Black Arrow Cyber Threat Intelligence Briefing 18 September 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
We often highlight the importance of both cyber security and cyber resilience, to not only help reduce the likelihood of a cyber incident but also enable the organisation to survive when one occurs. We include both this week, starting with a focus for business leaders on the gap between how quickly organisations expect to recover and what may actually be achievable. Research highlights weaknesses in recovery planning, backup validation and testing, while separate findings reinforce the need for directors to understand their organisation’s cyber risks and resilience arrangements.
On cyber security, we look at evolving phishing attacks designed to compromise Microsoft 365 accounts and the importance of an organisation’s culture in enabling employees to report mistakes or suspicious activity quickly. We also highlight the need for business leaders to manage the continuing growth of AI-related risk as organisations give AI tools and agents greater access to data, systems and business processes.
For business leaders, the consistent message is that security and resilience require strategic management across people, operations and technology. Contact us to discuss how proportionate cyber security and resilience can support your organisation in achieving its priorities.
Top Cyber Stories of the Last Week
Recovery Readiness a Missing Link in Cyber Resilience, Finds Report
New research highlights a gap between cyberattack prevention and the ability to recover when disruption occurs. While 62% of organisations have isolated backups, only 36% can validate the integrity of that data when needed, and just 51% have a clean recovery environment ready. Fewer than half have tested or rehearsed their recovery plans in the past year. The findings suggest that prolonged outages remain a significant business risk, with effective cyber resilience depending not only on preventing attacks, but on knowing what data can be restored, where it will be recovered and how quickly operations can resume.
Most Firms Unable to Recover Quickly from Ransomware
Many organisations may be significantly overestimating how quickly they could recover from ransomware. Fenix24 found that just four of more than 800 organisations it assessed came close to their stated 24 to 48-hour recovery targets, and only for partial operations, while full recovery typically took weeks. Over 99% lacked a documented plan for restoring trusted login and authentication systems after an attack, while even where backups survived, 38% still failed to support recovery. Recommendations for business leaders include mapping dependencies for the most revenue-critical services and testing the full restore process against recovery targets.
https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/
Passkey-Themed Phishing Attacks Lead to Microsoft 365 Data Theft
Microsoft has warned that extortion groups are using convincing passkey, MFA and single sign-on themed phishing attacks to compromise corporate Microsoft accounts. Attackers impersonate IT support, often contacting employees by phone or text before directing them to fake or manipulated authentication processes. Once access is gained, they can explore Microsoft 365 environments, steal emails and files from SharePoint and OneDrive, and add their own authentication methods to maintain access. Business safeguards recommended by Microsoft include phishing-resistant MFA, restricting sensitive cloud resources to managed devices, and disabling device-code authentication where it is unnecessary.
New Warnings for Directors as Cyber Security Complexity Increases
UK directors are being warned to take a closer look at cyber security as threats become more complex and many businesses remain underprepared. The UK Government’s Cyber Security Breaches Survey 2025/26 found that 43% of participating UK businesses identified a breach or attack in the previous year, while only 41% of small businesses had carried out a cyber security risk assessment and 44% had a business continuity plan covering cyber risk. Directors should understand their organisation’s vulnerabilities, the protections in place and the extent of insurance cover, rather than assume these issues are being adequately managed elsewhere.
https://www.emergingrisks.co.uk/new-warnings-for-directors-as-cyber-security-complexity-increases/
More than a Third of Small UK Firms Impacted by Hacks – Report
Nearly two in five small UK businesses (38%) suffered a successful cyberattack in the past year, compared with 29% globally. Hiscox found each UK incident cost the small business an average of £26,650, and cyber incidents worldwide caused around 32 hours of disruption. The wider impact of cyber incidents can be significant, with 32% of companies worldwide reporting delayed growth plans, 30% financial damage and 29% lost business opportunities. For business leaders, the findings support treating cyber risk as a recurring business cost, including resilience measures.
https://www.standard.co.uk/news/tech/hiscox-b1296997.html
Could Blame Culture Be Cyber Security’s Next Achilles Heel?
