Black Arrow Cyber Threat Intelligence Briefing 02 October 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

This week, we examine how forgotten Microsoft 365 accounts, unresolved vulnerabilities and gaps in basic cyber security skills leave organisations exposed. These findings reinforce the importance of clear ownership for security in the organisation, and ensuring those responsible have the skills and support to maintain fundamental protections.

Cyber security goes beyond technology, and this week we demonstrate how criminals exploit human trust through phone-based attacks, employment scams and deepfake impersonation. Employee awareness needs to reflect these threats, with practical guidance that helps employees make safer decisions at work, including when using AI.

We also examine the gap between confidence in AI readiness and the controls needed to protect information and oversee AI activity. As adoption grows and systems become more capable, leaders need to ensure that access, autonomy and human accountability are managed.

Wider risks include supply chain, quantum computing and geopolitical risks, while collaboration between security and finance can help align investment with business exposure. Russia’s cyberattacks and physical disruption reinforce the need to prepare for interruptions to critical services.

As this week’s review shows, cyber security and cyber resilience require proportionate management across people, operations and technology. Contact us to discuss how we can help your organisation prepare and respond.


Top Cyber Stories of the Last Week

Hackers Broke into Microsoft 365 Through Forgotten Accounts Nobody Was Watching

Attackers have compromised Microsoft 365 environments by targeting forgotten service accounts that remained active but lacked proper security controls. Attackers tried likely default passwords against 5,714 accounts across 28 Microsoft 365 environments, successfully accessing seven. All involved non-personal accounts used for routine business functions, with six breached within seven minutes, suggesting shared or unchanged passwords. Once inside, attackers accessed services including Microsoft Office, OneDrive, Teams and SharePoint. The findings highlight the risk from unmanaged accounts that lack clear ownership, multi-factor authentication and regular credential reviews.

https://cybersecuritynews.com/hackers-broke-into-microsoft-365/

Most Open Critical and High Flaws Are over 90 Days Old

Detectify found that serious vulnerabilities are often left exposed on internet-facing systems for months after organisations know about them. Up to 97% of open critical and high-severity flaws in the US, UK and Nordics had been exposed for over 90 days. Public-sector organisations resolved the lowest proportion of serious flaws within 90 days of detection, while organisations with exposed AI tools fixed them at less than half the rate of the wider customer base. The findings highlight the risk of known weaknesses becoming accepted by default rather than through a deliberate decision.

https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/

More than Half of UK Businesses Lack Confidence in Basic Cyber Skills

Government research found that most UK businesses had at least one routine cyber security task their security lead did not feel confident performing. Some 57% reported a basic technical skills gap, up from 49% last year, equivalent to around 808,000 businesses. Detecting and removing malicious software was the most common weakness, affecting 38% of businesses and 47% of charities. Researchers cautioned that the rise may partly reflect greater awareness rather than worsening capability, but the findings still highlight widespread weaknesses in fundamental cyber security skills, particularly among smaller organisations with limited specialist resources.

https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991

How a Phone Call Allowed a Hacker to Steal Millions of People’s Personal Data

Voice phishing remains a highly effective way for attackers to breach organisations, with a single convincing phone call sometimes enough to gain access to sensitive systems and data. Dutch telecoms provider Odido recently suffered a breach affecting more than six million people after an attacker tricked a customer support employee into entering their credentials into a fake login page. Similar call-based attacks have also affected Google, Cisco, Charter and RingCentral, highlighting that even large technology companies remain vulnerable to attackers who exploit human trust rather than technical weaknesses.

https://this.weekinsecurity.com/fear-the-phone-call-hackers-are-calling-for-your-personal-data/

Employment Scam Victims Tripled at Financial Firms in 21 Countries

Employment scams, where criminals pose as recruiters or employers to trick people with fake job offers, are rising sharply across financial institutions. Reported victims increased 258% over the past year across more than 370 banks and financial firms in 21 countries. Overall scam reports rose 35%, while nine in ten scam sessions now begin on a mobile device. Investment scams caused the highest average losses at $6,600 per case. Researchers also found that unusual payments, new beneficiaries and customers apparently being coached by phone can provide opportunities to detect scams before money leaves the account.

