Black Arrow Cyber Threat Intelligence Briefing 31 July 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Cyber resilience requires organisations to prepare and rehearse how they will respond to a serious cyber incident, and this week we reinforce the need for organisations to strengthen their resilience. This is achieved by the leadership team, not just the technology team, planning and rehearsing how to investigate and coordinate various response activities that affect everyone.
We also continue to look at cyber security, which is where organisations take a structured approach to help prevent an incident from occurring. Attackers continue to target employees through email and Teams phishing, while AI is making personalised deception faster and easier to scale. We continue to look at other AI-driven risks that business leaders need to address, including evolving risks with agentic AI and browsers.
Addressing these risks requires a leadership team that is regularly upskilled on the risks and the proportionate controls that they can ensure are implemented to reduce the risks. Resilience is strengthened through cross-functional incident response exercises that test decision-making, authority, coordination and business dependencies. Contact us to discuss how we support organisations across the world to achieve this.
Top Cyber Stories of the Last Week
73% of Organisations Say They Are Not Fully Ready for a Major Cyberattack
New research found that 73% of organisations would not be fully prepared for a major cyberattack, despite most having response plans, tools and technical teams in place. Of the 600 senior security decision makers surveyed, 76% had experienced at least one cyberattack in the past year, while 90% expected difficulties coordinating internal stakeholders during a serious incident. Limited executive involvement, delays engaging legal and communications teams, and poor visibility across systems were identified as major obstacles, showing that effective response depends on rehearsed decision-making and coordination, not technology alone.
https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
Why the Biggest AI-Driven Cyber Threat Is Still Human Nature
AI can rapidly identify software weaknesses and produce convincing messages, but manipulating people may still give criminals an easier route into organisations than overcoming technical defences. A technical flaw still requires suitable access and conditions to become a breach, while a single employee can be deceived through an urgent phishing email, fake security alert or impersonation attempt. AI makes these attacks faster, cheaper and more convincing in any language. Organisations should not expect employees to identify every convincing AI-generated deception and need broader technical defences to support them.
Phishing Dominates as Initial Entry Method for Cyberattacks, as Hackers Hone Evasion Techniques
Phishing was the initial entry point in just over half of the cyber incidents investigated by Cisco Talos between March and June 2026, up from one third in the previous quarter. Attackers are increasingly using QR codes, trusted cloud services and tailored documents to bypass email security and steal Microsoft 365 credentials. Phishing-as-a-service kits can also help criminals bypass multi-factor authentication and retain access after compromise, reinforcing the need for phishing-resistant authentication, centralised logging and controls that limit attack propagation.
https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
AI Is Gaining Ability to Personalise Cyberattacks, Enabling Phishing at Scale
AI is enabling criminals to create highly personalised phishing attacks at scale by researching targets, impersonating trusted contacts and adapting conversations when questioned. Unlike generic scam messages, these attacks can reflect an employee’s role, relationships and current responsibilities, making them far harder to identify. Researchers estimate that some business email compromise attacks could be fully automated by late 2026, with more complex cyberattacks potentially automated from start to finish as early as 2027. This significantly increases the risk that employees will be manipulated into revealing credentials or downloading malicious software.
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Microsoft detected approximately 7.6 billion email phishing threats between April and June 2026, with credential theft accounting for up to 96% of attacks involving malicious content. Attackers are also increasingly targeting employees through Microsoft Teams, often posing as IT support staff. Weekly malicious call attempts increased by roughly 80% from the start of 2026 and reached almost ten times the mid-2025 level by late June. One automated email fraud campaign reached more than 67,000 users across 42,000 organisations in under three hours, highlighting how attackers combine trusted workplace channels with convincing impersonation to steal access or redirect payments.
https://cybersecuritynews.com/email-phishing-threats-as-teams-vishing-attacks/
Year-Long Russian Attacks Infect Users as Soon as They Look at an Email
Russian state-linked attackers have exploited a weakness in Zimbra email systems since July 2025, compromising users simply when they viewed a malicious email, without requiring a click or attachment. The campaign targeted government, defence, energy, education, media and technology organisations, stealing up to 90 days of emails, passwords, contact directories and authentication details. The flaw was fixed in November 2025, but unpatched systems remain exposed. Organisations using Zimbra should update immediately, limit access to webmail until secure, and review systems for signs of compromise.
