Black Arrow Cyber Threat Intelligence Briefing 18 September 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We often highlight the importance of both cyber security and cyber resilience, to not only help reduce the likelihood of a cyber incident but also enable the organisation to survive when one occurs. We include both this week, starting with a focus for business leaders on the gap between how quickly organisations expect to recover and what may actually be achievable. Research highlights weaknesses in recovery planning, backup validation and testing, while separate findings reinforce the need for directors to understand their organisation’s cyber risks and resilience arrangements.

On cyber security, we look at evolving phishing attacks designed to compromise Microsoft 365 accounts and the importance of an organisation’s culture in enabling employees to report mistakes or suspicious activity quickly. We also highlight the need for business leaders to manage the continuing growth of AI-related risk as organisations give AI tools and agents greater access to data, systems and business processes.

For business leaders, the consistent message is that security and resilience require strategic management across people, operations and technology. Contact us to discuss how proportionate cyber security and resilience can support your organisation in achieving its priorities.


Top Cyber Stories of the Last Week

Recovery Readiness a Missing Link in Cyber Resilience, Finds Report

New research highlights a gap between cyberattack prevention and the ability to recover when disruption occurs. While 62% of organisations have isolated backups, only 36% can validate the integrity of that data when needed, and just 51% have a clean recovery environment ready. Fewer than half have tested or rehearsed their recovery plans in the past year. The findings suggest that prolonged outages remain a significant business risk, with effective cyber resilience depending not only on preventing attacks, but on knowing what data can be restored, where it will be recovered and how quickly operations can resume.

https://www.siliconrepublic.com/enterprise/recovery-readiness-is-the-missing-link-in-cyber-resilience-finds-report

Most Firms Unable to Recover Quickly from Ransomware

Many organisations may be significantly overestimating how quickly they could recover from ransomware. Fenix24 found that just four of more than 800 organisations it assessed came close to their stated 24 to 48-hour recovery targets, and only for partial operations, while full recovery typically took weeks. Over 99% lacked a documented plan for restoring trusted login and authentication systems after an attack, while even where backups survived, 38% still failed to support recovery. Recommendations for business leaders include mapping dependencies for the most revenue-critical services and testing the full restore process against recovery targets.

https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/

Passkey-Themed Phishing Attacks Lead to Microsoft 365 Data Theft

Microsoft has warned that extortion groups are using convincing passkey, MFA and single sign-on themed phishing attacks to compromise corporate Microsoft accounts. Attackers impersonate IT support, often contacting employees by phone or text before directing them to fake or manipulated authentication processes. Once access is gained, they can explore Microsoft 365 environments, steal emails and files from SharePoint and OneDrive, and add their own authentication methods to maintain access. Business safeguards recommended by Microsoft include phishing-resistant MFA, restricting sensitive cloud resources to managed devices, and disabling device-code authentication where it is unnecessary.

https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/

New Warnings for Directors as Cyber Security Complexity Increases

UK directors are being warned to take a closer look at cyber security as threats become more complex and many businesses remain underprepared. The UK Government’s Cyber Security Breaches Survey 2025/26 found that 43% of participating UK businesses identified a breach or attack in the previous year, while only 41% of small businesses had carried out a cyber security risk assessment and 44% had a business continuity plan covering cyber risk. Directors should understand their organisation’s vulnerabilities, the protections in place and the extent of insurance cover, rather than assume these issues are being adequately managed elsewhere.

https://www.emergingrisks.co.uk/new-warnings-for-directors-as-cyber-security-complexity-increases/

More than a Third of Small UK Firms Impacted by Hacks – Report

Nearly two in five small UK businesses (38%) suffered a successful cyberattack in the past year, compared with 29% globally. Hiscox found each UK incident cost the small business an average of £26,650, and cyber incidents worldwide caused around 32 hours of disruption. The wider impact of cyber incidents can be significant, with 32% of companies worldwide reporting delayed growth plans, 30% financial damage and 29% lost business opportunities. For business leaders, the findings support treating cyber risk as a recurring business cost, including resilience measures.

https://www.standard.co.uk/news/tech/hiscox-b1296997.html

Could Blame Culture Be Cyber Security’s Next Achilles Heel?