A blame culture around cyber security incidents can make organisations less resilient by discouraging employees from reporting mistakes or suspicious activity quickly. IBM attributed 95% of data breaches to human error, while separate research found that 74% of CISOs regarded human error as their leading cyber security risk. With only 43% of employees working exclusively from an office, businesses need simple reporting processes that work across locations and devices. Treating incidents as opportunities to improve controls, processes and training can help reduce delays, contain threats faster and identify weaknesses before they cause greater harm.
https://www.itsecurityguru.org/2026/09/16/could-blame-culture-be-cybersecuritys-next-achilles-heel/
AI Governance Needs to Become Part of the CISO’s GRC Program
As AI tools gain access to corporate data and applications, and greater ability to act independently, they create additional cyber security risks. Traditional governance programmes may not adequately address these changes. Before deployment, organisations should understand the information and systems an AI tool can reach, the actions it is permitted to perform, and the potential impact of error or compromise. Policies alone are not enough; AI governance should ensure security risks are assessed before deployment and reassessed as systems, permissions or data-processing practices change.
https://www.scworld.com/perspective/ai-governance-needs-to-become-part-of-the-cisos-grc-program
CISOs Race to Control AI Agents Without Destroying Their Value
AI agents are rapidly creating a new cyber security risk as organisations give software increasing access to sensitive systems, data and business processes. Team8 found 71% of CISOs are already experimenting with AI agent capabilities, while 78% cited AI and agent security as their biggest concern. The danger is that an over-privileged agent can act at speed and scale, following poorly defined instructions in ways that expose data, alter systems or trigger damaging actions before anyone intervenes. Organisations now need effective controls around what agents can access and do without undermining their business value.
https://www.securityweek.com/cisos-race-to-control-ai-agents-without-destroying-their-value/
Your Employees Are Already Using AI Tools You Never Approved
AI adoption is moving faster than many organisations can govern it safely. OneTrust found that 74% of organisations have already adopted AI across teams or business processes, while 87% encourage the use of AI agents. However, nearly half reported an incident in the past year where AI systems or agents took unapproved actions, and 33% said employees had used unapproved AI tools because approved options were not available quickly enough. Only 5% said coordination and accountability were defined across the AI lifecycle, while data loss, corruption or misclassification and unvetted automation were identified as leading concerns. For business leaders, the findings highlight the need to provide approved AI options quickly enough to meet business needs and establish clear ownership and accountability for AI governance.
https://www.helpnetsecurity.com/2026/09/15/onetrust-enterprise-ai-governance-trends-report/
Anthropic CEO: Time to Shift from Improving to Controlling AI
Anthropic CEO Dario Amodei has warned that AI capabilities are advancing faster than organisations’ ability to understand and control them, increasing the risk from autonomous AI agents. The concern for businesses is immediate: an agent with excessive access could move across systems, expose sensitive data or cause damage at machine speed before a human intervenes. Experts argue that AI agents should be treated as potentially untrusted users, with tightly restricted access, temporary credentials and detailed monitoring. As autonomy grows, organisations that fail to impose clear limits could quickly lose visibility and control over what their AI systems are doing.
https://www.darkreading.com/cyber-risk/anthropic-ceo-shift-from-improving-to-controlling-ai
NATO Prevented Russia from Cutting a Critical Undersea Cable Using a Tool That Leaves No ‘Traceable Fingerprints’ on Fibre-Optic Wires
NATO allies disrupted a Russian military exercise near Svalbard involving technology reportedly designed to damage critical undersea communications cables while leaving little evidence of how the attack was carried out. The operation involved Russia's specialist deep-sea unit and was stopped before any cables were damaged. The targeted area includes two 1,400km fibre-optic cables connecting Svalbard with mainland Norway. With undersea cables carrying vast amounts of international communications and data traffic, the incident highlights both their strategic importance and the difficulty of attributing deliberate damage when little physical evidence is left behind.
Governance, Risk and Compliance
New warnings for directors as cyber security complexity increases
Recovery readiness a missing link in cyber resilience, finds report
More than a third of small UK firms impacted by hacks – report | The Standard
Cyber attacks costing SMEs full working week in operational disruption
Only 8% of Organizations Make Cybersecurity a Permanent Priority After a Breach, ManageEngine Finds
Business Security Is a Myth. Only the Paranoid Survive.
Could blame culture be cybersecurity’s next Achilles heel? - IT Security Guru
Why compliance does not guarantee cyber resilience - Design Solutions
When is a business really recovered from a cyberattack?
