the daily brief
Cyber / Brief — 7 Oct 2026
South Korea has become the first state to attribute bank intrusions to AI agents: officials say breaches at seven lenders including Shinhan, KB Kookmin and Hana that exposed 68,000 people's records were run with ARTEX AI, a Chinese-language open-source penetration tool from GitHub…
South Korea has become the first state to attribute bank intrusions to AI agents: officials say breaches at seven lenders including Shinhan, KB Kookmin and Hana that exposed 68,000 people's records were run with ARTEX AI, a Chinese-language open-source penetration tool from GitHub, through 33 addresses in a dozen countries, and President Lee told his cabinet that AI now lets anyone hack with ease, while CrowdStrike showed that even the strongest safety classifier on frontier models is defeated by splitting harmful work into benign pieces and reassembling it with a local model, and Anthropic opened a three-tier programme handing reduced-safeguard Mythos to vetted defenders, red teams and, under US government review, testers of power grids and flight systems. In Berlin, August Hanning, who ran the BND from 1998 to 2005, was arrested for treason over some 2,000 leaked chancellery briefings on Iran, Russia and partner-service reporting that he allegedly bought from a serving officer for a decade and used for a foreign service, the same day EU diplomats were reported to be quietly planning for a mass-casualty hybrid attack after drones sank two cargo ships inside NATO members' waters. Brussels is studying a bloc-wide levy on US tech revenue as a trade weapon, member states are close to a blanket legitimate-interest basis for training AI on personal data in the data omnibus, MEPs are reviving an AI liability law with Sam Altman's backing ahead of a 13 October hearing, Mistral shipped a trillion-parameter open-weight model it says beats every US and European rival, and the ECB set out the digital euro's path to first issuance in 2029 against the two-thirds of euro-area card payments that run on foreign schemes. The FBI and Secret Service warned that FortiBleed is still locking operators out of hundreds of thousands of firewalls and feeding ransomware crews, attackers who hijacked three country-code registries minted valid certificates for Google and other global brands, and extortionists pushed their ransom note to ASOS customers through the retailer's own app.
Top Stories
- South Korean officials believe AI agents were used to hack several banks — The Record from Recorded Future News · Threat Intelligence (CTI)
- The EU shelved AI liability rules. Sam Altman has revived the debate. — Technology – POLITICO · AI & Power
- FirstFT: Brussels explores broad levy targeting revenue from US tech — myFT following · EU & Technology
- German ex-spy chief arrested over espionage and treason allegations involving leaked BND files — EUobserver · Threat Intelligence (CTI)
- Mistral unveils le Chonk, says "significantly outperforms” any open-weight models developed in US or Europe — Tech.eu · EU & Technology
AI & Power
The EU shelved AI liability rules. Sam Altman has revived the debate. — Technology – POLITICO
Why it matters: The AI Liability Act is back on the table in Parliament with OpenAI's chief executive as an unlikely supporter, days before labs testify to MEPs on safety and liability.
MEPs are digging in on calls to revive an AI liability law after Sam Altman said someone must answer when something goes wrong, POLITICO reports. Four lawmakers from the Greens, EPP, S&D and Renew, including AI Act co-rapporteurs Axel Voss and Brando Benifei, set out in a 16 September note that the Act leaves a gap for unforeseen damage from broadly capable systems and want a standalone AI Liability Act alongside it; the Commission withdrew its directive in 2025 as premature. Parliament has summoned AI companies to a hearing on 13 October on safety and liability. With OpenAI facing a California subpoena, an FTC probe and the Hugging Face suit, liability is the lever Brussels dropped and Washington's courts are now using.
Expanding the Cyber Verification Program — Anthropic News
Why it matters: Anthropic formalising tiered access to Mythos with reduced cyber safeguards, including a US-government-reviewed tier for grid and aviation testing; the access-control model a week after it warned about open weights.
Anthropic expanded its Cyber Verification Program into three tiers: Defense Access for incident response, malware reverse-engineering and vulnerability analysis, open to companies, universities, governments, infrastructure operators and researchers with disclosure records; Red Team Access adding authorised penetration testing for organisations only; and Specialized Access for verified bodies testing safety-critical systems such as flight operating systems, power grids and telecoms, reviewed with the US government. Each tier unlocks Opus 5.5, Sonnet 5.5 and Mythos 5.1 with progressively reduced blocking classifiers, data retention is required for monitoring, and a zero-retention enterprise option follows this autumn. The Register calls it a reconfigured cool-kids programme; the question for European operators is who vets them and under whose law.
They told the world AI was dangerous. Now Trump’s allies are coming for them. — Technology
Why it matters: The administration adopting safety advocates' ideas while sidelining the advocates; the political purge behind the accord.
