๐ง Subscribe to the podcast feed | Download episode
Security News
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide (The Register) โ The US, UK, and five allied governments published a joint advisory exposing PRC-linked espionage tooling, targeting patterns, and tradecraft across government, defence, and critical infrastructure. Review the full advisory on the NCSC and CISA portals; update network monitoring and access controls against the named indicators.
Ransomware attack disrupts Japan's IDCF cloud used by govt clients (BleepingComputer) โ IDC Frontier, a major Japanese cloud provider, has been hit by ransomware disrupting services for government agency clients โ a direct critical infrastructure availability incident.
Azure October CVEs: App Service RCE and multiple privilege escalations (Microsoft MSRC) โ October's Azure patch batch includes CVE-2026-77900 (App Service RCE), CVE-2026-88131 (Dataverse RCE), CVE-2026-69435 (SRE Agent EoP), CVE-2026-94510 (Bookings EoP), and CVE-2026-96207 (Partner Center EoP). Apply through standard Azure update mechanisms.
Suspect behind South Korea bank hacks may be 26-year-old Chinese national (Reuters) โ Investigators have identified a suspect in the AI-powered coordinated intrusion campaign against seven South Korean banks โ a 26-year-old Chinese national. The case adds further context to the joint PRC espionage advisory above.
Trump Mobile hack and apparent lack of FCC authorization raise security alarms (Ars Technica) โ Ars reports on breach claims against Trump Mobile alongside questions about whether the carrier has valid FCC authorisation, adding regulatory and security dimensions to ongoing US telecom exposure stories.
NightSpire ransomware cluster continues rapid expansion โ New victims posted in the past 24 hours include Vietnam SuperPort (port logistics), KC Pharmaceuticals, Medcom Tech, and multiple entities across Latin America, Europe, and Asia. NightSpire has now accumulated over 20 confirmed victims in a short operating window.
Argentina national social security database breach claimed โ A threat actor claims to have obtained data from ANSES, Argentina's national social security administration, reportedly covering 14.7 million citizens. A separate breach claim against consumer credit platform Credicuotas compounds the picture of sustained targeting of Argentine financial and government infrastructure.
Morocco government data incidents โ A breach affecting the Ministry of Islamic Affairs has been reported, alongside a separate leak of approximately 39,000 journalist records referencing prior Pegasus spyware exposure. Both incidents affect public sector data in a country with a documented history of commercial spyware use.
Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates โ NetRunner ransomware โ US healthcare sector continues to take hits; this oncology practice is the latest claimed victim, joining Riviera Healthcare Center and Morton LTC Pharmacy in the 48-hour window.
Croatian Ministry of Agriculture โ BARRACUDA ransomware โ A European government ministry hit by a group with a name referencing the Barracuda ESG zero-day exploitation campaigns from prior years.
UK & Critical National Infrastructure
The seven-nation joint advisory on PRC cyber espionage published today is the most significant UK-relevant intelligence release in this cycle. UK security teams should treat it as a priority action item โ review the full advisory from the NCSC, assess network monitoring coverage against named indicators, and verify access controls on systems matching the described target profile.
The IDC Frontier Japan cloud ransomware incident is a direct analogue for UK cloud providers serving public sector clients. The incident model โ ransomware deployed against a hyperscaler with government tenancy โ is a threat scenario UK CNI defenders should ensure is modelled in their resilience planning.
Threat intelligence from criminal markets continues to show UK-attributed access and data listings. Combined with last week's UK government shell access postings, the pattern of commercially traded UK public sector exposure remains active.
Ransomware Victims (48h) โ 27 victims ยท 12 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| anubis | Leadec | ๐ฉ๐ช DE | Manufacturing |
| BYOD | T-Mobile US | ๐บ๐ธ US | Technology |
| dragonforce | โ ๏ธ Petrosul | ๐ง๐ท BR | โ ๏ธ Energy |
| dragonforce | RรSO | ๐ซ๐ท FR | Technology |
| Eclipse | dipecarr.com.br | ๐ง๐ท BR | Manufacturing |
| Eclipse | simplexengg.in | ๐ฎ๐ณ IN | Manufacturing |
| Eclipse | sanjoseattorneys.com | ๐บ๐ธ US | Professional Services |
| Eclipse | DIPECARR | ๐ง๐ท BR | Other |
| Eclipse | โ ๏ธ Global AirFreight International | ๐ธ๐ฌ SG | โ ๏ธ Transportation |
| interlock | โ ๏ธ Riviera Healthcare Center | ๐บ๐ธ US | โ ๏ธ Healthcare |
| Panzer | University of Rostock | ๐ฉ๐ช DE | Education |
| payload | Boullard Musique | ๐ซ๐ท FR | Retail |
| qilin | MCM Telecom | ๐ฒ๐ฝ MX | Technology |
| qilin | Qatar National Import & Export | ๐ถ๐ฆ QA | Other |
| qilin | Matadero Frigorรญfico Avinyรณ | ๐ช๐ธ ES | Agriculture |
| RunSomeWares | โ ๏ธ Morton LTC Pharmacy | ๐บ๐ธ US | โ ๏ธ Healthcare |
| SilentRansomGroup | โ ๏ธ Baker McKenzie | ๐บ๐ธ US | Professional Services |
| SilentRansomGroup | Andersen Group Inc. | โ | Professional Services |
| SilentRansomGroup | K... | โ | โ |
| Storm | โ ๏ธ Cooperative Des Techniciens Ambulanciers De La Monte | ๐จ๐ฆ CA | โ ๏ธ Healthcare |
| UmBra | SOCOCO | ๐ซ๐ท FR | Technology |
| UmBra | Manipal Academy of Higher Edu | ๐ฎ๐ณ IN | Education |
| UmBra | IIT Roorkee | ๐ฎ๐ณ IN | Education |
| UmBra | FSE, Cairo University | ๐ช๐ฌ EG | Education |
| UmBra | SANAtech Global Solutions | โ | Technology |
| UmBra | Raqib | โ | Technology |
| UmBra | โ ๏ธ Tharisa | ๐ฟ๐ฆ ZA | โ ๏ธ Mining |
HaveIBeenPwned โ New Breaches
No new breaches added to HIBP in the past 24 hours.