UK FCA Findings On Firms' Resilience To Systemic Risk | A&O Shearman - JDSupra
DNSFilter Exposes AI Gap Between the Security Operations Center (SOC) and the Boardroom
Protection against digital threats is now a necessity for businesses, not an option | Pressat
MSPs say nearly half their customers rely on them for CISO services - Help Net Security
Threats
Ransomware, Extortion and Destructive Attacks
Most Firms Unable to Recover Quickly from Ransomware - Infosecurity Magazine
New Android malware encrypts files, steals data, and harasses victims
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
Conti ransomware crew member sentenced to four years in prison | CyberScoop
Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler
Inside the Scattered Spider Playbook: How UK Retailers Got Social Engineered - Infosecurity Magazine
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Expanding Threat of Ransomware | Edexec
Ransomware and Destructive Attack Victims
ShinyHunters expose 6.4M in attack on medical supplier McKesson
A CISO's Lessons in Ransomware Response and Recovery - Infosecurity Magazine
Phishing & Email Based Attacks
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Why AI Is So Good at Scamming Humans
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign - Infosecurity Magazine
Revolut handed nearly 700 customers’ data to scammers
Business Email Compromise and AI: The Rise of Personalized Cyberattacks
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Business Email Compromise (BEC)/Email Account Compromise (EAC)
Business Email Compromise and AI: The Rise of Personalized Cyberattacks
Other Social Engineering
What we know about the Revolut data breach so far - Help Net Security
Attackers call employees' personal phones to break into Microsoft 365 accounts - Help Net Security
Fake CAPTCHAs are tricking people into hacking their own computers, and it's working | TechSpot
Most Fraudulent Hires Receive Credentials Before Detection - Infosecurity Magazine
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
HBO Max Reddit account compromised to serve ClickFix attacks
Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit | Group-IB Blog
Children reporting naked image sextortion scams 'more than double' | News Tech | Metro News
Artificial Intelligence
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals - SecurityWeek
Business Email Compromise and AI: The Rise of Personalized Cyberattacks
More Capable AI, Not Enough Guardrails - Security Affairs
AI governance needs to become part of the CISO’s GRC program | perspective | SC Media
CISOs Race to Control AI Agents Without Destroying Their Value - SecurityWeek
AI Cyberattacks Find the Cracks in Enterprise Security
How AI is redefining corporate cyber-readiness | Sifted
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Why AI Is So Good at Scamming Humans
A New Claude 's Sandbox Failure Shows How AI Can Rationalize Real-World Harm
Snickers AI candy bar exposes prompt injection risk | Cybernews
OpenAI Considers Slowing Advanced AI Development, Sam Altman Tells Employees - Bloomberg
GDPR wasn't designed for AI and that's a security problem | Computer Weekly
Security through obscurity is dead, and AI delivered the fatal blow
Most Organizations Skip Permissions Reviews Before Deploying AI Tools - Infosecurity Magazine
Your employees are already using AI tools you never approved - Help Net Security
OpenAI sets plan to disclose safety incidents and reveals more issues - BBC News
The hardest AI security problems now live in what an agent is permitted to do
Business Security Is a Myth. Only the Paranoid Survive.
AI's Threat To Cybersecurity Is Significant, Expert Says
AI-powered threat actor UAT-10147 targets web servers for fraud and data theft | brief | MSSP Alert
Palantir, Nvidia, Booz Allen restrict Anthropic and OpenAI models
The latest AI doomsayer is China’s intelligence boss
OpenAI's Altman Won't Do IPO This Year, Calls AI Extinction Risk 'Unacceptable' | NTD
BragJack Attack Can Turn a Browser's Agentic AI Against It
Threat actors are coming for your AI assets to operationalize their use of AI | CSO Online
Why we have to start thinking ahead to combat rogue AI
NCSC advises employees to think carefully about the AI tools they use | UKAuthority
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says - SecurityWeek
Hackers Used Claude to Hunt for Secrets in 1.8 Million Android Apps
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Trump And Vance Suggest AI Slowdown Conspiracy: Feels Like A ‘Trojan Horse’
OpenAI's malicious bot swarm attacked RubyGems
AI is breaking down the wall between cyber and physical security | CSO Online
Spain gets its first taste of AI-aided cyber attack
Divisions emerge in the tech industry over calls for a coordinated AI slowdown | The Independent
Careers, Roles, Skills, Working in Cyber and Information Security
Cybersecurity talent shortage requires new approach beyond recruitment | brief | MSSP Alert
Finding Hope During Tough Tech Times
Cloud/SaaS
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign - Infosecurity Magazine
AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran - WSJ
Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Cyber Crime, Organised Crime & Criminal Actors
Five alleged leaders of Black Axe’s operations in South Africa extradited to US | CyberScoop
Low-quality casino sites conceal highly dangerous threat actors
Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler
Data Breaches/Leaks
Revolut handed nearly 700 customers’ data to scammers
Cyberattacks on Law Firms Nearly Double as Stolen Documents Hit the Dark Web - Decrypt
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Spain gets its first taste of AI-aided cyber attack
Twitch data leak claim: 40,000 streamers allegedly exposed | Cybernews
IDScan confirms breach after 153 million driver’s licenses leak on dark web - Help Net Security
