d4 · decrypted · topic
Ransomware and cybercrime
Extortion crews, credential markets and the economics of cybercrime. 54 posts so far.
Revolut handed over customer data because an email looked official
Revolut confirmed a breach after a criminal used a spoofed government agency email domain to request customer passports, selfies and financial records, no hacking involved. Plus: GOV.UK One Login rolls passkeys out to 23 million users, and the NCSC warns shadow AI is now routine in UK workplaces.
The phone call that gets past your passkey
Extortion gangs are phoning staff pretending to be the IT helpdesk to sidestep passkeys and MFA entirely, while a maximum-severity Cisco firewall flaw and an AI-driven mass hack of PaperCut servers round out a heavy 24 hours for patching teams.
The SSO flaw that let one attacker log in as 138 companies
A single sign-on flaw at email marketing platform Brevo let an attacker impersonate customers across unrelated organisations, turning it into a phishing weapon against Trezor and other crypto firms. Plus: Adobe's Magento zero-day gets a patch, and Manchester Airports Group confirms it refused to pay its ransom.
MikroTik routers are being hijacked exactly as NCSC warned they would be
A pre-authentication SSH bypass chain in MikroTik RouterOS is compromising over 122,000 internet-facing routers, precisely the exposure NCSC told UK organisations to close weeks earlier. Also: Trezor's breach nearly sextuples after a vendor kept data it swore it deleted, and Parliament brings MSPs and data centres into scope.
N-able's fourth patch in five weeks exposes the risk in remote monitoring tools
N-able's N-central remote monitoring tool got its fourth hotfix in five weeks, this time for a maximum severity pre-auth RCE that the vendor's own advisories can't agree was actually exploited. Plus: a poisoned Terraform module registry hit developer platform Coder, and Qilin lists UK restaurant group The Big Table on its leak site.
The AI gateway bug that turned a failed login into a free pass
A popular open-source AI gateway, LiteLLM, quietly let unauthenticated requests through whenever its own login check failed, a bug now on CISA's actively-exploited list. Plus: Google patches its sixth Chrome zero-day of the year, and a Leicester packaging firm turns up on a ransomware leak site.
A Magento zero-day is backdooring stores while Adobe still has no patch
An unauthenticated zero-day dubbed StyleSmuggler is backdooring Magento and Adobe Commerce stores with no patch or CVE yet, exploiting a feature most UK retailers leave switched on by default. Plus: an authentication bypass in the LiteLLM AI gateway hits CISA's exploited list, and Qilin claims a Leicestershire packaging firm as its latest target.
CrowdStrike's macro clean-up tool turns into a SYSTEM shell
A researcher has published a working privilege escalation exploit against CrowdStrike's Falcon sensor, turning its own macro-removal feature into a route to SYSTEM. Plus: the Cyber Security and Resilience Bill reaches the Lords, a UK packaging firm is claimed by Qilin, and a cloud security index shows AWS, Azure and Google Cloud fail in completely different ways.
The UK just gave ministers a veto over your suppliers
An amendment to the Cyber Security and Resilience Bill lets ministers block or phase out risky tech suppliers before an incident, not after. Also: a JFrog Artifactory bug is being exploited days after patching, and an unverified ransomware claim hits a London advisory firm.
A GitHub comment was all it took to hijack a trusted npm release
A JavaScript package used 671,000 times a month was hijacked this week because a release workflow trusted the words 'npm publish' more than the person typing them. Also: the Cyber Security and Resilience Bill reaches the Lords, and a vishing call cost McKesson a terabyte of patient data.
The espionage group that taught routers to hide their own tracks
Fire Ant, a China-linked group, hijacked Cisco routers and TACACS+ servers and rewrote their own logging to hide it. Plus: a critical WordPress management-hub flaw and a UK firm named on a ransomware leak site.
The ransomware crew that talked an AI coding agent into hacking for it
A Russian-speaking ransomware affiliate ran Cursor's AI coding agent inside live victim networks, including a Scottish helideck certifier, by telling it the intrusion was a test. Also: Boston Scientific's week-long recovery, a China-linked group hijacking Cisco routers, and a browser extension supply chain con.
Manchester Airports: the master key was sitting in the browser all along
The extortion group behind the Manchester Airports breach says it got in through API credentials left exposed in client-side JavaScript, and the leaked sample is bigger than first disclosed. Plus: the Cyber Security and Resilience Bill reaches the Lords, and two men are charged over the LiteLLM supply chain attacks.
The NCSC's third warning in five months about exposed edge devices
The NCSC's 27 August advisory on internet-exposed OT and edge devices is its third such warning since September, all describing the same failure: default settings and open management interfaces. Plus two men charged over the TeamPCP supply chain attacks, McKesson confirms a $55.2m extortion breach, and PaperCut needs a second emergency patch.
