Black Arrow Cyber Threat Intelligence Briefing 28 August 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
We start this week by looking at developing attacker techniques, including phishing attacks that can be steered in real time, malware designed to remain dormant until activated, and mobile malware capable of stealing login and authentication details that could provide access to business systems.
We also look at the growing risks associated with AI. Research highlights extensive use of personal and unapproved AI tools, while AI is also accelerating vulnerability discovery. Ransomware activity remains high, reinforcing the need for organisations to understand where they are exposed and prioritise the risks that matter most.
The wider message is that security, governance and resilience must develop alongside the threat. In the UK, Provision 29 of the UK Corporate Governance Code reinforces the need for reliable evidence that important controls are working, while effective incident response, secure backups and tested recovery arrangements can materially affect how quickly an organisation recovers.
We support organisations in various countries to address these risks and requirements. Contact us to discuss how we help leadership teams to strengthen proportionate cyber security, governance and resilience.
Top Cyber Stories of the Last Week
ZeroTokens Phishing Platform Steers Attacks in Real Time
A phishing campaign has used a platform called ZeroTokens to let criminals monitor victims and alter fraudulent login screens in real time. More than 45,000 messages were sent to over 24,000 recipients across 700 organisations, with 24,000 sent on a single day. The attacks targeted financial information, login details, card data and verification codes, while adapting prompts to retry failed verification steps. Researchers found the platform supported templates for 53 financial institutions and 36 card issuers, and assessed that information captured through the phishing interaction would most likely be used outside the platform for financial theft or payment redirection.
https://www.infosecurity-magazine.com/news/zerotokens-phishing-real-time/
ToxicPanda Banking Trojan Matures into Enterprise Threat
A new version of the ToxicPanda Android banking Trojan has expanded from targeting 16 financial institutions to 349 banking, digital wallet and cryptocurrency applications across 16 countries. Attackers are using legitimate cloud services to distribute the malware that can now issue 167 remote commands and gain deeper, persistent control of infected devices, including stealing screen-lock credentials. This creates wider business risk because employee smartphones often hold authentication credentials and provide access to corporate applications.
https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat
New Windows Malware Lays Dormant Until a Custom Command Activates It like a Sleeper Agent
Security researchers have identified SLEEPWALKER, an unusual form of Windows malware designed to remain dormant until it receives a specially crafted network signal. Unlike conventional malware, it contains no built-in malicious functions, helping it avoid detection while disguised as a legitimate security management component. Once activated, it can receive additional capabilities and execute instructions. No active campaigns or confirmed victims have been identified, but researchers believe its highly targeted design could indicate nation-state involvement rather than widespread criminal use.
What Your CISO Is Trying to Tell You, and Why It Matters More Than You Think
Effective cyber risk management requires security teams to communicate technical risks in terms that business leaders can understand and act on. Security teams can struggle to secure executive support when risks are presented through technical scores, acronyms and system details rather than potential business impact. With AI accelerating the pace at which threats evolve, that communication gap is becoming increasingly important. Cyber security risks are more likely to prompt timely decisions when leaders understand which business services are affected, the consequences of delaying action, the cost or disruption involved, who owns the response and what risk will remain afterwards.
Why Provision 29 Is Raising the Bar for Board Accountability
The revised UK Corporate Governance Code is increasing expectations on boards to demonstrate that important internal controls are working effectively, rather than relying on periodic compliance checks. From 2026, Provision 29 requires boards to assess and report on material controls using reliable evidence. For cyber security, this strengthens the case for more continuous monitoring, as annual assessments can quickly become outdated across cloud services, conventional IT infrastructure and third-party suppliers. More timely information can help boards understand changing risks and provide greater confidence when making formal declarations about control effectiveness.
Worrying Cyber Security Gaps Expose UK Charities
Research into 380 of the UK’s largest and best-known charities found widespread cyber security weaknesses, with exposed staff or supplier passwords affecting 44% of well-known charities and 55% of the largest by income. Around one in three could also have emails forged in their name, increasing the risk of fraudulent appeals or payment requests. Larger charities were not necessarily better protected, with better-funded organisations more likely to have exposed credentials and internal login pages. Nine in 10 also lacked a published process for reporting security weaknesses, although none appeared on ransomware leak sites.
https://tfn.scot/news/worrying-cybersecurity-gaps-expose-uk-charities
How Shadow IT Threatens Your Cyber Security and Digital Sovereignty
The rapid adoption of unapproved apps, cloud services and AI tools is creating a growing cyber security and governance risk for organisations. Employees often adopt these tools for convenience, but sensitive data can then move outside approved systems, leaving organisations with limited visibility over where it is stored, who can access it and how it is used. AI note-taking tools and personal accounts are increasing this challenge. Effective control requires organisations to provide usable approved alternatives, monitor what tools are being used and ensure sensitive information remains within appropriately governed environments.
