Briefing — 20 September 2026

Audio not available for this episode — ElevenLabs quota exhausted. Full transcript below. Resets 2 October 2026.

🎧 Subscribe to the podcast feed

Security News

ShinyHunters hacks Clop's leak site, threatens to extort the gang (BleepingComputer) — The extortion group turned its own techniques against one of ransomware's biggest names; Clop's data leak infrastructure has been compromised by a rival actor.

BragJack: malicious browser extensions hijack AI browser agents (BleepingComputer) — Proof-of-concept from researcher Gal Weizman (Forever Security) shows how extensions can intercept and redirect AI agent sessions in enterprise browser deployments.

WaterPlum (North Korea) confirmed: 30,000 devices, 100+ countries, $10M stolen (BleepingComputer) — Joint advisory confirms fake AI/blockchain recruiter personas tricking job applicants into running malware during technical interviews.

Noon (Egypt) breach claim — 40 million records (Threat Feed) — Threat actor claims to have obtained 40M records from the Egyptian e-commerce platform on 19 September; unverified but significant if confirmed.

Pakistan NADRA national identity database — 900GB claimed (Threat Feed) — Full identity records from Pakistan's national registration authority being offered on darknet forums; scale and sensitivity make this a critical watch item.

Agentic security: the billion-dollar challenge nobody has solved yet (The Register) — Analysis piece on the gap between AI agent deployment velocity and the security controls to govern them; timely after Gemini breakout and BragJack this week.

Electrolux hit by EMPERADOR ransomware — 41GB claimed (Threat Feed) — The Swedish appliance manufacturer joins EMPERADOR's victim list; 41GB exfiltration claimed, publication within 2–3 days.

N0n adds Fanatics Inc (Threat Feed) — Sports merchandise company added to N0n's growing claim list; publication within 2–3 days.

UBS Securities — 800,000 records breach claimed (Threat Feed) — Unverified claim on a darknet forum; data reportedly includes personally identifiable financial records.

PS5 Linux project abandoned after Sony patches AI-discovered exploit (Slashdot) — Sony patched the vulnerability before it could be widely used; notable as an early example of AI-assisted vulnerability discovery affecting consumer hardware.

Saint-Joseph & Marie-Lannelongue Hospitals breach — 15,000 records (Threat Feed) — French hospital group data including patient records allegedly leaked; healthcare sector continues to face persistent targeting.

Alleged compromise of Colombian Telmex telecommunications infrastructure (Threat Feed) — Threat actor claims access to Telmex Colombia's telecom systems; no independent verification.


UK & Critical National Infrastructure

EY employee data [UK] — A threat actor claims to have compromised an Ernst & Young cybersecurity employee's data and is offering it for sale. Targeted employee compromise at a major professional services firm; the profile of the victim (cybersecurity role) elevates the risk beyond the data volume.

UK boat/yacht store customer records — Approximately 4,000+ customer records from an unidentified UK marine retailer being sold via a darknet forum. Low volume, but illustrates the breadth of targeting against UK SMEs.

NCSC CTO Weekly — week ending 20 September 2026 (Substack): Key themes from Ollie Whitehouse's weekly summary:

  • Edge device targeting continues — operationally the dominant theme this fortnight; the NCSC has published updated guidance on digital forensics and protective monitoring specifications for network device vendors.
  • Iranian spyware exposure — UK, US, and Dutch AIVD joint advisory (CHOSEN BRICK) on Iranian state actors targeting dissidents, activists, and journalists via WhatsApp and Telegram. Still the active NCSC advisory.
  • Cyber Adversary Simulation (CyAS) scheme — NCSC's new assured scheme for adversary simulation providers is now open; scheme documents published.
  • GOV.UK One Login passkeys — Passkeys rolling out to 23 million users across UK government services; significant step for public sector authentication security.
  • UK cyber resilience — Outgoing DSIT Deputy Director reflects on remaining gaps, including the opportunity to align regulations with EU counterparts to reduce compliance overhead.

No new NCSC advisories were published in the past 48 hours. CHOSEN BRICK (15 September 2026) remains the active advisory.

CNI targeting: Qilin's claim against Inland and Offshore Contractors (Trinidad & Tobago, energy/utilities) and N0n's active compromise of Inter, Venezuela's largest ISP, are the most significant CNI hits in the current window. UK energy and telecoms operators should treat the ongoing N0n surge as an active threat reference.


Ransomware Victims (48h)

39 victims · 17 groups

GroupVictimCountrySector
N0nInter (Venezuela's largest internet provider)🇻🇪 Venezuela⚠️ Telecoms / CNI
N0nPayPal support operations (Transcom WorldWide)🇸🇪 SwedenFinancial Services
N0nMinistry of Education — Argentina🇦🇷 Argentina⚠️ Government
N0nAstraZeneca Türkiye🇹🇷 Turkey⚠️ Healthcare / Pharma
N0nArgentem Creek Partners🇺🇸 USAFinancial Services
N0nSTOKR (digital securities platform)🇱🇺 LuxembourgFinancial Services
N0nUnited Federation of Teachers🇺🇸 USAEducation
N0nKonnatus (usucapião legal services)🇧🇷 BrazilProfessional Services
N0nBeLi Teacher / FSC education centers🇻🇳 VietnamEducation
N0nVietnamese betting operator (GC789 / Boundless TE)🇻🇳 VietnamOther
qilinInland and Offshore Contractors🇹🇹 Trinidad & Tobago⚠️ Energy & Utilities
qilinAscend Com🇸🇬 SingaporeTechnology
qilinCeres Tolvas🇦🇷 ArgentinaAgriculture
qilinFuturo Forestal🇨🇱 ChileAgriculture
qilinGrupo Juste🇲🇽 MexicoOther
playVista Plastic Solutions🇨🇦 CanadaManufacturing
playInglewood Golf🇨🇦 CanadaHospitality
playBarrett Mahony Consulting Engineers🇮🇪 IrelandProfessional Services
rhysidaMPA Pharma🇩🇪 Germany⚠️ Healthcare / Pharma
rhysidaKreishandwerkerschaft Borken🇩🇪 GermanyProfessional Services
emperadorElectrolux🇸🇪 SwedenManufacturing
emperadorCassias MG Government🇧🇷 Brazil⚠️ Government
EndZoneAccela🇺🇸 USAGovernment / Software
EndZoneAT&T🇺🇸 USA⚠️ Telecoms
SpiralsPITTSRAD🇺🇸 USA⚠️ Healthcare / Radiology
SpiralsANYTHINGITTechnology
incransomroancampingholidays.com🇳🇱 NetherlandsHospitality
incransomkendallhunt.com🇺🇸 USAEducation
arcusmediaSchneider's Computing🇨🇦 CanadaTechnology
arcusmediaAKAZZO🇧🇷 Brazil
AuditTeamtd***up (redacted)🇮🇹 Italy
AuditTeamPaid Victim 192EB2B6AD7B98D9🇷🇺 Russia
anubisQuest Group🇺🇸 USAStaffing
PanzerK3G Solutions Brazil🇧🇷 BrazilTelecoms / IT
GammaxPremier Lighting & Controls🇺🇸 USAManufacturing
Vexy RansomwareQuy Nhon University🇻🇳 VietnamEducation
lockbit5forus.cl🇨🇱 ChileProfessional Services
unsafevoltgames.ioTechnology
cry0Young Injury Law🇺🇸 USAProfessional Services
Show Comments