Briefing โ€” 23 September 2026

๐ŸŽง Subscribe to the podcast feed

Security News

CLOSEDQUORUM: Windows malware uses LLMs to autonomously select post-compromise actions (The Register) โ€” New malware queries Google Gemini, DeepSeek, Qwen, and Mistral at runtime to dynamically choose lateral movement, persistence, or exfiltration actions based on the compromised host โ€” the first documented AI-directed adaptive malware.

Microsoft disrupts EvilTokens AI-powered device-code phishing platform (Ars Technica / Dark Reading) โ€” Microsoft seized 50 websites and disabled 150+ domains of a PhaaS operation that used an AI chatbot to guide victims into compromising ~12,000 Microsoft 365 accounts via device-code phishing.

Chinese threat actor exploits ZyXEL switches and WordPress to steal government data (BleepingComputer) โ€” 996 ZyXEL GS1900 managed switches and WordPress installations exploited to extract 18,500+ records from government targets; dual-vendor opportunistic campaign.

Rogue external MFA providers can capture cleartext passwords during login (BleepingComputer) โ€” Researchers demonstrate that privileged access to an identity provider allows registration of a malicious external MFA provider that silently harvests passwords from normal authentication flows.

CVE-2026-85880 Windows SYSTEM privilege escalation exploit for sale โ€” An actor on exploit.in is selling a bundled exploit + dropper framework targeting Windows 10 and 11 privilege escalation to SYSTEM. No public patch status confirmed at time of recording.

Kovo Healthtech Corp breach claim โ€” 2.7 TB including patient records โ€” A threat actor claims to have exfiltrated 2.7 terabytes of data from Kovo Healthtech Corp including financial details, patient records, and customer information.

Fresenius Medical Care breach claim โ€” publication imminent โ€” One of the world's largest kidney dialysis providers is the subject of a breach claim, with the actor stating publication within 2โ€“3 days. Fresenius serves millions of patients globally.

INSS breach claim โ€” 15.92 TB of Israeli national security documents โ€” Threat actors claim to have exfiltrated 15.92 terabytes of material from the Institute for National Security Studies, including strategic papers, internal communications, and conference records.

Investigate Europe GlobะฐLeaks system breach claim โ€” A 6 TB data claim against Investigate Europe reportedly includes their GlobะฐLeaks informant management system, raising direct source confidentiality concerns for cross-border investigative journalism.

'We hacked the FBI': Hackers claim data on all FBI employees (404 Media) โ€” Threat actors claim to hold data on the entire FBI employee roster; scope and verification remain unconfirmed.

Macfinger ClickFix campaign: injected scripts on legitimate websites (SANS ISC) โ€” Analysis of a persistent ClickFix social engineering campaign using malicious scripts injected into legitimate websites to direct users into running malicious commands via fake browser error prompts.

Sweden fines Miljรถdata $183,000 for breach affecting 2.2 million records (BleepingComputer) โ€” Sweden's IMY data protection regulator imposes SEK 1.8 million fine on IT provider Miljรถdata for inadequate security measures leading to a 2.2 million-record breach in August 2025.

LockBit 5.0 victim claim: Taspen Life (Indonesia) โ€” A claim has appeared on what is labelled a LockBit 5.0 dark web site, listing Taspen Life, an Indonesian insurer, with a 14โ€“15 day publication deadline. LockBit variant claims require independent verification.


UK & Critical National Infrastructure

No new NCSC advisories have been issued in the past 48 hours.

CLOSEDQUORUM and UK Windows environments โ€” CLOSEDQUORUM is directly relevant to all UK defenders operating Windows infrastructure. Malware that queries external LLM APIs at runtime to select post-compromise actions creates detection challenges for signature-based and behaviour-rule-based tools. Defenders should consider monitoring for unusual outbound HTTPS traffic to known AI API endpoints from endpoints that should not be making such calls.

SCADA and ICS threat activity โ€” The threat feed today contains two entries of note for UK CNI teams: an alleged unauthorised access to a power monitoring SCADA system; and the active sale of a tool (TRK25 ADVANCED SCADA) explicitly marketed for attacking industrial control systems and HMI interfaces. Neither has confirmed UK impact, but both represent actionable intelligence items for CNI operators in energy, water, and utilities.

Rogue MFA provider technique โ€” UK financial and public sector risk โ€” The rogue external MFA provider attack documented today is particularly relevant to UK financial institutions and public sector entities using federated identity platforms. The technique allows password capture even in environments with ostensibly strong MFA controls, and does not require phishing end users โ€” only privileged access to the identity provider.

Fresenius Medical Care breach โ€” Fresenius operates renal care facilities in the UK. If the breach claim is confirmed and patient data is included, UK GDPR notification obligations and ICO reporting may apply.


