Black Arrow Cyber Threat Intelligence Briefing 11 September 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

Our review of the specialist and general media this week is longer that usual, as it contains several insights into current attacker tactics that business leaders need to understand and ensure their organisations are prepared for. These include new forms of attacks targeting employees, such as phishing designed to evade technical controls or defeat multi-factor authentication, fake security checks that trick users into taking harmful actions, and phone-based social engineering. We also describe how AI is increasing the speed, scale and autonomy of cyberattacks, while organisations face separate governance challenges around unapproved AI tools and access credentials used by software rather than people.

For business leaders, our insights reinforce the need for employee awareness to keep pace with changing attack techniques and risks, as traditional warning signs are becoming less reliable, and employees increasingly need to judge communications and requests that may appear legitimate. In our experience, this is best achieved through a blended-learning awareness programme that includes engaging, interactive in-person training to encourage discussion, improve behaviour and reduce risk. Contact us to discuss how we can support your wider cyber security awareness programme.


Top Cyber Stories of the Last Week

New Phishing Attack Creates Malicious Pages inside the Victim’s Browser

Attackers are creating fraudulent pages inside victims’ browsers, making them harder for traditional security tools to detect and block. Barracuda identified a campaign using Docusign-themed emails and Microsoft Teams as part of the route to the fraudulent page, helping the activity appear trustworthy. Unlike conventional phishing, which tricks people into visiting fake websites, the attack causes the browser to generate the phishing page itself, leaving no fixed web page to block. The technique highlights the need for stronger protection of user accounts, closer monitoring of browser activity and email security that checks the full sequence of links and redirects.

https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/

BigBear Microsoft 365 Phishing Service Bypassed MFA at 258 Organisations

A phishing service called BigBear 2.0 has bypassed multi-factor authentication, which requires additional identity checks beyond a password, at 258 organisations. Researchers at CloudSEK uncovered 5,137 stolen credential records affecting victims across more than 40 countries. The service intercepts legitimate Microsoft 365 sign-ins, allowing criminals to take over accounts after users complete authentication checks, potentially exposing emails, files and connected applications. The findings show that MFA can still be defeated when attackers capture authenticated sessions, reinforcing the need for phishing-resistant authentication and access controls that require managed devices.

https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/

Microsoft Warns Fake CAPTCHA Is Tricking Windows Users into Running Malware

Fake online verification checks are tricking Windows users into running malicious commands that could expose business networks to data theft and ransomware. Microsoft has identified a campaign called TerminalFix, which impersonates trusted services such as Cloudflare and asks users to paste commands into Windows tools. When users follow these instructions, they can give attackers lasting access to a device and a route into wider company systems. Organisations should remind staff how legitimate checks work. In addition, access to powerful tools should be restricted where practical, and devices monitored for unusual activity.

https://www.techspot.com/news/113721-microsoft-warns-fake-captcha-pages-tricking-windows-users.html

Cyber Criminals Are Adapting ASCII Smuggling for Mass Phishing Campaigns

Cyber criminals are using invisible Unicode characters to disguise words in phishing emails and bypass traditional spam filters. Microsoft observed a sharp rise in the technique from February, with around 96% of detected activity linked to finance-themed lures sent from hundreds of disposable domains. The hidden characters can split words such as “funding” without changing how they appear to recipients, making simple keyword-based filtering less effective. Microsoft recommends that organisations remove or standardise invisible characters before scanning emails, and apply the same controls where AI tools process email content.

https://www.itpro.com/security/cyber-crime/cyber-criminals-are-adapting-ascii-smuggling-for-mass-phishing-campaigns

Hackers Are Calling: The Vishing Campaign Targeting Financial Institutions

A vishing campaign targeting major US financial institutions shows how a simple phone call can lead to a serious cyberattack. Attackers are posing as IT helpdesk staff and directing employees to fake login pages that capture passwords and multi-factor authentication codes. Apollo Global Management disclosed that personal data including social security numbers was stolen, while dozens of firms including Blackstone, KKR and Moody’s were reportedly targeted. Ransom demands have reportedly ranged from $750,000 to $3 million, reinforcing the need to train employees for unexpected calls and strengthen verification procedures for credential and MFA resets.

