Black Arrow Cyber Threat Intelligence Briefing 25 September 2026
Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.
Executive Summary
How insurers assess risk can offer a useful perspective for business leaders. This week, we look at insurers considering limits on cover as they work to understand and price agentic AI risks, while Travelers’ research places cyber threats ahead of economic and geopolitical concerns.
Examples of AI systems acting beyond intended boundaries highlight why organisations need to know what AI agents can access and do and verify that controls work in practice. At the same time, attackers are continuing to target employees as a way to access systems and information with deepfake calls and, as the Revolut incident shows, impersonating emails; these attacks reinforce the need for independent checks before releasing sensitive information or authorising high-risk requests. This underlines our approach: cyber security is not just IT; it is about people, operations and technology.
For business leaders, the growing and faster attacks make both cyber security and cyber resilience essential. For security, priorities include managing permissions and strengthening core protections. For resilience, the focus is on preparing the leadership team to quickly respond in a structured manner to a cyber incident, and rehearsing how critical operations would continue through disruption to systems, suppliers or infrastructure. As always, proportionality is key. Contact us to discuss how to achieve this.
Top Cyber Stories of the Last Week
Cyber Insurers Consider Limiting Coverage as Sector Scrambles to Price Agentic AI Risks
Cyber insurers are considering restricting some cover as they struggle to quantify the risks created by agentic AI, systems capable of taking actions autonomously. AI-enabled attacks are accelerating dramatically, with activity that previously took weeks potentially being completed in minutes, while attackers may be able to operate at ten times the previous pace. Insurers are now reviewing how AI should be defined and covered in policies. For organisations, the increased speed of attacks reinforces the importance of basic controls such as multi-factor authentication as part of a wider strategy.
Travelers Risk Index: Cyber Threats the Top Business Concern as AI Heightens Risk
In Travelers’ latest Risk Index, cyber threats ranked above economic and geopolitical concerns, with 58% of respondents expressing worry about cyber risk. While 89% of organisations now use AI in day-to-day operations, only 59% report having established arrangements for employees’ use of the technology. More than half are concerned about AI-related cyber incidents, including phishing and exploitation of system weaknesses. Cyber insurance uptake has risen to 70%. For business leaders, the report highlights that testing of incident response plans and cyberattack simulations should be a focus for improvement.
https://www.claimsjournal.com/news/national/2026/09/23/340321.htm
Amid Ongoing Rogue Incidents, Debate over AI Safety Gets Real
Growing evidence that advanced AI systems can behave in unexpected ways is intensifying concerns over how organisations control their use. During testing, AI models have bypassed restrictions, accessed the internet when they were expected to remain isolated, and searched for exposed credentials. The immediate business risk is less about AI becoming uncontrollable and more about poorly governed systems causing disruption, security incidents or unexpected costs. Google cited one case where an inadequately restricted AI agent generated $50,000 in charges and halted business transactions, highlighting the importance of monitoring what AI systems are actually doing.
https://www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real
Google's Gemini Goes Rogue, Hacks 3 Companies during Cyber Security Test - Here’s What Happened
Google’s Gemini AI breached the systems of three real companies during a controlled cyber security exercise after mistaking them for part of the test environment. In one case, it repeatedly guessed login credentials until it gained access, while in two others it found exposed credentials in a public online repository. The model stopped once it recognised the systems belonged to genuine organisations and Google said no harm was caused. The incident highlights the risk that increasingly autonomous AI systems may act beyond intended boundaries when testing or pursuing cyber security objectives.
Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are creating new cyber security risks as they move into everyday business use. Attackers can use AI to make phishing and other attacks faster, more convincing and more personalised, while AI systems themselves can be manipulated through malicious instructions or compromised data. Unapproved AI tools can also introduce significant risk if they gain access to sensitive systems and information without sufficient oversight. Organisations need to identify AI use across the business, restrict agents’ permissions to their assigned tasks and assess whether their defences can keep pace with automated attacks.
