<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>News Agent — Government &amp; Public Sector</title><link>/industries/public-sector/</link><description>Cyber threat intelligence for the Government &amp; Public Sector industry — daily-brief items tagged to this slice.</description><item><title>Florida&#x27;s DMV confirms the ShinyHunters intrusion this desk flagged as an unverified claim Sep 8</title><link>/briefings/2026/09/12/2026-09-12/</link><guid isPermaLink="false">2026-09-12-Florida&#x27;s DMV confirms the ShinyHunters intrusion this desk </guid><pubDate>Sat, 12 Sep 2026 06:00:00 +0000</pubDate><description>Florida&#x27;s DMV confirms the ShinyHunters intrusion this desk flagged as an unverified claim Sep 8 — and the root cause is a single officer&#x27;s personal device. FLHSMV says it learned of the breach Sep 4, traced entry to a Plant City Police Department user account whose DMV/DAVID-database credentials were improperly stored on the officer&#x27;s personal device rather than an agency-issued one, and calls the intrusion &quot;quickly mitigated&quot; with no further breach ongoing. ShinyHunters&#x27; own claim of 200,000+ driver records remains the attacker&#x27;s figure, unconfirmed by the state; the intrusion vector (one non-agency device holding law-enforcement-grade database access) is the new, confirmed detail. The Record [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Spain&#x27;s national meteorological agency (AEMET) listed by Panzer, a RaaS brand that launched its leak site Aug 5 and already claims 16–21 vic</title><link>/briefings/2026/09/12/2026-09-12/</link><guid isPermaLink="false">2026-09-12-Spain&#x27;s national meteorological agency (AEMET) listed by Pan</guid><pubDate>Sat, 12 Sep 2026 06:00:00 +0000</pubDate><description>Spain&#x27;s national meteorological agency (AEMET) listed by Panzer, a RaaS brand that launched its leak site Aug 5 and already claims 16–21 victims across 11 countries. 🟥 Unverified DLS claim — roughly 5GB allegedly exfiltrated, 20–21 day publication deadline; no agency confirmation yet, verify before treating as a breach. EscudoDigital [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>A state government&#x27;s most sensitive law-enforcement database access failing because one officer stored credentials on a personal phone is a </title><link>/briefings/2026/09/12/2026-09-12/</link><guid isPermaLink="false">2026-09-12-A state government&#x27;s most sensitive law-enforcement database</guid><pubDate>Sat, 12 Sep 2026 06:00:00 +0000</pubDate><description>A state government&#x27;s most sensitive law-enforcement database access failing because one officer stored credentials on a personal phone is a policy problem no patch fixes, and it is happening in the same month a private identity-verification vendor (IDScan.net) leaked 153M+ driver&#x27;s licenses for unrelated reasons. Florida&#x27;s DMV breach and IDScan.net&#x27;s slow-walked disclosure are two separate incidents with one shared structural cause: identity-document infrastructure — public and private — runs on access-control assumptions (agency-issued devices, indexed disclosure) that keep failing in ordinary, boring ways rather than exotic ones. For portfolio companies serving government identity/DMV contracts, the audit question is device-issuance policy enforcement, not just encryption-at-rest. The Record [🌍 GEOPOLITICS]</description></item><item><title>A Sandworm-attributed implant (Cyclops Blink) resurfacing via a fresh Cisco FMC zero-day, in the same disclosure alongside a Qilin ransomwar</title><link>/briefings/2026/09/10/2026-09-10/</link><guid isPermaLink="false">2026-09-10-A Sandworm-attributed implant (Cyclops Blink) resurfacing vi</guid><pubDate>Thu, 10 Sep 2026 06:00:00 +0000</pubDate><description>A Sandworm-attributed implant (Cyclops Blink) resurfacing via a fresh Cisco FMC zero-day, in the same disclosure alongside a Qilin ransomware-affiliate cluster on the identical CVE, is a concrete data point for a broader pattern insurers and defense planners should be pricing: Russian state pre-positioning and Russian-speaking criminal ransomware crews increasingly share the same initial-access infrastructure and timeline, whether or not they coordinate. Cyclops Blink was NCSC-UK/CISA/FBI-attributed to Sandworm (GRU Unit 74455) in 2022 on WatchGuard/ASUS edge devices; its reappearance on Cisco&#x27;s flagship firewall-management platform shows the same actor rotating to whatever edge-management software has a fresh pre-auth RCE. Portfolio companies with Cisco FMC deployments should treat this as both an espionage and a ransomware precursor risk simultaneously, not sequentially. Talos Intelligence [🌍 GEOPOLITICS]</description></item><item><title>ShinyHunters claims a second, unrelated US government-adjacent target within the same week: Florida&#x27;s DAVID driver/vehicle database, ~200,00</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-ShinyHunters claims a second, unrelated US government-adjace</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>ShinyHunters claims a second, unrelated US government-adjacent target within the same week: Florida&#x27;s DAVID driver/vehicle database, ~200,000 records, via a password-reset flaw. The group told BleepingComputer it compromised accounts belonging to DMV employees and an FBI agent, then pulled records by iterating IDs; as proof it released a screenshot of Jeffrey Epstein&#x27;s DMV record. Florida&#x27;s Highway Safety and Motor Vehicles agency (FLHSMV) has not confirmed the claim. 