This weekly roundup covers a stark small-business cyberattack report out of the UK, a hardware flaw exposing Nintendo Switch owners to nearby attackers, the largest known seizure of AI deepfake porn websites, a candid conversation on AI’s role in offensive security, new US legislation targeting elder fraud, and a fresh national threat-intelligence partnership in the UAE.
From consumer hardware to national policy, this week’s developments show that exposure isn’t limited to large enterprises or nation-state targets — small businesses, individual console owners, and everyday victims of fraud and non-consensual imagery are all squarely in scope, even as governments and industry move to close the gaps.
The Cyber Express Weekly Roundup
UK Small Businesses Face Higher Cyberattack Rates Than Global Peers, Hiscox Report Finds
UK small firms are being hit by cyberattacks at a rate well above the global average, according to Hiscox’s 10th annual Cyber Readiness Report. The survey of nearly 7,000 smaller businesses worldwide, including 1,000 in the UK, found that 38% of UK firms suffered a successful attack in the past year, compared with a 29% global average — the highest rate among all markets surveyed. Read more…
Cyble Signs MOU with UAE Cyber Security Council to Boost National Threat Intelligence
Cyble, an AI-native cybersecurity firm, has signed a Memorandum of Understanding with the UAE’s Cyber Security Council to strengthen the country’s national threat intelligence capabilities. Announced in Abu Dhabi in September 2026, the agreement centers on delivering advanced threat intelligence, early warning capabilities, and insights into emerging cyber risks facing government and critical infrastructure entities across the UAE. Read more…
Nintendo Switch Flaw Let Nearby Attackers Run Code, Steal Data
Nintendo has patched a flaw in the original Switch that let nearby attackers hijack its QR-code-based “Send to Smartphone” feature to run unauthorized code or steal data, including account information stored on the console. Tracked as CVE-2026-82079, the bug affected consoles on firmware older than version 23.0.0; the Switch 2 is unaffected. Read more…
Manhattan D.A. Seizes 12 Deepfake Porn Websites in Largest Known Takedown of Its Kind
The Manhattan District Attorney’s Office has seized 12 websites allegedly used to create, sell, and distribute AI-generated deepfake pornography targeting roughly 1,200 real people without their consent. Announced by D.A. Alvin L. Bragg Jr., it’s described as the largest known seizure of AI-generated celebrity deepfake websites to date, and the investigation is ongoing. Read more…
Rahul Singh Choudhary on AI’s Growing Role in Cryptanalysis and Offensive Security
In the latest episode of Security Pill Season 2.0, The Cyber Express interviewed cybersecurity analyst Rahul Singh Choudhary about how AI is reshaping cryptanalysis, vulnerability research, and penetration testing. The conversation opens with a key question: has AI moved from merely assisting security research to actively participating in it — particularly around the cryptographic assumptions underpinning wallets, exchanges, and smart contracts? Read more…
US House Passes GUARD Act to Boost Law Enforcement Fight Against Elder Fraud, Crypto Scams
The U.S. House of Representatives has passed the bipartisan GUARD Act (H.R. 2978) on September 15, 2026, aimed at strengthening law enforcement’s ability to combat elder financial fraud and cryptocurrency scams. Co-led by Representatives Josh Gottheimer, Zachary Nunn, and Scott Fitzgerald, the bill now heads to the Senate. Read more…
Weekly Cybersecurity Takeaway
This week’s developments span the full spectrum of cyber risk — from small UK businesses absorbing a disproportionate share of attacks, to a hardware-level flaw putting console owners at physical-proximity risk, to AI tools being weaponized for non-consensual imagery at unprecedented scale.
Meanwhile, policy responses are accelerating on multiple fronts: US lawmakers are moving to arm local investigators against crypto-enabled elder fraud, and the UAE is deepening its national threat-intelligence posture through public-private partnership.
Taken together, the stories point to a widening gap between the speed of exploitation — whether by scammers, deepfake operators, or nearby attackers exploiting hardware — and the pace of institutional response, even as that response visibly picks up.






































