the daily brief
Cyber / Brief — 16 Sep 2026
Britain, the United States and the Netherlands jointly unmasked an Iranian state spyware operation — codenamed CHOSEN BRICK — that lures dissidents, activists and journalists with elaborate ruses, in one case a faked MRI scan, before turning their own phones into listening posts run over…
Britain, the United States and the Netherlands jointly unmasked an Iranian state spyware operation — codenamed CHOSEN BRICK — that lures dissidents, activists and journalists with elaborate ruses, in one case a faked MRI scan, before turning their own phones into listening posts run over Telegram, the latest sign that Tehran's intelligence services treat émigré critics as targets for surveillance and, the agencies warn, worse. Closer to home for millions of ordinary customers, the Texas utility CenterPoint Energy confirmed that a hacker drained personal records on some 7.49 million people through an exposed, poorly-guarded interface — a reminder that the soft underbelly of a critical-infrastructure operator is usually the billing database, not the grid — while researchers charted an industrialised fraud economy of rented remote-access trojans, browser-hijacking bank malware and Chinese-language laundering marketplaces feeding the global scam machine. And the argument over how fast to build AI grew louder and stranger: OpenAI was reported to be sounding out investors at a valuation north of $1.2 trillion just days after its own leadership called for the industry to slow down, Nvidia's Jensen Huang insisted the sector "doesn't need any new laws" and Mark Zuckerberg backed independent evaluators over any pause — even as President Trump dismissed safety fears as a "hoax" and EU governments prepared to meet on whether to hold the line on the bloc's AI rulebook.
Top Stories
- CISA: Critical VMware RCE flaw now exploited by ransomware gangs — BleepingComputer · Cybersecurity & Threats
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists — The Hacker News · Threat Intelligence (CTI)
- OpenAI Weighs Funding Round at Over $1.2 Trillion Valuation — Bloomberg Technology · AI & Power
- EU countries to discuss AI rules as Trump calls safety warnings a ‘hoax’ — Cybersecurity and Data Protection – POLITICO · EU & Technology
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens — The Hacker News · Cybersecurity & Threats
AI & Power
OpenAI Weighs Funding Round at Over $1.2 Trillion Valuation — Bloomberg Technology
Why it matters: OpenAI reportedly sounding out investors at a valuation north of $1.2 trillion — days after its own leadership called for the industry to slow down — is the central contradiction of the AI moment in one headline: the loudest voice for caution is also raising money faster and larger than any company in history.
OpenAI is in early talks with investors about a pre-IPO funding round that would value it at more than $1.2 trillion, according to reporting on discussions initiated by investors on 15 September — a figure that would eclipse its $730-billion valuation in February and the $852-billion round closed on 31 March, on the back of annualised revenue that passed $40 billion after the GPT-5.6 release. The talks matter because they capture the defining tension of the fortnight: OpenAI's leadership joined the frontier labs' call to slow cutting-edge AI development barely a week ago, yet the company is simultaneously courting the largest private valuation ever recorded, underscoring that the commercial gravity pulling toward acceleration is enormous even among those urging restraint. Sam Altman has said a 2026 IPO would be 'ill-advised,' so the round is a private-market bet on OpenAI's trajectory rather than a step toward public listing. For Europe — where the AI Act is being tested against exactly this dynamic of breakneck commercial momentum — the scale of capital chasing frontier AI is a reminder that governance is being written against a counterparty raising sums that dwarf most national research budgets, and that the incentives of the firms building the technology run hard toward speed regardless of the safety rhetoric.
Nvidia’s Huang Says AI Industry Doesn’t Need Any New Laws — Bloomberg Technology
Why it matters: Nvidia's Jensen Huang declaring that the AI industry 'doesn't need any new laws' is the accelerationist case stated by the company that sells the picks and shovels — the chipmaker with the most to gain from unchecked expansion arguing, with Trump's backing, that regulation is a solution in search of a problem.
