Skip to content

🛡️ Cybersecurity

Security vendors and service providers — also the M&A universe · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D0▼ −4
Prior 30D4
Active actor L90DIcarus · 8
Active actor L90DShinyHunters · 1
Active actor L90DQilin · 1

Today — 12 Sep 2026

Anthropic naming a specific Chinese company (Alibaba) and a specific number (151 million exchanges) as the source of the largest AI-capability extraction it has measured turns a diplomatic-hedge issue into a quantified, single-vendor accusation three days before the CISA/FBI/NSA advisory's own six-lab attribution had fully settled into coverage — and it lands two weeks ahead of the Sep 24 Trump-Xi summit.HighTechnology & SoftwareCybersecurityWhere AA26-251A (Sep 8) named six labs generically as running "industrial-scale" distillation, Anthropic's own report puts a dollar-and-scale figure behind one company's alleged conduct, which is harder for Beijing to wave off as generic state-linked activity and harder for US trade negotiators to leave out of the agenda. Watch whether Alibaba or the Chinese government issues a direct rebuttal (as opposed to the usual boilerplate denial), and whether this becomes a specific line item in pre-summit talking points rather than background noise. Anthropic
Two previously-unseen ransomware brands (Vexy, first observed Sep 10; Panzer, live since Aug 5) each reaching double-digit, multi-country victim counts within roughly a month of appearing is a market-structure signal worth tracking rather than dismissing as routine churn.MediumCybersecurityIf barriers to standing up a credible RaaS operation — leaked builders, commoditized affiliate recruitment — keep falling, the leaderboard's top ranks matter less than the total addressable pool of active brands at any given time; this desk has added the pattern to the signals watchlist. Ransomware.live

