Navigating Critical VeloCloud Flaws and Rising Malware Tactics In today’s episode of ‘Threat Analysis’, we delve into a critical vulnerability affecting VeloCloud Orchestrator environments. With a CVSS score of ten, this flaw allows remote attackers to potentially gain full control over VCO hosts, posing significant risks to small and medium businesses. We explore why robust systems alone aren’t enough and the crucial steps to mitigate such threats. Next, we examine the stealthy operations of the OpenSUpdater malware, exploiting open-source software flexibility. This malware disguises itself within recompiled 7zip SFX stubs, evading traditional security measures and necessitating a shift in cybersecurity strategies. Additionally, we spotlight ClickFix, a growing threat leveraging social engineering tactics through clipboard poisoning. This episode underlines the importance of fostering a security-conscious culture within organisations to combat evolving cyber threats effectively. Join Mauven as we navigate these digital challenges, advocating for proactive vigilance and robust cybersecurity practices. Chapters Intro Introduction to today’s focus on digital vulnerabilities. Critical VeloCloud Vulnerability Exploration of the severe VeloCloud Orchestrator flaw and its implications. CTA Encouragement to subscribe and spread the word about Threat Analysis. OpenSUpdater Malware Tactics Discussion on how OpenSUpdater exploits open-source software vulnerabilities. The Verdict on ClickFix Insight into ClickFix’s effective social engineering strategies. Outro Conclusion emphasising the importance of cybersecurity vigilance. Links https://www.securityweek.com/velocloud-vulnerability https://threatpost.com/opensupdater-malware https://www.csoonline.com/social-engineering-tricks
TeamCity Ransomware, Roundcube Exploitation, and ClickFix Social Engineering CISA confirms ransomware gangs are actively exploiting a critical JetBrains TeamCity vulnerability patched in July, eleven weeks after the fix became available. UK SMBs face supply chain exposure through managed service providers and development partners with access to production environments. Meanwhile, the Canadian Centre for Cyber Security reports active exploitation of a four-month-old Roundcube Webmail code injection flaw that requires no user interaction beyond reading email. The ClickFix social engineering technique continues to deliver multiple malware families including PavinLoader and AvisLoader, which uses peer-to-peer infrastructure designed to outlast traditional takedown responses. This briefing examines the persistent gap between patch availability and patch application, and provides actionable guidance for UK small and medium businesses on verifying third-party patch status, confirming email infrastructure security, and implementing staff awareness controls that technical measures cannot replace. Chapters Introduction Overview of three active threats exploiting the gap between patch availability and application: JetBrains TeamCity ransomware exploitation, Roundcube Webmail active attacks, and the persistent ClickFix social engineering campaign. TeamCity Ransomware Exploitation CISA confirms ransomware groups are exploiting a critical TeamCity RCE vulnerability eleven weeks after the July patch. Examination of supply chain exposure for UK SMBs through managed service providers and development partners with access to production environments. Call to Action Encouragement to follow the show and share the briefing with colleagues who need threat intelligence. Roundcube Webmail Active Exploitation Canadian Centre for Cyber Security reports active exploitation of CVE-2026-48842, a code injection vulnerability in Roundcube Webmail, four months after the May patch. Analysis of the attack surface and guidance for UK SMBs using hosted email infrastructure. ClickFix Social Engineering Campaign Examination of the ClickFix technique as initial access vector across multiple malware campaigns including PavinLoader and AvisLoader. Guidance on staff awareness training as the primary defence against social engineering that technical controls cannot prevent. AI Command and Control Research Brief assessment of Cisco Talos CLOSEDQUORUM research on AI-directed malware. Clarification that this remains proof-of-concept rather than an operational threat currently observed in the wild. Summary and Closing Recap of actionable steps for TeamCity patch verification, Roundcube infrastructure security confirmation, and ClickFix staff briefing. Emphasis on the effectiveness of asking the right questions over technical complexity. Links https://www.cisa.gov/news-events/alerts https://cyber.gc.ca/en/guidance https://www.ncsc.gov.uk/guidance https://blog.talosintelligence.com/
Chrome Zero-Days, Android Banking Trojan, and VeloCloud Exploit Five Chrome V8 vulnerabilities are under active exploitation by Chinese threat actors right now. A single malicious page visit can compromise an unpatched device without user interaction beyond the click. Meanwhile, the RemControl Android banking trojan is targeting UK financial institutions through fake app downloads, stealing credentials via Accessibility Service abuse. Arista has patched an actively exploited VeloCloud Orchestrator zero-day affecting SD-WAN infrastructure, and Microsoft’s September updates have broken Always On VPN for some Windows 11 systems. Mauven walks through the exploitation chains, the real exposure for UK SMBs, and the concrete actions required before close of business today. This is not theoretical risk. These are operational threats requiring immediate patch management, staff briefings, and infrastructure verification. Chapters Intro Chrome is being actively exploited by a Chinese threat actor. Unpatched browsers can be compromised through a single page visit with no user action beyond the click. Chrome V8: Multiple Zero-Days Under Active Exploitation Five CVEs published against Chromium’s V8 engine are confirmed under active exploitation. Chinese threat actor UTA0565 is using fake domains and phishing emails to silently exploit browsers and escalate to full device compromise. UK SMBs with unmanaged or inconsistently patched Chrome installations face immediate risk. Update Chrome across all devices today and verify browser restarts. CTA Follow the show and share with colleagues who need daily threat intelligence. RemControl: Android Banking Trojan Targeting Western European Banks RemControl is an Android banking trojan distributed via fake TVTap IPTV download pages in paid search ads. It abuses Accessibility Service permissions to inject phishing overlays on legitimate banking apps and stream device screens in real time. UK banks are in scope. Staff personal devices used for work represent soft perimeter risk. Brief staff to only install apps from official stores and decline Accessibility Service requests from non-essential apps. Arista VeloCloud Orchestrator: Actively Exploited Zero-Day Arista has patched an actively exploited zero-day in VeloCloud Orchestrator on-premises deployments. VCO manages SD-WAN infrastructure. Most UK SMBs will encounter this through managed service providers. Ask your IT provider if VCO is in your environment and confirm the patch has been applied today. September Windows Updates and Always On VPN Microsoft’s September security updates break Always On VPN on some Windows 11 systems. Remote staff losing VPN connectivity should not work around it by bypassing the VPN. Wait for Microsoft’s fix or apply their documented workaround. Do not remove the control. The Pattern Worth Noting Today’s threats exploit the browser, the phone, and the network connection. The defences are patch management, staff awareness, and infrastructure visibility. ClickFix campaigns continue to succeed through bulletproof hosting and social engineering that asks users to paste commands into Windows Run dialogs. The threat surface is everyday infrastructure. The controls are unglamorous and effective. Outro Update Chrome today, brief staff on APK risks this week, and verify VeloCloud patching if applicable. Three actions within reach before close of business. Links https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap/ https://www.group-ib.com/blog/remcontrol-android-banking-trojan/ https://www.arista.com/en/support/advisories-notices/security-advisory https://www.microsoft.com/en-us/windows/windows-11 https://www.blackhillsinfosec.com/clickfix-research/
Seventeen Days of Silence, Autonomous AI Implants, and a Zero-Day Router Today’s briefing covers three active threats that exploit gaps in oversight and attention. First, Huntress published a timeline of an INC ransomware attack that compromised 175 endpoints after a 17-day period of apparent dormancy, demonstrating how patient adversaries use dwell time as a weapon. Second, Cisco Talos released details of CLOSEDQUORUM, the first documented malware implant exhibiting fully autonomous command and control capabilities, alongside their new CAIRN research toolkit designed to hunt AI-integrated threats. Third, D-Link disclosed a maximum-severity remote code execution vulnerability in the DIR-822A router with no patch available and a public exploit already circulating. All three threats share a common characteristic: they operate in the spaces between human monitoring cycles, relying on the assumption that reduced visibility equals reduced risk. This episode provides specific, actionable guidance for UK small businesses on securing remote access, implementing behavioural monitoring, and conducting immediate network hardware audits. Chapters Introduction: The Common Thread Mauven introduces three threats united by a single characteristic: all rely on gaps in attention and monitoring to succeed. INC Ransomware: The Quiet Breach That Wasn’t Huntress timeline reveals a ransomware campaign that compromised 175 endpoints after 17 days of dormancy, demonstrating how initial access brokers and ransomware affiliates exploit dwell time. Specific guidance on securing RDP access with VPN and MFA. Call to Action Brief reminder to follow the show and share with colleagues who need threat intelligence. CLOSEDQUORUM: The First Confirmed Autonomous AI C2 Implant Cisco Talos documents the first malware with fully autonomous command and control, released alongside their CAIRN research toolkit. Analysis of operational implications and the shift from signature-based to behavioural detection requirements. D-Link DIR-822A: Maximum Severity, No Patch, Exploit Already Public D-Link discloses CVE-2026-86296, a maximum-severity RCE vulnerability in end-of-life hardware with no patch available. Immediate removal required. Context provided on Windows Defender zero-day and the importance of network hardware inventory. Closing Analysis Mauven synthesises the three threats and emphasises that effective defence relies on consistent application of basic controls and active monitoring, not sophisticated tools alone. Specific action items for UK SMBs. Links https://www.huntress.com/blog/inc-ransomware-attack-timeline https://blog.talosintelligence.com/closedquorum-autonomous-ai-malware/ https://blog.talosintelligence.com/cairn-toolkit/ https://www.dlink.com/en/security-bulletin/ https://www.ncsc.gov.uk/guidance/securing-remote-access
Evolving Cyber Threats Facing UK Businesses Join Mauven MacLeod for today’s Threat Analysis as we explore significant cyber threats impacting UK businesses. We begin with TraderTraitor, a subgroup of the Lazarus Group, which has shifted focus from cryptocurrency firms to IT services providers, highlighting a strategic expansion in their attack vectors. For small businesses, this underscores the importance of cybersecurity, regardless of sector involvement. Next, we examine Head Mare’s exploit of vulnerabilities in TrueConf’s video conferencing servers using PhantomCore malware. This highlights the critical need for robust communication security amidst the rise in remote work. Finally, we cover Microsoft’s recommendation to transition from SMS-based authentication to passkeys, emphasising the importance of strengthening digital identity security. Proactive security practices, including regular audits and comprehensive patch management, are essential for enduring in today’s hostile cyber landscape. Chapters Intro Mauven introduces the episode, highlighting the interconnected nature of cyber threats affecting UK businesses. TraderTraitor’s IT Services Attack Discussion on TraderTraitor’s shift to target IT services, urging small businesses to enhance their cybersecurity measures. CTA Reminder to follow the show for daily updates and share with others. Head Mare’s PhantomCore Exploit Examination of Head Mare’s attack on TrueConf, stressing the importance of communication security and patch management. Microsoft’s Authentication Transition Coverage of Microsoft’s push towards passkey authentication, advising businesses to adopt more secure identity protocols. Outro Summary of key points and encouragement to stay proactive in cybersecurity. Links https://example.com/tradertraitor https://example.com/headmare https://example.com/microsoft-passkeys
Third-Party Trust Exploited: Brevo, Clop, and RMM Abuse On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious code into JavaScript assets that reached over 100,000 customer websites. WordPress administrators had backdoor plugins silently installed while logged in; regular visitors faced ClickFix credential-harvesting overlays. Meanwhile, the Clop threat group continues exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid data exfiltration, targeting UK manufacturing and engineering supply chains. A third campaign involves Settra ransomware maintaining persistence via MeshAgent, a legitimate remote monitoring tool that endpoint security often trusts by default. All three attacks share one structural weakness: reliance on third-party platforms, scripts, and tools that UK small businesses cannot directly audit or control. This briefing walks through the mechanics of each campaign, explains why supply chain compromise scales so effectively, and sets out the specific questions business owners must ask their web developers, IT providers, and managed service providers today. No patch can protect you from a script you load from someone else’s content delivery network, and no endpoint tool will flag an RMM agent it has been trained to trust. The NCSC has published supply chain guidance repeatedly; these campaigns demonstrate how rarely it is applied in practice. Chapters Intro Mauven frames the common vulnerability across today’s campaigns: reliance on third-party platforms that UK small businesses cannot audit, patch, or monitor in real time. Brevo Supply Chain Attack On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious JavaScript that silently installed WordPress backdoor plugins on admin machines and delivered ClickFix credential-harvesting overlays to visitors across over 100,000 customer sites. CTA Mauven asks listeners to follow the show and share it with colleagues who need the briefing. Clop Returns with a Custom Implant The Clop threat group is exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid credential harvesting, database enumeration, and data exfiltration, targeting UK manufacturing and engineering businesses. Settra Ransomware and RMM Abuse Settra ransomware maintains persistence by installing MeshAgent, a legitimate remote monitoring tool that endpoint security trusts by default, making unauthorised access harder to detect. The Wider Pattern Mauven connects all three campaigns to the same structural weakness: shared platforms, scripts, and tools that businesses cannot directly control, and the persistent gap between available NCSC guidance and real-world application. Outro Mauven summarises the specific actions listeners must take today: audit Brevo-linked sites, confirm PTC Windchill patches, and ask MSPs which RMM agents are authorised and how unauthorised ones would be detected. Links https://sansec.io/research/brevo-supply-chain-attack https://www.ncsc.gov.uk/collection/supply-chain-security https://www.reliaquest.com/blog/clop-ransomware-ptc-windchill-cve-2026-12569/ https://www.huntress.com/blog/settra-ransomware-analysis
Cisco ISE Zero-Day and GhostCode OAuth Phishing Demand Immediate Action Two critical threats require immediate attention from UK businesses today. Cisco has disclosed an authentication bypass vulnerability in its Identity Services Engine with a maximum CVSS score of 10.0, and exploitation is already confirmed as active. ISE functions as a network gatekeeper for VPN, device compliance, and access control, making this vulnerability a direct path to your network perimeter. Separately, the GhostCode phishing technique weaponises Microsoft’s legitimate OAuth device code flow to bypass multi-factor authentication entirely. The attack arrives via business contact forms, presents victims with authentic Microsoft URLs, and produces valid session tokens that persist even after password resets. Analysis of ransomware activity in Japan reveals that 80 per cent of victims had capital under one billion yen, confirming that small and medium businesses are the majority of targets, not the exception. With Windows 11 24H2 reaching end of support in October 2026, unpatched endpoints remain a consistent entry point in post-breach analysis. This briefing provides specific actions for patching, MFA hardening, conditional access policies, and session revocation. Chapters Introduction Mauven introduces two urgent threats: a Cisco vulnerability with active exploitation and a phishing technique that bypasses MFA controls most organisations rely on. Cisco ISE Authentication Bypass (CVSS 10.0) Analysis of the critical Cisco Identity Services Engine vulnerability with confirmed active exploitation, explaining why network access control systems are high-value targets and providing immediate patching guidance. Call to Action Encouragement to follow the show and share with business owners and IT providers who need timely threat intelligence. GhostCode OAuth Device Code Phishing Detailed breakdown of the GhostCode phishing kit that abuses Microsoft’s OAuth 2.0 device authorisation flow to bypass MFA, including detection indicators and specific mitigation steps. Ransomware Targeting of Smaller Businesses Analysis of Cisco Talos data showing 80 per cent of ransomware victims in Japan were small and medium enterprises, challenging the assumption that smaller size reduces risk. Windows 11 24H2 End of Support Reminder that Windows 11 24H2 Home and Pro editions reach end of support in October 2026, with guidance on fleet assessment and update planning. Outro Recap of the two key takeaways: immediate patching and verification actions, and the structural reality that small businesses are primary ransomware targets. Links https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-FweYPvM8 https://www.esentire.com/blog/ghostcode-phishing-campaign-targets-businesses-via-contact-forms https://blog.talosintelligence.com/threat-roundup-0905-0912/ https://support.microsoft.com/en-us/windows/windows-11-version-24h2-update-history-0929c747-ca28-4e21-93d3-0d56f5c7f1b4
ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect vulnerability, the remote access tool used by countless UK IT providers to support small business clients. Attackers are targeting managed service providers to gain indirect access to entire client portfolios. Meanwhile, the GhostCode phishing campaign is bypassing traditional defences by abusing Microsoft’s legitimate OAuth device code flow, landing in inboxes through web contact forms and requiring no fake login pages. Finally, Google has patched a zero-day privilege escalation flaw in Pixel devices that was exploited in targeted attacks. This briefing explains why these threats matter to UK SMBs, what the attack patterns look like in practice, and what concrete actions business owners and IT managers should take today. Mauven MacLeod delivers the technical detail and the operational context that turns threat intelligence into defensible decisions. Chapters Introduction Mauven introduces two active threats targeting UK small businesses through legitimate infrastructure: a remotely exploited ScreenConnect flaw and an OAuth device phishing technique that bypasses traditional defences. ScreenConnect: CISA Confirms Active Exploitation CISA has added a critical ConnectWise ScreenConnect vulnerability to its Known Exploited Vulnerabilities catalogue. Attackers are targeting IT providers to gain indirect access to their SMB clients. Business owners are advised to verify their MSP has patched the tool and to understand the supply chain risk. Call to Action A reminder to follow the show and share the briefing with colleagues who need the information. GhostCode: OAuth Device Phishing eSentire has documented the GhostCode phishing kit, which abuses Microsoft’s OAuth device code flow to gain persistent access to Microsoft 365 accounts. The campaign impersonates procurement officers, uses web contact forms, and directs victims to legitimate Microsoft URLs, bypassing traditional phishing defences. Pixel Zero-Day Google’s September 2026 patch for Pixel devices includes a fix for a zero-day privilege escalation vulnerability exploited in targeted attacks. Organisations using Pixel devices should install the update immediately. Closing Remarks Mauven summarises the three practical actions listeners should take: verify ScreenConnect patch status with IT providers, brief staff on OAuth device code phishing indicators, and review OAuth app consents in Microsoft Entra admin centre. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.esentire.com/ https://otx.alienvault.com/ https://www.ncsc.gov.uk/ https://support.google.com/pixelphone/answer/4457705
Web Skimmers, IoT Botnets, and Search Engine Fraud: Trust Under Attack Three active cybercriminal campaigns are exploiting trust in routine business systems. GrelosGTM injects payment skimmers into Google Tag Manager containers on compromised e-commerce sites, bypassing traditional file integrity checks and PCI compliance tools. Two IoT malware families, KATARU and Evooo1Bot, are scanning for unpatched edge devices using vulnerabilities dating back to 2007, turning compromised routers and network appliances into proxy infrastructure. Meanwhile, criminals are creating convincing fake versions of legitimate financial portals that surface in organic search results through typosquatting and Punycode manipulation. Each campaign targets a different attack surface, but all exploit the same underlying assumption: that familiar tools, devices, and search results are inherently trustworthy. Mauven MacLeod examines the behavioural incentives that make these attacks effective and outlines practical steps UK businesses can take today to audit their Google Tag Manager containers, verify firmware on internet-facing devices, and reduce social engineering risks through simple URL management practices. Chapters Introduction Overview of three active campaigns exploiting trust in marketing tools, network hardware, and search engine results. GrelosGTM: Payment Skimming Hidden Inside a Marketing Tool Group-IB research on a cybercriminal group injecting malicious scripts into Google Tag Manager containers on Magento e-commerce sites. Practical audit steps for UK businesses. Call to Action Encouragement to follow the show and share with small business owners. KATARU and Evooo1Bot: Two IoT Botnets Scanning for Unpatched Devices Two Mirai-derived botnets exploiting weak credentials and decades-old vulnerabilities in internet-facing edge devices. Includes FortiGate SSL-VPN intrusion campaign detail and firmware audit checklist. Search Engine Fraud: Fake Crypto Gift Card Checkouts Criminals creating convincing fake versions of legitimate portals that appear in organic search results through typosquatting and Punycode manipulation. Simple URL management mitigations. Closing Connecting thread across all three campaigns and practical takeaway: audit the things you have stopped looking at. Links https://www.group-ib.com/resources/research-hub/grelosgtm/ https://www.nozominetworks.com/blog/kataru-botnet-exploits-iot-devices/ https://www.infosecurity-magazine.com/news/evooo1bot-botnet-targets-iot/ https://hunt.io/blog/cve-2024-21762-fortinet-ssl-vpn-exploitation https://www.malwarebytes.com/blog/scams/2026/09/fake-bitrefill-sites-search-engine-fraud https://www.ncsc.gov.uk/guidance/securing-e-commerce-sites
Revolut Social Engineering Breach and GitLab Path Traversal Exploit A major fintech data breach demonstrates how impersonation attacks bypass technical defences entirely, whilst a maximum-severity GitLab vulnerability enters active exploitation. This episode examines Revolut’s disclosure of customer financial and passport data released following a fraudulent government agency impersonation, highlighting the procedural failures that enable social engineering at scale. We cover CISA’s addition of a GitLab path traversal flaw to the Known Exploited Vulnerabilities catalogue, the supply chain implications for UK SMBs, and practical verification procedures that prevent data disclosure to unauthorised parties. Operational updates include Microsoft’s September patches breaking Remote Desktop Services on Windows Server, and the UK government’s passkey rollout across 23 million GOV.UK accounts. The episode focuses on verification protocols, out-of-band confirmation procedures, and supply chain questioning as practical defences against non-technical attack vectors that compromise organisations with significant security resources. Chapters Introduction Mauven introduces the episode focus on a fintech breach achieved through convincing impersonation rather than technical exploitation, setting up the central theme of procedural failures in data handling. Revolut Breach via Government Impersonation Analysis of Revolut’s data breach following a fraudulent government agency request, examining the social engineering mechanism, customer impact, verification procedure failures, and practical implementation of out-of-band confirmation protocols for UK SMBs handling data disclosure requests. CTA Call to action encouraging listeners to follow the show and share with colleagues handling data requests and code repositories. GitLab Path Traversal Flaw, Actively Exploited, Maximum Severity Coverage of CISA’s addition of a GitLab path traversal vulnerability to the Known Exploited Vulnerabilities catalogue, explanation of path traversal attack mechanics, supply chain exposure risks through developer and MSP relationships, and immediate patching requirements. September Windows Updates and RDS Microsoft’s September 2026 security updates breaking Remote Desktop Services functionality on Windows Server, the patching versus functionality trade-off, and recommendations for planned deployment with awareness of the known issue. UK Government Passkey Rollout UK government’s passkey implementation across 23 million GOV.UK accounts, the stated rationale of reducing phishing exposure and SMS verification costs, and implications for SMB authentication strategy beyond SMS-based MFA. Outro Summary emphasising that high-impact attacks often require minimal technical sophistication, practical actions on verification procedures and supply chain patching status, and closing remarks. Links https://www.ncsc.gov.uk/guidance/impersonation-attacks https://www.ncsc.gov.uk/collection/guidelines-secure-system-configuration https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.gov.uk/government/news/passkeys-rollout-govuk-accounts
Russian State Actors Target Business Travellers via Hotel Wi-Fi This episode examines three active threat campaigns with direct SMB relevance. Russian state group APT29 (Midnight Blizzard) is conducting large-scale credential harvesting through compromised hotel and conference Wi-Fi networks across the UK and Europe, specifically targeting business travellers. The operation exploits captive portal authentication flows to harvest Microsoft 365 credentials through spoofed login pages and device code phishing that bypasses MFA. A second campaign demonstrates AI-orchestrated exploitation of PaperCut print management software, progressing from vulnerability research to remote code execution in under four hours across 440+ installations. The episode also covers a maximum-severity GitLab path traversal vulnerability and recent Conti ransomware sentencing. Analysis focuses on the systematic targeting of authentication layers, the operational risk to SMBs from compromised cloud tenancies, and the acceleration of exploit development through AI automation. Practical guidance addresses device code flow controls, conditional access policies, VPN discipline for travelling staff, and the limitations of MFA as a single defensive layer. Chapters Introduction: Active Campaigns Targeting Business Travellers Overview of Russian state-sponsored credential harvesting via UK hotel Wi-Fi networks and AI-orchestrated PaperCut exploitation campaign. Episode positions APT29 activity as immediate SMB threat rather than purely government-sector concern. CaptiveCrunch: APT29 Hotel Wi-Fi Credential Harvesting Detailed analysis of Midnight Blizzard (APT29) campaign exploiting captive portal networks at hotels and conferences. Explains device code phishing technique that bypasses MFA, SMB impact from compromised Microsoft 365 tenancies, and four immediate mitigation actions including device code flow controls and conditional access policies. Call to Action Listener engagement request to follow show and share briefing given active campaign status. AI-Orchestrated PaperCut Exploitation Analysis of CVE-2026-81578 and CVE-2026-82078 exploitation campaign against PaperCut print management software. Details AI agent automation achieving remote code execution in under four hours across 440+ targets. Provides specific guidance on patch verification, internet exposure assessment, and compromise indicators. GitLab Vulnerability and Conti Sentencing Brief coverage of CVE-2026-85706 maximum-severity GitLab path traversal vulnerability requiring immediate patching. Notes Ukrainian national receiving four-year sentence for Conti ransomware development, with analysis positioning outcome as illustrating enforcement limitations rather than meaningful deterrent. The Wider Pattern: Authentication Layer Under Systematic Attack Synthesis identifying authentication layer as common target across multiple active campaigns. Argues current threat landscape reflects prioritisation failure rather than technology limitation, given documented NCSC guidance on phishing-resistant MFA and conditional access controls. Closing: Practical Takeaways Summary of actionable guidance: disable unnecessary device code flow, patch PaperCut installations, brief travelling staff on captive portal risks before conference season. Links https://www.zscaler.com/blogs/security-research/ https://www.ncsc.gov.uk/ https://www.greynoiseintell.com/ https://blackpointcyber.com/ https://www.bleepingcomputer.com/ https://about.gitlab.com/releases/categories/security/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.microsoft.com/security/blog/
WatchGuard Ransomware Exploitation and Chrome Zero-Day Chain Target UK SMBs Two active exploitation campaigns are affecting UK small businesses today. Ransomware operators are exploiting a critical WatchGuard Firebox vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalogue in December 2025, yet remains unpatched in many deployments nine months later. The flaw allows remote, unauthenticated code execution on internet-facing devices. Separately, four China-aligned threat actors have adopted an identical Chrome and Windows zero-day exploit chain within days of each other, enabling full system compromise through a single malicious webpage visit. The BlueMoon exploit kit combines CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Patches are available for both campaigns. Additionally, Cisco Secure Firewall Management Center is under active exploitation via two vulnerabilities that grant administrative control, with possible connections to the Qilin ransomware group. Today’s briefing provides specific remediation steps for each threat and examines why a nine-month-old vulnerability continues to find victims, highlighting fundamental patch management failures across the UK SMB sector. Mauven frames the discussion around visibility, accountability, and the compression of exploitation windows in modern threat environments. Chapters Introduction Mauven opens the tenth of September 2026 briefing with two active exploitation events affecting UK small businesses: a nine-month-old WatchGuard vulnerability now used by ransomware operators, and a browser-based zero-day chain adopted by four state-aligned actors within days. WatchGuard Firebox Ransomware Exploitation CISA confirms ransomware gangs are actively exploiting a critical remote code execution flaw in WatchGuard Firebox appliances. The vulnerability was added to the KEV catalogue in December 2025, yet remains unpatched in many UK SMB deployments. Ransomware operators use automated scanning to find vulnerable devices. Mauven emphasises the need to verify firmware versions immediately and obtain written confirmation from managed service providers. Call to Action Mauven encourages listeners to follow the show and share it with colleagues who need daily threat intelligence. BlueMoon Chrome Zero-Day Exploit Chain Proofpoint and Volexity report on the BlueMoon exploit kit, which chains CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Four China-aligned threat actors adopted identical exploitation within days, suggesting coordinated or brokered tooling. The attack requires only visiting a compromised webpage and achieves full system compromise. Patches are available from Google and Microsoft’s September 2026 Patch Tuesday. Cisco Secure Firewall Management Center Exploitation Cisco Talos tracks active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center, which together grant administrative control. Possible connections to the Qilin ransomware group are noted. The vulnerability primarily affects mid-market professional services and managed security provider infrastructure. Patch Management Reality Check Mauven examines the operational reality of three network security products under active exploitation in the same news cycle. The continued exploitation of a nine-month-old WatchGuard vulnerability demonstrates that patch management is treated as optional despite NCSC guidance. The core issue is visibility: organisations must be able to answer which internet-facing devices and applications were updated in the last thirty days. Closing and Practical Takeaway Mauven summarises the immediate action items: confirm WatchGuard Firebox firmware is current and verify Chrome and Windows updates are applied across all devices. Listeners are encouraged to demand specific answers from IT providers, not vague reassurances. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.proofpoint.com/us/blog/threat-insight/bluemoon-exploit-kit https://www.volexity.com/blog/2026/09/bluemoon-exploit-chain-analysis/ https://www.watchguard.com/security-advisories https://blog.talosintelligence.com/cisco-fmc-vulnerabilities/ https://www.ncsc.gov.uk/guidance/patch-management