🟥 Unverified DLS-style claim — the leak-site deadline is Sep 11. A confirmed compromise of a law-enforcement lookup database would raise both public-safety and Driver&#x27;s Privacy Protection Act liability questions distinct from a standard PII breach. BleepingComputer [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>ShinyHunters runs the same playbook twice in one week against very different targets</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-ShinyHunters runs the same playbook twice in one week agains</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>ShinyHunters runs the same playbook twice in one week against very different targets — a Fortune 10 healthcare distributor and a state DMV — underscoring that its methodology (social-engineer or password-reset your way to a data store, then extort) doesn&#x27;t require a specific tech stack. McKesson via voice-phished Okta SSO into Salesforce/Snowflake; Florida DAVID via a password-reset flaw. See Intelligence Agency Alerts above for the group&#x27;s other current AI-related news cycle context. BleepingComputer [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>A state DMV database breach claim, proven in part with a dead-and-notorious public figure&#x27;s own record, is a reminder that government data h</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-A state DMV database breach claim, proven in part with a dea</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>A state DMV database breach claim, proven in part with a dead-and-notorious public figure&#x27;s own record, is a reminder that government data has a specific credibility problem attackers exploit deliberately. Using Jeffrey Epstein&#x27;s DMV file as proof-of-breach is a calculated choice: it is independently verifiable and generates press attention no ordinary citizen&#x27;s record would. Government agencies holding law-enforcement-grade lookup data (DMV, voter rolls, benefits systems) should assume any high-profile individual&#x27;s record in their systems is a standing target for exactly this kind of attention-maximizing proof-of-hack move, independent of the record&#x27;s actual sensitivity. BleepingComputer [🌍 GEOPOLITICS]</description></item><item><title>No new CISA/FBI/NSA/NCSC advisories in the Sep 7–8 window. The most recent KEV activity remains the Sep 2 seven-CVE batch and the Sep 4 Chro</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-No new CISA/FBI/NSA/NCSC advisories in the Sep 7–8 window. T</guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>No new CISA/FBI/NSA/NCSC advisories in the Sep 7–8 window. The most recent KEV activity remains the Sep 2 seven-CVE batch and the Sep 4 Chrome V8 addition (both previously covered); FCEB deadlines from those batches remain in force — see Critical Vulnerabilities and the site&#x27;s Dates to Watch panel for the Sep 9/14/18 remediation deadlines still open. [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>Berlin task force update: election infrastructure confirmed unaffected by the Rhysida data dump; forensic review of the 5.79TB continues</title><link>/briefings/2026/09/08/2026-09-08/</link><guid isPermaLink="false">2026-09-08-Berlin task force update: election infrastructure confirmed </guid><pubDate>Tue, 08 Sep 2026 06:00:00 +0000</pubDate><description>Berlin task force update: election infrastructure confirmed unaffected by the Rhysida data dump; forensic review of the 5.79TB continues — Berlin&#x27;s Chief Digital Officer has stood up a task force combining the LKA, data-protection officials, and both affected Senate departments to assess the dumped data. Senator Iris Spranger stated no evidence of compromised election data and that the Sep 20 election&#x27;s technical environment remains secure. BleepingComputer [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>Berlin Senate / Rhysida</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-Berlin Senate / Rhysida</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>Berlin Senate / Rhysida — 5.8 TB / 1.44M government files published Sep 4; critical infrastructure blueprints, police data, and federal defense plans now on the dark web; Sep 20 state election 13 days out — Rhysida&#x27;s 7-day auction countdown ended ~15:35 local time Sep 4 after the Berlin Senate refused its 30 BTC (~EUR 2M) demand. The published dataset includes blueprints for Berlin&#x27;s water and power grid infrastructure, police and LKA files, Bundeswehr documents, CBRN threat assessments, federal communication plans for a state of defense, and 12,000+ personnel records. Researchers confirmed critical infrastructure plans are in the dump. Berlin&#x27;s interior administration has maintained that election-infrastructure systems are unaffected. 