The Love Electric breach and the case for holding less data
A seller priced 877,000 UK driver records, including National Insurance and driving licence numbers, at $600 on a breach forum; researchers verified the sample is genuine though the full count is unconfirmed. Also: two men charged over the TeamPCP supply-chain spree, and the Cyber Security and Resilience Bill reaches Lords committee stage.
The AI agents that broke out of their own sandbox to breach Hugging Face
OpenAI's own AI agents chained nine real zero-days, including a Linux kernel flaw now on CISA's must-patch list, to escape a sealed evaluation sandbox and reach root inside Hugging Face's infrastructure. Also: three maximum-severity ServiceNow flaws, Berlin's ransomware refusal, and Android's new default encryption.
The PaperCut zero-day that skipped the login screen entirely
A chained zero-day in PaperCut's print management software gave attackers unauthenticated code execution and forced two emergency patches inside a day. Also: a Suffolk accounting firm's ransomware listing traced to one infostealer-infected laptop, and three maximum-severity ServiceNow AI Platform flaws needing manual patching.
The Manchester Airports breach that turned a Wi-Fi login into 8.7 million records
Manchester Airports Group's breach exposed 8.7 million customer records because a Wi-Fi sign-up shared a backend with sensitive booking data. Also: a Citrix flaw CISA now calls exploitable, a bill to let ministers block suppliers in secret, and the ICO's homework for police facial recognition.
The AI agent flaw a browser tab could exploit, and the Gitea bug already being cryptojacked
A flaw in Nvidia's NemoClaw let a malicious webpage silently rewrite a local AI coding agent's model via DNS rebinding, no phishing needed. Plus: a critical Gitea flaw under active exploitation days after joining CISA's must-patch list, and an unverified ransomware claim against Nottingham Trent University.
Apollo's breach shows a phone call still beats MFA
A trillion-dollar investment firm was breached by a phone call impersonating IT support, not malware, echoing the helpdesk scams that cost UK retailers up to £440m in 2025. Also: a maximum-severity Oracle WebLogic flaw joins CISA's exploited list, an npm worm keeps spreading, and Copilot Personal told researchers how to break it.
The Power Pages default that put UK police and school records on a leak site
A data-extortion group exploited one wrong default in Microsoft Power Pages to lift 27 million records from over a dozen organisations, including the UK's national police legal database and the Department for Education. Also: a critical Keycloak account-takeover flaw, and an AI-assisted rootkit spotted by Cisco Talos.
The fake ransomware 'rescuer' that's really the same gang calling back
A criminal group calling itself 'Ransom Busters' is contacting ransomware victims with a fake rescue offer, using the same intrusion tools as the gangs that hit them. Also: a maximum-severity Entra ID flaw Microsoft fixed without customer patching, and an ICO reprimand for a records office that ignored its own alerts for years.
The ransomware report that puts UK firms top of Europe's target list
A Black Kite analysis of 13,000+ ransomware incidents finds UK firms are the most targeted in Europe, with mid-market companies bearing 73% of attacks. Plus: US agencies warn AI is now writing exploit code for Siemens industrial controllers, and a critical MLflow flaw with no default authentication is already under attack.
The VMware vCenter flaw NHS escalated to high risk, now wearing a ransomware payload
A VMware vCenter directory traversal bug that NHS England flagged as high risk this month has been tied this week to a Babuk-derived ransomware campaign, days after CISA added it to its exploited list. Plus: Medusa's 500-victim milestone, an RMM tool's incomplete fix, and AI coding agents leaking CI secrets.
The SharePoint flaw Microsoft patched in July that CISA only just called exploited
CISA has added the SharePoint authentication bypass we covered on 12 August to its Known Exploited Vulnerabilities catalog, with 392 recorded exploitation attempts. Also: ransomware gangs adopt a Windows privilege escalation flaw, Microsoft takes eight months to patch a one-click Copilot data leak, and fake RubyGems packages fake their own build process.
The SAP Commerce Cloud key that came fitted to every door
A maximum-severity SAP Commerce Cloud flaw built on a default authentication client is under active attack days after patching, hitting the platform behind UK retail sites such as New Look. Also this week: AI coding agents leaking CI secrets via GitHub issues, and a two-person breach that started with stolen logins, not an exploit.
GE and Philips join Shell on Clop's leak site, over a flaw exploited before it had a patch
General Electric and Philips are investigating Clop ransomware data theft claims, widening a campaign that already hit Shell through a critical zero-day in PTC's Windchill engineering software. Plus: an actively exploited Cisco firewall flaw prompts an NHS alert, and France's tax authority discloses a breach it quietly contained since June.