The Washington Post reports that the Trump administration and its allies are embracing some ideas championed by AI safety advocates, from testing to incident reporting, while working to marginalise the movement in Washington, after Senator Moreno's letter warning Anthropic against alarmism and a $100 million pro-AI midterm spending push backed by Trump allies. Meanwhile Senators Warren and Blumenthal demanded answers by 19 October on industry influence over the still-unreleased AI regulatory framework and whether any independent evaluators were consulted.
Read the charter for the White House’s ‘Super Intelligence Force’ — Cybersecurity and Data Protection – POLITICO
Why it matters: The charter gives the Super Intelligence Force broad authority over how industry and government handle national-security threats from AI; the text is now public.
POLITICO published the charter of the Super Intelligence Force, which gives the body led by Director of National Intelligence Jay Clayton broad authority to determine how the technology industry and the federal government should address threats to national security from AI, with the FTC chair, the Pentagon CTO and the OPM director as members and a mandate to engage consumers, religious groups, infrastructure providers and companies. It places AI governance inside the intelligence community with no statutory basis and no independent evaluator seat.
AI tools flood into underground cybercrime markets — Axios
Why it matters: Criminal forums on a buying spree for AI tooling; the demand side of the capability spread Anthropic and Microsoft described.
Research shared with Axios finds hackers on underground forums buying AI tools that package once-specialised capabilities, from phishing-kit generation and malware obfuscation to automated reconnaissance and jailbroken assistants, with listings and prices rising sharply through 2026. It arrives as South Korea attributes bank breaches to an open-source Chinese AI penetration tool and as CrowdStrike shows classifiers can be bypassed by decomposition.
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers — Blog
Why it matters: CrowdStrike demonstrates that even a robust per-request classifier is defeated by splitting harmful work into benign pieces and reassembling with a local model; the architecture, not the classifier, is the flaw.
CrowdStrike's Cyber Superintelligence Lab found that direct bypass attempts against a Level 3 safety classifier protecting Claude Opus 5.5 and Fable 5 failed in all of roughly 515 techniques, but a pipeline that decomposes a harmful request into individually legitimate subtasks, reframed as game modding, detection engineering or ordinary software work, and reassembles the output with an unclassified open-weight model produced working exploit code in nine of ten offensive categories, failing only on EDR evasion which the classifier blocks conceptually. The lab concludes that per-request evaluation is the wrong threat model and that cross-request, cross-provider monitoring has structural limits once local models are in the loop.
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps — darkreading
Why it matters: Google turning an agent on its own web applications and validating exploitability; the defender side of the AI discovery boom.
Dark Reading reports that Google's PageBreak AI agent found about 500 flaws in the company's web applications, pairing AI discovery with deterministic validation to confirm exploitability and assign risk. It is the same loop that produced the Epic, Titan and Rejetto findings, now internalised by a platform owner, and it arrives the week Google paused its open-source bounty under a flood of invalid automated reports.
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets — www.theregister.com - Articles
Why it matters: Encrypted prompt injection making GitHub's coding agent exfiltrate developer secrets, with the outcome depending on which model the user was silently assigned.
Adversa AI showed that GitHub Copilot CLI in autopilot mode can be made to leak secrets from local files by fetching a web page carrying encrypted instructions and two decryption keys, one of which harvests .env contents before the other reveals exfiltration instructions; Microsoft's mai-code-1.1-flash executed the chain on half of attempts while OpenAI's GPT-5.6 refused, and auto-selected accounts could get either model. GitHub declined to treat it as a product vulnerability because users direct the tool to untrusted content. For enterprises the model-dependence is the finding: the safety of an agent product changes under the user without notice.
Democrats press White House on still-secret AI framework — Semafor
Why it matters: Senate Democrats forcing disclosure of who wrote the administration's AI framework.
Senators Elizabeth Warren and Richard Blumenthal asked administration officials to disclose meetings and communications with industry that shaped the still-unreleased AI regulatory framework under the June executive order, whether independent evaluators or non-industry stakeholders were consulted and how pre-deployment testing works, with answers due by 19 October, citing Mark Zuckerberg's reported role in the White House accord.
EU & Technology
FirstFT: Brussels explores broad levy targeting revenue from US tech — myFT following
Why it matters: The Commission studying a bloc-wide levy on US tech revenue as a trade countermeasure; the digital tax returns as a weapon rather than a fiscal measure.
The FT reports Brussels is exploring a broad levy targeting revenue from US technology companies, reviving the idea von der Leyen floated of a levy on digital advertising revenues across the bloc if trade talks with Washington fail, alongside the Anti-Coercion Instrument's power to restrict services and public procurement. It lands as Germany and France ask for faster trade weapons aimed at China and as the US tech sector lobbies Brussels at record scale.
Mistral unveils le Chonk, says "significantly outperforms” any open-weight models developed in US or Europe — Tech.eu
Why it matters: Europe's flagship lab releasing a trillion-parameter open-weight model it says beats every US and European open model; the sovereignty argument gets a frontier-class artefact.
