Black Arrow Cyber Threat Intelligence Briefing 28 August 2026

Welcome to this week’s Black Arrow Cyber Threat Intelligence Briefing – a weekly digest, collated and curated by our cyber experts to provide senior and middle management with an easy to digest round up of the most notable threats, vulnerabilities, and cyber related news from the last week.

Executive Summary

We start this week by looking at developing attacker techniques, including phishing attacks that can be steered in real time, malware designed to remain dormant until activated, and mobile malware capable of stealing login and authentication details that could provide access to business systems.

We also look at the growing risks associated with AI. Research highlights extensive use of personal and unapproved AI tools, while AI is also accelerating vulnerability discovery. Ransomware activity remains high, reinforcing the need for organisations to understand where they are exposed and prioritise the risks that matter most.

The wider message is that security, governance and resilience must develop alongside the threat. In the UK, Provision 29 of the UK Corporate Governance Code reinforces the need for reliable evidence that important controls are working, while effective incident response, secure backups and tested recovery arrangements can materially affect how quickly an organisation recovers.

We support organisations in various countries to address these risks and requirements. Contact us to discuss how we help leadership teams to strengthen proportionate cyber security, governance and resilience.


Top Cyber Stories of the Last Week

ZeroTokens Phishing Platform Steers Attacks in Real Time

A phishing campaign has used a platform called ZeroTokens to let criminals monitor victims and alter fraudulent login screens in real time. More than 45,000 messages were sent to over 24,000 recipients across 700 organisations, with 24,000 sent on a single day. The attacks targeted financial information, login details, card data and verification codes, while adapting prompts to retry failed verification steps. Researchers found the platform supported templates for 53 financial institutions and 36 card issuers, and assessed that information captured through the phishing interaction would most likely be used outside the platform for financial theft or payment redirection.

https://www.infosecurity-magazine.com/news/zerotokens-phishing-real-time/

ToxicPanda Banking Trojan Matures into Enterprise Threat

A new version of the ToxicPanda Android banking Trojan has expanded from targeting 16 financial institutions to 349 banking, digital wallet and cryptocurrency applications across 16 countries. Attackers are using legitimate cloud services to distribute the malware that can now issue 167 remote commands and gain deeper, persistent control of infected devices, including stealing screen-lock credentials. This creates wider business risk because employee smartphones often hold authentication credentials and provide access to corporate applications.

https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat

New Windows Malware Lays Dormant Until a Custom Command Activates It like a Sleeper Agent

Security researchers have identified SLEEPWALKER, an unusual form of Windows malware designed to remain dormant until it receives a specially crafted network signal. Unlike conventional malware, it contains no built-in malicious functions, helping it avoid detection while disguised as a legitimate security management component. Once activated, it can receive additional capabilities and execute instructions. No active campaigns or confirmed victims have been identified, but researchers believe its highly targeted design could indicate nation-state involvement rather than widespread criminal use.

https://www.techradar.com/pro/security/new-windows-malware-lays-dormant-until-a-custom-command-activates-it-like-a-sleeper-agent

What Your CISO Is Trying to Tell You, and Why It Matters More Than You Think

Effective cyber risk management requires security teams to communicate technical risks in terms that business leaders can understand and act on. Security teams can struggle to secure executive support when risks are presented through technical scores, acronyms and system details rather than potential business impact. With AI accelerating the pace at which threats evolve, that communication gap is becoming increasingly important. Cyber security risks are more likely to prompt timely decisions when leaders understand which business services are affected, the consequences of delaying action, the cost or disruption involved, who owns the response and what risk will remain afterwards.

https://www.forbes.com/councils/forbestechcouncil/2026/08/25/what-your-ciso-is-trying-to-tell-you-and-why-it-matters-more-than-you-think/

Why Provision 29 Is Raising the Bar for Board Accountability

The revised UK Corporate Governance Code is increasing expectations on boards to demonstrate that important internal controls are working effectively, rather than relying on periodic compliance checks. From 2026, Provision 29 requires boards to assess and report on material controls using reliable evidence. For cyber security, this strengthens the case for more continuous monitoring, as annual assessments can quickly become outdated across cloud services, conventional IT infrastructure and third-party suppliers. More timely information can help boards understand changing risks and provide greater confidence when making formal declarations about control effectiveness.

