๐ง Subscribe to the podcast feed
Security News
CLOSEDQUORUM: Windows malware uses LLMs to autonomously select post-compromise actions (The Register) โ New malware queries Google Gemini, DeepSeek, Qwen, and Mistral at runtime to dynamically choose lateral movement, persistence, or exfiltration actions based on the compromised host โ the first documented AI-directed adaptive malware.
Microsoft disrupts EvilTokens AI-powered device-code phishing platform (Ars Technica / Dark Reading) โ Microsoft seized 50 websites and disabled 150+ domains of a PhaaS operation that used an AI chatbot to guide victims into compromising ~12,000 Microsoft 365 accounts via device-code phishing.
Chinese threat actor exploits ZyXEL switches and WordPress to steal government data (BleepingComputer) โ 996 ZyXEL GS1900 managed switches and WordPress installations exploited to extract 18,500+ records from government targets; dual-vendor opportunistic campaign.
Rogue external MFA providers can capture cleartext passwords during login (BleepingComputer) โ Researchers demonstrate that privileged access to an identity provider allows registration of a malicious external MFA provider that silently harvests passwords from normal authentication flows.
CVE-2026-85880 Windows SYSTEM privilege escalation exploit for sale โ An actor on exploit.in is selling a bundled exploit + dropper framework targeting Windows 10 and 11 privilege escalation to SYSTEM. No public patch status confirmed at time of recording.
Kovo Healthtech Corp breach claim โ 2.7 TB including patient records โ A threat actor claims to have exfiltrated 2.7 terabytes of data from Kovo Healthtech Corp including financial details, patient records, and customer information.
Fresenius Medical Care breach claim โ publication imminent โ One of the world's largest kidney dialysis providers is the subject of a breach claim, with the actor stating publication within 2โ3 days. Fresenius serves millions of patients globally.
INSS breach claim โ 15.92 TB of Israeli national security documents โ Threat actors claim to have exfiltrated 15.92 terabytes of material from the Institute for National Security Studies, including strategic papers, internal communications, and conference records.
Investigate Europe GlobะฐLeaks system breach claim โ A 6 TB data claim against Investigate Europe reportedly includes their GlobะฐLeaks informant management system, raising direct source confidentiality concerns for cross-border investigative journalism.
'We hacked the FBI': Hackers claim data on all FBI employees (404 Media) โ Threat actors claim to hold data on the entire FBI employee roster; scope and verification remain unconfirmed.
Macfinger ClickFix campaign: injected scripts on legitimate websites (SANS ISC) โ Analysis of a persistent ClickFix social engineering campaign using malicious scripts injected into legitimate websites to direct users into running malicious commands via fake browser error prompts.
Sweden fines Miljรถdata $183,000 for breach affecting 2.2 million records (BleepingComputer) โ Sweden's IMY data protection regulator imposes SEK 1.8 million fine on IT provider Miljรถdata for inadequate security measures leading to a 2.2 million-record breach in August 2025.
LockBit 5.0 victim claim: Taspen Life (Indonesia) โ A claim has appeared on what is labelled a LockBit 5.0 dark web site, listing Taspen Life, an Indonesian insurer, with a 14โ15 day publication deadline. LockBit variant claims require independent verification.
UK & Critical National Infrastructure
No new NCSC advisories have been issued in the past 48 hours.
CLOSEDQUORUM and UK Windows environments โ CLOSEDQUORUM is directly relevant to all UK defenders operating Windows infrastructure. Malware that queries external LLM APIs at runtime to select post-compromise actions creates detection challenges for signature-based and behaviour-rule-based tools. Defenders should consider monitoring for unusual outbound HTTPS traffic to known AI API endpoints from endpoints that should not be making such calls.
SCADA and ICS threat activity โ The threat feed today contains two entries of note for UK CNI teams: an alleged unauthorised access to a power monitoring SCADA system; and the active sale of a tool (TRK25 ADVANCED SCADA) explicitly marketed for attacking industrial control systems and HMI interfaces. Neither has confirmed UK impact, but both represent actionable intelligence items for CNI operators in energy, water, and utilities.
Rogue MFA provider technique โ UK financial and public sector risk โ The rogue external MFA provider attack documented today is particularly relevant to UK financial institutions and public sector entities using federated identity platforms. The technique allows password capture even in environments with ostensibly strong MFA controls, and does not require phishing end users โ only privileged access to the identity provider.
Fresenius Medical Care breach โ Fresenius operates renal care facilities in the UK. If the breach claim is confirmed and patient data is included, UK GDPR notification obligations and ICO reporting may apply.
