Briefing โ€” 11 October 2026

๐ŸŽง Subscribe to the podcast feed | Download episode

Security News

ARTEX AI and Claude agents used in cyberattacks on South Korean banks (BleepingComputer) โ€” Attackers deployed ARTEX AI combined with Claude agents in coordinated intrusion attempts against South Korean financial institutions, the first confirmed case of AI agents with tool-use capability being directed against bank infrastructure.

Satya Nadella: assume all AI models are compromised (The Verge) โ€” Microsoft's CEO publicly stated that security teams should default to assuming AI models have been compromised, reflecting a new consensus that AI supply chains are an active attacker surface.

White House mandates AI companies report security incidents (Slashdot) โ€” Following the Claude false police tip incident, the White House issued a directive requiring AI companies to report security incidents, accelerating the regulatory environment around AI safety.

Hackers abuse Google Ads and Bing redirects to push Claude ClickFix attacks (BleepingComputer) โ€” Attackers continue to exploit legitimate Bing redirect URLs in Google search ads pointing to fake Claude AI installer pages that deliver credential-harvesting malware via ClickFix.

Cyber exec arrested in case tied to ShinyHunters (BleepingComputer) โ€” A cybersecurity executive has been arrested in connection with ShinyHunters, the third arrest linked to the group this week following the FBI breach and two prior suspect arrests.

Ubuntu confirms DDoS attack on its web infrastructure (Slashdot) โ€” Canonical confirmed the DDoS attack against Ubuntu's web infrastructure reported earlier this week, highlighting the targeting of critical open source platform infrastructure.

Danish CPR data breach enabled by "123456" password (Copenhagen Post) โ€” Denmark's national civil registration number system โ€” underpinning identity, tax, and healthcare โ€” was breached via a default credential, underscoring endemic authentication failures in government infrastructure.

Insider cyber extortion plot against industrial firm lands engineer in prison (SecurityWeek) โ€” An engineer has been sentenced after using legitimate OT access credentials to attempt extortion following a workplace grievance โ€” a case study in the credential revocation gap in operational technology environments.

Google Domains impacted by ccTLD hijacks (SecurityWeek) โ€” The .gh, .sl, and .as country-code TLD hijacks obtained valid HTTPS certificates for Google domains, raising ongoing concerns about certificate transparency and domain validation trust.

OpenAI disrupts two AI-enabled influence operations (Slashdot) โ€” OpenAI shut down a Russian-run Latin American propaganda campaign and an Iranian fake-journalist network that planted fabricated articles in legitimate US publications using ChatGPT accounts.

ShinyHunters targets education sector with Oracle PeopleSoft exploit (Mandiant / Google GTIG) โ€” Mandiant and GTIG disclose an active ShinyHunters (UNC6240) campaign exploiting Oracle PeopleSoft infrastructure against education sector targets, running Mayโ€“June 2026.

Two characters open typosquatting opportunities in Chromium browsers (The Register) โ€” A newly disclosed Chromium behaviour allows two-character domain lookalikes to bypass visual detection, creating a broad typosquatting attack surface across Chrome and Edge.


UK & Critical National Infrastructure

lopay, the UK-based fintech payments company, remains the only confirmed UK victim in this ransomware window โ€” claimed by Black X, with the description confirming exfiltration of customer card data, banking details, and transaction history.

No new NCSC advisories have been issued in the past 48 hours.

The dominant CNI-relevant theme this week is the confirmed operational use of AI agents as attack infrastructure. The ARTEX AI and Claude agent attack against South Korean banks is the live proof-of-concept that the NCSC's AI security guidance anticipated: AI tooling is no longer just a defender capability โ€” it is now active offensive infrastructure against financial sector targets. UK financial institutions should review their AI agent governance, prompt injection mitigations, and lateral movement controls in AI-integrated environments.

