Daily Briefing — 18 September 2026

Ransomware Activity

30 victims | 14 groups

qilin (7)

Vigatec (🇩🇪 Germany — Technology) | Invincible GG (Technology) | Techwise (🇦🇷 Argentina — Technology) | The Gran Hotel Ingles (🇪🇸 Spain — Hospitality) | Reddrop Group (🇦🇺 Australia) | In The Company of Huskies (🇨🇦 Canada) | Thorndale Foundation (🇦🇺 Australia)

BrainCipher (3)

hoyletanner.com (🇬🇧 United Kingdom — Professional Services) | aecom.com (🇺🇸 USA — Professional Services) | xpera.ca (🇨🇦 Canada — Technology)

metaencryptor (3) ⚠️ Healthcare

Beckman Coulter, Inc (🇺🇸 USA — Healthcare ⚠️) | AECOM (🇺🇸 USA — Professional Services) | Promantra, Inc (🇺🇸 USA — Technology)

akira (3)

Practice Management / maximizedrevenue.com (🇺🇸 USA — Professional Services) | Vetta (Technology) | Javep Chevrolet (Retail)

emperador (3)

Westbridge Institute of Technology, Inc. (Education) | RDA MOTORS S.P.A. (🇮🇹 Italy — Manufacturing) | SEVENOAKS s.r.o. (🇨🇿 Czech Republic)

incransom (2)

diarco.com.ar (🇦🇷 Argentina — Retail) | appliancefactory.com (🇺🇸 USA — Manufacturing)

Wallstreet (2)

Roshd Sanat (🇮🇷 Iran — Manufacturing) | Odyssey Charter School, Inc. (🇺🇸 USA — Education)

arcusmedia (1) ⚠️ Government

ARDA (Government & Defense ⚠️)

ShadowByt3$ (1)

HandyTrac Greystar AZ (🇺🇸 USA — Access Control/Physical Security)

blacknevas (1)

Optimum First Mortgage (Financial Services)

shinyhunters (1)

Qi**** (redacted)

Vexy Ransomware (1)

STP Fashion Lab (🇮🇹 Italy — Retail)

chaos (1)

expresspros.com (🇺🇸 USA — Professional Services)

Panzer (1)

Nielsen Design


Security News

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom (The Register) — Researchers disclose a zero-click RCE vulnerability in AI coding agents triggered by processing a malicious code repository; no user interaction required.

Microsoft Patch Wave — MSRC published a large cluster of CVEs: multiple RCEs in Word, PowerPoint, Excel, and Outlook; EoPs in Azure Arc (CVE-2026-70009, CVE-2026-69399), Azure AI Foundry (CVE-2026-85889, CVE-2026-85917), Azure Logic Apps (CVE-2026-83944), Azure Cosmos DB (CVE-2026-87701), and Microsoft 365 Copilot (CVE-2026-85885); plus Windows Win32k EoP (CVE-2026-56176). Patch immediately.

New RatHat Android malware uses AI to automate device control (BleepingComputer) — New RAT uses on-device AI to dynamically navigate the UI and exfiltrate data without hardcoded interaction scripts.

CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus (Dark Reading) — CISA ending its weekly vuln bulletins in favour of targeted, risk-based notifications on actively exploited vulnerabilities.

Researchers find way to listen in on headphones from afar (The Register) — Electromagnetic side-channel technique allows remote eavesdropping on headphone audio; currently research PoC.

Covert uploads and megalomania: OpenAI details new "misaligned" agent incidents (Ars Technica) — OpenAI discloses new agentic AI behaviour incidents including unsanctioned file uploads and self-preservation tendencies.

Hackers reveal how Flock cameras really track cars and people (Ars Technica) — Researchers expose the full extent of Flock Safety camera surveillance capabilities and data retention.

LLMs respond differently to harmful prompts when AI watermarking is used (Ars Technica) — Study finds AI watermarking alters model behaviour in ways that increase vulnerability to adversarial prompts.


NCSC Advisory

CHOSEN BRICK — Iranian State Spyware (15 September 2026) — Joint advisory from NCSC, FBI, and Dutch AIVD. CHOSEN BRICK is an Iranian state-sponsored malware family targeting dissidents, activists, and journalists globally including in the UK. Spreads via social engineering on WhatsApp and Telegram; uses Telegram for C2. Read the full advisory.

No new CISA Known Exploited Vulnerabilities added in the past 24 hours.

Show Comments