UK Cybersecurity: Patch Tuesday and New Threats In today’s briefing, Mauven examines key cybersecurity threats relevant to UK businesses. Microsoft’s record Patch Tuesday reveals 973 vulnerabilities, with 113 rated as critical, highlighting the urgency for timely updates. Two zero-day vulnerabilities pose active risks. Small and medium UK businesses often underestimate their appeal to cybercriminals, leaving systems vulnerable. Additionally, Plex Media Servers have over 36,000 exposed units due to security lapses, stressing the need for rigorous patch compliance. The emergence of the BlueMoon exploit chain underlines the danger of using outdated software, as state actors weaponise newly discovered vulnerabilities in platforms like Chrome and Windows. Maintaining up-to-date systems is imperative to prevent costly breaches and attacks. The episode concludes with a reminder that procrastination with updates can be perilous, urging businesses to prioritize security. Chapters Intro Introduction to today’s cybersecurity briefing, highlighting the importance of system updates. Microsoft’s Record Patch Tuesday Analysis of Microsoft’s 973 vulnerabilities, including 113 critical ones and two active zero-day threats, stressing the importance of updates. CTA Encouragement to follow the podcast for regular updates and share with others. Plex Media Servers Threat Discussion on the vulnerabilities in over 36,000 exposed Plex Media Servers and the importance of patch compliance. BlueMoon Exploit Chain Insight into the BlueMoon exploit chain and how outdated systems are exploited by state actors, emphasising the need for current systems. Outro Final thoughts on the critical nature of timely system updates for business survival. Links https://www.ncsc.gov.uk https://www.microsoft.com/security/blog https://www.shadowserver.org
Cyber Threats Every UK SME Must Address Today In this episode of Threat Analysis, hosted by Mauven, we delve into pressing cybersecurity threats facing UK small and medium-sized businesses (SMEs). We begin with the StyleSmuggler zero-day vulnerability targeting Magento and Adobe Commerce. Identified as CVE-2025-54236, this flaw allows unauthorised remote code execution, which underscores the importance of immediate patching. Despite Adobe’s emergency patch, many SMEs remain vulnerable due to a lack of awareness or resources. We also explore the BigBear 2.0 phishing campaign, which successfully obtained credentials from over five thousand Microsoft 365 accounts globally. This highlights the increasing adoption of phishing-as-a-service models, making it vital for businesses to implement multifactor authentication and foster a culture of vigilance. Mauven emphasises the need for rapid patch management and strong phishing defenses, encouraging businesses to prioritise vulnerabilities based on their potential impact. Through proactive measures and informed strategies, UK SMEs can safeguard against emerging cyber threats. Chapters Intro Introduction to today’s cybersecurity threats for UK SMEs. StyleSmuggler Zero-Day in Magento Explanation of the StyleSmuggler vulnerability and the need for urgent patching. CTA Encouragement to follow and share the podcast. BigBear Phishing Campaign Targets Microsoft 365 Details of the BigBear phishing campaign and the importance of multifactor authentication. Implications for UK SMBs Discussion on the necessity of strong cybersecurity measures for UK SMEs. Outro Conclusion emphasising proactive defense and awareness. Links https://www.theregister.com/2025/11/15/microsoft_365_bigbear_campaign https://adobe-patches.com/magento-styleSmuggler
Magento Zero-Day Threat and Crypto Heist Insights Mauven delves into pressing cybersecurity issues facing UK businesses. The alarming zero-day vulnerability in Magento, known as Stylesmuggler, threatens e-commerce operations with unauthorised remote code execution risks. The episode stresses the importance of immediate action, such as disabling unnecessary services and utilising robust web application firewalls until Adobe releases a patch. Additionally, the recent $320 million cryptocurrency heist from Liquid Network serves as a wake-up call for digital currency security, urging businesses to adopt offline cold storage solutions and perform comprehensive protocol audits. The episode also covers the significant data breach at Mathspace due to insufficient Metabase security, underscoring the need for encryption and third-party compliance. The vulnerability in ConnectWise’s ScreenConnect tool alerts managed service providers to engage actively with vendors for updates. Across these discussions, the emphasis remains on pre-emptive actions and maintaining robust security measures. Chapters Intro Introduction to threats impacting UK businesses, focusing on Magento vulnerability. Unpatched Magento Zero-Day Vulnerability Details on the Magento Stylesmuggler zero-day vulnerability affecting UK e-commerce. CTA Call to action for listeners to subscribe and share the podcast. Liquid Network $320M Cryptocurrency Heist Discussion on the significant cryptocurrency heist and its implications. Mathspace Data Breach: Lessons in Data Management Analysis of the Mathspace data breach and its impact on data management practices. ConnectWise ScreenConnect Vulnerability Examination of vulnerabilities in ConnectWise’s ScreenConnect tool. Outro Conclusion with a focus on the importance of proactive security measures. Links https://www.magento.com/security https://www.liquid.network/blog/august-2026-security-incident https://www.mathspace.com/security https://www.connectwise.com/the-latest-on-security
Access Management Failures: Teams Impersonation, Infostealer Sessions, and Leaver Risk Three separate incidents this week reveal a single, critical vulnerability across UK small businesses: access management. Microsoft Threat Intelligence has confirmed an active campaign exploiting Teams external collaboration to impersonate IT helpdesk staff, tricking employees into installing remote access tools that deploy malicious payloads. Meanwhile, new analysis shows that resetting passwords after infostealer compromise leaves authenticated session tokens active, allowing attackers continued access for days. A separate case study documents a terminated employee retaining elevated access long enough to cause hundreds of thousands in damages, purely because no formal offboarding checklist existed. The technical controls to prevent all three scenarios are available and documented. What is missing is operational discipline: caller verification before granting remote access, session revocation alongside password resets, and comprehensive leaver access audits. This episode provides specific, actionable guidance for small businesses without dedicated security teams, walking through the configuration changes, staff briefings, and process checklists required to close these gaps before they are exploited. Chapters Introduction Overview of three incidents that all point to access management as the primary UK SMB vulnerability right now, with context from yesterday’s coverage and Microsoft’s new formal confirmation. Attackers Impersonating IT Helpdesk via Microsoft Teams Detailed breakdown of the confirmed Microsoft Teams helpdesk impersonation campaign, including the full technical chain from initial contact to lateral movement, and specific configuration and process changes required to mitigate the risk. Call to Action Brief listener engagement prompt. Infostealer Sessions: The MFA Problem Nobody Is Talking About Analysis of the session token problem in infostealer incidents, why password resets alone are insufficient, and the specific session revocation steps required in Microsoft 365 and other platforms. The Leaver Who Kept Access Case study of a terminated employee retaining elevated access due to absent offboarding processes, with practical guidance on access audits and leaver checklists for small businesses. The Pattern Connecting All Three Synthesis of the common access management gap across all three incidents and the operational discipline required to close it. Closing Practical takeaway and episode close. Links https://www.microsoft.com/en-us/security/blog/threat-intelligence/ https://www.huntress.com/ https://www.ncsc.gov.uk/guidance/phishing-resistant-authentication https://www.bleepingcomputer.com/ https://unit42.paloaltonetworks.com/ https://www.theregister.com/ https://www.ncsc.gov.uk/collection/identity-and-access-management
SonicWall Zero-Days, Teams Vishing Campaign, and Third-Party Identity Risk On 2 September 2026, SonicWall disclosed two vulnerabilities in the SMA1000 remote access appliance series being actively chained together for remote code execution at the time of public disclosure. This episode provides immediate guidance for organisations running SonicWall perimeter devices, including patch verification and compromise auditing procedures. The briefing examines the Spring Ring campaign, a sustained Microsoft Teams vishing operation documented by Unit 42 that successfully targeted over 150 employees across ten companies between January and April 2026, using impersonated IT helpdesk calls to deploy remote monitoring tools and credential theft techniques including PetitPotam. Coverage includes Dropbox account compromises resulting from a Lenovo email verification flaw, illustrating third-party identity risk in business service authentication. Additional notes cover the multi-agency Sality botnet takedown after 23 years of operation, and emerging UK cyber legislation placing regulatory responsibility for AI deployment risk on end-user organisations rather than vendors. Chapters Introduction Overview of three critical threat developments requiring immediate action, particularly a SonicWall zero-day exploitation event disclosed whilst under active attack. SonicWall SMA1000: Two Chained Zero-Days Under Active Exploitation Detailed analysis of actively exploited server-side request forgery and command injection vulnerabilities in SonicWall SMA1000 remote access appliances, with specific guidance on patch verification and compromise auditing for affected organisations. Call to Action Listener engagement prompt encouraging subscription and peer sharing of threat intelligence briefings. Microsoft Teams Vishing: Spring Ring Targeted 150+ Employees Across 10 Companies Comprehensive examination of the Spring Ring social engineering campaign using Microsoft Teams voice calls to impersonate IT helpdesk staff, including technical details of PetitPotam credential theft and practical staff briefing guidance. Dropbox Accounts Breached via Lenovo Email Verification Flaw Case study in third-party identity risk, covering Dropbox account compromises resulting from a vulnerability in Lenovo’s email verification process, with recommendations for identity provider auditing and multi-factor authentication. In Brief: The Sality Botnet Is Down Multi-agency disruption of the Sality botnet after 23 years of operation, including context on infected system remediation. A Note on the UK Cyber Bill Policy development update on UK cyber legislation framing regulatory responsibility for AI deployment risk on end users rather than vendors. Closing Summary of priority actions and episode conclusion. Links https://www.sonicwall.com/ https://unit42.paloaltonetworks.com/ https://www.ncsc.gov.uk/ https://www.dropbox.com/ https://www.crowdstrike.com/ https://www.shadowserver.org/ https://www.theregister.com/
Exchange Auth Bypass, PaperCut Data Theft, and Softaculous Supply Chain Attack Nearly 22,000 Microsoft Exchange servers remain unpatched for a critical authentication bypass vulnerability allowing complete mailbox takeover. PaperCut print management software, deployed across thousands of UK offices, is actively exploited for data theft days after a patch was released. A 33-hour BGP hijack of Softaculous infrastructure may have poisoned the hosting supply chain for small business websites. This briefing provides specific verification steps for IT providers, explains why the window between patch release and exploitation continues to shrink, and connects these incidents to wider supply chain and social engineering threats including Teams vishing campaigns and fake CAPTCHA attacks. For UK small businesses running on-premises Exchange, PaperCut installations, or shared hosting websites, today’s combination represents direct and immediate exposure requiring same-day action. Chapters Introduction Three active threats with direct paths into UK small business environments: 22,000 unpatched Exchange servers, active PaperCut exploitation for data theft, and a 33-hour BGP hijack of Softaculous infrastructure. CVE-2026-62911: Exchange Authentication Bypass High-severity vulnerability allowing unauthenticated attackers to hijack all user mailboxes on 22,000 internet-exposed Exchange servers. Verification steps for IT providers and the organisational failure behind persistent Exchange patching delays. Listener Call to Action Encouragement to follow the show and share with those running on-premises Exchange or shared hosting sites. PaperCut Zero-Day Exploitation and Active Data Theft Two PaperCut vulnerabilities patched last week now actively exploited for data theft campaigns. The shrinking window between patch release and exploitation, and why data theft differs from ransomware in detection and response. Softaculous BGP Hijack and Supply Chain Exposure Explanation of BGP hijacking mechanism and the 33-hour interception of Softaculous traffic affecting shared hosting infrastructure. Supply chain attack implications for small business websites and required audit steps. Wider Threat Context Connections between today’s threats and broader patterns including Teams vishing campaigns, ClickFix fake CAPTCHA attacks, and the shift from perimeter to user-focused initial access vectors. Closing Actions and Summary Three immediate actions: verify Exchange patch status, confirm PaperCut updates and check for prior compromise, audit shared hosting credentials and installations. Service level agreement implications if IT providers cannot respond within one working day. Links https://www.bleepingcomputer.com/news/security/22-000-microsoft-exchange-servers-exposed-to-auth-bypass-attacks/ https://www.theregister.com/2026/08/29/softaculous_bgp_hijack/ https://unit42.paloaltonetworks.com/spring-ring-vishing-campaign/ https://www.microsoft.com/security/blog/terminalfix-campaign
Airport Breach, Terminal Attacks, and Defender Alert Fatigue Manchester Airports Group has suffered a confirmed data breach larger than initially disclosed, with 86GB of validated customer and travel records now in threat actor hands. UK businesses with corporate travel through Manchester, Stansted, or East Midlands face immediate phishing risk. Meanwhile, the TerminalFix campaign bypasses email defences entirely by tricking users into executing malicious PowerShell commands through fake Cloudflare CAPTCHA overlays on compromised websites. Microsoft Defender’s broken status alerts, with official guidance to ignore warnings, create a window where genuine malware could disable endpoint protection undetected. Mauven examines the gap between initial breach disclosures and validated impact, the social engineering techniques that route around traditional defences, and why session token theft from infostealer malware cannot be resolved by password resets alone. Practical guidance includes staff briefings on travel data targeting, application control policies for Windows Terminal, and management-layer monitoring to compensate for unreliable user-facing alerts. Chapters Introduction Overview of three active threats affecting UK businesses: a confirmed airport breach with validated stolen data, a social engineering campaign designed to bypass email defences, and a Microsoft Defender issue creating alert fatigue. Manchester Airports Group Breach FulcrumSec claims 86GB data theft from Manchester Airports Group, with independently validated customer and travel records. Analysis of the disclosure gap, targeting risks for corporate travel, and practical steps for businesses with MAG connections. Call to Action Encouragement to follow the show and share the episode with UK business contacts who need awareness of the Manchester Airports situation. TerminalFix Campaign Microsoft’s analysis of TerminalFix, a ClickFix variant using fake Cloudflare CAPTCHA overlays on compromised websites to trick users into executing malicious PowerShell commands through Windows Terminal, bypassing email-based defences entirely. Microsoft Defender Alert Fatigue Latest Defender update causes false ‘antivirus is turned off’ alerts, with Microsoft advising users to ignore warnings. Implications for security culture and the need for management-layer monitoring during the issue. Infostealer Session Theft Anthropic confirms Claude session token theft via infostealer malware, illustrating broader principle that stolen session cookies remain valid after password resets and require explicit session revocation across all platforms. Closing Summary of common theme across stories: existing defences do not address current attack vectors. Three immediate actions for UK businesses: brief staff on MAG breach targeting, educate on terminal-based social engineering, and implement management-layer Defender monitoring. Links https://www.bleepingcomputer.com/news/security/manchester-airports-group-investigates-fulcrumsec-data-breach-claims/ https://www.microsoft.com/en-us/security/blog/2024/08/30/terminalfix-campaign-uses-fake-cloudflare-verification-to-deliver-malware/ https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-falsely-warns-that-antivirus-is-turned-off/ https://www.anthropic.com/news/session-token-theft-incident https://www.ncsc.gov.uk/guidance/business-email-compromise https://www.ncsc.gov.uk/guidance/social-engineering
Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants This episode examines three active threats targeting UK small businesses through infrastructure that is often managed inattentively. PaperCut print management servers face active zero-day exploitation with no official vendor patch available, forcing organisations to choose between unvalidated emergency fixes or taking systems offline. A Microsoft Teams vishing campaign, running since January 2026, uses social engineering and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor for ransomware operators. Research into ZBT router firmware reveals three pre-installed implants, including DARKLANTERN, an unauthenticated backdoor offering root shell access. The episode also covers critical ServiceNow vulnerabilities, over 8,300 unpatched Gitea instances facing active exploitation, and CISA’s observation that most exploited vulnerabilities in 2026 should have been eradicated decades ago. The common thread is infrastructure that organisations do not actively monitor: print servers, router firmware, and remote access tools that staff use without scrutiny. Mauven provides specific, actionable guidance for each threat, emphasising that the surfaces receiving least attention from defenders are those being studied most carefully by attackers. Chapters Introduction Overview of three active threats targeting infrastructure that UK small businesses manage inattentively: a print server zero-day, an eight-month Teams vishing campaign, and firmware implants in routers. PaperCut Zero-Day: Active Exploitation, No Official Patch PaperCut print management servers face active zero-day exploitation with no validated vendor patch. The software, widely deployed in UK SMBs, has administrative access to networked devices and was previously exploited by ransomware groups in 2023. Organisations must choose between applying an unvalidated emergency patch or taking servers offline. Call to Action Brief listener engagement request. Microsoft Teams Vishing: GoGRPC Backdoor and the Ransomware Pipeline Zscaler research details an eight-month campaign using Microsoft Teams vishing and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor. Attackers impersonate IT support, gain remote access, and sell network access to ransomware operators. The attack exploits normalised IT support behaviours. Firmware Implants in the Supply Chain: ZBT Routers VulnCheck identifies three firmware implants in ZBT routers distributed globally: SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS. DARKLANTERN provides unauthenticated root shell access via UDP port 9992. The implants were present in firmware before devices reached customers, representing a hardware-layer supply chain compromise. ServiceNow, Gitea, and the CISA Observation Three maximum-severity vulnerabilities patched in ServiceNow AI Platform. Over 8,300 internet-exposed Gitea instances remain unpatched against actively exploited remote code execution flaws. CISA notes that most exploited vulnerabilities in 2026 should have been eradicated decades ago, citing organisational culture failures. Closing Remarks The common thread across all threats is infrastructure inattention. Print servers, router firmware, and remote access tools that organisations do not actively monitor are precisely the surfaces attackers study most carefully. Practical guidance emphasises active management of unglamorous infrastructure. Links https://www.theregister.com/ https://www.papercut.com/ https://www.ncsc.gov.uk/ https://www.zscaler.com/blogs/security-research/ https://www.microsoft.com/ https://vulncheck.com/ https://www.servicenow.com/ https://www.shadowserver.org/ https://www.cisa.gov/
NCSC Edge Device Warning, Manchester Airports Breach, and Teams Vishing Today’s briefing examines three urgent threats to UK small businesses. The NCSC has issued a fresh alert on internet-exposed edge devices, highlighting persistent failures in patch management and configuration that attackers are actively exploiting. Manchester Airports Group has confirmed a breach affecting 8.7 million UK customers, creating significant downstream phishing risk through compromised travel data. Zscaler research details an ongoing Microsoft Teams vishing campaign deploying the GoGRPC backdoor, demonstrating how ransomware operations have industrialised initial access through collaboration platforms. The episode provides specific, actionable guidance for each threat, from verifying patch dates on VPN appliances to configuring Quick Assist controls and preparing staff for contextualised spear-phishing. We also note the arrest of two individuals connected to TeamPCP supply chain attacks. Each story is framed through the operational gaps that enable these threats, with practical steps UK SMBs can implement today. Chapters Introduction Overview of three urgent threats: NCSC edge device alert, Manchester Airports data breach, and industrialised ransomware access via Microsoft Teams. NCSC Alert on Internet-Exposed Edge Devices Analysis of the NCSC advisory on disruptive incidents linked to unpatched VPNs, firewalls, and edge devices. Covers operational failures in patch management, specific checks for UK SMBs, and the critical Fortinet EMS vulnerability CVE-2026-35616. Call to Action Invitation to follow the show and share with colleagues. Manchester Airports Group Data Breach Examination of the 8.7 million customer breach, the downstream spear-phishing risk from exposed travel data, and practical steps for businesses whose staff or customers may be affected. Microsoft Teams Vishing Campaign and GoGRPC Backdoor Detailed analysis of Zscaler research on Teams-based social engineering delivering the GoGRPC backdoor. Covers the attack pattern, configuration controls for Quick Assist, and staff training requirements. TeamPCP Supply Chain Arrests Brief note on arrests connected to developer supply chain attacks, highlighting ongoing exposure for UK SMBs using third-party software. Closing Summary and Actions Consolidated practical guidance: verify patch dates, configure Quick Assist controls, brief staff on Teams vishing, and assess Manchester Airports exposure. Links https://www.ncsc.gov.uk/ https://www.esentire.com/ https://www.zscaler.com/ https://ico.org.uk/
Ubiquiti UniFi Max-Severity Flaws and Gitea Active Exploitation Three maximum-severity vulnerabilities have been disclosed in Ubiquiti’s UniFi network products, all exploitable remotely without authentication. Separately, CISA has confirmed active exploitation of a critical code injection flaw in Gitea, the self-hosted Git service widely used for internal code repositories. Both disclosures highlight a persistent gap in how UK businesses secure infrastructure that sits behind the public perimeter. UniFi kit manages internal networks and physical security systems across thousands of SMBs, yet firmware updates often lag months behind current versions. Gitea servers hold development code, credentials, and API keys, but are frequently treated as lower-priority assets despite their access to production environments. The observed Gitea exploitation involves cryptominer deployment, but the real risk is remote code execution on systems that touch sensitive infrastructure. This episode examines why trusted infrastructure receives less scrutiny than customer-facing systems, and why that gap creates exploitable exposure. Mauven provides specific patch guidance, incident response steps, and asset inventory priorities for both vulnerabilities. Chapters Intro Mauven introduces episode thirty-nine, focusing on infrastructure vulnerabilities that receive insufficient security attention despite supporting critical business operations. Ubiquiti UniFi: Three Max-Severity Flaws Three maximum CVSS score vulnerabilities disclosed in UniFi Network Application and UniFi Protect, all exploitable remotely without authentication. Covers authentication bypass and command injection risks, UK SMB deployment patterns, and immediate patching requirements. CTA Brief call to action encouraging listeners to follow the podcast and share with colleagues managing network infrastructure. Gitea RCE: CISA Confirms Active Exploitation CISA adds critical Gitea code injection vulnerability to Known Exploited Vulnerabilities catalogue following confirmed cryptominer deployment. Discusses risks to self-hosted Git repositories, credential exposure, and the need for log analysis and repository auditing. The Trusted Infrastructure Problem Analysis of why infrastructure supporting operations rather than serving customers receives less security scrutiny, creating exploitable gaps. Covers NCSC guidance on vulnerability management and notes a ClickFix phishing campaign using npm mirror infrastructure. Outro Summary of patch requirements and asset review priorities for both UniFi and Gitea. Closing remarks and episode credits. Links https://community.ui.com/releases https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.ncsc.gov.uk/collection/vulnerability-management
ClickFix Malware, Check Point Bypass, and Zimbra Campaign Hits 270 Servers Three active threats demand immediate attention from UK small businesses today. ClickFix social engineering campaigns have matured into a multi-vector malware ecosystem using MSI packages, NodeJS execution, and fake CAPTCHA lures to deliver persistent backdoors across Windows and macOS systems. Attackers are abusing legitimate Windows tools and storing command-and-control addresses in blockchain smart contracts, making traditional network defences less effective. Check Point has confirmed active exploitation of CVE-2026-16232, a critical authentication bypass in SmartConsole that grants unauthenticated remote attackers full administrative access to firewall management servers. Organisations using managed service providers for firewall infrastructure need specific answers about exposure windows and remediation status. A remote code execution vulnerability in Zimbra Collaboration Suite has already compromised over 270 email servers, with the campaign ongoing. This episode provides actionable guidance on endpoint monitoring configuration, management server security reviews, and supplier due diligence for email hosting platforms. None of these threats are theoretical. All three are actively exploiting UK organisations today. Chapters Introduction Mauven introduces three active threats affecting UK small businesses: a mature social engineering malware ecosystem, a critical firewall management authentication bypass under active exploitation, and an email server vulnerability with over 270 confirmed compromises. ClickFix: The Social Engineering Technique That Grew Up Analysis of ClickFix malware campaigns using MSI packages with DLL sideloading, NodeJS execution, and fake CAPTCHA lures. Coverage includes PavinLoader’s blockchain-based command-and-control infrastructure, cross-platform macOS variants, and fraudulent SysScan websites. Practical guidance on endpoint protection configuration and staff awareness training. Call to Action Encouragement to follow the show and share threat intelligence with professional networks to close the gap between awareness and action. Check Point SmartConsole: Authentication Bypass Under Active Exploitation Detailed examination of CVE-2026-16232 and accompanying privilege escalation vulnerabilities in Check Point SmartConsole. Focus on exploitation conditions, attack chains, and specific questions UK SMBs must ask managed service providers about exposure and remediation. Zimbra RCE: 270 Servers Down, Campaign Ongoing Coverage of the ongoing Zimbra Collaboration Suite remote code execution campaign affecting over 270 instances. Discussion of supply chain risks through managed hosting providers and the operational impact of email server compromise. Guidance on verification and patching. Closing Remarks Mauven identifies the common thread across all three threats: attackers exploiting configuration gaps and awareness failures rather than extraordinary techniques. Recap of actionable steps for endpoint monitoring, supplier verification, and staff training. Links https://fieldeffect.com/ https://malwarebytes.com/ https://checkpoint.com/ https://shadowserver.org/ https://bleepingcomputer.com/ https://zimbra.com/
Zimbra Zero-Click RCE, Check Point Bypass, and Device Code Phishing This episode examines three active threats demanding immediate attention from UK small businesses. First, a zero-click remote code execution vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) under active exploitation by Russian-linked threat actors, with a three-day federal patch deadline from CISA. Second, an authentication bypass flaw in Check Point SmartConsole (CVE-2026-16232) allowing unauthenticated remote attackers full administrative access to exposed management servers. Third, a vishing and device code phishing campaign by the Helix data extortion group that requires no malware and leaves minimal forensic trace. The episode emphasises that all three threats exploit the gap between what organisations have configured and what they actually review. Practical actions include patching Zimbra immediately, verifying Check Point management interfaces are IP-restricted, enabling Microsoft 365 unified audit logging, and training staff on device code phishing recognition. The common thread is organisational discipline: knowing what is running in your environment, how it is configured, and whether anyone is reviewing the evidence of activity within it. Chapters Introduction Mauven introduces three threats for 24 August 2026: two confirmed, actively exploited vulnerabilities with patches available, and a social engineering campaign that leaves no malware trace. The third threat is identified as the most dangerous for UK small businesses reliant on endpoint detection alone. Zimbra Zero-Click RCE Under Active Exploitation CISA has added CVE-2025-66376, a zero-click remote code execution flaw in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities catalogue with a three-day federal patch deadline. The vulnerability is being exploited by Russian-linked threat actor Void Blizzard (LAUNDRY BEAR) in a systematic credential harvesting operation targeting government, defence, transportation, and financial sector organisations across NATO member states. UK small businesses, particularly legal firms, accountancy practices, and professional services running on-premises email, must patch immediately, verify Zimbra deployment status, restrict internet access if patching cannot occur immediately, and review access logs for anomalous activity. Call to Action Listeners are encouraged to follow the show and share the briefing with colleagues who can act on the information presented. Check Point SmartConsole Authentication Bypass Check Point has confirmed active exploitation of CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that allows unauthenticated remote attackers full administrative access to exposed Management Servers. Exploitation has been confirmed against customers with management interfaces exposed to the internet without IP restrictions. UK organisations using Check Point products must apply security updates immediately, verify all management interfaces are IP-restricted with documentation, review access logs for authentication attempts from unexpected sources, and confirm managed service providers have patched all deployments. Helix Vishing and Device Code Phishing ReliaQuest has documented a data extortion group named Helix running a three-stage attack requiring no malware: vishing calls impersonating managers using open-source research from LinkedIn and company websites, device code phishing directing employees to enter codes into legitimate Microsoft authentication pages to grant attackers persistent access tokens, and automated SharePoint exfiltration. The campaign leaves no endpoint detection evidence and is only visible in Microsoft 365 unified audit logs. UK small businesses must brief all staff on device code phishing, establish verbal verification procedures for credential-related requests, enable unified audit logging in Microsoft 365, and consider Conditional Access policies restricting device code authentication flows. The Pattern This Week All three threats exploit the gap between what organisations have configured and what they have reviewed. Zimbra instances not audited since deployment, management interfaces opened for remote access and never locked down, and Microsoft 365 audit logs not being read represent ordinary accumulated drift rather than exotic failures. The adversaries target organisations that have not implemented basic controls, and the discipline required to close these gaps is organisational rather than technical. Conclusion The practical takeaway is to answer three questions immediately: is Zimbra running anywhere in your environment, is any network device management interface accessible from the internet without IP restriction, and is unified audit logging enabled in your Microsoft 365 tenant. If the answers are unknown, organisations must find out today. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://unit42.paloaltonetworks.com/ https://www.checkpoint.com/advisories/ https://www.ncsc.gov.uk/ https://www.reliaquest.com/ https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code
Teams Impersonation and Rust Supply Chain Attacks Hit UK SMBs This episode examines two unconnected but similarly exploitative campaigns targeting UK small businesses in August 2026. The first, SynkLoader, uses Microsoft Teams to impersonate IT helpdesk staff, delivering memory-resident malware through plausible maintenance requests. The attack succeeds because default Teams external access settings allow unrestricted messages from unknown tenants. The second involves a coordinated supply chain attack against three legitimate Rust programming language packages, injecting malicious code through a typosquatted dependency that executes during software builds. Both campaigns exploit trust in familiar channels rather than technical vulnerabilities. Mauven MacLeod explains why these attacks work, what they reveal about default configurations in SMB environments, and provides actionable steps: restricting Teams external federation, establishing clear IT contact protocols, auditing Rust dependencies for the malicious proc-macro1 package, and questioning software vendors about supply chain verification. The episode emphasises that effective defence requires deliberately changing insecure defaults, not advanced security tooling. Chapters Introduction Mauven introduces two active campaigns targeting UK small businesses through trusted channels: a Teams-based helpdesk impersonation attack and a Rust programming language supply chain compromise. Both exploit default configurations rather than technical vulnerabilities. SynkLoader: When Your IT Helpdesk Comes to You Analysis of SynkLoader malware delivered via Microsoft Teams helpdesk impersonation. The attack uses MSI installers to deploy multi-language, memory-resident malware that bypasses endpoint detection, establishes command-and-control access, and captures credentials through fake lock screens. Succeeds because default Teams external access settings allow unrestricted external messages. Call to Action Encouragement to follow the show and share with colleagues who would benefit from daily threat intelligence briefings. Rust Supply Chain: The Dependency You Did Not Know You Had Examination of a coordinated supply chain attack against three legitimate Rust packages through a typosquatted dependency called proc-macro1. Malicious code executed during software builds, potentially compromising both bespoke software and commercial products. Highlights the gap in SMB software procurement processes around supply chain verification. The Wider Picture Connects both campaigns through their exploitation of trust in familiar channels and legitimate-seeming sources. Emphasises that effective attacks against small businesses rely on familiarity rather than technical sophistication, and that changing insecure defaults requires deliberate decisions. Closing Recap of practical actions: verify Teams external federation settings and question IT providers about software supply chain verification processes. Two questions that reveal the current security posture. Links https://expel.com/blog/synkloader-analysis/ https://socket.dev/blog/rust-supply-chain-attack https://www.ncsc.gov.uk/guidance/phishing-resistant-authentication https://www.ncsc.gov.uk/collection/supply-chain-security