https://www.itsecurityguru.org/2026/08/26/why-provision-29-is-raising-the-bar-for-board-accountability/

Worrying Cyber Security Gaps Expose UK Charities

Research into 380 of the UK’s largest and best-known charities found widespread cyber security weaknesses, with exposed staff or supplier passwords affecting 44% of well-known charities and 55% of the largest by income. Around one in three could also have emails forged in their name, increasing the risk of fraudulent appeals or payment requests. Larger charities were not necessarily better protected, with better-funded organisations more likely to have exposed credentials and internal login pages. Nine in 10 also lacked a published process for reporting security weaknesses, although none appeared on ransomware leak sites.

https://tfn.scot/news/worrying-cybersecurity-gaps-expose-uk-charities

How Shadow IT Threatens Your Cyber Security and Digital Sovereignty

The rapid adoption of unapproved apps, cloud services and AI tools is creating a growing cyber security and governance risk for organisations. Employees often adopt these tools for convenience, but sensitive data can then move outside approved systems, leaving organisations with limited visibility over where it is stored, who can access it and how it is used. AI note-taking tools and personal accounts are increasing this challenge. Effective control requires organisations to provide usable approved alternatives, monitor what tools are being used and ensure sensitive information remains within appropriately governed environments.

https://www.forbes.com/councils/forbestechcouncil/2026/08/20/how-shadow-it-threatens-your-cybersecurity-and-digital-sovereignty/

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Akamai has found that a small group of intensive AI users may be creating a disproportionate share of organisational risk. The 5% of employees who use AI most intensively use it at 12 times the rate of the least active half, while 47% of enterprise AI conversations take place through personal rather than managed corporate accounts. Around 14% of enterprise AI conversations involved corporate email addresses linked to personal AI subscriptions, potentially exposing sensitive data. AI browser and coding extensions add further risk, with nearly 75% requesting significant permissions and 16% containing known security weaknesses.

https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html

AI Vulnerability Discovery Scores the Highest Impact of 20 Emerging Risks

AI-powered vulnerability discovery has emerged as the highest-impact of 20 emerging risks identified by Gartner, with 76% of respondents placing it in their top ten. Organisations expect the effects to become tangible within the next two years as AI makes it faster and easier to find previously unknown security weaknesses and turn them into usable attacks. While respondents also ranked themselves highly prepared, Gartner warns that vulnerability discovery could outpace organisations' ability to fix weaknesses, raising the risk of serious cyber incidents and disruption to operations.

https://www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/

Ransomware Attack Volumes Hit ‘High Water Mark’ in July

Ransomware activity reached its highest level of 2026 so far in July, with 894 recorded attacks, up almost 25% from June. North America accounted for 41% of incidents and Europe 29%, while one rapidly growing criminal group was linked to 15% of attacks. NCC Group also warned that artificial intelligence is increasing the speed and scale of cyberattacks by helping criminals automate activity and create more convincing phishing content. Emerging AI agents capable of carrying out ransomware attacks with little or no human involvement could further increase the threat.

https://www.computerweekly.com/news/366649779/Ransomware-attack-volumes-hit-high-water-mark-in-July

Incident Response: Why the First Two Hours After an Attack Set the Tone

The first two hours following a cyberattack can significantly influence how quickly an organisation recovers. Poor early decisions, such as wiping compromised systems, can destroy evidence, leave attackers' access routes in place and turn a five-day recovery into a five-week crisis. Effective response depends on quickly assembling legal, forensic and recovery specialists, establishing secure communications and understanding what has been affected. Tested backups are equally important, as many failures only become apparent during recovery. Organisations that prepare response arrangements in advance are better placed to contain disruption and restore operations quickly.

https://www.informationweek.com/incident-response/incident-response-why-the-first-two-hours-after-an-attack-set-the-tone