Nvidia CEO Jensen Huang said the AI industry does not need any new laws, doubling down after an onstage appearance with President Trump and aligning the world's most valuable chipmaker squarely with the anti-regulation camp. The stance matters because Nvidia is the primary hardware beneficiary of the AI build-out, and its chief executive publicly rejecting new rules — at the moment frontier labs are calling for restraint, insiders are warning of existential risk, and markets are wobbling on safety fears — lends heavyweight commercial weight to the accelerationist position. It fits the fortnight's hardening split between those urging guardrails (the slow-down call, Obama's rebuke, EU lawmakers) and those insisting regulation would 'kill the golden goose,' with Huang and Trump anchoring the latter. For Europe, whose AI Act is precisely the kind of binding regime Huang argues against, the intervention is a marker of the transatlantic gulf: the dominant US industry voices are lobbying against new law while Brussels enforces it, and the pressure on the EU to soften its rulebook is coming partly from exactly these quarters.
Zuckerberg Backs Independent Evaluators for AI Safety Over Slowing Development — Bloomberg Technology
Why it matters: Mark Zuckerberg backing independent evaluators for AI safety rather than slowing development is Meta staking out a middle path in the slow-down fight — accept external scrutiny, reject the brakes — a formulation that lets the industry claim responsibility without conceding the pace.
Mark Zuckerberg endorsed independent evaluators to assess AI safety in preference to slowing frontier development, positioning Meta between the two poles of the debate. The move matters because it offers the industry a rhetorically appealing alternative to a pause: submit models to external evaluation while keeping the throttle open — a stance that signals openness to accountability without accepting the constraint the slow-down camp argues is necessary. It joins a crowded field of divergent positions (OpenAI's slow-down call, Huang's no-new-laws, Anthropic's guardrail advocacy, the Trump administration's dismissal of risk), and evaluators-not-brakes is likely to become a favoured compromise framing for firms wary of regulation but conscious of public unease. For Europe, third-party evaluation resonates with the AI Act's conformity-assessment and systemic-risk-evaluation architecture, so Zuckerberg's framing partly converges with the European model — though the key question the EU debate keeps returning to is whether evaluation without enforceable limits is sufficient, or whether, as the safety camp contends, some capabilities warrant hard constraints rather than assessment alone.
OpenAI backs bipartisan push to address AI biothreats — Cybersecurity and Data Protection – POLITICO
Why it matters: OpenAI backing a bipartisan push to address AI biothreats is the one corner of AI safety where Washington's warring camps can still agree — the risk that frontier models lower the barrier to engineering a pathogen being concrete enough to unite an otherwise polarised debate.
OpenAI threw its support behind a bipartisan legislative effort to address the biosecurity risks of advanced AI — specifically the concern that capable models could help non-experts design or synthesise dangerous pathogens. The endorsement matters because biothreats are the rare AI-risk domain with genuine cross-party traction in a US politics otherwise split between accelerationists and safety advocates: the prospect of AI-assisted bioweapon development is concrete, catastrophic and legible to lawmakers in a way that diffuse 'existential risk' is not. It also lets OpenAI demonstrate safety bona fides on a specific, tractable harm while it courts a record valuation and resists broader regulation — a targeted commitment that is easier to make than agreeing to slow down. For Europe, where biosecurity intersects the AI Act's high-risk provisions and existing dual-use export controls, a US bipartisan move on AI-and-bio is a potential point of transatlantic convergence, and a reminder that the most actionable AI-safety policy may emerge issue-by-issue around concrete catastrophic risks rather than as a grand regulatory bargain.
SoftBank CDS Hovers Near 3-Year High on OpenAI Funding Concerns — Bloomberg Technology
Why it matters: SoftBank's credit-default swaps hovering near a three-year high on worries about its OpenAI exposure is the financial system beginning to price the risk beneath the AI boom — the cost of insuring one of its biggest backers against default creeping up as the sums committed to frontier AI grow vertiginous.