https://www.jdsupra.com/legalnews/hackers-are-calling-the-vishing-2784746/

NHIs Now the Number One Corporate Entry Point for Hackers

Digital accounts and access credentials used by software rather than people, known as non-human identities, are emerging as a major route into corporate systems. Examples include AI agents, service accounts and application access keys. SpyCloud found non-human identities accounted for 31% of intrusions, compared with 17% involving social engineering attacks that manipulate people. Although 95% of organisations believe they have adequate visibility of these identities, only 36% actively monitor them. The study found 68% had experienced an identity-related security event, reinforcing the need for stronger monitoring and formal controls over the access given to AI tools and agents.

https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/

AI Is Making Phishing Scams Almost Impossible to Spot – 5 Steps Employers Should Take to Combat Latest Threat

Artificial intelligence is making fraudulent messages more convincing, removing traditional warning signs and enabling personalised scams at scale. Huntress reported a nearly 15-fold increase in attempts to trick employees into authorising an attacker’s device during the first four months of 2026 compared with the second half of 2025. These attacks use genuine sign-in pages and can succeed despite additional identity checks. Employers should respond by updating phishing training, requiring separate-channel verification for sensitive requests, extending scrutiny beyond email, educating employees about newer attack techniques and treating phishing defence as a joint responsibility for IT and HR.

https://www.jdsupra.com/legalnews/ai-is-making-phishing-scams-almost-2513494/

AI Agents Carried Out Every Step of This Ransomware Attack – Then Left the Victim an 80-Page Security Audit

A ransomware attacker used frontier AI models and AI agents to breach an enterprise network in under 10 hours, a process that Unit 42 estimates would normally take human attackers around two weeks. The AI agents carried out much of the intrusion autonomously, mapping internal systems, stealing passwords and access tokens, accessing cloud and identity environments and adapting their approach as they progressed. No previously unknown vulnerability was required. After completing the attack, the AI system even produced an 80-page report detailing the security weaknesses it had exploited, highlighting how AI can dramatically increase the speed and efficiency of cyberattacks.

https://www.theregister.com/security/2026/09/02/ai-agents-carried-out-every-step-of-this-ransomware-attack-then-left-the-victim-an-80-page-security-audit/5294009

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

Google has warned that artificial intelligence is allowing smaller and less well-resourced attackers to operate at a scale previously associated with nation states. One attacker used an AI coding assistant to plan and execute a mass credential-theft campaign in under six hours. Google has also observed Chinese, Iranian and North Korean state-linked groups using AI for target research, phishing, malware development and cryptocurrency theft. The growing concern is not that AI changes the fundamentals of cyberattacks, but that it significantly increases their speed and scale and gives less well-resourced attackers greater capability.

https://www.securityweek.com/ai-is-giving-lesser-resourced-attackers-nation-state-level-reach-google-warns/

‘You Cannot Manage What You Do Not Know’: The NCSC Is Calling for a Crackdown on Shadow AI

Unapproved artificial intelligence tools, known as ‘shadow AI’, can expose organisations to risks including data breaches, loss of intellectual property and failure to meet regulatory requirements, the UK’s National Cyber Security Centre has warned. Microsoft research found that 71% of UK employees had used unapproved consumer AI tools at work, with more than half reporting weekly use. Sensitive information shared with these services may be retained or reused outside organisational control. The NCSC recommends understanding why employees use these tools, establishing practical policies and providing approved alternatives so businesses can benefit from AI while managing cyber security risks.

https://www.itpro.com/security/you-cannot-manage-what-you-do-not-know-the-ncsc-is-calling-for-a-crackdown-on-shadow-ai

Why Judgment Is Emerging as Cyber Security’s Defining Skill

While artificial intelligence takes on a greater role in cyber security analysis, technically sound recommendations can still disrupt critical services or financial processes if they overlook how the business operates. Decisions about allowing AI to act independently should reflect the potential business impact and how easily actions can be reversed. Experienced cyber security professionals can add knowledge of the organisation that may be missing from AI analysis, including how systems are used, which services rely on them and what previous incidents have shown. This human judgement remains essential to ensure decisions reflect both the threat and the wider business consequences.

