Briefing โ€” 10 October 2026

๐ŸŽง Subscribe to the podcast feed | Download episode

Security News

Japan confirms arrest of Russian Qilin operative, extradition to Germany (The Record) โ€” Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national linked to the Qilin ransomware group โ€” the first publicly confirmed Qilin arrest.

FBI arrests second suspected ShinyHunters member after FBI breach (BleepingComputer) โ€” A second ShinyHunters suspect has been arrested following last month's confirmed breach of FBI systems by the group; the FBI Director confirmed the arrest.

FBI arrests co-founder of ransomware negotiation firm (Krebs on Security) โ€” The FBI arrested the co-founder of a Canadian cybersecurity firm specialising in ransomware recovery, following the DOJ charges pattern reported earlier this week against Zohar Pinhasi.

Hackers abuse Google Ads and Bing redirects to push Claude ClickFix malware (BleepingComputer) โ€” Attackers are embedding legitimate Bing redirect URLs in Google search ads pointing to fake Claude AI installer pages that deliver credential-harvesting malware via ClickFix.

AWS AgentCore security undone by single credential-requesting prompt (The Register) โ€” A now-patched prompt injection vulnerability in AWS Bedrock AgentCore could allow a single crafted prompt to steal credentials and pivot across an organisation's entire agent fleet.

Unpatched AhsayCBS backup platform flaws exploited for webshells and cryptomining (BleepingComputer) โ€” Critical and medium-severity vulnerabilities in AhsayCBS enterprise backup management are being actively exploited to deploy webshells and mine cryptocurrency; audit exposure immediately.

iRhythm cardiac sensor company notifying states of data breach (The Record) โ€” iRhythm, which makes wearable cardiac monitoring patches used by hundreds of thousands of patients, has begun notifying regulators of a breach from earlier this year involving sensitive health and device data.

Ukraine drones knock out two Yandex AI data centres (Ars Technica) โ€” Drone strikes destroyed two of five Yandex data centres, disrupting the dominant Russian internet and AI platform's advertising, search, and mapping services.

ASOS breach reveals the risks in customer-facing SaaS identity (Dark Reading) โ€” Analysis of the ASOS social engineering attack shows how compromising a single employee identity via push-bombing enabled much deeper corporate network access โ€” a warning for all SaaS-heavy retail operators.

OpenAI fires three safety researchers in dispute over AI risk handling (SecurityWeek) โ€” OpenAI dismissed three safety researchers it says violated policies on handling sensitive information; the researchers dispute this, citing disagreements over how AI safety concerns are escalated.


UK & Critical National Infrastructure

lopay, a UK-based fintech payments company, is the sole UK victim in this ransomware window, claimed by Black X. lopay operates in the financial services sector; organisations using lopay should monitor for any service anomalies or vendor communications.

The ongoing ASOS breach analysis is directly relevant to UK retail and e-commerce organisations. Dark Reading's assessment highlights that a single compromised identity โ€” obtained via social engineering and push notification fatigue โ€” gave attackers access beyond the initial compromise point. UK retailers operating mixed SaaS environments should review identity and MFA posture.

No new NCSC advisories in the past 48 hours. The Qilin arrest in Japan and Rhysida's targeting of US county government both warrant monitoring: Qilin has UK victims in previous windows, and Rhysida has previously targeted NHS organisations.


Ransomware Victims (48h) โ€” 37 victims ยท 20 groups

GroupVictimCountrySector
akiraDesign Electricโ€”Manufacturing
akiraTigerPress (DCC)โ€”Other
akiraYaremaโ€”Other
anubisโš ๏ธ Myndโ€”โš ๏ธ Healthcare
arcusmediaAETHOS๐Ÿ‡ง๐Ÿ‡ท BROther
arcusmediaLadrillera Mecanizada๐Ÿ‡ฒ๐Ÿ‡ฝ MXManufacturing
arcusmediamblllp๐Ÿ‡จ๐Ÿ‡ฆ CAOther
BarracudaMinistarstvo poljoprivrede, ลกumarstva i ribarstva๐Ÿ‡ญ๐Ÿ‡ท HRGovernment (Agriculture Ministry)
Black Xโš ๏ธ bayer๐Ÿ‡ฉ๐Ÿ‡ช DEโš ๏ธ Healthcare / Pharma
Black XenTouch๐Ÿ‡ฏ๐Ÿ‡ต JPTechnology
Black Xโš ๏ธ lopay ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBโš ๏ธ Financial Services
bravoxDudley Land Company๐Ÿ‡บ๐Ÿ‡ธ USOther
emperadorImperial Diamond Jewelleryโ€”Retail
interlockShalom Christian Academy๐Ÿ‡บ๐Ÿ‡ธ USEducation
netrunnerโš ๏ธ Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Healthcare
nightspirePMG Project Management Group๐Ÿ‡ฆ๐Ÿ‡ช AEProfessional Services
Panzerโš ๏ธ Supreme Energy๐Ÿ‡ธ๐Ÿ‡ฌ SGโš ๏ธ Energy
Panzersolutendโ€”Technology
payloadBoullard Musique๐Ÿ‡จ๐Ÿ‡ญ CHRetail
qilinHagiva Yh๐Ÿ‡ฎ๐Ÿ‡ฑ ILOther
qilinMCM Telecom๐Ÿ‡ฒ๐Ÿ‡ฝ MXTechnology
qilinMelchioni Spa๐Ÿ‡ฎ๐Ÿ‡น ITManufacturing
qilinTepcomp๐Ÿ‡ซ๐Ÿ‡ฎ FITechnology
qilinVadeto Group๐Ÿ‡ธ๐Ÿ‡ช SEOther
rhysidaโš ๏ธ Anne Arundel County๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Government
rhysidaRealManage๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
RunSomeWaresโš ๏ธ Morton LTC Pharmacy๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Healthcare
SilentRansomGroupAndersen Group Inc.โ€”Professional Services
SilentRansomGroupโš ๏ธ Baker McKenzie๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
SilentRansomGroupO'Hagan Meyerโ€”Professional Services
termiteโš ๏ธ iDentalSoft๐Ÿ‡ง๐Ÿ‡ท BRโš ๏ธ Healthcare
thegentlemenโš ๏ธ Deloitte๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
threeamโš ๏ธ fleetworksinc.com๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Transportation
UmBraFSE, Cairo University๐Ÿ‡ช๐Ÿ‡ฌ EGEducation
UmBraIIT Roorkee๐Ÿ‡ฎ๐Ÿ‡ณ INEducation
UmBraManipal Academy of Higher Edu๐Ÿ‡ฎ๐Ÿ‡ณ INEducation
UmBraSOCOCO๐Ÿ‡ง๐Ÿ‡ท BRTechnology

HaveIBeenPwned โ€” New Breaches

BreachDate AddedAccountsData Exposed
Neogen9 Oct 2026435,963Email addresses, employers, job titles, names, phone numbers, physical addresses, salutations
Show Comments