The cost of insuring SoftBank's debt against default has climbed to near a three-year high, driven by investor concern over the Japanese conglomerate's heavy financial commitments to OpenAI and the broader AI build-out. The move matters because credit-default-swap spreads are a market signal of perceived risk, and their widening on SoftBank — one of the largest financiers of the AI expansion — suggests the financial system is starting to price the danger that the enormous capital being poured into frontier AI may not pay off, or may strain the balance sheets of those funding it. It connects to the fortnight's market-anxiety thread (the chip-stock selloff on safety fears, the scale of OpenAI's reported $1.2-trillion ambitions) and to the growing question of whether AI valuations and funding commitments are sustainable. For Europe and global markets, rising insurance costs on a key AI backer are an early indicator that the boom carries systemic financial risk as well as technological and safety risk, and that the vast sums committed to AI are beginning to register as a source of credit concern, not just equity exuberance.
EU & Technology
EU countries to discuss AI rules as Trump calls safety warnings a ‘hoax’ — Cybersecurity and Data Protection – POLITICO
Why it matters: EU governments preparing to meet on the bloc's AI rules just as President Trump brands safety warnings a 'hoax' is the transatlantic fight over AI governance coming to a head — Brussels under pressure from US lobbying and a hostile White House to water down the world's most assertive AI law at the very moment its own lawmakers insist it must hold the line.
Representatives from EU member states are scheduled to meet on 18 September to discuss the bloc's AI rules, amid concern from EU lawmakers that the Commission may be weighing whether to soften parts of the AI Act under pressure from US technology lobbying and the Trump administration — which has branded the Act anti-innovation and anti-American, with the President dismissing AI-safety fears outright as a 'hoax.' The meeting matters because it is the concrete forum where the transatlantic conflict over AI governance plays out: American AI vendors have intensified lobbying against provisions of the Act, and lawmakers worry Brussels may curry favour with Washington by diluting the rulebook, even as they warn against 'watering down' Europe's rules to please Trump. It crystallises the fortnight's central governance story from the European side — the EU as the world's most assertive AI regulator, now squeezed between its own precautionary commitments and external pressure to retreat. For European digital sovereignty, the 18 September discussion is a test of whether the bloc holds firm on the AI Act as a statement of regulatory autonomy, or bends to the accelerationist, deregulatory pressure emanating from the US industry and administration.
UK pubs can legally accept digital ID for age assurance; now, implementation begins — Biometric Update
Why it matters: UK pubs winning the legal right to accept digital ID for age checks — with implementation now beginning — is the quiet mainstreaming of digital identity into everyday British life, the government's contested ID scheme finding a practical foothold at the bar even as its broader rollout remains politically fraught.
The UK has cleared the way for pubs to legally accept digital ID for age assurance, and implementation is now beginning — a concrete step in embedding digital identity into routine transactions like buying alcohol. The development matters because age assurance is one of the most tangible on-ramps for digital identity adoption, and licensed premises accepting a digital credential to verify a customer is over 18 normalises the technology in daily life, following the global age-verification wave (the EU's forthcoming Kids Act, device-level age checks, national schemes). It also sits within the fraught politics of the UK's broader digital-ID ambitions, which have drawn privacy and civil-liberties objections and an on-again-off-again reception. For European digital-identity and sovereignty debates — where the EUDI wallet is advancing the same idea of portable, verifiable credentials — the British move is a marker of how age assurance is becoming the practical wedge for digital ID, and a reminder that the design questions (privacy, data minimisation, avoiding a surveillance-by-default architecture, and giving citizens genuine choice) determine whether such schemes extend or erode trust as they move from policy into the everyday.
China & Technology
China Defense Minister Urges Nations to Step Up AI Oversight — Bloomberg Technology
Why it matters: China's defence minister urging nations to step up AI oversight is Beijing claiming the mantle of AI caution on the world stage — a striking counterpoint to Washington's 'hoax' dismissal, and a reminder that the AI-safety debate is now a venue for geopolitical positioning as much as genuine concern.
