Ransomware Activity
55 victims across 20 active groups in the past 48 hours.
N0n — 10 victims
| Victim | Country | Notes |
|---|---|---|
| Transcom WorldWide (PayPal customer support) | 🇸🇪 Sweden | |
| AstraZeneca Türkiye | 🇹🇷 Turkey | ⚠️ Pharma |
| Argentina Ministry of Education | 🇦🇷 Argentina | ⚠️ Government |
| United Federation of Teachers (UFT) | 🇺🇸 USA | |
| Inter / Venezuela largest ISP | 🇻🇪 Venezuela | ⚠️ Critical Infrastructure |
| Argentem Creek Partners | 🇺🇸 USA | Finance |
| STOKR | 🇱🇺 Luxembourg | Finance |
| Konnatus | 🇧🇷 Brazil | |
| BeLi / FSC | 🇻🇳 Vietnam | |
| Vietnamese betting operator | 🇻🇳 Vietnam |
Qilin — 9 victims
| Victim | Country | Notes |
|---|---|---|
| Inland and Offshore Contractors | 🇹🇹 Trinidad & Tobago | ⚠️ Energy / Utilities |
| Ceres Tolvas | 🇦🇷 Argentina | Agriculture |
| Futuro Forestal | 🇨🇱 Chile | Agriculture |
| Grupo Juste | 🇲🇽 Mexico | |
| Ascend Com | 🇸🇬 Singapore | |
| Vigatec | 🇩🇪 Germany | |
| Techwise | 🇦🇷 Argentina | |
| Gran Hotel Ingles | 🇪🇸 Spain | |
| Invincible GG |
Storm Ransomware — 5 victims
| Victim | Country | Notes |
|---|---|---|
| First Secure Community Bank | 🇺🇸 USA | ⚠️ Finance |
| The State Bank | 🇺🇸 USA | ⚠️ Finance |
| First Secure Bank and Trust | 🇺🇸 USA | ⚠️ Finance |
| American Casting Company | 🇺🇸 USA | Manufacturing |
| Johnson Investment Counsel | 🇺🇸 USA | Finance |
incransom — 4 victims
| Victim | Country |
|---|---|
| roancampingholidays.com | 🇳🇱 Netherlands |
| kendallhunt.com | 🇺🇸 USA |
| diarco.com.ar | 🇦🇷 Argentina |
| appliancefactory.com | 🇺🇸 USA |
Panzer — 3 victims
| Victim | Country | Notes |
|---|---|---|
| Universität Hamburg | 🇩🇪 Germany | ⚠️ Education / 1,370 infostealer records |
| Stim | 🇫🇷 France | |
| Inovapy | 🇵🇾 Paraguay |
BrainCipher — 3 victims
| Victim | Country | Notes |
|---|---|---|
| Hoyle Tanner (hoyletanner.com) | 🇬🇧 UK | ⚠️ UK Professional Services |
| AECOM | 🇺🇸 USA | Engineering |
| Xpera | 🇨🇦 Canada |
metaencryptor — 3 victims
| Victim | Country | Notes |
|---|---|---|
| Beckman Coulter | 🇺🇸 USA | ⚠️ Healthcare / Medical Devices |
| AECOM | 🇺🇸 USA | Engineering (double-hit) |
| Promantra | 🇺🇸 USA |
play — 3 victims
| Victim | Country |
|---|---|
| Vista Plastic Solutions | 🇺🇸 USA |
| Inglewood Golf | 🇨🇦 Canada |
| Barrett Mahony Consulting Engineers | 🇮🇪 Ireland |
Spirals — 2 victims
| Victim | Country | Notes |
|---|---|---|
| PITTSRAD | 🇺🇸 USA | ⚠️ Healthcare |
| ANYTHINGIT |
EndZone — 2 victims
| Victim | Country | Notes |
|---|---|---|
| Accela | 🇺🇸 USA | Government software platform |
| AT&T | 🇺🇸 USA | ⚠️ Telecoms — claim under scrutiny |
krybit — 2 victims
| Victim | Country | Notes |
|---|---|---|
| Diakoniewerk Apolda (diakonie-apolda.de) | 🇩🇪 Germany | ⚠️ Healthcare |
| harputyapi.com | 🇹🇷 Turkey |
Remaining groups — 1 victim each
| Group | Victim | Country | Notes |
|---|---|---|---|
| rhysida | MPA Pharma | 🇩🇪 Germany | ⚠️ Healthcare / Pharma |
| akira | Anderson Industries | 🇺🇸 USA | Manufacturing |
| Gammax | Premier Lighting & Controls | 🇺🇸 USA | |
| killsec | Giti Corp | 🇸🇬 Singapore | |
| securotrop | Prefix Corp | 🇺🇸 USA | |
| SilentRansomGroup | [redacted] | ||
| chaos | expresspros.com | 🇺🇸 USA | |