https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/

Deepfakes Become a Board Priority Once an Executive Falls for One

Deepfake attacks are becoming a significant business risk, with nearly three-quarters of security leaders saying they encountered or suspected one in the past year, yet only 10% have dedicated defences. Attackers are using convincing fake voices and video to impersonate trusted people during calls, meetings and job interviews. Among affected organisations, nearly half reported costs of at least $500,000 and around a quarter reported costs of at least $1 million. Almost half also experienced further cyberattacks, while 37% believe a single deepfake incident could threaten their organisation’s survival.

https://www.helpnetsecurity.com/2026/09/29/pindrop-enterprise-deepfake-attacks-report/

AI Security Awareness Is the New Frontline of Cyber Security

As AI becomes embedded in everyday work, employee behaviour is emerging as a growing cyber security risk. For 68% of CISOs in the research, employees represented the greatest cyber security risk to their organisation, and 40% feared staff were disclosing sensitive data to generative AI tools. Traditional annual training is increasingly inadequate against AI-enabled phishing, deepfakes and social engineering. Organisations need more continuous and targeted awareness, with safeguards and guidance applied when risky behaviour occurs, such as uploading confidential data to public AI platforms or acting on unverified AI-generated advice.

https://www.infosecurity-magazine.com/opinions/ai-security-awareness-cybersecurity/

Microsoft 365 Governance Incidents Rise amid AI Overconfidence

Microsoft 365 governance problems affected 77% of organisations surveyed over the past year, with former employees retaining access, compliance gaps and sensitive data reaching the wrong people among the most common issues. As Microsoft Copilot adoption doubled to 56%, 93% of organisations believed their governance was ready for AI, yet 29% had already experienced AI exposing sensitive internal information. The findings suggest a significant gap between confidence and reality, with 37% citing a lack of AI governance expertise and 34% calling for stronger controls over AI agents.

https://www.msspalert.com/brief/microsoft-365-governance-incidents-rise-amid-ai-overconfidence

AI Tests the Limits of Enterprise Security Governance

AI adoption is moving faster than many organisations’ governance processes can handle, increasing the risk of uncontrolled use and data leakage. AWS research found that while more than half of European businesses use AI, only 24% have a documented approach to responsible use and just 10% have a data governance strategy. The report recommends assessing AI projects by risk, keeping people accountable for sensitive decisions, and limiting AI agents’ autonomy until they have demonstrated reliability. It also warns that overly slow approval processes can drive employees towards unsanctioned AI tools outside corporate oversight.

https://www.helpnetsecurity.com/2026/09/28/ai-agent-security-governance-aws-report/

Anthropic IPO Filing Warns Its AI Could Blackmail, Manipulate and Threaten Humanity

Anthropic has warned prospective investors that increasingly capable AI systems could become harder to control, potentially resisting shutdown, manipulating information or developing unexpected behaviours after deployment. Around 80 pages of its 261-page IPO prospectus are devoted to risk factors. More immediate concerns include data leaks, cyberattacks, regulatory breaches and operational failures that could lead to financial losses. The company could seek a valuation of more than $2 trillion after revenue rose twelvefold to nearly $4.6 billion in 2025, despite an operating loss of $8.06 billion.

https://invezz.com/news/2026/09/29/anthropic-ipo-filing-warns-its-ai-could-blackmail-manipulate-and-threaten-humanity/

Four Cyber Threats Harbouring Big Plans for the Future

Four emerging threats are placing growing pressure on organisational resilience: AI-enabled attacks, supply chain compromise, quantum computing and geopolitical conflict. AI is making phishing, deepfakes and vulnerability discovery faster and more convincing, while trusted suppliers can provide attackers with indirect access into organisations. Quantum computing also creates a longer-term risk to sensitive encrypted data, with migration to quantum-resistant security expected to take years. At the same time, nation-state activity is increasingly affecting critical infrastructure and business operations, reinforcing the need to treat cyber security resilience as an ongoing operational capability rather than a one-off technology project.

https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/

Why the CISO-CFO Relationship Is a Key to Cyber Security Success

Strong alignment between cyber security and finance is becoming increasingly important to business resilience, yet research reports that only 47% of CISOs worked with CFOs on strategic cyber security investment plans. Poor coordination can result in misdirected spending, weaker preparedness and greater financial exposure. With 74% of surveyed enterprises experiencing at least one attempted business email compromise attack in 2025, closer collaboration can help ensure investment is focused on protecting critical financial systems, reducing risk and supporting business growth.