China's defence minister called on nations to strengthen oversight of artificial intelligence, publicly aligning Beijing with the pro-guardrails position on the global stage. The intervention matters because it sharpens the geopolitical framing of the AI-safety debate: as the US administration dismisses AI risk as a 'hoax' and the EU wrestles with whether to hold its rulebook, China positioning itself as an advocate for oversight is both a genuine signal (Beijing has its own AI-risk warnings and heavy domestic control instincts) and a strategic play to appear the responsible power while Washington resists restraint. It connects to China's earlier state-security AI-risk cautions and its rejection of the West's slow-down proposal as a 'Cold War playbook' — a stance that wants oversight on its own terms, not the West's. For Europe, a Chinese call for AI oversight complicates the simple democracies-versus-authoritarians framing of AI governance: it opens the rhetorical possibility of broad international agreement on the need for guardrails while underscoring that the substance — whose rules, enforced how, serving whose interests — remains where the real contest lies, and that Beijing intends to shape any emerging global norms rather than merely follow them.
China’s New Exit-Entry Rules Expand Identity Verification Powers — ID Tech
Why it matters: China's new exit-entry rules expanding identity-verification powers is the surveillance state extending its reach to the border — tightening who can be tracked, and how, as people cross in and out of the country, a further hardening of the identity architecture that underpins Beijing's control.
China has introduced new exit-entry regulations that expand the authorities' identity-verification powers over people crossing its borders, strengthening the state's ability to collect and check identity data at the frontier. The rules matter because border control is a key node of state surveillance and identity governance, and expanding verification powers there extends China's already-extensive identity-tracking apparatus to the movement of people in and out of the country — with implications for citizens, dual nationals, foreign visitors and, potentially, the diaspora and dissidents Beijing monitors. It fits China's broader pattern of building comprehensive, state-controlled identity infrastructure (contrasting sharply with the privacy-preserving, citizen-controlled model Europe aspires to with the EUDI wallet) and with the security minister's and defence minister's assertive posture this fortnight. For European digital-sovereignty and identity policy, China's exit-entry expansion is a reference point at the opposite end of the spectrum — a reminder that identity systems can be architected for state control or for individual empowerment, and that the design choices Europe makes about verification, data minimisation and citizen control are what distinguish its model from the surveillance-first approach exemplified here.
Threat Intelligence (CTI)
[P1] Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists — The Hacker News
Why it matters: Britain, the United States and the Netherlands jointly unmasked an Iranian state spyware operation that lures dissidents, activists and journalists with elaborate deceptions — in one case a faked MRI scan — before turning their own phones into listening posts, a rare three-nation callout of Tehran's campaign of transnational repression by cyber means.
The UK's NCSC, together with US and Dutch authorities, issued a joint advisory exposing spyware — named CHOSEN BRICK by British intelligence — used by Iranian state-sponsored operators tied to the Ministry of Intelligence and Security (MOIS) to target individuals seen as threats to the regime: dissidents, activists and journalists. The malware is delivered after extensive social-engineering: an operator posing over WhatsApp or Telegram as a known contact or as messaging-platform tech support builds trust, then sends a lure — reportedly including a fake MRI scan of a disc herniation. Telegram is used as a command-and-control channel to infiltrate devices, steal data and support hack-and-leak operations aimed at damaging targets' reputations. Once installed, the spyware can read messages and emails, activate the microphone and capture screenshots, giving operators a detailed picture of a target's contacts and movements. The advisory notes Iranian services have plotted to kidnap and even assassinate perceived enemies, including abroad.
severity high · exploited in the wild · EU: GDPR, NIS2 · actor Iran / MOIS (three-nation advisory; high confidence) (80%), escalation
[P2] PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting — Blog
Why it matters: Researchers say a stealthy npm supply-chain campaign was almost certainly built with a large language model and run by a self-styled bug-bounty hunter — malware written by AI, hidden behind package names that AI coding assistants themselves hallucinate, harvesting developer secrets from anyone who installs it.
