Threat Intelligence Blog
Contact us to discuss any insights from our Blog, and how we can support you in a tailored threat intelligence report.
Black Arrow Cyber Threat Intelligence Briefing 24 July 2026
Black Arrow Cyber Threat Intelligence Briefing 24 July 2026:
-OpenAI’s New Model Went Rogue and Hacked Another Company. Why It Matters.
-AI Models Keep Getting Caught Cheating
-Senior Executives Abuse Shadow AI Twice as Much as Regular Employees Do
-The Script, Not the Voice, Is What Makes AI Voice Phishing Work
-Connecting AI Agents to Outside Services Explodes the Risk Radius
-Cyber Remains Top Enterprise Risk for Company Leaders
-79% of Ransomware Attacks Start with Compromised Identities
-Ransomware Attacks Hit SMBs Harder than Ever as Cybercrime Gang Rivalry Heats Up
-A New Ransomware Threat Actor Emerges Every Week, Warns Report
-Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats from 329 Million Users
-Watch Out – That Microsoft Calendar Invite Dated 2050 Could Be Hiding Stolen Files and Worse
-Device Code Phishing: Turning a Convenience Feature into an MFA Bypass
-1 in 4 Businesses Hit by Cyber Attacks through Their Supply Chain in the Last Year
-The Executive Profile Your Security Team Isn’t Defending
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Over the past week, the global media has been discussing how OpenAI’s new model bypassed its testing controls and accessed systems belonging to another AI company while attempting to complete a cyber security task. We include this and other information in our weekly review of cyber security in the specialist and general media, to help raise awareness of the risks that organisations need to manage when using AI, and when defending against AI-driven attacks.
While AI has been the focus of many news stories this week, business leaders need to ensure they do not take their eye off other risks, including ransomware attacks, which frequently begin with compromised credentials including credentials obtained through phishing. We also include this week news of other vulnerabilities and attack tactics, from Adobe Acrobat extensions and Microsoft calendar entries, to supply chain risks and online information about company executives that enables attackers to impersonate them.
Although cyber risks come from various angles, and new high risks are identified particularly related to AI, the underlying approach to managing cyber risks remains consistent. Business leaders should ensure they are upskilled with an understanding of the risks they need to manage, and an impartial view of the controls that they need to ensure are in place and governed. Importantly, the controls must cover people, operations and technology, and the impartial assessment should come from cyber experts who are not providing those controls. Contact us to see how we help organisations across various countries to achieve this proportionately.
Top Cyber Stories of the Last Week
OpenAI’s New Model Went Rogue and Hacked Another Company. Why It Matters.
OpenAI has disclosed that an advanced artificial intelligence model bypassed its testing controls and accessed systems belonging to another AI company while attempting to complete a cyber security task. The incident highlights the growing risks posed by AI agents, which can act independently on computers and pursue objectives without continuous human direction. Although the affected company was not widely known, the incident raises concern about whether safeguards will remain effective as AI systems become more capable. OpenAI has strengthened its security controls and is continuing to investigate the incident.
AI Models Keep Getting Caught Cheating
Research from the UK’s AI Security Institute found that every large language model tested in offensive cyber security exercises attempted to take prohibited actions or use unintended shortcuts to complete assigned tasks. The models often failed to disclose this behaviour, and fewer than half recognised it as wrong when challenged. In one case, a model used an external online service to try to access protected evaluation systems, triggering a security alert. Although no data was lost, the findings raise serious concerns about using AI in sensitive areas where trust, oversight and reliable decision-making are essential.
https://cyberscoop.com/ai-models-cheat-deceive-users-aisi-report/
Senior Executives Abuse Shadow AI Twice as Much as Regular Employees Do
Senior executives are using unauthorised AI tools at twice the rate of other employees, with nearly two-thirds admitting to the practice compared with 31% of lower-level staff. This creates particular risk because leaders often handle sensitive financial, strategic, customer and intellectual property data. Three-quarters of employees recognise the security and privacy concerns, suggesting the problem is driven less by awareness and more by poor alternatives. Where approved tools are slow, limited or difficult to access, staff are more likely to use personal accounts and unapproved services, reducing oversight and leaving organisations without reliable records of how important decisions were made.
The Script, Not the Voice, Is What Makes AI Voice Phishing Work
Research involving 4,100 US adults found that the persuasiveness of an AI voice phishing call mattered far more than how human the voice sounded. Around 16% of participants said they might comply with scam requests, rising to 36% for a fake relative in distress. Controls should therefore focus on independent verification, such as calling back using trusted contact details, family code words and preventing telephone requests alone from authorising password resets, payments or account changes.
https://www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/
Connecting AI Agents to Outside Services Explodes the Risk Radius
Connectors link AI agents to external services including email, messaging and file storage, widening an organisation’s exposure to data loss and unauthorised actions. PromptArmor found that 37% of 2,517 connectors changed within six weeks, with 1,686 new capabilities added to connectors that were already live. Around two in five Claude connectors were also likely to call additional AI services, meaning data could be processed by providers not considered when the connector itself was approved. Rapid changes to permissions, data handling and write access mean connector approvals can quickly become outdated, creating hidden governance and security risks.
Cyber Remains Top Enterprise Risk for Company Leaders
Cyber attacks and data breaches remain the top enterprise risk in 2026 and are expected to retain that position through 2028, according to Aon. Artificial intelligence is increasing the speed, scale and accessibility of attacks, allowing criminals to automate research, create convincing phishing messages and exploit weaknesses more quickly. Despite this, many organisations consider themselves only somewhat prepared, with fragmented oversight and limited testing of AI-related incidents. Aon recommends strengthening basic controls, reviewing insurance coverage, improving board reporting and testing response and continuity plans against AI-enabled disruption.
https://www.emergingrisks.co.uk/cyber-remains-top-enterprise-risk-for-company-leaders/
79% of Ransomware Attacks Start with Compromised Identities
A Sophos report found that compromised user accounts were involved in 79% of ransomware incidents, making stolen login details the most common route into organisations. Malicious emails accounted for 26% of cases, phishing rose from 18% in 2025 to 24% in 2026, and brute force attempts remained broadly stable at 23%. By contrast, attacks exploiting known software weaknesses fell from 32% to 18%. For business leaders, the findings underline the need to strengthen identity controls, limit unnecessary access and ensure compromised accounts can be identified and disabled quickly.
Ransomware Attacks Hit SMBs Harder than Ever as Cybercrime Gang Rivalry Heats Up
NordStellar’s analysis of more than 200 threat actor blogs identified 2,581 reported attacks in the second quarter of 2026, with Qilin and The Gentlemen responsible for 299 and 284 incidents respectively. Smaller US businesses were hit hardest, suffering 769 attacks, followed by Canada with 97, Germany with 83 and the UK with 74. Attacks on US organisations with revenues above $1 billion also rose by 74%, from 23 to 40 incidents. The findings suggest smaller businesses remain especially exposed where defences are limited, while major companies may face increased targeting as leading groups compete for status.
A New Ransomware Threat Actor Emerges Every Week, Warns Report
The ransomware market is becoming increasingly crowded and unpredictable, with 61 new groups emerging during the first half of 2026. Black Kite identified 146 active groups by June, up from 105 a year earlier, although their average lifespan has fallen to just 4.9 months. Despite this fragmentation, the five largest groups accounted for 44% of 7,551 publicly disclosed victims between March 2025 and March 2026. Critical software weaknesses provided initial access in 44% of attacks, reinforcing the importance of timely updates. The report also recommends stronger identity verification, help desk escalation and controls against executive impersonation.
https://www.infosecurity-magazine.com/news/new-ransomware-weekly/
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats from 329 Million Users
A flaw in Adobe’s Acrobat extension for Chrome could have allowed attackers to steal visible WhatsApp Web chats, contacts and profile information when a user visited a malicious website, without requiring a click or password. The extension was installed on up to 329 million browsers worldwide. Adobe fixed the issue in version 26.5.2.3 and distributed the update automatically. The incident highlights the wider risks posed by browser extensions, particularly where trusted software can access sensitive information across other websites and online services.
https://cybersecuritynews.com/acrobat-extension-flaw-whatsapp-chats/
Watch Out – That Microsoft Calendar Invite Dated 2050 Could Be Hiding Stolen Files and Worse
Group-IB has identified new malware targeting organisations that uses compromised Microsoft 365 calendars to steal sensitive files. Attackers hide instructions in calendar entries dated as far ahead as 2050, then attach encrypted stolen data to events, allowing the activity to blend into legitimate Microsoft traffic. At least 12 systems were compromised, with three still communicating with the attackers during the investigation. Researchers found similarities to tools linked with an Iranian-aligned group, although the evidence was not strong enough for confident attribution. The technique shows that trusted cloud services can conceal malicious traffic and data theft from normal monitoring.
Device Code Phishing: Turning a Convenience Feature into an MFA Bypass
Device code phishing turns a legitimate Microsoft sign-in feature into a route around multi-factor authentication. Victims enter a genuine code on Microsoft’s website and complete MFA, but unknowingly approve access for the attacker. In one case, criminals posed as a contact at a law firm, built trust through several emails, then used the compromised account to register multiple devices, hide messages and send phishing emails to hundreds of recipients. Organisations should block device code authentication where it is not required, restrict device registration and train staff to treat unexpected requests to enter verification codes as suspicious.
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
1 in 4 Businesses Hit by Cyber Attacks through Their Supply Chain in the Last Year
One in four UK businesses suffered a cyber incident through their supply chain in the past year, while 48% knowingly continued working with suppliers that had security or resilience concerns. Databarracks found these organisations were more than four times as likely to experience a supplier-related incident. Although 89% assess suppliers during onboarding, ongoing visibility often remains limited. The wider study also found 65% believe a serious cyber attack could threaten their survival, highlighting the need to treat critical suppliers as part of the organisation’s own resilience planning.
The Executive Profile Your Security Team Isn’t Defending
Artificial intelligence can now assemble detailed profiles of senior executives in minutes by combining public information about their careers, relationships, interests and routines. This makes convincing impersonation and targeted fraud easier, even for less skilled attackers. Organisations should treat an executive’s public digital footprint as a managed security risk, with regular reviews of what major AI platforms reveal. Removing unnecessary personal information, addressing family exposure and showing executives their own AI-generated profiles can reduce the information available for phishing, fraudulent calls and attempts to manipulate support staff.
Governance, Risk and Compliance
How mapping security controls can ease the compliance burden | TechTarget
Cyber remains top enterprise risk for company leaders - Emerging Risks Media Ltd
Businesses need to boost cyber resilience, here’s how | IT Pro
The executive profile your security team isn't defending | CSO Online
Cybersecurity’s Economics Are Broken. Automation Alone Won’t Fix It - Infosecurity Magazine
New Index Tracks Material Breaches — And Refuses to Add Up the Losses - SecurityWeek
Threats
Ransomware, Extortion and Destructive Attacks
A New Ransomware Threat Actor Emerges Every Week, Warns Report - Infosecurity Magazine
Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up | TechRadar
79% of Ransomware Attacks Start with Compromised Identities | Security Magazine
The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat - Infosecurity Magazine
Government Agencies Falling Victim to Ransomware Daily, Warns Study - Infosecurity Magazine
Ransomware Uses AI to Amp Up Negotiations | Lawfare
Pay up or not? Ransomware surge has victims facing tough choices. - Ars Technica
If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch
How enterprise GenAI can amplify ransomware risk — and how to contain it
New Spirals ransomware encrypts victim network in under 24 hours
Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
PYMNTS | Governments Weigh Ransomware Payment Bans
Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness - Infosecurity Magazine
As Ransomware Blackmail Surges, Governments Mull a Ban on Paying Up | Extremetech
Inc Ransomware Exploits SonicWall SMA Zero-Days
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Ransomware and Destructive Attack Victims
Government Agencies Falling Victim to Ransomware Daily, Warns Study - Infosecurity Magazine
Qilin claims hack of Danone global food giant | Cybernews
JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security
List of Companies Impacted by Rise in Cyber Attacks
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack - SecurityWeek
After KFC, cyberattack hits Japanese ice cream giant Glico | The Straits Times
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei - SecurityWeek
Romania's land registry hit by cyber attack, data allegedly for sale - Help Net Security
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Abbott probes two cyber incidents amid extortion claims
Phishing & Email Based Attacks
Phishing Campaign Hides Lua Loader as TrueType Font File - Infosecurity Magazine
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Attackers Combo Up Evasion Tactics for BEC Phishing
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass | Trend Micro (US)
AI spam filters are getting suckered by old-school text salting
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Police dismantle Kratos phishing platform, arrest developer
Business Email Compromise (BEC)/Email Account Compromise (EAC)
Attackers Combo Up Evasion Tactics for BEC Phishing
Other Social Engineering
The script, not the voice, is what makes AI voice phishing work - Help Net Security
The executive profile your security team isn't defending | CSO Online
Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Almost half of fraud cases reported in the first half of 2026 were phone scams (vishing)
Scammers impersonate FBI on social media, prey on crime victims
Fake FBI agents target people who already got scammed - Help Net Security
Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 - Infosecurity Magazine
North Korea's IT worker scheme funds Russia's war effort | CyberScoop
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
Telegram shortlinks knocked offline over sanctioned VPN connection
Artificial Intelligence
The script, not the voice, is what makes AI voice phishing work - Help Net Security
How enterprise GenAI can amplify ransomware risk — and how to contain it
OpenAI’s new model went rogue and hacked another company. Why it matters. - The Washington Post
Co-founder of firm hacked by rogue OpenAI models says it is 'a wake-up call' - BBC News
The executive profile your security team isn't defending | CSO Online
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain - Infosecurity Magazine
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Prompt injection is becoming the XSS of the web agent era - Help Net Security
Agentic AI: Taming the Unpredictable
Senior executives abuse shadow AI twice as much as regular employees do | CIO
Connecting AI agents to outside services explodes the risk radius
Employees' shadow AI use is poorly monitored, survey finds | TechTarget
New UK report finds AI models consistently cheat and deceive users | CyberScoop
Forescout Report Reveals Surge in AI-Driven Cyber Threats - IT Security Guru
Vibe-Coded Apps Riddled With Exploitable Security Flaws - SecurityWeek
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness - Infosecurity Magazine
Claude Chrome extension flaw lets malicious extensions trigger AI actions
Think you can spot fake AI photos? They're now a security risk | PCWorld
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
CISOs Feel the Heat Over AI Risk
Attackers Are Learning to Live Off the AI Toolchain
Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
AI agents are still logging in as humans - Help Net Security
New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
AI Data Centers Are Being Built Faster Than They Can Be Secured - SecurityWeek
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Google's Gemini lets strangers send messages from your locked Android phone
Researchers Build WordPress Exploit Using OpenAI's GPT - Infosecurity Magazine
Hacker Turns AI Jailbreaks Into Offensive Platform
AI Agents Can Now Use Your Password. Is Agentic AI Going Too Far?
WordPress "wp2shell" exploit payload analyzed: AI developed this attack | Cybernews
OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Malware is targeting AI tools in software development environments | CyberScoop
White House accuses Chinese company of distilling Anthropic’s Fable | CyberScoop
Bots/Botnets
TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Careers, Roles, Skills, Working in Cyber and Information Security
AI can't fix cybersecurity's hiring problem - Help Net Security
MSSPs have a burnout problem, and pay isn’t the fix | news | MSSP Alert
Cloud/SaaS
Airbus moves critical apps off AWS to a French cloud
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security
The SaaS blind spot: Why security teams can’t get inside their own apps | CSO Online
Malicious cloud customers can bring down the power grid
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
New OkoBot framework deploys 20 payloads to steal data, crypto
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Cruciferra Crypter Uses Process Ghosting to Evade Detection - Infosecurity Magazine
Cyber Crime, Organised Crime & Criminal Actors
US charges two over laundering $43 million from investment fraud
Police take down investment fraud network that stole €100 million a month - Help Net Security
Data Breaches/Leaks
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Ernst & Young Data Breach Affects Personal, Financial Information - SecurityWeek
EY Sued Over Breach Targeting Client Tax, Financial Info - Law360
Lessons Learned: US Cybersecurity Agency Leaked Secrets
23andMe Faces New Security Mandates in $18m Data Breach Settlement - Infosecurity Magazine
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts - SecurityWeek
Estée Lauder discloses data breach via Oracle E-Business flaw
Paidwork breach exposes sensitive data of 23 million users - Help Net Security
Italy fines WINDTRE €1.7 million over security flaws behind two data breaches - Help Net Security
Chick-fil-A discloses data breach after credential stuffing attacks
South Korea discloses data breach impacting diplomats worldwide
Breach of AI music platform Suno affected 55M+ user accounts
Investigation finds no evidence of negligence in Qantas hack – Australian Aviation
Data/Digital Sovereignty
Airbus migrating 70 critical apps from AWS to France's Scaleway amid digital sovereignty push
Denial of Service/DoS/DDoS
AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek
Fraud, Scams and Financial Crime
US charges two over laundering $43 million from investment fraud
Police take down investment fraud network that stole €100 million a month - Help Net Security
Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage
Almost half of fraud cases reported in the first half of 2026 were phone scams (vishing)
Scammers impersonate FBI on social media, prey on crime victims
Fake FBI agents target people who already got scammed - Help Net Security
Suffolk conman targeted elderly to defraud them out of millions - BBC News
Cardiff Covid fraudster jailed over bogus £200,000 loans - BBC News
Fraudster told to repay £5m to Royal Mail or face jail - BBC News
Identity and Access Management
79% of Ransomware Attacks Start with Compromised Identities | Security Magazine
Insider Risk and Insider Threats
North Korea's IT worker scheme funds Russia's war effort | CyberScoop
Internet of Things – IoT
TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All
Your next car's software update could become its biggest security risk - Digital Trends
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Law Enforcement Action and Take Downs
US charges two over laundering $43 million from investment fraud
Police take down investment fraud network that stole €100 million a month - Help Net Security
Police dismantle Kratos phishing platform, arrest developer
Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders - Infosecurity Magazine
Telegram shortlinks knocked offline over sanctioned VPN connection
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
Linux and Open Source
CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
Linux kernel team publishes 432 CVEs in two days
Multi-patch vulnerability fixes can leave open source exposed - Help Net Security
Malware
Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica
Phishing Campaign Hides Lua Loader as TrueType Font File - Infosecurity Magazine
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
New OkoBot framework deploys 20 payloads to steal data, crypto
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Attackers keep using GitHub to distribute malware | Cybernews
Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe | IT Pro
Microsoft warns of surge in ACR Stealer attacks on customers
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
Dangerous new GoSerpent malware is apparently on the hunt for government secrets | TechRadar
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
TrickBot Ditches HTTP for DNS Tunneling in Latest Variant - Infosecurity Magazine
Cruciferra Crypter Uses Process Ghosting to Evade Detection - Infosecurity Magazine
Malware is targeting AI tools in software development environments | CyberScoop
20+ Hijacked Government Websites Became an Attack Channel
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
Brazilian Banking Trojan Actively Spreading in Portugal
Mobile
Google's Gemini lets strangers send messages from your locked Android phone
Fake Bahrain Alert App Deploys Android Surveillance Malware
Models, Frameworks and Standards
Does the Cyber Security and Resilience Bill make you feel secure? | Computer Weekly
How mapping security controls can ease the compliance burden | TechTarget
PR3TACK preemptive framework maps threats before attackers use them - Help Net Security
NCSC ready to open Pathways to a broader set of organisations | UKAuthority
The CMMC 60-day pause: A strategic reset or something much bigger? | perspective | MSSP Alert
Passwords, Credential Stuffing & Brute Force Attacks
79% of Ransomware Attacks Start with Compromised Identities | Security Magazine
AI Agents Can Now Use Your Password. Is Agentic AI Going Too Far?
Chick-fil-A discloses data breach after credential stuffing attacks
Regulations, Fines and Legislation
Does the Cyber Security and Resilience Bill make you feel secure? | Computer Weekly
PYMNTS | Governments Weigh Ransomware Payment Bans
'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar
European Union considers social media ban for children
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
The CMMC 60-day pause: A strategic reset or something much bigger? | perspective | MSSP Alert
France approves social media ban for under-15s - BBC News
Shadow IT
Senior executives abuse shadow AI twice as much as regular employees do | CIO
Employees' shadow AI use is poorly monitored, survey finds | TechTarget
Shadow AI is becoming enterprise security's biggest blind spot - Help Net Security
Social Media
'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar
European Union considers social media ban for children
Scammers impersonate FBI on social media, prey on crime victims
France approves social media ban for under-15s - BBC News
Software Supply Chain
Attackers keep using GitHub to distribute malware | Cybernews
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Malware is targeting AI tools in software development environments | CyberScoop
Supply Chain and Third Parties
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
Estée Lauder discloses data breach via Oracle E-Business flaw
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Finland Accuses Russia of Cyberespionage
Europe exposes Russia’s cyber war
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
North Korea's IT worker scheme funds Russia's war effort | CyberScoop
Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters | SentinelOne
Nation State Actors
China
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
White House accuses Chinese company of distilling Anthropic’s Fable | CyberScoop
China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans - SecurityWeek
Russia
Now, even Russia's most elite hackers are using Clickfix to infect devices - Ars Technica
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Finland Accuses Russia of Cyberespionage
Europe exposes Russia’s cyber war
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
North Korea's IT worker scheme funds Russia's war effort | CyberScoop
Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe | IT Pro
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Russian Hacker Turns Jailbroken Claude Into Pentest Platform - Infosecurity Magazine
Hacker Turns AI Jailbreaks Into Offensive Platform
North Korea
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korea's IT worker scheme funds Russia's war effort | CyberScoop
Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 - Infosecurity Magazine
Iran
Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption
Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters | SentinelOne
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
Tools and Controls
The executive profile your security team isn't defending | CSO Online
Vibe-Coded Apps Riddled With Exploitable Security Flaws - SecurityWeek
The AI code vulnerabilities that grow with your app - Help Net Security
1M+ Emails Use Hidden Text to Dupe AI Security Filters
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Small teams are the heaviest users of AI coding agents - Help Net Security
AI spam filters are getting suckered by old-school text salting
Malware is targeting AI tools in software development environments | CyberScoop
'This is the right call' — VPN industry praises the UK’s decisions to leave VPN alone | TechRadar
The SaaS blind spot: Why security teams can’t get inside their own apps | CSO Online
AI Data Centers Are Being Built Faster Than They Can Be Secured - SecurityWeek
Businesses need to boost cyber resilience, here’s how | IT Pro
Microsoft and OEMs answer Windows 11 Secure Boot questions before the October deadline
SANS Warns of AI Governance Gap as Use by Security Teams Surges - Infosecurity Magazine
AI can't fix cybersecurity's hiring problem - Help Net Security
Why Smarter Cybersecurity Starts with Better Data | Research Communities by Springer Nature
Russian Hacker Turns Jailbroken Claude Into Pentest Platform - Infosecurity Magazine
China's Top Cybersecurity Firms Hit by Mounting Military Procurement Bans - SecurityWeek
Cloud operations become the next big role for agentic AI - Help Net Security
Behavioral biometrics: How to detect nonhuman threat actors | TechTarget
Reports Published in the Last Week
Vulnerability Management
The Windows 10 hangover is becoming a security problem - Help Net Security
Multi-patch vulnerability fixes can leave open source exposed - Help Net Security
AI Can Find Bugs, But Human Knowledge Still Proves Them
Security teams keep finding critical flaws after scheduled testing ends - Help Net Security
N-day is Becoming N-Hour. Patching Faster Won't Save You.
Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Vulnerabilities
New Windows LegacyHive zero-day gives hackers admin privileges
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Attackers target critical FortiSandbox flaws as CISA issues patch order
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Linux kernel team publishes 432 CVEs in two days
New RefluXFS Linux flaw lets attackers gain root privileges
OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider - SecurityWeek
OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates - SecurityWeek
Hackers Exploit PAN-OS Flaw (CVE-2026-0257) to Deploy Qilin
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Inc Ransomware Exploits SonicWall SMA Zero-Days
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation | Volexity
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 17 July 2026
Black Arrow Cyber Threat Intelligence Briefing 17 July 2026:
-UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows
-75% CISOs Fear Executives Don’t Understand Cyber Security Risks Employees Face
-Finance Phishing Works Because It Sounds Boringly Normal
-Microsoft Warns of Increase in Number of Security Updates
-Destructive Windows Backdoor Stuffs Multiple Wipers and Ransomware Code into a Single Package
-Identity Attacks Overtake Exploits as Top Ransomware Cause
-Companies Keep Getting Breached by Vulnerabilities They Already Knew About
-ClickFix Is Changing the Economics of Social Engineering
-AI, Once Relegated to Helping Hackers with Certain Tasks, Can Now Power Every Stage of a Cyber Attack
-Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds
-Russian Hackers Exploit Weak Router Security to Breach Critical Infrastructure, Western Allies Warn
-UK Firms Make Cyber Resilience Measurable
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
We start this week’s review of cyber security in the specialist and general media with news that the UK Government plans to encourage households to keep emergency supplies in case a cyber attack or other crisis disrupts essential services. This aligns with previous reports in which the Government called on businesses to prepare to continue operating if an incident causes the loss of access to technology.
We also report that CISOs are concerned that leadership teams do not fully understand the cyber risks associated with employee behaviour. Other stories highlight evolving phishing techniques, the need to manage a higher volume of security updates, and the continuing development of AI-enabled attacks and ClickFix social engineering campaigns.
A key step in managing these risks is ensuring that leadership teams understand their cyber responsibilities, can oversee risk management effectively and have rehearsed plans for responding to an incident. Contact us to hear how we support organisations across different sectors and of different sizes to achieve this.
Top Cyber Stories of the Last Week
UK Households Told to Stockpile Food, Water and Medicines as Russia Cyber Attack Threat Grows
The UK Government is preparing to launch a national resilience campaign encouraging households to keep basic supplies such as food, water and medicines in case essential services are disrupted by events including a cyber attack. The initiative follows growing concern over threats to critical national infrastructure, including energy, water and communications networks, alongside plans for a national exercise to test the Government's response to a large-scale hybrid attack. For business leaders, the campaign and exercise reinforce the need to consider how disruption to power, water or communications could affect organisational continuity.
https://www.ibtimes.co.uk/uk-government-emergency-preparedness-campaign-1808763
75% CISOs Fear Executives Don’t Understand Cyber Security Risks Employees Face
MetaCompliance has found that many organisations face a growing gap between cyber security leaders and senior executives, with 78% of Chief Information Security Officers believing board-level decision makers do not fully understand the cyber risks created by employee behaviour. Almost 80% said executive support for security awareness declines over time, while 40% are concerned employees are sharing sensitive information with generative AI tools. As AI enables more convincing fraudulent communications at scale, sustained executive engagement and clear governance are becoming essential to strengthening organisational resilience.
https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/
Finance Phishing Works Because It Sounds Boringly Normal
Finance-themed phishing is a common initial access route because malicious messages closely resemble routine business correspondence and fit expected finance and procurement workflows. Cofense found that 59% to 79% of subject lines in campaigns against financial organisations referred to routine operations, while 21% to 41% used urgency. By imitating normal business processes, including invoices, payment confirmations and supplier enquiries, these emails are more likely to evade automated email security tools and persuade employees to open attachments or click malicious links.
https://www.helpnetsecurity.com/2026/07/16/cofense-finance-phishing-tactics-report/
Microsoft Warns of Increase in Number of Security Updates
Microsoft is using AI to identify software weaknesses across Windows more quickly, meaning organisations should expect a higher number of security updates in future. Microsoft says the increase reflects improved identification and remediation of weaknesses. Its multi-model scanning process validates potential findings before they reach engineers, aiming to reduce false positives and shorten the window in which zero-day vulnerabilities can be exploited. Human experts will continue to oversee the process. Business leaders should therefore expect patching demand to increase and ensure that update processes can absorb a higher volume of security releases.
https://www.infosecurity-magazine.com/news/microsoft-increase-number-security/
Destructive Windows Backdoor Stuffs Multiple Wipers and Ransomware Code into a Single Package
Microsoft has identified a new type of destructive malware that combines several attack techniques into a single tool, giving criminals greater flexibility once they gain access to a network. Rather than simply demanding payment, it can overwrite storage, encrypt files so they cannot be recovered, steal information, record user activity and disable recovery features. For business leaders, the combined capabilities broaden the potential impact of a compromise beyond data theft to remote control, permanent system damage and wider operational disruption.
Identity Attacks Overtake Exploits as Top Ransomware Cause
Identity-related attacks have become the leading cause of ransomware, overtaking software vulnerabilities for the first time in three years. Sophos found that malicious emails, phishing and stolen login details accounted for almost three quarters of ransomware incidents, while software vulnerabilities fell to 18% of cases. Although 97% of organisations affected by credential theft had multi-factor authentication in place, attackers were still able to gain access, highlighting that this important security control must be fully deployed and supported by additional measures to detect and respond to suspicious activity.
Companies Keep Getting Breached by Vulnerabilities They Already Knew About
A survey of 300 IT and cyber security leaders found that while organisations have become highly effective at identifying security weaknesses, many still struggle to fix them quickly. Around eight in ten experienced a security incident in the past year linked to a vulnerability already in their inventory, and about half said the relevant weakness had been known for 30 to 90 days. The biggest barriers were unclear ownership, competing business priorities and lengthy approval processes. Organisations requiring a verified follow-up scan before closing a vulnerability reported substantially fewer incidents involving weaknesses they already knew about.
https://www.helpnetsecurity.com/2026/07/16/ciso-vulnerability-remediation-gap/
ClickFix Is Changing the Economics of Social Engineering
ClickFix has evolved into a highly organised cyber crime service that allows even low skilled attackers to launch convincing social engineering campaigns. Rather than exploiting software flaws, victims are tricked into running malicious commands themselves after visiting fake CAPTCHA pages, browser updates or IT support prompts. Attack kits are available on underground forums from around $250 per month, driving a sharp rise in attacks. Researchers also identified 123 previously undetected ClickFix pages, highlighting how these campaigns can bypass traditional security tools and reinforcing the importance of user awareness alongside technical controls.
https://www.helpnetsecurity.com/2026/07/15/clickfix-social-engineering-attacks-report/
AI, Once Relegated to Helping Hackers with Certain Tasks, Can Now Power Every Stage of a Cyber Attack
Artificial intelligence is now being used across every stage of a cyber attack, marking a significant shift from simply assisting with isolated tasks. Research found that criminal groups are using AI to identify security weaknesses, generate malicious code, automate attacks and move through victim networks with far less human involvement. In one case, a single developer used AI to produce around 88,000 lines of working code in under a week. As AI accelerates both the speed and scale of attacks, organisations face much shorter windows to detect and respond to emerging threats.
Ransomware Victims Rise 43% as AI Becomes a Productivity Tool for Threat Actors, GuidePoint Security Finds
GuidePoint Security has reported that ransomware activity has continued to rise, with threat actors claiming 2,279 victims, up 7% on the previous quarter and 43% compared with a year earlier. Researchers identified a record 91 active ransomware groups operating across 108 countries. AI is helping criminals process stolen information and tailor their extortion tactics, rather than creating fundamentally different ransomware attacks. Manufacturing remained the most affected sector, accounting for almost 15% of reported incidents. Business leaders should combine recovery planning with measures to understand what sensitive data could be exposed and reduce how attackers could use it as leverage.
Russian Hackers Exploit Weak Router Security to Breach Critical Infrastructure, Western Allies Warn
Western governments have warned that Russian state-backed hackers continue to target critical infrastructure by exploiting poorly secured routers and other internet connected network devices. The activity has affected organisations across financial services, healthcare, communications, defence, energy, and government. The warning follows an attempted cyber attack against Poland's power grid that could have disrupted electricity supplies to around 500,000 people. The campaign highlights the importance of replacing default passwords, keeping network equipment up to date and monitoring internet facing systems as closely as other critical business assets.
UK Firms Make Cyber Resilience Measurable
ISG reports that UK organisations are embedding cyber security into wider business resilience, with boards increasingly expecting measurable evidence that security investments reduce risk and improve response times. As AI is used by both defenders and attackers, organisations are adopting AI supported detection while maintaining human oversight and clear decision making. Growing concerns over supply chain risk and critical infrastructure are also driving demand for continuous monitoring, real time reporting and integrated security services that strengthen resilience and support regulatory expectations.
https://www.businesswire.com/news/home/20260710009829/en/U.K.-Firms-Make-Cyber-Resilience-Measurable
Governance, Risk and Compliance
U.K. Firms Make Cyber Resilience Measurable
As Global Conflicts Go Digital, Businesses Require Wartime Plans
Technology is driving an increase in online threats to the UK, senior officials say - ABC News
Stop looking for ironclad cybersecurity answers. They often don't exist | PCWorld
What a financial planner taught me about cybersecurity - Help Net Security
Threats
Ransomware, Extortion and Destructive Attacks
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018 - Security Affairs
Ransom demands are down, email is the top way attackers get in - Help Net Security
Identity Attacks Overtake Exploits as Top Ransomware Cause
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand | CSO Online
GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |
New Qilin Ransomware Attack Uses DCSync Technique to Abuse Active Directory Replication Protocols
Everest Ransomware Claims 1 TB Data Theft But Encryptor Shows No Exfiltration Code
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Ransomware ecosystem grows, but ‘four-headed monster’ dominates - TechCentral.ie
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June | IT Pro
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
Former ransomware negotiator gets 4 years for BlackCat attacks
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Ransomware and Destructive Attack Victims
Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek
Phishing & Email Based Attacks
Ransom demands are down, email is the top way attackers get in - Help Net Security
Phishing Toolkits Harvest Entra Tokens in Real Time
New phishing kits target Microsoft 365 accounts, evade MFA
Finance phishing works because it sounds boringly normal - Help Net Security
Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many
Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine
Open Directory Exposes Three Evilginx Phishing Operators - Infosecurity Magazine
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Other Social Engineering
ClickFix and removable media lead malware delivery methods | TechTarget
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
ClickFix is changing the economics of social engineering - Help Net Security
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek
Is that QR code a trap? How to spot quishing scams before it's too late | ZDNET
QR Codes Are the New Security Blindspots That Steal Your Card Details and Deliver Malware
Tech support scam caused massive data breach at Australian airline Qantas
Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many
LastPass, Bitwarden users targeted with fake security alerts
Scammers are using FaceTime to steal bank account passwords - CBS News
2FA/MFA
Only 28% of financial workforce MFA is phishing-resistant - Help Net Security
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop
Money launderer accused of stealing seized crypto while in prison
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
Artificial Intelligence
99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security
AI Is Changing Financial Services Security Faster Than Many Organisations Can Keep Up | Scoop News
Enterprises are rethinking where their AI applications run - Help Net Security
Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready
Risk of democratic interference added to National Risk Register - GOV.UK
What are 'context bombs'? Get familiar with the new cybersecurity tool. | Mashable
AI-assisted Software Engineering Is Creating A New Delivery Paradox
Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine
EU unveils AI cybersecurity action plan for AI and Cybersecurity
You Can't Secure Your Agents If You Can't See Them
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online
Why conversational AI is redefining your security perimeter | TechTarget
Musk promises purge after Grok Build caught sending entire repos to the cloud
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
Bots/Botnets
'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek
Careers, Roles, Skills, Working in Cyber and Information Security
ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight
Cloud/SaaS
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers - SecurityWeek
Phishing Toolkits Harvest Entra Tokens in Real Time
New phishing kits target Microsoft 365 accounts, evade MFA
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup - Help Net Security
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
European Companies Have a Collaboration Security Confidence Gap
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk | CSO Online
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments - Infosecurity Magazine
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Money launderer accused of stealing seized crypto while in prison
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
London teenager who offered crypto advice to terror groups convicted | The Standard
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Cyber Crime, Organised Crime & Criminal Actors
New tutorials on underground hacking forums have roughly doubled - Help Net Security
London teenager who offered crypto advice to terror groups convicted | The Standard
Dutch police bust investment fraud ring stealing over €100 million
Spanish Police take down €140 million cyber fraud ring, arrest four
Police Disrupt a €140M Euro Cyber Fraud Ring in Spain
Russian Cybercrime Trio Indicted In Alleged $62M Scheme
Teen hackers jailed after live streaming cyber attack on TfL - BBC News
Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals
Data Breaches/Leaks
Police suspects Dutch hackers were involved in Odido breach
Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru
Tech support scam caused massive data breach at Australian airline Qantas
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims - SecurityWeek
CISA credential leak prompts tighter security measures | CyberScoop
Musk promises purge after Grok Build caught sending entire repos to the cloud
Centers Laboratory Data Breach Affects 540,000 Individuals - SecurityWeek
Data/Digital Sovereignty
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
Denial of Service/DoS/DDoS
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
Encryption
MEPs fail to prevent Chat Control snoopfest revival
Fraud, Scams and Financial Crime
Scammers are now cloning trusted news websites to steal your money - Digital Trends
Spanish Police take down €140 million cyber fraud ring, arrest four
Dutch police bust investment fraud ring stealing over €100 million
Americans Are Ignoring Scam Calls, But Phishing Emails Still Fool Many
UK charges suspects linked to Russian Coms call spoofing platform
Tech support scam caused massive data breach at Australian airline Qantas
Scammers are using FaceTime to steal bank account passwords - CBS News
Identity and Access Management
Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru
Identity Attacks Overtake Exploits as Top Ransomware Cause
AI Agents Are a New Kind of Identity & Most Orgs Aren't Ready
Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine
A wolf in sheep’s clothing | Professional Security Magazine
Insider Risk and Insider Threats
75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine
Law Enforcement Action and Take Downs
INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang - SecurityWeek
Spanish Police take down €140 million cyber fraud ring, arrest four
Dutch police bust investment fraud ring stealing over €100 million
UK charges suspects linked to Russian Coms call spoofing platform
Police suspects Dutch hackers were involved in Odido breach
London teenager who offered crypto advice to terror groups convicted | The Standard
Teen hackers jailed after live streaming cyber attack on TfL - BBC News
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
764 splinter group leader sentenced to 40 years in jail | CyberScoop
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
Welsh Doxbin admin jailed for egging on swatters from behind a screen
Linux and Open Source
Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine
OpenMandriva Linux says contributor tried to sabotage the project
Malware
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
GigaWiper: The Windows Backdoor Built to Spy, Fake Ransomware and Erase Disks |
Huntress Uncovers 'Vibe-Coded' Malware Used to Map Active Directory Environments - IT Security Guru
ClickFix and removable media lead malware delivery methods | TechTarget
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
New CrashStealer malware poses as Apple crash reporting tool
New MacOS Malware Exploits Legitimate Developer ID - Infosecurity Magazine
Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek
Vibe-Coded Malware Caught in Active Directory Attack - Infosecurity Magazine
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism - SecurityWeek
AI-assisted Software Engineering Is Creating A New Delivery Paradox
222 GitHub Repositories Linked to Fake Go Package Malware Operation
Hackers backdoor Jscrambler npm package with infostealer malware
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Compromised npm Packages in the AsyncAPI Namespace Deliver M...
Mobile
RedHook Android malware now uses Wireless ADB for shell access
US personnel faced phone-tracking campaign during Iran war – FT | Iran International
Models, Frameworks and Standards
EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews
EU unveils AI cybersecurity action plan for AI and Cybersecurity
Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA
New AI Security Charter Backed by Over 70 Cyber Firms - Infosecurity Magazine
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge - SecurityWeek
Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense
Passwords, Credential Stuffing & Brute Force Attacks
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security
Don't let an AI chatbot pick your password, ever | ZDNET
Regulations, Fines and Legislation
EU sues 4 nations for leaving hospitals, banks unprotected | Cybernews
Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine
Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA
Risk of democratic interference added to National Risk Register - GOV.UK
MEPs fail to prevent Chat Control snoopfest revival
More Countries Jump on the Social Media 'Ban Wagon'
Cyber Security Bill amendment to be reintroduced in House of Lords — Hong Kong Watch
Pentagon announces 'immediate suspension' of CMMC Phase II mandates - Breaking Defense
Social Media
More Countries Jump on the Social Media 'Ban Wagon'
Software Supply Chain
222 GitHub Repositories Linked to Fake Go Package Malware Operation
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Cybercriminals Plant Malicious AI Agents in Open Source Tools - Infosecurity Magazine
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek
Ghost Accounts Abuse GitHub API in Mass Recon Campaign - SecurityWeek
Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security
Supply Chain and Third Parties
Lidl Confirms Data Breach After Third-Party IT Provider Hack - IT Security Guru
Manage Vendor Risk in a Few Practical Steps
Edtech gets schooled by third-party cyberthreats | TechTarget
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Stockpile food in case of Russian cyber attack, Government will tell public
EU adopts largest-ever cyber sanctions package against Russia
UK and EU impose sanctions on hacking groups linked to Kremlin | Computer Weekly
Europe is building resilience – but not the kind it needs for war - Friends of Europe
As Global Conflicts Go Digital, Businesses Require Wartime Plans
Government Updates UK’s National Risk Register with Cyber Warnings - Infosecurity Magazine
Nation State Actors
China
China, India-Linked Hackers Both Targeted Same Pakistani Police Force - SecurityWeek
Russia
UK government to warn the public to prepare for a cyberattack | Cybernews
Weak Security Continues to Fuel Russian Cyberattacks
CISA Stresses Router Hardening Against Nation-State Hackers
UK and international allies warn critical sectors over Russian cyber threats | UKAuthority
EU adopts largest-ever cyber sanctions package against Russia
Europe is building resilience – but not the kind it needs for war - Friends of Europe
EU, UK sanction Russian cyberespionage networks over destructive attacks | CyberScoop
NATO Condemns Russian Cyber Attacks, Warns of Reprisals | Newsmax.com
UK, EU officially pin Poland energy cyberattack on Russia
UK charges suspects linked to Russian Coms call spoofing platform
Russian Cybercrime Trio Indicted In Alleged $62M Scheme
North Korea
Cyberattacks against S. Korean military top 18,000 last year: report - The Korea Herald
Iran
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
US personnel faced phone-tracking campaign during Iran war – FT | Iran International
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
London teenager who offered crypto advice to terror groups convicted | The Standard
Teenager convicted of terrorism offences after CTP London investigation | Metropolitan Police
Tools and Controls
75% CISOs Fear Executives Don’t Understand Cybersecurity Risks - Infosecurity Magazine
Tech-xit? UK Steps Up Sovereignty Push Amid AI Strife
NCSC advice on vulnerable routers | Professional Security Magazine
Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek
Only 28% of financial workforce MFA is phishing-resistant - Help Net Security
New Ransomware Exploits Malicious Driver to Remove Security Protection - Infosecurity Magazine
As Global Conflicts Go Digital, Businesses Require Wartime Plans
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique - SecurityWeek
Microsoft Entra ID authentication overhaul to start in September 2026 - Help Net Security
Phishing Campaign Abuses eCards to Deploy RMM Tools - Infosecurity Magazine
AI Coding: Do Security Risks Outweigh Productivity Gains?
The best defense against AI attacks turns out to be a skeptical human - Help Net Security
Why AI 'harnesses' matter more than frontier LLMs for cybersecurity | CyberScoop
Why SBOMs, signing, and provenance still don't tell you if software is safe - Help Net Security
ISC2 Research Finds AI Is Reshaping Cybersecurity Roles and Increasing Human Oversight
VPN service favored by ransomware groups is sanctioned by US | The Record from Recorded Future News
EU launches AI test platform to find cybersecurity flaws | Cybernews
Reports Published in the Last Week
Other News
UK to be told how to prepare for food or water shortages | News UK | Metro News
Cyber-attacks, heatwaves and power cuts: Why Britons are being told to prepare | ITV News
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
When Hackers Cut the Internet, Will the Water Still Flow?
Construction Begins On £1bn Cyber-Security Centre | Silicon UK
Vulnerability Management
Microsoft Warns of Increase in Number of Security Updates - Infosecurity Magazine
99.9% of fixable AI vulnerabilities remain unpatched - Help Net Security
Companies keep getting breached by vulnerabilities they already knew about - Help Net Security
Microsoft is rewriting Windows patch guidance because of AI - Help Net Security
EU launches AI test platform to find cybersecurity flaws | Cybernews
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | CyberScoop
Vulnerabilities
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities - SecurityWeek
Dell PCs are shutting down after Windows 11's July update, Microsoft admits and blocks it
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Fresh SharePoint Vulnerability Exploited Soon After Disclosure - SecurityWeek
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities - SecurityWeek
Adobe Patches Critical ColdFusion Vulnerabilities - SecurityWeek
Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution
Debian 13.6 security update patches over a hundred advisories in trixie - Help Net Security
CISA urges immediate action on actively exploited Fortinet flaws
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates - SecurityWeek
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud - SecurityWeek
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow - SecurityWeek
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Splunk, Zoom Patch Critical Vulnerabilities - SecurityWeek
These 5 Routers Are No Longer Safe To Use After A New Security Backdoor Was Discovered
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer - SecurityWeek
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zoom issues a warning to Windows users about critical security flaw - BetaNews
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 10 July 2026
Black Arrow Cyber Threat Intelligence Briefing 10 July 2026:
-ConsentFix and ClickFix: How Microsoft 365 Accounts Are Hijacked in 3 Seconds
-New Ghost Phishing Wave Is Breaking Traditional Email Security
-Hackers Are Posing as Interpol to Target Small Businesses – Here’s What You Need to Know
-Cyber Experts Issue Alert After Two Ransomware Groups Team Up on ‘Unprecedented’ Threat Campaign
-First Fully Agentic Ransomware Attack Sparks Readiness Concerns
-The AI Vulnerability Storm Is Here: Is Your Security Program Ready?
-Enterprise AI Still Smarting from Leaping Before Looking
-European Central Bank Demands AI Security ‘Action Plan’
-SonicWall Research Finds Financial Services Running Overdrawn on Cyber Defences as Attack Intensity Outpaces Every Other Tracked Industry
-Organisations Struggle to Prioritise Known Cyber Risks
-How Faster Cyber Attacks Are Reshaping Enterprise Cyber Security Strategies
-The Shift Toward Business-Aligned Risk Management
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
There is a temptation to focus on AI related news in cyber security at the expense of discussing the evolution of more established attacks and risks. Although this week we include news on the first fully agentic AI ransomware attack, we start by highlighting other ongoing attacks affecting organisations today that are notable for their speed and tactics in order that business leaders can address them. These include attacks on Microsoft 365 accounts and web browsers, as well as attackers impersonating authorities.
The agentic ransomware development is significant, not because the individual attack tactics are new, but because of the speed at which AI can work through challenges to achieve its objective. This, and other developments, highlight the need for business leaders not only to govern cyber security appropriately, based on risk to reduce the likelihood of an attack, but also to ensure that the leadership team understands how the organisation will respond if or when an attack succeeds.
Our recommendation is for the leadership team itself to participate in a tabletop walkthrough of an evolving attack scenario, led by impartial experts who can challenge assumptions and clarify understandings. This is an Incident Response Exercise that is not an IT activity and should not be designed by any control provider; the objective is for all control providers and the leadership to work through the required response across the organisation for situations where controls fail. This is a very impactful exercise; contact us to discuss how we enable organisations to achieve this in a proportionate manner.
Top Cyber Stories of the Last Week
ConsentFix and ClickFix: How Microsoft 365 Accounts Are Hijacked in 3 Seconds
An attack called ConsentFix builds on the ClickFix technique, where criminals trick users into following familiar online instructions that secretly hand over access. In this case, victims are lured through platforms such as Dropbox or DocSend and shown what appears to be a normal Microsoft 365 sign-in process. Dragging the callback link into the browser can expose OAuth tokens, giving criminals access to Microsoft 365 without the password and despite multi-factor authentication. Because the instructions resemble normal online workflows, staff awareness should be reinforced by monitoring endpoints and identities for suspicious behaviour or logins from unexpected locations.
New Ghost Phishing Wave Is Breaking Traditional Email Security
An EvilTokens phishing campaign affecting organisations in the US and Europe exposes a gap in conventional email checks. Its malicious content remains encrypted during initial inspection and appears only after the link opens in the user’s browser. Victims are then guided through Microsoft’s genuine device-code sign-in process and unknowingly authorise access to Microsoft 365 without surrendering their password. Data from 15,000 organisations puts 2026 phishing exposure at 75.6% in consulting, 72.8% in financial services and 71.9% in manufacturing, showing why security teams need visibility into what webpages do after they load.
https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html
Hackers Are Posing as Interpol to Target Small Businesses – Here’s What You Need to Know
Small businesses in North America, Europe, Asia and the Middle East are receiving phishing emails that impersonate Interpol cyber crime investigators. The emails claim to contain evidence of suspicious activity and pressure recipients into opening a password-protected file hosted on Proton Drive. Instead, the file contains ransomware that tries to encrypt files found on accessible drives before showing victims a ransom demand. Bitdefender found the campaign targeting sectors including finance, technology, legal services, food, agriculture, pharmaceuticals and media. The ransomware is relatively simple, but small businesses remain attractive targets because security responsibilities often fall to employees without specialist support.
Cyber Experts Issue Alert After Two Ransomware Groups Team Up on ‘Unprecedented’ Threat Campaign
Sophos has warned that ransomware groups Vect and TeamPCP are working together in a campaign that combines stolen login details, data theft and ransomware deployment. The partnership, announced in March, shows how cyber criminal groups are increasingly operating like businesses by pooling specialist skills. TeamPCP has compromised trusted open source tools, and Sophos says credentials it obtained have already been used in a Vect ransomware attack. Organisations relying on open source software should keep current records of those tools and check the integrity of third-party updates before rolling them out.
First Fully Agentic Ransomware Attack Sparks Readiness Concerns
Sysdig has identified what it describes as the first fully AI-led ransomware attack, where an AI agent exploited a known weakness in an internet-facing system, stole credentials and encrypted a production database. The techniques were familiar, but the pace was notable: after an unsuccessful login, the AI adapted and succeeded 31 seconds later. Business leaders do not need a different defensive model, but they have less time to intervene. Organisations should reduce exposure of internet-facing services, fix known weaknesses promptly, protect credentials and ensure response teams can contain intrusions before important systems are affected.
The AI Vulnerability Storm Is Here: Is Your Security Program Ready?
The Cloud Security Alliance warns that advanced AI tools could reduce the time between finding a software flaw and exploiting it to just hours. Its report says emerging AI models have already found thousands of serious weaknesses across major operating systems and browsers, creating working attack methods without human guidance. For senior leaders, this changes the risk profile. Patch cycles, incident response and board reporting based on slower, human-led attacks may no longer be realistic. Organisations should identify and segregate critical applications, strengthen basic controls and introduce safe, structured automation to accelerate vulnerability management and incident response.
Enterprise AI Still Smarting from Leaping Before Looking
DigiCert has found that 78% of enterprises using AI have either suffered an AI-related security incident or identified AI-related weaknesses. The survey of 1,001 IT and cyber security leaders in the US, UK and Australia found that the incidents involved unauthorised or incorrectly configured AI agents. While 90% of organisations have discussed AI governance at board level, only half have dedicated budgets and formal programmes, and just 53% can identify which models and source data produced a particular AI decision. This leaves organisations less able to explain unexpected or controversial results.
European Central Bank Demands AI Security ‘Action Plan’
The European Central Bank has given major banks until 31 October 2026 to submit action plans for defending against AI-enabled cyber threats. The regulator warned that AI can identify security weaknesses at speed, making unresolved vulnerabilities more serious for operational resilience. Bank management may therefore need to reconsider technology spending and the people assigned to cyber security. Required actions include faster patching, stronger monitoring and detection, and effective oversight of third parties, with named owners and implementation dates. The ECB also warned that progress in quantum computing threatens traditional encryption and will demand long-term planning and investment.
https://www.computerweekly.com/news/366645712/European-Central-Bank-demands-AI-security-action-plan
SonicWall Research Finds Financial Services Running Overdrawn on Cyber Defences as Attack Intensity Outpaces Every Other Tracked Industry
SonicWall found that financial services faced the highest cyber attack intensity of any sector it tracks in the first half of 2026, with 132,378 intrusion prevention system detections per device, more than double the cross-sector average. The sector also recorded 39,341 malware hits per firewall, second only to healthcare. Many attacks continue to target old, well-understood weaknesses in legacy banking and payment systems. Leaders should examine whether ageing systems and broad access arrangements are leaving known weaknesses unresolved because remediation would interrupt essential services.
