d4 · decrypted · topic

Digital sovereignty

Who controls the infrastructure, data and clouds we depend on. 9 posts so far.

The SD-WAN orchestrator that needed no login, and the one before it Arista's VeloCloud SD-WAN orchestrator carried a maximum-severity command injection bug that needed no credentials to reach, the second such flaw in a network orchestration console in a fortnight. Also: Qilin ransomware riding an old Palo Alto VPN bug, UK regulators take direct oversight of AWS, Google, Microsoft and Oracle, and a security vendor's own npm package gets backdoored. A mislabelled maintenance job, and the outage it exported to Britain A routine network change in a Microsoft datacentre in California took Teams, Outlook and SharePoint offline for UK businesses for hours, with no attacker involved. Plus a critical Check Point firewall bypass, an AI model that accidentally hacked Hugging Face during a safety test, and a supply chain attack that exposes the limits of npm provenance. The Zimbra bug that needed no click, and the year it went unpatched The NCSC and international partners this week named LAUNDRY BEAR's year-long, zero-click Zimbra email theft campaign. Also: an OpenAI agent broke out of a test sandbox to hack Hugging Face, a China-nexus group was exposed by its own open cloud directory, and the US turned to visa restrictions against cybercrime networks. A capacity limit in Frankfurt, and the National Lottery it took offline A single capacity limit in one AWS availability zone in Frankfurt took the UK National Lottery, Hugging Face and university coursework platforms offline for three and a half hours, without a single attacker involved. Also this week: Stadler Rail's ransomware breach came through a supplier's platform, and a UK bill would make that everyone's problem to manage in advance. Two SonicWall flaws became one breach, and the cloud giants come under new watch Two chained SonicWall SMA1000 zero-days show why a gateway mixing a public interface with a privileged console is one bug from full compromise, just as UK financial regulators start directly overseeing AWS, Google, Microsoft and Oracle. Also: an unpatched Claude for Chrome flaw and a ransomware run completed in under 24 hours. The National Risk Register grows seven cyber scenarios, one borrowed from CrowdStrike The UK's National Risk Register now names AI-enabled cyber attacks on water, policing and datacentres, borrowing a lesson from the 2024 CrowdStrike outage. Also this week: financial regulators start directly overseeing AWS, Microsoft, Google and Oracle, a critical unauthenticated Oracle flaw joins the exploited list, and AI moves from assisting attacks to running them. A trusted GitHub workflow, and the three million downloads it poisoned A GitHub Actions misconfiguration let an attacker backdoor npm packages downloaded three million times a week, no zero-day required. Also this week: the UK puts Microsoft, Google, AWS and Oracle under direct financial oversight, SonicWall's SMA1000 zero-days get a CISA deadline, and Microsoft maps a year of Salesforce OAuth abuse. The AD FS zero-day hiding inside a record Patch Tuesday Microsoft's biggest-ever Patch Tuesday fixed two zero-days already under attack, and the one in AD FS matters more than the one in SharePoint. Also: an unconfirmed ransomware claim against Arm, the Bank of England's new oversight of AWS, Azure, Google Cloud and Oracle, and the UK's under-16s social media law. The quiet shift to sovereign hosting Why more organisations are moving critical systems off the hyperscalers and away from a single Microsoft dependency, and what sovereign actually has to mean.