CrowdStrike, in research published 15 September, assessed that PhantomRaven — a JavaScript information-stealer distributed via malicious npm packages — was almost certainly generated using a large language model, and is operated by a self-proclaimed bug-bounty hunter. The campaign began in August 2025 (first publicly disclosed 29 October 2025, then covering 126 packages and 86,000-plus downloads), with three further waves between November 2025 and February 2026 distributing 88 packages via 50 disposable accounts. It abuses 'slopsquatting' — creating plausible package names that AI assistants like Copilot or ChatGPT hallucinate and suggest — and a detection-evasion technique CrowdStrike calls Remote Dynamic Dependencies (RDD), where running 'npm install' silently pulls the malicious dependency from an attacker server and executes it. Because PhantomRaven logs were not seen on criminal log shops, CrowdStrike inferred the operator likely reserved the harvested developer data for bug-bounty opportunities rather than sale.
severity high · exploited in the wild · EU: NIS2, CRA
[P2] Electric and gas utility CenterPoint Energy warns of data breach after dark web post — The Record from Recorded Future News
Why it matters: The Texas utility CenterPoint Energy confirmed that a hacker drained personal records on some 7.49 million customers through an exposed, poorly-guarded interface — a stark reminder that the vulnerable seam of a critical-infrastructure operator is often the billing database, not the grid itself.
Electric and gas utility CenterPoint Energy filed an 8-K with the SEC confirming it became aware of a dark-web post this month claiming to offer data stolen from the company. A threat actor using the handle '4d722e4d656f77' posted on 1 September claiming to have leaked a database of roughly 7.49 million CenterPoint customers, said to have been obtained from a company-controlled API that allegedly lacked adequate authentication, rate limiting and other protections. CenterPoint's investigation found that intruders did obtain personal information relating to a portion of customers through one of its external-facing systems. The exposed fields reportedly include names, phone numbers, email and service/billing addresses, account and premise identifiers, billing amounts, payment information, autopay/paperless status and the last four digits of Social Security numbers. The company said the delivery of electric and gas services was not affected, and has not confirmed the authenticity or the exact size of the published dataset; class-action interest has followed.
severity high · exploited in the wild · EU: GDPR, NIS2, CER Directive
[P2] KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — The Hacker News
Why it matters: A banking-fraud crew has found a way to make Google Chrome and Microsoft Edge vouch for its own malicious add-on — forging the browser's internal integrity checks so a rogue extension appears legitimate — then using it to drain the sessions of a dozen banks' customers, so far almost entirely in Brazil.
Researchers (Elastic) detailed KREMLIN, a banking-fraud operation that installs malicious Chrome and Edge extensions by a novel forgery technique: it force-closes the browser, extracts encryption keys from a debugged browser process, and regenerates the HMACs and encrypted hashes stored in the browser's Secure Preferences so the extension passes the browser's own integrity checks. The installed extension steals cookies, session tokens, browsing history, screenshots and keystrokes, and can inject HTML or redirect users — targeting customers of twelve Brazilian banks. The operators have been active since at least May 2025, attributed to seven distinct campaigns since mid-June 2025, and also distribute off-the-shelf trojans (Pulsar RAT, Remcos RAT). The malware chain uses multi-stage JavaScript loaders, sandbox evasion, SentinelOne binary sideloading, and Ethereum smart contracts as a dead-drop to deliver C2 endpoints (the contract updated as recently as 13 August 2026). Elastic identified 1,515 infected systems, over 98% in Brazil.
severity high · EU: NIS2, GDPR, DORA
[P2] VectraRAT Can Hack Windows Enterprises for $250 per Month — darkreading
Why it matters: A newly-surfaced remote-access trojan built from scratch is being rented to criminals for $250 a month, handing even low-skilled attackers a full-featured toolkit to take over corporate Windows machines — hidden desktops, keylogging and stealthy privilege escalation included — with victims already surfacing in Germany, the US and Russia.
