Black Arrow Cyber Threat Intelligence Briefing 11 September 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Our review of the specialist and general media this week is longer that usual, as it contains several insights into current attacker tactics that business leaders need to understand and ensure their organisations are prepared for. These include new forms of attacks targeting employees, such as phishing designed to evade technical controls or defeat multi-factor authentication, fake security checks that trick users into taking harmful actions, and phone-based social engineering. We also describe how AI is increasing the speed, scale and autonomy of cyberattacks, while organisations face separate governance challenges around unapproved AI tools and access credentials used by software rather than people.
For business leaders, our insights reinforce the need for employee awareness to keep pace with changing attack techniques and risks, as traditional warning signs are becoming less reliable, and employees increasingly need to judge communications and requests that may appear legitimate. In our experience, this is best achieved through a blended-learning awareness programme that includes engaging, interactive in-person training to encourage discussion, improve behaviour and reduce risk. Contact us to discuss how we can support your wider cyber security awareness programme.
Top Cyber Stories of the Last Week
New Phishing Attack Creates Malicious Pages inside the Victim’s Browser
Attackers are creating fraudulent pages inside victims’ browsers, making them harder for traditional security tools to detect and block. Barracuda identified a campaign using Docusign-themed emails and Microsoft Teams as part of the route to the fraudulent page, helping the activity appear trustworthy. Unlike conventional phishing, which tricks people into visiting fake websites, the attack causes the browser to generate the phishing page itself, leaving no fixed web page to block. The technique highlights the need for stronger protection of user accounts, closer monitoring of browser activity and email security that checks the full sequence of links and redirects.
https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/
BigBear Microsoft 365 Phishing Service Bypassed MFA at 258 Organisations
A phishing service called BigBear 2.0 has bypassed multi-factor authentication, which requires additional identity checks beyond a password, at 258 organisations. Researchers at CloudSEK uncovered 5,137 stolen credential records affecting victims across more than 40 countries. The service intercepts legitimate Microsoft 365 sign-ins, allowing criminals to take over accounts after users complete authentication checks, potentially exposing emails, files and connected applications. The findings show that MFA can still be defeated when attackers capture authenticated sessions, reinforcing the need for phishing-resistant authentication and access controls that require managed devices.
Microsoft Warns Fake CAPTCHA Is Tricking Windows Users into Running Malware
Fake online verification checks are tricking Windows users into running malicious commands that could expose business networks to data theft and ransomware. Microsoft has identified a campaign called TerminalFix, which impersonates trusted services such as Cloudflare and asks users to paste commands into Windows tools. When users follow these instructions, they can give attackers lasting access to a device and a route into wider company systems. Organisations should remind staff how legitimate checks work. In addition, access to powerful tools should be restricted where practical, and devices monitored for unusual activity.
https://www.techspot.com/news/113721-microsoft-warns-fake-captcha-pages-tricking-windows-users.html
Cyber Criminals Are Adapting ASCII Smuggling for Mass Phishing Campaigns
Cyber criminals are using invisible Unicode characters to disguise words in phishing emails and bypass traditional spam filters. Microsoft observed a sharp rise in the technique from February, with around 96% of detected activity linked to finance-themed lures sent from hundreds of disposable domains. The hidden characters can split words such as “funding” without changing how they appear to recipients, making simple keyword-based filtering less effective. Microsoft recommends that organisations remove or standardise invisible characters before scanning emails, and apply the same controls where AI tools process email content.
Hackers Are Calling: The Vishing Campaign Targeting Financial Institutions
A vishing campaign targeting major US financial institutions shows how a simple phone call can lead to a serious cyberattack. Attackers are posing as IT helpdesk staff and directing employees to fake login pages that capture passwords and multi-factor authentication codes. Apollo Global Management disclosed that personal data including social security numbers was stolen, while dozens of firms including Blackstone, KKR and Moody’s were reportedly targeted. Ransom demands have reportedly ranged from $750,000 to $3 million, reinforcing the need to train employees for unexpected calls and strengthen verification procedures for credential and MFA resets.