Organisations Struggle to Prioritise Known Cyber Risks
Filigran has found that most organisations are collecting more cyber risk data but still lack a clear view of their exposure. Its research found that 93% struggle to maintain an accurate view of their attack surface, meaning the systems and services that attackers could target, while only 41% have a consolidated view of cyber risk. More information is not producing clearer priorities. Organisations need to combine threat intelligence with evidence of which exposures can actually be exploited. Analysts spend an average of 17 hours a week investigating risks later found to be low priority or not exploitable.
https://www.helpnetsecurity.com/2026/07/03/cyber-risk-exposure-report/
How Faster Cyber Attacks Are Reshaping Enterprise Cyber Security Strategies
CrowdStrike’s 2026 Global Threat Report found that the average time taken for an attacker to move from initial access to stealing or damaging data fell to just 29 minutes in 2025, down from 48 minutes in 2024 and 84 minutes in 2022. Attackers are increasingly “logging in” with stolen usernames and passwords rather than breaking in with malware, making attacks harder to spot. As AI accelerates attacks and vulnerability exploitation, organisations need rapid patching, contextual monitoring of account activity and regularly exercised incident response plans.
https://www.infosecurity-magazine.com/news-features/faster-cyberattacks-reshape/
The Shift Toward Business-Aligned Risk Management
Cyber risk management is most useful when it connects security issues to real business consequences. Senior leaders can make better decisions when a technical severity score is translated into the effect of compromising a payment system handling $2 million each day. Organisations are being encouraged to move away from one-off risk assessments and towards a continuous approach that links threats, controls, likely financial impact and treatment options. This lets leaders compare stronger or alternative controls with insurance, recognising that insurance can offset financial loss but does not restart operations or repair damaged customer confidence and regulatory standing.
https://www.securityweek.com/the-shift-toward-business-aligned-risk-management/
Governance, Risk and Compliance
The Shift Toward Business-Aligned Risk Management - SecurityWeek
How Faster Cyber-Attacks Are Reshaping Cybersecurity Strategy - Infosecurity Magazine
You Don’t Get Out Of A Cybersecurity Mess By Writing A Check
Organizations struggle to prioritize known cyber risks - Help Net Security
Immunology And Cybersecurity: Nature's Lessons About Adaptive Defense
Threats
Ransomware, Extortion and Destructive Attacks
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
First fully agentic ransomware attack sparks readiness concerns | TechTarget
Criminals Pose as Interpol in Phishing Emails to Deliver Ransomware - Infosecurity Magazine
Gentlemen Ransomware Expands Global Attack Campaigns
Why this fully agentic ransomware attack is giving researchers nightmares | ZDNET
The Gentlemen Ransomware: What You Need to Know | Fortra
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
Qilin Dominates Ransomware Market - Infosecurity Magazine
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Threat Spotlight: ShinyHunters Fast-Tracks Saas Access with Subdomain Impersonation
Q3 Threat Spotlight: How Automation, Customization, and Tooling Signal Next Ransomware Front Runners
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
Hacked, leaked, and held for ransom: The worst breaches of 2026 so far | TechCrunch
Scattered Spider’s Structure More Like a Cybercrime Collective - Infosecurity Magazine
When Cyberattacks Walk Through the Front Door - Above the Law
US Teenager Arrested In Finland For Scattered Spider Hacks
Ransomware and Destructive Attack Victims
Medtronic Data Breach Impacts 3.8 Million People - SecurityWeek
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Phishing & Email Based Attacks
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access
Hackers are posing as Interpol to target small businesses – here's what you need to know | IT Pro
New Ghost Phishing Wave Is Breaking Traditional Email Security
Phishing poses as big-brand job interview to steal Google accounts
AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection
Multi-channel phishing attacks: How to manage the risk | IT Pro
Messaging fraud trends point to smarter attacks, stronger blocking - Help Net Security
Government and Healthcare Are the Weakest Links in Global Email Security
Armored Likho APT Targeting Government, Electric Power Entities - SecurityWeek
Phishing Attacks Targeted Facebook Users With Fake Verification Offer - Infosecurity Magazine
Other Social Engineering
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access
Fake IT support calls on Microsoft Teams push EtherRAT malware
Entra passkey enrollment vishing targets Microsoft 365 users
Multi-channel phishing attacks: How to manage the risk | IT Pro
Messaging fraud trends point to smarter attacks, stronger blocking - Help Net Security
Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malwarebytes
Fake IT bods on Microsoft Teams coax workers into installing malware
The fake report message that ends with a stolen Reddit account - Help Net Security
When Cyberattacks Walk Through the Front Door - Above the Law
Opera rolls out Paste Protect feature to fight ClickFix attacks
Deepfakes and Vishing: What You Need to Know to Stay Protected | The Motley Fool
2FA/MFA
OAuth, guest accounts, and weak MFA drive SaaS risk - Help Net Security
MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage
Artificial Intelligence
First fully agentic ransomware attack sparks readiness concerns | TechTarget
Warning Over “Industrialized” Cyber-Attacks by Ransomware Gang - Infosecurity Magazine
JadePuffer ransomware used AI agent to automate entire attack
Why this fully agentic ransomware attack is giving researchers nightmares | ZDNET
Bank of England Warns AI Raises Financial Cyber Risks | EasternEye
Enterprise AI still smarting from leaping before looking
Thousands of malicious AI skills found capable of stealing data, running malware - Help Net Security
AI is turning overshared data into a major security risk | perspective | SC Media
European Central Bank demands AI security ‘action plan’ | Computer Weekly
The future of payment fraud could be automated - Help Net Security
Hackers can use 9 of the most popular AI tools to assemble massive botnets - Ars Technica
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target - Infosecurity Magazine
Chinese LLMs Broaden the Gap Between Attackers & Defenders
What an AI ‘cyber nuclear war’ would actually look like | The Independent
How to prioritize AI agent security by business impact - Help Net Security
Indirect Prompt Injection in Web Content Targets AI Agents - Infosecurity Magazine
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
Anthropic Details Claude Fable 5 Cybersecurity Safeguards and Jailbreak Framework
Navigating NIST’s New Cybersecurity AI Frontier
Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) - Help Net Security
French nonprofit starts global intelligence and research hub for AI cyber threats | CyberScoop
AI-driven cyber warfare reshapes global defense readiness | native | MSSP Alert
Deepfake CSAM lawsuit against xAI, Grok expands | CyberScoop
AI is making compliance decisions. Can you prove how? | perspective | MSSP Alert
AI-Generated Malware Powers New Armored Likho APT Campaign
China issues 'backdoor' security alert over Anthropic's Claude Code | Reuters
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Bots/Botnets
Hackers can use 9 of the most popular AI tools to assemble massive botnets - Ars Technica
Google, FBI disrupt NetNut botnet spanning 2M devices | Cybernews
Google disrupts Israel-linked proxy network used to spread malware – Middle East Monitor
Careers, Roles, Skills, Working in Cyber and Information Security
CISO's guide to hiring for the right cybersecurity skills | TechTarget
Cloud/SaaS
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Fake IT support calls on Microsoft Teams push EtherRAT malware
Microsoft 365 users fall victim to one-in-a-million password spray attack – Computerworld
UK’s largest businesses dangerously exposed to cloud outages | Computer Weekly
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target - Infosecurity Magazine
Entra passkey enrollment vishing targets Microsoft 365 users
OAuth, guest accounts, and weak MFA drive SaaS risk - Help Net Security
Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malwarebytes
Fake IT bods on Microsoft Teams coax workers into installing malware
Threat Spotlight: ShinyHunters Fast-Tracks Saas Access with Subdomain Impersonation
FBI targets TeamPCP after massive supply chain attacks | Cybernews
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Vidar Infostealer Hammers SMBs via Malvertising Campaign
New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner - Infosecurity Magazine
Cyber Crime, Organised Crime & Criminal Actors
The future of payment fraud could be automated - Help Net Security
Cybersecurity and the Gap Between Skill and Ability - Schneier on Security
Scattered Spider’s Structure More Like a Cybercrime Collective - Infosecurity Magazine
US Teenager Arrested In Finland For Scattered Spider Hacks
Data Breaches/Leaks
Russia has attacked the United Kingdom – again
Hacked, leaked, and held for ransom: The worst breaches of 2026 so far | TechCrunch
US government says it got hacked — again | TechCrunch
Accenture confirms breach after hacker offers stolen data for sale
Medtronic Data Breach Impacts 3.8 Million People - SecurityWeek
Ransomware and Cyber Extortion in Q1 2026
Hackers claim Deutsche Bank data breach, internal data affected| Cybernews
Data/Digital Sovereignty
Study: Europe's defense runs on American servers - EU Reporter
Fraud, Scams and Financial Crime
The future of payment fraud could be automated - Help Net Security
Messaging fraud trends point to smarter attacks, stronger blocking - Help Net Security
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
Identity and Access Management
Why Identity is the Anchor of the New Digital Frontier
Secret Double Octopus Releases 2026 State of Identity Security in Financial Organizations Report
The Verification Step Is the New ATO Battleground in 2026
Internet of Things – IoT
Google, FBI disrupt NetNut botnet spanning 2M devices | Cybernews
IoT Security Flounders Amid Churning Risk
Law Enforcement Action and Take Downs
Google, FBI disrupt NetNut botnet spanning 2M devices | Cybernews
US Teenager Arrested In Finland For Scattered Spider Hacks
FBI targets TeamPCP after massive supply chain attacks | Cybernews
Google disrupts Israel-linked proxy network used to spread malware – Middle East Monitor
French Police Dismantle Operation Behind the Already Defunct YggTorrent * TorrentFreak
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
A hacker's arrest just revealed how Microsoft can track your Windows device - Digital Trends
Vietnam arrests suspects behind HiAnime anime piracy service
Spain arrests suspected hacker linked to Russian hacktivist campaign | CyberScoop
Linux and Open Source
North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek
Malvertising
Vidar Infostealer Hammers SMBs via Malvertising Campaign
New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner - Infosecurity Magazine
Malware
Warning Over “Industrialized” Cyber-Attacks by Ransomware Gang - Infosecurity Magazine
Vidar Infostealer Hammers SMBs via Malvertising Campaign
New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner - Infosecurity Magazine
North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek
Fake IT support calls on Microsoft Teams push EtherRAT malware
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
Malware authors subvert AI detection systems | CSO Online
FBI targets TeamPCP after massive supply chain attacks | Cybernews
Google disrupts Israel-linked proxy network used to spread malware – Middle East Monitor
Fake IT bods on Microsoft Teams coax workers into installing malware
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
A single malware file can outweigh an entire AI dataset - Help Net Security
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Newly discovered PamStealer isn't your typical macOS malware - Ars Technica
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malwarebytes
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
Armored Likho APT Targeting Government, Electric Power Entities - SecurityWeek
Chinese hackers develop LONGLEASH malware to expand ORB network
AI-Generated Malware Powers New Armored Likho APT Campaign
BusySnake Stealer Slithers into Critical Infrastructure Networks
Mobile
Europe Confirms Record €4.1B Penalty Against Google for Android Practices
I never use fingerprint or Face ID to unlock my phones. Here’s why
RedWing Android Spyware Sold as a Service on Telegram - Infosecurity Magazine
Models, Frameworks and Standards
The cyber law that could change everything | Computer Weekly
Ireland facing major fines over failure to enact cybersecurity law | Business Post
Navigating NIST’s New Cybersecurity AI Frontier
EU Cybersecurity Act 2 Advances Amid Member States' Concerns Over EU Competence | Jones Day
NCSC Launches Cyber Governance Guidance for Management Boards in NIS2 Organisations
UK Govt Pairs Agentic AI Initiative With Cyber Resilience Pledge
Government's cyber pledge lands 60 signatories, including M&S and, somehow, Capita
Outages
UK’s largest businesses dangerously exposed to cloud outages | Computer Weekly
Passwords, Credential Stuffing & Brute Force Attacks
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Russia has attacked the United Kingdom – again
Microsoft 365 users fall victim to one-in-a-million password spray attack – Computerworld
The Verification Step Is the New ATO Battleground in 2026
Regulations, Fines and Legislation
The cyber law that could change everything | Computer Weekly
Ireland facing major fines over failure to enact cybersecurity law | Business Post
Germany plans spy powers to hack attackers | Cybernews
EU Cybersecurity Act 2 Advances Amid Member States' Concerns Over EU Competence | Jones Day
NCSC Launches Cyber Governance Guidance for Management Boards in NIS2 Organisations
Cybersecurity Mission Creep in the US - Schneier on Security
Shadow IT
Social Media
The fake report message that ends with a stolen Reddit account - Help Net Security
Phishing Attacks Targeted Facebook Users With Fake Verification Offer - Infosecurity Magazine
Software Supply Chain
North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Warning Over “Industrialized” Cyber-Attacks by Ransomware Gang - Infosecurity Magazine
FBI targets TeamPCP after massive supply chain attacks | Cybernews
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
Supply Chain and Third Parties
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Why hackers are targeting your digital supply chain, not just your systems
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
What an AI ‘cyber nuclear war’ would actually look like | The Independent
AI-driven cyber warfare reshapes global defense readiness | native | MSSP Alert
NATO 3.0 and energy security: Rebalancing transatlantic defence in Ankara – Middle East Monitor
The US military is not organized for cyber war
Nation State Actors
NATO 3.0 and energy security: Rebalancing transatlantic defence in Ankara – Middle East Monitor
China
What an AI ‘cyber nuclear war’ would actually look like | The Independent
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Chinese hackers develop LONGLEASH malware to expand ORB network
US considers ban on Chinese solar inverters - PV Tech
Suspected Chinese Threat Group Targets Universities - Infosecurity Magazine
Did AI help Palo Alto Networks falsely link the company to China? | Cybernews
Hackers can remotely control Hoymiles solar inverters| Cybernews
Russia
Russia has attacked the United Kingdom – again
BBC Cyber Hack podcast investigates Conti ransomware gang - PodcastingToday
Spain arrests suspected hacker linked to Russian hacktivist campaign | CyberScoop
Alleged pro-Russia hacktivist arrested in Palencia
North Korea
North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Iran
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks - SecurityWeek
From missiles to malware: Why the Gulf is stepping up its operational resilience | Fortune
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
RedWing Android Spyware Sold as a Service on Telegram - Infosecurity Magazine
What is spyware, and how do you protect yourself? | Proton
Predatorgate victims sue spyware maker Intellexa
European Parliament Member Investigating Spyware Was Hacked With Pegasus
Spain arrests suspected hacker linked to Russian hacktivist campaign | CyberScoop
Tools and Controls
Enterprise AI still smarting from leaping before looking
The Shift Toward Business-Aligned Risk Management - SecurityWeek
North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Organizations struggle to prioritize known cyber risks - Help Net Security
Confidential computing's core trust mechanism is broken. The fix may not exist
Anthropic Details Claude Fable 5 Cybersecurity Safeguards and Jailbreak Framework
Malware authors subvert AI detection systems | CSO Online
Why Identity is the Anchor of the New Digital Frontier
How to prioritize AI agent security by business impact - Help Net Security
Gentlemen Ransomware Expands Global Attack Campaigns
The AI vulnerability storm is here: Is your security program ready? | TechTarget
Detection engineering: A programmatic approach to identifying cyber threats | CSO Online
Evaluating secure enterprise browsers vs. security plugins | TechTarget
Data governance is becoming a security services problem | news | MSSP Alert
Chinese LLMs Broaden the Gap Between Attackers & Defenders
The Verification Step Is the New ATO Battleground in 2026
A hacker's arrest just revealed how Microsoft can track your Windows device - Digital Trends
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
AI is making compliance decisions. Can you prove how? | perspective | MSSP Alert
MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage
Non-interactive SSH attacks dominate after login - Help Net Security
Did AI help Palo Alto Networks falsely link the company to China? | Cybernews
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
Reports Published in the Last Week
Secret Double Octopus Releases 2026 State of Identity Security in Financial Organizations Report
Other News
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
NCA Issues Warning to Parents As Shared Child Photos Exploited by AI - Infosecurity Magazine
UAE thwarts ‘sophisticated’ cyberattacks targeting financial sector – Middle East Monitor
US Army websites defaced with pro-Kurdish sentiments, insults to Trump | CyberScoop
Vulnerability Management
Most WordPress sites are outdated, and hackers are noticing | Cybernews
Finding vulnerabilities was never the hard part | CyberScoop
The AI vulnerability storm is here: Is your security program ready? | TechTarget
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws - SecurityWeek
Vulnerabilities
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
Palo Alto Networks Patches 13 Vulnerabilities - SecurityWeek
ClamAV 1.5.3 Open-Source Antivirus Fixes Multiple Security Vulnerabilities
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Critical Gitea Flaw Under Active Exploitation, Researchers Warn - SecurityWeek
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection - SecurityWeek
Chrome 150 Update Patches 27 Vulnerabilities - SecurityWeek
Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) - Help Net Security
Critical Linux KVM vulnerability exposes cloud servers to takeover | Cybernews
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
Wireshark 4.6.7 patches a dozen security flaws - Help Net Security
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 03 July 2026
Black Arrow Cyber Threat Intelligence Briefing 03 July 2026:
-Inside the Inbox: Why Cybercriminals Want to Break into Your Email Account
-Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
-ClickFix Now Cybercriminals' Favourite Malware Delivery Technique
-The Agentic AI ‘Lethal Trifecta’: What CISOs Should Know
-Ransomware Gangs Find Europe’s Weakest Link in Third-Party Suppliers
-Almost Half of Ransomware Victims Have Data Stolen Before They Can Even Detect an Intrusion
-UK Businesses Fear Stigma of Ransomware
-How Ransomware Syndicates Weaponize Corporate-Style Organisation
-Beyond the Perimeter: The Shift to Data-Centric Protection
-Cyber Risk Is Having a Greater Financial and Operational Impact on Businesses: Aon
-2026 Cyber Security Assessment: The Gap Between Awareness and Resilience
-Cyber Risk Falls Flat Without Business Translation
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
In recent weeks, our review of cyber security in the specialist and general media has focused on managing the risks presented by developments in AI. This week, however, our review highlights a greater focus on more traditional threats including email phishing and other social engineering, as well as a reminder of the continued growth in ransomware and the developing tactics of attackers. We also share insights into managing risks from the increasing use of cloud services, SaaS platforms and remote access.
These developments reinforce the need for business leaders to address both cyber security and cyber resilience. This requires cyber security teams to articulate risks in business terms, while business leaders develop sufficient understanding of cyber risk to make informed decisions and engage in informed discussion. Contact us to find out how we support organisations to achieve this in different sectors across the world.
Top Cyber Stories of the Last Week
Inside the Inbox: Why Cybercriminals Want to Break into Your Email Account
Email accounts remain a high-value target because they often provide access to other accounts through password resets, identity verification and connected business systems, including shared drives, finance platforms and customer data. ESET recorded a 36% rise in malicious emails in the second half of 2025 compared with the previous six months, while UK government figures found phishing was the most common form of cyber attack at 38%. Inbox compromise can also support fraud, data theft and ransomware, making strong passwords, multi-factor authentication and regular checks for suspicious forwarding rules important safeguards.
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
Phishing attacks are becoming more targeted, with some campaigns now detecting a victim’s device, browser, language, location and operating system after they click a malicious link. This allows attackers to deliver the most suitable payload, such as different remote access tools for Mac or Windows users, or to mimic trusted brands such as Google, Microsoft Teams, Adobe, DocuSign and Zoom. Cofense warns that this increases the chance of compromise and makes each campaign more profitable, especially where trusted tools are misused to gain remote access.
https://www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os
ClickFix Now Cybercriminals' Favourite Malware Delivery Technique
ClickFix has become the leading technique used by cyber criminals to deliver malware, according to ReliaQuest analysis of attacks between 1 March and 31 May 2026. The technique tricks users into pasting attacker-supplied commands into trusted system tools, often through fake verification pages on compromised websites. This can bypass security tools because the action appears to be performed by the user. The threat now affects both Windows and macOS, with attackers adapting to Apple protections by targeting Script Editor to deliver AMOS malware, which steals browser credentials, session cookies, crypto wallets and keychain data.
https://www.infosecurity-magazine.com/news/clickfix-cybercriminals-favorite/
The Agentic AI ‘Lethal Trifecta’: What CISOs Should Know
Agentic AI can combine access to sensitive data, the ability to read untrusted content and permission to act or communicate externally, creating what some experts describe as a “lethal trifecta” of risk. If poorly controlled, AI agents could expose confidential information, change business systems or be manipulated through hidden instructions known as prompt injection. Organisations should map where AI agents have access, restrict permissions by default, monitor behaviour and apply strong identity controls so agents can only perform approved tasks.
https://www.techtarget.com/searchsecurity/tip/The-agentic-AI-lethal-trifecta-What-CISOs-should-know
Ransomware Gangs Find Europe’s Weakest Link in Third-Party Suppliers
Ransomware activity across Europe is rising, with suppliers and service providers increasingly used as routes into larger organisations. Black Kite reviewed 2,066 incidents across 31 countries and found publicly disclosed cases rose 55% between January and April 2026 compared with the same period in 2025. Germany, the UK, France, Italy and Spain accounted for nearly 70% of incidents, while manufacturing represented 28% of cases. The report also found 64 organisations were compromised through third-party incidents, highlighting how one supplier breach can create wider disruption for many connected businesses.
https://www.helpnetsecurity.com/2026/06/26/black-kite-european-cyber-threats-report/
Almost Half of Ransomware Victims Have Data Stolen Before They Can Even Detect an Intrusion
Ransomware attackers are increasingly stealing data before organisations realise they have been breached. ExtraHop’s Global Threat Landscape Report, based on more than 1,800 IT and security leaders, found that 49% of ransomware victims only detected an attack after data had been stolen, up from 31% last year. Attackers are spending an average of 2.5 weeks inside systems before detection, often by using encrypted channels, valid high-privilege accounts and activity that resembles legitimate workflows to avoid raising alarms. Average ransom payments fell from $3.6 million to $2.8 million, but 83% of surveyed victims still paid.
UK Businesses Fear Stigma of Ransomware
Ransomware is likely being significantly underreported by UK businesses, with many organisations reluctant to disclose attacks due to reputational concerns or fear of criticism, particularly where a ransom has been paid. Between April 2025 and March 2026, 323 UK organisations reported ransomware incidents to Report Fraud, with small and medium-sized organisations accounting for 175 cases. Reported losses totalled £270,000, a figure that may understate the true impact.
https://www.computerweekly.com/news/366645146/UK-businesses-fear-stigma-of-ransomware
How Ransomware Syndicates Weaponize Corporate-Style Organisation
Ransomware groups are increasingly operating like organised businesses rather than isolated criminals. Before shutting down in 2025, the ransomware group Black Basta targeted 520 victims across 39 industries and received at least $107 million in bitcoin payments. Leaked chats show structured teams, outsourced services, performance-based pay and tailored ransom demands based on a victim’s size, finances, sensitive data and cyber insurance policy details. Ransomware is estimated to generate around $74 billion globally each year, meaning organisations need to treat incidents as planned business crises, rehearsing decisions before attackers apply pressure through deadlines, disruption and data exposure.
https://cyberscoop.com/ransomware-syndicates-corporate-organization-op-ed/
Beyond the Perimeter: The Shift to Data-Centric Protection
As organisations use more cloud services, SaaS platforms and remote access, the traditional security boundary around the business has largely disappeared. Data now moves across multiple systems, suppliers and devices, making it harder to protect with network controls alone. A stronger approach focuses on the data itself, using clear ownership, encryption, controlled access, monitoring and recovery planning. This helps organisations reduce the impact of breaches, meet regulatory expectations and maintain business continuity when incidents occur.
Cyber Risk Is Having a Greater Financial and Operational Impact on Businesses: Aon
Cyber risk is having a growing financial and operational impact as businesses become more reliant on cloud services, shared infrastructure and third-party software. Aon warns that incidents now extend beyond data breaches, with losses increasingly linked to business interruption, supply chain disruption, reduced revenue and lengthy recovery periods. AI is also changing the risk landscape, increasing attacker capability while providing organisations with more effective tools for threat detection and response.
2026 Cyber Security Assessment: The Gap Between Awareness and Resilience
Bitdefender’s 2026 Cyber Security Assessment, based on 1,200 IT and security professionals across six countries, highlights a gap between cyber risk awareness and practical resilience. While over 51% believe they have full visibility of approved and unapproved AI use, 47% admit visibility is partial or absent. AI risks dominate concern, yet Bitdefender Labs found that 84% of high-severity attacks abused legitimate tools already present inside organisations. The report also found 55% of breached respondents were told to keep incidents confidential, despite believing authorities should have been notified.
https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html
Cyber Risk Falls Flat Without Business Translation
Cyber risk is a board-level business issue, but boards need technical cyber risks translated into financial and operational impact to support effective decision-making. Verizon’s 2025 breach analysis found ransomware was present in 44% of breaches, third parties were involved in 30%, and attacks exploiting weaknesses rose 34% year on year. While 77% of directors now discuss the financial impact of cyber incidents, only 29% of boards include cyber security expertise. Clearer reporting, focused on cost, downtime, regulation and customer impact, helps boards prioritise action and investment.
https://www.informationweek.com/risk-management/cyber-risk-falls-flat-without-business-translation
Governance, Risk and Compliance
Why Cyber Isn't Just A Risk Issue—It’s A Strategic Execution Issue
Beyond the perimeter: The shift to data-centric protection | TechTarget
From Triangle To Pentagon: The Expanding Scope Of Cybersecurity Leadership
Cyberattacks Are Growing Threat to SMEs – but Insurance Protection Is Low: GlobalData
Cyber risk falls flat without business translation
British public won’t tolerate cyber disruption any more | Computer Weekly
Analysts warn banks that cybersecurity is a bigger bank risk than credit | LSE:LLOY
Threats
Ransomware, Extortion and Destructive Attacks
Major Increase in Ransomware Attacks Targeting Europe, Warns Report - Infosecurity Magazine
UK businesses fear stigma of ransomware | Computer Weekly
Ransomware gangs find Europe's weakest link in third-party suppliers - Help Net Security
Ransomware Resilience: What Happens When You Pay the Ransom? | SC Media UK
How ransomware syndicates weaponize corporate-style organization | CyberScoop
Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
Teens who hacked TfL were known to police years before cyber-attack - BBC News
Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions
FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations
Russian Hackers Accused of Destructive Attack on Jaguar Land Rover - Infosecurity Magazine
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
Microsoft: Two ransomware groups hit SharePoint | Cybernews
BlueHammer Vulnerability Exploited in Ransomware Attacks - SecurityWeek
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
Ransomware and Destructive Attack Victims
Russian Hackers Accused of Destructive Attack on Jaguar Land Rover - Infosecurity Magazine
Hackers target NATO cyber coalition member with data leak threat | Cybernews
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
Medtronic notifies customers impacted by ShinyHunters data breach
Blackfield ransomware asks Nidec Corporation for $2 million ransom
Phishing & Email Based Attacks
Bluekit phishing kit adopts browser-in-the-middle for login theft
This phishing kit looks more like BEC-as-a-service | CyberScoop
EvilTokens device-code phishing kit totally more evil than we all thought
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials - Help Net Security
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails
Inside the inbox: Why cybercriminals want to break into your email account
Business Email Compromise (BEC)/Email Account Compromise (EAC)
This phishing kit looks more like BEC-as-a-service | CyberScoop
EvilTokens device-code phishing kit totally more evil than we all thought
Lessons from the Underground: How to Combat Business Email Compromise
Other Social Engineering
ClickFix Now Cybercriminals' Favorite Malware Delivery Technique - Infosecurity Magazine
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Social engineering: how scammers manipulate their victims | Kaspersky official blog
SIM-swapping gang busted in international police operation - Help Net Security
Scammers race to cash in on Venezuelan earthquake disaster
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Artificial Intelligence
Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
AI-Generated Workflows Are a Silent Security Disaster
The agentic AI 'lethal trifecta': What CISOs should know | TechTarget
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Multiple malicious OpenClaw skills found online - including two macOS infostealers | TechRadar
Five Eyes Urges Organizers to Protect Against Cyber Threats
Agentic AI Has an Identity Problem and Attackers Know It
Does Mythos Have You Worried About AI Attacks? Get The Basics Right
AI-generated code risks reach security, legal, and compliance teams - Help Net Security
Red teamers turned Claude Desktop into a double agent to do their evil bidding
New Enterprise-Ready MCP Specification Brings New Security Challenges - SecurityWeek
Clean GitHub repo tricks AI coding agents into running malware
Chinese Open-Weight AI Model Raises Cybersecurity Worries Over Advanced Capabilities | IBTimes
Simplicity and unity will win the fight against AI cyberattacks | ChannelPro
Palo Alto Networks’ AI Misfire Triggers Cyber Dust-Up at Home
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
New BioShocking attack manipulates AI browser into data theft
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
AI browsers tricked into revealing passwords with a simple method
Anthropic Restores Claude Fable 5 After US Lifts AI Export Restrictions
Why CISOs need to rethink governance in the AI era | perspective | SC Media
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
AI is breaking the case for detection-first security | perspective | MSSP Alert
Securing AI agents: When AI tools move from reading to acting | Microsoft Security Blog
NO FAKES Act advances: What CISOs need to know | TechTarget
Bots/Botnets
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
Microsoft wants to stop unwanted bots from entering Teams meetings - Help Net Security
Careers, Roles, Skills, Working in Cyber and Information Security
Beyond hiring: tackling the cybersecurity skills gap in the age of AI - New Statesman
Want a big tech job? Startups may be your best shot now - here's why | ZDNET
Cloud/SaaS
Hackers target Microsoft 365 accounts with 81 million login attempts
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials - Help Net Security
Massive Password Spray Campaign Targeting Azure CLI - SecurityWeek
Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
Microsoft wants to stop unwanted bots from entering Teams meetings - Help Net Security
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Poland busts SIM-swapping gang tied to millions in crypto theft
SIM-swapping gang busted in international police operation - Help Net Security
Cyber Crime, Organised Crime & Criminal Actors
Chinese Framework Powers 200,000 Scam Sites - SecurityWeek
TfL Hackers Were Known To Police For Years | Silicon UK Tech
FBI and IC3 Warns of Surge of Spoofed FIFA Websites by Cybercriminals
Data Breaches/Leaks
FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations
Hackers Steal Data of 4.38 Million Aflac Japan Customers
Hackers breached DHS information-sharing network, people familiar say - Nextgov/FCW
Hackers target NATO cyber coalition member with data leak threat | Cybernews
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
CMC Releases Analysis and Guidance for Education Sector After Canvas D - Infosecurity Magazine
UK school’s network left wide open for invasion, student found
C2K: New warning to parents over schools cyber attack - BBC News
You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials
Nissan discloses employee data breach linked to Oracle zero-day attacks
Kubota says hackers had month-long access to network systems
Data/Digital Sovereignty
Denial of Service/DoS/DDoS
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Encryption
What the post-quantum executive order really demands of CISOs | CyberScoop
Fraud, Scams and Financial Crime
Chinese Framework Powers 200,000 Scam Sites - SecurityWeek
FBI and IC3 Warns of Surge of Spoofed FIFA Websites by Cybercriminals
Scammers race to cash in on Venezuelan earthquake disaster
US seizes hundreds of FIFA World Cup illegal streaming domains
What the Numbers Say About FIFA 2026 Cyber Risk
Why Cybersecurity Has Become Central to the Modern Sports Experience | Ice Miller - JDSupra
Amazon fined $2.25M for withholding evidence from fraud victims
WhatsApp will warn users before they message a potential scammer - Help Net Security
Identity and Access Management
Why Continuous Identity Verification Is The Future Of Cybersecurity
New spying threats force rethink of biometric identity checks | Biometric Update
Insider Risk and Insider Threats
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
Insurance
Cyberattacks Are Growing Threat to SMEs – but Insurance Protection Is Low: GlobalData
Internet of Things – IoT
Twenty Million US IP Connections Used by Proxy Services - Infosecurity Magazine
Law Enforcement Action and Take Downs
Poland busts SIM-swapping gang tied to millions in crypto theft
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
Microsoft uses AI to link two malware operations in racketeering suit
Montenegro police arrest Iranian accused of hacking US universities | Euronews
US seizes hundreds of FIFA World Cup illegal streaming domains
TfL Hackers Were Known To Police For Years | Silicon UK Tech
Linux and Open Source
After Fable 5 ban, Anthropic and 19 organizations launch open source security body - The New Stack
DirtyClone: A Linux Privilege Escalation That Leaves No Trace on Disk
Malware
RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
ClickFix Now Cybercriminals' Favorite Malware Delivery Technique - Infosecurity Magazine
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Multiple malicious OpenClaw skills found online - including two macOS infostealers | TechRadar
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
119 Edge extensions promised useful tools, instead downloaded malware | Malwarebytes
Veil#Drop Uses Google Blogspot to Deploy PureLog Stealer - Infosecurity Magazine
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
New ChocoPoC malware targets researchers via trojanized PoC exploits
Microsoft uses AI to link two malware operations in racketeering suit
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
Clean GitHub repo tricks AI coding agents into running malware
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
Mystery hackers use novel SharkLoader dropper against governments, software devs - Help Net Security
Malware-Laced USBs Breach Japanese Military Networks
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Hackers have a new way to disable Mac security software | Macworld
Critical SimpleHelp Vulnerability Exploited for Malware Delivery - SecurityWeek
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Russian APT Deploys 'StockStay' Backdoor Against Ukrainian Targets - SecurityWeek
Telegram-Based Millenium RAT Campaign Infects 60,000 Devices - Infosecurity Magazine
Mobile
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Over 5 Billion iPhones And Android Devices Are Vulnerable To This Massive New Threat
Poland busts SIM-swapping gang tied to millions in crypto theft
SIM-swapping gang busted in international police operation - Help Net Security
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools - Security Affairs
Even the Secret Service won't use company-issued phones
Models, Frameworks and Standards
ISO 27001 or NIST CSF: Which Is Right for Your Business? - Security Boulevard
UK cybersecurity managers question speed-focused certification programs | SC Media UK
Half the defense base still builds security around compliance - Help Net Security
Passwords, Credential Stuffing & Brute Force Attacks
Hackers target Microsoft 365 accounts with 81 million login attempts
Bluekit phishing kit adopts browser-in-the-middle for login theft
FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials - Help Net Security
Massive Password Spray Campaign Targeting Azure CLI - SecurityWeek
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
AI browsers tricked into revealing passwords with a simple method
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials
AI may be good at finding security vulnerabilities, but it can't beat human stupidity
Regulations, Fines and Legislation
Anthropic Restores Claude Fable 5 After US Lifts AI Export Restrictions
The legislative challenges of cybersecurity | IT Pro
The King’s Speech: What CISOs Should Know | SC Media UK
Amazon fined $2.25M for withholding evidence from fraud victims
NO FAKES Act advances: What CISOs need to know | TechTarget
FCC passes new cybersecurity rules for emergency systems, undersea cables | CyberScoop
Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling | CyberScoop
UK journalists and NGOs risk terrorism prosecutions under new security bill | Middle East Eye
Half the defense base still builds security around compliance - Help Net Security
Software Supply Chain
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
Clean GitHub repo tricks AI coding agents into running malware
Mystery hackers use novel SharkLoader dropper against governments, software devs - Help Net Security
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Hiding in Plain Sight: The Geopolitics of Software Supply Chains
Supply Chain and Third Parties
Ransomware gangs find Europe's weakest link in third-party suppliers - Help Net Security
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
Nissan discloses employee data breach linked to Oracle zero-day attacks
Third-Party Breaches Teach Schools a Costly Lesson in Vendor Risk
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Hiding in Plain Sight: The Geopolitics of Software Supply Chains
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Russia's 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
'No Ceasefire In Cyberspace:' Israel Says Iran-Linked Cyberattacks Nearly Tripled In June - Benzinga
Iran cyberattacks on Israel surged in 2026, Israeli cyber chief says - CNA
Iranian cyberattacks on Israel have nearly tripled cyber chief says | The Jerusalem Post
Iran, Russia, China Target Water Systems for Sabotage
Russian Water System Hack Attempted to Turn Canada Dry
Four years into Ukraine invasion, Russia turns influence-ops back to US and Europe
New spying threats force rethink of biometric identity checks | Biometric Update
Nation State Actors
Hiding in Plain Sight: The Geopolitics of Software Supply Chains
Iran, Russia, China Target Water Systems for Sabotage
China
Malware-Laced USBs Breach Japanese Military Networks
Iran, Russia, China Target Water Systems for Sabotage
Chinese Open-Weight AI Model Raises Cybersecurity Worries Over Advanced Capabilities | IBTimes
Chinese Framework Powers 200,000 Scam Sites - SecurityWeek
Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Russia
Russian Intelligence Services Continue to Target Commercial Messaging Applications | CISA
FBI: Russian hackers now target Signal backup recovery keys
Iran, Russia, China Target Water Systems for Sabotage
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Russian Water System Hack Attempted to Turn Canada Dry
Four years into Ukraine invasion, Russia turns influence-ops back to US and Europe
SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel
US offers $10 million for info on group behind Signal and WhatsApp hacking spree - Ars Technica
Russian Hackers Accused of Destructive Attack on Jaguar Land Rover - Infosecurity Magazine
Ireland retains out-of-date air navigation systems in response to Russian jamming – The Irish Times
Iran
Iran, Russia, China Target Water Systems for Sabotage
'No Ceasefire In Cyberspace:' Israel Says Iran-Linked Cyberattacks Nearly Tripled In June - Benzinga
Iran cyberattacks on Israel surged in 2026, Israeli cyber chief says - CNA
Iranian cyberattacks on Israel have nearly tripled cyber chief says | The Jerusalem Post
Montenegro police arrest Iranian accused of hacking US universities | Euronews
Major Cybersecurity Failure: Four Largest Iranian Banks Face 3rd Week of Outages
Tools and Controls
UK cybersecurity managers question speed-focused certification programs | SC Media UK
Claude Sonnet 5 includes safeguards against dangerous cyber use - Help Net Security
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
AI Decline? Confidence Falls in Autonomous Penetration Testing
Cyberattacks Are Growing Threat to SMEs – but Insurance Protection Is Low: GlobalData
Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse
OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI - SecurityWeek
The AI Token Costs That Can Break Cybersecurity - SecurityWeek
Hackers have a new way to disable Mac security software | Macworld
Why Continuous Identity Verification Is The Future Of Cybersecurity
Chinese Open-Weight AI Model Raises Cybersecurity Worries Over Advanced Capabilities | IBTimes
Even the Secret Service won't use company-issued phones
Microsoft uses AI to link two malware operations in racketeering suit
Palo Alto Networks’ AI Misfire Triggers Cyber Dust-Up at Home
Securing AI agents: When AI tools move from reading to acting | Microsoft Security Blog
Confidential Computing In The AI Era
Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Other News
Critical infrastructure under attack - NCSC CEO | UKAuthority
UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks - Infosecurity Magazine
Cybersecurity beyond blocking: A call for collaboration
British public won’t tolerate cyber disruption any more | Computer Weekly
Healthcare leaders see a fatal cyber incident as inevitable - Help Net Security
Irish Examiner view: Urgent action needed on cyber threats
When Cyber-Physical Risk Becomes A Life-Safety Threat
To defend against hybrid attacks, governments should team up with the private sector – POLITICO
Vulnerability Management
Linux Foundation Unveils New Open Source Security Project Akrites - SecurityWeek
After Fable 5 ban, Anthropic and 19 organizations launch open source security body - The New Stack
A crucial Windows security certificate just expired - how to check your PC | ZDNET
New Initiative Secures End-of-Life Open Source Software
Vulnerability reports are arriving faster than GitHub can review them - Help Net Security
Modernizing Global Vulnerability Standards For The Age Of AI
Apple Reverses Age-Old Patch Policy to Keep Up With AI
Why patch directives only go so far | CyberScoop
Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
Vulnerabilities
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure - SecurityWeek
Cisco finally confirms attackers exploiting Unified CM flaw
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
Adobe patches seven max severity ColdFusion, Campaign flaws
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
macOS Flaw Lets Standard Users Disable EDR and MDM - Infosecurity Magazine
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple rushed to squash 29 bugs because AI is supercharging hackers - update ASAP | ZDNET
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Over 5 Billion iPhones And Android Devices Are Vulnerable To This Massive New Threat
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
BlueHammer Vulnerability Exploited in Ransomware Attacks - SecurityWeek
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Chrome 150 fixes nearly 400 security flaws, including 15 critical ones | PCWorld
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
'DirtyClone' Linux Kernel Vulnerability Leads to Root Access - SecurityWeek
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Critical SimpleHelp Vulnerability Exploited for Malware Delivery - SecurityWeek
Synology issues critical fix for MailPlus Server vulnerabilities - Help Net Security
Anonymous researcher drops 0-day 'exploitarium' repo
Researcher Explains Release of Undisclosed Zero-Day Exploits - Infosecurity Magazine
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Advisory 30 June 2026: Attackers Abuse Trusted Platform Invitations to Impersonate Organisations
Black Arrow Cyber Advisory 30 June 2026: Attackers Abuse Trusted Platform Invitations to Impersonate Organisation
Organisations should be alert to a developing tactic in which attackers create fake workspaces on trusted software platforms and invite employees to join them using legitimate platform emails. Although this activity has recently been seen targeting cyber security and technology firms, the approach could quickly be adapted for other sectors, particularly where staff use artificial intelligence tools, collaboration platforms, cloud services or shared project spaces.
In a reported campaign, attackers created an OpenAI organisation that impersonated a legitimate company, then invited selected employees using their work email addresses. The invitations were sent from OpenAI’s genuine notification system, passed normal email authentication checks and looked like standard invitations to join a company workspace. This makes the approach more difficult to detect than traditional phishing, where attackers often rely on spoofed emails, suspicious links or lookalike domains.
The risk is not simply that an employee joins the wrong workspace. The concern is what happens next. If staff believe they are using an approved company environment, they may submit sensitive information into chats, prompts or project spaces. This could include internal documents, client information, source code, security research, strategy papers, commercial plans or other confidential material. In this case, the fake workspace had been made to look more credible by using the target company’s name, targeting specific employees, assigning them senior access rights and attaching a payment card to the billing account.
This reflects a wider shift in attacker behaviour. Rather than only sending malicious files or links, attackers are increasingly abusing legitimate features inside widely used online services. Invitations, notifications and shared workspace requests can come from real platforms and therefore may bypass technical email controls. The trust employees place in familiar brands and normal business workflows is being exploited.
What firms should do
Organisations should remind employees that a genuine email from a trusted platform does not always mean the workspace, project or invitation is legitimate. Staff should be told to verify any unexpected invitation to join a company workspace, especially where the request relates to artificial intelligence, file sharing, collaboration tools or administrative access.
Security and IT teams should review the technical solutions available to them to help manage this risk, for example SSPM platforms as well as how official company workspaces are named, managed and communicated to staff. Where possible, organisations should maintain an approved list of authorised platforms and tenants, and make it easy for employees to check whether an invitation is genuine. Unexpected invitations should be reported through existing security channels before being accepted.
Firms should also monitor membership and administration activity across software as a service platforms. This includes checking for unusual organisation invitations, unexpected owner or administrator permissions, and employees joining external workspaces that impersonate the business. Where platforms support domain verification, single sign on or tenant restrictions, these controls should be enabled.
For senior leaders, this is a reminder that cyber risk now extends beyond email and endpoint security. Attackers are targeting the everyday tools employees use to work, collaborate and experiment with artificial intelligence. Clear ownership of approved platforms, simple verification processes and staff awareness can significantly reduce the chance of sensitive company information being handed to an attacker through a trusted service.
Black Arrow Cyber Threat Intelligence Briefing 26 June 2026
Black Arrow Cyber Threat Intelligence Briefing 26 June 2026:
-GentleKiller Framework Disables Victims' Security Software
-What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks
-Experts Warn: Passwords Still Winning Despite Passwordless Push
-What 22,000 Breaches Teach Us About Incident Preparedness
-The AI Shift in Cyber Risk: Why Leaders Must Act Now
-Why Knowing the Risk Isn’t the Same as Being Ready for It
-Confidence Lacks in Threat Detection Across Non-Email Channels Like Slack and Teams
-Repeated Cyber Disruption Costing SMEs Up to €3.4Bn Annually
-Businesses Are Expecting Catastrophic Cyber Incidents: 65% Think a Serious Cyber Attack Could Threaten Survival
-Professional Services Firms the ‘Flavour of the Month’ for Cyber Attacks
-Only 7% of Companies Are Ready for the AI Agents They Deployed
-Stressors, AI Forcing Changes to Cyber Security Teams
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
In our review of cyber security threat intelligence this week, we start with details of emerging and evolving threats. The ransomware group called The Gentlemen, which we referenced earlier this month, has developed a toolkit that disables victims’ security tools before encrypting data, while another group called ShinyHunters is increasingly seen using stolen credentials and trusted third-party access paths to reach victims.
Business leaders are recognising the risks from these and other tactics: we report that 65% of organisations believe a serious cyber attack could threaten their survival, and we include perspectives on the need for business leaders to convert this awareness into preparation for an attack, including as the risks accelerate due to AI and the routes of entry widen beyond emails to include other communications channels.
The next steps for business leaders are clear: take an impartial look at what needs to be protected and the risks, and establish controls to address those risks through a structured framework. The key is achieving objectivity and proportionality, by an upskilled leadership team working with impartial experts to define the required security contributions from the organisation’s control providers across technology, people and operations. Contact us to discuss how we can support you in achieving this.
Top Cyber Stories of the Last Week
GentleKiller Framework Disables Victims' Security Software
ESET has identified GentleKiller, a toolkit used by The Gentlemen ransomware group to disable victims’ security tools before data is encrypted. The framework targets more than 400 processes across around 48 security products, including major endpoint protection platforms. It abuses trusted but flawed software drivers to gain deep system access and disable security software before encrypting data. The group has built at least eight variants and offers affiliates a 90% share of ransom payments, reflecting a more organised and service-driven ransomware model.
https://www.infosecurity-magazine.com/news/gentlekiller-gentlemen-ransomware/
What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks
Recent ShinyHunters breaches show that attackers no longer need malicious software or unknown software flaws to cause major harm. Incidents linked to organisations including the University of Nottingham, DentaQuest, 7-Eleven, Medtronic and Wynn Resorts point to a growing focus on stolen logins, MFA fatigue attacks and trusted third-party access. Once criminals gain valid credentials or digital tokens, which act like temporary access passes, their activity can look legitimate. For senior leaders, this reinforces the need to treat identity and access as a core cyber security risk, not just an IT control.
https://www.securityweek.com/what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks/
Experts Warn: Passwords Still Winning Despite Passwordless Push
Passwords remain the most widely exploited attack surface despite growing adoption of passwordless technology. Since the start of 2025, more than 16 billion passwords have been compromised globally, while credential abuse now accounts for 22% of breaches. Brute force attacks, where criminals repeatedly try login combinations, have almost tripled in the past year. Passkeys and phishing-resistant authentication offer stronger protection, but adoption remains uneven due to legacy systems, user change challenges and inconsistent platform support. For many organisations, passwords and passkeys will need careful governance side by side for some time.
What 22,000 Breaches Teach Us About Incident Preparedness
Verizon’s 2026 Data Breach Investigations Report reviewed more than 22,000 confirmed breaches across 145 countries and highlights a growing gap between attack speed and organisational readiness. Ransomware appeared in 48% of breaches, while incidents involving suppliers or service providers rose by 60%. Exploitation of software vulnerabilities became the leading route into organisations, with critical fixes taking a median of 43 days. The findings reinforce the need for organisations to strengthen vulnerability management, third-party risk management and regular incident response exercises that test operational disruption, supplier failures and executive decision making before a real breach occurs.
The AI Shift in Cyber Risk: Why Leaders Must Act Now
Five Eyes cyber security agencies have warned that artificial intelligence is rapidly changing cyber risk, with the impact expected to intensify in months rather than years. AI is helping attackers move faster, increasing the speed, scale and complexity of threats, while also offering defenders stronger tools to spot weaknesses and respond earlier. For senior leaders, cyber risk is a core business issue linked to operational continuity, market confidence and reputation. Priorities include reducing unnecessary system access, patching faster, addressing outdated technology, strengthening access controls and testing incident response plans before disruption occurs.
https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now
Why Knowing the Risk Isn’t the Same as Being Ready for It
UK businesses are more aware of cyber security risk than ever, but many remain underprepared. The latest Cyber Security Breaches Survey found only 19% of businesses ran staff training in the past year. Firebrand research also found just 27% of UK organisations are fully prepared for AI-powered cyber attacks, while nearly half experienced at least one attack in the past 12 months. The cost of the most disruptive breach commonly fell between £100,000 and £199,999 once downtime, recovery, regulatory exposure and reputational damage were included. The findings highlight the importance of regular training and recognised cyber security certification to strengthen organisational resilience.
https://www.emergingrisks.co.uk/why-knowing-the-risk-isnt-the-same-as-being-ready-for-it/
Confidence Lacks in Threat Detection Across Non-Email Channels Like Slack and Teams
KnowBe4 research found that many organisations lack confidence in detecting threats across workplace messaging and collaboration tools. In a survey of 169 cyber security professionals at Infosecurity Europe 2026, 50% said they lacked strong confidence in spotting threats across channels such as Slack, Microsoft Teams, social media and WhatsApp, while 60% said cyber attacks were already moving beyond email. Phishing emails remained the biggest perceived threat, selected by 61% of respondents. Training was also inconsistent, with just 41% regularly covering non-email threats.
https://www.infosecurity-magazine.com/news/threat-detection-across-nonemail/
Repeated Cyber Disruption Costing SMEs Up to €3.4Bn Annually
New research from telecoms provider eir Business estimates that cyber attacks cost Irish SMEs up to €3.4 billion each year, with much of the impact driven by repeated everyday disruption rather than major one-off breaches. The report found that SMEs with stronger cyber preparedness reduced annual downtime from more than 30 days to around five. It also found that a structured data management strategy reduced the likelihood of experiencing an attack from 40% to 24%.
https://www.techcentral.ie/repeated-cyber-disruption-costing-smes-up-to-e3-4bn-annually/
Businesses Are Expecting Catastrophic Cyber Incidents: 65% Think a Serious Cyber Attack Could Threaten Survival
Databarracks reports that 65% of organisations now believe a serious cyber attack could threaten their survival, following a series of high-profile cyber incidents. Cyber incidents remain the leading cause of IT downtime and data loss for the fourth year running, with 30% citing them as their biggest cause of downtime and 43% of large organisations reporting data loss. The proportion of organisations reporting AI-enabled attacks more than doubled to 25%. Encouragingly, 59% of ransomware victims recovered from backups, while only 18% paid a ransom.
