📝 Show notes
CyberAware Daily — 2026-09-06
- DarkWatch weekly stats: 445,719 captures, 7,216 entities, 1,385 alerts, 5 active targets
- Recap: 153M driver licence data breach — freeze your credit now (free in UK)
- Warning: Unpatched Magento/Adobe Commerce zero-day backdoors online shops
- Business alert: JetBrains TeamCity breach led to AWS credential theft — update everything
- Action: Change passwords if you've been in a breach, and enable 2FA on your main email
- Coming Monday: Phishing and OAuth scams deep dive
More at https://cyberawareuk.co.uk
📄 Full transcript
Right then, Alex, it's Sunday, and you know what that means,
time to look back at the week that was in the world of scams and cyber trouble.
I do love a good weekly recap, but I've got to ask,
what does the Darkwatch Intel show us this week?
Well, the numbers are pretty big. Darkwatch clocked over 445,000 captures,
more than 7,200 entities, and 1,385 alerts. But here's the one that really matters,
five active targets right now. Five active targets sound serious.
What does that actually mean for someone in Wigan or Cardiff?
It means there are at least five ongoing attacks that we know about,
and the bad guys are actively going after them. But it's not about scaring people,
it's about being ahead of the game.
So what's the biggest story from this week that folk need to know about?
Well, we talked earlier about that FBI probe into the sale of 153 million driving licenses.
That's a huge one, your driving license number is a golden ticket for identity thieves.
Yeah, we covered that on Monday. But it's still worth remembering why it matters even now,
isn't it? Exactly. If you haven't already, it's not too late to freeze your credit with the likes of
Equifax, Experian, and TransUnion. It's free in the UK, and it blocks anyone from opening accounts in
your name. And we've said this before, but it doesn't hurt to repeat it. Freezing your credit
is like putting a deadbolt on your financial front door.
Now, turning to the business side of things, there's been a nasty zero day in Magento and
Adobe Commerce that hackers are using to backdoor online shops. That's a big deal for anyone running
a store. But what about Joe Public, who just shops online? Does that affect them?
Potentially yes, because if a shop gets backdoored,
the criminals can slip in malicious code that nabs payment card details.
So if you see a small online store start acting weird or asking for extra payment details,
think twice. And there was also that story about JetBrains TeamCity being breached.
They got AWS credentials. That sounds like a big business problem.
It is, but here's the takeaway for everyone. It's a reminder that even the big software companies
aren't infallible. That's why it's so important to keep everything updated from your phone to your
router. So what's the single best thing we can do right now, today?
Simple. Check if you've ever received a data breach notification, and if you have,
change those passwords. And if you haven't, set up two-factor authentication on your main email
account today. That's practical. And what can you tease for the week ahead on the show?
Monday we're diving into the latest phishing scams doing the rounds, plus we'll show you how to spot
a fake OAuth app before it gets your logins. So join us then. Sounds good. Remember folks,
a little caution goes a long way. Stay sharp, and we'll catch you tomorrow.
And as always, if you think you've been scammed, report it to Action Fraud, better to be safe than sorry.