses. The survey of 1,001 IT and cyber security leaders in the US, UK and Australia found that the incidents involved unauthorised or incorrectly configured AI agents. While 90% of organisations have discussed AI governance at board level, only half have dedicated budgets and formal programmes, and just 53% can identify which models and source data produced a particular AI decision. This leaves organisations less able to explain unexpected or controversial results.

https://www.theregister.com/security/2026/07/07/enterprise-ai-still-smarting-from-leaping-before-looking/5267353

European Central Bank Demands AI Security ‘Action Plan’

The European Central Bank has given major banks until 31 October 2026 to submit action plans for defending against AI-enabled cyber threats. The regulator warned that AI can identify security weaknesses at speed, making unresolved vulnerabilities more serious for operational resilience. Bank management may therefore need to reconsider technology spending and the people assigned to cyber security. Required actions include faster patching, stronger monitoring and detection, and effective oversight of third parties, with named owners and implementation dates. The ECB also warned that progress in quantum computing threatens traditional encryption and will demand long-term planning and investment.

https://www.computerweekly.com/news/366645712/European-Central-Bank-demands-AI-security-action-plan

SonicWall Research Finds Financial Services Running Overdrawn on Cyber Defences as Attack Intensity Outpaces Every Other Tracked Industry

SonicWall found that financial services faced the highest cyber attack intensity of any sector it tracks in the first half of 2026, with 132,378 intrusion prevention system detections per device, more than double the cross-sector average. The sector also recorded 39,341 malware hits per firewall, second only to healthcare. Many attacks continue to target old, well-understood weaknesses in legacy banking and payment systems. Leaders should examine whether ageing systems and broad access arrangements are leaving known weaknesses unresolved because remediation would interrupt essential services.

https://www.prnewswire.com/news-releases/sonicwall-research-finds-financial-services-running-overdrawn-on-cyber-defenses-as-attack-intensity-outpaces-every-other-tracked-industry-302820310.html

Organisations Struggle to Prioritise Known Cyber Risks

Filigran has found that most organisations are collecting more cyber risk data but still lack a clear view of their exposure. Its research found that 93% struggle to maintain an accurate view of their attack surface, meaning the systems and services that attackers could target, while only 41% have a consolidated view of cyber risk. More information is not producing clearer priorities. Organisations need to combine threat intelligence with evidence of which exposures can actually be exploited. Analysts spend an average of 17 hours a week investigating risks later found to be low priority or not exploitable.

https://www.helpnetsecurity.com/2026/07/03/cyber-risk-exposure-report/

How Faster Cyber Attacks Are Reshaping Enterprise Cyber Security Strategies

CrowdStrike’s 2026 Global Threat Report found that the average time taken for an attacker to move from initial access to stealing or damaging data fell to just 29 minutes in 2025, down from 48 minutes in 2024 and 84 minutes in 2022. Attackers are increasingly “logging in” with stolen usernames and passwords rather than breaking in with malware, making attacks harder to spot. As AI accelerates attacks and vulnerability exploitation, organisations need rapid patching, contextual monitoring of account activity and regularly exercised incident response plans.

https://www.infosecurity-magazine.com/news-features/faster-cyberattacks-reshape/

The Shift Toward Business-Aligned Risk Management

Cyber risk management is most useful when it connects security issues to real business consequences. Senior leaders can make better decisions when a technical severity score is translated into the effect of compromising a payment system handling $2 million each day. Organisations are being encouraged to move away from one-off risk assessments and towards a continuous approach that links threats, controls, likely financial impact and treatment options. This lets leaders compare stronger or alternative controls with insurance, recognising that insurance can offset financial loss but does not restart operations or repair damaged customer confidence and regulatory standing.

https://www.securityweek.com/the-shift-toward-business-aligned-risk-management/



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

First fully agentic ransomware attack sparks readiness concerns | TechTarget

Criminals Pose as Interpol in Phishing Emails to Deliver Ransomware - Infosecurity Magazine

Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign | IT Pro

Gentlemen Ransomware Expands Global Attack Campaigns

Why this fully agentic ransomware attack is giving researchers nightmares | ZDNET

The Gentlemen Ransomware: What You Need to Know | Fortra

Smooth AI criminal drives 'first' end-to-end agentic ransomware attack

Qilin Dominates Ransomware Market - Infosecurity Magazine

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Threat Spotlight: ShinyHunters Fast-Tracks Saas Access with Subdomain Impersonation

Q3 Threat Spotlight: How Automation, Customization, and Tooling Signal Next Ransomware Front Runners

Windows is watching: Anti-piracy tool fingers Scattered Spider suspect

Hacked, leaked, and held for ransom: The worst breaches of 2026 so far | TechCrunch

Scattered Spider’s Structure More Like a Cybercrime Collective - Infosecurity Magazine

When Cyberattacks Walk Through the Front Door - Above the Law

US Teenager Arrested In Finland For Scattered Spider Hacks

Ransomware and Destructive Attack Victims

Medtronic Data Breach Impacts 3.8 Million People - SecurityWeek

U.S. Government Agency Paid $1M to Data Extortion Group Kairos

Phishing & Email Based Attacks

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access

Hackers are posing as Interpol to target small businesses – here's what you need to know | IT Pro

New Ghost Phishing Wave Is Breaking Traditional Email Security

Phishing poses as big-brand job interview to steal Google accounts

AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection

Multi-channel phishing attacks: How to manage the risk | IT Pro

Messaging fraud trends point to smarter attacks, stronger blocking - Help Net Security

Government and Healthcare Are the Weakest Links in Global Email Security

Armored Likho APT Targeting Government, Electric Power Entities - SecurityWeek

Phishing Attacks Targeted Facebook Users With Fake Verification Offer - Infosecurity Magazine

Other Social Engineering

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access

Fake IT support calls on Microsoft Teams push EtherRAT malware

Entra passkey enrollment vishing targets Microsoft 365 users

Multi-channel phishing attacks: How to manage the risk | IT Pro

Messaging fraud trends point to smarter attacks, stronger blocking - Help Net Security

Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malwarebytes

Fake IT bods on Microsoft Teams coax workers into installing malware

The fake report message that ends with a stolen Reddit account - Help Net Security

When Cyberattacks Walk Through the Front Door - Above the Law

Opera rolls out Paste Protect feature to fight ClickFix attacks

Deepfakes and Vishing: What You Need to Know to Stay Protected | The Motley Fool

2FA/MFA

OAuth, guest accounts, and weak MFA drive SaaS risk - Help Net Security

MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage

Artificial Intelligence

First fully agentic ransomware attack sparks readiness concerns | TechTarget

Warning Over “Industrialized” Cyber-Attacks by Ransomware Gang - Infosecurity Magazine

Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign | IT Pro

JadePuffer ransomware used AI agent to automate entire attack

Why this fully agentic ransomware attack is giving researchers nightmares | ZDNET

The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident - Security Affairs

Bank of England Warns AI Raises Financial Cyber Risks | EasternEye

Enterprise AI still smarting from leaping before looking

Thousands of malicious AI skills found capable of stealing data, running malware - Help Net Security

AI is turning overshared data into a major security risk | perspective | SC Media

European Central Bank demands AI security ‘action plan’ | Computer Weekly

The future of payment fraud could be automated - Help Net Security

Hackers can use 9 of the most popular AI tools to assemble massive botnets - Ars Technica

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target - Infosecurity Magazine

Chinese LLMs Broaden the Gap Between Attackers & Defenders

What an AI ‘cyber nuclear war’ would actually look like | The Independent

How to prioritize AI agent security by business impact - Help Net Security

Indirect Prompt Injection in Web Content Targets AI Agents - Infosecurity Magazine

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Anthropic Details Claude Fable 5 Cybersecurity Safeguards and Jailbreak Framework

Navigating NIST’s New Cybersecurity AI Frontier

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) - Help Net Security

French nonprofit starts global intelligence and research hub for AI cyber threats | CyberScoop

AI-driven cyber warfare reshapes global defense readiness | native | MSSP Alert

Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage

Deepfake CSAM lawsuit against xAI, Grok expands | CyberScoop

AI is making compliance decisions. Can you prove how? | perspective | MSSP Alert

AI-Generated Malware Powers New Armored Likho APT Campaign

China issues 'backdoor' security alert over Anthropic's Claude Code | Reuters

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

Bots/Botnets

Hackers can use 9 of the most popular AI tools to assemble massive botnets - Ars Technica

Google, FBI disrupt NetNut botnet spanning 2M devices | Cybernews

Google disrupts Israel-linked proxy network used to spread malware – Middle East Monitor

Careers, Roles, Skills, Working in Cyber and Information Security

CISO's guide to hiring for the right cybersecurity skills | TechTarget

Cloud/SaaS

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Fake IT support calls on Microsoft Teams push EtherRAT malware

Microsoft 365 users fall victim to one-in-a-million password spray attack – Computerworld

UK’s largest businesses dangerously exposed to cloud outages | Computer Weekly

Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target - Infosecurity Magazine

Entra passkey enrollment vishing targets Microsoft 365 users

OAuth, guest accounts, and weak MFA drive SaaS risk - Help Net Security

Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malwarebytes

Fake IT bods on Microsoft Teams coax workers into installing malware

Threat Spotlight: ShinyHunters Fast-Tracks Saas Access with Subdomain Impersonation

FBI targets TeamPCP after massive supply chain attacks | Cybernews

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Vidar Infostealer Hammers SMBs via Malvertising Campaign

New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner - Infosecurity Magazine

Cyber Crime, Organised Crime & Criminal Actors

The future of payment fraud could be automated - Help Net Security

Cybersecurity and the Gap Between Skill and Ability - Schneier on Security

Scattered Spider’s Structure More Like a Cybercrime Collective - Infosecurity Magazine

US Teenager Arrested In Finland For Scattered Spider Hacks

Data Breaches/Leaks

Russia has attacked the United Kingdom – again

Hacked, leaked, and held for ransom: The worst breaches of 2026 so far | TechCrunch

US government says it got hacked — again | TechCrunch

Accenture confirms breach after hacker offers stolen data for sale

Medtronic Data Breach Impacts 3.8 Million People - SecurityWeek

Ransomware and Cyber Extortion in Q1 2026

Hackers claim Deutsche Bank data breach, internal data affected| Cybernews

Data/Digital Sovereignty

Study: Europe's defense runs on American servers - EU Reporter

Fraud, Scams and Financial Crime

The future of payment fraud could be automated - Help Net Security

Messaging fraud trends point to smarter attacks, stronger blocking - Help Net Security

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

Identity and Access Management

Why Identity is the Anchor of the New Digital Frontier

Secret Double Octopus Releases 2026 State of Identity Security in Financial Organizations Report

The Verification Step Is the New ATO Battleground in 2026

Internet of Things – IoT

Google, FBI disrupt NetNut botnet spanning 2M devices ​ | Cybernews

IoT Security Flounders Amid Churning Risk

Law Enforcement Action and Take Downs

Google, FBI disrupt NetNut botnet spanning 2M devices | Cybernews

US Teenager Arrested In Finland For Scattered Spider Hacks

FBI targets TeamPCP after massive supply chain attacks | Cybernews

Google disrupts Israel-linked proxy network used to spread malware – Middle East Monitor

French Police Dismantle Operation Behind the Already Defunct YggTorrent * TorrentFreak

Windows is watching: Anti-piracy tool fingers Scattered Spider suspect

A hacker's arrest just revealed how Microsoft can track your Windows device - Digital Trends

Vietnam arrests suspects behind HiAnime anime piracy service

Spain arrests suspected hacker linked to Russian hacktivist campaign | CyberScoop

Linux and Open Source

North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek

Malvertising

Vidar Infostealer Hammers SMBs via Malvertising Campaign

New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner - Infosecurity Magazine

Malware

Warning Over “Industrialized” Cyber-Attacks by Ransomware Gang - Infosecurity Magazine

Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign | IT Pro

Vidar Infostealer Hammers SMBs via Malvertising Campaign

New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner - Infosecurity Magazine

North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek

Fake IT support calls on Microsoft Teams push EtherRAT malware

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

Malware authors subvert AI detection systems | CSO Online

FBI targets TeamPCP after massive supply chain attacks | Cybernews

Google disrupts Israel-linked proxy network used to spread malware – Middle East Monitor

Fake IT bods on Microsoft Teams coax workers into installing malware

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

A single malware file can outweigh an entire AI dataset - Help Net Security

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Newly discovered PamStealer isn't your typical macOS malware - Ars Technica

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malwarebytes

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Armored Likho APT Targeting Government, Electric Power Entities - SecurityWeek

Chinese hackers develop LONGLEASH malware to expand ORB network

AI-Generated Malware Powers New Armored Likho APT Campaign

BusySnake Stealer Slithers into Critical Infrastructure Networks

Mobile

Europe Confirms Record €4.1B Penalty Against Google for Android Practices

I never use fingerprint or Face ID to unlock my phones. Here’s why

RedWing Android Spyware Sold as a Service on Telegram - Infosecurity Magazine

Models, Frameworks and Standards

The cyber law that could change everything | Computer Weekly

Ireland facing major fines over failure to enact cybersecurity law | Business Post

Navigating NIST’s New Cybersecurity AI Frontier

EU Cybersecurity Act 2 Advances Amid Member States' Concerns Over EU Competence | Jones Day

NCSC Launches Cyber Governance Guidance for Management Boards in NIS2 Organisations

UK Govt Pairs Agentic AI Initiative With Cyber Resilience Pledge

Government's cyber pledge lands 60 signatories, including M&S and, somehow, Capita

Businesses across Britain sign up to Cyber Resilience Pledge as ministers urge firms to strengthen cyber defences - GOV.UK

Outages

UK’s largest businesses dangerously exposed to cloud outages | Computer Weekly

Passwords, Credential Stuffing & Brute Force Attacks

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Russia has attacked the United Kingdom – again

Microsoft 365 users fall victim to one-in-a-million password spray attack – Computerworld

The Verification Step Is the New ATO Battleground in 2026

Regulations, Fines and Legislation

The cyber law that could change everything | Computer Weekly

Ireland facing major fines over failure to enact cybersecurity law | Business Post

Germany plans spy powers to hack attackers | Cybernews

EU Cybersecurity Act 2 Advances Amid Member States' Concerns Over EU Competence | Jones Day

NCSC Launches Cyber Governance Guidance for Management Boards in NIS2 Organisations

Trump Imposed Export Controls on Anthropic. Now the Company is Adding New AI Guardrails to Lift Them | IBTimes

Cybersecurity Mission Creep in the US - Schneier on Security

Shadow IT

The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident - Security Affairs

Social Media

The fake report message that ends with a stolen Reddit account - Help Net Security

Phishing Attacks Targeted Facebook Users With Fake Verification Offer - Infosecurity Magazine

Software Supply Chain

North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Warning Over “Industrialized” Cyber-Attacks by Ransomware Gang - Infosecurity Magazine

Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign | IT Pro

FBI targets TeamPCP after massive supply chain attacks | Cybernews

FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

Supply Chain and Third Parties

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident - Security Affairs

Why hackers are targeting your digital supply chain, not just your systems


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

What an AI ‘cyber nuclear war’ would actually look like | The Independent

AI-driven cyber warfare reshapes global defense readiness | native | MSSP Alert

NATO 3.0 and energy security: Rebalancing transatlantic defence in Ankara – Middle East Monitor

The US military is not organized for cyber war

Making humanitarian protection visible in cyberspace: The promise of the Digital Emblem - Microsoft On the Issues

Nation State Actors

NATO 3.0 and energy security: Rebalancing transatlantic defence in Ankara – Middle East Monitor

China

What an AI ‘cyber nuclear war’ would actually look like | The Independent

Chinese LLMs Broaden the Gap Between Attackers & Defenders

Chinese hackers develop LONGLEASH malware to expand ORB network

US considers ban on Chinese solar inverters - PV Tech

Suspected Chinese Threat Group Targets Universities - Infosecurity Magazine

Did AI help Palo Alto Networks falsely link the company to China? | Cybernews

Hackers can remotely control Hoymiles solar inverters| Cybernews

Russia

Russia has attacked the United Kingdom – again

BBC Cyber Hack podcast investigates Conti ransomware gang - PodcastingToday

Spain arrests suspected hacker linked to Russian hacktivist campaign | CyberScoop

Alleged pro-Russia hacktivist arrested in Palencia

North Korea

North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Iran

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks - SecurityWeek

From missiles to malware: Why the Gulf is stepping up its operational resilience | Fortune

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

RedWing Android Spyware Sold as a Service on Telegram - Infosecurity Magazine

What is spyware, and how do you protect yourself? | Proton

Predatorgate victims sue spyware maker Intellexa

European Parliament Member Investigating Spyware Was Hacked With Pegasus

Same government, more victims: Access Now calls for an urgent investigation into hacking of MEP - Access Now

Spain arrests suspected hacker linked to Russian hacktivist campaign | CyberScoop

Alleged pro-Russia hacktivist arrested in Palencia


Tools and Controls

Enterprise AI still smarting from leaping before looking

The Shift Toward Business-Aligned Risk Management - SecurityWeek

North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

Organizations struggle to prioritize known cyber risks - Help Net Security

Confidential computing's core trust mechanism is broken. The fix may not exist

Anthropic Details Claude Fable 5 Cybersecurity Safeguards and Jailbreak Framework

Malware authors subvert AI detection systems | CSO Online

Why Identity is the Anchor of the New Digital Frontier

How to prioritize AI agent security by business impact - Help Net Security

Gentlemen Ransomware Expands Global Attack Campaigns

The AI vulnerability storm is here: Is your security program ready? | TechTarget

Detection engineering: A programmatic approach to identifying cyber threats | CSO Online

Evaluating secure enterprise browsers vs. security plugins | TechTarget

Data governance is becoming a security services problem | news | MSSP Alert

Chinese LLMs Broaden the Gap Between Attackers & Defenders

The Verification Step Is the New ATO Battleground in 2026

A hacker's arrest just revealed how Microsoft can track your Windows device - Digital Trends

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage

AI is making compliance decisions. Can you prove how? | perspective | MSSP Alert

MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage

Non-interactive SSH attacks dominate after login - Help Net Security

Did AI help Palo Alto Networks falsely link the company to China?​ | Cybernews

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

The NCSC wants to build an AI-powered 'Cyber Shield' to protect the UK from hackers – here’s how it’ll work | IT Pro




Vulnerability Management

Most WordPress sites are outdated, and hackers are noticing | Cybernews

Finding vulnerabilities was never the hard part | CyberScoop

The AI vulnerability storm is here: Is your security program ready? | TechTarget

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws - SecurityWeek

Vulnerabilities

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day

CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Palo Alto Networks Patches 13 Vulnerabilities - SecurityWeek

‘100% of Hide My Email addresses were exploitable’: Apple’s security feature can be duped into supplying the real contact info — and the bug has remained unpatched for over a year | TechRadar

ClamAV 1.5.3 Open-Source Antivirus Fixes Multiple Security Vulnerabilities

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

Critical Gitea Flaw Under Active Exploitation, Researchers Warn - SecurityWeek

Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection - SecurityWeek

Chrome 150 Update Patches 27 Vulnerabilities - SecurityWeek

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) - Help Net Security

Critical Linux KVM vulnerability exposes cloud servers to takeover​ | Cybernews

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

Wireshark 4.6.7 patches a dozen security flaws - Help Net Security


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 03 July 2026

Black Arrow Cyber Threat Intelligence Briefing 03 July 2026:

-Inside the Inbox: Why Cybercriminals Want to Break into Your Email Account

-Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

-ClickFix Now Cybercriminals' Favourite Malware Delivery Technique

-The Agentic AI ‘Lethal Trifecta’: What CISOs Should Know

-Ransomware Gangs Find Europe’s Weakest Link in Third-Party Suppliers

-Almost Half of Ransomware Victims Have Data Stolen Before They Can Even Detect an Intrusion

-UK Businesses Fear Stigma of Ransomware

-How Ransomware Syndicates Weaponize Corporate-Style Organisation

-Beyond the Perimeter: The Shift to Data-Centric Protection

-Cyber Risk Is Having a Greater Financial and Operational Impact on Businesses: Aon

-2026 Cyber Security Assessment: The Gap Between Awareness and Resilience

-Cyber Risk Falls Flat Without Business Translation

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

In recent weeks, our review of cyber security in the specialist and general media has focused on managing the risks presented by developments in AI. This week, however, our review highlights a greater focus on more traditional threats including email phishing and other social engineering, as well as a reminder of the continued growth in ransomware and the developing tactics of attackers. We also share insights into managing risks from the increasing use of cloud services, SaaS platforms and remote access.

These developments reinforce the need for business leaders to address both cyber security and cyber resilience. This requires cyber security teams to articulate risks in business terms, while business leaders develop sufficient understanding of cyber risk to make informed decisions and engage in informed discussion. Contact us to find out how we support organisations to achieve this in different sectors across the world.


Top Cyber Stories of the Last Week

Inside the Inbox: Why Cybercriminals Want to Break into Your Email Account

Email accounts remain a high-value target because they often provide access to other accounts through password resets, identity verification and connected business systems, including shared drives, finance platforms and customer data. ESET recorded a 36% rise in malicious emails in the second half of 2025 compared with the previous six months, while UK government figures found phishing was the most common form of cyber attack at 38%. Inbox compromise can also support fraud, data theft and ransomware, making strong passwords, multi-factor authentication and regular checks for suspicious forwarding rules important safeguards.

https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-account/

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Phishing attacks are becoming more targeted, with some campaigns now detecting a victim’s device, browser, language, location and operating system after they click a malicious link. This allows attackers to deliver the most suitable payload, such as different remote access tools for Mac or Windows users, or to mimic trusted brands such as Google, Microsoft Teams, Adobe, DocuSign and Zoom. Cofense warns that this increases the chance of compromise and makes each campaign more profitable, especially where trusted tools are misused to gain remote access.

https://www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os

ClickFix Now Cybercriminals' Favourite Malware Delivery Technique

ClickFix has become the leading technique used by cyber criminals to deliver malware, according to ReliaQuest analysis of attacks between 1 March and 31 May 2026. The technique tricks users into pasting attacker-supplied commands into trusted system tools, often through fake verification pages on compromised websites. This can bypass security tools because the action appears to be performed by the user. The threat now affects both Windows and macOS, with attackers adapting to Apple protections by targeting Script Editor to deliver AMOS malware, which steals browser credentials, session cookies, crypto wallets and keychain data.

https://www.infosecurity-magazine.com/news/clickfix-cybercriminals-favorite/

The Agentic AI ‘Lethal Trifecta’: What CISOs Should Know

Agentic AI can combine access to sensitive data, the ability to read untrusted content and permission to act or communicate externally, creating what some experts describe as a “lethal trifecta” of risk. If poorly controlled, AI agents could expose confidential information, change business systems or be manipulated through hidden instructions known as prompt injection. Organisations should map where AI agents have access, restrict permissions by default, monitor behaviour and apply strong identity controls so agents can only perform approved tasks.

https://www.techtarget.com/searchsecurity/tip/The-agentic-AI-lethal-trifecta-What-CISOs-should-know

Ransomware Gangs Find Europe’s Weakest Link in Third-Party Suppliers

Ransomware activity across Europe is rising, with suppliers and service providers increasingly used as routes into larger organisations. Black Kite reviewed 2,066 incidents across 31 countries and found publicly disclosed cases rose 55% between January and April 2026 compared with the same period in 2025. Germany, the UK, France, Italy and Spain accounted for nearly 70% of incidents, while manufacturing represented 28% of cases. The report also found 64 organisations were compromised through third-party incidents, highlighting how one supplier breach can create wider disruption for many connected businesses.

https://www.helpnetsecurity.com/2026/06/26/black-kite-european-cyber-threats-report/

Almost Half of Ransomware Victims Have Data Stolen Before They Can Even Detect an Intrusion

Ransomware attackers are increasingly stealing data before organisations realise they have been breached. ExtraHop’s Global Threat Landscape Report, based on more than 1,800 IT and security leaders, found that 49% of ransomware victims only detected an attack after data had been stolen, up from 31% last year. Attackers are spending an average of 2.5 weeks inside systems before detection, often by using encrypted channels, valid high-privilege accounts and activity that resembles legitimate workflows to avoid raising alarms. Average ransom payments fell from $3.6 million to $2.8 million, but 83% of surveyed victims still paid.

https://www.techradar.com/pro/security/almost-half-of-ransomware-victims-have-data-stolen-before-they-can-even-detect-an-intrusion

UK Businesses Fear Stigma of Ransomware

Ransomware is likely being significantly underreported by UK businesses, with many organisations reluctant to disclose attacks due to reputational concerns or fear of criticism, particularly where a ransom has been paid. Between April 2025 and March 2026, 323 UK organisations reported ransomware incidents to Report Fraud, with small and medium-sized organisations accounting for 175 cases. Reported losses totalled £270,000, a figure that may understate the true impact.

https://www.computerweekly.com/news/366645146/UK-businesses-fear-stigma-of-ransomware

How Ransomware Syndicates Weaponize Corporate-Style Organisation

Ransomware groups are increasingly operating like organised businesses rather than isolated criminals. Before shutting down in 2025, the ransomware group Black Basta targeted 520 victims across 39 industries and received at least $107 million in bitcoin payments. Leaked chats show structured teams, outsourced services, performance-based pay and tailored ransom demands based on a victim’s size, finances, sensitive data and cyber insurance policy details. Ransomware is estimated to generate around $74 billion globally each year, meaning organisations need to treat incidents as planned business crises, rehearsing decisions before attackers apply pressure through deadlines, disruption and data exposure.

https://cyberscoop.com/ransomware-syndicates-corporate-organization-op-ed/

Beyond the Perimeter: The Shift to Data-Centric Protection

As organisations use more cloud services, SaaS platforms and remote access, the traditional security boundary around the business has largely disappeared. Data now moves across multiple systems, suppliers and devices, making it harder to protect with network controls alone. A stronger approach focuses on the data itself, using clear ownership, encryption, controlled access, monitoring and recovery planning. This helps organisations reduce the impact of breaches, meet regulatory expectations and maintain business continuity when incidents occur.

https://www.techtarget.com/searchsecurity/tip/Beyond-the-perimeter-The-shift-to-data-centric-protection

Cyber Risk Is Having a Greater Financial and Operational Impact on Businesses: Aon

Cyber risk is having a growing financial and operational impact as businesses become more reliant on cloud services, shared infrastructure and third-party software. Aon warns that incidents now extend beyond data breaches, with losses increasingly linked to business interruption, supply chain disruption, reduced revenue and lengthy recovery periods. AI is also changing the risk landscape, increasing attacker capability while providing organisations with more effective tools for threat detection and response.

https://www.reinsurancene.ws/cyber-risk-is-having-a-greater-financial-and-operational-impact-on-businesses-aon/

2026 Cyber Security Assessment: The Gap Between Awareness and Resilience

Bitdefender’s 2026 Cyber Security Assessment, based on 1,200 IT and security professionals across six countries, highlights a gap between cyber risk awareness and practical resilience. While over 51% believe they have full visibility of approved and unapproved AI use, 47% admit visibility is partial or absent. AI risks dominate concern, yet Bitdefender Labs found that 84% of high-severity attacks abused legitimate tools already present inside organisations. The report also found 55% of breached respondents were told to keep incidents confidential, despite believing authorities should have been notified.

https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html

Cyber Risk Falls Flat Without Business Translation

Cyber risk is a board-level business issue, but boards need technical cyber risks translated into financial and operational impact to support effective decision-making. Verizon’s 2025 breach analysis found ransomware was present in 44% of breaches, third parties were involved in 30%, and attacks exploiting weaknesses rose 34% year on year. While 77% of directors now discuss the financial impact of cyber incidents, only 29% of boards include cyber security expertise. Clearer reporting, focused on cost, downtime, regulation and customer impact, helps boards prioritise action and investment.

https://www.informationweek.com/risk-management/cyber-risk-falls-flat-without-business-translation



Threats

Ransomware, Extortion and Destructive Attacks

Major Increase in Ransomware Attacks Targeting Europe, Warns Report - Infosecurity Magazine

UK businesses fear stigma of ransomware | Computer Weekly

Almost half of ransomware victims have data stolen before they can even detect an intrusion | TechRadar

Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

Ransomware gangs find Europe's weakest link in third-party suppliers - Help Net Security

Ransomware Resilience: What Happens When You Pay the Ransom? | SC Media UK

How ransomware syndicates weaponize corporate-style organization | CyberScoop

Somebody told DeepSeek to build in-browser ransomware and it gleefully complied

‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolen | IT Pro

Teens who hacked TfL were known to police years before cyber-attack - BBC News

Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions

FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations

Russian Hackers Accused of Destructive Attack on Jaguar Land Rover - Infosecurity Magazine

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

Microsoft: Two ransomware groups hit SharePoint | Cybernews

BlueHammer Vulnerability Exploited in Ransomware Attacks - SecurityWeek

Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues

Ransomware and Destructive Attack Victims

Russian Hackers Accused of Destructive Attack on Jaguar Land Rover - Infosecurity Magazine

Hackers target NATO cyber coalition member with data leak threat​ | Cybernews

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

Medtronic notifies customers impacted by ShinyHunters data breach

Blackfield ransomware asks Nidec Corporation for $2 million ransom

Phishing & Email Based Attacks

Bluekit phishing kit adopts browser-in-the-middle for login theft

This phishing kit looks more like BEC-as-a-service | CyberScoop

EvilTokens device-code phishing kit totally more evil than we all thought

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials - Help Net Security

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails

Inside the inbox: Why cybercriminals want to break into your email account

Business Email Compromise (BEC)/Email Account Compromise (EAC)

This phishing kit looks more like BEC-as-a-service | CyberScoop

EvilTokens device-code phishing kit totally more evil than we all thought

Lessons from the Underground: How to Combat Business Email Compromise

Other Social Engineering

ClickFix Now Cybercriminals' Favorite Malware Delivery Technique - Infosecurity Magazine

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Social engineering: how scammers manipulate their victims | Kaspersky official blog

SIM-swapping gang busted in international police operation - Help Net Security

Scammers race to cash in on Venezuelan earthquake disaster

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Wallpaper Engine puts an end to .exe wallpapers after malware spreads on the Steam Workshop - PC Guide

This Common Travel Convenience Is Becoming One of Scammers’ Favorite Tools, According to Cybersecurity Experts

Artificial Intelligence

Somebody told DeepSeek to build in-browser ransomware and it gleefully complied

Companies keep bolting AI onto their products, and the security bill is coming due - Help Net Security

AI-Generated Workflows Are a Silent Security Disaster

The agentic AI 'lethal trifecta': What CISOs should know | TechTarget

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Multiple malicious OpenClaw skills found online - including two macOS infostealers | TechRadar

Five Eyes Urges Organizers to Protect Against Cyber Threats

Agentic AI Has an Identity Problem and Attackers Know It

Does Mythos Have You Worried About AI Attacks? Get The Basics Right

AI-generated code risks reach security, legal, and compliance teams - Help Net Security

Red teamers turned Claude Desktop into a double agent to do their evil bidding

New Enterprise-Ready MCP Specification Brings New Security Challenges - SecurityWeek

Clean GitHub repo tricks AI coding agents into running malware

Chinese Open-Weight AI Model Raises Cybersecurity Worries Over Advanced Capabilities | IBTimes

Simplicity and unity will win the fight against AI cyberattacks | ChannelPro

Palo Alto Networks’ AI Misfire Triggers Cyber Dust-Up at Home

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

New BioShocking attack manipulates AI browser into data theft

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

AI browsers tricked into revealing passwords with a simple method

Anthropic Restores Claude Fable 5 After US Lifts AI Export Restrictions

Why CISOs need to rethink governance in the AI era | perspective | SC Media

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

AI is breaking the case for detection-first security | perspective | MSSP Alert

Securing AI agents: When AI tools move from reading to acting | Microsoft Security Blog

NO FAKES Act advances: What CISOs need to know | TechTarget

Why businesses are choosing cheap Chinese AI models over AI giants | Artificial Intelligence News - Business Standard

Bots/Botnets

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow

Microsoft wants to stop unwanted bots from entering Teams meetings - Help Net Security

Careers, Roles, Skills, Working in Cyber and Information Security

Beyond hiring: tackling the cybersecurity skills gap in the age of AI - New Statesman

Want a big tech job? Startups may be your best shot now - here's why | ZDNET

Cloud/SaaS

Hackers target Microsoft 365 accounts with 81 million login attempts

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials - Help Net Security

Massive Password Spray Campaign Targeting Azure CLI - SecurityWeek

Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Microsoft wants to stop unwanted bots from entering Teams meetings - Help Net Security

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Poland busts SIM-swapping gang tied to millions in crypto theft

SIM-swapping gang busted in international police operation - Help Net Security

Cyber Crime, Organised Crime & Criminal Actors

Chinese Framework Powers 200,000 Scam Sites - SecurityWeek

TfL Hackers Were Known To Police For Years | Silicon UK Tech

FBI and IC3 Warns of Surge of Spoofed FIFA Websites by Cybercriminals

Data Breaches/Leaks

FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations

Unnamed hackers steal stolen data from Icarus hackers responsible for Klue supply chain hack — and yes, it's as confusing as it sounds | TechRadar

Hackers Steal Data of 4.38 Million Aflac Japan Customers

Hackers breached DHS information-sharing network, people familiar say - Nextgov/FCW

Hackers target NATO cyber coalition member with data leak threat​ | Cybernews

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

CMC Releases Analysis and Guidance for Education Sector After Canvas D - Infosecurity Magazine

UK school’s network left wide open for invasion, student found

C2K: New warning to parents over schools cyber attack - BBC News

You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials

Nissan discloses employee data breach linked to Oracle zero-day attacks

Kubota says hackers had month-long access to network systems

Data/Digital Sovereignty

Digital sovereignty at the UN: Inside the global push to replace US cloud giants with open-source tech | ZDNET

Denial of Service/DoS/DDoS

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

Encryption

Preparing for Q-Day: New Executive Orders Address Quantum Innovation and Post-Quantum Cryptography | K&L Gates LLP - JDSupra

What the post-quantum executive order really demands of CISOs | CyberScoop

Fraud, Scams and Financial Crime

Chinese Framework Powers 200,000 Scam Sites - SecurityWeek

FBI and IC3 Warns of Surge of Spoofed FIFA Websites by Cybercriminals

Scammers race to cash in on Venezuelan earthquake disaster

US seizes hundreds of FIFA World Cup illegal streaming domains

What the Numbers Say About FIFA 2026 Cyber Risk

Why Cybersecurity Has Become Central to the Modern Sports Experience | Ice Miller - JDSupra

Amazon fined $2.25M for withholding evidence from fraud victims

WhatsApp will warn users before they message a potential scammer - Help Net Security

Identity and Access Management

Why Continuous Identity Verification Is The Future Of Cybersecurity

New spying threats force rethink of biometric identity checks | Biometric Update

Insider Risk and Insider Threats

Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues

Insurance

Cyberattacks Are Growing Threat to SMEs – but Insurance Protection Is Low: GlobalData

Internet of Things – IoT

Twenty Million US IP Connections Used by Proxy Services - Infosecurity Magazine

Law Enforcement Action and Take Downs

Poland busts SIM-swapping gang tied to millions in crypto theft

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

Microsoft uses AI to link two malware operations in racketeering suit

Montenegro police arrest Iranian accused of hacking US universities | Euronews

US seizes hundreds of FIFA World Cup illegal streaming domains

TfL Hackers Were Known To Police For Years | Silicon UK Tech

Linux and Open Source

After Fable 5 ban, Anthropic and 19 organizations launch open source security body - The New Stack

DirtyClone: A Linux Privilege Escalation That Leaves No Trace on Disk

Malware

RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow

ClickFix Now Cybercriminals' Favorite Malware Delivery Technique - Infosecurity Magazine

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Multiple malicious OpenClaw skills found online - including two macOS infostealers | TechRadar

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

119 Edge extensions promised useful tools, instead downloaded malware | Malwarebytes

Veil#Drop Uses Google Blogspot to Deploy PureLog Stealer - Infosecurity Magazine

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

New ChocoPoC malware targets researchers via trojanized PoC exploits

Microsoft uses AI to link two malware operations in racketeering suit

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Clean GitHub repo tricks AI coding agents into running malware