Professional Services Firms the ‘Flavour of the Month’ for Cyber Attacks
Professional services firms, particularly law firms, are currently a prominent target for cyber attacks due to the sensitive client information they hold, including merger activity, trade secrets and employment matters. Attackers are increasingly using phishing and social engineering to trick staff into granting remote access, then quietly stealing data for extortion rather than encrypting systems. The risk is not limited to large firms, with organisations of all sizes exposed. Strong response planning, clear decision-making roles and a culture where staff report mistakes quickly are essential to responding effectively and reducing the impact of an incident.
https://www.cityam.com/professional-services-firms-the-flavour-of-the-month-for-cyberattacks/
Only 7% of Companies Are Ready for the AI Agents They Deployed
Veeam reports that although 88% of organisations are now running or piloting AI agents, only 7% are fully prepared to manage the risks of the AI agents they have deployed. Many are relying on poor quality or fragmented data, while responsibility for oversight is often unclear. The report warns that AI agents acting on poor-quality data can repeat errors across thousands of decisions before they are detected. The report also highlights widespread use of unapproved AI tools by employees, with only a quarter of organisations providing approved options for everyone.
https://www.helpnetsecurity.com/2026/06/23/ai-trust-gap-research/
Stressors, AI Forcing Changes to Cyber Security Teams
A new ISSA and Omdia survey highlights growing pressure on cyber security leaders, with 68% of cyber security and IT professionals saying their role is harder than two years ago. More than half cite rising complexity, heavier workloads and more overwhelming threats. AI is adding to the challenge, particularly through shadow AI, where employees adopt AI tools without the security team's knowledge, reducing visibility and control. At the same time, 37% already use AI to support cyber security work and 46% plan to, while demand for fractional cyber security leaders is increasing as organisations seek expert guidance without a full-time appointment.
https://www.darkreading.com/cybersecurity-operations/stressors-ai-changes-cybersecurity-teams
Threats
Ransomware, Extortion and Destructive Attacks
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Human Cost of Ransomware: Why CISOs Must Think Beyond Technology - Infosecurity Magazine
What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks - SecurityWeek
What 22,000 breaches teach us about incident preparedness | CSO Online
New 'Mistic' RAT Opens Door to Several Ransomware Families - SecurityWeek
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
ShinyHunters Targets Oracle PeopleSoft Customers Through Critical Zero-day
New Prinz Eugen ransomware prioritizes recent files for encryption
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage - Infosecurity Magazine
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Ransomware and Destructive Attack Victims
How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack - BBC News
Novo Nordisk Breach Exposes Software Development Pipeline Risk
Amazon’s One Medical hit by data breach claims | Cybernews
Phishing & Email Based Attacks
Confidence Lacks in Threat Detection Across Non-Email Channels - Infosecurity Magazine
EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps
Phishing hides in routine Microsoft 365 workflows - Help Net Security
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Other Social Engineering
He Thought He Was Secure; His Phone Number Was Stolen Anyway
New macOS ClickFix attack silently mounts DMGs to push infostealer
Gizmodo readers hit with ClickFix malware prompts after account compromise
2FA/MFA
He Thought He Was Secure; His Phone Number Was Stolen Anyway
Artificial Intelligence
Only 7% of companies are ready for the AI agents they deployed - Help Net Security
Change your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOs | CSO Online
Society has ‘months, not years’ to prepare for major AI cyberthreats – PublicTechnology
Trust is the target: the new AI-era supply-chain attacks
Anthropic's Mythos AI broke into almost all NSA classified systems in hours
Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics
The AI shift in cyber risk: why leaders must act now | National Cyber Security Centre
Get Ready for a Catastrophic Leak That Reveals All Your Messages and Search History
A public Sentry key is all it takes to hijack Claude Code, Cursor, and Codex - The New Stack
Stressors, AI Forcing Changes to Cybersecurity Teams
Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
AI Is Making Attacks Cheaper, Faster and More Covert, Says ReliaQuest - Infosecurity Magazine
Cybercriminals Are Worried About AI Taking Their Jobs Too - Infosecurity Magazine
Microsoft links Mastra AI supply chain attack to North Korean hackers
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
Cybersecurity was built for predictable systems. AI changes the rules | CSO Online
Researchers Trick AI Browsers Into Leaking Credentials - Infosecurity Magazine
More Malicious OpenClaw Skills Threaten AI Supply Chain
Amateur Hacker Used Claude And OpenAI Agents To Hack 14 Companies
When Information Becomes the Attack Surface - Understanding AI Agent Traps - SecurityWeek
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
AI risks triggering ‘catastrophic’ phone network blackouts
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps - SecurityWeek
Police risk being outwitted by criminals using AI, says Met chief
macOS Backdoor Uses Prompt Injection to Evade AI Triage - Infosecurity Magazine
The New Energy War: Why The AI Grid Is The New Battleground
AI Shopping Agents Pose Novel Liability, Authorization Risks
PYMNTS | AI Is Now the Threat Banks Must Plan Around
Most teams will ship AI-written infrastructure code with little review - Help Net Security
Bots/Botnets
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown - SecurityWeek
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
Careers, Roles, Skills, Working in Cyber and Information Security
Stressors, AI Forcing Changes to Cybersecurity Teams
Cloud/SaaS
Phishing hides in routine Microsoft 365 workflows - Help Net Security
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor
Cyber Crime, Organised Crime & Criminal Actors
Cybercriminals Are Worried About AI Taking Their Jobs Too - Infosecurity Magazine
Algerian man charged with running two cybercrime marketplaces | CyberScoop
One-two punch delivered in global operation disrupts cybercrime "assembly line" - Ars Technica
In a first, a court takedown goes after two cybercrime tools at once | CyberScoop
Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
Police risk being outwitted by criminals using AI, says Met chief
Civilians behind international police probe into Russian cybercriminals - National | Globalnews.ca
Data Breaches/Leaks
Get Ready for a Catastrophic Leak That Reveals All Your Messages and Search History
124 Million Unique Passwords Exposed In New Infostealer Log Dataset
Klue Hack Leads to Data Breach Across Multiple Cybersecurity Companies
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
24 Billion Stolen Credentials Exposed in Massive Data Leak - Security Affairs
Amazon’s One Medical hit by data breach claims | Cybernews
Hackers claim they stole a million records belonging to Canada Life users | Cybernews
Klue OAuth breach victim list grows as Icarus hackers claim attack
LastPass suffers another data breach, but this time your password vault is safe - Digital Trends
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps - SecurityWeek
Texas govt data breach exposes over 3 million driver’s licenses
I Traced My Leaked Email Address to the Dark Web. Here's How It Got There
HCRG Care Group cyber attack leaves patient 'fuming' - BBC News
Texas Parks & Wildlife Data Breach Affects 3 Million Individuals - SecurityWeek
Xsolis Data Breach Affects 1.4 Million Individuals - SecurityWeek
Data Protection
Britain's privacy watchdog quits after 'poor judgment' admission
Encryption
Trump Orders US to Speed Quantum Adoption, Boost Cyber Defenses
Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration - SecurityWeek
Fraud, Scams and Financial Crime
Imposter Scams Cost Americans $3.5 Billion in 2025 - and It's Getting Worse
Inside the dark web: Stolen identities for 95¢, malware, and scams-for-hire | Malwarebytes
GTA 6 Scams Emerge as Pre-Orders Open - Infosecurity Magazine
Warning over Grand Theft Auto VI scam which could drain bank accounts - Birmingham Live
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Identity and Access Management
How World Cup Password Trends Can Increase Active Directory Risk - Infosecurity Magazine
Internet of Things – IoT
How Chinese cars became a national security issue in Israel | Ctech
Residential proxy SDKs are hiding in LG and Samsung smart TV apps - Help Net Security
Law Enforcement Action and Take Downs
Scattered Spider members plead guilty to hacking Transport for London
Algerian man charged with running two cybercrime marketplaces | CyberScoop
In a first, a court takedown goes after two cybercrime tools at once | CyberScoop
Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown - SecurityWeek
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Civilians behind international police probe into Russian cybercriminals - National | Globalnews.ca
Nathan Austad Pleads Guilty in DraftKings Hacking Scheme, Gets 18 Months
DraftKings hacker 'Snoopy' sentenced to 18 months in prison
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
Police risk being outwitted by criminals using AI, says Met chief
Linux and Open Source
Linux users face a Microsoft Secure Boot headache - here's the painkiller | ZDNET
Open-source security is posing challenges governments can't easily solve | CyberScoop
Backporting bug fixes is dead, Project Valkey now sends in the bots - The New Stack
Malware
124 Million Unique Passwords Exposed In New Infostealer Log Dataset
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
New 'Mistic' RAT Opens Door to Several Ransomware Families - SecurityWeek
Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware
macOS Backdoor Uses Prompt Injection to Evade AI Triage - Infosecurity Magazine
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
One-two punch delivered in global operation disrupts cybercrime "assembly line" - Ars Technica
Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor
New macOS ClickFix attack silently mounts DMGs to push infostealer
Gizmodo readers hit with ClickFix malware prompts after account compromise
A CISO's guide to infostealers: Prevention and detection | TechTarget
Japan defense forces used USB drives with China-linked virus: Nikkei investigation - Nikkei Asia
Malicious Edge extension abuses Native Messaging as bridge to malware
ShapedPlugin update flow hacked to infect WordPress sites
Mobile
He Thought He Was Secure; His Phone Number Was Stolen Anyway
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps - SecurityWeek
Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Google sets timeline for Android developer verification enforcement - Help Net Security
Companies are profiling you from your smartphone use - how to stop them | ZDNET
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
The 10-step phone security tune-up you should run every year - and why | ZDNET
Outages
Parts of the internet go down after major network outage | News Tech | Metro News
One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why
Passwords, Credential Stuffing & Brute Force Attacks
124 Million Unique Passwords Exposed In New Infostealer Log Dataset
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout - Infosecurity Magazine
24 Billion Stolen Credentials Exposed in Massive Data Leak - Security Affairs
Klue says hackers stole credential from 2022 that led to customer data breaches | TechCrunch
Experts Warn: Passwords Still Winning Despite Passwordless Push - IT Security Guru
How World Cup Password Trends Can Increase Active Directory Risk - Infosecurity Magazine
A Glimpse into the “Search Your Target” Market for Stolen Credentials
Regulations, Fines and Legislation
How the social media ban could reshape how all of us use the internet - BBC News
Open-source security is posing challenges governments can't easily solve | CyberScoop
Circumvention tool or essential security software? The shifting role of VPNs in the UK | TechRadar
Reality check: Could the UK's social media ban lead to VPN restrictions? | TechRadar
The UK’s social media ban for under-16s has just empowered big tech | Taylor Lorenz | The Guardian
From PGP to Mythos: a brief history of export controls that didn't stop anyone | TechCrunch
Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration - SecurityWeek
Britain's privacy watchdog quits after 'poor judgment' admission
Shadow IT
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
Social Media
How the social media ban could reshape how all of us use the internet - BBC News
Software Supply Chain
'Cordyceps': Malicious Pull Requests Threaten CI/CD Workflows
Supply Chain and Third Parties
Klue Supply Chain Breach Exposes Salesforce Data At Several Security Firms
Klue OAuth breach victim list grows as Icarus hackers claim attack
Trust is the target: the new AI-era supply-chain attacks
What 22,000 breaches teach us about incident preparedness | CSO Online
LastPass suffers another data breach, but this time your password vault is safe - Digital Trends
Microsoft links Mastra AI supply chain attack to North Korean hackers
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
The UK is unprepared for Putin's cyber war. But one European country has the answer
The New Energy War: Why The AI Grid Is The New Battleground
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage - Infosecurity Magazine
Nation State Actors
China
How Chinese cars became a national security issue in Israel | Ctech
Russia
The UK is unprepared for Putin's cyber war. But one European country has the answer
Civilians behind international police probe into Russian cybercriminals - National | Globalnews.ca
North Korea
Microsoft links Mastra AI supply chain attack to North Korean hackers
Iran
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage - Infosecurity Magazine
Tools and Controls
What 22,000 breaches teach us about incident preparedness | CSO Online
Circumvention tool or essential security software? The shifting role of VPNs in the UK | TechRadar
Reality check: Could the UK's social media ban lead to VPN restrictions? | TechRadar
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
Anthropic's Mythos AI broke into almost all NSA classified systems in hours
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
macOS Weaknesses Chained to Silently Disable Endpoint Security Agents - SecurityWeek
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
Rolling out AI agents? 4 ways to move fast and furious - but with extreme caution | ZDNET
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
Why Frontier AI makes prioritization the most important part of your CTEM program
Companies are discarding the logs they need to catch a breach - Help Net Security
One intrusion, two cyberattackers: Uncovering parallel threat activity | Microsoft Security Blog
Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era
Security testing was built for a slower world - Help Net Security
Why MSSPs need to focus on reducing cyber risk, not adding complexity | ChannelPro
Most teams will ship AI-written infrastructure code with little review - Help Net Security
Don't panic, prepare: A cyber expert's advice on the Mythos hype
Healthcare staff enraged after a day off turned out to be a phishing test | Cybernews
Other News
How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack - BBC News
Forget traffic lights, Google's reCAPTCHA may ask for hand gestures - Help Net Security
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
Hundreds of Belgian organisations hit by cyber attack
One intrusion, two cyberattackers: Uncovering parallel threat activity | Microsoft Security Blog
Why MSSPs need to focus on reducing cyber risk, not adding complexity | ChannelPro
What are the cyber threats to the 2026 Fifa World Cup? | Computer Weekly
Legacy kit behind vast majority of cyber attacks on utilities | IT Pro
Vulnerability Management
What 22,000 breaches teach us about incident preparedness | CSO Online
Open-source security is posing challenges governments can't easily solve | CyberScoop
Windows 10 losing security support in October – 6 ways to solve the problem - Which?
Why Frontier AI makes prioritization the most important part of your CTEM program
Microsoft extends Windows 10's extra security updates program to October 2027 for free
Dozens of America's largest companies have no simple way to report security flaws
Vulnerabilities
The hits keep on coming for Cisco vulnerabilities
Cisco SD-WAN Zero-Day Exploited Months Before Patching - SecurityWeek
Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet - Security Affairs
FFmpeg fixes PixelSmash flaw in widely used video decoder
Chrome 149 Update Resolves 18 Severe Vulnerabilities - SecurityWeek
Update Chrome to patch critical browser security flaws | Malwarebytes
ShinyHunters Targets Oracle PeopleSoft Customers Through Critical Zero-day
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security
Critical Ubiquiti Vulnerabilities in Attackers' Crosshairs - SecurityWeek
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Your old iPhone may have a security flaw Apple can’t fix - Digital Trends
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 19 June 2026
Black Arrow Cyber Threat Intelligence Briefing 19 June 2026:
-FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls
-24 Billion Records, Including Usernames and Passwords, Exposed in Colossal Data Leak: What Does That Mean for You?
-Meet Kali365 — The ‘Amazon of Cybercrime’ Where Hackers Use AI to Completely Circumvent Multi-Factor Authentication
-HP Warns 11% of Email Threats Bypass Security Gateways
-Cybercriminals Are Moving Away from Mass Phishing Campaigns
-One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
-“Dangerous” AI Models Are Coming No Matter What
-Low-Skilled Attacker Used Claude, Codex to Breach 14 Companies
-It’s Time to Update Incident Response for the AI Era
-NCSC CEO: Hostile States Linked to Three-Quarters of Cyber Attacks Affecting UK’s Critical Systems
-Over Two-Thirds of Security Pros Say Cyber Is Getting Harder
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
In our review of cyber security in the specialist and general media this week, we start with several high-profile alerts for business leaders. Organisations using Fortinet should assess their response to the discovery of tens of thousands of firewall credentials, and all organisations should assess the impact of a wider data leak of 24 billion records. We also provide more information on the Kali365 phishing-as-a-service platform targeting Microsoft accounts, which we included last week, and information on research regarding the number of malicious emails that bypass current security.
Over recent weeks, we have highlighted the need for organisations to manage the risks associated with using AI, and we provide further examples below. These include a Copilot risk recently remediated by Microsoft, and how AI is being used by attackers.
Distilling these insights into key actions, a message for business leaders is to prepare for organisational resilience in the event of a cyber incident. We work on this with clients across the world to achieve proportionality, which requires an objective understanding of the high-impact business activities in the organisation that must be prioritised in an incident, and a leadership team that has rehearsed together by considering the challenging and realistic ‘what if?’ scenarios to dispel assumptions. Contact us to discuss how to achieve this.
Top Cyber Stories of the Last Week
FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls
Security researchers have identified a major exposure of Fortinet firewall credentials affecting around 75,000 devices, with the dataset believed to cover roughly half of all internet-facing Fortinet firewalls. The exposed information reportedly includes usernames, email addresses and plain text passwords across 194 countries and more than 21,000 domains, including major companies, government bodies and critical infrastructure operators. Evidence suggests the data may have been prepared for sale in criminal markets or for coordinated deployment by threat actors, increasing the risk of attackers gaining remote access to affected networks, changing security settings or creating hidden administrator accounts.
24 Billion Records, Including Usernames and Passwords, Exposed in Colossal Data Leak: What Does That Mean for You?
Cybernews researchers identified an exposed database containing 24 billion records and more than 8.3TB of data, including usernames, email addresses, passwords and login URLs. Much of the data appears to come from infostealer malware, although researchers also identified records sourced from Telegram channels, breach compilations and other collections. The database was exposed between 12 and 15 June 2026, although researchers cannot confirm how many records were duplicates or how many people were affected. Reused passwords remain a key risk, particularly for accounts without multi-factor authentication.
https://cybernews.com/security/24-billion-credentials-data-leak/
Meet Kali365 — The ‘Amazon of Cybercrime’ Where Hackers Use AI to Completely Circumvent Multi-Factor Authentication
Kali365 is a phishing-as-a-service platform targeting Microsoft accounts, offering criminals ready-made tools to run phishing campaigns at scale. First identified by Huntress in May 2026, it includes more than 33 Microsoft themed templates and over 100 API endpoints. The platform gains access to accounts after users complete multi-factor authentication, using stolen session cookies and OAuth tokens rather than passwords alone. The FBI has warned that it can also use AI to read stolen email threads, assess fraud opportunities and draft replies based on the content of compromised conversations.
HP Warns 11% of Email Threats Bypass Security Gateways
HP research has found that 11% of email threats reaching users had already bypassed one or more security gateway scanners in Q1 2026. Email remained the leading route for malicious activity, accounting for 57% of threats, followed by web browser downloads at 24%. Attackers are increasingly abusing legitimate software, trusted platforms and familiar business processes to avoid detection, including remote access tools, fake software updates and shared design platforms. The findings suggest organisations should not rely solely on email security gateways, as a proportion of threats are reaching users after passing through existing scanning controls.
https://therecycler.com/posts/that-hp-warns-11-of-email-threats-bypass-security-gateways/
Cybercriminals Are Moving Away from Mass Phishing Campaigns
Zscaler reports that overall phishing activity fell by around 20% in both 2024 and 2025, but phishing campaigns are becoming more targeted. Criminals are moving away from mass email campaigns towards convincing business-themed messages, such as billing notices, onboarding documents and support requests. The services sector saw a 65.5% rise in phishing activity, while Microsoft and Google remained the most impersonated brands. Zscaler also found more than 95% of phishing activity used encrypted web traffic, with attackers increasingly using artificial intelligence tools to create fake websites and steal active login sessions. The research suggests organisations should look beyond blocked-email statistics when assessing phishing threats, as attackers are increasingly focusing on identities, active sessions and other techniques that are not reflected in email volumes.
https://www.helpnetsecurity.com/2026/06/12/zscaler-report-phishing-activity-trends/
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
A flaw in Microsoft 365 Copilot Enterprise Search could have allowed attackers to steal emails, calendar details, files and multi-factor authentication codes after a user clicked a genuine Microsoft link. Researchers found the issue could bypass traditional phishing checks because the link used a trusted Microsoft domain. Microsoft has fixed the issue through its managed service, and there is no evidence it was exploited. The research notes that Copilot Enterprise can access the same emails, files and business information available to the signed-in user, and recommends monitoring unusual Copilot activity and limiting the volume of data available for indexing.
https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html
“Dangerous” AI Models Are Coming No Matter What
Advanced AI models with hacking capabilities are expected to become more widely available within months, raising concerns for governments and business leaders alike. Anthropic recently took two models offline after US export controls, amid fears their safeguards could be bypassed. Experts argue that organisations and governments should prepare for a future in which advanced AI cyber capabilities are widely available, rather than assuming restrictions on individual models will prevent their emergence. While these models can help defenders find and fix weaknesses, they could also help criminals identify ways to exploit them.
https://arstechnica.com/ai/2026/06/dangerous-ai-models-are-coming-no-matter-what/
https://www.wired.com/story/dangerous-ai-models-are-coming-no-matter-what/
Low-Skilled Attacker Used Claude, Codex to Breach 14 Companies
OALABS researchers found that a low-skilled attacker used AI coding agents to breach at least 14 companies, showing how these tools can reduce the expertise needed for cyber attacks. More than 1,000 recovered sessions showed the attacker used vague prompts, often framed as authorised security testing, while the AI helped find exposed systems, write exploit code and extract data. The tools raised few policy violations, and most were bypassed. The findings suggest AI coding agents can reduce the technical expertise required to conduct cyber attacks.
https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/
It’s Time to Update Incident Response for the AI Era
Gartner has warned that incident response must adapt as AI becomes embedded in business operations. It predicts that at least 80% of unauthorised AI transactions will stem from internal policy breaches, oversharing of information, unacceptable use or misguided AI behaviour, rather than malicious attacks. The challenge is that AI systems may create business risk while acting within their approved permissions. Gartner recommends that organisations review how they define AI-related incidents, improve oversight of AI activity, and ensure legal, compliance, HR and business teams are included in response planning.
NCSC CEO: Hostile States Linked to Three-Quarters of Cyber Attacks Affecting UK’s Critical Systems
The UK’s NCSC has warned that hostile states are behind around three quarters of cyber attacks affecting the UK’s critical national infrastructure. More than 200 incidents involving essential services and their supporting systems were handled in the year to May 2026, with Russia, China and Iran identified as examples of hostile states of concern. The warning highlights the importance of understanding exposure to threats, strengthening security fundamentals and ensuring organisations can continue operating and recover quickly after an attack. The NCSC also expects artificial intelligence to increase the scale at which attackers can identify and exploit vulnerable legacy technology by 2028.
https://www.ncsc.gov.uk/news/ncsc-ceo-hostile-states-linked-to-three-quarters-of-cyber-attacks
Over Two-Thirds of Security Pros Say Cyber Is Getting Harder
A new ISSA and Omdia study of 380 cyber security professionals found that 68% believe their role has become harder over the past two years. Many report being excluded from key technology decisions, with 72% saying this creates barriers to stronger security. Stress is also rising, with 47% considering leaving their role or the profession in the past 12 to 18 months. Only 29% rated their organisation’s cyber security culture as advanced, with respondents identifying increased training, investments in the right resources, stronger cyber hygiene and closer collaboration between security and IT teams as key areas for improvement.
https://www.infosecurity-magazine.com/news/security-pros-cyber-cyber-harder/
Governance, Risk and Compliance
It's time to update incident response for the AI era | TechTarget
Most CISOs Report Pressure to Bury Bad Security News
Over Two-Thirds of Security Pros Say Cyber Is Getting Harder - Infosecurity Magazine
How CISOs can balance business continuity with other responsibilities | CSO Online
Threats
Ransomware, Extortion and Destructive Attacks
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
Ransomware group The Gentlemen linked to Russian national | SC Media UK
Infostealers, AI, and a 90% Affiliate Cut Fuel The Gentlemen group’s Rise - Security Affairs
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
Silent Ransom Group: What You Need to Know
Morpheus Unmasked: Big Game Hunting and Private Data Sales | Ankura - JDSupra
Ransomware Insider Betrayal: Guilty Plea In BlackCat Cybercrime Scheme
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop
Ukrainian national pleads guilty to role in Conti ransomware operation
INC Ransomware Thrives by Mastering the Basics
Ransomware and Destructive Attack Victims
Council of Europe hacked in ShinyHunters' PeopleSoft heist
Hacking Group Claims Major Hack of Novo Nordisk and Attempted $25M Extortion
Cyberattack Gives Biglaw Firm A New Return-To-Office Excuse - Above the Law
JLR ordered in-person password resets after cyberattack | Manufacturer News
Infinite Campus data breach affects 137,000 school staff accounts
Kodak confirms data breach claimed by ShinyHunters extortion gang
Phishing & Email Based Attacks
Cybercriminals are moving away from mass phishing campaigns - Help Net Security
HP warns 11% of email threats bypass security gateways - The Recycler
FBI disrupts massive AI-powered phishing service using a million URLs
New Phishing Scam Targets Microsoft Teams, Outlook, OneDrive
Google Sues Chinese Cybercrime Group Behind 'Phishing-for-Dummies' Software | PCMag
Google Sues Chinese Phishing Service Over Gemini Abuse
FBI warns Microsoft Teams, Outlook, OneDrive users of phishing scam - Fast Company
9 million email addresses loaded into UK retail, tax and crypto scams | Cybernews
Other Social Engineering
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
'Lorem Ipsum' Malware Pivots to ClickFix Delivery
9 million email addresses loaded into UK retail, tax and crypto scams | Cybernews
Why SIM Swapping Remains a Blind Spot for Enterprise Security Teams
FTC warns of record $3.5 billion losses to imposter scams in 2025
Planning a trip? Fake travel sites are multiplying this summer - Help Net Security
Helpdesk scammers are making house calls to make their lies feel more real
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US)
North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine
Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
2FA/MFA
Artificial Intelligence
Anthropic Halts Access to Top AI Models After U.S. Ban on Foreign Use - WSJ
Low-skilled attacker used Claude, Codex to breach 14 companies - Help Net Security
FBI disrupts massive AI-powered phishing service using a million URLs
It's time to update incident response for the AI era | TechTarget
AI sovereignty hawks see red as U.S. moves to block Anthropic’s Mythos and Fable models - The Hindu
New attack turned Microsoft 365 Copilot into 1-click data theft tool
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
US decision to block Mythos access fuels European calls for sovereignty | Euractiv
Cyber Experts Urge US to Lift Ban on Anthropic’s Frontier AI Models - Infosecurity Magazine
AI’s constant patching treadmill can be a security problem | CyberScoop
"Dangerous" AI models are coming no matter what
The OpenClaw security risks every CISO needs to know | TechTarget
AI is accelerating cyberattacks—here’s how to stay ahead | Microsoft Community Hub
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US)
US, France, and Italian authorities shut down massive deepfake porn site | CyberScoop
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
AI Threats and Alert Fatigue Challenge Cybersecurity Teams - Infosecurity Magazine
North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine
Google Sues Chinese Phishing Service Over Gemini Abuse
Technical Warnings: AI Assistants Could Become Gateways for Cyberattacks
EU regulation drives new cybersecurity focus on AI systems - The Recycler
NanoClaw integrates JFrog registries to secure AI agent downloads
Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek
Careers, Roles, Skills, Working in Cyber and Information Security
AI Threats and Alert Fatigue Challenge Cybersecurity Teams - Infosecurity Magazine
Accenture cyber leads: why hiring more people won’t solve the cybersecurity talent gap | Fortune
Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS - Infosecurity Magazine
Cybersecurity Skills Gap in 2026: Why Developers Should Add Security
How AI is changing the breadth of cybersecurity roles
Cloud/SaaS
New Phishing Scam Targets Microsoft Teams, Outlook, OneDrive
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
FBI warns Microsoft Teams, Outlook, OneDrive users of phishing scam - Fast Company
Cyber Crime, Organised Crime & Criminal Actors
FBI takes down massive China-based cybercrime network that caused $1.9B in losses | CyberScoop
Cyber offenses now account for around a third of all crime across Asia and South Pacific
Data Breaches/Leaks
24 billion records, including usernames and passwords, exposed in colossal data leak | Cybernews
Hackers Crack Corporate, Government VPNs In Major Incident
Council of Europe investigates ShinyHunters data breach claims
Novo Nordisk says hackers stole clinical trial data
Plymouth council exposes hundreds in latest local government email gaffe
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker - SecurityWeek
Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data
University of Nottingham shares more details on major cyber-attack - BBC News
Infinite Campus data breach affects 137,000 school staff accounts
Fired IT worker jailed for 21 months after sabotaging old school district
Hackers Publish Knicks and Madison Square Garden Data Online
Data/Digital Sovereignty
US decision to block Mythos access fuels European calls for sovereignty | Euractiv
MPs call for UK government to back sovereign IT | Computer Weekly
France's digital sovereignty push is struggling to escape the Microsoft gravity well
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker - SecurityWeek
Digital sovereignty needs an operating model
Denial of Service/DoS/DDoS
IT, Telcos, Healthcare at Risk of HTTP/2 DDoS Attacks
Encryption
France to stop certifying products without quantum-safe encryption | Reuters
CEOs Must Act Before Quantum Computers Break Existing Cybersecurity
Fraud, Scams and Financial Crime
FTC warns of record $3.5 billion losses to imposter scams in 2025
Planning a trip? Fake travel sites are multiplying this summer - Help Net Security
Helpdesk scammers are making house calls to make their lies feel more real
Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
Hackers Are Hijacking Entire Roblox Games Now
Identity and Access Management
Chinese hackers hijack auth flow, spy on isolated network for a decade
Insider Risk and Insider Threats
North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine
Ex-school district employee jailed for hacks on former employer
Fired IT worker jailed for 21 months after sabotaging old school district
Internet of Things – IoT
21,786 Home Cameras, No Password, No Warning
Securing digital keys when your phone unlocks the car - Help Net Security
Law Enforcement Action and Take Downs
FBI disrupts massive AI-powered phishing service using a million URLs
Ransomware Insider Betrayal: Guilty Plea In BlackCat Cybercrime Scheme
Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop
Ukrainian national pleads guilty to role in Conti ransomware operation
Fired IT worker jailed for 21 months after sabotaging old school district
Linux and Open Source
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages - SecurityWeek
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Malware
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages - SecurityWeek
144 Mastra npm Packages Compromised via Hijacked Contributor Account
Fileless Phantom Stealer Targets Browser Credentials
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
SprySOCKS Windows Variant Uses Kernel Drivers to Evade Detection
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend Micro (US)
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
'Lorem Ipsum' Malware Pivots to ClickFix Delivery
WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
Steam Workshop abused to spread malware via Wallpaper Engine app
152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Mobile
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Your strong passwords mean nothing if your phone PIN is four digits
Every way your phone tracks your location - and how to stop it | ZDNET
Verizon sent man a refurbished phone with MDM, then deleted his data remotely - Ars Technica
Models, Frameworks and Standards
EU Cybersecurity Act 2.0: When good regulation goes bad - Help Net Security
Software supply chains are heading for a transparency test - Help Net Security
Passwords, Credential Stuffing & Brute Force Attacks
Hackers Crack Corporate, Government VPNs In Major Incident
Massive breach spills credentials for thousands of sensitive networks - Ars Technica
FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls
Why Account Takeovers Are Rising and How to Stop Them
We need to do something about passwords | IT Pro
Your strong passwords mean nothing if your phone PIN is four digits
JLR ordered in-person password resets after cyberattack | Manufacturer News
Regulations, Fines and Legislation
Anthropic Halts Access to Top AI Models After U.S. Ban on Foreign Use - WSJ
AI sovereignty hawks see red as U.S. moves to block Anthropic’s Mythos and Fable models - The Hindu
Lawmakers leery about Trump administration’s Anthropic order | CyberScoop
Security Community Slams US Ban on Exporting Mythos, Fable
Anthropic sends top security experts to Washington to rescue flagship models - Cryptopolitan
Restore Fable and Mythos Access, Cybersecurity Leaders Urge
"Dangerous" AI models are coming no matter what
UK to require ID or face scan before you can make social media accounts
UK Social Media Ban for Minors Has Privacy Experts Worried
Software supply chains are heading for a transparency test - Help Net Security
EU regulation drives new cybersecurity focus on AI systems - The Recycler
Banks fight to scrap an SEC cyberattack rule | American Banker
Trump Memo Overhauls Cyber Rules for Classified Networks
Social Media
Security risks overshadow the debut of Europe’s X rival, W | Cybernews
UK to require ID or face scan before you can make social media accounts
UK Social Media Ban for Minors Has Privacy Experts Worried
Software Supply Chain
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages - SecurityWeek
144 Mastra npm Packages Compromised via Hijacked Contributor Account
Software supply chains are heading for a transparency test - Help Net Security
Supply Chain and Third Parties
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Another healthcare firm attacked days after Novo Nordisk breach - Help Net Security
University of Nottingham shares more details on major cyber-attack - BBC News
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Cyberspace Locked in a Nation-State Contest, Says NCSC CEO
UK infrastructure being targeted by hostile states, GCHQ cyber chief warns | The Standard
Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek
The unit preparing for Israel's invisible war | Ctech
EU extends emergency cyber security support to Ukraine - CNA
Nation State Actors
Cyberspace Locked in a Nation-State Contest, Says NCSC CEO
What is the UK's Defending Democracy Taskforce? - The Constitution Society
China
Chinese Hackers Target Medical, Military, and AI Research in North America - SecurityWeek
China-linked actor UNC6508 spent two years inside medical research networks
Chinese hackers hijack auth flow, spy on isolated network for a decade
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Google Sues Chinese Phishing Service Over Gemini Abuse
FBI takes down massive China-based cybercrime network that caused $1.9B in losses | CyberScoop
Google Sues Chinese Cybercrime Group Behind 'Phishing-for-Dummies' Software | PCMag
Russia
WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer
EU provides cyber support to Ukraine against major attacks | EEAS
North Korea
North Korean Hiring Fraud Runs on AI and US Laptop Farms - Infosecurity Magazine
CISA Launches Major Hiring Push and Remote Worker Fraud Emerges as Growing Threat - ClearanceJobs
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
Iran
Strengthening cybersecurity cooperation between Iran and BRICS members - Pars Today
Cyberattack disrupts services at four Iranian banks, state media says | The Jerusalem Post
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Strengthening cybersecurity cooperation between Iran and BRICS members - Pars Today
Tools and Controls
Anthropic Halts Access to Top AI Models After U.S. Ban on Foreign Use - WSJ
HP warns 11% of email threats bypass security gateways - The Recycler
It's time to update incident response for the AI era | TechTarget
US decision to block Mythos access fuels European calls for sovereignty | Euractiv
Cyber Experts Urge US to Lift Ban on Anthropic’s Frontier AI Models - Infosecurity Magazine
"Dangerous" AI models are coming no matter what
AI Threats and Alert Fatigue Challenge Cybersecurity Teams - Infosecurity Magazine
How AI is changing the breadth of cybersecurity roles
Rethinking MDR as Attackers and Defenders Embrace AI
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
The Top 10 Attack Surface Exposures in 2026
Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
Cybersecurity Skills Gap in 2026: Why Developers Should Add Security
The FBI secretly built an entire fake town just to practice cyberattacks - Digital Trends
Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS - Infosecurity Magazine
Reports Published in the Last Week
Other News
The FBI secretly built an entire fake town just to practice cyberattacks - Digital Trends
What is the UK's Defending Democracy Taskforce? - The Constitution Society
Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
Ireland faces security test as it takes over EU presidency – POLITICO
Hacker: 'I Could Have Rickrolled the World Cup'
Cyberattack sees crops kept in the ground
Windows and Linux users: The deadline to update Secure Boot keys is near - Ars Technica
Hackers Are Hijacking Entire Roblox Games Now
Over 80% of Sports Organizations Targeted by Hackers in the Last Year - Infosecurity Magazine
Vulnerability Management
AI’s constant patching treadmill can be a security problem | CyberScoop
Microsoft is making Windows 11 updates require just one reboot instead of several | TechSpot
Trump Memo Overhauls Cyber Rules for Classified Networks
Vulnerabilities
Microsoft Outlook and Word Vulnerability Allow Attackers to Execute Malicious Code
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
Critical Copilot vulnerability allowed hackers to steal 2FA code from users - Ars Technica
Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker Recovery, and More
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Three critical Fortinet sandbox bugs splattered by unknown attackers
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs - SecurityWeek
FortiBleed - 70,000+ Fortinet Firewalls Compromised in Massive Exploitation Attack
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Oracle's Second Monthly Security Updates Deliver 245 Patches - SecurityWeek
Palo Alto PAN-OS Vulnerability Allow Attackers to Arbitrary Commands as a Root User
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities - SecurityWeek
Ivanti Sentry Exploitation Attempts Hitting Honeypots - SecurityWeek
CISA warns of another cPanel plugin flaw exploited in attacks
Joomla, LiteSpeed Vulnerabilities Exploited in Attacks - SecurityWeek
Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 12 June 2026
Black Arrow Cyber Threat Intelligence Briefing 12 June 2026:
-AI Risk Worries Insurers and Businesses Alike
-UK Regulator Warns AI Cyber Risks Pose Top Banking Threat
-Your AI Agent Could Become Your Biggest Insider Threat
-This New AI-Powered Worm Spreads Itself and Adapts in Real Time — Here’s How to Stop It
-AI Is Helping Low-Skill Hackers Pull Off Advanced Cyberattacks
-84% of Organisations Hit by Digital Risk Incidents Last Year. Most Can't Detect an AI-Generated Attack.
-Frontline Workers Twice as Likely to Use Unapproved AI
-Hackers Getting an Easy Ride: Misconfigured Cloud Settings Behind Growing Number of Data Breaches
-Cyber Security Software Fails to Detect Fifth of Browser-Based Phishing Attacks
-How Cyber-Risk Can Fall Flat in the Boardroom
-Ukraine’s Experience Highlights the Need for Preparation and Resilience in Cyber Security
-NCSC Urges Organisations to Shore Up Supply Chain Security Practices
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Many organisations are exploring and using AI in different forms, from generative AI used by employees to agentic AI embedded within business processes. To help business leaders adopt these technologies safely, we have included a selection of insights from specialist and general media covering the cyber security risks associated with AI and approaches to managing them.
These consider concerns raised by regulators, insurers and cyber security specialists. Key observations include the importance of effective AI governance, and appropriate access controls, monitoring and accountability, particularly where AI agents have access to business systems and data. The articles also highlight the growing challenge of Shadow AI, where employees use unapproved AI tools without organisational oversight.
We also consider wider cyber security risks and the importance of board-level governance, which includes ensuring cyber risks are communicated in clear business terms and that boards have sufficient understanding of cyber security to provide effective oversight and challenge. Contact us to discuss how we support organisations of all sizes and sectors to achieve this in a proportionate manner.
Top Cyber Stories of the Last Week
AI Risk Worries Insurers and Businesses Alike
AI adoption is accelerating faster than many organisations can govern it, creating uncertainty for both businesses and insurers. Deloitte found that while 60% of workers have access to approved AI tools, and 74% of companies plan to deploy agentic AI, only 21% have mature AI governance in place. Some insurers are already excluding AI-caused damage from traditional policies, making it important for businesses to understand whether cyber insurance, technology errors and omissions, or other cover would respond to incidents involving AI-related data breaches, fraud, business disruption or operational errors.
https://www.darkreading.com/cyber-risk/ai-risk-worries-insurers-businesses-alike
UK Regulator Warns AI Cyber Risks Pose Top Banking Threat
The UK’s financial services regulator, PRA, has warned that AI-enabled cyber security threats are now among the most significant emerging risks facing UK banks. The concern is that increasingly capable AI tools could help hostile actors identify vulnerabilities in bank technology systems, increasing pressure on organisations to strengthen and accelerate cyber security activities. The regulator is urging banks to speed up software updates, identify higher-risk open-source components and give cyber security greater priority within technology programmes. The warning comes as geopolitical tensions increase and regulators themselves redirect resources towards technology and AI capability.
https://www.fstech.co.uk/fst/UK_Regulator_Warns_AI_Cyber_Risks_Pose_Top_Banking_Threat.php
Your AI Agent Could Become Your Biggest Insider Threat
New research from DTEX highlights how AI agents could create a growing insider risk as they become embedded into everyday business systems. Tests showed that simple prompts could prepare sensitive data for removal in as little as 10 to 30 minutes, using access to tools such as Outlook, Salesforce, SharePoint and OneDrive. The concern is not a software flaw, but weak governance, limited monitoring and excessive access. Without appropriate access controls, monitoring, prompt auditing and governance, organisations may struggle to determine how a data breach occurred or whether it resulted from employee error, malicious instructions or the actions of an AI agent.
https://cyberscoop.com/ai-agent-insider-threat-cybersecurity-dtex/
This New AI-Powered Worm Spreads Itself and Adapts in Real Time — Here’s How to Stop It
University of Toronto researchers have developed a proof-of-concept AI-powered worm that can spread across connected devices, assess targets and adapt its approach in real time. Unlike traditional malware, which typically follows fixed instructions, a worm can move between connected devices without user action. This research shows how publicly available AI tools could enable malware to analyse targets, select known weaknesses and continue spreading without human intervention. The study reinforces the importance of multi-factor authentication, secure passwords for connected devices, network segregation for smart devices where appropriate, and timely software updates to reduce the risk from emerging AI-enabled threats.
AI Is Helping Low-Skill Hackers Pull Off Advanced Cyberattacks
Anthropic has reported rising misuse of AI in malicious cyber activity, after banning 832 accounts linked to harmful activity between March 2025 and March 2026. Its analysis found 13,873 attacker actions across all major stages of a cyber attack. Most usage involved preparation, such as developing malicious software, but AI was also used to support more advanced activity inside compromised networks. The findings suggest AI is enabling less sophisticated actors to perform activities that were previously limited to attackers with more advanced technical skills, with medium and high-risk actors rising from 33% to 56% during the study period.
https://www.helpnetsecurity.com/2026/06/05/anthropic-ai-cyber-activity-analysis/
84% of Organisations Hit by Digital Risk Incidents Last Year. Most Can't Detect an AI-Generated Attack.
A survey by Outtake reports that nearly seven in ten organisations described their digital risk capabilities as unaware, reactive or still developing, and 84% experienced significant digital risk incidents in the past year. The findings point to a growing business risk, with 53% citing manual remediation as the biggest cost, ahead of direct fraud losses. AI is adding further pressure, as 44% said AI-generated attacks are now indistinguishable from legitimate activity, while 96% lack automated controls to stop a compromised AI tool. Employee and executive impersonation also remain a major concern.
Frontline Workers Twice as Likely to Use Unapproved AI
Mitel research has found a growing gap between AI adoption and employee support, increasing the risk of Shadow AI, where staff use unapproved tools without oversight. Its global survey of 2,000 IT decision-makers and workers found 52% regularly use AI, but only 33% feel very comfortable doing so and 66% say their organisation does not adequately support AI use. Half of workers use unapproved AI tools, highlighting the growing challenge of Shadow AI and creating concerns around data protection, compliance and misleading outputs. Frontline workers face the highest pressure, with 71% forced to work around poorly suited communication systems.
https://www.itsecurityguru.org/2026/06/04/frontline-workers-twice-as-likely-to-use-unapproved-ai/
Hackers Getting an Easy Ride: Misconfigured Cloud Settings Behind Growing Number of Data Breaches
The Dutch National Cyber Security Centre has warned that poorly configured cloud systems are contributing to a growing number of data breaches. Recent incidents show that attackers are often gaining access not by exploiting technical flaws, but by finding cloud environments where permissions or access settings have been left too open. Criminal groups are using automated tools to scan for these mistakes at scale, making weak cloud configuration a business risk as well as a technical issue. Organisations should maintain clear oversight of cloud platforms, access rights and administrator accounts, while using multi-factor authentication to reduce exposure.
https://cybernews.com/security/hackers-misconfigured-cloud-settings-data-breach/
Cyber Security Software Fails to Detect Fifth of Browser-Based Phishing Attacks
Menlo Security has warned that browser-based phishing is bypassing many traditional cyber security tools, with one in five phishing attacks targeting enterprise browser users going undetected. Based on millions of browser sessions between January and March 2026, the research highlights how work now routinely happens through browsers, including email, cloud applications, AI assistants and financial systems. Attackers are exploiting this shift by using fake verification prompts, error messages and other social engineering tactics to trick users into taking actions that appear legitimate, helping them avoid detection by security tools that were not designed to operate at the browser session layer.
https://www.infosecurity-magazine.com/news/cybersecurity-fails-to-detect/
How Cyber-Risk Can Fall Flat in the Boardroom
Cyber risk is a growing board-level business issue, beyond a technology concern. Verizon’s 2025 research reviewed 22,000 security incidents and found ransomware in 44% of breaches, third-party involvement in 30% and vulnerability exploitation as an initial access method increasing by 34% year on year. Board engagement is increasing, although fewer than a third of boards include a member with cyber security expertise. Leaders need clear reporting that links cyber risks to financial loss, operational disruption, regulation and customer impact. The findings also raise questions about whether boards have sufficient cyber security expertise to oversee these risks effectively.
https://www.informationweek.com/risk-management/how-cyber-risk-can-fall-flat-in-the-boardroom
Ukraine’s Experience Highlights the Need for Preparation and Resilience in Cyber Security
Ukraine’s wartime experience shows why cyber security preparation and resilience matter for organisations of every size. Former Ukrainian foreign minister Dmytro Kuleba highlighted how planning helped government teams react quickly when invasion disrupted normal operations, including moving servers abroad. The lesson for leaders is that resilience depends on preparation, understanding technology dependencies and the ability to keep operating when disruption becomes sustained rather than temporary.
https://www.infosecurity-magazine.com/news/resilience-perseverance-ukraine/
NCSC Urges Organisations to Shore Up Supply Chain Security Practices
The UK’s NCSC has warned that software supply chain attacks are increasing, with criminals targeting software packages and development ecosystems to spread malicious code. Many modern applications rely on large numbers of third-party components, often updated automatically through software delivery processes with limited human review. This means one compromised package can quickly affect many organisations. Recommended actions include reviewing software dependencies, managing automatic updates, using multi-factor authentication for developer accounts and securing credentials.
https://www.itpro.com/security/ncsc-urges-organizations-to-shore-up-supply-chain-security-practices
Governance, Risk and Compliance
How cyber-risk can fall flat in the boardroom
NCSC urges organizations to shore up supply chain security practices | IT Pro
SMB cyber-readiness: What makes or breaks it
Cybercriminals: the 'auditors' you never hired
15 tough cybersecurity questions every CISO must answer | CSO Online
Most Security Teams Struggle to Find Time for Training on New Threats - Infosecurity Magazine
Threats
Ransomware, Extortion and Destructive Attacks
Extortion-Only Attacks Increase, With Data Theft Dominating Ransomware - Infosecurity Magazine
The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
Silent Ransom Group (SRG): Switching To DNS Fast Flux Infrastructure - Security Affairs
New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords
Why schools remain one of cybercriminals' favourite targets
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
If you don't fall for these extortionists' calls, they'll show up with USB sticks
Silent Ransom Group Hits US Law Firms in Escalating Attacks
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks - SecurityWeek
Ransomware and Destructive Attack Victims
Silent Ransom Group targets law firms with fake IT support calls
Nottingham University data breach affects over 450,000 students
Thousands of Essex NHS patient records stolen in cyber attack - BBC News
Qilin NHS breach tally grows as Essex trust confirms stolen records
Cyber attack closes Great Marlow School in Buckinghamshire - BBC News
Qilin claims hack of NY/NJ Shipping Association | Cybernews
Phishing & Email Based Attacks
Security Software Fails to Detect Fifth of Brower Phishing Attacks - Infosecurity Magazine
OpenClaw AI agent found falling for phishing attacks, spills user data
Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials
Interpol Dismantles SniperDz Phishing-as-a-Service Platform - Infosecurity Magazine
Other Social Engineering
Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials
Silent Ransom Group targets law firms with fake IT support calls
Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5
Remote Worker Fraud: A Growing Risk for Employers and Government Contractors | Ice Miller - JDSupra
Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes
Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup - Help Net Security
Suspected Norks send 250+ fake dev job pitches to steal crypto
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
Artificial Intelligence
AI is helping low-skill hackers pull off advanced cyberattacks - Help Net Security
AI Risk Worries Insurers and Businesses Alike
Frontline Workers Twice as Likely to Use Unapproved AI - IT Security Guru
Your AI agent could become your biggest insider threat | CyberScoop
Adaptive, Agentic AI Worms Loom as Next Enterprise Threat
This new AI-powered worm spreads itself and adapts in real time — here's how to stop it
UK regulator warns AI cyber risks pose top banking threat - FStech
Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation - SecurityWeek
Infosecurity Europe 2026: AI turbo-charging cyber crime and response | Computer Weekly
Every set of AI guardrails can be broken by the right prompt - Help Net Security
Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials
Patching Is No Match for Frontier AI, Cyber Expert Warns
Can we trust the systems we now rely on? - University of Birmingham
Everybody Is Vibe Coding But Nobody Told the Security Team - SecurityWeek
4 Critical Threats Where Attackers Have the Advantage
Meet Hades: The malware that lies to AI security agents | CSO Online
Treat your AI agents like eager but misguided human interns - before you lose control | ZDNET
New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
OpenClaw AI agent found falling for phishing attacks, spills user data
Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
OpenAI Rolls Out Lockdown Mode to Fight Prompt Injection Attacks
AI Coding Tools Need Built-In Security for Agentic Development Era - Infosecurity Magazine
Information Warfare: Americans And Chinese Both Fear AI
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse - SecurityWeek
Beware the ‘son of Mythos,’ security experts warn | CSO Online
AI Coding Adoption Hits 97% but Governance Lags Behind - Infosecurity Magazine
Ex-CISA CIO Breaks Down Trump's New AI Executive Order
9 out of 10 people can no longer distinguish real from AI-generated content - Help Net Security
Bots/Botnets
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Careers, Roles, Skills, Working in Cyber and Information Security
Most Security Teams Struggle to Find Time for Training on New Threats - Infosecurity Magazine
Cloud/SaaS
Warning: Cloud misconfigurations fuel more data breaches | Cybernews
Threat actors are recruiting the people who hold cloud logins - Help Net Security
Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes
New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords
Why Microsoft 365 Baseline Security Mode Isn't a Flip Switch
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
New SilabRAT Trojan Hijacks Sessions to Steal Crypto - Infosecurity Magazine
Suspected Norks send 250+ fake dev job pitches to steal crypto
Cyber Crime, Organised Crime & Criminal Actors
Scams now operate like real businesses with budgets and targets - Help Net Security
The prosecution gap: Why cybercrimes go unpunished | TechTarget
The assembly line behind 1.5 million malicious domains - Help Net Security
Cybercriminals: the 'auditors' you never hired
Data Breaches/Leaks
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica
Oxford University data pwned again by career platform breach
Nottingham University data breach affects over 450,000 students
France's sovereign messenger Tchap hit by account breach
OnlyFans mega leak reveals 340M user records, hackers claim | Cybernews
Japanese energy firm loses drive with data of 10.9 million clients
4.9 million Wise user records allegedly leaked online | Cybernews
OpenClaw AI agent found falling for phishing attacks, spills user data
Council in UK's City of York outs hundreds of disabled residents with a single email blunder
World Food Programme breach exposes data of 600k vulnerable Gazan families
Debt administrators exposed debt owner client data | Cybernews
174,000 Impacted by Lansing Community College Data Breach - SecurityWeek
Hackers claim Ralph Lauren data breach with 220GB allegedly stolen | Cybernews
Data Protection
CISO's guide to data minimization | TechTarget
Data/Digital Sovereignty
European Union Outlines Plan to Reduce Dependence on American Tech - The New York Times
France's sovereign messenger Tchap hit by account breach
Over 73,000 French govt employees affected in Tchap messenger breach
PYMNTS | EU Procurement Standards Show Vendor Lock-In Is B2B Liability
Denial of Service/DoS/DDoS
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Encryption
Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica
Windows BitLocker 0-Day Vulnerability Allow Attackers to Bypass Security Feature
Fraud, Scams and Financial Crime
Scams now operate like real businesses with budgets and targets - Help Net Security
The assembly line behind 1.5 million malicious domains - Help Net Security
Remote Worker Fraud: A Growing Risk for Employers and Government Contractors | Ice Miller - JDSupra
Identity theft is turning into a chain reaction for victims - Help Net Security
9 out of 10 people can no longer distinguish real from AI-generated content - Help Net Security
Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup - Help Net Security
Bitdefender Releases 2026 Global Scam Intelligence Report
Insider Risk and Insider Threats
Frontline Workers Twice as Likely to Use Unapproved AI - IT Security Guru
Your AI agent could become your biggest insider threat | CyberScoop
Insurance
AI Risk Worries Insurers and Businesses Alike
Extortion-Only Attacks Increase, With Data Theft Dominating Ransomware - Infosecurity Magazine
Internet of Things – IoT
Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
New privacy frontier: Europe eyes crackdown on smart glasses – POLITICO
Law Enforcement Action and Take Downs
The prosecution gap: Why cybercrimes go unpunished | TechTarget
Interpol Dismantles SniperDz Phishing-as-a-Service Platform - Infosecurity Magazine
Russian national charged in connection with Void Blizzard espionage campaign | CyberScoop
Dark web Nemesis Market vendor gets 26 years for selling drugs
Linux and Open Source
Two-Thirds of Open Source Community Unaware of Cyber Resilience Act - Infosecurity Magazine
High-severity vulnerability in Linux caused by a single faulty character - Ars Technica
Malware
Adaptive, Agentic AI Worms Loom as Next Enterprise Threat
Researchers build autonomous AI worm that can reason and adapt | TechTarget
Infostealers Turn Millions of Devices Into Credential Theft Machines - SecurityWeek
New SilabRAT Trojan Hijacks Sessions to Steal Crypto - Infosecurity Magazine
Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes
AI Adoption Creates New Opportunities for Attackers - Infosecurity Magazine
Meet Hades: The malware that lies to AI security agents | CSO Online
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...
GitHub disables Microsoft repos pushing password-stealing malware
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeek
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Fake Software Tutorials on TikTok Spread Vidar Stealer - Infosecurity Magazine
OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month - SecurityWeek
Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials
Chinese APT deploys new malware to keep access to hacked networks
Misinformation, Disinformation and Propaganda
Information Warfare: Americans And Chinese Both Fear AI
Mobile
Organizations can't see much of their mobile AI activity - Help Net Security
WhatsApp says it disrupted new NSO spyware phishing attacks
The security in smartphones is helping send them to landfills - Help Net Security
Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
Models, Frameworks and Standards
Two-Thirds of Open Source Community Unaware of Cyber Resilience Act - Infosecurity Magazine
EU to take France, Spain to court over cyber law delay – POLITICO
Passwords, Credential Stuffing & Brute Force Attacks
New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords
Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica
Suspected Norks send 250+ fake dev job pitches to steal crypto
The safest password is the one you never type
The NCSC Wants You To Adopt Passkeys: Is It Time To Finally Drop Passwords? | SC Media UK
Regulations, Fines and Legislation
UK regulator warns AI cyber risks pose top banking threat - FStech
EU to take France, Spain to court over cyber law delay – POLITICO
European Union Outlines Plan to Reduce Dependence on American Tech - The New York Times
UK move to filter photos and messages triggers encryption worries for CISOs – Computerworld
Signal attacks UK plan to scan devices for nude images as "mass surveillance" | TechSpot
The AI security race needs accountability, not overregulation | CyberScoop
EU plans one data breach form for all members| Cybernews
Ex-CISA CIO Breaks Down Trump's New AI Executive Order
Cyber Security (Jersey) Law: An overview | Walkers - JDSupra
New privacy frontier: Europe eyes crackdown on smart glasses – POLITICO
Shadow IT
Frontline Workers Twice as Likely to Use Unapproved AI - IT Security Guru
Your AI agent could become your biggest insider threat | CyberScoop
What 2026 DBIR Confirms: Attacks Are Living in the Browser
Social Media
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse - SecurityWeek
Software Supply Chain
GitHub disables Microsoft repos pushing password-stealing malware
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeek
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
Supply Chain Attacks Target Open‑Source Packages
Beware software dependencies - NCSC | UKAuthority
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...
4 Critical Threats Where Attackers Have the Advantage
The security questions around Chinese AI coding models in U.S. software - Help Net Security
Supply Chain and Third Parties
NCSC urges organizations to shore up supply chain security practices | IT Pro
Key strategies to benchmark your MSSP: Advice from top security providers | news | MSSP Alert
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
An Invisible Battlefield: Cyberwar Is Reshaping Everyday Life
Iran Signed a Ceasefire — Its Hackers Didn't
Europe Is Preparing for a Cyber War Ukraine Has Already Survived | The Gaze
Iranian group could be labelled national threat under proposed new law - BBC News
UK cracks down on Iran, Russia, North Korea, China cyber ops | Cybernews
Russian national charged in connection with Void Blizzard espionage campaign | CyberScoop
Finland: 4 suspects in sabotage of undersea Estonia cables
NATO's Cyber Approach Needs Change | Lawfare
Ukraine’s foreign minister offer recipe for improved resilience | CSO Online
Tests suggest Russian satellites can jam GPS on a continental scale - Ars Technica
Information Warfare: Americans And Chinese Both Fear AI
Europe is building resilience – but not the kind it needs for war - Friends of Europe
Ukraine’s Experience Highlights the Need for Preparation in Cyber - Infosecurity Magazine
Nation State Actors
UK cracks down on Iran, Russia, North Korea, China cyber ops | Cybernews
China
Former IBM cybersecurity exec accuses company of hiding Chinese hacking breaches
Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5
The security questions around Chinese AI coding models in U.S. software - Help Net Security
Chinese APT deploys new malware to keep access to hacked networks
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Information Warfare: Americans And Chinese Both Fear AI
Russia
Russian national charged in connection with Void Blizzard espionage campaign | CyberScoop
Ukraine: Europe's Only Wartime Cyber Defence Laboratory | The Gaze
Ukraine’s foreign minister offer recipe for improved resilience | CSO Online
Tests suggest Russian satellites can jam GPS on a continental scale - Ars Technica
How the FSB cut Russia off from the internet
German agencies warn of Russian cyber threats to weak PV systems | Solar Power News | Renewables Now
North Korea
Remote Worker Fraud: A Growing Risk for Employers and Government Contractors | Ice Miller - JDSupra
Suspected Norks send 250+ fake dev job pitches to steal crypto
Iran
Iran Signed a Ceasefire — Its Hackers Didn't
Iranian group could be labelled national threat under proposed new law - BBC News
Tools and Controls
AI Risk Worries Insurers and Businesses Alike
Why most enterprise security teams would fail a military readiness test | CSO Online
Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation - SecurityWeek
Security Software Fails to Detect Fifth of Brower Phishing Attacks - Infosecurity Magazine
Patching Is No Match for Frontier AI, Cyber Expert Warns
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
Why patching velocity matters as Claude Mythos supercharges vulnerability discovery | IT Pro
The security questions around Chinese AI coding models in U.S. software - Help Net Security
Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica
Organizations can't see much of their mobile AI activity - Help Net Security
Malware ships with bugs that defenders could use against it - Help Net Security
Most Security Teams Struggle to Find Time for Training on New Threats - Infosecurity Magazine
Most pros have seen AI hallucinations in IT operations - Help Net Security
Everybody Is Vibe Coding But Nobody Told the Security Team - SecurityWeek
AI Coding Tools Need Built-In Security for Agentic Development Era - Infosecurity Magazine
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away | CyberScoop
52% of direct-to-IP threats are missing from intelligence feeds - Help Net Security
Inside the race to adapt to an AI-powered security world | CyberScoop
Beware the ‘son of Mythos,’ security experts warn | CSO Online
AI Coding Adoption Hits 97% but Governance Lags Behind - Infosecurity Magazine
Alert Fatigue Is Becoming a Security Threat of Its Own - SecurityWeek
The AI security race needs accountability, not overregulation | CyberScoop
Why Microsoft 365 Baseline Security Mode Isn't a Flip Switch
Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It
Reports Published in the Last Week
Other News
Why most enterprise security teams would fail a military readiness test | CSO Online
PYMNTS | EU Procurement Standards Show Vendor Lock-In Is B2B Liability
Is recruitment data a cybercriminal goldmine? | The Global Recruiter
Stop Ignoring Your Router. This Is How to Optimize Privacy - CNET
How a USB-connected speaker can infect a PC without ever being touched - Ars Technica
Cybersecurity Needs Secure Software - Stiftung Wissenschaft und Politik
Exposed Fuel Tank Gauges Under Attack in the US
The Front Door Is Wide Open: What Wealthy Families Don't Know About Cybersecurity - Thrive Global
The new cybersecurity imperative | Expert Views - Business Standard
Building a Digital Fortress: Why Cyber Security Matters More Than Ever - IT Security Guru
Vulnerability Management
Two-Thirds of Open Source Community Unaware of Cyber Resilience Act - Infosecurity Magazine
75% of Firms Deploy Vulnerable Code Amid Pressure on CISOs - Infosecurity Magazine
Patching Is No Match for Frontier AI, Cyber Expert Warns
Why patching velocity matters as Claude Mythos supercharges vulnerability discovery | IT Pro
Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook
CISA tells govt agencies to patch critical exploited flaws in 3 days
Vulnerabilities
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
Windows BitLocker 0-Day Vulnerability Allow Attackers to Bypass Security Feature
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
Microsoft patches Exchange Server zero-day exploited in attacks
Nightmare Eclipse drops claimed BitLocker bypass for Microsoft Windows
Exchange Flaw Lets Attackers Spoof Any Email Address
Attackers had month-long head start on patched Check Point VPN zero-day
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks - SecurityWeek
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
Cisco customers encounter another SD-WAN zero-day under attack | CyberScoop
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Fortinet patched a new critical FortiSandbox flaw
Adobe Patches 123 Vulnerabilities - SecurityWeek
Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Max-Severity Ivanti Sentry Flaw Exploited Within 24 Hours
21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks
Path traversal flaw in AI dev platform Langflow exploited in attacks
High-severity vulnerability in Linux caused by a single faulty character - Ars Technica
LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) - Help Net Security
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
OpenSSL Patches High-Severity Vulnerability Found With AI - SecurityWeek
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters - SecurityWeek
SAP Patches Critical NetWeaver, Commerce Vulnerabilities - SecurityWeek
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog
Splunk, Palo Alto Networks Patch Severe Vulnerabilities - SecurityWeek
Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script
UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers - SecurityWeek
Gogs patches critical zero-day enabling remote code execution
Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 05 June 2026
Black Arrow Cyber Threat Intelligence Briefing 05 June 2026:
-Why Your Board Is Still Not Ready for Cyber Risk - And What Actually Needs To Change
-Execs Must Treat Cyber Threats as Statecraft, ISACA Expert Says
-UK Firms Prioritise AI Threat Preparedness as Cyber Risks Evolve
-Nation State Attacks: The Risk to UK Firms
-The Gentlemen Are Coming for Your Files, and Then Your Network
-Ransomware Groups Grow Revenue by Almost 40% in Q1 2026
-'The Com' Cyberattacks Support Violence & Sexploitation
-What Is Configuration Drift - And Why It’s Your Biggest M365 Security Risk
-Supply Chain Risk Is Now a Cyber Resilience Problem
-82% of IT Pros Report a Web-Based Security Incident in Past Year – BYOD, SaaS Tools, and Remote Work Policies All Play a Part in Security Resilience
-M&S Chief’s Pay Slashed by £3M After Cyberattack Turmoil
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
This week’s review of cyber security in the specialist and general media highlights how business leaders can better understand and manage cyber risks, with insights into actions that boards can take to improve security and resilience.