https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/

Working with Your Board around Risk – Why Cyber Responsibility Can’t Be Shirked

Chief Information Security Officers (CISOs) play a major role in supporting boards with their responsibility for cyber risks in the organisation, by providing the right information on risk management expressed in business terms. As digital dependence and cyber disruption increase, directors need cyber risks expressed in business terms, including potential financial losses and the effectiveness of existing controls, so they can make informed investment decisions. The UK Government’s Cyber Resilience Pledge calls for greater board engagement, including cyber security governance training and consideration of supplier risk. Ultimately, boards need to ensure the organisation can continue operating when cyber disruption occurs.

https://www.computerweekly.com/opinion/Working-with-your-board-around-risk-why-cyber-responsibility-cant-be-shirked

Digital Sovereignty Now a Boardroom Priority as Companies Confront Escalating Tech Risks, Survey Finds

Dependence on critical technology providers is becoming a boardroom concern as geopolitical tensions, export controls and cyber threats increase the risks associated with critical digital infrastructure. A Capgemini survey of 1,300 large organisations across 11 countries found nearly half would need between three months and a year to replace a critical provider, while more than a third would need longer than a year. To address this business risk, organisations are increasingly focusing on keeping important data, AI models and key workloads under their control, alongside contingency planning to ensure they can switch providers if access is disrupted.

https://allwork.space/2026/09/digital-sovereignty-now-a-boardroom-priority-as-companies-confront-escalating-tech-risks-survey-finds/

The AI Reality Check: The Real Challenge Is Governing Complexity

Artificial intelligence is accelerating how attackers identify and exploit connections between systems, accounts, suppliers and data, making unmanaged digital complexity a growing cyber security risk. While AI is increasingly important for defence, technology alone cannot ensure resilience. Organisations need to understand how their systems connect, where sensitive information flows and who can access it. AI systems acting independently require clearly defined permissions, monitoring and accountable human oversight. Strong access controls and effective governance remain essential, while decisions about acceptable risk, policy and accountability must remain with people.

https://www.techfinitive.com/opinions/the-ai-reality-check-the-real-challenge-is-governing-complexity/



Threats

Ransomware, Extortion and Destructive Attacks

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Extortion crews have their eyes on high-value AI data, Google warns

Cryptolocker ransomware: A look back at its widespread impact | brief | MSSP Alert

Ransom! The Unfortunate New Normal: Cybersecurity Considerations for Fiduciaries | J.S. Held - JDSupra

Fake GTA6 'Leaked Download' Caught Spreading RATs, Infostealer and Wiper Ransomware - IT Security Guru

Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS

CRPx0 Ransomware: What You Need to Know | Fortra

Ransomware and Destructive Attack Victims

Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online | IT Pro

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Re - Infosecurity Magazine

ShinyHunters Gained Access to 6 Million Customers Record Using a Single Call

Storm ransomware claims attack on Boeing, Airbus supplier | Cybernews

Odido hackers mock police, threaten another Netherlands hack | Cybernews

Boston Scientific Flags Financial Hit From Cyberattack

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

Veradigm warns of patient data breach after ransomware gang claims attack

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Phishing & Email Based Attacks

Scammers have figured out the best time to text you - Help Net Security

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser - SecurityWeek

AI is Making Phishing Scams Almost Impossible to Spot – 5 Steps Employers Should Take to Combat Latest Threat | Fisher Phillips - JDSupra

Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online | IT Pro

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog

Outsider Phishing Kit Survives Takedown With 700 New Pages - Infosecurity Magazine

Hackers Use QR Codes With No Images to Bypass Email Security

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking

Protecting Against Zero-Click Attacks - IT Security Guru

IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security

BigBear phishing crew nets thousands of Microsoft 365 credentials

New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert

Trezor customers hit with phishing calls and letters after shipping-partner breach - Help Net Security

Hackers Use Brazilian Government Servers to Host Phishing Sites

Don’t Take The Bait: The New Phishing Threats To Asset Managers | Ropes & Gray LLP - JDSupra

Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions

Other Social Engineering

Scammers have figured out the best time to text you - Help Net Security

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser - SecurityWeek

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Microsoft warns fake CAPTCHA is tricking Windows users into running malware | TechSpot

Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online | IT Pro

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security

Large Enterprises Targeted in Fake Merger & Acquisition Scams

ClickFix Campaigns Abuse Legitimate Services for Persistence

Hackers Are Calling: The Vishing Campaign Targeting Financial Institutions | Goodwin - JDSupra

