decrypted · 16 september 2026 · vulnerabilities and patching · supply chain · surveillance and privacy
Iran's spyware campaign starts with a chat, not an exploit
The National Cyber Security Centre, the FBI and the Dutch AIVD used a joint advisory this week to expose CHOSEN BRICK, a Windows spyware family that Iranian state actors have been running against dissidents, activists and journalists, including people in the UK, since at least 2025. There is no clever exploit at the centre of this one. The advisory, published on 15 September, describes attackers spending weeks building rapport over WhatsApp and Telegram, posing as contacts or technical support, before persuading the target to install what looks like a normal app, Pictory, RunwayML and Norton Antivirus have all been spoofed as lures. Once it is running, CHOSEN BRICK reads Telegram and WhatsApp data, harvests contacts and emails, switches on the microphone, captures the screen, and in the worst cases deletes files or wipes the device entirely. It survives a reboot.
The con is the whole attack
Think of it less as a lock being picked and more as someone talking their way past a doorman by claiming to be a regular. No password was guessed, no software flaw was needed, the entire operation runs on borrowed trust. That is precisely what makes it hard to defend against with the usual toolkit: patching does nothing here, because there is nothing to patch.
Which is the Secure by Design lesson NCSC director Paul Chichester is really pointing at when he urges at-risk people to learn the social-engineering patterns rather than simply "be careful". You cannot out-vigilance a patient adversary who has weeks to spend on one target. What does work is removing the attacker's ability to cash in a successful con: application allowlisting that stops an unrecognised executable from running at all, endpoint tooling that flags new persistence mechanisms the moment they are created, and separating high-risk individuals' personal devices from any organisational network they touch. NCSC's advice to employers, to circulate the guidance to at-risk staff and support inspection of personal devices, is really an admission that the personal and the corporate perimeter have merged for anyone in journalism, activism or human rights work. UK organisations that employ or work with such people should treat this as a design requirement, not a training slide.
Why this is a UK story, not just an Iran story
The advisory is explicit that targeting reaches into the UK. For newsrooms, NGOs and law firms handling diaspora or human rights work, that means the threat model has to include state-level patience, not just opportunistic criminals. The right response is architectural: assume a determined operator will eventually get a device to run something, and make sure that when it happens, the blast radius is small.
Also this week
A critical authentication bypass in WSO2 API Manager, CVE-2026-5430, is now being actively exploited. The flaw lets an attacker forge a JWT signed with an algorithm the platform should never have accepted, netting a token with baked-in administrator rights. WatchTowr's honeypots caught forged tokens arriving on 13 September, months after WSO2 shipped a fix in May. Anyone running API Manager, Traffic Manager or the Universal Gateway on the affected 4.1 to 4.6 branches needs the patch now, not on the next maintenance window: the design flaw here, trusting an algorithm field the client controls, is a textbook case of validating the wrong thing.
Separately, Adobe patched a maximum-severity zero-day in Adobe Commerce and Magento Open Source, CVE-2026-75650, after confirming exploitation in the wild against merchants. Discovered by e-commerce security firm Sansec and codenamed StyleSmuggler, the flaw let unauthenticated attackers trigger code execution through a routine payment-failure email and drop a Rust backdoor or a PHP web shell, no login required. Adobe's patch landed on 7 September, but any UK retailer running an affected version should assume compromise until it has actually checked for the planted backdoors, not just applied the update.
Sources
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
- NCSC and Allies Warn of Iranian Spyware Campaign
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
- WSO2 Security Advisory WSO2-2026-5328 / CVE-2026-5430
- Adobe fixes critical Magento zero-day exploited to backdoor servers
- Adobe Security Bulletin APSB26-146: Adobe Commerce
If your organisation supports at-risk staff or runs Magento, WSO2 or similar exposed infrastructure and wants a second opinion on your defences, get in touch.
More like this
- Ransomware gangs catch up with a VMware bug CISA flagged in August 16 september 2026
- The bill comes due for the SSO flaw that hit 138 companies 13 september 2026
- A forged token is all it takes to become admin on WSO2's gateway 17 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.