The Latest Deepfake Numbers Give CISOs Plenty to Worry About
Criminals are using deepfake audio and video to impersonate people during calls. Gartner found that 41% of CISOs had experienced at least one social engineering incident involving a deepfake audio call in the past year, while 36% reported one involving video. The survey of 297 senior cyber security leaders also found 79% had faced phishing or business email compromise. As AI-generated voices and video become harder to distinguish from genuine communications, organisations may need stronger identity checks and independent verification for high-risk requests such as payments, account recovery and privileged access.
https://www.helpnetsecurity.com/2026/09/22/cisos-deepfake-incidents-social-engineering-survey/
Lessons Must Be Learnt from Cyberattack on Revolut, Experts Warn
Revolut has confirmed that an attacker impersonating an Italian government official persuaded staff to release sensitive information relating to a reported 650 customers. The data reportedly included identity documents, photographs, account statements and transaction histories, with some reports suggesting the attackers later sought a ransom. No Revolut systems were breached. Instead, the incident exploited trust in an apparently legitimate government email account, highlighting the risk of relying on email identity alone. Organisations should confirm sensitive data requests through a separate channel, authorise disclosure and cap the amount of information employees can provide.
https://www.thenationalnews.com/future/technology/2026/09/21/revolut-hack-data-breach-cyber/
CISOs Can No Longer Ignore the Nation-State Threat
Nation-state cyberattacks are becoming a more immediate business risk as AI helps attackers operate faster, more quietly and at greater scale. Organisations may be targeted because of their technology, customers, suppliers, contracts or infrastructure without realising they are strategically valuable. AI could also reduce the time between a newly discovered weakness and exploitation to seconds, making patching alone insufficient. Businesses therefore need to understand their exposure, strengthen core security controls and plan how critical operations would continue if systems, cloud services, suppliers or infrastructure were disrupted.
The SMB Cyber Security Squeeze: AI Agents at Work, Old Attacks in Overdrive
AI is increasing cyber security pressure on smaller businesses in two directions: creating new routes into company systems while making established attacks faster and cheaper. ESET found 40% of surveyed small and mid-sized businesses had no AI policy, while analysis of almost 900,000 AI agent skills identified more than 25,000 as suspicious and over 3,000 as malicious. Established threats are also accelerating, with Microsoft reporting AI-automated phishing emails achieved a 54% click rate compared with 12% for conventional attempts. Small businesses need to limit AI agents’ permissions and retain human oversight where decisions are too complex or ambiguous for reliable automation.
DarkMe RAT Trades Zero-Days for Plain Phishing Emails
DarkMe malware, previously linked to attacks on financial traders and cryptocurrency users, is now being distributed through simple phishing emails rather than sophisticated exploits. Victims are tricked into downloading what appears to be an image but is actually a malicious program. Once installed, DarkMe checks for signs that the computer is genuinely used by a person, establishes persistence, profiles the system, steals information from cryptocurrency wallets and can capture screenshots. Huntress says the activity highlights a wider shift towards high-volume, low-effort attacks because basic phishing techniques continue to succeed.
https://www.helpnetsecurity.com/2026/09/23/darkme-rat-phishing-email-hits-corporate-targets/
Ransomware Attacks Reach Record High for 2026
Ransomware activity reached a new high for 2026 in August, with NCC Group recording 1,073 victims globally, up 12% from July. North America accounted for 44% of known attacks and Europe 26%, while industrial organisations were the most targeted sector at 31% of incidents. Some criminal groups are also increasingly stealing data and demanding payment without encrypting systems, widening the threat beyond traditional ransomware. NCC Group linked the continuing rise to factors including advances in AI and geopolitical instability, reinforcing the importance of incident response plans and tabletop exercises to identify and address weaknesses.
https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/
The UK Government Are Urging People to Stockpile Food, and There’s More Than One Reason Why
The UK Government are reportedly reviewing national emergency plans and preparing new public guidance on how households can cope with disruption caused by cyberattacks, hostile state activity and extreme weather. People are being encouraged to keep a small supply of essentials such as bottled water, tinned food and dried goods in case normal services or supply chains are interrupted. The advice reflects a wider focus on national resilience, recognising that a serious cyberattack could have consequences beyond IT systems, potentially disrupting access to everyday goods and essential services.