AI remains a prominent theme, continuing a trend we have observed over recent months. Alongside this, we see cyber risks becoming more complex, spanning geopolitical threats, the evolution of ransomware, and security weaknesses that can emerge through routine business and technology changes. We also highlight the recently announced impact of last year’s M&S cyber attack on executive remuneration, illustrating how the consequences of a cyber incident can extend well beyond the initial disruption.
Our advice for business leaders remains consistent: focus on cyber security to reduce the likelihood of an incident, and on cyber resilience to withstand and recover from one. This requires boards to understand cyber risks in business terms, govern them through proportionate controls, and rehearse the leadership response before an incident occurs. Contact us to discuss how these themes can be addressed in your leadership meetings.
Top Cyber Stories of the Last Week
Why Your Board Is Still Not Ready for Cyber Risk - And What Actually Needs To Change
Cyber incidents have ranked as the top global risk for the fifth year running, according to the Allianz Commercial Risk Barometer, yet many boards still overestimate their organisation’s readiness. A key challenge is proving the return on cyber security investment, particularly where risks involve reputation, customer trust and business disruption. Stronger cyber resilience can reduce downtime, support customer retention and strengthen competitive positioning. Boards should treat cyber risk as a core business issue, with clear ownership, measurable reporting, independent assurance and consideration in strategy, mergers and acquisitions.
Execs Must Treat Cyber Threats as Statecraft, ISACA Expert Says
Information Security professional body ISACA has warned that cyber security risk can no longer be treated as a purely technical issue, as cyber, artificial intelligence and geopolitics are now increasingly connected. High profile attacks against commercial organisations have shown that private companies can become targets for state linked groups, sometimes for political rather than financial reasons. Emerging risks include covert foreign IT worker schemes, which can create trusted insider access. Boards should understand where they are exposed, test their crisis response, strengthen HR and supplier checks, and rehearse longer running scenarios involving nation state threats.
https://www.infosecurity-magazine.com/news/execs-cisos-must-treat-cyber/
UK Firms Prioritise AI Threat Preparedness as Cyber Risks Evolve
ManageEngine reports that AI-powered attacks are now the top concern for UK organisations, cited by 43% of respondents, with 41% prioritising investment in AI and advanced threat preparedness. More than three quarters of UK businesses experienced a cyber incident in the past year, above the European average, while 46% pointed to skills shortages as their main operational challenge. Although 94% of incidents are detected within 24 hours, recovery remains slower, with over a quarter taking more than 10 days, highlighting the need to strengthen resilience as threats become more complex.
https://www.infosecurity-magazine.com/news/uk-firms-prioritize-ai-threat/
Nation State Attacks: The Risk to UK Firms
The UK’s National Cyber Security Centre has warned that nation states, particularly China, Iran and Russia, are now behind most significant cyber incidents affecting the UK. These attacks are often focused on disruption, espionage or gaining long-term access, rather than financial gain, meaning ransom payments are unlikely to resolve the issue. Critical sectors such as finance, healthcare, technology, telecoms, energy, water and defence face heightened risk, as do suppliers that provide access to larger organisations. Strong basic controls, regular recovery testing and clear oversight remain essential as geopolitical tensions continue to shape cyber activity.
https://insight.scmagazineuk.com/nation-state-attacks-the-risk-to-uk-firms
The Gentlemen Are Coming for Your Files, and Then Your Network
Microsoft has warned that ransomware called ‘Gentlemen’, developed by a group with the same name, is actively targeting organisations across education, transport, healthcare and financial services worldwide. First seen in mid 2025 and still active in 2026, the ransomware can spread from one compromised machine to others across a network before encrypting files. This means a single breach can quickly become a wider business disruption. ‘Gentlemen’ now operates as ransomware-as-a-service, where criminal affiliates can pay to use the software to carry out attacks. Early detection of unusual access, stolen password use and remote system activity is critical to limiting impact.
Ransomware Groups Grow Revenue by Almost 40% in Q1 2026
Rapid7 has reported that ransomware revenue rose by almost 40% year on year in the first quarter of 2026, reaching an estimated $529.2 million. The growth reflects a more mature criminal market, where ransomware groups can buy ready-made access to organisations through dark web brokers rather than breaking in themselves. Leading groups generated significant revenue, with Qilin estimated at $193 million and Gentlemen at $52 million between July 2025 and March 2026. The findings show how resilient and commercialised cyber crime operations have become.
'The Com' Cyberattacks Support Violence & Sexploitation
Researchers report that ‘The Com’, a loose criminal network linked to groups such as Scattered Spider, combines cyber crime with wider criminal activity, blurring the boundaries between its hacking groups and other criminal networks. The group is largely North American, often young, and recruits through gaming and social media communities. Its activity shows how weak cloud security can create harm beyond the breached organisation, with stolen access and extortion funding further criminal operations. Recent activity may have quietened, but researchers warn the group remains active and continues to evolve its tactics.
https://www.darkreading.com/threat-intelligence/the-com-cyberattacks-violence-sexploitation
What Is Configuration Drift - And Why It’s Your Biggest M365 Security Risk
Configuration drift is a growing Microsoft 365 security risk, particularly for managed service providers overseeing many client environments. It occurs when security settings gradually move away from an agreed baseline through routine changes, such as temporary access exceptions, relaxed sharing controls or admin permissions that are not later removed. These changes can weaken defences without triggering obvious alerts. Continuous monitoring and automated remediation can help identify and correct drift quickly, reducing the risk of incidents and supporting stronger governance across multiple Microsoft 365 tenants.
Supply Chain Risk Is Now a Cyber Resilience Problem
AI demand is putting pressure on the supply of DRAM and NAND, the memory and storage components that underpin backup and recovery infrastructure. As availability tightens and costs rise, cyber resilience strategies that rely on continually adding more hardware may become harder to sustain. More efficient architectures, which reduce the amount of data stored, moved and managed, can lower dependency on scarce components, reduce the number of systems needing protection, and support faster recovery. This makes infrastructure efficiency not just a cost issue, but a strategic cyber security consideration.
https://www.dell.com/en-us/blog/supply-chain-risk-is-now-a-cyber-resilience-problem/
82% of IT Pros Report a Web-Based Security Incident in Past Year – BYOD, SaaS Tools, and Remote Work Policies All Play a Part in Security Resilience
NordLayer reports a clear gap between confidence and reality in web-based security. While 73% of organisations believe they are prepared for attacks through browsers and web applications, 82% experienced an incident in the past year. The risk is growing as businesses rely more heavily on online software, remote working and personal devices. Malware designed to steal login details harvested 1.8 million credentials and 68.8 billion cookies last year, giving attackers a way to access systems by appearing to log in legitimately rather than forcing their way in.
M&S Chief’s Pay Slashed by £3M After Cyberattack Turmoil
The chief executive of UK retailer Marks & Spencer saw his pay fall by more than 40% after a major cyber attack disrupted the retailer’s operations and M&S cancelled its executive bonus scheme. The attack halted online services for weeks, affected card payments in some stores, and contributed to weaker financial performance, resulting in lower bonus and share-based awards for executives. M&S put the total cost at £133.3 million, although more than £100 million has been recovered through insurance.
https://www.cityam.com/ms-pay-slashed-after-cyberattack-turmoil/
Governance, Risk and Compliance
Why Your Board Is Still Not Ready for Cyber Risk
EU organizations buckle under rising compliance pressure - Help Net Security
UK Firms Prioritize AI Threat Preparedness as Cyber Risks Evolve - Infosecurity Magazine
NCSC Urges Immediate Action to Boost Resilience as Uncertainty Persist - Infosecurity Magazine
Building Cyber Resilience For Mission-critical Operations In 2026
6 critical security gaps every CISO must address | CSO Online
Business Leaders Lack Understanding of Threat Intelligence - Infosecurity Magazine
How to Get Boards to Prioritize Cyber Risk Quantification - Infosecurity Magazine
Cybersecurity Staff Prefer CISOs With Real Attack Response Experience - Infosecurity Magazine
CISO burnout: How to prevent contagion across the team | Computer Weekly
Two New Reports Offer Competing Explanations for Cybersecurity's Growing Crisis - SecurityWeek
Lost in translation: Cybersecurity board reporting for CISOs | TechTarget
Threats
Ransomware, Extortion and Destructive Attacks
Ransomware groups grow revenue by almost 40% in Q1 2026 | TechRadar
'The Com' Cyberattacks Support Violence & Sexploitation
The Gentlemen are coming for your files, and then your network | CSO Online
The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks
Pink is the latest goon squad to use fake helpdesk calls to steal creds
'Dumbass' criminal breaks the 'first rule of ransomware club'
Ransomware and Destructive Attack Victims
Inside the Charter data breach: hackers leak 13M+ customer data | Cybernews
Charter Communications data breach affects 4.9 million accounts
M&S chief's pay slashed by £3m after cyberattack turmoil
IKEA faces data leak threat after hackers claim theft of internal code | Cybernews
Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers
Phishing & Email Based Attacks
Attackers Abuse Shared Content for ChatGPT Phishing Campaign - Infosecurity Magazine
Infostealers are becoming the go-to phishing payload | Malwarebytes
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
ChatGPT prompt injection turns web pages into phishing lures
BTMOB Android malware service generates custom phishing payloads
Threat Actors Deploy Tiflux RMM For Persistent Remote Access
LinkedIn-themed phishing abuses Adobe's A/B testing platform - Help Net Security
There’s a new phishing scam: fake invitations | The Seattle Times
PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
Europe's hotel data breach hits 100+ properties | Cybernews
Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek
China's TA4922 Expands Cybercrime Attacks Globally
Signal users targeted in backup-stealing phishing attacks | Malwarebytes
Social Security numbers exposed in Rich Products cyberattack | Cybernews
Other Social Engineering
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Pink is the latest goon squad to use fake helpdesk calls to steal creds
There’s a new phishing scam: fake invitations | The Seattle Times
Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek
Cyber espionage campaign targeted stock exchange executive’s Outlook account
As the 2026 World Cup Looms, a Shadow Tournament of Cyber Fraud Begins | OCCRP
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
Five Eyes: China expanding state secret recruitment campaign
5K+ election domains registered ahead of US midterms
2FA/MFA
Microsoft fixes outage affecting MFA setup, MySignIn service
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
Artificial Intelligence
Attackers Abuse Shared Content for ChatGPT Phishing Campaign - Infosecurity Magazine
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
UK Firms Prioritize AI Threat Preparedness as Cyber Risks Evolve - Infosecurity Magazine
145 AI laws passed in 2025 and privacy teams aren't catching a break - Help Net Security
Only 11% of production agents pass the AI agent security bar - Help Net Security
Security of 100 AI Agents Tested and Ranked – What You Need to Know - SecurityWeek
The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks
Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar
Cybersecurity threats from new language models | Max-Planck-Gesellschaft
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web - Infosecurity Magazine
Free AI model powers self-spreading worm in enterprise test network
Commvault says it's time to rethink resiliency as AI crooks leave victims in a 'dark, dead' state
Hugging Face security analysis: ~70,000 live secrets and API keys, private repos, and leaky pics!
UK banks still lack access to Mythos AI model, BoE's Bailey says - CNA
ICO publishes blog on AI-powered cyber threats | A&O Shearman - JDSupra
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
Cyber threats are becoming 'high level' with AI
President Trump Signs AI Executive Order After Delaying It Over China Concerns - Decrypt
Bots/Botnets
Botnet of 17 Million Devices Dismantled in the Netherlands
Huge Botnet Linked To Russia Infected Over 10 Million Devices Before Being Shut Down
Careers, Roles, Skills, Working in Cyber and Information Security
6 critical security gaps every CISO must address | CSO Online
CISO burnout: How to prevent contagion across the team | Computer Weekly
Cloud/SaaS
PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
19.6 Billion Files Are Sitting Open on the Internet. No Password Required
FSB Group Gamaredon Hides Worm in Windows Data Streams - Infosecurity Magazine
Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2
What is configuration drift — And why it’s your biggest M365 security risk | native | MSSP Alert
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets
Cyber Crime, Organised Crime & Criminal Actors
'The Com' Cyberattacks Support Violence & Sexploitation
Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek
China's TA4922 Expands Cybercrime Attacks Globally
Dutch Raid Fails to Dent Russian Bulletproof Host
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown - SecurityWeek
Data Breaches/Leaks
19.6 Billion Files Are Sitting Open on the Internet. No Password Required
Hugging Face security analysis: ~70,000 live secrets and API keys, private repos, and leaky pics!
Your OnlyFans may not be private – and neither are your passwords | Cybernews
The worst hacks and breaches of 2026 (so far) | TechCrunch
Europe's hotel data breach hits 100+ properties | Cybernews
Troops’ phones leaked location data to foreign adversaries
Man sent to prison for selling data of 7 millions elderly Americans
23andMe Failed to Stop Months-Long Hack, State Alleges
California AG sues 23andMe over 2023 breach exposing health data
A Fake UK Visa Site Left 100,000 Passports Wide Open. Then Sent Lawyers Instead of a Fix.
Social Security numbers exposed in Rich Products cyberattack | Cybernews
Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers
Scots affected by Capita cyber attack given route to compensation | Scottish Legal News
Spain arrests doxer leaking sensitive data of govt employees
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
Ultrahuman says recent hack didn't affect passwords or credit cards
GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying
64,000 accounts exposed in breach of GTA V cheat service Atlas Menu - Help Net Security
Hackers just stole health data from Ultrahuman users, and I’m ditching my smart ring because of it
Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals - SecurityWeek
Data Protection
ICO publishes blog on AI-powered cyber threats | A&O Shearman - JDSupra
Data/Digital Sovereignty
Vivre la Linux: Behind France’s bold open source move into digital sovereignty
Denial of Service/DoS/DDoS
Why Your Rate Limits Fail Under Distributed DDoS Attacks - Security Boulevard
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
Encryption
Let's Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats
Fraud, Scams and Financial Crime
Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar
As the 2026 World Cup Looms, a Shadow Tournament of Cyber Fraud Begins | OCCRP
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
Meta tries to get ahead of scammers before the World Cup begins - Help Net Security
Insurance
Cyber Insurance Rates Are Dropping, but Exclusions Widen
Internet of Things – IoT
Are our cars spying on us? A cybersecurity expert explains how to stay safe
Hacking your car’s dash cam in real time, remotely: tips, tricks, and lazy manufacturers.
How To Reduce Cyber Risks Across Connected Devices And Services
Law Enforcement Action and Take Downs
Botnet of 17 Million Devices Dismantled in the Netherlands
Huge Botnet Linked To Russia Infected Over 10 Million Devices Before Being Shut Down
Man sent to prison for selling data of 7 millions elderly Americans
Dutch Raid Fails to Dent Russian Bulletproof Host
Sextortionist sentenced to 33 years for targeting 145 children
Spain arrests doxer leaking sensitive data of govt employees
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown - SecurityWeek
European authorities crack down on illegal streaming networks | CyberScoop
Police seize £1.2m of kit from illegal streaming operation - BBC News
DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets
Reporting Cybersecurity Incidents to Law Enforcement- Best Practice
29 Arrests, Nine Crime Groups Dismantled: Another Blow to Illegal Streaming
Linux and Open Source
Organizations Warned of Exploited Linux Kernel Vulnerability - SecurityWeek
Vivre la Linux: Behind France’s bold open source move into digital sovereignty
New CIFSwitch Linux flaw gives root on multiple distributions
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access - SecurityWeek
Dozens of Red Hat packages backdoored through its official NPM channel - Ars Technica
Shai-Hulud malware infects Red Hat npm packages downloaded 80K times weekly
Malware
Attackers Abuse Shared Content for ChatGPT Phishing Campaign - Infosecurity Magazine
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Infostealers are becoming the go-to phishing payload | Malwarebytes
Android Banking Trojan OverlayPhantom Abuses Accessibility Service to Control Devices
Dozens of Red Hat packages backdoored through its official NPM channel - Ars Technica
Shai-Hulud malware infects Red Hat npm packages downloaded 80K times weekly
Free AI model powers self-spreading worm in enterprise test network
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
Chinese hackers use new Atlas RAT malware in European cyberattacks
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
Rust-Written IronWorm Hits NPM Supply Chain
Mobile
Russian hacker tricked MAGA Telegram channel with jailbroken AI | TechRadar
Troops’ phones leaked location data to foreign adversaries
BTMOB Android malware service generates custom phishing payloads
Signal users targeted in backup-stealing phishing attacks | Malwarebytes
Mobile security's dirty cupboard: The app layer nobody's watching
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
Models, Frameworks and Standards
EU organizations buckle under rising compliance pressure - Help Net Security
145 AI laws passed in 2025 and privacy teams aren't catching a break - Help Net Security
Anthropic to Open Mythos AI to EU's ENISA
ENISA report shows cybersecurity gains across EU critical sectors ...
MSSPs need to look beyond AI compliance badges | perspective | MSSP Alert
Outages
Microsoft fixes outage affecting MFA setup, MySignIn service
Microsoft Exchange Online outage causes email delays, failures
Passwords, Credential Stuffing & Brute Force Attacks
Your OnlyFans may not be private – and neither are your passwords | Cybernews
Pink is the latest goon squad to use fake helpdesk calls to steal creds
Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads - SecurityWeek
Regulations, Fines and Legislation
EU organizations buckle under rising compliance pressure - Help Net Security
145 AI laws passed in 2025 and privacy teams aren't catching a break - Help Net Security
President Trump Signs AI Executive Order After Delaying It Over China Concerns - Decrypt
Executive order sets voluntary cyber reviews for advanced AI | Miami Herald
EO 14390 raises stakes for enterprise cybersecurity | TechTarget
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels | CyberScoop
CISA close to issuing new cyber AI directive | Federal News Network
Social Media
Your OnlyFans may not be private – and neither are your passwords | Cybernews
Five Eyes: China expanding state secret recruitment campaign
LinkedIn-themed phishing abuses Adobe's A/B testing platform - Help Net Security
Software Supply Chain
Rust-Written IronWorm Hits NPM Supply Chain
Supply Chain and Third Parties
Supply Chain Risk Is Now a Cyber Resilience Problem | Dell
Scots affected by Capita cyber attack given route to compensation | Scottish Legal News
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Nation state attacks: The risk to UK firms | SC Media UK
Why Execs and CISOs Must Treat Cyber Threats as Statecraft - Infosecurity Magazine
Five Eyes: China expanding state secret recruitment campaign
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Plan to toughen protections for subsea internet cables amid heightened Russian activity - GOV.UK
The Pentagon Finally Admits That Location Data Is a Battlefield Problem - Security Affairs
Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms - Infosecurity Magazine
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
Cyber espionage campaign targeted stock exchange executive’s Outlook account
A Year After Launch, Ukraine’s Tallinn Mechanism Is Becoming a Cybersecurity Hub | The Gaze
Nation State Actors
Nation state attacks: The risk to UK firms | SC Media UK
Why Execs and CISOs Must Treat Cyber Threats as Statecraft - Infosecurity Magazine
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
China
Are our cars spying on us? A cybersecurity expert explains how to stay safe
Five Eyes: China expanding state secret recruitment campaign
Chinese hackers use new Atlas RAT malware in European cyberattacks
The Green Grid’s Hidden Backdoor: Who Controls Europe's Clean Energy?
Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms - Infosecurity Magazine
Germany, Spain said to push back on European plan to ban Huawei gear
China Uses Dual-Method Cyberattack on Czech Orgs
Chinese Cybercrime Group in Spotlight for Record Campaign Pace - SecurityWeek
China's TA4922 Expands Cybercrime Attacks Globally
China turns its aging camera network into an AI-powered mass surveillance apparatus
Russia
FSB Group Gamaredon Hides Worm in Windows Data Streams - Infosecurity Magazine
Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2
The Green Grid’s Hidden Backdoor: Who Controls Europe's Clean Energy?
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Plan to toughen protections for subsea internet cables amid heightened Russian activity - GOV.UK
Huge Botnet Linked To Russia Infected Over 10 Million Devices Before Being Shut Down
Estonians' will to defend the country remains high, cyberattacks seen as a threat | News | ERR
'Dumbass' criminal breaks the 'first rule of ransomware club'
Russian spy agency says foreign spies turned officials' smartphones into surveillance devices
Russia Says Foreign Spyware Found on High-Ranking Officials' Mobile Phones
North Korea
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
Iran
Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms - Infosecurity Magazine
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
Tools and Controls
Building Cyber Resilience For Mission-critical Operations In 2026
Microsoft under fire for threatening security researcher with criminal investigation | TechCrunch
Two New Reports Offer Competing Explanations for Cybersecurity's Growing Crisis - SecurityWeek
How to Get Boards to Prioritize Cyber Risk Quantification - Infosecurity Magazine
Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks
Microsoft quietly removes a blog post claiming Windows 11 offers sufficient security - BetaNews
Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads - SecurityWeek
How To Reduce Cyber Risks Across Connected Devices And Services
Why Your Rate Limits Fail Under Distributed DDoS Attacks - Security Boulevard
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
Threat Actors Deploy Tiflux RMM For Persistent Remote Access
Business Leaders Lack Understanding of Threat Intelligence - Infosecurity Magazine
Lost in translation: Cybersecurity board reporting for CISOs | TechTarget
The behavioral signals that sharpen Trojan malware detection - Help Net Security
Known vulnerabilities behind most application security incidents - Help Net Security
How Leading Organizations Are Turning EDR Into Operational Resilience
Raising the Cybersecurity Stakes: Ante up for the Agentic Era - SecurityWeek
Anthropic to Open Mythos AI to EU's ENISA
UK banks still lack access to Mythos AI model, BoE's Bailey says - CNA
Zoom CISO: AI as Security Enabler, Not Role-Replacer
Agent Threat Rules: Open detection rule format for AI agent security threats - Help Net Security
Anthropic ups Glasswing partner count 4x, UK banks snubbed
Hackers Can Weaponize Lenovo Driver to Terminate EDR Processes
Reports Published in the Last Week
Other News
Farage's £5m gift leak 'hack' reported to police by Labour - Essex Live
Microsoft quietly removes a blog post claiming Windows 11 offers sufficient security - BetaNews
ENISA report shows cybersecurity gains across EU critical sectors ...
No Longer Invisible: When Cyber Attacks Go Physical
Security Specialist Warns of Business Aviation Cyberattack Threats | Aviation International News
National cyber shield could be ready in five years | Computer Weekly
Vulnerability Management
IBM and Red Hat believe they have the answer to open source security risks | IT Pro
Vulnerabilities
Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) - Help Net Security
Microsoft blames unexpected Windows driver updates on caching issue
Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 - SecurityWeek
Organizations Warned of Exploited Linux Kernel Vulnerability - SecurityWeek
New CIFSwitch Linux flaw gives root on multiple distributions
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access - SecurityWeek
Oracle's First Monthly Patches Resolve 77 Vulnerabilities - SecurityWeek
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Recent Palo Alto Networks Vulnerability Exploited for Weeks - SecurityWeek
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Chrome 148 Update Patches 151 Vulnerabilities - SecurityWeek
The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks
Critical Flowise Flaw Gives Attackers Full Server Control - Infosecurity Magazine
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian Targets
Acer working to patch max severity zero-days in Wave 7 routers
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 29 May 2026
Black Arrow Cyber Threat Intelligence Briefing 29 May 2026:
-Could Your CEO Be the Weakest Link When It Comes to AI Security? New Study Warns Execs Are ‘Knowingly Bypassing Safeguards Because the Perceived Benefits Outweigh the Risks’
-Companies Built AI into Core Systems Before Figuring out How to Govern It
-When Your Biggest Security Risk Has Never Signed a Contract
-The AI Phishing Revolution: From Spray-and-Pray to Autonomous Operations
-Bosses Blinded by Confidence About Shadow AI Use by Workers
-68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise
-Preparing for Severe Cyber Threat: Why Leaders Must Act Now
-The UK’s Top Spy Says the Window to Stay Ahead of China and Russia Is Narrowing and Cyber Security Needs to Become ‘10 Times More Urgent’
-UK Spy Chief Labels AI ‘Unstoppable Force’ with Offensive, Defensive Ramifications for Cyberspace
-Phishing Most Prevalent Cyber Attack, Confirms UK Survey
-Security Experts Caution MFA Alone Can No Longer Stop Threat Actors
-To Pay, or Not to Pay: 58% of CISOs Say They Would Pay the Ransom for Their Data
-Lessons for Organisations from the Verizon 2026 Data Breach Investigations Report
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Continuing the theme from recent weeks, our review of current cyber news in the media considers how organisations can use AI more securely by being aware of the risks and the need for stronger governance and oversight.
We highlight that this starts from the top of the organisation, including how the leadership uses AI, how they understand the risks to their core systems, and how they can fulfil regulatory and accountability responsibilities where AI agent failures cause disruption or harm. We also report on messaging from the UK’s NCSC on the need for organisations to strengthen their security in the face of escalating risks.
Alongside AI risks, traditional cyber risks remain: we include a reminder that phishing and vulnerability exploits are top cyber threats (which are also empowered by AI), alongside third-party risks.
While the threat landscape shifts and evolves, the actions required from business leaders remain consistent: ensure an objective and complete understanding of your risks, and an unbiased assessment of how your controls address those risks. Contact us to discuss how to achieve this proportionately.
Top Cyber Stories of the Last Week
Could Your CEO Be the Weakest Link When It Comes to AI Security? New Study Warns Execs Are ‘Knowingly Bypassing Safeguards Because the Perceived Benefits Outweigh the Risks’
New research from TrustedTech highlights a growing risk around unapproved AI use, with 62% of senior leaders admitting to using tools outside company controls, double the rate of wider employees. More than a quarter said they would continue using AI even if it was banned, despite many being concerned about staff doing the same. The risk is greater at leadership level because executives often have access to sensitive financial, HR, customer and legal data. The findings highlight how behaviour at senior level can undermine governance and increase organisational risk as AI adoption accelerates.
Companies Built AI into Core Systems Before Figuring Out How to Govern It
Check Point reports that 70% of organisations now use generative AI in live environments, while 64% have AI agents in pilot or production. In some cases, these agents have privileged access to core systems, increasing exposure to security incidents. More than half of organisations have already experienced at least one AI-related security issue, including unapproved AI use, AI-generated phishing, deepfake content and sensitive data leaks. Yet only 5% have visibility of the AI tools and services being used, leaving many organisations unable to consistently govern access, data flows and risk.
https://www.helpnetsecurity.com/2026/05/28/check-point-genai-security-controls-report/
When Your Biggest Security Risk Has Never Signed a Contract
As AI agents, systems that can act independently on behalf of an organisation, become embedded in business processes, accountability is moving from policy into law. UK and EU regimes increasingly expect a named senior leader to show reasonable oversight when agent failures cause disruption or harm. Responsibility cannot simply be assigned on paper. Senior sponsors need enough practical understanding to supervise the agents they own, supported by formal training that links legal accountability with meaningful operational control.
https://www.computerweekly.com/opinion/When-your-biggest-security-risk-has-never-signed-a-contract
The AI Phishing Revolution: From Spray-and-Pray to Autonomous Operations
AI is reshaping phishing from broad, low-effort scams into targeted, always-on campaigns. Attackers can now create convincing, personalised emails in under five minutes, operate across email, text, voice and collaboration tools, and adapt their approach when a target does not respond. Some attacks also bypass multi-factor authentication by tricking users into approving legitimate-looking login requests. With AI reducing the skill and cost needed to run these campaigns, organisations face a shift where attacks operate continuously and adapt in real time, making traditional, user-focused defences increasingly less effective.
Bosses Blinded by Confidence about Shadow AI Use by Workers
Okta research found that 58% of organisations experienced an AI-related security incident or near miss in the past year, despite 90% of executives feeling confident they can see how AI is being used. The gap is driven by “shadow AI”, where employees use unapproved tools outside company oversight. More than half of knowledge workers admitted doing this, including 55% in the UK. Some also shared confidential documents, HR information or even login details, increasing business risk. The findings suggest a disconnect between leadership visibility and actual AI usage, increasing exposure to data leakage and governance challenges as adoption grows.
68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise
Barclays reports that 68% of UK business leaders expect to increase cyber security spending over the next 12 months, as AI adoption and geopolitical uncertainty reshape technology priorities. Despite this, fewer than three in 10 firms are confident they could respond effectively to a major cyber incident. Average cyber security spend has reached £505,000 so far in 2026, rising to £1.3m among large businesses. Key concerns include loss of sensitive data or intellectual property, disruption to operations, loss of revenue and damage to customer trust.
https://www.infosecurity-magazine.com/news/uk-firms-cyber-spending-ai-risks/
Preparing for Severe Cyber Threat: Why Leaders Must Act Now
The NCSC has warned that severe cyber threats are becoming a credible risk for organisations delivering the UK’s critical services, including financial services, health, energy, transport, and communications. These attacks can cause extended downtime, financial loss, reputational damage and risks to public safety. With technologies such as advanced AI increasing the speed and scale of attacks, leaders are being urged to plan beyond prevention. Building resilience means identifying critical systems, preparing for degraded operations, rehearsing recovery plans and ensuring key decisions are understood before a major incident occurs.
https://www.ncsc.gov.uk/blogs/preparing-for-severe-cyber-threat-why-leaders-must-act-now
The UK’s Top Spy Says the Window to Stay Ahead of China and Russia Is Narrowing and Cyber Security Needs to Become ‘10 Times More Urgent’
GCHQ has warned that the UK and its allies have a narrowing window to stay ahead of growing cyber and intelligence threats from China and Russia. The agency’s director said warfare is becoming increasingly driven by data, artificial intelligence and automation, while Russia is intensifying activity against critical infrastructure, democratic processes, supply chains and public trust. The warning highlights the increasing pressure on organisations to strengthen supply chain resilience, protect data and manage access controls as part of a more urgent approach to cyber security.
UK Spy Chief Labels AI ‘Unstoppable Force’ with Offensive, Defensive Ramifications for Cyberspace
GCHQ has warned that artificial intelligence is reshaping cyber security, creating both new opportunities and risks. Anne Keast-Butler, head of the UK intelligence agency, described AI as an “unstoppable force” that can be used to find weaknesses in critical technology and to support activity below the level of traditional warfare. GCHQ is developing an AI powered cyber shield to strengthen national defences, while warning that countries including China and Russia are using AI, data and automation to enhance cyber and hybrid threats.
https://cyberscoop.com/gchq-warns-ai-cyber-warfare-threats/
Phishing Most Prevalent Cyber Attack, Confirms UK Survey
New UK government research shows cyber attacks remain a persistent risk, affecting 43% of businesses and 28% of charities in the past year. Phishing, where criminals trick people into sharing information or clicking harmful links, remains the most common attack, impacting 38% of businesses and 25% of charities. Larger organisations face higher exposure, with 69% reporting an incident. Despite this, only around 30% conduct cyber risk assessments, while just 25% of businesses and 19% of charities have formal response plans. Supply chain oversight also remains limited, leaving many organisations exposed through partners and providers.
Security Experts Caution MFA Alone Can No Longer Stop Threat Actors
Security researchers are warning that multi factor authentication is no longer enough on its own to stop account takeover attempts. New phishing services can steal Microsoft 365 access tokens, which allow criminals to access Outlook, Teams and OneDrive without needing a password or another login check. One service, Kali365, costs from $250 for 30 days and gives even less skilled attackers ready-made templates, dashboards and AI generated messages. This shift highlights how attackers are bypassing traditional authentication controls, reflecting a move toward identity-focused risks such as token misuse and anomalous account activity rather than reliance on login-based protections alone.
To Pay, or Not to Pay: 58% of CISOs Say They Would Pay the Ransom for Their Data
A survey of 750 CISOs in the US and UK found that 58% would be willing to pay a ransom to end a ransomware incident, despite official guidance advising against it. In practice, fewer organisations appear to pay, with IDC reporting that 37% of affected companies did so last year. Paying does not guarantee recovery, with some organisations receiving incomplete data restoration and only 60% of SMEs in one survey recovering all or part of their data after payment. The findings highlight the operational and recovery risks of ransomware, where payment does not guarantee data restoration and can still result in prolonged disruption.
Lessons for Organisations from the Verizon 2026 Data Breach Investigations Report
Verizon’s 2026 Data Breach Investigations Report highlights how many breaches still stem from gaps in basic cyber security controls. Based on more than 31,000 incidents and 22,000 confirmed breaches across 145 countries, the report found vulnerability exploitation was the leading route into organisations, accounting for 31% of breaches. Ransomware remained a major issue, appearing in 48% of breaches, while third party involvement also featured in 48%. The report also points to rising risks from employee use of unauthorised AI tools, with sensitive internal information being uploaded outside corporate control.
https://www.helpnetsecurity.com/2026/05/25/lessons-from-verizon-dbir-2026-findings/
Governance, Risk and Compliance
68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise - Infosecurity Magazine
The readiness paradox: Why a false sense of cyber confidence is becoming a liability | CyberScoop
UK businesses accelerate cyber and AI investment amidst geopolitical tensions | WebWire
Preparing for severe cyber threat: why leaders must act now | National Cyber Security Centre
Developing An Executive Cybersecurity Strategy When Director Duties Extend To The Home Router
Threats
Ransomware, Extortion and Destructive Attacks
Why pure extortion is replacing traditional ransomware - Security Affairs
To pay, or not to pay: 58% of CISOs say they would pay the ransom for their data | CSO Online
The Hidden Ransomware Economy Running on Exposed Databases
Ransomware Actors Show Up In Person to Steal Law Firm Data
The Gentlemen is Making Its Mark in the Ransomware World - Security Boulevard
Law enforcement shuts down VPN service used by two dozen ransomware gangs | TechCrunch
Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files
More Australian firms are panicking and paying ransoms | The North West Star | Mt Isa, QLD
Ransomware and Destructive Attack Victims
Charter confirms data breach after ShinyHunters extortion threat
MyPillow appears on Play ransomware leak site
Phishing & Email Based Attacks
Phishing most prevalent cyber attack, confirms UK survey | ICAEW
Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security
FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required
The AI Phishing Revolution - IT Security Guru
AI-Powered Phishing Puts MSSPs on the Defensive: Barracuda | news | MSSP Alert
Inside business email compromise attack: Real-world examples | TechTarget
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Chinese Threat Actors Shift to Live Credential Interception - Infosecurity Magazine
Business Email Compromise (BEC)/Email Account Compromise (EAC)
Inside business email compromise attack: Real-world examples | TechTarget
Other Social Engineering
MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
700+ education and tech websites hijacked in huge ClickFix malware campaign | Malwarebytes
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Iranian Hackers Using Fake Job Sites to Breach Defense Firms
Thousands of Fake FIFA Domains Target World Cup Fans - Infosecurity Magazine
FBI director Kash Patel’s brand website taken offline after malware reports
2FA/MFA
Security experts caution MFA alone can no longer stop threat actors | CSO Online
Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security
FBI warns about fast-growing phishing kit targeting Microsoft 365 users | CyberScoop
MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions | NL Times
Artificial Intelligence
Turns out the C-suite loves shadow AI - Help Net Security
Companies built AI into core systems before figuring out how to govern it - Help Net Security
When your biggest security risk has never signed a contract | Computer Weekly
Bosses blinded by confidence about shadow AI use by workers
The AI Phishing Revolution - IT Security Guru
ECB convenes banks over AI cybersecurity risks from Mythos
AI guardrails stripped from Meta and Google models in minutes
European AI adoption hits 99% with regulated data driving most policy violations - Help Net Security
GCHQ draws up plans for world-first national AI cyber defence system | The Standard
Frontier AI models collapse under multi-turn AI attacks, Cisco finds - Help Net Security
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek
Defenders Fall Behind, as AI Rewrites the Rules of a Data Breach
Fake Gemini and Claude Code Sites Spread Infostealers - Infosecurity Magazine
The Growing Cybersecurity Risks To The Supply Chain In The AI Era
GPU mining malware spreads via SEO poisoning, AI chatbots
Why AI Could Make Cybersecurity One of the Hottest Jobs in Tech - ClearanceJobs
Cisco used AI to write security incident reports, with mixed results
Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security
Trump Postpones Signing AI Security Order Over Parts He Disliked
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms | CyberScoop
Anthropic Says a Mythos-Class AI Model Will Be Available Soon - CNET
Bots/Botnets
Canadian Man Arrested for Operating Kimwolf Botnet - SecurityWeek
GlassWorm Botnet Disrupted - SecurityWeek
Careers, Roles, Skills, Working in Cyber and Information Security
Why AI Could Make Cybersecurity One of the Hottest Jobs in Tech - ClearanceJobs
Amid fears of AI killing tech jobs, companies race to fill cybersecurity roles - Sherwood News
One Job That Is Growing in the A.I. Era? Cybersecurity Experts. - The New York Times
Why Burnout in Cybersecurity Demands Risk-Based Response - Infosecurity Magazine
Cloud/SaaS
Microsoft 365 users targeted by new phishing threat that bypasses MFA - Help Net Security
FBI warns about fast-growing phishing kit targeting Microsoft 365 users | CyberScoop
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
GPU mining malware spreads via SEO poisoning, AI chatbots
Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Cyber Crime, Organised Crime & Criminal Actors
Ghost hackers: the cybersecurity mystery that nobody has solved | TechCrunch
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation
Canadian Man Arrested for Operating Kimwolf Botnet - SecurityWeek
One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
Former US execs plead guilty to aiding tech support scammers
Data Breaches/Leaks
Hacker claims to leak massive WhatsApp database before vanishing from forums | Cybernews
Defenders Fall Behind, as AI Rewrites the Rules of a Data Breach
46k plaintext passwords pwned in Myspace93 breach
German hospitals targeted in massive cyberattack
Victims 'violated' after South Staffs Water's data breach - BBC News
OnlyFans mega leak reveals 340M user records, hackers claim | Cybernews
UK luxury car drivers' data may be exposed after Mercedes data leak claim | Cybernews
340 Million OnlyFans Profiles Allegedly Rebuilt from Leaks
Trump Mobile site leaks customer data as phone finally ships
7-Eleven data breach exposes personal information of 185,000 people
DocketWise Data Breach Impacts 143,000 - SecurityWeek
Data Protection
European AI adoption hits 99% with regulated data driving most policy violations - Help Net Security
Data/Digital Sovereignty
How a 900% Surge in Cyberattacks Is Forcing Europe to Rethink Its Tech Sovereignty — UNITED24 Media
Dutch Government just said no to an American firm buying the keys to their digital State
Denial of Service/DoS/DDoS
Why the Surge in DDoS Attacks Should Worry Security Leaders - Infosecurity Magazine
Encryption
Texas AG sues Meta over claims that WhatsApp doesn't provide end-to-end encryption - Ars Technica
‘Q-Day’ could be cybersecurity’s Armageddon | The Week
Apple open-sources quantum-resistant encryption code | CyberScoop
Fraud, Scams and Financial Crime
Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
Is your phone bill higher? 200+ Android apps might secretly be stealing money from you - PhoneArena
Thousands of Fake FIFA Domains Target World Cup Fans - Infosecurity Magazine
Security Leaders Should Prepare for World Cup Scams | Security Magazine
Fake Streams, Counterfeit Merch & Scams: How Fraudsters Target F1 Fans - Infosecurity Magazine
Insider Risk and Insider Threats
Turns out the C-suite loves shadow AI - Help Net Security
Bosses blinded by confidence about shadow AI use by workers
Why ‘shadow AI’ could become an expensive headache for businesses
Internet of Things – IoT
This Is Where Your Doorbell Camera's Security Footage Actually Goes
Law Enforcement Action and Take Downs
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands - SecurityWeek
Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
GlassWorm Botnet Disrupted - SecurityWeek
Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions | NL Times
Romanian Hacker Gets Nearly 5 Years in US Prison Over Network Intrusion
Canadian Man Arrested for Operating Kimwolf Botnet - SecurityWeek
Former US execs plead guilty to aiding tech support scammers
Dutch police arrests suspect linked to Ajax football club hack
Linux and Open Source
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale | WIRED
Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend
Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation
Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects - SecurityWeek
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant
Malware
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek
Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation
GPU mining malware spreads via SEO poisoning, AI chatbots
700+ education and tech websites hijacked in huge ClickFix malware campaign | Malwarebytes
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant
GlassWorm Botnet Disrupted - SecurityWeek
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Fake Gemini and Claude Code Sites Spread Infostealers - Infosecurity Magazine
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security
Megalodon chums the waters in 5.5K+ GitHub repo poisonings
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Attackers Move Past Typosquatting to Realistic Package Impersonation - Infosecurity Magazine
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers
FBI director Kash Patel’s brand website taken offline after malware reports
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
Iranian APT Targets Aviation, Software Companies With Updated Tools - SecurityWeek
Scammers are Exploiting GTA 6 Hype to Spread Malware | Extremetech
Chinese APTs Share Linux Backdoor in Telco Attacks
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Misinformation, Disinformation and Propaganda
Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation
Mobile
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Is your phone bill higher? 200+ Android apps might secretly be stealing money from you - PhoneArena
BTMOB Android RAT Spreads Through No-Code Builder Tooling - Infosecurity Magazine
Outages
Downtime has become a $600 billion business problem - Help Net Security
Passwords, Credential Stuffing & Brute Force Attacks
The Credential Crisis: How Stolen Credentials Defeat Modern Security - SecurityWeek
Why businesses still get password management wrong | TNW Deals
Typed the wrong macOS password? That brief pause isn't a glitch | Macworld
Regulations, Fines and Legislation
ECB convenes banks over AI cybersecurity risks from Mythos
'We cannot regulate cyber threats away,' top lawyer warns
Trump Postpones Signing AI Security Order Over Parts He Disliked
Minister Lloyd cyber security speech at the New Statesman - GOV.UK
Restoring CISA is one issue many lawmakers can agree on | Federal News Network
Shadow IT
Turns out the C-suite loves shadow AI - Help Net Security
Bosses blinded by confidence about shadow AI use by workers
Why ‘shadow AI’ could become an expensive headache for businesses
Social Media
46k plaintext passwords pwned in Myspace93 breach
Software Supply Chain
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale | WIRED
Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation
Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack - SecurityWeek
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Megalodon chums the waters in 5.5K+ GitHub repo poisonings
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
The Growing Cybersecurity Risks To The Supply Chain In The AI Era
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
Supply Chain and Third Parties
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems - SecurityWeek
The Growing Cybersecurity Risks To The Supply Chain In The AI Era
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
UK Spy Chief Warns China Is Closing Cyber Gap With West
Cyber warfare is outpacing global legal accountability - The Hindu
How concerned should CIOs be with geopolitics? | CIO
Nation State Actors
China
UK Spy Chief Warns China Is Closing Cyber Gap With West
Chinese Threat Actors Shift to Live Credential Interception - Infosecurity Magazine
China-Linked Hackers Target Southeast Asian Edge Routers With Custom Linux Implant
Chinese APTs Share Linux Backdoor in Telco Attacks
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Russia
Russia 'relentlessly targeting' critical infrastructure, democracy - GCHQ - BBC News
Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands - SecurityWeek
Two arrested for facilitating pro-Russia cyberattacks, violating EU sanctions | NL Times
Experts question Nigel Farage’s Russian phone-hacking claims
North Korea
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Iran
Iranian Hackers Using Fake Job Sites to Breach Defense Firms
Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
Iranian APT Targets Aviation, Software Companies With Updated Tools - SecurityWeek
The LA Metro Attack Wasn't Hacktivism. It Was a State Operation With a Costume On.
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
How concerned should CIOs be with geopolitics? | CIO
A nation on a hard drive: Inside the rise of digital embassies – POLITICO
Tools and Controls
Security experts caution MFA alone can no longer stop threat actors | CSO Online
Anthropic's Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing
Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump
MFA Prompt Bombing: Why Your Second Factor Isn't Saving You
Preparing for severe cyber threat: why leaders must act now | National Cyber Security Centre
The Next-Gen Flipper Zero Looks Even More Powerful Than Expected
Project Glasswing by Anthropic didn't just find the bugs. It also found the real vuln | Ctech
Why businesses still get password management wrong | TNW Deals
Why Burnout in Cybersecurity Demands Risk-Based Response - Infosecurity Magazine
Cybersecurity Evolution: Perimeter Defense to AI-Native Security
Apple open-sources quantum-resistant encryption code | CyberScoop
European AI adoption hits 99% with regulated data driving most policy violations - Help Net Security
Amid fears of AI killing tech jobs, companies race to fill cybersecurity roles - Sherwood News
One Job That Is Growing in the A.I. Era? Cybersecurity Experts. - The New York Times
Cisco used AI to write security incident reports, with mixed results
Anthropic adds 28 security and compliance integrations for Claude - Help Net Security
For CISOs, dawn of OpenAI Daybreak brings good and bad news | TechTarget
Claude now reviews and fixes vulnerabilities as you write code - Help Net Security
Other News
Tech giants need oversight to protect national security
Farage under mounting pressure to prove Russian hack claim | Nigel Farage | The Guardian
Water, the Soft Underbelly of Critical Infrastructure
OT attacks shift from recon to physical control, raising stakes | TechTarget
A nation on a hard drive: Inside the rise of digital embassies – POLITICO
Cyber attacks are ‘inevitable’, warns NHS comms lead | PR Week UK
Experts question Nigel Farage’s Russian phone-hacking claims
Scottish social enterprise supports national cyber efforts | Computer Weekly
Vulnerability Management
Anthropic's Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
Microsoft Threatens Researcher Over Bug Reports, Triggers Cybersecurity Uproar
Three-Quarters of Firms Knowingly Ship Vulnerable Code, Says Checkmarx - Infosecurity Magazine
NIST’s CVE Shift Raises the Bar for Vulnerability Prioritization | perspective | MSSP Alert
Why some security fixes never reach your vulnerability dashboard | CSO Online
Verizon 2026 DBIR: 6 key takeaways for CISOs | TechTarget
Project Glasswing by Anthropic didn't just find the bugs. It also found the real vuln | Ctech
Anthropic to release Mythos-class models to the public
Why CISA Accepting KEV Nominations Is So Important | Security Magazine
Cisco refines its risk-based vulnerability disclosure for the AI era - Help Net Security
Vulnerabilities
Microsoft patches two zero-day flaws in Defender | CSO Online
SharePoint Has a New RCE Flaw. If You Haven't Patched Yet, Go Do That.
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure - SecurityWeek
CVE-2026-9082: Drupal's Highly Critical SQL Injection Flaw Is Already Under Active Attack
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
700+ education and tech websites hijacked in huge ClickFix malware campaign | Malwarebytes
Gitea Vulnerability Exposed 30,000 Deployments to Attacks - SecurityWeek
New Gogs 0-Day Vulnerability Lets Attackers Run Malicious Code on the Server Remotely
KnowledgeDeliver flaw exploited as a zero-day to install web shells
Dirty Frag, Copy Fail, Fragnesia: The start of a worrisome Linux security trend
Notepad++ fixes critical vulnerabilities that can lead to malware | Cybernews
Trend Micro warns of Apex One zero-day exploited in the wild
Ubiquiti patches three max severity UniFi OS vulnerabilities
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 22 May 2026
Black Arrow Cyber Threat Intelligence Briefing 22 May 2026:
-Bank of England, FCA and Treasury Raise Alarm Over Frontier AI
-NCSC Publishes Guidance on Securing Agentic AI Use
-Social Engineering Attacks Are Rising as Employee Data Becomes Easier to Exploit
-Mobile Phishing Is a Bigger Threat than Email Now – How to Stay Protected
-Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
-Critical Microsoft Vulnerabilities Doubled: from Exposure to Escalation
-Cyber Attacks Cost UK Businesses £3.7Bn in Litigation in 2025
-Crime Increasingly a ‘Serious Barrier’ to UK Growth, Say Business Leaders
-Cyber Resilience is the New Business Continuity Plan
-Cyber Threats Push SMBs to Spend More on Security
-When Compliance Isn’t Continuous, That’s a Security Risk
-Taking Care of Business: The CISO’s Role in a Cyber Crisis
-Four Incident Response Mistakes That Slow Recovery and Raise Breach Costs
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Authorities in the UK have warned organisations about the cyber risks of AI, both because it has elevated the risks of an attack and the internal risks when used by organisations in their operations. While AI presents new risks, attackers are also advancing their use of more established tactics, from social engineering to exploiting vulnerabilities.
Research this week highlights the effects of cyber attacks, through the financial costs to organisations and the damage to business growth. In response, business leaders are focusing on their resilience to a cyber incident, including their business continuity plans. We highlight that, for organisations with regulatory requirements, compliance must be continuous.
We also discuss how resilience is played out in the way organisations respond to a cyber incident, and the role of a CISO in helping the business leadership team to manage the effect of an incident throughout the organisation. We describe how preparation for a cyber incident is essential, and some mistakes to avoid. Contact us to discuss how we support organisations like yours to lay the foundations to manage a cyber incident more confidently.
Top Cyber Stories of the Last Week
Bank of England, FCA and Treasury Raise Alarm Over Frontier AI
The Bank of England, FCA and Treasury have warned UK financial services firms to strengthen cyber security controls as frontier AI (advanced AI systems at the cutting edge of capability) increases the speed, scale and cost efficiency of attacks. The authorities said current models can already exceed what a skilled practitioner could achieve, raising risks to customers, market integrity and financial stability. Boards are expected to understand the threat, invest in core defences, manage supplier risk, fix weaknesses quickly, protect data and access, and improve response and recovery planning.
https://www.infosecurity-magazine.com/news/bank-england-fca-treasury-alarm/
NCSC Publishes Guidance on Securing Agentic AI Use
The UK’s NCSC has issued new guidance on the safe use of agentic AI, meaning AI systems that can act with a degree of independence. Developed with partners in Australia, Canada, the US and New Zealand, the guidance warns that poorly controlled AI agents could access too much data, make decisions faster than people can review, or behave unpredictably. Organisations are advised to start with tightly controlled pilots, limit access to only what is necessary, monitor activity closely and ensure clear ownership, human oversight and incident response plans before wider deployment.
https://www.infosecurity-magazine.com/news/ncsc-publishes-guidance-securing/
Social Engineering Attacks Are Rising as Employee Data Becomes Easier to Exploit
Optery reports that targeted social engineering is rising, with 96% of cyber security leaders seeing an increase over the past year. Attackers are using legitimate data brokers and people search sites to find employee details, such as personal phone numbers, email addresses, job roles and home addresses, making impersonation more convincing across email, calls, texts and social media. Nearly three quarters reported credential compromise linked to these attacks, while IT and identity teams were targeted more often than executives. The research found that organisations are increasingly prioritising reduction of exposed employee data, with around 60% already using this approach and a third identifying it as a top investment priority.
Mobile Phishing Is a Bigger Threat than Email Now – How to Stay Protected
Verizon’s latest data breach research shows attackers are increasingly moving from email to mobile channels such as text messages and phone calls. Based on more than 31,000 incidents and 22,000 confirmed breaches, phone-based phishing was around 40% more effective than email in simulations. Human involvement featured in 62% of breaches, while exploitation of software weaknesses rose to 31% of initial entry points. The report also highlights growing risks from unapproved AI use, with 67% of employees using personal AI accounts on company devices.
https://www.zdnet.com/article/mobile-phishing-is-a-bigger-threat-than-email-now/
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
Verizon’s 2026 DBIR found that exploiting unpatched vulnerabilities became the leading cause of data breaches in 2025, accounting for 31% of cases across more than 22,000 confirmed breaches. Credential abuse fell to 13%, while ransomware appeared in 48% of breaches. Patching performance also worsened, with the median time to fully fix flaws rising to 43 days. Third parties were involved in 48% of breaches, highlighting the growing risk from suppliers and cloud services. The findings underscore the urgency of prioritising vulnerability remediation and strengthening core security practices, as attack speeds increase and exposure expands through third-party and cloud dependencies.
