Black Arrow Cyber Threat Intelligence Briefing 14 August 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start our review of the specialist and general media this week by looking at the importance of recovery and resilience when responding to a cyberattack. This is essential, as attackers increasingly seek to damage backups and recovery capabilities, requiring organisations to focus not only on preventing attacks but also on recovering from them. Resilience, recovery planning and governance are as important as traditional security controls as cyber threats increase in speed and scale.

At the same time, ransomware remains a significant threat, while criminals continue to exploit familiar weaknesses including compromised credentials, social engineering, insider access and third-party relationships. Reporting this week highlights attackers targeting managers and other employees with valuable business access, alongside growing concerns over AI governance and accountability.

The consistent message for business leaders is that cyber security and resilience must be addressed together, and must consider the risks presented by AI. Contact us to discuss how we help organisations strengthen proportionate cyber security, resilience and governance by understanding and addressing current and evolving cyber risks.


Top Cyber Stories of the Last Week

AI Is Changing Cyber Threats. Recovery Is Becoming Just as Important as Prevention

AI is accelerating software development, but it is also widening the range of systems, identities and data that organisations must protect. Security leaders warn that faster development and increasingly autonomous AI tools can introduce weaknesses more quickly and make attacks harder to contain. This is shifting attention from prevention alone towards cyber resilience, including the ability to identify trusted backups and restore operations quickly after an incident. Organisations are also being encouraged to apply clear access controls to AI systems, regularly test recovery plans and treat resilience as a business continuity priority rather than simply a technical or compliance issue.

https://yourstory.com/2026/08/ai-is-changing-cyber-threats-recovery-is-becoming-just-as-important-as-prevention

Why Recovery Readiness Has Become the New Standard for Cyber Resilience

Ransomware increasingly targets an organisation’s ability to recover, with more than 90% of attacks attempting to delete or tamper with backups and nearly 60% succeeding. This exposes a critical gap between simply storing backup data and being able to restore business operations quickly. The risk is compounded by identity-based attacks, fragmented protection across cloud and on-premises systems, and limited testing of recovery plans. 18% of organisations test recovery monthly, while just one in five report unified backup protection across hybrid environments, increasing the risk of prolonged disruption, financial loss and reputational damage.

https://www.zdnet.com/paid-content/article/why-recovery-readiness-has-become-the-new-standard-for-cyber-resilience/

‘The Easiest Way into a Company Isn’t Always Through a Vulnerability Anymore’: Hackers Are Building a Global Insider Threat Recruitment Network – and They’re Even Offering Referral Bonuses

Cyber criminals are increasingly paying employees to provide access to company systems, approve fraudulent activity or leak sensitive data, creating a growing insider threat across sectors including financial services, telecommunications, logistics and social media. TrendAI found a structured criminal market offering fixed payments, profit sharing and even referral bonuses, with prices ranging from a few hundred dollars for credentials to $1,000 a day for specific internal actions. Organisations should treat unusual staff activity and approval exceptions as potential security concerns, while reducing reliance on single-person authority for high-risk transactions.

https://www.itpro.com/security/the-easiest-way-into-a-company-isnt-always-through-a-vulnerability-anymore-hackers-are-building-a-global-insider-threat-recruitment-network-and-theyre-even-offering-referral-bonuses

Cyber Security Needs a New Operating Model

The European Central Bank has warned that AI is accelerating cyber attacks to the point where traditional security processes may no longer move quickly enough. Europe’s largest banks have been asked to submit plans addressing AI-enabled cyber threats by 31 October 2026, reflecting a wider regulatory shift towards treating AI as an operational risk rather than an emerging concern. As attackers increasingly use AI to identify weaknesses and develop attacks at scale, organisations will need to prioritise risks based on real-world exposure and strengthen their ability to respond before vulnerabilities can be exploited.

https://www.csoonline.com/article/4206138/cybersecurity-needs-a-new-operating-model.html

