Contents
Dear reader,
There’s a back-to-school feeling in the air and we’re looking forward to this autumn across both Islands. Here in Guernsey, work continues on our office build and we hope to be ready to welcome Islanders in-person in the coming weeks. We’ve also met with key stakeholders to understand more about the areas of concern, and how GCSC can add value. (If you did attend those events, thank you for your time. We held similar meetings in Jersey not long after JCSC was formed, and they have been the foundation for valuable relationships.)
Over in Jersey, we saw the first parts of the Cyber Security (Jersey) Law come into effect in 1 September. While some of the provisions are simply formalising what we already do, others add much-needed clarity on our role and responsibilities. Remember, the parts of the Law relating to Operators of Essential Services (OES) will come into effect on 1 December. If you are classified as an OES, the countdown is very much on.
We’re also looking forward to October which is - as you know - Cyber Security Awareness Month. We’ll be running Cyber Simulation Events, and supporting an industry briefing here in Guernsey (see more below). We’ll also be attending the Channel Islands Cyber Security Conference in Jersey on Friday 16 October. We’ll be sharing more information about the programme for October shortly, so keep your eyes peeled.
Until next time,

GCSC October Events
How Cyber Criminals Really Target Guernsey Businesses - Thursday 8 October 2026

GCSC is pleased to be supporting an upcoming briefing for Guernsey’s financial services sector, led by Parity Technologies. During the session international experts Huntress will outline how criminals really target local businesses, including a walkthrough of what happens during a real attack. GCSC will open the morning with our own view of the threat landscape here in Guernsey. Click below for full details and registration:
Guernsey Cyber Simulation Events - Wednesday 14 October

We’re partnering with Soteria Communications to run Cyber Simulation events for organisations in Guernsey on Wednesday 14 October. As with previous events, these simulations will give organisations a chance to experience a real-time incident, and plan their response.
All events are free to attend, and will be run confidentially. Book your free place today:
For All Organisations: 9am - 12pm
For Financial Services: 1pm - 4pm
We’ll also run an event for providers of Critical National Infrastructure (CNI). To book onto this event, email [email protected].
Channel Islands Cyber Security Conference: Friday 16 October
Booking for the 2026 Channel Islands Cyber Security Conference is open. We’ll be attending and speaking at the conference, which will bring together practitioners from the Channel Islands, UK, and beyond.
Speakers for the day will include:
Peter Job of Intergence and Dave Mareels of Sophos
Rob Shapland, Director of Cyonic Cyber and ethical hacker
Andy Compton, CEO of Cortida Ltd
Attendees in Guernsey can tune into the live stream, which will run throughout the conference. Places are always in demand, so book your ticket today.
GCSC Premises Update
Work continues on the GCSC office in Upland Road with signwriting now completed.

With furniture and network infrastructure due in the coming weeks we are hoping to be in a position to welcome guests soon.
GCSC would like to thank Amalgamated Facilities Management, Interior Systems, Quantum, Smith Signs, Spaces, SystemLabs and Vision Networks for their work towards establishing the operations centre.
Phish of the Month: Big Bear 2.0

