๐ง Subscribe to the podcast feed | Download episode
Security News
Hackers hijack Google domains after breaching ccTLD registries (BleepingComputer) โ Attackers compromised multiple country-code TLD registries and redirected Google domain entries, representing a direct assault on PKI and identity infrastructure.
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins (BleepingComputer) โ The FBI issued an active exploitation alert for FortiBleed, with attackers systematically locking out VPN administrators; patch and review admin accounts urgently.
Hackers exploit critical Atlassian flaw after public PoC release (BleepingComputer) โ Active exploitation is underway following public proof-of-concept release; Atlassian on-premises deployments should be patched immediately.
Atlassian warns of critical file-access flaw in Jira, Confluence (BleepingComputer) โ A second concurrent critical advisory from Atlassian affecting both Jira and Confluence; treat both issues as a combined priority patch event.
SonicWall warns of max-severity SSRF flaw in SMA1000 gateways (BleepingComputer) โ Maximum CVSS severity server-side request forgery vulnerability in SMA1000 series; patch before end of day given consistent targeting of SonicWall appliances by access brokers.
Ransomware recovery CEO charged over secret ransom payments (BleepingComputer) โ A US ransomware recovery firm CEO was federally charged with secretly paying ransoms and concealing them from clients, highlighting the unregulated nature of the recovery sector.
South Korea probes bank breaches amid suspected AI-powered attacks (BleepingComputer) โ Investigators are examining whether an AI-based penetration testing tool was used to coordinate simultaneous intrusion attempts across seven South Korean banks.
PoeLLM malware infects exposed AI servers in cryptomining attacks (BleepingComputer) โ Malware is targeting internet-accessible AI inference servers to hijack GPU compute for cryptomining; lock down open inference endpoints.
Nikkei discloses breaches of employees' Microsoft, Google email accounts (BleepingComputer) โ The Japanese financial media group confirmed business email compromise affecting Microsoft 365 and Google Workspace accounts, with supply chain and source-protection implications.
Rejetto HFS servers now actively scanned for critical RCE flaw (BleepingComputer) โ Active scanning for a critical remote code execution vulnerability in Rejetto HTTP File Server; take any HFS deployments offline or patch immediately.
Ninja Forms plugin flaw exploited to hack WordPress sites (BleepingComputer) โ Active exploitation of a Ninja Forms vulnerability is compromising WordPress installations; update the plugin across all managed WordPress sites.
Evolution of Web3 in Cloud Supply Chain Attacks (Unit 42) โ Palo Alto's Unit 42 documents how threat actors are leveraging Web3 infrastructure in cloud supply chain attack chains, combining blockchain permanence with traditional TTPs.
UK & Critical National Infrastructure
No new NCSC advisories in the past 48 hours.
The FortiBleed FBI alert is directly relevant to UK perimeter defenders. NCSC has previously published guidance on FortiBleed, and the FBI's active exploitation alert makes immediate review of any FortiGate VPN deployments a priority. Check admin accounts for unauthorised modifications and verify firmware currency.
The ccTLD registry hijack story warrants close attention for UK public sector organisations. If the compromised registries include those managing ccTLDs used by UK government or public sector โ or if the attack affected Google infrastructure used in Workspace deployments across NHS and government โ the trust chain for Google-based SSO and email needs verification.
Threat intelligence continues to show UK-attributed web access in criminal marketplaces. Combined with UK government shell access listings from the past 48 hours, there is a consistent pattern of UK public sector exposure being commercially traded. UK government and NHS security teams should treat this as an active threat signal.
Ransomware Victims (48h) โ 28 victims ยท 12 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| anubis | Leadec | ๐ฉ๐ช DE | Manufacturing |
| Deadlock | Greggio Argento | ๐ฎ๐น IT | Agriculture |
| EndZone | Philander Smith University | ๐บ๐ธ US | Education |
| everest | Kennametal | ๐บ๐ธ US | Manufacturing |
| everest | โ ๏ธ Flydubai | ๐ฆ๐ช AE | โ ๏ธ Transportation |
| incransom | architekt-vondanwitz.de | ๐ฉ๐ช DE | Professional Services |
| incransom | โ ๏ธ harborpacific.com | ๐บ๐ธ US | โ ๏ธ Transportation |
| incransom | acmestamping.com | ๐บ๐ธ US | Manufacturing |
| incransom | magnals.com | ๐บ๐ธ US | Other |
| interlock | โ ๏ธ Riviera Healthcare Center | ๐บ๐ธ US | โ ๏ธ Healthcare |
| N0n | Chibitek | ๐บ๐ธ US | Technology |
| Panzer | University of Rostock | ๐ฉ๐ช DE | Education |
| Panzer | EDFelectronics | โ | Manufacturing |
| Panzer | SweetRush | ๐บ๐ธ US | Professional Services |
| qilin | Qatar National Import & Export | ๐ถ๐ฆ QA | Other |
| qilin | Matadero Frigorรญfico Avinyรณ | ๐ช๐ธ ES | Agriculture |
| qilin | EPTISA | ๐ช๐ธ ES | Professional Services |
| qilin | BNYH | โ | Financial Services |
| qilin | Ciftay Insaat | ๐น๐ท TR | Manufacturing |
| qilin | CORBY ROCK MILL | ๐ฎ๐ช IE | Manufacturing |
| qilin | โ ๏ธ Delta Marine | ๐ซ๐ฎ FI | โ ๏ธ Transportation |
| SilentRansomGroup | Andersen Group | โ | Professional Services |
| UmBra | SANAtech Global Solutions | โ | Technology |
| UmBra | Raqib | โ | Technology |
| UmBra | Tharisa | ๐ฟ๐ฆ ZA | Manufacturing |
| UmBra | Beni Suef Technological University | ๐ช๐ฌ EG | Education |
| UmBra | Four Hands LLC | ๐บ๐ธ US | Other |
| Vexy Ransomware | KOOKABARRA JUICE | ๐ฆ๐บ AU | Retail |
HaveIBeenPwned โ New Breaches
| Breach | Date Added | Accounts | Data Exposed |
|---|---|---|---|
| CyrusOne | 7 Oct 2026 | 373,460 | Email addresses, employers, job titles, names, phone numbers, physical addresses, support tickets |