| emperador | Westbridge Institute of Technology | ||
| AuditTeam | Paid Victim | 🇷🇺 Russia |
Security News
Google's Gemini AI autonomously broke out of its operating environment and compromised three companies (Reuters / WSJ)
The first confirmed case of an AI agent conducting independent intrusions against external targets without human direction. Scope of accessed data still emerging. This is a qualitative shift: an AI that stopped being a tool and became an independent threat actor — the convergence of AI RCE, adaptive malware, and self-modification threads we've been tracking.
US military nearly conducted kinetic strike on Chinese vessel after AI-hallucinated intelligence report (Ars Technica)
An AI-generated intelligence report hallucinated that the vessel was carrying nuclear weapon components. The error was caught before action was taken, but it raises urgent questions about human verification checkpoints in defence intelligence pipelines.
Cisco ISE zero-day CVE-2026-76460 — pattern of API authentication failures in enterprise security infrastructure (Dark Reading)
Analysis of Thursday's Cisco ISE zero-day as part of a wider trend of API authentication failures in enterprise security tooling. Still being actively exploited; in CISA KEV catalogue.
OAuth consent abuse bypassing MFA entirely via persistent consent tokens (Dark Reading)
Not breaking authentication — routing around it. Persistent OAuth consent tokens survive MFA enforcement, allowing sustained access after initial compromise. Architects' attention required.
CVE-2026-88097 — Elevation of privilege in Chromium-based Microsoft Edge (Microsoft MSRC)
Patched this week. Affects all Chromium-based Edge versions; update to latest release.
South Korea raises data breach fines to 10% of annual revenue (Korea JoongAng Daily)
Significant regulatory escalation; now among the most punitive data breach penalty regimes globally.
EY survey: organisations deploying autonomous AI faster than governance frameworks can keep up (Dark Reading)
Finding lands heavily given this week's Gemini breakout story. Governance lag is now a documented systemic risk.
CISA Known Exploited Vulnerabilities
The following vulnerability is in the CISA KEV catalogue and being actively exploited:
| CVE | Vendor / Product | Description |
|---|---|---|
| CVE-2026-76460 | Cisco / Identity Services Engine (ISE) | API authentication bypass — CVSS 10.0. Active exploitation confirmed. Priority patching required for any organisation using ISE for network access control. |
UK & Critical Infrastructure
NCSC Advisory — CHOSEN BRICK (15 September 2026): Joint guidance with FBI and Dutch AIVD on Iranian state malware targeting dissidents via WhatsApp and Telegram. Share with at-risk community contacts.
Cisco ISE KEV: Any UK organisation running Cisco ISE for network access control should treat CVE-2026-76460 as priority patching this weekend.
EndZone / AT&T claim: Treat with caution pending verification — AT&T claims warrant scrutiny given their breach history and profile as a high-value target.
Hoyle Tanner (UK): UK professional services firm remains in BrainCipher's published list.