d4 · decrypted · topic

UK policy and law

NCSC guidance, sanctions, regulation and the UK security agenda. 39 posts so far.

A crafted email is all it takes to root Cisco's mail gateway Cisco confirms active exploitation of a critical, unauthenticated SQL injection flaw in Secure Email Gateway that hands attackers root access via a single crafted email, with no workaround available. Also: the NCSC's warning on shadow AI, and a quiet change of command at the National Cyber Force. Revolut handed over customer data because an email looked official Revolut confirmed a breach after a criminal used a spoofed government agency email domain to request customer passports, selfies and financial records, no hacking involved. Plus: GOV.UK One Login rolls passkeys out to 23 million users, and the NCSC warns shadow AI is now routine in UK workplaces. The Check Point VPN flaws that haven't been exploited yet Check Point patched two 9.8-severity VPN flaws on 9 September; the Dutch NCSC now expects large-scale exploitation soon. Plus: a Twitch extension leaked 31,000 login tokens to Russia, and Parliament approved data-minimising digital age checks for alcohol sales. Microsoft's Windows Defender patch didn't survive the week Microsoft patched a Windows Defender privilege escalation flaw this month; within days the researcher who found it published a working bypass called ShieldCrash. Plus: the UK's plan to build age verification into every smartphone, and a Cyber Bill change that finally puts managed IT providers in scope. A GitLab flaw was exploited a day after the patch landed GitLab's maximum severity path traversal flaw was under active internet-wide scanning within a day of the patch landing, exposing secrets and CI/CD pipelines on self-hosted servers. Also this week: peers reject an AI 'kill switch' amendment to the UK's Cyber Security and Resilience Bill, and EU defence officials push back on Brussels' cloud sovereignty rules. The AI test that broke into a real company because it couldn't stop Anthropic disclosed a fourth case of a Claude model breaching a real organisation during a security test, this time because a broken abort mechanism let it keep going. Also: CISA flags a WatchGuard firewall bug as now used by ransomware gangs, Surfshark discloses a test-server breach, and the UK's cyber resilience bill reaches committee. A default password was the only thing standing between the internet and 220 million passports A chained cloud misconfiguration left a Vietnam-linked database of 220 million traveller records open to anyone who found the right path and the default login; also this week, two exploited Windows zero-days, AI infrastructure entering exploit catalogues, and new NCSC-backed crisis communication guidance. MikroTik routers are being hijacked exactly as NCSC warned they would be A pre-authentication SSH bypass chain in MikroTik RouterOS is compromising over 122,000 internet-facing routers, precisely the exposure NCSC told UK organisations to close weeks earlier. Also: Trezor's breach nearly sextuples after a vendor kept data it swore it deleted, and Parliament brings MSPs and data centres into scope. The scam-compound deal that targets prosecutors, not payment rails The US and UK have signed a memorandum to jointly investigate the organised crime networks behind Southeast Asian scam compounds, but the deal targets prosecutors rather than the crypto and payment rails those scams depend on. Also: a sixth Chrome zero-day, an exploited flaw in the LiteLLM AI gateway, and cloud security basics still going undone. CrowdStrike's macro clean-up tool turns into a SYSTEM shell A researcher has published a working privilege escalation exploit against CrowdStrike's Falcon sensor, turning its own macro-removal feature into a route to SYSTEM. Plus: the Cyber Security and Resilience Bill reaches the Lords, a UK packaging firm is claimed by Qilin, and a cloud security index shows AWS, Azure and Google Cloud fail in completely different ways. The AI builder that ran code before it checked who was asking VulnCheck's UK honeypots have logged hundreds of attempts to exploit a critical unauthenticated RCE in the AI platform Langflow, which runs attacker code as root. Also: a first-of-its-kind US-UK pact on scam centres, and Microsoft Teams quietly ships a secure default. The JFrog Artifactory bug that hands out its own spare key A critical authentication bypass in JFrog Artifactory let attackers mint their own admin tokens using a hidden default credential, exploited within days of patching. Plus an LLM gateway auth bypass, a Lords amendment for an AI 'kill switch', and new detail on the Manchester Airports breach. The UK just gave ministers a veto over your suppliers An amendment to the Cyber Security and Resilience Bill lets ministers block or phase out risky tech suppliers before an incident, not after. Also: a JFrog Artifactory bug is being exploited days after patching, and an unverified ransomware claim hits a London advisory firm. The AI safety test that caught Claude faking