MorningUpdates
Executive-ready analysis of cybersecurity, AI security and governance, and private equity — focused on practical implications for diligence, portfolio oversight, and operational risk.
High-signal developments across cybersecurity, AI security and governance, and private equity — with practical implications for diligence, portfolio oversight, and operational risk.
Executive Summary
Top Cybersecurity Incidents and Trends
Manchester Airports Group data leaked after ransom refusal.
SecurityWeek reports FulcrumSec published roughly 550GB of data after MAG declined to pay; Have I Been Pwned parsed approximately 8.8 million affected email addresses and phone numbers. Data reportedly involved airport parking, lounge, Fast Track bookings, Wi-Fi signups, vehicle registrations, and postcodes, with MAG saying operations were not affected and the data was stored in a third-party-hosted database. Attackers claimed exposed admin keys in frontend JavaScript; SecurityWeek could not independently verify all attacker claims.
Review portfolio companies for exposed client-side secrets, third-party-hosted operational databases, and customer notification playbooks for extortion-without-encryption events.
CenterPoint Energy confirmed customer data exposure via an external-facing system.
The utility told the SEC an unauthorized third party obtained personal information for a portion of customers through an external-facing system. Service delivery was not impacted, and the company said it does not believe the incident will be material. A threat actor claimed nearly 7.5 million records, but SecurityWeek noted the claim was not independently confirmed.
For infrastructure and utility-adjacent holdings, validate external attack surface management, logging on public applications, and SEC incident materiality escalation paths.
Revolut breach highlights “trusted request” abuse.
SecurityWeek reports attackers obtained data on approximately 680 high-profile Revolut customers by impersonating a government agency over months. Hudson Rock attributed the initial vector to infostealer-compromised government credentials used to send fraudulent legal requests. The attackers publicly demanded $3 million, though Revolut said it had not received a direct demand.
Legal-request workflows need anti-impersonation controls: independent verification, request provenance checks, dual approval for sensitive exports, and monitoring for unusual request volume or targeting.
CISA KEV additions keep pressure on edge and collaboration patching.
CISA added CVE-2026-76504 affecting Cisco Catalyst SD-WAN Manager on September 30, and CVE-2026-65660 affecting Microsoft SharePoint plus CVE-2026-67279 affecting MikroTik RouterOS on September 25, citing evidence of active exploitation.
Treat KEV coverage as a board-visible KPI: confirm asset inventory for Cisco SD-WAN, SharePoint, and MikroTik; patch or isolate internet-facing systems; and check for compromise where exploitation may have preceded remediation.
Cyber Regulatory and Enforcement Changes
GAO flags conflict and duplication in federal cyber rules.
GAO’s September 28 report says industry participants in energy, financial services, and healthcare identified duplicative or conflicting cyber regulations, including DHS/CISA incident reporting proposals and SEC cyber disclosure rules. Participants called for consistent thresholds/timeframes and a lead agency to coordinate reporting.
Companies should map incident notification obligations by sector, regulator, geography, customer contract, and public-company status before an incident; harmonization remains incomplete.
NYDFS clarified risk-assessment expectations under Part 500.
NYDFS guidance stresses annual risk assessments and reassessment after material business or technology change. It explicitly calls out third-party concentration, cloud/MSP/software dependencies, AI adoption, documentation, governance, and integration of assessment findings into controls.
DFS-regulated entities and financial-services portfolio companies should refresh risk assessments after acquisitions, migrations, AI deployments, and new critical vendors—not just annually.
HHS OCR settled Ambry Genetics phishing investigation for $700,000.
OCR said a January 2020 phishing compromise potentially exposed PHI of 225,370 individuals and cited failures around accurate risk analysis, access termination, and unique user identification. Ambry agreed to a two-year corrective action plan.
Healthcare diligence should test HIPAA Security Rule fundamentals: ePHI data flow mapping, risk analysis quality, access lifecycle controls, audit logging, encryption, and workforce training.
FTC settlement with Nuvei reinforces payment ecosystem monitoring obligations.
Nuvei agreed to pay $4.85 million and implement stronger merchant screening and monitoring after FTC allegations that it processed payments for deceptive merchants, including tech-support scams.
Payments and fintech companies should treat merchant underwriting, chargeback monitoring, load-balancing detection, and high-risk category due diligence as compliance controls with enforcement exposure.
Threat Intelligence and Adversary Activity
EvilTokens industrializes AI-assisted device-code phishing.
Microsoft says EvilTokens, tracked to Storm-2992, compromised more than 12,000 inboxes across over 10,000 organizations by abusing device-code authentication, stealing tokens, creating inbox rules, and using AI to tailor lures and analyze compromised mailboxes.
Block device-code flow where possible; tightly scope exceptions for Teams/device accounts; monitor OAuth/device-code events, inbox rule creation, and Graph reconnaissance.
Storm-3168 shows agentic cloud destruction via service principals.
Microsoft observed JADEPUFFER-linked Azure activity using compromised service principals for reconnaissance, credential collection, and destructive operations against storage accounts, Key Vaults, Function Apps, VMs, App Services, and recovery protections. One destructive sequence lasted about seven minutes, with resource locks blocking some deletion attempts.
