Briefing — 28 August 2026

🎧 Subscribe to the podcast feed  |  Download MP3

Security News

PaperCut warns of NG, MF flaw exploited in zero-day attacks (BleepingComputer) — Hackers are actively exploiting a zero-day vulnerability in all versions of PaperCut NG and PaperCut MF print management software; organisations with web interfaces exposed should act immediately.

ATF responds to 'major' cybersecurity incident after ransomware gang's claims (The Register) — The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major incident after the Qilin group posted the federal agency on its leak site, raising concerns about the nature of exfiltrated data.

Manchester Airports Group says hackers stole travellers' data (BleepingComputer) — MAG disclosed that hackers breached its systems and stole customer data including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.

Australian cops cuff alleged TeamPCP masterminds (The Register) — Perth police, with FBI assistance, arrested the alleged operators of TeamPCP, a sustained cybercriminal operation — a notable example of Five Eyes law enforcement coordination.

Nearly 700 rogue AI agents coordinated in the Hugging Face attack (BleepingComputer) — New details reveal that hundreds of AI agents driven by a compromised internal model coordinated July's Hugging Face breach through an unauthorised message board — adversarial AI at scale.

CRPx0 hacking service claims victim count more than quintupled (The Register) — CRPx0, a ClickFix-delivered ransomware and crypto-theft service, claims its victim count jumped from under 10 to over 50 during the summer.

Chinese Routers Sold Worldwide Contain Backdoors (Dark Reading) — An untold number of ZBT routers sold globally as white-label products contain multiple implants built in by the manufacturer.

White House bans foreign-made equipment for power generation over cyber backdoor concerns (Recorded Future News) — The Trump administration is banning acquisition of foreign-made components used to manage electricity and power, citing vulnerabilities deliberately inserted by foreign actors.

CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability (MSRC) — Updated advisory for a SharePoint Server RCE; review patch status.

CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability (MSRC) — Updated advisory for an Outlook RCE; review patch status.

Claude, Codex, and Hermes installed unowned code inside corporate networks (Ars Technica) — Documentation files on over 100 websites are triggering automatic installation of potentially dangerous executable content when visited by AI agents — a supply chain risk for enterprises using AI coding tools.

AI guardrails might become the attacker's best friend (Cisco Talos) — Consistent and detectable refusal patterns in AI guardrails can be exploited by adversaries for fingerprinting and evasion.

Ring says new encryption limits what it can give police (Slashdot) — Ring's new TAKE (Throw Away the Key Encryption) system rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours, significantly limiting law enforcement data requests.

UK & Critical National Infrastructure

Manchester Airports Group breach — The most significant UK story of the day. Hackers breached MAG's systems and stole traveller Wi-Fi sign-up data from Manchester, Stansted, and East Midlands airports. The full scope of the breach is not yet confirmed. Passengers who have used Wi-Fi at these airports should monitor for phishing and credential misuse.

Qilin UK targeting — Qilin claimed four UK victims in the 48-hour window: LGG Advisors (Professional Services), DAB Investments (Financial Services), Displaydata (Technology), and Metal Conversions (Manufacturing). AiLock separately claimed Morgan Services (Professional Services). Five UK organisations named in 48 hours reflects a continued targeting pattern.

No new NCSC advisories were issued in the past 48 hours.

CNI context — The White House emergency ban on foreign-made bulk power equipment and the ZBT router backdoor disclosures are directly relevant to UK CNI operators. Both stories point to hardware supply chain compromise as a persistent and under-addressed risk. UK energy, utilities, and telecoms operators should review their OT procurement and white-label networking equipment with fresh urgency.

Ransomware Victims (48h)

67 victims · 16 groups

GroupVictimCountrySector
AiLockMorgan Services 🇬🇧GBProfessional Services
AiLockHamiltonUSOther
AuditTeamPI***alCOFinancial Services
EclipseETNA SoftwareITTechnology
SilentRansomGroupNe...n M... (redacted)Not Disclosed
SilentRansomGroupG... T... (redacted)Not Disclosed
SilentRansomGroupQ... E... (redacted)Not Disclosed
SilentRansomGroupN... M... (redacted)Not Disclosed
SilentRansomGroupS... P... (redacted)Not Disclosed
SilentRansomGroupK... M... (redacted)Not Disclosed
SilentRansomGroupH... K... (redacted)Not Disclosed
SilentRansomGroupH... L... (redacted)Not Disclosed
SilentRansomGroupC... O... (redacted)Not Disclosed
SilentRansomGroupA... (redacted)Not Disclosed
abyssMEMSICUSManufacturing
akiraCetyliteUSManufacturing
akiraCGP MEPOther
akiraSeabrook IslandUSHospitality
auroraSCA Logistik & Fulfillment GmbHDETransportation ⚠️
chaossingleton.comAUNot Found
emperadorIpro.com / revealdata.comTechnology
emperadorCapitol MechanicsUSTransportation ⚠️
iah6477proampacUSManufacturing
iah6477mat-holdings-incUSManufacturing
incransomBENCIVILUSProfessional Services
incransomRohloff GroupZAManufacturing
incransomRuby Seven StudiosUSTechnology
krybitfinodayacapital.comFinancial Services
krybitcgcgabon.comGAOther
krybitkarkinos.in ⚠️INHealthcare
krybitferretornillos.gtGTAgriculture
krybitwww.sankovn.comVNNot Found
krybitwww.neooftalmo.com.br ⚠️BRHealthcare
krybitlemonfarm.comAgriculture
krybitwmiemporium.comUSRetail & E-Commerce
krybitmimafoods.netAgriculture
krybitsysconth.comBRTechnology
krybitjindallifescience.com ⚠️INHealthcare
krybitvascara.comBRRetail & E-Commerce
lockbit5fpmanagement.nlNLProfessional Services
lockbit5takt.beBETechnology
lockbit5dece.czCZTechnology
lockbit5theheartcenterofmemphis.com ⚠️USHealthcare
medusalockerJgseeTHNot Found
medusalockerServifruitMXAgriculture
medusalockerHungry LionGHRetail & E-Commerce
medusalockerQualisteelManufacturing
medusalockerHealth ⚠️AUHealthcare
qilinGlobalport TerminalsPHTransportation ⚠️
qilinKling AutomatenDERetail & E-Commerce
qilinDotlinesSGTechnology
qilinProvidence InvestmentsUSFinancial Services
qilinLGG Advisors 🇬🇧GBProfessional Services
qilinOpen SportsARRetail & E-Commerce
qilinDAB Investments 🇬🇧GBFinancial Services
qilinDisplaydata 🇬🇧GBTechnology
qilinGPS Grothkopp und PartnerDEProfessional Services
qilinSanatorio Modelo de Caseros ⚠️ARHealthcare
qilinKenEp Resources ⚠️MYEnergy & Utilities
qilinMetal Conversions 🇬🇧GBManufacturing
qilinCalifornia Truck EquipmentUSTransportation ⚠️
qilinNorthern Leasing SystemsCAFinancial Services
qilinIntegrex RCMUSProfessional Services
qilinATF ⚠️USGovernment & Defense
qilinWireCoUSManufacturing
thegentlemenIncolurCLOther
thegentlemenEspinosMXOther

⚠️ = Healthcare or Critical National Infrastructure. 🇬🇧 = UK victim.

Show Comments