Black Arrow Cyber Threat Intelligence Briefing 25 September 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

How insurers assess risk can offer a useful perspective for business leaders. This week, we look at insurers considering limits on cover as they work to understand and price agentic AI risks, while Travelers’ research places cyber threats ahead of economic and geopolitical concerns.

Examples of AI systems acting beyond intended boundaries highlight why organisations need to know what AI agents can access and do and verify that controls work in practice. At the same time, attackers are continuing to target employees as a way to access systems and information with deepfake calls and, as the Revolut incident shows, impersonating emails; these attacks reinforce the need for independent checks before releasing sensitive information or authorising high-risk requests. This underlines our approach: cyber security is not just IT; it is about people, operations and technology.

For business leaders, the growing and faster attacks make both cyber security and cyber resilience essential. For security, priorities include managing permissions and strengthening core protections. For resilience, the focus is on preparing the leadership team to quickly respond in a structured manner to a cyber incident, and rehearsing how critical operations would continue through disruption to systems, suppliers or infrastructure. As always, proportionality is key. Contact us to discuss how to achieve this.


Top Cyber Stories of the Last Week

Cyber Insurers Consider Limiting Coverage as Sector Scrambles to Price Agentic AI Risks

Cyber insurers are considering restricting some cover as they struggle to quantify the risks created by agentic AI, systems capable of taking actions autonomously. AI-enabled attacks are accelerating dramatically, with activity that previously took weeks potentially being completed in minutes, while attackers may be able to operate at ten times the previous pace. Insurers are now reviewing how AI should be defined and covered in policies. For organisations, the increased speed of attacks reinforces the importance of basic controls such as multi-factor authentication as part of a wider strategy.

https://www.cityam.com/cyber-insurers-consider-coverage-pullback-as-sector-scrambles-to-price-agentic-ai-risks/

Travelers Risk Index: Cyber Threats the Top Business Concern as AI Heightens Risk

In Travelers’ latest Risk Index, cyber threats ranked above economic and geopolitical concerns, with 58% of respondents expressing worry about cyber risk. While 89% of organisations now use AI in day-to-day operations, only 59% report having established arrangements for employees’ use of the technology. More than half are concerned about AI-related cyber incidents, including phishing and exploitation of system weaknesses. Cyber insurance uptake has risen to 70%. For business leaders, the report highlights that testing of incident response plans and cyberattack simulations should be a focus for improvement.

https://www.claimsjournal.com/news/national/2026/09/23/340321.htm

Amid Ongoing Rogue Incidents, Debate over AI Safety Gets Real

Growing evidence that advanced AI systems can behave in unexpected ways is intensifying concerns over how organisations control their use. During testing, AI models have bypassed restrictions, accessed the internet when they were expected to remain isolated, and searched for exposed credentials. The immediate business risk is less about AI becoming uncontrollable and more about poorly governed systems causing disruption, security incidents or unexpected costs. Google cited one case where an inadequately restricted AI agent generated $50,000 in charges and halted business transactions, highlighting the importance of monitoring what AI systems are actually doing.

https://www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real

Google's Gemini Goes Rogue, Hacks 3 Companies during Cyber Security Test - Here’s What Happened

Google’s Gemini AI breached the systems of three real companies during a controlled cyber security exercise after mistaking them for part of the test environment. In one case, it repeatedly guessed login credentials until it gained access, while in two others it found exposed credentials in a public online repository. The model stopped once it recognised the systems belonged to genuine organisations and Google said no harm was caused. The incident highlights the risk that increasingly autonomous AI systems may act beyond intended boundaries when testing or pursuing cyber security objectives.

https://www.benzinga.com/markets/tech/26/09/61883834/googles-gemini-goes-rogue-hacks-3-companies-during-cybersecurity-test-heres-what-happened

Four AI Agent Security Risks Organisations Can’t Afford to Ignore

AI agents are creating new cyber security risks as they move into everyday business use. Attackers can use AI to make phishing and other attacks faster, more convincing and more personalised, while AI systems themselves can be manipulated through malicious instructions or compromised data. Unapproved AI tools can also introduce significant risk if they gain access to sensitive systems and information without sufficient oversight. Organisations need to identify AI use across the business, restrict agents’ permissions to their assigned tasks and assess whether their defences can keep pace with automated attacks.