MLflow Exploitation, NetScaler Emergency Patch, and European Banking Trojan CISA has confirmed active exploitation of a critical MLflow vulnerability, demanding immediate action from any organisation running AI or machine learning infrastructure. The server-side request forgery flaw allows attackers to access internal systems, and deployment patterns mean the platform often sits outside normal security review cycles. Separately, Citrix has issued an urgent advisory for NetScaler Gateway and ADC vulnerabilities, with language reflecting high exploitation likelihood. The perimeter-facing nature of these widely deployed remote access solutions makes them priority targets. Finally, the Manic Android banking trojan is spreading across Europe with a relay-based exfiltration capability that partially defeats network controls, raising BYOD security questions for UK small businesses. The NCSC has also published new guidance on managing agentic AI cyber risk, connecting to broader concerns about autonomous systems acting on behalf of users without adequate security review. Chapters Introduction Mauven opens with three stories requiring immediate action: a CISA-confirmed active exploitation, an urgent Citrix advisory, and a European banking malware threat relevant to UK businesses. MLflow Under Active Exploitation CISA adds MLflow to the Known Exploited Vulnerabilities catalogue following confirmed active attacks. The server-side request forgery vulnerability affects AI and machine learning deployments that often sit outside normal security review cycles, creating exposure many organisations may not be aware of. Call to Action Listeners are encouraged to follow the show and share the briefing, particularly with those managing IT for small businesses who need urgent awareness of the MLflow exploitation. Citrix NetScaler Emergency Advisory Citrix issues urgent patching guidance for NetScaler Gateway and ADC vulnerabilities. The perimeter-facing nature of these widely deployed products, combined with Citrix’s deliberate use of emergency language, signals high exploitation risk requiring immediate verification with IT providers. Manic Android Malware in Europe The Manic banking trojan spreads across Europe with relay-based exfiltration capability that routes stolen data through nearby infected devices, partially defeating network controls. BYOD practices in UK small businesses create exposure when personal Android devices access work accounts. NCSC Guidance on Agentic AI The NCSC publishes guidance on managing cyber risk from autonomous AI systems that act on behalf of users. Prompt injection attacks against agentic AI tools represent an escalating threat as these systems gain access to business accounts and services. Closing Mauven connects the common thread across all stories: security gaps emerge when deployment outpaces security review. The practical priority is knowing what runs in your environment, who manages it, and how responsibility is verified. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://support.citrix.com/ https://www.ncsc.gov.uk/blog-post/managing-cyber-risk-agentic-ai https://www.theregister.com/
Critical Windows RCE Under Active Exploit, Clop Custom Tooling, and MFA Bypass Phishing This episode covers three active threats with credible paths to UK small businesses. First, CISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation against network-reachable systems. Second, Clop ransomware has returned with purpose-built tooling targeting PTC Windchill in manufacturing supply chains, deploying custom web shells designed for credential harvesting and data exfiltration. Third, the Mirage2FA phishing-as-a-service platform is bypassing multifactor authentication through adversary-in-the-middle session token theft, with over four thousand confirmed Microsoft 365 victims. Mauven explains the technical mechanisms behind each threat, identifies the specific organisations at risk, and provides actionable steps that require no budget approval: verifying Windows patch status for IKE Extension, questioning manufacturing suppliers about Windchill patching, and reviewing Microsoft 365 conditional access policies to detect session anomalies. The episode also notes FBI confirmation of Medusa ransomware breaching over five hundred US critical infrastructure organisations using living-off-the-land techniques. All three primary threats demonstrate that speed of response, supplier questioning, and configuration review matter more than technology spending for most small business cyber resilience. Chapters Introduction Mauven introduces three threats with credible UK small business impact: a Windows vulnerability under active exploitation, Clop ransomware with custom tooling, and an MFA-bypassing phishing platform. Windows IKE Extension RCE: CISA KEV Addition CISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue. The flaw is network-reachable, requires no authentication, and allows arbitrary code execution. Mauven explains why active exploitation status demands immediate Windows patch verification, particularly for organisations using Windows-based VPN solutions. Support the Show Brief call to action encouraging listeners to follow the show and share with business owners who need operational threat intelligence. Clop Returns with Purpose-Built Tooling Clop ransomware is targeting PTC Windchill in manufacturing and engineering supply chains using custom-developed web shells. ReliaQuest analysis confirms the toolkit includes credential harvesting, database enumeration, and Java-based exfiltration components. Mauven explains the supply chain exposure risk and recommends questioning suppliers about Windchill patching status. Mirage2FA Phishing-as-a-Service Bypasses MFA Mirage2FA operates as an adversary-in-the-middle proxy, capturing authenticated Microsoft 365 session tokens after users complete MFA. ANY.RUN analysis identifies over four thousand victims. Mauven explains why MFA alone is insufficient without conditional access policies detecting impossible travel and anomalous session use. Medusa Ransomware Context FBI confirms Medusa ransomware has breached over five hundred US critical infrastructure organisations since June 2021 using phishing, unpatched vulnerabilities, and living-off-the-land techniques. Mauven notes the tactics are internationally relevant and the confirmed victim count likely understates true impact. Summary and Actions Three actions requiring no budget: verify Windows IKE Extension patch deployment, question manufacturing suppliers about PTC Windchill patching, and review Microsoft 365 conditional access configuration to detect session token theft. Mauven emphasises that difficulty having these conversations is itself diagnostic of resilience gaps. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.reliaquest.com/blog/clop-ransomware-ptc-windchill-cve-2026-12569/ https://any.run/cybersecurity-blog/mirage2fa-phishing-kit-analysis/ https://www.fbi.gov/news/press-releases/fbi-issues-alert-on-medusa-ransomware https://www.ncsc.gov.uk/collection/supply-chain-security
Windows Task Host Ransomware Exploitation and Microsoft Copilot Injection Flaw Two Microsoft vulnerabilities demand immediate attention from UK small businesses running Windows endpoints and Microsoft 365. CISA has confirmed active ransomware exploitation of the Windows Task Host privilege escalation flaw, four months after its initial disclosure. This vulnerability allows attackers who have gained initial access to escalate to system-level privileges, enabling lateral movement and full ransomware deployment. Separately, Microsoft has disclosed CVE-2026-24301, a command injection vulnerability in Copilot that enables information disclosure across the entire Microsoft 365 data estate. Because Copilot operates within user permission contexts, the vulnerability exposes whatever data those users can access, including financial records, HR files, and confidential client information. Researchers have also documented C2Looper, a Rust-based backdoor that uses GitHub for command-and-control traffic and connects to ClickFix infection chains. Together, these developments illustrate a complete ransomware kill chain from initial access through privilege escalation to deployment. Organisations must confirm Windows patch status today, review Copilot access permissions against the principle of least privilege, and brief staff on ClickFix lures that present as fake browser error messages. Chapters Introduction Overview of two Microsoft vulnerabilities affecting Windows endpoints and Microsoft 365, both requiring immediate action. CISA has confirmed ransomware exploitation of the Windows Task Host flaw, whilst Microsoft has disclosed a command injection vulnerability in Copilot. Windows Task Host Ransomware Exploitation Analysis of the Windows Task Host privilege escalation vulnerability, now confirmed by CISA as actively exploited by ransomware groups. Explains how attackers use the flaw to escalate from low-privilege access to system-level control, enabling lateral movement and full estate compromise. Four months have passed since disclosure. Call to Action Encouragement to follow the show and share it with others who need threat intelligence information. CVE-2026-24301 Microsoft Copilot Command Injection Examination of the newly disclosed command injection vulnerability in Microsoft Copilot. Explains how Copilot’s deep integration with Microsoft 365 data means the vulnerability exposes entire organisational data estates through user permission contexts. Addresses the risk of default enablement and the need for permissions audits. C2Looper and Ransomware Delivery Chains Overview of C2Looper, a Rust-based backdoor that uses GitHub for command-and-control traffic, and its connection to ClickFix infection chains. Describes the complete ransomware kill chain from initial access through privilege escalation, emphasising the importance of staff awareness training on ClickFix techniques. Conclusion Practical summary of required actions: confirm Windows patch status immediately, review Copilot access permissions, apply least privilege principles, and brief staff on ClickFix lures this week. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301 https://www.theregister.com/ https://www.zscaler.com/blogs/security-research/
Clop, ShinyHunters, and SAP: When Supplier Risk Becomes Attack Surface Three distinct threat campaigns broke on 14 August 2026, and each one targets the same vulnerability: supplier and third-party infrastructure. Clop ransomware claimed 89GB of Shell data via managed file transfer platforms, continuing a six-year pattern of targeting MFT tools across supply chains. ShinyHunters exposed 1.6 million RingCentral accounts while simultaneously running OAuth abuse campaigns against Salesforce and other SaaS platforms, weaponising legitimate integrations and voice phishing. A maximum-severity SAP Commerce Cloud vulnerability moved from patch release to active exploitation in just three days. Meanwhile, supplier breaches at the Crown Office and Procurator Fiscal Service in Scotland and Trezor’s logistics partner reinforce the same pattern: organisations with sound internal controls are being compromised through third-party infrastructure they don’t directly manage. This briefing explains why managed file transfer platforms, OAuth connections, and unpatched supplier software represent the dominant attack surface in 2026, and provides actionable steps for UK small businesses to identify and close these exposure gaps before threat actors exploit them. Chapters Introduction Three separate threat streams reveal a unified pattern: organisations with well-managed internal environments are being compromised through supplier infrastructure, SaaS integrations, and third-party software. Clop Claims Shell: The Method Is Six Years Old Clop ransomware claimed 89GB of Shell data via PTC FlexPLM and Windchill platforms. Team Cymru analysis shows Clop has run nine campaigns over six years, systematically targeting managed file transfer tools across supply chains. Call to Action Encouragement to follow the show and share with colleagues who may underestimate their exposure to supplier-based threats. ShinyHunters Pivots from Data Theft to SaaS Infiltration ShinyHunters breached RingCentral, exposing 1.6 million accounts, while simultaneously running OAuth abuse campaigns against Salesforce and other SaaS platforms using voice phishing, supply chain compromise, and credential theft. SAP Commerce Cloud: Maximum Severity, Already Exploited A maximum-severity remote code execution vulnerability in SAP Commerce Cloud moved from patch release to active exploitation in three days, compressing response windows and exposing retailers and e-commerce operators. The Pattern Underneath Today’s Stories Clop, ShinyHunters, and the SAP campaign all exploit third-party and supplier exposure. Additional breaches at Crown Office Scotland and Trezor’s logistics partner reinforce that supplier risk is the dominant attack surface in 2026. Closing Practical takeaways: map supplier access, audit OAuth connections, patch on severity rather than schedule, and brief staff on voice phishing tactics targeting legitimate application approval processes. Links https://haveibeenpwned.com https://www.teamcymru.com https://www.microsoft.com/security/blog https://defused.com https://www.ncsc.gov.uk
Cybersecurity Challenges Facing UK SMEs Today’s episode tackles key cybersecurity challenges facing UK small and medium enterprises. We delve into the exploits by the Russian-aligned group TA488, discuss vulnerabilities such as CVE-2026-42897, and examine the broader impact of cyber incidents beyond primary targets. Learn about the MacSync Stealer threat to macOS and the potential risks associated with Anthropic’s Claude AI models. Finally, we explore the recent CAF Bank incident affecting thousands of charities. Each section offers insights and actionable steps to bolster your organisation’s security posture amidst these evolving threats. Chapters Intro Introduction to key cybersecurity issues facing UK businesses, including TA488 exploits and AI vulnerabilities. CVE-2026-42897 and TA488 Discusses the CVE-2026-42897 vulnerability exploited by TA488 and the importance of patch management. CTA Encourages listeners to follow the podcast and share it with others who might benefit. MacSync Stealer on macOS Explores the MacSync Stealer threat via Google Ads affecting macOS users and stresses the need for education and advanced protection. Anthropic’s Claude AI Models Examines issues of AI containment and security with Claude AI models, urging robust governance frameworks. CAF Bank Incident Analyzes the cyber incident affecting CAF Bank, highlighting the importance of financial security measures and contingency plans. Outro Concludes with a call for vigilance and accountability in tech environments to secure against threats. Links https://www.ncsc.gov.uk/collection/toolkit-for-small-businesses https://www.example.com/security-patch-guidance
UK SMBs Face Escalating Cyber Threats In today’s episode of Threat Analysis, Mauven MacLeod delves into critical cybersecurity challenges confronting UK small businesses. We address Russian state-sponsored email attacks targeting Microsoft Outlook with a unique ‘half-click’ method, which offers notable resilience against traditional security measures. Understanding the implications of such threats is essential for businesses to protect their digital environments and reputations. Additionally, we examine the rise of attacks within the npm registry, impacting software development operations. This new threat utilises worm-like behaviours to infiltrate popular packages and steal credentials via blockchain transactions. These complex methods highlight the importance of thorough vigilance and robust security strategies for companies relying on open-source software. Mauven emphasises the necessity of incorporating comprehensive security measures, combining human and technological approaches, to effectively manage and counter these evolving threats. Don’t miss out on the need for keen awareness and proactive defences in safeguarding your business. Chapters Intro Mauven highlights the critical cyber threats facing UK SMBs and the importance of robust security. Russian State-Sponsored Email Attacks Targeting Outlook Discussion on the ‘half-click’ method used by Russian hackers in Outlook attacks, emphasising resilience and the need for awareness. CTA Encouragement to follow the show and share with those who need cybersecurity insights. NPM Registry Hosting New Supply Chain Attacks Exploration of worm-like attacks within the npm registry targeting credentials via blockchain, calling for vigilant dependency management. Outro Conclusion on the necessity of proactive cybersecurity measures for UK SMBs, previewing future threat analyses. Links https://www.ncsc.gov.uk https://www.microsoft.com
