Daily Security Briefing – 21 September 2026

Monday, 21 September 2026. 18 ransomware victims across 11 groups. UK charity breach, North Korean mass-infection campaign, AI industry lawsuit.

Ransomware Activity

18 victims across 11 groups in the last 24 hours. Three healthcare targets, one government entity, one energy sector organisation.

Qilin (4): Zorlu Holding (TR/Manufacturing), ShopDunk (TH/Retail), KMLS (DE), Touring Club Suisse (CH/Transport). Emperador (3): Alabama Woman's Health Care (US/Healthcare ⚠️), Studio Notarile Associato (IT), Cassias Municipal Government (BR/Gov). Orova (2): Siddhi Green Excellence (IN/Energy ⚠️), Euramex Management Group (US). Arcusmedia (2): AKAZZO (BR), Schneider's Computing (CA). INC Ransom (2): Second House (IT), Maryann Kriger (US). ThreeAM (1): Newman Tractor (US). Nightspire (1): Great Bay Bio (HK/Healthcare ⚠️). LockBit 5.0 (1): Siinqee Bank S.C. (ET). Bravox (1): TOWILL (US). Rhysida (1): Kreishandwerkerschaft Borken (DE).


Security News

🇬🇧 RNLI confirms cyberattack — supporters' data stolen (LBC) — Royal National Lifeboat Institution confirms data breach affecting supporter personal information.

North Korean hackers posed as recruiters — 30,000 devices infected (Slashdot) — Lazarus-linked campaign used fake job offers to deploy malware worldwide.

Lawsuit: Anthropic, OpenAI, SpaceX AI, Google allegedly colluded on AI slowdown (Slashdot) — Anti-trust lawsuit claims illegal agreement among major AI labs.

AI chatbots give wrong answers to financial queries 'most of the time' (FT) — Study highlights accuracy failures in AI financial guidance.

ProxyLogon exploit PoC for sale on underground forums — fresh circulation may precede new Exchange attack wave against unpatched organisations.

DCSA (US Defense Counterintelligence and Security Agency) — alleged breach claim, data reportedly for sale. Agency manages security clearances for millions of federal employees.

⚠️ Transener (Argentina) — high-voltage electricity grid blueprints and network documentation leaked. Critical infrastructure exposure.

RedClinica (Chile) — Hospital Clínico Universidad de Chile 120GB data breach, patient and medical records.

Parler — 16.2M user records reportedly for sale.

South Korea NHIS database — National Health Insurance Service data allegedly for sale.

Medusa Network DDoS claim against LG Electronics.


🎧 Listen to today's audio briefing

Show Comments