New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert

Fake GTA6 'Leaked Download' Caught Spreading RATs, Infostealer and Wiper Ransomware - IT Security Guru

Trezor customers hit with phishing calls and letters after shipping-partner breach - Help Net Security

Don’t Take The Bait: The New Phishing Threats To Asset Managers | Ropes & Gray LLP - JDSupra

2FA/MFA

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Artificial Intelligence

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

AI means fundamentals matter more than ever | Professional Security Magazine

'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI | IT Pro

AI is Making Phishing Scams Almost Impossible to Spot – 5 Steps Employers Should Take to Combat Latest Threat | Fisher Phillips - JDSupra

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Why CISOs should focus on real AI threats, not hype | CSO Online

Companies Have 6 Months to Prepare for Automated Attacks

Why AI Agent Sandboxes Are Failing Security Tests

AI Can Jump Sandboxes. Easy-Peasy. The World Needs New Borders That Can Actually Contain It. - Security Boulevard

Another Anthropic model gained access to the open internet during testing, company says - CBS News

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog

AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat

How AI Agents Are Creating a New Kind of Security Risk

GPT-6 Astra Draws Scrutiny for Being Harder to Monitor Even as OpenAI Calls It More Aligned - gHacks Tech News

What the AI Warning Letter Completely Missed

Insurers Search for Answers to Rein in Rogue AI

18 ways to check whether data can be trusted for AI - Help Net Security

An AI kill switch ‘only solves half the problem’ with national security – British firms need to reduce reliance on foreign tech | IT Pro

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Cybercriminals are turning AI’s safety guardrails against it | Ctech

The Ungoverned Frontier of Agentic AI Cyberattacks

Your AI agent's system prompt is not a security control - Help Net Security

Anthropic pledges to try harder to keep models under control, asks partners to chip in

UK cyber bill targets AI users, not the vendors building it

As agentic AI adoption accelerates, Rubrik warns of growing security gaps | TahawulTech.com

The AI safety rule workers need: no agent gets power without a named human owner – Labour Hub

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

How AI is changing cybersecurity threats (and how it isn't)

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

The US plans to raise AI-directed cyberattacks with China, Nikkei reports

The AI cybersecurity arms race is on | CIO

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

Financial Firms Inundated By AI Security Findings, FCA Warns

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Man gets 15 years for extorting women with AI-generated porn videos

US Government Claims Chinese AI Firms Distilling Frontier Models

Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions

Nvidia transfers Open Secure AI Alliance to Linux Foundation | brief | MSSP Alert

Bots/Botnets

‘Attackers are steering their botnets with greater precision and control’: DDoS attack numbers might be dwindling, but they’re intensifying | IT Pro

Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

New Linux Bot Hides as Kernel Process and Launches DDoS Attacks

Careers, Roles, Skills, Working in Cyber and Information Security

Why Today's Cybersecurity Leaders Must Help Shape Tomorrow's Talent - Infosecurity Magazine

HMRC offers £173k for chief security officer – PublicTechnology

Cloud/SaaS

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

IT help-desk vishing tricks executives into handing over Microsoft 365 access - Help Net Security

How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts

New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

ClickFix Moves into the Browser to Steal Cryptocurrency - Infosecurity Magazine

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Trezor data breach impact now reaches 81,000 customers

JSCeal Hides Crypto Malware in V8 Bytecode

Hackers Drain $320 Million From Liquid Network, Then Return Most of It

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle - Help Net Security

Cyber Crime, Organised Crime & Criminal Actors

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle - Help Net Security

A dark-web site claimed to sell 153 million driver's licenses, then vanished | TechSpot

Russian national extradited to US for alleged involvement in bank-account takeover scheme | CyberScoop

Data Breaches/Leaks

How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts

A dark-web site claimed to sell 153 million driver's licenses, then vanished | TechSpot

Trezor data breach impact now reaches 81,000 customers

IDScan sued over alleged data breach affecting 153 million drivers

Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Odido hackers mock police, threaten another Netherlands hack | Cybernews

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Mathspace: Over a million Aussies' data stolen in major hack to learning platform | Daily Mail Online

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

Veradigm warns of patient data breach after ransomware gang claims attack

AdaptHealth confirms 4.1 million people exposed in July cyberattack

French hospital fined €500,000 after breach exposes data of 727,000

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

Data/Digital Sovereignty

An AI kill switch ‘only solves half the problem’ with national security – British firms need to reduce reliance on foreign tech | IT Pro

