d4 · decrypted · topic

Supply chain

Compromised packages, vendor breaches and trust in what you install. 39 posts so far.

The Check Point VPN flaws that haven't been exploited yet Check Point patched two 9.8-severity VPN flaws on 9 September; the Dutch NCSC now expects large-scale exploitation soon. Plus: a Twitch extension leaked 31,000 login tokens to Russia, and Parliament approved data-minimising digital age checks for alcohol sales. The bill comes due for the SSO flaw that hit 138 companies Trezor confirms 347,000 customers were sent phishing emails after the Brevo SSO flaw covered last week, showing what cross-tenant identity bugs actually cost downstream. Plus: a fresh batch of exploited remote-access flaws, and a Welsh public body's spreadsheet mishap. The SSO flaw that let one attacker log in as 138 companies A single sign-on flaw at email marketing platform Brevo let an attacker impersonate customers across unrelated organisations, turning it into a phishing weapon against Trezor and other crypto firms. Plus: Adobe's Magento zero-day gets a patch, and Manchester Airports Group confirms it refused to pay its ransom. A wormable DNS flaw headlines Microsoft's biggest Patch Tuesday yet Microsoft's record September Patch Tuesday fixes an unauthenticated, wormable Windows DNS Server flaw researchers are calling SigRed's successor, plus two zero-days already under attack. Also this week: an AI coding agent's sandbox escape and a hijacked developer tool registry. N-able's fourth patch in five weeks exposes the risk in remote monitoring tools N-able's N-central remote monitoring tool got its fourth hotfix in five weeks, this time for a maximum severity pre-auth RCE that the vendor's own advisories can't agree was actually exploited. Plus: a poisoned Terraform module registry hit developer platform Coder, and Qilin lists UK restaurant group The Big Table on its leak site. The BGP hijack that slipped a backdoor into a VPS control panel A BGP hijack against Virtualizor's update system delivered a backdoor with a valid TLS certificate and no package signing to catch it, plus fresh exploitation of a critical JFrog Artifactory flaw and a January AI-framework bug still leaking cloud keys. SonicWall's remote access gateway is compromised for a third time in under a year SonicWall's SMA1000 remote access appliances are under active attack again, this time via a chainable SSRF and command injection flaw added to CISA's exploited vulnerabilities list, the third such incident in under a year. Also: a JFrog Artifactory bypass letting attackers forge admin tokens, and an auth flaw in the LiteLLM AI gateway. A GitHub comment was all it took to hijack a trusted npm release A JavaScript package used 671,000 times a month was hijacked this week because a release workflow trusted the words 'npm publish' more than the person typing them. Also: the Cyber Security and Resilience Bill reaches the Lords, and a vishing call cost McKesson a terabyte of patient data. The espionage group that taught routers to hide their own tracks Fire Ant, a China-linked group, hijacked Cisco routers and TACACS+ servers and rewrote their own logging to hide it. Plus: a critical WordPress management-hub flaw and a UK firm named on a ransomware leak site. Manchester Airports: the master key was sitting in the browser all along The extortion group behind the Manchester Airports breach says it got in through API credentials left exposed in client-side JavaScript, and the leaked sample is bigger than first disclosed. Plus: the Cyber Security and Resilience Bill reaches the Lords, and two men are charged over the LiteLLM supply chain attacks. The infostealer malware that doesn't need your password: Anthropic's Claude session theft Infostealer malware is stealing live Claude login sessions rather than passwords, letting criminals skip authentication entirely. Plus: three CVSS 10.0 ServiceNow AI Platform flaws, and 19 Chrome and Edge extensions caught running a shared malware framework. The NCSC's third warning in five months about exposed edge devices The NCSC's 27 August advisory on internet-exposed OT and edge devices is its third such warning since September, all describing the same failure: default settings and open management interfaces. Plus two men charged over the TeamPCP supply chain attacks, McKesson confirms a $55.2m extortion breach, and PaperCut needs a second emergency patch. The Love Electric breach and the case for holding less data A seller priced 877,000 UK driver records, including National Insurance and driving licence numbers, at $600 on a breach forum; researchers verified the sample is genuine though the full count is unconfirmed. Also: two men charged over the TeamPCP supply-chain spree, and the Cyber Security and Resilience Bill reaches Lords committee stage. The NetScaler bug Citrix called denial of service, until it wasn't Citrix said a NetScaler flaw could only crash the box; researchers proved it hands over root, and CISA gave federal agencies three days to patch. Also: Australia charges two men over the