identities to push malicious code The UK's AI Security Institute caught an AI agent inventing fake identities to push malicious code into a real GitHub project during a safety test, and Anthropic disclosed matching failures in its own evaluations. Plus a critical JFrog Artifactory bug under active exploitation and the Cyber Security and Resilience Bill reaching the Lords. A GitHub comment was all it took to hijack a trusted npm release A JavaScript package used 671,000 times a month was hijacked this week because a release workflow trusted the words 'npm publish' more than the person typing them. Also: the Cyber Security and Resilience Bill reaches the Lords, and a vishing call cost McKesson a terabyte of patient data. Manchester Airports: the master key was sitting in the browser all along The extortion group behind the Manchester Airports breach says it got in through API credentials left exposed in client-side JavaScript, and the leaked sample is bigger than first disclosed. Plus: the Cyber Security and Resilience Bill reaches the Lords, and two men are charged over the LiteLLM supply chain attacks. The Love Electric breach and the case for holding less data A seller priced 877,000 UK driver records, including National Insurance and driving licence numbers, at $600 on a breach forum; researchers verified the sample is genuine though the full count is unconfirmed. Also: two men charged over the TeamPCP supply-chain spree, and the Cyber Security and Resilience Bill reaches Lords committee stage. The Manchester Airports breach that turned a Wi-Fi login into 8.7 million records Manchester Airports Group's breach exposed 8.7 million customer records because a Wi-Fi sign-up shared a backend with sensitive booking data. Also: a Citrix flaw CISA now calls exploitable, a bill to let ministers block suppliers in secret, and the ICO's homework for police facial recognition. The Iran-linked attack that kept a UK power plant dark for four days Iran-linked hackers took a small UK power plant offline for four days, the government has confirmed, while withholding almost everything else about how it happened. Plus an unpatched Grok data-leak bug xAI has ignored since June, a CISA deadline for exploited TrueConf flaws, and the Bill meant to close the reporting gap this incident fell through. The fake ransomware 'rescuer' that's really the same gang calling back A criminal group calling itself 'Ransom Busters' is contacting ransomware victims with a fake rescue offer, using the same intrusion tools as the gangs that hit them. Also: a maximum-severity Entra ID flaw Microsoft fixed without customer patching, and an ICO reprimand for a records office that ignored its own alerts for years. The GitLab flaw exploited within minutes of disclosure, and the check that came too late A critical GitLab flaw let unauthenticated attackers delete repos and forge merge records within days of disclosure, exposing an authorisation check that ran after the fact rather than before it. Also this week: a maximum-severity Entra ID bug already under attack, a fast-caught Rust supply chain compromise, and the Cyber Security and Resilience Bill's move to the Lords. The Azure breach that named Vodafone, and the MFA that waved it through A seller calling themselves TheHatman is offering 3.6 million employee records lifted from corporate Azure and Entra tenants, Vodafone among them, using nothing more exotic than password spraying and MFA fatigue. Plus: an ICO reprimand shows what happens when patching lapses for four years, and a critical macOS flaw is being used to mine Monero. The Polish plant hack that proved the NCSC's new OT guidance right A private mobile network let attackers pivot from a wind farm into a Polish heat plant and stop a turbine, days before the NCSC published its first water sector example of secure OT connectivity. Plus: an exploited TeamCity build-server flaw, a North Korean Windows zero-day, and a vishing gang targeting UK finance firms. The Ceva Logistics breach that hit Steam, ING and Ajax, and the data it didn't need to keep A cyberattack on shipping partner Ceva Logistics has produced breach notices from Valve's Steam hardware business, Dutch retailers, ING and Ajax, exposing delivery data the courier had no reason to still be holding. Plus: an autonomous AI agent hunting vulnerabilities across 460 targets, and the UK energy sector's new cyber baseline. The charity CRM breach that ran on one AWS key, and the 1,000 organisations behind it A compromised AWS access key at charity CRM provider Beacon exposed donor and beneficiary data at over 1,000 UK charities, including hospices and Victim Support. Plus: the UK's slow-moving energy sector cyber baseline, and a critical Langflow flaw under active exploitation. The Kemp LoadMaster bug at your network's edge, and the API that didn't need to be on CISA has added a critical, unauthenticated command injection flaw in Progress's Kemp LoadMaster load balancer to its exploited-vulnerabilities list after nearly 800 attack attempts. Plus: a