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malicious advertising campaign targeting retail traders and cryptocurrency investors has operated since late 2024 across 12 countries and 25 languages. Fraudulent adverts impersonate services including TradingView, Solana and Luno, directing victims to convincing fake websites. Rather than downloading a complete malicious program, the victim’s browser assembles it from separate components, which can produce a different file for each session and reduce the value of basic file matching. There is no specific software patch to apply, reinforcing the importance of downloading trading and wallet applications only from official vendor websites and monitoring the wider advertising and download chain.
https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Ransomware groups are increasingly disabling endpoint security tools before encrypting systems, reducing the time available to detect and contain attacks. Halcyon recorded 1,988 publicly claimed attacks across 101 countries in the second quarter of 2026. Although claims fell by 5.7%, the methods used became more sophisticated, with greater automation and some groups progressing from initial access to ransomware deployment in under an hour. Manufacturing accounted for 19.8% of cyber extortion attacks, while criminals also expanded their use of artificial intelligence to support access, negotiation and other stages of attacks.
https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
Agentic Browsers Rewind Web Security by 20 Years
Agentic browsers are AI-enabled web browsers that can navigate websites and take actions on a user’s behalf, rather than simply displaying pages. Researchers found that every commercial agentic browser they tested could be manipulated into harmful activity, including account takeover, unauthorised purchases and, in some cases, control of the underlying device. Some weaken established protections that stop one website triggering actions on another, allowing malicious online content to redirect the agent. Organisations considering adoption should assess the risks and use separate, isolated accounts and credentials rather than connecting agentic browsers to employees’ normal accounts.
https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years
OpenAI's Rogue AI Hacked Four More Platforms besides Hugging Face
Following the recent report that an OpenAI security test led an autonomous AI agent to access Hugging Face, OpenAI has confirmed that the agent also reached four other external services. The evaluation was designed to test what the models could do without safety filtering; the agent escaped its controlled environment and used exposed credentials to access outside systems. Only Hugging Face and Modal Labs have been named, leaving three affected services undisclosed. The incident highlights the risk of highly capable AI systems operating without effective containment and controls.
https://decrypt.co/374645/openais-rogue-ai-hacked-four-more-platforms-besides-hugging-face
Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts
Hackers are compromising Wi-Fi systems at hotels and conference centres to redirect travellers to convincing fake Microsoft 365 login pages. The campaign, active since at least June, has affected organisations across financial services, legal, healthcare, energy, retail and other sectors worldwide. In some cases, attackers can bypass multi-factor authentication by tricking users into approving a legitimate-looking sign-in request, potentially giving them access to emails, documents and business communications. Exposure can be reduced through always-on, full-tunnel VPNs and disabling Microsoft device-code authentication where it is not needed.
Response to Fraud Must Transform Faster, Warns City of London Police
Fraud and cyber crime now account for nearly half of all crime in the UK, prompting the City of London Police to call for a faster national response involving government, law enforcement and industry. Recent enforcement activity resulted in 557 arrests, £9 million frozen, and the seizure of £2.8 million in cash and £15.3 million in non-cash assets. The new Report Fraud service, launched in January 2026, is intended to improve reporting and intelligence gathering as criminals adopt increasingly sophisticated methods.