Cyber Threats: Helpdesk Attacks and WordPress Risks Mauven MacLeod presents today’s Threat Analysis, focusing on pressing cyber threats faced by UK small and medium businesses. She explores two major issues: vishing attacks exploiting Microsoft Teams and vulnerabilities in WordPress. Vishing attacks target companies through Microsoft Teams, where attackers impersonate IT helpdesk staff and deploy the GoGRPC backdoor. This can lead to ransomware attacks, compromising sensitive company data. Mauven emphasises the importance of staff awareness and technological safeguards to mitigate risks. The episode also highlights critical vulnerabilities in WordPress Core, affecting versions 6.9.0 to 7.0.1. These vulnerabilities allow unauthorised remote code execution, potentially leading to total site takeovers. Businesses are urged to apply patches immediately to protect their websites and customer data. The National Cyber Security Centre underlines the urgency of this action. Mauven stresses that these insights should lead to a comprehensive cybersecurity strategy, incorporating regular updates, employee training, and robust security policies. Chapters Intro Mauven introduces the episode’s focus on cyber threats targeting UK businesses: Microsoft Teams vishing attacks and WordPress vulnerabilities. Helpdesk Hijackers: Microsoft Teams Vishing Attacks Discussion of vishing attacks via Microsoft Teams, where attackers exploit helpdesk impersonations to deploy the GoGRPC backdoor, posing risks to UK businesses. CTA A call to action for listeners to follow the podcast for daily briefings and share it with others who might benefit. WordPress Vulnerabilities: wp2shell Threat Overview of critical vulnerabilities in WordPress versions 6.9.0 to 7.0.1, allowing remote code execution. Emphasises the need for immediate patches. Implications for UK SMBs The importance of integrating cybersecurity into business culture, ensuring systems and staff are well-prepared against current threats. Outro Mauven wraps up with a reminder to remain vigilant and to use these insights to strengthen business security. Links https://www.ncsc.gov.uk/ https://www.microsoft.com/
Urgent Vulnerabilities for UK Businesses In today’s episode, Mauven MacLeod tackles pressing vulnerabilities affecting UK small and medium businesses. Microsoft’s Defender for Endpoint is under scrutiny due to bugs that leave Linux systems unprotected. From installation issues on hardened RHEL systems to deactivation on restart, these glitches pose significant security risks. Attention is drawn to Java Spring Boot’s exposed endpoints revealing sensitive data, underscoring GDPR compliance risks. The discussion moves to critical vulnerabilities, CVE-2026-16461 and 8450, and their severe implications. Finally, Google’s cybercrime taxonomy offers new insights into defending against threats. It’s an urgent call to action for businesses to address these threats promptly. Chapters Intro Introduction to the urgency of addressing security vulnerabilities for UK businesses. Microsoft Defender for Endpoint Analysis of vulnerabilities in Microsoft Defender, affecting Linux systems and RHEL installations. Java Spring Boot Vulnerabilities Exposed heapdump endpoints in Java Spring Boot pose risks of data exposure and GDPR violations. Microsoft Security Response Critical vulnerabilities CVE-2026-16461 and CVE-2026-8450 discussed with potential impacts. Google’s Cybercrime Taxonomy Google’s new cybercrime taxonomy aids in understanding and targeting specific threats effectively. Outro Final thoughts on the need for urgent action to secure business systems against vulnerabilities. Links https://docs.microsoft.com/en-us/microsoft-defender-endpoint/linux-installation https://spring.io/projects/spring-boot https://www.cve.org/CVERecord?id=CVE-2026-16461 https://www.cve.org/CVERecord?id=CVE-2026-8450 https://security.googleblog.com/2023/07/new-cybercrime-taxonomy.html
Addressing Mistic Backdoor and FortiBleed Risks In today’s episode of Threat Analysis, Mauven MacLeod explores two significant cyber threats impacting UK small and medium-sized businesses: the Mistic backdoor and the FortiBleed campaign. Both threats exploit vulnerabilities requiring immediate attention. The Mistic backdoor, potentially operated by the notorious access broker Woodgnat, uses sideloading attacks to infiltrate systems. This method often goes unnoticed and has been a staple in cybercriminal activities for years, affecting industries like professional services and healthcare. Mauven emphasises the importance of meaningful conversations with IT teams to mitigate such risks and secure vendor relationships effectively. The episode then shifts focus to the FortiBleed campaign, which targets Fortinet’s FortiGate firewalls. These essential components of network security are under significant threat as FortiBleed employs an immediate credential theft strategy. This can escalate from potential risk to an operational crisis rapidly. Mauven advises businesses to apply necessary patches promptly and enhance network monitoring protocols to detect unusual activities. Both threats underscore the necessity for proactive cybersecurity measures. Chapters Intro Mauven introduces the episode’s focus on two cyber threats, Mistic backdoor and FortiBleed, highlighting the urgency for UK businesses to address these vulnerabilities. Mistic Backdoor: Initial Access and Credential Theft Discussion on Mistic backdoor’s sideloading attacks by Woodgnat. Emphasises the need for businesses to engage with IT teams to mitigate risks and secure systems effectively. CTA Encouragement to follow the podcast for daily updates and share with others who could benefit from the information. FortiBleed Campaign: A Primer on Credential Harvesting Analysis of the FortiBleed campaign targeting Fortinet FortiGate firewalls. Highlights the urgent requirement for applying patches and enhancing network monitoring protocols. Outro Reinforces the necessity for vigilance and proactive measures in cybersecurity strategies. Encourages continual threat assessment and response. Links https://cisa.gov
UK SMBs Face Ransomware Re-Extortion and Langflow Threats In this episode of Threat Analysis, Mauven MacLeod explores critical cyber threats that UK small and medium-sized businesses (SMBs) must be aware of. The discussion begins with the increasing trend of ransomware re-extortion, where attackers demand additional payments even after receiving a ransom. Proofpoint reports show over a third of victims are affected by this tactic, highlighting the necessity for robust cybersecurity measures. The episode also covers a significant vulnerability in Langflow, as identified by CISA, which allows remote code execution and is being actively exploited. Mauven stresses the importance of immediate patching to secure AI systems against potential breaches. Additionally, the new JADEPUFFER ransomware poses a risk to AI models critical to business operations. Lastly, a vulnerability in Adobe’s Chrome extension exposes WhatsApp chats to unauthorised access, underscoring the need for secure communication policies. Join Mauven for insights into these pressing cybersecurity challenges. Chapters Intro Introduction to the episode’s focus on critical cyber threats for UK SMBs. Ransomware Re-Extortion Discussion on the trend of ransomware re-extortion affecting over a third of victims. CTA Encouragement to follow the podcast for regular updates. Langflow RCE Vulnerability Exploration of a critical vulnerability in Langflow allowing remote code execution. JADEPUFFER Ransomware Examination of JADEPUFFER ransomware targeting AI models and infrastructure. Adobe Chrome Extension Vulnerability Coverage of a security flaw in Adobe’s Chrome extension impacting WhatsApp security. Outro Conclusion with a call to action to strengthen cybersecurity defences. Links https://www.proofpoint.com https://cisa.gov
Protecting Against Ransomware and Evolving Cyber Threats In today’s briefing, Mauven MacLeod delves into imperative cybersecurity updates impacting UK businesses. The Qilin ransomware gang is actively exploiting a critical flaw in Palo Alto Networks’ GlobalProtect VPN, posing significant risks even to small enterprises. This episode underscores why businesses of all sizes must prioritise security updates to guard against cybercriminals. Additionally, Mauven discusses the emerging Jadepuffer group targeting AI technologies and the HOLLOWGRAPH campaign, which ingeniously utilises Microsoft 365 calendars for sinister purposes. The episode highlights the necessity for vigilant, proactive security practices and the importance of continuous education in the face of evolving threats. Chapters Intro Mauven introduces the episode, focusing on the Qilin ransomware gang exploiting a VPN flaw and emphasising the need for all businesses to be vigilant. Qilin Ransomware Exploits VPN Flaw Analysis of the Qilin ransomware exploiting a critical VPN vulnerability and its implications for businesses of all sizes. CTA Encouragement to follow the podcast for regular updates. Evolving Ransomware Tactics and Jadepuffer Discussion on Jadepuffer targeting AI models and the importance of staying ahead of sophisticated cyber threats. HOLLOWGRAPH Campaign Risks Overview of the HOLLOWGRAPH campaign using Microsoft 365 calendars for espionage, urging businesses to reassess security measures. Outro Concluding remarks on the importance of staying informed and proactive against digital threats. Links https://www.paloaltonetworks.com https://www.ncsc.gov.uk https://arcticwolf.com
ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing Three critical threats demand immediate attention today. A remote code execution vulnerability in ServiceNow’s AI Platform (CVE-2026-6875) is now actively exploited in the wild, requiring urgent patch verification from direct users and managed service providers alike. Meanwhile, a vishing campaign running since April has been successfully defeating Microsoft 365 passkey enrolment through carefully scripted social engineering, targeting UK SMBs who adopted phishing-resistant MFA but failed to brief staff on the human attack vector. The third story examines FortiBleed, an industrial-scale FortiGate credential harvesting operation exposed when attackers left their staging server accessible, revealing 36 rented GPUs running distributed password cracking as a production workflow. The episode also covers the Cruciferra crypter service, which offers high-quality endpoint evasion as a purchased feature, and the Hugging Face breach involving an autonomous AI agent. Each story includes specific, actionable guidance for UK organisations, with particular emphasis on the ServiceNow vulnerability requiring same-day verification from users and their supply chain. Chapters Introduction Mauven flags three threats requiring immediate action, particularly a ServiceNow vulnerability that has moved from patch-available to actively exploited. The episode will cover required responses for ServiceNow users, Microsoft 365 passkey vishing, and industrial-scale FortiGate credential harvesting. CVE-2026-6875: ServiceNow AI Platform RCE Under Active Exploitation Critical remote code execution vulnerability in ServiceNow AI Platform confirmed under active exploitation. Direct users must verify patch status immediately. Indirect exposure through managed service providers presents significant risk to UK SMBs. Specific guidance provided on what questions to ask providers and when patch confirmation is required. Call to Action Brief encouragement to follow the show and share with colleagues who need the briefing. O-UNC-066: Vishing Actors Defeating Microsoft 365 Passkey Enrolment Campaign active since April uses phone-based social engineering to register attacker-controlled passkeys to victim Microsoft 365 accounts. Attackers use domains containing ‘passkey’, impersonate Microsoft support, and guide targets through fake enrolment while simultaneously registering their own credentials. Three-part mitigation: restrict enrolment policies in Entra, brief staff on the attack pattern, and focus training on reception and finance staff most likely to receive calls. FortiBleed: Industrial-Scale VPN Credential Harvesting Exposed attacker staging server reveals large-scale FortiGate credential harvesting using 36 rented GPUs for distributed password cracking. Operation uses credential reuse, brute force, and GPU-accelerated hash cracking as an industrial workflow. Likely feeds initial access broker market serving ransomware operators. Guidance provided on verifying patch status, rotating credentials, and reviewing authentication logs. Also on the Radar Two additional items: Cruciferra crypter service offering high-quality endpoint evasion including BYOVD-based EDR tampering as a purchased feature, and Hugging Face breach involving autonomous AI agent access to production infrastructure and credentials. Both items flag direction of travel rather than immediate operational response. Closing Summary Recap of required actions: ServiceNow patch verification today, Microsoft 365 Entra policy review and staff briefing on vishing, FortiGate patch status and credential rotation. Emphasises that attackers operate at industrial scale while effective defences require consistent follow-through on straightforward measures. Links https://www.defused.com/ https://www.servicenow.com/ https://www.okta.com/ https://www.ncsc.gov.uk/ https://www.cloudsek.com/ https://www.fortinet.com/ https://www.proofpoint.com/ https://huggingface.co/
FortiSandbox Exploit, Windows Zero-Day, and ClickFix Infrastructure at Scale CISA added critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed in-the-wild exploitation. The US federal patching deadline is Sunday, but active exploitation means UK organisations should treat this as immediate priority. A newly published Windows local privilege escalation vulnerability called LegacyHive works on fully patched systems with no fix available, creating serious risk when combined with active ClickFix campaigns delivering initial access. ClickFix techniques now support at least five concurrent malware operations including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A Huntress case study documents how one ClickFix compromise spread to eleven hosts before detection. The episode provides specific, actionable guidance for SMBs: verify FortiSandbox patch status with IT providers today, brief staff on ClickFix lures immediately, review user permissions to execute scripts, and ensure endpoint detection monitors for HTA execution and PowerShell spawning from browser processes. The convergence of mature exploit infrastructure, public zero-day proof-of-concept, and active campaigns targeting European users represents a significant immediate threat to UK small business networks. Chapters Introduction Mauven opens the seventeenth of July briefing with three urgent stories. Two require immediate technical action before the weekend, whilst the third demands procedural response to an unpatched vulnerability. FortiSandbox Active Exploitation CISA confirmed active exploitation of critical FortiSandbox command injection vulnerabilities, ordering US federal agencies to patch by Sunday. FortiSandbox is a threat analysis appliance, not the firewall, creating particular concern as the security tool itself becomes attack surface. Guidance covers immediate patching requirements, how to verify MSP compliance, and the importance of asset inventory for unknown Fortinet deployments. Call to Action Brief appeal to follow the show and share with colleagues who need threat intelligence. LegacyHive Zero-Day Vulnerability A public proof-of-concept for Windows local privilege escalation called LegacyHive works on fully patched systems with no available fix. The vulnerability requires initial access first, which current ClickFix campaigns are actively providing across European targets. Defence recommendations focus on preventing initial compromise through application allow-listing, endpoint detection configuration, and staff awareness of ClickFix techniques. ClickFix Campaign Infrastructure At least five distinct malware operations now use ClickFix delivery techniques, including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A detailed Huntress case study shows one ClickFix compromise spreading to eleven hosts. Practical guidance includes immediate staff briefing, permission reviews to block arbitrary script execution, and verification that managed detection providers monitor relevant observable behaviours. Conclusion The convergence of mature ClickFix infrastructure, public Windows zero-day exploitation capability, and continuing Fortinet vulnerability exploitation represents the gap between published guidance and implemented defences. Two immediate actions: verify FortiSandbox patch status and brief staff on ClickFix lures before Friday. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.theregister.com/ https://www.ncsc.gov.uk/ https://www.bleepingcomputer.com/ https://www.huntress.com/ https://www.microsoft.com/