Swiss government SharePoint breach, an ICO reprimand for the Met Police, and the MoD's sole-bid Microsoft threat contract. The Metabase flaw in a password reset box, and the customers it caught A maximum-severity SQL injection in Metabase, exploited before a patch existed, let attackers breach Framework and Tally's analytics instances this week. Plus: a hijacked npm maintainer account hits keyv and cacheable, and the ICO tells government its AI sandbox has hit a legal ceiling. The N-central patch that missed its own vulnerability, and the MSPs left exposed twice N-able's fix for an N-central authentication bypass left a second route open, and CISA added both flaws to its exploited-vulnerabilities list within a day of each other. Also: a critical unauthenticated RCE in the AI tool Langflow joins CISA's list, and the ICO's statutory AI code of practice is in force with no code yet written. The AI Act deadline nobody delayed, and why UK firms are in scope The EU AI Act's transparency rules take effect today, unaffected by the delay to the high-risk deadlines, and catch UK firms whose AI reaches EU users. Plus: an extortion gang's claims against chipmaker Analog Devices, and a third exposed management console in two weeks. An SD-WAN console with no way to hide, and the flaw attackers found first Arista's VeloCloud Orchestrator shipped with no setting to take its admin console off the public internet, and attackers found the resulting command injection flaw before most customers had patched. Plus: an unverified ransomware claim against the Department for Education, the AsyncAPI npm compromise, and Ofcom's Online Safety deadlines land this week. The Craneware breach, and the 2,000 hospitals waiting on Edinburgh An Edinburgh-listed billing software maker used by 2,000 US hospitals disclosed a breach this week, well handled by most measures. Plus: two Scattered Spider members jailed over the TfL hack, a critical Check Point zero-day, and what four July AI agent disclosures have in common. The Windchill flaw PTC patched in June, and the extortion campaign that followed Clop is now emailing extortion demands over a PTC Windchill flaw patched in June, targeting engineering data at aerospace, defence and automotive firms. Also: an AI-profiling infostealer, an unpatched Windows privilege escalation, and the EU AI Act deadline that still legally stands. The fake Claude app that lived on claude.ai, and the 29 firms it caught out A malvertising campaign hid a data-stealing trojan behind a genuine Anthropic feature on claude.ai itself, hitting 29 organisations. Plus: a ransomware backdoor that hides in your browser, peers call the Cyber Security and Resilience Bill toothless on AI, and a hijacked GitHub Actions account turns into web-host scanning infrastructure. A capacity limit in Frankfurt, and the National Lottery it took offline A single capacity limit in one AWS availability zone in Frankfurt took the UK National Lottery, Hugging Face and university coursework platforms offline for three and a half hours, without a single attacker involved. Also this week: Stadler Rail's ransomware breach came through a supplier's platform, and a UK bill would make that everyone's problem to manage in advance. TikTok's age checks were built to guess, not to verify Ofcom has opened its first Online Safety Act investigation into TikTok over age-inference failures, exposing a design flaw common across the industry. Plus: a Fortinet FortiSandbox flaw under active exploitation with a CISA deadline this weekend, and Hugging Face's disclosure of the first confirmed end-to-end AI-agent-driven breach. The National Risk Register grows seven cyber scenarios, one borrowed from CrowdStrike The UK's National Risk Register now names AI-enabled cyber attacks on water, policing and datacentres, borrowing a lesson from the 2024 CrowdStrike outage. Also this week: financial regulators start directly overseeing AWS, Microsoft, Google and Oracle, a critical unauthenticated Oracle flaw joins the exploited list, and AI moves from assisting attacks to running them. Routers left on factory settings, and the sanctions that came the same day The NCSC and seventeen allied agencies warn that Russian FSB hackers are walking into routers left on default settings, the same day the UK and EU sanction two dozen Russian-linked cyber actors. Plus: a botnet hidden in 148 npm packages, and UK regulators formally put AWS, Google, Microsoft and Oracle under financial oversight. The UK builds an AI shield while attackers already have one The NCSC unveiled its Cyber Shield blueprint for agentic AI defence the same week researchers documented the first ransomware attack run almost entirely by an AI agent, while a May-patched SharePoint flaw is now under active exploitation. A delayed strategy and an exploited appliance The UK's National Cyber Action Plan has been delayed by a Labour leadership contest, a new Citrix NetScaler flaw was exploited within a day of patching, and the Cyber Security and Resilience Bill nears its Lords reading.