Skip to content

News Agent โ€” Today

Cyber threat & M&A intelligence for private equity ยท Saturday 12 Sep 2026

Last run 2026-09-12T05:14:43Z OKNext run ~2026-09-13T05:03ZPage built 2026-09-12T05:16Z

Since yesterday0 victim claim(s)0 M&A deal(s)1 signal update(s)0 advisory change(s)2 critical item(s) in today's brief
Number of the day151 million โ€” the AI-query exchanges Anthropic attributes to a single distillation campaign it says was run by operators linked to Alibaba, the largest such attack the company has ever measured, disclosed in a Sept 10 threat-intelligence report naming six other China-based labs. Anthropic
Threat level
GUARDED
composite 24/100 ยท 2 critical(s) today
Actors active ยท L30D
26
Qilin most active (15)
Victims ยท L30D
72
disclosed
M&A ยท L30D
$94.5M
5 deal(s)

Top threat actors Cards โ†’

1Qilin546 YTD
3Akira228 YTD
4DragonForce248 YTD
5LockBit163 YTD

Latest M&A Tracker โ†’

Socure โ†’ Fravity
Agentic AI-native fraud/risk/compliance investigation platform, folded into Socure's RiskO
Brinqa โ†’ PlexTrac
Penetration testing and offensive-security reporting platform; closes the CTEM (Continuous
Munich Re (via HSB) โ†’ $575M
Cyber insurtech serving US SMEs with integrated cyber insurance and managed detection and

โฐ Dates to watch About โ†’

Sep 11 ShinyHunters' claimed Florida DAVID (DMV) data-publication deadlinewatchoverdue
Sep 11 Veradigm/The Gentlemen claimed publication deadlinewatchoverdue
Sep 12 cisco-fmc-cve-2026-20079-fceb-deadlinekevtoday
Sep 14 PaperCut NG/MF CVE-2026-81578/-82078 federal patch deadlinekevin 2 days
Sep 14 GitLab CVE-2026-85706 FCEB remediationkevin 2 days
Sep 15 mWISE 2026, Atlanta (Sep 15-17) โ€” likely M&A announcement clustereventin 3 days

๐Ÿงฑ Systemic vendor watch Full roster โ†’

๐Ÿ”ด Snowflake17 item(s) L14D
๐Ÿ”ด PaperCut13 item(s) L14D
๐Ÿ”ด Okta11 item(s) L14D
๐Ÿ”ด Citrix / NetScaler11 item(s) L14D
๐Ÿ”ด JFrog9 item(s) L14D

๐ŸŒ Travel advisories Sources โ†’

Hover a highlighted country for detail.

Simple World MapAuthor: Al MacDonaldEditor: Fritz LekschasLicense: CC BY-SA 3.0ID: ISO 3166-1 or "_[a-zA-Z]" if an ISO code is not availableAfghanistan โ€” Do Not TravelHaiti โ€” Do Not TravelIran โ€” Do Not TravelNorth Korea โ€” Do Not TravelMyanmar (Burma) โ€” Do Not TravelMexico โ€” Reconsider TravelPakistan โ€” Reconsider TravelRussia โ€” Do Not TravelUkraine โ€” Do Not Travel
Do Not TravelReconsider TravelExercise Caution
Latest updates
Ukraine Do Not Travel2026-07-21
Active armed conflict with Russia
Russia Do Not Travel2026-07-21
Arbitrary enforcement of local law, wrongful detention of US citizens, military conflict with Ukraine
North Korea Do Not Travel2026-07-21
Serious risk of arrest and long-term detention of US citizens
Iran Do Not Travel2026-07-21
Risk of arrest, wrongful detention of US citizens
Afghanistan Do Not Travel2026-07-21
Terrorism, civil unrest, risk of kidnapping
Myanmar (Burma) Do Not Travel2026-07-21
Civil war conditions, armed conflict
Haiti Do Not Travel2026-07-21
Kidnapping, crime, civil unrest
Pakistan Reconsider Travel2026-07-21
Terrorism, sectarian violence
Mexico Reconsider Travel2026-07-21
Crime and kidnapping (varies significantly by state)

