d4 · decrypted · topic

UK policy and law

NCSC guidance, sanctions, regulation and the UK security agenda. 10 posts so far.

An SD-WAN console with no way to hide, and the flaw attackers found first Arista's VeloCloud Orchestrator shipped with no setting to take its admin console off the public internet, and attackers found the resulting command injection flaw before most customers had patched. Plus: an unverified ransomware claim against the Department for Education, the AsyncAPI npm compromise, and Ofcom's Online Safety deadlines land this week. The Craneware breach, and the 2,000 hospitals waiting on Edinburgh An Edinburgh-listed billing software maker used by 2,000 US hospitals disclosed a breach this week, well handled by most measures. Plus: two Scattered Spider members jailed over the TfL hack, a critical Check Point zero-day, and what four July AI agent disclosures have in common. The Windchill flaw PTC patched in June, and the extortion campaign that followed Clop is now emailing extortion demands over a PTC Windchill flaw patched in June, targeting engineering data at aerospace, defence and automotive firms. Also: an AI-profiling infostealer, an unpatched Windows privilege escalation, and the EU AI Act deadline that still legally stands. The fake Claude app that lived on claude.ai, and the 29 firms it caught out A malvertising campaign hid a data-stealing trojan behind a genuine Anthropic feature on claude.ai itself, hitting 29 organisations. Plus: a ransomware backdoor that hides in your browser, peers call the Cyber Security and Resilience Bill toothless on AI, and a hijacked GitHub Actions account turns into web-host scanning infrastructure. A capacity limit in Frankfurt, and the National Lottery it took offline A single capacity limit in one AWS availability zone in Frankfurt took the UK National Lottery, Hugging Face and university coursework platforms offline for three and a half hours, without a single attacker involved. Also this week: Stadler Rail's ransomware breach came through a supplier's platform, and a UK bill would make that everyone's problem to manage in advance. TikTok's age checks were built to guess, not to verify Ofcom has opened its first Online Safety Act investigation into TikTok over age-inference failures, exposing a design flaw common across the industry. Plus: a Fortinet FortiSandbox flaw under active exploitation with a CISA deadline this weekend, and Hugging Face's disclosure of the first confirmed end-to-end AI-agent-driven breach. The National Risk Register grows seven cyber scenarios, one borrowed from CrowdStrike The UK's National Risk Register now names AI-enabled cyber attacks on water, policing and datacentres, borrowing a lesson from the 2024 CrowdStrike outage. Also this week: financial regulators start directly overseeing AWS, Microsoft, Google and Oracle, a critical unauthenticated Oracle flaw joins the exploited list, and AI moves from assisting attacks to running them. Routers left on factory settings, and the sanctions that came the same day The NCSC and seventeen allied agencies warn that Russian FSB hackers are walking into routers left on default settings, the same day the UK and EU sanction two dozen Russian-linked cyber actors. Plus: a botnet hidden in 148 npm packages, and UK regulators formally put AWS, Google, Microsoft and Oracle under financial oversight. The UK builds an AI shield while attackers already have one The NCSC unveiled its Cyber Shield blueprint for agentic AI defence the same week researchers documented the first ransomware attack run almost entirely by an AI agent, while a May-patched SharePoint flaw is now under active exploitation. A delayed strategy and an exploited appliance The UK's National Cyber Action Plan has been delayed by a Labour leadership contest, a new Citrix NetScaler flaw was exploited within a day of patching, and the Cyber Security and Resilience Bill nears its Lords reading.