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

Mystery hackers use novel SharkLoader dropper against governments, software devs - Help Net Security

Malware-Laced USBs Breach Japanese Military Networks

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Hackers have a new way to disable Mac security software | Macworld

Critical SimpleHelp Vulnerability Exploited for Malware Delivery - SecurityWeek

Microsoft takes down over 100 malicious Edge extensions hiding malware in images and fonts | TechRadar

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware

Russian APT Deploys 'StockStay' Backdoor Against Ukrainian Targets - SecurityWeek

Telegram-Based Millenium RAT Campaign Infects 60,000 Devices - Infosecurity Magazine

Mobile

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

Over 5 Billion iPhones And Android Devices Are Vulnerable To This Massive New Threat

Poland busts SIM-swapping gang tied to millions in crypto theft

SIM-swapping gang busted in international police operation - Help Net Security

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools - Security Affairs

Even the Secret Service won't use company-issued phones

Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract | CyberScoop

Models, Frameworks and Standards

ISO 27001 or NIST CSF: Which Is Right for Your Business? - Security Boulevard

UK cybersecurity managers question speed-focused certification programs | SC Media UK

Half the defense base still builds security around compliance - Help Net Security

Passwords, Credential Stuffing & Brute Force Attacks

Hackers target Microsoft 365 accounts with 81 million login attempts

Bluekit phishing kit adopts browser-in-the-middle for login theft

FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials - Help Net Security

Massive Password Spray Campaign Targeting Azure CLI - SecurityWeek

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

AI browsers tricked into revealing passwords with a simple method

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials

AI may be good at finding security vulnerabilities, but it can't beat human stupidity

Regulations, Fines and Legislation

Anthropic Restores Claude Fable 5 After US Lifts AI Export Restrictions

Metropolitan Police chief warns against law updates amid substantial tech expansion | Computer Weekly

The legislative challenges of cybersecurity | IT Pro

The King’s Speech: What CISOs Should Know | SC Media UK

Amazon fined $2.25M for withholding evidence from fraud victims

Preparing for Q-Day: New Executive Orders Address Quantum Innovation and Post-Quantum Cryptography | K&L Gates LLP - JDSupra

NO FAKES Act advances: What CISOs need to know | TechTarget

Trump’s New AI Frontier: The Executive Order Regulating Frontier AI Models | Foley Hoag LLP - Security, Privacy and the Law - JDSupra

FCC passes new cybersecurity rules for emergency systems, undersea cables | CyberScoop

Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling | CyberScoop

UK journalists and NGOs risk terrorism prosecutions under new security bill | Middle East Eye

Half the defense base still builds security around compliance - Help Net Security

Software Supply Chain

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds

Clean GitHub repo tricks AI coding agents into running malware

Mystery hackers use novel SharkLoader dropper against governments, software devs - Help Net Security

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

Hiding in Plain Sight: The Geopolitics of Software Supply Chains

Supply Chain and Third Parties

Ransomware gangs find Europe's weakest link in third-party suppliers - Help Net Security

Unnamed hackers steal stolen data from Icarus hackers responsible for Klue supply chain hack — and yes, it's as confusing as it sounds | TechRadar

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

Nissan discloses employee data breach linked to Oracle zero-day attacks

Third-Party Breaches Teach Schools a Costly Lesson in Vendor Risk


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Hiding in Plain Sight: The Geopolitics of Software Supply Chains

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

Russia's 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

'No Ceasefire In Cyberspace:' Israel Says Iran-Linked Cyberattacks Nearly Tripled In June - Benzinga

Iran cyberattacks on Israel surged in 2026, Israeli cyber chief says - CNA

Iranian cyberattacks on Israel have nearly tripled cyber chief says | The Jerusalem Post

Iran, Russia, China Target Water Systems for Sabotage

Russian Water System Hack Attempted to Turn Canada Dry

Four years into Ukraine invasion, Russia turns influence-ops back to US and Europe

New spying threats force rethink of biometric identity checks | Biometric Update

Nation State Actors

Hiding in Plain Sight: The Geopolitics of Software Supply Chains

Iran, Russia, China Target Water Systems for Sabotage

China

Malware-Laced USBs Breach Japanese Military Networks

Iran, Russia, China Target Water Systems for Sabotage

Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware

Chinese Open-Weight AI Model Raises Cybersecurity Worries Over Advanced Capabilities | IBTimes

Chinese Framework Powers 200,000 Scam Sites - SecurityWeek

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder

Russia

Russian Intelligence Services Continue to Target Commercial Messaging Applications | CISA

FBI: Russian hackers now target Signal backup recovery keys

Iran, Russia, China Target Water Systems for Sabotage

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

Russian Water System Hack Attempted to Turn Canada Dry

Four years into Ukraine invasion, Russia turns influence-ops back to US and Europe

SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel

US offers $10 million for info on group behind Signal and WhatsApp hacking spree - Ars Technica

SBU neutralizes over 16,000 Russian cyberattacks, cyber incidents since 2022, largely targeting media

Russian Hackers Accused of Destructive Attack on Jaguar Land Rover - Infosecurity Magazine

Ireland retains out-of-date air navigation systems in response to Russian jamming – The Irish Times

Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract | CyberScoop

Iran

Iran, Russia, China Target Water Systems for Sabotage

'No Ceasefire In Cyberspace:' Israel Says Iran-Linked Cyberattacks Nearly Tripled In June - Benzinga

Iran cyberattacks on Israel surged in 2026, Israeli cyber chief says - CNA

Iranian cyberattacks on Israel have nearly tripled cyber chief says | The Jerusalem Post

Montenegro police arrest Iranian accused of hacking US universities | Euronews

Major Cybersecurity Failure: Four Largest Iranian Banks Face 3rd Week of Outages


Tools and Controls

Less than one in ten of cybersecurity pros trust AI testing tools to find vulnerabilities, with over three-quarters say their AI vulnerability scanning tools missed critical flaws | TechRadar

UK cybersecurity managers question speed-focused certification programs | SC Media UK

Claude Sonnet 5 includes safeguards against dangerous cyber use - Help Net Security

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls

AI Decline? Confidence Falls in Autonomous Penetration Testing

Cyberattacks Are Growing Threat to SMEs – but Insurance Protection Is Low: GlobalData

Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse

OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI - SecurityWeek

The AI Token Costs That Can Break Cybersecurity - SecurityWeek

Hackers have a new way to disable Mac security software | Macworld

Why Continuous Identity Verification Is The Future Of Cybersecurity

78% of Security Teams Experience Critical False Negatives From Automated Scanning Tools as AI Struggles to Detect and Resolve Vulnerabilities

It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns

Chinese Open-Weight AI Model Raises Cybersecurity Worries Over Advanced Capabilities | IBTimes

Even the Secret Service won't use company-issued phones

Microsoft uses AI to link two malware operations in racketeering suit

Palo Alto Networks’ AI Misfire Triggers Cyber Dust-Up at Home

Securing AI agents: When AI tools move from reading to acting | Microsoft Security Blog

Confidential Computing In The AI Era

Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract | CyberScoop

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder



Vulnerability Management

Less than one in ten of cybersecurity pros trust AI testing tools to find vulnerabilities, with over three-quarters say their AI vulnerability scanning tools missed critical flaws | TechRadar

Linux Foundation Unveils New Open Source Security Project Akrites - SecurityWeek

After Fable 5 ban, Anthropic and 19 organizations launch open source security body - The New Stack

A crucial Windows security certificate just expired - how to check your PC | ZDNET

New Initiative Secures End-of-Life Open Source Software

It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns

Vulnerability reports are arriving faster than GitHub can review them - Help Net Security

Modernizing Global Vulnerability Standards For The Age Of AI

Apple Reverses Age-Old Patch Policy to Keep Up With AI

Why patch directives only go so far | CyberScoop

Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder

Vulnerabilities

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure - SecurityWeek

Cisco finally confirms attackers exploiting Unified CM flaw

Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed

Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released

Adobe patches seven max severity ColdFusion, Campaign flaws

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin - Help Net Security

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

macOS Flaw Lets Standard Users Disable EDR and MDM - Infosecurity Magazine

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

Apple rushed to squash 29 bugs because AI is supercharging hackers - update ASAP | ZDNET

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

Over 5 Billion iPhones And Android Devices Are Vulnerable To This Massive New Threat

Amazon Q VS Extension Flaw Leads to Cloud Credential Theft

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

BlueHammer Vulnerability Exploited in Ransomware Attacks - SecurityWeek

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Chrome 150 fixes nearly 400 security flaws, including 15 critical ones | PCWorld

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

'DirtyClone' Linux Kernel Vulnerability Leads to Root Access - SecurityWeek

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

Critical SimpleHelp Vulnerability Exploited for Malware Delivery - SecurityWeek

Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253) - Security Boulevard

Synology issues critical fix for MailPlus Server vulnerabilities - Help Net Security

Anonymous researcher drops 0-day 'exploitarium' repo

Researcher Explains Release of Undisclosed Zero-Day Exploits - Infosecurity Magazine


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Advisory 30 June 2026: Attackers Abuse Trusted Platform Invitations to Impersonate Organisations

Black Arrow Cyber Advisory 30 June 2026: Attackers Abuse Trusted Platform Invitations to Impersonate Organisation

Organisations should be alert to a developing tactic in which attackers create fake workspaces on trusted software platforms and invite employees to join them using legitimate platform emails. Although this activity has recently been seen targeting cyber security and technology firms, the approach could quickly be adapted for other sectors, particularly where staff use artificial intelligence tools, collaboration platforms, cloud services or shared project spaces.

In a reported campaign, attackers created an OpenAI organisation that impersonated a legitimate company, then invited selected employees using their work email addresses. The invitations were sent from OpenAI’s genuine notification system, passed normal email authentication checks and looked like standard invitations to join a company workspace. This makes the approach more difficult to detect than traditional phishing, where attackers often rely on spoofed emails, suspicious links or lookalike domains.

The risk is not simply that an employee joins the wrong workspace. The concern is what happens next. If staff believe they are using an approved company environment, they may submit sensitive information into chats, prompts or project spaces. This could include internal documents, client information, source code, security research, strategy papers, commercial plans or other confidential material. In this case, the fake workspace had been made to look more credible by using the target company’s name, targeting specific employees, assigning them senior access rights and attaching a payment card to the billing account.

This reflects a wider shift in attacker behaviour. Rather than only sending malicious files or links, attackers are increasingly abusing legitimate features inside widely used online services. Invitations, notifications and shared workspace requests can come from real platforms and therefore may bypass technical email controls. The trust employees place in familiar brands and normal business workflows is being exploited.

What firms should do

Organisations should remind employees that a genuine email from a trusted platform does not always mean the workspace, project or invitation is legitimate. Staff should be told to verify any unexpected invitation to join a company workspace, especially where the request relates to artificial intelligence, file sharing, collaboration tools or administrative access.

Security and IT teams should review the technical solutions available to them to help manage this risk, for example SSPM platforms as well as how official company workspaces are named, managed and communicated to staff. Where possible, organisations should maintain an approved list of authorised platforms and tenants, and make it easy for employees to check whether an invitation is genuine. Unexpected invitations should be reported through existing security channels before being accepted.

Firms should also monitor membership and administration activity across software as a service platforms. This includes checking for unusual organisation invitations, unexpected owner or administrator permissions, and employees joining external workspaces that impersonate the business. Where platforms support domain verification, single sign on or tenant restrictions, these controls should be enabled.

For senior leaders, this is a reminder that cyber risk now extends beyond email and endpoint security. Attackers are targeting the everyday tools employees use to work, collaborate and experiment with artificial intelligence. Clear ownership of approved platforms, simple verification processes and staff awareness can significantly reduce the chance of sensitive company information being handed to an attacker through a trusted service.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 26 June 2026

Black Arrow Cyber Threat Intelligence Briefing 26 June 2026:

-GentleKiller Framework Disables Victims' Security Software

-What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

-Experts Warn: Passwords Still Winning Despite Passwordless Push

-What 22,000 Breaches Teach Us About Incident Preparedness

-The AI Shift in Cyber Risk: Why Leaders Must Act Now

-Why Knowing the Risk Isn’t the Same as Being Ready for It

-Confidence Lacks in Threat Detection Across Non-Email Channels Like Slack and Teams

-Repeated Cyber Disruption Costing SMEs Up to €3.4Bn Annually

-Businesses Are Expecting Catastrophic Cyber Incidents: 65% Think a Serious Cyber Attack Could Threaten Survival

-Professional Services Firms the ‘Flavour of the Month’ for Cyber Attacks

-Only 7% of Companies Are Ready for the AI Agents They Deployed

-Stressors, AI Forcing Changes to Cyber Security Teams

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

In our review of cyber security threat intelligence this week, we start with details of emerging and evolving threats. The ransomware group called The Gentlemen, which we referenced earlier this month, has developed a toolkit that disables victims’ security tools before encrypting data, while another group called ShinyHunters is increasingly seen using stolen credentials and trusted third-party access paths to reach victims.

Business leaders are recognising the risks from these and other tactics: we report that 65% of organisations believe a serious cyber attack could threaten their survival, and we include perspectives on the need for business leaders to convert this awareness into preparation for an attack, including as the risks accelerate due to AI and the routes of entry widen beyond emails to include other communications channels.

The next steps for business leaders are clear: take an impartial look at what needs to be protected and the risks, and establish controls to address those risks through a structured framework. The key is achieving objectivity and proportionality, by an upskilled leadership team working with impartial experts to define the required security contributions from the organisation’s control providers across technology, people and operations. Contact us to discuss how we can support you in achieving this.


Top Cyber Stories of the Last Week

GentleKiller Framework Disables Victims' Security Software

ESET has identified GentleKiller, a toolkit used by The Gentlemen ransomware group to disable victims’ security tools before data is encrypted. The framework targets more than 400 processes across around 48 security products, including major endpoint protection platforms. It abuses trusted but flawed software drivers to gain deep system access and disable security software before encrypting data. The group has built at least eight variants and offers affiliates a 90% share of ransom payments, reflecting a more organised and service-driven ransomware model.

https://www.infosecurity-magazine.com/news/gentlekiller-gentlemen-ransomware/

What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

Recent ShinyHunters breaches show that attackers no longer need malicious software or unknown software flaws to cause major harm. Incidents linked to organisations including the University of Nottingham, DentaQuest, 7-Eleven, Medtronic and Wynn Resorts point to a growing focus on stolen logins, MFA fatigue attacks and trusted third-party access. Once criminals gain valid credentials or digital tokens, which act like temporary access passes, their activity can look legitimate. For senior leaders, this reinforces the need to treat identity and access as a core cyber security risk, not just an IT control.

https://www.securityweek.com/what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks/

Experts Warn: Passwords Still Winning Despite Passwordless Push

Passwords remain the most widely exploited attack surface despite growing adoption of passwordless technology. Since the start of 2025, more than 16 billion passwords have been compromised globally, while credential abuse now accounts for 22% of breaches. Brute force attacks, where criminals repeatedly try login combinations, have almost tripled in the past year. Passkeys and phishing-resistant authentication offer stronger protection, but adoption remains uneven due to legacy systems, user change challenges and inconsistent platform support. For many organisations, passwords and passkeys will need careful governance side by side for some time.

https://www.itsecurityguru.org/2026/06/23/experts-warn-passwords-still-winning-despite-passwordless-push/

What 22,000 Breaches Teach Us About Incident Preparedness

Verizon’s 2026 Data Breach Investigations Report reviewed more than 22,000 confirmed breaches across 145 countries and highlights a growing gap between attack speed and organisational readiness. Ransomware appeared in 48% of breaches, while incidents involving suppliers or service providers rose by 60%. Exploitation of software vulnerabilities became the leading route into organisations, with critical fixes taking a median of 43 days. The findings reinforce the need for organisations to strengthen vulnerability management, third-party risk management and regular incident response exercises that test operational disruption, supplier failures and executive decision making before a real breach occurs.

https://www.csoonline.com/article/4185797/what-22000-breaches-teach-us-about-incident-preparedness.html

The AI Shift in Cyber Risk: Why Leaders Must Act Now

Five Eyes cyber security agencies have warned that artificial intelligence is rapidly changing cyber risk, with the impact expected to intensify in months rather than years. AI is helping attackers move faster, increasing the speed, scale and complexity of threats, while also offering defenders stronger tools to spot weaknesses and respond earlier. For senior leaders, cyber risk is a core business issue linked to operational continuity, market confidence and reputation. Priorities include reducing unnecessary system access, patching faster, addressing outdated technology, strengthening access controls and testing incident response plans before disruption occurs.

https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now

Why Knowing the Risk Isn’t the Same as Being Ready for It

UK businesses are more aware of cyber security risk than ever, but many remain underprepared. The latest Cyber Security Breaches Survey found only 19% of businesses ran staff training in the past year. Firebrand research also found just 27% of UK organisations are fully prepared for AI-powered cyber attacks, while nearly half experienced at least one attack in the past 12 months. The cost of the most disruptive breach commonly fell between £100,000 and £199,999 once downtime, recovery, regulatory exposure and reputational damage were included. The findings highlight the importance of regular training and recognised cyber security certification to strengthen organisational resilience.

https://www.emergingrisks.co.uk/why-knowing-the-risk-isnt-the-same-as-being-ready-for-it/

Confidence Lacks in Threat Detection Across Non-Email Channels Like Slack and Teams

KnowBe4 research found that many organisations lack confidence in detecting threats across workplace messaging and collaboration tools. In a survey of 169 cyber security professionals at Infosecurity Europe 2026, 50% said they lacked strong confidence in spotting threats across channels such as Slack, Microsoft Teams, social media and WhatsApp, while 60% said cyber attacks were already moving beyond email. Phishing emails remained the biggest perceived threat, selected by 61% of respondents. Training was also inconsistent, with just 41% regularly covering non-email threats.

https://www.infosecurity-magazine.com/news/threat-detection-across-nonemail/

Repeated Cyber Disruption Costing SMEs Up to €3.4Bn Annually

New research from telecoms provider eir Business estimates that cyber attacks cost Irish SMEs up to €3.4 billion each year, with much of the impact driven by repeated everyday disruption rather than major one-off breaches. The report found that SMEs with stronger cyber preparedness reduced annual downtime from more than 30 days to around five. It also found that a structured data management strategy reduced the likelihood of experiencing an attack from 40% to 24%.

https://www.techcentral.ie/repeated-cyber-disruption-costing-smes-up-to-e3-4bn-annually/

Businesses Are Expecting Catastrophic Cyber Incidents: 65% Think a Serious Cyber Attack Could Threaten Survival

Databarracks reports that 65% of organisations now believe a serious cyber attack could threaten their survival, following a series of high-profile cyber incidents. Cyber incidents remain the leading cause of IT downtime and data loss for the fourth year running, with 30% citing them as their biggest cause of downtime and 43% of large organisations reporting data loss. The proportion of organisations reporting AI-enabled attacks more than doubled to 25%. Encouragingly, 59% of ransomware victims recovered from backups, while only 18% paid a ransom.

https://www.prnewswire.com/news-releases/businesses-are-expecting-catastrophic-cyber-incidents-65-think-a-serious-cyber-attack-could-threaten-survival-302809003.html

Professional Services Firms the ‘Flavour of the Month’ for Cyber Attacks

Professional services firms, particularly law firms, are currently a prominent target for cyber attacks due to the sensitive client information they hold, including merger activity, trade secrets and employment matters. Attackers are increasingly using phishing and social engineering to trick staff into granting remote access, then quietly stealing data for extortion rather than encrypting systems. The risk is not limited to large firms, with organisations of all sizes exposed. Strong response planning, clear decision-making roles and a culture where staff report mistakes quickly are essential to responding effectively and reducing the impact of an incident.

https://www.cityam.com/professional-services-firms-the-flavour-of-the-month-for-cyberattacks/

Only 7% of Companies Are Ready for the AI Agents They Deployed

Veeam reports that although 88% of organisations are now running or piloting AI agents, only 7% are fully prepared to manage the risks of the AI agents they have deployed. Many are relying on poor quality or fragmented data, while responsibility for oversight is often unclear. The report warns that AI agents acting on poor-quality data can repeat errors across thousands of decisions before they are detected. The report also highlights widespread use of unapproved AI tools by employees, with only a quarter of organisations providing approved options for everyone.

https://www.helpnetsecurity.com/2026/06/23/ai-trust-gap-research/

Stressors, AI Forcing Changes to Cyber Security Teams

A new ISSA and Omdia survey highlights growing pressure on cyber security leaders, with 68% of cyber security and IT professionals saying their role is harder than two years ago. More than half cite rising complexity, heavier workloads and more overwhelming threats. AI is adding to the challenge, particularly through shadow AI, where employees adopt AI tools without the security team's knowledge, reducing visibility and control. At the same time, 37% already use AI to support cyber security work and 46% plan to, while demand for fractional cyber security leaders is increasing as organisations seek expert guidance without a full-time appointment.

https://www.darkreading.com/cybersecurity-operations/stressors-ai-changes-cybersecurity-teams



Threats

Ransomware, Extortion and Destructive Attacks

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Human Cost of Ransomware: Why CISOs Must Think Beyond Technology - Infosecurity Magazine

What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks - SecurityWeek

What 22,000 breaches teach us about incident preparedness | CSO Online

New 'Mistic' RAT Opens Door to Several Ransomware Families - SecurityWeek

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

ShinyHunters Targets Oracle PeopleSoft Customers Through Critical Zero-day

New Prinz Eugen ransomware prioritizes recent files for encryption

Two Britons plead guilty to £39m 2024 cyber-attack on Transport for London | Cybercrime | The Guardian

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage - Infosecurity Magazine

INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

Ransomware and Destructive Attack Victims

How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack - BBC News

Novo Nordisk Breach Exposes Software Development Pipeline Risk

Amazon’s One Medical hit by data breach claims​ | Cybernews

Phishing & Email Based Attacks

Confidence Lacks in Threat Detection Across Non-Email Channels - Infosecurity Magazine

EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps

Phishing hides in routine Microsoft 365 workflows - Help Net Security

INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

Other Social Engineering

He Thought He Was Secure; His Phone Number Was Stolen Anyway

New macOS ClickFix attack silently mounts DMGs to push infostealer

Gizmodo readers hit with ClickFix malware prompts after account compromise

2FA/MFA

He Thought He Was Secure; His Phone Number Was Stolen Anyway

Artificial Intelligence

Only 7% of companies are ready for the AI agents they deployed - Help Net Security

Change your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOs | CSO Online

Society has ‘months, not years’ to prepare for major AI cyberthreats – PublicTechnology

Trust is the target: the new AI-era supply-chain attacks

Anthropic's Mythos AI broke into almost all NSA classified systems in hours

Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics

The AI shift in cyber risk: why leaders must act now | National Cyber Security Centre

Get Ready for a Catastrophic Leak That Reveals All Your Messages and Search History

A public Sentry key is all it takes to hijack Claude Code, Cursor, and Codex - The New Stack

Stressors, AI Forcing Changes to Cybersecurity Teams

Microsoft warns AI agents are being 'AutoJack'-ed to deliver RCE payloads by browsing untrusted websites | TechRadar

Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

AI Is Making Attacks Cheaper, Faster and More Covert, Says ReliaQuest - Infosecurity Magazine

Cybercriminals Are Worried About AI Taking Their Jobs Too - Infosecurity Magazine

Microsoft links Mastra AI supply chain attack to North Korean hackers

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

Cybersecurity was built for predictable systems. AI changes the rules | CSO Online

Researchers Trick AI Browsers Into Leaking Credentials - Infosecurity Magazine

More Malicious OpenClaw Skills Threaten AI Supply Chain

Amateur Hacker Used Claude And OpenAI Agents To Hack 14 Companies

When Information Becomes the Attack Surface - Understanding AI Agent Traps - SecurityWeek

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

AI risks triggering ‘catastrophic’ phone network blackouts

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps - SecurityWeek

Police risk being outwitted by criminals using AI, says Met chief

macOS Backdoor Uses Prompt Injection to Evade AI Triage - Infosecurity Magazine

The New Energy War: Why The AI Grid Is The New Battleground

AI Shopping Agents Pose Novel Liability, Authorization Risks

PYMNTS | AI Is Now the Threat Banks Must Plan Around

Most teams will ship AI-written infrastructure code with little review - Help Net Security

Signal's Meredith Whittaker says AI chatbots 'are not your friends' and calls Copilot agents a backdoor

Bots/Botnets

15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown - SecurityWeek

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

Careers, Roles, Skills, Working in Cyber and Information Security

Stressors, AI Forcing Changes to Cybersecurity Teams

Cloud/SaaS

Phishing hides in routine Microsoft 365 workflows - Help Net Security

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor

Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware - Help Net Security

Cyber Crime, Organised Crime & Criminal Actors

Cybercriminals Are Worried About AI Taking Their Jobs Too - Infosecurity Magazine

Algerian man charged with running two cybercrime marketplaces | CyberScoop

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement | The Record from Recorded Future News

One-two punch delivered in global operation disrupts cybercrime "assembly line" - Ars Technica

In a first, a court takedown goes after two cybercrime tools at once | CyberScoop

Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame

Police risk being outwitted by criminals using AI, says Met chief

Civilians behind international police probe into Russian cybercriminals - National | Globalnews.ca

Data Breaches/Leaks

Get Ready for a Catastrophic Leak That Reveals All Your Messages and Search History

124 Million Unique Passwords Exposed In New Infostealer Log Dataset

Klue Hack Leads to Data Breach Across Multiple Cybersecurity Companies

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

24 Billion Stolen Credentials Exposed in Massive Data Leak - Security Affairs

Why Tata Electronics' cyber breach could be a concern for Apple and Tesla | Company News - Business Standard

Amazon’s One Medical hit by data breach claims​ | Cybernews

Hackers claim they stole a million records belonging to Canada Life users​ | Cybernews

Klue OAuth breach victim list grows as Icarus hackers claim attack

LastPass suffers another data breach, but this time your password vault is safe - Digital Trends

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps - SecurityWeek

Texas govt data breach exposes over 3 million driver’s licenses

Key Trump allies and Musk on leaked list for secretive Peter Thiel retreat | Peter Thiel | The Guardian

I Traced My Leaked Email Address to the Dark Web. Here's How It Got There

HCRG Care Group cyber attack leaves patient 'fuming' - BBC News

Texas Parks & Wildlife Data Breach Affects 3 Million Individuals - SecurityWeek

Xsolis Data Breach Affects 1.4 Million Individuals - SecurityWeek

Data Protection

Britain's privacy watchdog quits after 'poor judgment' admission

Encryption

Trump Orders US to Speed Quantum Adoption, Boost Cyber Defenses

Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration - SecurityWeek

Fraud, Scams and Financial Crime

Imposter Scams Cost Americans $3.5 Billion in 2025 - and It's Getting Worse

Inside the dark web: Stolen identities for 95¢, malware, and scams-for-hire | Malwarebytes

GTA 6 Scams Emerge as Pre-Orders Open - Infosecurity Magazine

Warning over Grand Theft Auto VI scam which could drain bank accounts - Birmingham Live

INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

Directors linked to £100m Ponzi scheme lose latest human rights appeal - Bailiwick Express News Guernsey

Identity and Access Management

How World Cup Password Trends Can Increase Active Directory Risk - Infosecurity Magazine

Internet of Things – IoT

How Chinese cars became a national security issue in Israel | Ctech

Residential proxy SDKs are hiding in LG and Samsung smart TV apps - Help Net Security

Law Enforcement Action and Take Downs

Scattered Spider members plead guilty to hacking Transport for London

Algerian man charged with running two cybercrime marketplaces | CyberScoop

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement | The Record from Recorded Future News

In a first, a court takedown goes after two cybercrime tools at once | CyberScoop

Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame

15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown - SecurityWeek

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Police raid malware network tied to Russia's Evil Corp hacker group | The Record from Recorded Future News

Civilians behind international police probe into Russian cybercriminals - National | Globalnews.ca

Nathan Austad Pleads Guilty in DraftKings Hacking Scheme, Gets 18 Months

DraftKings hacker 'Snoopy' sentenced to 18 months in prison

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

Police risk being outwitted by criminals using AI, says Met chief

Linux and Open Source

Linux users face a Microsoft Secure Boot headache - here's the painkiller | ZDNET

Open-source security is posing challenges governments can't easily solve | CyberScoop

Backporting bug fixes is dead, Project Valkey now sends in the bots - The New Stack

Malware

124 Million Unique Passwords Exposed In New Infostealer Log Dataset

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

New 'Mistic' RAT Opens Door to Several Ransomware Families - SecurityWeek

Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware

macOS Backdoor Uses Prompt Injection to Evade AI Triage - Infosecurity Magazine

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement | The Record from Recorded Future News

One-two punch delivered in global operation disrupts cybercrime "assembly line" - Ars Technica

Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame

Police raid malware network tied to Russia's Evil Corp hacker group | The Record from Recorded Future News

Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor

Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware - Help Net Security

New macOS ClickFix attack silently mounts DMGs to push infostealer

Gizmodo readers hit with ClickFix malware prompts after account compromise

A CISO's guide to infostealers: Prevention and detection | TechTarget

Japan defense forces used USB drives with China-linked virus: Nikkei investigation - Nikkei Asia

Malicious Edge extension abuses Native Messaging as bridge to malware

ShapedPlugin update flow hacked to infect WordPress sites

Mobile

He Thought He Was Secure; His Phone Number Was Stolen Anyway

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps - SecurityWeek

Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Google sets timeline for Android developer verification enforcement - Help Net Security

Companies are profiling you from your smartphone use - how to stop them | ZDNET

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

The 10-step phone security tune-up you should run every year - and why | ZDNET

Outages

Parts of the internet go down after major network outage | News Tech | Metro News

One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why

Passwords, Credential Stuffing & Brute Force Attacks

124 Million Unique Passwords Exposed In New Infostealer Log Dataset

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout - Infosecurity Magazine

24 Billion Stolen Credentials Exposed in Massive Data Leak - Security Affairs

Klue says hackers stole credential from 2022 that led to customer data breaches | TechCrunch

Experts Warn: Passwords Still Winning Despite Passwordless Push - IT Security Guru

How World Cup Password Trends Can Increase Active Directory Risk - Infosecurity Magazine

A Glimpse into the “Search Your Target” Market for Stolen Credentials

Regulations, Fines and Legislation

How the social media ban could reshape how all of us use the internet - BBC News

Open-source security is posing challenges governments can't easily solve | CyberScoop

Circumvention tool or essential security software? The shifting role of VPNs in the UK | TechRadar

Reality check: Could the UK's social media ban lead to VPN restrictions? | TechRadar

The UK’s social media ban for under-16s has just empowered big tech | Taylor Lorenz | The Guardian

From PGP to Mythos: a brief history of export controls that didn't stop anyone | TechCrunch

Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration - SecurityWeek

Britain's privacy watchdog quits after 'poor judgment' admission

Contractor Settles False Claim Allegations Over Cybersecurity Violations | Cohen Seglias Pallas Greenhall & Furman PC - JDSupra

Shadow IT

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

Social Media

How the social media ban could reshape how all of us use the internet - BBC News

Software Supply Chain

'Cordyceps': Malicious Pull Requests Threaten CI/CD Workflows

Supply Chain and Third Parties

Klue Supply Chain Breach Exposes Salesforce Data At Several Security Firms

Klue OAuth breach victim list grows as Icarus hackers claim attack

Trust is the target: the new AI-era supply-chain attacks

What 22,000 breaches teach us about incident preparedness | CSO Online

Why Tata Electronics' cyber breach could be a concern for Apple and Tesla | Company News - Business Standard

LastPass suffers another data breach, but this time your password vault is safe - Digital Trends

Microsoft links Mastra AI supply chain attack to North Korean hackers

Reinforcing Supply Chain Cybersecurity- 5 Strategies


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

The UK is unprepared for Putin's cyber war. But one European country has the answer

The New Energy War: Why The AI Grid Is The New Battleground

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage - Infosecurity Magazine

Inside Iran’s Cyber War Machine -Exclusive: Iran’s IRGC taps Russian and Chinese experts for global cyberattacks and dissident tracking

Hackers infiltrate Russian battlefield software and reportedly replace military map data with Ukrainian flags and disruptive messages | TechRadar

Nation State Actors

China

How Chinese cars became a national security issue in Israel | Ctech

Experts flag possible influence operations ahead of Taiwan's local elections | Taiwan News | Jun. 20, 2026 14:54

Russia

The UK is unprepared for Putin's cyber war. But one European country has the answer

Hackers infiltrate Russian battlefield software and reportedly replace military map data with Ukrainian flags and disruptive messages | TechRadar

Police raid malware network tied to Russia's Evil Corp hacker group | The Record from Recorded Future News

Civilians behind international police probe into Russian cybercriminals - National | Globalnews.ca

North Korea

Microsoft links Mastra AI supply chain attack to North Korean hackers

Iran

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage - Infosecurity Magazine

Inside Iran’s Cyber War Machine - Exclusive: Iran’s IRGC taps Russian and Chinese experts for global cyberattacks and dissident tracking

Iran-linked hackers claim FBI drone breach and World Cup threat as questions swirl around evidence and surveillance systems | TechRadar

Iran-linked hackers breached a California water utility serving millions and published everything they found online | TechRadar


Tools and Controls

What 22,000 breaches teach us about incident preparedness | CSO Online

Circumvention tool or essential security software? The shifting role of VPNs in the UK | TechRadar

Reality check: Could the UK's social media ban lead to VPN restrictions? | TechRadar

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

Anthropic's Mythos AI broke into almost all NSA classified systems in hours

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents - SecurityWeek

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

Rolling out AI agents? 4 ways to move fast and furious - but with extreme caution | ZDNET

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

Why Frontier AI makes prioritization the most important part of your CTEM program

Companies are discarding the logs they need to catch a breach - Help Net Security

One intrusion, two cyberattackers: Uncovering parallel threat activity | Microsoft Security Blog

Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era

Security testing was built for a slower world - Help Net Security

Why MSSPs need to focus on reducing cyber risk, not adding complexity | ChannelPro

Most teams will ship AI-written infrastructure code with little review - Help Net Security

Don't panic, prepare: A cyber expert's advice on the Mythos hype

Healthcare staff enraged after a day off turned out to be a phishing test ​ | Cybernews



Vulnerability Management

What 22,000 breaches teach us about incident preparedness | CSO Online

Open-source security is posing challenges governments can't easily solve | CyberScoop

Windows 10 losing security support in October – 6 ways to solve the problem - Which?

Get Out of Security Debt

Why Frontier AI makes prioritization the most important part of your CTEM program

Microsoft extends Windows 10's extra security updates program to October 2027 for free

Dozens of America's largest companies have no simple way to report security flaws

Vulnerabilities

Microsoft's June update fixed 208 security flaws and introduced a cascade of new bugs across all Windows versions

The hits keep on coming for Cisco vulnerabilities

Cisco SD-WAN Zero-Day Exploited Months Before Patching - SecurityWeek

Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet - Security Affairs

FFmpeg fixes PixelSmash flaw in widely used video decoder

Chrome 149 Update Resolves 18 Severe Vulnerabilities - SecurityWeek

Update Chrome to patch critical browser security flaws | Malwarebytes

ShinyHunters Targets Oracle PeopleSoft Customers Through Critical Zero-day

Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security

Critical Ubiquiti Vulnerabilities in Attackers' Crosshairs - SecurityWeek

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Your old iPhone may have a security flaw Apple can’t fix - Digital Trends

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 19 June 2026

Black Arrow Cyber Threat Intelligence Briefing 19 June 2026:

-FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls

-24 Billion Records, Including Usernames and Passwords, Exposed in Colossal Data Leak: What Does That Mean for You?

-Meet Kali365 — The ‘Amazon of Cybercrime’ Where Hackers Use AI to Completely Circumvent Multi-Factor Authentication

-HP Warns 11% of Email Threats Bypass Security Gateways

-Cybercriminals Are Moving Away from Mass Phishing Campaigns

-One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

-“Dangerous” AI Models Are Coming No Matter What

-Low-Skilled Attacker Used Claude, Codex to Breach 14 Companies

-It’s Time to Update Incident Response for the AI Era

-NCSC CEO: Hostile States Linked to Three-Quarters of Cyber Attacks Affecting UK’s Critical Systems

-Over Two-Thirds of Security Pros Say Cyber Is Getting Harder

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

In our review of cyber security in the specialist and general media this week, we start with several high-profile alerts for business leaders. Organisations using Fortinet should assess their response to the discovery of tens of thousands of firewall credentials, and all organisations should assess the impact of a wider data leak of 24 billion records. We also provide more information on the Kali365 phishing-as-a-service platform targeting Microsoft accounts, which we included last week, and information on research regarding the number of malicious emails that bypass current security.

