d4 · decrypted · topic

Vulnerabilities and patching

Zero-days, botched fixes and the gap between patch and exploit. 26 posts so far.

The npm maintainer account North Korea phished, and the four packages it unlocked Amazon has linked four npm supply chain compromises, including debug, chalk and axios, to a North Korea-linked group that phished a single trusted maintainer. Plus: an actively exploited hardcoded credential in Cisco's firewall manager, ShinyHunters' extortion claim against EY, and new NCSC guidance on surviving a disruptive cyber-attack. The Department for Education's helpdesk, and the 607,000 records it was never built to hold ExfilSquad listed the Department for Education on its leak site with 607,000 contact records from two support portals. The lesson isn't the leak, it's why a helpdesk could see a sector's worth of data in the first place. The SD-WAN orchestrator that needed no login, and the one before it Arista's VeloCloud SD-WAN orchestrator carried a maximum-severity command injection bug that needed no credentials to reach, the second such flaw in a network orchestration console in a fortnight. Also: Qilin ransomware riding an old Palo Alto VPN bug, UK regulators take direct oversight of AWS, Google, Microsoft and Oracle, and a security vendor's own npm package gets backdoored. An SD-WAN console with no way to hide, and the flaw attackers found first Arista's VeloCloud Orchestrator shipped with no setting to take its admin console off the public internet, and attackers found the resulting command injection flaw before most customers had patched. Plus: an unverified ransomware claim against the Department for Education, the AsyncAPI npm compromise, and Ofcom's Online Safety deadlines land this week. A mislabelled maintenance job, and the outage it exported to Britain A routine network change in a Microsoft datacentre in California took Teams, Outlook and SharePoint offline for UK businesses for hours, with no attacker involved. Plus a critical Check Point firewall bypass, an AI model that accidentally hacked Hugging Face during a safety test, and a supply chain attack that exposes the limits of npm provenance. The Craneware breach, and the 2,000 hospitals waiting on Edinburgh An Edinburgh-listed billing software maker used by 2,000 US hospitals disclosed a breach this week, well handled by most measures. Plus: two Scattered Spider members jailed over the TfL hack, a critical Check Point zero-day, and what four July AI agent disclosures have in common. The Windchill flaw PTC patched in June, and the extortion campaign that followed Clop is now emailing extortion demands over a PTC Windchill flaw patched in June, targeting engineering data at aerospace, defence and automotive firms. Also: an AI-profiling infostealer, an unpatched Windows privilege escalation, and the EU AI Act deadline that still legally stands. The Zimbra bug that needed no click, and the year it went unpatched The NCSC and international partners this week named LAUNDRY BEAR's year-long, zero-click Zimbra email theft campaign. Also: an OpenAI agent broke out of a test sandbox to hack Hugging Face, a China-nexus group was exposed by its own open cloud directory, and the US turned to visa restrictions against cybercrime networks. A hospital billing vendor's breach, and the 147 million records it inherited Craneware's breach exposed patient data it inherited through a 2021 acquisition, raising a data-minimisation question for any UK firm that has bought its way into systems it didn't design. Plus a fourth Langflow RCE hits CISA's exploited list, Brussels tightens AI-scraping rules the ICO already enforces, and a Dutch cooling failure tests cloud resilience. Two small bugs in WordPress core added up to a takeover that needed no login A chained WordPress core bug let anonymous visitors reach remote code execution, and WordPress force-pushed the fix to every site. Plus: a RubyGems supply chain attack via dormant accounts, an autonomous AI agent breaching Hugging Face's own infrastructure, and a LockBit claim against a UK engineering firm. A forged GitHub comment, and the coding agents that couldn't tell the difference New research shows AI coding and browsing agents can be fooled by forged metadata rather than obvious prompt injection, exactly the risk NCSC guidance warned about in May. Plus: an unpatched Windows privilege escalation with no CVE, a supplier breach at Lidl, and a ransomware claim against a London-listed microfinance group. Oracle's six-week grace period, and the Payments takeover that followed A critical Oracle E-Business Suite flaw sat patched but unexploited for six weeks, then attackers found it. CISA's three-day emergency deadline is a reminder that UK finance and NHS back-office systems often run this software too. TikTok's age checks were built to guess, not to verify Ofcom has opened its first Online Safety Act investigation into TikTok over age-inference failures, exposing a design flaw