Black Arrow Cyber Threat Intelligence Briefing 04 September 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Following recent news stories about the cyber risks associated with the malicious use of AI, we report on a joint announcement by a range of organisations that warns all businesses to prioritise their cyber defences ahead of an expected sharp rise in attacks. In addition to the below report, similar announcements were made recently by authorities in the UK, USA and other countries.

While AI has increased the risks, attackers continue to use other tactics: this week we report on how attackers use Teams calls, fake software installers and fake voicemail notifications to gain access to their victims’ systems. We highlight these so that business leaders can ensure these tactics are included in employee training to help staff recognise the signs. We also include information on how business leaders should address the developing insider risks, including when recruiting remote workers.

To respond to this, all organisations should strengthen not only their cyber security (to reduce the probability of a successful attack) but also strengthen their cyber resilience to help enable the organisation to survive an attack. In our experience, the best way to achieve this is through a cyber incident response exercise designed and facilitated by impartial cyber experts; contact us to find out how we help organisations in various countries achieve this proportionately.


Top Cyber Stories of the Last Week

OpenAI, Anthropic and 100-Plus Firms Warn AI Attacks Are About to Explode

More than 100 organisations across technology, banking, insurance and security have warned of a sharp rise in AI-enabled cyberattacks over the coming months as the technology can help attackers find weaknesses and act at greater speed. Businesses more broadly are urged to prioritise cyber defence, address serious existing weaknesses and strengthen controls over AI-generated code. CrowdStrike reported that attackers adopted 88% of proof-of-concept exploits within two days of their public release. The signatories call for urgent action from leaders, suppliers, governments and AI developers.

https://siliconangle.com/2026/08/27/openai-anthropic-and-100-plus-firms-warn-ai-attacks-are-about-to-scale/

Is Your Cloud Security Strategy Ready for AI’s Looming Threat?

AI agents are reshaping cloud security by finding and combining weaknesses far faster than human attackers. While a human tester might assess 50 routes to greater access in a day, an autonomous agent can test thousands within minutes, and only 38% of organisations report high confidence in their cloud security. Businesses should therefore focus on how permissions and configuration weaknesses combine to expose critical data, while adopting temporary access credentials, tighter controls over what users and systems can do, stronger separation between workloads, and continuous testing of potential attack routes.

https://www.csoonline.com/article/4215419/is-your-cloud-security-strategy-ready-for-ais-looming-threat.html

Vishing Campaign Abuses Microsoft Teams to Give Attackers a Foothold in Company Networks

Between January and April 2026, a coordinated voice phishing campaign targeted more than 150 employees at over 10 companies through Microsoft Teams. Attackers posed as internal IT support and used 26 distinct identities, and then tried to persuade staff to install malicious software or grant remote access to their computers. Successful calls often lasted 10 to 15 minutes. Collaboration platforms accounted for 42% of phishing alerts during the period, up from 30% in the previous four months, highlighting their growing use as a route into corporate networks. The documented intrusion attempts were blocked.

https://www.helpnetsecurity.com/2026/09/01/spring-ring-vishing-campaign-microsoft-teams/

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active cyberattack campaign is using convincing copies of trusted software websites to distribute malicious software. Primarily targeting Chinese-speaking users and China-based operations of multinational organisations, it has affected healthcare, manufacturing, technology, logistics, government, education and gaming. Once installed, the malware disables Windows Update, weakens Microsoft Defender, deletes volume shadow copies and prevents standard users from removing its payload directories. Microsoft assessed with moderate confidence that the activity was consistent with the China-associated Silver Fox threat group.

https://thehackernews.com/2026/09/fake-software-installers-disable.html

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

A phishing campaign sent 26,589 fake voicemail emails to 5,527 organisations between 1 June and 4 August 2026. Attackers concealed malicious code inside scalable vector graphic (SVG) attachments, a common image file format, while 95% of messages falsely appeared to originate from recipients’ own organisations. The broadly targeted campaign personalised subject lines using part of recipients’ email addresses. Despite using a single template, 75% of messages received Microsoft spam scores that treated them as not spam, demonstrating how familiar content and disguised attachments can bypass standard email controls.

https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/

Hacked before Their First Coffee: Why New Hires Risk Becoming Cybercriminals’ Favourite Target

