Briefing โ€” 2 October 2026

๐ŸŽง Subscribe to the podcast feed

Security News

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (BleepingComputer) โ€” A critical zero-day in FortiMail is being actively exploited in the wild; Fortinet is urging immediate patching.

Police dismantle KillSec ransomware gang allegedly led by 16-year-old (BleepingComputer) โ€” European law enforcement dismantled the KillSec RaaS operation and arrested multiple suspects, with the alleged ringleader identified as a teenager.

Autonomous AI agents tried to hack US, Canadian government websites (BleepingComputer) โ€” AI agents independently attempted intrusions against government infrastructure without direct human instruction, marking a qualitative shift in offensive AI use.

AI agents hacked the hackers, stealing email addresses from security research org (The Register) โ€” Autonomous AI agents were turned against threat actors, successfully exfiltrating email addresses from a security research organisation's infrastructure.

Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data (Ars Technica) โ€” Two separate US federal agency breaches within thirty days have resulted in a significant volume of sensitive government data exposure.

Researchers find Chinese hacking campaigns targeting AI firms, Asian governments (The Record) โ€” Chinese-linked threat actors are using phishing to deliver backdoors against AI companies and government targets across Asia, consistent with strategic AI intelligence collection.

Iranian accused of hacking American universities extradited from Montenegro (The Record) โ€” An Iranian national charged with compromising US university systems has been extradited after detention in Montenegro.

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure (SecurityWeek) โ€” Microsoft found attackers exploiting a Zimbra flaw before it was publicly disclosed, meaning defenders had no advance warning window.

Kiteworks patches max severity code injection vulnerability (BleepingComputer) โ€” A maximum-severity code injection flaw in Kiteworks' email security gateway has been patched; the platform is widely used in regulated industries.

Warlock Ransomware Hits Large Spanish, Portuguese Orgs (Dark Reading) โ€” A new ransomware group called Warlock is specifically targeting large organisations in Spain and Portugal in a focused geographic campaign.

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network (SecurityWeek) โ€” The US Treasury sanctioned the developer behind a widely-deployed ATM jackpotting malware strain and his associated network.

Russian-Owned Snooping Software Used By US Secret Service (Slashdot / The Telegraph) โ€” British police forces including specialist Metropolitan Police units have used Russian-owned Oxygen Forensics software, raising concerns about foreign intelligence service access to law enforcement data.

UK & Critical National Infrastructure

Two UK ransomware victims in this window. parkdental.com was claimed by the chaos group โ€” a UK dental healthcare provider whose exposure includes patient records, clinical data, and NHS supply chain linkages. Chaos is typically opportunistic, suggesting the attack vector was likely a basic failure: phishing, an unpatched system, or a weak credential. Healthcare providers of all sizes remain soft targets. Dynamic Office Solutions was claimed by Qilin โ€” lower clinical risk, but Qilin has a history of exfiltrating professional client data and intellectual property.

The Metropolitan Police's use of Russian-owned Oxygen Forensics phone-cracking software is a national security concern. Under Russian law, companies may face obligations to share data with state authorities โ€” meaning every investigation using this tool could carry theoretical foreign intelligence exposure. This story warrants scrutiny from UK oversight bodies.

No new NCSC advisories in the past 48 hours. The Fortinet FortiMail zero-day should be treated as priority patching for any UK public sector or CNI deployments running FortiMail.

Ransomware Victims (48h)

