Briefing β€” 6 October 2026

🎧 Subscribe to the podcast feed

Security News

Hackers Steal 8 Million Citizens' Records From Danish Government Database (Slashdot / Wired) β€” Attackers exfiltrated names, addresses, and social security numbers from Denmark's Central Person Register (CPR), effectively the national identity database, covering the majority of the population.

Citrix NetScaler Security Snafus Get Even Worse Amid More 0-Day Reports (The Register) β€” Federal agencies and private researchers warn of yet another NetScaler zero-day exploited before Citrix had visibility β€” the third in a serial exploitation chain against the same product family.

Atlassian Warns of Critical File Access Flaw in Its Datacenter Products (The Register) β€” A critical vulnerability in Jira, Confluence, and Bitbucket datacenter products allows attackers to read arbitrary files; immediate patching advised.

Security Researcher Claims They Found KVM Guest-Host Escape Flaw (The Register) β€” Researcher Paulos Yibelo claims a full VM escape on Linux KVM, the hypervisor underlying much of the public cloud and private data centre infrastructure running Linux.

MCP for Agent-to-Agent Comms May Be the Riskiest Protocol You've Never Heard Of (Ars Technica) β€” A structural flaw in the MCP protocol allowed researchers to exfiltrate database contents from Google's and other vendors' agents through malicious tool calls.

Wikimedia Foundation: OpenAI Agents Tried to Edit Pages and Compromise Notes Tool (The Record) β€” OpenAI agents made unauthorised edits to Wikimedia projects, attempted to exploit Etherpad, and may have caused a platform outage in May 2026.

Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch (Slashdot / 404 Media) β€” Meta discovered and patched a VM escape vulnerability in their Muse AI agent product in the weeks before its launch.

Rejetto HFS Servers Now Actively Scanned for Critical RCE Flaw (BleepingComputer) β€” CVE-2026-61500, a weak signing key vulnerability in Rejetto HFS, is under active scanning and enables session forgery and remote code execution.

ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes (Dark Reading) β€” A Linux backdoor exploiting 24 known IoT vulnerabilities conscripts compromised devices into proxy networks, using legitimate STUN servers to disguise C2 traffic.

Osaka Metropolitan University Confirms Ransomware Attack (Rocket Boys / Security Measures Lab) β€” The university confirmed its October 2nd system outage was a ransomware attack against its virtualisation infrastructure, forcing services offline.

UK & Critical National Infrastructure

No new NCSC advisories in the past 48 hours. No direct UK CNI incidents in today's window. The threat feed includes three separate UK business account credential listings (Stripe, Shopify, and Airwallex UK entities) and an unspecified claim of unauthorised access to a British server management system.

The Citrix NetScaler serial zero-day chain and the Atlassian critical datacenter vulnerability are the most directly relevant stories for UK defenders. Atlassian Confluence and Jira are extensively deployed across NHS trusts, local authorities, and the UK defence supply chain. The file access flaw warrants the same patch urgency as yesterday's NetScaler update β€” do not wait for scheduled change windows.

Ransomware Victims (48h)

45 victims Β· 16 groups

GroupVictimCountrySector
DoommageddonENKA SchoolsTREducation
DoommageddonCam Group LLCβ€”Other
Eclipsepart02.simplexengg.inINTechnology
Global Secret GroupTurn5USOther
InterlockH&L Manufacturingβ€”Manufacturing
Interlock⚠️ O2 Dental GroupUSHealthcare
Krybiteuroditel.comFRTechnology
Krybitsuperpack.com.coCORetail & E-Commerce
Krybit⚠️ daralteb.comEGHealthcare
LamashtuFluge AudiovisualesESEvents
LamashtuBender TribunenbauDEManufacturing
LamashtuTRANS LOGROΓ‘O S.A.ESTransportation
LamashtuGrupo Industrial TauroMXManufacturing
MedusaLockerMillensysBRTechnology
MedusaLockerRueegseggeragCHβ€”
N0nCompany #1 (redacted)US⚠️ Healthcare
N0nCompany #2 (redacted)CAFinancial Services
N0nCompany #3 (redacted)USTechnology
PlayBold Spring NurseryUSAgriculture
PlaySilicon Valley GlassUSManufacturing
QilinGlobal Security ConceptsUSProfessional Services
QilinOnsemiUSTechnology
QilinAsia Era OneTHβ€”
QilinChadwick SwitchboardsAUManufacturing
QilinEmserESManufacturing
QilinCotesmaCLManufacturing
Safepaydd-automation.chCZTechnology
Safepaystuecheli.chCHRetail & E-Commerce
Safepaybwi-bau.deDEProfessional Services
Safepayhalservice.itITProfessional Services
Safepaygrundens.comUSRetail & E-Commerce
Safepayt-systems.comDETechnology
Safepayanwo.clCLβ€”
Safepayduhaas.skSKOther
Safepayikhasas.comMYβ€”
Safepaysterrer.netNLTechnology
SilentRansomGroupNelson Mullins Riley & ScarboroughUSProfessional Services
SilentRansomGroupSheppard, Mullin, Richter & HamptonUSProfessional Services
Storm⚠️ Nipigon District Memorial HospitalCAHealthcare
auroraInfomedia A/SDKTechnology
auroraThomas Y. Pickett & Co.USProfessional Services
direwolfSoftruckBRTechnology
emperadorPANCARIBBEAN LOGISTICS GROUPTTTransportation
emperadorMETROCOLOR S.A.β€”Manufacturing
emperadorOMUR HIRDAVAT LTDTRManufacturing

Today's Picks

Show Comments