A blame culture around cyber security incidents can make organisations less resilient by discouraging employees from reporting mistakes or suspicious activity quickly. IBM attributed 95% of data breaches to human error, while separate research found that 74% of CISOs regarded human error as their leading cyber security risk. With only 43% of employees working exclusively from an office, businesses need simple reporting processes that work across locations and devices. Treating incidents as opportunities to improve controls, processes and training can help reduce delays, contain threats faster and identify weaknesses before they cause greater harm.

https://www.itsecurityguru.org/2026/09/16/could-blame-culture-be-cybersecuritys-next-achilles-heel/

AI Governance Needs to Become Part of the CISO’s GRC Program

As AI tools gain access to corporate data and applications, and greater ability to act independently, they create additional cyber security risks. Traditional governance programmes may not adequately address these changes. Before deployment, organisations should understand the information and systems an AI tool can reach, the actions it is permitted to perform, and the potential impact of error or compromise. Policies alone are not enough; AI governance should ensure security risks are assessed before deployment and reassessed as systems, permissions or data-processing practices change.

https://www.scworld.com/perspective/ai-governance-needs-to-become-part-of-the-cisos-grc-program

CISOs Race to Control AI Agents Without Destroying Their Value

AI agents are rapidly creating a new cyber security risk as organisations give software increasing access to sensitive systems, data and business processes. Team8 found 71% of CISOs are already experimenting with AI agent capabilities, while 78% cited AI and agent security as their biggest concern. The danger is that an over-privileged agent can act at speed and scale, following poorly defined instructions in ways that expose data, alter systems or trigger damaging actions before anyone intervenes. Organisations now need effective controls around what agents can access and do without undermining their business value.

https://www.securityweek.com/cisos-race-to-control-ai-agents-without-destroying-their-value/

Your Employees Are Already Using AI Tools You Never Approved

AI adoption is moving faster than many organisations can govern it safely. OneTrust found that 74% of organisations have already adopted AI across teams or business processes, while 87% encourage the use of AI agents. However, nearly half reported an incident in the past year where AI systems or agents took unapproved actions, and 33% said employees had used unapproved AI tools because approved options were not available quickly enough. Only 5% said coordination and accountability were defined across the AI lifecycle, while data loss, corruption or misclassification and unvetted automation were identified as leading concerns. For business leaders, the findings highlight the need to provide approved AI options quickly enough to meet business needs and establish clear ownership and accountability for AI governance.

https://www.helpnetsecurity.com/2026/09/15/onetrust-enterprise-ai-governance-trends-report/

Anthropic CEO: Time to Shift from Improving to Controlling AI

Anthropic CEO Dario Amodei has warned that AI capabilities are advancing faster than organisations’ ability to understand and control them, increasing the risk from autonomous AI agents. The concern for businesses is immediate: an agent with excessive access could move across systems, expose sensitive data or cause damage at machine speed before a human intervenes. Experts argue that AI agents should be treated as potentially untrusted users, with tightly restricted access, temporary credentials and detailed monitoring. As autonomy grows, organisations that fail to impose clear limits could quickly lose visibility and control over what their AI systems are doing.

https://www.darkreading.com/cyber-risk/anthropic-ceo-shift-from-improving-to-controlling-ai

NATO Prevented Russia from Cutting a Critical Undersea Cable Using a Tool That Leaves No ‘Traceable Fingerprints’ on Fibre-Optic Wires

