Briefing โ€” 26 September 2026

๐ŸŽง Subscribe to the podcast feed | Direct MP3

Security News

Kiteworks urges 6-hour server shutdown over potential zero-day attacks (BleepingComputer / The Record) โ€” Secure file-sharing platform Kiteworks told customers worldwide to shut down servers on Saturday after receiving credible threat intelligence from federal intelligence agencies warning of an imminent attack targeting its systems.

Storm-3168: Agentic-driven cloud attacks using compromised service principals (Microsoft Security Blog) โ€” Microsoft Research published analysis of JADEPUFFER/Storm-3168, described as the first documented agentic ransomware: the group uses compromised cloud service principals for automated, AI-driven lateral movement and extortion at scale.

ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' (The Register) โ€” ShinyHunters claims it compromised an FBI-affiliated site to make a statement about protecting its extortion operation, with five days remaining on its current ultimatum to an unnamed victim.

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw (BleepingComputer) โ€” Clop's data leak site was compromised through an unpatched unauthenticated path traversal flaw in Grav CMS; Clop has since migrated to a new Tor address.

Bitget blames North Korea for $387.5M crypto wallet raid (The Register) โ€” Crypto exchange Bitget confirmed a North Korean-attributed attack resulted in $387.5 million stolen; some wallet addresses were frozen but most funds have moved.

CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacks (BleepingComputer) โ€” CISA added CVE-2026-5430, a critical WSO2 authentication bypass, to the Known Exploited Vulnerabilities catalogue alongside SharePoint and Adobe Commerce flaws under active exploitation.

There's a new way to break RSA encryption (Slashdot / Ars Technica) โ€” Researchers published a classical computing RSA signature forgery technique that reduces effective RSA security to an unacceptable threshold, strengthening the case for prompt RSA deprecation.

Google ads caught delivering convincing scareware to unsuspecting users (Ars Technica) โ€” Researchers found Google ads across high-traffic websites delivering tech support scareware that freezes browser screens on Windows and Mac, directing victims to bogus call centre numbers.

Crooks use fake desktop apps to fool HR staff into giving remote access (The Register) โ€” Attackers are distributing fraudulent HR software Windows apps that grant remote access once installed, targeting HR staff who have broad access to employee data.

U.S. Soldier gets 70 months in prison for AT&T, Verizon extortions (Krebs on Security) โ€” A US Army soldier was sentenced to 70 months for hacking AT&T and Verizon and extorting both companies using call metadata from more than 100 million customers.

Labcorp to overhaul data security practices, pay $2.3M fine (The Record) โ€” Labcorp agreed to a $2.3 million settlement and full security overhaul with specific focus on vendor data-sharing controls and third-party risk management.

Elementor WordPress flaw lets attackers create admin accounts (BleepingComputer) โ€” A CSRF vulnerability in the Elementor plugin could allow unauthenticated attackers to create WordPress administrator accounts.

UK & Critical National Infrastructure

Welsh police cyberattack ๐Ÿ‡ฌ๐Ÿ‡ง: Dyfed-Powys Police disclosed a cyberattack disrupting non-emergency systems and potentially compromising staff information โ€” the latest in a pattern of UK law enforcement targeting. (The Record)

UK energy sector โ€” double ransomware hit: Ar Valve Resources (Energy & Utilities, GB) was claimed by Wallstreet in this period, joining GDM Pipelines (Qilin) from yesterday. Two UK energy sector claims in 48 hours represents a notable concentration; both claims remain active and unconfirmed by the organisations.

Revolut ๐Ÿ‡ฌ๐Ÿ‡ง: ImNotAVillain's ransomware claim against Revolut remains live, concurrent with the DriveWealth social engineering breach disclosed yesterday that affected some Revolut customers. No indication of passwords or financial data compromised in the DriveWealth incident.

No new NCSC advisories have been published in the past 48 hours.

Ransomware Victims (48h)

40 victims ยท 16 groups

GroupVictimCountrySector
dragonforceHEC Group๐Ÿ‡น๐Ÿ‡ผ TWOther
emperadorElectrolux & Ontracโ€”Manufacturing
everestCENELEC๐Ÿ‡ง๐Ÿ‡ช BEProfessional Services
everestETSโ€”Education
everestMorula IVF โš ๏ธ๐Ÿ‡ฟ๐Ÿ‡ฆ ZAHealthcare
everestReliance Auditโ€”Professional Services
everestSecuritas Group๐Ÿ‡ธ๐Ÿ‡ช SEProfessional Services
everestUNIRITA๐Ÿ‡ฏ๐Ÿ‡ต JPTechnology
ImNotAVillainRevolut ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBFinancial Services
incransombnlawmacau.com๐Ÿ‡ฒ๐Ÿ‡ด MOProfessional Services
incransomGrupo Caberj๐Ÿ‡ง๐Ÿ‡ท BRManufacturing
incransompharma5.ma โš ๏ธ๐Ÿ‡ฒ๐Ÿ‡ฆ MAHealthcare
incransomukbjja.org ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBOther
incransomwelgenone.com โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USHealthcare
krybitairtanzania.co.tz๐Ÿ‡น๐Ÿ‡ฟ TZTransportation
krybitefada.sa๐Ÿ‡ธ๐Ÿ‡ฆ SAOther
krybitwww.jonesthegrocer.com๐Ÿ‡ฆ๐Ÿ‡บ AURetail
lockbit5corisricambi.it๐Ÿ‡ฎ๐Ÿ‡น ITOther
metaencryptorGE Vernova Inc. โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USEnergy & Utilities
metaencryptorPKF Hadiwinata๐Ÿ‡ฎ๐Ÿ‡ฉ IDProfessional Services
metaencryptorPlatinum Healthcare Staffing โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USHealthcare
N0nTapClicks๐Ÿ‡บ๐Ÿ‡ธ USTechnology
qilinAll Tech Machine & Engineering๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
qilinDao Groupโ€”Other
qilinGDM Pipelines โš ๏ธ ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBEnergy & Utilities
qilinIberia Compositech Manufacturing๐Ÿ‡ช๐Ÿ‡ธ ESManufacturing
qilinInversiones Bolรญvar๐Ÿ‡จ๐Ÿ‡ด COFinancial Services
qilinZig Inge Group๐Ÿ‡ฆ๐Ÿ‡บ AUOther
rhysidaNEAD Pro๐Ÿ‡ฎ๐Ÿ‡น ITProfessional Services
SilentRansomGroupN...โ€”Unknown
SilentRansomGroupS...โ€”Unknown
SpiralsArmada Credit Bureau๐Ÿ‡บ๐Ÿ‡ฌ UGFinancial Services
Vexy RansomwareMajani Insurance Brokers๐Ÿ‡ฐ๐Ÿ‡ช KEFinancial Services
WallstreetAr Valve Resources โš ๏ธ ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBEnergy & Utilities
WallstreetBeatus Cartons ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBManufacturing
WallstreetBreast Implant Center of Hawaii โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USHealthcare
WallstreetCatholic University of El Salvador๐Ÿ‡ธ๐Ÿ‡ป SVEducation
WallstreetGTFM๐Ÿ‡บ๐Ÿ‡ธ USOther
WallstreetPrater & Ridley Attorneys๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
WallstreetTobin & Company๐Ÿ‡บ๐Ÿ‡ธ USFinancial Services

shinyhunters posted a statement update โ€” not a victim listing: claims goals achieved, 5 days remaining, denies financial motivation.

Show Comments