Business Continuity and Cyber Security: Two Sides of the Same Coin

Business continuity and cyber security cannot be treated separately as attackers increasingly target the systems organisations rely on to recover from disruption. Research found that 93% of ransomware attacks targeted backup repositories, while 68% of breaches involved a human element. With the average global cost of a data breach reaching $4.88 million, organisations need recovery arrangements that remain secure during an attack. This includes protecting backups, separating critical systems, maintaining alternative communications and regularly testing recovery plans against realistic cyberattack scenarios.

https://www.csoonline.com/article/4086135/business-continuity-and-cybersecurity-two-sides-of-the-same-coin.html



Threats

Ransomware, Extortion and Destructive Attacks

Ransomware attack volumes hit ‘high-water mark’ in July | Computer Weekly

Ransomware attackers are zeroing in on mid-market companies - Help Net Security

Scammers pose as ransomware recovery agents, but just go on to steal more from victims | TechRadar

Scattered Spider Targets Tech Companies for Help-Desk Exploitation - ReliaQuest

Tricky 'SynkLoader' Multitool May Herald Ransomware

Ransomware surges as criminals deploy AI tools | Microscope

Autonomous AI Ransomware Threat Peaks 2026

Gunra Ransomware: What You Need to Know |Fortra

Ransomware and Destructive Attack Victims

US Bank claimed by hackers, posted on the dark web | Cybernews

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited - SecurityWeek

ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta | TechRadar

ATF confirms “major incident” after recent Qilin breach claims

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

ShinyHunters Leaks 7.1 Million Baxter International Records

Phishing & Email Based Attacks

ZeroTokens Phishing Platform Steers Attacks in Real Time - Infosecurity Magazine

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets - SecurityWeek

Fake bank websites play dead to evade security scanners - Help Net Security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine

Russian snoops add OAuth abuse to targeted phishing campaigns

Hackers abuse npm mirrors to host phishing redirect pages

New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls | TechRadar

First-time buyer lost £47,000 after email 'impersonated' - The Mirror

Def Con Attendees Targeted by Persistent Phishing Campaign - Infosecurity Magazine

Other Social Engineering

Think you’d never fall for it? Modern cybercriminals are counting on that | Federal News Network

Fake bank websites play dead to evade security scanners - Help Net Security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine

Scattered Spider Targets Tech Companies for Help-Desk Exploitation - ReliaQuest

Attackers impersonate popular AI brands to spread malware - Help Net Security

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Beware of fake Indeed interview apps used to install spyware | Malwarebytes

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Red Flags That Expose Fake North Korean IT Workers

Cybercriminals perfect 'social engineering': 'Each hack feeds the chances of the next one succeeding - France 24

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

First-time buyer lost £47,000 after email 'impersonated' - The Mirror

Scammers cost Irish adults €760m last year - survey – The Irish Times

‘Hang up’ warning issued as fraudsters target Isle of Man residents by phone | iomtoday.co.im

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice | CyberScoop

2FA/MFA

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Artificial Intelligence

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty

Why "Shady AI" is Security's Next Big Governance Problem

Why AI cyberattacks are outpacing enterprise defenses | CSO Online

A low-tech solution from the past may be your best defense against AI deepfakes | ZDNET

AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security

New study finds bosses are far more comfortable sharing work documents with AI than their employees — despite the security risks | TechRadar

Four in Five AI Tools Run with No IT Oversight, Research Finds - Infosecurity Magazine

Attackers impersonate popular AI brands to spread malware - Help Net Security

Ransomware surges as criminals deploy AI tools | Microscope

Autonomous AI Ransomware Threat Peaks 2026

PYMNTS | OpenAI Exec Tells People to Expect AI-Driven Cyberattacks

The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes - Help Net Security

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Grok chat duped into swallowing injected instructions

NCSC, comments on agentic AI | Professional Security Magazine

ISMG Editors: AI-Assisted Cyberattacks Gain Speed and Scale

What The Hugging Face Cyberattack Teaches Leaders About AI

AI supply chain risk is showing up in developer workflows first - Help Net Security

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

OpenAI: Agent behavior that led to Hugging Face intrusion formed in May | CyberScoop

The Hugging Face incident and the road ahead | OpenAI

OpenAI previews privacy-focused system for detecting AI misuse - Help Net Security

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses - SecurityWeek

AI Agents Taking Unsanctioned Action During Cyber Testing

Eight AI Agents Attacked Taiwan's Government for Four Days — With No Human Pulling the Trigger - Times Tabloid

Fake Codex Download Uses Google Sites to Deliver macOS Malware - Infosecurity Magazine

Could OpenClaw have actually hacked that Australian gym? We decided to test it.