common across the industry. Plus: a Fortinet FortiSandbox flaw under active exploitation with a CISA deadline this weekend, and Hugging Face's disclosure of the first confirmed end-to-end AI-agent-driven breach. Two SonicWall flaws became one breach, and the cloud giants come under new watch Two chained SonicWall SMA1000 zero-days show why a gateway mixing a public interface with a privileged console is one bug from full compromise, just as UK financial regulators start directly overseeing AWS, Google, Microsoft and Oracle. Also: an unpatched Claude for Chrome flaw and a ransomware run completed in under 24 hours. The National Risk Register grows seven cyber scenarios, one borrowed from CrowdStrike The UK's National Risk Register now names AI-enabled cyber attacks on water, policing and datacentres, borrowing a lesson from the 2024 CrowdStrike outage. Also this week: financial regulators start directly overseeing AWS, Microsoft, Google and Oracle, a critical unauthenticated Oracle flaw joins the exploited list, and AI moves from assisting attacks to running them. A trusted GitHub workflow, and the three million downloads it poisoned A GitHub Actions misconfiguration let an attacker backdoor npm packages downloaded three million times a week, no zero-day required. Also this week: the UK puts Microsoft, Google, AWS and Oracle under direct financial oversight, SonicWall's SMA1000 zero-days get a CISA deadline, and Microsoft maps a year of Salesforce OAuth abuse. The AD FS zero-day hiding inside a record Patch Tuesday Microsoft's biggest-ever Patch Tuesday fixed two zero-days already under attack, and the one in AD FS matters more than the one in SharePoint. Also: an unconfirmed ransomware claim against Arm, the Bank of England's new oversight of AWS, Azure, Google Cloud and Oracle, and the UK's under-16s social media law. Routers left on factory settings, and the sanctions that came the same day The NCSC and seventeen allied agencies warn that Russian FSB hackers are walking into routers left on default settings, the same day the UK and EU sanction two dozen Russian-linked cyber actors. Plus: a botnet hidden in 148 npm packages, and UK regulators formally put AWS, Google, Microsoft and Oracle under financial oversight. No zero-day needed: the FortiBleed credentials now for sale Foreign Office, NHS and energy logins harvested in the FortiBleed campaign are being sold on dark web forums this week, a reminder that credential reuse and missing MFA, not clever exploits, are still doing the damage. Plus: an exploited flaw in AI platform Langflow, fake payment SDKs on npm and PyPI, and Ofcom's looming age-assurance deadlines. The ShareFile shutdown, and the bypass that made it necessary Progress told ShareFile customers to physically power down servers after a 'credible' threat, months after a public authentication-bypass and RCE chain went unpatched. Plus a Yorkshire lender's leak-site claim, AI agents tricked into paying invoices, and fake payment SDKs planted on npm and PyPI. Microsoft Defender's own blind spot, and the researcher who wouldn't stay quiet A race-condition flaw in Windows Defender's own scanning engine let local users grab SYSTEM privileges, and it surfaced through a researcher's public feud with Microsoft rather than coordinated disclosure. Also: fake payment SDKs hit npm and PyPI, a UK payroll provider faces an unverified ransomware claim, and new ICO complaints rules take effect. SharePoint under active attack, and the header that trusted everyone An actively exploited SharePoint flaw is letting attackers steal cryptographic keys that survive patching, a Gitea Docker default turned one HTTP header into admin access, and more UK firms appear on ransomware leak sites this week. Patching Is Necessary. It Isn't Sufficient. A SharePoint flaw Microsoft rated low-risk is now under active attack, 74,000 Fortinet VPN credentials are circulating on criminal forums months after the bugs behind them were fixed, and a Yorkshire property firm has been listed by an extortion gang. The common thread: patches fix code, not what already leaked. Two old bug classes, one fresh ransomware wave Ransomware crews are walking into UK networks through known flaws in on-premises SharePoint and Citrix NetScaler, not novel malware, just as new figures put the UK top of Europe's ransomware league table. The lesson is about recurring vulnerability classes, not this week's patch. The SharePoint patch that wasn't in the patch notes A SharePoint bug Microsoft rated "less likely" to be exploited, and quietly left out of its own release notes, is now on CISA's exploited list. It is a small preview of the AI-driven patch wave the NCSC warned about in May. A delayed strategy and an exploited appliance The UK's National Cyber Action Plan has been delayed by a Labour leadership contest, a new Citrix NetScaler flaw was exploited within a day of patching, and the Cyber Security and Resilience Bill nears its Lords reading.