All episodes
Week of Sep 7, 2026

Threat Vectr Weekly — week of Sep 7

13 min
Share this episode

Stories covered this week

Transcript

Narrated by two AI anchors. Lightly formatted for reading.

Marcus

Welcome to Threat Vectr Weekly, your ten-minute briefing on the cybersecurity and digital safety stories that actually matter. I'm Marcus, and this week we have a lot to get through. A China-linked spy group has gone deeper into corporate networks than we've seen before, quietly turning off the lights as it goes. Australian regulators are telling smart glasses makers to stop treating bystanders like unwilling participants in a surveillance experiment. And a mother's account of what the online predator network known as 764 did to her child is the kind of thing that should make every parent put down what they're doing. We've also got a phone theft that cost one New Zealand man fifty thousand dollars, a White House insider who turned presidential speeches into a betting scheme, and more. Let's get into it.

Elena

We start this week with a story that isn't really about cybersecurity in the traditional sense, but it belongs here because it lives on the same platforms we talk about every week. A member of a predator network called 764 was sentenced to decades in prison this month, and Guardian Australia published an account from the mother of one of its victims that is genuinely difficult to read. So what is 764? It's a loose global network of online predators who target children, mostly through platforms built for gaming and chat, including Discord. The entry point is often something totally ordinary, a link inside a server a teenager is already in. From there, the group uses grooming, which means slowly building false trust with a child until they can manipulate and abuse them. Victims have been coerced into producing images and video of themselves, and that material is then used as blackmail to demand more. The practical takeaway here is not complicated. Talk to the children in your life about who they are actually speaking to online, and make clear that no stranger, however friendly, should ever be asking for images. Over to you Marcus.

Marcus

And that story really does underscore something we say a lot on this show: the threat surface includes people, not just software. Now, from child safety to corporate security, and a theme that dominated Black Hat USA in Las Vegas this summer. New research from Omdia, a technology analysis firm, found that eighty-eight percent of organisations are planning to spend more on what the industry calls offensive security, basically controlled attack drills where your own security team tries to break in before the bad guys do. The reason for the surge in spending is speed. AI is now giving attackers the ability to find and exploit weaknesses faster than human defenders can respond. The old model of running a penetration test once a year and ticking a compliance box is simply not keeping pace. The same research found that ninety-nine percent of organisations are treating software supply chain security as a board-level concern, which tells you something about how seriously executives are now taking this. One honest caveat from the research: AI tools used defensively can be unpredictable, can be manipulated by outside inputs, and can run up serious computing costs. The technology is not a silver bullet. Elena?

Elena

Right, and the cost of doing nothing is clearly higher than the cost of experimenting. Speaking of attackers moving fast, let's talk about a group called Fire Ant. Researchers at the incident response firm Sygnia have published findings linking this China-aligned espionage group to a fresh campaign that has gone deeper into corporate and government networks than we've seen from them before. Previously, Fire Ant was known for breaking into VMware hypervisors, which are the software layers that let one physical server run dozens of virtual machines. That's already a serious target. But now Sygnia says Fire Ant has moved into Cisco IOS XR routers, the heavy-duty machines that carry traffic across large corporate and carrier networks, along with TACACS servers, which are the systems that check whether a network engineer is actually authorised to log in to your gear. And then they're switching off or blinding the security logs, so defenders can't see what happened. If you run large network infrastructure, Sygnia's advice is direct: audit your router configurations, review TACACS accounts, and specifically check whether logging has been silently disabled. That last one is the tell. Back to you.

Marcus

That pivot from hypervisors to routers is significant. It means this group is going after the plumbing, the stuff that if it goes wrong, everything goes wrong. Now, a story from New Zealand that is a crisp reminder of how much damage a stolen phone can do. A Hamilton man named Marith Khao has been sentenced to eighteen months in prison after a thief's stolen cellphone gave criminals a direct route into the victim's Sharesies account. Sharesies is a New Zealand investment app that lets ordinary people buy and sell shares from their phone. Once inside, the criminals initiated three bank transfers totalling more than fifty thousand dollars. Sharesies caught the fraud partway through and blocked two of those transfers before they cleared. But seventeen thousand, six hundred and fifty-eight dollars had already landed in Khao's account. Khao received that money knowing it came from fraud, which makes him what courts call a money mule, someone who accepts and moves stolen funds on behalf of criminals, usually for a cut. He was convicted of money laundering and related charges. A separate incident from two years earlier showed Khao had also helped launder twenty-four thousand dollars stolen from a seventy-seven-year-old scam victim. The total across both cases: about seventy-four thousand dollars. The takeaway is practical. A stolen phone without strong screen-lock and app-level authentication is a key to your financial life. Elena?