Social Engineering, Trojanised Tools, and Supply Chain Attacks This episode examines three contemporary threats exploiting trusted channels. Following the sentencing of two Scattered Spider members for the Transport for London breach, we analyse why social engineering remains devastatingly effective against organisations of all sizes. We then review a Russian campaign distributing trojanised WebEx and Zoom installers delivering Starland RAT, demonstrating how legitimate software becomes an attack vector. Finally, we cover the AsyncAPI npm supply chain compromise, where GitHub Actions vulnerabilities enabled injection of Miasma v3 worm into packages with valid provenance attestations. The common thread: attackers succeed not through technical brilliance, but by exploiting routine trust in familiar processes. We provide actionable guidance on helpdesk authentication procedures, software download verification, and dependency chain auditing. Additional coverage includes CISA’s Oracle E-Business Suite KEV listing and the approaching Windows 10 end-of-support deadline. Presented by Mauven MacLeod with behavioural analysis and concrete defensive measures for UK small businesses. Chapters Introduction Opening remarks establishing the episode’s central theme: trusted channels being weaponised through social engineering, trojanised software, and compromised dependencies. Scattered Spider Sentencing Analysis of two British Scattered Spider members receiving five-and-a-half-year sentences for the Transport for London breach, focusing on the social engineering techniques used and practical implications for SMB helpdesk procedures. Call to Action Audience engagement request encouraging listeners to follow the show and share with business owners. Trojanised WebEx and Zoom Examination of Russian actor UAT-11795 distributing backdoored collaboration software installers through phishing and search poisoning, delivering Starland RAT with credential theft and cryptocurrency targeting capabilities. AsyncAPI npm Supply Chain Compromise Technical breakdown of the AsyncAPI organisation compromise via GitHub Actions vulnerability, resulting in Miasma v3 worm delivery through four npm packages with valid provenance attestations and novel execution timing. Also on the Radar Brief coverage of CISA’s Oracle E-Business Suite KEV addition and the approaching Windows 10 end-of-support deadline for Home and Pro editions. Closing Remarks Summary emphasising verification over assumption, with specific guidance on questioning helpdesk authentication procedures. Links https://www.ncsc.gov.uk/ https://www.microsoft.com/security/ https://jfrog.com/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://zoom.com https://webex.com
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack On 15 July 2026, Mauven MacLeod examines three active threats facing UK organisations. CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation targeting on-premises deployments, with particular exposure among professional services firms still running legacy infrastructure. The second story details a misconfigured phishing operation that exposed 218 confirmed victims across twelve countries using Adversary-in-the-Middle techniques that bypass standard multi-factor authentication, including OAuth Device Code Flow attacks against Microsoft 365 and Google Workspace users. Finally, a supply chain attack against the AsyncAPI generator repository saw an attacker exploit a misconfigured GitHub Actions workflow to publish five malicious npm packages containing the Miasma botnet loader, which executes at import time without user interaction. The briefing emphasises that none of these attacks relied on novel techniques or nation-state resources, but succeeded through known vulnerabilities, unpatched systems, and insufficient authentication controls. Chapters Introduction Mauven opens the 15 July 2026 briefing, noting three stories involving confirmed victims and active exploitation, all stemming from known weaknesses rather than novel attack methods. SharePoint Server: Three CVEs, Active Exploitation, Patch Now CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaws affect on-premises deployments, not SharePoint Online. UK professional services firms, legal practices, and accountancy firms running legacy on-premises infrastructure face elevated risk. Mauven emphasises that KEV listing represents a late warning, not an early one, and calls for immediate patching and documented remediation. Call to Action Mauven encourages listeners to follow the show and share it with colleagues who would benefit from daily threat intelligence briefings. AiTM Phishing: Three Operators Exposed, 218 Confirmed Victims Lexfo researchers discovered a misconfigured Python HTTP server that exposed the infrastructure of three phishing operators, including one with 218 confirmed victims using OAuth Device Code Flow attacks and another operating an Adversary-in-the-Middle platform since 2018. AiTM attacks bypass standard multi-factor authentication by intercepting authenticated session tokens. Mauven explains why phishing-resistant MFA such as FIDO2 is necessary and provides specific guidance on OAuth Device Code Flow recognition and conditional access policy review. AsyncAPI npm Supply Chain: Poisoned Packages, Botnet Loader An attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository to exfiltrate a privileged access token, then published five malicious npm packages containing the Miasma botnet loader. The malicious code executes at import time without user interaction. Mauven advises organisations to audit AsyncAPI-related dependencies, review build logs from 14 July, and verify whether technology partners have assessed their exposure. Also Worth Noting The NCSC has announced that certified Cyber Advisors are offering free thirty-minute consultations for small businesses. Microsoft has halted Patch Tuesday updates for some Dell devices following reports of shutdowns and overheating. Closing Remarks Mauven concludes by noting that all three stories involve exploitation of known weaknesses through patience and known techniques, rather than exotic capabilities. The briefing emphasises checking on-premises SharePoint deployments and treating patching as an urgent priority. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.lexfo.fr/ https://www.ncsc.gov.uk/ https://www.wiz.io/ https://socket.dev/ https://github.com/asyncapi
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure Two active phishing kits, Jalisco and OmegaLord, are defeating multi-factor authentication on Microsoft 365 accounts through adversary-in-the-middle proxying and device code abuse. At the same time, documented research shows a jailbroken AI model built a fully functional command-and-control server in six minutes with minimal human input. For UK SMBs relying on MFA as their primary Microsoft 365 defence, these developments demand immediate action. Mauven examines how commoditised MFA bypass techniques work, why they matter disproportionately to UK professional services firms, and what controls to deploy now before Microsoft’s passkeys rollout in September. Also covered: critical SAP patches, actively exploited Joomla vulnerabilities, and practical steps to take this week. This episode makes clear that MFA alone is no longer sufficient, and the window to implement additional controls is closing as attack tools become cheaper and easier to deploy. Chapters Introduction Mauven introduces two critical developments: active phishing kits defeating Microsoft 365 MFA and AI-assisted attack infrastructure built in minutes. These trends signal a fundamental shift for UK businesses relying on MFA as primary defence. Jalisco and OmegaLord: When MFA Is No Longer the Answer Detailed examination of two operational phishing kits using adversary-in-the-middle proxying and device code abuse to defeat MFA on Microsoft 365. Explains why UK professional services firms are disproportionately exposed and outlines immediate mitigations including Conditional Access policies, FIDO2 keys, and token lifetime controls. Call to Action Mauven asks listeners to follow the show and share it with anyone relying solely on MFA for Microsoft 365 protection. AI Is Doing Ninety Per Cent of the Work Now Analysis of documented research showing a jailbroken Gemini model building a functional command-and-control server in six minutes. Discusses implications for UK SMBs as attack infrastructure becomes trivially easy to deploy at scale. Briefly Noted: SAP and Joomla SAP’s July 2026 patch addresses sixteen vulnerabilities including three critical flaws. Actively exploited Joomla extension vulnerabilities with CVSS 10.0 scores threaten UK SMB websites, particularly older professional services and hospitality sites. What to Do Today Four prioritised actions: verify Microsoft 365 Conditional Access configuration, patch Joomla extensions, review SAP July patches, and brief staff on device code authentication requests. Emphasises urgency of the MFA bypass issue. Outro Mauven summarises that MFA alone is insufficient for Microsoft 365 and that Conditional Access policies and phishing-resistant authentication are now baseline requirements. Links https://www.microsoft.com/en-us/security/blog/2026/07/jalisco-omegalord-phishing-kits https://cloud.google.com/blog/topics/threat-intelligence/gemini-jailbreak-c2-research https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html https://developer.joomla.org/security-centre.html https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse This briefing examines three concurrent threats that share a common vulnerability: neglected infrastructure. The NCSC and eight international partners issued a joint advisory on Russian state actors (FSB-linked Static Tundra and Berserk Bear) exploiting poorly configured network edge devices to establish persistent access in critical infrastructure. The same techniques work on any misconfigured router, including those deployed in UK SMEs. Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details, recalling the MOVEit compromise of 2023. Finally, Stormshield documented a phishing campaign impersonating DocuSign to install legitimate Remote Monitoring and Management tools (specifically Atera) as attacker infrastructure. Across all three incidents, the entry point is not sophisticated exploitation but basic configuration oversights: unchanged default credentials, unpatched firmware, unverified document signing workflows. UK small businesses using managed service providers, file transfer systems, or document signing tools face immediate exposure if they have not recently audited which remote access tools are authorised, verified router configurations, or trained staff to validate DocuSign notifications through the portal rather than email links. Chapters Introduction Mauven introduces three apparently unrelated threats that share a single operating principle: attackers exploiting unlocked doors rather than breaking through reinforced ones. Russian State Actors Targeting Network Edge Devices A nine-country joint advisory warns of FSB-linked actors exploiting misconfigured routers for persistent access. The technique works on any poorly configured device, not just critical infrastructure. UK SMEs must verify that default credentials are changed, remote management interfaces are disabled, and firmware is current. Call to Action Listeners are encouraged to follow the show and share it with others who need threat intelligence. Progress ShareFile Emergency Shutdown Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details. Given Progress’s MOVEit breach history, UK SMEs using ShareFile must immediately verify whether they are affected and document what data transits through the platform. DocuSign Impersonation and RMM Tool Abuse Stormshield documented a phishing campaign impersonating DocuSign to install legitimate RMM tools (Atera) as attacker infrastructure. Because the payload is legitimate software, endpoint detection often fails to flag it. UK SMEs must train staff to verify DocuSign notifications through the portal, maintain an authorised RMM tool list, and treat any DocuSign prompt requesting software installation as malicious. Conclusion The three threats share a common vulnerability: organisations have not recently audited their own infrastructure. The action item for UK SMEs is to verify router configurations, file transfer system deployments, and authorised RMM tools this week, not next quarter. Links https://www.ncsc.gov.uk/news/joint-advisory-russian-cyber-actors-targeting-network-edge-devices https://www.stormshield.com/news/docusign-phishing-campaign-deploys-atera-rmm/ https://www.ncsc.gov.uk/guidance/rm-tool-abuse https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors This episode examines three current UK cyber security incidents that share a troubling characteristic: all were preventable. Mauven MacLeod analyses the seven-step ransomware chain exploiting unpatched Citrix NetScaler appliances (CVE-2025-5777), documented by Huntress across multiple UK organisations. The briefing covers SilabRAT, a subscription-based Remote Access Trojan sold for £3,900 monthly that clones browser sessions to bypass multi-factor authentication, posing particular risk to finance teams and managed service providers. The episode also examines an NHS Forth Valley data breach caused by a misdirected email, representing the most common breach category reported to the ICO. Additional coverage includes GigaWiper destructive malware and active exploitation of Check Point VPN vulnerabilities (CVE-2026-50751) associated with Qilin ransomware. The analysis emphasises the systemic gap between awareness and action, providing specific verification steps for UK small and medium businesses. Chapters Introduction: The Common Thread of Prevention Failures Mauven introduces three unrelated but preventable security incidents affecting UK organisations with existing IT support and best-practice solutions. The episode examines systemic failures in closing known security gaps. CitrixBleed 2: Seven-Step Ransomware Chain Analysis of the seven-step attack chain exploiting CVE-2025-5777 in Citrix NetScaler appliances, documented by Huntress across multiple UK organisations. Covers the automated exploitation process, Dragonforce ransomware deployment, and the disproportionate risk to UK mid-market professional services firms. Call to Action Brief encouragement to follow the show and share with business owners who need threat intelligence briefings. SilabRAT: Credential Theft by Subscription Examination of SilabRAT Remote Access Trojan, available for £3,900 monthly, which clones browser profiles and sessions to bypass multi-factor authentication. Covers Hidden Virtual Network Computing capabilities, targeting of finance teams, and supply chain risks through compromised managed service providers. NHS Forth Valley: An Email Incident Without an Attacker Analysis of a maternity patient data breach at NHS Forth Valley caused by misdirected email, representing the most common breach category in ICO statistics. Discusses the need for documented verification processes before sending bulk emails containing sensitive data. On the Radar: GigaWiper and Check Point VPN Brief coverage of GigaWiper destructive malware and active exploitation of CVE-2026-50751 in Check Point Remote Access VPN since May 2026, associated with Qilin ransomware. Emphasises immediate patch verification requirements. Conclusion: The Gap Between Awareness and Action Summary emphasising that the common thread across all incidents is the failure to act on known risks. Provides specific action items for verifying patch status of NetScaler and Check Point VPN systems. Links https://www.huntress.com/blog/citrixbleed-2-seven-step-ransomware-chain https://www.group-ib.com/blog/silabrat-analysis/ https://www.theregister.com/2026/07/nhs-forth-valley-maternity-data-breach https://www.ncsc.gov.uk/guidance/email-security https://www.microsoft.com/en-us/security/blog/gigawiper-analysis https://www.checkpoint.com/advisories/cve-2026-50751
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways A delayed patch for the RoguePlanet zero-day in Windows Defender has finally arrived, but working exploit code was publicly available for weeks before Microsoft closed the vulnerability. Mauven examines what that exposure window means for UK SMBs and why confirming patch deployment today is not optional. The Vidar infostealer campaign has quietly evolved beyond phishing emails into developer toolchains, with malicious Go modules staged across more than two hundred GitHub repositories designed to appear credible and actively maintained. Socket’s Operation Muck and Load research reveals how attackers are using commit farming and typosquatting to compromise software supply chains, particularly targeting payment SDK names. Finally, the NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification that may reduce friction for smaller organisations pursuing verified assessment. Mauven explores what this policy shift signals about the growing expectation for Plus-level certification in public sector contracts and supply chain assurance. Three practical actions close the episode: verify the RoguePlanet patch has been applied, implement dependency verification for developers pulling open-source packages, and review the NCSC pathways guidance if you hold basic Cyber Essentials certification. Chapters Introduction Mauven previews three stories: a delayed zero-day patch, an infostealer campaign migrating into developer toolchains, and an underreported NCSC policy update with practical implications for UK small businesses. RoguePlanet Zero-Day Patched, Weeks Late Microsoft has patched the RoguePlanet zero-day in Windows Defender, but exploit code was publicly available for weeks before the fix arrived. Mauven explains the exposure risk, emphasises the urgency of confirming patch deployment, and advises reviewing any anomalous Defender behaviour during the vulnerability window. Mid-Episode CTA Mauven encourages listeners to follow the show and share Threat Analysis with colleagues who need daily UK threat intelligence briefings. Vidar Infostealer Moves Into Developer Supply Chains The Vidar infostealer campaign has evolved from phishing emails to compromising developer toolchains. Socket’s Operation Muck and Load research identified malicious Go modules staged across 222 GitHub repositories using commit farming to appear credible. Seventeen typosquatted packages targeting payment SDKs were published on 7 July. Mauven details practical verification steps for developers pulling open-source dependencies. NCSC Cyber Essentials Pathways The NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification. Mauven contextualises the policy update, explains why Plus certification is increasingly required for public sector contracts and supply chain assurance, and advises organisations holding basic certification to review the new pathways guidance. Closing Actions and Outro Mauven summarises three priority actions: confirm the RoguePlanet patch has been applied, brief developers on dependency verification, and read the NCSC Cyber Essentials Pathways blog. Closing remarks reinforce the importance of understanding vulnerability windows and consistent threat awareness. Links https://www.theregister.com/ https://asec.ahnlab.com/en/ https://unit42.paloaltonetworks.com/ https://socket.dev/ https://www.ncsc.gov.uk/blog-post/