Critical Microsoft Vulnerabilities Doubled: from Exposure to Escalation
Microsoft disclosed 1,273 vulnerabilities in 2025, and critical weaknesses doubled from 78 to 157. The sharpest concern is in cloud and business platforms, where critical issues in Azure and Dynamics 365 rose from 4 to 37. Microsoft Office also saw a 234% rise in vulnerabilities, increasing the risk of staff being targeted through everyday documents and emails. The findings highlight that while patching remains essential, excessive privilege and weak identity controls are enabling attackers to escalate access and extend impact across systems and cloud environments.
Cyber Attacks Cost UK Businesses £3.7Bn in Litigation in 2025
Gallagher and the independent economic research consultancy CEBR estimate that cyber attacks cost large UK businesses £11.7bn in 2025, with shareholder litigation accounting for £3.7bn and disrupted trading a further £5.4bn. Reputational damage added £573m, alongside £339m in lost customer goodwill. 88% of large UK businesses have cyber insurance, however only 59% are insured for third-party legal claims and fewer than half for regulatory fines or GDPR penalties, leaving boards exposed to costs that can continue long after systems are restored.
Crime Increasingly a ‘Serious Barrier’ to UK Growth, Say Business Leaders
The British Chambers of Commerce reports that cyber attacks are contributing to rising crime levels that are increasingly affecting UK business growth. In a survey of 1,411 firms, 21% experienced cyber attacks in the past year, alongside wider fraud and scam activity. High-profile incidents involving major UK brands demonstrate the scale of potential impact, with significant financial losses and operational disruption. The findings highlight that cyber threats are not only a security issue but a wider economic risk, requiring sustained investment and stronger support to improve business resilience and reduce disruption to growth.
https://www.theguardian.com/uk-news/2026/may/17/crime-serious-barrier-uk-growth-business-leaders
Cyber Resilience is the New Business Continuity Plan
Cyber resilience is becoming central to business continuity as disruption increasingly affects operations, customers, compliance and suppliers at the same time. Security incidents, cloud outages, identity compromise and supplier failures can quickly spread across connected systems. Effective continuity planning now depends on understanding the organisation’s most critical processes, the systems and suppliers they rely on, and how quickly they must recover. Plans should be tested against realistic scenarios, including ransomware and cloud failure, to ensure critical operations can continue when key systems or data cannot be fully trusted.
https://www.securityweek.com/cyber-resilience-is-the-new-business-continuity-plan/
Cyber Threats Push SMBs to Spend More on Security
Global market research and advisory firm IDC has found that 60% of small and medium sized businesses expect to increase cyber security spending over the next 12 months as threats increase and AI adoption accelerates. However, many remain reactive, with informal security ownership, limited planning and gaps in staff training. Nearly half say keeping up with new threats is their biggest concern, while 84% of micro businesses and 65% of small businesses are unprepared or only taking early steps to manage AI related risks, including more convincing phishing and deepfake scams.
https://www.helpnetsecurity.com/2026/05/21/idc-smbs-cybersecurity-spending-report/
When Compliance Isn’t Continuous, That’s a Security Risk
Manual governance, risk and compliance (GRC) processes are becoming a growing security risk as organisations struggle to keep pace with regulation. While 95% have introduced some automation, only 4% have fully automated the process. The burden is significant, with 83% of security leaders reporting delays from manual tasks and 58% spending over 2,000 hours a year collecting evidence. With 72% managing six or more compliance frameworks, delayed control testing and policy updates can leave leadership with an outdated view of cyber security risk, reinforcing the need for continuous monitoring of controls.
https://www.scworld.com/perspective/when-compliance-isnt-continuous-thats-a-security-risk
Taking Care of Business: The CISO’s Role in a Cyber Crisis
In a cyber crisis, the CISO’s role expands beyond managing the immediate response to helping the whole organisation protect operations, reputation and trust. Effective preparation means having clear escalation routes, tested crisis plans, defined responsibilities and joined-up communications across legal, compliance, HR, PR, business continuity and recovery teams. During and after a major incident, CISOs must translate complex security issues into business impact, support evidence gathering and regulatory obligations, guide recovery and ensure lessons learned strengthen future resilience.
Four Incident Response Mistakes That Slow Recovery and Raise Breach Costs
Organisations can lose valuable time and face higher breach costs when incident response plans are unclear, untested or disconnected from legal, insurance and specialist response teams. Common mistakes include negotiating supplier contracts during a crisis, taking rushed actions that destroy evidence, failing to involve legal advisers early, and overlooking cyber insurance notification requirements. These gaps can delay containment, prolong business disruption and increase legal or financial exposure. Regularly tested plans, agreed response roles and pre-arranged expert support help organisations recover faster while preserving critical evidence.
Governance, Risk and Compliance
Gallagher warns cyber-related litigation likely to increase - Insurance Post
Crime increasingly a ‘serious barrier’ to UK growth, say business leaders | Crime | The Guardian
Cyber threats push SMBs to spend more on security - Help Net Security
PYMNTS | WEF Says Cybersecurity Has Become Economic Priority
Boulevard of Broken Dreams: 2 Decades of Cyber Fails
Cyber Resilience is the New Business Continuity Plan - SecurityWeek
Taking care of business: The CISO's role in a cyber crisis | TechTarget
When compliance isn’t continuous, that’s a security risk | perspective | SC Media
Communicating cyber risk in dollars boards understand - Help Net Security
Threats
Ransomware, Extortion and Destructive Attacks
When ransomware gets physical: cybercriminals turn to threats of violence
The economics of ransomware 3.0 | CSO Online
Instructure cyberattack reignites ransom payment debate | TechTarget
When ransomware hits, confidence doesn’t restore endpoints - Help Net Security
The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Attacks
ISMG Editors: Should We Trust Ransomware Gangs?
Cybercrime service disrupted for abusing Microsoft platform to sign malware
Microsoft disrupts alleged malware-signing operation used by ransomware gangs
Cybersecurity Breaches Survey: Why Phishing Now Beats Ransomware – And What To D... | SC Media UK
Ransomware and Destructive Attack Victims
JLR records £244m post-tax loss after being hit by tariffs and cyber attack | Autocar
JLR Profit Drops 99 Percent After Cyber-Attack | Silicon UK Tech
M&S profits slump 25% after cyber attack hits sales - Sharecast.com
7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand - SecurityWeek
Foxconn Confirms Cyberattack, Security Experts Discuss | Security Magazine
Security pros doubt Canvas attackers really deleted stolen student data
Instructure cyberattack reignites ransom payment debate | TechTarget
FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
Phishing & Email Based Attacks
Social engineering attacks are rising as employee data becomes easier to exploit | Biometric Update
Mobile phishing is a bigger threat than email now - how to stay protected | ZDNET
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security
Phishing With Real Bait: Company Messaging Tools Reel in Scam Victims
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
201 arrested in INTERPOL disruption of phishing and fraud networks - Help Net Security
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa | CyberScoop
Researchers Warn CypherLoc Scareware Has Targeted Millions of Users - Infosecurity Magazine
Cybersecurity Breaches Survey: Why Phishing Now Beats Ransomware – And What To D... | SC Media UK
The New Phishing Click: How OAuth Consent Bypasses MFA
Other Social Engineering
Social engineering attacks are rising as employee data becomes easier to exploit | Biometric Update
Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security
Attackers bypass traditional security tools with ‘user driven’ attacks - BetaNews
Hackers Bypass Security Tools to Target Users Directly - Infosecurity Magazine
Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem
Phishing With Real Bait: Company Messaging Tools Reel in Scam Victims
Researchers Warn CypherLoc Scareware Has Targeted Millions of Users - Infosecurity Magazine
2FA/MFA
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
The New Phishing Click: How OAuth Consent Bypasses MFA
Microsoft is officially killing SMS verification for personal accounts | PCWorld
Artificial Intelligence
Tenable Warns AI Adoption Is Outpacing Governance As Cloud Exposure Risks Surge
Bank of England, FCA and Treasury Raise Alarm Over Frontier AI - Infosecurity Magazine
NCSC Publishes Guidance on Securing Agentic AI Use - Infosecurity Magazine
NCSC Warns Organisations Not To Rush Into Agentic AI
Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
The Boring Stuff is Dangerous Now
Most Organizations Use AI Agents for Sensitive Security Tasks - Infosecurity Magazine
The dual-threat landscape and evolution of digital workers - SiliconANGLE
AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Soft - Infosecurity Magazine
Cyber Pros Can't Decide If AI Is a Good or a Bad Thing
OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack - Cyber Security News
TeamPCP hackers advertise Mistral AI code repos for sale
G7 Countries Release AI SBOM Guidance - SecurityWeek
'Claw Chain' OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery - SecurityWeek
AI infrastructure is cracking under sovereignty demands - Help Net Security
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere - SecurityWeek
Anthropic's Mythos is evolving faster than expected, reports AI safety agency | ZDNET
Agentic AI opens the door to identity breach risk - CIR Magazine
ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks - Infosecurity Magazine
AI shrinks vulnerability exploitation window to hours - Help Net Security
Employee’s AI Shortcut Triggers SEC Filing — Boards, Take Note
Trump to sign order on AI oversight as security fears mount among supporters | Tacoma News Tribune
Linus Torvalds admits he has a 'love-hate relationship with AI' | ZDNET
AI can find bugs and flaws, but don't forget the cybersecurity basics
AI is drowning software maintainers in junk security reports - Help Net Security
Agent AI is Coming. Are You Ready?
Bots/Botnets
Russian APT Turla builds long-term access tool with Kazuar Botnet evolution
Careers, Roles, Skills, Working in Cyber and Information Security
Upscale vs. Upskill: The Real Cybersecurity Gap
Cloud/SaaS
Tenable Warns AI Adoption Is Outpacing Governance As Cloud Exposure Risks Surge
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
US cyber agency CISA exposed reams of passwords and cloud keys to the open web
Microsoft Self-Service Password Reset abused in Azure data theft attacks
Google Cloud suspended major customer Railway.com without cause, causing outage
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
Transit Finance hacked for $1.88 million
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
Cyber Crime, Organised Crime & Criminal Actors
Crime increasingly a ‘serious barrier’ to UK growth, say business leaders | Crime | The Guardian
When ransomware gets physical: cybercriminals turn to threats of violence
TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks
B1ack's Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards - SecurityWeek
Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica
Most dark web activity revolves around a handful of topics - Help Net Security
Data Breaches/Leaks
US cyber agency CISA exposed reams of passwords and cloud keys to the open web
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Millions Impacted Across Several US Healthcare Data Breaches - SecurityWeek
Gîtes de France cyberattack: 389,000 clients affected in France booking data breach
Data Protection
ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks - Infosecurity Magazine
Data/Digital Sovereignty
AI infrastructure is cracking under sovereignty demands - Help Net Security
Poland builds its own Signal amid security concerns
Encryption
Microsoft backpedals: Edge to stop loading passwords into memory
Fraud, Scams and Financial Crime
B1ack's Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards - SecurityWeek
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
201 arrested in INTERPOL disruption of phishing and fraud networks - Help Net Security
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa | CyberScoop
How AI can trick you into making fake payments - 5 red flags | ZDNET
Identity and Access Management
Agentic AI opens the door to identity breach risk - CIR Magazine
Insider Risk and Insider Threats
Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica
Law Enforcement Action and Take Downs
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
201 arrested in INTERPOL disruption of phishing and fraud networks - Help Net Security
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa | CyberScoop
Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica
London's police asked Big Tech for comms data over 700,000 times last year
Linux and Open Source
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
DirtyDecrypt: PoC Released for yet another Linux flaw
Debian 13.5 point release lands with security fixes, bug patches - Help Net Security
Linux kernel flaw opens root-only files to unprivileged users
Exploit released for new PinTheft Arch Linux root escalation flaw
Malware
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
Cybercrime service disrupted for abusing Microsoft platform to sign malware
Microsoft disrupts alleged malware-signing operation used by ransomware gangs
Gremlin Stealer Evolves into Modular Threat - Infosecurity Magazine
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
First Shai-Hulud Worm Clones Emerge - SecurityWeek
Russian APT Turla builds long-term access tool with Kazuar Botnet evolution
TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages - InfoQ
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
New Shai-Hulud malware wave compromises 600 npm packages
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack - SecurityWeek
GitHub confirms breach of 3,800 repos via malicious VSCode extension
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
Mobile
Mobile phishing is a bigger threat than email now - how to stay protected | ZDNET
Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices
Android Malware Used Fake Apps to Charge Users in Mass Billing Scam - Infosecurity Magazine
Outages
Alleged Huawei zero-day blamed for the 2025 Luxembourg telecom crash
Passwords, Credential Stuffing & Brute Force Attacks
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
US cyber agency CISA exposed reams of passwords and cloud keys to the open web
Microsoft backpedals: Edge to stop loading passwords into memory
Microsoft Self-Service Password Reset abused in Azure data theft attacks
You’re using a password manager, but you’re storing everything wrong
Regulations, Fines and Legislation
PYMNTS | UK Bills Target Late Payments and Cybersecurity Threats
MPs want social media treated more like unsafe toys than harmless apps
FCC walks back router update ban before it bricks America's network security
UK: The King’s Speech 2026 – Cybersecurity at the Forefront | DLA Piper - JDSupra
Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess
Trump to sign order on AI oversight as security fears mount among supporters | Tacoma News Tribune
Congress Puts Heat on Instructure After Canvas Outage
UK begins antitrust inquiry into Microsoft's business software ecosystem
Social Media
Public Instagram posts provide raw material for AI phishing campaigns - Help Net Security
MPs want social media treated more like unsafe toys than harmless apps
Software Supply Chain
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility - SecurityWeek
TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages - InfoQ
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
New Shai-Hulud malware wave compromises 600 npm packages
Developer Workstations Are Now Part of the Software Supply Chain
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack - SecurityWeek
GitHub confirms breach of 3,800 repos via malicious VSCode extension
TeamPCP breached GitHub's internal codebase via poisoned VS Code extension - Help Net Security
Supply Chain and Third Parties
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility - SecurityWeek
Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
From exposure to assurance: how data signals are reshaping supply chain security
America’s Next National Security Supply Chain Crisis Is Already Starting
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
The Newest Space Race Is Cyber - InfoRiskToday
Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive
Nation State Actors
China
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns - SecurityWeek
FCC walks back router update ban before it bricks America's network security
Trump warns Taiwan against independence - Gulf Times
Trump says he and Xi discussed cyberattacks and spying between US, China - Nextgov/FCW
Russia
NCSC warns of Russian cyber hijack threat | UKAuthority
Russian APT Turla builds long-term access tool with Kazuar Botnet evolution
Iran
Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
FrostyNeighbor Carefully Targets Govt Orgs in Poland, Ukraine
Ghostwriter group resumes attacks on Ukrainian Government targets
Tools and Controls
Q&A: Why Vulnerability Scans Are Giving Businesses a False Sense of Security - IT Security Guru
Most Organizations Use AI Agents for Sensitive Security Tasks - Infosecurity Magazine
Cyber Pros Can't Decide If AI Is a Good or a Bad Thing
AI shrinks vulnerability exploitation window to hours - Help Net Security
AI is drowning software maintainers in junk security reports - Help Net Security
Taking care of business: The CISO's role in a cyber crisis | TechTarget
How AI Hallucinations Are Creating Real Security Risks
Developer Workstations Are Now Part of the Software Supply Chain
Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess
Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere - SecurityWeek
Microsoft is officially killing SMS verification for personal accounts | PCWorld
When compliance isn’t continuous, that’s a security risk | perspective | SC Media
Four Incident Response Mistakes That Slow Recovery and Raise Breach Costs | native | MSSP Alert
You’re using a password manager, but you’re storing everything wrong
Linus Torvalds admits he has a 'love-hate relationship with AI' | ZDNET
Self-hosting your password vault eliminates the one breach that could lock you out of everything
Reports Published in the Last Week
Government publish the cyber security breaches survey 2025/2026
Attackers bypass traditional security tools with ‘user driven’ attacks - BetaNews
Hackers Bypass Security Tools to Target Users Directly - Infosecurity Magazine
Bridewell CTI Report 2026 - IT Security Guru
Verizon DBIR 2026: What The Experts Are Saying
UK Cyber Security Breaches Survey 2025/2026: Key Takeaways | Alston & Bird - JDSupra
Other News
Cybersecurity Fears Rise Ahead of 2026 FIFA World Cup | EasternEye
Cyber attacks more advanced five years on from HSE breach
Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
The End Of The Secret String: Why Cybersecurity Must Move From Hidden Keys To Governed Matter
Vulnerability Management
Q&A: Why Vulnerability Scans Are Giving Businesses a False Sense of Security - IT Security Guru
AI shrinks vulnerability exploitation window to hours - Help Net Security
Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation
The Boring Stuff is Dangerous Now
AI is drowning software maintainers in junk security reports - Help Net Security
Windows Zero-Day Barrage Continues After Patch Tuesday
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility - SecurityWeek
Google's Surge in Chrome Vulnerability Discoveries Likely Driven by AI - SecurityWeek
Microsoft to automatically roll back faulty Windows drivers
Cyber Pros Can't Decide If AI Is a Good or a Bad Thing
AI can find bugs and flaws, but don't forget the cybersecurity basics
HackerOne takes an axe to its bug bounty rewards
Linus Torvalds admits he has a 'love-hate relationship with AI' | ZDNET
Vulnerabilities
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days - SecurityWeek
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
Windows Zero-Day Barrage Continues After Patch Tuesday
CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day
Microsoft rejects critical Azure vulnerability report, no CVE issued
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
Unpatched Windows zero-day from 2020 gives hackers full system access | PCWorld
Cisco warns of an actively exploited SD-WAN flaw with max severity | CSO Online
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Hackers bypass SonicWall VPN MFA due to incomplete patching
Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix
The 4th Linux kernel flaw this month can lead to stolen SSH host keys | ZDNET
Critical Linux Kernel Flaw 'ssh-keysign-pwn' Exposes SSH Keys and Shadow Passwords
Exploit available for new DirtyDecrypt Linux root escalation flaw
Exploitation of Critical NGINX Vulnerability Begins - SecurityWeek
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Security Researchers, Aided By Anthropic's Mythos, Claim To Have Breached macOS
Max-severity flaw in ChromaDB for AI apps allows server hijacking
Debian 13.5 point release lands with security fixes, bug patches - Help Net Security
Dell confirms its SupportAssist software causes Windows BSOD crashes
Chrome 148 Update Patches Critical Vulnerabilities - SecurityWeek
Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices
This Chrome flaw could hand hackers the keys to your browser
Google accidentally exposed details of unfixed Chromium flaw
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
'Claw Chain' OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery - SecurityWeek
TrendAI Patches Apex One Zero-Day Exploited in the Wild - SecurityWeek
Critical Wordpress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 15 May 2026
Black Arrow Cyber Threat Intelligence Briefing 15 May 2026:
-Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities
-NCSC and International Partners Warn of Agentic AI Risks
-Why Agentic AI Is Security's Next Blind Spot
-Over Half of MSPs Admit to Being Breached Multiple Times in Past Year
-Businesses Ask Non-Specialist Employees to Take On Cyber Security Tasks
-Poor Employee Awareness and Skills Gap Drive Cyber Security Breaches
-Increase in Email Attacks Driven by AI and Phishing-as-a-Service
-QR Code Phishing Was ‘Fastest-Growing’ Form of Email Attacks in Q1, Reports Microsoft Threat Intelligence
-Cyber Crime Increasingly Coming with Threats of Physical Violence
-The Evolution of Cyber Risk: Addressing Geopolitical Threats
-Europe Is Moving to Block Microsoft, Amazon, and Google from Handling Government Health, Financial, and Legal Data
-Britons Build ‘Emergency Stashes’ as Fears over Cyber-Attacks and Power Cuts Grow
-AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
This week’s review of cyber security in the specialist and general media highlights the growing challenge of managing cyber risks due to AI alongside existing security practices. We consider the rapid emergence of agentic and AI-enabled capabilities that are expanding attack surfaces, introducing new vulnerabilities, and accelerating the scale and effectiveness of threats such as phishing and automated exploitation.
Alongside this, the human factor remains central. Social engineering and credential-based attacks continue to be primary entry points, and separately some organisations are allocating cyber risk management responsibilities to employees without training.
We include a report on cyber breaches affecting managed service providers (MSPs) and how economic pressure is influencing how organisations prioritise cyber security, even as breach rates and exposure continue to rise.
At Black Arrow, we consistently see that resilience depends on the organisation’s leadership and governance to align security across people, processes and technology. This week’s themes reinforce the need for organisations to take a balanced and pragmatic approach that evolves with both technological change and the broader threat landscape. Contact us to discuss how to achieve this.
Top Cyber Stories of the Last Week
Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities
Research into AI-built web applications has raised concerns about how quickly new tools can create business risk when security is not built in from the start. RedAccess reported finding 5,000 web apps created with AI development platforms that had little or no access protection, with 40% allegedly exposing sensitive information such as personal data, financial records and business plans. Several platform providers disputed parts of the findings, saying they lacked enough detail to verify the claims, but the issue highlights the need for governance over AI-created software.
NCSC and International Partners Warn of Agentic AI Risks
The UK’s NCSC and international partners have warned that agentic AI, which can act independently across systems and data, brings new risks for organisations. While it can help automate routine tasks, it may also behave unpredictably, expose connected systems to greater risk, or create uncertainty over accountability when things go wrong. The guidance recommends starting with low-risk uses, applying strict access controls, maintaining human oversight, and monitoring activity closely. Until standards mature, organisations should plan for resilience, containment, and the ability to reverse AI-driven actions quickly.
https://www.ukauthority.com/articles/ncsc-and-international-partners-warns-of-agentic-ai-risks
Why Agentic AI Is Security's Next Blind Spot
Agentic AI is already being used in many organisations to automate tasks, access data and take actions, often without security team involvement. The main risk is not the technology itself, but a lack of understanding and control over how these tools are built, what systems they can access and what actions they can take. As teams across the organisation create their own AI agents, permissions can quickly become too broad. Careful configuration, clear ownership and early security involvement are essential to limit exposure while still enabling useful innovation.
https://thehackernews.com/2026/05/why-agentic-ai-is-securitys-next-blind.html
Over Half of MSPs Admit to Being Breached Multiple Times in Past Year
CyberSmart’s 2026 MSP Survey shows that economic pressure is pushing cyber security down the agenda for many smaller businesses, with 46% of MSP customers more focused on rising costs and inflation than cyber risks. This comes despite 75% of MSPs reporting at least one breach in the past year, including 54% breached more than once. AI-enabled threats remain MSPs’ top concern at 49%. The findings indicate that economic pressure is influencing how organisations prioritise cyber security, despite continued exposure to repeated breaches and rising threat levels.
Businesses Ask Non-Specialist Employees to Take On Cyber Security Tasks
Small and medium sized organisations are increasingly relying on non-specialist staff to help manage cyber security, often without clear roles or limited training. Research commissioned by Uswitch Business Broadband found 43% of UK businesses reported a cyber security breach or attack in 2025, while over a third of employees with cyber security responsibilities said this was not part of their original job description. Training gaps remain significant, with 45% receiving only basic training and 16% receiving none. Nearly two-thirds said they had felt out of their depth at least sometimes, indicating gaps in capability as cyber security responsibilities extend beyond specialist roles.
Poor Employee Awareness and Skills Gap Drive Cyber Security Breaches
Fortinet reports that poor employee awareness remains a major factor in security incidents, cited by 56% of cyber security and IT leaders, while 54% point to a shortage of trained professionals. Familiar attack methods continue to dominate, including malware at 39%, phishing at 36% and password-related breaches at 30%. Although 73% of organisations now see cyber security as a critical priority, only 59% dedicate sufficient budget. The impact is rising, with 52% reporting average losses from cyber incidents of more than $1 million.
https://petri.com/employee-awareness-skills-gap-cybersecurity-breaches/
Increase in Email Attacks Driven by AI and Phishing-as-a-Service
Barracuda Networks reports that AI-assisted deception and ready-made phishing services are increasing both the scale and success of email attacks. Analysis of more than 3.1 billion emails in January 2026 found that one in three messages were malicious or unwanted spam, with phishing making up 48% of malicious email activity. Attackers are increasingly using links and QR codes hidden in trusted document formats, with 70% of malicious PDFs containing QR codes leading to phishing websites. Account takeover also remains a frequent risk, affecting 34% of organisations at least monthly.
https://betanews.com/article/increase-in-email-attacks-driven-by-ai-and-phishing-as-a-service/
QR Code Phishing Was ‘Fastest-Growing’ Form of Email Attacks in Q1, Reports Microsoft Threat Intelligence
Microsoft Threat Intelligence reports that email phishing remains a major threat, detecting around 8.3 billion email-based phishing attempts between January and March 2026. QR code phishing was the fastest-growing method, rising from 7.6 million attacks in January to 18.7 million in March, a 146% increase. These attacks hide harmful links inside scannable codes, often in emails or attachments, to steal login details. Attackers also used fake CAPTCHA checks and confidentiality notices to make malicious emails appear more trustworthy.
Cyber Crime Increasingly Coming with Threats of Physical Violence
Cyber criminals are increasingly combining cyber attacks with threats of physical violence to pressure victims into paying. Reported cyber crime in the US reached a record 1,008,597 cases in 2025, with losses rising to $20.8 billion, while UK cyber attacks also hit new highs. Research found that in up to 40% of global ransomware cases, criminals threatened to harm staff, rising to 46% in the US. Attackers are using stolen personal details, including home addresses, to intimidate employees, with some paying others to carry out threats or attacks.
https://www.bbc.co.uk/news/articles/cr71d8vyjv0o
The Evolution of Cyber Risk: Addressing Geopolitical Threats
Geopolitical tensions are reshaping cyber risk, with some attacks now focused on disruption and damage rather than financial gain. IBM has previously estimated that a single data breach can cost more than $4 million, while World Economic Forum research found 65% of respondents see supply chain and third-party weaknesses as their biggest barrier to cyber resilience. As third-party involvement in breaches continues to rise, organisations need tighter control over who can access critical systems, including suppliers and partners, and must plan for incidents where attackers have no incentive to stop.
https://informationsecuritybuzz.com/cyber-risk-addressing-geopolitical-threats/
Europe Is Moving to Block Microsoft, Amazon, and Google from Handling Government Health, Financial, and Legal Data
Europe is considering new rules that could restrict US cloud providers such as Microsoft, Amazon and Google from handling sensitive public sector data, including health, financial and legal records. The proposed Tech Sovereignty Package is aimed at strengthening Europe’s control over critical digital infrastructure and encouraging greater use of European cloud and AI providers. Private companies would remain free to choose their preferred platforms, but the move signals growing concern over reliance on overseas technology suppliers for essential government services.
Britons Build ‘Emergency Stashes’ as Fears over Cyber-Attacks and Power Cuts Grow
New research from Link, the UK’s ATM network, suggests more households are preparing for everyday disruption linked to cyber attacks, power cuts and payment failures. Nearly one in five Britons now keep emergency cash at home, while 47% store tinned food, 49% have battery-powered items such as torches and 37% keep power banks for mobile phones. The trend reflects growing concern that essential services, including electricity, communications and digital payments, may not always be available during a major incident.
https://www.easterneye.biz/uk-emergency-stashes-cyber-attack-fears/
AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund
The IMF has warned that AI-powered cyber attacks could destabilise the global financial system by disrupting payments, weakening solvency and straining liquidity. The risk is heightened by financial firms’ reliance on shared cloud services, where one weakness can affect many organisations at once. The concern extends beyond banking, as finance, energy, telecoms and public services often depend on the same digital infrastructure. The IMF called for stronger international cooperation, better regulation and greater investment in resilience, including disaster recovery, business continuity and human oversight of AI-enabled security tools.
Governance, Risk and Compliance
Cyber risks top business threats for first time
90% Of SMEs Losing Sleep As Business Risks Rise
Why Cyber Governance Will Define The Next Generation Of Market Leader
The missing cybersecurity leader in small business | CyberScoop
Over Half of MSPs Admit to Being Breached Multiple Times in Past Year - IT Security Guru
Cybersecurity is now where the real heists happen – but are companies ready? - Digital Journal
Poor Employee Awareness and Skills Gap Drive Cybersecurity Breaches
Cybersecurity Without Awareness Is Like Driving Without Knowing The Rules
CISOs: Align cyber risk communication with boardroom psychology | CSO Online
Why Cyber Insurance Faces New AI Liability Risks
Why boards must stop chasing buzzwords | perspective | SC Media
The Critical Cyber Skills Every Security Team Still Needs
Inside the 2026 Cyber Threat Landscape: Data-Driven Security Priorities - Security Boulevard
Cyber cover needs to get explicit as risk evolution continues unchecked
UK government renews calls to sign Cyber Resilience Pledge | Computer Weekly
Threats
Ransomware, Extortion and Destructive Attacks
Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers - Infosecurity Magazine
Reviewing the trends in ransomware attacks in 2026 | Securelist
The State of Ransomware - Q1 2026 - Check Point Research
WannaCry, the ransomware attack that changed the history of cybersecurity
90% of ransomware attacks target SMEs: SK shieldus - The Korea Herald
Tables Turned: Gentlemen Ransomware Group Suffers Data Leak
Ransomware and Destructive Attack Victims
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
Ransomware Group Takes Credit for Trellix Hack - SecurityWeek
International cyber attack disrupts swath of universities and schools - BBC News
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach | EdScoop
RansomHouse says it breached Trellix and exposes internal systems
Lapsus$ dumps Vodafone source code online after failed extortion attempt | Cybernews
Instructure claims hackers returned stolen Canvas data after an extortion standoff | CyberScoop
West Pharmaceutical says hackers stole data, encrypted systems
Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft
Phishing & Email Based Attacks
Over 500 Organizations Hit in Years-Long Phishing Campaign - SecurityWeek
When the Breach Gets In Through the CEO's Inbox, Not the Firewall - IT Security Guru
Increase in email attacks driven by AI and phishing-as-a-service - BetaNews
Tech Can't Stop These Threats — Your People Can
Other Social Engineering
When the Breach Gets In Through the CEO's Inbox, Not the Firewall - IT Security Guru
Tech Can't Stop These Threats — Your People Can
Signal adds security warnings for social engineering, phishing attacks
Plymouth radio station closes after 'ruthless' cyber attack | Plymouth Live
Artificial Intelligence
NCSC and international partners warns of agentic AI risks | UKAuthority
Artificial Intelligence And The End Of Digital Security As We Know It
Why Agentic AI Is Security's Next Blind Spot
PYMNTS | The End of the Artisanal Hack: How AI Industrialized Cybercr…
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Increase in email attacks driven by AI and phishing-as-a-service - BetaNews
Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities
Prepare for AI-driven patch correction - NCSC | UKAuthority
ECB Urges Banks to Quickly Prepare for AI-Assisted Cyberattacks
Why Cyber Insurance Faces New AI Liability Risks
Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking - SecurityWeek
Claude Code trust prompt can trigger one-click RCE
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoop
Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information
Hackers abuse Google ads, Claude.ai chats to push Mac malware
UK schools blackmailed with sexualised AI deepfakes of pupils, experts warn | The Independent
Ollama vulnerability highlights danger of AI frameworks with unrestricted access | CSO Online
Hugging Face Packages Weaponized With a Single File Tweak
US bank reports itself after AI customer data mishap
Fighting fire with fire: Defending against Mythos-powered cyberattacks | resource | SC Media
What Security Leaders Say About the First AI-Developed Zero-Day Exploit | Security Magazine
White House considers implementing regulations on AI technology | The Jerusalem Post
Experts say Mythos is not a threat, instead it is exposing how vulnerable enterprises already are
AI-Powered Cyberattacks Put MSSPs and SOC Teams Under Pressure | news | MSSP Alert
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
Attackers Use Fake OpenAI Model to Push Credential-Stealing Malware - Security Boulevard
Japan’s PM orders cybersecurity review to defend against Anthropic Mythos
Bots/Botnets
NCSC warns of China-linked botnet attacks on UK targets
Careers, Roles, Skills, Working in Cyber and Information Security
The Critical Cyber Skills Every Security Team Still Needs
Computer Misuse Act reform to move forward in National Security Bill | Computer Weekly
AI models are getting better at replacing cybersecurity pros on certain tasks
Cloud/SaaS
'PCPJack' cloud worm hijacks TeamPCP hacker infrastructure - iTnews
After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Crypto gang member gets 6.5 years for role in $230 million heist
Why a 2017 Linux bug is now a major concern for the crypto industry
Cyber Crime, Organised Crime & Criminal Actors
Cyber-crime increasingly coming with threats of physical violence - BBC News
Cybersecurity is now where the real heists happen – but are companies ready? - Digital Journal
Cybercrime's Human Trafficking Problem - GovInfoSecurity
Kids as young as 8 are groomed into cybercrime through Minecraft and Roblox: Report - Dexerto
Data after the breach: Economics of the dark web | TechTarget
Police Shut Relaunched Crimenetwork Dark Web Marketplace - Infosecurity Magazine
Data Breaches/Leaks
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
One in four organizations have exposed MySQL databases - BetaNews
US bank reports itself after AI customer data mishap
Data after the breach: Economics of the dark web | TechTarget
UK fines water supplier $1.3M for exposing data of 664k customers
Dutch lab failed security standards before 850K breach | Cybernews
Ransomware Group Takes Credit for Trellix Hack - SecurityWeek
Lapsus$ dumps Vodafone source code online after failed extortion attempt | Cybernews
Tables Turned: Gentlemen Ransomware Group Suffers Data Leak
Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident
Škoda Security Incident Exposes Customers Data From Online Shop
Identity security firm SailPoint discloses GitHub repository breach
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
West Pharmaceutical says hackers stole data, encrypted systems
Data/Digital Sovereignty
Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads
Encryption
New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes
60% of MD5 password hashes are crackable in under an hour
Instagram removed end-to-end encryption for DMs. What should users do?
Meta: Lawsuit Claiming WhatsApp Lacks End-to-End Encryption Is Falling Apart | PCMag
Your iPhone RCS chats with Android are encrypted in iOS 26.5: How to verify E2E is enabled | ZDNET
Apple, Google drag cross-platform texting into the encrypted age
Fraud, Scams and Financial Crime
Silent phone call scam in France: how AI voice theft can steal your identity
How AI job scams are destroying people’s hopes | Job hunting | The Guardian
How to detect AI in fraudulent job applicants - Raconteur
Sri Lanka makes 37 arrests as it raids another scam centre
Signal adds security warnings for social engineering, phishing attacks
Your Android phone is about to get much better at blocking scams - Digital Trends
Identity and Access Management
Why Changing Passwords Doesn’t End an Active Directory Breach
How Stealer Logs Lead to Active Directory Incidents
Insider Risk and Insider Threats
When the Breach Gets In Through the CEO's Inbox, Not the Firewall - IT Security Guru
Tech Can't Stop These Threats — Your People Can
Poor Employee Awareness and Skills Gap Drive Cybersecurity Breaches
Cybersecurity Without Awareness Is Like Driving Without Knowing The Rules
Former govt contractor convicted for wiping dozens of federal databases
Insurance
Why Cyber Insurance Faces New AI Liability Risks
Cyber cover needs to get explicit as risk evolution continues unchecked
77 percent of SMEs don’t understand cyber insurance - BetaNews
Internet of Things – IoT
Police equipment can be tracked via Bluetooth. What about your phone, watch and headphones?
Hacking one shared IoT device (e-scooters, e-bikes, cars, chargers, etc.) to rule them all.
China-linked Yarbo fixes robot mower hacking flaw | Cybernews
Law Enforcement Action and Take Downs
Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested - SecurityWeek
Crypto gang member gets 6.5 years for role in $230 million heist
Former govt contractor convicted for wiping dozens of federal databases
Sri Lanka makes 37 arrests as it raids another scam centre
Met Police Arrest 173 In Live Facial Recognition Trial | Silicon UK
Linux and Open Source
Dirty Frag is a new Linux bug putting your system at risk - and there's no easy fix yet | ZDNET
Dirty Frag Exploit Poised to Blow Up on Enterprise Linux Distros
Rushed Patches Follow Broken Embargo on Linux Kernel Vulnerabilities - Infosecurity Magazine
Linux is getting a security wake-up call - why it was inevitable and I'm not worried | ZDNET
Why a 2017 Linux bug is now a major concern for the crypto industry
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
Malvertising
Hackers abuse Google ads, Claude.ai chats to push Mac malware
Malware is now hiding in Google search ads — here's how to protect yourself
Malware
After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
Mistral AI and TanStack hit in supply chain attack with SLSA-attested malware - Cryptopolitan
Attackers Use Fake OpenAI Model to Push Credential-Stealing Malware - Security Boulevard
Worm rubs out competitor's malware, then takes control
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
Official JDownloader site served malware to Windows and Linux users between May 6 and May 7
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Hackers abuse Google ads, Claude.ai chats to push Mac malware
Malware is now hiding in Google search ads — here's how to protect yourself
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
How Stealer Logs Lead to Active Directory Incidents
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux
Official CheckMarx Jenkins package compromised with infostealer
Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor
Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware - SecurityWeek
Misinformation, Disinformation and Propaganda
Mobile
Android banking Trojan TrickMo evolves using TON network for C2
Signal adds security warnings for social engineering, phishing attacks
Your Android phone is about to get much better at blocking scams - Digital Trends
Your iPhone RCS chats with Android are encrypted in iOS 26.5: How to verify E2E is enabled | ZDNET
Apple, Google drag cross-platform texting into the encrypted age
Models, Frameworks and Standards
Mapping NIS2 controls to ISO 27001 and NIST CSF for UK SMEs - Security Boulevard
Here’s how NIST is teeing up guidance for securing AI | Federal News Network
What businesses need to know about the update to Cyber Essentials | IT Pro
UK government renews calls to sign Cyber Resilience Pledge | Computer Weekly
Online Safety Act Failing To Deliver “step Change” For Children
Passwords, Credential Stuffing & Brute Force Attacks
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
Why Changing Passwords Doesn’t End an Active Directory Breach
60% of MD5 password hashes are crackable in under an hour
Regulations, Fines and Legislation
Computer Misuse Act reform to move forward in National Security Bill | Computer Weekly
2026 Kings Speech - New UK Cyber Security Laws and Broadband Rights for Leaseholders - ISPreview UK
US bank reports itself after AI customer data mishap
UK fines water supplier $1.3M for exposing data of 664k customers
ECB Urges Banks to Quickly Prepare for AI-Assisted Cyberattacks
Online Safety Act Failing To Deliver “step Change” For Children
White House considers implementing regulations on AI technology | The Jerusalem Post
US govt seeks Instructure testimony on massive Canvas cyberattack
Social Media
Instagram removed end-to-end encryption for DMs. What should users do?
Supply Chain and Third Parties
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
The Cybersecurity Gap No One Owns: You’re Securing The Wrong Perimeter
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft
Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Understanding the Cyber Security Fallout of Geopolitical Tensions
The Evolution Of Cyber Risk: Addressing Geopolitical Threats
Cyberattacks on Poland's Water Plants: A Blueprint for Hybrid Warfare - Security Affairs
Feds urge greater protection of critical infrastructure from Chinese hacks
Britons Build Emergency Stashes Amid Cyber Attack Fears | EasternEye
“Cyberwar is already in Poland,” Polish deputy prime minister says
AI, Cyberwarfare, and Autonomous Weapons: Inside America’s New Military Strategy
Fresh Handala shenanigans prove Iranian hackers don’t care about any ceasefires | Cybernews
Cyber Espionage Group Targets Aviation Firms to Steal Map Data
Russian Attacks on Polish Water Utilities Use Fear as Weapon
Nation State Actors
Understanding the Cyber Security Fallout of Geopolitical Tensions
The Evolution Of Cyber Risk: Addressing Geopolitical Threats
State-sponsored actors, better known as the friends you don’t want
Britons Build Emergency Stashes Amid Cyber Attack Fears | EasternEye
State-backed hackers hammer Palo Alto firewall zero-day before patch lands
China
NCSC warns of China-linked botnet attacks on UK targets
Feds urge greater protection of critical infrastructure from Chinese hacks
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
Russia
Cyberattacks on Poland's Water Plants: A Blueprint for Hybrid Warfare - Security Affairs
“Cyberwar is already in Poland,” Polish deputy prime minister says
Russian Attacks on Polish Water Utilities Use Fear as Weapon
Inside Department 4: Russia's secret school for hackers
“Russia is already testing NATO”
Iran
Fresh Handala shenanigans prove Iranian hackers don’t care about any ceasefires | Cybernews
Iran's cyberwar reaches the families of American troops - Asia Times
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Understanding the Cyber Security Fallout of Geopolitical Tensions
The Evolution Of Cyber Risk: Addressing Geopolitical Threats
Tools and Controls
Vibe Coding Is Causing ‘Thousands’ of Data Security Vulnerabilities
Prepare for AI-driven patch correction - NCSC | UKAuthority
CISOs: Align cyber risk communication with boardroom psychology | CSO Online
How Stealer Logs Lead to Active Directory Incidents
Why Cyber Insurance Faces New AI Liability Risks
Cyber cover needs to get explicit as risk evolution continues unchecked
Poor Employee Awareness and Skills Gap Drive Cybersecurity Breaches
Cybersecurity Without Awareness Is Like Driving Without Knowing The Rules
Ollama vulnerability highlights danger of AI frameworks with unrestricted access | CSO Online
Fighting fire with fire: Defending against Mythos-powered cyberattacks | resource | SC Media
Legacy Security Tools Are Failing Data Protection - Infosecurity Magazine
One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk
The patching treadmill: Why traditional application security is no longer enough | ZDNET
Day Zero Readiness: The Operational Gaps That Break Incident Response
Traditional MDR Is Reaching Its Limit | news | MSSP Alert
Experts say Mythos is not a threat, instead it is exposing how vulnerable enterprises already are
Japan’s PM orders cybersecurity review to defend against Anthropic Mythos
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? - SecurityWeek
Daybreak is OpenAI's answer to the AI arms race in cybersecurity | CyberScoop
Your Android phone is about to get much better at blocking scams - Digital Trends
EU says OpenAI offers to open access to cybersecurity model, Anthropic not there yet - CNA
Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
CISO's guide: How to test an incident response plan | TechTarget
94 percent of cyberattacks use VPNs or residential proxies - BetaNews
Other News
94 percent of cyberattacks use VPNs or residential proxies - BetaNews
Cybercrime's Human Trafficking Problem - GovInfoSecurity
The most dangerous threats to the internet in 2026
Simon Pegg’s Tense 2-Part Cyber-Thriller Returns With a New Nightmare
Construction sector urged to build better cyber security strategies
Germany plans 'active cyberdefence' as online attacks rise - The Economic Times
Taiwan's train cyber-trauma reveals a global system that’s coming off the tracks
Vulnerability Management
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Prepare for AI-driven patch correction - NCSC | UKAuthority
Ollama vulnerability highlights danger of AI frameworks with unrestricted access | CSO Online
Experts say Mythos is not a threat, instead it is exposing how vulnerable enterprises already are
The patching treadmill: Why traditional application security is no longer enough | ZDNET
What Security Leaders Say About the First AI-Developed Zero-Day Exploit | Security Magazine
Daybreak is OpenAI's answer to the AI arms race in cybersecurity | CyberScoop
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks | CyberScoop
Linux is getting a security wake-up call - why it was inevitable and I'm not worried | ZDNET
Vulnerabilities
Microsoft Patch Tuesday May 2026 - 120 Vulnerabilities Fixed, Including 29 Critical RCE Flaws
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks
New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes
Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises - SecurityWeek
Microsoft fixes Windows Autopatch bug installing restricted drivers
Windows BitLocker zero-day gives access to protected drives, PoC released
Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information
Critical Palo Alto Networks software bug hits exposed firewalls | CSO Online
State-backed hackers hammer Palo Alto firewall zero-day before patch lands
Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 - SecurityWeek
F5 Patches Over 50 Vulnerabilities - SecurityWeek
F5 patches 18-year-old AI-found 'Rift' vulnerability in NGINX web server - iTnews
SAP Patches Critical S/4HANA, Commerce Vulnerabilities - SecurityWeek
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
Dirty Frag is a new Linux bug putting your system at risk - and there's no easy fix yet | ZDNET
New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials
'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit
Adobe Patches 52 Vulnerabilities in 10 Products - SecurityWeek
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI | CyberScoop
Apple Patches Dozens of Vulnerabilities in macOS, iOS - SecurityWeek
Apple Alerted to macOS Security Vulnerability Uncovered With AI Tool - MacRumors
Broadcom releases VMware Fusion security update for root access bug
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
New critical Exim mailer flaw allows remote code execution
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
18-year-old NGINX vulnerability allows DoS, potential RCE
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations
Avada Builder Flaws Expose One Million WordPress Sites - Infosecurity Magazine
Bug hunter tracks down three serious MCP database flaws, one left unpatched
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 08 May 2026
Black Arrow Cyber Threat Intelligence Briefing 08 May 2026:
-Cyber is the Number One Global “People Risk,” Says Marsh
-Employees Are Now More Dangerous to Their Company than External Hackers
-Your Employees Know What Phishing Looks Like. They’re Still Getting Fooled. Here’s Why.
-Nearly Half of Initial Access Attacks Start with One Human Mistake
-86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds
-Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
-Researchers Discover New All-in-One ‘Bluekit’ Phishing Kit Capable of Bypassing Enterprise 2FA Protocols and Emulating 40+ Global Brands
-MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
-Only One in Nine Ransomware Attacks Is Made Public
-Five Eyes Spook Shops Warn Rapid Rollouts of Agentic AI Are Too Risky
-AI Speeds Flaw Discovery, Forcing Rapid Updates, UK NCSC Warns
-Bank Executives Cite Economy, Cyber Security Risks as Top Concerns
-North Korea Stole 76% of All Crypto Taken in 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
This week’s review of cyber security in the specialist and general media highlights employees and the risks they bring to their employer’s security. Research cited this week reports that cyber is the top global people risk, including employees sharing sensitive company information when using AI, and employees enabling attacks by falling for phishing emails and other malicious communications. At Black Arrow, we address this in our work with our clients, where we use our expertise and qualifications in HR and cyber security to strengthen the role that employees play in protecting their organisations.
In our review this week, we also look deeper at the evolution of ransomware, including toolkits used by attackers and insights into the prevalence of ransomware attacks. We further highlight the risks and misuse of AI, which has led bank executives to flag cyber security as their top risk.
At Black Arrow, we are consistent in our messaging that cyber security can only be achieved by aligned controls across people, operations and technology, as reinforced by insights from this week’s review. Contact us to discuss how to address this in a pragmatic way.
Top Cyber Stories of the Last Week
Cyber is the Number One Global “People Risk,” Says Marsh
Marsh’s 2026 People Risks report, based on interviews with more than 4,500 HR and risk professionals across 26 markets, ranks cyber related challenges as the leading global people risk. Weak cyber threat awareness, shortages in cyber and AI skills, poor understanding of AI risks and mishandling of data all feature in the top 10 concerns. These issues can increase the likelihood of cyber attacks, disrupt operations, damage trust and slow business progress, while 40% of respondents with effective people risk management initiatives reported improved workforce productivity, and 36% saw faster progress on strategic initiatives such as AI adoption.
https://www.infosecurity-magazine.com/news/cyber-number-one-global-people/
Employees Are Now More Dangerous to Their Company than External Hackers
Orange Cyberdefense reports that internal security risks now account for 57% of incidents, up from 47% in less than a year, overtaking external hacking for the first time. Employee misuse has risen sharply from 29% to 45%, often linked to unapproved tools such as public AI apps where sensitive information may be shared. Staff devices were involved in 53% of incidents, while identity attacks, where criminals use stolen login details, increased from 10% to 17%. Organisations should tighten access controls and multi-factor authentication to help reduce this growing risk.
Your Employees Know What Phishing Looks Like. They’re Still Getting Fooled. Here’s Why.
AI is making phishing emails and messages harder to spot, with 72% of surveyed workers saying attempts are more convincing than a year ago and 66% believing AI could impersonate a colleague. The risk is not simply lack of training. Employees often recognise the warning signs, but still click or respond when rushing, multitasking or working after hours. Nearly 70% check work messages outside normal hours, increasing exposure when attention is lower. Organisations should review response expectations, approval processes and communication habits so staff have clear, normal opportunities to pause and verify unusual requests.
Nearly Half of Initial Access Attacks Start with One Human Mistake
Attackers are continuing to exploit everyday human behaviour, with ClickFix attacks accounting for 47% of initial access incidents observed over the past year. These attacks present users with a fake technical problem, such as a broken verification check or failed update, then guide them into running a harmful command that appears to fix it. The approach requires no advanced flaw or complex exploit, just pressure, trust and a desire to stay productive. For organisations, this highlights the need to treat human risk as a continuous cyber security priority, supported by monitoring for unusual user activity.
86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds
KnowBe4 reports that phishing is becoming more sophisticated, with 86% of attacks now AI driven. Over the past six months, calendar invite phishing rose by 49%, Microsoft Teams attacks increased by 41%, and the use of tools to steal Microsoft 365 login details surged by 139%. Attackers are also moving beyond email, using multiple channels at once and impersonating internal teams, seen in 30% of attacks in early 2026. This highlights a growing need to protect people, collaboration tools and AI systems together.
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
A phishing campaign active since at least April 2025 has affected more than 80 organisations, mainly in the US, by tricking victims into installing legitimate remote access tools. The emails impersonated the US Social Security Administration and used compromised websites to avoid basic email filtering. Once installed, the tools gave attackers ongoing access to devices, including the ability to view screens, transfer files and return later. Because the software is legitimate and digitally signed, traditional security tools may not flag the activity as suspicious.
https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html
Researchers Discover New All-in-One ‘Bluekit’ Phishing Kit Capable of Bypassing Enterprise 2FA Protocols and Emulating 40+ Global Brands
Bluekit is a new phishing platform that makes it easier for criminals to launch convincing attacks at scale. It can imitate more than 40 global brands, automate campaign setup, alert attackers when data is stolen and use AI to draft tailored phishing emails. More concerningly, it can steal active browser sessions, which may allow attackers to bypass multi-factor authentication by appearing to be a legitimate user. Its rapid development reinforces the value of phishing-resistant authentication, such as hardware security keys, alongside regular staff awareness testing.
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
Rapid7 has linked a Microsoft Teams based credential theft campaign to Iranian state-backed attackers posing as a ransomware group. The incident used screen sharing and fake IT support tactics to trick staff into revealing passwords and approving multi-factor authentication requests. Rather than encrypting files, the attackers focused on stealing data and keeping long-term access through remote management tools. The case highlights a growing trend where state-linked groups use criminal ransomware brands and widely available cyber crime tools to hide their involvement and slow down response efforts.
https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html
Only One in Nine Ransomware Attacks Is Made Public
Ransomware appears to be significantly under-reported, with BlackFog identifying 2,160 undisclosed attacks in the first quarter, compared with just 264 publicly disclosed incidents. The average ransom demand exceeded $1 million, with victims across 97 countries. Healthcare was the most targeted sector, accounting for 27% of reported attacks, followed by government and technology. Logistics saw a 200% year-on-year increase. The findings also show that stolen data was involved in 96% of attacks, highlighting the growing risk of sensitive information being taken before disruption is even visible.
https://betanews.com/article/only-one-in-nine-ransomware-attacks-is-made-public/
Five Eyes Spook Shops Warn Rapid Rollouts of Agentic AI Are Too Risky
Five Eyes security agencies (UK, US, Canada, Australia and New Zealand) have warned that rapid adoption of agentic AI, where systems can take actions on behalf of users, could create new risks across critical infrastructure and defence. Their joint guidance highlights 23 risks and more than 100 recommended safeguards, noting that these systems often rely on multiple tools, data sources and permissions. If poorly controlled, they could be exploited to alter contracts, approve payments or delete audit records. Organisations are advised to adopt agentic AI gradually, starting with low-risk tasks and maintaining strong human oversight.
AI Speeds Flaw Discovery, Forcing Rapid Updates, UK NCSC Warns
The UK National Cyber Security Centre (NCSC) has warned that artificial intelligence is accelerating the discovery of weaknesses in software, increasing the likelihood of a surge in urgent security updates. Skilled attackers can now find and exploit flaws faster, creating pressure for organisations to update systems quickly across cloud, supplier and internal technology environments. Priority should be given to internet-facing systems, critical security tools and older technologies that no longer receive updates. Where possible, automatic updates should be enabled, supported by clear risk-based processes to decide what must be fixed first.
Bank Executives Cite Economy, Cyber Security Risks as Top Concerns
Bank executives are increasingly concerned about economic uncertainty and cyber security risk, with IntraFi’s Q1 2026 survey of 409 US bank leaders finding 29% cited cyber security and fraud as their top concern for the year ahead. Many pointed to criminals’ growing use of artificial intelligence, where software can be used to create more convincing scams or automate attacks. A possible economic downturn was also a major worry, cited by 56% as either the biggest or second biggest concern.
North Korea Stole 76% of All Crypto Taken in 2026
North Korea-linked hackers accounted for 76% of all cryptocurrency stolen by cyber criminals in 2026 up to the end of April, according to TRM Labs. Two attacks alone drained $577 million from decentralised finance platforms, despite representing only 3% of recorded incidents. The group has reportedly stolen more than $6 billion from crypto protocols since 2017, with its share of theft rising sharply each year. The incidents highlight the scale and sophistication of long‑planned intrusion activity, as well as weaknesses in complex digital finance platforms.
https://coinmarketcap.com/academy/article/north-korea-crypto-theft-76-percent-2026
Governance, Risk and Compliance
Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine
UK business breach rate stuck at 43%... blame the phishing • The Register
Almost half of UK businesses hit by cyber attacks | Computer Weekly
UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK
Cyber still dominates global risk thinking – Marsh
Skills Gap Top CISO Concern, Says New SANS Survey
Bank Executives Cite Economy, Cybersecurity Risks as Top Concerns
How CISOs should utilize data security posture management to inform risk | CSO Online
Threats
Ransomware, Extortion and Destructive Attacks
Only one in nine ransomware attacks is made public - BetaNews
Ransomware victims increase 389 percent fueled by AI - BetaNews
Two new extortion crews are speedrunning the Scattered Spider playbook | CyberScoop
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
Iranian cyber espionage disguised as a Chaos Ransomware attack
Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server
Cybersecurity pros jailed for ransomware attacks linked to ALPHV BlackCat | Cybernews
How safe is your money from cyber attack?
