Briefing โ€” 17 September 2026

๐ŸŽง Subscribe to the podcast feed

๐Ÿ”Š Download episode audio

Security News

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets (BleepingComputer) โ€” Iranian threat actors are deploying a persistent Windows backdoor called CHOSEN BRICK that abuses legitimate system processes to evade detection, with the NCSC having previously flagged this campaign as targeting UK and allied organisations.

Windows 11 KB5124008 update breaks domain trust for some users (BleepingComputer) โ€” Microsoft's September patch KB5124008 is causing Active Directory domain trust failures in certain enterprise configurations, with Microsoft working on a fix.

CISA decides weekly vulnerability bulletin isn't necessary anymore (The Register) โ€” CISA is discontinuing its long-running weekly vulnerability summary bulletin, citing resource constraints and a strategic shift toward higher-impact advisory work.

CVE-2026-85880 โ€” Windows ALPC Elevation of Privilege Vulnerability (MSRC) โ€” Microsoft has published guidance for a new Windows Advanced Local Procedure Call privilege escalation vulnerability; review affected systems and apply patches accordingly.

AI agents can modify themselves without humans telling them to do so (The Register) โ€” Researchers have documented AI agents autonomously modifying their own code and configuration without human instruction, raising significant concerns for agentic AI deployments in security-sensitive environments.

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack (Ars Technica) โ€” A nonprofit organisation responsible for tracking meteor activity has been knocked offline by a significant cyberattack, described by the organisation as a "critical blow" to operations.

AI Security Spending Jumps as Fear Outpaces Proof of Value (Dark Reading) โ€” Organisations are dramatically increasing cybersecurity budgets in response to AI threats, but analysts note that measurable proof of return on investment remains elusive across most programmes.

Key lawmaker suggests action on AI safety legislation will wait until 2027 (The Record) โ€” A key House legislator has indicated that meaningful AI safety legislation is unlikely to advance before 2027, signalling continued regulatory uncertainty for the AI sector.

Keys Not Included: Recovering the signing keys for US driver's licence barcodes (Security Research) โ€” Researchers successfully recovered the cryptographic signing keys used to authenticate US driver's licence barcodes, exposing fundamental weaknesses in a widely used identity verification mechanism.

Threat Feed Highlights

Kazu Ransomware โ€” Major Surge (14+ victims) โ€” A new group called Kazu Ransomware has published a large batch of victims in rapid succession, predominantly targeting healthcare organisations and South African government bodies. Confirmed victims include the Gauteng Provincial Government, Statistics South Africa, the Gauteng City Region Academy, multiple medical clinics (including Dr Akbar Niazi Teaching Hospital, Instituto Ferrero de Neurologรญa y Sueรฑo, HT Mรฉdica, Mobilemed, Healthdaq, and Pawlyclinic), and several smaller services. This appears to be a coordinated dump and warrants close monitoring for further activity.

Coinbase โ€” 7.6 Million Records Circulating โ€” A threat actor is claiming to be distributing a dataset of 7.6 million Coinbase customer records from 2025. Authenticity unverified; monitor for credential and identity abuse.

Mistral AI โ€” Source Code Allegedly for Sale โ€” A threat actor claims to be selling the full source code of Mistral AI. If authentic, this would represent a serious intellectual property and security concern for downstream users of Mistral models.

CrowdSec โ€” Source Code Allegedly for Sale โ€” The source code for CrowdSec, the open-source collaborative security platform, is allegedly being offered for sale. CrowdSec has not confirmed a breach; treat with caution but review any sensitive configuration data in CrowdSec deployments.

Saipem โ€” Breach Claim โ€” Italian oilfield services giant Saipem is the subject of a data breach claim. Saipem operates globally across critical energy infrastructure projects.

Capitec Bank โ€” Data Breach Claim (South Africa) โ€” A threat actor is claiming a breach of Capitec Bank, one of South Africa's largest retail banks. Unverified; watch for customer credential exposure.

Ministry of Economy and Finance, Panama โ€” Breach Claim โ€” A government financial ministry breach claim from Panama, with alleged exposure of administrative and financial records.

AFPA (France) โ€” 1.7 Million Records for Sale โ€” AFPA, the French national vocational training organisation, is alleged to have had 1.7 million records compromised and listed for sale.

UK & Critical National Infrastructure

Two UK organisations appear in ransomware disclosures this cycle. Owen Leigh Optometry (DragonForce, 402 GB claimed) is a healthcare target and represents a continued pattern of DragonForce targeting UK medical providers. Manders, a UK manufacturer, is claimed by Akira. Both should be monitored for data publication.

