Briefing β€” 25 September 2026

🎧 Subscribe to the podcast feed

Security News

Crook used three open-source AI agents to breach Fortune 500 hospitality company, major US airline and 25+ orgs (The Register) β€” A threat actor chained three publicly available agentic AI frameworks to compromise over 25 organisations with no custom tooling or nation-state resources.

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability (SecurityWeek) β€” As autonomous agents carry out intrusions without direct human control, legal frameworks struggle to assign liability to operators, developers, or victims.

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing (Dark Reading) β€” Researchers demonstrate that Salesforce AI agents can be manipulated to send phishing messages to Slack users, expanding the enterprise attack surface.

MacSync malware uses public iCloud calendars to deliver new payloads (BleepingComputer) β€” A newly documented macOS threat abuses iCloud calendar events as a covert C2 channel, bypassing traditional email-based detection.

SectopRAT Returns, Hiding Inside a Legitimate Application (Dark Reading) β€” The infostealer resurfaces with a new delivery mechanism, embedding itself within a legitimate application to evade detection.

Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges (The Record) β€” The Department of Justice alleges a forensics contractor with federal security clearances concealed its Russian connections, raising supply-chain integrity concerns.

Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks (The Record) β€” US legislators propose a voluntary cybersecurity standards framework for telecoms in response to the Salt Typhoon intrusions that affected multiple major carriers.

CVE-2026-69282 β€” Microsoft SharePoint Remote Code Execution (MSRC) β€” A critical RCE vulnerability in Microsoft Office SharePoint requiring prompt patching across enterprise environments.

CVE-2026-68894 β€” Windows Error Reporting Elevation of Privilege (MSRC) β€” A privilege escalation flaw in Windows Error Reporting that could allow local attackers to gain elevated system access.

Sourcehut account takeover via build logs (XSS in ansi2html) (Hacker News) β€” An XSS vulnerability in the ANSI-to-HTML converter used in Sourcehut build logs enabled full account takeover β€” relevant to any CI/CD pipeline processing third-party output.

DriveWealth Suffers Data Breach Affecting Revolut Customers (Finextra) β€” DriveWealth, which provides brokerage infrastructure for Revolut's investment products, has disclosed a breach impacting Revolut customer data β€” coinciding with a ransomware claim against Revolut itself.

UK & Critical National Infrastructure

⚠️ GDM Pipelines (UK) β€” Qilin ransomware claim. A UK energy and utilities firm listed in the 48-hour ransomware window. Energy pipelines infrastructure sits at the core of CNI; the scope of any compromise is unconfirmed but warrants monitoring.

⚠️ Revolut (UK) β€” ImNotAVillain ransomware claim. Revolut, headquartered in the UK and serving tens of millions of customers globally, has been listed by the group ImNotAVillain. This coincides with the separate DriveWealth breach affecting Revolut's investment product customers. Two concurrent exposure events around the same brand in the same window.

ukbjja.org (UK) β€” The UK Brazilian Jiu-Jitsu Association listed by incransom.

Telecom security legislation (US/global relevance): US lawmakers have introduced a bill for voluntary telecom cyber standards following Salt Typhoon. UK telecoms face equivalent exposure from state-affiliated intrusions; the legislative debate in Washington sets a precedent that DSIT and NCSC will be watching.

No new NCSC advisories in the past 48 hours.

Ransomware Victims (48h)

45 victims Β· 18 groups

GroupVictimCountrySector
akiraStrack CompaniesUSManufacturing
akiraWallatecβ€”Other
arcusmediaAGROFRUTO SACPEAgriculture and Food Production
BarracudaAbtach Ltd.β€”Not Found
BarracudaSolucioning S.A.AROther
Booba ProjectCOSEF - Consorzio di Sviluppo Economico del FriuliITOther
Booba Project⚠️ Smart Eye Careβ€”Healthcare
Booba ProjectThe Merrimack CountyUSGovernment & Defense
Booba ProjectWashington CountyUSGovernment & Defense
BrainCiphergoldstarfinancial.comUSFinancial Services
dragonforce⚠️ Arizona Vascular Medical Equipment, IncUSHealthcare
dragonforceBMGP GroupeFROther
dragonforceElite Industech Co., LtdTHManufacturing
dragonforceHEC GroupTWOther
emperadorOnTracUSTransportation
emperadorRECEITA FEDERAL DO BRASILBRGovernment & Defense
EndZoneeTeamβ€”Professional Services
EndZoneTrump MobileUSTechnology
ImNotAVillainItalyITGovernment & Defense
ImNotAVillain⚠️ πŸ‡¬πŸ‡§ RevolutGBFinancial Services
incransombnlawmacau.com / bn-ip.comMOProfessional Services
incransomGrupo CaberjBRManufacturing
incransomLemon LawUSProfessional Services
incransomπŸ‡¬πŸ‡§ ukbjja.orgGBNot Found
incransom⚠️ welgenone.comUSHealthcare
krybitairtanzania.co.tzTZTransportation
krybitefada.saSAOther
krybitjonesthegrocer.comAURetail & E-Commerce
medusalockerAbvBGOther
medusalockerAokkefFRNot Found
medusalockerSeznamCZTechnology
qilinAgora coopΓ©rative agricoleFRAgriculture and Food Production
qilinAll Tech Machine & EngineeringUSManufacturing
qilinDao Groupβ€”Other
qilin⚠️ πŸ‡¬πŸ‡§ GDM PipelinesGBEnergy & Utilities
qilinInkriptβ€”Technology
qilinInversiones BolΓ­varCOFinancial Services
qilinZig Inge GroupAUNot Found
rhysidaLegisβ€”Professional Services
rhysidaNEAD Proβ€”Not Found
shinyhuntersFinal statement re PSAβ€”Not Found
spacebearsTomix / Grupo JOPERPTManufacturing
SpiralsASYAD GROUPOMTransportation
WallstreetCatholic University of El SalvadorSVEducation
WallstreetPrater & Ridley Attorneys At LawUSProfessional Services

Today's Picks

Show Comments