https://www.jdsupra.com/legalnews/hackers-are-calling-the-vishing-2784746/
NHIs Now the Number One Corporate Entry Point for Hackers
Digital accounts and access credentials used by software rather than people, known as non-human identities, are emerging as a major route into corporate systems. Examples include AI agents, service accounts and application access keys. SpyCloud found non-human identities accounted for 31% of intrusions, compared with 17% involving social engineering attacks that manipulate people. Although 95% of organisations believe they have adequate visibility of these identities, only 36% actively monitor them. The study found 68% had experienced an identity-related security event, reinforcing the need for stronger monitoring and formal controls over the access given to AI tools and agents.
https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/
AI Is Making Phishing Scams Almost Impossible to Spot – 5 Steps Employers Should Take to Combat Latest Threat
Artificial intelligence is making fraudulent messages more convincing, removing traditional warning signs and enabling personalised scams at scale. Huntress reported a nearly 15-fold increase in attempts to trick employees into authorising an attacker’s device during the first four months of 2026 compared with the second half of 2025. These attacks use genuine sign-in pages and can succeed despite additional identity checks. Employers should respond by updating phishing training, requiring separate-channel verification for sensitive requests, extending scrutiny beyond email, educating employees about newer attack techniques and treating phishing defence as a joint responsibility for IT and HR.
https://www.jdsupra.com/legalnews/ai-is-making-phishing-scams-almost-2513494/
AI Agents Carried Out Every Step of This Ransomware Attack – Then Left the Victim an 80-Page Security Audit
A ransomware attacker used frontier AI models and AI agents to breach an enterprise network in under 10 hours, a process that Unit 42 estimates would normally take human attackers around two weeks. The AI agents carried out much of the intrusion autonomously, mapping internal systems, stealing passwords and access tokens, accessing cloud and identity environments and adapting their approach as they progressed. No previously unknown vulnerability was required. After completing the attack, the AI system even produced an 80-page report detailing the security weaknesses it had exploited, highlighting how AI can dramatically increase the speed and efficiency of cyberattacks.
AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Google has warned that artificial intelligence is allowing smaller and less well-resourced attackers to operate at a scale previously associated with nation states. One attacker used an AI coding assistant to plan and execute a mass credential-theft campaign in under six hours. Google has also observed Chinese, Iranian and North Korean state-linked groups using AI for target research, phishing, malware development and cryptocurrency theft. The growing concern is not that AI changes the fundamentals of cyberattacks, but that it significantly increases their speed and scale and gives less well-resourced attackers greater capability.
‘You Cannot Manage What You Do Not Know’: The NCSC Is Calling for a Crackdown on Shadow AI
Unapproved artificial intelligence tools, known as ‘shadow AI’, can expose organisations to risks including data breaches, loss of intellectual property and failure to meet regulatory requirements, the UK’s National Cyber Security Centre has warned. Microsoft research found that 71% of UK employees had used unapproved consumer AI tools at work, with more than half reporting weekly use. Sensitive information shared with these services may be retained or reused outside organisational control. The NCSC recommends understanding why employees use these tools, establishing practical policies and providing approved alternatives so businesses can benefit from AI while managing cyber security risks.
Why Judgment Is Emerging as Cyber Security’s Defining Skill
While artificial intelligence takes on a greater role in cyber security analysis, technically sound recommendations can still disrupt critical services or financial processes if they overlook how the business operates. Decisions about allowing AI to act independently should reflect the potential business impact and how easily actions can be reversed. Experienced cyber security professionals can add knowledge of the organisation that may be missing from AI analysis, including how systems are used, which services rely on them and what previous incidents have shown. This human judgement remains essential to ensure decisions reflect both the threat and the wider business consequences.
https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/
Working with Your Board around Risk – Why Cyber Responsibility Can’t Be Shirked
Chief Information Security Officers (CISOs) play a major role in supporting boards with their responsibility for cyber risks in the organisation, by providing the right information on risk management expressed in business terms. As digital dependence and cyber disruption increase, directors need cyber risks expressed in business terms, including potential financial losses and the effectiveness of existing controls, so they can make informed investment decisions. The UK Government’s Cyber Resilience Pledge calls for greater board engagement, including cyber security governance training and consideration of supplier risk. Ultimately, boards need to ensure the organisation can continue operating when cyber disruption occurs.
Digital Sovereignty Now a Boardroom Priority as Companies Confront Escalating Tech Risks, Survey Finds
Dependence on critical technology providers is becoming a boardroom concern as geopolitical tensions, export controls and cyber threats increase the risks associated with critical digital infrastructure. A Capgemini survey of 1,300 large organisations across 11 countries found nearly half would need between three months and a year to replace a critical provider, while more than a third would need longer than a year. To address this business risk, organisations are increasingly focusing on keeping important data, AI models and key workloads under their control, alongside contingency planning to ensure they can switch providers if access is disrupted.