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Akamai has found that a small group of intensive AI users may be creating a disproportionate share of organisational risk. The 5% of employees who use AI most intensively use it at 12 times the rate of the least active half, while 47% of enterprise AI conversations take place through personal rather than managed corporate accounts. Around 14% of enterprise AI conversations involved corporate email addresses linked to personal AI subscriptions, potentially exposing sensitive data. AI browser and coding extensions add further risk, with nearly 75% requesting significant permissions and 16% containing known security weaknesses.
https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html
AI Vulnerability Discovery Scores the Highest Impact of 20 Emerging Risks
AI-powered vulnerability discovery has emerged as the highest-impact of 20 emerging risks identified by Gartner, with 76% of respondents placing it in their top ten. Organisations expect the effects to become tangible within the next two years as AI makes it faster and easier to find previously unknown security weaknesses and turn them into usable attacks. While respondents also ranked themselves highly prepared, Gartner warns that vulnerability discovery could outpace organisations' ability to fix weaknesses, raising the risk of serious cyber incidents and disruption to operations.
https://www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/
Ransomware Attack Volumes Hit ‘High Water Mark’ in July
Ransomware activity reached its highest level of 2026 so far in July, with 894 recorded attacks, up almost 25% from June. North America accounted for 41% of incidents and Europe 29%, while one rapidly growing criminal group was linked to 15% of attacks. NCC Group also warned that artificial intelligence is increasing the speed and scale of cyberattacks by helping criminals automate activity and create more convincing phishing content. Emerging AI agents capable of carrying out ransomware attacks with little or no human involvement could further increase the threat.
https://www.computerweekly.com/news/366649779/Ransomware-attack-volumes-hit-high-water-mark-in-July
Incident Response: Why the First Two Hours After an Attack Set the Tone
The first two hours following a cyberattack can significantly influence how quickly an organisation recovers. Poor early decisions, such as wiping compromised systems, can destroy evidence, leave attackers' access routes in place and turn a five-day recovery into a five-week crisis. Effective response depends on quickly assembling legal, forensic and recovery specialists, establishing secure communications and understanding what has been affected. Tested backups are equally important, as many failures only become apparent during recovery. Organisations that prepare response arrangements in advance are better placed to contain disruption and restore operations quickly.
Business Continuity and Cyber Security: Two Sides of the Same Coin
Business continuity and cyber security cannot be treated separately as attackers increasingly target the systems organisations rely on to recover from disruption. Research found that 93% of ransomware attacks targeted backup repositories, while 68% of breaches involved a human element. With the average global cost of a data breach reaching $4.88 million, organisations need recovery arrangements that remain secure during an attack. This includes protecting backups, separating critical systems, maintaining alternative communications and regularly testing recovery plans against realistic cyberattack scenarios.
Governance, Risk and Compliance
The CISO’s next challenge: resilience, not just security | SC Media UK
Hired for One Job, Judged on Another: The CISO’s Real Problem - SecurityWeek
Financial damage from cyber attacks grows despite falling claims volumes | Insurance Times
Is Cyber Facing an Affordability Crisis?
