๐ง Subscribe to the podcast feed | Download episode
Security News
ARTEX AI and Claude agents used in cyberattacks on South Korean banks (BleepingComputer) โ Attackers deployed ARTEX AI combined with Claude agents in coordinated intrusion attempts against South Korean financial institutions, the first confirmed case of AI agents with tool-use capability being directed against bank infrastructure.
Satya Nadella: assume all AI models are compromised (The Verge) โ Microsoft's CEO publicly stated that security teams should default to assuming AI models have been compromised, reflecting a new consensus that AI supply chains are an active attacker surface.
White House mandates AI companies report security incidents (Slashdot) โ Following the Claude false police tip incident, the White House issued a directive requiring AI companies to report security incidents, accelerating the regulatory environment around AI safety.
Hackers abuse Google Ads and Bing redirects to push Claude ClickFix attacks (BleepingComputer) โ Attackers continue to exploit legitimate Bing redirect URLs in Google search ads pointing to fake Claude AI installer pages that deliver credential-harvesting malware via ClickFix.
Cyber exec arrested in case tied to ShinyHunters (BleepingComputer) โ A cybersecurity executive has been arrested in connection with ShinyHunters, the third arrest linked to the group this week following the FBI breach and two prior suspect arrests.
Ubuntu confirms DDoS attack on its web infrastructure (Slashdot) โ Canonical confirmed the DDoS attack against Ubuntu's web infrastructure reported earlier this week, highlighting the targeting of critical open source platform infrastructure.
Danish CPR data breach enabled by "123456" password (Copenhagen Post) โ Denmark's national civil registration number system โ underpinning identity, tax, and healthcare โ was breached via a default credential, underscoring endemic authentication failures in government infrastructure.
Insider cyber extortion plot against industrial firm lands engineer in prison (SecurityWeek) โ An engineer has been sentenced after using legitimate OT access credentials to attempt extortion following a workplace grievance โ a case study in the credential revocation gap in operational technology environments.
Google Domains impacted by ccTLD hijacks (SecurityWeek) โ The .gh, .sl, and .as country-code TLD hijacks obtained valid HTTPS certificates for Google domains, raising ongoing concerns about certificate transparency and domain validation trust.
OpenAI disrupts two AI-enabled influence operations (Slashdot) โ OpenAI shut down a Russian-run Latin American propaganda campaign and an Iranian fake-journalist network that planted fabricated articles in legitimate US publications using ChatGPT accounts.
ShinyHunters targets education sector with Oracle PeopleSoft exploit (Mandiant / Google GTIG) โ Mandiant and GTIG disclose an active ShinyHunters (UNC6240) campaign exploiting Oracle PeopleSoft infrastructure against education sector targets, running MayโJune 2026.
Two characters open typosquatting opportunities in Chromium browsers (The Register) โ A newly disclosed Chromium behaviour allows two-character domain lookalikes to bypass visual detection, creating a broad typosquatting attack surface across Chrome and Edge.
UK & Critical National Infrastructure
lopay, the UK-based fintech payments company, remains the only confirmed UK victim in this ransomware window โ claimed by Black X, with the description confirming exfiltration of customer card data, banking details, and transaction history.
No new NCSC advisories have been issued in the past 48 hours.
The dominant CNI-relevant theme this week is the confirmed operational use of AI agents as attack infrastructure. The ARTEX AI and Claude agent attack against South Korean banks is the live proof-of-concept that the NCSC's AI security guidance anticipated: AI tooling is no longer just a defender capability โ it is now active offensive infrastructure against financial sector targets. UK financial institutions should review their AI agent governance, prompt injection mitigations, and lateral movement controls in AI-integrated environments.
Rhysida's Anne Arundel County data description โ methadone clinic records under 42 CFR Part 2, jail gang-intelligence files, and 2.6TB of government records โ is the clearest illustration yet of how a single ransomware event against a county government can expose the full breadth of sensitive public services data. UK local authorities with comparable data holdings should treat this as a tabletop reference case.
Ransomware Victims (48h) โ 35 victims ยท 19 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| anubis | โ ๏ธ Mynd | โ | โ ๏ธ Healthcare |
| arcusmedia | AETHOS | ๐ง๐ท BR | Other |
| arcusmedia | Ladrillera Mecanizada | ๐ฒ๐ฝ MX | Manufacturing |
| arcusmedia | mblllp | ๐จ๐ฆ CA | Other |
| Black X | โ ๏ธ bayer | ๐ฉ๐ช DE | โ ๏ธ Healthcare / Pharma |
| Black X | enTouch | ๐ฏ๐ต JP | Technology |
| Black X | โ ๏ธ lopay ๐ฌ๐ง | ๐ฌ๐ง GB | โ ๏ธ Financial Services |
| bravox | Dudley Land Company | ๐บ๐ธ US | Other |
| chaos | โ ๏ธ astranahealth.com | ๐บ๐ธ US | โ ๏ธ Healthcare |
| Deadlock | โ ๏ธ idi pharma | ๐ช๐ธ ES | โ ๏ธ Healthcare |
| Deadlock | Saber1 | ๐บ๐ธ US | Manufacturing |
| dragonforce | TEXMA International Co., Ltd | ๐น๐ผ TW | Manufacturing |
| emperador | Imperial Diamond Jewellery | โ | Retail |
| exitium | KOIKE Sanso Kogoyo Co. Ltd. | ๐ฏ๐ต JP | Manufacturing |
| interlock | Shalom Christian Academy | ๐บ๐ธ US | Education |
| Panzer | โ ๏ธ Supreme Energy | ๐ธ๐ฌ SG | โ ๏ธ Energy |
| Panzer | solutend | โ | Technology |
| qilin | ACI Proyectos SAS | ๐จ๐ด CO | Other |
| qilin | Glenhardie Country Club | ๐บ๐ธ US | Hospitality |
| qilin | Hagiva Yh | ๐ฎ๐ฑ IL | Other |
| qilin | LD Constructora | ๐จ๐ฑ CL | Manufacturing |
| qilin | Melchioni Spa | ๐ฎ๐น IT | Manufacturing |
| qilin | โ ๏ธ Secretarรญa de Modernizaciรณn e Innovaciรณn | ๐ฆ๐ท AR | โ ๏ธ Government |
| qilin | Tepcomp | ๐ซ๐ฎ FI | Technology |
| qilin | Vadeto Group | ๐ธ๐ช SE | Other |
| Redact | โ ๏ธ DexCom | ๐บ๐ธ US | โ ๏ธ Healthcare (Medical Devices) |
| rhysida | โ ๏ธ Anne Arundel County | ๐บ๐ธ US | โ ๏ธ Government |
| rhysida | Gress Clark Young & Schoepper | ๐บ๐ธ US | Professional Services |
| rhysida | RealManage | ๐บ๐ธ US | Professional Services |
| safepay | dwi-bau.de | ๐ฉ๐ช DE | Manufacturing |
| safepay | hoteldelfinolugano.ch | ๐จ๐ญ CH | Hospitality |
| termite | โ ๏ธ iDentalSoft | ๐ง๐ท BR | โ ๏ธ Healthcare |
| thegentlemen | โ ๏ธ Royal Thai Air Force | ๐น๐ญ TH | โ ๏ธ Government / Defence |
| threeam | โ ๏ธ fleetworksinc.com | ๐บ๐ธ US | โ ๏ธ Transportation |
| UmBra | Helwan University (HITU) | ๐ช๐ฌ EG | Education |