Ransomware Victims โ€” 48 Hours (22โ€“23 September 2026)

44 victims ยท 22 groups

GroupVictimCountrySector
akiraCoe Press Equipment๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
akiraDI.C.S.EL. S.R.L.๐Ÿ‡ฎ๐Ÿ‡น ITManufacturing
akiraTDMIโ€”Unknown
anubisSumma Goldโ€”Mining
Booba ProjectGOTTHELF๐Ÿ‡ฒ๐Ÿ‡ฉ MDUnknown
Booba ProjectTulare Western High School๐Ÿ‡บ๐Ÿ‡ธ USEducation
Doommageddonโš ๏ธ Charlottesville Police Department๐Ÿ‡บ๐Ÿ‡ธ USGovernment & Defense
EndZoneโš ๏ธ Gomomentum.com๐Ÿ‡บ๐Ÿ‡ธ USTelecom โ€” 58K users reportedly disconnected
Global Secret GroupAllied Supply Co.๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
Global Secret GroupKjla๐Ÿ‡บ๐Ÿ‡ธ USBroadcasting
kairosKrapf Group๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
metaencryptorAstemo, Ltd.๐Ÿ‡ฏ๐Ÿ‡ต JPManufacturing (80K employees)
metaencryptorBruker Corporation๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
metaencryptorFlex Ltd๐Ÿ‡บ๐Ÿ‡ธ USManufacturing (150K employees)
metaencryptorโš ๏ธ Hudson MD Group, LLC๐Ÿ‡บ๐Ÿ‡ธ USHealthcare โ€” multispecialty medical group
metaencryptorHyVision System. Inc๐Ÿ‡ฐ๐Ÿ‡ท KRTechnology
metaencryptorVisual Intelligence, Inc.๐Ÿ‡บ๐Ÿ‡ธ USTechnology
moneymessageโš ๏ธ U.S. Electrical Services and Wiedenbach Brown๐Ÿ‡บ๐Ÿ‡ธ USEnergy & Utilities
N0nAFRICA-TECH๐Ÿ‡ฒ๐Ÿ‡ฑ MLTechnology
N0nFinSoft (Kolibri retail software)๐Ÿ‡บ๐Ÿ‡ฟ UZRetail & Technology
playHurley๐Ÿ‡บ๐Ÿ‡ธ USOther
playMetallco๐Ÿ‡ณ๐Ÿ‡ด NOManufacturing
qilinColumbus Informatica๐Ÿ‡ฎ๐Ÿ‡น ITTechnology
qilinTelrad Networks๐Ÿ‡ฎ๐Ÿ‡ฑ ILTechnology
qilinTextile City๐Ÿ‡จ๐Ÿ‡ฆ CAManufacturing
qilinThe Fifty/50๐Ÿ‡บ๐Ÿ‡ธ USHospitality
secp0NAI Earle Furman๐Ÿ‡บ๐Ÿ‡ธ USReal Estate
shinyhuntersPSA โ€” READ THIS NOW (Clop leak site)โ€”Extortion of extortionists
SilentRansomGroupB... [redacted]โ€”Unknown
SilentRansomGroupCozen O'Connor๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services (law firm)
SilentRansomGroupHogan Lovells Cadwaladerโ€”Professional Services (phantom entity per ransomware.live)
SilentRansomGroupW... [redacted]โ€”Unknown
StormManroc Developments๐Ÿ‡จ๐Ÿ‡ฆ CAMining
StormThe Money Store๐Ÿ‡บ๐Ÿ‡ธ USFinancial Services
Stormโš ๏ธ TrueCore Behavioral Solutions๐Ÿ‡บ๐Ÿ‡ธ USHealthcare โ€” mental health, at-risk youth
termiteSealcon๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
termitetheLender๐Ÿ‡บ๐Ÿ‡ธ USFinancial Services
termiteTruAmerica Multifamily๐Ÿ‡บ๐Ÿ‡ธ USReal Estate
thegentlemenGrupolider๐Ÿ‡ฆ๐Ÿ‡ด AOAgriculture / Logistics
threeamnewmantractor.com๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
titanโš ๏ธ Grupo Hospifar S.R.L.๐Ÿ‡ฆ๐Ÿ‡ท ARHealthcare
titanโš ๏ธ Sherman Chan, DDS, Inc.โ€”Healthcare โ€” dental practice
unsafekyyba.com๐Ÿ‡ซ๐Ÿ‡ฎ FITechnology
AuditTeamPr***IT๐Ÿ‡ฎ๐Ÿ‡น ITProfessional Services

HaveIBeenPwned โ€” New Breaches

BreachDate AddedAccountsData Exposed
LimeLeads (B2B lead generation service)22 Sep 202617,838,396Email addresses, Employers, Geographic locations, Job titles
Show Comments