Rhysida's Anne Arundel County data description โ€” methadone clinic records under 42 CFR Part 2, jail gang-intelligence files, and 2.6TB of government records โ€” is the clearest illustration yet of how a single ransomware event against a county government can expose the full breadth of sensitive public services data. UK local authorities with comparable data holdings should treat this as a tabletop reference case.


Ransomware Victims (48h) โ€” 35 victims ยท 19 groups

GroupVictimCountrySector
anubisโš ๏ธ Myndโ€”โš ๏ธ Healthcare
arcusmediaAETHOS๐Ÿ‡ง๐Ÿ‡ท BROther
arcusmediaLadrillera Mecanizada๐Ÿ‡ฒ๐Ÿ‡ฝ MXManufacturing
arcusmediamblllp๐Ÿ‡จ๐Ÿ‡ฆ CAOther
Black Xโš ๏ธ bayer๐Ÿ‡ฉ๐Ÿ‡ช DEโš ๏ธ Healthcare / Pharma
Black XenTouch๐Ÿ‡ฏ๐Ÿ‡ต JPTechnology
Black Xโš ๏ธ lopay ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBโš ๏ธ Financial Services
bravoxDudley Land Company๐Ÿ‡บ๐Ÿ‡ธ USOther
chaosโš ๏ธ astranahealth.com๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Healthcare
Deadlockโš ๏ธ idi pharma๐Ÿ‡ช๐Ÿ‡ธ ESโš ๏ธ Healthcare
DeadlockSaber1๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
dragonforceTEXMA International Co., Ltd๐Ÿ‡น๐Ÿ‡ผ TWManufacturing
emperadorImperial Diamond Jewelleryโ€”Retail
exitiumKOIKE Sanso Kogoyo Co. Ltd.๐Ÿ‡ฏ๐Ÿ‡ต JPManufacturing
interlockShalom Christian Academy๐Ÿ‡บ๐Ÿ‡ธ USEducation
Panzerโš ๏ธ Supreme Energy๐Ÿ‡ธ๐Ÿ‡ฌ SGโš ๏ธ Energy
Panzersolutendโ€”Technology
qilinACI Proyectos SAS๐Ÿ‡จ๐Ÿ‡ด COOther
qilinGlenhardie Country Club๐Ÿ‡บ๐Ÿ‡ธ USHospitality
qilinHagiva Yh๐Ÿ‡ฎ๐Ÿ‡ฑ ILOther
qilinLD Constructora๐Ÿ‡จ๐Ÿ‡ฑ CLManufacturing
qilinMelchioni Spa๐Ÿ‡ฎ๐Ÿ‡น ITManufacturing
qilinโš ๏ธ Secretarรญa de Modernizaciรณn e Innovaciรณn๐Ÿ‡ฆ๐Ÿ‡ท ARโš ๏ธ Government
qilinTepcomp๐Ÿ‡ซ๐Ÿ‡ฎ FITechnology
qilinVadeto Group๐Ÿ‡ธ๐Ÿ‡ช SEOther
Redactโš ๏ธ DexCom๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Healthcare (Medical Devices)
rhysidaโš ๏ธ Anne Arundel County๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Government
rhysidaGress Clark Young & Schoepper๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
rhysidaRealManage๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
safepaydwi-bau.de๐Ÿ‡ฉ๐Ÿ‡ช DEManufacturing
safepayhoteldelfinolugano.ch๐Ÿ‡จ๐Ÿ‡ญ CHHospitality
termiteโš ๏ธ iDentalSoft๐Ÿ‡ง๐Ÿ‡ท BRโš ๏ธ Healthcare
thegentlemenโš ๏ธ Royal Thai Air Force๐Ÿ‡น๐Ÿ‡ญ THโš ๏ธ Government / Defence
threeamโš ๏ธ fleetworksinc.com๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Transportation
UmBraHelwan University (HITU)๐Ÿ‡ช๐Ÿ‡ฌ EGEducation
Show Comments