SOCRadar documented VectraRAT, a previously-undocumented malware-as-a-service platform comprising a full-featured Windows implant, command-and-control infrastructure and an operator panel built entirely from scratch, rented for around $250 per month. Unlike many MaaS offerings that build on existing malware, VectraRAT is a bespoke platform; once installed it provides a hidden desktop, remote CMD and PowerShell access, keylogging, file transfer, process discovery, clipboard manipulation and SOCKS5 proxy functionality, and it incorporates a UAC-bypass technique to obtain a high-integrity process without triggering the usual elevation prompt. It is delivered via the Amadey loader and ClickFix pages, has targeted corporate Windows editions including Windows Server 2025, and its victims are mainly in the US, Russia and Germany. The research was published around 15 September 2026.
severity high · exploited in the wild · EU: NIS2
[P3] Suspected Black Axe gang leaders face cybercrime charges in the US — BleepingComputer
Why it matters: Five alleged leaders of the Black Axe cybercrime syndicate — the sprawling Nigerian-origin network behind romance and advance-fee scams worldwide — have been extradited to the United States to face fraud and money-laundering charges, a rare high-level decapitation of a group usually pursued only at its lower rungs.
Five alleged leaders of the Black Axe syndicate — Perry Osagiede, Franklyn Osagiede, Osariemen Clement, Collins Otughwor and Musa Mudashiru — were extradited from South Africa to the United States on 11 September 2026 to face wire-fraud and money-laundering charges. Arrested in South Africa in 2021 at the US's request, they are accused of coordinating a large-scale internet-fraud campaign from 2011 to 2021 involving advance-fee schemes and romance scams, using multiple aliases, social-media and online-dating platforms and VoIP numbers to deceive US victims into sending money — and coercing those who refused, including with threats to publish sensitive photos. If convicted they face up to 20 years each for wire fraud and money laundering, plus additional time for aggravated identity theft. The action follows 'Operation Jackal IV,' in which law enforcement from 22 countries arrested 58 people and identified 263 suspects linked to African-organised-crime cyber networks.
severity medium · actor Black Axe syndicate (named; DOJ indictment) (70%)
[P3] Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group — Recorded Future
Why it matters: A profile of 'Tajin Group' — a vendor on the Chinese-language Xinbi guarantee marketplace — pulls back the curtain on the industrialised card-fraud-and-money-laundering economy that services global cybercrime, days after US authorities seized the marketplace's channels and sanctioned it as a criminal organisation.
Recorded Future's Insikt Group profiled Tajin Group, a vendor operating on the Xinbi Guarantee marketplace, whose April 2026 Telegram announcement detailed updates to its card-fraud and money-laundering services: cash-out methods exploiting Chinese banks (ICBC, Bank of China, China Construction Bank, Agricultural Bank), stolen-payment-card handling procedures, techniques to bypass banks' risk-control systems, and plans to expand into overseas remote-control services and 'sync panel' schemes across dozens of countries. The profile sits within the broader Chinese-language 'guarantee' marketplace ecosystem — Telegram-based escrow platforms connecting launderers with customers — which processed an estimated $16.1 billion in illicit funds in 2025, over 20% of crypto money-laundering activity. On 7 September 2026 the US authorised seizure of Telegram channels hosting the Xinbi Guarantee marketplace, and Treasury sanctioned it as a Transnational Criminal Organisation used by Chinese cybercriminals for scams, fraud and money laundering.
severity medium · actor Tajin Group (marketplace vendor; named) (50%)
Defence & National Security
US Coast Guard Boarded Oil Supertanker in Cyber Attack Probe — Bloomberg Technology
Why it matters: US forces and the FBI boarding a Texas-bound oil supertanker to investigate a suspected cyberattack is the maritime frontier of critical-infrastructure conflict made physical — armed personnel climbing aboard a tanker at sea because its networks may have been compromised by overseas actors, a scenario until recently the stuff of tabletop exercises.
