Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business 0 followers
Follow
Social Engineering, Trojanised Tools, and Supply Chain Attacks

Social Engineering, Trojanised Tools, and Supply Chain Attacks

Jul 16, 2026 • 16min 49s

Episode description

Social Engineering, Trojanised Tools, and Supply Chain Attacks

This episode examines three contemporary threats exploiting trusted channels. Following the sentencing of two Scattered Spider members for the Transport for London breach, we analyse why social engineering remains devastatingly effective against organisations of all sizes. We then review a Russian campaign distributing trojanised WebEx and Zoom installers delivering Starland RAT, demonstrating how legitimate software becomes an attack vector. Finally, we cover the AsyncAPI npm supply chain compromise, where GitHub Actions vulnerabilities enabled injection of Miasma v3 worm into packages with valid provenance attestations. The common thread: attackers succeed not through technical brilliance, but by exploiting routine trust in familiar processes. We provide actionable guidance on helpdesk authentication procedures, software download verification, and dependency chain auditing. Additional coverage includes CISA’s Oracle E-Business Suite KEV listing and the approaching Windows 10 end-of-support deadline. Presented by Mauven MacLeod with behavioural analysis and concrete defensive measures for UK small businesses.

Chapters

  • Introduction Opening remarks establishing the episode’s central theme: trusted channels being weaponised through social engineering, trojanised software, and compromised dependencies.
  • Scattered Spider Sentencing Analysis of two British Scattered Spider members receiving five-and-a-half-year sentences for the Transport for London breach, focusing on the social engineering techniques used and practical implications for SMB helpdesk procedures.
  • Call to Action Audience engagement request encouraging listeners to follow the show and share with business owners.
  • Trojanised WebEx and Zoom Examination of Russian actor UAT-11795 distributing backdoored collaboration software installers through phishing and search poisoning, delivering Starland RAT with credential theft and cryptocurrency targeting capabilities.
  • AsyncAPI npm Supply Chain Compromise Technical breakdown of the AsyncAPI organisation compromise via GitHub Actions vulnerability, resulting in Miasma v3 worm delivery through four npm packages with valid provenance attestations and novel execution timing.
  • Also on the Radar Brief coverage of CISA’s Oracle E-Business Suite KEV addition and the approaching Windows 10 end-of-support deadline for Home and Pro editions.
  • Closing Remarks Summary emphasising verification over assumption, with specific guidance on questioning helpdesk authentication procedures.

Links

  • https://www.ncsc.gov.uk/
  • https://www.microsoft.com/security/
  • https://jfrog.com/
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://zoom.com
  • https://webex.com
Comments0 Activity1 Chapters0 Transcript–
Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business @ThreatAnalysis Jul 16, 2026
16:49 Social Engineering, Trojanised Tools, and Supply Chain Attacks
Jul 16, 2026
Social Engineering, Trojanised Tools, and Supply Chain Attacks
0 0 0
RSS Podcast feed
HomeLinksCreditsMap

Powered by Castopod

Persons