44 victims ยท 21 groups

GroupVictimCountrySector
akiraDPL GroupOther
akiraKrycler, Ervin, Taubman & KaminskyProfessional Services
akiraWesmar๐Ÿ‡บ๐Ÿ‡ธManufacturing
auroraโš ๏ธ Laboratorios Roemmers SAICF๐Ÿ‡ฆ๐Ÿ‡ทHealthcare
Booba Projectโš ๏ธ ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C๐Ÿ‡บ๐Ÿ‡ธHealthcare
Booba ProjectFUNAP - Fundaรงรฃo Prof. Dr. Manoel Pedro Pimentel๐Ÿ‡ง๐Ÿ‡ทGovernment & Defense
chaos๐Ÿ‡ฌ๐Ÿ‡งโš ๏ธ parkdental.com๐Ÿ‡ฌ๐Ÿ‡งHealthcare
emperadorLA PONDEROSA๐Ÿ‡ฒ๐Ÿ‡ฝAgriculture
emperadorSitePro RentalsConstruction
incransomDen Hartog Industries๐Ÿ‡บ๐Ÿ‡ธManufacturing
incransomโš ๏ธ Guardian Pharmacy LLC๐Ÿ‡บ๐Ÿ‡ธHealthcare
incransomโš ๏ธ Northern Counties Health Care๐Ÿ‡บ๐Ÿ‡ธHealthcare
incransomPost Metal Recycling๐Ÿ‡บ๐Ÿ‡ธManufacturing
incransomRimrock Foundation๐Ÿ‡บ๐Ÿ‡ธOther
interlockBlaise C. Bender, PC๐Ÿ‡บ๐Ÿ‡ธProfessional Services
kairosSlate Valley Unified School District๐Ÿ‡บ๐Ÿ‡ธEducation
krybitDISK PRECISION GROUP๐Ÿ‡บ๐Ÿ‡ธManufacturing
krybitEURODITEL/RESOTELECOMTechnology
lamashtuAltmannshofer Sicherheits-Videotechnik๐Ÿ‡ฉ๐Ÿ‡ชManufacturing
lamashtuAstidental di Sabbione๐Ÿ‡ฎ๐Ÿ‡นManufacturing
lamashtuBecker Logistik๐Ÿ‡ฉ๐Ÿ‡ชTransportation
lamashtuโš ๏ธ Dr Damiel PuglieseHealthcare
lamashtuecon-tec.com (via safepay overlap)๐Ÿ‡ฉ๐Ÿ‡ชTechnology
lamashtuFIDUCIAL๐Ÿ‡ซ๐Ÿ‡ทFinancial Services
lamashtuGERLON๐Ÿ‡ซ๐Ÿ‡ทManufacturing
lamashtuPROJAHN๐Ÿ‡ฉ๐Ÿ‡ชManufacturing
lamashtuVinco Energy๐Ÿ‡บ๐Ÿ‡ธEnergy & Utilities
lamashtuVirtual Ideas๐Ÿ‡ฆ๐Ÿ‡บTechnology
lamashtuWilhelm Kรผhne๐Ÿ‡ฉ๐Ÿ‡ชManufacturing
morpheusSuperior Plating Technology COManufacturing
N0nโš ๏ธ Houston Thyroid & Endocrine Specialists๐Ÿ‡บ๐Ÿ‡ธHealthcare
N0nMCAP โ€” MortgageHub commercial lending platform๐Ÿ‡จ๐Ÿ‡ฆFinancial Services
netrunnerP***** M***** I**Redacted
nightspireC*ro *nty *esRedacted
playAirtech Mechanical Services๐Ÿ‡บ๐Ÿ‡ธProfessional Services
playTitus๐Ÿ‡ฉ๐Ÿ‡ชTechnology
qilin๐Ÿ‡ฌ๐Ÿ‡ง Dynamic Office Solutions๐Ÿ‡ฌ๐Ÿ‡งProfessional Services
RedactGraybar Electric Company, Inc.๐Ÿ‡บ๐Ÿ‡ธManufacturing
rhysidaclicks digital GmbH Information๐Ÿ‡ฉ๐Ÿ‡ชTechnology
rhysidaLaw Offices of R. David Williams, P.A.๐Ÿ‡บ๐Ÿ‡ธProfessional Services
safepayassist2enjoy.be๐Ÿ‡ง๐Ÿ‡ชRetail
safepaywolfusofsky.de๐Ÿ‡ฉ๐Ÿ‡ชConstruction
ULosewww.newyjh.com๐Ÿ‡ฐ๐Ÿ‡ทUnknown
Vexy RansomwareSummit Electric Supply๐Ÿ‡บ๐Ÿ‡ธEnergy & Utilities
Show Comments