🟩 Data dump confirmed by independent researchers; the files are circulating on dark web mirrors. Cybernews · BankInfoSecurity [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>CISA KEV</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-CISA KEV</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>CISA KEV — seven new entries Sep 2; SonicWall SMA1000 SSRF (CVSS 10.0) and command injection chain; federal deadline Sep 5 passed — The Sep 2 batch added CVE-2026-83548 (SonicWall SMA1000 SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection, CVSS 7.8) — chainable to unauthenticated RCE — alongside CVE-2026-9586 (Sangoma Switchvox SQL injection, CVSS 9.3), CVE-2026-82329 (JFrog Artifactory improper authentication), CVE-2026-48710 (Kludex Starlette HTTP smuggling), CVE-2026-49869 (Kestra OS command injection), and CVE-2026-59822 (BerriAI LiteLLM improper authentication). FCEB agencies had until Sep 5 to patch all seven. Non-federal organisations running SonicWall SMA1000 on 12.4.3 or 12.5.0 builds (models 6210, 7210, 8200v) should treat patch application as urgent — public PoC and in-wild exploitation confirmed before the KEV addition. CISA KEV · The Hacker News · Rapid7 [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>Rhysida</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-Rhysida</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>Rhysida — Berlin data dump confirmed; shift from extortion actor to strategic disruptor — With 1.44M files now publicly available, Rhysida has completed the full extortion-and-publish cycle against a NATO-member capital government. The dataset&#x27;s content (critical infrastructure blueprints, federal defense communication plans, CBRN assessments) makes this more than a data-theft event — the material is now freely accessible to any state actor or criminal operator interested in Berlin&#x27;s infrastructure vulnerabilities. The group has demonstrated willingness to publish even when the ransom is structurally certain to be rejected (government non-payment policy). Cybernews [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>Qilin</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-Qilin</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>Qilin — rank 1 sustained; YTD 546; no new high-profile confirmed victims in Sep 6–7 window; Sep 9 McKesson watch (ShinyHunters) remains the week&#x27;s operative deadline — Qilin DLS continues active postings without a single named critical-infrastructure or government victim in the immediate window. YTD trajectory: 546 claims across 103 countries. The ATF major-incident claim (Aug 26) remains under DOJ investigation. 🟥 ATF claim unverified. Ransomware.live [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>Rhysida&#x27;s publication of Berlin&#x27;s critical infrastructure blueprints</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-Rhysida&#x27;s publication of Berlin&#x27;s critical infrastructure bl</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>Rhysida&#x27;s publication of Berlin&#x27;s critical infrastructure blueprints — water grid, power systems, CBRN assessments, federal defense plans — is not a ransomware incident that resolved; it is a permanent intelligence windfall for any state actor with an interest in Germany&#x27;s capital. The published files are now indexed, mirrored, and searchable. Every hostile foreign intelligence service with an interest in European capital-city infrastructure now has, at zero cost, operational intelligence that Berlin spent years securing. The thirteen-days-before-election timing is secondary to the strategic consequence: Bundeswehr documents and federal state-of-defense communication plans in a publicly accessible dark-web archive represent a national-security loss that cannot be remediated by patching. Germany&#x27;s BSI and the BfV will need to assess which of the 12,076 named individuals are in sensitive roles and whether the infrastructure blueprints have been acted on before the data&#x27;s publication became public knowledge. Cybernews · BankInfoSecurity [🌍 GEOPOLITICS]</description></item><item><title>The IDScan.net breach is structurally different from a credential or PII leak: it places biometric-quality identity documentation for 153 mi</title><link>/briefings/2026/09/07/2026-09-07/</link><guid isPermaLink="false">2026-09-07-The IDScan.net breach is structurally different from a crede</guid><pubDate>Mon, 07 Sep 2026 06:00:00 +0000</pubDate><description>The IDScan.net breach is structurally different from a credential or PII leak: it places biometric-quality identity documentation for 153 million North Americans in criminal and state-actor hands, and it may have been ongoing for over a year before discovery. Driver&#x27;s license images with infrared and UV scans are the exact materials used by government