Briefing โ€” 4 September 2026

๐ŸŽง Subscribe to the podcast feed

Security News

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register) โ€” A working proof-of-concept exploit for CrowdStrike Falcon has been published by a well-known vulnerability researcher; given Falcon's kernel-level privileges, this is a high-priority exposure for enterprise environments.

Coder's registry infrastructure compromised to push malicious modules (BleepingComputer) โ€” Attackers compromised the Coder package registry to distribute malicious modules, continuing the trend of supply chain attacks targeting developer tooling and build pipelines.

ASCII smuggling crosses over from AI prompt injection to phishing evasion (Microsoft Security Blog) โ€” A technique originally developed for AI prompt injection โ€” using invisible Unicode characters to hide instructions โ€” has been adapted for phishing campaigns that bypass email security filters.

Large group of Serbian opposition, activist figures targeted with spyware (The Record) โ€” A broad targeting campaign using Pegasus spyware has been identified against Serbian opposition politicians and civil society activists, raising further concerns about commercial spyware abuse in Europe.

HPE patches critical ArubaOS-CX remote code execution flaw (BleepingComputer) โ€” HPE has released a patch for a critical RCE vulnerability in ArubaOS-CX; organisations running Aruba network switching infrastructure should prioritise this update.

Cisco searched for IOS XR bugs and found so many it rolled them into an update release (The Register) โ€” Cisco proactively audited IOS XR and discovered enough vulnerabilities to warrant a dedicated bundled release, highlighting the ongoing complexity debt in legacy network operating systems.

Did ShinyHunters breach ReliaQuest? (Dark Reading) โ€” An investigation is underway into whether threat group ShinyHunters compromised ReliaQuest, a managed security provider โ€” a sensitive target given the visibility MSPs have into their clients' environments.

French hospital fined โ‚ฌ500,000 after breach exposes data of 727,000 (BleepingComputer) โ€” France's CNIL fined Hรดpital privรฉ de la Loire โ‚ฌ500K following a 2025 breach that exposed data of over 727,000 patients and third parties, including health records.

Large enterprises targeted in fake Merger & Acquisition scams (Dark Reading) โ€” Sophisticated social engineering campaigns impersonating M&A advisors and financial executives are being used to extract wire transfers and sensitive deal documentation from large organisations.

OpenAI commits $1B in AI credits to frontline cyber defenders (The Register) โ€” OpenAI has pledged one billion dollars in AI compute credits to cybersecurity defenders, with a focus on smaller teams, non-profits, and threat intelligence organisations.

UK & Critical National Infrastructure

No UK-specific cyber incidents in today's 48-hour window, and no new NCSC advisories have been issued. However, the most CNI-relevant story for UK defenders is the CrowdStrike Falcon exploit proof-of-concept. CrowdStrike is deeply embedded across UK critical national infrastructure โ€” financial services, utilities, and government contractors โ€” and a working exploit for the endpoint agent itself represents a significant potential exposure at kernel level. UK security teams should monitor CrowdStrike's response and apply any guidance or patches immediately.

The energy sector targeting by direwolf (PTT Oil, Thailand) and Storm (Petrocare Construction, Canada) is also a continued reminder that CNI attack surface extends to suppliers and international partners. UK energy and transport operators with cross-border supply chain dependencies should review third-party exposure accordingly.

Ransomware Victims (48h)

20 victims ยท 9 groups

GroupVictimCountrySector
direwolfCartrack Holdings๐Ÿ‡ฟ๐Ÿ‡ฆ ZATransportation
direwolfPTT Oil and Retail Business๐Ÿ‡น๐Ÿ‡ญ THEnergy & Utilities โš ๏ธ
incransommyglobal.com๐Ÿ‡ฒ๐Ÿ‡พ MYOther
insomniaN***************๐Ÿ‡บ๐Ÿ‡ธ USUnknown
krybitligacancerguate.org (INCAN)๐Ÿ‡ฌ๐Ÿ‡น GTHealthcare โš ๏ธ
medusalockerLicindia๐Ÿ‡ฎ๐Ÿ‡ณ INOther
PanzerDinas Komunikasi dan Informatika๐Ÿ‡ฎ๐Ÿ‡ฉ IDGovernment & Defense
qilinUak University๐Ÿ‡น๐Ÿ‡ท TREducation
SilentRansomGroupKatten Muchin Rosenman๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
SilentRansomGroupP... S...โ€”Redacted
SilentRansomGroupA...en๐Ÿ‡ฉ๐Ÿ‡ช DERedacted
SilentRansomGroupGreenberg Traurig๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
SilentRansomGroupG... ...gโ€”Redacted
SilentRansomGroupS... M...โ€”Redacted
StormPetrocare Construction๐Ÿ‡จ๐Ÿ‡ฆ CAEnergy & Utilities โš ๏ธ
StormGSAC Auto Financing๐Ÿ‡บ๐Ÿ‡ธ USFinancial Services
StormStar Aviation, Inc๐Ÿ‡บ๐Ÿ‡ธ USTransportation
Vexy RansomwareMcDonald's Ecuador๐Ÿ‡ช๐Ÿ‡จ ECHospitality
WallstreetAmerica's Food Basket๐Ÿ‡บ๐Ÿ‡ธ USRetail & E-Commerce
WallstreetOrmond Beach Florida๐Ÿ‡บ๐Ÿ‡ธ USMunicipal
Show Comments