Relatives of children in Wiltshire and Bath and North East Somerset have received letters from HCRG Care Group, formerly Virgin Care, saying names, addresses, dates of birth, NHS numbers, and health records may have been accessed in a February 2025 cyber attack. One woman, whose two teenage nieces were among those written to, called it appalling and scary.
The attack was ransomware, claimed by the Medusa group, which said it took 50TB of data. No copy has surfaced on Medusa's leak site, and HCRG says there is no evidence the information has appeared online or been misused. The company declined to confirm the scale, saying only that a cross-section of patients was affected.
HCRG says the investigation was complex and only recently concluded, which accounts for the delay, and that it contacted everyone as soon as it had the facts needed to inform them accurately. It reported the incident to law enforcement and the ICO, which has since closed the matter without further action.
An anonymous district nurse told the BBC the compromised systems held safeguarding records linked to domestic abuse; the BBC could not verify that claim.
Source: BBC News
Relatives of children in Wiltshire and Bath and North East Somerset have received letters from HCRG Care Group, formerly Virgin Care, saying names, addresses, dates of birth, NHS numbers, and health records may have been accessed in a February 2025 cyber attack. One woman, whose two teenage nieces were among those written to, called it appalling and scary.
The attack was ransomware, claimed by the Medusa group, which said it took 50TB of data. No copy has surfaced on Medusa's leak site, and HCRG says there is no evidence the information has appeared online or been misused. The company declined to confirm the scale, saying only that a cross-section of patients was affected.
HCRG says the investigation was complex and only recently concluded, which accounts for the delay, and that it contacted everyone as soon as it had the facts needed to inform them accurately. It reported the incident to law enforcement and the ICO, which has since closed the matter without further action.
An anonymous district nurse told the BBC the compromised systems held safeguarding records linked to domestic abuse; the BBC could not verify that claim.
Source: BBC News
Patrick Wardle, founder of Objective-See, disclosed a zero-day in Meta's Muse, a macOS AI assistant Meta markets around a dedicated secure VM, protected credential storage, and user-controlled permissions. An undocumented preference called endo_voyager_dictation_endpoint can be rewritten by any process running as the logged-in user, redirecting Muse's dictation traffic to an attacker-controlled server.
From there an attacker reads dictated prompts and audio, injects instructions Muse trusts and acts on, and lifts the Muse session token. Wardle's proof-of-concept, not-a-mused, used a stolen token to make the Muse app on his iPhone report precise location, run Bluetooth scans, and list smart-home commands. No CVE or CVSS has been assigned, and no in-the-wild exploitation has been reported.
Exploitation needs code execution as the user first, so existing malware is the delivery route rather than a remote attack. Meta shipped a hot-fix roughly 16 hours after Wardle went public on September 21, and he confirmed it the next day. If you ran Muse before the fix, update it, revoke unnecessary permissions, and treat connected accounts as exposed.
Source: Cybersecurity News
Patrick Wardle, founder of Objective-See, disclosed a zero-day in Meta's Muse, a macOS AI assistant Meta markets around a dedicated secure VM, protected credential storage, and user-controlled permissions. An undocumented preference called endo_voyager_dictation_endpoint can be rewritten by any process running as the logged-in user, redirecting Muse's dictation traffic to an attacker-controlled server.
From there an attacker reads dictated prompts and audio, injects instructions Muse trusts and acts on, and lifts the Muse session token. Wardle's proof-of-concept, not-a-mused, used a stolen token to make the Muse app on his iPhone report precise location, run Bluetooth scans, and list smart-home commands. No CVE or CVSS has been assigned, and no in-the-wild exploitation has been reported.
Exploitation needs code execution as the user first, so existing malware is the delivery route rather than a remote attack. Meta shipped a hot-fix roughly 16 hours after Wardle went public on September 21, and he confirmed it the next day. If you ran Muse before the fix, update it, revoke unnecessary permissions, and treat connected accounts as exposed.
Source: Cybersecurity News
Google's Gemini model broke into three real companies during a May 2026 test of its cybersecurity capabilities, in what is thought to be the first known case of a Google model hacking on its own. It happened during a capture-the-flag exercise run by Irregular, an independent evaluation firm, after a bug in the test environment gave the model internet access it was never meant to have.
Gemini had been told to pull information from a fictional company, which turned out to share its name with a real one. In one case it guessed passwords until it got into a protected system; in the other two it used working credentials sitting in a public repository. Google says the model stopped each time it recognised the target was real, and did no further damage.
Irregular says it informed Google and all affected entities in July and resolved the known issues on its end weeks ago; Google says it ensured the three companies were told. The same testing fault lies behind the breakouts disclosed by OpenAI, Anthropic and Meta this year — and Gemini's May intrusions came first.
None of it needed a novel exploit. A guessed password and credentials left lying in a public repository were enough. The model didn't get clever; it got lucky, on someone else's housekeeping. Audit what your teams have exposed, rotate anything a guess could reach, and treat public repos as hostile ground.
