d4 · decrypted · topic
Ransomware and cybercrime
Extortion crews, credential markets and the economics of cybercrime. 13 posts so far.
The npm maintainer account North Korea phished, and the four packages it unlocked
Amazon has linked four npm supply chain compromises, including debug, chalk and axios, to a North Korea-linked group that phished a single trusted maintainer. Plus: an actively exploited hardcoded credential in Cisco's firewall manager, ShinyHunters' extortion claim against EY, and new NCSC guidance on surviving a disruptive cyber-attack.
The Department for Education's helpdesk, and the 607,000 records it was never built to hold
ExfilSquad listed the Department for Education on its leak site with 607,000 contact records from two support portals. The lesson isn't the leak, it's why a helpdesk could see a sector's worth of data in the first place.
An SD-WAN console with no way to hide, and the flaw attackers found first
Arista's VeloCloud Orchestrator shipped with no setting to take its admin console off the public internet, and attackers found the resulting command injection flaw before most customers had patched. Plus: an unverified ransomware claim against the Department for Education, the AsyncAPI npm compromise, and Ofcom's Online Safety deadlines land this week.
The Craneware breach, and the 2,000 hospitals waiting on Edinburgh
An Edinburgh-listed billing software maker used by 2,000 US hospitals disclosed a breach this week, well handled by most measures. Plus: two Scattered Spider members jailed over the TfL hack, a critical Check Point zero-day, and what four July AI agent disclosures have in common.
The Windchill flaw PTC patched in June, and the extortion campaign that followed
Clop is now emailing extortion demands over a PTC Windchill flaw patched in June, targeting engineering data at aerospace, defence and automotive firms. Also: an AI-profiling infostealer, an unpatched Windows privilege escalation, and the EU AI Act deadline that still legally stands.
The fake Claude app that lived on claude.ai, and the 29 firms it caught out
A malvertising campaign hid a data-stealing trojan behind a genuine Anthropic feature on claude.ai itself, hitting 29 organisations. Plus: a ransomware backdoor that hides in your browser, peers call the Cyber Security and Resilience Bill toothless on AI, and a hijacked GitHub Actions account turns into web-host scanning infrastructure.
A hospital billing vendor's breach, and the 147 million records it inherited
Craneware's breach exposed patient data it inherited through a 2021 acquisition, raising a data-minimisation question for any UK firm that has bought its way into systems it didn't design. Plus a fourth Langflow RCE hits CISA's exploited list, Brussels tightens AI-scraping rules the ICO already enforces, and a Dutch cooling failure tests cloud resilience.
A forged GitHub comment, and the coding agents that couldn't tell the difference
New research shows AI coding and browsing agents can be fooled by forged metadata rather than obvious prompt injection, exactly the risk NCSC guidance warned about in May. Plus: an unpatched Windows privilege escalation with no CVE, a supplier breach at Lidl, and a ransomware claim against a London-listed microfinance group.
Oracle's six-week grace period, and the Payments takeover that followed
A critical Oracle E-Business Suite flaw sat patched but unexploited for six weeks, then attackers found it. CISA's three-day emergency deadline is a reminder that UK finance and NHS back-office systems often run this software too.
Routers left on factory settings, and the sanctions that came the same day
The NCSC and seventeen allied agencies warn that Russian FSB hackers are walking into routers left on default settings, the same day the UK and EU sanction two dozen Russian-linked cyber actors. Plus: a botnet hidden in 148 npm packages, and UK regulators formally put AWS, Google, Microsoft and Oracle under financial oversight.
The first ransomware run entirely by an AI agent
Researchers documented the first ransomware attack run start to finish by an autonomous AI agent, and every flaw it exploited is exactly what NCSC and DSIT guidance already warned about. Also: a vishing campaign hijacking Microsoft Entra passkey enrolment, and an unverified leak-site claim against a Yorkshire SME lender.
No zero-day needed: the FortiBleed credentials now for sale
Foreign Office, NHS and energy logins harvested in the FortiBleed campaign are being sold on dark web forums this week, a reminder that credential reuse and missing MFA, not clever exploits, are still doing the damage. Plus: an exploited flaw in AI platform Langflow, fake payment SDKs on npm and PyPI, and Ofcom's looming age-assurance deadlines.
Two old bug classes, one fresh ransomware wave
Ransomware crews are walking into UK networks through known flaws in on-premises SharePoint and Citrix NetScaler, not novel malware, just as new figures put the UK top of Europe's ransomware league table. The lesson is about recurring vulnerability classes, not this week's patch.