ChatGPT can now search Apple Messages, raising privacy concerns | Fortune

Careers, Roles, Skills, Working in Cyber and Information Security

Cybersecurity Job Ads Requiring AI Skills Double - Infosecurity Magazine

Cloud/SaaS

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

New malware turns Microsoft cloud into its control center | CSO Online

Researchers Uncover Thousands of Leaked AWS Keys - Infosecurity Magazine

NIST Warns of Unique Security Risks in Multi-Cloud Environments - Infosecurity Magazine

Cryptocurrency/Cryptomining/Cryptojacking/NFTs/Blockchain

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Cyber Crime, Organised Crime & Criminal Actors

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A $25 template helped scammers build hundreds of phantom bank domains - Help Net Security

More Than Half of Gen Z Has Faced a Cyberattack - tovima.com

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects - Infosecurity Magazine

Your Shredded Visa Card May Still Work at the Checkout - Security Affairs

Scammers cost Irish adults €760m last year - survey – The Irish Times

Data Breaches/Leaks

Researchers Uncover Thousands of Leaked AWS Keys - Infosecurity Magazine

US Bank claimed by hackers, posted on the dark web | Cybernews

Personal Information Exposed in Apollo Global Data Breach - SecurityWeek

More Than 9 Million Facial Images Were Leaked Online

Cyberattack hits 63% of Latvia’s population | Al Bawaba

88 ID Verification Breaches Show the Cost of Collecting Identity Data

French tax authority says break-in exposed data of 600K, including some private messages

Target may have suffered another damaging data leak as hackers claim 8.6GB haul | TechRadar

ShinyHunters Leaks 7.1 Million Baxter International Records

Sensitive Information Exposed in Nutex Health Data Breach - SecurityWeek

Data/Digital Sovereignty

How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty

The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know

Why Israel's outsized influence on global tech is worrying | Al Majalla

Denial of Service/DoS/DDoS

Massive DDoS attack disrupts Norway’s government digital services

Pro-Russian hackers declare ‘cyberwar’ on Norway

Encryption

Nearly half of enterprises have no one leading PQC migration - Help Net Security

Quantum Cyberattacks Are Now A CIO Deadline, Not A Research Topic

Fraud, Scams and Financial Crime

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A $25 template helped scammers build hundreds of phantom bank domains - Help Net Security

Fake bank websites play dead to evade security scanners - Help Net Security

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Your Shredded Visa Card May Still Work at the Checkout - Security Affairs

Scammers cost Irish adults €760m last year - survey – The Irish Times

Scams: Why You Can No Longer Trust Your Eyes And Ears | Scoop News

Up to £464m ‘moved through more than 3,000 UK high street shell companies’ | Business | The Guardian

Identity and Access Management

88 ID Verification Breaches Show the Cost of Collecting Identity Data

Insider Risk and Insider Threats

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

Red Flags That Expose Fake North Korean IT Workers

Insurance

Average Cyber Insurance Losses Increase Despite Fewer Claims - Infosecurity Magazine

Internet of Things – IoT

Slovakia finds Russian backdoors in speed cameras | Cybernews

Hackers infect Android car head units with proxy botnet malware

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout | Tom's Hardware

Law Enforcement Action and Take Downs

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects - Infosecurity Magazine

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist | CyberScoop

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice | CyberScoop

Linux and Open Source

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researcher tricks Apple’s Find My into sharing location data with Linux

China joins Europe in scrapping Windows for Linux | ZDNET

Malware

ToxicPanda Banking Trojan Matures Into Enterprise Threat

New Windows malware lays dormant until a custom command activates it like a sleeper agent | TechRadar

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Hackers Weaponize OpenClaw AI Agents to Push Malware and Steal Crypto Wallets