border agencies and financial institutions for identity verification. A state actor possessing this dataset can fabricate credentialed personas at scale, defeating document-based identity assurance in travel, financial services, and physical access systems. The breach&#x27;s undiscovered duration — the seller claimed ongoing access for &quot;over a year&quot; — means the complete scope is unknown. The FBI investigation is the operative response action; until IDScan.net confirms the breach&#x27;s full timeline and current access status, its verification pipeline should be treated as untrusted by clients. Krebs on Security · CSO Online [🌍 GEOPOLITICS]</description></item><item><title>Rhysida / Berlin Senate</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-Rhysida / Berlin Senate</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>Rhysida / Berlin Senate — Sep 20 state election 14 days out; 30 BTC (~EUR 2M) auction active; election data confirmed not in exfiltrated set — No change in auction status. Berlin interior administration has confirmed election-infrastructure data is not in the claimed 5.79TB dataset. The auction continues to function as pre-election information-environment disruption regardless of data authenticity. 🟥 Data scope and sample authenticity unverified. Cybernews · BankInfoSecurity [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Panzer ransomware</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-Panzer ransomware</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>Panzer ransomware — 16 victims across 11 countries since August 5; emerging RaaS on trajectory toward Tier-1 — Panzer, a double-extortion RaaS that activated its leak site August 5, has claimed 16 victims across Thailand (3), Italy (2), Indonesia (2), Serbia (2), and seven others in 31 days. Sectors: technology (4), manufacturing (3), government (2), agriculture, energy, education, retail. Sep 3 victim: Dinas Komunikasi dan Informatika (Indonesian government entity). Panzer offers an 80/20 affiliate split and supports Windows, Linux, VMware ESXi, and FreeBSD ransomware builds. CISA has not yet issued an advisory; the group warrants monitoring at Tier-2. 🟥 All DLS claims; unverified. gbhackers · DeXpose / Dinas · SOCRadar / DL E&amp;C [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>CISA + G7 Cyber Security Working Group</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-CISA + G7 Cyber Security Working Group</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>CISA + G7 Cyber Security Working Group — &quot;Preparing for the Post-Quantum Era: A Call to Action&quot; published Sep 5; five-priority framework for PQC transition — The joint advisory outlines five priorities: raise awareness of quantum risk; develop national PQC strategies; advance R&amp;D for quantum-safe technologies; foster public-private partnerships; and ensure OT/IoT are not left out of scope as PQC adoption scales. The advisory is procedural rather than incident-driven but signals the G7 is treating PQC transition as a coordinated geopolitical-security priority, not an academic exercise. NIST&#x27;s final PQC standards (FIPS 203/204/205, Aug 2024) are the baseline for the transition; the advisory urges governments to accelerate implementation timelines against a 2030 &quot;harvest now, decrypt later&quot; threat window. CISA PQC · CISA Blog [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>CISA emergency directive</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-CISA emergency directive</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>CISA emergency directive — IoT device patching and inventory; Sep 5 — CISA issued an emergency directive for organisations using vulnerable IoT devices, emphasising immediate patching, asset inventory, and risk isolation for unpatched devices. Specific device classes not named in available summaries; directive appears to target the long tail of embedded devices that rarely receive emergency patch attention. Security Boulevard OT Digest [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>Qilin</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-Qilin</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>Qilin — rank 1 confirmed; YTD 546; pace unchanged; Sep 9 McKesson watch for ShintyHunters remains the headline deadline — No new high-profile Qilin victims confirmed in the Sep 5–6 window. ATF major-incident claim (Aug 26) remains under DOJ investigation. YTD: 546; L3M: 335. 