Black Arrow Cyber Threat Intelligence Briefing 09 October 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start this week with a reminder that business leaders should use established security controls to manage the growing cyber risks presented by AI. Microsoft reports that attackers can now steal data and spread across systems within minutes rather than days, reinforcing the need to control access, monitor suspicious behaviour and prepare to respond. Reports of AI agents acting outside intended limits and employees using unapproved AI tools highlight the need for organisations to establish clear permissions, oversight and accountability. Deepfake phone and video calls reinforce the importance of operational controls and practical employee training.

When a cyber incident happens, insurance can help absorb financial losses but organisations still need effective controls and rehearsed response arrangements to mitigate the damage. We examine risks from insecure supply chains and criminals using employees to gain entry to organisations. We also take a wider view, looking at record cyberattack attempts against monitored UK businesses and Russia’s use of cyberattacks and sabotage across Europe.

For business leaders, these insights reinforce the need to manage cyber security and resilience across people, operations and technology. Contact us to discuss how to achieve this through proportionate cyber governance.

Top Cyber Stories of the Last Week

AI Has Changed Attack Speed, Not Security Fundamentals

AI tools are helping both attackers and defenders identify software weaknesses, as attackers develop ways to exploit them more quickly. Protecting applications while security fixes are pending depends on established practices, despite renewed attention to “virtual patching”, which uses protective controls to reduce exposure to unfixed weaknesses. For business leaders, priorities include restricting access, giving users only the permissions they need, encrypting data and monitoring for suspicious activity. Organisations should also strengthen incident response procedures and continually assess weaknesses.

https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

AI is reducing the time attackers need after a breach to steal data, uncover login details and spread across systems from days to minutes, according to Microsoft’s Digital Defense Report 2026. Phishing, which uses deceptive messages to gain access, increased from 7% of incidents in 2025 to 23% in 2026. Attacks exploiting weaknesses in internet-facing applications rose from 15% to 24%. Government was the most targeted sector, accounting for 27% of attacks. Microsoft recommends investing in AI-supported defences, stronger checks on users’ identities and tighter controls over access to sensitive systems.

https://www.infosecurity-magazine.com/news/microsoft-ai-attack-time-minutes/

OpenAI Alerts 100+ Orgs That Its ‘Misaligned Models’ Attempted to Break In – or Worse

OpenAI contacted over 100 organisations about possible access to their systems by its agents acting outside their intended scope; OpenAI stressed that notification did not necessarily indicate system compromise or access to private information. Separately, an analysis of public evidence by Asymmetric Security found that OpenAI’s agents accessed data belonging to 55 organisations including government bodies; it also identified that OpenAI’s agents had accessed the testing environments of third parties, while gaps in records prevented investigators from ruling out access to sensitive data. The notifications and findings raise concerns regarding AI developers’ responsibility for limiting and monitoring agents’ actions.

https://www.theregister.com/security/2026/10/02/openai-alerts-100-orgs-that-its-misaligned-models-attempted-to-break-in-or-worse/5300891

Why Staff Using ChatGPT, Claude and Gemini for Work Could Create Problems for Employers

Employees using unapproved AI tools such as ChatGPT, Claude and Gemini for work risk exposing confidential business and customer information. Employers may lack visibility over which tools staff use and what data they share. Experts recommend approved alternatives, staff training and clear limits on access to sensitive information. As AI systems take on more tasks with less human supervision, businesses also need thorough testing, ongoing monitoring and clear human accountability, including decisions about what systems can access and when to switch them off.

https://www.thenationalnews.com/news/uae/2026/10/07/why-staff-using-chatgpt-claude-and-gemini-for-work-could-create-problems-for-employers/

A Familiar Face Is No Longer Proof: Rethinking Social Engineering Defence for the Deepfake Era

Artificial intelligence is making impersonation scams more convincing and easier to carry out at scale. Cyber security experts warn that deepfakes, which imitate someone’s voice or appearance, can exploit trust to obtain money, passwords or sensitive information. Unexpected or urgent requests should be checked through a separate, trusted route, such as calling a previously saved number. Organisations should reinforce these checks through regular, practical staff training, encourage strong, unique passwords with additional identity checks, and ensure employees confirm that AI tools are approved before entering company information.