The New Mandate for CISOs: Become an Architect of Secure AI

AI adoption is accelerating faster than many organisations can govern it, with Netskope reporting that 73% of organisations now use AI but only 7% enforce security policies in real time. Despite 90% of cyber security professionals increasing AI security budgets this year, 29% feel less secure than 12 months ago. The growing use of unapproved AI tools is increasing the risk of sensitive data exposure and inconsistent controls. Effective AI adoption therefore depends on clear governance, appropriate safeguards and strong data protection, enabling organisations to innovate while maintaining oversight and reducing business risk.

https://www.raconteur.net/technology/the-new-mandate-for-cisos-become-an-architect-of-secure-ai

Ransomware Attacks Spike as World Distracted by AI

Comparitech recorded 799 ransomware attacks in July, a 20% rise making it the second busiest month of the year. Finance, technology, pharmaceutical and education organisations saw the sharpest increases. The United States accounted for 322 incidents, far ahead of Germany with 40. Two ransomware groups, The Gentlemen and Qilin, were linked to almost a third of recorded attacks, highlighting that established threats such as stolen login details and unpatched systems remain significant despite growing attention on AI related risks.

https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934

Ransomware Attackers Target Managers to Steal Data and Move Deeper into Corporate Networks

Ransomware groups are increasingly targeting managers and other senior employees because their everyday access can provide a route to sensitive data, financial processes and wider corporate systems. Zscaler tracked 351 victims across 334 organisations in one month, with 62% holding manager-level roles or above and around 75% working in finance, sales, operations, HR or marketing. Industrial organisations accounted for 35.5% of victims. The findings highlight that attackers do not need administrator access to cause significant disruption, making tighter access controls, verification of unusual requests and rapid investigation of compromised accounts increasingly important.

https://cybersecuritynews.com/ransomware-attackers-target-managers/

Ransom-Seeking Hackers Set Their Sights on Wall Street’s Trillion-Dollar Private Equity Firms

Ransom-seeking criminals have targeted dozens of major US financial institutions, private equity firms, law firms and other businesses using convincing phone calls and fake login websites. Google reported on the campaign, while Reuters' analysis of 72 malicious websites listed in Google’s report found that more than 200 organisations had been targeted over a five-week period. Attackers impersonated internal IT support teams and persuaded employees to disclose passwords and multi-factor authentication codes, allowing them to take control of accounts. The campaign highlights how simple manipulation of employees can bypass sophisticated technical security controls, particularly where highly sensitive financial and commercial data could make organisations attractive ransom targets.

https://www.independent.co.uk/tech/google-hackers-wall-street-ransom-b3029209.html

Who Is Liable When AI Goes Rogue? Lawyers See New Risks

As autonomous AI agents become more capable of acting without human oversight, recent incidents involving OpenAI, Anthropic and Meta have raised new questions over legal responsibility when AI systems breach corporate networks. Potential claims could come from affected businesses, customers, employees, shareholders and regulators, with liability potentially extending to both AI developers and organisations deploying the technology. Existing negligence and computer access laws may apply, although courts are still determining how concepts such as intent and foreseeability should be treated when an AI system acts independently. California has also introduced legislation preventing companies from avoiding liability simply by blaming the AI itself.

https://indianexpress.com/article/technology/artificial-intelligence/who-is-liable-when-ai-goes-rogue-lawyers-see-new-risks-10822929/

UK Charities Count the Cost of Beacon CRM Cyberattack

Beacon CRM, a platform used by more than 1,500 organisations, has confirmed a cyberattack in which customer database backups were likely stolen. Customers have been advised to assume all information held on the platform before 27 July was accessed and may have been readable despite encryption. A number of UK charities have confirmed potential exposure of personal information, including names, contact details, dates of birth and donation records. Early evidence suggests compromised login credentials were used to gain access, highlighting the potential impact of a supplier breach on organisations and the people whose data they hold.

https://www.theregister.com/security/2026/08/05/uk-charities-count-the-cost-of-beacon-crm-cyberattack/5283305