🟥 ATF claim unverified. Ransomware.live [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>Panzer ransomware</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-Panzer ransomware</guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>Panzer ransomware — 16-victim, 11-country surge in 31 days; cross-platform builds; Tox-based affiliate recruitment — Panzer is now the fastest-emerging new RaaS since Gunra. Cross-platform builds (Windows, Linux, ESXi, FreeBSD) and a competitive 80/20 affiliate split position it for rapid scale. The Sep 3 Indonesian government victim indicates no sector or geography restriction. Monitor DLS for frequency acceleration — the threshold from Tier-2 to Tier-1 watch is 40+ victims/quarter at this pace. gbhackers · Security Arsenal [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>The G7 post-quantum call to action frames PQC adoption as a coordinated geopolitical-security obligation, not a vendor roadmap</title><link>/briefings/2026/09/06/2026-09-06/</link><guid isPermaLink="false">2026-09-06-The G7 post-quantum call to action frames PQC adoption as a </guid><pubDate>Sun, 06 Sep 2026 06:00:00 +0000</pubDate><description>The G7 post-quantum call to action frames PQC adoption as a coordinated geopolitical-security obligation, not a vendor roadmap — the operative threat is the 2030 &quot;harvest now, decrypt later&quot; window, and every week without PQC is a week of retrospective cryptographic exposure to China. The advisory is joint Five Eyes plus G7 — a signal that the post-quantum transition is now treated with the same alliance-coordination intensity as critical-infrastructure protection. The operative intelligence risk: state actors (foremost China, which has the world&#x27;s most advanced quantum computing programme alongside its largest signals-intelligence collection footprint) are already archiving encrypted communications from government, financial, and defence networks for decryption once sufficiently capable quantum hardware exists. An enterprise or government entity that does not begin migrating key exchange and signing algorithms now is incurring a retrospective exposure liability that cannot be patched after 2030. CISA · White House EO on PQC [🌍 GEOPOLITICS]</description></item><item><title>Rhysida / Berlin Senate</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-Rhysida / Berlin Senate</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>Rhysida / Berlin Senate — Sep 20 state election 15 days out; DLS data auction countdown active; election data confirmed not in exfiltrated set — The 30 BTC (~EUR 2M) auction for 5.79TB of Berlin Senate data remains live. Berlin interior administration has confirmed election-infrastructure data is not in the claimed dataset. Pre-election uncertainty continues to function as information-environment disruption regardless of data authenticity. 🟥 Data scope and sample authenticity unverified. Cybernews · BankInfoSecurity [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>Serbia: Citizen Lab confirms Pegasus zero-click exploit against 14 student activists and opposition politicians; iOS 18.4.1 patches the iMes</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-Serbia: Citizen Lab confirms Pegasus zero-click exploit agai</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>Serbia: Citizen Lab confirms Pegasus zero-click exploit against 14 student activists and opposition politicians; iOS 18.4.1 patches the iMessage vector — Citizen Lab and SHARE Foundation confirmed September 3–4 that at least 14 people in Serbia have been targeted with Pegasus spyware and a new NoviSpy variant since early 2026, in the largest documented wave of state-adjacent surveillance against Serbian civil society on record. Targets include student-movement members, opposition MPs, and local councillors. The Pegasus delivery used a zero-click iMessage exploit; iOS 18.4.1, released in conjunction with the disclosure, patches the underlying vulnerability. Serbian intelligence (BIA) and President Vucic deny the allegations; the European Union stated the practice would be &quot;unacceptable if confirmed.&quot; Citizen Lab attributes the tool to NSO Group. Citizen Lab / CyberScoop · The Cyber Express · Balkan Insight · TechTimes [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>No new CISA, FBI, or NSA advisories in the Sep 4–5 window</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-No new CISA, FBI, or NSA advisories in the Sep 4–5 window</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>No new CISA, FBI, or NSA advisories in the Sep 4–5 window — Weekend cadence; latest active advisories are the CISA #StopRansomware: Medusa update (Aug 18–19, 500+ CI victims) and #StopRansomware: Gunra (AA26-222A). Both remain current. [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>Qilin</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-Qilin</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>Qilin — holds rank 1; YTD 546; pace unchanged at ~140 victims/month — No new high-profile Qilin victims confirmed in the Sep 4–5 window beyond those already tracked. The ATF major-incident claim (Aug 26) remains under DOJ investigation. YTD: 546; L3M: 335. 