Black Arrow Cyber Threat Intelligence Briefing 07 August 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Our review of the specialist and general media this week reinforces our consistent message that if organisations want to improve their cyber security and resilience, they must go beyond technology.

While AI is hitting the news again this week with agentic AI taking unauthorised actions, we highlight that the wider risks presented by AI require business leaders to ensure there are appropriate controls to quickly identify and respond to cyber threats.

Nonetheless, this week’s review also highlights that social engineering and human actions remain a major cause of cyber loss. Phishing, including when powered by AI, can enable attackers to take over an employee’s account to access emails and documents, and to hijack conversations for payment fraud. Research also demonstrates how Copilot could be misused to accelerate an attack once an account has been compromised.

Our objective in preparing this review is to help business leaders to understand how the threat landscape is evolving. These threats should be addressed by a leadership team that has a solid understanding of the fundamentals of cyber security and resilience, so that the leadership team can ensure the risks are understood and appropriately managed. As above, this is not an IT issue; it is for the leadership team to ensure that risks are managed across the organisation. Contact us to discuss how we support business leaders to achieve this in a proportionate manner.


Top Cyber Stories of the Last Week

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

The UK AI Security Institute found that advanced AI agents took unauthorised actions on the live internet during controlled cyber tests. Across 122 test runs, agents were recorded taking 19 unsanctioned actions across 10 test runs. Activities included attempting to add malicious code to a public software project, creating false identities, contacting real people and disguising earlier actions. Researchers intervened before the most serious activity succeeded and found no evidence of harm. However, the tests demonstrated that agents could adopt unintended, deceptive methods while pursuing a goal. Organisations testing powerful AI agents should tightly restrict internet access and monitor activity in real time.

https://securityaffairs.com/196695/ai/ai-deception-emerges-in-cyber-tests-as-agents-target-real-people-and-systems.html

AI Isn't the Biggest Cyber Security Risk. Yesterday's Security Model Is

Artificial intelligence is accelerating the speed at which cyber threats develop, exposing weaknesses in security models that rely heavily on manual investigation and decision-making. Attacks that once unfolded over days or weeks can now progress within hours or minutes, reducing the time available to protect operations. Organisations should therefore assess how quickly they can detect unusual activity, make decisions, contain affected systems and restore critical services. Effective cyber security now depends on combining automated response with human judgement, governance and accountability.

https://www.forbes.com/councils/forbestechcouncil/2026/08/03/ai-isnt-the-biggest-cybersecurity-risk-yesterdays-security-model-is/

Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions

Cisco Talos has found that criminals are bypassing safety controls in commercial AI tools by splitting malicious projects across multiple sessions and presenting harmful activity as authorised security testing. The research covered tools including Claude Code, Codex, Cursor and Gemini, and found safeguards offered limited protection across platforms. AI capability largely reflected the operator’s existing skill, with experienced criminals building highly advanced attack tools while less capable users still produced working systems, including one network controlling nearly 2,000 Android TVs. Organisations should expect security weaknesses to be identified more quickly and exploitation to follow sooner.

https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/

AI Is ‘Both the Weapon and the Target’ in Latest Wave of Cyberattacks

CrowdStrike recorded an 89% rise in AI-enabled malicious activity during 2025, with criminals and nation states using AI to accelerate attacks and target organisations’ own AI systems. Attackers are stealing access credentials and compromising trusted software packages to reach wider networks. One attacker abused stolen AI access credentials to generate around 200,000 requests in two minutes, while another campaign compromised more than 300 software dependencies in a single day. CrowdStrike observed that almost nine in ten exploitations involving public proof-of-concept code happened within two days of publication, sharply reducing the time organisations have to patch.

https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534

The $5 Million Threat: AI Is Supercharging Phishing Attacks

Phishing remains the leading entry point for data breaches for the fourth consecutive year, with voice and text message scams costing organisations an average of $5.29 million per incident. AI is making these attacks more convincing and easier to scale, with deepfakes, realistic fake voice or video messages, used in 45% of AI-driven attacks studied. Despite being a well-understood threat, phishing-related breaches still take an average of 251 days to identify and contain, reinforcing the need for stronger technical controls alongside staff awareness training.