Over recent weeks, we have highlighted the need for organisations to manage the risks associated with using AI, and we provide further examples below. These include a Copilot risk recently remediated by Microsoft, and how AI is being used by attackers.

Distilling these insights into key actions, a message for business leaders is to prepare for organisational resilience in the event of a cyber incident. We work on this with clients across the world to achieve proportionality, which requires an objective understanding of the high-impact business activities in the organisation that must be prioritised in an incident, and a leadership team that has rehearsed together by considering the challenging and realistic ‘what if?’ scenarios to dispel assumptions. Contact us to discuss how to achieve this.


Top Cyber Stories of the Last Week

FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls

Security researchers have identified a major exposure of Fortinet firewall credentials affecting around 75,000 devices, with the dataset believed to cover roughly half of all internet-facing Fortinet firewalls. The exposed information reportedly includes usernames, email addresses and plain text passwords across 194 countries and more than 21,000 domains, including major companies, government bodies and critical infrastructure operators. Evidence suggests the data may have been prepared for sale in criminal markets or for coordinated deployment by threat actors, increasing the risk of attackers gaining remote access to affected networks, changing security settings or creating hidden administrator accounts.

https://securityaffairs.com/193817/hacking/fortibleed-exposes-admin-passwords-for-75000-fortinet-firewalls.html

24 Billion Records, Including Usernames and Passwords, Exposed in Colossal Data Leak: What Does That Mean for You?

Cybernews researchers identified an exposed database containing 24 billion records and more than 8.3TB of data, including usernames, email addresses, passwords and login URLs. Much of the data appears to come from infostealer malware, although researchers also identified records sourced from Telegram channels, breach compilations and other collections. The database was exposed between 12 and 15 June 2026, although researchers cannot confirm how many records were duplicates or how many people were affected. Reused passwords remain a key risk, particularly for accounts without multi-factor authentication.

https://cybernews.com/security/24-billion-credentials-data-leak/

Meet Kali365 — The ‘Amazon of Cybercrime’ Where Hackers Use AI to Completely Circumvent Multi-Factor Authentication

Kali365 is a phishing-as-a-service platform targeting Microsoft accounts, offering criminals ready-made tools to run phishing campaigns at scale. First identified by Huntress in May 2026, it includes more than 33 Microsoft themed templates and over 100 API endpoints. The platform gains access to accounts after users complete multi-factor authentication, using stolen session cookies and OAuth tokens rather than passwords alone. The FBI has warned that it can also use AI to read stolen email threads, assess fraud opportunities and draft replies based on the content of compromised conversations.

https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication

HP Warns 11% of Email Threats Bypass Security Gateways

HP research has found that 11% of email threats reaching users had already bypassed one or more security gateway scanners in Q1 2026. Email remained the leading route for malicious activity, accounting for 57% of threats, followed by web browser downloads at 24%. Attackers are increasingly abusing legitimate software, trusted platforms and familiar business processes to avoid detection, including remote access tools, fake software updates and shared design platforms. The findings suggest organisations should not rely solely on email security gateways, as a proportion of threats are reaching users after passing through existing scanning controls.

https://therecycler.com/posts/that-hp-warns-11-of-email-threats-bypass-security-gateways/

Cybercriminals Are Moving Away from Mass Phishing Campaigns

Zscaler reports that overall phishing activity fell by around 20% in both 2024 and 2025, but phishing campaigns are becoming more targeted. Criminals are moving away from mass email campaigns towards convincing business-themed messages, such as billing notices, onboarding documents and support requests. The services sector saw a 65.5% rise in phishing activity, while Microsoft and Google remained the most impersonated brands. Zscaler also found more than 95% of phishing activity used encrypted web traffic, with attackers increasingly using artificial intelligence tools to create fake websites and steal active login sessions. The research suggests organisations should look beyond blocked-email statistics when assessing phishing threats, as attackers are increasingly focusing on identities, active sessions and other techniques that are not reflected in email volumes.

https://www.helpnetsecurity.com/2026/06/12/zscaler-report-phishing-activity-trends/

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

A flaw in Microsoft 365 Copilot Enterprise Search could have allowed attackers to steal emails, calendar details, files and multi-factor authentication codes after a user clicked a genuine Microsoft link. Researchers found the issue could bypass traditional phishing checks because the link used a trusted Microsoft domain. Microsoft has fixed the issue through its managed service, and there is no evidence it was exploited. The research notes that Copilot Enterprise can access the same emails, files and business information available to the signed-in user, and recommends monitoring unusual Copilot activity and limiting the volume of data available for indexing.

https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html

“Dangerous” AI Models Are Coming No Matter What

Advanced AI models with hacking capabilities are expected to become more widely available within months, raising concerns for governments and business leaders alike. Anthropic recently took two models offline after US export controls, amid fears their safeguards could be bypassed. Experts argue that organisations and governments should prepare for a future in which advanced AI cyber capabilities are widely available, rather than assuming restrictions on individual models will prevent their emergence. While these models can help defenders find and fix weaknesses, they could also help criminals identify ways to exploit them.

https://arstechnica.com/ai/2026/06/dangerous-ai-models-are-coming-no-matter-what/

https://www.wired.com/story/dangerous-ai-models-are-coming-no-matter-what/

Low-Skilled Attacker Used Claude, Codex to Breach 14 Companies

OALABS researchers found that a low-skilled attacker used AI coding agents to breach at least 14 companies, showing how these tools can reduce the expertise needed for cyber attacks. More than 1,000 recovered sessions showed the attacker used vague prompts, often framed as authorised security testing, while the AI helped find exposed systems, write exploit code and extract data. The tools raised few policy violations, and most were bypassed. The findings suggest AI coding agents can reduce the technical expertise required to conduct cyber attacks.

https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/

It’s Time to Update Incident Response for the AI Era

Gartner has warned that incident response must adapt as AI becomes embedded in business operations. It predicts that at least 80% of unauthorised AI transactions will stem from internal policy breaches, oversharing of information, unacceptable use or misguided AI behaviour, rather than malicious attacks. The challenge is that AI systems may create business risk while acting within their approved permissions. Gartner recommends that organisations review how they define AI-related incidents, improve oversight of AI activity, and ensure legal, compliance, HR and business teams are included in response planning.

https://www.techtarget.com/searchsecurity/news/366644312/Its-time-to-update-incident-response-for-the-AI-era

NCSC CEO: Hostile States Linked to Three-Quarters of Cyber Attacks Affecting UK’s Critical Systems

The UK’s NCSC has warned that hostile states are behind around three quarters of cyber attacks affecting the UK’s critical national infrastructure. More than 200 incidents involving essential services and their supporting systems were handled in the year to May 2026, with Russia, China and Iran identified as examples of hostile states of concern. The warning highlights the importance of understanding exposure to threats, strengthening security fundamentals and ensuring organisations can continue operating and recover quickly after an attack. The NCSC also expects artificial intelligence to increase the scale at which attackers can identify and exploit vulnerable legacy technology by 2028.

https://www.ncsc.gov.uk/news/ncsc-ceo-hostile-states-linked-to-three-quarters-of-cyber-attacks

Over Two-Thirds of Security Pros Say Cyber Is Getting Harder

A new ISSA and Omdia study of 380 cyber security professionals found that 68% believe their role has become harder over the past two years. Many report being excluded from key technology decisions, with 72% saying this creates barriers to stronger security. Stress is also rising, with 47% considering leaving their role or the profession in the past 12 to 18 months. Only 29% rated their organisation’s cyber security culture as advanced, with respondents identifying increased training, investments in the right resources, stronger cyber hygiene and closer collaboration between security and IT teams as key areas for improvement.

https://www.infosecurity-magazine.com/news/security-pros-cyber-cyber-harder/



Threats

Ransomware, Extortion and Destructive Attacks

DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months

Ransomware group The Gentlemen linked to Russian national | SC Media UK

Infostealers, AI, and a 90% Affiliate Cut Fuel The Gentlemen group’s Rise - Security Affairs

Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic

Silent Ransom Group: What You Need to Know

Morpheus Unmasked: Big Game Hunting and Private Data Sales | Ankura - JDSupra

Ransomware Insider Betrayal: Guilty Plea In BlackCat Cybercrime Scheme

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop

Ukrainian national pleads guilty to role in Conti ransomware operation

INC Ransomware Thrives by Mastering the Basics

Ransomware and Destructive Attack Victims

Nottingham University cyber attack: Everything we know so far as ShinyHunters claims responsibility | IT Pro

Council of Europe hacked in ShinyHunters' PeopleSoft heist

Hacking Group Claims Major Hack of Novo Nordisk and Attempted $25M Extortion

Cyberattack Gives Biglaw Firm A New Return-To-Office Excuse - Above the Law

JLR ordered in-person password resets after cyberattack | Manufacturer News

Infinite Campus data breach affects 137,000 school staff accounts

Kodak confirms data breach claimed by ShinyHunters extortion gang

Phishing & Email Based Attacks

Cybercriminals are moving away from mass phishing campaigns - Help Net Security

HP warns 11% of email threats bypass security gateways - The Recycler

Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication | TechRadar

FBI disrupts massive AI-powered phishing service using a million URLs

New Phishing Scam Targets Microsoft Teams, Outlook, OneDrive

Google Sues Chinese Cybercrime Group Behind 'Phishing-for-Dummies' Software | PCMag

FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI —$88 cybercrime product linked to $1.9 billion in losses, 3.87 million stolen cards | Tom's Hardware

Google Sues Chinese Phishing Service Over Gemini Abuse

FBI warns Microsoft Teams, Outlook, OneDrive users of phishing scam - Fast Company

9 million email addresses loaded into UK retail, tax and crypto scams | Cybernews

Microsoft Defender email security benchmarking: Key insights from one year of data | Microsoft Security Blog

Other Social Engineering

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

'Lorem Ipsum' Malware Pivots to ClickFix Delivery

9 million email addresses loaded into UK retail, tax and crypto scams ​ | Cybernews

Why SIM Swapping Remains a Blind Spot for Enterprise Security Teams

FTC warns of record $3.5 billion losses to imposter scams in 2025

Planning a trip? Fake travel sites are multiplying this summer - Help Net Security

Helpdesk scammers are making house calls to make their lies feel more real

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US)

North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine

From Reels to risks: How scammers are turning videos into malware traps | Tech News - Business Standard

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

2FA/MFA

Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication | TechRadar

Artificial Intelligence

Anthropic Halts Access to Top AI Models After U.S. Ban on Foreign Use - WSJ

Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication | TechRadar

Low-skilled attacker used Claude, Codex to breach 14 companies - Help Net Security

FBI disrupts massive AI-powered phishing service using a million URLs

It's time to update incident response for the AI era | TechTarget

AI sovereignty hawks see red as U.S. moves to block Anthropic’s Mythos and Fable models - The Hindu

New attack turned Microsoft 365 Copilot into 1-click data theft tool

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI —$88 cybercrime product linked to $1.9 billion in losses, 3.87 million stolen cards | Tom's Hardware

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

US decision to block Mythos access fuels European calls for sovereignty | Euractiv

Cyber Experts Urge US to Lift Ban on Anthropic’s Frontier AI Models - Infosecurity Magazine

AI’s constant patching treadmill can be a security problem | CyberScoop

"Dangerous" AI models are coming no matter what

The OpenClaw security risks every CISO needs to know | TechTarget

AI is accelerating cyberattacks—here’s how to stay ahead | Microsoft Community Hub

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US)

US, France, and Italian authorities shut down massive deepfake porn site | CyberScoop

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

Vibe coders are gonna vibe code: How CISOs are tackling code sprawl

AI Threats and Alert Fatigue Challenge Cybersecurity Teams - Infosecurity Magazine

North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine

Google Sues Chinese Phishing Service Over Gemini Abuse

Technical Warnings: AI Assistants Could Become Gateways for Cyberattacks

EU regulation drives new cybersecurity focus on AI systems - The Recycler

NanoClaw integrates JFrog registries to secure AI agent downloads

Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek

The Executive Order on Advanced AI Innovation and Security: What Businesses Need to Know | Mayer Brown - JDSupra

AI Execution Is Pushing CIOs Back to IT Fundamentals, Info-Tech Research Group's Best of 2026 Mid-Year Report Finds

Careers, Roles, Skills, Working in Cyber and Information Security

AI Threats and Alert Fatigue Challenge Cybersecurity Teams - Infosecurity Magazine

Accenture cyber leads: why hiring more people won’t solve the cybersecurity talent gap | Fortune

Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS - Infosecurity Magazine

Cybersecurity Skills Gap in 2026: Why Developers Should Add Security

How AI is changing the breadth of cybersecurity roles

Cloud/SaaS

New Phishing Scam Targets Microsoft Teams, Outlook, OneDrive

DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months

FBI warns Microsoft Teams, Outlook, OneDrive users of phishing scam - Fast Company

Cyber Crime, Organised Crime & Criminal Actors

FBI takes down massive China-based cybercrime network that caused $1.9B in losses | CyberScoop

Cyber offenses now account for around a third of all crime across Asia and South Pacific

Data Breaches/Leaks

24 billion records, including usernames and passwords, exposed in colossal data leak | Cybernews

'The credential data leak is dangerous simply because of its enormous size': Experts warn "colossal" breach exposes 24 billion records including personal info | TechRadar

Hackers Crack Corporate, Government VPNs In Major Incident

Council of Europe investigates ShinyHunters data breach claims

Novo Nordisk says hackers stole clinical trial data

Plymouth council exposes hundreds in latest local government email gaffe

French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker - SecurityWeek

Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data

University of Nottingham shares more details on major cyber-attack - BBC News

Infinite Campus data breach affects 137,000 school staff accounts

Fired IT worker jailed for 21 months after sabotaging old school district

Hackers Publish Knicks and Madison Square Garden Data Online

Data/Digital Sovereignty

US decision to block Mythos access fuels European calls for sovereignty | Euractiv

Europe is starting to break up with US big tech. But it’s still abiding by the Silicon Valley rulebook | Max von Thun | The Guardian

MPs call for UK government to back sovereign IT | Computer Weekly

France's digital sovereignty push is struggling to escape the Microsoft gravity well

French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker - SecurityWeek

Digital sovereignty needs an operating model

Denial of Service/DoS/DDoS

IT, Telcos, Healthcare at Risk of HTTP/2 DDoS Attacks

Encryption

France to stop certifying products without quantum-safe encryption | Reuters

CEOs Must Act Before Quantum Computers Break Existing Cybersecurity

Fraud, Scams and Financial Crime

FTC warns of record $3.5 billion losses to imposter scams in 2025

Planning a trip? Fake travel sites are multiplying this summer - Help Net Security

Helpdesk scammers are making house calls to make their lies feel more real

15 Cybercriminals, 40 Fake Websites: Major FIFA World Cup Ticket Fraud Network Identified - Report | Football News

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

Hackers Are Hijacking Entire Roblox Games Now

Identity and Access Management

Chinese hackers hijack auth flow, spy on isolated network for a decade

Insider Risk and Insider Threats

North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine

Ex-school district employee jailed for hacks on former employer

Fired IT worker jailed for 21 months after sabotaging old school district

Internet of Things – IoT

21,786 Home Cameras, No Password, No Warning

Securing digital keys when your phone unlocks the car - Help Net Security

Law Enforcement Action and Take Downs

FBI disrupts massive AI-powered phishing service using a million URLs

FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI —$88 cybercrime product linked to $1.9 billion in losses, 3.87 million stolen cards | Tom's Hardware

Ransomware Insider Betrayal: Guilty Plea In BlackCat Cybercrime Scheme

Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop

Ukrainian national pleads guilty to role in Conti ransomware operation

Fired IT worker jailed for 21 months after sabotaging old school district

Linux and Open Source

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages - SecurityWeek

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Malware

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages - SecurityWeek

144 Mastra npm Packages Compromised via Hijacked Contributor Account

Fileless Phantom Stealer Targets Browser Credentials

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

SprySOCKS Windows Variant Uses Kernel Drivers to Evade Detection

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US)

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

'Lorem Ipsum' Malware Pivots to ClickFix Delivery

WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer

From package to postinstall payload: Inside the Mastra npm supply chain compromise | Microsoft Security Blog

From Reels to risks: How scammers are turning videos into malware traps | Tech News - Business Standard

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

Steam Workshop abused to spread malware via Wallpaper Engine app

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

Mobile

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

Your strong passwords mean nothing if your phone PIN is four digits

Every way your phone tracks your location - and how to stop it | ZDNET

Verizon sent man a refurbished phone with MDM, then deleted his data remotely - Ars Technica

Models, Frameworks and Standards

EU Cybersecurity Act 2.0: When good regulation goes bad - Help Net Security

Software supply chains are heading for a transparency test - Help Net Security

Passwords, Credential Stuffing & Brute Force Attacks

Hackers Crack Corporate, Government VPNs In Major Incident

Massive breach spills credentials for thousands of sensitive networks - Ars Technica

FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls

Why Account Takeovers Are Rising and How to Stop Them

We need to do something about passwords | IT Pro

Your strong passwords mean nothing if your phone PIN is four digits

JLR ordered in-person password resets after cyberattack | Manufacturer News

Regulations, Fines and Legislation

Anthropic Halts Access to Top AI Models After U.S. Ban on Foreign Use - WSJ

AI sovereignty hawks see red as U.S. moves to block Anthropic’s Mythos and Fable models - The Hindu

Lawmakers leery about Trump administration’s Anthropic order | CyberScoop

Security Community Slams US Ban on Exporting Mythos, Fable

Anthropic sends top security experts to Washington to rescue flagship models - Cryptopolitan

Restore Fable and Mythos Access, Cybersecurity Leaders Urge

Anthropic Pushes Back Against US Order Restricting Claude Fable 5, Backed by Cybersecurity Experts - gHacks Tech News

"Dangerous" AI models are coming no matter what

UK to require ID or face scan before you can make social media accounts

UK Social Media Ban for Minors Has Privacy Experts Worried

Software supply chains are heading for a transparency test - Help Net Security

EU regulation drives new cybersecurity focus on AI systems - The Recycler

Banks fight to scrap an SEC cyberattack rule | American Banker

Trump Memo Overhauls Cyber Rules for Classified Networks

The Executive Order on Advanced AI Innovation and Security: What Businesses Need to Know | Mayer Brown - JDSupra

Social Media

Security risks overshadow the debut of Europe’s X rival, W | Cybernews

UK to require ID or face scan before you can make social media accounts

UK Social Media Ban for Minors Has Privacy Experts Worried

From Reels to risks: How scammers are turning videos into malware traps | Tech News - Business Standard

Software Supply Chain

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages - SecurityWeek

144 Mastra npm Packages Compromised via Hijacked Contributor Account

Software supply chains are heading for a transparency test - Help Net Security

From package to postinstall payload: Inside the Mastra npm supply chain compromise | Microsoft Security Blog

Supply Chain and Third Parties

Early Warning Signs of Supply-Chain Attacks Live in the Dark Web

Another healthcare firm attacked days after Novo Nordisk breach - Help Net Security

University of Nottingham shares more details on major cyber-attack - BBC News


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Cyberspace Locked in a Nation-State Contest, Says NCSC CEO

Hostile states launched nearly 200 attacks on UK infrastructure in five months, says NCSC chief | Computer Weekly

UK infrastructure being targeted by hostile states, GCHQ cyber chief warns | The Standard

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems | National Cyber Security Centre

Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek

Google exposes China espionage group that’s been lurking in networks undetected since 2023 | CyberScoop

The unit preparing for Israel's invisible war | Ctech

EU extends emergency cyber security support to Ukraine - CNA

2036 Starts Today: A Call to Action for NATO's Cyber Future > The Cyber Defense Review > Article View

Nation State Actors

Cyberspace Locked in a Nation-State Contest, Says NCSC CEO

Hostile states launched nearly 200 attacks on UK infrastructure in five months, says NCSC chief | Computer Weekly

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems | National Cyber Security Centre

What is the UK's Defending Democracy Taskforce? - The Constitution Society

China

Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek

China-linked actor UNC6508 spent two years inside medical research networks

Chinese hackers hijack auth flow, spy on isolated network for a decade

Netgear countersues TP-Link, saying firm 'remains, at its core, a Chinese company selling Chinese-made products' — alleges its 'American company' rebrand is false advertising | Tom's Hardware

Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain

Google Sues Chinese Phishing Service Over Gemini Abuse

FBI takes down massive China-based cybercrime network that caused $1.9B in losses | CyberScoop

Google Sues Chinese Cybercrime Group Behind 'Phishing-for-Dummies' Software | PCMag

Russia

WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer

EU provides cyber support to Ukraine against major attacks | EEAS

North Korea

North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine

CISA Launches Major Hiring Push and Remote Worker Fraud Emerges as Growing Threat - ClearanceJobs

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

Iran

Iran-Linked Handala Breached a California Water Utility. It Could Have Done Worse, and It Knows That. - Security Affairs

Strengthening cybersecurity cooperation between Iran and BRICS members - Pars Today

Cyberattack disrupts services at four Iranian banks, state media says | The Jerusalem Post

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Strengthening cybersecurity cooperation between Iran and BRICS members - Pars Today





Vulnerability Management

AI’s constant patching treadmill can be a security problem | CyberScoop

AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flaw | TechSpot

The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects - Help Net Security

Microsoft is making Windows 11 updates require just one reboot instead of several | TechSpot

Trump Memo Overhauls Cyber Rules for Classified Networks

Vulnerabilities

Microsoft Outlook and Word Vulnerability Allow Attackers to Execute Malicious Code

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

Critical Copilot vulnerability allowed hackers to steal 2FA code from users - Ars Technica

Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker Recovery, and More

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

Three critical Fortinet sandbox bugs splattered by unknown attackers

3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs - SecurityWeek

FortiBleed - 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack

ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

Oracle's Second Monthly Security Updates Deliver 245 Patches - SecurityWeek

Palo Alto PAN-OS Vulnerability Allow Attackers to Arbitrary Commands as a Root User

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558) - Help Net Security

Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities - SecurityWeek

Ivanti Sentry Exploitation Attempts Hitting Honeypots - SecurityWeek

CISA warns of another cPanel plugin flaw exploited in attacks

Joomla, LiteSpeed Vulnerabilities Exploited in Attacks - SecurityWeek

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer

Over 1 million WordPress sites at risk after popular plugin hacked — OptinMonster among those hit in CDN supply-chain attack | TechRadar


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 12 June 2026

Black Arrow Cyber Threat Intelligence Briefing 12 June 2026:

-AI Risk Worries Insurers and Businesses Alike

-UK Regulator Warns AI Cyber Risks Pose Top Banking Threat

-Your AI Agent Could Become Your Biggest Insider Threat

-This New AI-Powered Worm Spreads Itself and Adapts in Real Time — Here’s How to Stop It

-AI Is Helping Low-Skill Hackers Pull Off Advanced Cyberattacks

-84% of Organisations Hit by Digital Risk Incidents Last Year. Most Can't Detect an AI-Generated Attack.

-Frontline Workers Twice as Likely to Use Unapproved AI

-Hackers Getting an Easy Ride: Misconfigured Cloud Settings Behind Growing Number of Data Breaches

-Cyber Security Software Fails to Detect Fifth of Browser-Based Phishing Attacks

-How Cyber-Risk Can Fall Flat in the Boardroom

-Ukraine’s Experience Highlights the Need for Preparation and Resilience in Cyber Security

-NCSC Urges Organisations to Shore Up Supply Chain Security Practices

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Many organisations are exploring and using AI in different forms, from generative AI used by employees to agentic AI embedded within business processes. To help business leaders adopt these technologies safely, we have included a selection of insights from specialist and general media covering the cyber security risks associated with AI and approaches to managing them.

These consider concerns raised by regulators, insurers and cyber security specialists. Key observations include the importance of effective AI governance, and appropriate access controls, monitoring and accountability, particularly where AI agents have access to business systems and data. The articles also highlight the growing challenge of Shadow AI, where employees use unapproved AI tools without organisational oversight.

We also consider wider cyber security risks and the importance of board-level governance, which includes ensuring cyber risks are communicated in clear business terms and that boards have sufficient understanding of cyber security to provide effective oversight and challenge. Contact us to discuss how we support organisations of all sizes and sectors to achieve this in a proportionate manner.


Top Cyber Stories of the Last Week

AI Risk Worries Insurers and Businesses Alike

AI adoption is accelerating faster than many organisations can govern it, creating uncertainty for both businesses and insurers. Deloitte found that while 60% of workers have access to approved AI tools, and 74% of companies plan to deploy agentic AI, only 21% have mature AI governance in place. Some insurers are already excluding AI-caused damage from traditional policies, making it important for businesses to understand whether cyber insurance, technology errors and omissions, or other cover would respond to incidents involving AI-related data breaches, fraud, business disruption or operational errors.

https://www.darkreading.com/cyber-risk/ai-risk-worries-insurers-businesses-alike

UK Regulator Warns AI Cyber Risks Pose Top Banking Threat

The UK’s financial services regulator, PRA, has warned that AI-enabled cyber security threats are now among the most significant emerging risks facing UK banks. The concern is that increasingly capable AI tools could help hostile actors identify vulnerabilities in bank technology systems, increasing pressure on organisations to strengthen and accelerate cyber security activities. The regulator is urging banks to speed up software updates, identify higher-risk open-source components and give cyber security greater priority within technology programmes. The warning comes as geopolitical tensions increase and regulators themselves redirect resources towards technology and AI capability.

https://www.fstech.co.uk/fst/UK_Regulator_Warns_AI_Cyber_Risks_Pose_Top_Banking_Threat.php

Your AI Agent Could Become Your Biggest Insider Threat

New research from DTEX highlights how AI agents could create a growing insider risk as they become embedded into everyday business systems. Tests showed that simple prompts could prepare sensitive data for removal in as little as 10 to 30 minutes, using access to tools such as Outlook, Salesforce, SharePoint and OneDrive. The concern is not a software flaw, but weak governance, limited monitoring and excessive access. Without appropriate access controls, monitoring, prompt auditing and governance, organisations may struggle to determine how a data breach occurred or whether it resulted from employee error, malicious instructions or the actions of an AI agent.

https://cyberscoop.com/ai-agent-insider-threat-cybersecurity-dtex/

This New AI-Powered Worm Spreads Itself and Adapts in Real Time — Here’s How to Stop It

University of Toronto researchers have developed a proof-of-concept AI-powered worm that can spread across connected devices, assess targets and adapt its approach in real time. Unlike traditional malware, which typically follows fixed instructions, a worm can move between connected devices without user action. This research shows how publicly available AI tools could enable malware to analyse targets, select known weaknesses and continue spreading without human intervention. The study reinforces the importance of multi-factor authentication, secure passwords for connected devices, network segregation for smart devices where appropriate, and timely software updates to reduce the risk from emerging AI-enabled threats.

https://www.makeuseof.com/this-new-ai-powered-worm-spreads-itself-and-adapts-in-real-time-heres-how-to-stop-it/

AI Is Helping Low-Skill Hackers Pull Off Advanced Cyberattacks

Anthropic has reported rising misuse of AI in malicious cyber activity, after banning 832 accounts linked to harmful activity between March 2025 and March 2026. Its analysis found 13,873 attacker actions across all major stages of a cyber attack. Most usage involved preparation, such as developing malicious software, but AI was also used to support more advanced activity inside compromised networks. The findings suggest AI is enabling less sophisticated actors to perform activities that were previously limited to attackers with more advanced technical skills, with medium and high-risk actors rising from 33% to 56% during the study period.

https://www.helpnetsecurity.com/2026/06/05/anthropic-ai-cyber-activity-analysis/

84% of Organisations Hit by Digital Risk Incidents Last Year. Most Can't Detect an AI-Generated Attack.

A survey by Outtake reports that nearly seven in ten organisations described their digital risk capabilities as unaware, reactive or still developing, and 84% experienced significant digital risk incidents in the past year. The findings point to a growing business risk, with 53% citing manual remediation as the biggest cost, ahead of direct fraud losses. AI is adding further pressure, as 44% said AI-generated attacks are now indistinguishable from legitimate activity, while 96% lack automated controls to stop a compromised AI tool. Employee and executive impersonation also remain a major concern.

https://www.businesswire.com/news/home/20260604343787/en/84-of-Organizations-Hit-by-Digital-Risk-Incidents-Last-Year.-Most-Cant-Detect-an-AI-Generated-Attack.

Frontline Workers Twice as Likely to Use Unapproved AI

Mitel research has found a growing gap between AI adoption and employee support, increasing the risk of Shadow AI, where staff use unapproved tools without oversight. Its global survey of 2,000 IT decision-makers and workers found 52% regularly use AI, but only 33% feel very comfortable doing so and 66% say their organisation does not adequately support AI use. Half of workers use unapproved AI tools, highlighting the growing challenge of Shadow AI and creating concerns around data protection, compliance and misleading outputs. Frontline workers face the highest pressure, with 71% forced to work around poorly suited communication systems.

https://www.itsecurityguru.org/2026/06/04/frontline-workers-twice-as-likely-to-use-unapproved-ai/

Hackers Getting an Easy Ride: Misconfigured Cloud Settings Behind Growing Number of Data Breaches

The Dutch National Cyber Security Centre has warned that poorly configured cloud systems are contributing to a growing number of data breaches. Recent incidents show that attackers are often gaining access not by exploiting technical flaws, but by finding cloud environments where permissions or access settings have been left too open. Criminal groups are using automated tools to scan for these mistakes at scale, making weak cloud configuration a business risk as well as a technical issue. Organisations should maintain clear oversight of cloud platforms, access rights and administrator accounts, while using multi-factor authentication to reduce exposure.

https://cybernews.com/security/hackers-misconfigured-cloud-settings-data-breach/

Cyber Security Software Fails to Detect Fifth of Browser-Based Phishing Attacks

Menlo Security has warned that browser-based phishing is bypassing many traditional cyber security tools, with one in five phishing attacks targeting enterprise browser users going undetected. Based on millions of browser sessions between January and March 2026, the research highlights how work now routinely happens through browsers, including email, cloud applications, AI assistants and financial systems. Attackers are exploiting this shift by using fake verification prompts, error messages and other social engineering tactics to trick users into taking actions that appear legitimate, helping them avoid detection by security tools that were not designed to operate at the browser session layer.

https://www.infosecurity-magazine.com/news/cybersecurity-fails-to-detect/

How Cyber-Risk Can Fall Flat in the Boardroom

Cyber risk is a growing board-level business issue, beyond a technology concern. Verizon’s 2025 research reviewed 22,000 security incidents and found ransomware in 44% of breaches, third-party involvement in 30% and vulnerability exploitation as an initial access method increasing by 34% year on year. Board engagement is increasing, although fewer than a third of boards include a member with cyber security expertise. Leaders need clear reporting that links cyber risks to financial loss, operational disruption, regulation and customer impact. The findings also raise questions about whether boards have sufficient cyber security expertise to oversee these risks effectively.

https://www.informationweek.com/risk-management/how-cyber-risk-can-fall-flat-in-the-boardroom

Ukraine’s Experience Highlights the Need for Preparation and Resilience in Cyber Security

Ukraine’s wartime experience shows why cyber security preparation and resilience matter for organisations of every size. Former Ukrainian foreign minister Dmytro Kuleba highlighted how planning helped government teams react quickly when invasion disrupted normal operations, including moving servers abroad. The lesson for leaders is that resilience depends on preparation, understanding technology dependencies and the ability to keep operating when disruption becomes sustained rather than temporary.

https://www.infosecurity-magazine.com/news/resilience-perseverance-ukraine/

NCSC Urges Organisations to Shore Up Supply Chain Security Practices

The UK’s NCSC has warned that software supply chain attacks are increasing, with criminals targeting software packages and development ecosystems to spread malicious code. Many modern applications rely on large numbers of third-party components, often updated automatically through software delivery processes with limited human review. This means one compromised package can quickly affect many organisations. Recommended actions include reviewing software dependencies, managing automatic updates, using multi-factor authentication for developer accounts and securing credentials.

https://www.itpro.com/security/ncsc-urges-organizations-to-shore-up-supply-chain-security-practices



Threats

Ransomware, Extortion and Destructive Attacks

Extortion-Only Attacks Increase, With Data Theft Dominating Ransomware - Infosecurity Magazine

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

Silent Ransom Group (SRG): Switching To DNS Fast Flux Infrastructure - Security Affairs

New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords

Why schools remain one of cybercriminals' favourite targets

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

If you don't fall for these extortionists' calls, they'll show up with USB sticks

Silent Ransom Group Hits US Law Firms in Escalating Attacks

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks - SecurityWeek

Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline - Europol analysis links the criminal service to over 15 international cybercrime investigations | Europol

Ransomware and Destructive Attack Victims

Silent Ransom Group targets law firms with fake IT support calls

Nottingham University data breach affects over 450,000 students

Thousands of Essex NHS patient records stolen in cyber attack - BBC News

Qilin NHS breach tally grows as Essex trust confirms stolen records

Cyber attack closes Great Marlow School in Buckinghamshire - BBC News

Qilin claims hack of NY/NJ Shipping Association | Cybernews

Phishing & Email Based Attacks

Security Software Fails to Detect Fifth of Brower Phishing Attacks - Infosecurity Magazine

OpenClaw AI agent found falling for phishing attacks, spills user data

Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials - Help Net Security

Hackers used Google Cloud links and fake New York Times pages to power a massive global phishing machine | TechRadar

Interpol Dismantles SniperDz Phishing-as-a-Service Platform - Infosecurity Magazine

Other Social Engineering

Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials

Silent Ransom Group targets law firms with fake IT support calls

Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5

Remote Worker Fraud: A Growing Risk for Employers and Government Contractors | Ice Miller - JDSupra

Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes

Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup - Help Net Security

Suspected Norks send 250+ fake dev job pitches to steal crypto

Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victims | IT Pro

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

British teenager sanctioned by Russia over his report on alleged Moscow-backed crypto laundering | Euronews

Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline - Europol analysis links the criminal service to over 15 international cybercrime investigations | Europol

Artificial Intelligence

AI is helping low-skill hackers pull off advanced cyberattacks - Help Net Security

AI Risk Worries Insurers and Businesses Alike

Frontline Workers Twice as Likely to Use Unapproved AI - IT Security Guru

Your AI agent could become your biggest insider threat | CyberScoop

Adaptive, Agentic AI Worms Loom as Next Enterprise Threat

This new AI-powered worm spreads itself and adapts in real time — here's how to stop it

UK regulator warns AI cyber risks pose top banking threat - FStech

84% of Organizations Hit by Digital Risk Incidents Last Year. Most Can't Detect an AI-Generated Attack.

Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation - SecurityWeek

Infosecurity Europe 2026: AI turbo-charging cyber crime and response | Computer Weekly

Every set of AI guardrails can be broken by the right prompt - Help Net Security

Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials

Patching Is No Match for Frontier AI, Cyber Expert Warns

Can we trust the systems we now rely on? - University of Birmingham

Everybody Is Vibe Coding But Nobody Told the Security Team - SecurityWeek

4 Critical Threats Where Attackers Have the Advantage

Meet Hades: The malware that lies to AI security agents | CSO Online

Treat your AI agents like eager but misguided human interns - before you lose control | ZDNET

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

OpenClaw AI agent found falling for phishing attacks, spills user data

Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

OpenAI Rolls Out Lockdown Mode to Fight Prompt Injection Attacks

AI Coding Tools Need Built-In Security for Agentic Development Era - Infosecurity Magazine

Information Warfare: Americans And Chinese Both Fear AI

Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse - SecurityWeek

Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow - SecurityWeek

Beware the ‘son of Mythos,’ security experts warn | CSO Online

New AI Executive Order Calls for Frontier Model Security, Early Government Access and AI-Enabled Cyber Defense | Skadden, Arps, Slate, Meagher & Flom LLP - JDSupra

AI Coding Adoption Hits 97% but Governance Lags Behind - Infosecurity Magazine

Nearly every security chief fears AI-generated code as development teams race ahead of outdated oversight systems | TechRadar

Trump Issues Executive Order Seeking to Promote Collaboration with AI Developers to Combat Emerging Cyber Threats | Morrison & Foerster LLP - JDSupra

Ex-CISA CIO Breaks Down Trump's New AI Executive Order

9 out of 10 people can no longer distinguish real from AI-generated content - Help Net Security

Bots/Botnets

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Security experts sound alarm over 'expanded' China-linked botnet used to target US critical infrastructure and military assets | IT Pro

Careers, Roles, Skills, Working in Cyber and Information Security

Most Security Teams Struggle to Find Time for Training on New Threats - Infosecurity Magazine

Cloud/SaaS

Warning: Cloud misconfigurations fuel more data breaches | Cybernews

Threat actors are recruiting the people who hold cloud logins - Help Net Security

Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials - Help Net Security

New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords

Hackers used Google Cloud links and fake New York Times pages to power a massive global phishing machine | TechRadar

Why Microsoft 365 Baseline Security Mode Isn't a Flip Switch

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War | TechRadar

New SilabRAT Trojan Hijacks Sessions to Steal Crypto - Infosecurity Magazine

British teenager sanctioned by Russia over his report on alleged Moscow-backed crypto laundering | Euronews

Suspected Norks send 250+ fake dev job pitches to steal crypto

Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline - Europol analysis links the criminal service to over 15 international cybercrime investigations | Europol

Cyber Crime, Organised Crime & Criminal Actors

Scams now operate like real businesses with budgets and targets - Help Net Security

The prosecution gap: Why cybercrimes go unpunished | TechTarget

The assembly line behind 1.5 million malicious domains - Help Net Security

Cybercriminals: the 'auditors' you never hired

Data Breaches/Leaks

Former cyber executive turned whistleblower accuses IBM of covering up several data breaches | TechCrunch

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica

Oxford University data pwned again by career platform breach

Nottingham University data breach affects over 450,000 students

France's sovereign messenger Tchap hit by account breach

ServiceNow reveals security issue affecting customer data, but won't reveal much on what actually happened | TechRadar

OnlyFans mega leak reveals 340M user records, hackers claim | Cybernews

Japanese energy firm loses drive with data of 10.9 million clients

4.9 million Wise user records allegedly leaked online | Cybernews

OpenClaw AI agent found falling for phishing attacks, spills user data

Council in UK's City of York outs hundreds of disabled residents with a single email blunder

World Food Programme breach exposes data of 600k vulnerable Gazan families

Debt administrators exposed debt owner client data | Cybernews

174,000 Impacted by Lansing Community College Data Breach - SecurityWeek

Hackers claim Ralph Lauren data breach with 220GB allegedly stolen | Cybernews

Data Protection

CISO's guide to data minimization | TechTarget

Data/Digital Sovereignty

European Union Outlines Plan to Reduce Dependence on American Tech - The New York Times

France's sovereign messenger Tchap hit by account breach

Over 73,000 French govt employees affected in Tchap messenger breach

PYMNTS | EU Procurement Standards Show Vendor Lock-In Is B2B Liability

Denial of Service/DoS/DDoS

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Encryption

Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica

Windows BitLocker 0-Day Vulnerability Allow Attackers to Bypass Security Feature

Outlook may have allowed unencrypted connections for decades, report claims — Fedora and Dovecot upgrade reveal protocol downgrade issue present since at least 2007 | Tom's Hardware

Fraud, Scams and Financial Crime

Scams now operate like real businesses with budgets and targets - Help Net Security

The assembly line behind 1.5 million malicious domains - Help Net Security

Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War | TechRadar

Remote Worker Fraud: A Growing Risk for Employers and Government Contractors | Ice Miller - JDSupra

Identity theft is turning into a chain reaction for victims - Help Net Security

9 out of 10 people can no longer distinguish real from AI-generated content - Help Net Security

Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup - Help Net Security

Bitdefender Releases 2026 Global Scam Intelligence Report

Insider Risk and Insider Threats

Frontline Workers Twice as Likely to Use Unapproved AI - IT Security Guru

Your AI agent could become your biggest insider threat | CyberScoop

Insurance

AI Risk Worries Insurers and Businesses Alike

Extortion-Only Attacks Increase, With Data Theft Dominating Ransomware - Infosecurity Magazine

Internet of Things – IoT

Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI

New privacy frontier: Europe eyes crackdown on smart glasses – POLITICO

Law Enforcement Action and Take Downs

Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline - Europol analysis links the criminal service to over 15 international cybercrime investigations | Europol

The prosecution gap: Why cybercrimes go unpunished | TechTarget

Interpol Dismantles SniperDz Phishing-as-a-Service Platform - Infosecurity Magazine

Russian national charged in connection with Void Blizzard espionage campaign | CyberScoop

Dark web Nemesis Market vendor gets 26 years for selling drugs

Linux and Open Source

Two-Thirds of Open Source Community Unaware of Cyber Resilience Act - Infosecurity Magazine

High-severity vulnerability in Linux caused by a single faulty character - Ars Technica

Malware

Adaptive, Agentic AI Worms Loom as Next Enterprise Threat

Researchers build autonomous AI worm that can reason and adapt | TechTarget

Infostealers Turn Millions of Devices Into Credential Theft Machines - SecurityWeek

New SilabRAT Trojan Hijacks Sessions to Steal Crypto - Infosecurity Magazine

Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes

AI Adoption Creates New Opportunities for Attackers - Infosecurity Magazine

Meet Hades: The malware that lies to AI security agents | CSO Online

Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...

GitHub disables Microsoft repos pushing password-stealing malware

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeek

Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories

Ghost CMS Under Siege: How a SQL Injection Turned 700+ Blogs Into Malware Distribution Networks - Security Boulevard

Fake Software Tutorials on TikTok Spread Vidar Stealer - Infosecurity Magazine

OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month - SecurityWeek

Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials

Chinese APT deploys new malware to keep access to hacked networks

Misinformation, Disinformation and Propaganda

Information Warfare: Americans And Chinese Both Fear AI

Mobile

Organizations can't see much of their mobile AI activity - Help Net Security

WhatsApp says it disrupted new NSO spyware phishing attacks

The security in smartphones is helping send them to landfills - Help Net Security

Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps

Models, Frameworks and Standards

Two-Thirds of Open Source Community Unaware of Cyber Resilience Act - Infosecurity Magazine

EU to take France, Spain to court over cyber law delay – POLITICO

Passwords, Credential Stuffing & Brute Force Attacks

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials - Help Net Security

New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords

Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica

Suspected Norks send 250+ fake dev job pitches to steal crypto

The safest password is the one you never type

The NCSC Wants You To Adopt Passkeys: Is It Time To Finally Drop Passwords? | SC Media UK

Regulations, Fines and Legislation

UK regulator warns AI cyber risks pose top banking threat - FStech

EU to take France, Spain to court over cyber law delay – POLITICO

European Union Outlines Plan to Reduce Dependence on American Tech - The New York Times

UK move to filter photos and messages triggers encryption worries for CISOs – Computerworld

Signal attacks UK plan to scan devices for nude images as "mass surveillance" | TechSpot

The Great American Artificial Intelligence Act Would Reshape AI Regulation, Cybersecurity Compliance, and Developer Oversight - ClearanceJobs

New AI Executive Order Calls for Frontier Model Security, Early Government Access and AI-Enabled Cyber Defense | Skadden, Arps, Slate, Meagher & Flom LLP - JDSupra

The AI security race needs accountability, not overregulation | CyberScoop

EU plans one data breach form for all members| Cybernews

Ex-CISA CIO Breaks Down Trump's New AI Executive Order

Cyber Security (Jersey) Law: An overview | Walkers - JDSupra

New privacy frontier: Europe eyes crackdown on smart glasses – POLITICO

Shadow IT

Frontline Workers Twice as Likely to Use Unapproved AI - IT Security Guru

Your AI agent could become your biggest insider threat | CyberScoop

What 2026 DBIR Confirms: Attacks Are Living in the Browser

Social Media

NEW: Violent Threats Against Members of Congress Quadrupled After Meta Rolled Back Moderation Policies — Center for Countering Digital Hate | CCDH

Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse - SecurityWeek

Software Supply Chain

GitHub disables Microsoft repos pushing password-stealing malware

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeek

Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Supply Chain Attacks Target Open‑Source Packages

Beware software dependencies - NCSC | UKAuthority

Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...

4 Critical Threats Where Attackers Have the Advantage

The security questions around Chinese AI coding models in U.S. software - Help Net Security

Supply Chain and Third Parties

Former cyber executive turned whistleblower accuses IBM of covering up several data breaches | TechCrunch

NCSC urges organizations to shore up supply chain security practices | IT Pro

Key strategies to benchmark your MSSP: Advice from top security providers | news | MSSP Alert


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

An Invisible Battlefield: Cyberwar Is Reshaping Everyday Life

Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War | TechRadar

Iran Signed a Ceasefire — Its Hackers Didn't

Europe Is Preparing for a Cyber War Ukraine Has Already Survived | The Gaze

Rearming Europe for deterrence: Short-term priorities and policy options | Centre for European Reform

Iranian group could be labelled national threat under proposed new law - BBC News

UK cracks down on Iran, Russia, North Korea, China cyber ops | Cybernews

Russian national charged in connection with Void Blizzard espionage campaign | CyberScoop

Finland: 4 suspects in sabotage of undersea Estonia cables

Finland deploys new system to detect threats to undersea cables — distributed acoustic sensors measure vibrations from the seabed and informs the authorities and operators of suspicious activities | Tom's Hardware

NATO's Cyber Approach Needs Change | Lawfare

Ukraine’s foreign minister offer recipe for improved resilience | CSO Online

Tests suggest Russian satellites can jam GPS on a continental scale - Ars Technica

Information Warfare: Americans And Chinese Both Fear AI

Europe is building resilience – but not the kind it needs for war - Friends of Europe

Ukraine’s Experience Highlights the Need for Preparation in Cyber - Infosecurity Magazine

Nation State Actors

UK cracks down on Iran, Russia, North Korea, China cyber ops | Cybernews

China

Former IBM cybersecurity exec accuses company of hiding Chinese hacking breaches

Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5

The security questions around Chinese AI coding models in U.S. software - Help Net Security

Chinese APT deploys new malware to keep access to hacked networks

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Security experts sound alarm over 'expanded' China-linked botnet used to target US critical infrastructure and military assets | IT Pro

Information Warfare: Americans And Chinese Both Fear AI

Russia

Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War | TechRadar

Russian national charged in connection with Void Blizzard espionage campaign | CyberScoop

Ukraine: Europe's Only Wartime Cyber Defence Laboratory | The Gaze

Ukraine’s foreign minister offer recipe for improved resilience | CSO Online

Tests suggest Russian satellites can jam GPS on a continental scale - Ars Technica

British teenager sanctioned by Russia over his report on alleged Moscow-backed crypto laundering | Euronews

How the FSB cut Russia off from the internet

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open | Trend Micro (US)

German agencies warn of Russian cyber threats to weak PV systems | Solar Power News | Renewables Now

North Korea

Remote Worker Fraud: A Growing Risk for Employers and Government Contractors | Ice Miller - JDSupra

Suspected Norks send 250+ fake dev job pitches to steal crypto

Iran

Iran Signed a Ceasefire — Its Hackers Didn't

Iranian group could be labelled national threat under proposed new law - BBC News


Tools and Controls

AI Risk Worries Insurers and Businesses Alike

Why most enterprise security teams would fail a military readiness test | CSO Online

Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation - SecurityWeek

Security Software Fails to Detect Fifth of Brower Phishing Attacks - Infosecurity Magazine

Patching Is No Match for Frontier AI, Cyber Expert Warns

Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch

Why patching velocity matters as Claude Mythos supercharges vulnerability discovery | IT Pro

The security questions around Chinese AI coding models in U.S. software - Help Net Security

Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica

Organizations can't see much of their mobile AI activity - Help Net Security

Malware ships with bugs that defenders could use against it - Help Net Security

Most Security Teams Struggle to Find Time for Training on New Threats - Infosecurity Magazine

Most pros have seen AI hallucinations in IT operations - Help Net Security

Everybody Is Vibe Coding But Nobody Told the Security Team - SecurityWeek

AI Coding Tools Need Built-In Security for Agentic Development Era - Infosecurity Magazine

Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away | CyberScoop

52% of direct-to-IP threats are missing from intelligence feeds - Help Net Security

Inside the race to adapt to an AI-powered security world | CyberScoop

Beware the ‘son of Mythos,’ security experts warn | CSO Online

AI Coding Adoption Hits 97% but Governance Lags Behind - Infosecurity Magazine

Nearly every security chief fears AI-generated code as development teams race ahead of outdated oversight systems | TechRadar

Alert Fatigue Is Becoming a Security Threat of Its Own - SecurityWeek

The AI security race needs accountability, not overregulation | CyberScoop

Why Microsoft 365 Baseline Security Mode Isn't a Flip Switch

Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It

Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver




Vulnerability Management

Two-Thirds of Open Source Community Unaware of Cyber Resilience Act - Infosecurity Magazine

75% of Firms Deploy Vulnerable Code Amid Pressure on CISOs - Infosecurity Magazine

Patching Is No Match for Frontier AI, Cyber Expert Warns

Why patching velocity matters as Claude Mythos supercharges vulnerability discovery | IT Pro

Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook

CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says | The Record from Recorded Future News

CISA tells govt agencies to patch critical exploited flaws in 3 days

Vulnerabilities

Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws

Windows BitLocker 0-Day Vulnerability Allow Attackers to Bypass Security Feature

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

Microsoft patches Exchange Server zero-day exploited in attacks

Nightmare Eclipse drops claimed BitLocker bypass for Microsoft Windows

Exchange Flaw Lets Attackers Spoof Any Email Address

Attackers had month-long head start on patched Check Point VPN zero-day

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks - SecurityWeek

Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

Cisco customers encounter another SD-WAN zero-day under attack | CyberScoop

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Fortinet patched a new critical FortiSandbox flaw

Adobe Patches 123 Vulnerabilities - SecurityWeek

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Max-Severity Ivanti Sentry Flaw Exploited Within 24 Hours

21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks

Path traversal flaw in AI dev platform Langflow exploited in attacks

High-severity vulnerability in Linux caused by a single faulty character - Ars Technica

LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) - Help Net Security

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

OpenSSL Patches High-Severity Vulnerability Found With AI - SecurityWeek

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters - SecurityWeek

SAP Patches Critical NetWeaver, Commerce Vulnerabilities - SecurityWeek

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances

U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog

Splunk, Palo Alto Networks Patch Severe Vulnerabilities - SecurityWeek

Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script

UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers - SecurityWeek

Gogs patches critical zero-day enabling remote code execution

Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open | Trend Micro (US)

Critical Everest Forms Pro flaw exploited to take over WordPress sites


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3

Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.


Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 05 June 2026

Black Arrow Cyber Threat Intelligence Briefing 05 June 2026:

-Why Your Board Is Still Not Ready for Cyber Risk - And What Actually Needs To Change

-Execs Must Treat Cyber Threats as Statecraft, ISACA Expert Says

-UK Firms Prioritise AI Threat Preparedness as Cyber Risks Evolve

-Nation State Attacks: The Risk to UK Firms

-The Gentlemen Are Coming for Your Files, and Then Your Network

-Ransomware Groups Grow Revenue by Almost 40% in Q1 2026

-'The Com' Cyberattacks Support Violence & Sexploitation

-What Is Configuration Drift - And Why It’s Your Biggest M365 Security Risk

-Supply Chain Risk Is Now a Cyber Resilience Problem

-82% of IT Pros Report a Web-Based Security Incident in Past Year – BYOD, SaaS Tools, and Remote Work Policies All Play a Part in Security Resilience

-M&S Chief’s Pay Slashed by £3M After Cyberattack Turmoil

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

This week’s review of cyber security in the specialist and general media highlights how business leaders can better understand and manage cyber risks, with insights into actions that boards can take to improve security and resilience.

AI remains a prominent theme, continuing a trend we have observed over recent months. Alongside this, we see cyber risks becoming more complex, spanning geopolitical threats, the evolution of ransomware, and security weaknesses that can emerge through routine business and technology changes. We also highlight the recently announced impact of last year’s M&S cyber attack on executive remuneration, illustrating how the consequences of a cyber incident can extend well beyond the initial disruption.

Our advice for business leaders remains consistent: focus on cyber security to reduce the likelihood of an incident, and on cyber resilience to withstand and recover from one. This requires boards to understand cyber risks in business terms, govern them through proportionate controls, and rehearse the leadership response before an incident occurs. Contact us to discuss how these themes can be addressed in your leadership meetings.

Top Cyber Stories of the Last Week

Why Your Board Is Still Not Ready for Cyber Risk - And What Actually Needs To Change

Cyber incidents have ranked as the top global risk for the fifth year running, according to the Allianz Commercial Risk Barometer, yet many boards still overestimate their organisation’s readiness. A key challenge is proving the return on cyber security investment, particularly where risks involve reputation, customer trust and business disruption. Stronger cyber resilience can reduce downtime, support customer retention and strengthen competitive positioning. Boards should treat cyber risk as a core business issue, with clear ownership, measurable reporting, independent assurance and consideration in strategy, mergers and acquisitions.

https://www.forbes.com/councils/forbestechcouncil/2026/06/02/why-your-board-is-still-not-ready-for-cyber-risk-and-what-actually-needs-to-change/

Execs Must Treat Cyber Threats as Statecraft, ISACA Expert Says

Information Security professional body ISACA has warned that cyber security risk can no longer be treated as a purely technical issue, as cyber, artificial intelligence and geopolitics are now increasingly connected. High profile attacks against commercial organisations have shown that private companies can become targets for state linked groups, sometimes for political rather than financial reasons. Emerging risks include covert foreign IT worker schemes, which can create trusted insider access. Boards should understand where they are exposed, test their crisis response, strengthen HR and supplier checks, and rehearse longer running scenarios involving nation state threats.

https://www.infosecurity-magazine.com/news/execs-cisos-must-treat-cyber/

UK Firms Prioritise AI Threat Preparedness as Cyber Risks Evolve

ManageEngine reports that AI-powered attacks are now the top concern for UK organisations, cited by 43% of respondents, with 41% prioritising investment in AI and advanced threat preparedness. More than three quarters of UK businesses experienced a cyber incident in the past year, above the European average, while 46% pointed to skills shortages as their main operational challenge. Although 94% of incidents are detected within 24 hours, recovery remains slower, with over a quarter taking more than 10 days, highlighting the need to strengthen resilience as threats become more complex.

https://www.infosecurity-magazine.com/news/uk-firms-prioritize-ai-threat/

Nation State Attacks: The Risk to UK Firms

The UK’s National Cyber Security Centre has warned that nation states, particularly China, Iran and Russia, are now behind most significant cyber incidents affecting the UK. These attacks are often focused on disruption, espionage or gaining long-term access, rather than financial gain, meaning ransom payments are unlikely to resolve the issue. Critical sectors such as finance, healthcare, technology, telecoms, energy, water and defence face heightened risk, as do suppliers that provide access to larger organisations. Strong basic controls, regular recovery testing and clear oversight remain essential as geopolitical tensions continue to shape cyber activity.

https://insight.scmagazineuk.com/nation-state-attacks-the-risk-to-uk-firms

The Gentlemen Are Coming for Your Files, and Then Your Network

Microsoft has warned that ransomware called ‘Gentlemen’, developed by a group with the same name, is actively targeting organisations across education, transport, healthcare and financial services worldwide. First seen in mid 2025 and still active in 2026, the ransomware can spread from one compromised machine to others across a network before encrypting files. This means a single breach can quickly become a wider business disruption. ‘Gentlemen’ now operates as ransomware-as-a-service, where criminal affiliates can pay to use the software to carry out attacks. Early detection of unusual access, stolen password use and remote system activity is critical to limiting impact.

https://www.csoonline.com/article/4178580/the-gentlemen-are-coming-for-your-files-and-then-your-network.html

Ransomware Groups Grow Revenue by Almost 40% in Q1 2026

Rapid7 has reported that ransomware revenue rose by almost 40% year on year in the first quarter of 2026, reaching an estimated $529.2 million. The growth reflects a more mature criminal market, where ransomware groups can buy ready-made access to organisations through dark web brokers rather than breaking in themselves. Leading groups generated significant revenue, with Qilin estimated at $193 million and Gentlemen at $52 million between July 2025 and March 2026. The findings show how resilient and commercialised cyber crime operations have become.

https://www.techradar.com/pro/security/ransomware-groups-grow-revenue-by-almost-40-percent-in-q1-2026

'The Com' Cyberattacks Support Violence & Sexploitation

Researchers report that ‘The Com’, a loose criminal network linked to groups such as Scattered Spider, combines cyber crime with wider criminal activity, blurring the boundaries between its hacking groups and other criminal networks. The group is largely North American, often young, and recruits through gaming and social media communities. Its activity shows how weak cloud security can create harm beyond the breached organisation, with stolen access and extortion funding further criminal operations. Recent activity may have quietened, but researchers warn the group remains active and continues to evolve its tactics.

https://www.darkreading.com/threat-intelligence/the-com-cyberattacks-violence-sexploitation

What Is Configuration Drift - And Why It’s Your Biggest M365 Security Risk

Configuration drift is a growing Microsoft 365 security risk, particularly for managed service providers overseeing many client environments. It occurs when security settings gradually move away from an agreed baseline through routine changes, such as temporary access exceptions, relaxed sharing controls or admin permissions that are not later removed. These changes can weaken defences without triggering obvious alerts. Continuous monitoring and automated remediation can help identify and correct drift quickly, reducing the risk of incidents and supporting stronger governance across multiple Microsoft 365 tenants.

https://www.msspalert.com/native/what-is-configuration-drift-and-why-its-your-biggest-m365-security-risk

Supply Chain Risk Is Now a Cyber Resilience Problem

AI demand is putting pressure on the supply of DRAM and NAND, the memory and storage components that underpin backup and recovery infrastructure. As availability tightens and costs rise, cyber resilience strategies that rely on continually adding more hardware may become harder to sustain. More efficient architectures, which reduce the amount of data stored, moved and managed, can lower dependency on scarce components, reduce the number of systems needing protection, and support faster recovery. This makes infrastructure efficiency not just a cost issue, but a strategic cyber security consideration.

https://www.dell.com/en-us/blog/supply-chain-risk-is-now-a-cyber-resilience-problem/

82% of IT Pros Report a Web-Based Security Incident in Past Year – BYOD, SaaS Tools, and Remote Work Policies All Play a Part in Security Resilience

NordLayer reports a clear gap between confidence and reality in web-based security. While 73% of organisations believe they are prepared for attacks through browsers and web applications, 82% experienced an incident in the past year. The risk is growing as businesses rely more heavily on online software, remote working and personal devices. Malware designed to steal login details harvested 1.8 million credentials and 68.8 billion cookies last year, giving attackers a way to access systems by appearing to log in legitimately rather than forcing their way in.

https://www.techradar.com/pro/security/82-percent-of-it-pros-report-a-web-based-security-incident-in-past-year-byod-saas-tools-and-remote-work-policies-all-play-a-part-in-security-resilience

M&S Chief’s Pay Slashed by £3M After Cyberattack Turmoil

The chief executive of UK retailer Marks & Spencer saw his pay fall by more than 40% after a major cyber attack disrupted the retailer’s operations and M&S cancelled its executive bonus scheme. The attack halted online services for weeks, affected card payments in some stores, and contributed to weaker financial performance, resulting in lower bonus and share-based awards for executives. M&S put the total cost at £133.3 million, although more than £100 million has been recovered through insurance.

https://www.cityam.com/ms-pay-slashed-after-cyberattack-turmoil/



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware groups grow revenue by almost 40% in Q1 2026 | TechRadar

'The Com' Cyberattacks Support Violence & Sexploitation

Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chief | IT Pro

The Gentlemen are coming for your files, and then your network | CSO Online

The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks

Pink is the latest goon squad to use fake helpdesk calls to steal creds

'Dumbass' criminal breaks the 'first rule of ransomware club'

Ransomware and Destructive Attack Victims

Inside the Charter data breach: hackers leak 13M+ customer data | Cybernews

Charter Communications data breach affects 4.9 million accounts

M&S chief's pay slashed by £3m after cyberattack turmoil

IKEA faces data leak threat after hackers claim theft of internal code | Cybernews

Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers

Phishing & Email Based Attacks

Attackers Abuse Shared Content for ChatGPT Phishing Campaign - Infosecurity Magazine

Infostealers are becoming the go-to phishing payload | Malwarebytes

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

ChatGPT prompt injection turns web pages into phishing lures

BTMOB Android malware service generates custom phishing payloads

Threat Actors Deploy Tiflux RMM For Persistent Remote Access

LinkedIn-themed phishing abuses Adobe's A/B testing platform - Help Net Security

There’s a new phishing scam: fake invitations | The Seattle Times

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

Europe's hotel data breach hits 100+ properties | Cybernews

Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek

China's TA4922 Expands Cybercrime Attacks Globally

Signal users targeted in backup-stealing phishing attacks | Malwarebytes

Social Security numbers exposed in Rich Products cyberattack | Cybernews

Other Social Engineering

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

Pink is the latest goon squad to use fake helpdesk calls to steal creds

There’s a new phishing scam: fake invitations | The Seattle Times

Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek

Cyber espionage campaign targeted stock exchange executive’s Outlook account

As the 2026 World Cup Looms, a Shadow Tournament of Cyber Fraud Begins | OCCRP

FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Five Eyes: China expanding state secret recruitment campaign

Why a surge of election-related websites could spell rising cyber threats for the midterms | PBS News

5K+ election domains registered ahead of US midterms

2FA/MFA

Microsoft fixes outage affecting MFA setup, MySignIn service

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say - SecurityWeek

Artificial Intelligence

Attackers Abuse ChatGPT Share Links to Host Fake Outage Pages That Deliver Malware - gHacks Tech News

Attackers Abuse Shared Content for ChatGPT Phishing Campaign - Infosecurity Magazine

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

UK Firms Prioritize AI Threat Preparedness as Cyber Risks Evolve - Infosecurity Magazine

145 AI laws passed in 2025 and privacy teams aren't catching a break - Help Net Security

Only 11% of production agents pass the AI agent security bar - Help Net Security

Security of 100 AI Agents Tested and Ranked – What You Need to Know - SecurityWeek

The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks

Instagram Accounts Hijacked by Tricking Meta AI Support Into Verifying Attackers as Owners - gHacks Tech News

Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar

Cybersecurity threats from new language models | Max-Planck-Gesellschaft

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web - Infosecurity Magazine

Free AI model powers self-spreading worm in enterprise test network

Commvault says it's time to rethink resiliency as AI crooks leave victims in a 'dark, dead' state

Hugging Face security analysis: ~70,000 live secrets and API keys, private repos, and leaky pics!

UK banks still lack access to Mythos AI model, BoE's Bailey says - CNA

ICO publishes blog on AI-powered cyber threats | A&O Shearman - JDSupra

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

Cyber threats are becoming 'high level' with AI

President Trump Signs AI Executive Order After Delaying It Over China Concerns - Decrypt

Bots/Botnets

Botnet of 17 Million Devices Dismantled in the Netherlands

Huge Botnet Linked To Russia Infected Over 10 Million Devices Before Being Shut Down

Careers, Roles, Skills, Working in Cyber and Information Security

6 critical security gaps every CISO must address | CSO Online

CISO burnout: How to prevent contagion across the team | Computer Weekly

Cloud/SaaS

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

19.6 Billion Files Are Sitting Open on the Internet. No Password Required

FSB Group Gamaredon Hides Worm in Windows Data Streams - Infosecurity Magazine

Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2

What is configuration drift — And why it’s your biggest M365 security risk | native | MSSP Alert

82% of IT pros report a web-based security incident in past year – BYOD, SaaS tools, and remote work policies all play a part in security resilience | TechRadar

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

Cyber Crime, Organised Crime & Criminal Actors

'The Com' Cyberattacks Support Violence & Sexploitation

Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek

China's TA4922 Expands Cybercrime Attacks Globally

Dutch Raid Fails to Dent Russian Bulletproof Host

Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown - SecurityWeek

Data Breaches/Leaks

19.6 Billion Files Are Sitting Open on the Internet. No Password Required

Hugging Face security analysis: ~70,000 live secrets and API keys, private repos, and leaky pics!

Your OnlyFans may not be private – and neither are your passwords | Cybernews

The worst hacks and breaches of 2026 (so far) | TechCrunch

Europe's hotel data breach hits 100+ properties | Cybernews

Troops’ phones leaked location data to foreign adversaries

Man sent to prison for selling data of 7 millions elderly Americans

23andMe Failed to Stop Months-Long Hack, State Alleges

California AG sues 23andMe over 2023 breach exposing health data

A Fake UK Visa Site Left 100,000 Passports Wide Open. Then Sent Lawyers Instead of a Fix.

Social Security numbers exposed in Rich Products cyberattack | Cybernews

Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers

Scots affected by Capita cyber attack given route to compensation | Scottish Legal News

Spain arrests doxer leaking sensitive data of govt employees

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

Ultrahuman says recent hack didn't affect passwords or credit cards

GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying

64,000 accounts exposed in breach of GTA V cheat service Atlas Menu - Help Net Security

Hackers just stole health data from Ultrahuman users, and I’m ditching my smart ring because of it

Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals - SecurityWeek

Data Protection

ICO publishes blog on AI-powered cyber threats | A&O Shearman - JDSupra

Data/Digital Sovereignty

Vivre la Linux: Behind France’s bold open source move into digital sovereignty

Denial of Service/DoS/DDoS

Why Your Rate Limits Fail Under Distributed DDoS Attacks - Security Boulevard

New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute

Encryption

Let's Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats

Fraud, Scams and Financial Crime

Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar

As the 2026 World Cup Looms, a Shadow Tournament of Cyber Fraud Begins | OCCRP

FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Meta tries to get ahead of scammers before the World Cup begins - Help Net Security

Insurance

Cyber Insurance Rates Are Dropping, but Exclusions Widen

Internet of Things – IoT

Are our cars spying on us? A cybersecurity expert explains how to stay safe

Hacking your car’s dash cam in real time, remotely: tips, tricks, and lazy manufacturers.

How To Reduce Cyber Risks Across Connected Devices And Services

Thieves can pull off keyless car theft in under a minute and here's how to stop them - Help Net Security

Ring has been collecting visitor's facial biometrics without consent, class action lawsuit alleges | TechRadar

Law Enforcement Action and Take Downs

Botnet of 17 Million Devices Dismantled in the Netherlands

Huge Botnet Linked To Russia Infected Over 10 Million Devices Before Being Shut Down

Man sent to prison for selling data of 7 millions elderly Americans

Dutch Raid Fails to Dent Russian Bulletproof Host

Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 | CyberScoop

Sextortionist sentenced to 33 years for targeting 145 children

Spain arrests doxer leaking sensitive data of govt employees

Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown - SecurityWeek

European authorities crack down on illegal streaming networks | CyberScoop

Police seize £1.2m of kit from illegal streaming operation - BBC News

DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

Reporting Cybersecurity Incidents to Law Enforcement- Best Practice

29 Arrests, Nine Crime Groups Dismantled: Another Blow to Illegal Streaming

Linux and Open Source

Organizations Warned of Exploited Linux Kernel Vulnerability - SecurityWeek

Vivre la Linux: Behind France’s bold open source move into digital sovereignty

Open-source security is a mess - IBM and Red Hat bet $5 billion and 20,000 engineers can fix it | ZDNET

New CIFSwitch Linux flaw gives root on multiple distributions

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access - SecurityWeek

Dozens of Red Hat packages backdoored through its official NPM channel - Ars Technica

Shai-Hulud malware infects Red Hat npm packages downloaded 80K times weekly

Malware

Attackers Abuse Shared Content for ChatGPT Phishing Campaign - Infosecurity Magazine

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

Infostealers are becoming the go-to phishing payload | Malwarebytes

Android Banking Trojan OverlayPhantom Abuses Accessibility Service to Control Devices

Dozens of Red Hat packages backdoored through its official NPM channel - Ars Technica

Shai-Hulud malware infects Red Hat npm packages downloaded 80K times weekly

Attackers Abuse ChatGPT Share Links to Host Fake Outage Pages That Deliver Malware - gHacks Tech News

Free AI model powers self-spreading worm in enterprise test network

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure

Chinese hackers use new Atlas RAT malware in European cyberattacks

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

Rust-Written IronWorm Hits NPM Supply Chain

Mobile

Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar

Troops’ phones leaked location data to foreign adversaries

BTMOB Android malware service generates custom phishing payloads

Signal users targeted in backup-stealing phishing attacks | Malwarebytes

Mobile security's dirty cupboard: The app layer nobody's watching

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk - SecurityWeek

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

Models, Frameworks and Standards

EU organizations buckle under rising compliance pressure - Help Net Security

145 AI laws passed in 2025 and privacy teams aren't catching a break - Help Net Security

Anthropic to Open Mythos AI to EU's ENISA

ENISA report shows cybersecurity gains across EU critical sectors ...

MSSPs need to look beyond AI compliance badges | perspective | MSSP Alert

Outages

Microsoft fixes outage affecting MFA setup, MySignIn service

Microsoft Exchange Online outage causes email delays, failures

Passwords, Credential Stuffing & Brute Force Attacks

Your OnlyFans may not be private – and neither are your passwords | Cybernews

Pink is the latest goon squad to use fake helpdesk calls to steal creds

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads - SecurityWeek

Microsoft is ditching password-based authentication tomorrow – Edge browser will switch to Windows Hello access | TechRadar

Regulations, Fines and Legislation

EU organizations buckle under rising compliance pressure - Help Net Security

145 AI laws passed in 2025 and privacy teams aren't catching a break - Help Net Security

President Trump Signs AI Executive Order After Delaying It Over China Concerns - Decrypt

Executive order sets voluntary cyber reviews for advanced AI | Miami Herald

EO 14390 raises stakes for enterprise cybersecurity | TechTarget

DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels | CyberScoop

CISA close to issuing new cyber AI directive | Federal News Network

Social Media

Your OnlyFans may not be private – and neither are your passwords | Cybernews

Instagram Accounts Hijacked by Tricking Meta AI Support Into Verifying Attackers as Owners - gHacks Tech News

Five Eyes: China expanding state secret recruitment campaign

LinkedIn-themed phishing abuses Adobe's A/B testing platform - Help Net Security

Software Supply Chain

Rust-Written IronWorm Hits NPM Supply Chain

Supply Chain and Third Parties

Supply Chain Risk Is Now a Cyber Resilience Problem | Dell

Scots affected by Capita cyber attack given route to compensation | Scottish Legal News


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Nation state attacks: The risk to UK firms | SC Media UK

Why Execs and CISOs Must Treat Cyber Threats as Statecraft - Infosecurity Magazine

Putin sends submarines to survey Britain's subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen

Five Eyes: China expanding state secret recruitment campaign

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

Plan to toughen protections for subsea internet cables amid heightened Russian activity - GOV.UK

The Pentagon Finally Admits That Location Data Is a Battlefield Problem - Security Affairs

Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say - SecurityWeek

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms - Infosecurity Magazine

As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

Cyber espionage campaign targeted stock exchange executive’s Outlook account

A Year After Launch, Ukraine’s Tallinn Mechanism Is Becoming a Cybersecurity Hub | The Gaze

Nation State Actors

Nation state attacks: The risk to UK firms | SC Media UK

Why Execs and CISOs Must Treat Cyber Threats as Statecraft - Infosecurity Magazine

Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns - Help Net Security

As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

China

Are our cars spying on us? A cybersecurity expert explains how to stay safe

Five Eyes: China expanding state secret recruitment campaign

Chinese hackers use new Atlas RAT malware in European cyberattacks

The Green Grid’s Hidden Backdoor: Who Controls Europe's Clean Energy?