Attackers impersonate popular AI brands to spread malware - Help Net Security

AI Speeds Up Malware Development, Not Its Success Rate: Analysis - SecurityWeek

Fake Codex Download Uses Google Sites to Deliver macOS Malware - Infosecurity Magazine

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Tricky 'SynkLoader' Multitool May Herald Ransomware

Hackers abuse FTP server banners to deliver new Windows malware

New Agent Tesla Malware Variant Boosts Evasion Capabilities - Infosecurity Magazine

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Hackers infect Android car head units with proxy botnet malware

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Hackers abuse npm mirrors to host phishing redirect pages

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Misinformation, Disinformation and Propaganda

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

OpenAI banned Russian ChatGPT accounts backing covert influence operation

Mobile

ToxicPanda Banking Trojan Matures Into Enterprise Threat

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

Models, Frameworks and Standards

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts - SecurityWeek

Firms urged to prepare for eventual NIS2 implementation

Passwords, Credential Stuffing & Brute Force Attacks

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets - SecurityWeek

Fake Recruiter Scams Target Corporate Credentials on Mobile - Infosecurity Magazine

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Hackers poison popular Rust crates to steal developers' credentials

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes - Help Net Security

Privacy, Surveillance

Your Comcast router doubles as a motion detector now - and a potential police informant | ZDNET

More Than 9 Million Facial Images Were Leaked Online

Researcher tricks Apple’s Find My into sharing location data with Linux

The best and worst AI for your privacy, ranked - and how each handles your data | ZDNET

ChatGPT can now search Apple Messages, raising privacy concerns | Fortune

Windows 11 is finally getting better privacy controls for cameras and mics | PCWorld

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears | CyberScoop

Flock Announces Band-Aids Meant To Remedy Totally Predictable And Widespread Abuse Of Surveillance Equipment

Regulations, Fines and Legislation

Senator asks US government watchdog to review how feds use hacking tools | TechCrunch

UK government set to adjudicate on ‘risky’ tech purchases | Computer Weekly

Meta agrees to $18 billion settlement over teen social media harms

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears | CyberScoop

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts - SecurityWeek

Trump Moves to Ban Some Foreign Energy Equipment From Grid - Bloomberg

Shadow IT

Employees' shadow AI use is poorly monitored, survey finds | TechTarget

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

How Shadow IT Threatens Your Cybersecurity And Digital Sovereignty

Why "Shady AI" is Security's Next Big Governance Problem

Shadow AI presents cyber security challenge - CIR Magazine

Social Media

TikTok reaches $400m US children's privacy settlement | US News | Sky News

Meta agrees to $18 billion settlement over teen social media harms

Software Supply Chain

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

New malware turns Microsoft cloud into its control center | CSO Online

AI supply chain risk is showing up in developer workflows first - Help Net Security

Hackers poison popular Rust crates to steal developers' credentials

Hackers abuse npm mirrors to host phishing redirect pages

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

This Mini PC Brand Accidentally Hosted Malware-Infected Drivers On Its Website

Supply Chain and Third Parties

Financial damage from cyber attacks grows despite falling claims volumes | Insurance Times

Is Cyber Facing an Affordability Crisis?

AI supply chain risk is showing up in developer workflows first - Help Net Security


Nation State Actors, Advanced Persistent Threats (APTs), Cyber Warfare, Cyber Espionage and Geopolitical Threats/Activity

Cyber Warfare and Cyber Espionage

UK to warn public to store tinned food in case of emergencies: FT

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Officials disrupt Chinese espionage operation that hit multiple federal agencies | CyberScoop

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware | The Record from Recorded Future News

Nation State Actors

China

UK government set to adjudicate on ‘risky’ tech purchases | Computer Weekly

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate - Help Net Security

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware | The Record from Recorded Future News

Trump Moves to Ban Some Foreign Energy Equipment From Grid - Bloomberg

China joins Europe in scrapping Windows for Linux | ZDNET

Eight AI Agents Attacked Taiwan's Government for Four Days — With No Human Pulling the Trigger - Times Tabloid

China-linked Threats to Operational Technology

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Russia

UK to warn public to store tinned food in case of emergencies: FT

OpenAI says it took down a malicious Russian plan to spread misinformation on ChatGPT | TechRadar