https://www.itsecurityguru.org/2026/09/18/four-ai-agent-security-risks-organisations-cant-afford-to-ignore/

The Latest Deepfake Numbers Give CISOs Plenty to Worry About

Criminals are using deepfake audio and video to impersonate people during calls. Gartner found that 41% of CISOs had experienced at least one social engineering incident involving a deepfake audio call in the past year, while 36% reported one involving video. The survey of 297 senior cyber security leaders also found 79% had faced phishing or business email compromise. As AI-generated voices and video become harder to distinguish from genuine communications, organisations may need stronger identity checks and independent verification for high-risk requests such as payments, account recovery and privileged access.

https://www.helpnetsecurity.com/2026/09/22/cisos-deepfake-incidents-social-engineering-survey/

Lessons Must Be Learnt from Cyberattack on Revolut, Experts Warn

Revolut has confirmed that an attacker impersonating an Italian government official persuaded staff to release sensitive information relating to a reported 650 customers. The data reportedly included identity documents, photographs, account statements and transaction histories, with some reports suggesting the attackers later sought a ransom. No Revolut systems were breached. Instead, the incident exploited trust in an apparently legitimate government email account, highlighting the risk of relying on email identity alone. Organisations should confirm sensitive data requests through a separate channel, authorise disclosure and cap the amount of information employees can provide.

https://www.thenationalnews.com/future/technology/2026/09/21/revolut-hack-data-breach-cyber/

CISOs Can No Longer Ignore the Nation-State Threat

Nation-state cyberattacks are becoming a more immediate business risk as AI helps attackers operate faster, more quietly and at greater scale. Organisations may be targeted because of their technology, customers, suppliers, contracts or infrastructure without realising they are strategically valuable. AI could also reduce the time between a newly discovered weakness and exploitation to seconds, making patching alone insufficient. Businesses therefore need to understand their exposure, strengthen core security controls and plan how critical operations would continue if systems, cloud services, suppliers or infrastructure were disrupted.

https://www.csoonline.com/article/4224629/ai-reshapes-the-nation-state-threat-landscape-for-cisos.html

The SMB Cyber Security Squeeze: AI Agents at Work, Old Attacks in Overdrive

AI is increasing cyber security pressure on smaller businesses in two directions: creating new routes into company systems while making established attacks faster and cheaper. ESET found 40% of surveyed small and mid-sized businesses had no AI policy, while analysis of almost 900,000 AI agent skills identified more than 25,000 as suspicious and over 3,000 as malicious. Established threats are also accelerating, with Microsoft reporting AI-automated phishing emails achieved a 54% click rate compared with 12% for conventional attempts. Small businesses need to limit AI agents’ permissions and retain human oversight where decisions are too complex or ambiguous for reliable automation.

https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/

DarkMe RAT Trades Zero-Days for Plain Phishing Emails

DarkMe malware, previously linked to attacks on financial traders and cryptocurrency users, is now being distributed through simple phishing emails rather than sophisticated exploits. Victims are tricked into downloading what appears to be an image but is actually a malicious program. Once installed, DarkMe checks for signs that the computer is genuinely used by a person, establishes persistence, profiles the system, steals information from cryptocurrency wallets and can capture screenshots. Huntress says the activity highlights a wider shift towards high-volume, low-effort attacks because basic phishing techniques continue to succeed.

https://www.helpnetsecurity.com/2026/09/23/darkme-rat-phishing-email-hits-corporate-targets/

Ransomware Attacks Reach Record High for 2026

Ransomware activity reached a new high for 2026 in August, with NCC Group recording 1,073 victims globally, up 12% from July. North America accounted for 44% of known attacks and Europe 26%, while industrial organisations were the most targeted sector at 31% of incidents. Some criminal groups are also increasingly stealing data and demanding payment without encrypting systems, widening the threat beyond traditional ransomware. NCC Group linked the continuing rise to factors including advances in AI and geopolitical instability, reinforcing the importance of incident response plans and tabletop exercises to identify and address weaknesses.

https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/

The UK Government Are Urging People to Stockpile Food, and There’s More Than One Reason Why