The US Coast Guard, alongside the FBI and military personnel, boarded a Texas-bound, foreign-flagged oil supertanker to investigate indications that its onboard network had been compromised by overseas cyber actors, according to reporting on the operation. The episode matters because it is a concrete instance of maritime operational-technology security becoming a matter of armed state response: shipping and port infrastructure sit at the intersection of global trade, energy supply and cyber-physical risk, and a boarding to probe a suspected vessel-network compromise signals that the threat to maritime systems is now treated as serious enough to warrant physical intervention at sea. It follows reports of an earlier cyberattack on a giant crude tanker in the Strait of Gibraltar that reportedly cut communications for many hours and interfered with engine-room systems — a reminder that attacks on ship control systems carry safety and environmental stakes, not just data-theft ones. For Europe, whose ports, shipping lanes and energy imports are exposed to the same risks, the boarding underscores that maritime cyber-security — of vessels, navigation and port OT — is a critical-infrastructure and national-security concern requiring the kind of resilience and incident-response capability the continent is building for its other essential sectors.
Digital Sovereignty & Identity
From data residency to key sovereignty: Thales launches UK cloud HSM — Biometric Update
Why it matters: Thales launching a UK-hosted cloud hardware-security module — keeping cryptographic keys generated, stored and destroyed within the country — marks the sovereignty conversation shifting from where data sits to who controls the keys, the deeper layer of control that determines whether 'sovereign cloud' means anything at all.
Thales launched a UK-hosted Luna Cloud HSM service in which customers' cryptographic keys are generated, stored, used, backed up and destroyed entirely within the United Kingdom, backed by two in-country Data Protection on Demand instances for resilience. The launch matters because it reflects a maturing of the digital-sovereignty debate — from data residency (where information is stored) to key sovereignty (who ultimately controls the cryptographic keys that protect it), the more fundamental question for regulated and public-sector organisations wary of foreign jurisdiction over their most sensitive assets. It targets exactly the buyers — government, regulated industries — for whom cloud adoption hinges on retaining cryptographic control, and it fits the broader European push for sovereign-cloud arrangements that keep keys and control in trusted hands rather than deferring to non-European hyperscalers' jurisdictions. For Europe's digital-sovereignty agenda, key-management sovereignty is a decisive detail: encryption only delivers control if the keys are held under the right jurisdiction and governance, so offerings that keep key lifecycle in-country address a genuine gap — while the harder strategic question remains how far such arrangements, often built atop US hyperscaler platforms, deliver true autonomy versus a sovereignty veneer over dependence.
Cybersecurity & Threats
[P1] CISA: Critical VMware RCE flaw now exploited by ransomware gangs — BleepingComputer
Why it matters: Ransomware gangs have joined the assault on a maximum-severity flaw in VMware vCenter — the console that manages an organisation's entire virtual estate — turning what began as suspected state-actor espionage into a broad extortion threat against every enterprise still running an unpatched server.
CISA warned that ransomware crews are now exploiting CVE-2026-59310, a critical (CVSS 9.8) directory-traversal flaw in the vCenter Syslog server component that lets an unauthenticated attacker with network access execute arbitrary code. Broadcom fixed it on 29 July; roughly two weeks later researchers reported 361-plus IP addresses across 47 countries compromised after a suspected APT actor began exploiting the flaw to deploy a reverse-SSH tool for persistence and remote access, and CISA added it to the Known Exploited Vulnerabilities catalogue with a three-day federal remediation deadline. Over the following weekend CISA updated the KEV entry to flag active abuse by ransomware gangs — a shift from a single suspected state-linked actor to multiple financially-motivated crews. vCenter Server is the central management plane for VMware virtualised environments, so compromise yields control over the virtual-machine estate it administers.
severity critical (CVSS 9.8) · exploited in the wild · CVE-2026-59310 · EU: NIS2, DORA, CER Directive
[P1] Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens — The Hacker News
Why it matters: Attackers are forging administrator tokens against WSO2's API Manager by abusing a maximum-severity authentication-bypass flaw — the gateway that fronts an organisation's APIs can be tricked into accepting a token it should reject, handing an intruder the keys to the API estate without any password.