The AI Reality Check: The Real Challenge Is Governing Complexity
Artificial intelligence is accelerating how attackers identify and exploit connections between systems, accounts, suppliers and data, making unmanaged digital complexity a growing cyber security risk. While AI is increasingly important for defence, technology alone cannot ensure resilience. Organisations need to understand how their systems connect, where sensitive information flows and who can access it. AI systems acting independently require clearly defined permissions, monitoring and accountable human oversight. Strong access controls and effective governance remain essential, while decisions about acceptable risk, policy and accountability must remain with people.
Governance, Risk and Compliance
Why judgment is emerging as cybersecurity’s defining skill | CyberScoop
Peers ask why UK cyber bill leaves execs off the personal liability hook
Working with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly
Boards prepare for digital infrastructure shocks, survey says - CNA
The AI cybersecurity war has a new front line star, and a seven-figure price
The AI reality check: The real challenge is governing complexity | TechFinitive
Compliance experts find firms lack staff skilled in security and regulation
AI adoption brings new security headaches for already stretched CISOs - Help Net Security
Why CISOs should focus on real AI threats, not hype | CSO Online
Climate resilience reveals key enterprise networking blind spot | Computer Weekly
Why Today's Cybersecurity Leaders Must Help Shape Tomorrow's Talent - Infosecurity Magazine
“Security cannot simply act as a roadblock, because that stops the momentum that lead | Ctech
Threats
Ransomware, Extortion and Destructive Attacks
Extortion crews have their eyes on high-value AI data, Google warns
Cryptolocker ransomware: A look back at its widespread impact | brief | MSSP Alert
Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS
CRPx0 Ransomware: What You Need to Know | Fortra
Ransomware and Destructive Attack Victims
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Re - Infosecurity Magazine
ShinyHunters Gained Access to 6 Million Customers Record Using a Single Call
Storm ransomware claims attack on Boeing, Airbus supplier | Cybernews
Odido hackers mock police, threaten another Netherlands hack | Cybernews
Boston Scientific Flags Financial Hit From Cyberattack
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
Veradigm warns of patient data breach after ransomware gang claims attack
AdaptHealth confirms 4.1 million people exposed in July cyberattack
Phishing & Email Based Attacks
Scammers have figured out the best time to text you - Help Net Security
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser - SecurityWeek
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog
Outsider Phishing Kit Survives Takedown With 700 New Pages - Infosecurity Magazine
Hackers Use QR Codes With No Images to Bypass Email Security
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking
Protecting Against Zero-Click Attacks - IT Security Guru
IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security
BigBear phishing crew nets thousands of Microsoft 365 credentials
New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert
Hackers Use Brazilian Government Servers to Host Phishing Sites
Don’t Take The Bait: The New Phishing Threats To Asset Managers | Ropes & Gray LLP - JDSupra
Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions
Other Social Engineering
Scammers have figured out the best time to text you - Help Net Security
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser - SecurityWeek
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Microsoft warns fake CAPTCHA is tricking Windows users into running malware | TechSpot
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security
Large Enterprises Targeted in Fake Merger & Acquisition Scams
ClickFix Campaigns Abuse Legitimate Services for Persistence
Hackers Are Calling: The Vishing Campaign Targeting Financial Institutions | Goodwin - JDSupra
New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert
Don’t Take The Bait: The New Phishing Threats To Asset Managers | Ropes & Gray LLP - JDSupra
2FA/MFA
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Artificial Intelligence
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
AI means fundamentals matter more than ever | Professional Security Magazine
'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI | IT Pro
Why CISOs should focus on real AI threats, not hype | CSO Online
Companies Have 6 Months to Prepare for Automated Attacks
Why AI Agent Sandboxes Are Failing Security Tests
Another Anthropic model gained access to the open internet during testing, company says - CBS News
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog
AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat
How AI Agents Are Creating a New Kind of Security Risk
What the AI Warning Letter Completely Missed
Insurers Search for Answers to Rein in Rogue AI
18 ways to check whether data can be trusted for AI - Help Net Security
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Cybercriminals are turning AI’s safety guardrails against it | Ctech
The Ungoverned Frontier of Agentic AI Cyberattacks