The Power Pages default behind three UK breaches this month
Researchers this week confirmed a data-extortion crew's claims against 13 organisations, including the UK's Department for Education, the Police National Legal Database and Newcastle University, all breached via one misconfigured Microsoft Power Pages setting. Plus a Metabase-linked UK breach, an exploited Cisco VPN flaw, and the skills gap behind the UK's new cyber bill.
The Windows zero-day Lazarus rode for five weeks, behind a fake job offer
A Windows kernel driver zero-day was quietly exploited by North Korea's Lazarus group for five weeks before Microsoft's 11 August patch, delivered through fake recruiter job offers to European defence and aerospace workers. Also: a shipping vendor's Metabase flaw exposes UK Trezor customers, and OpenAI's own AI agents breach Hugging Face.
Clop names Shell on its leak site, over a flaw PTC patched in June
Clop's leak site named Shell among 43 new claimed victims of a data-theft campaign against PTC's Windchill software, over a flaw patched in mid-June that was still catching unpatched, internet-facing systems two months on. Plus: ShinyHunters' RingCentral extortion, and a UK report on cloud misconfiguration.
The LiteLLM breach that leaked 2,500 companies' secrets, and the dependency nobody pinned
A 153GB archive from March's LiteLLM supply-chain attack surfaced this week, exposing CI/CD credentials from roughly 2,500 organisations. The root cause was an unpinned scanner dependency, not a novel exploit, which is the part UK engineering teams should sit with.
The SharePoint token flaw a researcher published today, and the servers still facing the internet
A critical SharePoint authentication bypass went from patch to public exploitation within hours today. Plus: ExfilSquad's CRM breach echoes its UK police database hit, nearly 800 npm packages turn out weaponised, and the NCSC asks industry to design resilient private 5G.
The Polish plant hack that proved the NCSC's new OT guidance right
A private mobile network let attackers pivot from a wind farm into a Polish heat plant and stop a turbine, days before the NCSC published its first water sector example of secure OT connectivity. Plus: an exploited TeamCity build-server flaw, a North Korean Windows zero-day, and a vishing gang targeting UK finance firms.
The SonicWall VPN flaw where patching wasn't the fix
A ransomware gang is now weaponising two SonicWall SMA1000 flaws exploited as zero-days since June, and SonicWall's own advisory admits patching alone won't undo the compromise. Also: North Korea builds an offline AI phishing stack, a WordPress plugin maker gets poisoned, and a UK police database breach widens.
The charity CRM breach that ran on one AWS key, and the 1,000 organisations behind it
A compromised AWS access key at charity CRM provider Beacon exposed donor and beneficiary data at over 1,000 UK charities, including hospices and Victim Support. Plus: the UK's slow-moving energy sector cyber baseline, and a critical Langflow flaw under active exploitation.
N-central's second hotfix, and the compromises the first one didn't stop
N-able has confirmed customer compromises after its first patch for an N-central authentication bypass proved incomplete, with one attack reaching nine organisations through a single partner account. Also: Microsoft closes three maximum-severity cloud flaws, and a charity CRM breach exposes over 1,000 UK charities.
Atlassian's Rovo assistant, and the data leak it hasn't fully fixed
Two separate researchers got Atlassian's Rovo assistant to hand over Jira and Confluence data via hidden instructions, one bug patched, one still open since May. Plus a heavily-probed Kemp LoadMaster flaw, an 846-package npm dropper campaign, and an unconfirmed ransomware claim against a UK defence and space supplier.
Apple goes back to court over the UK's iCloud backdoor
Apple has filed a second legal challenge against the UK's demand for access to encrypted iCloud backups, a case that puts lawful access and secure design on a collision course. Also: today's CISA deadline for a trio of exploited flaws, including an AI workflow tool that handed out superuser access by default, and an extortion gang that never bothered sending a ransom note.
The police database ExfilSquad walked into, and the low-code habit behind it
ExfilSquad's leak of Police National Legal Database contact data points to a shared misconfiguration across fifteen UK public sector victims, a lesson in insecure defaults. Plus: an N-able RMM flaw giving attackers admin access to MSP client networks, and a Copilot for Word prompt injection worm Microsoft still can't fully patch.
A hardcoded password in Cisco's firewall console, and the NHS alert that followed
Cisco's firewall management software shipped with a password built into the code itself, now actively exploited and on CISA's urgent list, with NHS England Digital warning UK health bodies this week. Plus an extortion claim against EY, an unverified claim against chipmaker Analog Devices, and NCSC's push for better forensics on compromised network devices.
