Weekly Security Roundup — week ending Sunday 11 October 2026

šŸŽ§ Download episode | Subscribe to the podcast feed


Security Stories

AI agents in live bank attacks: ARTEX AI and Claude deployed against South Korean financial sector

BleepingComputer | SecurityWeek

A Chinese threat actor deployed the ARTEX AI penetration testing suite alongside Claude agents in coordinated intrusions against South Korean banks — the first confirmed case of AI agents with tool-use capability used as live offensive infrastructure against the financial sector. South Korea's president cited AI use publicly; its financial regulator held an emergency meeting; CrowdStrike attributed the activity to a China-based actor. The NCSC CTO's analysis is apposite: the root cause is latent web application and edge device vulnerability, not the AI itself — but AI has now demonstrably compressed the time-to-exploitation window.

ShinyHunters crackdown: arrests across four countries in one week

Krebs on Security | BleepingComputer

The FBI arrested the founder of a ransomware negotiation firm in connection with the ShinyHunters investigation — the group that previously exfiltrated data on thousands of FBI employees. A second ShinyHunters suspect was separately arrested in the US. Reuters then reported a third suspect, Saif al-Din Khader, detained in Jordan and cooperating with the bureau. Germany simultaneously announced the extradition and custody of an alleged core Qilin ransomware member, a Russian national arrested in Japan in May. The co-creator of Empire Market received a 40-year federal sentence in the same week.

Citrix NetScaler, SonicWall SMA1000, and FortiBleed: edge devices under mass exploitation

BleepingComputer (Citrix) | BleepingComputer (SonicWall) | BleepingComputer (FortiBleed)

Citrix patched a critical RCE in NetScaler ADC and Gateway (CVE-2026-88771) with exploitation observed before disclosure — threat actors deployed PHP webshells, modified Apache configurations, and set SUID bits for root access; Finland's NCSC confirmed multiple intrusions. SonicWall disclosed a max-severity SMA1000 flaw under active exploitation. The FBI and Secret Service issued a joint advisory on FortiBleed: over 86,600 Fortinet devices compromised across 194 countries, with some organisations locked out by attacker-modified credentials. An Atlassian Jira and Confluence pre-auth arbitrary file read (CVE-2026-21589) requiring no authentication added further patching urgency.

UK and international partners formally call out China's Integrity Technology Group

NCSC UK | SecurityWeek

The UK NCSC and international partners publicly attributed global sensitive data theft to Integrity Technology Group — a Beijing-based company with PRC government contracts, also tracked as Flax Typhoon. The US DOJ and FBI simultaneously seized two hacking tools used by the group: Microscan and FishHub, used to scan and compromise US and foreign critical infrastructure. The Netherlands AIVD and MIVD issued a joint advisory noting Chinese actors have obtained source code for specific Western edge device products, with AI tooling expected to accelerate their zero-day exploitation capability.

Ransomware: BigID, DexCom, Anne Arundel County — and thegentlemen extends its campaign

The week's most notable ransomware disclosures included BigID (a data security and privacy platform) and Confluent (a data streaming platform) — both claimed by The Gentlemen, who had already claimed Deloitte and the Royal Thai Air Force in the prior window. Redact claimed DexCom, a medical device manufacturer with nearly $5B in revenue, in the Healthcare sector. Rhysida's data description from Anne Arundel County, Maryland, includes methadone clinic records protected under 42 CFR Part 2, jail gang intelligence files, and 2.6 terabytes of government records — a single-county breach with cross-service implications for the most sensitive categories of public data.

Supply chain and infrastructure: trojanised Terraform, pre-baked Android firmware malware, ccTLD hijacks

Zscaler (TraderTraitor) | SecurityWeek (Android) | SecurityWeek (ccTLD)

Zscaler detailed a trojanised Terraform provider attributed to North Korea's TraderTraitor group, executing malicious code at load time and deploying a Rust cross-platform backdoor with layered C2 via Pastebin and Nostr. Pre-baked firmware malware was found in budget Android devices across 150+ countries as a supply chain compromise. And the hijacking of three ccTLDs — Ghana's .gh, Sierra Leone's .sl, and American Samoa's .as — produced valid HTTPS certificates for several Google domains; Chrome responded via CRLSets, but affected organisations included multiple global brands.