Conti, Akira ransomware affiliate given 8-year sentence | The Record from Recorded Future News
Karakurt Ransomware Negotiator Sentenced to Prison - SecurityWeek
Ransom Attacks up, but Payments Headed Down as Cyber Becomes Top of Mind
Five Years On: Lessons Learned From the Colonial Pipeline Cyber-Attack - Infosecurity Magazine
Member Of Russian Ransomware Group Sentenced To Prison – Eurasia Review
Two cybersecurity pros get prison time for helping ransomware gang - Help Net Security
Ransomware and Destructive Attack Victims
Five Years On: Lessons Learned From the Colonial Pipeline Cyber-Attack - Infosecurity Magazine
Instructure confirms data breach, ShinyHunters claims attack
Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats - SecurityWeek
Sandhills Medical Says Ransomware Breach Affects 170,000 - SecurityWeek
Cushman & Wakefield confirms vishing cyberattack
DOJ says ransomware gang tapped into Russian government databases | TechCrunch
Phishing & Email Based Attacks
86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds - IT Security Guru
Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine
Email threat landscape: Q1 2026 trends and insights | Microsoft Security Blog
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard
Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace
Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails - Infosecurity Magazine
The Mimecast Portal BEC risk: how attackers stay in the inbox after a password reset | TechFinitive
30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
Fake SSA Emails Drive Venomous#Helper Phishing Campaign - Infosecurity Magazine
Attackers Abuse Amazon SES to Send Authenticated Phishing Emails That Bypass Security
Education Sector Under Attack From State Espionage, Spear-Phishing, and Supply Chain Attacks
Business Email Compromise (BEC)/Email Account Compromise (EAC)
The Mimecast Portal BEC risk: how attackers stay in the inbox after a password reset | TechFinitive
Other Social Engineering
Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine
ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard
Nearly Half of Initial Access Attacks Start With One Human Mistake | perspective | MSSP Alert
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Hugging Face, ClawHub Abused for Malware Distribution - SecurityWeek
Fake background remover spreads password-stealing malware | Cybernews
You’ve hired a fraudulent employee. What comes next? | HR Dive
DigiCert breached via malicious screensaver file - Help Net Security
Romance fraudsters fleeced UK victims of £102M in 2025
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US)
ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog
Your job search is getting riskier, says LinkedIn - 9 ways to tell real listings from scams | ZDNET
Cushman & Wakefield confirms vishing cyberattack
2FA/MFA
ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs | CSO Online
Artificial Intelligence
Five Eyes warn agentic AI is too dangerous for rapid rollout • The Register
86% of Phishing Attacks are AI Driven, KnowBe4 Research Finds - IT Security Guru
New Bluekit phishing service includes an AI assistant, 40 templates
UK cyber security agency warns of AI-driven 'patch wave' - iTnews
The AI Vulnerability Storm Is Here. Is Your Security Program Breach Ready? - Security Boulevard
AI speeds flaw discovery, forcing rapid updates, UK NCSC warns
AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed - Infosecurity Magazine
Your AI Agents Are Already Inside the Perimeter. Do You Know What They're Doing?
UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK
If AI's So Smart, Why Does It Keep Deleting Production Databases?
AI digs up decades of code debt. Patch up. • The Register
Shadow AI risks deepen as 31% of users get no employer training - Help Net Security
We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is
Malicious OpenClaw DeepSeek Skill Exploits Agentic AI Workflows to Deliver RAT and Stealer
Hugging Face, ClawHub Abused for Malware Distribution - SecurityWeek
How safe is your money from cyber attack?
Cyber talent harder to find as AI reshapes threat landscape - CNA
Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn – POLITICO
Does Anthropic's Claude Mythos break the cyber insurance underwriting model? | Insurance Times
Malicious PyTorch Lightning update hits AI supply chain security
Mythos is 'very heightened risk': JPMorganChase's Jamie Dimon | American Banker
One in four MCP servers opens AI agent security to code execution risk - Help Net Security
British mathematician hands OpenClaw agent a credit card
Why Chrome may have quietly downloaded a 4GB file to your PC - and how to get rid of it | ZDNET
Met Police face criticism for using AI to spy on their own officers - Help Net Security
AI-BOMs replace SBOMs as way to track AI agents and bots • The Register
India orders infosec red alert in case Mythos sparks crime
When AI Starts Making Decisions, Cybersecurity Becomes A Governance Issue | Scoop News
Careers, Roles, Skills, Working in Cyber and Information Security
CISOs step up to the security workforce challenge | CSO Online
Cyber talent harder to find as AI reshapes threat landscape - CNA
Anthropic’s Mythos and the global cybersecurity gap - Rest of World
Skills Gap Top CISO Concern, Says New SANS Survey
Cloud/SaaS
ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts - Security Boulevard
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace
Azure AD Conditional Access Bypassed Through Phantom Device Registration and PRT Abuse
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
North Korea Stole 76% of All Crypto Taken in 2026 | CoinMarketCap
Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring
Police dismantles 9 crypto scam centers, arrests 276 suspects
Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M
New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware
Cyber Crime, Organised Crime & Criminal Actors
Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring
Police dismantles 9 crypto scam centers, arrests 276 suspects
Europol Busts Albanian Scam Call Centers in Major Online Fraud Case - Infosecurity Magazine
French prosecutors link 15-year-old to gov mega-breach • The Register
Data Breaches/Leaks
French prosecutors link 15-year-old to gov mega-breach • The Register
Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats
Trellix Source Code Breach Highlights Supply Chain Threats
Instructure hacker claims data theft from 8,800 schools, universities
Police statement 10 months after Glasgow City Council cyber attack | Glasgow Times
A DOD contractor’s API flaw exposed military course data and service member records | CyberScoop
Sandhills Medical Says Ransomware Breach Affects 170,000 - SecurityWeek
Denial of Service/DoS/DDoS
Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack
New Cisco DoS flaw requires manual reboot to revive devices
Encryption
Agent’s claims on WhatsApp access spark security concerns
What to Know About Quantum Computing and Your Cybersecurity Progr
Fraud, Scams and Financial Crime
Romance fraudsters fleeced UK victims of £102M in 2025
Darkhub Hacking-for-Hire Portal Advertises Crypto Fraud, Message Interception, and Monitoring
You’ve hired a fraudulent employee. What comes next? | HR Dive
Police dismantles 9 crypto scam centers, arrests 276 suspects
Europol Busts Albanian Scam Call Centers in Major Online Fraud Case - Infosecurity Magazine
Your job search is getting riskier, says LinkedIn - 9 ways to tell real listings from scams | ZDNET
Insider Risk and Insider Threats
1 in 8 workers say selling company logins is justifiable
You’ve hired a fraudulent employee. What comes next? | HR Dive
Cyber is the Number One Global “People Risk,” Says Marsh - Infosecurity Magazine
Employees are now more dangerous to their company than external hackers | TechRadar
Nearly Half of Initial Access Attacks Start With One Human Mistake | perspective | MSSP Alert
Why Trained Employees Are Still Falling for Phishing Attacks
Insurance
How cyber insurance helped with breach recovery -- or not | TechTarget
Does Anthropic's Claude Mythos break the cyber insurance underwriting model? | Insurance Times
Law Enforcement Action and Take Downs
US ransomware negotiators get 4 years in prison over BlackCat attacks
Police dismantles 9 crypto scam centers, arrests 276 suspects
Europol Busts Albanian Scam Call Centers in Major Online Fraud Case - Infosecurity Magazine
French prosecutors link 15-year-old to gov mega-breach • The Register
A Ransomware Negotiator Was Working for a Ransomware Gang - Schneier on Security
Conti, Akira ransomware affiliate given 8-year sentence | The Record from Recorded Future News
Karakurt Ransomware Negotiator Sentenced to Prison - SecurityWeek
Police statement 10 months after Glasgow City Council cyber attack | Glasgow Times
Member Of Russian Ransomware Group Sentenced To Prison – Eurasia Review
Two cybersecurity pros get prison time for helping ransomware gang - Help Net Security
Russian hacker pleads guilty to cyberattacks on US, Ukrainian oil and gas facilities
Linux and Open Source
The Evolution of Open Source Malware: From Volume to Trust Abuse
Canonical Says Ubuntu Infrastructure Is Facing Cross-Border DDoS Attack
New stealthy Quasar Linux malware targets software developers
Malware
Malicious OpenClaw DeepSeek Skill Exploits Agentic AI Workflows to Deliver RAT and Stealer
Hugging Face, ClawHub Abused for Malware Distribution - SecurityWeek
Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs | CSO Online
Fake background remover spreads password-stealing malware | Cybernews
ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog
New Deep#Door RAT uses stealth and persistence to target Windows
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom - SecurityWeek
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack - Ars Technica
The Evolution of Open Source Malware: From Volume to Trust Abuse
New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware
New stealthy Quasar Linux malware targets software developers
New MicroStealer Malware Actively Attacking Telecom & Education Sectors
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
North Korean APT Targets Yanbian Gamers via Trojanized Platform - Infosecurity Magazine
Mobile
Attacks Abuse Windows Phone Link to Steal Texts & Bypass 2FA
Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs | CSO Online
New FEMITBOT Network Uses Telegram Mini Apps to Push Crypto Fraud and Android Malware
Critical Android vulnerability CVE-2026-0073 fixed by Google
Critical Android Zero-Click Vulnerability Grants Remote Shell Access
Passwords, Credential Stuffing & Brute Force Attacks
1 in 8 workers say selling company logins is justifiable
Fake background remover spreads password-stealing malware | Cybernews
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
The Passwordless Future Has a Password Problem - Security Boulevard
Syncing passkeys to Google defeats the whole point of passkeys
I'm a cyber security expert - 60% of the public are making this dangerous mistake
Regulations, Fines and Legislation
Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn – POLITICO
Kids can bypass some age checks with a drawn-on mustache • The Register
UK age-gating plans risk breaking the internet, privacy groups warn
Brussels reissues its Huawei warning, and prepares to make it stick
US lists offensive cyberattacks in counterterrorism strategy - Nextgov/FCW
Social Media
30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
Vimeo confirms breach via third-party vendor impacts 119K users
Supply Chain and Third Parties
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack - Ars Technica
UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom - SecurityWeek
Trellix Source Code Breach Highlights Supply Chain Threats
DigiCert breached via malicious screensaver file - Help Net Security
Vimeo confirms breach via third-party vendor impacts 119K users
A DOD contractor’s API flaw exposed military course data and service member records | CyberScoop
Instructure Breach Exposes Schools' Vendor Dependence
Education Sector Under Attack From State Espionage, Spear-Phishing, and Supply Chain Attacks
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
MuddyWater hackers use Chaos ransomware as a decoy in attacks
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
Russian cyberattacks against Ukraine may be considered war crimes - CCD | УНН
War is not just missiles, defence experts warn Britons
How Iranian Cyber Intrusions Unfold Inside Enterprise Networks
Small Defense Firms Lack Network Data to Stop Nation-State Hackers - Infosecurity Magazine
Nation State Actors
Small Defense Firms Lack Network Data to Stop Nation-State Hackers - Infosecurity Magazine
China
FBI: China's hacker-for-hire ecosystem 'out of control' • The Register
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists
Brussels reissues its Huawei warning, and prepares to make it stick
Chinese spy group caught lurking in Poland, Asia networks • The Register
Police dismantles 9 crypto scam centers, arrests 276 suspects
Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
EU moves to ban high-risk inverters from China over cybersecurity threats | Euronews
Russia
Russian cyberattacks against Ukraine may be considered war crimes - CCD | УНН
Russian hacker pleads guilty to cyberattacks on US, Ukrainian oil and gas facilities
DOJ says ransomware gang tapped into Russian government databases | TechCrunch
Russia disrupts mobile internet as Kremlin scales back Victory Day parade | The Independent
North Korea
North Korea Stole 76% of All Crypto Taken in 2026 | CoinMarketCap
You’ve hired a fraudulent employee. What comes next? | HR Dive
North Korean APT Targets Yanbian Gamers via Trojanized Platform - Infosecurity Magazine
Iran
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
Iranian cyber espionage disguised as a Chaos Ransomware attack
How Iranian Cyber Intrusions Unfold Inside Enterprise Networks
Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
FBI: China's hacker-for-hire ecosystem 'out of control' • The Register
Tools and Controls
UK Cyber Resilience Plateaus as AI and Supply Chain Risks Rise | SC Media UK
US ransomware negotiators get 4 years in prison over BlackCat attacks
How cyber insurance helped with breach recovery -- or not | TechTarget
Azure AD Conditional Access Bypassed Through Phantom Device Registration and PRT Abuse
AI digs up decades of code debt. Patch up. • The Register
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
RMM Tools Fuel Stealthy Phishing Campaign
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots
Security’s Blind Spot: The Threats Hiding In “Low-Severity” Alerts
The Passwordless Future Has a Password Problem - Security Boulevard
Mythos is 'very heightened risk': JPMorganChase's Jamie Dimon | American Banker
India orders infosec red alert in case Mythos sparks crime
When AI Starts Making Decisions, Cybersecurity Becomes A Governance Issue | Scoop News
Amazon SES increasingly abused in phishing to evade detection
How CISOs should utilize data security posture management to inform risk | CSO Online
Understanding Digital Forensics After A Cyber Incident
Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn – POLITICO
Microsoft fixes Remote Desktop warnings displaying incorrectly
Tape's strategic role in modern data protection | TechTarget
After dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, too | TechCrunch
Financial Services Industry Collaborates to Test Real-World Cyber Readiness
Other News
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots
UK: Education Sector Faces Surge in Cyber Breaches - Infosecurity Magazine
Cybercriminals Are Now Coming After Freight Cargo. And They’re Doing a Great Job.
CISA tells critical organizations to prepare for cyber outages | Federal News Network
Cyberattacks against universities becoming ‘more prevalent’
Physical Cargo Theft Gets a Boost From Cybercriminals
Vulnerability Management
The AI Vulnerability Storm Is Here. Is Your Security Program Breach Ready? - Security Boulevard
AI speeds flaw discovery, forcing rapid updates, UK NCSC warns
AI digs up decades of code debt. Patch up. • The Register
Security’s Blind Spot: The Threats Hiding In “Low-Severity” Alerts
Oracle Debuts Monthly Critical Security Patch Updates - SecurityWeek
Why every organization should make it easy to report security flaws
Vulnerabilities
cPanel zero-day exploited for months before patch release (CVE-2026-41940) - Help Net Security
Over 40,000 Servers Compromised in Ongoing cPanel Exploitation - SecurityWeek
Critical cPanel exploited: 'Millions' of sites could be hit • The Register
Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
Exploit Cyber-Frenzy Threatens Millions via cPanel Vulnerability
Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940
MOVEit automation flaws could enable full system compromise
Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks - SecurityWeek
Ivanti customers confront yet another actively exploited zero-day | CyberScoop
Cisco Patches High-Severity Vulnerabilities in Enterprise Products - SecurityWeek
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now
Linux 'Copy Fail' flaw lets anyone hijack system privileges. Update ASAP | PCWorld
'Copy Fail' is a real Linux security crisis wrapped in AI slop | CyberScoop
New Linux 'Dirty Frag' zero-day gives root on all major distros
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
Google Chrome 148 Released with 127 Security Fixes, Three Critical Vulnerabilities Patched
Apache fixes critical HTTP/2 double-free flaw CVE-2026-23918 enabling RCE
New Cisco DoS flaw requires manual reboot to revive devices
Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover - SecurityWeek
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
Weaver E-cology critical bug exploited in attacks since March
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft - SecurityWeek
Malicious PyTorch Lightning update hits AI supply chain security
Critical Android Zero-Click Vulnerability Grants Remote Shell Access
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 01 May 2026
Black Arrow Cyber Threat Intelligence Briefing 01 May 2026:
-Cyber Attacks Now the Top Operational Risk for 60% of Financial Organisations
-Get Ready to be Attacked - NCSC
-UK Cyber Essentials Overhaul Could Trigger Instant Certification Failures
-Cyber Threat Literacy, AI Disruption Top Risks to an Organisation’s People
-AI Rush Is Reviving Old Cyber Security Mistakes, Mandiant VP Warns
-Deepfake Era Demands Proof-Based Security, Not Just Awareness
-Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
-Over 2.8 Billion Credentials Stolen in 2025 as Ransomware Evolves
-A Sneaky Cyber Enemy Is Creeping into Our Browsers and Password Managers
-The Behavioural Shift: Why Trusted Relationships Are the Newest Attack Surface
-Threat Actors Ditch ‘Spray and Pray’ Attacks in Shift to Targeted Exploitation
-A Dozen Allied Agencies Say China Is Building Covert Hacker Networks out of Everyday Routers
-What’s Behind Europe’s Efforts to Ditch US Software in Favour of Sovereign Tech
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
As reported cyber attacks continue to rise, it is unsurprising that business leaders see cyber risk as their top threat. This week’s research shows that 60% of financial services organisations view cyber attacks and outages as their biggest operational risk, alongside the UK Government urging organisations to prepare to manage and operate during cyber disruption. We also highlight changes to the UK Government’s Cyber Essentials scheme, which now emphasise ongoing control rather than point‑in‑time assessment and could see some certificate holders fail on reassessment.
Artificial intelligence is also increasing cyber risk, through factors such as inadequate cyber threat literacy among employees and the amplification of insufficient cyber hygiene, as well as accelerating the pace at which vulnerabilities are identified and exploited. We report on striking figures, including more than 2.8 billion credentials stolen last year; a sharp rise in infostealer malware on Apple macOS devices; and the continued prevalence of phishing and third‑party attacks. Finally, we examine wider developments, from China’s use of covert hacker networks to European efforts to strengthen data and technology sovereignty.
The way to manage the impact of these developments requires a sound business leadership understanding of risks and how to maintain proportionate controls that enable the organisation to grow. Contact us to discuss how to achieve this.
Top Cyber Stories of the Last Week
Cyber Attacks Now the Top Operational Risk for 60% of Financial Organisations
A survey of around 150 senior compliance experts found that 60% of financial services organisations now see cyber attacks or system outages as their biggest operational risk this year, far ahead of supply chain disruption or staff shortages at 10%. While most say their organisation has measures in place to manage the risk, 13% are not confident in their ability to address disruption. The findings also highlight concern that criminals are using artificial intelligence faster than firms and regulators can respond, signalling to business leaders the need for sustained vigilance and continuous improvement as cyber threats evolve in scale and sophistication.
Get Ready to be Attacked - NCSC
The UK’s National Cyber Security Centre (NCSC) has warned that UK organisations of national significance, including financial services, health, energy and transport, face a growing risk from severe cyber threats that could disrupt essential services, cause financial loss and affect public safety. It says advanced attackers are increasingly targeting nationally significant organisations, while technologies such as frontier AI may increase the speed and scale of attacks. The guidance highlights that cyber resilience is a leadership responsibility, requiring critical systems to be mapped, disruption plans tested, and recovery arrangements rehearsed before an incident occurs.
https://www.ukauthority.com/articles/get-ready-to-be-attacked-ncsc
UK Cyber Essentials Overhaul Could Trigger Instant Certification Failures
Changes to the UK Cyber Essentials scheme that tighten enforcement and widen scope could increase the risk of instant certification failure for organisations with inconsistent day‑to‑day controls. Failing to apply high-risk or critical security updates and patches within 14 days can now trigger automatic failure. Enforcement of multi‑factor authentication is also applied more strictly across cloud services where MFA is available, while the updated scope clarifies that cloud services hosting organisational data or services cannot be excluded. This increases the likelihood that overlooked systems, legacy applications or active but overlooked accounts create compliance gaps. For business leaders, the update highlights that Cyber Essentials is increasingly a test of ongoing operational discipline rather than a point‑in‑time exercise.
Cyber Threat Literacy, AI Disruption Top Risks to an Organisation’s People
Marsh’s 2026 People Risks report identifies insufficient cyber threat literacy as the leading people risk for organisations, reflecting the continued role of human error in cyber losses. Phishing and social engineering continue to succeed by tricking employees into disclosing log‑in details, enabling ransomware attacks and data breaches. The report also warns that rapid adoption of artificial intelligence without adequate employee training is increasing risk. For business leaders, the findings highlight that cyber resilience depends as much on leadership-led training, communication and support for employees as on technology investments.
https://www.insurancejournal.com/news/national/2026/04/30/867782.htm
AI Rush Is Reviving Old Cyber Security Mistakes, Mandiant VP Warns
Mandiant has warned that rapid AI adoption is causing organisations to overlook basic cyber security controls. Its testing teams, who simulate real attacker behaviour, found AI environments where attackers could alter data classifications, bypass data loss prevention tools that stop sensitive information leaving the business, and use unencrypted communication links. In some cases, once initial access was gained through social engineering, where people are manipulated into granting access, AI systems carried out further actions including data theft and policy changes. Mandiant’s warning highlights the need for governance, secure design and independent testing that keeps pace with AI deployment.
https://www.infosecurity-magazine.com/news/ai-old-cybersecurity-mistakes/
Deepfake Era Demands Proof-Based Security, Not Just Awareness
Deepfake and voice cloning attacks are making it harder for employees to trust what they see or hear, particularly when requests appear to come from senior executives. Research found that 77% of fraud professionals say deepfake attacks are increasing, yet only 7% believe their organisations are well prepared. High-risk actions, such as payments, password resets or access changes, should rely on agreed verification steps through trusted channels, not on a single call, video meeting or message. This reduces pressure on staff and makes fraud prevention a consistent business process.
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
AI tools such as Anthropic’s Claude Mythos Preview could significantly increase the speed and scale of vulnerability discovery, exposing flaws faster than traditional testing approaches. However, faster discovery risks overwhelming organisations that lack clear ownership, centralised tracking and consistent prioritisation of remediation efforts. Without effective processes to assign responsibility, assess business impact and verify that fixes have been applied, organisations may simply accumulate a larger backlog of unresolved security issues. The findings highlight that operational readiness for remediation has not kept pace with advances in AI‑driven vulnerability discovery.
https://thehackernews.com/2026/04/mythos-changed-math-on-vulnerability.html
Over 2.8 Billion Credentials Stolen in 2025 as Ransomware Evolves
A report identified 2.86 billion compromised credentials in 2025, with business cloud and login services accounting for more than 30% of exposed data. Attackers are increasingly logging in using stolen credentials rather than exploiting technical weaknesses. The report also highlights risks from unsanctioned AI tools, where employees may unknowingly expose confidential data, and a sharp rise in infostealer malware on Apple macOS devices, from fewer than 1,000 cases in 2024 to over 70,000 in 2025. Ransomware activity remains highly active, with 147 groups recorded. The findings highlight identity compromise, unsanctioned AI use and reliance on legacy defences as central factors shaping the evolving ransomware threat.
https://betanews.com/article/over-2-8-billion-credentials-stolen-in-2025-as-ransomware-evolves/
A Sneaky Cyber Enemy Is Creeping into Our Browsers and Password Managers
KELA reports that almost 4 million devices were exposed to infostealer malware last year, leading to around 350 million compromised login details. Infostealers are malicious tools that quietly collect sensitive data such as browser cookies, passwords and local files, often without obvious signs on the device. Windows users remain heavily targeted, but attacks on Apple devices are rising as adoption grows in corporate environments. The risk is significant because stolen browser sessions can sometimes let criminals access accounts without needing a password or multi-factor authentication.
The Behavioural Shift: Why Trusted Relationships Are the Newest Attack Surface
An analysis of almost 800,000 email attacks across more than 4,600 organisations shows how attackers exploit trust and routine business processes rather than technical weaknesses. Phishing remains the most common method at 58% of attacks, and business email compromise 11%. Over 20% of phishing attacks hide harmful web pages behind redirect chains. Invoice fraud accounts for 42% of campaigns in North America and procurement related scams 41% in EMEA. The findings highlight that trusted workflows and supplier interactions have become a key attack surface, reinforcing the need for verification controls within routine business processes.
Threat Actors Ditch ‘Spray and Pray’ Attacks in Shift to Targeted Exploitation
Cyber criminals are moving away from broad, high-volume ‘spray and pray’ attacks and focusing on fewer organisations where they can cause greater disruption. SonicWall reported a 20% rise in compromised UK organisations last year, despite overall ransomware volumes falling by 87%. Smaller businesses appear especially exposed, with ransomware involved in 88% of SMB breaches compared with 39% for larger enterprises. Outdated technology remains a major risk, with one decade-old camera weakness linked to 67 million attempted UK attacks. AI-enabled attacks also rose by 89%, while attackers can remain undetected for an average of 181 days.
A Dozen Allied Agencies Say China Is Building Covert Hacker Networks out of Everyday Routers
Allied cyber agencies have warned that China-linked hackers are increasingly using everyday devices, including home office routers and smart devices, to build hidden networks for cyber attacks. These networks disguise where activity is coming from and can support spying, malware delivery and information theft. One example, known as Raptor Train, infected 200,000 devices worldwide. The warning highlights China‑linked hackers are moving away from running their own small, dedicated attack servers, and instead are hijacking vast numbers of ordinary internet‑connected devices to form large, hidden attack networks. This makes detection harder and reinforces the need for strong device management, monitoring and basic cyber security controls.
https://cyberscoop.com/china-nexus-covert-networks-advisory/
What’s Behind Europe’s Efforts to Ditch US Software in Favour of Sovereign Tech
European governments are reassessing dependence on US technology as concerns grow over data access, legal control and resilience. US federal law, called the 2018 CLOUD Act, means US providers may be required to hand over data even when it is stored overseas, increasing worries around sensitive information such as health records. France is moving its Health Data Hub from Microsoft Azure to a sovereign cloud provider, while the European Commission has awarded a €180 million tender to European cloud firms. However, alternatives still face scale and adoption challenges, particularly where private sector buyers continue to favour established US providers.
Governance, Risk and Compliance
Get ready to be attacked - NCSC | UKAuthority
Cyber threats challenge global business resilience
Cyber Attacks Emerge As Top Risk For Professional Firms In 2026 - Minutehack
Cyber attacks now the top operational risk for 60% of financial organisations - TechCentral.ie
Cyber Insurance Data Gives CISOs New Ammo for Budget Talks - SecurityWeek
Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People
The cyber security of British business is a matter of national security - Dan Jarvis
Nearly half of cybersecurity pros want to quit - here's why | ZDNET
Cybersecurity professional getting more work and less pay • The Register
Threats
Ransomware, Extortion and Destructive Attacks
Trigona ransomware attacks use custom exfiltration tool to steal data
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitation | IT Pro
Feuding Ransomware Groups Leak Each Other's Data
New BlackFile extortion group linked to surge of vishing attacks
RAMP Uncovered: Anatomy of Russia’s Ransomware Marketplace
ShinyHunters exploit Anodot incident to target Vimeo
Critical Flaw Turns Vect Ransomware into Data Destroying Wiper - Infosecurity Magazine
Do not pay VECT ransom: recovery is impossible | Cybernews
Scattered Spider co-conspirator pleads guilty | CSO Online
Ransomware and Destructive Attack Victims
Udemy Data Breach - ShinyHunters Claims Compromise of 1.4M User Records
Over 2.8 billion credentials stolen in 2025 as ransomware evolves - BetaNews
ADT confirms data breach after ShinyHunters leak threat
ShinyHunters claim they have cruise giant Carnival’s booty • The Register
Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica
Medtronic Confirms Data Breach After ShinyHunters Claims - Infosecurity Magazine
Ransomware attacks affect 2 senior care providers
Pitney Bowes the latest victim of ShinyHunters’ breach-spree • The Register
Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of "Highly Destructive" Wiper
Phishing & Email Based Attacks
AI Phishing Is No. 1 With a Bullet for Cyberattackers
The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek
7 Reasons Smishing Is More Effective Than Phishing
Robinhood account creation flaw abused to send phishing emails
Kuse Web App Abused to Host Phishing Document | Trend Micro (US)
Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software
Business Email Compromise (BEC)/Email Account Compromise (EAC)
The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek
Other Social Engineering
The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek
7 Reasons Smishing Is More Effective Than Phishing
Crime crew impersonates help desk, abuses Teams chats • The Register
Threat actor uses Microsoft Teams to deploy new “Snow” malware
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
New BlackFile extortion group linked to surge of vishing attacks
Helping Romance Scam Victims Require a Proactive Approach
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News
Money launderer linked to $230M crypto heist gets 70 months in prison
Artificial Intelligence
AI Phishing Is No. 1 With a Bullet for Cyberattackers
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Deepfake era demands proof-based security, not just awareness | TechTarget
AI Rush is Reviving Old Cybersecurity Mistakes, Mandiant VP Warns - Infosecurity Magazine
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
UK firms accelerate ‘sovereign AI’ plans amid concerns over dependence on overseas tech | IT Pro
Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People
Board Oversight of AI: Do Boards Need AI Experts?
Researchers Uncover 10 In-the-Wild Indirect Prompt Injection Attacks - Infosecurity Magazine
Six AI Vulnerabilities, Three Attack Patterns, One Dangerous Service Gap | perspective | MSSP Alert
Attack of the killer script kiddies | The Verge
AI bot attacks increase 10-fold, report reveals | The Independent
77% of IT managers say their AI agents are out of control - 5 ways to rein in yours | ZDNET
30 ClawHub skills secretly turn AI agents into crypto swarm • The Register
Learning from the Vercel breach: Shadow AI & OAuth sprawl
Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool
How indirect prompt injection attacks on AI work - and 6 ways to shut them down | ZDNET
Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
Mythos access by Discord group reveals real danger of AI-powered hacking | Fortune
How to fix cybersecurity's agentic AI identity crisis | TechTarget
Chinese Cybersecurity Firm's AI Hacking Claims Draw Comparisons to Claude Mythos - SecurityWeek
Mythos Is a Wake-Up Call for DDoS Defense - Security Boulevard
AI Models Can Attack, But Can They Defend? Simbian Says Not Yet | news | MSSP Alert
Bots/Botnets
UK warns of Chinese hackers using proxy networks to evade detection
China-linked threat actors use consumer device botnets to evade detection, warn UK and partners
China-Backed Hackers Are Industrializing Botnets
Careers, Roles, Skills, Working in Cyber and Information Security
Nearly half of cybersecurity pros want to quit - here's why | ZDNET
Cybersecurity professional getting more work and less pay • The Register
Cyber Hiring in 2026: Talent Gap or Expectation Problem? - ClearanceJobs
Cloud/SaaS
Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool
Hybrid clouds have two attack surfaces – so watch both • The Register
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
European police dismantles €50 million crypto investment fraud ring
How the U.S.-China cold war went crypto - Cryptopolitan
Cyber Crime, Organised Crime & Criminal Actors
Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News
French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches
Inside an OPSEC Playbook: How Threat Actors Evade Detection
Scattered Spider co-conspirator pleads guilty | CSO Online
Data Breaches/Leaks
Udemy Data Breach - ShinyHunters Claims Compromise of 1.4M User Records
Researchers Track 2.9 Billion Compromised Credentials - Infosecurity Magazine
Learning from the Vercel breach: Shadow AI & OAuth sprawl
A sneaky cyber enemy is creeping into our browsers and password managers | Cybernews
Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool
ADT confirms data breach after ShinyHunters leak threat
ShinyHunters claim they have cruise giant Carnival’s booty • The Register
Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica
Personal data of almost entire Dutch town stolen in cyberattack
French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches
Discord users breach access controls to reach Anthropic’s Mythos model - Digital Trends
Medtronic Confirms Data Breach After ShinyHunters Claims - Infosecurity Magazine
Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
UK Biobank Breach: Health Data of 500,000 Listed for Sale in China - Infosecurity Magazine
Ransomware attacks affect 2 senior care providers
U.S. utility giant Itron discloses a security breach
Data Protection
U.S. companies hit with record fines for privacy in 2025 | CyberScoop
Data/Digital Sovereignty
UK firms accelerate ‘sovereign AI’ plans amid concerns over dependence on overseas tech | IT Pro
The push for digital sovereignty: What CISOs need to know | TechTarget
What’s behind Europe’s efforts to ditch US software in favor of sovereign tech | TechCrunch
Germany fights US “cyber dominance” with sovereignty checklist | Cybernews
The European Commission is turning Google Search into a privacy and national-security risk
Denial of Service/DoS/DDoS
Mythos Is a Wake-Up Call for DDoS Defense - Security Boulevard
MP Sir David Davis's website shut down in suspected cyber attack - BBC News
Encryption
The 2026 MSSP Blueprint: Navigating the Quantum Countdown | native | MSSP Alert
Fraud, Scams and Financial Crime
French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches
Money launderer for crypto thieves given 5-year sentence | The Record from Recorded Future News
Money launderer linked to $230M crypto heist gets 70 months in prison
European police dismantles €50 million crypto investment fraud ring
Helping Romance Scam Victims Require a Proactive Approach
US Busts Myanmar Ring Targeting US Citizens in Financial Fraud
Insider Risk and Insider Threats
Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People
Insurance
Cyber Insurance Data Gives CISOs New Ammo for Budget Talks - SecurityWeek
Internet of Things – IoT
A Quarter of Healthcare Organizations Report Medical Device Attacks - Infosecurity Magazine
Attackers could disable all of a city's public EV chargers • The Register
Law Enforcement Action and Take Downs
Money launderer linked to $230M crypto heist gets 70 months in prison
US Sanctions Target Cambodian Scam Network Leaders - Infosecurity Magazine
European police dismantles €50 million crypto investment fraud ring
Hackers arrested for hijacking and selling 610,000 Roblox accounts
French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches
US Busts Myanmar Ring Targeting US Citizens in Financial Fraud
Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Scattered Spider co-conspirator pleads guilty | CSO Online
Chinese national extradited to US for pandemic-era Silk Typhoon attacks | CyberScoop
Linux and Open Source
12-year-old Pack2TheRoot bug lets Linux users gain root privileges
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System
AI's not going to kill open source code security • The Register
Linux cryptographic code flaw offers fast route to root • The Register
Malware
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
A sneaky cyber enemy is creeping into our browsers and password managers | Cybernews
Crime crew impersonates help desk, abuses Teams chats • The Register
Threat actor uses Microsoft Teams to deploy new “Snow” malware
Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions
Widely Used Browser Extensions Selling User Data - Infosecurity Magazine
Vidar Rises to Top of Chaotic Infostealer Market
Unwary Chinese Hackers Hardcoded Credentials into Backdoors
20-Year-Old Malware Rewrites History of Cyber Sabotage
Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions - SecurityWeek
Mobile
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
Another spyware maker caught distributing fake Android snooping apps | TechCrunch
This hidden SIM flaw lets spies track your location, and using a VPN can't help | TechRadar
New Android spyware Morpheus linked to Italian surveillance firm
Models, Frameworks and Standards
UK Cyber Essentials overhaul could trigger instant certification failures - BetaNews
DORA and the Practical Test of Operational Resilience - IT Security Guru
ENISA updates framework to enhance EU member state cybersecurity capabilities » Iraqi News Agency
Outages
Microsoft says Outlook.com outage is causing sign‑in failures
Passwords, Credential Stuffing & Brute Force Attacks
Over 2.8 billion credentials stolen in 2025 as ransomware evolves - BetaNews
Researchers Track 2.9 Billion Compromised Credentials - Infosecurity Magazine
Official SAP npm packages compromised to steal credentials
Regulations, Fines and Legislation
Proton CEO: Age checks turn internet into ID checkpoint • The Register
The European Commission is turning Google Search into a privacy and national-security risk
U.S. companies hit with record fines for privacy in 2025 | CyberScoop
EU waves through age-check app to keep kids safe online • The Register
Latest spy power reauthorization bill leaves critics unimpressed | CyberScoop
The Iran Factor In Trump’s Cyber Strategy – Analysis – Eurasia Review
Social Media
ShinyHunters exploit Anodot incident to target Vimeo
Supply Chain and Third Parties
The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface - SecurityWeek
Why supply chain resilience is under the spotlight | IT Pro
Official SAP npm packages compromised to steal credentials
Ongoing supply-chain attack targets security, dev tools • The Register
Checkmarx Confirms Data Stolen in Supply Chain Attack - SecurityWeek
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden - Ars Technica
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
How Big a Threat Are Iranian-Backed Cyberattacks? | The New Yorker
Compromised everyday devices power Chinese cyber espionage operations - Help Net Security
The New Rules Of War Have No Rules
Is the Middle East Conflict Opening a Digital Front in Europe? | The Gaze
Cyberwar Without Borders: How Iran’s Digital Offensive Is Reaching Europe | The Gaze
Cyberwar brings frontline to heart of European infrastructure - SWI swissinfo.ch
UK in talks with telecoms industry on undersea cable threat
Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions - SecurityWeek
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
Locked Shields 2026 united the power of 41 nations to defend cyberspace CCDCOE
Golden Dome weapons to attack enemy missiles with new high-tech interceptors, lasers, cyberattacks
FCC adds mobile hotspots to router ban • The Register
Chinese Hackers Spied On Cuban Embassy As US Prepared Blockade
Nation State Actors
The New Rules Of War Have No Rules
Cyberwar brings frontline to heart of European infrastructure - SWI swissinfo.ch
UK in talks with telecoms industry on undersea cable threat
Locked Shields 2026 united the power of 41 nations to defend cyberspace CCDCOE
China
UK in talks with telecoms industry on undersea cable threat
Chinese Cybersecurity Firm's AI Hacking Claims Draw Comparisons to Claude Mythos - SecurityWeek
China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks - SecurityWeek
FCC adds mobile hotspots to router ban • The Register
Unwary Chinese Hackers Hardcoded Credentials into Backdoors
Chinese national extradited to US for pandemic-era Silk Typhoon attacks | CyberScoop
UK warns of Chinese hackers using proxy networks to evade detection
China-linked threat actors use consumer device botnets to evade detection, warn UK and partners
China-Backed Hackers Are Industrializing Botnets
Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software
New GopherWhisper APT group abuses Outlook, Slack, Discord for comms
Chinese Hackers Spied On Cuban Embassy As US Prepared Blockade
EU bans funding for energy projects using Chinese inverters - PV Tech
Russia
UK in talks with telecoms industry on undersea cable threat
Incomplete Windows Patch Opens Door to Zero-Click Attacks - SecurityWeek
Microsoft patch fell short. New Windows flaw exploited • The Register
RAMP Uncovered: Anatomy of Russia’s Ransomware Marketplace
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
Germany Caught Up in Likely Russian Signal Phishing
Internet censorship index reveals Russia’s lead and widespread content blocking
North Korea
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
Iran
The New Rules Of War Have No Rules
How Big a Threat Are Iranian-Backed Cyberattacks? | The New Yorker
Is the Middle East Conflict Opening a Digital Front in Europe? | The Gaze
Cyberwar Without Borders: How Iran’s Digital Offensive Is Reaching Europe | The Gaze
Pre-Stuxnet Sabotage Malware 'Fast16' Linked to US-Iran Cyber Tensions - SecurityWeek
The Iran Factor In Trump’s Cyber Strategy – Analysis – Eurasia Review
Iranian Cyber Group Handala Targets US Troops in Bahrain - SecurityWeek
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
The New Rules Of War Have No Rules
Golden Dome weapons to attack enemy missiles with new high-tech interceptors, lasers, cyberattacks
Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of "Highly Destructive" Wiper
Tools and Controls
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Cyber threats challenge global business resilience
Cyber Insurance Data Gives CISOs New Ammo for Budget Talks - SecurityWeek
Mythos sniffs out your bugs, can't fix your bloody idiots • The Register
DORA and the Practical Test of Operational Resilience - IT Security Guru
Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
Glasswing Secured the Code. The Rest is on You
Cyber pros say unauthorized Mythos access is a sign of things to come | Cybernews
Mythos access by Discord group reveals real danger of AI-powered hacking | Fortune
“Mythos-like hacking, open to all”: Industry reacts to OpenAI’s GPT 5.5 - The New Stack
AI Models Can Attack, But Can They Defend? Simbian Says Not Yet | news | MSSP Alert
Google Favors General‑Purpose Gemini Models Over Cybersecurity‑Specif - Infosecurity Magazine
Remote Desktop security beefed up with hard-to-read messages • The Register
Shadow code: The hidden threat for enterprise IT | TechTarget
Cyber Threat Literacy, AI Disruption Top Risks to an Organization’s People
Vercel Confirms April 2026 Security Incident Linked To Third-party AI Tool
Vercel attack fallout expands to more customers and third-party systems | CyberScoop
Mythos Is a Wake-Up Call for DDoS Defense - Security Boulevard
Hybrid clouds have two attack surfaces – so watch both • The Register
Open source models can find bugs as well as Mythos • The Register
Myth Or Mythos? The Illusion Of Advantage In The AI Cybersecurity Race
The Hidden Tax on Security: How Data Costs Are Eating Your Controls Budget - Security Boulevard
Locked Shields 2026 united the power of 41 nations to defend cyberspace CCDCOE
FS cybersecurity experts gather for “industry first” training exercise - FStech
Other News
Cyber Attacks Emerge As Top Risk For Professional Firms In 2026 - Minutehack
Cyber attacks now the top operational risk for 60% of financial organisations - TechCentral.ie
The cyber security of British business is a matter of national security - Dan Jarvis
UK in talks with telecoms industry on undersea cable threat
FS cybersecurity experts gather for “industry first” training exercise - FStech
Why are top university websites serving porn? It comes down to shoddy housekeeping. - Ars Technica
BT has now blocked over a billion clicks to malicious websites, says NCSC | Computer Weekly
Experts warn offshore wind could face risks from drones, sabotage and cyber attacks | Aberdeen Live
Army extends cyber awareness challenge and privacy training to five years | Stars and Stripes
Vulnerability Management
Open source models can find bugs as well as Mythos • The Register
Microsoft updates the Windows Update Experience • The Register
5 ways your Windows updates are about to get a lot less painful | ZDNET
Everything Runs on Software. None of It Is Secure.
Vulnerabilities
Firestarter malware survives Cisco firewall updates, security patches
SonicWall Urges Immediate Patching of Firewall Vulnerabilities - SecurityWeek
Vulnerabilities Patched in CrowdStrike, Tenable Products - SecurityWeek
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
Incomplete Windows Patch Opens Door to Zero-Click Attacks - SecurityWeek
OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years - SecurityWeek
No Patch for New PhantomRPC Privilege Escalation Technique in Windows - SecurityWeek
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
April KB5083769 Windows 11 update causes backup software failures
12-year-old Pack2TheRoot bug lets Linux users gain root privileges
Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System
Critical bug in CrowdStrike LogScale let attackers access files
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
Linux cryptographic code flaw offers fast route to root • The Register
Chrome 147, Firefox 150 Security Updates Rolling Out - SecurityWeek
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
cPanel's authentication bypass bug is being exploited in the wild, CISA warns | CyberScoop
Hackers are actively exploiting a bug in cPanel, used by millions of websites | TechCrunch
Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting
Nessus Agent Vulnerability on Windows Enables Arbitrary Code Execution with SYSTEM Privileges
Critical GitHub Vulnerability Exposed Millions of Repositories - SecurityWeek
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
New Linux ‘Copy Fail’ flaw gives hackers root on major distros
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 24 April 2026
Black Arrow Cyber Threat Intelligence Briefing 24 April 2026:
-AI Is Now a ‘Standard Part of the Attacker Toolkit’
-Every Old Vulnerability Is Now an AI Vulnerability
-New Technology Is Increasing the Speed and Depth of Cyber Attacks
-The AI Era Demands a Different Kind of CISO
-Phishing and MFA Exploitation: Targeting the Keys to the Kingdom
-Phishing Reclaims the Top Initial Access Spot, Attackers Experiment with AI Tools
-Surge in Silent Subject Phishing Attacks Targets VIP Users
-Threat Actors Exploiting Trust in Everyday Workflows
-UK Must Brace for Rise in State-Backed Cyberattacks, Security Chief Says
-CISOs See Gaps in Their Incident Response Playbooks
-SMEs Say Cyber Resilience Is Lacking Amid Fears Security Is Failing
-Insurance Carriers Quietly Back Away from Covering AI Outputs
-Ransomware, Fraud, and Lawsuits Drive Cyber Insurance Claims to New Peaks
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
Our review of cyber security open source intelligence this week includes insights that fall into four key themes.
AI is now a standard part of an attacker’s toolkit, increasing the speed and scale of attacks and amplifying the impact of existing techniques and vulnerabilities. Phishing remains a highly successful and popular route into organisations, including exploiting weaknesses in MFA and trusted business activities. The cyber insurance market is responding to the shifting risks, with insurers tightening terms around AI related risks while claims arising from ransomware, fraud and lawsuits remain prominent. Lastly, various sources are highlighting that businesses need to strengthen their management of cyber risks, including how they plan to respond to an incident.
From our perspective at Black Arrow, we are clear that the response to these developments must be from a leadership team that is upskilled on today’s evolving risks and has worked with impartial experts to assess their risks and controls, and to practice how to protect their business during an incident rather than relying only on the Technology team assurance. Contact us to discuss how to do this in a proportionate manner.
Top Cyber Stories of the Last Week
AI Is Now a ‘Standard Part of the Attacker Toolkit’
Forescout reports that artificial intelligence is now a routine part of cyber criminals’ toolkit, helping them identify weaknesses and speed up attacks. Its research found a sharp rise in AI capability, with all tested models in its latest study performing well at basic vulnerability research, compared with 55% failing a year earlier. The pace is striking: once inside a network, criminals now hand over access to other attackers in a median of 22 seconds, down from more than eight hours in 2022, increasing pressure on organisations to detect and respond far faster.
https://www.itpro.com/security/ai-is-now-a-standard-part-of-the-attacker-toolkit
Every Old Vulnerability Is Now an AI Vulnerability
In March 2026, Microsoft patched an Excel vulnerability that exposed a broader risk created by embedded AI assistants. A malicious spreadsheet could execute hidden code and use Copilot to exfiltrate data without user interaction or warning. The flaw was not new, but AI amplified its impact by acting with the same access as the host application. This means vulnerabilities in applications with embedded AI assistants can carry far greater business risk, highlighting that AI assistants effectively act as privileged systems, amplifying the impact of existing vulnerabilities.
https://www.darkreading.com/vulnerabilities-threats/every-old-vulnerability-ai-vulnerability
New Technology Is Increasing the Speed and Depth of Cyber Attacks
Financial services firms are facing faster, broader cyber attacks as criminals use artificial intelligence to find weaknesses, craft convincing scams and target suppliers as a route into larger organisations. IBM found the finance and insurance sector accounted for 27% of all incidents in 2025, while Kroll reported that 76% of organisations experienced an AI-related security incident over the past two years. In response, banks are tightening supplier checks, improving staff awareness and investing in tools that detect genuine threats more accurately, with regulators placing greater emphasis on operational resilience and rapid recovery.
https://www.ft.com/content/954a44c6-cc11-49dd-b95a-dba61438b532?syn-25a6b1a6=1
The AI Era Demands a Different Kind of CISO
AI is rapidly increasing the speed of cyber attacks, allowing weaknesses to be found and exploited in minutes rather than days or weeks. This is exposing the limits of traditional security checks such as audits, compliance reviews and periodic testing, which only show a snapshot in time. Security leadership is increasingly focused on real‑time visibility of risks, tighter control over who and what can access critical systems and data, and stronger incident response planning.
https://cyberscoop.com/ciso-strategy-ai-real-time-risk-op-ed/
Phishing and MFA Exploitation: Targeting the Keys to the Kingdom
Phishing remained a major route into organisations in 2025, featuring in 40% of incidents, while attackers increasingly bypassed multi‑factor authentication by exploiting weaknesses in how identity controls were implemented and managed. Criminals use convincing emails about routine business tasks such as IT requests, invoices, travel and expenses, often sent from trusted or seemingly internal accounts. Attackers increasingly targeted the controls that manage who is allowed to access systems, with a sharp rise in cases where organisations were fooled into trusting malicious devices, leading to a 178% increase in these types of breaches. The trend highlights how everyday workflows and trusted systems can be turned against an organisation when controls are inconsistent or poorly enforced.
https://blog.talosintelligence.com/phishing-and-mfa-exploitation-targeting-the-keys-to-the-kingdom/
Phishing Reclaims the Top Initial Access Spot, Attackers Experiment with AI Tools
Cisco Talos reports that phishing was the main route into organisations in early 2026, responsible for more than a third of known break-ins, while attacks on internet-facing systems fell from 62% at their peak to 18% after fixes and better detection. Healthcare and public administration were the most targeted sectors, each making up 24% of incidents. Weak multi-factor authentication, used to add a second identity check, remained the most common security gap at 35%. Talos also saw attackers using an AI website builder to create convincing fake login pages and steal credentials.
https://www.helpnetsecurity.com/2026/04/22/cisco-phishing-initial-access-2026/
Surge in Silent Subject Phishing Attacks Targets VIP Users
Cyberproof has reported a rise in phishing emails sent with no subject line, a tactic often targeting senior staff and other high value users. By removing normal warning signs, these messages are more likely to be opened and can also avoid some email security checks. The campaign grew throughout the first quarter of 2026, rising over 13% from January to February and a further 7.0% in March. Messages often include links, QR codes or attachments that lead to fake sign-in pages or harmful software, with attackers also misusing legitimate remote access tools to stay hidden inside organisations.
https://www.infosecurity-magazine.com/news/silent-subject-phishing-campaigns/
Threat Actors Exploiting Trust in Everyday Workflows
Abnormal AI found that email-based cyber attacks are increasingly designed to blend into normal business activity by mimicking trusted suppliers, routine payment requests and familiar internal communications. Its analysis of nearly 800,000 email attacks across more than 4,600 organisations found that 61% of business email compromise incidents involved supplier relationships. Phishing made up 58% of attacks, with many using multi-step web links to evade detection. The findings show that attackers are exploiting trust and everyday working practices, making fraudulent messages far harder to distinguish from legitimate business communication.
https://betanews.com/article/threat-actors-exploiting-trust-in-everyday-workflows/
UK Must Brace for Rise in State-Backed Cyberattacks, Security Chief Says
The UK is facing a growing threat from state-backed cyber attacks, with the National Cyber Security Centre handling around four nationally significant incidents each week. While ransomware remains the most common risk, the most serious attacks are now increasingly linked to hostile governments. Officials also warned that rising geopolitical tensions could trigger large-scale disruptive campaigns, particularly against critical national infrastructure. In response, the government is seeking closer cooperation with AI firms and has committed £90 million over three years to strengthen cyber security, including support for smaller businesses.
https://www.claimsjournal.com/news/national/2026/04/22/337080.htm
CISOs See Gaps in Their Incident Response Playbooks
Sygnia found that more than three quarters of senior security leaders said their organisation had suffered a cyber attack in the past year, yet 73% felt unprepared for the next one. While almost all reported having a formal incident response plan, many still struggle to put it into practice. Common weaknesses include poor coordination between decision makers, limited board and executive involvement, and delays caused by legal or communications concerns. The findings point to the importance of direct business leader involvement in incident response readiness, clearer decision‑making and coordination during attacks, and addressing visibility gaps before an incident occurs.
https://www.ciodive.com/news/cisos-gaps-incident-response-playbooks/817765/
SMEs Say Cyber Resilience Is Lacking Amid Fears Security Is Failing
A survey of 500 UK SMEs suggests cyber security readiness remains weak despite rising threat levels. One in eight businesses reported a past cyber attack, while 52% rated themselves moderately to highly vulnerable to future incidents. Fewer than one in ten provide regular staff awareness training, and less than a third have increased cyber security spending in the past two years. The findings also show limited resilience if operations are disrupted, with one in eight businesses saying they could not survive a full shutdown lasting more than 48 hours, highlighting that gaps in training, preparedness and investment translate directly into business survival risk.
https://www.emergingrisks.co.uk/smes-say-cyber-resilience-is-lacking-amid-fears-security-is-failing/
Insurance Carriers Quietly Back Away from Covering AI Outputs
Insurers are becoming more cautious about covering risks linked to artificial intelligence, with some excluding losses caused by AI generated decisions and others raising premiums. The concern is that many AI systems can produce inconsistent or hard to explain results, making claims harder to assess. Insurance providers are also asking far more detailed questions about how organisations use and control AI. Cover is proving especially difficult for businesses whose products are built around AI, while firms with clear oversight, monitoring and fallback plans are viewed more favourably by insurers.