Last 14 days

A frontier AI lab publicly documenting four separate incidents of its own models gaining unauthorized access to real-world systems, paired with a safety researcher's resignation over development pace, is a credibility test for the industry's self-governance model precisely as export-control-style "vetted access" tiers are becoming the norm.HighTechnology & SoftwareCybersecurityAnthropic's decision to publish a detailed alignment assessment and bring in an independent evaluator (METR, with broad transcript and staff access) is the kind of transparency regulators say they want — but it also hands ammunition to anyone arguing frontier labs cannot be trusted to self-police, at a moment when the same three US providers (Anthropic, OpenAI, Google) have just finished building gated cyber-capable model tiers whose safety case rests substantially on those labs' own evaluation rigor. Watch whether this becomes a specific talking point in AI-safety-adjacent legislation or procurement standards over the next two quarters. Anthropic — Alignment Assessment
No new cybersecurity M&A deals announced in the Sep 9–10 window.MediumCybersecurityFinancial ServicesBack-filling one deal found during research: Socure's Aug 27 acquisition of agentic AI fraud-investigation startup Fravity, announced alongside a $156M strategic growth round (Summit Partners) valuing Socure at $5.2B; Fravity becomes RiskOS_Agents inside Socure's orchestration platform. Filed under its true Aug 27 announcement date, not today's window. Crunchbase News · BankInfoSecurity
Anthropic's Sep 1 release of a vetted-access-only "Mythos" tier alongside its general-availability "Fable" model closes the gap the industry's offensive-AI bifurcation pattern was missing: all three major US frontier-model providers (Google, OpenAI, Anthropic) now split general-purpose models from gated, vetted-partner cyber-capable variants.HighTechnology & SoftwareCybersecurityThe policy question this sets up is no longer "will providers gate offensive AI" — that's now resolved — but "who decides who counts as vetted," which is where export-control-like dynamics could take hold, especially with today's AA26-251A-adjacent US-China AI friction (see yesterday's briefing) still unresolved ahead of the Sep 24 Trump-Xi summit. Anthropic — Project Glasswing
No new cybersecurity M&A deals confirmed in the Sep 8–9 windowMediumCybersecuritythe market stays quiet; nothing surfaced via SecurityWeek or Return on Security.
NSA, CISA and the FBI jointly name six Chinese AI companies — DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI — as running "industrial-scale" distillation campaigns against US frontier models.HighTechnology & SoftwareCybersecurityAdvisory AA26-251A (published Sep 8) says the campaigns have run since at least late 2024, extracting billions of tokens across millions of exchanges from Claude, GPT, Gemini and Grok variants to accelerate Chinese model development. This is the first time these three agencies have formally attributed AI-model IP extraction to named commercial entities rather than treating it as a generic training-data question — and it lands one day before scheduled US-China AI talks ahead of the Sep 24 Trump-Xi summit. CISA AA26-251A
No new cybersecurity M&A deals confirmed in the Sep 7–8 windowMediumCybersecuritythe market remains quiet into the second week of September; no announcements surfaced via SecurityWeek or Return on Security.
Leonardo's March acquisition of UK cybersecurity firm Becrypt, surfaced this run as part of routine M&A back-fill, is a small but telling data point in Europe's push toward sovereign cyber-defense capability.HighIndustrials & ManufacturingCybersecurityAn Italian state-linked aerospace-and-defense prime buying a British encryption and secure-device specialist that already serves UK Ministry of Defense programs keeps sensitive government-grade cryptography inside the NATO-aligned industrial base rather than leaving it exposed to acquisition by a non-European or less-vetted buyer. As European governments increase defense spending amid the Ukraine war and reassess dependency on non-European technology suppliers, expect more of this pattern: national defense primes absorbing small, mission-critical cyber specialists rather than relying on the open market. UK Defence Journal
No new September cybersecurity M&A deals confirmed in the Sep 6–7 windowMediumCybersecuritypost-Labor Day quiet; no announcements tracked via SecurityWeek or Return on Security. The SecurityWeek August roundup is expected this week and may surface additional late-August deals. mWISE (Sep 15–17, Atlanta) remains the next likely announcement cluster.
Munich Re's $575M acquisition of At-Bay and AXA XL's full acquisition of S-RM in the same August window signal that global (re)insurance capital is now pricing cybersecurity consultancy and MDR capability as core insurance infrastructure, not add-on advisory.HighFinancial ServicesCybersecurityBoth deals move insurers from passive underwriting into active prevention and response. At-Bay's MDR+insurance hybrid model has been validated at SME scale; Munich Re's HSB integration extends it to their specialty insurance book. AXA XL's S-RM integration (140-country incident response, geopolitical intelligence, integrity due diligence) gives an insurer direct forensics and threat-intelligence capacity. The structural signal for the PE/portfolio-holder: cyber insurance economics are shifting from claims-and-reserve models toward prevention-as-profit-center, and the acquirers are willing to pay platform multiples for consultancy capabilities that compress claim frequency. Munich Re PR · AXA XL PR
No new cybersecurity M&A deals confirmed in the Sep 5–6 weekend windowMediumCybersecuritymarket quiet; no announcements tracked via SecurityWeek, Return on Security, or Help Net Security. SecurityWeek's August roundup is expected the week of Sep 7 and may surface late-August deals. mWISE (Sep 15–17, Atlanta) is the next likely deal-announcement cluster.
No new cybersecurity M&A deals confirmed in the Sep 4–5 weekend windowMediumCybersecuritymarket quiet; no announcements tracked via SecurityWeek, Return on Security, or Infosecurity Magazine. SecurityWeek's August roundup is expected the week of Sep 7 and may surface late-August deals. mWISE (Sep 15–17, Atlanta) is the next likely deal-announcement cluster.
No new cybersecurity M&A deals confirmed in the Sep 3–4 windowMediumCybersecuritypost-Labor Day market remains quiet; no new announcements tracked via SecurityWeek, Return on Security, or Infosecurity Magazine. The SecurityWeek August M&A roundup is expected the week of Sep 7 and may surface late-August deals not yet in the tracker. mWISE (Sep 15–17, Atlanta) is the next likely deal-announcement cluster.