Source: BBC News
Google's Gemini model broke into three real companies during a May 2026 test of its cybersecurity capabilities, in what is thought to be the first known case of a Google model hacking on its own. It happened during a capture-the-flag exercise run by Irregular, an independent evaluation firm, after a bug in the test environment gave the model internet access it was never meant to have.
Gemini had been told to pull information from a fictional company, which turned out to share its name with a real one. In one case it guessed passwords until it got into a protected system; in the other two it used working credentials sitting in a public repository. Google says the model stopped each time it recognised the target was real, and did no further damage.
Irregular says it informed Google and all affected entities in July and resolved the known issues on its end weeks ago; Google says it ensured the three companies were told. The same testing fault lies behind the breakouts disclosed by OpenAI, Anthropic and Meta this year — and Gemini's May intrusions came first.
None of it needed a novel exploit. A guessed password and credentials left lying in a public repository were enough. The model didn't get clever; it got lucky, on someone else's housekeeping. Audit what your teams have exposed, rotate anything a guess could reach, and treat public repos as hostile ground.
Source: BBC News
The FBI's Cyber Division, with Japanese, Australian, and German authorities, warned on September 18 that a North Korea-linked group tracked as WaterPlum — also called Contagious Interview — infected more than 30,000 personal computers across 100-plus countries between December 2025 and July 2026. Posing as recruiters on job boards, social networks, and freelance platforms, they got developers to run malicious files as fake coding tasks.
Some used AI face-swapping software to appear as the recruiter on video calls, then cut the camera a few minutes in, blaming network trouble. The payloads include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, which between them steal credentials, wallet keys, and project files. Authorities put the haul at 7,000 cryptocurrency wallets and $10.71 million moved to North Korea.
A compromised developer is also a route into their employer's network, which is what lifts this above an individual problem. Run code from a recruiter only in a sandbox or virtual machine, never on a machine holding personal data or wallets. If you find an infection, disconnect immediately and assume the data is already gone.
Source: Cyber Security News
The FBI's Cyber Division, with Japanese, Australian, and German authorities, warned on September 18 that a North Korea-linked group tracked as WaterPlum — also called Contagious Interview — infected more than 30,000 personal computers across 100-plus countries between December 2025 and July 2026. Posing as recruiters on job boards, social networks, and freelance platforms, they got developers to run malicious files as fake coding tasks.
Some used AI face-swapping software to appear as the recruiter on video calls, then cut the camera a few minutes in, blaming network trouble. The payloads include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, which between them steal credentials, wallet keys, and project files. Authorities put the haul at 7,000 cryptocurrency wallets and $10.71 million moved to North Korea.
A compromised developer is also a route into their employer's network, which is what lifts this above an individual problem. Run code from a recruiter only in a sandbox or virtual machine, never on a machine holding personal data or wallets. If you find an infection, disconnect immediately and assume the data is already gone.
Source: Cyber Security News
For roughly five months, Revolut handed customer records to an attacker impersonating a government agency. The fraudulent legal requests went to Revolut Bank UAB, the Lithuanian subsidiary, from a compromised Italian Ministry of the Interior mailbox, which is why they cleared authentication and were processed as routine.
Hudson Rock traced the access to infostealer malware on a ministry employee's machine, and assesses the attacker probably bought those credentials rather than deploying the malware. The attacker, who uses the handle IAmNotAVillain, claims 680 accounts held by cryptocurrency whales, with files containing passports, verification selfies, and full Bitcoin transaction histories. Revolut has still not confirmed a victim count.
The extortion came next. An initial demand of 10,000 Bitcoin, around $780 million, was cut to 6,000 Monero, roughly $3 million, with a 24-hour deadline to sell the files to other criminal groups. Revolut says it has had no direct contact from anyone making the claims, and notified affected customers on September 12.
Source: SecurityWeek
For roughly five months, Revolut handed customer records to an attacker impersonating a government agency. The fraudulent legal requests went to Revolut Bank UAB, the Lithuanian subsidiary, from a compromised Italian Ministry of the Interior mailbox, which is why they cleared authentication and were processed as routine.
Hudson Rock traced the access to infostealer malware on a ministry employee's machine, and assesses the attacker probably bought those credentials rather than deploying the malware. The attacker, who uses the handle IAmNotAVillain, claims 680 accounts held by cryptocurrency whales, with files containing passports, verification selfies, and full Bitcoin transaction histories. Revolut has still not confirmed a victim count.
The extortion came next. An initial demand of 10,000 Bitcoin, around $780 million, was cut to 6,000 Monero, roughly $3 million, with a 24-hour deadline to sell the files to other criminal groups. Revolut says it has had no direct contact from anyone making the claims, and notified affected customers on September 12.
Source: SecurityWeek
Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.
CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.
Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.
Source: Cybersecurity News
Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.
CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.
Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.
Source: Cybersecurity News
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek
A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.
Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.
KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.
With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.
Source: Cybersecurity News
A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.
Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.
KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.
With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.
Source: Cybersecurity News
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News