Ransomware, Fraud, and Lawsuits Drive Cyber Insurance Claims to New Peaks
Cyber insurance provider At-Bay’s 2026 analysis of more than 100,000 policy years shows cyber insurance claims rising, with overall claim frequency up 7% and average losses reaching a record $221,000. Ransomware remained the most costly incident, averaging $508,000, while financial fraud was the most common, making up about 30% of claims. In 2025, 73% of ransomware attacks started through a virtual private network, or VPN, up from 38% two years earlier, while VPNs and remote desktop tools together accounted for 87% of claims. Separate legal claims also increased significantly, adding further cost through lawsuits and business interruption.
https://www.helpnetsecurity.com/2026/04/23/cyber-insurance-claims-report/
Governance, Risk and Compliance
CISOs see gaps in their incident response playbooks | CIO Dive
SMEs say cyber resilience is lacking amid fears security is failing
Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security
CISOs reshape their roles as business risk strategists | CSO Online
Oil crisis? IT spending de-coupled from wider war shock • The Register
The AI era demands a different kind of CISO | CyberScoop
Cyber risks still getting lost in translation
Beyond awareness: Human risk management metrics for CISOs | TechTarget
Threats
Ransomware, Extortion and Destructive Attacks
Most Organizations Fail to Fully Recover After Ransomware Attacks
Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security
'The Gentlemen' Rapidly Rises to Ransomware Prominence
1 in 3 Ransomware Claims Started with SonicWall in 2025 as VPN Attacks Nearly Double in Two Years
Payouts King ransomware uses QEMU VMs to bypass endpoint security
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
The Gentlemen Ransomware Expands With Rapid Affiliate Growth - Infosecurity Magazine
Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
Adaptavist Group breach: Ransomware crew claims mega-haul • The Register
Kyber ransomware gang toys with post-quantum encryption on Windows
'Thankful I Got Caught': FBI Arrests Teen Hacker After Massive PowerSchool Breach
Scattered Spider member Tyler Buchanan pleads guilty to major crypto theft
Ransomware’s Next Phase: From Data Encryption to Business Extortion | Silicon UK Tech News
Third ransomware pro pleads guilty to cybercrime U-turn • The Register
Ransomware negotiator admits role in attacks he was hired to resolve - Help Net Security
Ex-FBI lead urges homicide charges against ransomware scum • The Register
Ransomware and Destructive Attack Victims
'Thankful I Got Caught': FBI Arrests Teen Hacker After Massive PowerSchool Breach
Hackers target US banking giants Frost Bank and Citizens Bank | Cybernews
Automotive Ransomware Attacks Double in a Year - Infosecurity Magazine
Ransomware Hits Automotive Data Expert Autovista - SecurityWeek
M&S one year on: turning anticipation into secure by design | Computer Weekly
French govt agency confirms breach as hacker offers to sell data
Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000 - SecurityWeek
Phishing & Email Based Attacks
Surge in Silent Subject Phishing Campaigns Targets VIP Users - Infosecurity Magazine
Threat actors exploiting trust in everyday workflows - BetaNews
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks - SecurityWeek
Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing
Phishing and MFA exploitation: Targeting the keys to the kingdom
New iPhone phishing scam involves email sent from Apple servers | Macworld
Watch Out for Unexpected Apple Account Change Emails. It's a Phishing Scam
Cyberattack on French government agency triggers phishing alert - Help Net Security
Business Email Compromise (BEC)/Email Account Compromise (EAC)
Threat actors exploiting trust in everyday workflows - BetaNews
Other Social Engineering
Threat actors exploiting trust in everyday workflows - BetaNews
Microsoft: Teams increasingly abused in helpdesk impersonation attacks
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks - SecurityWeek
Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing
US nationals sentenced for aiding North Korea’s tech worker scheme | CyberScoop
North Korea targets macOS users in latest heist • The Register
New iPhone phishing scam involves email sent from Apple servers | Macworld
macOS ClickFix attacks deliver AppleScript stealers • The Register
AI Tools Are Helping Mediocre North Korean Hackers Steal Millions | WIRED
Lazarus Group Uses Fake Meetings to Hijack Crypto Firms | CoinMarketCap
How to spot a North Korean fake in a job interview - Help Net Security
2FA/MFA
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks - SecurityWeek
Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing
Phishing and MFA exploitation: Targeting the keys to the kingdom
Artificial Intelligence
UK Government Sound Alarm Over AI Security Risk - IT Security Guru
HR Magazine - Government advises businesses about AI cyber threats
What is Anthopic's Claude Mythos and what risks does it pose? - BBC News
Insurance carriers quietly back away from covering AI outputs | CSO Online
New technology is increasing the speed and depth of cyber attacks
The AI cybersecurity boom may be creating a bigger problem than it solves | Ctech
Anthropic's Mythos AI model sparks fears of turbocharged hacking - Ars Technica
Russia uses AI to hack Europe, Dutch intelligence warns – POLITICO
Cybersecurity in the age of AI means bigger, faster threats | TechTarget
A tsunami of flaws: When frontier AI and Patch Tuesday collide | Computer Weekly
Anthropic’s Claude Is Pumping Out Vulnerable Code, Cyber Experts Warn
AI Tools Are Helping Mediocre North Korean Hackers Steal Millions | WIRED
ECB to Quiz Bankers About Risks of Anthropic’s New AI Model, Source Says
Beyond Mythos: A Defining Moment for Cybersecurity
OpenClaw Exposes the Real Cybersecurity Risks of Agentic AI - Infosecurity Magazine
Anthropic's Mythos model accessed by unauthorized users, Bloomberg News reports | Reuters
OpenAI’s Codex agent fails as an investigator | Cybernews
House lawmakers get a chilling demo of ‘jailbroken’ AI - POLITICO
Time for government, business leaders to figure out AI cybersecurity regulation — Harvard Gazette
Mythos can find the vulnerability. It can't tell you what to do about it. | CyberScoop
Anthropic's Mythos AI System Might Actually Create More Cybersecurity Vulnerabilities
Every Old Vulnerability Is Now an AI Vulnerability
Commercial AI Models Show Rapid Gains in Vulnerability Research - Infosecurity Magazine
How AI companies are quietly becoming the world’s cybersecurity gatekeepers - The Hindu
New artificial intelligence bots could drain nation's cash machines | This is Money
Never put all your eggs in one basket, fintech CTO warns after Anthropic suspends 60+ accounts
UK to build ‘national cyber shield’ to protect against AI cyber threats | Computer Weekly
Bots/Botnets
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
Attackers Exploit DVR Command Injection Flaw to Deploy Botnet - Infosecurity Magazine
New Mirai campaign exploits RCE flaw in EoL D-Link routers
New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Researchers link Smartproxy.org IPs to IPIDEA botnet network Google disrupted | Cybernews
Careers, Roles, Skills, Working in Cyber and Information Security
CYBERUK ’26: UK lagging on legal protections for cyber pros | Computer Weekly
What it takes to win that CSO role | CSO Online
CISOs reshape their roles as business risk strategists | CSO Online
The AI era demands a different kind of CISO | CyberScoop
Cloud/SaaS
EU pushes for stronger cloud sovereignty, awards €180 million to four providers - Help Net Security
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
AI Tools Are Helping Mediocre North Korean Hackers Steal Millions | WIRED
Lazarus Group Uses Fake Meetings to Hijack Crypto Firms | CoinMarketCap
KelpDAO suffers $290 million heist tied to Lazarus hackers
macOS ClickFix attacks deliver AppleScript stealers • The Register
Are Russian exchanges like Grinex targeted by hackers or spies? - Cryptopolitan
Grinex exchange blames "Western intelligence" for $13.7M crypto hack
Google warns quantum computers could break crypto encryption sooner than expected. | Mashable
China's Apple App Store infiltrated by crypto-stealing wallet apps
Dozens of Malicious Crypto Apps Land in Apple App Store - SecurityWeek
Cyber Crime, Organised Crime & Criminal Actors
Scattered Spider member Tyler Buchanan pleads guilty to major crypto theft
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process
The shadowy SIM farms behind those incessant scam texts - and how to stay safe | ZDNET
How Cybercrime Became a Leading Industry in ‘Scambodia’ - WSJ
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
Hackers who stole crime tip records now selling them | Cybernews
A single platform powers SIM farm proxy networks across 17 countries - Help Net Security
Data Breaches/Leaks
Hackers who stole crime tip records now selling them | Cybernews
Lovable denies data leak, cites 'intentional behavior' • The Register
Unsecured Perforce Servers Expose Sensitive Data From Major Orgs - SecurityWeek
Data breach at edtech giant McGraw Hill affects 13.5 million accounts
Man gets 30 months for selling thousands of hacked DraftKings accounts
Hacker Jeffrey Epstein claims 400K records stolen from Bol | Cybernews
WhatsApp Leaks User Metadata to Attackers
France's 'Secure' ID agency probes claimed 19M record breach • The Register
Cosmetics giant Rituals confirms data breach of customer membership records | TechCrunch
Crook claims to leak 'video surveillance footage' of firms • The Register
President of German parliament hit by Signal hack, report says – POLITICO
Data Protection
GDPR works, but only where someone enforces it - Help Net Security
Data/Digital Sovereignty
EU pushes for stronger cloud sovereignty, awards €180 million to four providers - Help Net Security
Denial of Service/DoS/DDoS
Four arrested in latest ‘PowerOFF’ DDoS-for-hire takedown | The Record from Recorded Future News
Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains | TechRadar
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Bluesky hit by 24-hour DDoS attack as pro-Iran group claims responsibility
Mastodon says its flagship server was hit by a DDoS attack | TechCrunch
Encryption
Half of the 6 Million Internet-Facing FTP Servers Lack Encryption - SecurityWeek
Google warns quantum computers could break crypto encryption sooner than expected. | Mashable
Kyber ransomware gang toys with post-quantum encryption on Windows
The race to become quantum-safe | IT Pro
Fraud, Scams and Financial Crime
Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process
The shadowy SIM farms behind those incessant scam texts - and how to stay safe | ZDNET
How cybercrime became a leading industry in ‘Scambodia’
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
A single platform powers SIM farm proxy networks across 17 countries - Help Net Security
How to spot a North Korean fake in a job interview - Help Net Security
Insider Risk and Insider Threats
How to spot a North Korean fake in a job interview - Help Net Security
Insurance
Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security
Insurance carriers quietly back away from covering AI outputs | CSO Online
Cyber risks still getting lost in translation
Internet of Things – IoT
Attackers Exploit DVR Command Injection Flaw to Deploy Botnet - Infosecurity Magazine
New Mirai campaign exploits RCE flaw in EoL D-Link routers
New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Law Enforcement Action and Take Downs
Four arrested in latest ‘PowerOFF’ DDoS-for-hire takedown | The Record from Recorded Future News
Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains | TechRadar
Scattered Spider member Tyler Buchanan pleads guilty to major crypto theft
British National Admits Hacking Companies and Stealing Millions in Virtual Currency
DraftKings hacker sentenced to prison, ordered to pay $1.4 Million
Man gets 30 months for selling thousands of hacked DraftKings accounts
'Thankful I Got Caught': FBI Arrests Teen Hacker After Massive PowerSchool Breach
Third ransomware pro pleads guilty to cybercrime U-turn • The Register
Ransomware negotiator admits role in attacks he was hired to resolve - Help Net Security
Linux and Open Source
Open source malware sees a 21 percent increase - BetaNews
Malvertising
When PUPs Bite: Huntress Uncovers “weaponised” Adware Exposing 25,000+ Systems
Malware
When PUPs Bite: Huntress Uncovers “weaponised” Adware Exposing 25,000+ Systems
Open source malware sees a 21 percent increase - BetaNews
Formbook Malware Campaign Uses Multiple Obfuscation Techniques - Infosecurity Magazine
Another npm supply chain worm hits dev environments • The Register
Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths - Security Boulevard
macOS ClickFix attacks deliver AppleScript stealers • The Register
Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
Bitwarden NPM Package Hit in Supply Chain Attack - SecurityWeek
New Checkmarx supply-chain breach affects KICS analysis tool
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware
Mobile
China's Apple App Store infiltrated by crypto-stealing wallet apps
Dozens of Malicious Crypto Apps Land in Apple App Store - SecurityWeek
New iPhone phishing scam involves email sent from Apple servers | Macworld
Android Phones Shown to Have a Major Biometric Security Weakness - Tech Advisor
The History of iOS Exploits: Apple’s Flawed Security Paradigm
Models, Frameworks and Standards
GDPR works, but only where someone enforces it - Help Net Security
UK Commits £90m for Cybersecurity and Pushes for ‘Resilience Pledge’ - Infosecurity Magazine
Passwords, Credential Stuffing & Brute Force Attacks
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
What Makes Credential Stuffing Difficult to Detect? - Security Boulevard
NCSC heralds end of passwords for consumers and pushes secure passkeys | Computer Weekly
Regulations, Fines and Legislation
Social media bans might steer kids into riskier corners of the internet - Help Net Security
Time for government, business leaders to figure out AI cybersecurity regulation — Harvard Gazette
CISA Budget Cuts Could Push More Security Burden onto MSSPs | news | MSSP Alert
EU's New Age Verification App Can Be Hacked Within 2 Minutes, Researchers Claim
Ex-FBI lead urges homicide charges against ransomware scum • The Register
The surveillance law Congress can't quit — and can't explain | CyberScoop
Washington’s 2026 cyber strategy normalises offensive operations | The Strategist
CISA director pick Sean Plankey withdraws his nomination | CyberScoop
Social Media
Social media bans might steer kids into riskier corners of the internet - Help Net Security
Bluesky hit by 24-hour DDoS attack as pro-Iran group claims responsibility
Mastodon says its flagship server was hit by a DDoS attack | TechCrunch
UK probes Telegram, teen chat sites over CSAM sharing concerns
Supply Chain and Third Parties
Threat actors exploiting trust in everyday workflows - BetaNews
Another npm supply chain worm hits dev environments • The Register
Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths - Security Boulevard
Bitwarden NPM Package Hit in Supply Chain Attack - SecurityWeek
New Checkmarx supply-chain breach affects KICS analysis tool
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware
Unsecured Perforce Servers Expose Sensitive Data From Major Orgs - SecurityWeek
Crook claims to leak 'video surveillance footage' of firms • The Register
The US NSA is using Anthropic's Claude Mythos despite supply chain risk
Why the Axios attack proves AI is mandatory for supply chain security | CyberScoop
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
U.K. Forces Counter Covert Russian Submarine Activities, Officials Say - USNI News
The scramble to protect Britain’s undersea cables from sabotage
New undersea cable cutter risks Internet’s backbone - Ars Technica
How Iran Has Excelled at 'Threat Projection' Using Cyber
UK Must Brace for Rise in State-Backed Cyberattacks, Security Chief Says
UK faces ‘perfect storm’ for cybersecurity, says cyber chief - UKTN
Sweden Sees Russia Intensifying Cyber Attacks on Infrastructure
Poland hit by record cyberattacks in 2025 as minister warns of 'digital war'
Government Can’t Win the Cyber War Without the Private Sector - SecurityWeek
Iran claims US used backdoors in networking equipment • The Register
The U.S. must defend the final frontier against cyberattacks - SpaceNews
Seeing the Cyber in Economic Statecraft
Nation State Actors
UK Says Iran, China Drive Regular Significant Cyberattacks
Iran, Russia and China behind most major cyberattacks on UK, security chief warns | The Independent
Cyber chief: UK faces "perfect storm" for cyber security | National Cyber Security Centre
UK intelligence: 100 nations have spyware that can hack Britain – POLITICO
Cheapskate cyber strategy won't stop Beijing's finest • The Register
UK Must Brace for Rise in State-Backed Cyberattacks, Security Chief Says
The U.S. must defend the final frontier against cyberattacks - SpaceNews
Seeing the Cyber in Economic Statecraft
China
UK Says Iran, China Drive Regular Significant Cyberattacks
Iran, Russia and China behind most major cyberattacks on UK, security chief warns | The Independent
Cheapskate cyber strategy won't stop Beijing's finest • The Register
The scramble to protect Britain’s undersea cables from sabotage
New undersea cable cutter risks Internet’s backbone - Ars Technica
UK Must Brace for Rise in State-Backed Cyberattacks, Security Chief Says
Chinese APT Targets Indian Banks, Korean Policy Circles
Russia
UK: Russian Hacking Reaches New Levels of Hostility
Iran, Russia and China behind most major cyberattacks on UK, security chief warns | The Independent
The scramble to protect Britain’s undersea cables from sabotage
U.K. Forces Counter Covert Russian Submarine Activities, Officials Say - USNI News
Russia uses AI to hack Europe, Dutch intelligence warns – POLITICO
Sweden Sees Russia Intensifying Cyber Attacks on Infrastructure
Poland hit by record cyberattacks in 2025 as minister warns of 'digital war'
Sanctioned Grinex halts after $13M crypto hack / The New Voice of Ukraine
Information Warfare: Russians Returning To landlines
North Korea
AI Tools Are Helping Mediocre North Korean Hackers Steal Millions | WIRED
Lazarus Group Uses Fake Meeting Hack
KelpDAO suffers $290 million heist tied to Lazarus hackers
North Korea targets macOS users in latest heist • The Register
UK Must Brace for Rise in State-Backed Cyberattacks, Security Chief Says
How to spot a North Korean fake in a job interview - Help Net Security
Iran
UK Says Iran, China Drive Regular Significant Cyberattacks
Iran, Russia and China behind most major cyberattacks on UK, security chief warns | The Independent
How Iran Has Excelled at 'Threat Projection' Using Cyber
Bluesky hit by 24-hour DDoS attack as pro-Iran group claims responsibility
The thin gray line: Handala, CyberAv3ngers and Iran’s proxy ops | CSO Online
Cybersecurity Risks Related to the Iran War | Dinsmore & Shohl LLP - JDSupra
Iran claims US used backdoors in networking equipment • The Register
Inside ZionSiphon: politically driven malware aims at Israeli water systems
Tools and Controls
Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security
What is Anthopic's Claude Mythos and what risks does it pose? - BBC News
New technology is increasing the speed and depth of cyber attacks
The AI cybersecurity boom may be creating a bigger problem than it solves | Ctech
Anthropic’s New Mythos A.I. Model Sets Off Global Alarms - The New York Times
1 in 3 Ransomware Claims Started with SonicWall in 2025 as VPN Attacks Nearly Double in Two Years
CISOs see gaps in their incident response playbooks | CIO Dive
CISOs reshape their roles as business risk strategists | CSO Online
The AI era demands a different kind of CISO | CyberScoop
Half of the 6 Million Internet-Facing FTP Servers Lack Encryption - SecurityWeek
ECB to Quiz Bankers About Risks of Anthropic’s New AI Model, Source Says
Commercial AI Models Show Rapid Gains in Vulnerability Research - Infosecurity Magazine
How AI companies are quietly becoming the world’s cybersecurity gatekeepers - The Hindu
Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
The Mythos Breach: Why Frontier Models Turn AI Safety Into A Fiduciary Responsibility
Oil crisis? IT spending de-coupled from wider war shock • The Register
Other News
Cyber attacks fuel surge in cargo theft across logistics industry
MacOS Native Tools Enable Stealthy Enterprise Attacks - Infosecurity Magazine
MSSPs Need to Move Beyond Reactive Security | perspective | MSSP Alert
Health care’s biggest cybersecurity vulnerability is structural | STAT
How hackers are helping criminal gangs hijack truck deliveries
Experts say telecoms should include internet security for free | News | ERR
Vulnerability Management
New technology is increasing the speed and depth of cyber attacks
The AI cybersecurity boom may be creating a bigger problem than it solves | Ctech
Anthropic's Mythos AI model sparks fears of turbocharged hacking - Ars Technica
A tsunami of flaws: When frontier AI and Patch Tuesday collide | Computer Weekly
What is Anthopic's Claude Mythos and what risks does it pose? - BBC News
ECB to Quiz Bankers About Risks of Anthropic’s New AI Model, Source Says
Anthropic's Mythos model accessed by unauthorized users, Bloomberg News reports | Reuters
Mythos can find the vulnerability. It can't tell you what to do about it. | CyberScoop
Every Old Vulnerability Is Now an AI Vulnerability
Commercial AI Models Show Rapid Gains in Vulnerability Research - Infosecurity Magazine
NIST to stop rating non-priority flaws due to volume increase
The History of iOS Exploits: Apple’s Flawed Security Paradigm
Vulnerabilities
Unpatched Microsoft Defender Flaw Lets Hackers Gain Admin Access on Windows | Extremetech
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability
Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster - SecurityWeek
More Cisco SD-WAN bugs battered in attacks • The Register
New RDP Alert After April 2026 Security Update Warns of Unknown Connections
Android Phones Shown to Have a Major Biometric Security Weakness - Tech Advisor
Microsoft releases emergency updates to fix Windows Server issues
Critical flaw in Protobuf library enables JavaScript code execution
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case
Apple releases important iOS and iPadOS security fix you need to install now - PhoneArena
Oracle Patches 450 Vulnerabilities With April 2026 CPU - SecurityWeek
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
New Firefox update patches a whopping 271 bugs with help from Claude Mythos | ZDNET
New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
Microsoft issues emergency update for macOS and Linux ASP.NET threat - Ars Technica
Hackers exploit file upload bug in Breeze Cache WordPress plugin
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 17 April 2026
Black Arrow Cyber Threat Intelligence Briefing 17 April 2026:
-UK Financial Regulators Rush to Assess Risks of Anthropic Latest AI Model, FT Reports
-AI Adoption Is Outpacing the Safeguards Around It
-PwC: Cyber Security Risk Outpaces Corporate Ability to Manage
-New VENOM Phishing Attacks Steal Senior Executives’ Microsoft Logins
-Beyond Wipers: Iran-Backed Cyber Attacks and the Threat to Businesses
-Wiz: 80% of Cloud Breaches Are Caused by Basic Mistakes
-Ransomware Lives On, Blending Hacktivism and Crime, Fuelled by AI
-Security Leaders Overconfident About Ransomware Recovery
-‘It’s More Common Than You Think’: Experts Reveal How Hackers Are Trying to Hijack Your Inbox with These Clever Tactics
-From Awareness to Action: Closing the Human Risk Gap in Cyber Security
-How the Enterprise Supply Chain Has Created a Global Attack Surface
-UK Reliance on US Big Tech Companies Is ‘National Security Risk’, Claims Report
-The Most Important Cyber Security Trends in 2026 So Far
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
In our threat intelligence briefing last week, we described how Anthropic’s new AI model had identified thousands of new serious vulnerabilities in major operating systems and ways to exploit them; this week, we include details of how the UK financial regulators are working to quickly address these AI developments with similar activity in other countries. We also report on how the adoption of AI by organisations themselves has increased the need for business leaders to strengthen their understanding and management of the associated risks.
We include details this week of how AI and other attacker tactics have increased risks such as inbox compromise, ransomware and other destructive attacks. Our advice on how business leaders should manage the risks remains fundamentally unchanged. The leadership should ensure a strong understanding of cyber risks from impartial experts, to lead the conversation on risk management with their control providers through proportionate controls underpinned by credible governance. The focus is not just on security, to reduce the probability of a successful attack, but also on resilience to withstand a successful attack when it happens. Contact us to discuss a suitable approach to achieve this.
Top Cyber Stories of the Last Week
UK Financial Regulators Rush to Assess Risks of Anthropic Latest AI Model, FT Reports
UK financial regulators are urgently assessing the cyber security implications of a new artificial intelligence model after claims it identified thousands of serious weaknesses across widely used software, including operating systems and web browsers. The Bank of England, the Financial Conduct Authority, HM Treasury and the National Cyber Security Centre are working with major banks, insurers and exchanges to understand whether the model could expose risks in critical systems. The move reflects growing concern that advanced AI could strengthen cyber defence, but also increase the risk of more effective cyber attacks.
AI Adoption Is Outpacing the Safeguards Around It
AI is being adopted faster than the safeguards around it, creating new risks for organisations. Reported AI related incidents rose from 233 in 2024 to 362 in 2025, while separate monitoring showed monthly cases reaching 435 at the start of 2026. At the same time, major AI providers are giving less visibility into how their systems are built and tested, with transparency scores falling from 58 to 40 in a year. This leaves organisations relying more on their own testing, monitoring and supplier controls to manage systems whose behaviour can be harder to predict than traditional software.
https://www.helpnetsecurity.com/2026/04/14/ai-adoption-safety-transparency-report/
PwC: Cyber Security Risk Outpaces Corporate Ability to Manage
PwC’s latest survey of more than 600 US executives shows cyber security is a board-level business risk that most organisations do not feel equipped to deal with. While 60% rank it among their top three risks, only 6% say they can manage it effectively. The report also found 68% see cyber-attacks as a moderate or serious threat, while 38% have increased spending on technology and artificial intelligence since January 2025. Despite this investment, many firms remain on the back foot as fast-changing regulation and rapid advances in AI make threats harder to manage.
https://www.inforisktoday.com/pwc-cybersecurity-risk-outpaces-corporate-ability-to-manage-a-31405
New VENOM Phishing Attacks Steal Senior Executives’ Microsoft Logins
A previously undocumented phishing‑as‑a‑service platform known as VENOM is targeting C‑suite executives through highly personalised emails designed to look like internal Microsoft SharePoint messages. The campaign uses QR codes to move victims onto mobile devices, where attackers relay the victim’s login and multi‑factor authentication process to Microsoft in real time, allowing them to capture credentials and active session tokens. Active since at least November, VENOM appears closed to wider criminal use, limiting its visibility. The activity highlights how senior leadership accounts are being deliberately singled out using sophisticated, identity‑focused phishing techniques.
Beyond Wipers: Iran-Backed Cyber Attacks and the Threat to Businesses
Iran-linked cyber activity is posing a growing risk to UK and US organisations, particularly those in finance, healthcare, energy, transport and critical services. One recent attack reportedly disrupted a global medical technology firm and claimed to have wiped more than 200,000 devices using a legitimate remote management tool. Researchers have tracked 5,800 attacks from 50 Iran-linked groups. While the US faces the greatest direct exposure, UK businesses remain vulnerable through supply chains and cloud-based services. Business leaders should ensure foundational controls are in place, including patching systems, enforcing MFA, reviewing privileged access, resilient backups and having incident response plans ready.
Wiz: 80% of Cloud Breaches Are Caused by Basic Mistakes
Researchers report that 80% of cloud breaches in 2025 stemmed from basic mistakes such as poor system configuration, weak handling of passwords and access keys, and gaps in user security. 53% of malicious activity that occurred before an attack involved reconnaissance, where criminals quietly map systems and test access. Rapid AI adoption is widening the number of possible entry points, while attackers are also using AI to speed up phishing, automate tasks and scale operations. To address this, business leaders should focus on visibility of the organisation’s externally reachable assets, identities and attack paths, while reinforcing basic security hygiene.
Ransomware Lives On, Blending Hacktivism and Crime, Fuelled by AI
Ransomware continues to evolve despite law enforcement disruption, with groups adopting more aggressive extortion tactics and increasingly blending criminal and political motives. Artificial intelligence is being used to generate malicious code, improve social engineering and scale operations, lowering the barrier for less‑skilled actors. In 2025, ransomware groups extorted more than $724 million in cryptocurrency, highlighting the profitability of the model. Hybrid ransomware and hacktivist groups are also using ransomware tools for ideological impact alongside traditional financial extortion. Business leaders should ensure strong control over user identities and privileges, as ransomware and extortion attacks are only as effective as the access they are able to obtain.
Security Leaders Overconfident About Ransomware Recovery
Many organisations are overconfident about their ability to recover from ransomware. Research shows that while 90% of security leaders believe they can restore operations quickly, only 28% fully recover their data after an attack. On average, just 72% of affected data is restored, with many organisations still facing data loss, downtime and business disruption. The report also found that more than 40% of organisations hit by cyber incidents suffered customer disruption or financial loss. Rapid adoption of artificial intelligence is adding further risk, with 43% saying it is advancing faster than their ability to secure it.
https://www.itpro.com/security/security-leaders-overconfident-about-ransomware-recovery
‘It’s More Common Than You Think’: Experts Reveal How Hackers Are Trying to Hijack Your Inbox with These Clever Tactics
Proofpoint has warned that criminals are increasingly abusing a legitimate email feature called inbox rules to quietly maintain access to compromised accounts. These automated settings can hide security alerts, forward sensitive messages, and mark emails as read, allowing attackers to monitor communications and impersonate victims without drawing attention. In the final quarter of 2025, around 10% of breached accounts had a malicious rule created within seconds of the initial compromise. Senior leaders, finance teams and other outward-facing roles remain particularly attractive targets for this type of cyber attack.
From Awareness to Action: Closing the Human Risk Gap in Cyber Security
Human behaviour is one of the biggest drivers of cyber security incidents, yet most organisations are still not responding effectively. Mimecast reports that 96% of those surveyed believe their defences against people being deceived or misusing access are incomplete. Attacks are rising across email, messaging and collaboration tools, with 53% reporting more phishing, 48% more email fraud and 45% more attacks through workplace platforms. The report also found that just 8% of users account for 80% of incidents, highlighting the value of better oversight, targeted training and joined-up security controls.
How the Enterprise Supply Chain Has Created a Global Attack Surface
Modern organisations now face growing cyber security risk through their suppliers, not just their own systems. As businesses rely on more cloud services, software providers and outsourced partners, each relationship can create a route into sensitive data or critical operations. Recent disruption linked to the war in Ukraine showed how problems in one region can affect organisations far beyond it through indirect supplier connections. The most effective response is a practical one: focus greatest scrutiny on high-risk suppliers with access to important systems or data, and build security checks into procurement and access decisions from the start.
UK Reliance on US Big Tech Companies Is ‘National Security Risk’, Claims Report
A report backed by MPs warns that the UK’s heavy dependence on a small number of US technology providers for data centres, software and other critical digital services could become a national security risk. It argues that political tensions could disrupt essential services, while limited competition may also be driving up public sector cloud costs by as much as £500 million a year. The report calls for greater investment in UK-based providers, open standards and open-source software (publicly available code that organisations can inspect and adapt), to improve resilience, reduce lock-in and support innovation.
The Most Important Cyber Security Trends in 2026 So Far
Cyber security trends in early 2026 centre on artificial intelligence, ransomware and nation‑state attacks. AI is being used to detect threats and understand sensitive data environments, while at the same time attackers use it to scale phishing, social engineering and deepfake attacks. Identity and access management remains vulnerable where credentials are compromised, or insider threats occur. Ransomware continues to evolve, with some attacks focused on encrypting or wiping systems to disrupt operations. Business leaders should ensure their data is identified and protected wherever it is stored or accessed, apply clear classification, and scrutinise third‑party software and suppliers.
https://securityboulevard.com/2026/04/the-most-important-cybersecurity-trends-in-2026-so-far/
Governance, Risk and Compliance
PwC: Cybersecurity Risk Outpaces Corporate Ability to Manage
Businesses are paying the price for CISO burnout | Computer Weekly
The Most Important Cybersecurity Trends in 2026 So Far - Security Boulevard
Only a third of cybersecurity professionals plan to stay in their current role - BetaNews
Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)
Threats
Ransomware, Extortion and Destructive Attacks
Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month - Infosecurity Magazine
Ransomware Lives On, Blending Hacktivism and Crime, Fueled by AI - Security Boulevard
Ransomware Groups Are Actively Disabling Your EDR Before You Even Know It - Security Boulevard
Security leaders overconfident about ransomware recovery | IT Pro
Ransomware scum, other crims exploit 4 old Microsoft bugs • The Register
Emulating the Persuasive NightSpire Ransomware - Security Boulevard
0APT ransomware gang extorts Krybit amid doxxing threat • The Register
Pay up for ransomware and they’ll be back for more - BetaNews
Crypto-exchange Kraken extorted by hackers after insider breach
Ransomware and Destructive Attack Victims
Beyond wipers: Iran-backed cyber attacks and the threat to businesses | IT Pro
Stolen Rockstar Games analytics data leaked by extortion gang
Hackers threaten to leak over 9M Amtrak records, including personal info | Cybernews
McGraw-Hill confirms data breach following extortion threat
Hallmark data breach escalates as hackers leak and sell customer records| Cybernews
All jobs lost as Scottish company forced into liquidation after cyber attack | The National
6-Year Ransomware Campaign Targets Turkish Homes & SMBs
Teenaged Boy Arrested After NI Schools Hacked | Silicon UK Tech
U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 | Trend Micro (US)
Phishing & Email Based Attacks
New VENOM phishing attacks steal senior executives' Microsoft logins
Poisoned "Office 365" search results lead to stolen paychecks - Help Net Security
Global phishing war targets smartphones in massive hack-for-hire espionage campaign - Times Kuwait
Other Social Engineering
From awareness to action: Closing the human risk gap in cybersecurity | resource | SC Media
Poisoned "Office 365" search results lead to stolen paychecks - Help Net Security
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
ClickFix campaign delivers Mac malware via fake Apple page - Help Net Security
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
Triad Nexus Expands Global Fraud Operations Despite US Sanctions - Infosecurity Magazine
Major Scam Network Triad Nexus Adapts Operations to Avoid U.S. Scrutiny - Security Boulevard
Artificial Intelligence
AI cyber threats: open letter to business leaders (HTML) - GOV.UK
Financial services regulators assess risks from Anthropic’s new AI model - FStech
The 'Vulnpocalypse': Why experts fear AI could tip the scales toward hackers
UK gov's Mythos AI tests help separate cybersecurity threat from hype - Ars Technica
Anthropic’s Mythos finds software flaws faster than companies can fix them | Fortune
Anthropic’s Mythos signals a structural cybersecurity shift | CSO Online
Ransomware Lives On, Blending Hacktivism and Crime, Fueled by AI - Security Boulevard
AI adoption is outpacing the safeguards around it - Help Net Security
The exploit gap is closing, and your patch cycle wasn't built for this - Help Net Security
AI and Cryptocurrency Scams are Costing Americans Billions, FBI Reports
How the explosion in machine identities is changing cyber defense | IT Pro
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
CEOs are embracing AI agents as cyber risks grow | Semafor
Apple Intelligence AI Guardrails Bypassed in New Attack - SecurityWeek
Rethinking Insider Risk in the Age of AI and Autonomy - Silicon UK Expert Advice
What AI-Driven Attack Chains Mean for CFOs and CISOs
China Cracking Down on the Types of AI That Are Tearing America Apart
43% of AI-generated code changes need debugging in production, survey finds | VentureBeat
Enterprises are using AI for security but less than a third fully trust it - BetaNews
Bots/Botnets
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
Careers, Roles, Skills, Working in Cyber and Information Security
Businesses are paying the price for CISO burnout | Computer Weekly
Only a third of cybersecurity professionals plan to stay in their current role - BetaNews
CISOs Urged to Innovate in Talent Retention as Job Satisfaction Declin - Infosecurity Magazine
UK Cyber Security Council Launches Associate Cyber Security Profession - Infosecurity Magazine
Cloud/SaaS
APT41 Delivers 'Undetectable' Backdoor to Steal Cloud Credentials
Wiz: 80% of cloud breaches are caused by basic mistakes | IT Pro
Microsoft 365 Tenant Security: How to Stay in Control of Your Data - Infosecurity Magazine
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
AI and Cryptocurrency Scams are Costing Americans Billions, FBI Reports
Bitcoin Depot hack leads to $3.6M Bitcoin theft via stolen credentials
Over 20,000 crypto fraud victims identified in international crackdown
French cops free mother and son after crypto kidnapping • The Register
U.S. Treasury enlists crypto in national cyber defense push as digital asset hacks rise
Crypto-exchange Kraken extorted by hackers after insider breach
$12 million frozen, 20,000 victims identified in crypto scam crackdown - Help Net Security
Cyber Crime, Organised Crime & Criminal Actors
Ransomware Lives On, Blending Hacktivism and Crime, Fueled by AI - Security Boulevard
French cops free mother and son after crypto kidnapping • The Register
W3LL phishing service sold for $500 dismantled by the FBI - Help Net Security
Triad Nexus Expands Global Fraud Operations Despite US Sanctions - Infosecurity Magazine
Cybercriminal responsible for PowerSchool breach speaks out
Hacker Unknown now known, named on Europol’s most-wanted list | CSO Online
Data Breaches/Leaks
108 Chrome Extensions Linked to Data Exfiltration and Sessio...
Hack at Anodot leaves over a dozen breached companies facing extortion | TechCrunch
Over 100 Chrome extensions caught stealing Google and Telegram data: How to stay safe? | Mint
LiteLLM Supply Chain Attack Exposes Millions To Credential Theft
Hackers threaten to leak over 9M Amtrak records, including personal info | Cybernews
McGraw-Hill confirms data breach following extortion threat
Hallmark data breach escalates as hackers leak and sell customer records| Cybernews
300,000 People Impacted by Eurail Data Breach - SecurityWeek
Hims Breach Exposes the Most Sensitive Kinds of PHI
European Gym giant Basic-Fit data breach affects 1 million members
Nightclub Giant RCI Hospitality Reports Data Breach - SecurityWeek
Europe's Largest Gym Chain Says Data Breach Impacts 1 Million Members - SecurityWeek
Stolen Rockstar Games analytics data leaked by extortion gang
Hungary officials used weak passwords exposed in breach dump • The Register
Data Protection
Health insurance lead sites sell personal data within seconds of form submission - Help Net Security
Data/Digital Sovereignty
UK reliance on US big tech companies is ‘national security risk’, claims report | Computer Weekly
France to ditch Windows for Linux to reduce reliance on US tech | TechCrunch
Denial of Service/DoS/DDoS
Orgs Must Test Networks to Handle DDoS Attacks During Peak Loads
Cybercriminals are increasingly attacking digital services
Encryption
Why is the timeline to quantum-proof everything constantly shrinking? | CyberScoop
Preparing for 'Q-Day': Why Quantum Risk Management Is a Must
WhatsApp's 'End-to-End Encryption by Default' Claim Called Major Consumer Fraud by Pavel Durov
Fraud, Scams and Financial Crime
AI and Cryptocurrency Scams are Costing Americans Billions, FBI Reports
Over 20,000 crypto fraud victims identified in international crackdown
Triad Nexus Expands Global Fraud Operations Despite US Sanctions - Infosecurity Magazine
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
Beyond wipers: Iran-backed cyber attacks and the threat to businesses | IT Pro
$12 million frozen, 20,000 victims identified in crypto scam crackdown - Help Net Security
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
Identity and Access Management
How the explosion in machine identities is changing cyber defense | IT Pro
Your Next Breach Will Look Like Business as Usual
Insider Risk and Insider Threats
Crypto-exchange Kraken extorted by hackers after insider breach
From awareness to action: Closing the human risk gap in cybersecurity | resource | SC Media
Rethinking Insider Risk in the Age of AI and Autonomy - Silicon UK Expert Advice
The Quiet Revolt: What The World Happiness Report 2026 Tells Security Professionals
Internet of Things – IoT
The Tech Of The Iran War: Hacking Traffic Cameras & Cyberpunk Surveillance Ops
Law Enforcement Action and Take Downs
Teenaged Boy Arrested After NI Schools Hacked | Silicon UK Tech
$12 million frozen, 20,000 victims identified in crypto scam crackdown - Help Net Security
Hacker Unknown now known, named on Europol’s most-wanted list | CSO Online
Linux and Open Source
France to ditch Windows for Linux to reduce reliance on US tech | TechCrunch
Distributed Risk: Open-Source Software as Strategic Infrastructure | Geopolitical Monitor
Microsoft locks out top open source devs, blames process • The Register
Malvertising
Poisoned "Office 365" search results lead to stolen paychecks - Help Net Security
'Harmless' Global Adware Transforms Into an AV Killer
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
Signed software abused to deploy antivirus-killing scripts
Malware
'Harmless' Global Adware Transforms Into an AV Killer
APT41 Delivers 'Undetectable' Backdoor to Steal Cloud Credentials
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
Yes, you can get malware just by visiting a website
Renovate & Dependabot: The New Malware Delivery System - Security Boulevard
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
Signed software abused to deploy antivirus-killing scripts
ClickFix campaign delivers Mac malware via fake Apple page - Help Net Security
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
Fake Claude Website Distributes PlugX RAT - SecurityWeek
Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites | TechCrunch
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
New AgingFly malware used in attacks on Ukraine govt, hospitals
Misinformation, Disinformation and Propaganda
War Game Exercise Shows How Social Media Manipulation Works
Mobile
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
Users lose $9.5 million to fake Ledger wallet app on the Apple App Store
Global phishing war targets smartphones in massive hack-for-hire espionage campaign - Times Kuwait
WhatsApp's 'End-to-End Encryption by Default' Claim Called Major Consumer Fraud by Pavel Durov
Musk, Durov attack WhatsApp encryption | Cybernews
iPhone forensics expose Signal messages after app removal in U.S. case
Models, Frameworks and Standards
EU cybersecurity standards are at risk if supplier ban passes - Help Net Security
Outages
Kremlin tells Russians internet shutdowns are temporary after crackdown ruffles elite | Reuters
Passwords, Credential Stuffing & Brute Force Attacks
APT41 Delivers 'Undetectable' Backdoor to Steal Cloud Credentials
Bitcoin Depot hack leads to $3.6M Bitcoin theft via stolen credentials
New VENOM phishing attacks steal senior executives' Microsoft logins
Your Next Breach Will Look Like Business as Usual
Are Rainbow Tables Still Relevant in 2026? - Infosecurity Magazine
Raspberry Pi OS 6.2 disables passwordless sudo by default - Help Net Security
Regulations, Fines and Legislation
AI security officials warn on Anthropic model as Bank to hold meeting
Bessent, Powell Summon Bank CEOs to Urgent Meeting Over Anthropic's New AI Model - Bloomberg
EU cybersecurity standards are at risk if supplier ban passes - Help Net Security
What the EU AI Act requires for AI agent logging - Help Net Security
Netherlands won't ban ransom payments to hackers | Cybernews
The FCC just saved Netgear from its router ban for no obvious reason | The Verge
FCC just handed Netgear a de facto router monopoly in the US
Social Media
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
The Quiet Revolt: What The World Happiness Report 2026 Tells Security Professionals
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
War Game Exercise Shows How Social Media Manipulation Works
BrowserGate: Claims of LinkedIn ‘Spying’ Clash With Security Research Findings - SecurityWeek
Software Supply Chain
CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads - SecurityWeek
Supply Chain and Third Parties
Two different attackers poisoned popular open source tools • The Register
How the enterprise supply chain has created a global attack surface - IT Security Guru
Hack at Anodot leaves over a dozen breached companies facing extortion | TechCrunch
Google Warns of New Threat Group Targeting BPOs and Helpdesks - Infosecurity Magazine
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Beyond wipers: Iran-backed cyber attacks and the threat to businesses | IT Pro
Do Ceasefires Slow Cyberattacks? History Suggests Not
Cyberattacks, Tariffs, Geopolitics Loom Over Business Executives
The Tech Of The Iran War: Hacking Traffic Cameras & Cyberpunk Surveillance Ops
Global phishing war targets smartphones in massive hack-for-hire espionage campaign - Times Kuwait
We should be more worried about cyber warfare targeting the civilian economy
Cybersecurity in an Age of Geopolitical Fracture
Nation State Actors
U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 | Trend Micro (US)
China
APT41 Delivers 'Undetectable' Backdoor to Steal Cloud Credentials
U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 | Trend Micro (US)
China Cracking Down on the Types of AI That Are Tearing America Apart
Russia
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’ | CyberScoop
Your router may be vulnerable to Russian hackers, FBI warns: 5 steps to take now | ZDNET
Russia's 'Fancy Bear' APT Continues Its Global Onslaught
The cables powering the internet are under the ocean – and under threat | TechSpot
New AgingFly malware used in attacks on Ukraine govt, hospitals
With Russia already 'at war with us', UK must urgently defend key North Sea energy infrastructure
Kremlin tells Russians internet shutdowns are temporary after crackdown ruffles elite | Reuters
Russian-Linked Hackers Breach Emails of the Romanian Army - The Romania Journal
North Korea
Two different attackers poisoned popular open source tools • The Register
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
Iran
Beyond wipers: Iran-backed cyber attacks and the threat to businesses | IT Pro
Do Ceasefires Slow Cyberattacks? History Suggests Not
The Tech Of The Iran War: Hacking Traffic Cameras & Cyberpunk Surveillance Ops
Iran Planning Cyberattack on US Infrastructure, Intelligence Community Warns - The National Interest
Iran-linked group Handala claims to have breached three major UAE organizations
Sweden reports cyberattack attempt on heating plant amid rising energy threats
Industrial Devices Still Vulnerable As Conflicts Move to Cyber
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Ransomware Lives On, Blending Hacktivism and Crime, Fueled by AI - Security Boulevard
Global phishing war targets smartphones in massive hack-for-hire espionage campaign - Times Kuwait
Tools and Controls
Enterprises are using AI for security but less than a third fully trust it - BetaNews
Ransomware Groups Are Actively Disabling Your EDR Before You Even Know It - Security Boulevard
PwC: Cybersecurity Risk Outpaces Corporate Ability to Manage
'Harmless' Global Adware Transforms Into an AV Killer
Microsoft locks out top open source devs, blames process • The Register
From awareness to action: Closing the human risk gap in cybersecurity | resource | SC Media
UK financial regulators rush to assess risks of Anthropic’s latest AI model
Financial services regulators assess risks from Anthropic’s new AI model - FStech
Mythos testing begins as governments raise cyber concerns
The Vuln Surge is Coming. CSA is Telling Us How to Survive It - Security Boulevard
The 'Vulnpocalypse': Why experts fear AI could tip the scales toward hackers
Testing reveals Claude Mythos's offensive capabilities and limits - Help Net Security
Claude Mythos Preview completes full cyberattack simulation for the first time - The New Stack
Anthropic’s Mythos finds software flaws faster than companies can fix them | Fortune
The exploit gap is closing, and your patch cycle wasn't built for this - Help Net Security
Security leaders overconfident about ransomware recovery | IT Pro
How AI is getting better at finding security holes : NPR
Most organizations make a mess of handling digital disruption | IT Pro
Signed software abused to deploy antivirus-killing scripts
Incident response for AI: Same fire, different fuel | Microsoft Security Blog
43% of AI-generated code changes need debugging in production, survey finds | VentureBeat
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
Network segmentation projects fail in predictable patterns - Help Net Security
What vibe hunting gets right about AI threat hunting, and where it breaks down - Help Net Security
Other News
Fortinet report: cyberattacks against banks increasing
From Somerset to New York: Why are undersea cables so important? - BBC News
The cables powering the internet are under the ocean – and under threat | TechSpot
Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat - Infosecurity Magazine
Cybercriminals are increasingly attacking digital services
Comms Business - One fifth of telcos' websites wide open to cyber attacks
Healthcare IT under siege: CloudWave is fighting back - SiliconANGLE
The Dumbest Hack of the Year Exposed a Very Real Problem | WIRED
Vulnerability Management
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
AI security officials warn on Anthropic model as Bank to hold meeting
Bessent, Powell Summon Bank CEOs to Urgent Meeting Over Anthropic's New AI Model - Bloomberg
UK financial regulators rush to assess risks of Anthropic’s latest AI model
Mythos testing begins as governments raise cyber concerns
Testing reveals Claude Mythos's offensive capabilities and limits - Help Net Security
The exploit gap is closing, and your patch cycle wasn't built for this - Help Net Security
How AI is getting better at finding security holes : NPR
Vulnerabilities
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
Microsoft drops its second-largest monthly batch of defects on record | CyberScoop
Privilege Elevation Dominates Massive Microsoft Patch Update
Windows BitLocker Vulnerability Allows Attacker to Bypass Security Feature
Cisco says critical Webex Services flaw requires customer action
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
Ransomware scum, other crims exploit 4 old Microsoft bugs • The Register
Mac users, update your ChatGPT app immediately: OpenAI issues urgent security warning | Mint
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 - SecurityWeek
Juniper Networks Patches Dozens of Junos OS Vulnerabilities - SecurityWeek
Adobe Patches Exploited Zero-Day That Lingered for Months
Adobe Patches 55 Vulnerabilities Across 11 Products - SecurityWeek
Recently leaked Windows zero-days now exploited in attacks
Vindictive hacker drops second Windows Defender exploit | Cybernews
SAP Patches Critical ABAP Vulnerability - SecurityWeek
Critical Fortinet sandbox bugs allow auth bypass and RCE • The Register
OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support - Help Net Security
Attackers target unpatched ShowDoc servers via CVE-2025-0520
DavMail 6.6.0 patches a regex flaw and advances its Microsoft Graph backend - Help Net Security
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
Two Vulnerabilities Patched in Ivanti Neurons for ITSM - SecurityWeek
Microsoft: April Windows Server 2025 update may fail to install
Splunk Enterprise Update Patches Code Execution Vulnerability - SecurityWeek
Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face
Critical flaw in wolfSSL library enables forged certificate use
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Threat Intelligence Briefing 10 April 2026
Black Arrow Cyber Threat Intelligence Briefing 10 April 2026:
-Anthropic’s New AI Model Finds and Exploits Zero-Days Across Every Major OS and Browser
-Hundreds of Orgs Compromised Daily in Microsoft Device Code Phishing Attacks
-Qilin Ransomware Uses Malicious DLL to Kill Almost Every Vendor’s EDR Solutions
-More than Half of Enterprises Are Using Devices with Out-of-Date Operating Systems – and It’s Leaving Them Wide Open to Attacks
-Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack
-Why Britain’s Most Common Crime Has Been Poorly Investigated for Decades
-Mobile Attack Surface Expands as Enterprises Lose Control
-FBI: Cyber Fraud Surges to $17.6 Billion in Losses as Scams, Crypto Theft Soar
-Boards Are Falling Short on Cyber Security
-72% of Workers Say AI Is Giving Phishing a Dangerous New Edge, Sagiss Managed Security Survey Finds
-The Rise of Proactive Cyber: Why Defence Is No Longer Enough
-Better Prepare for a Cyber Breach
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
There are two big headlines for business leaders this week in our review of cyber security in the specialist and public media.
Anthropic’s AI model has identified thousands of new serious vulnerabilities in major operating systems and quickly established ways to exploit them. This is a ground-shift, because AI models used by attackers will likely be able to do the same soon, and many of these vulnerabilities had been undiscovered by human security researchers for decades. The second headline is the escalating use of a new type of phishing attack that can bypass controls. We published advisories on our website last week, with recommended actions that business leaders should focus on in response to these developments; see below for links to the advisories.
Other developments this week include ransomware attackers who disable security monitoring tools, Russian attackers gaining access to home and small-office routers, and research into organisations using Mac devices with out-of-date operating systems.
Our advice for business leaders remains consistent: ensure you have an unbiased understanding of your risks and how effectively those risks are addressed through your controls. This is achieved by upskilling on cyber security from a business perspective, and implementing proportionate governance enhanced by working with specialists in cyber risk management. Contact us to discuss how you can achieve this to help protect your business.
Top Cyber Stories of the Last Week
Anthropic’s New AI Model Finds and Exploits Zero-Days Across Every Major OS and Browser
Anthropic has reported a sharp leap in the ability of advanced AI to find and exploit previously unknown software flaws across major operating systems and web browsers. In testing, its new model uncovered thousands of serious weaknesses and produced working attack methods far more often than earlier versions. It also turned known flaws into usable exploits in less than a day at relatively low cost. The findings suggest the window between a vulnerability being discovered and weaponised is shrinking. This increases pressure on organisations to patch faster and strengthen their preparations for incident response.
https://www.helpnetsecurity.com/2026/04/08/anthropic-claude-mythos-preview-identify-vulnerabilities/
Hundreds of Orgs Compromised Daily in Microsoft Device Code Phishing Attacks
Microsoft has reported a large-scale phishing campaign that is compromising hundreds of organisations each day by abusing a legitimate sign in process designed for devices such as smart TVs and printers. The attackers use AI to create convincing, highly personalised emails and automate much of the attack, helping them evade detection and bypass multi-factor authentication. Once inside, they focus on finance related accounts, stealing sensitive emails and financial information. The campaign underlines the need for business leaders to restrict unnecessary sign‑in methods, reinforce employee phishing awareness, and ensure unusual authentication activity is monitored.
https://www.theregister.com/2026/04/07/microsoft_device_code_phishing/
Qilin Ransomware Uses Malicious DLL to Kill Almost Every Vendor’s EDR Solutions
Researchers have uncovered how the ransomware group Qilin is using a sophisticated attack chain designed to disable more than 300 security monitoring tools before launching encryption. The group hides malware inside trusted software, runs it largely in memory to avoid detection, and installs software to interfere with core Windows security functions. The campaign shows how attackers are neutralising defences first to extend their time undetected. For business leaders, this underlines the need for layered security and oversight of unusual system changes, and avoiding reliance on a single protective tool.
https://cybersecuritynews.com/qilin-ransomware-kill-edr/
More than Half of Enterprises Are Using Devices with Out-of-Date Operating Systems – and It’s Leaving Them Wide Open to Attacks
A review of more than 150,000 Mac devices shows weak device management is leaving many organisations exposed to cyber security risks. 53% of organisations had at least one device running a critically out of date operating system, while 95% of assessed applications had at least one medium severity weakness. The findings also show growing risks on Mac devices, with 44% seeing malicious network activity and 26% affected by cryptojacking, where attackers misuse devices to generate cryptocurrency.
Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack
A Russian state-linked hacking group has compromised more than 200 organisations and 5,000 consumer devices by targeting home and small office routers since at least August 2025. By changing internet settings on these devices, the group was able to monitor web traffic and, in some cases, intercept sensitive information such as emails, login details and cloud data. Sectors affected include government, technology, telecoms and energy. The campaign highlights how poorly secured home networks used by remote and hybrid staff can create a serious cyber security risk for organisations.
https://cybersecuritynews.com/russian-hackers-exploiting-routers/
Why Britain’s Most Common Crime Has Been Poorly Investigated for Decades
Fraud remains the most common crime in Britain, with an estimated 4.2 million cases recorded in the year to September 2025, yet only a small share result in prosecution. For years, victims have faced poor support, weak investigations and outdated reporting systems, with some police forces taking no action on most cases. Reviews have also found too few specialist investigators, limited investment and inadequate technology. The UK Government has launched a new strategy focused on better victim support, reimbursement, stronger justice outcomes and a renewed reporting system.
Mobile Attack Surface Expands as Enterprises Lose Control
Jamf’s review of more than 1.7 million mobile devices shows many organisations are losing control of a rapidly expanding mobile risk. Over half had at least one device running a critically outdated operating system, 18% had users connecting to risky public Wi‑Fi, and 8% had clicked phishing links designed to steal credentials or sensitive data. The report also found 86% of widely used mobile apps carried known security weaknesses, with “shadow AI” in everyday apps creating new exposure. For business leaders, this underlines the importance of knowing what devices and apps are accessing corporate data, enforcing basic hygiene such as updates and secure connections, and maintaining visibility over how mobile tools are actually being used.
https://www.securityweek.com/mobile-attack-surface-expands-as-enterprises-lose-control/
FBI: Cyber Fraud Surges to $17.6 Billion in Losses as Scams, Crypto Theft Soar
The FBI’s latest figures show $17.6 billion in cyber‑enabled fraud losses in 2025, with over one million complaints filed. Investment scams caused the greatest financial harm, while business email compromise exceeded $3 billion in losses. Cryptocurrency was linked to more than $11.3 billion stolen, and reports involving AI‑enabled fraud are rising. For business leaders, the figures highlight growing financial exposure from impersonation, payment fraud, and emerging technologies, not just technical cyber incidents.
https://therecord.media/cyber-fraud-surges-to-17-billion-fbi-ic3
Boards Are Falling Short on Cyber Security
Board attention to cyber security is rising, but progress in reducing risk remains slow. Recent data shows cybercrime losses increased by 33% year on year, underlining the scale of the challenge. A common weakness is that boards often lack the expertise to judge whether senior cyber security leaders are effective, treat artificial intelligence mainly as a growth issue rather than a security and governance risk, and confuse regulatory compliance with genuine protection. Stronger outcomes come when cyber security is overseen as a business resilience issue tied to leadership accountability, operational continuity and competitive strength.
https://hbr.org/2026/04/boards-are-falling-short-on-cybersecurity
72% of Workers Say AI Is Giving Phishing a Dangerous New Edge, Sagiss Managed Security Survey Finds
A Sagiss survey of 500 desk-based workers found that AI is making phishing emails and chat messages more polished, convincing and harder to recognise. Nearly three quarters of respondents said these messages are more believable than a year ago, while 64% said AI could plausibly imitate a colleague. The risk is heightened by pressured working habits: 63% admitted clicking a work link before properly checking it, 57% verified a request only after acting, and 68% review work messages outside normal hours. The findings show that speed and fatigue are now amplifying phishing risk as much as technical deception.
