Briefing โ€” 8 October 2026

๐ŸŽง Subscribe to the podcast feed | Download episode

Security News

Hackers hijack Google domains after breaching ccTLD registries (BleepingComputer) โ€” Attackers compromised multiple country-code TLD registries and redirected Google domain entries, representing a direct assault on PKI and identity infrastructure.

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins (BleepingComputer) โ€” The FBI issued an active exploitation alert for FortiBleed, with attackers systematically locking out VPN administrators; patch and review admin accounts urgently.

Hackers exploit critical Atlassian flaw after public PoC release (BleepingComputer) โ€” Active exploitation is underway following public proof-of-concept release; Atlassian on-premises deployments should be patched immediately.

Atlassian warns of critical file-access flaw in Jira, Confluence (BleepingComputer) โ€” A second concurrent critical advisory from Atlassian affecting both Jira and Confluence; treat both issues as a combined priority patch event.

SonicWall warns of max-severity SSRF flaw in SMA1000 gateways (BleepingComputer) โ€” Maximum CVSS severity server-side request forgery vulnerability in SMA1000 series; patch before end of day given consistent targeting of SonicWall appliances by access brokers.

Ransomware recovery CEO charged over secret ransom payments (BleepingComputer) โ€” A US ransomware recovery firm CEO was federally charged with secretly paying ransoms and concealing them from clients, highlighting the unregulated nature of the recovery sector.

South Korea probes bank breaches amid suspected AI-powered attacks (BleepingComputer) โ€” Investigators are examining whether an AI-based penetration testing tool was used to coordinate simultaneous intrusion attempts across seven South Korean banks.

PoeLLM malware infects exposed AI servers in cryptomining attacks (BleepingComputer) โ€” Malware is targeting internet-accessible AI inference servers to hijack GPU compute for cryptomining; lock down open inference endpoints.

Nikkei discloses breaches of employees' Microsoft, Google email accounts (BleepingComputer) โ€” The Japanese financial media group confirmed business email compromise affecting Microsoft 365 and Google Workspace accounts, with supply chain and source-protection implications.

Rejetto HFS servers now actively scanned for critical RCE flaw (BleepingComputer) โ€” Active scanning for a critical remote code execution vulnerability in Rejetto HTTP File Server; take any HFS deployments offline or patch immediately.

Ninja Forms plugin flaw exploited to hack WordPress sites (BleepingComputer) โ€” Active exploitation of a Ninja Forms vulnerability is compromising WordPress installations; update the plugin across all managed WordPress sites.

Evolution of Web3 in Cloud Supply Chain Attacks (Unit 42) โ€” Palo Alto's Unit 42 documents how threat actors are leveraging Web3 infrastructure in cloud supply chain attack chains, combining blockchain permanence with traditional TTPs.


UK & Critical National Infrastructure

No new NCSC advisories in the past 48 hours.

The FortiBleed FBI alert is directly relevant to UK perimeter defenders. NCSC has previously published guidance on FortiBleed, and the FBI's active exploitation alert makes immediate review of any FortiGate VPN deployments a priority. Check admin accounts for unauthorised modifications and verify firmware currency.

The ccTLD registry hijack story warrants close attention for UK public sector organisations. If the compromised registries include those managing ccTLDs used by UK government or public sector โ€” or if the attack affected Google infrastructure used in Workspace deployments across NHS and government โ€” the trust chain for Google-based SSO and email needs verification.

Threat intelligence continues to show UK-attributed web access in criminal marketplaces. Combined with UK government shell access listings from the past 48 hours, there is a consistent pattern of UK public sector exposure being commercially traded. UK government and NHS security teams should treat this as an active threat signal.


Ransomware Victims (48h) โ€” 28 victims ยท 12 groups

GroupVictimCountrySector
anubisLeadec๐Ÿ‡ฉ๐Ÿ‡ช DEManufacturing
DeadlockGreggio Argento๐Ÿ‡ฎ๐Ÿ‡น ITAgriculture
EndZonePhilander Smith University๐Ÿ‡บ๐Ÿ‡ธ USEducation
everestKennametal๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
everestโš ๏ธ Flydubai๐Ÿ‡ฆ๐Ÿ‡ช AEโš ๏ธ Transportation
incransomarchitekt-vondanwitz.de๐Ÿ‡ฉ๐Ÿ‡ช DEProfessional Services
incransomโš ๏ธ harborpacific.com๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Transportation
incransomacmestamping.com๐Ÿ‡บ๐Ÿ‡ธ USManufacturing
incransommagnals.com๐Ÿ‡บ๐Ÿ‡ธ USOther
interlockโš ๏ธ Riviera Healthcare Center๐Ÿ‡บ๐Ÿ‡ธ USโš ๏ธ Healthcare
N0nChibitek๐Ÿ‡บ๐Ÿ‡ธ USTechnology
PanzerUniversity of Rostock๐Ÿ‡ฉ๐Ÿ‡ช DEEducation
PanzerEDFelectronicsโ€”Manufacturing
PanzerSweetRush๐Ÿ‡บ๐Ÿ‡ธ USProfessional Services
qilinQatar National Import & Export๐Ÿ‡ถ๐Ÿ‡ฆ QAOther
qilinMatadero Frigorรญfico Avinyรณ๐Ÿ‡ช๐Ÿ‡ธ ESAgriculture
qilinEPTISA๐Ÿ‡ช๐Ÿ‡ธ ESProfessional Services
qilinBNYHโ€”Financial Services
qilinCiftay Insaat๐Ÿ‡น๐Ÿ‡ท TRManufacturing
qilinCORBY ROCK MILL๐Ÿ‡ฎ๐Ÿ‡ช IEManufacturing
qilinโš ๏ธ Delta Marine๐Ÿ‡ซ๐Ÿ‡ฎ FIโš ๏ธ Transportation
SilentRansomGroupAndersen Groupโ€”Professional Services
UmBraSANAtech Global Solutionsโ€”Technology
UmBraRaqibโ€”Technology
UmBraTharisa๐Ÿ‡ฟ๐Ÿ‡ฆ ZAManufacturing
UmBraBeni Suef Technological University๐Ÿ‡ช๐Ÿ‡ฌ EGEducation
UmBraFour Hands LLC๐Ÿ‡บ๐Ÿ‡ธ USOther
Vexy RansomwareKOOKABARRA JUICE๐Ÿ‡ฆ๐Ÿ‡บ AURetail

HaveIBeenPwned โ€” New Breaches

BreachDate AddedAccountsData Exposed
CyrusOne7 Oct 2026373,460Email addresses, employers, job titles, names, phone numbers, physical addresses, support tickets
Show Comments