Weekly Cyber Briefing 25.09.2026

Weekly Cyber Update: 25 September 2026

EU Cyber Resilience Act reporting goes live; Grindr settles class action suit; Google lifts the lid on AI attacks; and there are question marks over the resilience of food supply chains

The Cyber Threat Intelligence Briefing is a weekly round-up of the latest cybersecurity news, trends and indicators, curated by our CISO, Nick Harris. Here’s our pick of the top stories, and why you should care.


EU Cyber Resilience Act: Article 14 reporting goes live

The EU’s Cyber Resilience Act (CRA) entered its first operational phase today with reporting obligations. Manufacturers of connected hardware and software products sold into the EU must now report actively exploited vulnerabilities and severe security incidents to ENISA’s new Single Reporting Platform. The rest of the CRA applies next December.

What exactly is in scope?

IoT devices, routers, smartphones, laptops, connected machinery, accounting and finance software, and open source software. Basically, if a product has digital connectivity and is sold into the EU market, the CRA almost certainly applies, requiring a notification if:

  • There is reliable evidence that a malicious actor has exploited a flaw in a system without the system owner’s permission
  • There is an incident that affects, or could affect, a product’s ability to protect sensitive or important data or functions

How does it work?

An early warning must be submitted within 24 hours of the manufacturer becoming aware with a full notification within 72 hours and a final report within 14 days of a patch being available or a month after the incident notification. Weekends are counted and the European Commission has even helped define the “becoming aware” clock.

Next December, secure-by-default design, vulnerability handling processes, software bills of materials and CE marking will be required


Grindr to pay £26m over HIV status data shared with third parties

Grindr has agreed to pay £26m ($35.2m) to settle a UK class action (served in the US on behalf of 11,000 claimants) alleging it provided advertisers with sensitive user data, including individuals’ HIV status.

The incidents took place before early 2020, when Grindr was owned and operated by Chinese company Kuntun. The lawsuit was filed in April 2024. The settlement was signed on 4 September and includes no findings or admission of liability.

How did it happen?

Grindr’s DPO in May 2024 stated that HIV last-tested date information was shared with two third-party service providers in encrypted form, in order to facilitate the development and monitoring of a new feature that allowed users to include their HIV status in their profile. She said it was never used for advertising purposes and did not qualify as a data breach. However, the legal question was not whether the sharing was malicious, but whether it had an adequate lawful basis and whether users had been meaningfully informed.


GTIG: what AI is actually doing in attacks (and what it isn’t)

Google’s Threat Intelligence Group (GTIG) has published its Q2 2026 adversarial AI tracker, covering threat actors’ use of AI tools.

Its most concrete finding is a financially motivated threat actor who used an AI coding chatbot and a set of agent instructions to plan, build and execute a mass credential harvesting campaign in under six hours, operating from compromised cloud infrastructure. The agent autonomously managed the vulnerability scanning pipeline, performed real-time troubleshooting, and executed IP rotation logic without manual intervention. This reduced what GTIG calls “human-in-the-loop latency”. Another finding with clear practical implications is DUSTMAKER, malware attributed to UNC6780 (a financially motivated group also known as TeamPCP).

GTIG also observed increased threat actor demand for Claude and Gemini API credentials alongside traditional account credentials designed to provide AI API access. This is both because compute is expensive and because attacker tooling increasingly depends on it. (A note: GTIG specifically names Claude in the context of ShinyHunters’ extortion workflow.)

Where the evidence is thinner

Interestingly, the report states directly that it has not yet observed threat actors deploying fully autonomous exploitation pipelines against live targets in the wild. What it describes instead is a gradual maturation of humans using AI to accelerate specific phases of existing attack workflows.

The big takeaways are how AI is shortening the time available for defenders to detect and contain attacks, and that AI tooling in developer environments is now an active attack surface.


The food supply chain’s cyber problem is part of something bigger

The National Audit Office has published a report on the resilience of the food supply chain to disruptions. It includes a Defra statement that the department is less confident about the ability of businesses in the food supply chain to withstand shocks without government intervention over the next 5-10 years.

The NAO names M&S and Co-op directly, talks about the impact on resilience of the just-in-time model, and discusses the cyber exposure of the cold chain (the network of temperature-controlled facilities, vehicles and infrastructure that handles around 50% of food consumed in the UK).

The key structural problems the NAO identifies are:

  • No specific food supply chain assets are currently included in the government’s CNI Knowledge Base (the tool that maps critical national infrastructure)
  • The last national exercise that meaningfully tested food supply disruption scenarios was in 2023
  • Defra’s emergency response playbook has not been shared with food supply chain businesses
  • Defra lacks the legal powers to direct businesses during a catastrophic event. It cannot compel a supermarket to take actions during an emergency in the way that Norway’s Total Defence model allows
  • The food supply chain is not currently in scope of the Cyber Security and Resilience Bill

 

Latest articles

Be an insider. Sign up now!