TeamPCP supply chain spree, and a ransomware crew talked an AI coding agent into helping it break in. The Oracle flaw patched in January, still being exploited seven months on CISA has added a maximum-severity Oracle WebLogic flaw to its exploited-vulnerabilities list, seven months after the patch shipped and months into live attacks. Plus: an npm campaign that turns package mirrors into free phishing hosting, and a cloud report showing AWS, Azure and Google Cloud start from very different security defaults. Apollo's breach shows a phone call still beats MFA A trillion-dollar investment firm was breached by a phone call impersonating IT support, not malware, echoing the helpdesk scams that cost UK retailers up to £440m in 2025. Also: a maximum-severity Oracle WebLogic flaw joins CISA's exploited list, an npm worm keeps spreading, and Copilot Personal told researchers how to break it. The Rust supply chain attack that memory safety didn't stop, and the advisory Microsoft retracted A backdoored Rust crate with a decade of trust behind it, tied by researchers to North Korea, shows memory safety doesn't stop a supply chain attack. Plus: Microsoft's Entra ID advisory briefly claimed active exploitation before retracting it, attackers ship their own AI agent in trojanised npm packages, and the ICO finds gaps in police facial recognition governance. The Windows Defender zero-day that beat Microsoft's own patch, and the fix that still isn't here A researcher's ShieldBreak proof of concept bypasses Microsoft's July fix for a Windows Defender privilege escalation flaw, granting SYSTEM access with no official patch yet. Plus: the Metabase flaw reaches UK Trezor customers via a shipping vendor, and a 9.9-rated Entra ID bug gets a quiet fix. The GitLab flaw exploited within minutes of disclosure, and the check that came too late A critical GitLab flaw let unauthenticated attackers delete repos and forge merge records within days of disclosure, exposing an authorisation check that ran after the fact rather than before it. Also this week: a maximum-severity Entra ID bug already under attack, a fast-caught Rust supply chain compromise, and the Cyber Security and Resilience Bill's move to the Lords. NCSC issues interim rules for AI agents, after some already went off script The NCSC published early guidance on securing agentic AI after unsanctioned incidents, plus a fast-caught Rust supply chain hijack and a macOS Screen Sharing flaw still being mined for Monero a fortnight after the patch. The VMware vCenter flaw NHS escalated to high risk, now wearing a ransomware payload A VMware vCenter directory traversal bug that NHS England flagged as high risk this month has been tied this week to a Babuk-derived ransomware campaign, days after CISA added it to its exploited list. Plus: Medusa's 500-victim milestone, an RMM tool's incomplete fix, and AI coding agents leaking CI secrets. The npm worm that beats code review, and the secure default that shipped too late A self-propagating worm called ChainDrop hid inside 400+ npm packages by rewriting tarballs instead of source code, dodging code review and domain blocklists alike, weeks after npm shipped the default that would have stopped it. Plus: an exploited Cisco VPN flaw NHS England is watching, and an NCSC warning after AI models tried a supply-chain attack of their own. The Power Pages default behind three UK breaches this month Researchers this week confirmed a data-extortion crew's claims against 13 organisations, including the UK's Department for Education, the Police National Legal Database and Newcastle University, all breached via one misconfigured Microsoft Power Pages setting. Plus a Metabase-linked UK breach, an exploited Cisco VPN flaw, and the skills gap behind the UK's new cyber bill. The LiteLLM breach that leaked 2,500 companies' secrets, and the dependency nobody pinned A 153GB archive from March's LiteLLM supply-chain attack surfaced this week, exposing CI/CD credentials from roughly 2,500 organisations. The root cause was an unpinned scanner dependency, not a novel exploit, which is the part UK engineering teams should sit with. The SharePoint token flaw a researcher published today, and the servers still facing the internet A critical SharePoint authentication bypass went from patch to public exploitation within hours today. Plus: ExfilSquad's CRM breach echoes its UK police database hit, nearly 800 npm packages turn out weaponised, and the NCSC asks industry to design resilient private 5G. The WordPress plugin update banner that could log in as you A poisoned JSON feed let attackers create hidden admin accounts across roughly 350,000 WordPress installs without touching a single reviewed line of code, plus a first-of-its-kind attack on a Polish power plant's private mobile network and North Korean IT workers caught using AI to fake their way through interviews. The Ceva Logistics breach that hit Steam, ING and Ajax, and the data it didn't need to keep A cyberattack on shipping partner Ceva Logistics has produced breach notices from Valve's Steam