Your AI agent's system prompt is not a security control - Help Net Security
Anthropic pledges to try harder to keep models under control, asks partners to chip in
UK cyber bill targets AI users, not the vendors building it
As agentic AI adoption accelerates, Rubrik warns of growing security gaps | TahawulTech.com
The AI safety rule workers need: no agent gets power without a named human owner – Labour Hub
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
How AI is changing cybersecurity threats (and how it isn't)
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
The US plans to raise AI-directed cyberattacks with China, Nikkei reports
The AI cybersecurity arms race is on | CIO
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
Financial Firms Inundated By AI Security Findings, FCA Warns
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Man gets 15 years for extorting women with AI-generated porn videos
US Government Claims Chinese AI Firms Distilling Frontier Models
Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions
Nvidia transfers Open Secure AI Alliance to Linux Foundation | brief | MSSP Alert
Bots/Botnets
Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
Careers, Roles, Skills, Working in Cyber and Information Security
Why Today's Cybersecurity Leaders Must Help Shape Tomorrow's Talent - Infosecurity Magazine
HMRC offers £173k for chief security officer – PublicTechnology
Cloud/SaaS
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts
New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
ClickFix Moves into the Browser to Steal Cryptocurrency - Infosecurity Magazine
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Trezor data breach impact now reaches 81,000 customers
JSCeal Hides Crypto Malware in V8 Bytecode
Hackers Drain $320 Million From Liquid Network, Then Return Most of It
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle - Help Net Security
Cyber Crime, Organised Crime & Criminal Actors
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle - Help Net Security
A dark-web site claimed to sell 153 million driver's licenses, then vanished | TechSpot
Data Breaches/Leaks
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts
A dark-web site claimed to sell 153 million driver's licenses, then vanished | TechSpot
Trezor data breach impact now reaches 81,000 customers
IDScan sued over alleged data breach affecting 153 million drivers
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Odido hackers mock police, threaten another Netherlands hack | Cybernews
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
Veradigm warns of patient data breach after ransomware gang claims attack
AdaptHealth confirms 4.1 million people exposed in July cyberattack
French hospital fined €500,000 after breach exposes data of 727,000
Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff
Data/Digital Sovereignty
Switzerland tests a FOSS escape route from Microsoft 365
Denial of Service/DoS/DDoS
Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
Encryption
G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules - Infosecurity Magazine
Fraud, Scams and Financial Crime
Scammers have figured out the best time to text you - Help Net Security
Large Enterprises Targeted in Fake Merger & Acquisition Scams
How to spot scam websites that your browser says are safe | Kaspersky official blog
Gigabud Uses Android App Cloning to Evade Fraud Detection - Infosecurity Magazine
Loyalty points fraud is funding hacker holidays (Lock and Code S07E18) | Malwarebytes
Identity and Access Management
How AI Agents Are Creating a New Kind of Security Risk
NHIs Now the Number One Corporate Entry Point for Hackers - Infosecurity Magazine
Insider Risk and Insider Threats
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
Insurance
Insurers Search for Answers to Rein in Rogue AI
Internet of Things – IoT
LG Denies Its Televisions Record Ambient Conversations for Ad Targeting - CNET
Is Your Roomba a National Security Threat? Inside the FCC's Tech Crackdown - CNET
Police bodies consider risks and benefits of connected cars | UKAuthority
Norway Considers Ban On Meta Glasses' New Facial Recognition Features
Law Enforcement Action and Take Downs
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
Outsider Phishing Kit Survives Takedown With 700 New Pages - Infosecurity Magazine
Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle - Help Net Security
Man gets 15 years for extorting women with AI-generated porn videos
Linux and Open Source
Switzerland tests a FOSS escape route from Microsoft 365
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
North Korean Hackers Deploy New Linux Espionage Toolkit - SecurityWeek
Malvertising
StreamRat Android malware spreads through Meta and TikTok ads | Malwarebytes
Malware
Microsoft warns fake CAPTCHA is tricking Windows users into running malware | TechSpot
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
ClickFix Campaigns Abuse Legitimate Services for Persistence
Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns - IT Security Guru
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert
Popular Chrome Extensions Weaponized to Steal Crypto From 80,000 Users - gHacks Tech News
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Your Employee’s Password Appeared in an Infostealer Log. Now What?