Today's briefing

๐Ÿ’ผ M&A ACTIVITY
No new cybersecurity M&A deals announced in the Sep 11โ€“12 window.MediumWeekend quiet.
L30D summary (Aug 13 โ€“ Sep 12): 5 deals tracked, $669.5M+ in disclosed value. Biggest: Munich Re (via HSB) โ†’ At-Bay $575M (cyber insurtech/MDR); Datavault AI โ†’ CyberCatch Holdings $94.5M all-cash (AI-enabled compliance). Consolidation theme unchanged: insurers buying prevention capability rather than just underwriting risk (Munich Re/At-Bay), and platforms bolting on AI-security or agentic-AI tooling at undisclosed values (Fortinet/Virtue AI, Brinqa/PlexTrac, Socure/Fravity). The prior 30-day window's two smallest rounds (A Security $37M Series B, Tenet Security $6M seed, both Aug 12) have now rolled off the trailing window. SecurityWeek M&A Tracker
โš ๏ธ CRITICAL BREACHES & INCIDENTS
Florida's DMV confirms the ShinyHunters intrusion this desk flagged as an unverified claim Sep 8 โ€” and the root cause is a single officer's personal device.HighGovernment & Public SectorFLHSMV says it learned of the breach Sep 4, traced entry to a Plant City Police Department user account whose DMV/DAVID-database credentials were improperly stored on the officer's personal device rather than an agency-issued one, and calls the intrusion "quickly mitigated" with no further breach ongoing. ShinyHunters' own claim of 200,000+ driver records remains the attacker's figure, unconfirmed by the state; the intrusion vector (one non-agency device holding law-enforcement-grade database access) is the new, confirmed detail. The Record
General Santos Doctors Hospital, a 280-bed tertiary hospital in the Philippines, listed on Rhysida's leak site Sep 10.HighHealthcare & Life Sciences๐ŸŸฅ Unverified DLS claim โ€” roughly 3.5M files (2.44TB) allegedly exfiltrated, including name-tagged diagnostic scans, cancer-center records with national health-insurance IDs, and a staff register with professional license numbers; no hospital confirmation yet, verify before treating as a breach. Ransomware.live
Spain's national meteorological agency (AEMET) listed by Panzer, a RaaS brand that launched its leak site Aug 5 and already claims 16โ€“21 victims across 11 countries.MediumGovernment & Public Sector๐ŸŸฅ Unverified DLS claim โ€” roughly 5GB allegedly exfiltrated, 20โ€“21 day publication deadline; no agency confirmation yet, verify before treating as a breach. EscudoDigital
๐Ÿ”“ CRITICAL VULNERABILITIES
CISA adds a maximum-severity GitLab path-traversal flaw to KEV Sep 11, one day after attackers began exploiting it.CriticalTechnology & SoftwareCVE-2026-85706 (CVSS 10.0) lets an unauthenticated attacker abuse GitLab's repository commits API to read arbitrary files off a self-managed CE/EE server โ€” configs, secrets, anything the app can reach โ€” with no account or user interaction required. Affects versions 18.7โ€“19.1.7, 19.2โ€“19.2.5, and 19.3โ€“19.3.1; patch to 19.1.8/19.2.6/19.3.2 or later. Federal remediation due Sep 14. BleepingComputer ยท CISA KEV
Check Point discloses two 9.8-rated, unauthenticated RCE flaws in VPN certificate handling across its Quantum Security Gateway line, Spark Firewalls, and Security Management Server.HighTechnology & SoftwareCVE-2026-85102 is a certificate trust-validation bypass during VPN negotiation; CVE-2026-85103 is a heap buffer overflow in certificate decoding โ€” both remote, unauthenticated, no user interaction. Check Point says it has seen no exploitation as of disclosure (Sep 9); LivePatch Take 24 and Jumbo Hotfix Accumulator updates are available now. Given WatchGuard's Firebox flaw took nine months to reach ransomware use after KEV listing, "not yet exploited" is not a reason to delay patching VPN gateways. The Hacker News
๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY
No new CISA/FBI/NSA/NCSC advisory in the Sep 11โ€“12 windowMediumtoday's operative federal action is the GitLab KEV addition above, issued by CISA Sep 11.
๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY
Baseline DLS volume Sep 11โ€“12: roughly a dozen new named victims across tracked leak sitesMedium, including Safepay (compunnel.com, US IT/staffing), RansomHouse (California School Employees Association), Akira (Eagle Construction, US), Beast (M800/CINNOX, Hong Kong telecom-API provider), and EMPERADOR (EJ Easy Job, Colombia) โ€” none individually clears the bar for a new tracker entry beyond Rhysida/General Santos and Panzer/AEMET, noted above.