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms - Infosecurity Magazine

Germany, Spain said to push back on European plan to ban Huawei gear

China Uses Dual-Method Cyberattack on Czech Orgs

Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek

China's TA4922 Expands Cybercrime Attacks Globally

China turns its aging camera network into an AI-powered mass surveillance apparatus

Russia

Putin sends submarines to survey Britain's subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen

FSB Group Gamaredon Hides Worm in Windows Data Streams - Infosecurity Magazine

Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2

Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say - SecurityWeek

The Green Grid’s Hidden Backdoor: Who Controls Europe's Clean Energy?

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

Plan to toughen protections for subsea internet cables amid heightened Russian activity - GOV.UK

Huge Botnet Linked To Russia Infected Over 10 Million Devices Before Being Shut Down

Estonians' will to defend the country remains high, cyberattacks seen as a threat | News | ERR

'Dumbass' criminal breaks the 'first rule of ransomware club'

Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years | The Record from Recorded Future News

Russian spy agency says foreign spies turned officials' smartphones into surveillance devices

Russia Says Foreign Spyware Found on High-Ranking Officials' Mobile Phones

North Korea

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

Iran

As Iran threatens undersea cables in the Strait of Hormuz, is it time to rethink the internet? | The Independent

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms - Infosecurity Magazine

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT


Tools and Controls

Building Cyber Resilience For Mission-critical Operations In 2026

Microsoft under fire for threatening security researcher with criminal investigation | TechCrunch

Two New Reports Offer Competing Explanations for Cybersecurity's Growing Crisis - SecurityWeek

How to Get Boards to Prioritize Cyber Risk Quantification - Infosecurity Magazine

Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks

Microsoft quietly removes a blog post claiming Windows 11 offers sufficient security - BetaNews

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads - SecurityWeek

How To Reduce Cyber Risks Across Connected Devices And Services

Why Your Rate Limits Fail Under Distributed DDoS Attacks - Security Boulevard

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Threat Actors Deploy Tiflux RMM For Persistent Remote Access

Business Leaders Lack Understanding of Threat Intelligence - Infosecurity Magazine

Lost in translation: Cybersecurity board reporting for CISOs | TechTarget

The behavioral signals that sharpen Trojan malware detection - Help Net Security

Known vulnerabilities behind most application security incidents - Help Net Security

How Leading Organizations Are Turning EDR Into Operational Resilience

Raising the Cybersecurity Stakes: Ante up for the Agentic Era - SecurityWeek

Microsoft is ditching password-based authentication tomorrow – Edge browser will switch to Windows Hello access | TechRadar

Anthropic to Open Mythos AI to EU's ENISA

UK banks still lack access to Mythos AI model, BoE's Bailey says - CNA

Zoom CISO: AI as Security Enabler, Not Role-Replacer

Agent Threat Rules: Open detection rule format for AI agent security threats - Help Net Security

Anthropic ups Glasswing partner count 4x, UK banks snubbed

GCHQ debuts world-first AI cyber defense system to detect threats across critical national infrastructure, airlines, telecoms, and major companies | TechRadar

Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks - SecurityWeek

Hackers Can Weaponize Lenovo Driver to Terminate EDR Processes

Cyber Insurance Rates Are Dropping, but Exclusions Widen


Reports Published in the Last Week

SANS 2025 State of ICS/OT Security Report | IT Pro



Vulnerability Management

Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures

Open-source security is a mess - IBM and Red Hat bet $5 billion and 20,000 engineers can fix it | ZDNET

IBM and Red Hat believe they have the answer to open source security risks | IT Pro

Vulnerabilities

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) - Help Net Security

Microsoft blames unexpected Windows driver updates on caching issue

Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 - SecurityWeek

Organizations Warned of Exploited Linux Kernel Vulnerability - SecurityWeek

New CIFSwitch Linux flaw gives root on multiple distributions

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access - SecurityWeek

Oracle's First Monthly Patches Resolve 77 Vulnerabilities - SecurityWeek

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Recent Palo Alto Networks Vulnerability Exploited for Weeks - SecurityWeek

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

Chrome 148 Update Patches 151 Vulnerabilities - SecurityWeek

The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks

Critical Flowise Flaw Gives Attackers Full Server Control - Infosecurity Magazine

Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets

Acer working to patch max severity zero-days in Wave 7 routers


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 29 May 2026

Black Arrow Cyber Threat Intelligence Briefing 29 May 2026:

-Could Your CEO Be the Weakest Link When It Comes to AI Security? New Study Warns Execs Are ‘Knowingly Bypassing Safeguards Because the Perceived Benefits Outweigh the Risks’

-Companies Built AI into Core Systems Before Figuring out How to Govern It

-When Your Biggest Security Risk Has Never Signed a Contract

-The AI Phishing Revolution: From Spray-and-Pray to Autonomous Operations

-Bosses Blinded by Confidence About Shadow AI Use by Workers

-68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise

-Preparing for Severe Cyber Threat: Why Leaders Must Act Now

-The UK’s Top Spy Says the Window to Stay Ahead of China and Russia Is Narrowing and Cyber Security Needs to Become ‘10 Times More Urgent’

-UK Spy Chief Labels AI ‘Unstoppable Force’ with Offensive, Defensive Ramifications for Cyberspace

-Phishing Most Prevalent Cyber Attack, Confirms UK Survey

-Security Experts Caution MFA Alone Can No Longer Stop Threat Actors

-To Pay, or Not to Pay: 58% of CISOs Say They Would Pay the Ransom for Their Data

-Lessons for Organisations from the Verizon 2026 Data Breach Investigations Report

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Continuing the theme from recent weeks, our review of current cyber news in the media considers how organisations can use AI more securely by being aware of the risks and the need for stronger governance and oversight.

We highlight that this starts from the top of the organisation, including how the leadership uses AI, how they understand the risks to their core systems, and how they can fulfil regulatory and accountability responsibilities where AI agent failures cause disruption or harm. We also report on messaging from the UK’s NCSC on the need for organisations to strengthen their security in the face of escalating risks.

Alongside AI risks, traditional cyber risks remain: we include a reminder that phishing and vulnerability exploits are top cyber threats (which are also empowered by AI), alongside third-party risks.

While the threat landscape shifts and evolves, the actions required from business leaders remain consistent: ensure an objective and complete understanding of your risks, and an unbiased assessment of how your controls address those risks. Contact us to discuss how to achieve this proportionately.


Top Cyber Stories of the Last Week

Could Your CEO Be the Weakest Link When It Comes to AI Security? New Study Warns Execs Are ‘Knowingly Bypassing Safeguards Because the Perceived Benefits Outweigh the Risks’

New research from TrustedTech highlights a growing risk around unapproved AI use, with 62% of senior leaders admitting to using tools outside company controls, double the rate of wider employees. More than a quarter said they would continue using AI even if it was banned, despite many being concerned about staff doing the same. The risk is greater at leadership level because executives often have access to sensitive financial, HR, customer and legal data. The findings highlight how behaviour at senior level can undermine governance and increase organisational risk as AI adoption accelerates.

https://www.techradar.com/pro/security/could-your-ceo-be-the-weakest-link-when-it-comes-to-ai-security-new-study-warns-execs-are-knowingly-bypassing-safeguards-because-the-perceived-benefits-outweigh-the-risks

Companies Built AI into Core Systems Before Figuring Out How to Govern It

Check Point reports that 70% of organisations now use generative AI in live environments, while 64% have AI agents in pilot or production. In some cases, these agents have privileged access to core systems, increasing exposure to security incidents. More than half of organisations have already experienced at least one AI-related security issue, including unapproved AI use, AI-generated phishing, deepfake content and sensitive data leaks. Yet only 5% have visibility of the AI tools and services being used, leaving many organisations unable to consistently govern access, data flows and risk.

https://www.helpnetsecurity.com/2026/05/28/check-point-genai-security-controls-report/

When Your Biggest Security Risk Has Never Signed a Contract

As AI agents, systems that can act independently on behalf of an organisation, become embedded in business processes, accountability is moving from policy into law. UK and EU regimes increasingly expect a named senior leader to show reasonable oversight when agent failures cause disruption or harm. Responsibility cannot simply be assigned on paper. Senior sponsors need enough practical understanding to supervise the agents they own, supported by formal training that links legal accountability with meaningful operational control.

https://www.computerweekly.com/opinion/When-your-biggest-security-risk-has-never-signed-a-contract

The AI Phishing Revolution: From Spray-and-Pray to Autonomous Operations

AI is reshaping phishing from broad, low-effort scams into targeted, always-on campaigns. Attackers can now create convincing, personalised emails in under five minutes, operate across email, text, voice and collaboration tools, and adapt their approach when a target does not respond. Some attacks also bypass multi-factor authentication by tricking users into approving legitimate-looking login requests. With AI reducing the skill and cost needed to run these campaigns, organisations face a shift where attacks operate continuously and adapt in real time, making traditional, user-focused defences increasingly less effective.

https://www.itsecurityguru.org/2026/05/27/the-ai-phishing-revolution-from-spray-and-pray-to-autonomous-operations/

Bosses Blinded by Confidence about Shadow AI Use by Workers

Okta research found that 58% of organisations experienced an AI-related security incident or near miss in the past year, despite 90% of executives feeling confident they can see how AI is being used. The gap is driven by “shadow AI”, where employees use unapproved tools outside company oversight. More than half of knowledge workers admitted doing this, including 55% in the UK. Some also shared confidential documents, HR information or even login details, increasing business risk. The findings suggest a disconnect between leadership visibility and actual AI usage, increasing exposure to data leakage and governance challenges as adoption grows.

https://www.theregister.com/ai-ml/2026/05/27/bosses-blinded-by-confidence-about-shadow-ai-use-by-workers/5247275

68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise

Barclays reports that 68% of UK business leaders expect to increase cyber security spending over the next 12 months, as AI adoption and geopolitical uncertainty reshape technology priorities. Despite this, fewer than three in 10 firms are confident they could respond effectively to a major cyber incident. Average cyber security spend has reached £505,000 so far in 2026, rising to £1.3m among large businesses. Key concerns include loss of sensitive data or intellectual property, disruption to operations, loss of revenue and damage to customer trust.

https://www.infosecurity-magazine.com/news/uk-firms-cyber-spending-ai-risks/

Preparing for Severe Cyber Threat: Why Leaders Must Act Now

The NCSC has warned that severe cyber threats are becoming a credible risk for organisations delivering the UK’s critical services, including financial services, health, energy, transport, and communications. These attacks can cause extended downtime, financial loss, reputational damage and risks to public safety. With technologies such as advanced AI increasing the speed and scale of attacks, leaders are being urged to plan beyond prevention. Building resilience means identifying critical systems, preparing for degraded operations, rehearsing recovery plans and ensuring key decisions are understood before a major incident occurs.

https://www.ncsc.gov.uk/blogs/preparing-for-severe-cyber-threat-why-leaders-must-act-now

The UK’s Top Spy Says the Window to Stay Ahead of China and Russia Is Narrowing and Cyber Security Needs to Become ‘10 Times More Urgent’

GCHQ has warned that the UK and its allies have a narrowing window to stay ahead of growing cyber and intelligence threats from China and Russia. The agency’s director said warfare is becoming increasingly driven by data, artificial intelligence and automation, while Russia is intensifying activity against critical infrastructure, democratic processes, supply chains and public trust. The warning highlights the increasing pressure on organisations to strengthen supply chain resilience, protect data and manage access controls as part of a more urgent approach to cyber security.

https://fortune.com/2026/05/27/uk-top-spy-says-window-narrowing-for-west-to-stay-ahead-of-china-russia-intelligence-espionage-usa/

UK Spy Chief Labels AI ‘Unstoppable Force’ with Offensive, Defensive Ramifications for Cyberspace

GCHQ has warned that artificial intelligence is reshaping cyber security, creating both new opportunities and risks. Anne Keast-Butler, head of the UK intelligence agency, described AI as an “unstoppable force” that can be used to find weaknesses in critical technology and to support activity below the level of traditional warfare. GCHQ is developing an AI powered cyber shield to strengthen national defences, while warning that countries including China and Russia are using AI, data and automation to enhance cyber and hybrid threats.

https://cyberscoop.com/gchq-warns-ai-cyber-warfare-threats/

Phishing Most Prevalent Cyber Attack, Confirms UK Survey

New UK government research shows cyber attacks remain a persistent risk, affecting 43% of businesses and 28% of charities in the past year. Phishing, where criminals trick people into sharing information or clicking harmful links, remains the most common attack, impacting 38% of businesses and 25% of charities. Larger organisations face higher exposure, with 69% reporting an incident. Despite this, only around 30% conduct cyber risk assessments, while just 25% of businesses and 19% of charities have formal response plans. Supply chain oversight also remains limited, leaving many organisations exposed through partners and providers.

https://www.icaew.com/insights/viewpoints-on-the-news/2026/may-2026/phishing-most-prevalent-cyber-attack-confirms-uk-survey

Security Experts Caution MFA Alone Can No Longer Stop Threat Actors

Security researchers are warning that multi factor authentication is no longer enough on its own to stop account takeover attempts. New phishing services can steal Microsoft 365 access tokens, which allow criminals to access Outlook, Teams and OneDrive without needing a password or another login check. One service, Kali365, costs from $250 for 30 days and gives even less skilled attackers ready-made templates, dashboards and AI generated messages. This shift highlights how attackers are bypassing traditional authentication controls, reflecting a move toward identity-focused risks such as token misuse and anomalous account activity rather than reliance on login-based protections alone.

https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html

To Pay, or Not to Pay: 58% of CISOs Say They Would Pay the Ransom for Their Data

A survey of 750 CISOs in the US and UK found that 58% would be willing to pay a ransom to end a ransomware incident, despite official guidance advising against it. In practice, fewer organisations appear to pay, with IDC reporting that 37% of affected companies did so last year. Paying does not guarantee recovery, with some organisations receiving incomplete data restoration and only 60% of SMEs in one survey recovering all or part of their data after payment. The findings highlight the operational and recovery risks of ransomware, where payment does not guarantee data restoration and can still result in prolonged disruption.

https://www.csoonline.com/article/4176472/to-pay-or-not-to-pay-58-of-cisos-say-they-would-pay-the-ransom-for-their-data.html

Lessons for Organisations from the Verizon 2026 Data Breach Investigations Report

Verizon’s 2026 Data Breach Investigations Report highlights how many breaches still stem from gaps in basic cyber security controls. Based on more than 31,000 incidents and 22,000 confirmed breaches across 145 countries, the report found vulnerability exploitation was the leading route into organisations, accounting for 31% of breaches. Ransomware remained a major issue, appearing in 48% of breaches, while third party involvement also featured in 48%. The report also points to rising risks from employee use of unauthorised AI tools, with sensitive internal information being uploaded outside corporate control.

https://www.helpnetsecurity.com/2026/05/25/lessons-from-verizon-dbir-2026-findings/



Threats

Ransomware, Extortion and Destructive Attacks

Why pure extortion is replacing traditional ransomware - Security Affairs

To pay, or not to pay: 58% of CISOs say they would pay the ransom for their data | CSO Online

The Hidden Ransomware Economy Running on Exposed Databases

Ransomware Actors Show Up In Person to Steal Law Firm Data

The Gentlemen is Making Its Mark in the Ransomware World - Security Boulevard

Law enforcement shuts down VPN service used by two dozen ransomware gangs | TechCrunch

Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files

More Australian firms are panicking and paying ransoms | The North West Star | Mt Isa, QLD

Ransomware and Destructive Attack Victims

FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person | CyberScoop

Charter confirms data breach after ShinyHunters extortion threat

MyPillow appears on Play ransomware leak site

Phishing & Email Based Attacks

Phishing most prevalent cyber attack, confirms UK survey | ICAEW

Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security

FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required

Cyber insurers warn AI is accelerating phishing and business email compromise attacks | Insurance Times

The AI Phishing Revolution - IT Security Guru

AI-Powered Phishing Puts MSSPs on the Defensive: Barracuda | news | MSSP Alert

Inside business email compromise attack: Real-world examples | TechTarget

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Chinese Threat Actors Shift to Live Credential Interception - Infosecurity Magazine

CERT-UA reports attackers send emails to govt agencies allegedly from their team and State Special Communications Service

Business Email Compromise (BEC)/Email Account Compromise (EAC)

Cyber insurers warn AI is accelerating phishing and business email compromise attacks | Insurance Times

Inside business email compromise attack: Real-world examples | TechTarget

Other Social Engineering

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

700+ education and tech websites hijacked in huge ClickFix malware campaign | Malwarebytes

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Iranian Hackers Using Fake Job Sites to Breach Defense Firms

Thousands of Fake FIFA Domains Target World Cup Fans - Infosecurity Magazine

FBI director Kash Patel’s brand website taken offline after malware reports

2FA/MFA

Security experts caution MFA alone can no longer stop threat actors | CSO Online

Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security

FBI warns about fast-growing phishing kit targeting Microsoft 365 users | CyberScoop

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions | NL Times

Artificial Intelligence

Turns out the C-suite loves shadow AI - Help Net Security

Could your CEO be the weakest link when it comes to AI security? New study warns execs are 'knowingly bypassing safeguards because the perceived benefits outweigh the risks' | TechRadar

Companies built AI into core systems before figuring out how to govern it - Help Net Security

When your biggest security risk has never signed a contract | Computer Weekly

Bosses blinded by confidence about shadow AI use by workers

Cyber insurers warn AI is accelerating phishing and business email compromise attacks | Insurance Times

The AI Phishing Revolution - IT Security Guru

'The challenge is not a lack of technology, but a lack of alignment with the realities of work': Study claims workers are using unapproved AI tools at work, despite knowing the risks | TechRadar

AI shrinks zero-day exploit time from a year to a single day, heading toward one minute — Zero-Day Clock warns security window has collapsed | Tom's Hardware

UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace | CyberScoop

'Threat actors are adapting social engineering and monetization strategies to modern user behavior': Microsoft warns AI chatbots may be sending victims to malicious websites — so be on your guard when clicking | TechRadar

ECB convenes banks over AI cybersecurity risks from Mythos

AI guardrails stripped from Meta and Google models in minutes

European AI adoption hits 99% with regulated data driving most policy violations - Help Net Security

GCHQ draws up plans for world-first national AI cyber defence system | The Standard

Frontier AI models collapse under multi-turn AI attacks, Cisco finds - Help Net Security

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek

Worrying open-source security issue 'BadHost' could affect millions of AI agents, experts warn | TechRadar

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | Trend Micro (US)

Defenders Fall Behind, as AI Rewrites the Rules of a Data Breach

The New Legal Risk Isn’t AI Adoption—It’s AI Without Governance | Brownstein Hyatt Farber Schreck - JDSupra

Fake Gemini and Claude Code Sites Spread Infostealers - Infosecurity Magazine

The Growing Cybersecurity Risks To The Supply Chain In The AI Era

GPU mining malware spreads via SEO poisoning, AI chatbots

Why AI Could Make Cybersecurity One of the Hottest Jobs in Tech - ClearanceJobs

Cisco used AI to write security incident reports, with mixed results

Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers

Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security

Trump Postpones Signing AI Security Order Over Parts He Disliked

OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms | CyberScoop

Anthropic Says a Mythos-Class AI Model Will Be Available Soon - CNET

Bots/Botnets

Canadian Man Arrested for Operating Kimwolf Botnet - SecurityWeek

GlassWorm Botnet Disrupted - SecurityWeek

Careers, Roles, Skills, Working in Cyber and Information Security

Why AI Could Make Cybersecurity One of the Hottest Jobs in Tech - ClearanceJobs

Amid fears of AI killing tech jobs, companies race to fill cybersecurity roles - Sherwood News

One Job That Is Growing in the A.I. Era? Cybersecurity Experts. - The New York Times

UK plans for cybercrime law reform would protect almost no one, experts warn | The Record from Recorded Future News

Why Burnout in Cybersecurity Demands Risk-Based Response - Infosecurity Magazine

Cloud/SaaS

Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security

FBI warns about fast-growing phishing kit targeting Microsoft 365 users | CyberScoop

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

GPU mining malware spreads via SEO poisoning, AI chatbots

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | Trend Micro (US)

Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users

Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities | Microsoft Security Blog

Cyber Crime, Organised Crime & Criminal Actors

Ghost hackers: the cybersecurity mystery that nobody has solved | TechCrunch

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation

Canadian Man Arrested for Operating Kimwolf Botnet - SecurityWeek

One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure

Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Former US execs plead guilty to aiding tech support scammers

Data Breaches/Leaks

Hacker claims to leak massive WhatsApp database before vanishing from forums | Cybernews

Defenders Fall Behind, as AI Rewrites the Rules of a Data Breach

‘The Worst Leak I’ve Witnessed’: A CISA Contractor Left AWS GovCloud Credentials Sitting In A Public GitHub Repo | Techdirt

46k plaintext passwords pwned in Myspace93 breach

German hospitals targeted in massive cyberattack

German Football Association leaves open goal for hackers, who are claiming password theft | Cybernews

Victims 'violated' after South Staffs Water's data breach - BBC News

OnlyFans mega leak reveals 340M user records, hackers claim | Cybernews

UK luxury car drivers' data may be exposed after Mercedes data leak claim | Cybernews

340 Million OnlyFans Profiles Allegedly Rebuilt from Leaks

Trump Mobile probing second major data leak — additional breach allegedly exposes personal info of 27,000 pre-order customers | TechRadar

Trump Mobile site leaks customer data as phone finally ships

7-Eleven data breach exposes personal information of 185,000 people

DocketWise Data Breach Impacts 143,000 - SecurityWeek

Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries - SecurityWeek

Data Protection

European AI adoption hits 99% with regulated data driving most policy violations - Help Net Security

Data/Digital Sovereignty

How a 900% Surge in Cyberattacks Is Forcing Europe to Rethink Its Tech Sovereignty — UNITED24 Media

Dutch Government just said no to an American firm buying the keys to their digital State

Denial of Service/DoS/DDoS

Why the Surge in DDoS Attacks Should Worry Security Leaders - Infosecurity Magazine

Encryption

Texas AG sues Meta over claims that WhatsApp doesn't provide end-to-end encryption - Ars Technica

‘Q-Day’ could be cybersecurity’s Armageddon | The Week

Apple open-sources quantum-resistant encryption code | CyberScoop

Fraud, Scams and Financial Crime

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | Trend Micro (US)

Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users

Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet

Is your phone bill higher? 200+ Android apps might secretly be stealing money from you - PhoneArena

Thousands of Fake FIFA Domains Target World Cup Fans - Infosecurity Magazine

Security Leaders Should Prepare for World Cup Scams | Security Magazine

Fake Streams, Counterfeit Merch & Scams: How Fraudsters Target F1 Fans - Infosecurity Magazine

Insider Risk and Insider Threats

Turns out the C-suite loves shadow AI - Help Net Security

Could your CEO be the weakest link when it comes to AI security? New study warns execs are 'knowingly bypassing safeguards because the perceived benefits outweigh the risks' | TechRadar

Bosses blinded by confidence about shadow AI use by workers

'The challenge is not a lack of technology, but a lack of alignment with the realities of work': Study claims workers are using unapproved AI tools at work, despite knowing the risks | TechRadar

Why ‘shadow AI’ could become an expensive headache for businesses

Internet of Things – IoT

This Is Where Your Doorbell Camera's Security Footage Actually Goes

Law Enforcement Action and Take Downs

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands - SecurityWeek

Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation

Netherlands seizes 800 servers of hosting firm enabling cyberattacks

GlassWorm Botnet Disrupted - SecurityWeek

Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions | NL Times

Romanian Hacker Gets Nearly 5 Years in US Prison Over Network Intrusion

Canadian Man Arrested for Operating Kimwolf Botnet - SecurityWeek

Former US execs plead guilty to aiding tech support scammers

Dutch police arrests suspect linked to Ajax football club hack

Linux and Open Source

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale | WIRED

Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend

Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects - SecurityWeek

California moves to exempt Linux from its upcoming age-verification law after backlash over forcing operating systems to collect users’ ages — amendment proposed by the same lawmaker who wrote the original law | Tom's Hardware

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence | Microsoft Security Blog

Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?

China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant

Malware

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek

Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation

GPU mining malware spreads via SEO poisoning, AI chatbots

700+ education and tech websites hijacked in huge ClickFix malware campaign | Malwarebytes

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant

GlassWorm Botnet Disrupted - SecurityWeek

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Fake Gemini and Claude Code Sites Spread Infostealers - Infosecurity Magazine

Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security

Megalodon chums the waters in 5.5K+ GitHub repo poisonings

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

Attackers Move Past Typosquatting to Realistic Package Impersonation - Infosecurity Magazine

Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?

Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers

FBI director Kash Patel’s brand website taken offline after malware reports

Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

Iranian APT Targets Aviation, Software Companies With Updated Tools - SecurityWeek

Scammers are Exploiting GTA 6 Hype to Spread Malware | Extremetech

Chinese APTs Share Linux Backdoor in Telco Attacks

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Misinformation, Disinformation and Propaganda

Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | Trend Micro (US)

Russia is hacking its way onto social media platform Bluesky to spread disinformation, company says | The Independent

Mobile

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Is your phone bill higher? 200+ Android apps might secretly be stealing money from you - PhoneArena

BTMOB Android RAT Spreads Through No-Code Builder Tooling - Infosecurity Magazine

Whoops! Trump Mobile seems to be leaking customer information — and order numbers might be far lower than previously estimated | TechRadar

Outages

Downtime has become a $600 billion business problem - Help Net Security

Passwords, Credential Stuffing & Brute Force Attacks

The Credential Crisis: How Stolen Credentials Defeat Modern Security - SecurityWeek

Why businesses still get password management wrong | TNW Deals

German Football Association leaves open goal for hackers, who are claiming password theft | Cybernews

Typed the wrong macOS password? That brief pause isn't a glitch | Macworld

Regulations, Fines and Legislation

UK plans for cybercrime law reform would protect almost no one, experts warn | The Record from Recorded Future News

ECB convenes banks over AI cybersecurity risks from Mythos

'We cannot regulate cyber threats away,' top lawyer warns

Trump Postpones Signing AI Security Order Over Parts He Disliked

Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 - House of Commons Library

Minister Lloyd cyber security speech at the New Statesman - GOV.UK

California moves to exempt Linux from its upcoming age-verification law after backlash over forcing operating systems to collect users’ ages — amendment proposed by the same lawmaker who wrote the original law | Tom's Hardware

Restoring CISA is one issue many lawmakers can agree on | Federal News Network

National Cyber Security Centre 'absolutely' needs powers to deal with threats for Irish EU presidency

Shadow IT

Turns out the C-suite loves shadow AI - Help Net Security

Could your CEO be the weakest link when it comes to AI security? New study warns execs are 'knowingly bypassing safeguards because the perceived benefits outweigh the risks' | TechRadar

Bosses blinded by confidence about shadow AI use by workers

'The challenge is not a lack of technology, but a lack of alignment with the realities of work': Study claims workers are using unapproved AI tools at work, despite knowing the risks | TechRadar

Why ‘shadow AI’ could become an expensive headache for businesses

Social Media

Russia is hacking its way onto social media platform Bluesky to spread disinformation, company says | The Independent

46k plaintext passwords pwned in Myspace93 breach

Software Supply Chain

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale | WIRED

Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation

Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack - SecurityWeek

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

Megalodon chums the waters in 5.5K+ GitHub repo poisonings

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

The Growing Cybersecurity Risks To The Supply Chain In The AI Era

Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?

Supply Chain and Third Parties

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek

The Growing Cybersecurity Risks To The Supply Chain In The AI Era


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

The U.K.’s top spy says the window to stay ahead of China and Russia is narrowing and cybersecurity needs to become ‘10 times more urgent’

UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace | CyberScoop

UK Spy Chief Warns China Is Closing Cyber Gap With West

UK spy chief says West between peace and war and 500,000 Russians killed in Ukraine war so far - ABC News

Cyber warfare is outpacing global legal accountability - The Hindu

How concerned should CIOs be with geopolitics? | CIO

Even as AI gets better at finding digital weak spots, it doesn’t eliminate the human role in cyber conflict | Federal News Network

Nation State Actors

China

UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace | CyberScoop

UK Spy Chief Warns China Is Closing Cyber Gap With West

The U.K.’s top spy says the window to stay ahead of China and Russia is narrowing and cybersecurity needs to become ‘10 times more urgent’

Chinese Threat Actors Shift to Live Credential Interception - Infosecurity Magazine

China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant

Chinese APTs Share Linux Backdoor in Telco Attacks

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Russia

UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace | CyberScoop

The U.K.’s top spy says the window to stay ahead of China and Russia is narrowing and cybersecurity needs to become ‘10 times more urgent’

UK spy chief says West between peace and war and 500,000 Russians killed in Ukraine war so far - ABC News

Russia 'relentlessly targeting' critical infrastructure, democracy - GCHQ - BBC News

Russia is hacking its way onto social media platform Bluesky to spread disinformation, company says | The Independent

Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands - SecurityWeek

Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions | NL Times

Kremlin appoints cyber executive with alleged GRU ties to Security Council role | The Record from Recorded Future News

One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | Trend Micro (US)

Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries - SecurityWeek

CERT-UA reports attackers send emails to govt agencies allegedly from their team and State Special Communications Service

Experts question Nigel Farage’s Russian phone-hacking claims

North Korea

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Iran

Iranian Hackers Using Fake Job Sites to Breach Defense Firms

Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

Iranian APT Targets Aviation, Software Companies With Updated Tools - SecurityWeek

The LA Metro Attack Wasn't Hacktivism. It Was a State Operation With a Costume On.

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

How concerned should CIOs be with geopolitics? | CIO

A nation on a hard drive: Inside the rise of digital embassies – POLITICO


Tools and Controls

Security experts caution MFA alone can no longer stop threat actors | CSO Online

AI shrinks zero-day exploit time from a year to a single day, heading toward one minute — Zero-Day Clock warns security window has collapsed | Tom's Hardware

Anthropic's Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing

Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

Preparing for severe cyber threat: why leaders must act now | National Cyber Security Centre

The Next-Gen Flipper Zero Looks Even More Powerful Than Expected

Project Glasswing by Anthropic didn't just find the bugs. It also found the real vuln | Ctech

UK plans for cybercrime law reform would protect almost no one, experts warn | The Record from Recorded Future News

Why businesses still get password management wrong | TNW Deals

Why Burnout in Cybersecurity Demands Risk-Based Response - Infosecurity Magazine

Cybersecurity Evolution: Perimeter Defense to AI-Native Security

Apple open-sources quantum-resistant encryption code | CyberScoop

European AI adoption hits 99% with regulated data driving most policy violations - Help Net Security

Amid fears of AI killing tech jobs, companies race to fill cybersecurity roles - Sherwood News

One Job That Is Growing in the A.I. Era? Cybersecurity Experts. - The New York Times

Cisco used AI to write security incident reports, with mixed results

Anthropic launches Claude Opus 4.8, prepares Mythos-class models for all customers - Help Net Security

Anthropic adds 28 security and compliance integrations for Claude - Help Net Security

For CISOs, dawn of OpenAI Daybreak brings good and bad news | TechTarget

Claude now reviews and fixes vulnerabilities as you write code - Help Net Security




Vulnerability Management

AI shrinks zero-day exploit time from a year to a single day, heading toward one minute — Zero-Day Clock warns security window has collapsed | Tom's Hardware

Anthropic's Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft Threatens Researcher Over Bug Reports, Triggers Cybersecurity Uproar

Three-Quarters of Firms Knowingly Ship Vulnerable Code, Says Checkmarx - Infosecurity Magazine

NIST’s CVE Shift Raises the Bar for Vulnerability Prioritization | perspective | MSSP Alert

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report - Help Net Security

Why some security fixes never reach your vulnerability dashboard | CSO Online

Verizon 2026 DBIR: 6 key takeaways for CISOs | TechTarget

Project Glasswing by Anthropic didn't just find the bugs. It also found the real vuln | Ctech

Anthropic to release Mythos-class models to the public

Why CISA Accepting KEV Nominations Is So Important | Security Magazine

Cisco refines its risk-based vulnerability disclosure for the AI era - Help Net Security

Vulnerabilities

Microsoft patches two zero-day flaws in Defender | CSO Online

SharePoint Has a New RCE Flaw. If You Haven't Patched Yet, Go Do That.

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure - SecurityWeek

CVE-2026-9082: Drupal's Highly Critical SQL Injection Flaw Is Already Under Active Attack

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

700+ education and tech websites hijacked in huge ClickFix malware campaign | Malwarebytes

Gitea Vulnerability Exposed 30,000 Deployments to Attacks - SecurityWeek

New Gogs 0-Day Vulnerability Lets Attackers Run Malicious Code on the Server Remotely

KnowledgeDeliver flaw exploited as a zero-day to install web shells

Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend

Notepad++ fixes critical vulnerabilities that can lead to malware | Cybernews

Trend Micro warns of Apex One zero-day exploited in the wild

Ubiquiti patches three max severity UniFi OS vulnerabilities

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains - SecurityWeek

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate - SecurityWeek


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 22 May 2026

Black Arrow Cyber Threat Intelligence Briefing 22 May 2026:

-Bank of England, FCA and Treasury Raise Alarm Over Frontier AI

-NCSC Publishes Guidance on Securing Agentic AI Use

-Social Engineering Attacks Are Rising as Employee Data Becomes Easier to Exploit

-Mobile Phishing Is a Bigger Threat than Email Now – How to Stay Protected

-Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector

-Critical Microsoft Vulnerabilities Doubled: from Exposure to Escalation

-Cyber Attacks Cost UK Businesses £3.7Bn in Litigation in 2025

-Crime Increasingly a ‘Serious Barrier’ to UK Growth, Say Business Leaders

-Cyber Resilience is the New Business Continuity Plan

-Cyber Threats Push SMBs to Spend More on Security

-When Compliance Isn’t Continuous, That’s a Security Risk

-Taking Care of Business: The CISO’s Role in a Cyber Crisis

-Four Incident Response Mistakes That Slow Recovery and Raise Breach Costs

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Authorities in the UK have warned organisations about the cyber risks of AI, both because it has elevated the risks of an attack and the internal risks when used by organisations in their operations. While AI presents new risks, attackers are also advancing their use of more established tactics, from social engineering to exploiting vulnerabilities.

Research this week highlights the effects of cyber attacks, through the financial costs to organisations and the damage to business growth. In response, business leaders are focusing on their resilience to a cyber incident, including their business continuity plans. We highlight that, for organisations with regulatory requirements, compliance must be continuous.

We also discuss how resilience is played out in the way organisations respond to a cyber incident, and the role of a CISO in helping the business leadership team to manage the effect of an incident throughout the organisation. We describe how preparation for a cyber incident is essential, and some mistakes to avoid. Contact us to discuss how we support organisations like yours to lay the foundations to manage a cyber incident more confidently. 