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Mobile
The US military just turned off ad tracking on its phones. Maybe you should too
StreamRat Android malware spreads through Meta and TikTok ads | Malwarebytes
WeChat Worm Can Hijack Accounts Without Victims Answering Calls
Android's September 2026 Updates Patch 180 Vulnerabilities - SecurityWeek
Gigabud Uses Android App Cloning to Evade Fraud Detection - Infosecurity Magazine
Models, Frameworks and Standards
Peers ask why UK cyber bill leaves execs off the personal liability hook
UK cyber bill targets AI users, not the vendors building it
UK's Online Safety Act has made 'absolutely no difference,' kids say
DORA, NIS2 and the AI Act are One Job, Says UiPath's Field CISO | The Fintech Times
Understanding CMMC 2.0: A Guide for Defense Contractors | brief | MSSP Alert
Key Starting Point for CRA Reporting Obligations
The EU CRA's Real Question: What Shipped, and When Did You Know?
Government rejects Computer Misuse Act amendment to protect cyber professionals | Computer Weekly
Passwords, Credential Stuffing & Brute Force Attacks
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Your Employee’s Password Appeared in an Infostealer Log. Now What?
39 New Methods That Compromise Passkey Authentication
Privacy, Surveillance
LG Denies Its Televisions Record Ambient Conversations for Ad Targeting - CNET
Norway Considers Ban On Meta Glasses' New Facial Recognition Features
Regulations, Fines and Legislation
UK cyber bill targets AI users, not the vendors building it
UK's Online Safety Act has made 'absolutely no difference,' kids say
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Norway Considers Ban On Meta Glasses' New Facial Recognition Features
DORA, NIS2 and the AI Act are One Job, Says UiPath's Field CISO | The Fintech Times
Key Starting Point for CRA Reporting Obligations
The EU CRA's Real Question: What Shipped, and When Did You Know?
Government rejects Computer Misuse Act amendment to protect cyber professionals | Computer Weekly
French hospital fined €500,000 after breach exposes data of 727,000
FBI cyber leader details bureau’s first unclassified cyber strategy | Federal News Network
Understanding CMMC 2.0: A Guide for Defense Contractors | brief | MSSP Alert
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms | TechCrunch
Shadow IT
'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI | IT Pro
Software Supply Chain
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
Supply Chain and Third Parties
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Storm ransomware claims attack on Boeing, Airbus supplier | Cybernews
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Kremlin Intensifies Russia’s Shadow War Against Europe | The Gaze
Expert: Russia-NATO tensions likely to escalate - English Section
Russia’s invisible war is exposing Europe’s vulnerabilities - Decode39
The four ways the UK could respond to Putin’s grey war
Boards prepare for digital infrastructure shocks, survey says - CNA
Germany Unveils Four-Step Plan to Counter Russia’s Hybrid Threats | The Gaze
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
North Korean Hackers Deploy New Linux Espionage Toolkit - SecurityWeek
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters - Infosecurity Magazine
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
Russia widens targeting of European research centres | Science|Business
Army to mobilise veterans in preparation for war
Nation State Actors
Why hostile state cyber activity is now a day-to-day business risk - IT Security Guru
UK food supply chains need protecting according to new report - CILT
Boards prepare for digital infrastructure shocks, survey says - CNA
AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns - SecurityWeek
China
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Is Your Roomba a National Security Threat? Inside the FCC's Tech Crackdown - CNET
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
US Government Claims Chinese AI Firms Distilling Frontier Models
The US plans to raise AI-directed cyberattacks with China, Nikkei reports
Russia
Kremlin Intensifies Russia’s Shadow War Against Europe | The Gaze
Expert: Russia-NATO tensions likely to escalate - English Section
Russia’s invisible war is exposing Europe’s vulnerabilities - Decode39
The four ways the UK could respond to Putin’s grey war
Germany Unveils Four-Step Plan to Counter Russia’s Hybrid Threats | The Gaze
Protecting Against Zero-Click Attacks - IT Security Guru
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
Russia widens targeting of European research centres | Science|Business
Ukraine Must Cultivate 'Security-Minded' Cyber Defense
Army to mobilise veterans in preparation for war
North Korea
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters - Infosecurity Magazine
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Iran
Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions
$10 Million Reward Offered for Information on IRGC Cyber Operations Chief
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
UK food supply chains need protecting according to new report - CILT
Tools and Controls
The AI reality check: The real challenge is governing complexity | TechFinitive
Why judgment is emerging as cybersecurity’s defining skill | CyberScoop
Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns - IT Security Guru
Why AI Agent Sandboxes Are Failing Security Tests
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
Boards prepare for digital infrastructure shocks, survey says - CNA
Working with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly
Penetration Testing Only Works When It's Scoped To Business Risk
Browser-based work is creating a new cybersecurity battleground - Digital Journal
Serious N-central flaw puts MSPs and MSSPs on patch alert | news | MSSP Alert
Configuration Drift Is a Growing Cybersecurity Risk: Report
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
G7 sounds alarm on quantum cyber threats | IT Pro
As agentic AI adoption accelerates, Rubrik warns of growing security gaps | TahawulTech.com
Climate resilience reveals key enterprise networking blind spot | Computer Weekly
Root Evidence Finds the “Vulnpocalypse” Isn’t Showing Up in the Data
Most of the bugs Claude Mythos found have never been checked by a human - Help Net Security
AI Will End the Era of Hidden Vulnerabilities. Are Vendors Ready?
