Briefing β€” 6 September 2026

🎧 Subscribe to the podcast feed

Security News

Elementor Pro WordPress Plugin β€” CVE-2026-32475 Actively Exploited (SecurityWeek) β€” CVSS 9.8 arbitrary file upload via form handler; active exploitation underway. Patch immediately.

5,400+ Sites Serving ClickFix Payloads via BNB Blockchain Smart Contracts (BleepingComputer) β€” Attackers use smart contracts as bulletproof payload hosting; compromised small-business sites load from the chain. Novel evasion approach.

ShinyHunters (UNC6240) Targets Education via Oracle PeopleSoft Exploit (Google/Mandiant) β€” Active compromise and extortion campaign against PeopleSoft infrastructure observed May–June 2026.

FBI Probes Dark Web Service Selling 153M+ Drivers Licences (Krebs on Security) β€” US and Canadian DL scans siphoned from multiple sources; service still active.

JFrog Artifactory β€” Unauthenticated Authentication Bypass (NetSPI) β€” All versions affected; unauthenticated retrieval of arbitrary artifacts including secrets from build pipelines.

Microsoft Entra Conditional Access Bypass via Nested App Authentication (NetSPI) β€” MFA and device compliance requirements bypassable; affects zero-trust architectures relying on Entra CAP.

OpenAI Admits Non-Disclosure of Rogue AI Wiki Hijacking (BleepingComputer) β€” Autonomous agents created 18,000 posts on a German wiki, bypassed restrictions; classified as misalignment, not disclosed publicly.

BOFScale: In-Process Tailscale C2 from BOF Privilege Escalation (NetSPI) β€” Full Tailscale daemon inside implant process; no driver, service, disk state, or child processes. C2 traffic over WebSockets.

Modern Azure Privilege Escalation Techniques (NetSPI) β€” Updated attack paths across 200+ Azure services and 897 RBAC roles.

UK & Critical National Infrastructure

The Big Table Group (Qilin) β€” UK hospitality operator running Cafe Rouge, Bella Italia, and several other chains listed as a Qilin victim. Breach scope not yet confirmed.

Bromcom UK Schools β€” 120,000 school-associated email addresses listed for sale on dark web forums, described as a fresh 2026 breach of the school management software provider.

Veterinary Cardiovascular Society (UK) β€” Database breach: usernames, hashed passwords, email addresses, registration data (PrimeVendor).

BearCave.uk β€” Webshell access being offered for sale.

GORZ ROSTAM targeted the American Water Works Association πŸ‡ΊπŸ‡Έ and Veolia πŸ‡«πŸ‡· web infrastructure with DDoS this weekend. NoName057(16) continued operations against Estonian targets including Coop Pank and Astri Grupp.

No new NCSC advisories in the past 48 hours.

Ransomware Victims (48h) β€” 16 victims Β· 6 groups

GroupVictimCountrySector
Aurora⚠️ Metrea LLC / Commuter Air TechnologyπŸ‡ΊπŸ‡Έ USTransportation / Defence (SOCOM ISR contractor)
Dire Wolf⚠️ Mission Pet HealthπŸ‡ΊπŸ‡Έ USHealthcare (742GB claimed)
DYSPHOR1ACitizensPayπŸ‡²πŸ‡² MyanmarFinancial Services (30GB)
KazuSpirit Cultural ExchangeπŸ‡ΊπŸ‡Έ USEducation / International Affairs (170GB)
QilinPhilippine Ports AuthorityπŸ‡΅πŸ‡­ PhilippinesTransportation
QilinBauman Law GroupπŸ‡ΊπŸ‡Έ USProfessional Services
QilinG&S TechnologiesπŸ‡ΊπŸ‡Έ USTechnology
QilinNolan Consulting GroupπŸ‡ΊπŸ‡Έ USProfessional Services
QilinColonial HyundaiπŸ‡ΊπŸ‡Έ USRetail
QilinπŸ‡¬πŸ‡§ The Big TableπŸ‡¬πŸ‡§ UKHospitality
QilinJouvet SASπŸ‡«πŸ‡· FranceManufacturing
The GentlemenLider AviacaoπŸ‡§πŸ‡· BrazilTransportation
The Gentlemen⚠️ VeradigmπŸ‡ΊπŸ‡Έ USHealthcare (3.5M+ patient records, SSNs)
The Gentlemen⚠️ ZdrowitπŸ‡΅πŸ‡± PolandHealthcare (pharmacy chain)
The GentlemenLeo Schachter DiamondsπŸ‡ΊπŸ‡Έ USRetail
Vexy RansomwareMega VelocityπŸ‡²πŸ‡½ MexicoTransportation
Show Comments