Mistral unveiled Mistral Large 4, nicknamed Le Chonk, a one-trillion-parameter multimodal model it calls its largest and most capable, claiming it significantly outperforms any open-weight model from the US or Europe and leads on coding, agentic workflows, cybersecurity, finance and law, with preview access now and full API availability later in October. Fresh from a $3.4 billion raise at a $24 billion valuation, Mistral positions it against OpenAI and Anthropic and against cheaper Chinese open models, a week after Anthropic showed how cheaply open-weight safeguards can be stripped.
Einigung absehbar: EU-Staaten entscheiden über Cookie-Banner, KI-Training und Co. — netzpolitik.org
Why it matters: Member states close to agreeing a blanket legitimate-interest basis for AI training on personal data in the data omnibus, with the browser privacy-signal provision dropped.
EU ambassadors are negotiating the data omnibus with a Council position in sight that would let companies train AI on personal data under legitimate interest without consent, a blanket permission noyb and EDRi say breaks the GDPR's technology neutrality; Spain, Bulgaria, Latvia and Estonia oppose it while Poland, Czechia, Sweden and Denmark want it widened, and Germany's exemption proposal is seen as unworkable. The Commission's browser-based privacy-signals mechanism was cut after German and industry opposition, leaving a weak four-month cookie-refusal rule. Parliament's rapporteurs are split between no compromises on data protection and a real deregulation agenda.
Von der Leyen warns against EU budget cuts — Policy – POLITICO
Why it matters: The Commission president rebuking Berlin on the budget as seventeen capitals line up against cuts; the competitiveness fund is the prize.
Ursula von der Leyen cautioned against cuts to the EU's next seven-year budget in a direct rebuke to Germany's calls to slash spending, joining MEPs in defence of the 2 trillion euro plan ahead of the summit, as Brussels pleaded with capitals not to cut the shared budget. The 409 billion euro Competitiveness Fund that would finance chips, AI and defence is simultaneously the target of net-payer cuts and of a Parliament-Council split over whether non-EU countries may access its defence money.
Parliament and Council split on how non-EU countries get access to defense cash — Policy – POLITICO
Why it matters: Whether the UK, Norway or Turkey can tap EU defence money is the fight inside the competitiveness fund.
Negotiations over the proposed 409 billion euro Competitiveness Fund are splitting capitals and Parliament over whether non-EU countries should be allowed to tap its defence money, POLITICO reports, with the Council more open to associated-country access and Parliament insisting on European preference. The outcome sets the terms for UK participation under a government talking about rejoining, and for the Canada associated-status precedent floated for cloud.
Commission seeks 15-year safeguards on future member states, but says reforms won’t create two-tier EU — EUobserver
Why it matters: The pre-enlargement review: accession roadmaps for Ukraine, Moldova, Montenegro and Albania with up to fifteen years of post-accession safeguards.
The Commission's long-delayed pre-enlargement policy review proposes up to fifteen years of post-accession safeguards to penalise new members for backsliding and asks them not to block future enlargements over bilateral disputes, with accession roadmaps for Montenegro, Albania, Moldova and Ukraine due this month; Enlargement Commissioner Marta Kos calls the safeguards an insurance policy rather than a two-tier EU. Candidates will take on NIS2, the AI Act and the digital rulebook under this conditionality.
EU readies for China trade clash, as frustration grows over imbalance — Semafor
Why it matters: Berlin and Paris building the case for market exclusion as European job losses mount.
Semafor reports the EU's biggest economies gearing up for a clash with China over a trade imbalance they say is hollowing out European industry, with France and Germany pushing a mechanism to cut countries deemed harmful off from the bloc's businesses and consumers immediately, framed around systemic market-distorting practices and set against Volkswagen's plan to cut 100,000 jobs.
European defence tech gets a reality check — Sifted
Why it matters: The funding boom meets procurement reality: Sifted on what European defence startups still cannot sell.
Sifted reports from a London resilience conference that despite a record year, with Dealroom forecasting $10.5 billion in 2026, European defence startups face slow procurement, fragmented national requirements and capital that follows a handful of winners, a reality check on the drones-and-autonomy narrative as Covenant announces mass production of a long-range cruise missile in Germany.
Neuer Bundesdatenschutzbeauftragter: „Weder besonders hart, noch besonders lasch, sondern ausgewogen“ — netzpolitik.org
Why it matters: Germany's new federal data-protection commissioner setting out a balanced line while criticising parts of the omnibus.
Moritz Hennemann, Germany's new federal data-protection commissioner, used his first statement to describe his approach as neither especially hard nor lax but balanced, praising planned reform of data protection while criticising parts of the Commission's omnibus proposals, netzpolitik reports. His position matters because Germany's stance has been decisive in the Council's AI-training and cookie-signal fights.