Photo by Srikanth Sistu viaUnsplash
This regular series explores specific examples of phishing attacks that have caught our attention.
This issue we look at an example of a "phishing-as-a-service" (PhaaS) framework, which is being used to steal Microsoft 365 session tokens. For those unfamiliar, PhaaS is a subscription-based model where cyber criminals pay for access to the infrastructure needed to run phishing campaigns, without having to develop and maintain it themselves. (This is much like a legitimate business may purchase Software-As-A-Service). This example highlights how PhaaS allows less skilled threat actors to execute effective campaigns at scale.
What it is:
BigBear 2.0 is a commercial PhaaS platform based on Evilginx2 (a man-in-the-middle attack framework). It is configured to place a proxy between the victim and Microsoft’s legitimate sign-in service. This allows it to copy the resulting authenticated session token and pass it back to the bad actor. Security researchers at CloudSEK discovered and gained admin access to this service, identifying 5,137 exfiltrated records, 474 completed MFA-bypassed authentications, 1,032 plaintext passwords, 4,148 session cookies and 3,331 unique victim IP addresses. Interestingly, the phishing emails were delivered using "residential proxies" which matched the victim's location: this made it easier to bypass existing controls.
How it works:
The attack technique is what is known as "adversary-in-the-middle" phishing and it captures the entire session rather than just the password using the below steps:
The victim follows a phishing link in an email.
BigBear relays the victim’s interaction to the real Microsoft login service.
The victim supplies their password and successfully completes multi-factor authentication (MFA).
Microsoft creates an authenticated session and returns a session cookie.
BigBear copies that cookie.The attacker reuses the cookie to enter the victim’s Microsoft 365 session without repeating the login or MFA process.
Why it matters:
A stolen Microsoft 365 session token can provide access to all services available to that user (including Exchange Online, Teams, SharePoint and OneDrive) as well as applications connected through single sign-on. Although specific examples of the lure emails were not published in this case, it is likely they impersonated flows in the real Microsoft 365 experience so a credential/MFA prompt would be expected by the user.
What you can do:
The most important takeaways from this example are that modern phishing defence requires more than one control and reliance on some of the go-to advice isn't enough. Here are some points to consider:
MFA is essential but not sufficient by itself. Many modern attacks focus on bypassing or stealing MFA tokens.
Implement phishing-resistant MFA where possible. FIDO2/WebAuthn authentication methods are designed to verify website origin and much harder to proxy.
Security awareness training should prime users to be cautious of any email links that lead directly to login pages, and to treat unexpected 365 sign-in requests as suspicious.
A password reset alone may not be enough. Revoke active sessions/tokens, force re-authentication and review all sign-in activity and delegated permissions.
Prioritise hardening privileged accounts (admins, executives, those with access to sensitive data). Assume a user can be compromised even with MFA enabled - security controls should still prevent or limit access.
Read the original investigation by CloudSEK:
Self-Hosting Security
In this special focus, our intern Teague Mangan explores the world of home server security.
Many people, having grown tired of monthly subscriptions to various streaming services, have turned to self-hosting their own media servers such as Plex or Jellyfin. This sort of software allows you to manage and watch films and TV as well as store your own photos and music. It’s completely free and avoids content becoming unavailable because it lives on your device - anything from an old family desktop to a spare laptop.
Back in 2022, conversations surrounding the security of these services arose after it was discovered that the 2022 Last Pass breach originated from an employee’s own Plex server being compromised. This allowed the attacker to access the developer’s personal computer and install malware. The attacker was then able to find the developer’s password leading to the data breach.
This month, Plex is back in the news as ShadowServer announces they’ve found over 300,000 Plex servers exposed over the internet (including some in the Channel Islands). While it’s worth mentioning that exposed does not always mean vulnerable, this news comes just as Plex issues a security notice that all users should update their servers as soon as possible to the latest version.
Self-hosting can be a brilliant way of taking responsibility for your own data, but it also means you take responsibility for your data’s security too. Anyone running Pgoog
If you use Plex, Home Assistant, Nextcloud or similar services, you should keep in mind that if you don’t apply regular updates, you risk attackers gaining access to your data or hijacking the host machine for a botnet. Before you think “why would they target little old me?” attackers do not need to target you personally to become a risk. Automated scans search for outdated exposed services and match them against known vulnerabilities to see if you’re at risk.
So treat any exposed service the same way you would any internet-facing system and secure it. Place your services behind a VPN such as Tailscale or Wireguard if possible, apply updates when released, use 2FA and please, please, please, use a decent password.
Cyber Security in the News
Google Chrome zero-day under active exploitation
Google issued emergency updates for a high-severity V8 JavaScript engine zero-day (tracked as CVE-2026-85046) that was reportedly being exploited in the wild. The flaw could potentially allow code execution when a victim visits a malicious webpage.
Browser zero-days remain one of the most common enterprise initial-access vectors because every organisation relies on web browsers. Rapid patching is critical.
Record 974 CVEs in Microsoft Patch Tuesday
Microsoft has announced fixes for a record 974 CVEs in its September 2026 Patch Tuesday release. Most importantly, the release fixes two Windows vulnerabilities already being actively exploited: CVE-2026-85880, affecting Advanced Local Procedure Call, and CVE-2026-81963, affecting the Windows Update Stack. Read more below.
Jobs in Cyber
Are you recruiting for a cyber role locally? Tell us at [email protected] and we’ll share your job listing with the community.
Senior Information Security Consultant
Cyber security firm Zensec is looking for an Information Security Consultant to assist in providing virtual CISO (vCISO) and information security consultancy services to organisations across the Channel Islands.
Tools of the Month
Each month, we provide a roundup of tools that our team have found useful, and which could be useful to cyber security professionals. If you’ve found a helpful tool you’d like to share, please email us and we’ll include it in a future newsletter.
llmfit
If you’re looking to run a large language model (LLM) locally, llm fit can check your hardware and quickly tell you which models are compatible.
VisiData
VisiData is a free, open source tool that lets you quickly open, explore, summarise, and analyse datasets straight from your computer’s terminal. Excellent for tasks like frequency analysis.
Did you know? GCSC can also check potentially malicious files for you in our sandbox, but please let us know before sending them over.



