The Cyber Threat Intelligence Briefing is a weekly round-up of the latest cybersecurity news, trends and indicators, curated by our CISO, Nick Harris. Here’s our pick of the top stories, and why you should care.
EU Cyber Resilience Act: Article 14 reporting goes live
The EU’s Cyber Resilience Act (CRA) entered its first operational phase today with reporting obligations. Manufacturers of connected hardware and software products sold into the EU must now report actively exploited vulnerabilities and severe security incidents to ENISA’s new Single Reporting Platform. The rest of the CRA applies next December.
What exactly is in scope? IoT devices, routers, smartphones, laptops, connected machinery, accounting and finance software, and open source software. Basically, if a product has digital connectivity and is sold into the EU market, the CRA almost certainly applies, requiring a notification if:
- There is reliable evidence that a malicious actor has exploited a flaw in a system without the system owner’s permission
- There is an incident that affects, or could affect, a product’s ability to protect sensitive or important data or functions
How does it work? An early warning must be submitted within 24 hours of the manufacturer becoming aware. A full notification must be submitted within 72 hours and a final report within 14 days of a patch being available or a month after the incident notification. Weekends are counted and the European Commission has even helped define the “becoming aware” clock.
Next December, secure-by-default design, vulnerability handling processes, software bill of materials, and CE marking will be required
Grindr to pay £26m over HIV status data shared with third parties
Grindr has agreed to pay £26m ($35.2m) to settle a UK class action (served in the US on behalf of 11,000 claimants) alleging it provided advertisers with sensitive user data, including individuals’ HIV status.
The incidents took place before early 2020, when Grindr was owned and operated by Chinese company Kuntun. The lawsuit was filed in April 2024. The settlement was signed on September 4 and includes no findings or admission of liability.
How did it happen? The firm’s data protection officer in May 2024 stated that HIV testing date information was shared with two third-party service providers in encrypted form, to facilitate the development and monitoring of a new feature that allowed users to include their HIV status in their profile. She said it was never used for advertising purposes and was never the subject of a breach. However, the legal question was not whether the sharing was malicious, but whether it had an adequate lawful basis and whether users had been meaningfully informed.
GTIG: what AI is actually doing in attacks (and what it isn’t)
Google’s Threat Intelligence Group (GTIG) has published its Q2 2026 adversarial AI tracker, covering threat actors’ use of AI tools.
It details the activity of a financially motivated threat actor who used an AI coding chatbot and a set of agent instructions to plan, build and execute a mass credential harvesting campaign in under six hours, operating from compromised cloud infrastructure. The agent autonomously managed the vulnerability scanning pipeline, performed real-time troubleshooting, and executed IP rotation logic without manual intervention.
GTIG also observed increased demand for Claude and Gemini API credentials alongside traditional account credentials for AI API access. This is being driven by the fact that compute is expensive and attacker tooling increasingly depends on it.
Interestingly, the report states directly that it has not yet observed threat actors deploying fully autonomous exploitation pipelines against live targets in the wild. What it describes instead is a gradual maturation of humans using AI to accelerate specific phases of existing attack workflows.
The big takeaways are that AI is shortening the time available for defenders to detect and contain attacks, and AI tooling in developer environments is now an active attack surface.
The food supply chain’s cyber problem is part of something bigger
The National Audit Office (NAO) has published a report on the resilience of the food supply chain. It includes a Defra statement that reveals the department is less confident about the ability of businesses in the food supply chain to withstand shocks without government intervention over the next five to 10 years.
The NAO names M&S and the Co-op Group directly. It also talks about the consequences of the just-in-time model, and discusses the cyber exposure of the cold chain: the network of temperature-controlled facilities, vehicles and infrastructure that handles around 50% of food consumed in the UK.
The key structural problems the NAO identifies are:
- No specific food supply chain assets are currently included in the government’s CNI Knowledge Base (the tool that maps critical national infrastructure)
- The last national exercise that meaningfully tested food supply disruption scenarios was in 2023
- Defra’s emergency response playbook has not been shared with food supply chain businesses
- Defra lacks the legal powers to direct businesses during a catastrophic event. It cannot compel a supermarket to take action during an emergency in the way that Norway’s Total Defence model allows
- The food supply chain is not currently in scope of the Cyber Security and Resilience Bill