US & Technology
SpaceX in Talks to Borrow $40 Billion to Buy Nvidia Chips — Bloomberg Technology
Why it matters: A $40 billion debt raise to buy chips; the AI build-out's leverage keeps climbing.
SpaceX is in talks with banks and investors to raise $40 billion to buy Nvidia chips, in what would be among the largest debt financings ever, Bloomberg reports, as Lambda raises $4 billion before an IPO and the WSJ warns of a coming data-centre crunch. Ray Dalio says the AI bubble is approaching a burst point and the IMF's Georgieva names AI, oil and debt as a risk cocktail.
Former NSA chief Nakasone says agency overhaul is ‘probably needed’ — CyberScoop
Why it matters: The NSA reorganising into five mission directorates for AI, China, cyber, combat support and global intelligence; a 29-minute adversary dwell time is the stated reason.
Former NSA director Paul Nakasone said a reported reorganisation creating five organisations focused on AI, China, cybersecurity, combat support and global intelligence, each under a mission director, is probably necessary but will succeed or fail on implementation, citing adversaries moving through compromised networks in 29 minutes on average, down from hours in 2018, and the need for a defender's window on AI; 13.5% of the national-security workforce is retirement-eligible.
Lawmakers Introduce Multiple Laws to Curb Flock After 404 Media Coverage — 404 Media
Why it matters: Bipartisan bills to ban or constrain federal use of plate-reader networks after the Oklahoma ruling.
Senators Sanders and Merkley and Representative Ocasio-Cortez introduced a Ban Flock Act barring federal agencies from using automatic licence-plate readers and blocking funding to localities that use them, while Senator Hawley's Stop Flock Abuse Act would require written approval per search, deletion after ten days and a ban on facial-recognition integration, after 404 Media's reporting on data sharing with immigration enforcement and protest surveillance.
Here’s how experts think CISA should tell agencies to protect OT — CyberScoop
Why it matters: Industry's draft of what a federal OT security directive should require.
A coalition of cyber firms and critical-infrastructure operators set out the tasks it thinks CISA should assign federal agencies in a forthcoming operational-technology directive, from asset inventory and segmentation to remote-access controls, CyberScoop reports, as the FBI warns FortiBleed is still locking operators out of their own firewalls.
A Data-Center Crunch is Coming — Technology - WSJ.com
Why it matters: The WSJ on the capacity squeeze behind the chip-financing spree.
The WSJ reports that a data-centre crunch is coming as AI demand outruns power, packaging and construction, the constraint behind SpaceX's $40 billion chip debt, Amazon's off-balance-sheet chips and the SF Fed's warning that AI demand could extend the energy shock.
China & Technology
China’s Revised Defense Mobilization Law Touches Nearly Every Sector — The Diplomat
Why it matters: A mobilisation law that reaches private firms and the technology sector, with broader triggers; the legal basis for conscripting China's tech base in a crisis.
The Diplomat analyses China's revised Defense Mobilization Law, which widens the circumstances under which mobilisation can be declared and obliges a large number of entities including private firms to serve the state in wartime, touching logistics, telecoms, data and manufacturing. For foreign companies and their Chinese suppliers it defines the conditions under which commercial relationships become instruments of the state, relevant to RUSI's vendor-risk findings and the EU's economic-security reviews.
In Race With U.S., China Struggles to Recruit Foreign A.I. Researchers — NYT > Technology
Why it matters: China's AI boom retains its own researchers but fails to attract foreign ones despite a government push.
The New York Times reports that China's booming AI sector gives local researchers reason to stay but has yet to lure overseas scientists despite recruitment programmes, as US visa politics push talent elsewhere and Europe courts the same researchers. It is the human-capital counterpart to DeepSeek's $12 billion raise and Mistral's trillion-parameter release.
Would China agree to slow AI development? That’s the wrong question — Tech - South China Morning Post
Why it matters: Chinese commentary on the pause debate ahead of the November dialogue: the question is framed as the wrong one.
A South China Morning Post column argues that asking whether China would agree to slow AI development misreads Beijing, which sees development and safety as managed together under state coordination, and notes the summit readouts avoided the pause question entirely. It previews the Chinese position for the November US-China AI risk dialogue.
Taiwan Claims Two Hong Kong Residents Involved in Spying on DPP Lawmaker — Bloomberg Markets
Why it matters: Transnational repression reaching Taiwanese legislators through Hong Kong intermediaries.
Taiwan prosecutors said two Hong Kong residents paid for surveillance of a Democratic Progressive Party lawmaker and his family and indicted four Taiwanese individuals in what they called a transnational repression case, days after the FBI arrested a woman accused of surveilling the Taiwanese president's son in the US.
Not just AI. China is building technologies that challenge U.S. dominance — Rest of World -
Why it matters: Steve Feldstein's book on China's tech challenge beyond AI: batteries, solar, drones and satellites.