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Surfshark VPN says hackers breached internal testing, proxy servers
280,000 Impacted by Premier Medical Group Data Breach - SecurityWeek
Data/Digital Sovereignty
AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran - WSJ
Encryption
Why post-quantum cryptography is a national security priority | CSO Online
German police read WhatsApp, Signal messages without breaking encryption | Cybernews
New hardware device can RAM into encrypted memory, expose your data
Fraud, Scams and Financial Crime
Revolut handed nearly 700 customers’ data to scammers
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Why AI Is So Good at Scamming Humans
Five alleged leaders of Black Axe’s operations in South Africa extradited to US | CyberScoop
Identity and Access Management
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
4 Ways Organisations Create Non-Human Insider Risk - IT Security Guru
Insider Risk and Insider Threats
Most Fraudulent Hires Receive Credentials Before Detection - Infosecurity Magazine
4 Ways Organisations Create Non-Human Insider Risk - IT Security Guru
CISA Updates Insider Threat Guide With New Mitigation Advice - Infosecurity Magazine
How to respond when you suspect internal data theft | theHRD
Internet of Things – IoT
LG Denies Its TVs Are Spying on You (Unless You Opted In)
5 ways to stop smart TV snooping by LG and others | PCWorld
The internet of (compromised) things: securing IoT when you can’t trust (any) “thing” - Nextgov/FCW
Zero-Day Flaw in TP-Link Cameras Enables Covert Eavesdropping - Infosecurity Magazine
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
Law Enforcement Action and Take Downs
Five alleged leaders of Black Axe’s operations in South Africa extradited to US | CyberScoop
German police read WhatsApp, Signal messages without breaking encryption | Cybernews
Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler
Conti ransomware crew member sentenced to four years in prison | CyberScoop
Linux and Open Source
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages - Help Net Security
Malvertising
Snickers AI candy bar exposes prompt injection risk | Cybernews
Malware
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Low-quality casino sites conceal highly dangerous threat actors
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Malware bypasses browser checks to force install Chrome, Edge extensions
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Mobile
Hackers Used Claude to Hunt for Secrets in 1.8 Million Android Apps
New Android malware encrypts files, steals data, and harasses victims
Models, Frameworks and Standards
The Cyber Security And Resilience Bill: What’s New For UK Firms | SC Media UK
GDPR wasn't designed for AI and that's a security problem | Computer Weekly
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Re - Infosecurity Magazine
The British government rejects the “emergency kill switch” proposal to control rogue AI
Outages
CISA Calls for More Guidance, Less Spin, as Outages Escalate
Passwords, Credential Stuffing & Brute Force Attacks
UK.gov begins killing off passwords for 23 million users
Email users of broadband ISP BT suffer barrage of password reset messages UPDATE - ISPreview UK
Privacy, Surveillance
LG Denies Its TVs Are Spying on You (Unless You Opted In)
5 ways to stop smart TV snooping by LG and others | PCWorld
LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions - Ars Technica
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
Flock Wants a Closely Surveilled World with No Exit | The New Yorker
Regulations, Fines and Legislation
The Cyber Security And Resilience Bill: What’s New For UK Firms | SC Media UK
Cybercrime laws do make banks safer - LSE Business Review
GDPR wasn't designed for AI and that's a security problem | Computer Weekly
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Re - Infosecurity Magazine
The British government rejects the “emergency kill switch” proposal to control rogue AI
The White House has an AI oversight plan. But who will do the overseeing? - Atlantic Council
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal | CyberScoop
Trump calls Nvidia's Jensen Huang onstage, dismisses AI safety as a hoax
Shadow IT
Your employees are already using AI tools you never approved - Help Net Security
NCSC advises employees to think carefully about the AI tools they use | UKAuthority
Social Media
LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions - Ars Technica
HBO Max Reddit account compromised to serve ClickFix attacks
Software Supply Chain
Perfect-10 GitLab bug under attack days after patch lands
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Re - Infosecurity Magazine
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
EXCLUSIVE: NATO allies foil Russian subsea cable sabotage plot | Reuters
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
EU Parliament names Iran among states behind hybrid attacks on Europe | Iran International
Nation State Actors
U.S. Tracks Cyber Threats Against Nearly 20 Ships Worldwide
China
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
Can US-China Rules Prevent Military AI From Triggering a Crisis? - Modern Diplomacy
If AI really could kill us all, why give any ground to China? | CNN Business
Russia
EXCLUSIVE: NATO allies foil Russian subsea cable sabotage plot | Reuters
'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Iran
EU Parliament names Iran among states behind hybrid attacks on Europe | Iran International
AWS Says It Can’t Restore Some Data From Mideast Facilities Struck by Iran - WSJ
Tools and Controls
AI governance needs to become part of the CISO’s GRC program | perspective | SC Media
CISOs Race to Control AI Agents Without Destroying Their Value - SecurityWeek
Recovery readiness a missing link in cyber resilience, finds report
Only 8% of Organizations Make Cybersecurity a Permanent Priority After a Breach, ManageEngine Finds
AI Changed the Exposure Problem. Validation Needs to Change With It.