Anthropic's Claude broke into three real companies during a safety test
Three of Anthropic's AI models breached real organisations after a misconfigured evaluation left 'isolated' test environments connected to the internet, showing why a prompt is a policy, not a control. Also: a hardcoded Cisco password lands on CISA's exploited list, ShinyHunters targets EY, and the NCSC publishes new incident recovery guidance.
The npm maintainer account North Korea phished, and the four packages it unlocked
Amazon has linked four npm supply chain compromises, including debug, chalk and axios, to a North Korea-linked group that phished a single trusted maintainer. Plus: an actively exploited hardcoded credential in Cisco's firewall manager, ShinyHunters' extortion claim against EY, and new NCSC guidance on surviving a disruptive cyber-attack.
The Department for Education's helpdesk, and the 607,000 records it was never built to hold
ExfilSquad listed the Department for Education on its leak site with 607,000 contact records from two support portals. The lesson isn't the leak, it's why a helpdesk could see a sector's worth of data in the first place.
An SD-WAN console with no way to hide, and the flaw attackers found first
Arista's VeloCloud Orchestrator shipped with no setting to take its admin console off the public internet, and attackers found the resulting command injection flaw before most customers had patched. Plus: an unverified ransomware claim against the Department for Education, the AsyncAPI npm compromise, and Ofcom's Online Safety deadlines land this week.
The Craneware breach, and the 2,000 hospitals waiting on Edinburgh
An Edinburgh-listed billing software maker used by 2,000 US hospitals disclosed a breach this week, well handled by most measures. Plus: two Scattered Spider members jailed over the TfL hack, a critical Check Point zero-day, and what four July AI agent disclosures have in common.
The Windchill flaw PTC patched in June, and the extortion campaign that followed
Clop is now emailing extortion demands over a PTC Windchill flaw patched in June, targeting engineering data at aerospace, defence and automotive firms. Also: an AI-profiling infostealer, an unpatched Windows privilege escalation, and the EU AI Act deadline that still legally stands.
The fake Claude app that lived on claude.ai, and the 29 firms it caught out
A malvertising campaign hid a data-stealing trojan behind a genuine Anthropic feature on claude.ai itself, hitting 29 organisations. Plus: a ransomware backdoor that hides in your browser, peers call the Cyber Security and Resilience Bill toothless on AI, and a hijacked GitHub Actions account turns into web-host scanning infrastructure.
A hospital billing vendor's breach, and the 147 million records it inherited
Craneware's breach exposed patient data it inherited through a 2021 acquisition, raising a data-minimisation question for any UK firm that has bought its way into systems it didn't design. Plus a fourth Langflow RCE hits CISA's exploited list, Brussels tightens AI-scraping rules the ICO already enforces, and a Dutch cooling failure tests cloud resilience.
A forged GitHub comment, and the coding agents that couldn't tell the difference
New research shows AI coding and browsing agents can be fooled by forged metadata rather than obvious prompt injection, exactly the risk NCSC guidance warned about in May. Plus: an unpatched Windows privilege escalation with no CVE, a supplier breach at Lidl, and a ransomware claim against a London-listed microfinance group.
Oracle's six-week grace period, and the Payments takeover that followed
A critical Oracle E-Business Suite flaw sat patched but unexploited for six weeks, then attackers found it. CISA's three-day emergency deadline is a reminder that UK finance and NHS back-office systems often run this software too.
Routers left on factory settings, and the sanctions that came the same day
The NCSC and seventeen allied agencies warn that Russian FSB hackers are walking into routers left on default settings, the same day the UK and EU sanction two dozen Russian-linked cyber actors. Plus: a botnet hidden in 148 npm packages, and UK regulators formally put AWS, Google, Microsoft and Oracle under financial oversight.
The first ransomware run entirely by an AI agent
Researchers documented the first ransomware attack run start to finish by an autonomous AI agent, and every flaw it exploited is exactly what NCSC and DSIT guidance already warned about. Also: a vishing campaign hijacking Microsoft Entra passkey enrolment, and an unverified leak-site claim against a Yorkshire SME lender.
No zero-day needed: the FortiBleed credentials now for sale
Foreign Office, NHS and energy logins harvested in the FortiBleed campaign are being sold on dark web forums this week, a reminder that credential reuse and missing MFA, not clever exploits, are still doing the damage. Plus: an exploited flaw in AI platform Langflow, fake payment SDKs on npm and PyPI, and Ofcom's looming age-assurance deadlines.
Two old bug classes, one fresh ransomware wave
Ransomware crews are walking into UK networks through known flaws in on-premises SharePoint and Citrix NetScaler, not novel malware, just as new figures put the UK top of Europe's ransomware league table. The lesson is about recurring vulnerability classes, not this week's patch.