https://www.buzzfeed.com/bendzialdowski/uk-government-stockpile-food-what-to-buy
Only One in Ten UK Compliance and Security Professionals Are Confident They Could Meet New 24-Hour Cyber Breach Deadline, VinciWorks Poll Finds
UK organisations appear poorly prepared for the proposed Cyber Security and Resilience Bill, with only 10% of surveyed IT, compliance and security professionals confident they could meet new incident reporting deadlines of 24 and 72 hours. A further 38% believe they could comply but have never tested the process, while 26% are unsure. Under the Bill, serious failures could attract fines up to the higher of £17 million or 4% of worldwide turnover. Despite 68% expressing concern about severe disruption from cyberattacks, only a quarter of UK businesses currently have a formal incident response plan.
Governance, Risk and Compliance
Travelers Risk Index: Cyber Threats the Top Business Concern as AI Heightens Risk
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
Cyber insurers consider limiting coverage as sector scrambles to price agentic AI risks
CISOs can no longer ignore the nation-state threat | CSO Online
How the CISO-CMO Alliance Builds Trust Before Crisis Strikes
Threats
Ransomware, Extortion and Destructive Attacks
Ransomware Attacks Reach Record High for 2026 - Infosecurity Magazine
UAWire - Ransomware suspect wanted by Germany advises Russian party leader
Early Scattered Spider member pleads guilty to cybercrime spree | CyberScoop
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Scammers impersonate cops, use arrest threats to extort victims - Help Net Security
Manufacturing Accounts for 22% of all Ransomware Victims - Infosecurity Magazine
When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain
Ryuk ransomware member sentenced to 24 months in prison
Ransomware and Destructive Attack Victims
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek
Co-operative reveals jobs being cut under turnaround as losses widen | The Standard
FBI Hack Exposed FBI’s Own Hacking Unit
RansomHouse picks a fight with Namibia's defense establishment
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Phishing & Email Based Attacks
DarkMe RAT trades zero-days for plain phishing emails - Help Net Security
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek
Attackers Manipulate AI in Mass Disinformation, Phishing Campaign
A fake ChatGPT billing email is after your OpenAI password - Help Net Security
Revolut Customers Targeted with New Wave of Phishing Attacks - Infosecurity Magazine
Microsoft Disrupts EvilTokens Device Code Phishing Service
The next intellectual property thief may sound like your CEO - Help Net Security
Other Social Engineering
98% of fraudulent hires have company credentials by the time they’re caught - Help Net Security
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek
Fake parcel delivery messages steal your card and bank details | Malwarebytes
FBI: Fake cop and government impersonation scams cost victims $1.6B
The next intellectual property thief may sound like your CEO - Help Net Security
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The latest deepfake numbers give CISOs plenty to worry about - Help Net Security
Food festivals across UK targeted by AI scam, BBC finds - BBC News
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code - Infosecurity Magazine
Ireland among five EU countries 'targeted' by Chinese text-scam group
2FA/MFA
MFA Won't Save You From OAuth Consent Abuse
Artificial Intelligence
Travelers Risk Index: Cyber Threats the Top Business Concern as AI Heightens Risk
Cyber insurers consider limiting coverage as sector scrambles to price agentic AI risks
AI agents can modify themselves without humans telling them to do so
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
Four AI Agent Security Risks Organisations Can’t Afford to Ignore - IT Security Guru
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
Attackers Manipulate AI in Mass Disinformation, Phishing Campaign
New Android malware uses AI to steal bank logins and PINs | Malwarebytes
Researchers escape OpenAI Codex sandbox to run commands on host
The Target Is No Longer the Model. It’s the Agent.
