decrypted · 30 august 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain
The NCSC's third warning in five months about exposed edge devices
The National Cyber Security Centre published its third warning in five months about internet-exposed edge devices this week, and for the third time the cause was not some novel attack technique. Routers, firewalls and industrial control interfaces are sitting open to the internet on default settings, and a range of threat actors are walking straight through the front door. The NCSC's 27 August advisory names no single victim or vendor: it reads as a pattern being flagged before it turns into next month's breach report, and it repays five minutes precisely because it isn't about one incident.
What the NCSC is asking for
The advisory says the NCSC has seen increased targeting of operational technology systems across multiple sectors globally, "including in the UK," and that it has been engaging with affected sectors directly. Its recommendations are deliberately unglamorous: build a definitive inventory of everything that faces the internet, replace default credentials with stronger access controls, keep OT devices off the open internet entirely, favour secure industrial protocols over legacy ones, log all connectivity, and separate OT, management and business networks so one breach doesn't become three. None of this is new advice. That is exactly the problem it's trying to solve.
The third warning is the tell
This isn't an isolated alert. In September 2025 the NCSC flagged state-linked malware, RayInitiator and LINE VIPER, targeting end-of-support Cisco ASA 5500-X appliances. In July 2026 it named Russia's FSB Centre 16 exploiting routers through default and weak SNMP credentials and unpatched Cisco Smart Install flaws. Three warnings in five months, describing the same failure mode with different attackers attached each time. The Secure by Design lesson isn't "patch faster": it's that a management interface should never have been reachable without authentication in the first place, and that no team currently owns the job of re-checking exposure after the fix ships. An asset inventory nobody revisits is just a document.
Also this week
Two men charged over the TeamPCP supply chain campaign. The Australian Federal Police, working with the FBI and Western Australia Police, charged a 21-year-old and a 23-year-old from Western Australia with a combined 13 offences over their alleged role in TeamPCP, the group blamed for inserting malicious code into open-source tools including the Trivy and Checkmarx KICS scanners and the LiteLLM AI gateway. The AFP says the code reached more than 1,000 organisations, compromised over 500,000 credentials and exfiltrated at least 300GB of data across GitHub Actions, Docker Hub, npm, PyPI and OpenVSX. Arrests don't uninstall malicious code: any UK team that pulled these packages during the compromise window still has to check its own pipelines, not just read the headline with relief.
McKesson confirms a breach after a $55.2 million extortion demand. The US healthcare distributor disclosed a cybersecurity incident to US regulators after the ShinyHunters group claimed to have voice-phished McKesson staff using fake help desk domains, compromising Okta single sign-on and pulling around a terabyte of data from connected Salesforce and Snowflake environments over four days. The claimed 284 million records are a count of data rows, not confirmed individuals, but the pattern, a phone call defeating single sign-on to reach a third-party SaaS platform, is one plenty of UK organisations share. It's the same lesson as recent vishing breaches, just at a larger and more sensitive scale: verify the caller, not only the password.
PaperCut needed a second emergency patch within a day. Researchers at watchTowr and Huntress found that PaperCut's initial fix for the actively exploited NG/MF vulnerabilities we covered on Friday could itself be bypassed, and identified an additional authentication flaw besides. PaperCut shipped a second patch on 28 August covering versions 24 through 26. If you administer PaperCut and stopped at the first update, you aren't finished.
Sources
- NCSC: Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
- AFP: Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate
- BleepingComputer: Australia arrests alleged TeamPCP hackers behind supply-chain attacks
- BleepingComputer: McKesson discloses breach after ShinyHunters claims patient data theft
- BleepingComputer: PaperCut releases second emergency patch for exploited flaws
- Huntress: PaperCut actively exploited
If any of this touches your own systems or supply chain, get in touch.
More like this
- The SSO flaw that let one attacker log in as 138 companies 11 september 2026
- N-able's fourth patch in five weeks exposes the risk in remote monitoring tools 8 september 2026
- The espionage group that taught routers to hide their own tracks 1 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.