What Your CISO Is Trying To Tell You, And Why It Matters
Why Provision 29 is raising the bar for board accountability - IT Security Guru
Average Cyber Insurance Losses Increase Despite Fewer Claims - Infosecurity Magazine
Threats
Ransomware, Extortion and Destructive Attacks
Ransomware attack volumes hit ‘high-water mark’ in July | Computer Weekly
Ransomware attackers are zeroing in on mid-market companies - Help Net Security
Scammers pose as ransomware recovery agents, but just go on to steal more from victims | TechRadar
Scattered Spider Targets Tech Companies for Help-Desk Exploitation - ReliaQuest
Tricky 'SynkLoader' Multitool May Herald Ransomware
Ransomware surges as criminals deploy AI tools | Microscope
Autonomous AI Ransomware Threat Peaks 2026
Gunra Ransomware: What You Need to Know |Fortra
Ransomware and Destructive Attack Victims
US Bank claimed by hackers, posted on the dark web | Cybernews
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited - SecurityWeek
ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta | TechRadar
ATF confirms “major incident” after recent Qilin breach claims
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
ShinyHunters Leaks 7.1 Million Baxter International Records
Phishing & Email Based Attacks
ZeroTokens Phishing Platform Steers Attacks in Real Time - Infosecurity Magazine
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets - SecurityWeek
Fake bank websites play dead to evade security scanners - Help Net Security
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine
Russian snoops add OAuth abuse to targeted phishing campaigns
Hackers abuse npm mirrors to host phishing redirect pages
New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls | TechRadar
First-time buyer lost £47,000 after email 'impersonated' - The Mirror
Def Con Attendees Targeted by Persistent Phishing Campaign - Infosecurity Magazine
Other Social Engineering
Think you’d never fall for it? Modern cybercriminals are counting on that | Federal News Network
Fake bank websites play dead to evade security scanners - Help Net Security
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine
Scattered Spider Targets Tech Companies for Help-Desk Exploitation - ReliaQuest
Attackers impersonate popular AI brands to spread malware - Help Net Security
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine
Beware of fake Indeed interview apps used to install spyware | Malwarebytes
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Red Flags That Expose Fake North Korean IT Workers
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
First-time buyer lost £47,000 after email 'impersonated' - The Mirror
Scammers cost Irish adults €760m last year - survey – The Irish Times
‘Hang up’ warning issued as fraudsters target Isle of Man residents by phone | iomtoday.co.im
Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice | CyberScoop
2FA/MFA
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Artificial Intelligence
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Employees' shadow AI use is poorly monitored, survey finds | TechTarget
How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty
Why "Shady AI" is Security's Next Big Governance Problem
Why AI cyberattacks are outpacing enterprise defenses | CSO Online
A low-tech solution from the past may be your best defense against AI deepfakes | ZDNET
AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security
Four in Five AI Tools Run with No IT Oversight, Research Finds - Infosecurity Magazine
Attackers impersonate popular AI brands to spread malware - Help Net Security
Ransomware surges as criminals deploy AI tools | Microscope
Autonomous AI Ransomware Threat Peaks 2026
PYMNTS | OpenAI Exec Tells People to Expect AI-Driven Cyberattacks
The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes - Help Net Security
Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Grok chat duped into swallowing injected instructions
NCSC, comments on agentic AI | Professional Security Magazine
ISMG Editors: AI-Assisted Cyberattacks Gain Speed and Scale
What The Hugging Face Cyberattack Teaches Leaders About AI
AI supply chain risk is showing up in developer workflows first - Help Net Security
OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar
OpenAI: Agent behavior that led to Hugging Face intrusion formed in May | CyberScoop
The Hugging Face incident and the road ahead | OpenAI
OpenAI previews privacy-focused system for detecting AI misuse - Help Net Security
AI Agents Taking Unsanctioned Action During Cyber Testing
Fake Codex Download Uses Google Sites to Deliver macOS Malware - Infosecurity Magazine
Could OpenClaw have actually hacked that Australian gym? We decided to test it.
ChatGPT can now search Apple Messages, raising privacy concerns | Fortune
Careers, Roles, Skills, Working in Cyber and Information Security
Cybersecurity Job Ads Requiring AI Skills Double - Infosecurity Magazine
Cloud/SaaS
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
New malware turns Microsoft cloud into its control center | CSO Online
Researchers Uncover Thousands of Leaked AWS Keys - Infosecurity Magazine
NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Cyber Crime, Organised Crime & Criminal Actors
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
A $25 template helped scammers build hundreds of phantom bank domains - Help Net Security
More Than Half of Gen Z Has Faced a Cyberattack - tovima.com
Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects - Infosecurity Magazine
Your Shredded Visa Card May Still Work at the Checkout - Security Affairs
Scammers cost Irish adults €760m last year - survey – The Irish Times
Data Breaches/Leaks
Researchers Uncover Thousands of Leaked AWS Keys - Infosecurity Magazine
US Bank claimed by hackers, posted on the dark web | Cybernews
Personal Information Exposed in Apollo Global Data Breach - SecurityWeek
More Than 9 Million Facial Images Were Leaked Online
Cyberattack hits 63% of Latvia’s population | Al Bawaba
88 ID Verification Breaches Show the Cost of Collecting Identity Data