Most Organizations Skip Permissions Reviews Before Deploying AI Tools - Infosecurity Magazine
When is a business really recovered from a cyberattack?
AI Changed Cybersecurity Economics: CEOs Need To Change The Equation
The internet of (compromised) things: securing IoT when you can’t trust (any) “thing” - Nextgov/FCW
Security through obscurity is dead, and AI delivered the fatal blow
How Frontier AI is compressing cybersecurity response times | McKinsey
DNSFilter Exposes AI Gap Between the Security Operations Center (SOC) and the Boardroom
AI Security Spending Jumps as Fear Outpaces Proof of Value
This Dying Programming Language Powers Global Infrastructure — And It's A Problem
What Zero-Day Response Should Be in the Post-Mythos Era
Mythos has made 2026 patching hell. It might make 2027 a breeze
Using Cyber Decoys to Strengthen Detection and Response | CISA
Major Cyber Threat Detection Vendors Turn to New UK Testing Program - Infosecurity Magazine
CISA Calls for More Guidance, Less Spin, as Outages Escalate
Why post-quantum cryptography is a national security priority | CSO Online
Surfshark VPN says hackers breached internal testing, proxy servers
Technology in financial services: where’s the return? - Tech Monitor
Why Patch Automation Needs Brakes, Not Just an Accelerator
Cybersecurity's Tip Of The Spear: 8 Capabilities You Can't Assume Work
Two-thirds of cyber threats still require manual resolution | IT Pro
“We Think the Security Control Is Working” Is No Longer Good Enough - SecurityWeek
A CISO's Lessons in Ransomware Response and Recovery - Infosecurity Magazine
Your passkeys can now move between password managers on Android - Help Net Security
Other News
Cyberattacks on Law Firms Nearly Double as Stolen Documents Hit the Dark Web - Decrypt
More than a third of small UK firms impacted by hacks – report | The Standard
UK FCA Findings On Firms' Resilience To Systemic Risk | A&O Shearman - JDSupra
Major Cyber Threat Detection Vendors Turn to New UK Testing Program - Infosecurity Magazine
Cybersecurity's Tip Of The Spear: 8 Capabilities You Can't Assume Work
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal | CyberScoop
Estate agents under attack as cyber incidents jump 17% - Property Industry Eye
Hacking Unitree G1 humanoid robots: two RCEs to root shell via Wi-Fi and Bluetooth.
Vulnerability Management
AI Changed the Exposure Problem. Validation Needs to Change With It.
AI Changed Cybersecurity Economics: CEOs Need To Change The Equation
Security through obscurity is dead, and AI delivered the fatal blow
How Frontier AI is compressing cybersecurity response times | McKinsey
What Zero-Day Response Should Be in the Post-Mythos Era
CISA decides weekly vulnerability bulletin isn't necessary anymore
Why Patch Automation Needs Brakes, Not Just an Accelerator
Mythos has made 2026 patching hell. It might make 2027 a breeze
Vulnerabilities
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
'Sandworm' Chains Cisco Flaws to Deploy Cyclops Blink
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks - SecurityWeek
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
Artifactory flaws chained in attacks deploying backdoor malware
GitLab Vulnerability Exploited One Day After Disclosure - SecurityWeek
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
New ShieldCrash zero-day exploit bypasses Microsoft Defender security updates | brief | MSSP Alert
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Oracle Patches 800+ Vulnerabilities in September 2026 Security Update - SecurityWeek
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard - SecurityWeek
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities - SecurityWeek
Thai Broadband Provider Hacked via Fortinet Vulnerability - SecurityWeek
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Acronis warns of actively exploited flaw in its cPanel backup plugin
Google fixes actively exploited Android zero-day on Pixel devices
Hackers target WordPress sites via third-party WooCommerce plugin
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE - Infosecurity Magazine
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution - SecurityWeek
Chrome, Firefox Updates Patch 115 Vulnerabilities - SecurityWeek
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases - SecurityWeek
Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover - SecurityWeek
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages - Help Net Security
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) - Help Net Security
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps
TP-Link Tapo C200 flaws could let hackers spy through cameras | Cybernews
Hacking Unitree G1 humanoid robots: two RCEs to root shell via Wi-Fi and Bluetooth.
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.