Inside the BBC’s Emergency Plans for a Putin Cyber Attack

The BBC is strengthening plans to keep the public informed if a major cyberattack or power outage disrupts critical UK infrastructure. Its contingency planning prioritises radio, particularly FM, as a resilient communications channel when internet, television or mobile services may be unavailable. The UK Government is also preparing to encourage households to keep battery-powered or wind-up radios and other emergency supplies. Recent exercises involving 120 experts from the Cabinet Office, NHS and Ministry of Defence have tested scenarios affecting hospitals and traffic systems, highlighting growing concern over the resilience of essential services and communications.

https://inews.co.uk/news/media/bbc-emergency-putin-cyber-attack-4689896?ITO=newsnow



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware attacks spike as world distracted by AI

Europe Ransomware Attacks Up 29%, TicTac Research Finds

Ransomware Surges in July After Q2 Lull - Infosecurity Magazine

Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks

Why managers are ransomware's top targets now - and 6 ways to stay safe | ZDNET

Ransom-seeking hackers set their sights on Wall Street’s trillion-dollar private equity firms: report | The Independent

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

New StormEncryptor ransomware used by former Medusa affiliate

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

ExfilSquad Targets New Victims, Shares Data via Torrents

DeadLock ransomware uses blockchain to resist infrastructure takedown

Ransomware and Destructive Attack Victims

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

ExfilSquad Targets New Victims, Shares Data via Torrents

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout | The Record from Recorded Future News

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

Major hedge funds targeted in wave of attempted cyberattacks | Fortune

Bay Area city declares state of emergency over malicious cyberattack

Ransomware attack on Health Sciences Centre affects doors, ventilation and air-conditioning | CBC News

Wesco confirms security incident after ExfilSquad claims data theft

French rugby club Stade Français restores systems after cyberattack, probes data leak | The Record from Recorded Future News

Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo - Infosecurity Magazine

Manitoba health minister says cybersecurity priority after hospital attack

Phishing & Email Based Attacks

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

New Phishing Attack Uses SSL/TLS Certificates to Target Customers of High-Value Brands via WhatsApp

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

AI Phishing Now Frighteningly Normal, Hard to Detect

Real emails, hijacked payments: Two H1 2026 attack chains

Ofcom UK Blocked 481,521 Malicious Emails Over the Past 3 Years - ISPreview UK

Steam hardware distributor hit by cyberattack, 'expect fake messages,' Valve warns — Europe vendor has personal information and hardware purchase details stolen | Tom's Hardware

Other Social Engineering

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Hackers talked their way into Levi’s, and three computers were enough

Sherlock Holmes was the “OG” Social Engineer

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare | ZDNET

Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix

2FA/MFA

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

AML/CFT/Money Laundering/Terrorist Financing/Sanctions

New Zealand sanctions Russian hackers, propaganda groups over Ukraine war | The Record from Recorded Future News

Artificial Intelligence

Ransomware attacks spike as world distracted by AI

CISO AI risk management drives business growth - SiliconANGLE

The new mandate for CISOs: become an architect of secure AI - Raconteur

Frontier AI Has a Cybersecurity Expertise Problem - Security Boulevard

Humans in the loop miss a third of dangerous AI coding agent requests

AI agent creates fake personas, plants malware during UK security test | SC Media UK

Three Disclosures, Three Different Unintended Failures (OpenAI, Anthropic, and Now AISI) | Lowenstein Sandler LLP - JDSupra

AI experts are panicking about a terrifying new era of hacking. What can normal people do? | The Independent

UK cyber agency warns over frontier AI behaviour

Who is liable when AI goes rogue? Lawyers see new risks | Technology News - The Indian Express

IBM’s 2026 Cost of a Data Breach Report Signals a New Era of AI-Driven Cyber Risk | Alston & Bird - JDSupra

Cyberattacks are getting faster as AI helps hackers scale | Inquirer Technology

The AI Governance Gap Is a Leadership Problem: Waiting Won't Close It - SecurityWeek

Cyber resilience takes center stage as AI reshapes the CISO role - SiliconANGLE

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Meta becomes the third AI giant in two weeks to admit its model went rogue | TechSpot