https://www.itsecurityguru.org/2026/10/05/a-familiar-face-is-no-longer-proof-rethinking-social-engineering-defence-for-the-deepfake-era/

Botnets, Adversarial Attacks and Data Poisoning Top Leaders’ AI Threat List

PwC’s survey of 3,934 business and technology leaders across 71 countries found that half of security and technology executives identified attacks targeting artificial intelligence (AI) systems among their five biggest preparedness gaps. While 84% of security and finance leaders expect cyber security budgets to increase, only 39% of leaders asked had fully formalised plans to maintain or recover operations following cyber incidents. Fewer than a quarter would allow AI tools to manage and resolve attacks without human approval, reflecting caution about delegating responsibility to systems whose accuracy is not guaranteed.

https://www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/

Report Surfaces Sharp Increase in Malware Detections

Malicious software has overtaken phishing as the most frequently detected threat in EfficientIP’s analysis of 150 billion transactions through the Domain Name System, which helps direct internet traffic. Malware detections almost doubled to 3.84 billion, while the total number of threat signals increased by 24% to 13.85 billion. Phishing detections fell by 10%. EfficientIP suggests artificial intelligence could be helping criminals develop malware and launch attacks faster, although this remains unproven. The findings highlight the value of reviewing cyber security defences to block threats before they reach organisational networks.

https://securityboulevard.com/2026/10/report-surfaces-sharp-increase-in-malware-detections/

Cyber Insurance Is Not a Cyber Security Strategy

The 2026 Travelers Risk Index found that 70% of surveyed businesses bought cyber insurance, seven percentage points higher than last year. However, although cover can limit financial losses, it cannot prevent an incident. Only 72% of respondents used additional identity checks to protect administrator accounts, and almost nine in ten used artificial intelligence with only 59% working with formal rules governing staff use. Businesses need to rehearse cyberattack scenarios and test whether their response plans work in practice. For business leaders, insurance needs to sit alongside effective security measures including clear AI policies and practised procedures for managing an incident.

https://abovethelaw.com/2026/10/cyber-insurance-is-not-a-cybersecurity-strategy/

What Is Vendor Risk Assessment and Its Importance?

Weaknesses in external suppliers can expose organisations to data breaches, service disruption and reputational harm, with studies suggesting that 60% of organisations experience incidents linked to these vulnerabilities. Assessing suppliers’ cyber security, financial health and regulatory compliance before appointing them helps identify potential problems early. Oversight should extend to the supplier’s supplier, whose failings can also create risks. Regular reviews, closer scrutiny of higher-risk relationships and documented plans to address weaknesses can support ongoing protection. Automated tools can help track changes and make assessments more efficient.

https://smallbiztrends.com/vendor-risk-assessment/

Criminal Recruiters Want People on Your Payroll

Criminals are seeking employees willing to misuse workplace access to steal information, manipulate accounts, redirect shipments and enable fraud. Researchers identified examples where criminals tried to enlist existing employees or persuade accomplices to apply for jobs at targeted organisations, while others advertised illicit services they claimed relied on access provided by staff. Transportation was the most frequently mentioned industry, followed by technology and telecommunications; this ranking reflects the material analysed and does not establish how widespread insider threats are across industries.

https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/

How One Person’s Personal Information Can Put the Whole Family at Risk

One person’s poor cyber security habits can expose an entire household through shared accounts and connected devices. In December 2019, an attacker accessed a family’s Ring cameras and harassed a 13-year-old using login details stolen from another website which had been reused on the Ring account. Password reuse, publicly shared personal details and outdated devices can increase risks across the family, including fraud and identity theft. Unique passwords, an additional identity check when signing in, regular software updates and helping relatives recognise scams can reduce these risks.

https://cybernews.com/security/how-one-persons-information-can-put-the-family-at-risk/

UK Businesses Faced Record Cyberattack Attempts in Q3 2026

Beaming’s monitoring recorded a quarterly high in detected cyberattack attempts against UK businesses between July and September 2026. Each monitored business averaged 203,585 attempts, equivalent to 2,213 daily; an increase of almost 7% on the previous quarter. Services allowing remote management of connected equipment attracted the most attempts, followed by web services. During Cyber Security Awareness Month, Beaming recommends reviewing staff and supplier access, removing unnecessary remote connections, updating systems and testing backup restoration, with clear responsibilities for responding to incidents.

