d4 · decrypted · topic

Surveillance and privacy

Tracking, interception and the law around who watches whom. 13 posts so far.

Iran's spyware campaign starts with a chat, not an exploit The NCSC, FBI and Dutch AIVD exposed CHOSEN BRICK, Iranian spyware that reaches UK-based dissidents and journalists through fake friendships rather than a technical flaw. Plus: active exploitation of a critical WSO2 API Manager bug and a zero-day backdooring Adobe Commerce stores. Ransomware gangs catch up with a VMware bug CISA flagged in August CISA says ransomware crews have joined state-linked attackers exploiting an unauthenticated, critical VMware vCenter flaw first patched in July. Also this week: backdoors planted in JFrog Artifactory instances, and Apple's fight over a secret UK order to break iCloud encryption returns to the tribunal. Microsoft's Windows Defender patch didn't survive the week Microsoft patched a Windows Defender privilege escalation flaw this month; within days the researcher who found it published a working bypass called ShieldCrash. Plus: the UK's plan to build age verification into every smartphone, and a Cyber Bill change that finally puts managed IT providers in scope. The bill comes due for the SSO flaw that hit 138 companies Trezor confirms 347,000 customers were sent phishing emails after the Brevo SSO flaw covered last week, showing what cross-tenant identity bugs actually cost downstream. Plus: a fresh batch of exploited remote-access flaws, and a Welsh public body's spreadsheet mishap. A Russian spy operation had Claude rewrite its own malware after getting caught Anthropic says a Midnight Blizzard-linked group let Claude autonomously rebuild detected malware and hit 20+ targets; NCSC's agentic AI guidance explains the gap. Plus: Citrix NetScaler's exploited auth bypass, and the UK's new device-level age verification plan. The 768 AWS keys still working years after they leaked Truffle Security found hundreds of leaked AWS keys still granting full account control years after they leaked, a Zimbra mail flaw now under active exploitation, and Cifas data showing UK SIM swap fraud up 402% this year, with the design lesson from each. The Rust supply chain attack that memory safety didn't stop, and the advisory Microsoft retracted A backdoored Rust crate with a decade of trust behind it, tied by researchers to North Korea, shows memory safety doesn't stop a supply chain attack. Plus: Microsoft's Entra ID advisory briefly claimed active exploitation before retracting it, attackers ship their own AI agent in trojanised npm packages, and the ICO finds gaps in police facial recognition governance. The Azure breach that named Vodafone, and the MFA that waved it through A seller calling themselves TheHatman is offering 3.6 million employee records lifted from corporate Azure and Entra tenants, Vodafone among them, using nothing more exotic than password spraying and MFA fatigue. Plus: an ICO reprimand shows what happens when patching lapses for four years, and a critical macOS flaw is being used to mine Monero. GE and Philips join Shell on Clop's leak site, over a flaw exploited before it had a patch General Electric and Philips are investigating Clop ransomware data theft claims, widening a campaign that already hit Shell through a critical zero-day in PTC's Windchill engineering software. Plus: an actively exploited Cisco firewall flaw prompts an NHS alert, and France's tax authority discloses a breach it quietly contained since June. The Power Pages default behind three UK breaches this month Researchers this week confirmed a data-extortion crew's claims against 13 organisations, including the UK's Department for Education, the Police National Legal Database and Newcastle University, all breached via one misconfigured Microsoft Power Pages setting. Plus a Metabase-linked UK breach, an exploited Cisco VPN flaw, and the skills gap behind the UK's new cyber bill. Apple goes back to court over the UK's iCloud backdoor Apple has filed a second legal challenge against the UK's demand for access to encrypted iCloud backups, a case that puts lawful access and secure design on a collision course. Also: today's CISA deadline for a trio of exploited flaws, including an AI workflow tool that handed out superuser access by default, and an extortion gang that never bothered sending a ransom note. A hospital billing vendor's breach, and the 147 million records it inherited Craneware's breach exposed patient data it inherited through a 2021 acquisition, raising a data-minimisation question for any UK firm that has bought its way into systems it didn't design. Plus a fourth Langflow RCE hits CISA's exploited list, Brussels tightens AI-scraping rules the ICO already enforces, and a Dutch cooling failure tests cloud resilience. The AD FS zero-day hiding inside a record Patch Tuesday Microsoft's biggest-ever Patch Tuesday fixed two zero-days already under attack, and the one in AD FS matters more than the one in SharePoint. Also: an unconfirmed ransomware claim against Arm, the Bank of England's new oversight of AWS, Azure, Google Cloud and Oracle, and the UK's under-16s social media law.