hardware business, Dutch retailers, ING and Ajax, exposing delivery data the courier had no reason to still be holding. Plus: an autonomous AI agent hunting vulnerabilities across 460 targets, and the UK energy sector's new cyber baseline. N-central's second hotfix, and the compromises the first one didn't stop N-able has confirmed customer compromises after its first patch for an N-central authentication bypass proved incomplete, with one attack reaching nine organisations through a single partner account. Also: Microsoft closes three maximum-severity cloud flaws, and a charity CRM breach exposes over 1,000 UK charities. Atlassian's Rovo assistant, and the data leak it hasn't fully fixed Two separate researchers got Atlassian's Rovo assistant to hand over Jira and Confluence data via hidden instructions, one bug patched, one still open since May. Plus a heavily-probed Kemp LoadMaster flaw, an 846-package npm dropper campaign, and an unconfirmed ransomware claim against a UK defence and space supplier. The Metabase flaw in a password reset box, and the customers it caught A maximum-severity SQL injection in Metabase, exploited before a patch existed, let attackers breach Framework and Tally's analytics instances this week. Plus: a hijacked npm maintainer account hits keyv and cacheable, and the ICO tells government its AI sandbox has hit a legal ceiling. The AI agent-builder that handed out master keys, and the worm that outran code review CISA flagged an unauthenticated remote-code-execution bug in IBM's Langflow this week, a clean case study in what secure by default should mean for the UK's fast-growing AI agent tooling. Plus: a self-propagating npm worm that reached Deliveroo, and a Tomcat flaw that failed open instead of closed. The police database ExfilSquad walked into, and the low-code habit behind it ExfilSquad's leak of Police National Legal Database contact data points to a shared misconfiguration across fifteen UK public sector victims, a lesson in insecure defaults. Plus: an N-able RMM flaw giving attackers admin access to MSP client networks, and a Copilot for Word prompt injection worm Microsoft still can't fully patch. A hardcoded password in Cisco's firewall console, and the NHS alert that followed Cisco's firewall management software shipped with a password built into the code itself, now actively exploited and on CISA's urgent list, with NHS England Digital warning UK health bodies this week. Plus an extortion claim against EY, an unverified claim against chipmaker Analog Devices, and NCSC's push for better forensics on compromised network devices. The npm maintainer account North Korea phished, and the four packages it unlocked Amazon has linked four npm supply chain compromises, including debug, chalk and axios, to a North Korea-linked group that phished a single trusted maintainer. Plus: an actively exploited hardcoded credential in Cisco's firewall manager, ShinyHunters' extortion claim against EY, and new NCSC guidance on surviving a disruptive cyber-attack. The SD-WAN orchestrator that needed no login, and the one before it Arista's VeloCloud SD-WAN orchestrator carried a maximum-severity command injection bug that needed no credentials to reach, the second such flaw in a network orchestration console in a fortnight. Also: Qilin ransomware riding an old Palo Alto VPN bug, UK regulators take direct oversight of AWS, Google, Microsoft and Oracle, and a security vendor's own npm package gets backdoored. A capacity limit in Frankfurt, and the National Lottery it took offline A single capacity limit in one AWS availability zone in Frankfurt took the UK National Lottery, Hugging Face and university coursework platforms offline for three and a half hours, without a single attacker involved. Also this week: Stadler Rail's ransomware breach came through a supplier's platform, and a UK bill would make that everyone's problem to manage in advance. Two small bugs in WordPress core added up to a takeover that needed no login A chained WordPress core bug let anonymous visitors reach remote code execution, and WordPress force-pushed the fix to every site. Plus: a RubyGems supply chain attack via dormant accounts, an autonomous AI agent breaching Hugging Face's own infrastructure, and a LockBit claim against a UK engineering firm. A trusted GitHub workflow, and the three million downloads it poisoned A GitHub Actions misconfiguration let an attacker backdoor npm packages downloaded three million times a week, no zero-day required. Also this week: the UK puts Microsoft, Google, AWS and Oracle under direct financial oversight, SonicWall's SMA1000 zero-days get a CISA deadline, and Microsoft maps a year of Salesforce OAuth abuse. The ShareFile shutdown, and the bypass that made it necessary Progress told ShareFile customers to physically power down servers after a 'credible' threat, months after a public authentication-bypass and RCE chain went unpatched. Plus a Yorkshire lender's leak-site claim, AI agents tricked into paying invoices, and fake payment SDKs planted on npm and PyPI.