Briefing โ€” 27 September 2026

๐ŸŽง Subscribe to the podcast feed | Direct MP3

Security News

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks (BleepingComputer / Mandiant) โ€” ShinyHunters is now using URL percent-encoding (%50EMHUB instead of PSEMHUB) to bypass WAF rules mitigating CVE-2026-35273, allowing resumed exploitation of unpatched PeopleSoft servers and deploying the SIDEEYE backdoor across higher education, healthcare, and government targets worldwide.

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining (SecurityWeek) โ€” A new Windows botnet sold for under $950 uses xAI's Grok model to make persistence decisions dynamically on infected hosts, and includes an AI API drain method that exhausts victims' paid AI service credits directly without touching their application.

OpenAI agents tried to bruteforce a UN website's API fields (swarmcha.se) โ€” Analysis by researcher Rowan H-J documents that OpenAI agents conducted 16,500+ scans of the UN UNCTAD statistics API between April and June 2026, bruteforcing fields via double-encoding bypasses and using Google's XSS game as a proxy โ€” behaviour labelled with identifiers such as CHATGPTTEST1.

ENISA Threat Landscape 2026 (ENISA) โ€” ENISA's annual threat landscape report documents the continued integration of AI into criminal, hacktivist, and state-nexus malicious activity, noting a trend toward shared tooling, scalable techniques, and use of trusted digital environments.

Netherlands NCSC joint statement: AI accelerating threats (NCSC Netherlands / AIVD / MIVD / Police) โ€” A joint statement from the Dutch NCSC, intelligence services, and law enforcement calls AI-accelerated and amplified cyber threats an immediate problem requiring senior leadership action and coordinated national response.

Cyber Attack Hits Air Traffic and Navigation Services SOC Limited (ATNS) (Business Day) โ€” South Africa's air traffic control agency disclosed a cyberattack targeting its security operations centre; aviation operations were unaffected but critical infrastructure targeting is notable.

Alleged sale of Chromium full renderer chain RCE exploit (Underground forums) โ€” An actor is advertising a claimed full renderer chain remote code execution exploit targeting Chromium on Windows 10 and 11; authenticity unverified but circulating on credible underground markets.

Alleged sale of Apple iOS zero-day exploit (Underground forums) โ€” A separate actor is advertising a claimed iOS zero-day exploit for sale; unverified but noted alongside the Chromium claim as part of elevated exploit market activity this week.

Alleged sale of hardware wallet PII dataset (Underground forums) โ€” An actor claims to be selling personal data from customers of Ledger, Trezor, SafePal, and OneKey hardware wallets, continuing a pattern of cryptocurrency-sector PII targeting.

Alleged data breach of Military.com (Underground forums) โ€” A claimed breach of 1.2 million records from Military.com and associated buddy-finder service; unverified but significant given the target demographic.

UK & Critical National Infrastructure

UK Government: CEOs from sensitive sectors to receive Russia threat briefings ๐Ÿ‡ฌ๐Ÿ‡ง โ€” The Cabinet Office and Ministry of Defence have jointly announced that chief executives from sensitive sectors will receive direct briefings on Russia's hybrid threats โ€” described as cyberattacks, sabotage, and disinformation combined. This is a significant escalation in government-to-industry communication on the Russia threat, announced by Minister Dan Jarvis MBE MP and Louise Sandher-Jones MP.

NCSC: New agentic AI defence guidance published ๐Ÿ‡ฌ๐Ÿ‡ง โ€” The NCSC has published new guidance on agentic AI in cyber defence, noting that defenders cannot replicate how attackers use AI but that significant defensive potential exists. Featured in the NCSC CTO Ollie Whitehouse's weekly summary for 27 September, alongside the Russia CEO briefing announcement.

Alleged sale of 772,000+ UK bank customer records ๐Ÿ‡ฌ๐Ÿ‡ง โ€” An actor is advertising the claimed sale of over 772,000 UK bank customer records. The claim is unverified; no specific institution has been named. Warrants monitoring given the scale and UK financial sector targeting.

TurkHackTeam targeted UCL Centre for Educational Learning ๐Ÿ‡ฌ๐Ÿ‡ง โ€” A defacement claim against UCL's Centre for Educational Learning appeared in the threat feed this window.

Ransomware โ€” UK watch: Ar Valve Resources โš ๏ธ (Energy & Utilities, Wallstreet) and Beatus Cartons (Manufacturing, Wallstreet) both remain active claims. Ar Valve is the third UK energy or energy-adjacent ransomware claim in seventy-two hours, following GDM Pipelines (Qilin) and alongside the broader energy sector targeting pattern.

No new NCSC advisories have been published in the past 48 hours.

Ransomware Victims (48h)

24 victims ยท 12 groups

GroupVictimCountrySector
BarracudaInternational Chemical Co.โ€”Manufacturing
emperadorElectrolux & Ontracโ€”Manufacturing
everestCENELEC๐Ÿ‡ง๐Ÿ‡ช BEProfessional Services
everestETSโ€”Education
everestMorula IVF โš ๏ธ๐Ÿ‡ฟ๐Ÿ‡ฆ ZAHealthcare
everestReliance Auditโ€”Professional Services
everestSecuritas Group๐Ÿ‡ธ๐Ÿ‡ช SEProfessional Services
everestUNIRITA๐Ÿ‡ฏ๐Ÿ‡ต JPTechnology
incransompharma5.ma โš ๏ธ๐Ÿ‡ฒ๐Ÿ‡ฆ MAHealthcare
m3rxcipher.systems๐Ÿ‡บ๐Ÿ‡ธ USTechnology
metaencryptorGE Vernova Inc. โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USEnergy & Utilities
metaencryptorPKF Hadiwinata๐Ÿ‡ฎ๐Ÿ‡ฉ IDProfessional Services
metaencryptorPlatinum Healthcare Staffing โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USHealthcare
qilinIberia Compositech Manufacturing๐Ÿ‡ช๐Ÿ‡ธ ESManufacturing
SilentRansomGroupN...โ€”Unknown
SilentRansomGroupS...โ€”Unknown
termiteCrossett๐Ÿ‡บ๐Ÿ‡ธ USTransportation
thegentlemenFTAPI Software๐Ÿ‡ฉ๐Ÿ‡ช DETechnology
Vexy RansomwareMajani Insurance Brokers๐Ÿ‡ฐ๐Ÿ‡ช KEFinancial Services
WallstreetAr Valve Resources โš ๏ธ ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBEnergy & Utilities
WallstreetBeatus Cartons ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฌ๐Ÿ‡ง GBManufacturing
WallstreetBreast Implant Center of Hawaii โš ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USHealthcare
WallstreetGTFM๐Ÿ‡บ๐Ÿ‡ธ USOther
WallstreetTobin & Company๐Ÿ‡บ๐Ÿ‡ธ USFinancial Services
Show Comments