Mythos Vulnerability Firehose Hits a Human Bottleneck
The AI cybersecurity arms race is on | CIO
Financial Firms Inundated By AI Security Findings, FCA Warns
Humans have edge over AI in Dutch hacking contest | Computer Weekly
To keep the AI hacking genie bottled up, try one-way networks
Please stop using your ISP's DNS
France Establishes New Government-Focused Cyber Incident Response Unit - Infosecurity Magazine
UK government proposes AI first responders for cyber attacks | Computer Weekly
Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results - Help Net Security
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
“Security cannot simply act as a roadblock, because that stops the momentum that lead | Ctech
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation - Infosecurity Magazine
Researcher sends himself email from exploited company account | Cybernews
Other News
France Establishes New Government-Focused Cyber Incident Response Unit - Infosecurity Magazine
Kaspersky unveils how the worst cyber incidents hit SMBs over the past year | TahawulTech.com
UK government proposes AI first responders for cyber attacks | Computer Weekly
Cybersecurity for payment systems: Credit cards, terminals, and how it all works.
Data-rich systems and weak security: why France is a target for cyberattacks - RFI
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates | CyberScoop
Vulnerability Management
Chrome is now shipping updates every 2 weeks as AI changes the security landscape | TechCrunch
Configuration Drift Is a Growing Cybersecurity Risk: Report
Root Evidence Finds the “Vulnpocalypse” Isn’t Showing Up in the Data
Most of the bugs Claude Mythos found have never been checked by a human - Help Net Security
AI Will End the Era of Hidden Vulnerabilities. Are Vendors Ready?
Financial Firms Inundated By AI Security Findings, FCA Warns
Mythos Vulnerability Firehose Hits a Human Bottleneck
Vulnerabilities
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Critical Citrix NetScaler auth bypass now leveraged in attacks
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
N-able patches max severity N-central flaw amid ongoing attacks
Hackers exploit chained SonicWall gaps for remote code execution | brief | MSSP Alert
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
MikroTik Patches Critical Flaws Chained to Hack Routers - SecurityWeek
Chinese espionage groups swarm to exploit triple-link chain of zero-days | CyberScoop
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
Cisco discloses critical flaws in IOS XR and Nexus 9000 switches | brief | MSSP Alert
HPE Patches Critical RCE Vulnerabilities in AOS-CX - SecurityWeek
Ivanti Patches Critical Flaws Across Enterprise Security Products - SecurityWeek
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension - SecurityWeek
Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass and SQL Injection
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits - SecurityWeek
September Windows Server updates break Remote Desktop Services
ConnectWise warns of new ScreenConnect flaw without patch
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Another Artifactory CVE under attack by AI agents or humans
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day - SecurityWeek
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
Android's September 2026 Updates Patch 180 Vulnerabilities - SecurityWeek
Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories - SecurityWeek
Sangoma Switchvox Vulnerabilities Exploited in the Wild - SecurityWeek
Two major security flaws are affecting more than six million WordPress websites | TechRadar
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors - Help Net Security
The harmless logo your PC shows at startup has a terrifying security problem
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft fixes bug that wiped Windows desktop settings
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.