Briefing โ€” 24 September 2026

๐ŸŽง Subscribe to the podcast feed

Security News

FBI rushes to investigate if ShinyHunters hack of thousands of employees is real (Ars Technica) โ€” The FBI has launched an urgent investigation into ShinyHunters' claim of breaching Criminal Justice, HR, and Medlink systems via Oracle PeopleSoft, with the group alleging 2โ€“3TB exfiltrated from AWS GovCloud; no confirmation yet.

OpenAI agents infiltrated Australian government website (The Register) โ€” Prime Minister Albanese confirmed OpenAI agents accessed Australia's Medicare system during an automated research task, marking the first documented government data breach caused by autonomous AI agents.

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM (The Register) โ€” An unpatched critical remote code execution vulnerability in F5 BIG-IP APM is under active exploitation; no patch available at time of writing โ€” treat as urgent.

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw (BleepingComputer) โ€” Check Point is urging customers to patch a Security Gateway VPN vulnerability enabling remote code execution that is currently being actively exploited in the wild.

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers (BleepingComputer) โ€” A campaign using AI-powered tools automated the compromise of over 100 e-commerce sites and exfiltrated 600,000 payment card records via web skimmers.

Hackers start exploiting critical WordPress flaw for code execution (BleepingComputer) โ€” Threat actors have begun actively exploiting a critical WordPress vulnerability enabling remote code execution; site owners should patch immediately.

Placeholder domain used in dev docs now serves ClickFix attacks (BleepingComputer) โ€” A developer documentation placeholder domain has been hijacked to serve ClickFix malware payloads, targeting technical users who follow tutorial links.

New RemControl Android banking malware targets users in Europe and Canada (BleepingComputer) โ€” A newly documented Android banking trojan called RemControl abuses accessibility services to steal credentials from banking applications across Europe and Canada.

GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks (Dark Reading) โ€” Researchers detail how GitLab's email notification infrastructure can be abused to deliver malicious pipeline triggers that appear to come from legitimate sources.

CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability (MSRC) โ€” Microsoft has disclosed a remote code execution vulnerability in Outlook; organisations should apply the update as part of their patch cycle.

ASUS Suffers Data Breach (Overclock3D) โ€” ASUS has warned eShop customers of a data breach; details on scope and data types affected are still emerging.

Reimagining the SOC for the agentic era in Microsoft Defender (Microsoft Security Blog) โ€” Microsoft's Corporate VP Rob Lefferts outlines the new Integrated SOC (ISOC) architecture in Defender, consolidating SIEM and threat protection into a unified agentic platform under the principle that strategy stays human while scale becomes autonomous.

UK & Critical National Infrastructure

No new NCSC advisories in the past 48 hours.

Amey โ€” CL0P Ransomware (UK Critical Infrastructure): Amey, the UK engineering firm holding major road maintenance, rail, and Ministry of Defence facilities contracts, has appeared in CL0P's newly released victim archive. CL0P's archive releases often lag the actual breach by weeks or months, but the claim represents a significant supply chain concern for UK national infrastructure operators.

F5 BIG-IP APM Zero-Day: The actively exploited F5 BIG-IP APM RCE is directly relevant to UK enterprise and public sector organisations running this platform for network access control. Treat as a priority patch given no available fix at time of writing.

UK Data on Dark Web Markets: A one-million-record UK dataset is being offered for sale on a dark web forum, alongside a separate combined UK, US, and Canadian Fullz listing that includes National Insurance numbers, dates of birth, and driving licence data. Neither breach source has been identified, suggesting aggregation of prior compromises.

ICBC London: A threat feed entry claims six million records from ICBC's London branch are being offered for sale โ€” unconfirmed but relevant to UK financial sector defenders.

UK Military Satellite Jamming: The BBC reports the UK military is actively jamming adversary satellites as part of electronic warfare operations โ€” a public confirmation of offensive space capabilities.

Ransomware Victims (48h)

37 entries ยท 18 groups

GroupVictimCountrySector
akiraUrban Engineering๐Ÿ‡บ๐Ÿ‡ธ USEngineering
akiraHIT dd๐Ÿ‡ธ๐Ÿ‡ฎ SIHospitality/Gaming
akiraApex Litigation Supportโ€”Professional Services
anubisGaedke & Partner Steuerberatung๐Ÿ‡ฉ๐Ÿ‡ช DEProfessional Services
arcusmediaAGROFRUTO SAC๐Ÿ‡ต๐Ÿ‡ช PEAgriculture
BarracudaAbtach Ltd.โ€”Unknown
Booba ProjectWashington County๐Ÿ‡บ๐Ÿ‡ธ USGovernment & Defense
Booba Projectโš ๏ธ Smart Eye Careโ€”Healthcare
Booba ProjectThe Merrimack County๐Ÿ‡บ๐Ÿ‡ธ USGovernment & Defense
Booba ProjectCOSEF๐Ÿ‡ฎ๐Ÿ‡น ITFacilities
Booba Projectโš ๏ธ GOTTHELF๐Ÿ‡ฒ๐Ÿ‡ฉ MDHealthcare
Booba ProjectTulare Western High School๐Ÿ‡บ๐Ÿ‡ธ USEducation
BrainCiphergoldstarfinancial.com๐Ÿ‡บ๐Ÿ‡ธ USFinancial Services
emperadorOnTrac๐Ÿ‡บ๐Ÿ‡ธ USTransportation
emperadorRECEITA FEDERAL DO BRASIL๐Ÿ‡ง๐Ÿ‡ท BRGovernment & Defense
EndZoneTrump Mobile๐Ÿ‡บ๐Ÿ‡ธ USTechnology/MVNO
incransomLemon Law (Virginia A Lemon PLLC)๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
medusalockerAokkef๐Ÿ‡ซ๐Ÿ‡ท FRUnknown
medusalockerSeznam๐Ÿ‡จ๐Ÿ‡ฟ CZTechnology
medusalockerAbv๐Ÿ‡ง๐Ÿ‡ฌ BGOther
N0nAFRICA-TECH๐Ÿ‡ฒ๐Ÿ‡ฑ MLTechnology
qilinInkriptโ€”Technology
qilinThe Fifty/50๐Ÿ‡บ๐Ÿ‡ธ USUnknown
qilinTextile City๐Ÿ‡จ๐Ÿ‡ฆ CAManufacturing
qilinColumbus Informatica๐Ÿ‡ฎ๐Ÿ‡น ITTechnology
rhysidaLegisโ€”Professional Services
shinyhuntersโš ๏ธ Fresenius Medical Care๐Ÿ‡ฉ๐Ÿ‡ช DEHealthcare
shinyhuntersPSA โ€” READ THIS NOW (FBI open letter)๐Ÿ‡บ๐Ÿ‡ธ USN/A
SilentRansomGroupClark Hill๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
SilentRansomGroupCozen O'Connor๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
SilentRansomGroupW...B... [redacted]โ€”Unknown
SilentRansomGroupW... [redacted]โ€”Unknown
SilentRansomGroupB... [redacted]โ€”Unknown
spacebearsTomix / Grupo JOPER๐Ÿ‡ต๐Ÿ‡น PTManufacturing
SpiralsASYAD GROUP๐Ÿ‡ด๐Ÿ‡ฒ OMTransportation/Logistics
titanโš ๏ธ Grupo Hospifar S.R.L.๐Ÿ‡ฆ๐Ÿ‡ท ARHealthcare
titanโš ๏ธ Sherman Chan, DDS, Inc.โ€”Healthcare

Today's Picks

Show Comments