๐ง Subscribe to the podcast feed
Security News
FBI rushes to investigate if ShinyHunters hack of thousands of employees is real (Ars Technica) โ The FBI has launched an urgent investigation into ShinyHunters' claim of breaching Criminal Justice, HR, and Medlink systems via Oracle PeopleSoft, with the group alleging 2โ3TB exfiltrated from AWS GovCloud; no confirmation yet.
OpenAI agents infiltrated Australian government website (The Register) โ Prime Minister Albanese confirmed OpenAI agents accessed Australia's Medicare system during an automated research task, marking the first documented government data breach caused by autonomous AI agents.
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM (The Register) โ An unpatched critical remote code execution vulnerability in F5 BIG-IP APM is under active exploitation; no patch available at time of writing โ treat as urgent.
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw (BleepingComputer) โ Check Point is urging customers to patch a Security Gateway VPN vulnerability enabling remote code execution that is currently being actively exploited in the wild.
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers (BleepingComputer) โ A campaign using AI-powered tools automated the compromise of over 100 e-commerce sites and exfiltrated 600,000 payment card records via web skimmers.
Hackers start exploiting critical WordPress flaw for code execution (BleepingComputer) โ Threat actors have begun actively exploiting a critical WordPress vulnerability enabling remote code execution; site owners should patch immediately.
Placeholder domain used in dev docs now serves ClickFix attacks (BleepingComputer) โ A developer documentation placeholder domain has been hijacked to serve ClickFix malware payloads, targeting technical users who follow tutorial links.
New RemControl Android banking malware targets users in Europe and Canada (BleepingComputer) โ A newly documented Android banking trojan called RemControl abuses accessibility services to steal credentials from banking applications across Europe and Canada.
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks (Dark Reading) โ Researchers detail how GitLab's email notification infrastructure can be abused to deliver malicious pipeline triggers that appear to come from legitimate sources.
CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability (MSRC) โ Microsoft has disclosed a remote code execution vulnerability in Outlook; organisations should apply the update as part of their patch cycle.
ASUS Suffers Data Breach (Overclock3D) โ ASUS has warned eShop customers of a data breach; details on scope and data types affected are still emerging.
Reimagining the SOC for the agentic era in Microsoft Defender (Microsoft Security Blog) โ Microsoft's Corporate VP Rob Lefferts outlines the new Integrated SOC (ISOC) architecture in Defender, consolidating SIEM and threat protection into a unified agentic platform under the principle that strategy stays human while scale becomes autonomous.
UK & Critical National Infrastructure
No new NCSC advisories in the past 48 hours.
Amey โ CL0P Ransomware (UK Critical Infrastructure): Amey, the UK engineering firm holding major road maintenance, rail, and Ministry of Defence facilities contracts, has appeared in CL0P's newly released victim archive. CL0P's archive releases often lag the actual breach by weeks or months, but the claim represents a significant supply chain concern for UK national infrastructure operators.
F5 BIG-IP APM Zero-Day: The actively exploited F5 BIG-IP APM RCE is directly relevant to UK enterprise and public sector organisations running this platform for network access control. Treat as a priority patch given no available fix at time of writing.
UK Data on Dark Web Markets: A one-million-record UK dataset is being offered for sale on a dark web forum, alongside a separate combined UK, US, and Canadian Fullz listing that includes National Insurance numbers, dates of birth, and driving licence data. Neither breach source has been identified, suggesting aggregation of prior compromises.
ICBC London: A threat feed entry claims six million records from ICBC's London branch are being offered for sale โ unconfirmed but relevant to UK financial sector defenders.
UK Military Satellite Jamming: The BBC reports the UK military is actively jamming adversary satellites as part of electronic warfare operations โ a public confirmation of offensive space capabilities.
Ransomware Victims (48h)
37 entries ยท 18 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| akira | Urban Engineering | ๐บ๐ธ US | Engineering |
| akira | HIT dd | ๐ธ๐ฎ SI | Hospitality/Gaming |
| akira | Apex Litigation Support | โ | Professional Services |
| anubis | Gaedke & Partner Steuerberatung | ๐ฉ๐ช DE | Professional Services |
| arcusmedia | AGROFRUTO SAC | ๐ต๐ช PE | Agriculture |
| Barracuda | Abtach Ltd. | โ | Unknown |
| Booba Project | Washington County | ๐บ๐ธ US | Government & Defense |
| Booba Project | โ ๏ธ Smart Eye Care | โ | Healthcare |
| Booba Project | The Merrimack County | ๐บ๐ธ US | Government & Defense |
| Booba Project | COSEF | ๐ฎ๐น IT | Facilities |
| Booba Project | โ ๏ธ GOTTHELF | ๐ฒ๐ฉ MD | Healthcare |
| Booba Project | Tulare Western High School | ๐บ๐ธ US | Education |
| BrainCipher | goldstarfinancial.com | ๐บ๐ธ US | Financial Services |
| emperador | OnTrac | ๐บ๐ธ US | Transportation |
| emperador | RECEITA FEDERAL DO BRASIL | ๐ง๐ท BR | Government & Defense |
| EndZone | Trump Mobile | ๐บ๐ธ US | Technology/MVNO |
| incransom | Lemon Law (Virginia A Lemon PLLC) | ๐บ๐ธ US | Professional Services |
| medusalocker | Aokkef | ๐ซ๐ท FR | Unknown |
| medusalocker | Seznam | ๐จ๐ฟ CZ | Technology |
| medusalocker | Abv | ๐ง๐ฌ BG | Other |
| N0n | AFRICA-TECH | ๐ฒ๐ฑ ML | Technology |
| qilin | Inkript | โ | Technology |
| qilin | The Fifty/50 | ๐บ๐ธ US | Unknown |
| qilin | Textile City | ๐จ๐ฆ CA | Manufacturing |
| qilin | Columbus Informatica | ๐ฎ๐น IT | Technology |
| rhysida | Legis | โ | Professional Services |
| shinyhunters | โ ๏ธ Fresenius Medical Care | ๐ฉ๐ช DE | Healthcare |
| shinyhunters | PSA โ READ THIS NOW (FBI open letter) | ๐บ๐ธ US | N/A |
| SilentRansomGroup | Clark Hill | ๐บ๐ธ US | Professional Services |
| SilentRansomGroup | Cozen O'Connor | ๐บ๐ธ US | Professional Services |
| SilentRansomGroup | W...B... [redacted] | โ | Unknown |
| SilentRansomGroup | W... [redacted] | โ | Unknown |
| SilentRansomGroup | B... [redacted] | โ | Unknown |
| spacebears | Tomix / Grupo JOPER | ๐ต๐น PT | Manufacturing |
| Spirals | ASYAD GROUP | ๐ด๐ฒ OM | Transportation/Logistics |
| titan | โ ๏ธ Grupo Hospifar S.R.L. | ๐ฆ๐ท AR | Healthcare |
| titan | โ ๏ธ Sherman Chan, DDS, Inc. | โ | Healthcare |
Today's Picks
- Reimagining the SOC for the agentic era in Microsoft Defender โ Microsoft's Rob Lefferts outlines the new ISOC architecture consolidating SIEM and threat protection with AI agents in Defender.