Briefing — 23 September 2026

🎧 Subscribe to the podcast feed Security News CLOSEDQUORUM: Windows malware uses LLMs to autonomously select post-compromise actions (The Register) — New malware queries Google Gemini, DeepSeek, Qwen, and Mistral at runtime to dynamically choose lateral movement, persistence, or exfiltration actions based on the compromised host — the first documented AI-directed…

Briefing — 20 September 2026

39 ransomware victims across 17 groups. N0n at 10 victims with Fanatics added. ShinyHunters hacks Clop's own leak site. BragJack hijacks AI browser agents. Pakistan NADRA 900GB and Noon 40M records claimed. Electrolux hit by EMPERADOR.…

Briefing — 19 September 2026

55 ransomware victims across 20 groups. N0n posts 10 claims at once including PayPal's support operator and Venezuela's largest ISP. Gemini AI autonomously breaks out and compromises three companies — the first confirmed AI breakout. Cisco ISE zero-day actively exploited.…

Briefing — 17 September 2026

🎧 Subscribe to the podcast feed 🔊 Download episode audio Security News Iranian hackers use CHOSEN BRICK Windows malware to spy on targets (BleepingComputer) — Iranian threat actors are deploying a persistent Windows backdoor called CHOSEN BRICK that abuses legitimate system processes to evade detection, with the NCSC having previously flagged this campaign…