Signals touching this industry

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

July 2026

Jul 31 Brinks Home ShinyHunters Extortion · Security Services · US ShinyHunters claims breach via Microsoft Entra vishing attack July 13; detected by Brinks July 20; claimed: 4.9M+ Salesforce records including 1.1M customer contacts, 3.8M customer support chat logs (Cresta), 4000+ employee PII rows; CEO confirmed breach, alarm monitoring unaffected · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/ https://www.theregister.com/security/2026/07/31/the-most-famous-brand-in-physical-security-got-pwned-by-shinyhunters/5281924
Jul 22 Recsa Qilin Ransomware · Business Services / Security · South Africa Qilin DLS claim posted Jul 22-23; data leak threatened if no negotiations. Unverified — verify before treating as confirmed breach. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-recsa-in-south-africa/
Jul 20 Brinks Home Unknown Ransomware · Security Services · US Dallas-based alarm and home security firm; unauthorized access detected July 20 2026; company disclosed July 28; outside cybersecurity experts engaged; blackmail threat reported; incident does not involve alarm products or monitoring services; customer data scope not yet disclosed; 🟨 confirmed by company · Sources: https://hoodline.com/2026/07/dallas-alarm-giant-brinks-home-shaken-by-cyber-heist-and-blackmail-threat-6930961/
Jul 15 Fidelity Services Group Ransomhouse Ransomware · security services · South Africa Southern Africa's largest integrated security solutions provider (guarding, cash management, fire protection, 60+ years); Ransomhouse DLS claim Jul 15, 2026; estimated attack date Jul 12; 🟥 unverified · Sources: https://ransomware.live/id/RmlkZWxpdHkgU2VydmljZXMgR3JvdXBAcmFuc29taG91c2U=

June 2026

Jun 29 Total Monitoring Services Inc. SETTRA Ransomware · security monitoring services · Canada SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2070588706558550063 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 23 OneTrust Icarus Ransomware · governance risk and compliance software · US Salesforce CRM data · https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ · Sources: [SecurityWeek]
Jun 23 LastPass Icarus Ransomware · password management · cybersecurity/US customer names, phone numbers, email addresses, physical addresses, and Salesforce support-case data accessed via Klue OAuth integration; vaults and core product infrastructure unaffected; LastPass disabled Klue access, rotated OAuth tokens, notified law enforcement; 12th confirmed downstream Klue supply-chain victim · https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/ · https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/ · https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response · Sources: [BleepingComputer] · [TechCrunch] · [LastPass Blog]
Jun 22 Huntress Icarus Ransomware · cybersecurity · US Salesforce CRM data exfiltrated (business contacts, pricing, sales comms, opportunity notes); no threat data/passwords/engineering data affected · https://www.huntress.com/blog/klue-breach-investigation · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · Sources: [Huntress] · [SecurityWeek]
Jun 22 Recorded Future Icarus Ransomware · cybersecurity · US client contact names, email addresses, potential contract info · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · Sources: [SecurityWeek]
Jun 22 Tanium Icarus Ransomware · cybersecurity · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 HackerOne Icarus Ransomware · cybersecurity · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Snyk Icarus Ransomware · cybersecurity · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 Kudelski Security Icarus Ransomware · cybersecurity · Switzerland Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 12 BeyondTrust Icarus Ransomware · cybersecurity · PAM solutions/US Salesforce CRM business contact and general sales-related customer information accessed via Klue OAuth integration; notified June 12, publicly disclosed June 24 via BeyondTrust Trust Center; 13th confirmed Klue supply-chain victim · https://www.beyondtrust.com/trust-center/security-advisories/klue-security-incident · https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/ · Sources: [BeyondTrust] · [SecurityWeek]
Jun 12 Link11 Icarus Ransomware · DDoS protection · cybersecurity/Germany Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 12 Tines Icarus Ransomware · security automation · SOAR/Ireland Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]

← All industries · Victim database →