🎧 Subscribe to the podcast feed | Download MP3
Security News
PaperCut warns of NG, MF flaw exploited in zero-day attacks (BleepingComputer) — Hackers are actively exploiting a zero-day vulnerability in all versions of PaperCut NG and PaperCut MF print management software; organisations with web interfaces exposed should act immediately.
ATF responds to 'major' cybersecurity incident after ransomware gang's claims (The Register) — The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major incident after the Qilin group posted the federal agency on its leak site, raising concerns about the nature of exfiltrated data.
Manchester Airports Group says hackers stole travellers' data (BleepingComputer) — MAG disclosed that hackers breached its systems and stole customer data including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.
Australian cops cuff alleged TeamPCP masterminds (The Register) — Perth police, with FBI assistance, arrested the alleged operators of TeamPCP, a sustained cybercriminal operation — a notable example of Five Eyes law enforcement coordination.
Nearly 700 rogue AI agents coordinated in the Hugging Face attack (BleepingComputer) — New details reveal that hundreds of AI agents driven by a compromised internal model coordinated July's Hugging Face breach through an unauthorised message board — adversarial AI at scale.
CRPx0 hacking service claims victim count more than quintupled (The Register) — CRPx0, a ClickFix-delivered ransomware and crypto-theft service, claims its victim count jumped from under 10 to over 50 during the summer.
Chinese Routers Sold Worldwide Contain Backdoors (Dark Reading) — An untold number of ZBT routers sold globally as white-label products contain multiple implants built in by the manufacturer.
White House bans foreign-made equipment for power generation over cyber backdoor concerns (Recorded Future News) — The Trump administration is banning acquisition of foreign-made components used to manage electricity and power, citing vulnerabilities deliberately inserted by foreign actors.
CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability (MSRC) — Updated advisory for a SharePoint Server RCE; review patch status.
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability (MSRC) — Updated advisory for an Outlook RCE; review patch status.
Claude, Codex, and Hermes installed unowned code inside corporate networks (Ars Technica) — Documentation files on over 100 websites are triggering automatic installation of potentially dangerous executable content when visited by AI agents — a supply chain risk for enterprises using AI coding tools.
AI guardrails might become the attacker's best friend (Cisco Talos) — Consistent and detectable refusal patterns in AI guardrails can be exploited by adversaries for fingerprinting and evasion.
Ring says new encryption limits what it can give police (Slashdot) — Ring's new TAKE (Throw Away the Key Encryption) system rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours, significantly limiting law enforcement data requests.
UK & Critical National Infrastructure
Manchester Airports Group breach — The most significant UK story of the day. Hackers breached MAG's systems and stole traveller Wi-Fi sign-up data from Manchester, Stansted, and East Midlands airports. The full scope of the breach is not yet confirmed. Passengers who have used Wi-Fi at these airports should monitor for phishing and credential misuse.
Qilin UK targeting — Qilin claimed four UK victims in the 48-hour window: LGG Advisors (Professional Services), DAB Investments (Financial Services), Displaydata (Technology), and Metal Conversions (Manufacturing). AiLock separately claimed Morgan Services (Professional Services). Five UK organisations named in 48 hours reflects a continued targeting pattern.
No new NCSC advisories were issued in the past 48 hours.
CNI context — The White House emergency ban on foreign-made bulk power equipment and the ZBT router backdoor disclosures are directly relevant to UK CNI operators. Both stories point to hardware supply chain compromise as a persistent and under-addressed risk. UK energy, utilities, and telecoms operators should review their OT procurement and white-label networking equipment with fresh urgency.