Rest of World excerpts Steve Feldstein's Bytes and Bullets, arguing that China's challenge to US dominance extends well beyond AI into batteries, solar panels, drones and satellites, the dual-use sectors where European dependence is deepest and where the EU's trade weapons are now aimed.
Richard Yu Says Huawei Has Mass-Produced 381 Tau Chips, From Phones to Smart Cars — Pandaily - China Tech News, AI & Electric Vehicle Insights
Why it matters: Huawei's chip chief claiming hundreds of millions of domestic Tau chips across phones and cars.
Richard Yu said Huawei has mass-produced 381 million Tau chips spanning phones to smart cars, as the Mate 90 launches on domestic silicon and the company claims to have overtaken Nvidia in Chinese AI accelerator share, a data point on how far the sanctioned champion's vertical integration has gone.
Threat Intelligence (CTI)
[P1] South Korean officials believe AI agents were used to hack several banks — The Record from Recorded Future News
Why it matters: Seoul attributing breaches at seven banks to an open-source Chinese AI penetration tool and AI agents; the first state attribution of financial-sector intrusions to autonomous tooling.
South Korean officials believe AI agents were used to breach at least seven financial institutions including Shinhan, KB Kookmin, Hana and BNK between late September and early October, exposing data on at least 68,000 people including names, phone numbers, resident registration numbers, incomes, credit limits and loan details; investigators found traces of ARTEX AI, a Chinese-language open-source LLM-driven penetration tool distributed through GitHub, on a server used against Shinhan, identified 33 IP addresses across 12 countries, and President Lee said signs have emerged that AI agents were deployed and that AI now lets people hack with ease; a 28-investigator task force was formed and Lee called for AI-powered defensive tools.
severity critical · exploited in the wild · EU: DORA, NIS2, GDPR, AI Act
[P1] German ex-spy chief arrested over espionage and treason allegations involving leaked BND files — EUobserver
Why it matters: A former head of the BND arrested for treason over 2,000 leaked chancellery briefings, with at least one analysis prepared for a foreign service; an insider breach at the top of German intelligence.
August Hanning, who led the BND from 1998 to 2005, was arrested at his home on 6 October on suspicion of espionage and treason for allegedly obtaining classified BND information for years after leaving, under an arrangement with BND employee Manfred D. from spring 2010 to receive intelligence for payment for his private security consultancy; about 2,000 documents were found including briefings for the chancellery's weekly intelligence meetings on Iran's nuclear programme, Russian military operations and partner-service reporting, the latest from June 2022, and investigators say he prepared at least one analysis for a foreign, non-Russian intelligence service and used BND material with a foreign agent. Semafor reports he has been charged.
severity critical · exploited in the wild · EU: NIS2, EU Cyber Diplomacy Toolbox · actor August Hanning (arrested; foreign recipient service unnamed) (80%), escalation
[P2] ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise — Infosecurity Magazine
Why it matters: Extortionists pushing a ransom note to ASOS customers through the retailer's own app notifications; a third-party messaging platform compromise, not Snowflake.
On 6 October ASOS customers received a push notification signed xuanyewengateway claiming the attackers had fully compromised the retailer's Snowflake instance and demanding engagement; ASOS confirmed unauthorised activity involving third-party platforms used for customer communications, said names and contact details may have been accessed but not payment cards or passwords, and Snowflake found no compromise of its platform. The Xuanye Group claimed the breach on Telegram.
severity high · exploited in the wild · EU: GDPR, NIS2, DSA · actor Xuanye Group / xuanyewengateway (self-claimed) (50%), escalation
[P2] Japan hands over ‘Qilin’ hacker group member to Germany — DataBreaches.Net
Why it matters: A Russian national tied to Qilin extradited from Japan to Germany; the first Qilin arrest reaching European prosecution.
Japanese police captured a Russian national believed to be a key member of the Qilin ransomware group and extradited him to Germany at the request of German investigators, Jiji reports via DataBreaches.net; details of the German case and his role are limited, and Qilin remains the most active ransomware brand against hospitals and public bodies in Europe.
severity high · exploited in the wild · EU: NIS2, GDPR · actor Qilin (member extradited; role unconfirmed) (60%)
[P2] Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System — SecurityWeek
Why it matters: A state court system losing 1.3 million fine-and-fee records and 30,000 protection orders to a single phishing click.
The Arizona Supreme Court said attackers copied personal information on 1.3 million people with unpaid court fees, fines and restitution, nearly 30,000 active and inactive protection orders and 150,000 foster-care board reports dating to 2010 after a court employee clicked a malicious email link on 24 September; staff shut the attack down on a backup server within about two hours, no cases were affected and no juror, witness or employee data was taken; there is no evidence of use and no attribution.
severity high · exploited in the wild · EU: GDPR, NIS2
[P2] ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware — The Record from Recorded Future News
Why it matters: CERT-UA tracking a ClickFix operation across a hundred compromised Ukrainian sites delivering a Russian-developed stealer-as-a-service.