Reporting flagged active exploitation attempts against CVE-2026-5430, a critical (CVSS 10.0) JWT authentication-bypass in WSO2 products including API Manager. The flaw stems from improper validation that accepts JSON Web Tokens signed with algorithms other than those configured or supported — an algorithm-mismatch weakness that lets an attacker craft a token which is incorrectly validated, leading to unauthorised access up to and including administrative-account compromise and full account takeover. WSO2 issued fixed builds across affected products (API Manager, API Control Plane, Carbon API Manager REST API utility, Traffic Manager, Universal Gateway). WSO2's platform sits at the front of enterprise and government API estates, brokering authentication and routing for the services behind it, so a bypass that yields forged admin tokens undermines the trust boundary the gateway exists to enforce.
severity critical (CVSS 10.0) · exploited in the wild · CVE-2026-5430 · EU: NIS2, DORA
[P2] Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers — The Hacker News
Why it matters: A mass-scanning campaign is combing the internet for exposed Vite development servers and prising cloud credentials out of them — harvesting AWS keys, Azure tokens and infrastructure secrets from the dev machines that were never meant to face the public, at a rate of tens of thousands of probes.
F5 detailed a mass-scanning campaign exploiting CVE-2026-39364, a high-severity flaw in the Vite JavaScript build tool that lets an unauthenticated attacker bypass access restrictions via query-parameter manipulation and read sensitive files, including those meant to be blocked by Vite's server.fs.deny setting. The flaw affects Vite 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5. F5 observed more than 800 attacks and around 32,000 events in a month, with the scanning fleet systematically cycling through wordlists of environment files, AWS keys, Azure tokens and Infrastructure-as-Code state files; the campaign also leveraged older Vite flaws (CVE-2025-30208, CVE-2025-31125, CVE-2024-45811). Most activity originated from the US, Belgium and the Netherlands, using Google Cloud IP ranges for evasion. Exposed Vite dev servers are the target — development environments inadvertently reachable from the internet.
severity high · exploited in the wild · CVE-2026-39364 · EU: NIS2, CRA
[P1] Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells — The Hacker News
Why it matters: A fresh wave of attacks is planting PHP web shells on WordPress shops through a critical flaw in a WooCommerce wholesale plugin — any visitor can upload an executable file to sites running the vulnerable version, and web-application firewalls have already blocked well over a hundred thousand attempts.
Attackers are actively exploiting CVE-2026-27540, a critical (CVSS 9) unauthenticated arbitrary-file-upload flaw in the WooCommerce Wholesale Lead Capture plugin (Rymera Web Co), affecting all releases through 2.0.3.1 across roughly 6,000 active installations. The plugin's file-upload handling accepts any file type without validation, so an attacker can POST to the wwlc_file_upload_handler AJAX action with a forged file_settings parameter and a malicious .php file to drop a web shell that conducts reconnaissance and can stage further payloads. Wordfence reported blocking over 100,000 attacks tied to the flaw; the EPSS score is around 2%. It was disclosed and fixed in version 2.0.3.2 in February 2026, but a renewed exploitation wave against unpatched sites is the current concern.
severity critical (CVSS 9.0) · exploited in the wild · EPSS 0.02 · CVE-2026-27540 · EU: NIS2, GDPR
[P2] LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — The Hacker News
Why it matters: A flaw in the LiteSpeed Enterprise web server lets a single low-privilege hosting customer break out and seize root on the whole shared machine — one tenant on a crowded server able to reach across into every other site it hosts, the classic and dangerous failure of multi-tenant isolation.
cPanel published an advisory on 14 September warning that a flaw in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server. On such servers many customers' sites run on one machine, so an attacker holding a single hosting account could exploit the flaw to access or alter other customers' sites and the server itself, bypassing the controls that keep hosting accounts apart — including CageFS, the CloudLinux tool that gives each account a restricted view of the filesystem. The flaw affects LiteSpeed Enterprise versions before 6.3.7, and LiteSpeed released version 6.3.7 on 11 September. Reporting noted no confirmed in-the-wild exploitation of this specific flaw, though two earlier LiteSpeed cPanel-plugin flaws (CVE-2026-48172 and CVE-2026-54420) were actively exploited and added to CISA's KEV catalogue.
severity high · CVE-2026-48172 · EU: NIS2, CRA