๐ง Subscribe to the podcast feed | Download episode
Security News
Japan confirms arrest of Russian Qilin operative, extradition to Germany (The Record) โ Japan's National Police Agency confirmed the arrest and extradition to Germany of a Russian national linked to the Qilin ransomware group โ the first publicly confirmed Qilin arrest.
FBI arrests second suspected ShinyHunters member after FBI breach (BleepingComputer) โ A second ShinyHunters suspect has been arrested following last month's confirmed breach of FBI systems by the group; the FBI Director confirmed the arrest.
FBI arrests co-founder of ransomware negotiation firm (Krebs on Security) โ The FBI arrested the co-founder of a Canadian cybersecurity firm specialising in ransomware recovery, following the DOJ charges pattern reported earlier this week against Zohar Pinhasi.
Hackers abuse Google Ads and Bing redirects to push Claude ClickFix malware (BleepingComputer) โ Attackers are embedding legitimate Bing redirect URLs in Google search ads pointing to fake Claude AI installer pages that deliver credential-harvesting malware via ClickFix.
AWS AgentCore security undone by single credential-requesting prompt (The Register) โ A now-patched prompt injection vulnerability in AWS Bedrock AgentCore could allow a single crafted prompt to steal credentials and pivot across an organisation's entire agent fleet.
Unpatched AhsayCBS backup platform flaws exploited for webshells and cryptomining (BleepingComputer) โ Critical and medium-severity vulnerabilities in AhsayCBS enterprise backup management are being actively exploited to deploy webshells and mine cryptocurrency; audit exposure immediately.
iRhythm cardiac sensor company notifying states of data breach (The Record) โ iRhythm, which makes wearable cardiac monitoring patches used by hundreds of thousands of patients, has begun notifying regulators of a breach from earlier this year involving sensitive health and device data.
Ukraine drones knock out two Yandex AI data centres (Ars Technica) โ Drone strikes destroyed two of five Yandex data centres, disrupting the dominant Russian internet and AI platform's advertising, search, and mapping services.
ASOS breach reveals the risks in customer-facing SaaS identity (Dark Reading) โ Analysis of the ASOS social engineering attack shows how compromising a single employee identity via push-bombing enabled much deeper corporate network access โ a warning for all SaaS-heavy retail operators.
OpenAI fires three safety researchers in dispute over AI risk handling (SecurityWeek) โ OpenAI dismissed three safety researchers it says violated policies on handling sensitive information; the researchers dispute this, citing disagreements over how AI safety concerns are escalated.
UK & Critical National Infrastructure
lopay, a UK-based fintech payments company, is the sole UK victim in this ransomware window, claimed by Black X. lopay operates in the financial services sector; organisations using lopay should monitor for any service anomalies or vendor communications.
The ongoing ASOS breach analysis is directly relevant to UK retail and e-commerce organisations. Dark Reading's assessment highlights that a single compromised identity โ obtained via social engineering and push notification fatigue โ gave attackers access beyond the initial compromise point. UK retailers operating mixed SaaS environments should review identity and MFA posture.
No new NCSC advisories in the past 48 hours. The Qilin arrest in Japan and Rhysida's targeting of US county government both warrant monitoring: Qilin has UK victims in previous windows, and Rhysida has previously targeted NHS organisations.
Ransomware Victims (48h) โ 37 victims ยท 20 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| akira | Design Electric | โ | Manufacturing |
| akira | TigerPress (DCC) | โ | Other |
| akira | Yarema | โ | Other |
| anubis | โ ๏ธ Mynd | โ | โ ๏ธ Healthcare |
| arcusmedia | AETHOS | ๐ง๐ท BR | Other |
| arcusmedia | Ladrillera Mecanizada | ๐ฒ๐ฝ MX | Manufacturing |
| arcusmedia | mblllp | ๐จ๐ฆ CA | Other |
| Barracuda | Ministarstvo poljoprivrede, ลกumarstva i ribarstva | ๐ญ๐ท HR | Government (Agriculture Ministry) |
| Black X | โ ๏ธ bayer | ๐ฉ๐ช DE | โ ๏ธ Healthcare / Pharma |
| Black X | enTouch | ๐ฏ๐ต JP | Technology |
| Black X | โ ๏ธ lopay ๐ฌ๐ง | ๐ฌ๐ง GB | โ ๏ธ Financial Services |
| bravox | Dudley Land Company | ๐บ๐ธ US | Other |
| emperador | Imperial Diamond Jewellery | โ | Retail |
| interlock | Shalom Christian Academy | ๐บ๐ธ US | Education |
| netrunner | โ ๏ธ Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates | ๐บ๐ธ US | โ ๏ธ Healthcare |
| nightspire | PMG Project Management Group | ๐ฆ๐ช AE | Professional Services |
| Panzer | โ ๏ธ Supreme Energy | ๐ธ๐ฌ SG | โ ๏ธ Energy |
| Panzer | solutend | โ | Technology |
| payload | Boullard Musique | ๐จ๐ญ CH | Retail |
| qilin | Hagiva Yh | ๐ฎ๐ฑ IL | Other |
| qilin | MCM Telecom | ๐ฒ๐ฝ MX | Technology |
| qilin | Melchioni Spa | ๐ฎ๐น IT | Manufacturing |
| qilin | Tepcomp | ๐ซ๐ฎ FI | Technology |
| qilin | Vadeto Group | ๐ธ๐ช SE | Other |
| rhysida | โ ๏ธ Anne Arundel County | ๐บ๐ธ US | โ ๏ธ Government |
| rhysida | RealManage | ๐บ๐ธ US | Professional Services |
| RunSomeWares | โ ๏ธ Morton LTC Pharmacy | ๐บ๐ธ US | โ ๏ธ Healthcare |
| SilentRansomGroup | Andersen Group Inc. | โ | Professional Services |
| SilentRansomGroup | โ ๏ธ Baker McKenzie | ๐บ๐ธ US | Professional Services |
| SilentRansomGroup | O'Hagan Meyer | โ | Professional Services |
| termite | โ ๏ธ iDentalSoft | ๐ง๐ท BR | โ ๏ธ Healthcare |
| thegentlemen | โ ๏ธ Deloitte | ๐บ๐ธ US | Professional Services |
| threeam | โ ๏ธ fleetworksinc.com | ๐บ๐ธ US | โ ๏ธ Transportation |
| UmBra | FSE, Cairo University | ๐ช๐ฌ EG | Education |
| UmBra | IIT Roorkee | ๐ฎ๐ณ IN | Education |
| UmBra | Manipal Academy of Higher Edu | ๐ฎ๐ณ IN | Education |
| UmBra | SOCOCO | ๐ง๐ท BR | Technology |
HaveIBeenPwned โ New Breaches
| Breach | Date Added | Accounts | Data Exposed |
|---|---|---|---|
| Neogen | 9 Oct 2026 | 435,963 | Email addresses, employers, job titles, names, phone numbers, physical addresses, salutations |