NATO allies disrupted a Russian military exercise near Svalbard involving technology reportedly designed to damage critical undersea communications cables while leaving little evidence of how the attack was carried out. The operation involved Russia's specialist deep-sea unit and was stopped before any cables were damaged. The targeted area includes two 1,400km fibre-optic cables connecting Svalbard with mainland Norway. With undersea cables carrying vast amounts of international communications and data traffic, the incident highlights both their strategic importance and the difficulty of attributing deliberate damage when little physical evidence is left behind.

https://www.techradar.com/pro/nato-prevented-russia-from-cutting-a-critical-undersea-cable-using-a-tool-that-leaves-no-traceable-fingerprints-on-fibre-optic-wires-1-400km-long-lines-are-part-of-nasas-near-space-network



Threats

Ransomware, Extortion and Destructive Attacks

Most Firms Unable to Recover Quickly from Ransomware - Infosecurity Magazine

New Android malware encrypts files, steals data, and harasses victims

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Conti ransomware crew member sentenced to four years in prison | CyberScoop

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Inside the Scattered Spider Playbook: How UK Retailers Got Social Engineered - Infosecurity Magazine

Don’t pay the ransom: Warning to organisations to protect themselves from ransomware attacks as more than 320 businesses affected last year | Report Fraud | Official Press Release

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

The Expanding Threat of Ransomware | Edexec

Ransomware and Destructive Attack Victims

ShinyHunters expose 6.4M in attack on medical supplier McKesson

A CISO's Lessons in Ransomware Response and Recovery - Infosecurity Magazine

Phishing & Email Based Attacks

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack | TechRadar

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Why AI Is So Good at Scamming Humans

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign - Infosecurity Magazine

Revolut handed nearly 700 customers’ data to scammers

Business Email Compromise and AI: The Rise of Personalized Cyberattacks

Beware — these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware | TechRadar

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Business Email Compromise (BEC)/Email Account Compromise (EAC)

Business Email Compromise and AI: The Rise of Personalized Cyberattacks

Other Social Engineering

Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack | TechRadar

What we know about the Revolut data breach so far - Help Net Security

Attackers call employees' personal phones to break into Microsoft 365 accounts - Help Net Security

Fake CAPTCHAs are tricking people into hacking their own computers, and it's working | TechSpot

Most Fraudulent Hires Receive Credentials Before Detection - Infosecurity Magazine

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

HBO Max Reddit account compromised to serve ClickFix attacks

Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit | Group-IB Blog

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists | National Cyber Security Centre

Children reporting naked image sextortion scams 'more than double' | News Tech | Metro News

Artificial Intelligence

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals - SecurityWeek

Business Email Compromise and AI: The Rise of Personalized Cyberattacks

More Capable AI, Not Enough Guardrails - Security Affairs

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up - SecurityWeek

AI governance needs to become part of the CISO’s GRC program | perspective | SC Media

CISOs Race to Control AI Agents Without Destroying Their Value - SecurityWeek

AI Cyberattacks Find the Cracks in Enterprise Security

How AI is redefining corporate cyber-readiness | Sifted

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Why AI Is So Good at Scamming Humans

A New Claude 's Sandbox Failure Shows How AI Can Rationalize Real-World Harm

Snickers AI candy bar exposes prompt injection risk | Cybernews

OpenAI Considers Slowing Advanced AI Development, Sam Altman Tells Employees - Bloomberg

AI could kill all humans in next decade, warn experts: but how seriously should we take them? | AI (artificial intelligence) | The Guardian

GDPR wasn't designed for AI and that's a security problem | Computer Weekly

Security through obscurity is dead, and AI delivered the fatal blow

Most Organizations Skip Permissions Reviews Before Deploying AI Tools - Infosecurity Magazine

Your employees are already using AI tools you never approved - Help Net Security

OpenAI sets plan to disclose safety incidents and reveals more issues - BBC News

The hardest AI security problems now live in what an agent is permitted to do

Business Security Is a Myth. Only the Paranoid Survive.

