🎧 Subscribe to the podcast feed | Direct audio link
Security News
Muse, Meta's AI assistant, has a serious zero-day on launch day (Ars Technica) — A high-severity unpatched flaw discovered in Meta's new AI assistant Muse, just days after mass launch; Zuckerberg had promoted it as security-first.
CISA alerts: 3 Linux kernel flaws actively exploited (BleepingComputer) — One rated critical; attackers are actively exploiting all three — patch immediately.
BigCommerce data breach via Ribon third-party apps (BleepingComputer) — Attacker stole Ribon app credentials and injected malicious scripts into merchant storefronts; supply-chain vector.
Anthropic-linked CVEs pile up — attackers mostly shrug (The Register) — Fewer than 0.5% of AI-research-linked CVEs are seeing active exploitation despite predictions of AI-supercharged attacks.
US proposes AI incident alert system in US-China talks (SecurityWeek) — Bessent confirms proposal for nation-state AI security hotline; AI risk entering strategic arms-control-style dialogue.
Google fined €403M by Ireland DPC over location data (DPC) — Major GDPR enforcement action for unlawful processing of user location data.
TERMITE ransomware resurfaces — Three new victims claimed today: Sealcon, theLender, and TruAmerica Multifamily. After a quiet period, TERMITE appears to be ramping up activity.
Metaencryptor active — Five victims in 48h including Bruker Corporation and Flex Ltd (both major US-listed manufacturers), plus HyVision System (Korea) and Visual Intelligence (US).
inDrive — 39M records leaked — Ride-share platform's Indian user data including phone numbers, addresses, and registration details reportedly leaked on dark web forums.
DubiCars — 7M records (UAE) — Car marketplace breach claim; 7 million records including phone numbers and user data.
UK & Critical National Infrastructure
No new NCSC advisories have been published in the past 48 hours.
The CISA Linux kernel exploitation alert is directly relevant to UK defenders — Linux is foundational to UK CNI across cloud, telecoms, energy, and OT/ICS systems. The three flagged CVEs should be treated as priority patches.
The BigCommerce/Ribon supply chain breach is relevant for UK e-commerce operators. Third-party app credential theft leading to script injection is an increasingly common attack pattern — review all active third-party integrations and their credential hygiene.
The moneymessage claim against US Electrical Services is a reminder that energy utilities remain high-priority ransomware targets. UK energy organisations should maintain heightened vigilance.
Ransomware Victims (48h)
33 victims · 19 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| Doommageddon | Charlottesville Police Department | 🇺🇸 | ⚠️ Government & Defense |
| Emperor | Alabama Woman's Health Care | 🇺🇸 | ⚠️ Healthcare |
| Emperor | Studio Notarile Associato | 🇮🇹 | Professional Services |
| EndZone | Gomomentum.com | — | — |
| Global Secret Group | Allied Supply Co. | — | Manufacturing |
| Global Secret Group | Kjla | 🇺🇸 | — |
| INC Ransom | Second House | 🇪🇸 | Real Estate |
| INC Ransom | Maryann Kriger (Bonita Orthodontics) | 🇺🇸 | ⚠️ Medical Practice (minors' data) |
| krybit | acilnet.com | 🇹🇷 | Technology |
| LockBit 5.0 | Siinqee Bank S.C. | 🇸🇴 | ⚠️ Financial Services |
| metaencryptor | Bruker Corporation | 🇺🇸 | Manufacturing |
| metaencryptor | Flex Ltd | 🇺🇸 | Manufacturing |
| metaencryptor | Hudson MD Group LLC | 🇺🇸 | ⚠️ Healthcare |
| metaencryptor | HyVision System Inc | 🇰🇷 | Technology |
| metaencryptor | Visual Intelligence Inc | 🇺🇸 | Technology |
| moneymessage | US Electrical Services & Wiedenbach Brown | 🇺🇸 | ⚠️ Energy & Utilities |
| nightspire | Spo**** Schools | 🇺🇸 | Education |
| n0n | CS FINSOFT | — | — |
| Qilin | IKEGAMI TSUSHINKI | 🇯🇵 | Manufacturing |
| Qilin | Telrad Networks | 🇮🇱 | Technology |
| Qilin | Zorlu Holding | 🇹🇷 | Manufacturing |
| Qilin | ShopDunk | 🇹🇭 | Retail |
| Qilin | KMLS | 🇩🇪 | — |
| Qilin | Touring Club Suisse | 🇨🇭 | ⚠️ Transport |
| Secp0 | NAI Earle Furman | 🇺🇸 | Financial Services |
| SilentRansomGroup | Hogan Lovells Cadwalader | — | Professional Services |
| Storm | The Money Store | 🇺🇸 | Financial Services |
| Storm | TrueCore Behavioral Solutions | 🇺🇸 | ⚠️ Healthcare |
| Storm | Manroc Developments | 🇨🇦 | Other |
| TERMITE | Sealcon | — | — |
| TERMITE | theLender | — | — |
| TERMITE | TruAmerica Multifamily | — | — |
| thegentlemen | Grupolider | 🇦🇴 | Other |
| ThreeAM | Newman Tractor LLC | 🇺🇸 | Manufacturing |
| Akira | Prestige Management | 🇺🇸 | Professional Services |
| Anubis | Summa Gold | — | Manufacturing |
| Bravox | TOWILL | 🇺🇸 | Technology |
| unsafe | kyyba.com | 🇫🇮 | Technology |
HaveIBeenPwned — New Breaches
| Breach | Date Added | Accounts | Data Exposed |
|---|---|---|---|
| Burger King Russia | 21 Sep 2026 | 3,155,792 | Dates of birth, Email addresses, Genders, Geographic locations, Names |