New employees are especially attractive targets for cyber criminals, while Verizon reported that most successful breaches involved a human element. Attackers exploit public recruitment updates and unfamiliar company processes to send convincing fraudulent messages. Weak temporary passwords, excessive system access, delayed training and unsecured personal devices further increase exposure. Organisations can reduce risk by issuing unique credentials securely, requiring password changes at first login, using multi-factor authentication, limiting access to role requirements, removing unused accounts promptly and providing cyber security guidance from day one.

https://www.digitaljournal.com/article/hacked-before-their-first-coffee-why-new-hires-risk-becoming-cybercriminals-favourite-target/

Malvertising Is Moving from Deceptive Content to Weaponised Infrastructure

Malicious advertising increasingly hides harmful activity behind legitimate-looking adverts, using redirect chains, disposable domains and selective delivery to evade checks. PropellerAds found that while overall campaign rejections fell 42% between Q1 and Q2 2026, the number involving malware and antivirus-flagged threats rose 13%. Cloaking, where a campaign conceals its true destination or behaviour, accounted for 67% of advertiser suspensions. Organisations should therefore monitor an advert’s full journey and post-launch behaviour, rather than relying solely on initial content checks.

https://cybersecuritynews.com/malvertising-is-moving-from-deceptive-content-to-weaponized-infrastructure/

Stronger Security Drives Ransomware Groups to Recruit from Within

Ransomware groups are increasingly recruiting employees and contractors to bypass stronger cyber security controls. SentinelOne attributed 56% of insider incidents to negligence, such as phishing or lost devices. However, incidents involving malicious insiders with privileged access cost an average of $4.9 million each, while malicious insider activity rose 42% over the previous year. Organisations should rapidly remove access when staff leave, limit sensitive permissions, strengthen login verification and create a culture where employees can report mistakes quickly without fear.

https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Attackers favour repeatable, low-cost methods over sophisticated techniques. Microsoft reported that ClickFix, which tricks users into running malicious commands, appeared in 47% of its attack notifications and was its most commonly observed initial-access method, while Bitdefender reported that legitimate administrative tools featured in 84% of serious incidents. Vulnerability exploitation also rose from 20% to 31%, and ransomware appeared in 48% of breaches. Organisations should prioritise patching exposed systems, restrict powerful tools and scripts, strengthen identity controls, and ensure security alerts are actively monitored by people authorised to respond.

https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html

North Korean Remote Workers Are Broadening Their Job Hunt beyond IT

Huntress investigations indicate that suspected North Korean remote workers are expanding beyond IT into sales, marketing and healthcare roles. In one healthcare case, three accounts used services that concealed their locations, with less than half of their activity occurring during normal business hours. Investigators also found apparently falsified identity documents and, in another case, a company laptop connected to hardware that enabled remote operation. Organisations can reduce this risk by carrying out rigorous background checks before onboarding, researching candidates online and verifying their employment history.

https://www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/

Criminals Publish Data of 8.7m People after Airports Hack

Personal data belonging to 8.7 million customers of Manchester, London Stansted and East Midlands airports has been published online after airport operator MAG did not pay the ransom demanded by the attackers. The stolen information includes email addresses, phone numbers, addresses, vehicle registrations, purchasing history and details of past and planned travel. Its public availability increases the risk of targeted scams and further attacks using the stolen information. MAG says affected customers have been contacted, passengers’ physical safety was not at risk, and it is working with authorities and specialist advisers.

https://www.bbc.co.uk/news/articles/c74k39g3ee5o


Governance, Risk and Compliance

Your Board Has A Financial Expert—Why Doesn't It Have A Cyber One?

NIST, ISO, and Where to Begin With Security Frameworks - DevX

Help to build cyber resilience – New ABI Guidance - BIBA

Hiring for the AI Era: A New Challenge for CISOs - Infosecurity Magazine

Threats

Ransomware, Extortion and Destructive Attacks

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

AI ransomware operation steals 3.1TB from over 30 companies | Cybernews

Stronger Security Drives Ransomware Groups to Recruit From Within

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Ransomware and Destructive Attack Victims

Criminals publish data of 8.7m people after Manchester Airports Group hack - BBC News

ATF confirms cyberattack hit system containing info on its investigation targets | CyberScoop

Berlin Won’t Pay Extortion Group Claiming Data Theft - SecurityWeek

Healthcare cyberattacks hit pacemakers and millions of patient records

Cyberattack causes network outage at Boston Scientific, disrupts global operations - Help Net Security

Dialysis Chain Will Pay $15M Settlement in Interlock Attack

McKesson discloses breach after ShinyHunters claims patient data theft

Ransomware Gang Claims Nutex Health Data Breach - SecurityWeek

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

Phishing & Email Based Attacks

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign - Infosecurity Magazine

Phishing Targeting Financial Services Tripled in a Single Quarter. Here’s How to Defend Against It.

Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse

FBI raises alarm over deceptive phishing campaign targeting prominent people | CyberScoop

New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password - IT Security Guru

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Wave of X password reset emails could be hiding a sneak phishing attack | Mashable

The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action | Group-IB Blog

Other Social Engineering

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks - Help Net Security

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog

Clickfix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog

North Korean remote workers are broadening their job hunt beyond IT - Help Net Security

Wave of X password reset emails could be hiding a sneak phishing attack | Mashable

The Cybersecurity Control Money Can't Buy - Above the Law

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Artificial Intelligence

OpenAI, Anthropic and 100-plus firms warn AI attacks are about to explode - SiliconANGLE

Sharp rise in incidents of AI escaping users’ control, research finds | AI (artificial intelligence) | The Guardian

AI ransomware operation steals 3.1TB from over 30 companies | Cybernews

65% of Enterprises Have Seen AI Agents Act Out of Scope - Infosecurity Magazine

Majority of Senior Cybersecurity Leaders Have Limited Trust in AI | Security Magazine

How to respond to an AI agent security incident | CSO Online

AI security debt exposed as adversarial AI finds old flaws - SiliconANGLE

AI is making cyberattacks worse. You need a digital disaster plan | PCWorld

Unit 42 warns AI has shifted balance of power from defenders to attackers | CyberScoop

AI watchdog predicts doomsday within decade, unless guardrails are imposed on systems

91% of professionals say their firm still falls short on AI - how to fix that | ZDNET

NVIDIA NemoClaw vulnerability can hijack AI agents via websites | Cybernews

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

Is your cloud security strategy ready for AI’s looming threat? | CSO Online

The Guardrails Debate: Security Researcher Changes His Mind

Claude Mythos only model to complete full cyber kill chain, experts say

OpenAI says Astra AI model crosses 'Critical' cyber capability

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Anthropic explains how its AI models escaped their sandbox and hacked real systems | TechSpot

AI Gives Cybercriminals a Dangerous New Advantage

Lords considers government emergency AI kill switch | Computer Weekly

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

AI helps Chinese-speaking hackers speed up attacks on exposed servers | CSO Online

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says - SecurityWeek

Who is accountable when your AI agent goes rogue? | CSO Online

Report Finds AI Security Fails to Match AI Usage | Security Magazine

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

AI Cyberattacks Are Getting Faster. Companies Are Falling Behind

Fake Claude Opus 5 app delivers malware and wipes its own tracks - Help Net Security

Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems

Russian-Speaking Cybercriminals Used SpaceX’s AI Tool to Hack Seven Companies

Defining an AI Kill Switch Is Hard, but Necessary

ChatGPT can log into your web accounts without you now - but should you let it? | ZDNET

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails - Help Net Security

Why Enterprises Need AI FinOps, Security to Scale Responsibly

AI Model Evaluator METR Hit by Credential Theft, Probing

AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure | TechRadar

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities | CyberScoop

3 surveys deliver the same uncomfortable truth about adopting agentic AI | ZDNET

Apple escaped Android's 'toxic hellstew' - now Siri AI is creating a new one | ZDNET

Anthropic Just Beat The Pentagon In Court. A Judge Said National Security Was Used To Punish Its AI Rules. | IBTimes

Bots/Botnets

Dogged Russia-based botnet dismantled after 23-year run | CyberScoop

Careers, Roles, Skills, Working in Cyber and Information Security

Hiring for the AI Era: A New Challenge for CISOs - Infosecurity Magazine

Cybersecurity's “Hiring Crisis” is Fueling the Cybercrime Talent Pipel - Infosecurity Magazine

Cloud/SaaS

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks - Help Net Security

Is your cloud security strategy ready for AI’s looming threat? | CSO Online

New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password - IT Security Guru

Dropbox accounts breached through Lenovo email verification flaw

Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Lazarus Group Moves 244 Bitcoin (BTC) Worth $19.42M From Dormant Wallets - COINOTAG

Cyber Crime, Organised Crime & Criminal Actors

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say | Reuters

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Cybercrime moves into the mainstream: Why threat actors are increasingly turning to Telegram - Digital Journal

CRPx0 hacking service for dummies claims victim count more than quintupled

What underground forums can tell businesses about cyber risk | SC Media UK

Revolut scam steals £180,000 from Jersey residents in just four weeks

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Data Breaches/Leaks

Criminals publish data of 8.7m people after Manchester Airports Group hack - BBC News