AI's Threat To Cybersecurity Is Significant, Expert Says

AI-powered threat actor UAT-10147 targets web servers for fraud and data theft | brief | MSSP Alert

Palantir, Nvidia, Booz Allen restrict Anthropic and OpenAI models

The latest AI doomsayer is China’s intelligence boss

OpenAI's Altman Won't Do IPO This Year, Calls AI Extinction Risk 'Unacceptable' | NTD

BragJack Attack Can Turn a Browser's Agentic AI Against It

Threat actors are coming for your AI assets to operationalize their use of AI | CSO Online

Why we have to start thinking ahead to combat rogue AI

NCSC advises employees to think carefully about the AI tools they use | UKAuthority

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says - SecurityWeek

Hackers Used Claude to Hunt for Secrets in 1.8 Million Android Apps

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet - Security Affairs

Trump And Vance Suggest AI Slowdown Conspiracy: Feels Like A ‘Trojan Horse’

OpenAI's malicious bot swarm attacked RubyGems

AI is breaking down the wall between cyber and physical security | CSO Online

Spain gets its first taste of AI-aided cyber attack

Divisions emerge in the tech industry over calls for a coordinated AI slowdown | The Independent

Careers, Roles, Skills, Working in Cyber and Information Security

NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity - IT Security Guru

Cybersecurity talent shortage requires new approach beyond recruitment | brief | MSSP Alert

Finding Hope During Tough Tech Times

Cloud/SaaS

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign - Infosecurity Magazine

AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran - WSJ

Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

Cyber Crime, Organised Crime & Criminal Actors

Five alleged leaders of Black Axe’s operations in South Africa extradited to US | CyberScoop

Low-quality casino sites conceal highly dangerous threat actors

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Data Breaches/Leaks

Revolut handed nearly 700 customers’ data to scammers

Cyberattacks on Law Firms Nearly Double as Stolen Documents Hit the Dark Web - Decrypt

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Spain gets its first taste of AI-aided cyber attack

Twitch data leak claim: 40,000 streamers allegedly exposed | Cybernews

IDScan confirms breach after 153 million driver’s licenses leak on dark web - Help Net Security

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

Surfshark VPN says hackers breached internal testing, proxy servers

Non-Zero-Day VPN Flaw Left Japan 's Government Shared Network Platform Exposed: 246,000 Records at Risk

280,000 Impacted by Premier Medical Group Data Breach - SecurityWeek

Data/Digital Sovereignty

AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran - WSJ

Encryption

Why post-quantum cryptography is a national security priority | CSO Online

German police read WhatsApp, Signal messages without breaking encryption | Cybernews

New hardware device can RAM into encrypted memory, expose your data

Fraud, Scams and Financial Crime

Revolut handed nearly 700 customers’ data to scammers

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Why AI Is So Good at Scamming Humans

Five alleged leaders of Black Axe’s operations in South Africa extradited to US | CyberScoop

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

Identity and Access Management

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

4 Ways Organisations Create Non-Human Insider Risk - IT Security Guru

Insider Risk and Insider Threats

Most Fraudulent Hires Receive Credentials Before Detection - Infosecurity Magazine

4 Ways Organisations Create Non-Human Insider Risk - IT Security Guru

CISA Updates Insider Threat Guide With New Mitigation Advice - Infosecurity Magazine

How to respond when you suspect internal data theft | theHRD

Internet of Things – IoT

LG Denies Its TVs Are Spying on You (Unless You Opted In)

5 ways to stop smart TV snooping by LG and others | PCWorld

The internet of (compromised) things: securing IoT when you can’t trust (any) “thing” - Nextgov/FCW

Zero-Day Flaw in TP-Link Cameras Enables Covert Eavesdropping - Infosecurity Magazine

Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent

Law Enforcement Action and Take Downs

Five alleged leaders of Black Axe’s operations in South Africa extradited to US | CyberScoop

German police read WhatsApp, Signal messages without breaking encryption | Cybernews