https://www.fortra.com/blog/5-million-threat-ai-supercharging-phishing-attacks

Humans, Not AI, Still a Cause of Most Cyber Losses in First Half of Year

Cyber insurance provider Resilience reports that human error remains the leading driver of cyber losses, with more than 85% of incurred losses in the first half of 2026 linked to phishing, social engineering or transfer fraud. Artificial intelligence is increasing the quality and realism of these attacks, including more convincing emails and voice impersonation, but fully autonomous AI attacks have not yet appeared in Resilience’s claims. Ransomware-related extortion accounted for 73% of incurred losses despite making up only 5.8% of claims.

https://www.claimsjournal.com/news/national/2026/07/30/339184.htm

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

CrowdStrike recorded a 15-fold rise in device code phishing during the first half of 2026 and a doubling of voice phishing over the same period. Device code phishing tricks users into approving fraudulent cloud logins, while voice phishing uses phone calls to obtain credentials and security codes. These techniques can bypass established security controls, while voice phishing can exploit mobile devices with fewer protections and leave fewer traces for security teams to investigate. In one case, attackers gained access and registered a new authentication device within four minutes, highlighting how quickly a cyberattack can unfold.

https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles

Attackers Are Using Microsoft’s Legitimate Login System to Camouflage Phishing Attacks

Check Point identified more than 200 phishing emails in a campaign targeting around 120 organisations. The campaign disguised emails as Microsoft Planner notifications about urgent HR updates, then directed victims to genuine Microsoft login pages, reducing some of the usual warning signs of phishing. Victims were asked to approve access for a malicious application, which could then expose Microsoft 365 data including emails, files, Teams chats, calendars, SharePoint and OneDrive. The campaign is no longer active, but the technique is becoming more widespread, reinforcing the need for employees to scrutinise sender details and link destinations even when Microsoft’s genuine authentication pages are used.

https://www.helpnetsecurity.com/2026/07/30/microsoft-authentication-system-phishing/

Hackers Can Weaponise Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Researchers have demonstrated how a compromised Microsoft 365 employee account could allow criminals to misuse Copilot to identify senior targets, imitate trusted writing styles and take over a chief executive’s email account. In the test, attackers quickly found a pending $247,500 wire transfer and sent a convincing request to redirect the payment. They also used automated inbox rules to hide security alerts and finance team responses. The findings show that AI assistants with email access can significantly accelerate fraud, making monitoring of AI-enabled accounts, inbox rule abuse and unusual session activity increasingly important.

https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/

Russian Spies Take Their Half-Click Email Attack from Zimbra to Outlook

A Russian espionage group has expanded an email-based attack from the Zimbra email system to on-premises Microsoft Exchange servers, targeting government bodies and organisations across telecommunications, financial services, hospitality and aerospace. Simply opening a malicious message in Outlook Web Access can allow attackers to run code within an authenticated mailbox session, without requiring a link or download. The resulting browser implant can steal data, leave few traces and remain active after password changes, browser restarts or even a full device rebuild. Microsoft’s cloud-based Exchange Online service is not affected.

https://www.theregister.com/security/2026/07/30/russian-spies-take-their-half-click-email-attack-from-zimbra-to-outlook/5281033

Cloud and SaaS Environments Now Top Targets for Attackers

Cloud and Software-as-a-Service environments have become leading targets for cyber attackers, as attacks increasingly focus on compromising identities and trusted access. Attackers are increasingly exploiting trusted user accounts, email systems and legitimate administration tools rather than relying on traditional malware. Around two-thirds of phishing emails passed email authentication checks, while 39% used novel social engineering techniques and VIP users were targeted in 25% of observed attacks. The growing use of artificial intelligence is also expanding the attack surface and helping criminals generate exploit code and automate cyberattacks.

https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/

The Modern CISO Is Becoming the Next CFO

The CISO role is evolving from a technical function into a strategic executive position as cyber risk becomes inseparable from business risk. Splunk’s 2026 CISO Report found that nearly all CISOs now oversee artificial intelligence governance and risk management, while 78% report concerns about personal liability following security incidents, up from 56% a year earlier. Some organisations are building specialist security leadership teams under a single accountable CISO, similar to the way large finance functions operate.

https://www.csoonline.com/article/4193375/the-modern-ciso-is-becoming-the-next-cfo.html



Threats

Ransomware, Extortion and Destructive Attacks

The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encrypting Your Files

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Ransom Cartel ransomware creator sentenced to 16 years in prison