CERT-UA found that attackers compromised more than 100 websites in September, injecting fake Cloudflare verification pages that trick visitors into running PowerShell to install Lunex Stealer, which takes passwords, tokens and crypto-wallet data, enables remote access and installs a malicious browser extension disguised as a Microsoft Office Word Editor to steal cookies and credentials across seven Chromium browsers; CERT-UA tracks the cluster as UAC-0277 without attribution, and Ontinue describes Lunex as a malware-as-a-service platform built by Russian-speaking developers.
severity high · exploited in the wild · EU: NIS2, GDPR · actor UAC-0277 (CERT-UA cluster; unattributed) (30%)
Defence & National Security
EU quietly braces for nightmare scenario of multiple-casualty hybrid attack — Policy – POLITICO
Why it matters: Diplomats planning emergency teams, funding and crisis communications for a mass-casualty hybrid attack; the scenario behind the emergency protocol.
POLITICO reports that EU diplomats are quietly preparing for a nightmare scenario of a multiple-casualty hybrid attack, discussing emergency teams, EU funding and crisis communications, while some capitals warn Brussels against overreach. It follows the Leipzig drone, the Milrem arson, the BND's warning of violent conflict and drones sinking ships in NATO members' waters, and gives operational content to the emergency security protocol von der Leyen proposed.
Drones sink ships near NATO countries in “unacceptable” attacks, EU says — Ars Technica - All content
Why it matters: Drone strikes sink two cargo ships and kill sailors inside NATO members' exclusive economic zones; the EU calls it unacceptable, the attribution points to Russia.
Drones sank two cargo ships and damaged a third in the exclusive economic zones of NATO member countries for the first time, killing at least two sailors, in attacks the EU called unacceptable and that Ars Technica reports are likely Russian, with Bulgarian tankers struck in the Black Sea. Shipping groups had asked days earlier for counter-drone protection; the strikes move the hybrid campaign from sabotage on land to lethal force at sea.
EU deepens collective space security with mutual defense pact — Breaking Defense
Why it matters: A Council decision creating a collective-response framework for attacks on satellites, giving non-NATO members a security path outside the alliance.
Council Decision 2026/2195, approved on 23 September, lets the EU decide on a coordinated political, economic or military response when a member state requests help against threats to its space assets, extending beyond jointly owned systems such as Galileo and Copernicus to national satellites and infrastructure, Breaking Defense reports; Austria, Cyprus, Ireland and Malta gain a security pathway outside NATO. It builds on the 2023 space defence strategy and the push for strategic autonomy in orbit.
Covenant Plans Mass Production of Cruise Missiles in Germany — Bloomberg Markets
Why it matters: A startup building a factory for a long-range heavy-payload cruise missile in Germany; European deep-strike capacity from the venture market.
Defence startup Covenant says its heavy-payload long-range cruise missile Anthem will become key to Europe's deterrence and plans mass production at a new factory in Germany, Bloomberg reports, as Dealroom counts a record year for European defence startups and the Bundeswehr stands up a drone regiment with a 500-kilometre strike company.
France fires upgraded nuclear-capable missile from submarine for first time — Defense News
Why it matters: France's first submarine launch of the M51.3, with Macron framing it for allies and adversaries; the forward-deterrence offer gets hardware.
France test-fired the upgraded M51.3 strategic ballistic missile from the submarine Le Vigilant for the first time on 6 October, with range beyond 9,500 kilometres and improved accuracy and penetration, and Macron called it a very important moment for strategic credibility watched by allies and adversaries, as France builds new ballistic-missile submarines and hypersonic nuclear cruise missiles for Rafale under his forward-deterrence proposal to extend protection to European allies.
Pakistan, Saudi Arabia, Turkey Trigger Mutual Defense Pact — Foreign Policy
Why it matters: A nuclear-armed Pakistan and NATO's second-largest army activating a defence pact with Riyadh against the Houthis.
Pakistan, Saudi Arabia and Turkey activated the Mecca joint defence agreement on 5 October after Houthi strikes on Saudi infrastructure, treating an attack on one as an attack on all, with Pakistan offering reconnaissance and Turkey and Pakistan planning rapid deployments pending Turkish parliamentary ratification. Even the prospect reshapes the Red Sea conflict in which Europe's naval mission operates.
Digital Sovereignty & Identity
Piero Cipollone: Money in the digital age: digital euro, tokenisation and the role of central banks — ECB - European Central Bank
Why it matters: The ECB's digital euro timeline in one speech: trilogues now, pilot with 36 providers in 2027, first issuance 2029, with two-thirds of euro card payments on foreign schemes as the sovereignty case.