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Conti ransomware crew member sentenced to four years in prison | CyberScoop

Linux and Open Source

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages - Help Net Security

Malvertising

Snickers AI candy bar exposes prompt injection risk | Cybernews

Malware

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Low-quality casino sites conceal highly dangerous threat actors

Beware — these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware | TechRadar

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Malware bypasses browser checks to force install Chrome, Edge extensions

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Mobile

Hackers Used Claude to Hunt for Secrets in 1.8 Million Android Apps

New Android malware encrypts files, steals data, and harasses victims

Models, Frameworks and Standards

The Cyber Security And Resilience Bill: What’s New For UK Firms | SC Media UK

GDPR wasn't designed for AI and that's a security problem | Computer Weekly

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Re - Infosecurity Magazine

The British government rejects the “emergency kill switch” proposal to control rogue AI

Outages

CISA Calls for More Guidance, Less Spin, as Outages Escalate

Passwords, Credential Stuffing & Brute Force Attacks

UK.gov begins killing off passwords for 23 million users

Email users of broadband ISP BT suffer barrage of password reset messages UPDATE - ISPreview UK

Privacy, Surveillance

LG Denies Its TVs Are Spying on You (Unless You Opted In)

5 ways to stop smart TV snooping by LG and others | PCWorld

LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions - Ars Technica

Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent

Cut the cameras: Flock surveillance cameras spur rare bipartisan backlash | Technology | The Guardian

Flock Wants a Closely Surveilled World with No Exit | The New Yorker

Regulations, Fines and Legislation

The Cyber Security And Resilience Bill: What’s New For UK Firms | SC Media UK

Cybercrime laws do make banks safer - LSE Business Review

GDPR wasn't designed for AI and that's a security problem | Computer Weekly

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Re - Infosecurity Magazine

The British government rejects the “emergency kill switch” proposal to control rogue AI

The White House has an AI oversight plan. But who will do the overseeing? - Atlantic Council

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal | CyberScoop

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors - Infosecurity Magazine

Trump calls Nvidia's Jensen Huang onstage, dismisses AI safety as a hoax

Trump unleashes on AI guardrails in all-caps rant: ‘A strong and smart (High IQ!) president’ is all it needs | The Independent

Shadow IT

Your employees are already using AI tools you never approved - Help Net Security

NCSC advises employees to think carefully about the AI tools they use | UKAuthority

Social Media

LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions - Ars Technica

HBO Max Reddit account compromised to serve ClickFix attacks

Software Supply Chain

Perfect-10 GitLab bug under attack days after patch lands

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Re - Infosecurity Magazine

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

EXCLUSIVE: NATO allies foil Russian subsea cable sabotage plot | Reuters

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

EU Parliament names Iran among states behind hybrid attacks on Europe | Iran International

Nation State Actors

In the United States, the military and the FBI boarded an oil tanker following suspicions of a foreign cyberattack | УНН

U.S. Tracks Cyber Threats Against Nearly 20 Ships Worldwide

China

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

Can US-China Rules Prevent Military AI From Triggering a Crisis? - Modern Diplomacy

If AI really could kill us all, why give any ground to China? | CNN Business

Russia

EXCLUSIVE: NATO allies foil Russian subsea cable sabotage plot | Reuters

'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Iran

EU Parliament names Iran among states behind hybrid attacks on Europe | Iran International

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists | National Cyber Security Centre

AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran - WSJ


Tools and Controls

AI governance needs to become part of the CISO’s GRC program | perspective | SC Media

CISOs Race to Control AI Agents Without Destroying Their Value - SecurityWeek

Recovery readiness a missing link in cyber resilience, finds report

Only 8% of Organizations Make Cybersecurity a Permanent Priority After a Breach, ManageEngine Finds

AI Changed the Exposure Problem. Validation Needs to Change With It.