Threats
Ransomware, Extortion and Destructive Attacks
Bad news — paying a ransomware demand might cause hackers to come back and ask for more | TechRadar
Companies are still paying ransoms to cyber criminals despite official advice | IT Pro
Over a third of ransomware victims re-extorted after paying
Ransomware groups take aim at vulnerable VPNs | CSO Online
Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine
Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs
The Signs Were There: What the First Autonomous Ransomware Case Confirms | Trend Micro (US)
Ransomware gangs go after EMEA healthcare's supply chain - Help Net Security
ShinyHunters data leaks fuel $2,000 sextortion email scam
Clop ransomware targets Windchill, FlexPLM in data theft attacks
Ransomware Attacks Targeting Universities on the Rise - Infosecurity Magazine
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
Ransomware and Destructive Attack Victims
Ernst & Young data breach claimed by ShinyHunters extortion gang
Education department says 607,000 records taken in cyber attack - BBC News
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - SecurityWeek
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Phishing & Email Based Attacks
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian APT Laundry Bear perfects zero-click phishing attack | Computer Weekly
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Phishing Dominates as Initial Entry Method for Cyber-Attacks - Infosecurity Magazine
Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog
The best-funded companies open the most phishing attachments - Help Net Security
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks - Infosecurity Magazine
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
LogoKit Phishing Kit Screenshots Victim Sites in Real Time - Infosecurity Magazine
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | Trend Micro (US)
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Other Social Engineering
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Phishing Dominates as Initial Entry Method for Cyber-Attacks - Infosecurity Magazine
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
A new vishing campaign is targeting Microsoft Teams – here's what users need to know | IT Pro
ShinyHunters data leaks fuel $2,000 sextortion email scam
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
2FA/MFA
Artificial Intelligence
AI image fraud will cost $40 billion next year - can these international standards help? | ZDNET
One ChatGPT link could smuggle a rogue AI agent into your company
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
US lawmakers push for AI 'kill switch' after OpenAI models go rogue - BBC News
An AI agent can pass every safety check and still leak secrets - Help Net Security
Agentic Browsers Rewind Web Security by 20 Years
OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Face - Decrypt
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Microsoft Copilot Deployments Delayed Over Security Concerns - Infosecurity Magazine
New Dolphin X malware uses AI to rank high-value targets
OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
After Mythos, zero trust alone won’t be enough against AI-powered attacks | Federal News Network
Hugging Face breach reignites open-weights debate, raises liability questions - Help Net Security
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard - Infosecurity Magazine
One-click Claude Desktop Flaw Could Enable Hidden Prompt Injection And Code Execution
Your AI agents can reach data no one approved - Help Net Security
OpenAI models used Artifactory zero-days to escape to the internet
When AI Agents Escape Sandboxes, Old Security Rules Apply
Stronger AI Safety Requires Peeking Inside the 'Black Box'
Why The Biggest AI-Driven Cyber Threat Is Still Human Nature
The Signs Were There: What the First Autonomous Ransomware Case Confirms | Trend Micro (US)
Europe's Multilingual Reality Exposes AI Security Gaps
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
Nvidia forms Open Secure AI Alliance to build open-source security tools
NVIDIA’s Open Security AI Alliance Is Missing Some Big Names - Infosecurity Magazine
Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop
FBI sees Anthropic’s Mythos as a law enforcement challenge | FedScoop
Biggest ever MCP update brings metadata, cybersecurity enhancements - SiliconANGLE
Trump considering AI controls after OpenAI hacking incidents - BBC News
Why Mythos is the cybersecurity crisis we need | resource | SC Media
828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead
Beyond the Patch: How AI Continues to Change Cyber Hygiene
250 Eiffel Towers' worth of waste: The AI boom's toxic hardware problem | ZDNET
Rogue AI cyber incident heralds new 'era of agentic autonomous attacks' | Insurance Times
Bots/Botnets
Despite multiple takedowns, botnets continue to grow | CyberScoop
New Dysphoria DDoS botnet spreads to 200k devices worldwide
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Cloud/SaaS
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
A new vishing campaign is targeting Microsoft Teams – here's what users need to know | IT Pro
Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts | CSO Online
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Your team isn’t "ignoring security." They’re just underwater. - The New Stack
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Cyber Crime, Organised Crime & Criminal Actors
Europol flags 4,340 'horrific' URLs linked to The Com
Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders
Data Breaches/Leaks
Ernst & Young data breach claimed by ShinyHunters extortion gang
Education department says 607,000 records taken in cyber attack - BBC News
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack - SecurityWeek
Chick-fil-A data breach affects more than 13,000 customers
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
Tens of thousands of university account logins found on dark web
Data breach at medical billing firm MCBS affects 1.26 million people
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
DentaQuest disclosed a data breach that impacted +23 million individuals
Origin Energy Data Breach Affects 900,000 Australians - SecurityWeek
Denial of Service/DoS/DDoS
New Dysphoria DDoS botnet spreads to 200k devices worldwide
Encryption
Anthropic’s Claude Mythos finds weaknesses in encryption algorithms | CyberScoop
Fraud, Scams and Financial Crime
AI image fraud will cost $40 billion next year - can these international standards help? | ZDNET
Police Professional | Response to fraud must transform faster, warns City of London Police
Stolen Meta and Google ad accounts are worth more than the money they hold - Help Net Security
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan | Trend Micro (US)
Former policeman charged over French château ‘investment scam’
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Identity and Access Management
Flaws in Passkey Implementation Show Old Attacks Still Work
Insider Risk and Insider Threats
Why The Biggest AI-Driven Cyber Threat Is Still Human Nature
One ChatGPT link could smuggle a rogue AI agent into your company
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Internet of Things – IoT
Tengu botnet reboots Linux devices to survive removal - Help Net Security
The automotive software vulnerabilities hiding in your dashboard - Help Net Security
Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth | TechRadar
Law Enforcement Action and Take Downs
Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders
Police Professional | Response to fraud must transform faster, warns City of London Police
Europol flags 4,340 'horrific' URLs linked to The Com
FBI sees Anthropic’s Mythos as a law enforcement challenge | FedScoop
Man gets six years for hacking 750 women's Snapchat accounts
Former policeman charged over French château ‘investment scam’
Council worker spared prison after four-day data-snooping spree
Linux and Open Source
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched - Infosecurity Magazine
Malvertising
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser - Infosecurity Magazine
Malware
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser - Infosecurity Magazine
Tengu botnet reboots Linux devices to survive removal - Help Net Security
New Dysphoria DDoS botnet spreads to 200k devices worldwide
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Despite multiple takedowns, botnets continue to grow | CyberScoop
New Dolphin X malware uses AI to rank high-value targets
Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain | TechRadar
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Hackers abuse Notepad++ plugins to stealthily install malware
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Researchers replace downloaded macOS apps with evil twins, Apple shrugs
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Mobile
Iran-linked group caught hiding surveillance tools in fake apps | TechRadar
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
Is It Safe To Keep Using A Phone That No Longer Gets Update Support?
The US is charging an American citizen for wiping his phone at the border | The Verge
Android malware detection collapses when the context stage comes out - Help Net Security
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
Models, Frameworks and Standards
Examining the Unintended Consequences of the Online Safety Act - IT Security Guru
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation - Infosecurity Magazine
Outages
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft blames massive Microsoft 365 outage on maintenance bug
Cloudflare reveals what's behind major internet outages - Help Net Security
Passwords, Credential Stuffing & Brute Force Attacks
Why Resetting Passwords No Longer Stops Attackers
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days | CyberScoop
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Flaws in Passkey Implementation Show Old Attacks Still Work
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
I'm not letting Claude touch my passwords, no matter how safe Anthropic claims it is
Regulations, Fines and Legislation
Examining the Unintended Consequences of the Online Safety Act - IT Security Guru
US lawmakers push for AI 'kill switch' after OpenAI models go rogue - BBC News
The US is charging an American citizen for wiping his phone at the border | The Verge
Huawei ban to cost the EU up to €40 billion, says industry – POLITICO
Industry's message on CIRCIA: Please ask us fewer questions about cyberattacks | CyberScoop
The government has delivered its verdict on the proposed UK VPN ban | The Independent
AI, audits and OSINT featured in House intel bill | Federal News Network
Rubio restricts visas for sextortionists, cyber scammers | CyberScoop
Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices
US launches trade probe into EU over big tech fines | Euronews
Shadow IT
Shadow AI incident response begins with logs that may already be gone - Help Net Security
Shadow AI agents are multiplying. Here's how to find and secure them.