Elena

Absolutely, and most investment apps now offer additional PIN or biometric locks inside the app itself. Use them. Now, from New Zealand to Washington, and a story that sits at the intersection of insider access and financial trading. A former White House teleprompter operator named Gabriel Perez has been fined one hundred and seventy-two thousand dollars by the US Commodity Futures Trading Commission, the CFTC, which is the federal agency that oversees trading in commodities and certain prediction markets. The allegation is that Perez used his privileged government access to place winning bets on a platform called Kalshi, where users can wager real money on whether specific real-world events will happen. In this case, the bets were on whether President Trump would use particular words in his speeches. Perez knew what Trump was going to say before anyone else outside the room did, because his job was to load those words onto the teleprompter. The CFTC says that is material, nonpublic information, meaning facts not available to the public, and using it to trade is illegal. Perez has since left his White House post. The case is a useful reminder that insider trading rules now extend well beyond the stock market. Prediction markets are regulated financial instruments, and the same rules apply. Marcus?

Elena

Are you at risk? Attackers do not break in any more, they log in, and your people are the way in. Train2Secure teaches your employees to spot the email before they click it, and proves it works with real phishing simulations and compliance-ready reporting. From $1.59 per user, per month. That is less than a small cup of coffee. Start free today at Train2Secure dot com. That's Train, the number two, Secure, dot com.

Marcus

The speed at which regulators are adapting to new financial instruments is genuinely interesting. Now, let's spend a moment on something less dramatic but genuinely important for anyone who manages shared drives at work. A guide published this week, flagged by BleepingComputer and drawing on advice from a software firm called tenfold, walks through five habits for keeping file server permissions from spiralling out of control. File servers, the shared drives where staff store documents, still sit at the heart of most organisations, hospitals, law firms, local councils. And ransomware, the kind of malicious software that scrambles your files and demands payment to get them back, loves them precisely because permissions are so often a mess. The core problem is something called permissions drift. People change roles, projects end, staff leave, and old access is almost never revoked. Over time, someone in accounts payable can open the legal team's sensitive files, not because anyone decided they should, but because nobody decided they shouldn't. The fix is straightforward in principle: least-privilege access, meaning each person can only reach what their current job actually requires. Automated tools can flag risky permissions faster than manual audits, but the discipline has to come from management. Regular reviews and clear ownership of folders are the two habits that make the biggest difference. Elena?

Elena

And it's one of those things where the boring, unglamorous work of doing it right really does stop ransomware in its tracks. Now to Australia, where the eSafety Commissioner, the government body responsible for online safety, published formal advice this week telling smart glasses makers to build automatic face-blurring into their products by default. The advice specifically names Meta's Ray-Ban smart glasses as a prominent example of the technology under scrutiny. Those glasses look almost identical to standard sunglasses, but they contain a small forward-facing camera that can record or stream whatever the wearer sees. The concern is passive, continuous collection of images of people who never agreed to be filmed. Unlike someone holding up a phone to record, a smart glasses wearer gives almost no visible signal that recording is happening. eSafety is also calling for much more obvious indicators when a device is recording, and warning companies not to use accessibility benefits for blind and low-vision users as a reason to avoid privacy safeguards. Separately, the Australian federal government is facing calls to ban camera-equipped smart glasses outright. No breach occurred here, but the regulator's point is that the harm is structural, baked into the design. Back to you.

Marcus

And the opt-out-by-default argument only works if people know they need to opt out. That is a real design problem. We'll close this week with a story that is equal parts funny and instructive. A reader received an automated phone call claiming to be from Barclays Bank, warning of a suspicious payment of more than a thousand pounds to the retailer Argos. Two things were immediately obvious: the reader had not made any such payment, and they don't even bank with Barclays. Classic bank impersonation scam. Instead of hanging up, this reader decided to stay on the line and waste the fraudsters' time for hours. And that is actually a legitimate defensive move. Every minute a scammer spends on a call with someone who is onto them is a minute they are not calling a more vulnerable person. How does the scam work? The goal is panic. A recorded message or live caller pretending to be your bank's fraud team creates urgency, then pressures you into reading out account numbers, passwords, or one-time passcodes, the short codes your bank texts you to confirm your identity. Hand those over and the account is gone. The Financial Conduct Authority in the UK has documented this pattern extensively. The defence is simple: hang up, find the bank's real number from the back of your card or their official website, and call back yourself. Never trust a number a caller gives you. That's our eight stories for the week.

Marcus

That is Threat Vectr Weekly for the week of September the seventh. Thank you for spending ten minutes with us. If you want this briefing in your inbox each week, head to threatvectr dot com slash newsletter and sign up. We'll be back next week with whatever the threat landscape throws at us, and based on recent form, it will be something. Stay sharp, stay skeptical, and we'll see you then. If you got something out of this, a thumbs up and a subscribe genuinely helps.

© 2026 Threat Vectr