The UK Government are reportedly reviewing national emergency plans and preparing new public guidance on how households can cope with disruption caused by cyberattacks, hostile state activity and extreme weather. People are being encouraged to keep a small supply of essentials such as bottled water, tinned food and dried goods in case normal services or supply chains are interrupted. The advice reflects a wider focus on national resilience, recognising that a serious cyberattack could have consequences beyond IT systems, potentially disrupting access to everyday goods and essential services.

https://www.buzzfeed.com/bendzialdowski/uk-government-stockpile-food-what-to-buy

Only One in Ten UK Compliance and Security Professionals Are Confident They Could Meet New 24-Hour Cyber Breach Deadline, VinciWorks Poll Finds

UK organisations appear poorly prepared for the proposed Cyber Security and Resilience Bill, with only 10% of surveyed IT, compliance and security professionals confident they could meet new incident reporting deadlines of 24 and 72 hours. A further 38% believe they could comply but have never tested the process, while 26% are unsure. Under the Bill, serious failures could attract fines up to the higher of £17 million or 4% of worldwide turnover. Despite 68% expressing concern about severe disruption from cyberattacks, only a quarter of UK businesses currently have a formal incident response plan.

https://www.legalfutures.co.uk/associate-news/only-one-in-ten-uk-compliance-and-security-professionals-are-confident-they-could-meet-new-24-hour-cyber-breach-deadline-vinciworks-poll-finds



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware Attacks Reach Record High for 2026 - Infosecurity Magazine

UAWire - Ransomware suspect wanted by Germany advises Russian party leader

Early Scattered Spider member pleads guilty to cybercrime spree | CyberScoop

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Scammers impersonate cops, use arrest threats to extort victims - Help Net Security

Manufacturing Accounts for 22% of all Ransomware Victims - Infosecurity Magazine

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing - Infosecurity Magazine

When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain

Ryuk ransomware member sentenced to 24 months in prison

Ransomware and Destructive Attack Victims

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek

Co-operative reveals jobs being cut under turnaround as losses widen | The Standard

FBI Hack Exposed FBI’s Own Hacking Unit

RansomHouse picks a fight with Namibia's defense establishment

Academic publisher Elsevier hit by LAPSUS$ redirect attack

Phishing & Email Based Attacks

DarkMe RAT trades zero-days for plain phishing emails - Help Net Security

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek

Attackers Manipulate AI in Mass Disinformation, Phishing Campaign

A fake ChatGPT billing email is after your OpenAI password - Help Net Security

Revolut Customers Targeted with New Wave of Phishing Attacks - Infosecurity Magazine

Microsoft Disrupts EvilTokens Device Code Phishing Service

The next intellectual property thief may sound like your CEO - Help Net Security

Other Social Engineering

98% of fraudulent hires have company credentials by the time they’re caught - Help Net Security

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek

Fake parcel delivery messages steal your card and bank details | Malwarebytes

FBI: Fake cop and government impersonation scams cost victims $1.6B

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data | CyberScoop

The next intellectual property thief may sound like your CEO - Help Net Security

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

The latest deepfake numbers give CISOs plenty to worry about - Help Net Security

Food festivals across UK targeted by AI scam, BBC finds - BBC News

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code - Infosecurity Magazine

Ireland among five EU countries 'targeted' by Chinese text-scam group

2FA/MFA

MFA Won't Save You From OAuth Consent Abuse

Artificial Intelligence

Travelers Risk Index: Cyber Threats the Top Business Concern as AI Heightens Risk

Cyber insurers consider limiting coverage as sector scrambles to price agentic AI risks

AI agents can modify themselves without humans telling them to do so

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

EY Survey Finds Autonomous AI Implementation Outpaces Oversight

Four AI Agent Security Risks Organisations Can’t Afford to Ignore - IT Security Guru

Treasury chief says AI bosses, not their bots, will carry the can for criminal acts

Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real

Attackers Manipulate AI in Mass Disinformation, Phishing Campaign

Two in Five Organisations Hit by AI-Related Compliance Failures in Past Year, Research Finds - IT Security Guru

New Android malware uses AI to steal bank logins and PINs | Malwarebytes

Researchers escape OpenAI Codex sandbox to run commands on host

The Target Is No Longer the Model. It’s the Agent.

Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents

After OpenAI Cyberattack, UN Panel Warns Current Guardrails Are 'Unraveling' | Common Dreams

AI Agents Are Rewriting the Rules of Lateral Movement

Banks issue urgent warning using AI to shop online raises scam and fraud risks | The Independent

OpenAI agents ‘infiltrated Australian government website’

AI regulation: Heads of AI firms tell UN Security Council that it could be a risk to all humanity - The Economic Times

Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios - SecurityWeek

The next intellectual property thief may sound like your CEO - Help Net Security

The latest deepfake numbers give CISOs plenty to worry about - Help Net Security

A fake ChatGPT billing email is after your OpenAI password - Help Net Security

When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain

LLMs respond differently to harmful prompts when AI watermarking is used - Ars Technica

When AI goes rogue, its human overseers may be to blame

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

BragJack attacks hijack AI browser agents through malicious extensions

Somewhere in your traffic logs, a bot is doing more than looking - Help Net Security

Food festivals across UK targeted by AI scam, BBC finds - BBC News

LeakySensey proxy network hijacks over 87,000 IPs | Cybernews

Why AI Fluency Is Now an Imperative in Closing the Cyber Skills Gap - Infosecurity Magazine

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development - POLITICO

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Rogue AI Agents Put Trusted Access Under Scrutiny

Relays Are Masking Chinese Access to US Frontier AI Models

Blind panic signals something monstrous just unraveled in an AI lab - Raw Story

Nvidia boss says there is ‘0% chance’ AI destroys the world by 2030 | AI (artificial intelligence) | The Guardian

How AI is reshaping the cybersecurity talent pipeline

The AI hacking apocalypse is not inevitable | CyberScoop

Europe can regulate mad and bad AI. Now we must build the ability to make it safe - The Currency :The Currency

Bots/Botnets

Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods - Infosecurity Magazine

Somewhere in your traffic logs, a bot is doing more than looking - Help Net Security

Bots with good manners are better at fooling people on social media - Help Net Security

Nearly two-thirds of tested websites fail every bot test - Help Net Security

Careers, Roles, Skills, Working in Cyber and Information Security

Why AI Fluency Is Now an Imperative in Closing the Cyber Skills Gap - Infosecurity Magazine

How AI is reshaping the cybersecurity talent pipeline

Pentagon cyber chief: The demand far exceeds supply | CyberScoop

Cloud/SaaS

Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors | Police | The Guardian

NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data | CyberScoop

Cyber Crime, Organised Crime & Criminal Actors

Fake parcel delivery messages steal your card and bank details | Malwarebytes

FBI: Fake cop and government impersonation scams cost victims $1.6B

UK and Cambodia join forces to take down online scam networks - GOV.UK

Early Scattered Spider member pleads guilty to cybercrime spree | CyberScoop

Black Axe in South Africa: Six Nigerians Nigerians accused of romance scams to be extradited to the US - BBC News

Data Breaches/Leaks

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek

Hundreds of Leaked GitHub App Keys Still Authenticate - Infosecurity Magazine

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

London property manager breach may have exposed bank details and lockbox codes

Most WordPress pros still lack a breach recovery plan - Help Net Security

30,000-plus veterans affected by Baylor Genetics’ cybersecurity breach | FedScoop

Data Protection

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Data/Digital Sovereignty

Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors | Police | The Guardian

Denial of Service/DoS/DDoS

New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert

Europe’s technology backbone is becoming a cyber target - Help Net Security

Encryption

Legacy systems may not survive the impending quantum security problem | news | MSSP Alert

Fraud, Scams and Financial Crime

Fake parcel delivery messages steal your card and bank details | Malwarebytes

FBI: Fake cop and government impersonation scams cost victims $1.6B

UK and Cambodia join forces to take down online scam networks - GOV.UK

Bots with good manners are better at fooling people on social media - Help Net Security

Banks issue urgent warning using AI to shop online raises scam and fraud risks | The Independent

Black Axe in South Africa: Six Nigerians Nigerians accused of romance scams to be extradited to the US - BBC News

Food festivals across UK targeted by AI scam, BBC finds - BBC News

Ireland among five EU countries 'targeted' by Chinese text-scam group

Identity and Access Management

Hundreds of Leaked GitHub App Keys Still Authenticate - Infosecurity Magazine

How to Choose Between a Service Account vs User Account

Insider Risk and Insider Threats

98% of fraudulent hires have company credentials by the time they’re caught - Help Net Security