Social Media
Man gets six years for hacking 750 women's Snapchat accounts
Meta tackles AI-generated accounts with a free Facebook verification badge - Help Net Security
Software Supply Chain
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Supply Chain and Third Parties
Ransomware gangs go after EMEA healthcare's supply chain - Help Net Security
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Iran-linked group caught hiding surveillance tools in fake apps | TechRadar
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Finnish Intelligence Warns of Russian Cyberattacks - Freedom
The Red Cross plans to extend its protection to cyberspace - SWI swissinfo.ch
Ukrainian hackers cause Russian air defense to shoot down a Su-57 fighter | TechRadar
Can Cyber Operations Be Deterred? What Wargames Reveal
China
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Huawei ban to cost the EU up to €40 billion, says industry – POLITICO
Open weights vs. closed: An AI civil war's afoot, and the stakes are existential | ZDNET
Researchers Say a 'Ghost' Chinese Company Built the Network Hiding PLA Cyberattacks
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
Russia
Year-long Russian attacks infect users as soon as they look at an email
Laundry Bear pivots to new exploit days after Zimbra alert | Computer Weekly
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Finnish Intelligence Warns of Russian Cyberattacks - Freedom
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
Ukrainian hackers cause Russian air defense to shoot down a Su-57 fighter | TechRadar
How Ukrainian Cyber Operation May Have Led to Downing of russian Su-57 Near Moscow | Defense Express
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
North Korea
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Nearly 100,000 cyberattacks hit foreign ministry, affiliates in 6 months - The Korea Times
Iran
Iran-linked group caught hiding surveillance tools in fake apps | TechRadar
Handala Hacker Group claims cyberattack on U.S. communications infrastructure
Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
Tools and Controls
Why Resetting Passwords No Longer Stops Attackers
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Is Patching Dead? Vulnerability Management in the Post-Mythos Era - SecurityWeek
Has your security stack become your biggest cyber risk? | ChannelPro
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Ransomware groups take aim at vulnerable VPNs | CSO Online
Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine
The government has delivered its verdict on the proposed UK VPN ban | The Independent
Flaws in Passkey Implementation Show Old Attacks Still Work
OpenAI models used Artifactory zero-days to escape to the internet
When AI Agents Escape Sandboxes, Old Security Rules Apply
Google's solution to hacker name confusion? Yet another naming system | CyberScoop
Securing What Matters: Why Cyber Resilience Needs Prioritisation - IT Security Guru
Shadow AI incident response begins with logs that may already be gone - Help Net Security
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation - Infosecurity Magazine
Microsoft tightens Windows enterprise activation security - Help Net Security
Vulnerability management needs an update for the AI era | TechTarget
Reports Published in the Last Week
Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog
Vulnerability Management
Is Patching Dead? Vulnerability Management in the Post-Mythos Era - SecurityWeek
The shrinking exploit window and what it means for cybersecurity teams | native | MSSP Alert
Mythos Asks the Right Question. It Doesn't Answer It.
828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead
Is It Safe To Keep Using A Phone That No Longer Gets Update Support?
Vulnerabilities
Critical Flaw Led to Azure Cosmos DB Pwnage - SecurityWeek
Cyber Firm Wiz Says Flaw Could Have Exposed Thousands of Microsoft Cloud Customers
Confused Deputy Flaws Persist in Google Cloud, Microsoft Azure
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google Releases Patches for 370 Vulnerabilities in Chrome 151 - Infosecurity Magazine
Oracle drops 1,449 security patches like it's the new normal
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Critical VM Escape Vulnerability Patched in VMware ESXi - SecurityWeek
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
One-click Claude Desktop Flaw Could Enable Hidden Prompt Injection And Code Execution
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe - SecurityWeek
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day - SecurityWeek
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Unpatched Fastjson Vulnerability Exploited in Attacks - SecurityWeek
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain - Security Affairs
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard - Infosecurity Magazine
JFrog Patches Flaws Behind OpenAI Models' Escape
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched - Infosecurity Magazine
New Certighost PoC exploit lets attackers hijack Windows domains
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
vBulletin fixes critical pre-auth RCE flaw with public exploit
PTC Windchill Vulnerability Exploited in Ransomware Campaign - SecurityWeek
828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.