https://pressat.co.uk/releases/uk-businesses-faced-record-cyberattack-attempts-in-q3-2026-cce38edbf7249995fab0726abe69ab1b/

Russia Testing Europe’s Defences below Threshold of Open War, Experts Say

Experts warn that Russia is probing Europe’s readiness through sabotage, cyberattacks and incursions into NATO airspace while avoiding open conflict. Although European defences have improved since 2022, weaknesses persist in air defence, communications, intelligence and coordination between armed forces. The allocation of funding also raises concerns: President Zelensky said drones struck more than 80% of Russian targets destroyed on the battlefield, while a defence industry expert estimates they receive roughly 2% of European defence budgets. Closer cooperation with Ukraine aims to expand drone production and strengthen Europe’s ability to counter them.

https://kyivindependent.com/russia-testing-europes-defenses-below-threshold-of-open-war-experts-say/



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware Affiliate Double-Crosses Operator to Steal Victim Funds - Infosecurity Magazine

The monsters of Cybersecurity Awareness Month are getting stronger - Nextgov/FCW

Ransomware recovery CEO charged over secret ransom payments

Ransomware Attacks Can Begin Long Before Files Are Encrypted, ITSEC Asia Says

Microsoft: Qilin, Akira lead ransomware rankings under different metrics

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks | CyberScoop

Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site - Three arrests and eight searches across four European countries in an operation targeting a group linked to some 1 000 attacks worldwide | Europol

Warlock Ransomware Hits Large Spanish, Portuguese Orgs

Japan collars fugitive suspect of ransomware syndicate Qilin | The Asahi Shimbun: Breaking News, Japan News and Analysis

Engineer gets 32 months for sabotaging employer network | news | MSSP Alert

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Ransomware and Destructive Attack Victims

ASOS confirms data breach after “HACKED” in-app notifications

Hackers offer 1 million stolen Flink records to the highest bidder after extortion fails | NL Times

SafePay ransomware targets T-Systems in alleged breach | Cybernews

FBI Blames Contractor's Missed Patch for ShinyHunters Breach - SecurityWeek

Engineer sentenced for locking over 3,000 devices on employer network

Advantest confirms personal information stolen in ransomware attack

Trump Mobile customers' data dumped - and some never even received their gold device

Phishing & Email Based Attacks

Nearly 40,000 phishing attacks hit US financial firms in H1 2026 — automated AI agents and a new Seychelles bulletproof host fuel aggressive new campaigns — as threat actors turn to agentic AI and free developer hosting | TechRadar

The monsters of Cybersecurity Awareness Month are getting stronger - Nextgov/FCW

Kaspersky warns of phishing campaigns impersonating Zoom and Docusign | news | MSSP Alert

AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes | Malwarebytes

Power BI phishing campaign drops rogue ScreenConnect clients - IT Security Guru

‘They call every week’: the phishing attacks targeting past victims | Scams | The Guardian

Microsoft to soon block more email attachments in New Windows Outlook and web - Neowin

Other Social Engineering

A familiar face is no longer proof: rethinking social engineering defence for the deepfake era - IT Security Guru

Criminal recruiters want people on your payroll - Help Net Security

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor - SecurityWeek

Malicious Linux Implants Mimic Asian Mail Security Products

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

‘They call every week’: the phishing attacks targeting past victims | Scams | The Guardian

Most of Us Have Been Cyberattack Targets, Consumer Reports Finds. AI Isn't Helping - CNET

Phishing Toolkit Taps Social Media Posts and Advertisements

Why AI is making social engineering harder to spot - Federal News Network

EU survey: 3 in 4 workers encounter cyber threats at work | Cybernews

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

Telegram voicemail hack: late-night calls can hijack accounts | Cybernews

Real ChatGPT pages are being abused to deliver malware

Crypto Scammers Hijack Microsoft's Official X Account - SecurityWeek

2FA/MFA

The MFA you have isn't the MFA you think you have | CSO Online

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

Artificial Intelligence

AI Has Changed Attack Speed, Not Security Fundamentals - SecurityWeek

UK faces the most state-sponsored cyberattacks in Europe as AI narrows the attack timeline from days to minutes | TechRadar

OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse

A familiar face is no longer proof: rethinking social engineering defence for the deepfake era - IT Security Guru

Autonomous AI agents tried to hack US, Canadian government websites

Botnets, adversarial attacks and data poisoning top leaders' AI threat list - Help Net Security

AI security training soars amid rising threats | Channel Dive

OpenAI bots threat triggers UK security review

Why staff using ChatGPT, Claude and Gemini for work could create problems for employers | The National

Pacing the AI frontier won't solve agentic cybersecurity's most urgent problems | CSO Online

The monsters of Cybersecurity Awareness Month are getting stronger - Nextgov/FCW

AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes | Malwarebytes

AI agents keep access to company data after their work is done - Help Net Security

EU cybersecurity chief: Artificial intelligence using freedom people have given it | News | ERR

AI in cyber security: from evolving threats to automated defence

Why Securing The Intelligent Enterprise Requires A New Security Model

9 in 10 Americans have encountered a cyber scam as AI fuels fraud, Consumer Reports finds - CBS News

Chinese spies impersonate White House, Anthropic figures to phish AI policy experts - Help Net Security

OpenAI's wandering AI agents earn it a California subpoena

A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data | WIRED

The legal questions raised by agentic AI hacks | CyberScoop

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it - IT Security Guru

Is Your Organization Ready for 2027's AI Accountability Era?

Apple says it's tightening macOS 'Full Disk Access' controls due to new risks from AI agents | TechCrunch

Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

Cybercriminals have stolen AI logins from 80,000 organizations | Proton

Middle managers want tighter human oversight of AI than their bosses, TeamViewer research finds - IT Security Guru

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

Why AI is making social engineering harder to spot - Federal News Network

China’s open-weight AI powers new cybersecurity hacking win | The Straits Times

What Happens When Chinese AI Goes Rogue? - Bloomberg

“Attackers' agents don't need a security review, and that asymmetry worries me” | Ctech

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

Is It Fair to Blame 'Rogue' AI for Security Failures?

AI agents hacked the hackers, stealing email addresses from security research org

Malicious Email Could Hijack AI Agent and Access Connected Accounts - IT Security Guru

AI Tools Suspected in Korea’s Shinhan Bank Hack, Yonhap News Reports

Netskope CEO Sanjay Beri: Rogue Agents Make An AI ‘Kill Switch’ Mandatory

Six AI companies agree to voluntary safety accord with the White House | brief | MSSP Alert

Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

Musician sent to prison for $10 million streaming fraud using AI bots

OpenAI fires workers for 'mishandling sensitive information' - BBC News

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks - SecurityWeek

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

FBI, French authorities seize deepfake CSAM-for-sale websites | CyberScoop

Australian Gov't Weighs Mandatory AI Incident Reporting

Yann LeCun: Anthropic CEO Dario Amodei is ‘deluded,’ ‘crazy,’ and doesn’t understand cybersecurity | Fortune

Secure AI begins with trusted technology

No, AI is not similar to the Manhattan Project

Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval

RemoveMacAI turns off Apple Intelligence on macOS 27 and deletes its models - Help Net Security

Rolling the cyber dice with open-source and open-weight AI models | CSO Online

How to Govern the Pacing of the AI Frontier | Washington Monthly

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Who watches the AI watching your street? - Help Net Security

Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members - Decrypt

Careers, Roles, Skills, Working in Cyber and Information Security

Experience counts – not just certificates | Professional Security Magazine

Fewer women than ever in UK's 'old boys' club' cyber industry

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Crypto Scammers Hijack Microsoft's Official X Account - SecurityWeek

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cyber Crime, Organised Crime & Criminal Actors

Criminal recruiters want people on your payroll - Help Net Security

9 in 10 Americans Have Been Targeted by a Scam or Cyberattack | Extremetech

Police Urge Passkey Use After Surge in Cybercrime Profits - Infosecurity Magazine

Cyber: inside the evolving world of cyber crime | ICAEW

Data Breaches/Leaks

ASOS confirms data breach after “HACKED” in-app notifications

Oracle Health Hack Exposes Data of Nearly 20M People - CNET

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Swiss federal pension fund faces data breach after cyberattack - SWI swissinfo.ch