Most Organizations Skip Permissions Reviews Before Deploying AI Tools - Infosecurity Magazine

When is a business really recovered from a cyberattack?

AI Changed Cybersecurity Economics: CEOs Need To Change The Equation

The internet of (compromised) things: securing IoT when you can’t trust (any) “thing” - Nextgov/FCW

Security through obscurity is dead, and AI delivered the fatal blow

How Frontier AI is compressing cybersecurity response times | McKinsey

DNSFilter Exposes AI Gap Between the Security Operations Center (SOC) and the Boardroom

AI Security Spending Jumps as Fear Outpaces Proof of Value

This Dying Programming Language Powers Global Infrastructure — And It's A Problem

What Zero-Day Response Should Be in the Post-Mythos Era

Mythos has made 2026 patching hell. It might make 2027 a breeze

Using Cyber Decoys to Strengthen Detection and Response | CISA

Major Cyber Threat Detection Vendors Turn to New UK Testing Program - Infosecurity Magazine

CISA Calls for More Guidance, Less Spin, as Outages Escalate

Why post-quantum cryptography is a national security priority | CSO Online

Surfshark VPN says hackers breached internal testing, proxy servers

Technology in financial services: where’s the return? - Tech Monitor

Why Patch Automation Needs Brakes, Not Just an Accelerator

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities - Help Net Security

Cybersecurity's Tip Of The Spear: 8 Capabilities You Can't Assume Work

Two-thirds of cyber threats still require manual resolution | IT Pro

“We Think the Security Control Is Working” Is No Longer Good Enough - SecurityWeek

A CISO's Lessons in Ransomware Response and Recovery - Infosecurity Magazine

Your passkeys can now move between password managers on Android - Help Net Security

When the Whole Company Adopts AI: What It Does to Your SOC

Prophet Security Research Finds AI Is Cutting SOC Investigation Times, But Nearly Half Of In-house Builds Fail To Stick

Why organizations are supporting more authentication technologies — and how to do it | Biometric Update



Vulnerability Management

AI Changed the Exposure Problem. Validation Needs to Change With It.

AI Changed Cybersecurity Economics: CEOs Need To Change The Equation

Security through obscurity is dead, and AI delivered the fatal blow

How Frontier AI is compressing cybersecurity response times | McKinsey

What Zero-Day Response Should Be in the Post-Mythos Era

CISA decides weekly vulnerability bulletin isn't necessary anymore

Why Patch Automation Needs Brakes, Not Just an Accelerator

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities - Help Net Security

Mythos has made 2026 patching hell. It might make 2027 a breeze

Vulnerabilities

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks - SecurityWeek

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Artifactory flaws chained in attacks deploying backdoor malware

GitLab Vulnerability Exploited One Day After Disclosure - SecurityWeek

Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

New ShieldCrash zero-day exploit bypasses Microsoft Defender security updates | brief | MSSP Alert

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update - SecurityWeek

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard - SecurityWeek

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities - SecurityWeek

Thai Broadband Provider Hacked via Fortinet Vulnerability - SecurityWeek

Non-Zero-Day VPN Flaw Left Japan 's Government Shared Network Platform Exposed: 246,000 Records at Risk

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Acronis warns of actively exploited flaw in its cPanel backup plugin

Google fixes actively exploited Android zero-day on Pixel devices

Hackers target WordPress sites via third-party WooCommerce plugin

Human Attacker Hits Machine-Speed Exploitation of Marimo RCE - Infosecurity Magazine

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution - SecurityWeek

Chrome, Firefox Updates Patch 115 Vulnerabilities - SecurityWeek

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases - SecurityWeek

Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover - SecurityWeek

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages - Help Net Security

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) - Help Net Security

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

TP-Link Tapo C200 flaws could let hackers spy through cameras | Cybernews

Hacking Unitree G1 humanoid robots: two RCEs to root shell via Wi-Fi and Bluetooth.


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3

Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 11 September 2026