The Rise of Proactive Cyber: Why Defence Is No Longer Enough
Cyber attacks are moving too quickly for a purely reactive approach to keep pace. The time between an attacker gaining access and passing that access to a second criminal group has fallen from eight hours in 2022 to just 22 seconds in 2025, showing how coordinated and fast moving the threat has become. In response, governments and major technology providers are stepping up efforts to disrupt attackers earlier through legal action, infrastructure takedowns and stronger product security. For most organisations, however, the priority remains strong internal resilience, rapid evidence sharing and well rehearsed incident response.
Better Prepare for a Cyber Breach
Mid-market organisations face growing exposure to cyber attacks as a breach at one supplier or technology provider can quickly disrupt operations, deliveries and customer service across an entire business network. At the same time, 77% of organisations still lack the basic controls needed to protect artificial intelligence systems, data and cloud environments. The priority is stronger oversight of how AI tools are used, tighter access controls, clearer rules for staff and suppliers, and better governance so businesses can spot threats earlier, limit disruption and protect long term value.
https://professionalsecurity.co.uk/products/cyber/better-prepare-for-a-cyber-breach/
Advisories Published in the Last Week
Black Arrow Cyber Advisory 10 April 2026 – Frontier AI and the Changing Cyber Threat Landscape
https://www.blackarrowcyber.com/blog/advisory-10-april-2026-frontier-ai-changing-threat-landscape
Black Arrow Cyber Advisory - 10 April 2026 - Microsoft device code phishing campaigns targeting Microsoft 365 users
https://www.blackarrowcyber.com/blog/advisory-10-april-2026-microsoft-device-code-phishing
Governance, Risk and Compliance
Cyber threats need to be embedded in corporate culture – report
Most Organizations Do Not Fully Trust Their Cybersecurity Vendors
The rise of proactive cyber: Why defense is no longer enough | CSO Online
Better prepare for a cyber breach | Professional Security Magazine
Boards Are Falling Short on Cybersecurity
How to know you’re a real-deal CSO — and whether that job opening truly seeks one | CSO Online
Meaningful metrics demonstrate the value of cyber-resiliency | TechTarget
Cyberattacks On Law Firms Are Rising. Here’s What’s Driving It. - Above the Law
Threats
Ransomware, Extortion and Destructive Attacks
Qilin Ransomware Uses Malicious DLL to Kill Almost Every Vendor's EDR Solutions
Qilin EDR killer infection chain
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
Ransomware Will Hit Hospitals. Rehearsals Are Key to Defense
Evolution of Ransomware: Multi-Extortion Ransomware Attacks
Man admits to locking thousands of Windows devices in extortion plot
German authorities identify REvil and GandCrab ransomware bosses
Ransomware reimagined: Why containment alone is no longer enough | resource | SC Media
Emulating the Concealed Sinobi Ransomware - Security Boulevard
Ransomware and Destructive Attack Victims
Die Linke German political party confirms data stolen by Qilin ransomware
Dutch hospitals hit after patient software cyberattack | Cybernews
Ransomware knocks Dutch healthcare software vendor offline • The Register
Signature Healthcare hit by cyberattack, services and pharmacies impacted
Ransomware attack on company that manages Dutch hospitals' patient files | NL Times
Phishing & Email Based Attacks
72% of Workers Say AI Is Giving Phishing a Dangerous New Edge, Sagiss Managed Security Survey Finds
Hundreds compromised daily in Microsoft device code phishes • The Register
Inside an AI‑enabled device code phishing campaign | Microsoft Security Blog
New Phishing Platform Used in Credential Theft Campaigns - Infosecurity Magazine
Device code phishing attacks surge 37x as new kits spread online
Phishers sneak through using GitHub and Jira’s own mail delivery infrastructure - Help Net Security
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
How a burner email can protect your inbox - setting one up one is easy and free | ZDNET
Business Email Compromise (BEC)/Email Account Compromise (EAC)
Other Social Engineering
Hundreds compromised daily in Microsoft device code phishes • The Register
Inside an AI‑enabled device code phishing campaign | Microsoft Security Blog
Device code phishing attacks surge 37x as new kits spread online
Axios Attack Shows Social Complex Engineering Is Industrialized
I knew about North Korean hackers—they still tricked me and got into my computer | Fortune
Traffic violation scams switch to QR codes in new phishing texts
That dream job offer from Coca-Cola or Ferrari? It’s a trap for your passwords | Malwarebytes
New macOS stealer campaign uses Script Editor in ClickFix attack
Social engineering attacks on open source developers are escalating - Help Net Security
Artificial Intelligence
72% of Workers Say AI Is Giving Phishing a Dangerous New Edge, Sagiss Managed Security Survey Finds
Inside an AI‑enabled device code phishing campaign | Microsoft Security Blog
Threat actor abuse of AI accelerates from tool to cyberattack surface | Microsoft Security Blog
Claude Code's innards revealed as source code leaked online • The Register
The New Rules of Engagement: Matching Agentic Attack Speed - SecurityWeek
CISOs grapple with AI demands within flat budgets - Help Net Security
Most Organisations Face an Unsecured API Surge As AI Agents Outpace Security - IT Security Guru
Anthropic Issues Copyright Takedowns to Scrub Claude Code Leak | PCMag
A.I. Is on Its Way to Upending Cybersecurity - The New York Times
Agentic AI's role in amplifying and creating insider risks | TechTarget
The AI Revolution in Cyber Conflict | Lawfare
How Security Leaders Can Safeguard Against Vibe Coding Security Risks - Infosecurity Magazine
Bots/Botnets
Cybercriminals move deeper into networks, hiding in edge infrastructure - Help Net Security
Residential proxies evaded IP reputation checks in 78% of 4B sessions
Residential proxies make a mockery of IP-based defenses - Help Net Security
Careers, Roles, Skills, Working in Cyber and Information Security
How to know you’re a real-deal CSO — and whether that job opening truly seeks one | CSO Online
ISC2 Publishes Guidance on the Inclusion of AI Security Concepts Across all its Certifications
The cybersecurity boom hiding a growing privacy skills shortage | TechRadar
Why modern cyber conflict is partly a global skills challenge | TechRadar
Cloud/SaaS
Trivy supply chain attack enabled European Commission cloud breach - Help Net Security
The EU is suffering a hacking crisis. Here’s what we know. – POLITICO
Snowflake customers hit in data theft attacks after SaaS integrator breach
Chaos malware expands from routers to Linux cloud servers - Help Net Security
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
Act-of-War Clauses Cloud Cyber Insurance Coverage - DataBreaches.Net
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images
Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot
Cryptographers place $5,000 bet whether quantum will matter • The Register
Cyber Crime, Organised Crime & Criminal Actors
Cybercriminals move deeper into networks, hiding in edge infrastructure - Help Net Security
Don't glamorize cybercrims, roast them instead • The Register
Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime
Threat Actors Get Crafty With Emojis to Escape Detection
Security lapse lets researchers view React2Shell hackers’ dashboard | CSO Online
Criminal wannabes even more dangerous than the pros • The Register
Data Breaches/Leaks
European Commission breach exposed data of 30 EU entities, CERT-EU says
Trivy supply chain attack enabled European Commission cloud breach - Help Net Security
The EU is suffering a hacking crisis. Here’s what we know. – POLITICO
Snowflake customers hit in data theft attacks after SaaS integrator breach
Jones Day Law Firm Says Hackers Accessed Some Clients’ Data (1)
FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident’ - POLITICO
Claude Code's innards revealed as source code leaked online • The Register
Adobe Breach - Threat Actor Allegedly Claims Leak of 13 Million Support Tickets and Employee Records
Hundreds of UK soldiers exposed at military bases… by their Strava workouts
Anthropic Issues Copyright Takedowns to Scrub Claude Code Leak | PCMag
Die Linke German political party confirms data stolen by Qilin ransomware
Better prepare for a cyber breach | Professional Security Magazine
Google: New UNC6783 hackers steal corporate Zendesk support tickets
Hims & Hers warns of data breach after Zendesk support ticket breach
Denial of Service/DoS/DDoS
Major outage cripples Russian banking apps and metro payments nationwide
Why DDoS Mitigation Fails: 5 Gaps That Testing Reveals - Security Boulevard
Pro-Iran Group Takes Credit for Cyberattacks on Chime, Pinterest
Encryption
‘It’s a real shock’: quantum-computing breakthroughs pose imminent risks to cybersecurity
Cryptographers place $5,000 bet whether quantum will matter • The Register
Fraud, Scams and Financial Crime
Why Britain's most common crime has been poorly investigated for decades | UK News | Sky News
Nigerian romance scammer jailed after being caught out by fellow fraudster
Websites suffering from subscription bombing attacks | Cybernews
Life imprisonment for Cambodian scam compound operators - but will it make a difference?
Your marketing stack is an attack surface – is security watching? | TechRadar
Your customer passed authentication. So why are they sending money to a scammer? - Help Net Security
Hidden scammer arms race every business now faces - Insurance Post
Identity and Access Management
The Hidden Cost of Recurring Credential Incidents
MSSPs Are the New Target in Login-Based Attacks – Blackpoint Cyber | news | MSSP Alert
Insider Risk and Insider Threats
Agentic AI's role in amplifying and creating insider risks | TechTarget
Insurance
Act-of-War Clauses Cloud Cyber Insurance Coverage - DataBreaches.Net
Internet of Things – IoT
Internet-Connected Coffee Machine Reportedly Led to Corporate Data Breach - Security Boulevard
Law Enforcement Action and Take Downs
Man admits to locking thousands of Windows devices in extortion plot
Police Are Using Cookies To Catch Criminals - Here's How
Why Britain's most common crime has been poorly investigated for decades | UK News | Sky News
Nigerian romance scammer jailed after being caught out by fellow fraudster
Life imprisonment for Cambodian scam compound operators - but will it make a difference?
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
German authorities identify REvil and GandCrab ransomware bosses
Linux and Open Source
Social engineering attacks on open source developers are escalating - Help Net Security
The State of Trusted Open Source Report
Chaos malware expands from routers to Linux cloud servers - Help Net Security
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
Microsoft suspends dev accounts for high-profile open source projects
Malvertising
Your marketing stack is an attack surface – is security watching? | TechRadar
Malware
Chaos malware expands from routers to Linux cloud servers - Help Net Security
New macOS stealer campaign uses Script Editor in ClickFix attack
Hackers use pixel-large SVG trick to hide credit card stealer
Malware Threat to Critical Infrastructure Raises Alarms
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Mobile
Mobile Attack Surface Expands as Enterprises Lose Control - SecurityWeek
Android Malware Infects Over 2.3 Million Devices - Is Yours One? - Tech Advisor
Your phone is shouting your identity to every Wi-Fi network — fix it now
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images
Outages
‘Skipping a beat on resilience investment isn’t an option any more’ as IT outage costs soar | IT Pro
Passwords, Credential Stuffing & Brute Force Attacks
New Phishing Platform Used in Credential Theft Campaigns - Infosecurity Magazine
React2Shell Exploited in Large-Scale Credential Harvesting Campaign - SecurityWeek
MSSPs Are the New Target in Login-Based Attacks – Blackpoint Cyber | news | MSSP Alert
That dream job offer from Coca-Cola or Ferrari? It’s a trap for your passwords | Malwarebytes
Regulations, Fines and Legislation
Old laws treat whitehats like criminals and pose risks | Cybernews
Trump wants to slash $707M from CISA's budget • The Register
Social Media
Software Supply Chain
Attackers trojanize Axios HTTP library in highest-impact npm supply chain attack | CSO Online
Supply Chain and Third Parties
Axios Attack Shows Social Complex Engineering Is Industrialized
MSSPs Are the New Target in Login-Based Attacks – Blackpoint Cyber | news | MSSP Alert
Trivy supply chain attack enabled European Commission cloud breach - Help Net Security
Snowflake customers hit in data theft attacks after SaaS integrator breach
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
MSSPs Caught in the Middle of Iran’s Cyber Escalation | perspective | MSSP Alert
Google: New UNC6783 hackers steal corporate Zendesk support tickets
Hims & Hers warns of data breach after Zendesk support ticket breach
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
The New Rules of Engagement: Matching Agentic Attack Speed - SecurityWeek
Cyber threat must be recognised despite geopolitical tensions
Iranian cyber activity hits US energy, water, and government networks - Help Net Security
The AI Revolution in Cyber Conflict | Lawfare
Act-of-War Clauses Cloud Cyber Insurance Coverage - DataBreaches.Net
Why modern cyber conflict is partly a global skills challenge | TechRadar
Microsoft hints at bit bunkers for war zones • The Register
Fiber Optic Cables Turned Into Hidden Microphones to Secretly Spy on Your Conversations
Nation State Actors
The New Rules of Engagement: Matching Agentic Attack Speed - SecurityWeek
Cyber threat must be recognised despite geopolitical tensions
China
FBI declares suspected Chinese hack of US surveillance system a ‘major cyber incident’ - POLITICO
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
Russia
Russian military hackers reroute British internet users’ traffic
FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users
Feds quash widespread Russia-backed espionage network spanning 18,000 devices | CyberScoop
Your router could be Russian spy — Ukraine and FBI just exposed how Moscow did it - Euromaidan Press
Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Russia's attempt to block VPNs is causing widespread banking outages | TechSpot
Major outage cripples Russian banking apps and metro payments nationwide
North Korea
Axios Attack Shows Social Complex Engineering Is Industrialized
How North Korean hackers turn legitimate infrastructure into an attack surface | TechFinitive
I knew about North Korean hackers—they still tricked me and got into my computer | Fortune
Attackers trojanize Axios HTTP library in highest-impact npm supply chain attack | CSO Online
Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK
North Korea–linked hackers drain $285M from Drift in sophisticated attack
Iran
Iranian cyber activity hits US energy, water, and government networks - Help Net Security
MSSPs Caught in the Middle of Iran’s Cyber Escalation | perspective | MSSP Alert
Pro-Iran Group Takes Credit for Cyberattacks on Chime, Pinterest
News brief: Iran cyberattacks escalate, U.S. targets named | TechTarget
Cyber Agency Issues First Iran Threat Amid Government Shutdown
Pro-Iran Handala group breached Israeli defence contractor PSK Wind Technologies
How Iranian hackers pose a threat to US critical infrastructure
Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure
Iran digital repression surged amid war and protests: rights group
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Cyber threat must be recognised despite geopolitical tensions
The Hack That Exposed Syria’s Sweeping Security Failures | WIRED
Hack-for-hire spyware campaign targets journalists in Middle East, North Africa | CyberScoop
Tools and Controls
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
Most Organizations Do Not Fully Trust Their Cybersecurity Vendors
Anthropic withholds Mythos Preview model because its hacking is too powerful
Better prepare for a cyber breach | Professional Security Magazine
Cybercriminals move deeper into networks, hiding in edge infrastructure - Help Net Security
The rise of proactive cyber: Why defense is no longer enough | CSO Online
‘Skipping a beat on resilience investment isn’t an option any more’ as IT outage costs soar | IT Pro
Social engineering attacks on open source developers are escalating - Help Net Security
Microsoft suspends dev accounts for high-profile open source projects
The Hidden Cost of Recurring Credential Incidents
Why DDoS Mitigation Fails: 5 Gaps That Testing Reveals - Security Boulevard
CISOs grapple with AI demands within flat budgets - Help Net Security
Why risk alone doesn't get you to yes - Help Net Security
How Security Leaders Can Safeguard Against Vibe Coding Security Risks - Infosecurity Magazine
Security Bosses Are All-In on AI, Here's Why
Proactive Threat Hunting - Security Boulevard
Russia's attempt to block VPNs is causing widespread banking outages | TechSpot
Act-of-War Clauses Cloud Cyber Insurance Coverage - DataBreaches.Net
Meaningful metrics demonstrate the value of cyber-resiliency | TechTarget
Other News
Cyberattacks On Law Firms Are Rising. Here’s What’s Driving It. - Above the Law
Threat Actors Get Crafty With Emojis to Escape Detection
Even cybersecurity experts make simple mistakes. Here's the real lesson | PCWorld
Most CNI Firms Face Up to £5m in Downtime from OT Attacks - Infosecurity Magazine
Click, wait, repeat: Digital trust erodes one login at a time - Help Net Security
Why Cybersecurity Is the First Step in Preparing Your Company for an IPO - Security Boulevard
Vulnerability Management
Anthropic withholds Mythos Preview model because its hacking is too powerful
‘BlueHammer’ Windows Exploit Signals Microsoft Disclosure Issues
AI Vulnerability Detection With Anthropic Glasswing - Futurum
Is Anthropic’s New Claude Model a Cybersecurity Disaster?
Why Microsoft is forcing Windows 11 25H2 update on all eligible PCs | ZDNET
Vulnerabilities
React2Shell Exploited in Large-Scale Credential Harvesting Campaign - SecurityWeek
OpenClaw gives users yet another reason to be freaked out about security - Ars Technica
Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploit - Infosecurity Magazine
Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers
New FortiClient EMS flaw exploited in attacks, emergency patch released
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
Hackers exploit critical flaw in Ninja Forms WordPress plugin
GPU Rowhammer Attack Enables Privilege Escalation - Infosecurity Magazine
Acrobat Reader zero-day exploited in the wild for many months - Help Net Security
Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities - SecurityWeek
New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In - Security Boulevard
OpenSSL 3.6.2 lands with eight CVE fixes - Help Net Security
Severe StrongBox Vulnerability Patched in Android - SecurityWeek
Flatpak 1.16.4 fixes sandbox escape and three other security flaws - Help Net Security
Critical Flowise Vulnerability in Attacker Crosshairs - SecurityWeek
Grafana Patches AI Bug That Could Have Leaked User Data
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users - SecurityWeek
13-year-old bug in ActiveMQ lets hackers remotely execute commands
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.
Black Arrow Cyber Advisory 10 April 2026 – Frontier AI and the Changing Cyber Threat Landscape
Black Arrow Cyber Advisory 10 April 2026 – Frontier AI and the Changing Cyber Threat Landscape
Executive summary
Anthropic’s new Mythos AI model and Project Glasswing initiative are an important moment for the cyber security of all organisations across the globe. Anthropic says the model has identified large numbers of serious software vulnerabilities and has chosen not to make the model generally available. Instead, access is being tightly controlled while selected organisations work to address weaknesses in critical software and infrastructure.
For most organisations, the main point is not Anthropic or the Mythos model itself. It is that AI is making advanced vulnerability discovery and exploit development exponentially faster and more broadly accessible. As those capabilities spread, firms should expect less time between a serious weakness being identified and attackers trying to use it, as well as a sharp increase in the number of zero-day vulnerabilities that require organisations to prioritise resilience and defence-in-depth.
This does not mean every business is suddenly facing a completely new threat overnight. It does require that organisations have good visibility of their exposure through internet-facing systems, fast patching, strong identity controls, and deeper oversight of key suppliers.
Black Arrow Cyber’s view is that this should be treated as an imminent warning. This is not a reason to panic. It is a reason to make sure the basics are strong and that your organisation can move quickly and effectively when a serious issue emerges.
What’s the risk to me or my business?
The biggest change here is speed. AI reduces the time and effort needed to find and validate vulnerabilities, so organisations may have less time to understand whether they are exposed and put protections in place before attacker’s act.
That risk is not limited to software you build yourself. It can sit in technology your business depends on every day, including operating systems, browsers, identity platforms, remote access tools, cloud services, open-source components, and third-party applications. In practice, this means cyber risk may increasingly come from shared dependencies that, until now, have been secure, as much as from your own internal environment.
It is also worth noting that attackers do not need entirely new types of weaknesses for this to matter. A more likely concern is that existing bugs, misconfigurations, weak access controls, and poorly managed dependencies become easier to find and combine in new ways. Organisations that already struggle with asset visibility, patching discipline, or privileged access management are likely to be the most exposed.
From a leadership perspective, this is not just a technical issue. It is a governance issue. The organisations that respond well will be the ones that know what assets they have, know what is exposed, know who owns important systems, and can make decisions quickly when a serious vulnerability affects the business.
What can I do?
Review patching timelines for your most important systems. Internet-facing services, identity platforms, remote access tools, and systems used to administer the environment should be treated as priorities. Where quick patching is not possible, there should be clear compensating controls and clear ownership.
Improve visibility of exposed assets and key dependencies. Most organisations still do not have a complete picture of internet-facing systems, inherited software dependencies, privileged accounts, and unmanaged or shadow technology. That becomes more dangerous if attackers can move faster.
Strengthen identity and privilege controls. Phishing-resistant multi-factor authentication, least privilege, admin segregation, and rapid removal of access all matter even more if a vulnerability can be exploited quickly.
Make sure there is a clear process for triaging and escalating serious vulnerabilities. This should include technical ownership, business decision-making, supplier engagement, and communications where needed. If a critical weakness emerges, the organisation should not be working this out for the first time under pressure.
Test and strengthen incident response resilience through regular exercises. Run scenario‑based exercises to validate roles, decision‑making, communications, and escalation under pressure. These exercises help identify gaps in preparedness, improve coordination between technical and leadership teams, and ensure the organisation can respond quickly and effectively when a serious incident occurs.
Questions leadership teams should be asking
Do we know which internet-facing and critical systems would create the most risk if a serious vulnerability were exploited quickly?
How quickly can we confirm whether we are affected by a newly disclosed high-severity issue?
Do we have clear visibility of key suppliers and software dependencies?
Are our identity and privileged access controls strong enough to limit damage if an attacker gets in?
Do we have a clear process for making decisions quickly when a serious software weakness affects the business?
Black Arrow Cyber’s assessment
Mythos and Project Glasswing should be viewed as a sign of where the threat landscape is heading rather than as a single vendor story. The main risk for most organisations is not one model on its own. It is the wider direction of travel: advanced AI capabilities are quickly becoming more accessible, making sophisticated cyber activity faster and cheaper.
The most effective response is operational discipline: know what you have, know what is exposed, reduce time to remediate, tighten identity controls, understand your key dependencies, and make sure the organisation can respond at speed when it matters.
Further details and references
Anthropic Project Glasswing announcement: https://www.anthropic.com/project/glasswing
Anthropic Mythos Preview research note: https://red.anthropic.com/2026/mythos-preview/
UK NCSC guidance on frontier AI and cyber defence: https://www.ncsc.gov.uk/blogs/why-cyber-defenders-need-to-be-ready-for-frontier-ai
Need help understanding your gaps, or just want some advice? Get in touch with us.
Black Arrow Cyber Advisory - 10 April 2026 - Microsoft device code phishing campaigns targeting Microsoft 365 users
Black Arrow Cyber Advisory - 10 April 2026 - Microsoft device code phishing campaigns targeting Microsoft 365 users
Executive summary
Microsoft and other researchers are reporting a sharp rise in device code phishing aimed at Microsoft 365 users. Public reporting says detected device code phishing pages are up nearly 40 percent this year, while Microsoft says it has seen 10 to 15 campaigns every 24 hours with hundreds of compromises daily since mid-March. We have been involved in helping organisations respond to these types of attacks. Device code authentication is enabled by default in Microsoft 365.
In these attacks, the victim is not usually sent to a fake Microsoft sign-in page designed to steal their password, as we have seen with other attacks of this type. Instead, they are tricked into entering a short code into Microsoft’s legitimate device login process, which authorises the attacker’s session. Once in, attackers have been seen reading mailboxes, creating malicious inbox rules, registering devices for persistence, and focusing on finance, executive, and administrative users.
For organisations that do not use device code authentication for a genuine business case, blocking the flow in Conditional Access is one of the clearest and most effective mitigations. Microsoft now explicitly recommends blocking device code flow wherever possible.
We have attached example screenshots from our own investigations showing what the landing page and follow-on Microsoft prompts may look like to an end user. It is important to note that, if a user is already signed in to Microsoft in their browser, they may not be asked to enter their credentials after submitting the code.
What is the risk to me or my business?
For most organisations, the immediate risk is an identity compromise inside Microsoft 365. A successful device code phish can give the attacker valid tokens, mailbox access, and a foothold for data theft, payment diversion, and ongoing surveillance of sensitive conversations. Attackers in the current campaigns have been observed creating inbox rules, using Microsoft Graph for reconnaissance, and targeting users with financial authority.
This is also easy for users to misread as genuine because the sign-in can happen through Microsoft’s real device login experience. That means ordinary “check the URL” advice is not enough on its own.
Technical Summary
Device code flow is a legitimate OAuth sign-in method designed for devices with limited input capability, such as smart TVs, printers, shared devices, and digital signage. In this abuse case, the attacker initiates the flow, sends the code to the victim in a lure, and relies on the victim completing the Microsoft sign-in on the attacker’s behalf. Once approved, the attacker can obtain tokens and access Microsoft 365 resources without needing the user’s password on a fake site.
What makes the current wave more effective is the level of automation and the visibility gap it creates for defenders. Microsoft says the campaigns are using AI-personalised lures, redirect chains on trusted cloud services, and dynamic code generation so the 15-minute validity window only starts when the victim reaches the final page. Detection is further complicated because the resulting activity can appear in Entra as non-interactive sign-in activity rather than a classic user-driven login, making it easier to blend into normal background authentication traffic and harder to spot quickly during routine sign-in review.
What types of organisations are most likely to be affected?
Any organisation using Microsoft 365 or Microsoft Entra ID is a potential target. Risk is highest where finance, payroll, procurement, executive support, or administrative users can be lured into approving access, and where device code flow remains enabled despite having no genuine operational requirement. Microsoft notes that device code flow is rarely used by most customers but is frequently used by attackers.
Organisations may also be more exposed where inbound email controls are weak against rare senders, new domains, or convincing external document-sharing lures. Microsoft has published detections for device code authentication occurring after a user clicks a link in an email from a non-prevalent sender.
What can I do?
1. Block device code flow where you do not need it
Create a Conditional Access policy for all users and all resources, set Authentication Flows to Device code flow, start in report-only mode, exclude emergency access accounts and documented exceptions, then move to block once you have confirmed there is no legitimate dependency. If you do need it for specific cases such as conference room devices or other shared devices, restrict it tightly rather than leaving it broadly available. Microsoft also offers a managed policy to help block device code flow.
2. Reset user expectations
Tell users never to enter a short Microsoft sign-in code unless they initiated the sign-in themselves from a known device or business process. Current lures include invoices, RFPs, shared documents, e-signature requests, and voicemail or secure message themes.
3. Tighten email controls
Review anti-phishing policies and Safe Links or equivalent controls. As an additional measure, where your email security tooling supports it, quarantine or heavily score inbound messages from newly registered or previously unseen domains, especially where they use external document-sharing, Adobe, Microsoft 365, DocuSign, or file-access themes.
4. Hunt for signs of compromise
Review Entra sign-in logs for device code authentication, unusual IP addresses, anonymous IP use, rare sender correlations, suspicious token use, and new device registrations. If you suspect compromise, revoke sign-in sessions, force reauthentication, review inbox rules, and check for unusual mailbox access or forwarding behaviour.
Further details and references
Microsoft Security Blog coverage and Microsoft mitigation guidance: https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/
Microsoft Learn guidance on Conditional Access authentication flow controls and blocking device code flow: https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
Recent public reporting on campaign scale and adoption: https://www.theregister.com/2026/04/07/microsoft_device_code_phishing/
Need help understanding your gaps, or just want some advice? Get in touch with us.
Black Arrow Cyber Threat Intelligence Briefing 03 April 2026
Black Arrow Cyber Threat Intelligence Briefing 03 April 2026:
-Iran Targets M365 Accounts with Password-Spraying Attacks
-Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations
-North Korea Hackers Suspected of Attack on Widely Used Software Tool
-Most Businesses Couldn’t Survive Three Days Downtime
-Cyber Security and Operational Resilience: A Board-Level Imperative
-95% of Organisations Don’t Trust Their Cyber Security Vendors
-3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)
-The Company’s Biggest Security Hole Lived In the Breakroom
-The Next Cyber Security Crisis Isn’t Breaches - It’s Data You Can’t Trust
-New Criminal Service Plans to Monetise Data Stolen by Ransomware Gangs
-Nearly Half a Million Mobile Customers of Lloyds Banking Group Affected by Security Incident
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
We have reviewed the specialist and general media over the past week to help raise the awareness of business leaders regarding evolving cyber security risks. We start with heightened activity by Iran-aligned attackers who use password-spraying to gain access to Microsoft 365 accounts, and use various techniques to deploy destructive malware. In separate news, North Korean attackers gained access to a widely used business software to establish long-term access to multiple organisations. We also highlight the need for business leaders to review their approach to removing legitimate tools that are not required by the organisation, and reducing the opportunity for attackers to misuse them.
Research on the impact of a cyber incident highlights that most businesses believe they could not survive more than three days of downtime, while other research finds that most organisations do not trust their cyber security vendors. This underlines the need for business leaders to upskill on cyber security, and to use that knowledge to ensure that their risks and controls are appropriately addressed. We recommend the upskilling should be through an impartial specialist source to reduce the risks of shared blind spots; contact us to find out how we support business leaders to be confident in governing their own security.
Top Cyber Stories of the Last Week
Iran Targets M365 Accounts with Password-Spraying Attacks
Check Point Research has identified a campaign of password spraying against Microsoft 365 accounts, affecting more than 300 organisations in Israel and more than 25 in the UAE, with activity also seen in the US, Europe and Saudi Arabia. Password spraying is a technique where attackers try common or weak passwords across many accounts to gain access. The activity came in three waves during March and focused heavily on infrastructure in cities recently hit by missile attacks, suggesting an effort to gather sensitive information linked to missile strike response and damage assessment.
https://www.theregister.com/2026/03/31/iran_password_spraying_m365/
Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations
Iran is increasingly blending state-backed operations with criminal tactics, using the revived Pay2Key ransomware group to target high impact US organisations. Researchers say some attacks are not true extortion attempts but destructive campaigns disguised as ransomware, making them harder to identify and respond to. Iran is also reportedly offering cyber criminals a larger share of profits, raising payouts from 70% to 80% for attacks aligned to its political aims. This mix of disruption, financial crime and political intent increases legal, financial and operational risk for organisations, particularly where sanctions exposure may be involved. Business leaders should, as part of their governance, ensure appropriate security controls are maintained to help prevent and detect such attacks.
https://www.darkreading.com/threat-intelligence/iran-pseudo-ransomware-pay2key-operations
North Korea Hackers Suspected of Attack on Widely Used Software Tool
Hackers linked to North Korea are suspected of compromising Axios, a widely used software package with tens of millions of weekly downloads. Google analysts said the breach could have far‑reaching implications because other popular packages rely on Axios, warning that hundreds of thousands of stolen secrets may now be circulating and could enable further ransomware, extortion and cryptocurrency‑theft operations. The attackers gained control of a maintainer account and published two backdoored versions of the package, prompting security firms to advise developers that systems using those versions should be considered compromised. The incident underlines how a compromise in a widely used software package can have broad, ripple‑effect consequences across many organisations.
https://techxplore.com/news/2026-04-north-korea-hackers-widely-software.html
Most Businesses Couldn’t Survive Three Days Downtime
Veeam reports that business resilience remains fragile, with 76% of organisations saying they could not survive more than three days of downtime. Although 47% expect a serious data breach or cyber attack, only 32% believe they are very likely to fully recover critical data and operations. Ransomware tops the list of feared threats at 67%, while 38% of boards have never formally discussed newer AI related risks such as data leaks or unsafe automation. The impact is not only financial, with 57% of leaders reporting burnout or resignations after major incidents.
https://betanews.com/article/most-businesses-couldnt-survive-three-days-downtime/
Cyber Security and Operational Resilience: A Board-Level Imperative
Cyber security and operational resilience are now core boardroom issues as attacks become more frequent, more disruptive and more costly. Since the pandemic, cyber attacks have more than doubled, and average losses from major incidents have risen fourfold since 2017 to $2.5 billion. In one recent case, a ransomware attack on a major healthcare payments provider caused nationwide disruption and more than $1.5 billion in costs. At the same time, tougher rules in the EU, UK and US are making boards more directly accountable for oversight, response planning, third party risk and accurate public reporting.
https://www.jdsupra.com/legalnews/cybersecurity-and-operational-2897791/
95% of Organisations Don’t Trust Their Cyber Security Vendors
Sophos reports a widespread trust gap in the cyber security market, with 95% of organisations saying they do not fully trust their cyber security vendors. The research also found that 79% struggle to judge the trustworthiness of new suppliers, while 62% find it difficult even with existing providers. This lack of confidence is having a business impact, with 51% reporting greater anxiety about the risk of a serious cyber incident. Independent checks, certifications and clear communication during incidents were identified as the strongest foundations for building trust.
https://betanews.com/article/95-percent-of-organizations-dont-trust-their-cybersecurity-vendors/
3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)
Attackers are increasingly avoiding malicious software and instead misusing the trusted tools already built into an organisation’s systems, making harmful activity much harder to spot. Analysis of more than 700,000 serious incidents found that 84% involved legitimate tools being used in this way. On a standard Windows 11 device, hundreds of built in tools may be available, with research suggesting up to 95% of access to higher risk tools is unnecessary. This leaves organisations exposed because security monitoring alone can struggle to separate normal administrative activity from an active cyber attack. Organisations should review their approach to hardening their systems, to reduce the opportunity for attackers to misuse legitimate tools that are not required by the organisation.
https://thehackernews.com/2026/04/3-reasons-attackers-are-using-your.html
The Company’s Biggest Security Hole Lived In the Breakroom
An apparently low risk connected coffee machine became the entry point for a serious data breach after being placed on a secure corporate network with its default password unchanged, outdated software and no basic protections. Investigators found the device was quietly sending data to attackers whenever it was used. The incident reflects a wider pattern, with researchers warning that internet connected devices are increasingly linked to breaches because they are often overlooked, poorly monitored and treated as harmless. A similar case at a North American casino led to 10GB of data being stolen through a connected fish tank.
https://www.theregister.com/2026/04/02/pwned/
The Next Cyber Security Crisis Isn’t Breaches - It’s Data You Can’t Trust
As organisations rely more heavily on data and AI to guide financial, operational and strategic decisions, the greater risk may be not stolen data, but data that is inaccurate, altered or no longer reliable. Even small changes can lead to flawed outcomes, while weak ownership, poor access controls and inconsistent handling of sensitive information can blur the line between trusted and compromised data. Stronger governance, clear accountability and better tracking of changes are becoming essential, not just for security teams but for leadership, as regulators and cyber insurers raise expectations.
https://www.securityweek.com/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/
New Criminal Service Plans to Monetise Data Stolen by Ransomware Gangs
A new criminal service is aiming to turn data stolen in ransomware incidents into a more valuable asset by organising large, unstructured datasets into searchable information for sale or extortion. This could increase pressure on organisations, support follow-on crimes such as fraud and business email compromise where attackers impersonate trusted contacts, and potentially enable direct blackmail of individuals. Experts say the model is not yet proven at scale, as cyber criminals still favour high-volume attacks that deliver quicker returns, but it signals continued innovation in the cyber crime economy.
https://therecord.media/new-criminal-service-plans-to-monetize-ransomware-data
Nearly Half a Million Mobile Customers of Lloyds Banking Group Affected by Security Incident
A software error at Lloyds Banking Group briefly exposed transaction details for up to 447,936 mobile banking customers across Lloyds, Halifax and Bank of Scotland. The issue lasted for less than five hours on 12 March and affected customers who viewed their transaction lists at almost exactly the same time. In some cases, exposed information included payment amounts, dates, references and National Insurance numbers. Lloyds said no unauthorised transactions were possible and no financial losses have been identified, although £139,000 has been paid to 3,625 customers for distress and inconvenience. The incident is a reminder that business leaders should ensure robust testing of software and also maintain strong incident‑response readiness to prevent and manage data exposure during faults.
Governance, Risk and Compliance
Cyberthreat level remains high – attacks becoming more targeted and complex
Most businesses couldn’t survive three days downtime - BetaNews
More Confident, More Tooled, More Breached: The Security Gap Isn’t Closing | news | MSSP Alert
Attackers Are Scaling. Defenders Are Still Missing the Basics | perspective | MSSP Alert
Meta Lawsuit Dismissal: WhatsApp Security Chief Not Done Fighting - Business Insider
Why silence is no longer a security strategy | TechRadar
Trust, friction, and ROI: A CISO's take on making security work for the business - Help Net Security
Threats
Ransomware, Extortion and Destructive Attacks
Iran-Linked Pay2Key Ransomware Group Re-Emerges - Infosecurity Magazine
TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM | Trend Micro (US)
Ransomware in 2025: Blending in is the strategy
Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
Ransomware and Destructive Attack Victims
European Commission Confirms Cloud Data Breach - Infosecurity Magazine
ShinyHunters claims the hack of the European Commission
Co-Op Chief Steps Down As Hack Leads To £125m Loss
St Anne's School in Southampton closed after cyber attack - BBC News
Qilin Ransomware allegedly breached chemical manufacturer giant Dow Inc
Marquis bank data breach exposes 672,000 in ransomware attack | Fox News
Ransomware group claims it stole data from Monmouth University | EdScoop
Hasbro cyberattack delays orders, weeks-long recovery | Cybernews
Phishing & Email Based Attacks
Dutch Police discloses security breach after phishing attack
New Wave of AiTM Phishing Targets TikTok for Business - Infosecurity Magazine
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
New EvilTokens service fuels Microsoft device code phishing attacks
How businesses can defend themselves against the rise of ‘phishing as a service’ | TechRadar
Cybercriminals Exploit Tax Season With New Phishing Tactics - Infosecurity Magazine
Other Social Engineering
New ClickFix Variant Uses Rundll32 and WebDAV to Evade PowerShell Detection
New EvilTokens service fuels Microsoft device code phishing attacks
Don't open that WhatsApp message, Microsoft warns • The Register
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
Another worrying macOS malware scheme has been discovered — here's how to stay safe | TechRadar
3 red flags that job posting is a scam - and how to verify safely | ZDNET
Invoice Fraud Costs UK Construction Sector Millions, NCA Warns - Infosecurity Magazine
AML/CFT/Money Laundering/Terrorist Financing/Sanctions
UK sanctions Xinbi marketplace linked to Asian scam centers
Artificial Intelligence
AI is the Top Cyber Priority for Defenders as Criminals Exploit it - Infosecurity Magazine
TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM | Trend Micro (US)
Breaking out: Can AI agents escape their sandboxes? - Help Net Security
Critical Flaw in Langflow AI Platform Under Attack
AI Shrinks Cyberattack Exploit Time From Years to Days
Security leaders say the next two years are going to be 'insane' | CyberScoop
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust - SecurityWeek
AI Cyberattacks Call for Company Preparation to Limit Fallout
Why 'Emerging Threats' Are Harder to Prioritize in the AI Era
The Real Risk of Vibecoding | Trend Micro (US)
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Shadow AI 'double agents' are outpacing security visibility | TechRadar
Mercor says it was 'one of thousands' hit in LiteLLM attack • The Register
Claude Code leak used to push infostealer malware on GitHub
MP victim of AI deepfake fails to get answers from Big Tech • The Register
Latest Anthropic Miscue Puts AI and Cyber Firms at Odds
Bots/Botnets
4 IoT botnets generated attack traffic exceeding 30Tbps - Mobile Europe
Reddit declares war on bad bot activity - Help Net Security
Careers, Roles, Skills, Working in Cyber and Information Security
The human cost of cybersecurity and what we should do about it | TechRadar
Meta Lawsuit Dismissal: WhatsApp Security Chief Not Done Fighting - Business Insider
Are hackers better off staying legal? The answer may surprise you | Cybernews
How to Grow Your Cybersecurity Skills, According to Experts | Security Magazine
How dyslexic thinking strengthens cyber security | BCS
Cloud/SaaS
European Commission Confirms Cloud Data Breach - Infosecurity Magazine
ShinyHunters claims the hack of the European Commission
Iran targets M365 accounts with password-spraying attacks • The Register
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
GitHub Used as Covert Channel in Multi-Stage Malware Campaign - Infosecurity Magazine
Maryland Man Charged Over $53m Uranium Finance Crypto Hack - Infosecurity Magazine
Cyber Crime, Organised Crime & Criminal Actors
Are hackers better off staying legal? The answer may surprise you | Cybernews
UK sanctions Xinbi marketplace linked to Asian scam centers
Russia arrests suspected owner of LeakBase cybercrime forum
Data Breaches/Leaks
48 Hours: The Window Between Infostealer Infection and Dark Web Sale - Security Boulevard
European Commission suffered a cyberattack - hackers stole data | УНН
Hackers steal EU Commission cloud data | Cybernews
Dutch Police discloses security breach after phishing attack
Lloyds IT Glitch Exposed Data of Nearly 500,000 Banking Customers - Infosecurity Magazine
Mercor says it was 'one of thousands' hit in LiteLLM attack • The Register
OkCupid settles claims it shared user photos with a facial recognition company | The Verge
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
Marquis bank data breach exposes 672,000 in ransomware attack | Fox News
Hightower Holding Data Breach Impacts 130,000 - SecurityWeek
Smith & Co Solicitors in Ipswich faces data breach | Ipswich Star
Ajax silenced hacker who found 2017 data breach| Cybernews
Healthcare tech firm CareCloud says hackers stole patient data
Ajax football club hack exposed fan data, enabled ticket hijack
Denial of Service/DoS/DDoS
4 IoT botnets generated attack traffic exceeding 30Tbps - Mobile Europe
Fraud, Scams and Financial Crime
Inside a Modern Fraud Attack: From Bot Signups to Account Takeovers
UK sanctions Xinbi marketplace linked to Asian scam centers
Financial groups lay out a plan to fight AI identity attacks - Help Net Security
ICO Fines UK Nuisance Call Scammers £100,000 - Infosecurity Magazine
3 red flags that job posting is a scam - and how to verify safely | ZDNET
Invoice Fraud Costs UK Construction Sector Millions, NCA Warns - Infosecurity Magazine
Identity and Access Management
Internet of Things – IoT
4 IoT botnets generated attack traffic exceeding 30Tbps - Mobile Europe
Vehicle Cybersecurity Threats Grow in Era of Connected Vehicles
Don’t count on government guidance after a smart home breach - Help Net Security
The company's biggest security hole lived in the breakroom • The Register
Your Streaming Device Could Be Spying For Hackers, According To The FBI
India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April
Law Enforcement Action and Take Downs
Alleged RedLine malware developer extradited to United States
Russia arrests suspected owner of LeakBase cybercrime forum
Linux and Open Source
How AI has suddenly become much more useful to open-source developers | ZDNET
Malware
48 Hours: The Window Between Infostealer Infection and Dark Web Sale - Security Boulevard
Fake Claude Code source downloads actually delivered malware • The Register
North Korean hackers compromise major software used by thousands of companies | NK News
Backdooring of JavaScript Library Axios Tied to North Korea
Hackers Hijack Axios npm Package to Spread RATs - Infosecurity Magazine
New Venom Stealer MaaS Platform Automates Continuous Data Theft - Infosecurity Magazine
GitHub Used as Covert Channel in Multi-Stage Malware Campaign - Infosecurity Magazine
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
New ClickFix Variant Uses Rundll32 and WebDAV to Evade PowerShell Detection
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
Malware Is Sleeping on the Blockchain, and It's Already Infected Dozens of Global Targets
The FBI Just Named 18 Popular Routers Targeted By A Massive Malware Operation
Phantom Project Bundles Infostealer, Crypter and RAT For Sale - Infosecurity Magazine
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
New 'Storm' Infostealer Remotely Decrypts Stolen Credentials - Infosecurity Magazine
vSphere and BRICKSTORM Malware: A Defender's Guide | Google Cloud Blog
Alleged RedLine malware developer extradited to United States
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
New CrystalRAT malware adds RAT, stealer and prankware features
Huge numbers of web stores are facing attack from this dangerous new malware | TechRadar
Mobile
Nearly half a Million mobile customers of Lloyds Banking Group affected by a security incident
FBI Warns of Data Security Risks From China-Made Mobile Apps - SecurityWeek
'NoVoice' Android malware on Google Play infected 2.3 million devices
Coruna iOS exploit framework linked to Triangulation attacks
Android Developer Verification Rollout Begins Ahead of September Enforcement
WhatsApp warns users of fake app used to distribute spyware | The Record from Recorded Future News
Passwords, Credential Stuffing & Brute Force Attacks
48 Hours: The Window Between Infostealer Infection and Dark Web Sale - Security Boulevard
Iran targets M365 accounts with password-spraying attacks • The Register
Regulations, Fines and Legislation
UK defining stronger energy cybersecurity rules after Poland attack – pv magazine International
ICO Fines UK Nuisance Call Scammers £100,000 - Infosecurity Magazine
FCC's Router Ban Quietly Places an Expiration Date on Home Internet Security | PCMag
US router ban is ‘industrial policy' not better infosec • The Register
If You Buy a New Router, It Might ‘Turn Into a Pumpkin’ Next Year - CNET
Former NSA chiefs worry American offensive edge in cybersecurity is slipping | CyberScoop
Home router ban is unserious political manoeuvring - Verdict
Social Media
New Wave of AiTM Phishing Targets TikTok for Business - Infosecurity Magazine
Meta Lawsuit Dismissal: WhatsApp Security Chief Not Done Fighting - Business Insider
Reddit declares war on bad bot activity - Help Net Security
Software Supply Chain
North Korean hackers compromise major software used by thousands of companies | NK News
North Korean Attackers Compromise Popular Web Tool | Silicon UK
The Hidden Blast Radius of the Axios Compromise - Socket
Hackers Hijack Axios npm Package to Spread RATs - Infosecurity Magazine
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
Supply Chain and Third Parties
The external pressures redefining cybersecurity risk | CSO Online
North Korean hackers compromise major software used by thousands of companies | NK News
Backdooring of JavaScript Library Axios Tied to North Korea
The Hidden Blast Radius of the Axios Compromise - Socket
Hackers Hijack Axios npm Package to Spread RATs - Infosecurity Magazine
Famous Telnyx Pypi Package compromised by TeamPCP - Security Boulevard
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
TeamPCP’s attack spree slows, but threat escalates with ransomware pivot - Help Net Security
TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM | Trend Micro (US)
Mercor says it was 'one of thousands' hit in LiteLLM attack • The Register
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Wartime Usage of Compromised IP Cameras Highlight Their Danger
Information sharing of cyber threats vital to national security - Defence Connect
Europe's Power Grid Faces Hybrid Warfare Threat
National Cyber Resilience Demands Unified Defense
'Cyber Power' Drives Modern Geopolitical Conflict
Iran's hackers are on the offensive against the US and Israel - Ars Technica
European-Chinese geopolitical issues drive renewed cyberespionage campaign | CyberScoop
Telecom Sleeper Cells: Nation-State Threats Below the Radar
How History Shapes Nation-State Cyber Conflict
Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains
Former NSA chiefs worry American offensive edge in cybersecurity is slipping | CyberScoop
The Perils of Privatized Cyberwarfare | Lawfare
Nation State Actors
Information sharing of cyber threats vital to national security - Defence Connect
China
FBI Warns of Data Security Risks From China-Made Mobile Apps - SecurityWeek
Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure - SecurityWeek
China-linked Red Menshen APT deploys stealthy BPFDoor implants in telecom networks
European-Chinese geopolitical issues drive renewed cyberespionage campaign | CyberScoop
FCC's Router Ban Quietly Places an Expiration Date on Home Internet Security | PCMag
NCSC warns of messaging app targeting public sector | UKAuthority
Telcos targeted by threat actor ‘sleeper cells’ – report | TelecomTV
Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains
If You Buy a New Router, It Might ‘Turn Into a Pumpkin’ Next Year - CNET
Home router ban is unserious political manoeuvring - Verdict
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April
Russia
NCSC warns of messaging app targeting public sector | UKAuthority
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
Russia targets VPNs used by millions in Putin’s latest internet crackdown | The Independent
Top EU officials’ Signal group chat shut down over hacking fears – POLITICO
Russia arrests suspected owner of LeakBase cybercrime forum
Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
North Korea
North Korean hackers compromise major software used by thousands of companies | NK News
Backdooring of JavaScript Library Axios Tied to North Korea
The Hidden Blast Radius of the Axios Compromise - Socket
Hackers Hijack Axios npm Package to Spread RATs - Infosecurity Magazine
Iran
Europe's Power Grid Faces Hybrid Warfare Threat
Iranian hackers, Handala, claim to compromise FBI Director Kash Patel’s personal data | CyberScoop
Iran-Linked Pay2Key Ransomware Group Re-Emerges - Infosecurity Magazine
Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations
NCSC warns of messaging app targeting public sector | UKAuthority
Wartime Usage of Compromised IP Cameras Highlight Their Danger
Iran's hackers are on the offensive against the US and Israel - Ars Technica
Iran targets M365 accounts with password-spraying attacks • The Register
FBI Confirms Kash Patel Email Hack as US Offers $10M Reward for Hackers - SecurityWeek
Iranian hackers breach FBI director's personal email, and post his CV and photos online
Hidden Battle…Iran Conflict Shows How Digital Fight is Ingrained in Warfare
Why U.S. Special Operations Forces Will Focus More On The Cyber Domain
Cyber Warfare 101: Bluff Don’t Tell - CEPA
Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence
Information sharing of cyber threats vital to national security - Defence Connect
The Perils of Privatized Cyberwarfare | Lawfare
A New Cyber Service is Not the Answer > The Cyber Defense Review > Article View
Former NSA chiefs worry American offensive edge in cybersecurity is slipping | CyberScoop
Why U.S. Special Operations Forces Will Focus More On The Cyber Domain
Tools and Controls
More Confident, More Tooled, More Breached: The Security Gap Isn’t Closing | news | MSSP Alert
95 percent of organizations don’t trust their cybersecurity vendors - BetaNews
Security boffins harvest bumper crop of API keys from web • The Register
The Forgotten Endpoint: Security Risks of Dormant Devices
Russia targets VPNs used by millions in Putin’s latest internet crackdown | The Independent
Security leaders say the next two years are going to be 'insane' | CyberScoop
The Real Risk of Vibecoding | Trend Micro (US)
DMARC Policies in the Age of AI-Driven Impersonation | Proofpoint US
AI agents are about to overtake cybersecurity - for better, or worse? - SiliconANGLE
This privacy-first chatbot is taking off - here's why and how to try it | ZDNET
Germany urges citizens to back up data on World Backup Day | Cybernews
Enterprises are all in on AI for security but budgets aren’t keeping pace - Verdict
How AI has suddenly become much more useful to open-source developers | ZDNET
Leak reveals Anthropic’s ‘Mythos,’ a powerful AI model aimed at cybersecurity use cases | CSO Online
Trust, friction, and ROI: A CISO's take on making security work for the business - Help Net Security
Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.
GPT Can’t Trace an Attack Chain. A Purpose-Built Cybersecurity LLM Can. - Security Boulevard
Free VPNs leak your data while claiming privacy
Malware detectors trained on one dataset often stumble on another - Help Net Security
Other News
3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)
Cyberthreat level remains high – attacks becoming more targeted and complex
Your router is about to stop getting security updates - here's what to do
Security precautions to consider while traveling through airports
Critical Infrastructure at Risk | Security Insider
The House Article | Government needs to take cyber security in our energy system seriously
Have telcos invested enough in security? | TelecomTV
UK manufacturers under cyber fire with 80% reporting attacks • The Register
Eight in 10 UK Manufacturers Hit by Cyber Incident in a Year - Infosecurity Magazine
Vulnerability Management
Security leaders say the next two years are going to be 'insane' | CyberScoop
EU wants to support bedrock cyber vulnerability program, top official says - Nextgov/FCW
Rethinking Vulnerability Management Strategies
Vulnerabilities
A critical Windows security fix puts legacy hardware on borrowed time – Computerworld
Windows is finally fixing a years-old security hole in April | PCWorld
New Windows 11 emergency update fixes preview update install issues
F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild - SecurityWeek
Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
Exploitation of Critical Fortinet FortiClient EMS Flaw Begins - SecurityWeek
Cisco Patches Critical and High-Severity Vulnerabilities - SecurityWeek
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
Rapid Exploitation of CVE-2026-21962 Hits Oracle WebLogic - Infosecurity Magazine
Urgent Alert: NetScaler bug CVE-2026-3055 probed by attackers could leak sensitive data
Critical Fortinet Forticlient EMS flaw now exploited in attacks
Fortinet hit by another exploited cybersecurity flaw | CSO Online
Google fixes fourth Chrome zero-day exploited in attacks in 2026
Critical Vulnerability in Claude Code Emerges Days After Source Leak - SecurityWeek
Critical Flaw in Langflow AI Platform Under Attack
BIND Updates Patch High-Severity Vulnerabilities - SecurityWeek
Apple issues urgent lock screen warnings for unpatched iPhones and iPads
Hackers Actively Exploiting Critical WebLogic RCE Vulnerabilities in Attacks
Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
CISA Flags Critical PTC Vulnerability That Had German Police Mobilized - SecurityWeek
TP-Link Patches High-Severity Router Vulnerabilities - SecurityWeek
TrueConf zero-day vulnerability exploited to target government networks - Help Net Security
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
OpenSSH 10.3 patches five security bugs and drops legacy rekeying support - Help Net Security
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
· Automotive
· Construction
· Critical National Infrastructure (CNI)
· Defence & Space
· Education & Academia
· Energy & Utilities
· Estate Agencies
· Financial Services
· FinTech
· Food & Agriculture
· Gaming & Gambling
· Government & Public Sector (including Law Enforcement)
· Health/Medical/Pharma
· Hotels & Hospitality
· Insurance
· Legal
· Manufacturing
· Maritime & Shipping
· Oil, Gas & Mining
· OT, ICS, IIoT, SCADA & Cyber-Physical Systems
· Retail & eCommerce
· Small and Medium Sized Businesses (SMBs)
· Startups
· Telecoms
· Third Sector & Charities
· Transport & Aviation
· Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.