Cyberattack on major Polish invoicing platform exposes customer data | The Record from Recorded Future News

Danish university DTU breach exposes data of up to 200,000 people

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms - SecurityWeek

Housing association hit by cyber attack affecting 12,000 | The Oldham Times

Seoul megachurches hit by cyberattacks exposing member and donation data

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts - SecurityWeek

Data Protection

UK privacy watchdog starts over with new board and Manchester HQ

Data/Digital Sovereignty

‘Absolute s–t’: EU’s Microsoft Teams alternative draws bad reviews from officials – POLITICO

Encryption

Critical Healthcare Systems Aren't Quantum-Ready

Fraud, Scams and Financial Crime

Police Urge Passkey Use After Surge in Cybercrime Profits - Infosecurity Magazine

Crypto Scammers Hijack Microsoft's Official X Account - SecurityWeek

9 in 10 Americans have encountered a cyber scam as AI fuels fraud, Consumer Reports finds - CBS News

Why AI is making social engineering harder to spot - Federal News Network

‘They call every week’: the phishing attacks targeting past victims | Scams | The Guardian

Ransomware recovery CEO charged over secret ransom payments

Musician sent to prison for $10 million streaming fraud using AI bots

Insider Risk and Insider Threats

Why staff using ChatGPT, Claude and Gemini for work could create problems for employers | The National

Criminal recruiters want people on your payroll - Help Net Security

Insurance

Cyber Insurance Is Not A Cybersecurity Strategy - Above the Law

Internet of Things – IoT

Some car apps are slipping owners' data to big tech companies - Help Net Security

Tech in cars can be used to snoop on you, Dutch spy chiefs warn | Motoring | The Guardian

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes - Infosecurity Magazine

Law Enforcement Action and Take Downs

Ransomware recovery CEO charged over secret ransom payments

Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site - Three arrests and eight searches across four European countries in an operation targeting a group linked to some 1 000 attacks worldwide | Europol

Musician sent to prison for $10 million streaming fraud using AI bots

FBI confirms 'multiple' arrests related to ShinyHunters hack

Japan collars fugitive suspect of ransomware syndicate Qilin | The Asahi Shimbun: Breaking News, Japan News and Analysis

In Rare Move, Alleged Iranian State Hacker Extradited to US - SecurityWeek

Alleged dev of Ploutus ATM malware appears in US court after arrest

FBI, French authorities seize deepfake CSAM-for-sale websites | CyberScoop

Engineer sentenced for locking over 3,000 devices on employer network

Linux and Open Source

Legal risks pile up for Altman as OpenAI uncovers dozens of hacks – The Irish Times

Malicious Linux Implants Mimic Asian Mail Security Products

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws - SecurityWeek

‘Absolute s–t’: EU’s Microsoft Teams alternative draws bad reviews from officials – POLITICO

My 5 favorite Linux distros for security - and how they protect your privacy - ZDNET

Malware

Report Surfaces Sharp Increase in Malware Detections - Security Boulevard

Malicious Linux Implants Mimic Asian Mail Security Products

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws - SecurityWeek

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybercriminals have stolen AI logins from 80,000 organizations | Proton

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor - SecurityWeek

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

Real ChatGPT pages are being abused to deliver malware

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials | Socket

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Alleged dev of Ploutus ATM malware appears in US court after arrest

Microsoft to soon block more email attachments in New Windows Outlook and web - Neowin

Misinformation, Disinformation and Propaganda

Poland braces for Russian disinformation ahead of 2027 election - English Section

Mobile

Telegram voicemail hack: late-night calls can hijack accounts | Cybernews

Your Personal Data Is Safest Right After You Restart Your Phone - Here's Why

Passwords, Credential Stuffing & Brute Force Attacks

Police Urge Passkey Use After Surge in Cybercrime Profits - Infosecurity Magazine

High Awareness, Low Adoption: New Survey Reveals Nearly Half of Security Professionals Still Rely on Passwords

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Privacy, Surveillance

Some car apps are slipping owners' data to big tech companies - Help Net Security

Tech in cars can be used to snoop on you, Dutch spy chiefs warn | Motoring | The Guardian