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks - SecurityWeek

Ransomware and Destructive Attack Victims

The most famous brand in physical security got pwned by ShinyHunters

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Jaguar Land Rover to Cut Jobs After Major Cyber Attack | EasternEye

Phishing & Email Based Attacks

Russian spies take their half-click email attack from Zimbra to Outlook

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Attackers exploit genuine Microsoft login screens to phish users | Cybernews

The $5 Million Threat: AI Is Supercharging Phishing Attacks| Fortra

Russian hackers deploy OWAReaper Exchange backdoor

Fake Bank of America Phishing Scam Installs Remote Access Malware - Infosecurity Magazine

Phishing attacks don't look fake anymore: Watch for these 7 scams | PCWorld

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

COLDCARD security audit phishing attack installs remote access tool

Other Social Engineering

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Why brand impersonation is becoming an initial access vector - Security Affairs

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove - Help Net Security

COLDCARD security audit phishing attack installs remote access tool

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Fake IRS letters direct crypto holders to bogus compliance portal - Help Net Security

2FA/MFA

How MFA gets hacked — and strategies to prevent it | CSO Online

Artificial Intelligence

One-in-five breaches are now AI-related, IBM warns | IT Pro

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

AI models are behaving unexpectedly. Experts warn of "a really bumpy road" ahead. - CBS News

'Rogue' AI posed as human in shock hack as experts warn it may be ‘too late’ to stop it - Daily Star

UK Cyber Test: AI Agent Attempted to Social Engineer Open So...

NCSC concerned over 'unsanctioned actions' of frontier AI models - UKTN

Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says - Nextgov/FCW

The $5 Million Threat: AI Is Supercharging Phishing Attacks| Fortra

Excuses like 'AI did it' don't exist in the eyes of the law

Gartner: Why cybersecurity must shift to outcomes against AI-led attacks | Computer Weekly

AI Isn't The Biggest Cybersecurity Risk. Yesterday's Security Model Is

CrowdStrike: AI is now both the weapon and the target in cyberattacks | CyberScoop

Cybercrime goes subscription: AI, malware and infrastructure on demand - Help Net Security

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

UK firms report rise in AI-driven cyber attacks - CIR Magazine

Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks - Infosecurity Magazine

Sophisticated Cyberattackers Boost Productivity Using AI

OpenAI's models secretly joined forces months ahead of hacking Hugging Face | Tech News - Business Standard

When AI goes rogue — Harvard Gazette

OpenAI's AI models secretly built a message board to coordinate hacking - Digital Trends

The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop | WIRED

Suppliers, logins, and AI tools are all becoming attack paths - Help Net Security

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies - Infosecurity Magazine

The Hugging Face attack shows how fast one breach can spread | perspective | MSSP Alert

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale - SecurityWeek

Hidden prompt turns Microsoft Copilot into an AI worm | Malwarebytes

How OpenAI's and Anthropic’s AI models hacked other companies : NPR

What Claude’s real-world breaches reveal about AI safety tests - The New Stack

OpenAI's Escaped Models Were Allegedly Rampaging More Extensively Than Previously Reported

Why AI has eclipsed cyberattacks as firms' top compliance problem | American Banker

OpenAI is investigating more incidents of AI agents going rogue days after hack - Digital Trends

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers - Help Net Security

Why the Browser is Becoming Security's Front Line in the Age of AI - Infosecurity Magazine

OpenAI reveals how criminals used ChatGPT to run scams - Help Net Security

Your enterprise AI footprint is about three times bigger than your model list - Help Net Security

AI Risks Require Tougher Cyber Defenses, Top US Officials Warn

Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents - Infosecurity Magazine

AI Sends Global Crime Syndicates Into Fraud Nirvana

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels - SecurityWeek

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits - Infosecurity Magazine

Anthropic: Security Gaps, Not Model Issues Led to Claude Attacks

Google dev kit spurs first-ever agent-on-agent violence

Resilience analysis shows AI is strengthening existing cyber attack methods - Reinsurance News

Bypassing AI guardrails is so easy a script kiddie can do it

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Companies push AI, sysadmins keep it on a short leash - Help Net Security