https://www.darkreading.com/cyber-risk/how-to-manage-ciso-cfo-relationship-cybersecurity-success

Russia's Hybrid Cyber-Physical War in Europe Heats Up

Russia is intensifying a campaign of cyberattacks, sabotage, disinformation and drone activity across Europe, particularly against countries and organisations supporting Ukraine. Recorded Future says recent activity has targeted energy, water, public infrastructure and logistics, while disinformation campaigns have impersonated European media using AI-generated content. Organisations involved in logistics, critical infrastructure, defence-related supply chains and equipment used to repair damaged infrastructure may face greater risk. Researchers assess that Russia could increasingly combine cyberattacks, physical disruption and information operations to place greater pressure on European governments and NATO over the next two years.

https://www.darkreading.com/physical-security/russia-hybrid-cyber-physical-war-europe



Threats

Ransomware, Extortion and Destructive Attacks

Emerging Ransomware Gang Uses Backup Destruction Threats - Infosecurity Magazine

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments | Microsoft Security Blog

Ryuk ransomware member gets 2 years, $1.2M restitution | Cybernews

Cyber Worker Allegedly Moonlighted as ShinyHunters Hacker (1)

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

Ukrainian ransomware developer jailed for nearly 13 years

Ransomware and Destructive Attack Victims

FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day - Help Net Security

FBI tells ShinyHunters members to turn themselves in after recent arrest

South Africa Seeks Aid After Air Traffic Control Cyberattack

FTAPI data breach confirmed after The Gentlemen ransomware claim | Cybernews

Japanese Railway Operators Hit with Weekend Cyber Attacks - Infosecurity Magazine

Phishing & Email Based Attacks

Phishing Abuses RMM Tools for Persistent Access | Microsoft Security Blog

3 in 4 EU employees face cyber threats at work: Survey

Russian state hackers use new RedFlick technique to push malware

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

Know Your Enemy: Browser-Based Attack Techniques in 2026

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Researchers Identify AliExpress Phishing Domains Before Registration - Infosecurity Magazine

Former US Air Force members behind million-dollar BEC scheme head to prison - Help Net Security

Hackers’ cyberattacks on Ukrainians have focused on four areas - what to beware of | УНН

Business Email Compromise (BEC)/Email Account Compromise (EAC)

Former US Air Force members behind million-dollar BEC scheme head to prison - Help Net Security

Other Social Engineering

Deepfakes become a board priority once an executive falls for one - Help Net Security

How a phone call allowed a hacker to steal millions of people's personal data

3 in 4 EU employees face cyber threats at work: Survey

Russian state hackers use new RedFlick technique to push malware

Know Your Enemy: Browser-Based Attack Techniques in 2026

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Stopping IT Worker Scams Requires Revamped HR Process

Employment scam victims tripled at financial firms in 21 countries - Help Net Security

Documentation placeholder domain used in ClickFix attacks | CSO Online

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

Crooks use fake desktop apps to fool HR staff into giving them remote access

Hackers’ cyberattacks on Ukrainians have focused on four areas - what to beware of | УНН

2FA/MFA

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

US sanctions force The Netherlands off Microsoft and toward alternative NixOS-based software ecosystem — trial programs running now, first release expected at end of 2027 | Tom's Hardware

Artificial Intelligence

OpenAI took 2.5 hours to stop an AI agent that escaped its sandbox

AI Security Awareness is the New Frontline of Cybersecurity - Infosecurity Magazine

OpenAI Says It Will Not Release Newest Astra A.I. Model Over Safety Concerns - The New York Times

Anthropic IPO filing warns its AI could blackmail, manipulate and threaten humanity

Four Cyber Threats Harboring Big Plans for the Future - SecurityWeek

Deepfakes become a board priority once an executive falls for one - Help Net Security

Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

AI leaders have known about the extinction threat for decades | Judith Levine | The Guardian

OpenAI’s agents obscured hacking activity in government site breaches

Insider threats evolve as AI exposes hidden pathways across corporate systems - Digital Journal