Cyber Security Month 2026: Oversharing – Share with care

Who watches the AI watching your street? - Help Net Security

Citizen Lab Slams Trump, 'Techno-Fascist' Executives

Regulations, Fines and Legislation

GDPR Data Breach Notification in Poland: Deadlines, NIS2/DORA Overlap and Fines | Dudkowiak & Putyra - JDSupra

UK privacy watchdog starts over with new board and Manchester HQ

Six AI companies agree to voluntary safety accord with the White House | brief | MSSP Alert

Australian Gov't Weighs Mandatory AI Incident Reporting

How to Govern the Pacing of the AI Frontier | Washington Monthly

Agencies, critical infrastructure balance evolving cybersecurity risks - Federal News Network

Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity - SecurityWeek

Ofcom opens investigation into Meta over Instagram Instants risk checks

Singapore passes stricter data centre security Bill | The Straits Times

Former NSA chief Nakasone says agency overhaul is ‘probably needed’ | CyberScoop

TP-Link problems in US grow amid FCC router ban and four state lawsuits - Ars Technica

Major rules for federal contractors handling sensitive data are nearing the finish line | CyberScoop

Shadow IT

Why staff using ChatGPT, Claude and Gemini for work could create problems for employers | The National

Social Media

Phishing Toolkit Taps Social Media Posts and Advertisements

Cyber Security Month 2026: Oversharing – Share with care

Crypto Scammers Hijack Microsoft's Official X Account - SecurityWeek

Ofcom opens investigation into Meta over Instagram Instants risk checks

Software Supply Chain

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Flagged by the Machine: How Google Ads Suspended an Open-Source macOS Term as Malicious - InfoQ

Supply Chain and Third Parties

Danish CPR Breach Highlights Challenge of Supply Chain Risk - Infosecurity Magazine

PYMNTS | Europe Puts Hidden Technology Suppliers on CFOs’ Risk Radar

What Is Vendor Risk Assessment and Its Importance?

FBI Blames Contractor's Missed Patch for ShinyHunters Breach - SecurityWeek


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

UK faces the most state-sponsored cyberattacks in Europe as AI narrows the attack timeline from days to minutes | TechRadar

Russia testing Europe's defenses below threshold of open war, experts say

Thales CEO warns of 'frightening' rise in state-backed cyberattacks | The Jerusalem Post

Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker | The Record from Recorded Future News

UK not prepared for food shortages, experts warn

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

UK universities comb records for China links after MI5 warning

UK and Europe at risk from Chinese tech, says security think tank | Computer Weekly

Ukraine is third in world for cyberattacks after US and Israel, and first in Europe. Machine-speed assaults run continuously and without fatigue - Euromaidan Press

Chinese spies impersonate White House, Anthropic figures to phish AI policy experts - Help Net Security

Royal Navy sailor Teddy Young charged with spying for foreign power

German spy chief reassures MI6 after major intelligence leak

Nation State Actors

UK faces the most state-sponsored cyberattacks in Europe as AI narrows the attack timeline from days to minutes | TechRadar

Thales CEO warns of 'frightening' rise in state-backed cyberattacks | The Jerusalem Post

China

UK universities comb records for China links after MI5 warning

UK and Europe at risk from Chinese tech, says security think tank | Computer Weekly

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

China’s open-weight AI powers new cybersecurity hacking win | The Straits Times

What Happens When Chinese AI Goes Rogue? - Bloomberg

Chinese hackers target edge devices, Dutch agencies warn | Cybernews

Chinese spies impersonate White House, Anthropic figures to phish AI policy experts - Help Net Security

TP-Link problems in US grow amid FCC router ban and four state lawsuits - Ars Technica

Russia

Russia testing Europe's defenses below threshold of open war, experts say

Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker | The Record from Recorded Future News

UK not prepared for food shortages, experts warn

Ukraine is third in world for cyberattacks after US and Israel, and first in Europe. Machine-speed assaults run continuously and without fatigue - Euromaidan Press

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Poland braces for Russian disinformation ahead of 2027 election - English Section

Russia to double internet censorship budget in 2027, plotting new VPN traffic fee | TechRadar

Royal Navy sailor Teddy Young charged with spying for foreign power

Estonia pushes for cybersecurity boost ahead of elections | News | ERR

Iran

In Rare Move, Alleged Iranian State Hacker Extradited to US - SecurityWeek


Tools and Controls

Cyber Insurance Is Not A Cybersecurity Strategy - Above the Law

Businesses Pump Cyber Budgets as AI Risks Fuel Corporate Angst

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant - IT Security Guru

Verify it, don’t assume it: why untested security controls are making life easy for attackers - IT Security Guru

AI security training soars amid rising threats | Channel Dive

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it - IT Security Guru

Is Your Organization Ready for 2027's AI Accountability Era?