French tax authority says break-in exposed data of 600K, including some private messages
Target may have suffered another damaging data leak as hackers claim 8.6GB haul | TechRadar
ShinyHunters Leaks 7.1 Million Baxter International Records
Sensitive Information Exposed in Nutex Health Data Breach - SecurityWeek
Data/Digital Sovereignty
How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty
The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know
Why Israel's outsized influence on global tech is worrying | Al Majalla
Denial of Service/DoS/DDoS
Massive DDoS attack disrupts Norway’s government digital services
Pro-Russian hackers declare ‘cyberwar’ on Norway
Encryption
Nearly half of enterprises have no one leading PQC migration - Help Net Security
Quantum Cyberattacks Are Now A CIO Deadline, Not A Research Topic
Fraud, Scams and Financial Crime
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
A $25 template helped scammers build hundreds of phantom bank domains - Help Net Security
Fake bank websites play dead to evade security scanners - Help Net Security
Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine
Your Shredded Visa Card May Still Work at the Checkout - Security Affairs
Scammers cost Irish adults €760m last year - survey – The Irish Times
Scams: Why You Can No Longer Trust Your Eyes And Ears | Scoop News
Up to £464m ‘moved through more than 3,000 UK high street shell companies’ | Business | The Guardian
Identity and Access Management
88 ID Verification Breaches Show the Cost of Collecting Identity Data
Insider Risk and Insider Threats
Employees' shadow AI use is poorly monitored, survey finds | TechTarget
Red Flags That Expose Fake North Korean IT Workers
Insurance
Average Cyber Insurance Losses Increase Despite Fewer Claims - Infosecurity Magazine
Internet of Things – IoT
Slovakia finds Russian backdoors in speed cameras | Cybernews
Hackers infect Android car head units with proxy botnet malware
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Law Enforcement Action and Take Downs
Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects - Infosecurity Magazine
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice | CyberScoop
Linux and Open Source
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researcher tricks Apple’s Find My into sharing location data with Linux
China joins Europe in scrapping Windows for Linux | ZDNET
Malware
ToxicPanda Banking Trojan Matures Into Enterprise Threat
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets
Attackers impersonate popular AI brands to spread malware - Help Net Security
AI Speeds Up Malware Development, Not Its Success Rate: Analysis - SecurityWeek
Fake Codex Download Uses Google Sites to Deliver macOS Malware - Infosecurity Magazine
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Tricky 'SynkLoader' Multitool May Herald Ransomware
Hackers abuse FTP server banners to deliver new Windows malware
New Agent Tesla Malware Variant Boosts Evasion Capabilities - Infosecurity Magazine
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Hackers infect Android car head units with proxy botnet malware
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Hackers abuse npm mirrors to host phishing redirect pages
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Misinformation, Disinformation and Propaganda
OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar
OpenAI banned Russian ChatGPT accounts backing covert influence operation
Mobile
ToxicPanda Banking Trojan Matures Into Enterprise Threat
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
Models, Frameworks and Standards
Firms urged to prepare for eventual NIS2 implementation
Passwords, Credential Stuffing & Brute Force Attacks
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets - SecurityWeek
Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Hackers poison popular Rust crates to steal developers' credentials
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes - Help Net Security
Privacy, Surveillance
Your Comcast router doubles as a motion detector now - and a potential police informant | ZDNET
More Than 9 Million Facial Images Were Leaked Online
Researcher tricks Apple’s Find My into sharing location data with Linux
The best and worst AI for your privacy, ranked - and how each handles your data | ZDNET
ChatGPT can now search Apple Messages, raising privacy concerns | Fortune
Windows 11 is finally getting better privacy controls for cameras and mics | PCWorld
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears | CyberScoop
Regulations, Fines and Legislation
Senator asks US government watchdog to review how feds use hacking tools | TechCrunch
UK government set to adjudicate on ‘risky’ tech purchases | Computer Weekly
Meta agrees to $18 billion settlement over teen social media harms
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears | CyberScoop
Trump Moves to Ban Some Foreign Energy Equipment From Grid - Bloomberg
Shadow IT
Employees' shadow AI use is poorly monitored, survey finds | TechTarget
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty
Why "Shady AI" is Security's Next Big Governance Problem
Shadow AI presents cyber security challenge - CIR Magazine
Social Media
TikTok reaches $400m US children's privacy settlement | US News | Sky News
Meta agrees to $18 billion settlement over teen social media harms
Software Supply Chain
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
New malware turns Microsoft cloud into its control center | CSO Online
AI supply chain risk is showing up in developer workflows first - Help Net Security
Hackers poison popular Rust crates to steal developers' credentials
Hackers abuse npm mirrors to host phishing redirect pages
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
This Mini PC Brand Accidentally Hosted Malware-Infected Drivers On Its Website
Supply Chain and Third Parties
Financial damage from cyber attacks grows despite falling claims volumes | Insurance Times
Is Cyber Facing an Affordability Crisis?