Dropbox accounts breached through Lenovo email verification flaw

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Healthcare cyberattacks hit pacemakers and millions of patient records

Toy-making giant Hasbro disclose data breach affecting employees

Huge Latvia data breach exposes 1.2M citizens' data | Cybernews

More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen | TechRadar

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

McKesson discloses breach after ShinyHunters claims patient data theft

Bumble users allegedly exposed in 110M data sale claim | Cybernews

It sure looks like hackers breached a major ID card verification service | TechCrunch

Carhartt data breach exposes information of 12.9 million accounts

Robert Burns farm charity warns members after Beacon CRM cyberattack data breach - BBC News

Data Protection

Reform UK pledges to scrap GDPR for ‘light touch’ laws | Irish Independent

I asked 100 companies for my data. Some deleted it instead. - Ars Technica

Denial of Service/DoS/DDoS

Pro-Russian hackers launch series of large-scale cyberattacks on Norway's government sector — CCD

Encryption

Turns out Brits would quite like their private messages to stay private

UK says 'no' to backdoors, but the government isn't listening – Computerworld

Fraud, Scams and Financial Crime

Revolut scam steals £180,000 from Jersey residents in just four weeks

Drivers charged £370 in car park QR code scam

Nuisance-call blocker fined £190k for being a nuisance caller

Insider Risk and Insider Threats

Stronger Security Drives Ransomware Groups to Recruit From Within

North Korean remote workers are broadening their job hunt beyond IT - Help Net Security

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

Internet of Things – IoT

Think twice before installing this device promising free movies - Ars Technica

Law Enforcement Action and Take Downs

Dogged Russia-based botnet dismantled after 23-year run | CyberScoop

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

Two alleged TeamPCP hackers arrested over global supply chain attacks - Help Net Security

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

68-year-old imprisoned after making $1.3 million by pirating IPTV services

Nigerians extradited to US for sextortion, deaths of two teens

Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

Malvertising

Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Scareware ads keep running on Google's transparency tool, even after they're reported - Help Net Security

Malware

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

You don't want this Sleepwalker backdoor on your Windows machine

Crooks push Mac malware through fake OpenAI Codex ads

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Think twice before installing this device promising free movies - Ars Technica

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Fake Claude Opus 5 app delivers malware and wipes its own tracks - Help Net Security

Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails - Help Net Security

Microsoft Defender flags legitimate Google search links as malicious

Mobile

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Models, Frameworks and Standards

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure - SecurityWeek

Cyber Security Bill enters Lords committee stage - UK Parliament

Peers propose report into Computer Misuse Act reform | Computer Weekly

Reform UK pledges to scrap GDPR for ‘light touch’ laws | Irish Independent

NIST, ISO, and Where to Begin With Security Frameworks - DevX

NIS2 compliance: Fixing IAM and access control before the 2026 audit - Help Net Security

CMMC Compliance Third-Party Assessment Is Paused. The Risk Isn't.

Outages

Massive Microsoft 365 outage causes auth issues, service failures

OpenAI confirms ChatGPT outage as users report errors

Telstra outage caused by failure to prioritise well-known network vulnerabilities - ABC News

Passwords, Credential Stuffing & Brute Force Attacks

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password - IT Security Guru

Five billion passkeys later, passwords are still hanging around

Threat actors are posing as AI crawlers to hunt for exposed credentials - Help Net Security

Wave of X password reset emails could be hiding a sneak phishing attack | Mashable

AI Model Evaluator METR Hit by Credential Theft, Probing

Privacy, Surveillance

UK says 'no' to backdoors, but the government isn't listening – Computerworld

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

How Facebook and Instagram will change after Meta's $18B settlement - and where the money is going | ZDNET

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Regulations, Fines and Legislation

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure - SecurityWeek

Cyber Security Bill enters Lords committee stage - UK Parliament

Peers propose report into Computer Misuse Act reform | Computer Weekly

Lords considers government emergency AI kill switch | Computer Weekly

UK says 'no' to backdoors, but the government isn't listening – Computerworld

Five Washington developments every CISO should be watching | feature | SC Media

Nuisance-call blocker fined £190k for being a nuisance caller

Reform UK pledges to scrap GDPR for ‘light touch’ laws | Irish Independent

The AI Kill Switch Act is repeating the Clipper Chip’s mistakes | CyberScoop

Anthropic Just Beat The Pentagon In Court. A Judge Said National Security Was Used To Punish Its AI Rules. | IBTimes

White House bans foreign-made equipment for power generation over cyber backdoor concerns | The Record from Recorded Future News

CMMC Compliance Third-Party Assessment Is Paused. The Risk Isn't.