The MFA you have isn't the MFA you think you have | CSO Online

AI slop submissions force Google to freeze its open-source bug bounty - Help Net Security

Chinese hackers target edge devices, Dutch agencies warn | Cybernews

High Awareness, Low Adoption: New Survey Reveals Nearly Half of Security Professionals Still Rely on Passwords

Passkeys Urged As Hacked Account Losses Jump 417% | Northern Ireland News, 05/10/2026

Why Securing The Intelligent Enterprise Requires A New Security Model

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks - SecurityWeek

AI is speeding up exploits. Vulnerability spreadsheets can't keep up. - The New Stack

The Fine Art of Frustrating the Adversary

'BigDiskBuster' Leaves Microsoft Defender Running, Blocks Updates

More threat data is useful only if security teams can act on it | Inquirer Technology

What Is Agentic Pentesting? What It Proves, and Where It Stops.

Pricing your bad days and how to build an economic model for security decisions - Help Net Security

Russia to double internet censorship budget in 2027, plotting new VPN traffic fee | TechRadar

Microsoft to soon block more email attachments in New Windows Outlook and web - Neowin

My 5 favorite Linux distros for security - and how they protect your privacy - ZDNET

Rolling the cyber dice with open-source and open-weight AI models | CSO Online

Whatever happened to the 36-month IT security roadmap? | CSO Online

Businesses rethink security exposure management beyond faster patching | brief | MSSP Alert

From Innovation to Infrastructure: The AI Shift in Cyber Defence

CISO perspectives on managing vulnerability risks in the age of AI | Microsoft Security Blog

How to secure RMM software: 8 controls MSPs should test

AI collapsed the patching window. Washington needs a cyber risk operations doctrine. - Federal News Network

Critical Healthcare Systems Aren't Quantum-Ready

South Korean president calls for creation of tools that stop all cyber-attacks

Your Phishing Drill Numbers Are Lying to You - DataBreachToday

What happens when AI starts fighting cyber threats on its own? Here's how agentic security works - The Economic Times



Vulnerability Management

Vulnerability Backlogs Are an Ownership Problem

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Management - Infosecurity Magazine

AI is speeding up exploits. Vulnerability spreadsheets can't keep up. - The New Stack

FBI Blames Contractor's Missed Patch for ShinyHunters Breach - SecurityWeek

Businesses rethink security exposure management beyond faster patching | brief | MSSP Alert

CISO perspectives on managing vulnerability risks in the age of AI | Microsoft Security Blog

AI collapsed the patching window. Washington needs a cyber risk operations doctrine. - Federal News Network

Vulnerabilities

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Citrix patches NetScaler SAML zero-day exploited in attacks

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

Cisco SD-WAN Manager hit by zero-day admin access attack | CSO Online

SWIFT Banking & Government Middleware Enables RCE

Veeam Backup and Replication Vulnerability Allow Attackers to Execute Malicious Script

'BigDiskBuster' Leaves Microsoft Defender Running, Blocks Updates

Update Chrome and ChromeOS to fix critical security issues | Malwarebytes

Hackers exploit critical Atlassian flaw after public PoC release

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes | CSO Online

Microsoft catches hackers exploiting Zimbra bug before disclosure

Kiteworks, Citrix Incidents Show Challenge of Zero-Day Response

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Two flaws in Amazon Bedrock AgentCore SDK could expose AWS credentials | news | MSSP Alert

Fortra Patches Critical Vulnerabilities in BoKS - SecurityWeek

OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing - Help Net Security

Android's October 2026 Updates Patch 25 Vulnerabilities - SecurityWeek

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

Ninja Forms plugin flaw exploited to hack WordPress sites

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Management - Infosecurity Magazine

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Security researcher claims they found KVM guest-host escape flaw

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities - Infosecurity Magazine


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 02 October 2026