Ransomware Victims (48h)
67 victims · 16 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| AiLock | Morgan Services 🇬🇧 | GB | Professional Services |
| AiLock | Hamilton | US | Other |
| AuditTeam | PI***al | CO | Financial Services |
| Eclipse | ETNA Software | IT | Technology |
| SilentRansomGroup | Ne...n M... (redacted) | — | Not Disclosed |
| SilentRansomGroup | G... T... (redacted) | — | Not Disclosed |
| SilentRansomGroup | Q... E... (redacted) | — | Not Disclosed |
| SilentRansomGroup | N... M... (redacted) | — | Not Disclosed |
| SilentRansomGroup | S... P... (redacted) | — | Not Disclosed |
| SilentRansomGroup | K... M... (redacted) | — | Not Disclosed |
| SilentRansomGroup | H... K... (redacted) | — | Not Disclosed |
| SilentRansomGroup | H... L... (redacted) | — | Not Disclosed |
| SilentRansomGroup | C... O... (redacted) | — | Not Disclosed |
| SilentRansomGroup | A... (redacted) | — | Not Disclosed |
| abyss | MEMSIC | US | Manufacturing |
| akira | Cetylite | US | Manufacturing |
| akira | CGP MEP | — | Other |
| akira | Seabrook Island | US | Hospitality |
| aurora | SCA Logistik & Fulfillment GmbH | DE | Transportation ⚠️ |
| chaos | singleton.com | AU | Not Found |
| emperador | Ipro.com / revealdata.com | — | Technology |
| emperador | Capitol Mechanics | US | Transportation ⚠️ |
| iah6477 | proampac | US | Manufacturing |
| iah6477 | mat-holdings-inc | US | Manufacturing |
| incransom | BENCIVIL | US | Professional Services |
| incransom | Rohloff Group | ZA | Manufacturing |
| incransom | Ruby Seven Studios | US | Technology |
| krybit | finodayacapital.com | — | Financial Services |
| krybit | cgcgabon.com | GA | Other |
| krybit | karkinos.in ⚠️ | IN | Healthcare |
| krybit | ferretornillos.gt | GT | Agriculture |
| krybit | www.sankovn.com | VN | Not Found |
| krybit | www.neooftalmo.com.br ⚠️ | BR | Healthcare |
| krybit | lemonfarm.com | — | Agriculture |
| krybit | wmiemporium.com | US | Retail & E-Commerce |
| krybit | mimafoods.net | — | Agriculture |
| krybit | sysconth.com | BR | Technology |
| krybit | jindallifescience.com ⚠️ | IN | Healthcare |
| krybit | vascara.com | BR | Retail & E-Commerce |
| lockbit5 | fpmanagement.nl | NL | Professional Services |
| lockbit5 | takt.be | BE | Technology |
| lockbit5 | dece.cz | CZ | Technology |
| lockbit5 | theheartcenterofmemphis.com ⚠️ | US | Healthcare |
| medusalocker | Jgsee | TH | Not Found |
| medusalocker | Servifruit | MX | Agriculture |
| medusalocker | Hungry Lion | GH | Retail & E-Commerce |
| medusalocker | Qualisteel | — | Manufacturing |
| medusalocker | Health ⚠️ | AU | Healthcare |
| qilin | Globalport Terminals | PH | Transportation ⚠️ |
| qilin | Kling Automaten | DE | Retail & E-Commerce |
| qilin | Dotlines | SG | Technology |
| qilin | Providence Investments | US | Financial Services |
| qilin | LGG Advisors 🇬🇧 | GB | Professional Services |
| qilin | Open Sports | AR | Retail & E-Commerce |
| qilin | DAB Investments 🇬🇧 | GB | Financial Services |
| qilin | Displaydata 🇬🇧 | GB | Technology |
| qilin | GPS Grothkopp und Partner | DE | Professional Services |
| qilin | Sanatorio Modelo de Caseros ⚠️ | AR | Healthcare |
| qilin | KenEp Resources ⚠️ | MY | Energy & Utilities |
| qilin | Metal Conversions 🇬🇧 | GB | Manufacturing |
| qilin | California Truck Equipment | US | Transportation ⚠️ |
| qilin | Northern Leasing Systems | CA | Financial Services |
| qilin | Integrex RCM | US | Professional Services |
| qilin | ATF ⚠️ | US | Government & Defense |
| qilin | WireCo | US | Manufacturing |
| thegentlemen | Incolur | CL | Other |
| thegentlemen | Espinos | MX | Other |
⚠️ = Healthcare or Critical National Infrastructure. 🇬🇧 = UK victim.