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
After OpenAI Cyberattack, UN Panel Warns Current Guardrails Are 'Unraveling' | Common Dreams
AI Agents Are Rewriting the Rules of Lateral Movement
Banks issue urgent warning using AI to shop online raises scam and fraud risks | The Independent
OpenAI agents ‘infiltrated Australian government website’
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios - SecurityWeek
The next intellectual property thief may sound like your CEO - Help Net Security
The latest deepfake numbers give CISOs plenty to worry about - Help Net Security
A fake ChatGPT billing email is after your OpenAI password - Help Net Security
When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain
LLMs respond differently to harmful prompts when AI watermarking is used - Ars Technica
When AI goes rogue, its human overseers may be to blame
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
BragJack attacks hijack AI browser agents through malicious extensions
Somewhere in your traffic logs, a bot is doing more than looking - Help Net Security
Food festivals across UK targeted by AI scam, BBC finds - BBC News
LeakySensey proxy network hijacks over 87,000 IPs | Cybernews
Why AI Fluency Is Now an Imperative in Closing the Cyber Skills Gap - Infosecurity Magazine
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development - POLITICO
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Rogue AI Agents Put Trusted Access Under Scrutiny
Relays Are Masking Chinese Access to US Frontier AI Models
Blind panic signals something monstrous just unraveled in an AI lab - Raw Story
How AI is reshaping the cybersecurity talent pipeline
The AI hacking apocalypse is not inevitable | CyberScoop
Bots/Botnets
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods - Infosecurity Magazine
Somewhere in your traffic logs, a bot is doing more than looking - Help Net Security
Bots with good manners are better at fooling people on social media - Help Net Security
Nearly two-thirds of tested websites fail every bot test - Help Net Security
Careers, Roles, Skills, Working in Cyber and Information Security
Why AI Fluency Is Now an Imperative in Closing the Cyber Skills Gap - Infosecurity Magazine
How AI is reshaping the cybersecurity talent pipeline
Pentagon cyber chief: The demand far exceeds supply | CyberScoop
Cloud/SaaS
NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain
Cyber Crime, Organised Crime & Criminal Actors
Fake parcel delivery messages steal your card and bank details | Malwarebytes
FBI: Fake cop and government impersonation scams cost victims $1.6B
UK and Cambodia join forces to take down online scam networks - GOV.UK
Early Scattered Spider member pleads guilty to cybercrime spree | CyberScoop
Data Breaches/Leaks
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek
Hundreds of Leaked GitHub App Keys Still Authenticate - Infosecurity Magazine
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
London property manager breach may have exposed bank details and lockbox codes
Most WordPress pros still lack a breach recovery plan - Help Net Security
30,000-plus veterans affected by Baylor Genetics’ cybersecurity breach | FedScoop
Data Protection
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Data/Digital Sovereignty
Denial of Service/DoS/DDoS
New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert
Europe’s technology backbone is becoming a cyber target - Help Net Security
Encryption
Legacy systems may not survive the impending quantum security problem | news | MSSP Alert
Fraud, Scams and Financial Crime
Fake parcel delivery messages steal your card and bank details | Malwarebytes
FBI: Fake cop and government impersonation scams cost victims $1.6B
UK and Cambodia join forces to take down online scam networks - GOV.UK
Bots with good manners are better at fooling people on social media - Help Net Security
Banks issue urgent warning using AI to shop online raises scam and fraud risks | The Independent
Food festivals across UK targeted by AI scam, BBC finds - BBC News
Ireland among five EU countries 'targeted' by Chinese text-scam group
Identity and Access Management
Hundreds of Leaked GitHub App Keys Still Authenticate - Infosecurity Magazine
How to Choose Between a Service Account vs User Account
Insider Risk and Insider Threats
98% of fraudulent hires have company credentials by the time they’re caught - Help Net Security
Insurance
Cyber insurers consider limiting coverage as sector scrambles to price agentic AI risks
Internet of Things – IoT
New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert
Cars are becoming deadly cyber weapons
A BYD Shark 6 Hack Shows the Risks of Connected Cars
LeakySensey proxy network hijacks over 87,000 IPs | Cybernews
Abandoned IoT apps keep sending sensitive data to broken servers - Help Net Security
Australia banned these Chinese CCTV cameras. Now they're turning up in EVs - ABC News
Amazon to launch Ring ‘neighbourhood watch’ app in UK amid US privacy fears | Amazon | The Guardian
Law Enforcement Action and Take Downs
Early Scattered Spider member pleads guilty to cybercrime spree | CyberScoop
Microsoft Disrupts EvilTokens Device Code Phishing Service