Ransomware Victims โ 48 Hours (22โ23 September 2026)
44 victims ยท 22 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| akira | Coe Press Equipment | ๐บ๐ธ US | Manufacturing |
| akira | DI.C.S.EL. S.R.L. | ๐ฎ๐น IT | Manufacturing |
| akira | TDMI | โ | Unknown |
| anubis | Summa Gold | โ | Mining |
| Booba Project | GOTTHELF | ๐ฒ๐ฉ MD | Unknown |
| Booba Project | Tulare Western High School | ๐บ๐ธ US | Education |
| Doommageddon | โ ๏ธ Charlottesville Police Department | ๐บ๐ธ US | Government & Defense |
| EndZone | โ ๏ธ Gomomentum.com | ๐บ๐ธ US | Telecom โ 58K users reportedly disconnected |
| Global Secret Group | Allied Supply Co. | ๐บ๐ธ US | Manufacturing |
| Global Secret Group | Kjla | ๐บ๐ธ US | Broadcasting |
| kairos | Krapf Group | ๐บ๐ธ US | Manufacturing |
| metaencryptor | Astemo, Ltd. | ๐ฏ๐ต JP | Manufacturing (80K employees) |
| metaencryptor | Bruker Corporation | ๐บ๐ธ US | Manufacturing |
| metaencryptor | Flex Ltd | ๐บ๐ธ US | Manufacturing (150K employees) |
| metaencryptor | โ ๏ธ Hudson MD Group, LLC | ๐บ๐ธ US | Healthcare โ multispecialty medical group |
| metaencryptor | HyVision System. Inc | ๐ฐ๐ท KR | Technology |
| metaencryptor | Visual Intelligence, Inc. | ๐บ๐ธ US | Technology |
| moneymessage | โ ๏ธ U.S. Electrical Services and Wiedenbach Brown | ๐บ๐ธ US | Energy & Utilities |
| N0n | AFRICA-TECH | ๐ฒ๐ฑ ML | Technology |
| N0n | FinSoft (Kolibri retail software) | ๐บ๐ฟ UZ | Retail & Technology |
| play | Hurley | ๐บ๐ธ US | Other |
| play | Metallco | ๐ณ๐ด NO | Manufacturing |
| qilin | Columbus Informatica | ๐ฎ๐น IT | Technology |
| qilin | Telrad Networks | ๐ฎ๐ฑ IL | Technology |
| qilin | Textile City | ๐จ๐ฆ CA | Manufacturing |
| qilin | The Fifty/50 | ๐บ๐ธ US | Hospitality |
| secp0 | NAI Earle Furman | ๐บ๐ธ US | Real Estate |
| shinyhunters | PSA โ READ THIS NOW (Clop leak site) | โ | Extortion of extortionists |
| SilentRansomGroup | B... [redacted] | โ | Unknown |
| SilentRansomGroup | Cozen O'Connor | ๐บ๐ธ US | Professional Services (law firm) |
| SilentRansomGroup | Hogan Lovells Cadwalader | โ | Professional Services (phantom entity per ransomware.live) |
| SilentRansomGroup | W... [redacted] | โ | Unknown |
| Storm | Manroc Developments | ๐จ๐ฆ CA | Mining |
| Storm | The Money Store | ๐บ๐ธ US | Financial Services |
| Storm | โ ๏ธ TrueCore Behavioral Solutions | ๐บ๐ธ US | Healthcare โ mental health, at-risk youth |
| termite | Sealcon | ๐บ๐ธ US | Manufacturing |
| termite | theLender | ๐บ๐ธ US | Financial Services |
| termite | TruAmerica Multifamily | ๐บ๐ธ US | Real Estate |
| thegentlemen | Grupolider | ๐ฆ๐ด AO | Agriculture / Logistics |
| threeam | newmantractor.com | ๐บ๐ธ US | Manufacturing |
| titan | โ ๏ธ Grupo Hospifar S.R.L. | ๐ฆ๐ท AR | Healthcare |
| titan | โ ๏ธ Sherman Chan, DDS, Inc. | โ | Healthcare โ dental practice |
| unsafe | kyyba.com | ๐ซ๐ฎ FI | Technology |
| AuditTeam | Pr***IT | ๐ฎ๐น IT | Professional Services |
HaveIBeenPwned โ New Breaches
| Breach | Date Added | Accounts | Data Exposed |
|---|---|---|---|
| LimeLeads (B2B lead generation service) | 22 Sep 2026 | 17,838,396 | Email addresses, Employers, Geographic locations, Job titles |