Who Is Liable When an AI Agent Hacks a Third Party? | BakerHostetler - JDSupra

Hidden Text in PDFs Is Hijacking This AI Assistant - Decrypt

Innovation or Negligence? What Recent AI Hacks Mean for the Future of Cybersecurity

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks | TechRadar

AI deployments are stretching enterprise security to its limits - Help Net Security

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack - SecurityWeek

AI sandbox escape uncovered in Microsoft Copilot flaw - SiliconANGLE

Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agents | IT Pro

Researcher Claims Control of ChatGPT Secure Sandbox

Prompt injection isn't the bug, AI agent frameworks are

Why your AI orchestration framework is a critical security decision | CSO Online

Advertisers are trying to influence AI bots with secret ads

"GhostJacking" Exposes Identity Governance Gaps in AI Agents

The UK needs better AI governance

The Sandbox Failed: How OpenAI's Experimental AIs Went Rogue and Attacked Hugging Face

OpenAI reveals upcoming Astra model may possess 'critical’ hacking capabilities - SiliconANGLE

Chinese startup Moonshot's AI model breaks out of testing environment, researchers say

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data - SecurityWeek

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

How to report an AI Act violation in the EU - Help Net Security

Senior Derbyshire detective under investigation over use of AI - BBC News

An AI agent was asked to book a gym class, whe none was available, it decided to hack the system and jump the queue | TechSpot

Bots/Botnets

Kimwolf botnet rebuilt to survive takedowns, researchers say | CyberScoop

Careers, Roles, Skills, Working in Cyber and Information Security

What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience | ZDNET

'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today | ZDNET

Cyberattacks drive companies to hire specialised security talent in AI, cloud & threat intelligence - The Economic Times

Cloud/SaaS

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

Violent Physical Crypto Thefts Surge to $30m in Losses - Infosecurity Magazine

Go-Based macOS Malware Steals Crypto and Secrets - Infosecurity Magazine

Six npm Packages Read C2 Addresses From Ethereum Wallet - Infosecurity Magazine

Cyber Crime, Organised Crime & Criminal Actors

'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitment network – and they’re even offering referral bonuses | IT Pro

UK man tied to The Com sentenced for abusing 117 victims | CyberScoop

Looking Beyond the Numbers: Understanding Malicious Domain Registration Data

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Snowflake attacker pleads guilty to hack of 165 companies’ data | CSO Online

Data Breaches/Leaks

UK charities count the cost of Beacon CRM cyberattack

Beacon security incident: Hackers steal details of hundreds of lawyers who used mental health charity LawCare | Law Gazette

Beacon CRM confirms cyberattack exposed UK charity data | SC Media UK

Healthcare and Victim Support Charities Affected by Beacon Cyber Incid - Infosecurity Magazine

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack - SecurityWeek

Mozilla Issues New Firefox GPG Key Following Exposure - SecurityWeek

Hackers talked their way into Levi’s, and three computers were enough

3.8 Million Impacted by Unlimited Technology Systems Data Breach - SecurityWeek

Swiss government SharePoint breach compromised 200 accounts

London cops handed victim's new address and number to her stalker, watchdog says

Framework loses customer data in Metabase zero-day attack

Logistics Giant Ceva Suffers Data Breach Impacting European Clients - Infosecurity Magazine

Steam hardware distributor hit by cyberattack, 'expect fake messages,' Valve warns — Europe vendor has personal information and hardware purchase details stolen | Tom's Hardware

Champions Cup rugby team hacked in ransom attack with player data at risk

9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old

Data/Digital Sovereignty

US kill switch: 74% of European firms fear losing tech | Proton

75% of European businesses fear a US tech kill switch - American companies should, too | ZDNET

Denial of Service/DoS/DDoS

DDoS attacks over 1 Tbps surged fivefold in the second quarter

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common - Help Net Security

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Encryption

HP thin client disk encryption bypassed | Cybernews

Fraud, Scams and Financial Crime

Ready-made $500 kit puts a crypto scam within anyone's reach - Help Net Security

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Identity and Access Management