Top Cyber Stories of the Last Week

Bank of England, FCA and Treasury Raise Alarm Over Frontier AI

The Bank of England, FCA and Treasury have warned UK financial services firms to strengthen cyber security controls as frontier AI (advanced AI systems at the cutting edge of capability) increases the speed, scale and cost efficiency of attacks. The authorities said current models can already exceed what a skilled practitioner could achieve, raising risks to customers, market integrity and financial stability. Boards are expected to understand the threat, invest in core defences, manage supplier risk, fix weaknesses quickly, protect data and access, and improve response and recovery planning.

https://www.infosecurity-magazine.com/news/bank-england-fca-treasury-alarm/

NCSC Publishes Guidance on Securing Agentic AI Use

The UK’s NCSC has issued new guidance on the safe use of agentic AI, meaning AI systems that can act with a degree of independence. Developed with partners in Australia, Canada, the US and New Zealand, the guidance warns that poorly controlled AI agents could access too much data, make decisions faster than people can review, or behave unpredictably. Organisations are advised to start with tightly controlled pilots, limit access to only what is necessary, monitor activity closely and ensure clear ownership, human oversight and incident response plans before wider deployment.

https://www.infosecurity-magazine.com/news/ncsc-publishes-guidance-securing/

Social Engineering Attacks Are Rising as Employee Data Becomes Easier to Exploit

Optery reports that targeted social engineering is rising, with 96% of cyber security leaders seeing an increase over the past year. Attackers are using legitimate data brokers and people search sites to find employee details, such as personal phone numbers, email addresses, job roles and home addresses, making impersonation more convincing across email, calls, texts and social media. Nearly three quarters reported credential compromise linked to these attacks, while IT and identity teams were targeted more often than executives. The research found that organisations are increasingly prioritising reduction of exposed employee data, with around 60% already using this approach and a third identifying it as a top investment priority.

https://www.biometricupdate.com/202605/social-engineering-attacks-are-rising-as-employee-data-becomes-easier-to-exploit

Mobile Phishing Is a Bigger Threat than Email Now – How to Stay Protected

Verizon’s latest data breach research shows attackers are increasingly moving from email to mobile channels such as text messages and phone calls. Based on more than 31,000 incidents and 22,000 confirmed breaches, phone-based phishing was around 40% more effective than email in simulations. Human involvement featured in 62% of breaches, while exploitation of software weaknesses rose to 31% of initial entry points. The report also highlights growing risks from unapproved AI use, with 67% of employees using personal AI accounts on company devices.

https://www.zdnet.com/article/mobile-phishing-is-a-bigger-threat-than-email-now/

Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector

Verizon’s 2026 DBIR found that exploiting unpatched vulnerabilities became the leading cause of data breaches in 2025, accounting for 31% of cases across more than 22,000 confirmed breaches. Credential abuse fell to 13%, while ransomware appeared in 48% of breaches. Patching performance also worsened, with the median time to fully fix flaws rising to 43 days. Third parties were involved in 48% of breaches, highlighting the growing risk from suppliers and cloud services. The findings underscore the urgency of prioritising vulnerability remediation and strengthening core security practices, as attack speeds increase and exposure expands through third-party and cloud dependencies.

https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/

Critical Microsoft Vulnerabilities Doubled: from Exposure to Escalation

Microsoft disclosed 1,273 vulnerabilities in 2025, and critical weaknesses doubled from 78 to 157. The sharpest concern is in cloud and business platforms, where critical issues in Azure and Dynamics 365 rose from 4 to 37. Microsoft Office also saw a 234% rise in vulnerabilities, increasing the risk of staff being targeted through everyday documents and emails. The findings highlight that while patching remains essential, excessive privilege and weak identity controls are enabling attackers to escalate access and extend impact across systems and cloud environments.

https://www.bleepingcomputer.com/news/security/critical-microsoft-vulnerabilities-doubled-from-exposure-to-escalation/

Cyber Attacks Cost UK Businesses £3.7Bn in Litigation in 2025

Gallagher and the independent economic research consultancy CEBR estimate that cyber attacks cost large UK businesses £11.7bn in 2025, with shareholder litigation accounting for £3.7bn and disrupted trading a further £5.4bn. Reputational damage added £573m, alongside £339m in lost customer goodwill. 88% of large UK businesses have cyber insurance, however only 59% are insured for third-party legal claims and fewer than half for regulatory fines or GDPR penalties, leaving boards exposed to costs that can continue long after systems are restored.

https://www.uktech.news/cybersecurity/cyber-attacks-cost-uk-businesses-3-7bn-in-litigation-in-2025-20260518

Crime Increasingly a ‘Serious Barrier’ to UK Growth, Say Business Leaders

The British Chambers of Commerce reports that cyber attacks are contributing to rising crime levels that are increasingly affecting UK business growth. In a survey of 1,411 firms, 21% experienced cyber attacks in the past year, alongside wider fraud and scam activity. High-profile incidents involving major UK brands demonstrate the scale of potential impact, with significant financial losses and operational disruption. The findings highlight that cyber threats are not only a security issue but a wider economic risk, requiring sustained investment and stronger support to improve business resilience and reduce disruption to growth.

https://www.theguardian.com/uk-news/2026/may/17/crime-serious-barrier-uk-growth-business-leaders

Cyber Resilience is the New Business Continuity Plan

Cyber resilience is becoming central to business continuity as disruption increasingly affects operations, customers, compliance and suppliers at the same time. Security incidents, cloud outages, identity compromise and supplier failures can quickly spread across connected systems. Effective continuity planning now depends on understanding the organisation’s most critical processes, the systems and suppliers they rely on, and how quickly they must recover. Plans should be tested against realistic scenarios, including ransomware and cloud failure, to ensure critical operations can continue when key systems or data cannot be fully trusted.

https://www.securityweek.com/cyber-resilience-is-the-new-business-continuity-plan/

Cyber Threats Push SMBs to Spend More on Security

Global market research and advisory firm IDC has found that 60% of small and medium sized businesses expect to increase cyber security spending over the next 12 months as threats increase and AI adoption accelerates. However, many remain reactive, with informal security ownership, limited planning and gaps in staff training. Nearly half say keeping up with new threats is their biggest concern, while 84% of micro businesses and 65% of small businesses are unprepared or only taking early steps to manage AI related risks, including more convincing phishing and deepfake scams.

https://www.helpnetsecurity.com/2026/05/21/idc-smbs-cybersecurity-spending-report/

When Compliance Isn’t Continuous, That’s a Security Risk

Manual governance, risk and compliance (GRC) processes are becoming a growing security risk as organisations struggle to keep pace with regulation. While 95% have introduced some automation, only 4% have fully automated the process. The burden is significant, with 83% of security leaders reporting delays from manual tasks and 58% spending over 2,000 hours a year collecting evidence. With 72% managing six or more compliance frameworks, delayed control testing and policy updates can leave leadership with an outdated view of cyber security risk, reinforcing the need for continuous monitoring of controls.

https://www.scworld.com/perspective/when-compliance-isnt-continuous-thats-a-security-risk

Taking Care of Business: The CISO’s Role in a Cyber Crisis

In a cyber crisis, the CISO’s role expands beyond managing the immediate response to helping the whole organisation protect operations, reputation and trust. Effective preparation means having clear escalation routes, tested crisis plans, defined responsibilities and joined-up communications across legal, compliance, HR, PR, business continuity and recovery teams. During and after a major incident, CISOs must translate complex security issues into business impact, support evidence gathering and regulatory obligations, guide recovery and ensure lessons learned strengthen future resilience.

https://www.techtarget.com/searchsecurity/tip/Taking-care-of-business-The-CISOs-role-in-a-cyber-crisis

Four Incident Response Mistakes That Slow Recovery and Raise Breach Costs

Organisations can lose valuable time and face higher breach costs when incident response plans are unclear, untested or disconnected from legal, insurance and specialist response teams. Common mistakes include negotiating supplier contracts during a crisis, taking rushed actions that destroy evidence, failing to involve legal advisers early, and overlooking cyber insurance notification requirements. These gaps can delay containment, prolong business disruption and increase legal or financial exposure. Regularly tested plans, agreed response roles and pre-arranged expert support help organisations recover faster while preserving critical evidence.

https://www.msspalert.com/native/four-incident-response-mistakes-that-slow-recovery-and-raise-breach-costs



Threats

Ransomware, Extortion and Destructive Attacks

When ransomware gets physical: cybercriminals turn to threats of violence

The economics of ransomware 3.0 | CSO Online

Instructure cyberattack reignites ransom payment debate | TechTarget

When ransomware hits, confidence doesn’t restore endpoints - Help Net Security

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Attacks

ISMG Editors: Should We Trust Ransomware Gangs?

Cybercrime service disrupted for abusing Microsoft platform to sign malware

Microsoft disrupts cybercrime service offering malware disguised as legitimate software - Nextgov/FCW

Microsoft disrupts alleged malware-signing operation used by ransomware gangs

Cybersecurity Breaches Survey: Why Phishing Now Beats Ransomware – And What To D... | SC Media UK

Ransomware and Destructive Attack Victims

JLR records £244m post-tax loss after being hit by tariffs and cyber attack | Autocar

JLR Profit Drops 99 Percent After Cyber-Attack | Silicon UK Tech

M&S profits slump 25% after cyber attack hits sales - Sharecast.com

7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand - SecurityWeek

Foxconn Confirms Cyberattack, Security Experts Discuss | Security Magazine

Security pros doubt Canvas attackers really deleted stolen student data

Instructure cyberattack reignites ransom payment debate | TechTarget

FBI warns students and staff that ShinyHunters may come knocking after Canvas breach

Phishing & Email Based Attacks

Social engineering attacks are rising as employee data becomes easier to exploit | Biometric Update

Mobile phishing is a bigger threat than email now - how to stay protected | ZDNET

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security

Phishing With Real Bait: Company Messaging Tools Reel in Scam Victims

INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

201 arrested in INTERPOL disruption of phishing and fraud networks - Help Net Security

Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa | CyberScoop

Researchers Warn CypherLoc Scareware Has Targeted Millions of Users - Infosecurity Magazine

Cybersecurity Breaches Survey: Why Phishing Now Beats Ransomware – And What To D... | SC Media UK

The New Phishing Click: How OAuth Consent Bypasses MFA

Other Social Engineering

Social engineering attacks are rising as employee data becomes easier to exploit | Biometric Update

Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security

Attackers bypass traditional security tools with ‘user driven’ attacks - BetaNews

Hackers Bypass Security Tools to Target Users Directly - Infosecurity Magazine

Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

Phishing With Real Bait: Company Messaging Tools Reel in Scam Victims

Researchers Warn CypherLoc Scareware Has Targeted Millions of Users - Infosecurity Magazine

2FA/MFA

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

The New Phishing Click: How OAuth Consent Bypasses MFA

Microsoft is officially killing SMS verification for personal accounts | PCWorld

Artificial Intelligence

Tenable Warns AI Adoption Is Outpacing Governance As Cloud Exposure Risks Surge

Bank of England, FCA and Treasury Raise Alarm Over Frontier AI - Infosecurity Magazine

NCSC Publishes Guidance on Securing Agentic AI Use - Infosecurity Magazine

NCSC Warns Organisations Not To Rush Into Agentic AI

Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

The Boring Stuff is Dangerous Now

Most Organizations Use AI Agents for Sensitive Security Tasks - Infosecurity Magazine

The dual-threat landscape and evolution of digital workers - SiliconANGLE

One in 33 Employees Is Driving Nearly a Fifth of All Workplace AI Activity and Most Companies Are Only Just Waking Up to It - IT Security Guru

AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Soft - Infosecurity Magazine

Cyber Pros Can't Decide If AI Is a Good or a Bad Thing

OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack - Cyber Security News

TeamPCP hackers advertise Mistral AI code repos for sale

G7 Countries Release AI SBOM Guidance - SecurityWeek

'Claw Chain' OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery - SecurityWeek

AI infrastructure is cracking under sovereignty demands - Help Net Security

5 Steps to Managing Shadow AI Tools Without Slowing Down Employees

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere - SecurityWeek

Anthropic's Mythos is evolving faster than expected, reports AI safety agency | ZDNET

Agentic AI opens the door to identity breach risk - CIR Magazine

ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks - Infosecurity Magazine

AI shrinks vulnerability exploitation window to hours - Help Net Security

Employee’s AI Shortcut Triggers SEC Filing — Boards, Take Note

Trump to sign order on AI oversight as security fears mount among supporters | Tacoma News Tribune

Linus Torvalds admits he has a 'love-hate relationship with AI' | ZDNET

AI can find bugs and flaws, but don't forget the cybersecurity basics

AI is drowning software maintainers in junk security reports - Help Net Security

British public deeply fearful of AI – with one-in-five even thinking it will lead to civil unrest | IT Pro

Agent AI is Coming. Are You Ready?

Bots/Botnets

Russian APT Turla builds long-term access tool with Kazuar Botnet evolution

Careers, Roles, Skills, Working in Cyber and Information Security

Upscale vs. Upskill: The Real Cybersecurity Gap

Cloud/SaaS

Tenable Warns AI Adoption Is Outpacing Governance As Cloud Exposure Risks Surge

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

US cyber agency CISA exposed reams of passwords and cloud keys to the open web

Microsoft Self-Service Password Reset abused in Azure data theft attacks

Google Cloud suspended major customer Railway.com without cause, causing outage

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them

Transit Finance hacked for $1.88 million

FBI: Americans lost over $388 million to scams using crypto ATMs in 2025

Cyber Crime, Organised Crime & Criminal Actors

Crime increasingly a ‘serious barrier’ to UK growth, say business leaders | Crime | The Guardian

When ransomware gets physical: cybercriminals turn to threats of violence

Cyber attacks drive £3.7bn in shareholder litigation costs for UK businesses, Gallagher research finds - Reinsurance News

TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks

B1ack's Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards - SecurityWeek

Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica

Most dark web activity revolves around a handful of topics - Help Net Security

Data Breaches/Leaks

US cyber agency CISA exposed reams of passwords and cloud keys to the open web

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

OpenAI caught in TanStack npm supply chain chaos after employee devices compromised

Hackers threaten to leak Mistral files online — AI giant confirms breach, but not what data is involved | TechRadar

Millions Impacted Across Several US Healthcare Data Breaches - SecurityWeek

Gîtes de France cyberattack: 389,000 clients affected in France booking data breach

Data Protection

ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks - Infosecurity Magazine

Data/Digital Sovereignty

AI infrastructure is cracking under sovereignty demands - Help Net Security

Poland builds its own Signal amid security concerns

Encryption

Microsoft backpedals: Edge to stop loading passwords into memory

Fraud, Scams and Financial Crime

B1ack's Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards - SecurityWeek

FBI: Americans lost over $388 million to scams using crypto ATMs in 2025

INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

201 arrested in INTERPOL disruption of phishing and fraud networks - Help Net Security

Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa | CyberScoop

Game over for 74 suspected scammers after Dutch cops plastered their faces on billboards - Help Net Security

How AI can trick you into making fake payments - 5 red flags | ZDNET

Identity and Access Management

Agentic AI opens the door to identity breach risk - CIR Magazine

Insider Risk and Insider Threats

Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica

Law Enforcement Action and Take Downs

INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

201 arrested in INTERPOL disruption of phishing and fraud networks - Help Net Security

Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa | CyberScoop

Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica

Game over for 74 suspected scammers after Dutch cops plastered their faces on billboards - Help Net Security

London's police asked Big Tech for comms data over 700,000 times last year

Linux and Open Source

Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

DirtyDecrypt: PoC Released for yet another Linux flaw

Debian 13.5 point release lands with security fixes, bug patches - Help Net Security

Linux kernel flaw opens root-only files to unprivileged users

Exploit released for new PinTheft Arch Linux root escalation flaw

Malware

Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them

Cybercrime service disrupted for abusing Microsoft platform to sign malware

Microsoft disrupts cybercrime service offering malware disguised as legitimate software - Nextgov/FCW

Microsoft disrupts alleged malware-signing operation used by ransomware gangs

Gremlin Stealer Evolves into Modular Threat - Infosecurity Magazine

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

First Shai-Hulud Worm Clones Emerge - SecurityWeek

New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain - Help Net Security

Russian APT Turla builds long-term access tool with Kazuar Botnet evolution

TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages - InfoQ

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

New Shai-Hulud malware wave compromises 600 npm packages

Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack - SecurityWeek

GitHub confirms breach of 3,800 repos via malicious VSCode extension

'This reveals a broader security problem': Experts warn a key Microsoft legacy tool is still being abused to launch malware campaigns | TechRadar

Ukraine identifies infostealer operator tied to 28,000 stolen accounts

Valve removes free horror game from Steam after players discover it contains malware that steals your data - PC Guide

Mobile

Mobile phishing is a bigger threat than email now - how to stay protected | ZDNET

Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices

Android Malware Used Fake Apps to Charge Users in Mass Billing Scam - Infosecurity Magazine

Outages

Alleged Huawei zero-day blamed for the 2025 Luxembourg telecom crash

Passwords, Credential Stuffing & Brute Force Attacks

Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them

US cyber agency CISA exposed reams of passwords and cloud keys to the open web

Microsoft backpedals: Edge to stop loading passwords into memory

Microsoft Self-Service Password Reset abused in Azure data theft attacks

You’re using a password manager, but you’re storing everything wrong

Regulations, Fines and Legislation

PYMNTS | UK Bills Target Late Payments and Cybersecurity Threats

MPs want social media treated more like unsafe toys than harmless apps

FCC walks back router update ban before it bricks America's network security

UK: The King’s Speech 2026 – Cybersecurity at the Forefront | DLA Piper - JDSupra

Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess

Trump to sign order on AI oversight as security fears mount among supporters | Tacoma News Tribune

Congress Puts Heat on Instructure After Canvas Outage

UK begins antitrust inquiry into Microsoft's business software ecosystem

Social Media

Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security

MPs want social media treated more like unsafe toys than harmless apps

Software Supply Chain

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility - SecurityWeek

TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages - InfoQ

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

New Shai-Hulud malware wave compromises 600 npm packages

Developer Workstations Are Now Part of the Software Supply Chain

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks

Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack - SecurityWeek

GitHub confirms breach of 3,800 repos via malicious VSCode extension

TeamPCP breached GitHub's internal codebase via poisoned VS Code extension - Help Net Security

Supply Chain and Third Parties

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility - SecurityWeek

Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

OpenAI caught in TanStack npm supply chain chaos after employee devices compromised

From exposure to assurance: how data signals are reshaping supply chain security

America’s Next National Security Supply Chain Crisis Is Already Starting






Vulnerability Management

Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector - SecurityWeek

Q&A: Why Vulnerability Scans Are Giving Businesses a False Sense of Security - IT Security Guru

AI shrinks vulnerability exploitation window to hours - Help Net Security

Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation

The Boring Stuff is Dangerous Now

Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’

Ouroboros of cybersecurity is confirmed as the AI vulnerability disclosure cycle eats itself | TechFinitive

AI is drowning software maintainers in junk security reports - Help Net Security

Windows Zero-Day Barrage Continues After Patch Tuesday

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility - SecurityWeek

Google's Surge in Chrome Vulnerability Discoveries Likely Driven by AI - SecurityWeek

Microsoft to automatically roll back faulty Windows drivers

Cyber Pros Can't Decide If AI Is a Good or a Bad Thing

AI can find bugs and flaws, but don't forget the cybersecurity basics

HackerOne takes an axe to its bug bounty rewards

Linus Torvalds admits he has a 'love-hate relationship with AI' | ZDNET

Vulnerabilities

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days - SecurityWeek

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

Windows Zero-Day Barrage Continues After Patch Tuesday

CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day

Microsoft rejects critical Azure vulnerability report, no CVE issued

New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released

Unpatched Windows zero-day from 2020 gives hackers full system access | PCWorld

Cisco warns of an actively exploited SD-WAN flaw with max severity | CSO Online

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Hackers bypass SonicWall VPN MFA due to incomplete patching

Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix

The 4th Linux kernel flaw this month can lead to stolen SSH host keys | ZDNET

Critical Linux Kernel Flaw 'ssh-keysign-pwn' Exposes SSH Keys and Shadow Passwords

Exploit available for new DirtyDecrypt Linux root escalation flaw

Exploitation of Critical NGINX Vulnerability Begins - SecurityWeek

Critical flaw in software powering a third of the internet is already being exploited - free checker now available - IT Security Guru

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

Security Researchers, Aided By Anthropic's Mythos, Claim To Have Breached macOS

Max-severity flaw in ChromaDB for AI apps allows server hijacking

Debian 13.5 point release lands with security fixes, bug patches - Help Net Security

Dell confirms its SupportAssist software causes Windows BSOD crashes

Chrome 148 Update Patches Critical Vulnerabilities - SecurityWeek

Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices

This Chrome flaw could hand hackers the keys to your browser

Google accidentally exposed details of unfixed Chromium flaw

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

'Claw Chain' OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery - SecurityWeek

TrendAI Patches Apex One Zero-Day Exploited in the Wild - SecurityWeek

Critical Wordpress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 15 May 2026

Black Arrow Cyber Threat Intelligence Briefing 15 May 2026:

-Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities

-NCSC and International Partners Warn of Agentic AI Risks

-Why Agentic AI Is Security's Next Blind Spot

-Over Half of MSPs Admit to Being Breached Multiple Times in Past Year

-Businesses Ask Non-Specialist Employees to Take On Cyber Security Tasks

-Poor Employee Awareness and Skills Gap Drive Cyber Security Breaches

-Increase in Email Attacks Driven by AI and Phishing-as-a-Service

-QR Code Phishing Was ‘Fastest-Growing’ Form of Email Attacks in Q1, Reports Microsoft Threat Intelligence

-Cyber Crime Increasingly Coming with Threats of Physical Violence

-The Evolution of Cyber Risk: Addressing Geopolitical Threats

-Europe Is Moving to Block Microsoft, Amazon, and Google from Handling Government Health, Financial, and Legal Data

-Britons Build ‘Emergency Stashes’ as Fears over Cyber-Attacks and Power Cuts Grow

-AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund

‍‍Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

‍ ‍Executive Summary

This week’s review of cyber security in the specialist and general media highlights the growing challenge of managing cyber risks due to AI alongside existing security practices. We consider the rapid emergence of agentic and AI-enabled capabilities that are expanding attack surfaces, introducing new vulnerabilities, and accelerating the scale and effectiveness of threats such as phishing and automated exploitation.

Alongside this, the human factor remains central. Social engineering and credential-based attacks continue to be primary entry points, and separately some organisations are allocating cyber risk management responsibilities to employees without training.

We include a report on cyber breaches affecting managed service providers (MSPs) and how economic pressure is influencing how organisations prioritise cyber security, even as breach rates and exposure continue to rise.

At Black Arrow, we consistently see that resilience depends on the organisation’s leadership and governance to align security across people, processes and technology. This week’s themes reinforce the need for organisations to take a balanced and pragmatic approach that evolves with both technological change and the broader threat landscape. Contact us to discuss how to achieve this.


Top Cyber Stories of the Last Week

Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities

Research into AI-built web applications has raised concerns about how quickly new tools can create business risk when security is not built in from the start. RedAccess reported finding 5,000 web apps created with AI development platforms that had little or no access protection, with 40% allegedly exposing sensitive information such as personal data, financial records and business plans. Several platform providers disputed parts of the findings, saying they lacked enough detail to verify the claims, but the issue highlights the need for governance over AI-created software.

https://uk.pcmag.com/ai/164858/vibe-coding-is-causing-thousands-of-data-security-vulnerabilities-says

NCSC and International Partners Warn of Agentic AI Risks‍ ‍

The UK’s NCSC and international partners have warned that agentic AI, which can act independently across systems and data, brings new risks for organisations. While it can help automate routine tasks, it may also behave unpredictably, expose connected systems to greater risk, or create uncertainty over accountability when things go wrong. The guidance recommends starting with low-risk uses, applying strict access controls, maintaining human oversight, and monitoring activity closely. Until standards mature, organisations should plan for resilience, containment, and the ability to reverse AI-driven actions quickly.‍ ‍

https://www.ukauthority.com/articles/ncsc-and-international-partners-warns-of-agentic-ai-risks

Why Agentic AI Is Security's Next Blind Spot‍ ‍

Agentic AI is already being used in many organisations to automate tasks, access data and take actions, often without security team involvement. The main risk is not the technology itself, but a lack of understanding and control over how these tools are built, what systems they can access and what actions they can take. As teams across the organisation create their own AI agents, permissions can quickly become too broad. Careful configuration, clear ownership and early security involvement are essential to limit exposure while still enabling useful innovation.

https://thehackernews.com/2026/05/why-agentic-ai-is-securitys-next-blind.html

Over Half of MSPs Admit to Being Breached Multiple Times in Past Year

CyberSmart’s 2026 MSP Survey shows that economic pressure is pushing cyber security down the agenda for many smaller businesses, with 46% of MSP customers more focused on rising costs and inflation than cyber risks. This comes despite 75% of MSPs reporting at least one breach in the past year, including 54% breached more than once. AI-enabled threats remain MSPs’ top concern at 49%. The findings indicate that economic pressure is influencing how organisations prioritise cyber security, despite continued exposure to repeated breaches and rising threat levels.‍ ‍

https://www.itsecurityguru.org/2026/05/13/over-half-of-msps-admitted-to-being-breached-multiple-times-in-past-year/

Businesses Ask Non-Specialist Employees to Take On Cyber Security Tasks‍ ‍

Small and medium sized organisations are increasingly relying on non-specialist staff to help manage cyber security, often without clear roles or limited training. Research commissioned by Uswitch Business Broadband found 43% of UK businesses reported a cyber security breach or attack in 2025, while over a third of employees with cyber security responsibilities said this was not part of their original job description. Training gaps remain significant, with 45% receiving only basic training and 16% receiving none. Nearly two-thirds said they had felt out of their depth at least sometimes, indicating gaps in capability as cyber security responsibilities extend beyond specialist roles.

https://www.personneltoday.com/hr/businesses-ask-non-specialist-employees-to-take-on-cybersecurity-tasks/

Poor Employee Awareness and Skills Gap Drive Cyber Security Breaches

Fortinet reports that poor employee awareness remains a major factor in security incidents, cited by 56% of cyber security and IT leaders, while 54% point to a shortage of trained professionals. Familiar attack methods continue to dominate, including malware at 39%, phishing at 36% and password-related breaches at 30%. Although 73% of organisations now see cyber security as a critical priority, only 59% dedicate sufficient budget. The impact is rising, with 52% reporting average losses from cyber incidents of more than $1 million.

https://petri.com/employee-awareness-skills-gap-cybersecurity-breaches/

Increase in Email Attacks Driven by AI and Phishing-as-a-Service

Barracuda Networks reports that AI-assisted deception and ready-made phishing services are increasing both the scale and success of email attacks. Analysis of more than 3.1 billion emails in January 2026 found that one in three messages were malicious or unwanted spam, with phishing making up 48% of malicious email activity. Attackers are increasingly using links and QR codes hidden in trusted document formats, with 70% of malicious PDFs containing QR codes leading to phishing websites. Account takeover also remains a frequent risk, affecting 34% of organisations at least monthly.

https://betanews.com/article/increase-in-email-attacks-driven-by-ai-and-phishing-as-a-service/

QR Code Phishing Was ‘Fastest-Growing’ Form of Email Attacks in Q1, Reports Microsoft Threat Intelligence

Microsoft Threat Intelligence reports that email phishing remains a major threat, detecting around 8.3 billion email-based phishing attempts between January and March 2026. QR code phishing was the fastest-growing method, rising from 7.6 million attacks in January to 18.7 million in March, a 146% increase. These attacks hide harmful links inside scannable codes, often in emails or attachments, to steal login details. Attackers also used fake CAPTCHA checks and confidentiality notices to make malicious emails appear more trustworthy.

https://www.thehindu.com/sci-tech/technology/qr-code-phishing-was-fastest-growing-form-of-email-attacks-in-q1-reports-microsoft-threat-intelligence/article70950498.ece

Cyber Crime Increasingly Coming with Threats of Physical Violence‍ ‍

Cyber criminals are increasingly combining cyber attacks with threats of physical violence to pressure victims into paying. Reported cyber crime in the US reached a record 1,008,597 cases in 2025, with losses rising to $20.8 billion, while UK cyber attacks also hit new highs. Research found that in up to 40% of global ransomware cases, criminals threatened to harm staff, rising to 46% in the US. Attackers are using stolen personal details, including home addresses, to intimidate employees, with some paying others to carry out threats or attacks.

https://www.bbc.co.uk/news/articles/cr71d8vyjv0o

The Evolution of Cyber Risk: Addressing Geopolitical Threats‍ ‍

Geopolitical tensions are reshaping cyber risk, with some attacks now focused on disruption and damage rather than financial gain. IBM has previously estimated that a single data breach can cost more than $4 million, while World Economic Forum research found 65% of respondents see supply chain and third-party weaknesses as their biggest barrier to cyber resilience. As third-party involvement in breaches continues to rise, organisations need tighter control over who can access critical systems, including suppliers and partners, and must plan for incidents where attackers have no incentive to stop.

https://informationsecuritybuzz.com/cyber-risk-addressing-geopolitical-threats/

Europe Is Moving to Block Microsoft, Amazon, and Google from Handling Government Health, Financial, and Legal Data

Europe is considering new rules that could restrict US cloud providers such as Microsoft, Amazon and Google from handling sensitive public sector data, including health, financial and legal records. The proposed Tech Sovereignty Package is aimed at strengthening Europe’s control over critical digital infrastructure and encouraging greater use of European cloud and AI providers. Private companies would remain free to choose their preferred platforms, but the move signals growing concern over reliance on overseas technology suppliers for essential government services.

https://www.techspot.com/news/112362-europe-may-restrict-microsoft-amazon-google-handling-sensitive.html

Britons Build ‘Emergency Stashes’ as Fears over Cyber-Attacks and Power Cuts Grow‍ ‍

New research from Link, the UK’s ATM network, suggests more households are preparing for everyday disruption linked to cyber attacks, power cuts and payment failures. Nearly one in five Britons now keep emergency cash at home, while 47% store tinned food, 49% have battery-powered items such as torches and 37% keep power banks for mobile phones. The trend reflects growing concern that essential services, including electricity, communications and digital payments, may not always be available during a major incident.

https://www.easterneye.biz/uk-emergency-stashes-cyber-attack-fears/

AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund

The IMF has warned that AI-powered cyber attacks could destabilise the global financial system by disrupting payments, weakening solvency and straining liquidity. The risk is heightened by financial firms’ reliance on shared cloud services, where one weakness can affect many organisations at once. The concern extends beyond banking, as finance, energy, telecoms and public services often depend on the same digital infrastructure. The IMF called for stronger international cooperation, better regulation and greater investment in resilience, including disaster recovery, business continuity and human oversight of AI-enabled security tools.

https://www.computerweekly.com/news/366642863/AI-cyber-attack-threatens-global-financial-crisis-warns-International-Monetary-Fund



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers - Infosecurity Magazine

Reviewing the trends in ransomware attacks in 2026 | Securelist

The State of Ransomware - Q1 2026 - Check Point Research

WannaCry, the ransomware attack that changed the history of cybersecurity‍ ‍

90% of ransomware attacks target SMEs: SK shieldus - The Korea Herald

Who are ShinyHunters? The 'Pay-or-Leak' Gang that Just Left the Canvas Hacked Platform Dark | IBTimes UK

Tables Turned: Gentlemen Ransomware Group Suffers Data Leak

Ransomware and Destructive Attack Victims‍ ‍

Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak

Who are ShinyHunters? The 'Pay-or-Leak' Gang that Just Left the Canvas Hacked Platform Dark | IBTimes UK

Ransomware Group Takes Credit for Trellix Hack - SecurityWeek

International cyber attack disrupts swath of universities and schools - BBC News

ShinyHunters claims nearly 9,000 schools affected by Canvas data breach | EdScoop

RansomHouse says it breached Trellix and exposes internal systems

Lapsus$ dumps Vodafone source code online after failed extortion attempt​ | Cybernews

Instructure claims hackers returned stolen Canvas data after an extortion standoff | CyberScoop

West Pharmaceutical says hackers stole data, encrypted systems

Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft

Ransomware hackers claim breach at Foxconn, a major electronics manufacturer for Apple, Google, and Nvidia | TechCrunch

Phishing & Email Based Attacks‍ ‍

QR code phishing was ‘fastest-growing’ form of email attacks in Q1, reports Microsoft Threat Intelligence - The Hindu

Over 500 Organizations Hit in Years-Long Phishing Campaign - SecurityWeek

When the Breach Gets In Through the CEO's Inbox, Not the Firewall - IT Security Guru

Increase in email attacks driven by AI and phishing-as-a-service - BetaNews

Tech Can't Stop These Threats — Your People Can

Other Social Engineering

QR code phishing was ‘fastest-growing’ form of email attacks in Q1, reports Microsoft Threat Intelligence - The Hindu

When the Breach Gets In Through the CEO's Inbox, Not the Firewall - IT Security Guru

Tech Can't Stop These Threats — Your People Can

Signal adds security warnings for social engineering, phishing attacks

Plymouth radio station closes after 'ruthless' cyber attack | Plymouth Live

Artificial Intelligence ‍ ‍

NCSC and international partners warns of agentic AI risks | UKAuthority‍ ‍

AI cyber attack threatens global financial crisis, warns International Monetary Fund | Computer Weekly

Artificial Intelligence And The End Of Digital Security As We Know It

Why Agentic AI Is Security's Next Blind Spot

PYMNTS | The End of the Artisanal Hack: How AI Industrialized Cybercr…

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits

Increase in email attacks driven by AI and phishing-as-a-service - BetaNews

Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities‍ ‍

AI bots account for more than half of all web traffic, with 40% classified as malicious | Engineering and Technology Magazine

Prepare for AI-driven patch correction - NCSC | UKAuthority

ECB Urges Banks to Quickly Prepare for AI-Assisted Cyberattacks

Why Cyber Insurance Faces New AI Liability Risks

Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking - SecurityWeek

Claude Code trust prompt can trigger one-click RCE

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoop‍ ‍

Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

AI Is Supercharging Cybercrime— And IMF Says Finance May Not Be Ready - Barclays (NYSE:BCS), CrowdStrike - Benzinga

Hackers abuse Google ads, Claude.ai chats to push Mac malware

UK schools blackmailed with sexualised AI deepfakes of pupils, experts warn | The Independent

Ollama vulnerability highlights danger of AI frameworks with unrestricted access | CSO Online

Hugging Face Packages Weaponized With a Single File Tweak

US bank reports itself after AI customer data mishap

Fighting fire with fire: Defending against Mythos-powered cyberattacks | resource | SC Media

What Security Leaders Say About the First AI-Developed Zero-Day Exploit | Security Magazine

Worries About AI’s Risks to Humanity Loom Over the Trial Pitting Musk Against OpenAI’s Leaders - SecurityWeek‍ ‍

White House considers implementing regulations on AI technology | The Jerusalem Post

Google Chrome 'silently' downloads 4GB AI model to your device without permission, report claims — researcher says practice may violate EU law, waste thousands of kilowatts of energy | Tom's Hardware

Experts say Mythos is not a threat, instead it is exposing how vulnerable enterprises already are

AI-Powered Cyberattacks Put MSSPs and SOC Teams Under Pressure | news | MSSP Alert

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

Attackers Use Fake OpenAI Model to Push Credential-Stealing Malware - Security Boulevard

Japan’s PM orders cybersecurity review to defend against Anthropic Mythos

The Mythos Moment: When Hacking Tools Move from “Functional Fixedness” to “Divergent Hacker Thinking” - Security Boulevard

Bots/Botnets ‍ ‍

AI bots account for more than half of all web traffic, with 40% classified as malicious | Engineering and Technology Magazine

NCSC warns of China-linked botnet attacks on UK targets

Careers, Roles, Skills, Working in Cyber and Information Security

The Critical Cyber Skills Every Security Team Still Needs

Computer Misuse Act reform to move forward in National Security Bill | Computer Weekly

UK moves to shield security researchers in cybercrime law overhaul | The Record from Recorded Future News

AI models are getting better at replacing cybersecurity pros on certain tasks

Cloud/SaaS

'PCPJack' cloud worm hijacks TeamPCP hacker infrastructure - iTnews

After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain ‍ ‍

Crypto gang member gets 6.5 years for role in $230 million heist

Why a 2017 Linux bug is now a major concern for the crypto industry

Cyber Crime, Organised Crime & Criminal Actors

Cyber-crime increasingly coming with threats of physical violence - BBC News

Cybersecurity is now where the real heists happen – but are companies ready? - Digital Journal

Cybercrime's Human Trafficking Problem - GovInfoSecurity

Kids as young as 8 are groomed into cybercrime through Minecraft and Roblox: Report - Dexerto

Data after the breach: Economics of the dark web | TechTarget

Police Shut Relaunched Crimenetwork Dark Web Marketplace - Infosecurity Magazine

Data Breaches/Leaks

Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak

One in four organizations have exposed MySQL databases - BetaNews

US bank reports itself after AI customer data mishap

Data after the breach: Economics of the dark web | TechTarget

UK water company allowed hackers to lurk undetected for nearly two years, regulator finds | The Record from Recorded Future News

UK fines water supplier $1.3M for exposing data of 664k customers

Dutch lab failed security standards before 850K breach​ | Cybernews‍ ‍

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft | Trend Micro (US)

Who are ShinyHunters? The 'Pay-or-Leak' Gang that Just Left the Canvas Hacked Platform Dark | IBTimes UK

Ransomware Group Takes Credit for Trellix Hack - SecurityWeek

Lapsus$ dumps Vodafone source code online after failed extortion attempt​ | Cybernews

Tables Turned: Gentlemen Ransomware Group Suffers Data Leak

Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident

Škoda Security Incident Exposes Customers Data From Online Shop

Identity security firm SailPoint discloses GitHub repository breach

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data

West Pharmaceutical says hackers stole data, encrypted systems

Data/Digital Sovereignty

Europe is moving to block Microsoft, Amazon, and Google from handling government health, financial, and legal data | TechSpot

Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads

Encryption ‍ ‍

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

60% of MD5 password hashes are crackable in under an hour

Instagram removed end-to-end encryption for DMs. What should users do?