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability - SecurityWeek

AI Accounts Are Becoming the New Target for Infostealers

OpenAI's GPT-6 Astra ran supply chain attacks despite being told not to - Help Net Security

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Add one more AI worry to the nightmare scenario: self-replicating prompt injections

Top AI and tech firms sign 'morally binding' accord to 'self-police' development after meeting at White House | Euronews

OpenAI reveals ‘novel’ encryption bypass used in distillation attack | CyberScoop

Who's to blame for rogue AI? It could be you as ignorance of the law is no defence | TechFinitive

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'

Zuckerberg Is Feeling Himself, Rejects Calls for Cooperation on Safety

Rogue AI agents leave insurers facing dilemma over liability

Over 75% of Organizations Experience Microsoft 365 Governance Issues - Infosecurity Magazine

The cyber AI parity window now has a deadline | CSO Online

“Drunk” AI is terrible at keeping secrets - Help Net Security

Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

AI is supercharging hacking, and your local hospitals and banks aren’t ready | The Verge

Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open

MCP Is Creating Major Governance Gaps, Researchers Warn - Infosecurity Magazine

The AI security blind spot: Inadequate data governance | Freeman Mathis & Gary - JDSupra

AI models keep posting screenshots showing sensitive data from inside tech companies

RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions

OpenAI sued by safety group over autonomous hack of Hugging Face - ABC News

Sam Altman says OpenAI will delay its IPO until it overcomes safety concerns

The problem with uncensored AI may be how easy it is to buy | Inquirer Technology

OpenClaw slips on a suit to evade widespread business bans

AI tests the limits of enterprise security governance - Help Net Security

Securing data at the source in the age of agentic AI - SiliconANGLE

Trump Signs Order Renaming AI To ‘Super Intelligence’—Here’s What It Changes

Trump rules out joint US-China venture to develop AI - BBC News

Automated AI agent used to breach cybersecurity nonprofit DIVD

AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price - IT Security Guru

New bill would create federal investigative body for AI-driven hacks | CyberScoop

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

Researchers use LLMs to link anonymous forum accounts to real names for $1 to $4 per target

FI to review Swedish banks’ defenses against AI-powered cyberattacks | Sweden Herald

In Focus: Can cyber insurance keep up with AI? | Insurance Times

AI godfathers warn of runaway ‘intelligence explosion’ | AI (artificial intelligence) | The Guardian

Godfather of AI Predicts Total Breakdown of Society

Bots/Botnets

Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

Careers, Roles, Skills, Working in Cyber and Information Security

Cybersecurity hiring practices leave little room for junior talent - Help Net Security

Charity status for NeuroCyber | Professional Security Magazine

Cloud/SaaS

Over 75% of Organizations Experience Microsoft 365 Governance Issues - Infosecurity Magazine

Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Azure maintenance mess disrupted hybrid clouds, VPNs, cloudy VMware services

Microsoft tells nonprofits their deleted M365 data isn't coming back

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Attackers build “silent” cryptominer on victim’s machine and give themselves away - IT Security Guru

Vietnamese man charged in $16 million 'pig butchering' crypto scam

Cyber Crime, Organised Crime & Criminal Actors

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

The US Blacklists Alleged Venezuelan Cyber Crime Mastermind | OCCRP

Data Breaches/Leaks

Exposed GitLab project email addresses let attackers push code

Hundreds of GitHub App private keys leaked, granting broad access | news | MSSP Alert

Dyfed-Powys Police force confirms it was victim of cyber-attack | ITV News Wales

Poland probes second healthcare cyberattack as FM warns Russia may be planning ‘something big’ - TRT World

Another week, another data breach for Revolut customers

bne IntelliNews - Israeli investment giant Meitav's stock dives after large-scale cyberattack

Over 543,000 valid credentials exposed in public GitHub repositories

Cyberattack Hits Spanish Train Operator User Data

Times Car confirms data breach affecting 6.6 million user accounts

Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure

More than 3 million people affected by military data breach - Federal News Network

Astrana Health Data Breach Impacts Private, Confidential Information - SecurityWeek

16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data - Help Net Security

Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed - DataBreaches.Net

Data/Digital Sovereignty

US sanctions force The Netherlands off Microsoft and toward alternative NixOS-based software ecosystem — trial programs running now, first release expected at end of 2027 | Tom's Hardware