"GhostJacking" Exposes Identity Governance Gaps in AI Agents

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Insider Risk and Insider Threats

'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitment network – and they’re even offering referral bonuses | IT Pro

North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Internet of Things – IoT

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

Law Enforcement Action and Take Downs

UK man tied to The Com sentenced for abusing 117 victims | CyberScoop

Snowflake attacker pleads guilty to hack of 165 companies’ data | CSO Online

Linux and Open Source

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

How to combat the new threats in open-source libraries - SiliconANGLE

Growing Up The Hard Way

Malware

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Enterprise passkey security under threat from malware | CSO Online

How to combat the new threats in open-source libraries - SiliconANGLE

Go-Based macOS Malware Steals Crypto and Secrets - Infosecurity Magazine

Six npm Packages Read C2 Addresses From Ethereum Wallet - Infosecurity Magazine

Kimwolf botnet rebuilt to survive takedowns, researchers say | CyberScoop

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities - SecurityWeek

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix

Hackers breach TrueConf to trojanize client installers with backdoors

Lumma Stealer Malware Found in Pirated Copies of the “The Odyssey” - Security Boulevard

Misinformation, Disinformation and Propaganda

China launches cybersecurity investigation into Palo Alto Networks products - Global Times

Mobile

Coruna, DarkSword iOS Exploits Proliferate Globally

Android malware combo takes out loans and relays victims' credit cards

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G - Help Net Security

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Models, Frameworks and Standards

How to report an AI Act violation in the EU - Help Net Security

Department of War Suspends CMMC Phase 2 Assessment Requirements: Top Points For Defense Contractors | DLA Piper - JDSupra

HIPAA Security Rule Revamp? | McAfee & Taft - JDSupra

Passwords, Credential Stuffing & Brute Force Attacks

Enterprise passkey security under threat from malware | CSO Online

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Microsoft Removes Picture Password Setup in Windows 11, Pushing PINs, Passwords, and Biometrics - gHacks Tech News

Regulations, Fines and Legislation

How The UK’s Recent Cabinet Changes Could Impact Cybersecurity | SC Media UK

How to report an AI Act violation in the EU - Help Net Security

Outdated Cybercrime Laws Put Security Researchers at Risk

German cabinet approves new spying rules | Semafor

The UK needs better AI governance

HIPAA Security Rule Revamp? | McAfee & Taft - JDSupra

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

House-passed cyber bill for small businesses gets Senate companion | FedScoop

Social Media

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Software Supply Chain

How to combat the new threats in open-source libraries - SiliconANGLE

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Supply Chain and Third Parties

Beacon CRM confirms cyberattack exposed UK charity data | SC Media UK

UK charities count the cost of Beacon CRM cyberattack

Beacon security incident: Hackers steal details of hundreds of lawyers who used mental health charity LawCare | Law Gazette

Framework loses customer data in Metabase zero-day attack

Logistics Giant Ceva Suffers Data Breach Impacting European Clients - Infosecurity Magazine

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack - SecurityWeek


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Inside the BBC’s emergency plans for a Putin cyber attack

The Iran War Hits Home - FPIF

German intelligence services may be allowed to launch pre-emptive cyberattacks against Russia | European Pravda

Nation State Actors

Experts weigh in: Why is state involvement in cyberattacks so difficult to prove? - RTL Today

China

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

Russia

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Inside the BBC’s emergency plans for a Putin cyber attack

German intelligence services may be allowed to launch pre-emptive cyberattacks against Russia | European Pravda

Russian military hackers pose as recruiters to target Ukrainian IT workers | The Record from Recorded Future News

New Zealand sanctions Russian hackers, propaganda groups over Ukraine war | The Record from Recorded Future News

North Korea

Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks | TechRadar

North Korean spies are running local LLMs to cause AI mischief

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security

North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch

Researchers Create Fake Startup to Dupe North Koreans Looking for Remote Gigs

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Iran

The Iran War Hits Home - FPIF

Attacks on America’s ‘super vulnerable’ water systems should be a wake up call after years of warnings, cybersecurity experts say | The Independent

Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks


Tools and Controls

Why recovery readiness has become the new standard for cyber resilience | ZDNET

New N-able Zero Day Puts MSPs on Defensive - InfoRiskToday

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

The AI Governance Gap Is a Leadership Problem: Waiting Won't Close It - SecurityWeek

AI is changing cyber threats. Recovery is becoming just as important as prevention | YourStory

More than half of AI-generated patches are broken | CyberScoop

Cyber resilience takes center stage as AI reshapes the CISO role - SiliconANGLE

OpenAI Pauses Some Work on New Astra Model on Cyber Concerns

OpenAI launches GPT-5.6-Cyber and expands Daybreak with Red and Blue access tiers - Neowin

Meta Confirms One of Its AI Models Breached a Company During a Misconfigured Cyber Test - gHacks Tech News

Defenders Need to Think in Chains, Not Checklists

Enterprise Defenses Recovered at the Edge and Collapsed Inside

338 million attack simulations reveal the state of enterprise defense - Help Net Security

Meta AI model hacked a company during misconfigured cyber test

AI sandbox escape uncovered in Microsoft Copilot flaw - SiliconANGLE

Researcher Claims Control of ChatGPT Secure Sandbox

CISO principles for navigating cybersecurity incident disclosure

71% of CISOs spend 10+ hours on board reports - Help Net Security

Three in four AI-generated vulnerability patches leave something broken - Help Net Security

AI struggles to patch vulns without adult supervision

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

MSP, MSSP, MDR or MXDR: What are you really buying? | perspective | MSSP Alert

PYMNTS | Cybersecurity M&A Spree Maps the Next Attack Surface

The UK needs better AI governance

The inconvenient truth about AI pentesting: someone has to check all the work



Vulnerability Management

Cybersecurity needs a new operating model | CSO Online

More than half of AI-generated patches are broken | CyberScoop

Defenders Need to Think in Chains, Not Checklists

Three in four AI-generated vulnerability patches leave something broken - Help Net Security

AI struggles to patch vulns without adult supervision

Op-Ed: Are ‘Common Vulnerabilities and Exposures’ the reality of chronic cyber insecurity? - Digital Journal

NIST wants to overhaul its vulnerability database for the AI age | CyberScoop

CISA cautions against rigid rules for future of cyber vulnerability program - Nextgov/FCW

Why patching networks against cyberattacks is 'very scary' in the age of AI - Breaking Defense

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix - Help Net Security

NATO and an AI startup can now name and track software vulnerabilities | CyberScoop

Vulnerabilities

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

New Pass-ta-key attack reveals all the things we didn't know about passkeys - Ars Technica

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day - Infosecurity Magazine

Microsoft patches LegacyHive Windows zero-day vulnerability

Nightmare Eclipse Drops Windows Zero-Day Exploit 'ShieldBreak' - SecurityWeek

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) - Help Net Security

ClamAV 1.5.4 Open-Source Antivirus Fixes Eight Security Vulnerabilities

New N-able Zero Day Puts MSPs on Defensive - InfoRiskToday

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

vCenter Flaw Exploited Just Five Days After Disclosure - Infosecurity Magazine

Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Zoom flaw allowed attackers to take control of your iOS and Android devices - PhoneArena

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws - SecurityWeek

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP | ZDNET

Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform - SecurityWeek

Hackers breach TrueConf to trojanize client installers with backdoors

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Ivanti EPM Update Patches Remotely Exploitable Flaws - SecurityWeek

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data - SecurityWeek

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust - Infosecurity Magazine

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager - SecurityWeek

HP thin client disk encryption bypassed | Cybernews

Multiple Flaws in Enterprise Java Platforms Allow Attackers to Execute Remote Code

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Swiss government SharePoint breach compromised 200 accounts

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers - Help Net Security

WordPress 7.0.4 Patches Remote Code Execution Vulnerability - SecurityWeek

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People - SecurityWeek


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 07 August 2026