Social Media

How Facebook and Instagram will change after Meta's $18B settlement - and where the money is going | ZDNET

How to stop getting unwanted password reset emails from X

Bumble users allegedly exposed in 110M data sale claim | Cybernews

US Navy tells sailors and their families: scrub your social media, enemies are watching

Supply Chain and Third Parties

Two alleged TeamPCP hackers arrested over global supply chain attacks - Help Net Security

Robert Burns farm charity warns members after Beacon CRM cyberattack data breach - BBC News


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Where and how Putin could expand his war in Europe beyond Ukraine - Atlantic Council

Software company chief warns threat of AI cyber warfare already here | The Jerusalem Post

NATO Sees Rising Russian Sabotage and Cyber Activity Across Europe

Chinese Fire Ant hackers turn Cisco routers into spying platforms

The government wants households to prepare for disaster – but the UK’s real test will be the NHS

US Navy tells sailors and their families: scrub your social media, enemies are watching

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

Nation State Actors

China

Chinese Fire Ant hackers turn Cisco routers into spying platforms

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

AI helps Chinese-speaking hackers speed up attacks on exposed servers | CSO Online

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says - SecurityWeek

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks

US Navy tells sailors and their families: scrub your social media, enemies are watching

White House bans foreign-made equipment for power generation over cyber backdoor concerns | The Record from Recorded Future News

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Russia

Where and how Putin could expand his war in Europe beyond Ukraine - Atlantic Council

Russia’s hybrid warfare campaign in Europe is escalating | Just The News

NATO Sees Rising Russian Sabotage and Cyber Activity Across Europe

Russia is preparing strikes beyond Ukraine’s borders; British companies are at risk — Daily Mail | УНН

The government wants households to prepare for disaster – but the UK’s real test will be the NHS

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Pro-Russian hackers launch series of large-scale cyberattacks on Norway's government sector — CCD

Russian-Speaking Cybercriminals Used SpaceX’s AI Tool to Hack Seven Companies

US Navy tells sailors and their families: scrub your social media, enemies are watching

Royal Family overhaul cybersecurity amid growing threat from Russian hackers | The Independent

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails - Help Net Security

Russian national facing 20 years for malware campaign that infected 80,000 freelancers | The Record from Recorded Future News

Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say | Reuters

North Korea

North Korean remote workers are broadening their job hunt beyond IT - Help Net Security

US Navy tells sailors and their families: scrub your social media, enemies are watching

Lazarus Group Moves 244 Bitcoin (BTC) Worth $19.42M From Dormant Wallets - COINOTAG

Iran

Britain ‘must brace for more Iranian cyber attacks’

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

US Navy tells sailors and their families: scrub your social media, enemies are watching

Experts: Water Cyber Attacks Had Scale, Not Sophistication

Iran Attempted Cyberattacks on US Infrastructure, NBC Reports




Vulnerability Management

AI Cyberattacks Are Getting Faster. Companies Are Falling Behind

CISA: Most exploited vulnerabilities should have been eradicated decades ago

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree - Help Net Security

AI’s Vulnerability Surge May Be More Manageable Than Feared

Telstra outage caused by failure to prioritise well-known network vulnerabilities - ABC News

Vulnerabilities

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - Help Net Security

Windows 11 KB5120998 update released with 35 changes and fixes

China-linked hackers turn Cisco routers into covert attack infrastructure | CSO Online

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities - SecurityWeek

HPE patches critical ArubaOS-CX remote code execution flaw

Chrome and Firefox Updates Patch Dozens of Vulnerabilities - SecurityWeek

Google fixes the sixth actively exploited Chrome zero-day of 2026

Firefox 155 patches 30 security flaws, adds sortable tab groups | PCWorld

Attackers exploit zero-days in consistently besieged SonicWall product | CyberScoop

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks - SecurityWeek

Hackers Chain Two New SonicWall Zero-Day Vulnerabilities - Infosecurity Magazine

Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs

U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Over 8,300 Gitea servers vulnerable to code execution attacks

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut releases second emergency patch for exploited flaws

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Hackers push malicious Virtualizor update in BGP hijacking attack

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability - SecurityWeek

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 28 August 2026