Key Themes

AI as offensive infrastructure is no longer hypothetical. The ARTEX/Claude bank attacks, the CyberXero AI-augmented Ukrainian CNI campaign, and Huntback's exposure of an autonomous Claude Code vulnerability-hunting rig all landed in the same week. Each represents a different deployment model — a targeted nation-state actor, a financially motivated IAB, and a freelance offensive operator respectively. The NCSC CTO's framing is important: AI is a compounder of latent vulnerability exposure, not its cause. The treatment remains reducing attack surface and exposure faster than adversaries can weaponise new tooling.

Law enforcement has reached operational tempo against major cybercrime groups. Four countries, at least four arrests or detentions, two sentences — all in one week, all connected to the same overlapping criminal ecosystem. The ShinyHunters investigation is now generating cooperating witnesses. That changes the calculus for other actors: the question shifts from whether you will be identified to how long until someone with knowledge of your operation decides cooperation is preferable to prosecution.

Edge devices are the dominant initial access surface. Citrix, SonicWall, Fortinet, and Atlassian all had critical vulnerabilities in active exploitation this week. The AIVD advisory on Chinese actors with Western product source code access makes this worse: these aren't just n-day exploitation campaigns. The convergence of deep product knowledge, AI tooling, and coordinated state backing means the edge device exploitation problem will not be solved by patch velocity alone — architecture decisions matter.


NCSC CTO Deep Dive — week ending 11 October 2026

Author: Ollie Whitehouse (NCSC CTO) | Published: 10 October 2026 | Read in full

Audience: operational blue and purple teams; technical defenders in UK organisations and their supply chains.

Ollie Whitehouse led this week's summary with the formal NCSC callout of China's Integrity Technology Group — described as using "AI-enabled tools, large-scale botnets and hands-on exploitation techniques" — alongside the simultaneous DOJ/FBI seizure of Microscan and FishHub. He also highlighted the "Putin Tax" research quantifying 300+ Russia-linked cyber incidents affecting UK companies since 2022, and the formal UK-Germany joint partnership to counter sabotage and cyber attacks, announced by the Prime Minister's Office and Andy Burnham.

On AI and the South Korean bank attacks, Whitehouse urged against over-indexing on the enabler. His formulation: AI is not the cause of the breaches — it is a compounder of latent vulnerability which enabled an adversary with intent to pursue it. The urgency lies in organisations understanding their attack surfaces and being confident they are minimised, resilient, and detectable. He called out the Huntback research on autonomous offensive AI rigs as a further data point, and the ICO's launch of a call for evidence on data protection risks of agentic AI.

On the threat intelligence side, he covered Earth Sirrush — a Russia-aligned intrusion set running against Ukrainian government and defence since 2022, with 10+ malware families and poor enough operational security to trace its infrastructure to a single registrar. He highlighted CyberXero's AI-augmented campaign against Ukrainian critical infrastructure (SOCRadar). On China, the AIVD/MIVD joint advisory on edge device source code access received detailed treatment, as did Rapid7's analysis of BPFDoor and AVERAT implants targeting network edge devices. The Iranian Blinder Tunnel campaign against Iraqi critical infrastructure via trojanised coding challenges was noted.

Technical defence highlights from the summary: Apple's updated Full Disk Access controls for macOS, explicitly designed to limit AI agent access; the NSA mandate for post-quantum cryptography on all new national security systems by 2027 with legacy phase-out by 2030; the FortiBleed FBI/USSS joint advisory; the Citrix NetScaler exploitation wave; and a critical command execution vulnerability in DeepSeek-Reasonix Studio (CVE not yet published) enabling attacker code execution when a developer views a file diff — patched in version 2.21.0.


HaveIBeenPwned Activity — week ending 11 October 2026

Breach Added Breach Date Accounts Data Types
Angel One (Indian stock brokerage)7 Oct 2026Apr 20236,765,054Bank account numbers, DOB, email, financial investments, government IDs, names, phone, addresses
Neogen (food safety / animal health)9 Oct 2026Aug 2026435,963Email, employers, job titles, names, phone, physical addresses
CyrusOne (data centre operator)7 Oct 2026Aug 2026373,460Email, employers, job titles, names, phone, physical addresses, support tickets
Double Counter (Discord bot service)7 Oct 2026Oct 2026274,922Email addresses, geographic locations, names, usernames

Angel One's breach date of April 2023 means this data has circulated for over three years before appearing in HIBP — a common pattern for financial sector breaches that are quietly settled before public disclosure.

Show Comments