Daily Security Briefing – 22 September 2026

🎧 Subscribe to the podcast feed  |  Direct audio link

Security News

Muse, Meta's AI assistant, has a serious zero-day on launch day (Ars Technica) — A high-severity unpatched flaw discovered in Meta's new AI assistant Muse, just days after mass launch; Zuckerberg had promoted it as security-first.

CISA alerts: 3 Linux kernel flaws actively exploited (BleepingComputer) — One rated critical; attackers are actively exploiting all three — patch immediately.

BigCommerce data breach via Ribon third-party apps (BleepingComputer) — Attacker stole Ribon app credentials and injected malicious scripts into merchant storefronts; supply-chain vector.

Anthropic-linked CVEs pile up — attackers mostly shrug (The Register) — Fewer than 0.5% of AI-research-linked CVEs are seeing active exploitation despite predictions of AI-supercharged attacks.

US proposes AI incident alert system in US-China talks (SecurityWeek) — Bessent confirms proposal for nation-state AI security hotline; AI risk entering strategic arms-control-style dialogue.

Google fined €403M by Ireland DPC over location data (DPC) — Major GDPR enforcement action for unlawful processing of user location data.

TERMITE ransomware resurfaces — Three new victims claimed today: Sealcon, theLender, and TruAmerica Multifamily. After a quiet period, TERMITE appears to be ramping up activity.

Metaencryptor active — Five victims in 48h including Bruker Corporation and Flex Ltd (both major US-listed manufacturers), plus HyVision System (Korea) and Visual Intelligence (US).

inDrive — 39M records leaked — Ride-share platform's Indian user data including phone numbers, addresses, and registration details reportedly leaked on dark web forums.

DubiCars — 7M records (UAE) — Car marketplace breach claim; 7 million records including phone numbers and user data.

UK & Critical National Infrastructure

No new NCSC advisories have been published in the past 48 hours.

The CISA Linux kernel exploitation alert is directly relevant to UK defenders — Linux is foundational to UK CNI across cloud, telecoms, energy, and OT/ICS systems. The three flagged CVEs should be treated as priority patches.

The BigCommerce/Ribon supply chain breach is relevant for UK e-commerce operators. Third-party app credential theft leading to script injection is an increasingly common attack pattern — review all active third-party integrations and their credential hygiene.

The moneymessage claim against US Electrical Services is a reminder that energy utilities remain high-priority ransomware targets. UK energy organisations should maintain heightened vigilance.

Ransomware Victims (48h)

33 victims · 19 groups

GroupVictimCountrySector
DoommageddonCharlottesville Police Department🇺🇸⚠️ Government & Defense
EmperorAlabama Woman's Health Care🇺🇸⚠️ Healthcare
EmperorStudio Notarile Associato🇮🇹Professional Services
EndZoneGomomentum.com
Global Secret GroupAllied Supply Co.Manufacturing
Global Secret GroupKjla🇺🇸
INC RansomSecond House🇪🇸Real Estate
INC RansomMaryann Kriger (Bonita Orthodontics)🇺🇸⚠️ Medical Practice (minors' data)
krybitacilnet.com🇹🇷Technology
LockBit 5.0Siinqee Bank S.C.🇸🇴⚠️ Financial Services
metaencryptorBruker Corporation🇺🇸Manufacturing
metaencryptorFlex Ltd🇺🇸Manufacturing
metaencryptorHudson MD Group LLC🇺🇸⚠️ Healthcare
metaencryptorHyVision System Inc🇰🇷Technology
metaencryptorVisual Intelligence Inc🇺🇸Technology
moneymessageUS Electrical Services & Wiedenbach Brown🇺🇸⚠️ Energy & Utilities
nightspireSpo**** Schools🇺🇸Education
n0nCS FINSOFT
QilinIKEGAMI TSUSHINKI🇯🇵Manufacturing
QilinTelrad Networks🇮🇱Technology
QilinZorlu Holding🇹🇷Manufacturing
QilinShopDunk🇹🇭Retail
QilinKMLS🇩🇪
QilinTouring Club Suisse🇨🇭⚠️ Transport
Secp0NAI Earle Furman🇺🇸Financial Services
SilentRansomGroupHogan Lovells CadwaladerProfessional Services
StormThe Money Store🇺🇸Financial Services
StormTrueCore Behavioral Solutions🇺🇸⚠️ Healthcare
StormManroc Developments🇨🇦Other
TERMITESealcon
TERMITEtheLender
TERMITETruAmerica Multifamily
thegentlemenGrupolider🇦🇴Other
ThreeAMNewman Tractor LLC🇺🇸Manufacturing
AkiraPrestige Management🇺🇸Professional Services
AnubisSumma GoldManufacturing
BravoxTOWILL🇺🇸Technology
unsafekyyba.com🇫🇮Technology

HaveIBeenPwned — New Breaches

BreachDate AddedAccountsData Exposed
Burger King Russia21 Sep 20263,155,792Dates of birth, Email addresses, Genders, Geographic locations, Names
Show Comments