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

German firms report rising cyber threat from foreign intelligence services, study shows - The Economic Times

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout | Tom's Hardware

Pro-Russian hackers declare ‘cyberwar’ on Norway

AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking - SecurityWeek

Russia-Linked Threats to Operational Technology

Russia builds global satellite internet network to rival Starlink

North Korea

Red Flags That Expose Fake North Korean IT Workers

Iran

Iranian hackers carry out unprecedented attack on UK’s power network | The Independent

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Iran strikes deep: Attack on British infrastructure

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

UK power plant shutdown highlights CNI cyber challenges | Computer Weekly

Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’ | IT Pro

The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera

Big or small—Critical infrastructure under attack | McDonald Hopkins - JDSupra

Iran hackers vow to target US allies | Cybernews

Other Nation State Actors, Hacktivism, Extremism, Terrorism and Other Geopolitical Threat Intelligence

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Pakistan's Transparent Tribe Refreshes Tools for Afghan Attacks




Vulnerability Management

AI vulnerability discovery scores the highest impact of 20 emerging risks - Help Net Security

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

Silent Patches Don’t Stop Attackers - They Blind Defenders - SecurityWeek

Why mission risk should drive cyber operations strategies | perspective | SC Media

The Vulnerability Gap: Why Discovery Is Outrunning Repair

Frontier AI: Vulnerability Management's Systemic Revolution

Vulnerabilities

Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel

Microsoft patches max severity code execution, privilege escalation flaws

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security

That April Windows update you skipped? Hackers are exploiting it now | PCWorld

Microsoft: August updates break printing, PDF export in WPF apps

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Microsoft rolls out fix for Windows 11 crashes, gaming issues

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Recent Citrix NetScaler Vulnerability Exploited in the Wild - SecurityWeek

Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes

Hackers breached over 270 Zimbra servers in ongoing attacks

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Chrome 152 Patches Over 300 Vulnerabilities - SecurityWeek

Adobe and Nvidia Patch Dozens of Vulnerabilities - SecurityWeek

PaperCut Releases Emergency Patch for Exploited Zero-Day - SecurityWeek

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

Ubiquiti UniFi vulnerabilities: 21 critical bugs expose devices | Cybernews

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line | CyberScoop

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

GitLab Warns of Active Exploitation of Critical GraphQL Flaw

Critical Isolated-vm Vulnerability Leads to RCE on Host - SecurityWeek

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

91 Vulnerabilities Patched in Spring Application Framework - SecurityWeek

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Hackers target WordPress sites in miniOrange auth bypass attacks

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Critical Avada WordPress theme flaw enables zero-click RCE


Sector Specific

Industry specific threat intelligence reports are available.

Contact us to receive tailored reports specific to the industry/sector and geographies you operate in.

  • Automotive

  • Construction

  • Critical National Infrastructure (CNI)

  • Defence & Space

  • Education & Academia

  • Energy & Utilities

  • Estate Agencies

  • Financial Services

  • FinTech

  • Food & Agriculture

  • Gaming & Gambling

  • Government & Public Sector (including Law Enforcement)

  • Health/Medical/Pharma

  • Hotels & Hospitality

  • Insurance

  • Legal

  • Manufacturing

  • Maritime & Shipping

  • Oil, Gas & Mining

  • OT, ICS, IIoT, SCADA & Cyber-Physical Systems

  • Retail & eCommerce

  • Small and Medium Sized Businesses (SMBs)

  • Startups

  • Telecoms

  • Third Sector & Charities

  • Transport & Aviation

  • Web3


Contact us to help assess where your risks lie and to ensure you are doing all you can do to keep you and your business secure.

Look out for our ‘Cyber Tip Tuesday’ video blog and on our YouTube channel.

You can also follow us on Facebook, Twitter and LinkedIn.

Links to external articles are provided for general interest and awareness only. Linking to or reposting external content does not constitute endorsement of or by any organisation, service, or product. We do not control and are not responsible for the content, security, or availability of external websites or links. Full credit is given to the original authors and sources. E&OE.

Next
Next

Black Arrow Cyber Threat Intelligence Briefing 21 August 2026