Anthropic's fourth threat-intelligence report (published Sep 10, covering activity Anthropic identified and shut down between December 2025 and August 2026) discloses it dismantled five illicit-distillation campaigns from seven China-based AI labs โ€” Alibaba, DeepSeek, Moonshot AI, MiniMax, StepFun, Z.AI, and one more โ€” that generated nearly 190 million Claude exchanges.HighAlibaba's campaign alone accounted for 151M+ exchanges from over 3,500 accounts Anthropic describes as fraudulent, peaking near 3 million queries/day, allegedly to improve its Qwen models. This is Anthropic's own confirmation of the pattern the NSA/CISA/FBI joint advisory AA26-251A attributed to the same six labs by name on Sep 8 โ€” new here is the operator-level detail (Alibaba specifically, exchange volumes, account counts) and that Anthropic frames it as a nation-state-scale IP-extraction operation, not merely policy-violating API use. Anthropic
๐ŸŒ GEOPOLITICS
Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
Anthropic naming a specific Chinese company (Alibaba) and a specific number (151 million exchanges) as the source of the largest AI-capability extraction it has measured turns a diplomatic-hedge issue into a quantified, single-vendor accusation three days before the CISA/FBI/NSA advisory's own six-lab attribution had fully settled into coverage โ€” and it lands two weeks ahead of the Sep 24 Trump-Xi summit.HighTechnology & SoftwareCybersecurityWhere AA26-251A (Sep 8) named six labs generically as running "industrial-scale" distillation, Anthropic's own report puts a dollar-and-scale figure behind one company's alleged conduct, which is harder for Beijing to wave off as generic state-linked activity and harder for US trade negotiators to leave out of the agenda. Watch whether Alibaba or the Chinese government issues a direct rebuttal (as opposed to the usual boilerplate denial), and whether this becomes a specific line item in pre-summit talking points rather than background noise. Anthropic
A state government's most sensitive law-enforcement database access failing because one officer stored credentials on a personal phone is a policy problem no patch fixes, and it is happening in the same month a private identity-verification vendor (IDScan.net) leaked 153M+ driver's licenses for unrelated reasons.HighGovernment & Public SectorTechnology & SoftwareFlorida's DMV breach and IDScan.net's slow-walked disclosure are two separate incidents with one shared structural cause: identity-document infrastructure โ€” public and private โ€” runs on access-control assumptions (agency-issued devices, indexed disclosure) that keep failing in ordinary, boring ways rather than exotic ones. For portfolio companies serving government identity/DMV contracts, the audit question is device-issuance policy enforcement, not just encryption-at-rest. The Record
GitLab's flaw going from disclosure to confirmed exploitation in under 24 hours, set against WatchGuard's nine-month gap reported here Sep 11, brackets the actual range of the "known exploited" clock rather than picking one end of it as typical.MediumTechnology & SoftwareBoth are now federally mandated remediation items; the operational lesson for portfolio companies running self-managed developer infrastructure (GitLab, Jenkins, GitHub Enterprise) is that internet-facing dev-tooling now sits in the same rapid-exploitation tier as edge network appliances, not a slower "internal tooling" risk class. BleepingComputer
Two previously-unseen ransomware brands (Vexy, first observed Sep 10; Panzer, live since Aug 5) each reaching double-digit, multi-country victim counts within roughly a month of appearing is a market-structure signal worth tracking rather than dismissing as routine churn.MediumCybersecurityIf barriers to standing up a credible RaaS operation โ€” leaked builders, commoditized affiliate recruitment โ€” keep falling, the leaderboard's top ranks matter less than the total addressable pool of active brands at any given time; this desk has added the pattern to the signals watchlist. Ransomware.live