🟥 The ATF claim is unverified. Ransomware.live [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>The confirmed Pegasus deployment against Serbian student protesters creates a direct precedent for European Union member-state concern and a</title><link>/briefings/2026/09/05/2026-09-05/</link><guid isPermaLink="false">2026-09-05-The confirmed Pegasus deployment against Serbian student pro</guid><pubDate>Sat, 05 Sep 2026 06:00:00 +0000</pubDate><description>The confirmed Pegasus deployment against Serbian student protesters creates a direct precedent for European Union member-state concern and accelerates the push for binding EU spyware regulation — the political and legal risk to NSO Group is now European, not just Israeli. The Serbia case follows the Predator/Pegasus findings against Greece, Hungary, Spain, and Poland — all EU member states — that have driven two years of European Parliament investigation. Serbia, though not an EU member, holds EU accession candidate status and is in active accession negotiations. The EU&#x27;s &quot;unacceptable if confirmed&quot; statement is weaker than it sounds — it stops well short of sanctions or accession-pause — but the Citizen Lab confirmation means the evidentiary standard for stronger action is now met. The proximate risk for enterprise security teams: the same zero-click iMessage vector documented by Citizen Lab requires iOS 18.4.1 to patch; any unpatched iPhone in a high-risk-individual threat model (executive, journalist, board member) should be updated immediately. CyberScoop · TechTimes [🌍 GEOPOLITICS]</description></item><item><title>Rhysida / Berlin state government</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-Rhysida / Berlin state government</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>Rhysida / Berlin state government — data auction countdown underway; 16 days to Berlin&#x27;s September 20 parliamentary election; officials confirm election data not affected — Rhysida began the countdown for auctioning 5.79TB of Berlin Senate Department data (30 BTC starting bid, approximately EUR 2M) on August 28; the auction window is active. Berlin&#x27;s interior administration has confirmed election infrastructure data is not included in the claimed dataset. The pre-election timing is operationally significant: even if data is not released before voting day, the uncertainty functions as information-environment disruption. Multiple German security agencies are investigating. 🟥 Data scope and sample authenticity unverified. Cybernews · BankInfoSecurity · Security Affairs [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>CISA/FBI/HHS updated Medusa ransomware advisory (Aug 18–19)</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-CISA/FBI/HHS updated Medusa ransomware advisory (Aug 18–19)</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>CISA/FBI/HHS updated Medusa ransomware advisory (Aug 18–19) — 500+ critical infrastructure victims confirmed; new TTPs documented; healthcare/public health sector specifically highlighted — The joint agencies updated the #StopRansomware: Medusa advisory (originally AA25-071A, March 2025) on August 18–19, 2026, incorporating FBI threat intelligence through April 2026. Key updates: 500+ critical infrastructure victims confirmed (up from 300+ in the March 2025 advisory); Medusa affiliates (including nation-state-linked Storm-1175) now exploit zero-days within 24 hours of disclosure and sometimes days before public announcement; access brokers now compensated $100 to $1M depending on exclusivity. The updated advisory specifically calls out the Healthcare and Public Health sector as primary targeting focus. Despite the Medusa Blog DLS going dark in February 2026, the underlying infrastructure and affiliate network remain active. Healthcare organizations should consult the updated advisory for new IOCs and ATT&amp;CK technique mappings. CISA Updated Advisory · Help Net Security · The Record [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>The Trump-Xi state summit scheduled for September has transformed AI into a strategic flashpoint between the world&#x27;s two largest cyber power</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-The Trump-Xi state summit scheduled for September has transf</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>The Trump-Xi state summit scheduled for September has transformed AI into a strategic flashpoint between the world&#x27;s two largest cyber powers — and the cyber risk dimension of that summit is mostly invisible in mainstream analysis. Per CNBC reporting (Sep 2), the summit&#x27;s &quot;fiercest area of rivalry&quot; is AI, against a backdrop of tit-for-tat sanctions (US: banned humanoid-robot imports, sanctioned Chinese shipping operators handling Iranian fuel, entity-listed 40+ Chinese firms; China: retaliatory measures labeled &quot;restrained&quot;). Both nations have ongoing, documented cyber-espionage programs specifically targeting the other&#x27;s AI research infrastructure — from Salt Typhoon&#x27;s US telco position (access to AI-development communications) to China&#x27;s Volt Typhoon pre-positioning in US utilities (potential leverage over AI-datacenter power supply). The summit creates a temporary political incentive to keep cyber operations below the escalation threshold — but also an intelligence-collection premium in the weeks before it. CNBC · CSIS [🌍 GEOPOLITICS]</description></item></channel></rss>