FTAPI data breach confirmed after The Gentlemen ransomware claim | Cybernews

Encryption

Quantum threats: What CISOs should do to prepare | IT Pro

Fraud, Scams and Financial Crime

Employment scam victims tripled at financial firms in 21 countries - Help Net Security

Vietnamese man charged in $16 million 'pig butchering' crypto scam

Queensland government department loses $800,000 in cyber attack - ABC News

Review after €43k stolen from Department of Justice in text scam

Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data - IT Security Guru

Insider Risk and Insider Threats

Stopping IT Worker Scams Requires Revamped HR Process

Crooks use fake desktop apps to fool HR staff into giving them remote access

Insurance

In Focus: Can cyber insurance keep up with AI? | Insurance Times

Internet of Things – IoT

Your car and its mobile app are probably handing over all kinds of data to tech companies | TechCrunch

Law Enforcement Action and Take Downs

Ryuk ransomware member gets 2 years, $1.2M restitution | Cybernews

Cyber Worker Allegedly Moonlighted as ShinyHunters Hacker (1)

Vietnamese man charged in $16 million 'pig butchering' crypto scam

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

Former US Air Force members behind million-dollar BEC scheme head to prison - Help Net Security

FBI tells ShinyHunters members to turn themselves in after recent arrest

Ukrainian ransomware developer jailed for nearly 13 years

Linux and Open Source

US sanctions force The Netherlands off Microsoft and toward alternative NixOS-based software ecosystem — trial programs running now, first release expected at end of 2027 | Tom's Hardware

AI Finds Linux Kernel Bug That Can Grant Root Access | Cybernews

Malware

SectopRAT Returns, Hiding Inside a Legitimate Application

AI Accounts Are Becoming the New Target for Infostealers

Russian state hackers use new RedFlick technique to push malware

Hackers’ cyberattacks on Ukrainians have focused on four areas - what to beware of | УНН

MacSync malware uses public iCloud calendars to deliver new payloads

Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection

'NeedyMantis' Provides Long-Term Access to Compromised Networks

New macOS malware masquerades as Zoom installer | Macworld

Exposed GitLab project email addresses let attackers push code

Attackers build “silent” cryptominer on victim’s machine and give themselves away - IT Security Guru

RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Misinformation, Disinformation and Propaganda

UK gears up for fight against Russia’s disinformation machine - Help Net Security

Russia's Hybrid Cyber-Physical War in Europe Heats Up

Mobile

New Android malware RemControl steals banking PINs and blocks removal attempts - Help Net Security

Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

Apple patches CoreGraphics zero-day flaw exploited in attacks

GitHub's AI agent found 24 Android app vulnerabilities - Help Net Security

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Outages

Banking IT outages: find out how often your bank has gone down - Which?

Passwords, Credential Stuffing & Brute Force Attacks

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Privacy, Surveillance

Your car and its mobile app are probably handing over all kinds of data to tech companies | TechCrunch

'Using VPNs is not criminal:' digital rights advocates return for a second Defend VPNs Day of Action | TechRadar

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections - SecurityWeek

Surveillance Finds a Way

UK rail cops' £320K face-scanning spree nets zero matches

Regulations, Fines and Legislation

'Using VPNs is not criminal:' digital rights advocates return for a second Defend VPNs Day of Action | TechRadar

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections - SecurityWeek

New bill would create federal investigative body for AI-driven hacks | CyberScoop

FI to review Swedish banks’ defenses against AI-powered cyberattacks | Sweden Herald

Preemptive cybersecurity laws enforced in Japan amid rising threats - The Mainichi

Sweden boosts cyber threat security defences amid AI advances | Computer Weekly

Declassified: The FBI's New Cyber Strategy and What It Means for Companies | Mayer Brown - JDSupra

Social Media

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections - SecurityWeek

LinkedIn tests a way for connections to verify your work history - Help Net Security

Software Supply Chain

Exposed GitLab project email addresses let attackers push code

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Hundreds of GitHub App private keys leaked, granting broad access | news | MSSP Alert


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

UK gears up for fight against Russia’s disinformation machine - Help Net Security