AI supply chain risk is showing up in developer workflows first - Help Net Security
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
UK to warn public to store tinned food in case of emergencies: FT
OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Officials disrupt Chinese espionage operation that hit multiple federal agencies | CyberScoop
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Nation State Actors
China
UK government set to adjudicate on ‘risky’ tech purchases | Computer Weekly
Trump Moves to Ban Some Foreign Energy Equipment From Grid - Bloomberg
China joins Europe in scrapping Windows for Linux | ZDNET
China-linked Threats to Operational Technology
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Russia
UK to warn public to store tinned food in case of emergencies: FT
OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Pro-Russian hackers declare ‘cyberwar’ on Norway
Russia-Linked Threats to Operational Technology
Russia builds global satellite internet network to rival Starlink
North Korea
Red Flags That Expose Fake North Korean IT Workers
Iran
Iranian hackers carry out unprecedented attack on UK’s power network | The Independent
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Iran strikes deep: Attack on British infrastructure
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
UK power plant shutdown highlights CNI cyber challenges | Computer Weekly
The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera
Big or small—Critical infrastructure under attack | McDonald Hopkins - JDSupra
Iran hackers vow to target US allies | Cybernews
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Pakistan's Transparent Tribe Refreshes Tools for Afghan Attacks
Tools and Controls
Four in Five AI Tools Run with No IT Oversight, Research Finds - Infosecurity Magazine
The CISO’s next challenge: resilience, not just security | SC Media UK
Incident response: The first two hours post-attack set the tone
Why mission risk should drive cyber operations strategies | perspective | SC Media
A low-tech solution from the past may be your best defense against AI deepfakes | ZDNET
AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security
If you're not using AI to attack your own systems, your adversaries will
CISA's logging guidance works beyond government - Help Net Security
The patch window is collapsing: Why security needs a new control plane | Microsoft Azure Blog
Windows 11 is finally getting better privacy controls for cameras and mics | PCWorld
Cybersecurity Job Ads Requiring AI Skills Double - Infosecurity Magazine
Remote Help on Windows: Unattended Support with Remote Sign-In Is Here | Microsoft Community Hub
Senator asks US government watchdog to review how feds use hacking tools | TechCrunch
CISA issues guidance for agencies to improve cybersecurity data logging | Federal News Network
Microsoft Teams now lets admins block external bots from meetings
The best human hacking team still out-solved the best AI team - Help Net Security
PYMNTS | Cybersecurity Firms Weigh Internet Access for Frontier AI Testing
VMs won't contain cyber-capable agents - The Trail of Bits Blog
Other News
Worrying cybersecurity gaps expose UK charities - TFN
Anxiety over war, wildfires and cyber-attacks leads to growth in cash stocks in EU
Cybersecurity in the Healthcare Sector - Stiftung Wissenschaft und Politik
Japan outlines measures to protect infrastructure from cyberattacks - The Japan Times
Vulnerability Management
AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
Silent Patches Don’t Stop Attackers - They Blind Defenders - SecurityWeek
Why mission risk should drive cyber operations strategies | perspective | SC Media
The Vulnerability Gap: Why Discovery Is Outrunning Repair
Frontier AI: Vulnerability Management's Systemic Revolution
Vulnerabilities
Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel
Microsoft patches max severity code execution, privilege escalation flaws
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security
That April Windows update you skipped? Hackers are exploiting it now | PCWorld
Microsoft: August updates break printing, PDF export in WPF apps
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Microsoft rolls out fix for Windows 11 crashes, gaming issues
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
Recent Citrix NetScaler Vulnerability Exploited in the Wild - SecurityWeek
Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes
Hackers breached over 270 Zimbra servers in ongoing attacks
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
Chrome 152 Patches Over 300 Vulnerabilities - SecurityWeek
Adobe and Nvidia Patch Dozens of Vulnerabilities - SecurityWeek
PaperCut Releases Emergency Patch for Exploited Zero-Day - SecurityWeek
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
Ubiquiti UniFi vulnerabilities: 21 critical bugs expose devices | Cybernews
Three 10.0 security flaws fixed across Ubiquiti’s UniFi line | CyberScoop
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
Critical Isolated-vm Vulnerability Leads to RCE on Host - SecurityWeek
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
91 Vulnerabilities Patched in Spring Application Framework - SecurityWeek
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
Hackers target WordPress sites in miniOrange auth bypass attacks
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.