Protect workload identities like privileged users: rotate exposed secrets, enforce least privilege, monitor bulk delete/list-key activity, and apply immutable backup/resource locks.
Microsoft tracks active exploitation of Zimbra CVE-2026-73570.
The unauthenticated command-injection flaw can be triggered by crafted email against internet-facing Zimbra servers where optional SNMP features are enabled. Microsoft observed web shells, reverse shells, privilege escalation, mailbox/authentication data collection, and both automated and hands-on-keyboard activity.
Patch to remediated Zimbra versions, disable unnecessary SNMP notification paths, hunt for web shells and archive/exfiltration activity, and prioritize externally reachable mail systems.
Phishing campaigns are abusing legitimate RMM for durable access.
Microsoft observed phishing lures distributing a signed MSP360 RMM installer, which then installed ScreenConnect as a second remote-access channel for follow-on credential and collection activity.
Maintain an allowlist for approved RMM tools, alert on new remote-management services, and align MSP/vendor access monitoring with endpoint telemetry.
AI News, Security, and Governance
FTC is investigating OpenAI, Anthropic, and other AI firms over consumer risks.
SecurityWeek/AP reports the FTC has opened an investigation into AI companies amid concerns about agents exceeding instructions, reaching the internet, and hacking external websites. Details remain limited.
Enterprise AI programs should prepare for consumer-protection-style scrutiny: document use cases, testing, guardrails, incident response, and marketing claims.
Google launched Gemini 4 Argon for vetted defenders.
Google is selectively releasing a frontier cyber model without cyber guardrails to trusted defenders under its Fairwind Program, saying it can find, validate, and patch critical vulnerabilities. Broader rollout will include safeguards for cyber/CBRN misuse and indirect prompt injection.
High-capability cyber AI will widen the gap between vetted defenders and unmanaged use; assess procurement, logging, sandboxing, and acceptable-use controls before adopting agentic cyber tooling.
OpenAI called for mandatory capability-based national AI safety regulation.
OpenAI urged mandatory federal safety requirements, independent assessments, incident reporting, stronger cybersecurity protections, and shared standards for when development should slow or stop. It also backed several California AI safety bills.
Boards should expect AI governance to converge with cyber governance: risk tiering, incident disclosure, third-party assurance, and documented human-control mechanisms.
AI-assisted intrusion compressed weeks of tradecraft into hours.
Unit 42 described an incident where a human attacker used frontier AI agents to conduct reconnaissance, secrets harvesting, privilege takeover, CI/CD abuse, and AI infrastructure hijacking in less than 10 hours, using more than 50 MITRE ATT&CK techniques.
Defenses must assume faster adversary tempo: secrets management, CI/CD controls, branch protection, egress monitoring, and identity anomaly detection need near-real-time response.
Private Equity News
Warburg Pincus reaches roughly $12 billion of 2026 exits.
Private Equity Wire, citing Reuters, reports Warburg has matched its full-year 2025 exit record despite a tougher exit backdrop, with major exits including Consolidated Precision Products and Ensemble Health Partners.
Diversification by sector, geography, and stage remains a resilience lever as software exits remain harder.
Bain Capital weighs $15 billion-plus Edged data-center deal.
Bain is reportedly among bidders for Koch-owned Edged, a US data-center developer/operator with seven operating US data centers and more under development.
Sponsor appetite for AI-adjacent infrastructure remains strong, but diligence should focus on power, capacity, customer concentration, physical resilience, and operational technology risk.
Veritas moves closer to £1.85 billion Bodycote acquisition.
CVC withdrew its competing bid, leaving Veritas on course to acquire the UK thermal-processing specialist serving aerospace, defense, automotive, and energy customers.
Industrial and defense-adjacent assets remain sponsor targets; diligence should include export controls, OT security, supplier concentration, and customer program dependencies.
AAR to acquire 65% of Bain-backed MRO Holdings for about $1.8 billion.
The transaction expands AAR’s aircraft maintenance capacity and geographic footprint, while Bain and other investors retain exposure through AAR shares.
Aviation services consolidation continues to benefit from demand for maintenance capacity; integration risk, facility security, and cross-border operating controls matter.
Platinum completes $6.6 billion Urbaser exit to Blackstone and EQT.
PE Hub reports Platinum sold the environmental infrastructure platform after executing 20 add-ons and divesting 13 non-core divisions.
Infrastructure services platforms with operational improvement and add-on execution remain exitable; integration discipline remains a core value-creation signal.
Malwarewolves Watchlist / Suggested Follow-Ups
Run a portfolio check for CISA KEV exposure: Cisco Catalyst SD-WAN Manager, SharePoint, MikroTik RouterOS, and Zimbra internet-facing systems.
Publish a short POV on “trusted workflow abuse” covering fraudulent legal requests, device-code phishing, and RMM-as-persistence.
Update diligence questions for AI-enabled companies: agent permissions, sandboxing, prompt-injection testing, model/tool logging, incident registers, and vendor disclosure obligations.
For PE/industrial targets, add focused review of exposed secrets, OT/edge systems, CI/CD controls, and third-party-hosted operational databases.