Insurance

Cyber insurers consider limiting coverage as sector scrambles to price agentic AI risks

Internet of Things – IoT

New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert

Cars are becoming deadly cyber weapons

A BYD Shark 6 Hack Shows the Risks of Connected Cars

LeakySensey proxy network hijacks over 87,000 IPs | Cybernews

Abandoned IoT apps keep sending sensitive data to broken servers - Help Net Security

Hackers find encryption keys stored on stolen Flock camera despite company's denials — group extracts more than 27,000 clips, 1.6 million images captured in a span of 21 days from the device | Tom's Hardware

Australia banned these Chinese CCTV cameras. Now they're turning up in EVs - ABC News

Amazon to launch Ring ‘neighbourhood watch’ app in UK amid US privacy fears | Amazon | The Guardian

Law Enforcement Action and Take Downs

Black Axe in South Africa: Six Nigerians Nigerians accused of romance scams to be extradited to the US - BBC News

Early Scattered Spider member pleads guilty to cybercrime spree | CyberScoop

Microsoft Disrupts EvilTokens Device Code Phishing Service

Ryuk ransomware member sentenced to 24 months in prison

UK and Cambodia join forces to take down online scam networks - GOV.UK

Linux and Open Source

New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

Critical Linux kernel vulnerability ZcopyReaper allows privilege escalation | brief | MSSP Alert

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Malware

DarkMe RAT trades zero-days for plain phishing emails - Help Net Security

Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions

New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data | CyberScoop

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

Brevo Supply-Chain Attack Infected Over 100,000 Websites

EDR Evasion Stack Helps Process Injection Slip Past Defenses

Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods - Infosecurity Magazine

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code - Infosecurity Magazine

Happy Birthday, Shai-Hulud | Socket

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybercriminals Hiding New Malware in Torrents for Popular Films

The world's most sophisticated malware attack is reportedly now freely available on GitHub

Misinformation, Disinformation and Propaganda

Attackers Manipulate AI in Mass Disinformation, Phishing Campaign

Russia says cyberattacks hit electronic voting system during parliamentary elections | Sweden Herald

Mobile

New Android malware uses AI to steal bank logins and PINs | Malwarebytes

I turned off 2G and my phone stopped being a security liability

New RemControl Android banking malware targets users in Europe and Canada

Abandoned IoT apps keep sending sensitive data to broken servers - Help Net Security

Apple’s ‘Mercenary Spyware’ Warning Text Is Real | HuffPost Life

Models, Frameworks and Standards

Only one in ten UK compliance and security professionals are confident they could meet new 24-hour cyber breach deadline, VinciWorks poll finds - Legal Futures

DORA Year Two: Can Your SOC Actually See the Attack?

European Commission publishes new guidelines on the Cyber Resilience Act | Osborne Clarke

Meta launches legal challenge against UK media regulator over Online Safety Act | Ofcom | The Guardian

Privacy, Surveillance

Revealed: how Russia uses mobile ‘super-app’ Max to spy on its citizens | Russia | The Guardian

Hackers find encryption keys stored on stolen Flock camera despite company's denials — group extracts more than 27,000 clips, 1.6 million images captured in a span of 21 days from the device | Tom's Hardware

Amazon to launch Ring ‘neighbourhood watch’ app in UK amid US privacy fears | Amazon | The Guardian

Regulations, Fines and Legislation

Only one in ten UK compliance and security professionals are confident they could meet new 24-hour cyber breach deadline, VinciWorks poll finds - Legal Futures

DORA Year Two: Can Your SOC Actually See the Attack?