Russia's Hybrid Cyber-Physical War in Europe Heats Up

NATO chief says alliance 'ready' for Russia hybrid attack

Four Cyber Threats Harboring Big Plans for the Future - SecurityWeek

UK ministers to brief defence companies, infrastructure providers on Russia threats - Internazionale

The critical infrastructure Europe - and Nato - needs to protect from Russia | The Independent

The government wants UK households to stock up on nine items. Here’s what to buy | The Independent

Nation State Actors

Four Cyber Threats Harboring Big Plans for the Future - SecurityWeek

Fears of Foreign Cyberattacks on Academic Blogs

China

'NeedyMantis' Provides Long-Term Access to Compromised Networks

Russia

UK gears up for fight against Russia’s disinformation machine - Help Net Security

Russia's Hybrid Cyber-Physical War in Europe Heats Up

NATO chief says alliance 'ready' for Russia hybrid attack

UK ministers to brief defence companies, infrastructure providers on Russia threats - Internazionale

The critical infrastructure Europe - and Nato - needs to protect from Russia | The Independent

The government wants UK households to stock up on nine items. Here’s what to buy | The Independent

Russian state hackers use new RedFlick technique to push malware

Poland probes second healthcare cyberattack as FM warns Russia may be planning ‘something big’ - TRT World

CIA warns Russia is preparing attacks on Spain, France or Italy with drones from the sea: report | The Independent

Hackers’ cyberattacks on Ukrainians have focused on four areas - what to beware of | УНН

Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed - DataBreaches.Net

Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments

Kyiv internet providers report major outages after Russian attacks damage data centers | The Record from Recorded Future News

North Korea

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

Interpol builds huge database and IDs 126 terrorist suspects from face biometrics | Biometric Update

Tools and Controls

AI Security Awareness is the New Frontline of Cybersecurity - Infosecurity Magazine

Phishing Abuses RMM Tools for Persistent Access | Microsoft Security Blog

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

What Is IT Project Risk Management?

Most organizations need six months or longer to roll out new security controls - Help Net Security

Why Cybersecurity Will Survive The 'SaaS-Pocalypse'

'The Art of War' Never Said Know Only Your Vulnerabilities

'Using VPNs is not criminal:' digital rights advocates return for a second Defend VPNs Day of Action | TechRadar

AI Finds Linux Kernel Bug That Can Grant Root Access | Cybernews

Quantum threats: What CISOs should do to prepare | IT Pro

The cyber AI parity window now has a deadline | CSO Online

Half of threat hunters say bad data is their biggest problem - Help Net Security

Threat detection dashboards are masking security coverage gaps - Help Net Security

Microsoft shares new Windows 11 26H2 security recommendations for IT admins - Neowin

The vulnerabilities AI finds are the ones attackers want - Help Net Security

Begin at the End: How to Enable Agentic Remediation - SecurityWeek

Microsoft to block Entra ID script injection attacks starting October

16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data - Help Net Security

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

Google to critical infra orgs: Our AI scanners won't be evil, promise

Microsoft plans to deprecate Windows Deployment Services

Why AI won’t fix your cybersecurity problem - IT Security Guru



Vulnerability Management

CISA plans CVE overhaul as vulnerability volume explodes | news | MSSP Alert

Most open critical and high flaws are over 90 days old - Help Net Security

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

'The Art of War' Never Said Know Only Your Vulnerabilities

The vulnerabilities AI finds are the ones attackers want - Help Net Security

Vulnerabilities

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) - Help Net Security

Cisco warns of new SD-WAN zero-day exploited in attacks

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Chrome, Firefox Updates Patch Over 100 Vulnerabilities - SecurityWeek

TeamViewer urges users to patch severe flaws “as soon as possible”

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL - SecurityWeek

Cloudflare fixes Containers cross-tenant flaw exposing customer data

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability - SecurityWeek

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Elementor WordPress flaw lets attackers create admin accounts

Windows, Linux, Android File Notification Systems Leak User Activity - SecurityWeek

OpenInfra Europe's JFrog Artifactory instance breached, packages potentially compromised - Help Net Security

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

New Spectre v2 attack variant leaks Linux root password hash in minutes

AI Finds Linux Kernel Bug That Can Grant Root Access | Cybernews

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

GitHub's AI agent found 24 Android app vulnerabilities - Help Net Security


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 25 September 2026