Digital Sovereignty Now A Boardroom Priority As Companies Confront Escalating Tech Risks, Survey Finds

Switzerland tests a FOSS escape route from Microsoft 365

Denial of Service/DoS/DDoS

‘Attackers are steering their botnets with greater precision and control’: DDoS attack numbers might be dwindling, but they’re intensifying | IT Pro

Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting

New Linux Bot Hides as Kernel Process and Launches DDoS Attacks

Encryption

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules - Infosecurity Magazine

Fraud, Scams and Financial Crime

Scammers have figured out the best time to text you - Help Net Security

Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online | IT Pro

Large Enterprises Targeted in Fake Merger & Acquisition Scams

UK account-hack losses surge as new reporting system exposes hidden cases | The Record from Recorded Future News

How to spot scam websites that your browser says are safe | Kaspersky official blog

Gigabud Uses Android App Cloning to Evade Fraud Detection - Infosecurity Magazine

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18) | Malwarebytes

Identity and Access Management

How AI Agents Are Creating a New Kind of Security Risk

NHIs Now the Number One Corporate Entry Point for Hackers - Infosecurity Magazine

Insider Risk and Insider Threats

Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

Insurance

Insurers Search for Answers to Rein in Rogue AI

Internet of Things – IoT

LG Denies Its Televisions Record Ambient Conversations for Ad Targeting - CNET

Is Your Roomba a National Security Threat? Inside the FCC's Tech Crackdown - CNET

Police bodies consider risks and benefits of connected cars | UKAuthority

Norway Considers Ban On Meta Glasses' New Facial Recognition Features

Law Enforcement Action and Take Downs

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

Outsider Phishing Kit Survives Takedown With 700 New Pages - Infosecurity Magazine

Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle - Help Net Security

Man gets 15 years for extorting women with AI-generated porn videos

Russian national extradited to US for alleged involvement in bank-account takeover scheme | CyberScoop

Linux and Open Source

Switzerland tests a FOSS escape route from Microsoft 365

New Linux Bot Hides as Kernel Process and Launches DDoS Attacks

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

North Korean Hackers Deploy New Linux Espionage Toolkit - SecurityWeek

Malvertising

StreamRat Android malware spreads through Meta and TikTok ads | Malwarebytes

Malware

Microsoft warns fake CAPTCHA is tricking Windows users into running malware | TechSpot

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

ClickFix Campaigns Abuse Legitimate Services for Persistence

Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns - IT Security Guru

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

New Linux Bot Hides as Kernel Process and Launches DDoS Attacks

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

New SynkLoader malware distributed via Microsoft Teams phishing | brief | MSSP Alert

Fake GTA6 'Leaked Download' Caught Spreading RATs, Infostealer and Wiper Ransomware - IT Security Guru

Popular Chrome Extensions Weaponized to Steal Crypto From 80,000 Users - gHacks Tech News

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Your Employee’s Password Appeared in an Infostealer Log. Now What?

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Github for all — attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage | Tom's Hardware

Mobile

The US military just turned off ad tracking on its phones. Maybe you should too

StreamRat Android malware spreads through Meta and TikTok ads | Malwarebytes

WeChat Worm Can Hijack Accounts Without Victims Answering Calls

Android's September 2026 Updates Patch 180 Vulnerabilities - SecurityWeek

Gigabud Uses Android App Cloning to Evade Fraud Detection - Infosecurity Magazine

Models, Frameworks and Standards

Peers ask why UK cyber bill leaves execs off the personal liability hook

UK cyber bill targets AI users, not the vendors building it

UK's Online Safety Act has made 'absolutely no difference,' kids say

DORA, NIS2 and the AI Act are One Job, Says UiPath's Field CISO | The Fintech Times

Understanding CMMC 2.0: A Guide for Defense Contractors | brief | MSSP Alert

Key Starting Point for CRA Reporting Obligations

The EU CRA's Real Question: What Shipped, and When Did You Know?

Government rejects Computer Misuse Act amendment to protect cyber professionals | Computer Weekly

ISO 27001: What it is and How it Protects Your UK Business from Cyber Security Threats | The Global Recruiter

Passwords, Credential Stuffing & Brute Force Attacks

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Your Employee’s Password Appeared in an Infostealer Log. Now What?