Ryuk ransomware member sentenced to 24 months in prison
UK and Cambodia join forces to take down online scam networks - GOV.UK
Linux and Open Source
New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Critical Linux kernel vulnerability ZcopyReaper allows privilege escalation | brief | MSSP Alert
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
Malware
DarkMe RAT trades zero-days for plain phishing emails - Help Net Security
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
New KATARU malware targets Linux IoT devices for DDoS attacks | brief | MSSP Alert
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
Brevo Supply-Chain Attack Infected Over 100,000 Websites
EDR Evasion Stack Helps Process Injection Slip Past Defenses
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods - Infosecurity Magazine
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code - Infosecurity Magazine
Happy Birthday, Shai-Hulud | Socket
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybercriminals Hiding New Malware in Torrents for Popular Films
The world's most sophisticated malware attack is reportedly now freely available on GitHub
Misinformation, Disinformation and Propaganda
Attackers Manipulate AI in Mass Disinformation, Phishing Campaign
Russia says cyberattacks hit electronic voting system during parliamentary elections | Sweden Herald
Mobile
New Android malware uses AI to steal bank logins and PINs | Malwarebytes
I turned off 2G and my phone stopped being a security liability
New RemControl Android banking malware targets users in Europe and Canada
Abandoned IoT apps keep sending sensitive data to broken servers - Help Net Security
Apple’s ‘Mercenary Spyware’ Warning Text Is Real | HuffPost Life
Models, Frameworks and Standards
DORA Year Two: Can Your SOC Actually See the Attack?
European Commission publishes new guidelines on the Cyber Resilience Act | Osborne Clarke
Privacy, Surveillance
Revealed: how Russia uses mobile ‘super-app’ Max to spy on its citizens | Russia | The Guardian
Amazon to launch Ring ‘neighbourhood watch’ app in UK amid US privacy fears | Amazon | The Guardian
Regulations, Fines and Legislation
DORA Year Two: Can Your SOC Actually See the Attack?
European Commission publishes new guidelines on the Cyber Resilience Act | Osborne Clarke
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Hack-back programs could expose your security vendors | CSO Online
Google Fined €403 Million Over Location Data Practices
British regulator takes a hard look at Pornhub's Apple-powered age checks
Shadow IT
Four AI Agent Security Risks Organisations Can’t Afford to Ignore - IT Security Guru
Social Media
Bots with good manners are better at fooling people on social media - Help Net Security
Software Supply Chain
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Happy Birthday, Shai-Hulud | Socket
Hundreds of Leaked GitHub App Keys Still Authenticate - Infosecurity Magazine
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Supply Chain and Third Parties
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom - SecurityWeek
Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity
Cyber Warfare and Cyber Espionage
Russian hybrid threat against Europe is intensifying, Macron warns – The Irish News
UK Government Urges Food Stockpiling: Here's Why And What To Buy
From subsea cables to underwater drones: The race to secure the ocean floor
Revealed: how Russia uses mobile ‘super-app’ Max to spy on its citizens | Russia | The Guardian
AI Hallucination Nearly Triggered a US-China Military Confrontation
Nation State Actors
CISOs can no longer ignore the nation-state threat | CSO Online
China
From subsea cables to underwater drones: The race to secure the ocean floor
Relays Are Masking Chinese Access to US Frontier AI Models
AI Hallucination Nearly Triggered a US-China Military Confrontation
Australia banned these Chinese CCTV cameras. Now they're turning up in EVs - ABC News
Ireland among five EU countries 'targeted' by Chinese text-scam group
Foreign interference fears over cyberattacks on academic blogs
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers - SecurityWeek
America Has The Brain, China Has The Body: The Next US–China Tech War - Analysis - Eurasia Review
A BYD Shark 6 Hack Shows the Risks of Connected Cars
Russia
Russian hybrid threat against Europe is intensifying, Macron warns – The Irish News
UK Government Urges Food Stockpiling: Here's Why And What To Buy
Revealed: how Russia uses mobile ‘super-app’ Max to spy on its citizens | Russia | The Guardian
UAWire - Ransomware suspect wanted by Germany advises Russian party leader
Foreign interference fears over cyberattacks on academic blogs
Russia says cyberattacks hit electronic voting system during parliamentary elections | Sweden Herald
North Korea
From subsea cables to underwater drones: The race to secure the ocean floor
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Iran
Third tanker reports suspected cyberattack, US monitors 20 ships | Cybernews
Tools and Controls
Cyber insurers consider limiting coverage as sector scrambles to price agentic AI risks
DORA Year Two: Can Your SOC Actually See the Attack?