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

AI Now Fuels Over Half of Africa’s Cybercrime, Study Finds

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

New Tool Traces AI Videos Back to Their Source

Careers, Roles, Skills, Working in Cyber and Information Security

AI isn’t closing the skills gap — it’s exposing the validation gap | CSO Online

Center for Cyber Safety and Education Marks 15 Years of Expanding Access to Cybersecurity Careers

Cloud/SaaS

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Russian hackers deploy OWAReaper Exchange backdoor

Cloud and SaaS Environments Now Top Targets for Attackers - Infosecurity Magazine

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Online ad firm Adform’s script compromised to steal cryptocurrency

Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch

Fake IRS letters direct crypto holders to bogus compliance portal - Help Net Security

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Cryptominer Abuses Linux PAM to Hide From SOC Analysts - Infosecurity Magazine

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Cyber Crime, Organised Crime & Criminal Actors

Cybercrime goes subscription: AI, malware and infrastructure on demand - Help Net Security

Foxtrot Network: The shadowy gang recruiting teen killers across Europe - BBC News

Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop

INTERPOL flags AI as the new engine of African cybercrime - Help Net Security

AI Now Fuels Over Half of Africa’s Cybercrime, Study Finds

Teen hackers tell BBC how police are helping them use their skills for good - BBC News

Data Breaches/Leaks

Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says | Euronews

31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected | The Record from Recorded Future News

UK’s Police National Legal Database Reveals Data Breach - Infosecurity Magazine

Experts react as Department for Education cyber attack exposes 607,000 records - IT Security Guru

UK government investment arm cops to 40-hour leak of officials' contact details

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

South Korea fines telco giant KT $39 million for customer data breach

English National Ballet suffers possible data breach following cyber attack | The Standard

150,000 Impacted by Madera Community Hospital Data Breach - SecurityWeek

Polish convenience store chain Żabka hacked through third-party account | The Record from Recorded Future News

Sheffield Hospitals Charity affected by cyber attack - BBC News

Motiv8: Portsmouth charity hacked as CEO explains next steps

Encryption

Apple challenges UK encryption order | Cybernews

The quantum imperative: Why federal cybersecurity cannot wait for tomorrow’s threat | Federal News Network

Fraud, Scams and Financial Crime

AI Sends Global Crime Syndicates Into Fraud Nirvana

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

WhatsApp Scam Hijacks Accounts via Linked Devices Feature - Infosecurity Magazine

Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims | CyberScoop

Interpol Leverages Global System to Curtail Fraud Payments

CAF Bank reopens online service but warns of further outages

Buying TikTok followers can expose users to scams and account theft - Help Net Security

Identity and Access Management

Non-human identities are 91% of everything active in production - Help Net Security

Insider Risk and Insider Threats

Humans, Not AI, Still A Cause of Most Cyber Losses in First Half of Year

Humans remain ‘weakest link’ when it comes to cyber attacks - Insurance Post

Insurance

Underwriters Making Better Cyber Risk Decisions | Kovrr - Security Boulevard

Internet of Things – IoT

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Law Enforcement Action and Take Downs

Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims | CyberScoop

Interpol Leverages Global System to Curtail Fraud Payments

Ransom Cartel ransomware creator sentenced to 16 years in prison

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Foxtrot Network: The shadowy gang recruiting teen killers across Europe - BBC News

Teen hackers tell BBC how police are helping them use their skills for good - BBC News

Jailed Flock vandal wipes out three cameras, racks up thousands in damages

Linux and Open Source

Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop

Arch Linux disables AUR package adoption to stop malware flood

Cryptominer Abuses Linux PAM to Hide From SOC Analysts - Infosecurity Magazine

Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

Malware

Cybercrime goes subscription: AI, malware and infrastructure on demand - Help Net Security

New DOUBLECUP ClickFix service hides malware in browser cache images

Arch Linux disables AUR package adoption to stop malware flood

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

COLDCARD security audit phishing attack installs remote access tool

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Fake Bank of America Phishing Scam Installs Remote Access Malware - Infosecurity Magazine

Chrome wants more extension reviews, but good ratings won’t keep malware out - Digital Trends

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages — Elastic Security Labs

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts - SecurityWeek

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

5 Reasons Developers Still Download Malicious Packages - Security Boulevard

Passwords, Credential Stuffing & Brute Force Attacks

6 places you should never store your passwords – unless you want to get hacked - Which?