39 New Methods That Compromise Passkey Authentication

Privacy, Surveillance

LG Denies Its Televisions Record Ambient Conversations for Ad Targeting - CNET

Norway Considers Ban On Meta Glasses' New Facial Recognition Features

Regulations, Fines and Legislation

UK cyber bill targets AI users, not the vendors building it

UK's Online Safety Act has made 'absolutely no difference,' kids say

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Norway Considers Ban On Meta Glasses' New Facial Recognition Features

DORA, NIS2 and the AI Act are One Job, Says UiPath's Field CISO | The Fintech Times

Key Starting Point for CRA Reporting Obligations

The EU CRA's Real Question: What Shipped, and When Did You Know?

Government rejects Computer Misuse Act amendment to protect cyber professionals | Computer Weekly

French hospital fined €500,000 after breach exposes data of 727,000

FBI cyber leader details bureau’s first unclassified cyber strategy | Federal News Network

Understanding CMMC 2.0: A Guide for Defense Contractors | brief | MSSP Alert

Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms | TechCrunch

Shadow IT

'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI | IT Pro

Software Supply Chain

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

Supply Chain and Third Parties

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Storm ransomware claims attack on Boeing, Airbus supplier | Cybernews


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Kremlin Intensifies Russia’s Shadow War Against Europe | The Gaze

Expert: Russia-NATO tensions likely to escalate - English Section

Russia’s invisible war is exposing Europe’s vulnerabilities - Decode39

The four ways the UK could respond to Putin’s grey war

Boards prepare for digital infrastructure shocks, survey says - CNA

Germany Unveils Four-Step Plan to Counter Russia’s Hybrid Threats | The Gaze

One in 5 German firms feels impact of foreign hybrid threats - Read Qatar Tribune on the go for unrivalled news coverage

Compliance teams have gone continuous, but their evidence-gathering hasn't caught up - IT Security Guru

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

North Korean Hackers Deploy New Linux Espionage Toolkit - SecurityWeek

Minister tells Brits to stock up on days of supplies after ‘supersize’ El Niño warning | El Niño southern oscillation | The Guardian

Government must engage more with households, communities and industry to strengthen food supply chain resilience to shocks - NAO press release

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters - Infosecurity Magazine

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Russia widens targeting of European research centres | Science|Business

Army to mobilise veterans in preparation for war

Nation State Actors

Why hostile state cyber activity is now a day-to-day business risk - IT Security Guru

UK food supply chains need protecting according to new report - CILT

Boards prepare for digital infrastructure shocks, survey says - CNA

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns - SecurityWeek

China

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Is Your Roomba a National Security Threat? Inside the FCC's Tech Crackdown - CNET

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

US Government Claims Chinese AI Firms Distilling Frontier Models

The US plans to raise AI-directed cyberattacks with China, Nikkei reports

Russia

Kremlin Intensifies Russia’s Shadow War Against Europe | The Gaze

Expert: Russia-NATO tensions likely to escalate - English Section

Russia’s invisible war is exposing Europe’s vulnerabilities - Decode39

The four ways the UK could respond to Putin’s grey war

Germany Unveils Four-Step Plan to Counter Russia’s Hybrid Threats | The Gaze

One in 5 German firms feels impact of foreign hybrid threats - Read Qatar Tribune on the go for unrivalled news coverage

Compliance teams have gone continuous, but their evidence-gathering hasn't caught up - IT Security Guru

Minister tells Brits to stock up on days of supplies after ‘supersize’ El Niño warning | El Niño southern oscillation | The Guardian

Government must engage more with households, communities and industry to strengthen food supply chain resilience to shocks - NAO press release

Protecting Against Zero-Click Attacks - IT Security Guru

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Russia widens targeting of European research centres | Science|Business

Ukraine Must Cultivate 'Security-Minded' Cyber Defense

Army to mobilise veterans in preparation for war

Russian national extradited to US for alleged involvement in bank-account takeover scheme | CyberScoop

North Korea

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters - Infosecurity Magazine