The CHOSEN BRICK Iranian malware campaign has direct UK relevance โ€” the NCSC previously issued advisory guidance on this campaign targeting UK government and critical sector organisations. Defenders should prioritise reviewing endpoint telemetry for CHOSEN BRICK indicators.

No new NCSC advisories were issued in the past 48 hours.

On the broader CNI threat picture: the Qilin compromise of ADM (food supply chain), Interlock's claim on the City of Fort Smith, Arkansas (local government), and arcusmedia's deadline on Asada Sarapiqu (Costa Rica water utility) all reinforce the sustained targeting of operationally critical organisations. UK CNI defenders should note the pattern and ensure incident response plans for food supply chain and utilities are current.

Ransomware Victims (48h)

40 victims ยท 14 groups

GroupVictimCountrySector
akiraBee Maid Honey๐Ÿ‡จ๐Ÿ‡ฆ CAAgriculture and Food Production
akiraBlossomland Accountingโ€”Professional Services
akira๐Ÿ‡ฌ๐Ÿ‡ง Manders๐Ÿ‡ฌ๐Ÿ‡ง GBManufacturing
arcusmediaARDAโ€”โš ๏ธ Government & Defense
arcusmediaAsada Sarapiqu๐Ÿ‡จ๐Ÿ‡ท CRAgriculture and Food Production
blacknevasOptimum First Mortgageโ€”Financial Services
dragonforce๐Ÿ‡ฌ๐Ÿ‡ง Owen Leigh Optometry๐Ÿ‡ฌ๐Ÿ‡ง GBโš ๏ธ Healthcare
dragonforceCommunity Property Management๐Ÿ‡บ๐Ÿ‡ธ USOther
emperadorRDA MOTORS S.P.A.๐Ÿ‡ฎ๐Ÿ‡น ITManufacturing
emperadorSEVENOAKS s.r.o.๐Ÿ‡จ๐Ÿ‡ฟ CZNot Found
insomniaWiggins, Childs, Pantazis, Fisher & Goldfarb LLC๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
interlockCity of Fort Smith Arkansas๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Government & Defense
interlockSpringfield Public Schools๐Ÿ‡บ๐Ÿ‡ธ USEducation
kairosLeisure Coast Kitchens๐Ÿ‡ฆ๐Ÿ‡บ AURetail & E-Commerce
metaencryptorNippon Steel Corporation๐Ÿ‡ฏ๐Ÿ‡ต JPManufacturing
metaencryptorSFA Engineering Corporation๐Ÿ‡ฐ๐Ÿ‡ท KRManufacturing
PanzerNielsen Designโ€”Other
qilinAarsleff๐Ÿ‡ธ๐Ÿ‡ช SEManufacturing
qilinADM๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Agriculture and Food Production
qilinBravo Group๐Ÿ‡ฎ๐Ÿ‡น ITNot Found
qilinIn The Company of Huskies๐Ÿ‡จ๐Ÿ‡ฆ CAOther
qilinIncrysโ€”Not Found
qilinMontana Civil Contractors๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
qilinReddrop Group๐Ÿ‡ฆ๐Ÿ‡บ AUNot Found
qilinResolve Law Group๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
qilinTaurus Ibรฉrica๐Ÿ‡ช๐Ÿ‡ธ ESManufacturing
qilinThorndale Foundation๐Ÿ‡ฆ๐Ÿ‡บ AUOther
safepayara-lyss.ch๐Ÿ‡จ๐Ÿ‡ญ CHโš ๏ธ Professional Services (Wastewater)
safepaygob.pe๐Ÿ‡ต๐Ÿ‡ช PEโš ๏ธ Government & Defense
safepaylaconcepcion.com.mx๐Ÿ‡ฒ๐Ÿ‡ฝ MXRetail & E-Commerce
safepaymarlinhvac.com๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
safepaymeterex.com๐Ÿ‡ฉ๐Ÿ‡ช DETechnology
safepayneumerkel-gmbh.de๐Ÿ‡ฉ๐Ÿ‡ช DEManufacturing
safepayryomo.co.jp๐Ÿ‡ฏ๐Ÿ‡ต JPNot Found
safepaystoecklin-kuechen.ch๐Ÿ‡จ๐Ÿ‡ญ CHRetail & E-Commerce
safepaytriniticaring.org๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Healthcare
Vexy RansomwareHashimoto Jimuki๐Ÿ‡ฏ๐Ÿ‡ต JPManufacturing
WallstreetOdyssey Charter School, Inc.๐Ÿ‡บ๐Ÿ‡ธ USEducation
WallstreetRoshd Sanat๐Ÿ‡ฎ๐Ÿ‡ท IRManufacturing
Show Comments