Meta: Lawsuit Claiming WhatsApp Lacks End-to-End Encryption Is Falling Apart | PCMag

Your iPhone RCS chats with Android are encrypted in iOS 26.5: How to verify E2E is enabled | ZDNET

Apple, Google drag cross-platform texting into the encrypted age

Fraud, Scams and Financial Crime

Silent phone call scam in France: how AI voice theft can steal your identity

How AI job scams are destroying people’s hopes | Job hunting | The Guardian

How to detect AI in fraudulent job applicants - Raconteur

Sri Lanka makes 37 arrests as it raids another scam centre

Signal adds security warnings for social engineering, phishing attacks

Your Android phone is about to get much better at blocking scams - Digital Trends

Identity and Access Management

Why Changing Passwords Doesn’t End an Active Directory Breach

How Stealer Logs Lead to Active Directory Incidents

Insider Risk and Insider Threats

When the Breach Gets In Through the CEO's Inbox, Not the Firewall - IT Security Guru

Tech Can't Stop These Threats — Your People Can

Poor Employee Awareness and Skills Gap Drive Cybersecurity Breaches

Cybersecurity Without Awareness Is Like Driving Without Knowing The Rules

Wiping 96 US government databases after being fired may cost ex-hackers two decades in prison​ | Cybernews

Former govt contractor convicted for wiping dozens of federal databases

Insurance

Why Cyber Insurance Faces New AI Liability Risks

Cyber cover needs to get explicit as risk evolution continues unchecked

77 percent of SMEs don’t understand cyber insurance - BetaNews

Internet of Things – IoT

Police equipment can be tracked via Bluetooth. What about your phone, watch and headphones?

Hacking one shared IoT device (e-scooters, e-bikes, cars, chargers, etc.) to rule them all.

China-linked Yarbo fixes robot mower hacking flaw | Cybernews

Law Enforcement Action and Take Downs

Wiping 96 US government databases after being fired may cost ex-hackers two decades in prison​ | Cybernews

Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested - SecurityWeek

Crypto gang member gets 6.5 years for role in $230 million heist

Former govt contractor convicted for wiping dozens of federal databases

Sri Lanka makes 37 arrests as it raids another scam centre

Met Police Arrest 173 In Live Facial Recognition Trial | Silicon UK

Linux and Open Source

Dirty Frag is a new Linux bug putting your system at risk - and there's no easy fix yet | ZDNET‍ ‍

Dirty Frag: Linux kernel hit by second major security flaw in two weeks | The Record from Recorded Future News‍ ‍

Dirty Frag Exploit Poised to Blow Up on Enterprise Linux Distros

Rushed Patches Follow Broken Embargo on Linux Kernel Vulnerabilities - Infosecurity Magazine

Linux is getting a security wake-up call - why it was inevitable and I'm not worried | ZDNET

Why a 2017 Linux bug is now a major concern for the crypto industry

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

Malvertising

Hackers abuse Google ads, Claude.ai chats to push Mac malware

Malware is now hiding in Google search ads — here's how to protect yourself

Malware

After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets

PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems

Mistral AI and TanStack hit in supply chain attack with SLSA-attested malware - Cryptopolitan

Attackers Use Fake OpenAI Model to Push Credential-Stealing Malware - Security Boulevard

Worm rubs out competitor's malware, then takes control

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

Official JDownloader site served malware to Windows and Linux users between May 6 and May 7

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

Hackers abuse Google ads, Claude.ai chats to push Mac malware

Malware is now hiding in Google search ads — here's how to protect yourself

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

How Stealer Logs Lead to Active Directory Incidents‍ ‍

PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux

Official CheckMarx Jenkins package compromised with infostealer

Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor

Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware - SecurityWeek

Misinformation, Disinformation and Propaganda

The battle for the mind: How Europe can stay safe in the cognitive threat era – European Council on Foreign Relations

Mobile ‍ ‍

Android banking Trojan TrickMo evolves using TON network for C2

Signal adds security warnings for social engineering, phishing attacks

Your Android phone is about to get much better at blocking scams - Digital Trends

Your iPhone RCS chats with Android are encrypted in iOS 26.5: How to verify E2E is enabled | ZDNET

Apple, Google drag cross-platform texting into the encrypted age

Models, Frameworks and Standards

Mapping NIS2 controls to ISO 27001 and NIST CSF for UK SMEs - Security Boulevard

Here’s how NIST is teeing up guidance for securing AI | Federal News Network

What businesses need to know about the update to Cyber Essentials | IT Pro

UK government renews calls to sign Cyber Resilience Pledge | Computer Weekly

Government steps up action to strengthen cyber defences as UK cyber industry continues to grow - GOV.UK

Online Safety Act Failing To Deliver “step Change” For Children

Passwords, Credential Stuffing & Brute Force Attacks

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft | Trend Micro (US)

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

Why Changing Passwords Doesn’t End an Active Directory Breach

60% of MD5 password hashes are crackable in under an hour

Regulations, Fines and Legislation

Computer Misuse Act reform to move forward in National Security Bill | Computer Weekly

UK moves to shield security researchers in cybercrime law overhaul | The Record from Recorded Future News

2026 Kings Speech - New UK Cyber Security Laws and Broadband Rights for Leaseholders - ISPreview UK

US bank reports itself after AI customer data mishap

UK fines water supplier $1.3M for exposing data of 664k customers

ECB Urges Banks to Quickly Prepare for AI-Assisted Cyberattacks

Online Safety Act Failing To Deliver “step Change” For Children

White House considers implementing regulations on AI technology | The Jerusalem Post

Consultation: Proposals to update our General Statement of Policy under section 105Y of the Communications Act 2003

US govt seeks Instructure testimony on massive Canvas cyberattack

Social Media

Instagram removed end-to-end encryption for DMs. What should users do?

Supply Chain and Third Parties

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft | Trend Micro (US)

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack | CyberScoop

The Cybersecurity Gap No One Owns: You’re Securing The Wrong Perimeter

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft

Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Understanding the Cyber Security Fallout of Geopolitical Tensions

The Evolution Of Cyber Risk: Addressing Geopolitical Threats

Cyberattacks on Poland's Water Plants: A Blueprint for Hybrid Warfare - Security Affairs

Feds urge greater protection of critical infrastructure from Chinese hacks

Britons Build Emergency Stashes Amid Cyber Attack Fears | EasternEye

“Cyberwar is already in Poland,” Polish deputy prime minister says

The battle for the mind: How Europe can stay safe in the cognitive threat era – European Council on Foreign Relations

AI, Cyberwarfare, and Autonomous Weapons: Inside America’s New Military Strategy

Fresh Handala shenanigans prove Iranian hackers don’t care about any ceasefires​ | Cybernews

Cyber Espionage Group Targets Aviation Firms to Steal Map Data

Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia | Trend Micro (US)

Russian Attacks on Polish Water Utilities Use Fear as Weapon

Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign | SECURITY.COM

Nation State Actors

Understanding the Cyber Security Fallout of Geopolitical Tensions

The Evolution Of Cyber Risk: Addressing Geopolitical Threats

State-sponsored actors, better known as the friends you don’t want

Britons Build Emergency Stashes Amid Cyber Attack Fears | EasternEye

State-backed hackers hammer Palo Alto firewall zero-day before patch lands

China

NCSC warns of China-linked botnet attacks on UK targets

Feds urge greater protection of critical infrastructure from Chinese hacks

Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia | Trend Micro (US)

1 Campaign, 2 Targets: China’s Cyber Operations Hit Asian Governments and Dissidents Abroad – The Diplomat

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

Russia

Poland says hackers breached water treatment plants, and the US is facing the same threat | TechCrunch

Cyberattacks on Poland's Water Plants: A Blueprint for Hybrid Warfare - Security Affairs

“Cyberwar is already in Poland,” Polish deputy prime minister says

Russian Attacks on Polish Water Utilities Use Fear as Weapon

Inside Department 4: Russia's secret school for hackers

“Russia is already testing NATO”

Iran

Fresh Handala shenanigans prove Iranian hackers don’t care about any ceasefires​ | Cybernews

Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign | SECURITY.COM

Iran's cyberwar reaches the families of American troops - Asia Times

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Understanding the Cyber Security Fallout of Geopolitical Tensions

The Evolution Of Cyber Risk: Addressing Geopolitical Threats

Google and Amnesty International teamed up to make it harder for spyware vendors to hide | CyberScoop


Tools and Controls‍ ‍

Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities

Prepare for AI-driven patch correction - NCSC | UKAuthority

CISOs: Align cyber risk communication with boardroom psychology | CSO Online

How Stealer Logs Lead to Active Directory Incidents

Why Cyber Insurance Faces New AI Liability Risks

Cyber cover needs to get explicit as risk evolution continues unchecked

Poor Employee Awareness and Skills Gap Drive Cybersecurity Breaches

Cybersecurity Without Awareness Is Like Driving Without Knowing The Rules

Ollama vulnerability highlights danger of AI frameworks with unrestricted access | CSO Online

Fighting fire with fire: Defending against Mythos-powered cyberattacks | resource | SC Media

The Mythos Moment: When Hacking Tools Move from “Functional Fixedness” to “Divergent Hacker Thinking” - Security Boulevard

Why cyber resilience isn’t just a defence mechanism: How to create a secure foundation for innovation, too | IT Pro

Legacy Security Tools Are Failing Data Protection - Infosecurity Magazine

One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk

The patching treadmill: Why traditional application security is no longer enough | ZDNET

Day Zero Readiness: The Operational Gaps That Break Incident Response

Traditional MDR Is Reaching Its Limit | news | MSSP Alert

Experts say Mythos is not a threat, instead it is exposing how vulnerable enterprises already are

Japan’s PM orders cybersecurity review to defend against Anthropic Mythos

The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls

Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? - SecurityWeek

Daybreak is OpenAI's answer to the AI arms race in cybersecurity | CyberScoop

Your Android phone is about to get much better at blocking scams - Digital Trends

EU says OpenAI offers to open access to cybersecurity model, Anthropic not there yet - CNA

Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator

CISO's guide: How to test an incident response plan | TechTarget

94 percent of cyberattacks use VPNs or residential proxies - BetaNews



Vulnerability Management ‍

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits

Prepare for AI-driven patch correction - NCSC | UKAuthority

Ollama vulnerability highlights danger of AI frameworks with unrestricted access | CSO Online

Experts say Mythos is not a threat, instead it is exposing how vulnerable enterprises already are

The patching treadmill: Why traditional application security is no longer enough | ZDNET

What Security Leaders Say About the First AI-Developed Zero-Day Exploit | Security Magazine

Daybreak is OpenAI's answer to the AI arms race in cybersecurity | CyberScoop

Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks | CyberScoop

Linux is getting a security wake-up call - why it was inevitable and I'm not worried | ZDNET

Vulnerabilities

Microsoft Patch Tuesday May 2026 - 120 Vulnerabilities Fixed, Including 29 Critical RCE Flaws

Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises - SecurityWeek

Microsoft fixes Windows Autopatch bug installing restricted drivers

Windows BitLocker zero-day gives access to protected drives, PoC released

A security researcher says Microsoft secretly built a backdoor into BitLocker, releases an exploit to prove it | TechSpot

Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

Critical Palo Alto Networks software bug hits exposed firewalls | CSO Online

State-backed hackers hammer Palo Alto firewall zero-day before patch lands

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 - SecurityWeek

F5 Patches Over 50 Vulnerabilities - SecurityWeek

F5 patches 18-year-old AI-found 'Rift' vulnerability in NGINX web server - iTnews

SAP Patches Critical S/4HANA, Commerce Vulnerabilities - SecurityWeek

Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator

Dirty Frag is a new Linux bug putting your system at risk - and there's no easy fix yet | ZDNET

Dirty Frag: Linux kernel hit by second major security flaw in two weeks | The Record from Recorded Future News

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit

Another major Linux security issue uncovered - new Fragnesia flaw allows attackers to run malicious code as root | TechRadar

Adobe Patches 52 Vulnerabilities in 10 Products - SecurityWeek

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoop

Apple Patches Dozens of Vulnerabilities in macOS, iOS - SecurityWeek

Apple Alerted to macOS Security Vulnerability Uncovered With AI Tool - MacRumors

Broadcom releases VMware Fusion security update for root access bug

cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

New critical Exim mailer flaw allows remote code execution

New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

18-year-old NGINX vulnerability allows DoS, potential RCE

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations

Avada Builder Flaws Expose One Million WordPress Sites - Infosecurity Magazine

Over a million WordPress sites hit in plugin flaw — so patch now or face the consequences | TechRadar

Bug hunter tracks down three serious MCP database flaws, one left unpatched


Sector Specific ‍

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

·       Automotive

·       Construction

·       Critical National Infrastructure (CNI)

·       Defence & Space

·       Education & Academia

·       Energy & Utilities

·       Estate Agencies

·       Financial Services

·       FinTech

‍·       Food & Agriculture

·       Gaming & Gambling

·       Government & Public Sector (including Law Enforcement)

·       Health/Medical/Pharma

·       Hotels & Hospitality

·       Insurance

·       Legal

·       Manufacturing

·       Maritime & Shipping ‍

·       Oil, Gas & Mining

·       OT, ICS, IIoT, SCADA & Cyber-Physical Systems

·       Retail & eCommerce

·       Small and Medium Sized Businesses (SMBs)

·       Startups

·       Telecoms

·       Third Sector & Charities

·       Transport & Aviation ‍

·       Web3

‍ ‍

Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE. ‍

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 08 May 2026

Black Arrow Cyber Threat Intelligence Briefing 08 May 2026:

-Cyber is the Number One Global “People Risk,” Says Marsh

-Employees Are Now More Dangerous to Their Company than External Hackers

-Your Employees Know What Phishing Looks Like. They’re Still Getting Fooled. Here’s Why.

-Nearly Half of Initial Access Attacks Start with One Human Mistake

-86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds

-Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

-Researchers Discover New All-in-One ‘Bluekit’ Phishing Kit Capable of Bypassing Enterprise 2FA Protocols and Emulating 40+ Global Brands

-MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

-Only One in Nine Ransomware Attacks Is Made Public

-Five Eyes Spook Shops Warn Rapid Rollouts of Agentic AI Are Too Risky

-AI Speeds Flaw Discovery, Forcing Rapid Updates, UK NCSC Warns

-Bank Executives Cite Economy, Cyber Security Risks as Top Concerns

-North Korea Stole 76% of All Crypto Taken in 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

This week’s review of cyber security in the specialist and general media highlights employees and the risks they bring to their employer’s security. Research cited this week reports that cyber is the top global people risk, including employees sharing sensitive company information when using AI, and employees enabling attacks by falling for phishing emails and other malicious communications. At Black Arrow, we address this in our work with our clients, where we use our expertise and qualifications in HR and cyber security to strengthen the role that employees play in protecting their organisations.

In our review this week, we also look deeper at the evolution of ransomware, including toolkits used by attackers and insights into the prevalence of ransomware attacks. We further highlight the risks and misuse of AI, which has led bank executives to flag cyber security as their top risk.

At Black Arrow, we are consistent in our messaging that cyber security can only be achieved by aligned controls across people, operations and technology, as reinforced by insights from this week’s review. Contact us to discuss how to address this in a pragmatic way.


Top Cyber Stories of the Last Week

Cyber is the Number One Global “People Risk,” Says Marsh

Marsh’s 2026 People Risks report, based on interviews with more than 4,500 HR and risk professionals across 26 markets, ranks cyber related challenges as the leading global people risk. Weak cyber threat awareness, shortages in cyber and AI skills, poor understanding of AI risks and mishandling of data all feature in the top 10 concerns. These issues can increase the likelihood of cyber attacks, disrupt operations, damage trust and slow business progress, while 40% of respondents with effective people risk management initiatives reported improved workforce productivity, and 36% saw faster progress on strategic initiatives such as AI adoption.

https://www.infosecurity-magazine.com/news/cyber-number-one-global-people/

Employees Are Now More Dangerous to Their Company than External Hackers

Orange Cyberdefense reports that internal security risks now account for 57% of incidents, up from 47% in less than a year, overtaking external hacking for the first time. Employee misuse has risen sharply from 29% to 45%, often linked to unapproved tools such as public AI apps where sensitive information may be shared. Staff devices were involved in 53% of incidents, while identity attacks, where criminals use stolen login details, increased from 10% to 17%. Organisations should tighten access controls and multi-factor authentication to help reduce this growing risk.

https://www.techradar.com/pro/security/employees-are-now-more-dangerous-to-their-company-than-external-hackers

Your Employees Know What Phishing Looks Like. They’re Still Getting Fooled. Here’s Why.

AI is making phishing emails and messages harder to spot, with 72% of surveyed workers saying attempts are more convincing than a year ago and 66% believing AI could impersonate a colleague. The risk is not simply lack of training. Employees often recognise the warning signs, but still click or respond when rushing, multitasking or working after hours. Nearly 70% check work messages outside normal hours, increasing exposure when attention is lower. Organisations should review response expectations, approval processes and communication habits so staff have clear, normal opportunities to pause and verify unusual requests.

https://www.entrepreneur.com/science-technology/why-trained-employees-are-still-falling-for-phishing-attacks/504009

Nearly Half of Initial Access Attacks Start with One Human Mistake

Attackers are continuing to exploit everyday human behaviour, with ClickFix attacks accounting for 47% of initial access incidents observed over the past year. These attacks present users with a fake technical problem, such as a broken verification check or failed update, then guide them into running a harmful command that appears to fix it. The approach requires no advanced flaw or complex exploit, just pressure, trust and a desire to stay productive. For organisations, this highlights the need to treat human risk as a continuous cyber security priority, supported by monitoring for unusual user activity.

https://www.msspalert.com/perspective/nearly-half-of-initial-access-attacks-start-with-one-human-mistake

86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds

KnowBe4 reports that phishing is becoming more sophisticated, with 86% of attacks now AI driven. Over the past six months, calendar invite phishing rose by 49%, Microsoft Teams attacks increased by 41%, and the use of tools to steal Microsoft 365 login details surged by 139%. Attackers are also moving beyond email, using multiple channels at once and impersonating internal teams, seen in 30% of attacks in early 2026. This highlights a growing need to protect people, collaboration tools and AI systems together.

https://www.itsecurityguru.org/2026/05/01/86-of-phishing-attacks-are-ai-driven-knowbe4-research-finds/

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

A phishing campaign active since at least April 2025 has affected more than 80 organisations, mainly in the US, by tricking victims into installing legitimate remote access tools. The emails impersonated the US Social Security Administration and used compromised websites to avoid basic email filtering. Once installed, the tools gave attackers ongoing access to devices, including the ability to view screens, transfer files and return later. Because the software is legitimate and digitally signed, traditional security tools may not flag the activity as suspicious.

https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html

Researchers Discover New All-in-One ‘Bluekit’ Phishing Kit Capable of Bypassing Enterprise 2FA Protocols and Emulating 40+ Global Brands

Bluekit is a new phishing platform that makes it easier for criminals to launch convincing attacks at scale. It can imitate more than 40 global brands, automate campaign setup, alert attackers when data is stolen and use AI to draft tailored phishing emails. More concerningly, it can steal active browser sessions, which may allow attackers to bypass multi-factor authentication by appearing to be a legitimate user. Its rapid development reinforces the value of phishing-resistant authentication, such as hardware security keys, alongside regular staff awareness testing.

https://www.techradar.com/pro/security/researchers-discover-new-all-in-one-bluekit-phishing-kit-capable-of-bypassing-enterprise-2fa-protocols-and-emulating-40-global-brands

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

Rapid7 has linked a Microsoft Teams based credential theft campaign to Iranian state-backed attackers posing as a ransomware group. The incident used screen sharing and fake IT support tactics to trick staff into revealing passwords and approving multi-factor authentication requests. Rather than encrypting files, the attackers focused on stealing data and keeping long-term access through remote management tools. The case highlights a growing trend where state-linked groups use criminal ransomware brands and widely available cyber crime tools to hide their involvement and slow down response efforts.

https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html

Only One in Nine Ransomware Attacks Is Made Public

Ransomware appears to be significantly under-reported, with BlackFog identifying 2,160 undisclosed attacks in the first quarter, compared with just 264 publicly disclosed incidents. The average ransom demand exceeded $1 million, with victims across 97 countries. Healthcare was the most targeted sector, accounting for 27% of reported attacks, followed by government and technology. Logistics saw a 200% year-on-year increase. The findings also show that stolen data was involved in 96% of attacks, highlighting the growing risk of sensitive information being taken before disruption is even visible.

https://betanews.com/article/only-one-in-nine-ransomware-attacks-is-made-public/

Five Eyes Spook Shops Warn Rapid Rollouts of Agentic AI Are Too Risky

Five Eyes security agencies (UK, US, Canada, Australia and New Zealand) have warned that rapid adoption of agentic AI, where systems can take actions on behalf of users, could create new risks across critical infrastructure and defence. Their joint guidance highlights 23 risks and more than 100 recommended safeguards, noting that these systems often rely on multiple tools, data sources and permissions. If poorly controlled, they could be exploited to alter contracts, approve payments or delete audit records. Organisations are advised to adopt agentic AI gradually, starting with low-risk tasks and maintaining strong human oversight.

https://www.theregister.com/security/2026/05/04/five-eyes-warn-agentic-ai-is-too-dangerous-for-rapid-rollout/5229103

AI Speeds Flaw Discovery, Forcing Rapid Updates, UK NCSC Warns

The UK National Cyber Security Centre (NCSC) has warned that artificial intelligence is accelerating the discovery of weaknesses in software, increasing the likelihood of a surge in urgent security updates. Skilled attackers can now find and exploit flaws faster, creating pressure for organisations to update systems quickly across cloud, supplier and internal technology environments. Priority should be given to internet-facing systems, critical security tools and older technologies that no longer receive updates. Where possible, automatic updates should be enabled, supported by clear risk-based processes to decide what must be fixed first.

https://securityaffairs.com/191657/security/ai-speeds-flaw-discovery-forcing-rapid-updates-uk-ncsc-warns.html

Bank Executives Cite Economy, Cyber Security Risks as Top Concerns

Bank executives are increasingly concerned about economic uncertainty and cyber security risk, with IntraFi’s Q1 2026 survey of 409 US bank leaders finding 29% cited cyber security and fraud as their top concern for the year ahead. Many pointed to criminals’ growing use of artificial intelligence, where software can be used to create more convincing scams or automate attacks. A possible economic downturn was also a major worry, cited by 56% as either the biggest or second biggest concern.

https://www.prnewswire.com/news-releases/bank-executives-cite-economy-cybersecurity-risks-as-top-concerns-302762090.html

North Korea Stole 76% of All Crypto Taken in 2026

North Korea-linked hackers accounted for 76% of all cryptocurrency stolen by cyber criminals in 2026 up to the end of April, according to TRM Labs. Two attacks alone drained $577 million from decentralised finance platforms, despite representing only 3% of recorded incidents. The group has reportedly stolen more than $6 billion from crypto protocols since 2017, with its share of theft rising sharply each year. The incidents highlight the scale and sophistication of long‑planned intrusion activity, as well as weaknesses in complex digital finance platforms.

https://coinmarketcap.com/academy/article/north-korea-crypto-theft-76-percent-2026



Threats

Ransomware, Extortion and Destructive Attacks

Only one in nine ransomware attacks is made public - BetaNews

Ransomware victims increase 389 percent fueled by AI - BetaNews

Two new extortion crews are speedrunning the Scattered Spider playbook | CyberScoop

Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

Iranian cyber espionage disguised as a Chaos Ransomware attack

Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server

Cybersecurity pros jailed for ransomware attacks linked to ALPHV BlackCat | Cybernews

How safe is your money from cyber attack?

Conti, Akira ransomware affiliate given 8-year sentence | The Record from Recorded Future News

Karakurt Ransomware Negotiator Sentenced to Prison - SecurityWeek

Ransom Attacks up, but Payments Headed Down as Cyber Becomes Top of Mind

Five Years On: Lessons Learned From the Colonial Pipeline Cyber-Attack - Infosecurity Magazine

Member Of Russian Ransomware Group Sentenced To Prison – Eurasia Review

Two cybersecurity pros get prison time for helping ransomware gang - Help Net Security

Ransomware and Destructive Attack Victims

Five Years On: Lessons Learned From the Colonial Pipeline Cyber-Attack - Infosecurity Magazine

Instructure confirms data breach, ShinyHunters claims attack

Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats - SecurityWeek

Sandhills Medical Says Ransomware Breach Affects 170,000 - SecurityWeek

Ransomware group claims breach of pro-Orbán Hungarian media firm | The Record from Recorded Future News

Cushman & Wakefield confirms vishing cyberattack

DOJ says ransomware gang tapped into Russian government databases | TechCrunch

Phishing & Email Based Attacks

Over 35k users, 13k organisations hit in global phishing attack: Microsoft | Tech News - Business Standard

86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds - IT Security Guru

Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine

Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands | TechRadar

Email threat landscape: Q1 2026 trends and insights | Microsoft Security Blog

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard

'The inbox is no longer the only front line': Report claims vast majority of phishing attacks are now generated by AI - here's how to stay safe | TechRadar

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

QR code phishing surges 146% as Microsoft detects and analyzes 8.3 billion phishing threats in Q1 2026 – attackers are changing tactics to bypass security | TechRadar

Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails - Infosecurity Magazine

The Mimecast Portal BEC risk: how attackers stay in the inbox after a password reset | TechFinitive

30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign

Fake SSA Emails Drive Venomous#Helper Phishing Campaign - Infosecurity Magazine

Attackers Abuse Amazon SES to Send Authenticated Phishing Emails That Bypass Security

Education Sector Under Attack From State Espionage, Spear-Phishing, and Supply Chain Attacks

Business Email Compromise (BEC)/Email Account Compromise (EAC)

The Mimecast Portal BEC risk: how attackers stay in the inbox after a password reset | TechFinitive

Other Social Engineering

Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine

ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard

Nearly Half of Initial Access Attacks Start With One Human Mistake | perspective | MSSP Alert

QR code phishing surges 146% as Microsoft detects and analyzes 8.3 billion phishing threats in Q1 2026 – attackers are changing tactics to bypass security | TechRadar

Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

Hugging Face, ClawHub Abused for Malware Distribution - SecurityWeek

Fake background remover spreads password-stealing malware​ | Cybernews

You’ve hired a fraudulent employee. What comes next? | HR Dive

DigiCert breached via malicious screensaver file - Help Net Security

Romance fraudsters fleeced UK victims of £102M in 2025

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US)

ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog

Your job search is getting riskier, says LinkedIn - 9 ways to tell real listings from scams | ZDNET

Cushman & Wakefield confirms vishing cyberattack

2FA/MFA

ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard

Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands | TechRadar

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA

Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs | CSO Online

Artificial Intelligence

Five Eyes warn agentic AI is too dangerous for rapid rollout • The Register

86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds - IT Security Guru

New Bluekit phishing service includes an AI assistant, 40 templates

UK cyber security agency warns of AI-driven 'patch wave' - iTnews

Critical Infrastructure at Risk: Project Glasswing Urges Attention to AI-Driven Cyber-Risks | Epstein Becker & Green - JDSupra

The AI Vulnerability Storm Is Here. Is Your Security Program Breach Ready? - Security Boulevard

AI speeds flaw discovery, forcing rapid updates, UK NCSC warns

AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed - Infosecurity Magazine

Your AI Agents Are Already Inside the Perimeter. Do You Know What They're Doing?

UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK

If AI's So Smart, Why Does It Keep Deleting Production Databases?

AI digs up decades of code debt. Patch up. • The Register

Shadow AI risks deepen as 31% of users get no employer training - Help Net Security

We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is

Malicious OpenClaw DeepSeek Skill Exploits Agentic AI Workflows to Deliver RAT and Stealer

Hugging Face, ClawHub Abused for Malware Distribution - SecurityWeek

How safe is your money from cyber attack?

Cyber talent harder to find as AI reshapes threat landscape - CNA

Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn – POLITICO

Does Anthropic's Claude Mythos break the cyber insurance underwriting model? | Insurance Times

Malicious PyTorch Lightning update hits AI supply chain security

Mythos is 'very heightened risk': JPMorganChase's Jamie Dimon | American Banker

One in four MCP servers opens AI agent security to code execution risk - Help Net Security

Anthropic announces Claude Security public beta to find and fix software vulnerabilities  - SiliconANGLE

British mathematician hands OpenClaw agent a credit card

US and tech firms strike deal to review AI models for national security before public release | Technology | The Guardian

Why Chrome may have quietly downloaded a 4GB file to your PC - and how to get rid of it | ZDNET

Met Police face criticism for using AI to spy on their own officers - Help Net Security

AI-BOMs replace SBOMs as way to track AI agents and bots • The Register

India orders infosec red alert in case Mythos sparks crime

When AI Starts Making Decisions, Cybersecurity Becomes A Governance Issue | Scoop News

Careers, Roles, Skills, Working in Cyber and Information Security

CISOs step up to the security workforce challenge | CSO Online

‘We’re not investing as much as we should in their skills and development’: Skills shortages remain a key factor in security breaches — and things could get worse with AI in the equation | IT Pro

Cyber talent harder to find as AI reshapes threat landscape - CNA

Anthropic’s Mythos and the global cybersecurity gap - Rest of World

Skills Gap Top CISO Concern, Says New SANS Survey

Cloud/SaaS

ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard

Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

Azure AD Conditional Access Bypassed Through Phantom Device Registration and PRT Abuse

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

North Korea Stole 76% of All Crypto Taken in 2026 | CoinMarketCap

Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring

Police dismantles 9 crypto scam centers, arrests 276 suspects

Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M

New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware

Cyber Crime, Organised Crime & Criminal Actors

Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring

Police dismantles 9 crypto scam centers, arrests 276 suspects

Europol Busts Albanian Scam Call Centers in Major Online Fraud Case - Infosecurity Magazine

French prosecutors link 15-year-old to gov mega-breach • The Register

Data Breaches/Leaks

French prosecutors link 15-year-old to gov mega-breach • The Register

Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats

Trellix Source Code Breach Highlights Supply Chain Threats

Instructure hacker claims data theft from 8,800 schools, universities

Police statement 10 months after Glasgow City Council cyber attack | Glasgow Times

A DOD contractor’s API flaw exposed military course data and service member records | CyberScoop

Sandhills Medical Says Ransomware Breach Affects 170,000 - SecurityWeek

Denial of Service/DoS/DDoS

Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack

New Cisco DoS flaw requires manual reboot to revive devices

Encryption

Agent’s claims on WhatsApp access spark security concerns

What to Know About Quantum Computing and Your Cybersecurity Progr

Fraud, Scams and Financial Crime

Romance fraudsters fleeced UK victims of £102M in 2025

Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring

You’ve hired a fraudulent employee. What comes next? | HR Dive

Police dismantles 9 crypto scam centers, arrests 276 suspects

Europol Busts Albanian Scam Call Centers in Major Online Fraud Case - Infosecurity Magazine

Hackers drove through Toronto with fake cell towers, quietly hijacking thousands of phones and disrupting millions of connections in plain sight | TechRadar

Your job search is getting riskier, says LinkedIn - 9 ways to tell real listings from scams | ZDNET

Insider Risk and Insider Threats

1 in 8 workers say selling company logins is justifiable

You’ve hired a fraudulent employee. What comes next? | HR Dive

Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine

Employees are now more dangerous to their company than external hackers | TechRadar

Nearly Half of Initial Access Attacks Start With One Human Mistake | perspective | MSSP Alert

Why Trained Employees Are Still Falling for Phishing Attacks

Insurance

How cyber insurance helped with breach recovery -- or not | TechTarget

Does Anthropic's Claude Mythos break the cyber insurance underwriting model? | Insurance Times

Law Enforcement Action and Take Downs

US ransomware negotiators get 4 years in prison over BlackCat attacks

Police dismantles 9 crypto scam centers, arrests 276 suspects

Europol Busts Albanian Scam Call Centers in Major Online Fraud Case - Infosecurity Magazine

French prosecutors link 15-year-old to gov mega-breach • The Register

Cyber incident responders who carried out ransomware attacks given 4-year sentences | The Record from Recorded Future News

A Ransomware Negotiator Was Working for a Ransomware Gang - Schneier on Security

Conti, Akira ransomware affiliate given 8-year sentence | The Record from Recorded Future News

Karakurt Ransomware Negotiator Sentenced to Prison - SecurityWeek

Police statement 10 months after Glasgow City Council cyber attack | Glasgow Times

Member Of Russian Ransomware Group Sentenced To Prison – Eurasia Review

Two cybersecurity pros get prison time for helping ransomware gang - Help Net Security

Russian hacker pleads guilty to cyberattacks on US, Ukrainian oil and gas facilities

Linux and Open Source

CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments | Microsoft Security Blog

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) - Help Net Security

The Evolution of Open Source Malware: From Volume to Trust Abuse

Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack

New stealthy Quasar Linux malware targets software developers

Malware

Malicious OpenClaw DeepSeek Skill Exploits Agentic AI Workflows to Deliver RAT and Stealer

Hugging Face, ClawHub Abused for Malware Distribution - SecurityWeek

Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs | CSO Online

Fake background remover spreads password-stealing malware​ | Cybernews

ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog

New Deep#Door RAT uses stealth and persistence to target Windows

1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom - SecurityWeek

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack - Ars Technica

The Evolution of Open Source Malware: From Volume to Trust Abuse

New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware

New stealthy Quasar Linux malware targets software developers

New MicroStealer Malware Actively Attacking Telecom & Education Sectors

China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

North Korean APT Targets Yanbian Gamers via Trojanized Platform - Infosecurity Magazine

Mobile

Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA

Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs | CSO Online

New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware

Hackers drove through Toronto with fake cell towers, quietly hijacking thousands of phones and disrupting millions of connections in plain sight | TechRadar

Critical Android vulnerability CVE-2026-0073 fixed by Google

Critical Android Zero-Click Vulnerability Grants Remote Shell Access

Passwords, Credential Stuffing & Brute Force Attacks

1 in 8 workers say selling company logins is justifiable

Fake background remover spreads password-stealing malware​ | Cybernews

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch

The Passwordless Future Has a Password Problem - Security Boulevard

Syncing passkeys to Google defeats the whole point of passkeys

I'm a cyber security expert - 60% of the public are making this dangerous mistake

Regulations, Fines and Legislation

Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn – POLITICO

Kids can bypass some age checks with a drawn-on mustache • The Register

UK age-gating plans risk breaking the internet, privacy groups warn

Brussels reissues its Huawei warning, and prepares to make it stick

US lists offensive cyberattacks in counterterrorism strategy - Nextgov/FCW

Social Media

30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign

Vimeo confirms breach via third-party vendor impacts 119K users

Supply Chain and Third Parties

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack - Ars Technica

UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK

1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom - SecurityWeek

Trellix Source Code Breach Highlights Supply Chain Threats

DigiCert breached via malicious screensaver file - Help Net Security

Vimeo confirms breach via third-party vendor impacts 119K users

A DOD contractor’s API flaw exposed military course data and service member records | CyberScoop

Instructure Breach Exposes Schools' Vendor Dependence

Education Sector Under Attack From State Espionage, Spear-Phishing, and Supply Chain Attacks


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

MuddyWater hackers use Chaos ransomware as a decoy in attacks

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

Russian cyberattacks against Ukraine may be considered war crimes - CCD | УНН

War is not just missiles, defence experts warn Britons

How Iranian Cyber Intrusions Unfold Inside Enterprise Networks

Small Defense Firms Lack Network Data to Stop Nation-State Hackers - Infosecurity Magazine

Nation State Actors

Small Defense Firms Lack Network Data to Stop Nation-State Hackers - Infosecurity Magazine

China

FBI: China's hacker-for-hire ecosystem 'out of control' • The Register

China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists

Brussels reissues its Huawei warning, and prepares to make it stick

Chinese spy group caught lurking in Poland, Asia networks • The Register

Police dismantles 9 crypto scam centers, arrests 276 suspects

Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M

China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

EU moves to ban high-risk inverters from China over cybersecurity threats | Euronews