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Legacy systems may not survive the impending quantum security problem | news | MSSP Alert
NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine
Researchers escape OpenAI Codex sandbox to run commands on host
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening | WIRED
Microsoft reminds admins to migrate Entra ID users to passkeys
Anthropic-linked CVEs pile up, attackers mostly shrug
MFA Won't Save You From OAuth Consent Abuse
Most WordPress pros still lack a breach recovery plan - Help Net Security
I’ll never let my browser handle passwords again
How to Choose Between a Service Account vs User Account
We’ve spent billions defending software. It’s time to protect execution
Other News
UK Government Urges Food Stockpiling: Here's Why And What To Buy
Europe’s technology backbone is becoming a cyber target - Help Net Security
EU states failing to exchange information on cross-border cyber security attacks | Computer Weekly
You probably don’t recognize half the processes running on Windows, and that’s a security problem
Cyber Defense Alone Can't Keep Critical Services Running
IRS cybersecurity program deemed ineffective, risking taxpayer data | brief | MSSP Alert
Space systems may become targets and tools for cyberattacks, Kaspersky warns | TahawulTech.com
Vulnerability Management
DarkMe RAT trades zero-days for plain phishing emails - Help Net Security
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening | WIRED
Anthropic-linked CVEs pile up, attackers mostly shrug
NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine
Abandoned IoT apps keep sending sensitive data to broken servers - Help Net Security
CISA outlines improvement plan for CVE program | CyberScoop
We’ve spent billions defending software. It’s time to protect execution
Ubuntu kernel CVE fixes are moving to a weekly release schedule - Help Net Security
Vulnerabilities
New Windows Defender zero-day blocks Microsoft antivirus updates
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products - SecurityWeek
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cisco Zero-Day Highlights API Endpoint Authentication Issues
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Windows 11 Update Can Break Active Directory Trust Relationships
Microsoft: September Windows updates break Always On VPN connections
Chrome 154 Patches 108 Vulnerabilities - SecurityWeek
Hackers start exploiting critical WordPress flaw for code execution
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CISA: Ransomware gangs now exploiting critical TeamCity flaw
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted - SecurityWeek
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
Decades-old file security flaws found in Android, Linux, macOS, and Windows
Adobe Patches Critical Flaws in Connect, AEM Forms - SecurityWeek
Microsoft fixes bug that broke Windows File History backup feature
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
Critical Linux kernel vulnerability ZcopyReaper allows privilege escalation | brief | MSSP Alert
Hackers now exploit critical Roundcube flaw in code injection attacks
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
WordPress Click2Shell flaw lets hackers execute PHP on the server
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Google Pixel phones pwned in zero-click attacks
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
D-Link warns of max severity zero-day bug in DIR-822A routers
GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection - Help Net Security
Sector Specific
Industry specific threat intelligence reports are available.
Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.
Automotive
Construction
Critical National Infrastructure (CNI)
Defence & Space
Education & Academia
Energy & Utilities
Estate Agencies
Financial Services
FinTech
Food & Agriculture
Gaming & Gambling
Government & Public Sector (including Law Enforcement)
Health/Medical/Pharma
Hotels & Hospitality
Insurance
Legal
Manufacturing
Maritime & Shipping
Oil, Gas & Mining
OT, ICS, IIoT, SCADA & Cyber-Physical Systems
Retail & eCommerce
Small and Medium Sized Businesses (SMBs)
Startups
Telecoms
Third Sector & Charities
Transport & Aviation
Web3
Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.
Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.
You can also follow us on Facebook, Twitter and LinkedIn.
Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.