ECB executive board member Piero Cipollone said the digital euro legislation, with Council and Parliament positions agreed, is in trilogue and if concluded by end-2026 allows a pilot with 36 payment providers from the second half of 2027 and first issuance in 2029; the design is non-remunerated with holding limits and a waterfall to bank accounts, and ECB modelling across 2,025 banks finds contained liquidity effects at limits of 500 to 3,000 euros. On the wholesale side Pontes, live since 21 September, targets full 24/7 operation by mid-2028 and Appia delivers an integrated blueprint by 2028. His sovereignty argument: two-thirds of euro-area card payments run on international schemes and global technology companies.
Toronto-Based VPN Provider Plans to Quit Canada Over Lawful-Access Bill — The Citizen Lab
Why it matters: A censorship-circumvention tool with 20 million users leaving Canada over a lawful-access bill; the backdoor debate the EU is having over chat control, in a Five Eyes country.
Psiphon, spun out of the Citizen Lab and used by 20 million people a month to evade censorship in Iran, Russia and China, says it will relocate out of Canada if Bill C-22 passes, because the bill would require electronic service providers to make secret changes to their systems to give police and CSIS surveillance capabilities. Ron Deibert warns the bill would make it impossible for many privacy-preserving tools to operate in Canada. The same design question sits in the EU's stalled chat-control trilogue.
UK adds open banking to GOV.UK One Login identity verification — Biometric Update
Why it matters: Bank-verified identity as a route into the UK's state login, under a Swedish-owned contractor; inclusion through financial data.
The Government Digital Service awarded Ecospend, owned by Sweden's Trustly, a 4.7 million pound contract to add open-banking identity verification, validation and fraud risk assessment to GOV.UK One Login from 2027, alongside digital driving licences and newly launched passkeys, for a platform used by 23 million people across 250 services. It widens the evidence base for people without passports or licences, and makes bank data an identity source.
Where commercial value can actually be created around the EUDI Wallet — Biometric Update
Why it matters: The business-model question for the wallet now that national laws are in force: verifiers win first, wallet providers cannot charge users.
Biometric Update analyses where value accrues around the EUDI wallet: verifiers gain immediately by replacing document checks with credential presentations; issuers succeed when credentials ride on existing budgets; wallet providers, barred from charging individuals for basic functions, must sell to businesses; and selective disclosure blocks analytics-based models while verifier-pays-issuer billing without revealing the holder remains unsolved. Mandatory acceptance creates obligations, not revenue.
ICE builds common data and AI layer as biometric enforcement expands — Biometric Update
Why it matters: An enforcement agency assembling a data lakehouse with agentic AI over biometric, financial and location records; the integrated-surveillance architecture Europe's AI Act tries to constrain.
ICE is building STELLA, an enterprise data and AI architecture linking Homeland Security Investigations and Enforcement and Removal Operations through MuleSoft APIs, a Databricks lakehouse and an AI platform with planned software agents for multi-step tasks, under contracts to FCN, ASRC Federal and others across Google, Microsoft and AWS clouds, alongside a $25 million iris-recognition contract and access to private iris databases; which DHS biometric repositories connect is undocumented. ICE already runs 12 production AI applications.
Cambridge Facial Recognition Operation Scans 29,361 Faces and Leads to Three Arrests — ID Tech
Why it matters: Nearly 30,000 faces scanned for three arrests in a first deployment; the arithmetic of live facial recognition.
Cambridgeshire Constabulary's first live facial recognition operation scanned 29,361 faces to produce four matches and three arrests, figures the force published itself. Set beside London's rail trial with no arrests from alerts and the Fundamental Rights Agency's warning on indiscriminate systems, the ratio is the number that AI Act and UK oversight debates turn on.
Quantum & Cryptography
Critical Medical Devices Unable to Support PQC Transition — Infosecurity Magazine
Why it matters: Six percent of connected medical devices can run post-quantum cryptography; health data has a decades-long decryption horizon.
Forescout finds that only 6% of Internet of Medical Things devices and 16% of medical OT can support post-quantum cryptography, against 50% of IT devices, because of long lifecycles and limited upgrade paths; of more than 5,500 internet-exposed healthcare systems only 31% support TLS 1.3, the only version that enables standardised PQC. Medical records keep their value for decades, which makes them the prime harvest-now-decrypt-later target. The advice is inventory, isolate what cannot be upgraded, mandate TLS 1.3 in procurement and press vendors on PQC timelines, the same gaps the EU's PQC roadmap gives member states until 2030 to start closing.
BAQIS and CAS Physics Ship 2000 uW Modular Dilution Fridge Below 10 mK for Quantum Chips — Pandaily - China Tech News, AI & Electric Vehicle Insights
Why it matters: Chinese institutes shipping a domestic cryogen-free dilution refrigerator for quantum chips; supply-chain independence reaching the cryogenics layer.