Russia

Russian cyberattacks against Ukraine may be considered war crimes - CCD | УНН

Cyber spies target Russian aviation firms to steal satellite and GPS data | The Record from Recorded Future News

Russian hacker pleads guilty to cyberattacks on US, Ukrainian oil and gas facilities

DOJ says ransomware gang tapped into Russian government databases | TechCrunch

Russia disrupts mobile internet as Kremlin scales back Victory Day parade | The Independent

The Kremlin has been throttling the internet and blaming security threats. Many Russians aren't buying it | CBC News

North Korea

North Korea Stole 76% of All Crypto Taken in 2026 | CoinMarketCap

You’ve hired a fraudulent employee. What comes next? | HR Dive

North Korea calls US cyber threat claims a fabrication, warns of countermeasures | San Luis Obispo Tribune

North Korean APT Targets Yanbian Gamers via Trojanized Platform - Infosecurity Magazine

Iran

Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

Iranian cyber espionage disguised as a Chaos Ransomware attack

How Iranian Cyber Intrusions Unfold Inside Enterprise Networks

Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Ransomware group claims breach of pro-Orbán Hungarian media firm | The Record from Recorded Future News

FBI: China's hacker-for-hire ecosystem 'out of control' • The Register


Tools and Controls

Exclusive-US officials weigh cutting deadlines to fix digital flaws amid worries over AI-powered hacking, sources say - CNA

UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK

US ransomware negotiators get 4 years in prison over BlackCat attacks

How cyber insurance helped with breach recovery -- or not | TechTarget

Azure AD Conditional Access Bypassed Through Phantom Device Registration and PRT Abuse

AI digs up decades of code debt. Patch up. • The Register

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

RMM Tools Fuel Stealthy Phishing Campaign

Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha

Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots

Security’s Blind Spot: The Threats Hiding In “Low-Severity” Alerts

The Passwordless Future Has a Password Problem - Security Boulevard

Mythos is 'very heightened risk': JPMorganChase's Jamie Dimon | American Banker

India orders infosec red alert in case Mythos sparks crime

When AI Starts Making Decisions, Cybersecurity Becomes A Governance Issue | Scoop News

Amazon SES increasingly abused in phishing to evade detection

How CISOs should utilize data security posture management to inform risk | CSO Online

Understanding Digital Forensics After A Cyber Incident

Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn – POLITICO

Anthropic announces Claude Security public beta to find and fix software vulnerabilities  - SiliconANGLE

US and tech firms strike deal to review AI models for national security before public release | Technology | The Guardian

Microsoft fixes Remote Desktop warnings displaying incorrectly

Tape's strategic role in modern data protection | TechTarget

After dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, too | TechCrunch

Financial Services Industry Collaborates to Test Real-World Cyber Readiness



Vulnerability Management

Exclusive-US officials weigh cutting deadlines to fix digital flaws amid worries over AI-powered hacking, sources say - CNA

The AI Vulnerability Storm Is Here. Is Your Security Program Breach Ready? - Security Boulevard

AI speeds flaw discovery, forcing rapid updates, UK NCSC warns

AI digs up decades of code debt. Patch up. • The Register

Security’s Blind Spot: The Threats Hiding In “Low-Severity” Alerts

Oracle Debuts Monthly Critical Security Patch Updates - SecurityWeek

Why every organization should make it easy to report security flaws

Vulnerabilities

cPanel zero-day exploited for months before patch release (CVE-2026-41940) - Help Net Security

Over 40,000 Servers Compromised in Ongoing cPanel Exploitation - SecurityWeek

Critical cPanel exploited: 'Millions' of sites could be hit • The Register

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

Exploit Cyber-Frenzy Threatens Millions via cPanel Vulnerability

Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940

MOVEit automation flaws could enable full system compromise

Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks - SecurityWeek

Ivanti customers confront yet another actively exploited zero-day | CyberScoop

Cisco Patches High-Severity Vulnerabilities in Enterprise Products - SecurityWeek

SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now

Linux 'Copy Fail' flaw lets anyone hijack system privileges. Update ASAP | PCWorld

'Copy Fail' is a real Linux security crisis wrapped in AI slop | CyberScoop

New Linux 'Dirty Frag' zero-day gives root on all major distros

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) - Help Net Security

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Google Chrome 148 Released with 127 Security Fixes, Three Critical Vulnerabilities Patched

Apache fixes critical HTTP/2 double-free flaw CVE-2026-23918 enabling RCE

New Cisco DoS flaw requires manual reboot to revive devices

Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover - SecurityWeek

vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

Weaver E-cology critical bug exploited in attacks since March

Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft - SecurityWeek

Malicious PyTorch Lightning update hits AI supply chain security

Critical Android Zero-Click Vulnerability Grants Remote Shell Access


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

·       Automotive

·       Construction

·       Critical National Infrastructure (CNI)

·       Defence & Space

·       Education & Academia

·       Energy & Utilities

·       Estate Agencies

·       Financial Services

·       FinTech

·       Food & Agriculture

·       Gaming & Gambling

·       Government & Public Sector (including Law Enforcement)

·       Health/Medical/Pharma

·       Hotels & Hospitality

·       Insurance

·       Legal

·       Manufacturing

·       Maritime & Shipping

·       Oil, Gas & Mining

·       OT, ICS, IIoT, SCADA & Cyber-Physical Systems

·       Retail & eCommerce

·       Small and Medium Sized Businesses (SMBs)

·       Startups

·       Telecoms

·       Third Sector & Charities

·       Transport & Aviation

·       Web3

Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

 

Read More
Black Arrow Admin Black Arrow Admin

Black Arrow Cyber Threat Intelligence Briefing 01 May 2026

Black Arrow Cyber Threat Intelligence Briefing 01 May 2026:

-Cyber Attacks Now the Top Operational Risk for 60% of Financial Organisations

-Get Ready to be Attacked - NCSC

-UK Cyber Essentials Overhaul Could Trigger Instant Certification Failures

-Cyber Threat Literacy, AI Disruption Top Risks to an Organisation’s People

-AI Rush Is Reviving Old Cyber Security Mistakes, Mandiant VP Warns

-Deepfake Era Demands Proof-Based Security, Not Just Awareness

-Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

-Over 2.8 Billion Credentials Stolen in 2025 as Ransomware Evolves

-A Sneaky Cyber Enemy Is Creeping into Our Browsers and Password Managers

-The Behavioural Shift: Why Trusted Relationships Are the Newest Attack Surface

-Threat Actors Ditch ‘Spray and Pray’ Attacks in Shift to Targeted Exploitation

-A Dozen Allied Agencies Say China Is Building Covert Hacker Networks out of Everyday Routers

-What’s Behind Europe’s Efforts to Ditch US Software in Favour of Sovereign Tech

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

As reported cyber attacks continue to rise, it is unsurprising that business leaders see cyber risk as their top threat. This week’s research shows that 60% of financial services organisations view cyber attacks and outages as their biggest operational risk, alongside the UK Government urging organisations to prepare to manage and operate during cyber disruption. We also highlight changes to the UK Government’s Cyber Essentials scheme, which now emphasise ongoing control rather than point‑in‑time assessment and could see some certificate holders fail on reassessment.

Artificial intelligence is also increasing cyber risk, through factors such as inadequate cyber threat literacy among employees and the amplification of insufficient cyber hygiene, as well as accelerating the pace at which vulnerabilities are identified and exploited. We report on striking figures, including more than 2.8 billion credentials stolen last year; a sharp rise in infostealer malware on Apple macOS devices; and the continued prevalence of phishing and third‑party attacks. Finally, we examine wider developments, from China’s use of covert hacker networks to European efforts to strengthen data and technology sovereignty.

The way to manage the impact of these developments requires a sound business leadership understanding of risks and how to maintain proportionate controls that enable the organisation to grow. Contact us to discuss how to achieve this.


Top Cyber Stories of the Last Week

Cyber Attacks Now the Top Operational Risk for 60% of Financial Organisations

A survey of around 150 senior compliance experts found that 60% of financial services organisations now see cyber attacks or system outages as their biggest operational risk this year, far ahead of supply chain disruption or staff shortages at 10%. While most say their organisation has measures in place to manage the risk, 13% are not confident in their ability to address disruption. The findings also highlight concern that criminals are using artificial intelligence faster than firms and regulators can respond, signalling to business leaders the need for sustained vigilance and continuous improvement as cyber threats evolve in scale and sophistication.

https://www.techcentral.ie/cyberattacks-now-the-top-operational-risk-for-60-of-financial-organisations/

Get Ready to be Attacked - NCSC

The UK’s National Cyber Security Centre (NCSC) has warned that UK organisations of national significance, including financial services, health, energy and transport, face a growing risk from severe cyber threats that could disrupt essential services, cause financial loss and affect public safety. It says advanced attackers are increasingly targeting nationally significant organisations, while technologies such as frontier AI may increase the speed and scale of attacks. The guidance highlights that cyber resilience is a leadership responsibility, requiring critical systems to be mapped, disruption plans tested, and recovery arrangements rehearsed before an incident occurs.

https://www.ukauthority.com/articles/get-ready-to-be-attacked-ncsc

UK Cyber Essentials Overhaul Could Trigger Instant Certification Failures

Changes to the UK Cyber Essentials scheme that tighten enforcement and widen scope could increase the risk of instant certification failure for organisations with inconsistent day‑to‑day controls. Failing to apply high-risk or critical security updates and patches within 14 days can now trigger automatic failure. Enforcement of multi‑factor authentication is also applied more strictly across cloud services where MFA is available, while the updated scope clarifies that cloud services hosting organisational data or services cannot be excluded. This increases the likelihood that overlooked systems, legacy applications or active but overlooked accounts create compliance gaps. For business leaders, the update highlights that Cyber Essentials is increasingly a test of ongoing operational discipline rather than a point‑in‑time exercise.

https://betanews.com/article/uk-cyber-essentials-overhaul-could-trigger-instant-certification-failures/

Cyber Threat Literacy, AI Disruption Top Risks to an Organisation’s People

Marsh’s 2026 People Risks report identifies insufficient cyber threat literacy as the leading people risk for organisations, reflecting the continued role of human error in cyber losses. Phishing and social engineering continue to succeed by tricking employees into disclosing log‑in details, enabling ransomware attacks and data breaches. The report also warns that rapid adoption of artificial intelligence without adequate employee training is increasing risk. For business leaders, the findings highlight that cyber resilience depends as much on leadership-led training, communication and support for employees as on technology investments.

https://www.insurancejournal.com/news/national/2026/04/30/867782.htm

AI Rush Is Reviving Old Cyber Security Mistakes, Mandiant VP Warns

Mandiant has warned that rapid AI adoption is causing organisations to overlook basic cyber security controls. Its testing teams, who simulate real attacker behaviour, found AI environments where attackers could alter data classifications, bypass data loss prevention tools that stop sensitive information leaving the business, and use unencrypted communication links. In some cases, once initial access was gained through social engineering, where people are manipulated into granting access, AI systems carried out further actions including data theft and policy changes. Mandiant’s warning highlights the need for governance, secure design and independent testing that keeps pace with AI deployment.

https://www.infosecurity-magazine.com/news/ai-old-cybersecurity-mistakes/

Deepfake Era Demands Proof-Based Security, Not Just Awareness

Deepfake and voice cloning attacks are making it harder for employees to trust what they see or hear, particularly when requests appear to come from senior executives. Research found that 77% of fraud professionals say deepfake attacks are increasing, yet only 7% believe their organisations are well prepared. High-risk actions, such as payments, password resets or access changes, should rely on agreed verification steps through trusted channels, not on a single call, video meeting or message. This reduces pressure on staff and makes fraud prevention a consistent business process.

https://www.techtarget.com/searchsecurity/feature/Deepfake-era-demands-proof-based-security-not-just-awareness

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

AI tools such as Anthropic’s Claude Mythos Preview could significantly increase the speed and scale of vulnerability discovery, exposing flaws faster than traditional testing approaches. However, faster discovery risks overwhelming organisations that lack clear ownership, centralised tracking and consistent prioritisation of remediation efforts. Without effective processes to assign responsibility, assess business impact and verify that fixes have been applied, organisations may simply accumulate a larger backlog of unresolved security issues. The findings highlight that operational readiness for remediation has not kept pace with advances in AI‑driven vulnerability discovery.

https://thehackernews.com/2026/04/mythos-changed-math-on-vulnerability.html

Over 2.8 Billion Credentials Stolen in 2025 as Ransomware Evolves

A report identified 2.86 billion compromised credentials in 2025, with business cloud and login services accounting for more than 30% of exposed data. Attackers are increasingly logging in using stolen credentials rather than exploiting technical weaknesses. The report also highlights risks from unsanctioned AI tools, where employees may unknowingly expose confidential data, and a sharp rise in infostealer malware on Apple macOS devices, from fewer than 1,000 cases in 2024 to over 70,000 in 2025. Ransomware activity remains highly active, with 147 groups recorded. The findings highlight identity compromise, unsanctioned AI use and reliance on legacy defences as central factors shaping the evolving ransomware threat.

https://betanews.com/article/over-2-8-billion-credentials-stolen-in-2025-as-ransomware-evolves/

A Sneaky Cyber Enemy Is Creeping into Our Browsers and Password Managers

KELA reports that almost 4 million devices were exposed to infostealer malware last year, leading to around 350 million compromised login details. Infostealers are malicious tools that quietly collect sensitive data such as browser cookies, passwords and local files, often without obvious signs on the device. Windows users remain heavily targeted, but attacks on Apple devices are rising as adoption grows in corporate environments. The risk is significant because stolen browser sessions can sometimes let criminals access accounts without needing a password or multi-factor authentication.

https://cybernews.com/security/a-sneaky-cyber-enemy-is-creeping-into-our-browsers-and-password-managers/

The Behavioural Shift: Why Trusted Relationships Are the Newest Attack Surface

An analysis of almost 800,000 email attacks across more than 4,600 organisations shows how attackers exploit trust and routine business processes rather than technical weaknesses. Phishing remains the most common method at 58% of attacks, and business email compromise 11%. Over 20% of phishing attacks hide harmful web pages behind redirect chains. Invoice fraud accounts for 42% of campaigns in North America and procurement related scams 41% in EMEA. The findings highlight that trusted workflows and supplier interactions have become a key attack surface, reinforcing the need for verification controls within routine business processes.

https://www.securityweek.com/the-behavioral-shift-why-trusted-relationships-are-the-newest-attack-surface/

Threat Actors Ditch ‘Spray and Pray’ Attacks in Shift to Targeted Exploitation

Cyber criminals are moving away from broad, high-volume  ‘spray and pray’ attacks and focusing on fewer organisations where they can cause greater disruption. SonicWall reported a 20% rise in compromised UK organisations last year, despite overall ransomware volumes falling by 87%. Smaller businesses appear especially exposed, with ransomware involved in 88% of SMB breaches compared with 39% for larger enterprises. Outdated technology remains a major risk, with one decade-old camera weakness linked to 67 million attempted UK attacks. AI-enabled attacks also rose by 89%, while attackers can remain undetected for an average of 181 days.

https://www.itpro.com/security/cyber-attacks/threat-actors-ditch-spray-and-pray-attacks-in-shift-to-targeted-exploitation

A Dozen Allied Agencies Say China Is Building Covert Hacker Networks out of Everyday Routers

Allied cyber agencies have warned that China-linked hackers are increasingly using everyday devices, including home office routers and smart devices, to build hidden networks for cyber attacks. These networks disguise where activity is coming from and can support spying, malware delivery and information theft. One example, known as Raptor Train, infected 200,000 devices worldwide. The warning highlights China‑linked hackers are moving away from running their own small, dedicated attack servers, and instead are hijacking vast numbers of ordinary internet‑connected devices to form large, hidden attack networks. This makes detection harder and reinforces the need for strong device management, monitoring and basic cyber security controls.

https://cyberscoop.com/china-nexus-covert-networks-advisory/

What’s Behind Europe’s Efforts to Ditch US Software in Favour of Sovereign Tech

European governments are reassessing dependence on US technology as concerns grow over data access, legal control and resilience. US federal law, called the 2018 CLOUD Act, means US providers may be required to hand over data even when it is stored overseas, increasing worries around sensitive information such as health records. France is moving its Health Data Hub from Microsoft Azure to a sovereign cloud provider, while the European Commission has awarded a €180 million tender to European cloud firms. However, alternatives still face scale and adoption challenges, particularly where private sector buyers continue to favour established US providers.

https://techcrunch.com/2026/04/27/whats-behind-europes-efforts-to-ditch-u-s-software-in-favor-of-sovereign-tech/


Governance, Risk and Compliance

Get ready to be attacked - NCSC | UKAuthority

Beazley finds growing gap between business confidence and cyber resilience as risks intensify - Reinsurance News

Cyber threats challenge global business resilience

Cyber Attacks Emerge As Top Risk For Professional Firms In 2026 - Minutehack

Cyber attacks now the top operational risk for 60% of financial organisations - TechCentral.ie

Cyber Insurance Data Gives CISOs New Ammo for Budget Talks - SecurityWeek

Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People

The cyber security of British business is a matter of national security - Dan Jarvis

Insurance CROs flag cybersecurity as top risk while AI and data investment surge, EY/IIF survey finds - Reinsurance News

Nearly half of cybersecurity pros want to quit - here's why | ZDNET

Cybersecurity professional getting more work and less pay • The Register

Threats

Ransomware, Extortion and Destructive Attacks

Floppy to Mythos, how ransomware grew into multibillion-dollar industry | Tech News - Business Standard

Trigona ransomware attacks use custom exfiltration tool to steal data

Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitation | IT Pro

Feuding Ransomware Groups Leak Each Other's Data

New BlackFile extortion group linked to surge of vishing attacks

RAMP Uncovered: Anatomy of Russia’s Ransomware Marketplace

ShinyHunters exploit Anodot incident to target Vimeo

Critical Flaw Turns Vect Ransomware into Data Destroying Wiper - Infosecurity Magazine

Do not pay VECT ransom: recovery is impossible​ | Cybernews

Scattered Spider co-conspirator pleads guilty | CSO Online

Ransomware and Destructive Attack Victims

Udemy Data Breach - ShinyHunters Claims Compromise of 1.4M User Records

Over 2.8 billion credentials stolen in 2025 as ransomware evolves - BetaNews

ADT confirms data breach after ShinyHunters leak threat

ShinyHunters claim they have cruise giant Carnival’s booty • The Register

Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica

Medtronic Confirms Data Breach After ShinyHunters Claims - Infosecurity Magazine

Ransomware attacks affect 2 senior care providers

Pitney Bowes the latest victim of ShinyHunters’ breach-spree • The Register

Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of "Highly Destructive" Wiper

Phishing & Email Based Attacks

AI Phishing Is No. 1 With a Bullet for Cyberattackers

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek

7 Reasons Smishing Is More Effective Than Phishing

'This campaign works because it feels ordinary': Experts reveal how hackers use fake DHL messages to lure in victims | TechRadar

Robinhood account creation flaw abused to send phishing emails

Kuse Web App Abused to Host Phishing Document | Trend Micro (US)

Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software

Business Email Compromise (BEC)/Email Account Compromise (EAC)

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek

Other Social Engineering

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek

7 Reasons Smishing Is More Effective Than Phishing

Crime crew impersonates help desk, abuses Teams chats • The Register

Threat actor uses Microsoft Teams to deploy new “Snow” malware

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

'This campaign works because it feels ordinary': Experts reveal how hackers use fake DHL messages to lure in victims | TechRadar

New BlackFile extortion group linked to surge of vishing attacks

Helping Romance Scam Victims Require a Proactive Approach

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News

Money launderer linked to $230M crypto heist gets 70 months in prison

Artificial Intelligence

AI Phishing Is No. 1 With a Bullet for Cyberattackers

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

Deepfake era demands proof-based security, not just awareness | TechTarget

AI Rush is Reviving Old Cybersecurity Mistakes, Mandiant VP Warns - Infosecurity Magazine

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

UK firms accelerate ‘sovereign AI’ plans amid concerns over dependence on overseas tech | IT Pro

Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People

Board Oversight of AI: Do Boards Need AI Experts?

Researchers Uncover 10 In-the-Wild Indirect Prompt Injection Attacks - Infosecurity Magazine

Six AI Vulnerabilities, Three Attack Patterns, One Dangerous Service Gap | perspective | MSSP Alert

Attack of the killer script kiddies | The Verge

AI bot attacks increase 10-fold, report reveals | The Independent

77% of IT managers say their AI agents are out of control - 5 ways to rein in yours | ZDNET

30 ClawHub skills secretly turn AI agents into crypto swarm • The Register

Learning from the Vercel breach: Shadow AI & OAuth sprawl

Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool 

How indirect prompt injection attacks on AI work - and 6 ways to shut them down | ZDNET

Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?

Mythos access by Discord group reveals real danger of AI-powered hacking | Fortune

How to fix cybersecurity's agentic AI identity crisis | TechTarget

Chinese Cybersecurity Firm's AI Hacking Claims Draw Comparisons to Claude Mythos - SecurityWeek

Mythos Is a Wake-Up Call for DDoS Defense - Security Boulevard

Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue | Tom's Hardware

AI Models Can Attack, But Can They Defend? Simbian Says Not Yet | news | MSSP Alert

Trump Administration Vows Crackdown on Chinese Companies 'Exploiting' AI Models Made in US - SecurityWeek

Bots/Botnets

UK warns of Chinese hackers using proxy networks to evade detection

China-linked threat actors use consumer device botnets to evade detection, warn UK and partners

China-Backed Hackers Are Industrializing Botnets

Careers, Roles, Skills, Working in Cyber and Information Security

Nearly half of cybersecurity pros want to quit - here's why | ZDNET

Cybersecurity professional getting more work and less pay • The Register

Cyber Hiring in 2026: Talent Gap or Expectation Problem? - ClearanceJobs

From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield - Security Boulevard

Cloud/SaaS

Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool 

Hybrid clouds have two attack surfaces – so watch both • The Register

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News

26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases

European police dismantles €50 million crypto investment fraud ring

Pro-Russian Hacker Group Gamifies Cyberattacks on Europe With Crypto Rewards – Investigation - The Moscow Times

How the U.S.-China cold war went crypto - Cryptopolitan

Cyber Crime, Organised Crime & Criminal Actors

Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News

Pro-Russian Hacker Group Gamifies Cyberattacks on Europe With Crypto Rewards – Investigation - The Moscow Times

French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator - SecurityWeek

Inside an OPSEC Playbook: How Threat Actors Evade Detection

Scattered Spider co-conspirator pleads guilty | CSO Online

Data Breaches/Leaks

Udemy Data Breach - ShinyHunters Claims Compromise of 1.4M User Records

Researchers Track 2.9 Billion Compromised Credentials - Infosecurity Magazine

Learning from the Vercel breach: Shadow AI & OAuth sprawl

A sneaky cyber enemy is creeping into our browsers and password managers | Cybernews

Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool 

ADT confirms data breach after ShinyHunters leak threat

ShinyHunters claim they have cruise giant Carnival’s booty • The Register

Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica

Personal data of almost entire Dutch town stolen in cyberattack

French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches

Discord users breach access controls to reach Anthropic’s Mythos model - Digital Trends

Medtronic Confirms Data Breach After ShinyHunters Claims - Infosecurity Magazine

Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security

Private health records of half a million Britons offered for sale on Chinese website | Data and computer security | The Guardian

UK Biobank Breach: Health Data of 500,000 Listed for Sale in China - Infosecurity Magazine

Ransomware attacks affect 2 senior care providers

U.S. utility giant Itron discloses a security breach

Data Protection

U.S. companies hit with record fines for privacy in 2025 | CyberScoop

Data/Digital Sovereignty

UK firms accelerate ‘sovereign AI’ plans amid concerns over dependence on overseas tech | IT Pro

The push for digital sovereignty: What CISOs need to know | TechTarget

What’s behind Europe’s efforts to ditch US software in favor of sovereign tech | TechCrunch

Germany fights US “cyber dominance” with sovereignty checklist​ | Cybernews

The European Commission is turning Google Search into a privacy and national-security risk

Denial of Service/DoS/DDoS

Mythos Is a Wake-Up Call for DDoS Defense - Security Boulevard

MP Sir David Davis's website shut down in suspected cyber attack - BBC News

Encryption

The 2026 MSSP Blueprint: Navigating the Quantum Countdown | native | MSSP Alert

Fraud, Scams and Financial Crime

French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches

Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News

Money launderer linked to $230M crypto heist gets 70 months in prison

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator - SecurityWeek

European police dismantles €50 million crypto investment fraud ring

Helping Romance Scam Victims Require a Proactive Approach

US Busts Myanmar Ring Targeting US Citizens in Financial Fraud

Insider Risk and Insider Threats

Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People

Insurance

Cyber Insurance Data Gives CISOs New Ammo for Budget Talks - SecurityWeek

Internet of Things – IoT

A Quarter of Healthcare Organizations Report Medical Device Attacks - Infosecurity Magazine

Attackers could disable all of a city's public EV chargers • The Register

Law Enforcement Action and Take Downs

Money launderer linked to $230M crypto heist gets 70 months in prison

US Sanctions Target Cambodian Scam Network Leaders - Infosecurity Magazine

European police dismantles €50 million crypto investment fraud ring

Hackers arrested for hijacking and selling 610,000 Roblox accounts

French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches

US Busts Myanmar Ring Targeting US Citizens in Financial Fraud

Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security

Scattered Spider co-conspirator pleads guilty | CSO Online

Chinese national extradited to US for pandemic-era Silk Typhoon attacks | CyberScoop

Linux and Open Source

12-year-old Pack2TheRoot bug lets Linux users gain root privileges

Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System

AI's not going to kill open source code security • The Register

Linux cryptographic code flaw offers fast route to root • The Register

Malware

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

A sneaky cyber enemy is creeping into our browsers and password managers | Cybernews

Crime crew impersonates help desk, abuses Teams chats • The Register

Threat actor uses Microsoft Teams to deploy new “Snow” malware

Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica

Chernobyl virus turned 27 today, and it could brick your PC in ways modern malware can't by overwriting BIOS firmware | Tom's Hardware

Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions

Widely Used Browser Extensions Selling User Data - Infosecurity Magazine

Vidar Rises to Top of Chaotic Infostealer Market

Unwary Chinese Hackers Hardcoded Credentials into Backdoors

20-Year-Old Malware Rewrites History of Cyber Sabotage

Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions - SecurityWeek

Mobile

26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases

A new hacker tool could infect millions of iPhones worldwide. Here’s what you should do – The Irish Times

Another spyware maker caught distributing fake Android snooping apps | TechCrunch

This hidden SIM flaw lets spies track your location, and using a VPN can't help | TechRadar

New Android spyware Morpheus linked to Italian surveillance firm

Models, Frameworks and Standards

UK Cyber Essentials overhaul could trigger instant certification failures - BetaNews

DORA and the Practical Test of Operational Resilience - IT Security Guru

ENISA updates framework to enhance EU member state cybersecurity capabilities » Iraqi News Agency

Outages

Microsoft says Outlook.com outage is causing sign‑in failures

Passwords, Credential Stuffing & Brute Force Attacks

Over 2.8 billion credentials stolen in 2025 as ransomware evolves - BetaNews

Researchers Track 2.9 Billion Compromised Credentials - Infosecurity Magazine

Official SAP npm packages compromised to steal credentials

Regulations, Fines and Legislation

Proton CEO: Age checks turn internet into ID checkpoint • The Register

The Governance Gap: How the EU AI Act Makes API Security a Compliance Imperative - Security Boulevard

The European Commission is turning Google Search into a privacy and national-security risk

U.S. companies hit with record fines for privacy in 2025 | CyberScoop

EU waves through age-check app to keep kids safe online • The Register

Trump Administration Vows Crackdown on Chinese Companies 'Exploiting' AI Models Made in US - SecurityWeek

Latest spy power reauthorization bill leaves critics unimpressed | CyberScoop

The Iran Factor In Trump’s Cyber Strategy – Analysis – Eurasia Review

Social Media

LINKEDIN BROWSERGATE

ShinyHunters exploit Anodot incident to target Vimeo

Supply Chain and Third Parties

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek

Why supply chain resilience is under the spotlight | IT Pro

Official SAP npm packages compromised to steal credentials

Ongoing supply-chain attack targets security, dev tools • The Register

Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek

Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

How Big a Threat Are Iranian-Backed Cyberattacks? | The New Yorker

Iran’s cyber threat may be less ‘shock and awe’ than ‘low and slow,’ officials say | The Record from Recorded Future News

Compromised everyday devices power Chinese cyber espionage operations - Help Net Security

The New Rules Of War Have No Rules

Is the Middle East Conflict Opening a Digital Front in Europe? | The Gaze

Cyberwar Without Borders: How Iran’s Digital Offensive Is Reaching Europe | The Gaze

Cyberwar brings frontline to heart of European infrastructure  - SWI swissinfo.ch

UK in talks with telecoms industry on undersea cable threat

Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions - SecurityWeek

NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software

Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities | CyberScoop

Locked Shields 2026 united the power of 41 nations to defend cyberspace CCDCOE

Golden Dome weapons to attack enemy missiles with new high-tech interceptors, lasers, cyberattacks

FCC adds mobile hotspots to router ban • The Register

Chinese Hackers Spied On Cuban Embassy As US Prepared Blockade

Nation State Actors

The New Rules Of War Have No Rules

Cyberwar brings frontline to heart of European infrastructure  - SWI swissinfo.ch

UK in talks with telecoms industry on undersea cable threat

Locked Shields 2026 united the power of 41 nations to defend cyberspace CCDCOE

China

A dozen allied agencies say China is building covert hacker networks out of everyday routers | CyberScoop

UK in talks with telecoms industry on undersea cable threat

Chinese Cybersecurity Firm's AI Hacking Claims Draw Comparisons to Claude Mythos - SecurityWeek

China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks - SecurityWeek

FCC adds mobile hotspots to router ban • The Register

Trump Administration Vows Crackdown on Chinese Companies 'Exploiting' AI Models Made in US - SecurityWeek

Unwary Chinese Hackers Hardcoded Credentials into Backdoors

Chinese national extradited to US for pandemic-era Silk Typhoon attacks | CyberScoop

UK warns of Chinese hackers using proxy networks to evade detection

China-linked threat actors use consumer device botnets to evade detection, warn UK and partners

China-Backed Hackers Are Industrializing Botnets

Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software

New GopherWhisper APT group abuses Outlook, Slack, Discord for comms

Chinese Hackers Spied On Cuban Embassy As US Prepared Blockade

EU bans funding for energy projects using Chinese inverters - PV Tech

Russia

UK in talks with telecoms industry on undersea cable threat

Incomplete Windows Patch Opens Door to Zero-Click Attacks - SecurityWeek

Microsoft patch fell short. New Windows flaw exploited • The Register

Pro-Russian Hacker Group Gamifies Cyberattacks on Europe With Crypto Rewards – Investigation - The Moscow Times

RAMP Uncovered: Anatomy of Russia’s Ransomware Marketplace

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

Germany Caught Up in Likely Russian Signal Phishing

Internet censorship index reveals Russia’s lead and widespread content blocking

North Korea

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

Iran

The New Rules Of War Have No Rules

How Big a Threat Are Iranian-Backed Cyberattacks? | The New Yorker

Iran’s cyber threat may be less ‘shock and awe’ than ‘low and slow,’ officials say | The Record from Recorded Future News

Is the Middle East Conflict Opening a Digital Front in Europe? | The Gaze

Cyberwar Without Borders: How Iran’s Digital Offensive Is Reaching Europe | The Gaze

Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions - SecurityWeek

The Iran Factor In Trump’s Cyber Strategy – Analysis – Eurasia Review

Iranian Cyber Group Handala Targets US Troops in Bahrain - SecurityWeek

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

The New Rules Of War Have No Rules

Golden Dome weapons to attack enemy missiles with new high-tech interceptors, lasers, cyberattacks

Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of "Highly Destructive" Wiper


Tools and Controls

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

Beazley finds growing gap between business confidence and cyber resilience as risks intensify - Reinsurance News

Cyber threats challenge global business resilience

Cyber Insurance Data Gives CISOs New Ammo for Budget Talks - SecurityWeek

Mythos sniffs out your bugs, can't fix your bloody idiots • The Register

DORA and the Practical Test of Operational Resilience - IT Security Guru

Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?

Glasswing Secured the Code. The Rest is on You

Cyber pros say unauthorized Mythos access is a sign of things to come | Cybernews

Mythos access by Discord group reveals real danger of AI-powered hacking | Fortune

“Mythos-like hacking, open to all”: Industry reacts to OpenAI’s GPT 5.5 - The New Stack

AI Models Can Attack, But Can They Defend? Simbian Says Not Yet | news | MSSP Alert

Google Favors General‑Purpose Gemini Models Over Cybersecurity‑Specif - Infosecurity Magazine

Remote Desktop security beefed up with hard-to-read messages • The Register

Shadow code: The hidden threat for enterprise IT | TechTarget

Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People

Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool 

Vercel attack fallout expands to more customers and third-party systems | CyberScoop

Mythos Is a Wake-Up Call for DDoS Defense - Security Boulevard

Hybrid clouds have two attack surfaces – so watch both • The Register

Open source models can find bugs as well as Mythos • The Register

Myth Or Mythos? The Illusion Of Advantage In The AI Cybersecurity Race

The Hidden Tax on Security: How Data Costs Are Eating Your Controls Budget - Security Boulevard

Locked Shields 2026 united the power of 41 nations to defend cyberspace CCDCOE

Pro-Russian Hacker Group Gamifies Cyberattacks on Europe With Crypto Rewards – Investigation - The Moscow Times

FS cybersecurity experts gather for “industry first” training exercise - FStech



Vulnerability Management

Open source models can find bugs as well as Mythos • The Register

Microsoft updates the Windows Update Experience • The Register

5 ways your Windows updates are about to get a lot less painful | ZDNET

Everything Runs on Software. None of It Is Secure.

Vulnerabilities

US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied | CyberScoop

Firestarter malware survives Cisco firewall updates, security patches

SonicWall Urges Immediate Patching of Firewall Vulnerabilities - SecurityWeek

Vulnerabilities Patched in CrowdStrike, Tenable Products - SecurityWeek

CVSS scored these two Palo Alto CVEs as manageable. Chained, they gave attackers root access to 13,000 devices. | VentureBeat

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

Incomplete Windows Patch Opens Door to Zero-Click Attacks - SecurityWeek

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years - SecurityWeek

No Patch for New PhantomRPC Privilege Escalation Technique in Windows - SecurityWeek

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

April KB5083769 Windows 11 update causes backup software failures

12-year-old Pack2TheRoot bug lets Linux users gain root privileges

Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks

Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System

Critical bug in CrowdStrike LogScale let attackers access files

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

Linux cryptographic code flaw offers fast route to root • The Register

Chrome 147, Firefox 150 Security Updates Rolling Out - SecurityWeek

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

cPanel's authentication bypass bug is being exploited in the wild, CISA warns | CyberScoop

Hackers are actively exploiting a bug in cPanel, used by millions of websites | TechCrunch

Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting

Nessus Agent Vulnerability on Windows Enables Arbitrary Code Execution with SYSTEM Privileges

Critical GitHub Vulnerability Exposed Millions of Repositories - SecurityWeek

New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

New Linux ‘Copy Fail’ flaw gives hackers root on major distros

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

·       Automotive

·       Construction

·       Critical National Infrastructure (CNI)

·       Defence & Space

·       Education & Academia

·       Energy & Utilities

·       Estate Agencies

·       Financial Services

·       FinTech

·       Food & Agriculture

·       Gaming & Gambling

·       Government & Public Sector (including Law Enforcement)

·       Health/Medical/Pharma

·       Hotels & Hospitality

·       Insurance

·       Legal

·       Manufacturing

·       Maritime & Shipping

·       Oil, Gas & Mining

·       OT, ICS, IIoT, SCADA & Cyber-Physical Systems

·       Retail & eCommerce

·       Small and Medium Sized Businesses (SMBs)

·       Startups

·       Telecoms

·       Third Sector & Charities

·       Transport & Aviation

·       Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

 

Read More