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Iran

Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions

$10 Million Reward Offered for Information on IRGC Cyber Operations Chief

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

UK food supply chains need protecting according to new report - CILT


Tools and Controls

The AI reality check: The real challenge is governing complexity | TechFinitive

Why judgment is emerging as cybersecurity’s defining skill | CyberScoop

Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns - IT Security Guru

Why AI Agent Sandboxes Are Failing Security Tests

AI Can Jump Sandboxes. Easy-Peasy. The World Needs New Borders That Can Actually Contain It. - Security Boulevard

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

Boards prepare for digital infrastructure shocks, survey says - CNA

Working with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly

Penetration Testing Only Works When It's Scoped To Business Risk

Browser-based work is creating a new cybersecurity battleground - Digital Journal

Serious N-central flaw puts MSPs and MSSPs on patch alert | news | MSSP Alert

Configuration Drift Is a Growing Cybersecurity Risk: Report

Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

G7 sounds alarm on quantum cyber threats | IT Pro

As agentic AI adoption accelerates, Rubrik warns of growing security gaps | TahawulTech.com

Climate resilience reveals key enterprise networking blind spot | Computer Weekly

Root Evidence Finds the “Vulnpocalypse” Isn’t Showing Up in the Data

Most of the bugs Claude Mythos found have never been checked by a human - Help Net Security

AI Will End the Era of Hidden Vulnerabilities. Are Vendors Ready?

Mythos Vulnerability Firehose Hits a Human Bottleneck

The AI cybersecurity arms race is on | CIO

Financial Firms Inundated By AI Security Findings, FCA Warns

Humans have edge over AI in Dutch hacking contest | Computer Weekly

To keep the AI hacking genie bottled up, try one-way networks

Please stop using your ISP's DNS

AI is finding vulnerabilities faster. Who is funding the people expected to fix them? - IT Security Guru

Compliance teams have gone continuous, but their evidence-gathering hasn't caught up - IT Security Guru

France Establishes New Government-Focused Cyber Incident Response Unit - Infosecurity Magazine

UK government proposes AI first responders for cyber attacks | Computer Weekly

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results - Help Net Security

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

“Security cannot simply act as a roadblock, because that stops the momentum that lead | Ctech

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation - Infosecurity Magazine

Researcher sends himself email from exploited company account | Cybernews



Vulnerability Management

Chrome is now shipping updates every 2 weeks as AI changes the security landscape | TechCrunch

Configuration Drift Is a Growing Cybersecurity Risk: Report

Root Evidence Finds the “Vulnpocalypse” Isn’t Showing Up in the Data

Most of the bugs Claude Mythos found have never been checked by a human - Help Net Security

AI Will End the Era of Hidden Vulnerabilities. Are Vendors Ready?

Financial Firms Inundated By AI Security Findings, FCA Warns

Mythos Vulnerability Firehose Hits a Human Bottleneck

AI is finding vulnerabilities faster. Who is funding the people expected to fix them? - IT Security Guru

Vulnerabilities

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Critical Citrix NetScaler auth bypass now leveraged in attacks

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

N-able patches max severity N-central flaw amid ongoing attacks

Hackers exploit chained SonicWall gaps for remote code execution | brief | MSSP Alert

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

MikroTik Patches Critical Flaws Chained to Hack Routers - SecurityWeek

Chinese espionage groups swarm to exploit triple-link chain of zero-days | CyberScoop

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

Cisco discloses critical flaws in IOS XR and Nexus 9000 switches | brief | MSSP Alert

HPE Patches Critical RCE Vulnerabilities in AOS-CX - SecurityWeek

Ivanti Patches Critical Flaws Across Enterprise Security Products - SecurityWeek

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension - SecurityWeek

Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass and SQL Injection

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits - SecurityWeek

September Windows Server updates break Remote Desktop Services

ConnectWise warns of new ScreenConnect flaw without patch

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Another Artifactory CVE under attack by AI agents or humans

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day - SecurityWeek

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

Android's September 2026 Updates Patch 180 Vulnerabilities - SecurityWeek

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories - SecurityWeek

Sangoma Switchvox Vulnerabilities Exploited in the Wild - SecurityWeek

Two major security flaws are affecting more than six million WordPress websites | TechRadar

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors - Help Net Security

The harmless logo your PC shows at startup has a terrifying security problem

Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

Microsoft fixes bug that wiped Windows desktop settings

Over 36,000 exposed Plex servers vulnerable to recent flaws

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins - Help Net Security


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 04 September 2026