📝 Show notes
CyberAware Daily — 2026-09-13
- Weekly recap of real DarkWatch figures: 480,887 captures, 9,358 entities, 1,629 alerts and one active target tracked this week
- An active ransomware leak site was detected online. We explain what that means for ordinary households and what to do if a company you use is breached
- Microsoft released a large monthly patch bundle fixing nearly a thousand security issues. What actually matters for home users
- The FBI is investigating a service that sold more than 153 million driver's licence records. Why your licence details are valuable to fraudsters
- Two alleged members of TeamPCP were arrested in Australia
- CISA added five actively exploited flaws to its known exploited list, covering Artifactory, ScreenConnect and RouterOS. Relevant if you run a small business
- Research into how company-wide AI adoption changes security operations
- AI agents linked to a software supply chain campaign affecting the RubyGems library
More at https://cyberawareuk.co.uk
📄 Full transcript
It's Sunday the 13th of September, and this is CyberAware UK,
the show that helps British families stay a step ahead of the scammers.
I am joined as always by Alex. Alex, Sunday means recap day.
It does. And this week the Darkwatch numbers tell a busy story.
Across the last seven days they logged 480,887 captures, and those fed into 9,000,
358 entities and 1,629 alerts.
For anyone new, captures just means pieces of suspicious activity or data that the monitoring
picked up. Alerts are the ones that actually mattered enough to flag.
Right. And one active target is being tracked at the moment.
Darkwatch also spotted an active dark web leak site that's live and responding.
That's a ransomware crew publishing stolen data. We won't name the address, obviously.
The practical point for a normal household is that if a company you use gets hit,
the risk to you is usually your account details. So if you hear a firm you deal with has had a
breach, change that password and turn on two-step verification.
Good advice.
Now the big one in the news this week.
Microsoft plugged nearly a thousand security holes in one go.
That's a huge patch release.
Nearly a thousand sounds terrifying, but here's the calm version.
Microsoft fixes things in bulk every month.
The ones to care about are the flaws that are already being used by criminals,
and the fix is simply to let your updates install.
Most home machines do that overnight.
If yours keeps asking and you keep clicking later, just let it run.
Next, the FBI is investigating a service that was selling more than 153 million driver's license records.
That's a US case. So most of us aren't in those records.
But the lesson travels.
Your driving license details are valuable to a fraudster trying to open accounts in your name.
So keep a copy of your license number somewhere safe,
and if you're asked for it by someone who contacted you out of the blue,
stop and check before handing it over.
Two alleged hackers from a group called Team PCP were arrested in Australia.
Arrests are always welcome news.
It shows these operations do get chased.
It's not something you or I need to act on,
but it's a good reminder that reporting a scam in the UK,
whether it's to action fraud or your bank,
does feed the bigger picture.
And over in the States, the CISA added five flaws to their known exploited list.
The names are Artifactory, Screen Connect and Router OS.
Those are business tools mostly.
So if you're listening at home, this isn't aimed at your laptop.
But plenty of our listeners run small businesses.
If you use any of those three, get the updates applied this week.
If you don't recognize the names, you can safely move on.
There's also been research into what happens when a whole company suddenly adopts AI tools
and how that changes the security team's job.
Interesting, but not something a family needs to act on.
The short version is more tools means more things to keep an eye on.
Same principle applies at home, honestly.
Every new app you add is one more thing to keep updated
and one more place your details live.
And finally, AI agents have been linked to a software supply chain campaign
affecting the RubiGems code library.
That's deep developer territory.
If you're not writing code, it doesn't touch you.
If you are, treat your build tools with the same suspicion
you'd treat any download from the internet.
So that's the week.
One takeaway before we go.
Do the boring thing today.
Check your phone and laptop have no updates waiting
and make sure two-step verification
is switched on for your email and your bank.
That's the single habit that covers most of what we talked about.
Nicely put.
We're back tomorrow with a fresh episode.
Until then, stay sharp and stay kind to each other.