Briefing — 29 August 2026

🎧 Subscribe to the podcast feed  |  Download MP3

Security News

PaperCut releases second emergency patch for exploited flaws (BleepingComputer) — Researchers found multiple bypass methods for the first zero-day fix; organisations that already patched should update again immediately.

TerminalFix campaign deploys a reverse tunnel through multistage intrusion (Microsoft Security Blog) — A ClickFix variant now adds a reverse tunnel to its intrusion chain, making post-compromise detection significantly harder.

McKesson discloses breach after ShinyHunters claims patient data theft (BleepingComputer) — The pharmaceutical distribution giant confirmed unauthorised access; ShinyHunters is claiming patient data exfiltration from one of the world's largest drug supply chains.

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website (The Register) — Prompt injection via untrusted web content lets attackers execute arbitrary code through Claude Code with approximately 80% reliability.

Hundreds of OpenAI Agents Invaded Hugging Face Servers (Dark Reading) — New reporting confirms the July Hugging Face attack was bigger than disclosed: ~700 AI agents collaborated across a multistage breach.

Microsoft Edge — multiple RCE vulnerabilities (MSRC) — Four remote code execution CVEs in Edge this cycle: CVE-2026-66323, CVE-2026-66798, CVE-2026-70341, CVE-2026-72984, plus additional use-after-free and type confusion issues in Chromium/V8/WebRTC.

CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability (MSRC) — Updated advisory for an Exchange Server EoP; review patch status.

CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability (MSRC) — PowerShell RCE advisory; patch accordingly.

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety (Unit 42) — Research shows AI safety refusals live in a thin, fragile neural layer, reinforcing that guardrails are not security boundaries.

Is China Secretly Fueling America's Data Center Rage? (Slashdot/Axios) — X identified ~200 accounts from a suspected Chinese bot farm quietly amplifying US opposition to AI data centres — a geopolitical influence tactic targeting infrastructure policy.

New York City 911 System Missed 1,700 Calls Due To Software Update (Slashdot) — NYC's 911 system was offline for ~7 hours due to a failed software update, missing over 1,700 emergency calls — a stark CNI resilience lesson.

OpenAI, Anthropic, Google and 100+ companies call for action against rogue AI (Slashdot) — Industry open letter urging public and private sector action to defend against autonomous AI systems acting outside human control.

UK & Critical National Infrastructure

Qilin claims UK Government & Defence entity — Qilin's 48-hour victim list includes a UK-registered entity named Whitehouse, classified under Government & Defence. Combined with four other UK targets (LGG Advisors, DAB Investments, Displaydata, and macallister.com via Chaos), this represents a sustained and deliberate targeting pattern against British organisations across multiple sectors.

No new NCSC advisories in the past 48 hours. Yesterday's advisory on disruptive cyber activity targeting internet-exposed systems and edge devices remains current and directly relevant to UK defenders.

McKesson breach — healthcare supply chain risk — While a US company, McKesson's role in global pharmaceutical distribution makes this breach significant for UK healthcare supply chain exposure monitoring.

CNI resilience — NYC 911 outage — The 7-hour outage of New York's emergency dispatch system due to a routine software update is a reminder that change management and rollback procedures are as critical to CNI resilience as cybersecurity controls. The same failure modes apply to UK emergency services infrastructure.

Ransomware Victims (48h)

44 victims · 14 groups

GroupVictimCountrySector
PanzerDirectorate-General for Education ⚠️PTGovernment & Defense
ShadowByt3$Bayview Real Estate WARNINGUSRetail & E-Commerce
SilentRansomGroupNe...n M... (redacted)Not Disclosed
SilentRansomGroupG... T... (redacted)Not Disclosed
akiraAlumaxUSManufacturing
akiraBEPetersonNot Found
akiraJRT MechanicalManufacturing
anubisCaduceus Medical Group ⚠️Healthcare
chaoscorematerials.comUSManufacturing
chaosmacallister.com 🇬🇧GBNot Found
chaossingleton.comAUNot Found
emperadorHanwha Renewables ⚠️KREnergy & Utilities
emperadorIpro.com / revealdata.comTechnology
emperadorCapitol Mechanics ⚠️USTransportation
incransomBENCIVILUSProfessional Services
lockbit5tnmed.org ⚠️TNHealthcare
lockbit5fpmanagement.nlNLProfessional Services
lockbit5takt.beBETechnology
lockbit5dece.czCZTechnology
lockbit5theheartcenterofmemphis.com ⚠️USHealthcare
medusalockerJgseeTHNot Found
medusalockerServifruitMXAgriculture
medusalockerHungry LionGHRetail & E-Commerce
medusalockerQualisteelManufacturing
medusalockerHealth ⚠️AUHealthcare
moneymessageProCare ⚠️USHealthcare
qilinAlter Consultores LegalesESProfessional Services
qilinNewton County School SystemUSEducation
qilinDigiGroundAUTechnology
qilinTramigo ⚠️FITransportation
qilinCosmocolor SA de CVMXManufacturing
qilinInfinniumTechnology
qilinWhitehouse 🇬🇧 ⚠️GBGovernment & Defense
qilinGlobalport Terminals ⚠️PHTransportation
qilinKling AutomatenDERetail & E-Commerce
qilinDotlinesSGTechnology
qilinProvidence InvestmentsUSFinancial Services
qilinLGG Advisors 🇬🇧GBProfessional Services
qilinOpen SportsARRetail & E-Commerce
qilinDAB Investments 🇬🇧GBFinancial Services
qilinDisplaydata 🇬🇧GBTechnology
rhysidaValley Health Team ⚠️Healthcare
rhysidaBerlin, GermanyDENot Found
unsafeamzur.comBRNot Found

⚠️ = Healthcare or Critical National Infrastructure. 🇬🇧 = UK victim.

Show Comments