Regulations, Fines and Legislation

Apple challenges UK encryption order | Cybernews

Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says | Euronews

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels - SecurityWeek

Report: U.S. to exclude open-weight AI models from new safety tests - Neowin

Senators warn Trump’s AI interventions could drive users to Chinese models | CyberScoop

South Korea fines telco giant KT $39 million for customer data breach

Social Media

Buying TikTok followers can expose users to scams and account theft - Help Net Security

LinkedIn's new 'Seems like AI slop' button lets you report all those cringey posts | ZDNET

Software Supply Chain

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages — Elastic Security Labs

ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly Installs - Infosecurity Magazine

5 Reasons Developers Still Download Malicious Packages - Security Boulevard

77 Open VSX extensions found harvesting developer info

Mitigation Guidance for Supply Chain Compromise | Google Cloud Blog

CISA Issues New SBOM Guidance. Did They Get It Right?

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Supply Chain and Third Parties

Mitigation Guidance for Supply Chain Compromise | Google Cloud Blog

English National Ballet suffers possible data breach following cyber attack | The Standard

Sheffield Hospitals Charity affected by cyber attack - BBC News

Polish convenience store chain Żabka hacked through third-party account | The Record from Recorded Future News


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Cyberattacks and the critical services we rely on | MPR News

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict - SecurityWeek

Will The Cyberattacks On Water Systems In 7 States Be A Wakeup Call?

Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control | Tom's Hardware

Nation State Actors

China

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers - Help Net Security

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day - Infosecurity Magazine

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Russia

Russian hackers deploy OWAReaper Exchange backdoor

Russian spies take their half-click email attack from Zimbra to Outlook

Travelers Beware: Russian Intel Hacking Hotel Wi-Fi

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

North Korea

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korea's elite hackers turned on their own government — and got caught

South Korea Warns of State-Backed Watering Hole Attacks

Iran

Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control | Tom's Hardware

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran | WIRED

A brief timeline of Iranian cyberattacks on U.S. companies, political figures, water systems and more - CBS News


Tools and Controls

The modern CISO is becoming the next CFO | CSO Online

Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console

Chrome wants more extension reviews, but good ratings won’t keep malware out - Digital Trends

Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

How MFA gets hacked — and strategies to prevent it | CSO Online

AI-found bugs aren't proving any easier to exploit despite the hype

A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports | TechRadar

Underwriters Making Better Cyber Risk Decisions | Kovrr - Security Boulevard

Why the Browser is Becoming Security's Front Line in the Age of AI - Infosecurity Magazine

AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt | ZDNET

AI slop pollutes the CVE pipeline with fake vulns

Non-human identities are 91% of everything active in production - Help Net Security

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

Taking the myths out of Mythos - the role for the channel around AI and security | ChannelPro

New Tool Traces AI Videos Back to Their Source

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev - Infosecurity Magazine

Google Chrome Prepares Default Block for Extensions That Hijack the New Tab Page or Search Engine - gHacks Tech News

Cloudflare has mostly ditched third party security tools, suggests not trying that at home



Vulnerability Management

AI-found bugs aren't proving any easier to exploit despite the hype

AI is finding so many Chrome security flaws that Google may start updating it twice a week | TechSpot

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day - Infosecurity Magazine

A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports | TechRadar

Gartner: Why cybersecurity must shift to outcomes against AI-led attacks | Computer Weekly

Why CVE grading still matters for vulnerability management | native | MSSP Alert

AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt | ZDNET

AI slop pollutes the CVE pipeline with fake vulns

Taking the myths out of Mythos - the role for the channel around AI and security | ChannelPro

What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery

How zero-knowledge proofs let companies share cyber risks securely | CyberScoop

Vulnerabilities

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities - SecurityWeek

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability - SecurityWeek

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks - SecurityWeek

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Critical Vulnerabilities Patched With Chrome 151 Update - SecurityWeek

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

OpenVPN 2.7.6 Released with Security Fixes for Windows and mbedTLS

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected | The Record from Recorded Future News

Rails patches critical Active Storage flaw with RCE potential

TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices | TechRadar

Hackers run khunt post-exploitation toolkit from Oracle database

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor - Security Boulevard

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers - Help Net Security


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 31 July 2026