European Commission publishes new guidelines on the Cyber Resilience Act | Osborne Clarke

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Hack-back programs could expose your security vendors | CSO Online

Google Fined €403 Million Over Location Data Practices

British regulator takes a hard look at Pornhub's Apple-powered age checks

Europe can regulate mad and bad AI. Now we must build the ability to make it safe - The Currency :The Currency

Shadow IT

Four AI Agent Security Risks Organisations Can’t Afford to Ignore - IT Security Guru

Social Media

Bots with good manners are better at fooling people on social media - Help Net Security

Meta launches legal challenge against UK media regulator over Online Safety Act | Ofcom | The Guardian

Software Supply Chain

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Happy Birthday, Shai-Hulud | Socket

Hundreds of Leaked GitHub App Keys Still Authenticate - Infosecurity Magazine

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Supply Chain and Third Parties

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek

Brevo Supply-Chain Attack Infected Over 100,000 Websites


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

Russian hybrid threat against Europe is intensifying, Macron warns – The Irish News

UK Government Urges Food Stockpiling: Here's Why And What To Buy

From subsea cables to underwater drones: The race to secure the ocean floor

Revealed: how Russia uses mobile ‘super-app’ Max to spy on its citizens | Russia | The Guardian

AI Hallucination Nearly Triggered a US-China Military Confrontation

America's cyber strategy overlooks the infrastructure that actually keeps the military moving | CyberScoop

Nation State Actors

CISOs can no longer ignore the nation-state threat | CSO Online

China

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects | CyberScoop

From subsea cables to underwater drones: The race to secure the ocean floor

Relays Are Masking Chinese Access to US Frontier AI Models

The U.S. Is Highly Vulnerable to Cyber Threats From China. Here’s What It Should Do | Council on Foreign Relations

AI Hallucination Nearly Triggered a US-China Military Confrontation

Australia banned these Chinese CCTV cameras. Now they're turning up in EVs - ABC News

Ireland among five EU countries 'targeted' by Chinese text-scam group

Foreign interference fears over cyberattacks on academic blogs

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers - SecurityWeek

America Has The Brain, China Has The Body: The Next US–China Tech War - Analysis - Eurasia Review

A BYD Shark 6 Hack Shows the Risks of Connected Cars

Russia

Russian hybrid threat against Europe is intensifying, Macron warns – The Irish News

UK Government Urges Food Stockpiling: Here's Why And What To Buy

Revealed: how Russia uses mobile ‘super-app’ Max to spy on its citizens | Russia | The Guardian

UAWire - Ransomware suspect wanted by Germany advises Russian party leader

Foreign interference fears over cyberattacks on academic blogs

Russia's internet shutdowns disrupt warnings about incoming drone attacks | The Record from Recorded Future News

Russia says cyberattacks hit electronic voting system during parliamentary elections | Sweden Herald

North Korea

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data | CyberScoop

From subsea cables to underwater drones: The race to secure the ocean floor

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

Iran

America's cyber strategy overlooks the infrastructure that actually keeps the military moving | CyberScoop

Third tanker reports suspected cyberattack, US monitors 20 ships | Cybernews




Vulnerability Management

DarkMe RAT trades zero-days for plain phishing emails - Help Net Security

CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening | WIRED

Anthropic-linked CVEs pile up, attackers mostly shrug

NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine

Abandoned IoT apps keep sending sensitive data to broken servers - Help Net Security

CISA outlines improvement plan for CVE program | CyberScoop

We’ve spent billions defending software. It’s time to protect execution

Ubuntu kernel CVE fixes are moving to a weekly release schedule - Help Net Security

Vulnerabilities

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects | CyberScoop

New Windows Defender zero-day blocks Microsoft antivirus updates

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products - SecurityWeek

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cisco Zero-Day Highlights API Endpoint Authentication Issues

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

Windows 11 Update Can Break Active Directory Trust Relationships

Microsoft: September Windows updates break Always On VPN connections

Chrome 154 Patches 108 Vulnerabilities - SecurityWeek

Hackers start exploiting critical WordPress flaw for code execution

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

CISA: Ransomware gangs now exploiting critical TeamCity flaw

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted - SecurityWeek

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Decades-old file security flaws found in Android, Linux, macOS, and Windows

Adobe Patches Critical Flaws in Connect, AEM Forms - SecurityWeek

Microsoft fixes bug that broke Windows File History backup feature

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

Critical Linux kernel vulnerability ZcopyReaper allows privilege escalation | brief | MSSP Alert

Hackers now exploit critical Roundcube flaw in code injection attacks

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

WordPress Click2Shell flaw lets hackers execute PHP on the server

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

Google Pixel phones pwned in zero-click attacks

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

D-Link warns of max severity zero-day bug in DIR-822A routers

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection - Help Net Security


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 18 September 2026