The Beijing Academy of Quantum Information Sciences and the CAS Institute of Physics report a modular cryogen-free dilution refrigerator prototype delivering 2000 microwatts of cooling below 10 millikelvin for quantum chips, a component class dominated by a handful of European and US suppliers and subject to export controls.
Cybersecurity & Threats
[P1] Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks — CyberScoop
Why it matters: The FBI and Secret Service warning that FortiBleed is still locking operators out of hundreds of thousands of Fortinet firewalls and feeding ransomware affiliates.
The FBI and Secret Service issued an alert that FortiBleed, the credential-compromise campaign against Fortinet firewalls and VPN gateways first exposed in summer 2026 with more than 86,000 verified compromised devices across 194 countries and 400,000 to 450,000 targeted, remains active: attackers use stolen credentials to create administrator accounts and alter existing ones, can lock organisations out of their own devices, and initial-access brokers sell the access to ransomware affiliates including INC/Lynx and Payload.
severity critical · exploited in the wild · EU: NIS2, DORA, CER
[P1] Hackers obtain counterfeit TLS certificates for Google and other large services — Ars Technica - All content
Why it matters: Hijacked country-code registries let attackers mint valid certificates for Google and other global brands; the trust model held as designed and still failed.
Google disclosed that attackers hijacked the registries of three top-level domains, .gh for Ghana, .sl for Sierra Leone and .as for American Samoa, altered DNS records and nameserver delegations for chosen domains, passed domain-control validation like legitimate owners and obtained valid TLS certificates for Google properties and several leading global brands and online services; Google pushed the certificates into Chrome's CRLSets, asked the issuing CAs to revoke them, and found more in Certificate Transparency logs, warning it cannot guarantee it found every affected domain and that Chrome interventions do not protect other browsers.
severity critical · exploited in the wild · EU: NIS2, eIDAS 2.0, DORA
[P2] Ninja Forms plugin flaw exploited to hack WordPress sites — BleepingComputer
Why it matters: Stored cross-site scripting in two WordPress plugins on half a million sites, exploited to plant fake plugins and hidden administrators.
Attackers are exploiting stored XSS flaws in Ninja Forms (CVE-2026-94504, versions 3.15.3 and earlier, 500,000 sites) and WPC Product Bundles for WooCommerce (CVE-2026-93836, 8.6.6 and earlier, 30,000 sites), injecting script into form submissions and order data that runs when an administrator views it and installs a fake WP Smart Thumbnails plugin, creating a visible and a hidden administrator, a secret login URL and an unauthenticated file manager; the same actor hit both from imgcdn1[.]com in a campaign seen from 4 October. Updates to 3.15.4 and 8.6.7 do not remove existing infections.
severity high · exploited in the wild · CVE-2026-94504 · EU: GDPR, NIS2, PSD2
[P2] LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings — The Hacker News
Why it matters: Code execution from a spreadsheet with no macro warning in the office suites European administrations chose for sovereignty.
Researchers at V12 and Codean Labs showed that a malicious spreadsheet can make LibreOffice (CVE-2026-63277, before 26.2.5 and 26.8.0) and Apache OpenOffice (CVE-2026-59265, 4.1.16 and earlier) run attacker code on opening by using database-range functionality to pull a Java database driver from an attacker's server, with no macro prompt; the flaw requires Java support enabled, LibreOffice fixed it on 5 October and OpenOffice's fix awaits 4.1.17. No real-world attacks are confirmed.
severity high · CVE-2026-63277 · EU: NIS2, CRA
[P2] Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes — The Hacker News
Why it matters: A human-operated phishing platform impersonating AI advertising products to take over Google, Meta and TikTok ad accounts through live MFA relay.
Island researchers documented a human-operated phishing platform that builds fake advertising portals for ChatGPT, Gemini, Claude, Perplexity, Muse and Manus and uses browser-in-the-browser windows showing trusted domains while an operator drives the flow in real time, requesting passwords, triggering SMS and authenticator prompts and accepting or rejecting codes, targeting agency staff, media buyers and manager-account administrators to steal and resell advertising accounts and budgets.
severity high · exploited in the wild · EU: DSA, GDPR, NIS2
[P3] Long-Running NPM Malware Campaign Accumulates 40,000 Downloads — SecurityWeek
Why it matters: Eight malicious npm packages live for three years with 40,000 downloads; three were still installable this month.
Checkmarx documented MALFEX, a supply-chain campaign publishing eight malicious npm packages since August 2023 with more than 40,000 downloads, including function-flag with 37,000, delivering a Windows remote-access trojan with screen capture, keylogging and hidden desktop, a stealer targeting Discord, browsers and crypto wallets, and a per-version downloader; three packages remained installable as of 1 October and no legitimate packages depend on them.
severity medium · exploited in the wild · EU: CRA, NIS2