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch Ubiquiti has released security updates addressing seven critical vulnerabilities in UniFi OS, including one rated CVSS 10.0 that permits unauthenticated remote code execution. The widespread deployment of UniFi hardware in UK small business networks makes this a priority patching event. Separately, CISA has added an Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies after confirming active exploitation in the wild. ColdFusion remains widely deployed in UK professional services, legal and accountancy firms, and public sector environments, often in legacy web applications where platform visibility is poor. Finally, an ongoing phishing campaign delivering AsyncRAT and Remcos trojans continues to target finance, procurement, and operations staff using macro-enabled Excel attachments and fileless execution techniques. Mauven MacLeod provides specific guidance on how to verify patching status with IT providers, configure email filtering to block macro-enabled attachments, and enforce Office macro policy across business environments. Chapters Introduction Mauven opens the eighth of July briefing with a direct question about firmware version awareness, highlighting seven critical Ubiquiti UniFi OS vulnerabilities including one rated CVSS 10.0, a CISA emergency patch order for Adobe ColdFusion, and an ongoing phishing campaign targeting finance and procurement staff. Ubiquiti UniFi OS: Seven Critical Flaws, One at Maximum Severity Seven critical vulnerabilities in Ubiquiti UniFi OS have been disclosed, including a CVSS 10.0 command injection flaw permitting unauthenticated remote code execution. Given the widespread deployment of UniFi hardware in UK SMB networks and typically flat network architectures, successful exploitation provides attackers with perimeter-level access. Mauven advises requesting written confirmation of firmware updates from IT providers or checking firmware versions directly if self-managed. Call to Action Mauven encourages listeners to follow the show and share the episode with others who may have unpatched Ubiquiti infrastructure. Adobe ColdFusion: Actively Exploited, CISA Emergency Patch Deadline CISA has added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies by the end of the week. The flaw permits remote code execution and is confirmed exploited in the wild. ColdFusion remains widely deployed in UK professional services, legal, accountancy, and public sector environments, often in legacy web applications with poor platform visibility. Mauven recommends requesting written confirmation of patching from hosting providers and suppliers. On the Radar: AsyncRAT and Remcos Phishing Campaign An ongoing phishing campaign delivers AsyncRAT and Remcos remote access trojans via macro-enabled Excel attachments, using fileless execution techniques including steganography to evade signature-based detection. The campaign specifically targets finance, procurement, and operations staff who routinely receive Excel files from external parties. Mauven recommends disabling macro execution by default, deploying Attack Surface Reduction rules, configuring email gateways to quarantine macro-enabled files, and briefing staff in targeted functions. Closing Summary Mauven summarises three actionable items: obtain written confirmation of UniFi firmware updates, verify ColdFusion patching status with suppliers, and enforce Office macro policy with appropriate email filtering. None require significant budget, only deliberate follow-through. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.ncsc.gov.uk/
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge This episode examines three active threat vectors affecting UK businesses in July 2026. First, a sophisticated Microsoft Teams impersonation campaign documented by Unit 42, in which attackers pose as IT helpdesk staff to deploy EtherRAT remote access trojans without requiring any technical vulnerability. Second, a global phishing operation delivering AsyncRAT and Remcos through multi-stage infection chains that use steganography and fileless execution to evade detection, targeting finance, HR, and procurement functions. Third, the UK government’s new voluntary cyber pledge, signed by sixty organisations including two currently managing recovery from significant recent breaches. The episode also covers UAT-7810’s operational relay box networks and the NCSC’s Cyber Shield initiative. Practical mitigations include restricting Teams external access, blocking Office macros by default, implementing helpdesk verification processes, and ensuring endpoint protection uses behavioural detection rather than signature matching alone. Each recommendation is actionable within the current week and addresses documented attack patterns actively being exploited against UK small and medium businesses. Chapters Introduction Overview of three stories: two active threats requiring immediate attention and one piece of UK government policy that merits closer examination beyond the press release. Teams Helpdesk Scam: EtherRAT Unit 42 research documenting attackers impersonating IT helpdesk on Microsoft Teams to deploy EtherRAT. The attack requires no technical vulnerability, only a helpful employee. Covers Teams external access configuration, verification processes, and remote access tool auditing. Call to Action Reminder to follow the show and share with colleagues who would benefit from daily threat intelligence. Multi-Stage Phishing: AsyncRAT and Remcos SpiderLabs research on global phishing delivering AsyncRAT and Remcos through Excel attachments, HTA scripts, PowerShell, and steganography-concealed payloads. Targets finance, HR, and procurement. Emphasises macro blocking and behavioural detection requirements. UK Cyber Pledge: Sixty Signatories Examination of the UK government’s voluntary cyber pledge signed by sixty organisations, including two currently managing recovery from significant breaches. Discusses the difference between pledges and contractual security requirements. UAT-7810 ORB Networks Cisco Talos research on operational relay box networks built using compromised small business infrastructure. Explains why edge device security matters beyond direct targeting. NCSC Cyber Shield NCSC blog post on Cyber Shield, a sovereign AI-driven cyber defence initiative. Distinguishes between national-scale infrastructure projects and immediate operational threats. Summary and Actions Prioritised action list: restrict Teams external access, block Office macros, communicate helpdesk verification policy, confirm behavioural detection capability, and review supplier security contracts. Links https://unit42.paloaltonetworks.com/ https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ https://www.ncsc.gov.uk/guidance/macro-security-for-microsoft-office https://blog.talosintelligence.com/ https://www.ncsc.gov.uk/blog-post/cyber-shield https://www.ncsc.gov.uk/
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score of 10.0, affecting legacy installations across SMB websites, internal applications, and shared hosting environments managed by MSPs. Second, a criminal group designated CL-CRI-1147 and tracked as Pink is conducting voice phishing campaigns that impersonate IT helpdesks to extract credentials and bypass multi-factor authentication. Once inside, the group exfiltrates data from SharePoint and OneDrive, then issues a seventy-two-hour ransom demand. The tactic closely mirrors operations by UNC3753, documented by Google Cloud Threat Intelligence. Both threats exploit different attack surfaces but share a common trait: neither discriminates by organisation size. Mauven provides specific procedural guidance for patching, MSP coordination, staff briefings on vishing, and audit log monitoring to detect bulk data downloads before ransom demands arrive. Chapters Introduction Mauven introduces two current threats facing UK small businesses: an actively exploited Adobe ColdFusion vulnerability and a criminal vishing operation. Both target SMBs without discrimination based on size or sophistication. Adobe ColdFusion CVE-2026-48282: Patch It Today, Not This Week Analysis of CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed under active exploitation. Covers CVSS 10.0 scoring, unauthenticated remote code execution, exposure through legacy systems and MSP-managed environments, and immediate patching requirements. Call to Action Brief audience prompt to follow the show and share the briefing with colleagues who need current threat intelligence. Pink (CL-CRI-1147): When the Threat Just Calls You Up Examination of the Pink criminal group’s vishing operation that impersonates IT helpdesks to extract credentials and bypass MFA. Details the exfiltration timeline, procedural defences, staff briefing requirements, and technical monitoring for SharePoint and OneDrive bulk downloads. The Pattern Worth Noting Structural analysis connecting the Adobe vulnerability, vishing campaigns, and emerging ClickFix malware ecosystem. All three exploit different attack surfaces but converge on the same principle: automated and human-driven threats do not filter targets by organisation size. Closing Summary of two actionable steps: verify and patch ColdFusion installations immediately, and brief staff on the vishing rule that IT will never request credentials or MFA approval by phone. Links https://www.bleepingcomputer.com/news/security/adobe-coldfusion-cve-2026-48282-exploited/ https://www.cyber.gc.ca/en/alerts-advisories https://cloud.google.com/blog/topics/threat-intelligence/unc3753-vishing-law-firms
Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown This briefing examines three significant threats to UK small and medium businesses in July 2026. First, Cisco Talos’s analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft 365 device code authentication flows to bypass multi-factor authentication. The technique, productised for affiliate use, requires immediate Conditional Access policy review. Second, Blackpoint Cyber’s documentation of Avalon, a multi-stage ransomware framework using spoofed legal documents, Proton Drive hosting, and memory-only execution to evade detection. Third, the NetNut botnet takedown by Google and the FBI, involving two million compromised residential devices used as proxy infrastructure. The operational implications extend beyond the headline: unpatched IoT devices and routers continue to provide access via vulnerabilities from 2017 and 2018. Each attack is designed to appear normal within legitimate business operations. The briefing provides three concrete actions: restrict device code authentication in Entra ID, establish verification procedures for password-protected archives, and audit firmware on internet-facing devices. These measures address the gap between assumed and actual security control effectiveness in small business environments. Chapters Introduction Mauven introduces three threat items for 3rd July 2026, prioritised by risk to UK SMBs. Two are active attack campaigns with direct exposure, one is a law enforcement action with under-reported operational implications. ARToken M365 Phishing Platform Analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft device code authentication flows. The technique bypasses MFA by abusing legitimate authentication processes. Direct mitigation requires restricting device code flows through Conditional Access policies in Entra ID. Call to Action Listener engagement prompt encouraging follows and sharing. Avalon Ransomware Framework Blackpoint Cyber’s analysis of Avalon, a multi-stage attack framework using spoofed legal documents hosted on Proton Drive, password-protected ISO archives, and memory-only execution. Targets professional services with plausible social engineering. Requires staff training, behavioural endpoint detection, and ISO mounting restrictions. The NetNut Botnet Takedown Google and FBI action against NetNut residential proxy botnet involving two million compromised devices. Discusses how compromised devices provide cover for credential stuffing and fraud, and notes active propagation of similar botnets via vulnerabilities from 2017 and 2018. Emphasises firmware update and credential hygiene on internet-facing devices. Broader Pattern Note All three threats share a common characteristic: they are designed to appear normal within legitimate business operations. The security gap lies between assumed and actual control effectiveness, closed through visibility rather than additional tools. Outro Closing summary with practical question for IT providers regarding Conditional Access policies. Sign-off and production credit. Links https://blog.talosintelligence.com/artoken-phishing-as-a-service/ https://www.blackpointcyber.com/resources/blog/avalon-a-new-ransomware-framework/ https://www.theregister.com/2026/07/02/google_fbi_netnut_botnet/ https://www.ncsc.gov.uk/collection/device-security-guidance https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17215 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8007
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat The Gentlemen ransomware group has emerged as a top-ten global threat actor by deploying zero-day driver exploits to disable endpoint security tools before launching encryption attacks. Using a vulnerable Kontron driver and the Bring Your Own Vulnerable Driver technique, the group neutralises detection systems silently, often gaining hours of undetected access through compromised VPN and firewall appliances. Meanwhile, the ARToken phishing-as-a-service platform automates Microsoft 365 account takeover through device code phishing and Primary Refresh Token persistence. Standard multi-factor authentication does not prevent these attacks, as the OAuth authentication flows are legitimate. The platform includes automated email and SharePoint exfiltration, plus integrated business email compromise tooling that industrialises payment redirection fraud. UK small businesses using Microsoft 365 face direct exposure, particularly in professional services, accountancy, and financial sectors where client data and payment processes rely on email systems. The NCSC has published guidance on restricting device code flow and monitoring for these attacks, yet implementation remains inconsistent even in critical national infrastructure environments. Chapters Introduction Overview of two urgent threat developments: a ransomware group defeating endpoint security and an automated Microsoft 365 phishing platform bypassing multi-factor authentication. The Gentlemen Ransomware Group and Zero-Day Driver Exploits Analysis of The Gentlemen’s rise to top-ten threat status through Bring Your Own Vulnerable Driver techniques, their use of a Kontron driver zero-day to disable endpoint protection, and their systematic approach to network reconnaissance and ransomware deployment. Call to Action Encouragement to share the briefing and subscribe for daily updates. ARToken: Automated Microsoft 365 Account Takeover Detailed examination of the ARToken phishing-as-a-service platform, its device code phishing methodology, Primary Refresh Token persistence, automated data exfiltration, and integrated business email compromise workflows that bypass standard MFA. NCSC Penetration Testing Findings Brief discussion of persistent security gaps identified in critical national infrastructure, including default credentials, insufficient segmentation, and poor patch management. Closing Recommendations Summary of immediate actions: enable tamper protection, verify monitoring procedures, restrict device code flow in Microsoft 365, and implement out-of-band payment verification. Links https://securelist.com/the-gentlemen-ransomware-group/ https://expel.com/blog/ https://www.ncsc.gov.uk/guidance/bring-your-own-vulnerable-driver https://blog.talosintelligence.com/artoken-phishing-as-a-service/ https://www.ncsc.gov.uk/guidance/device-code-flow https://www.ncsc.gov.uk/blog-post/pen-testing-critical-national-infrastructure
Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack Two critical threats demand immediate attention from UK small businesses today. First, the BlueHammer vulnerability in Microsoft Defender has transitioned from targeted zero-day attacks to commodity ransomware operations, a shift that dramatically expands the pool of threat actors capable of exploiting it. CISA’s addition of BlueHammer to its Known Exploited Vulnerabilities catalogue confirms active exploitation in the wild, with the flaw enabling attackers to escalate privileges to SYSTEM level and deploy ransomware across entire networks. Second, Blackpoint Cyber has documented an active intrusion chain exploiting CVE-2026-48558, an authentication bypass in SimpleHelp remote monitoring and management software. This attack vector is particularly concerning because it targets the tools IT providers use to manage client systems, turning the trust relationship between businesses and their managed service providers into an attack surface. The operational implication is clear: attackers are systematically exploiting the privileged access that IT management tools provide, bypassing direct targeting in favour of supply chain compromise. Patches exist for both vulnerabilities. The gap between availability and deployment is where ransomware operators operate. UK SMBs should contact their IT providers today to confirm patching status and ask specific questions about RMM tool security. This briefing provides actionable guidance on exactly what to ask and why it matters. Chapters Introduction Mauven introduces today’s two threat stories: the BlueHammer vulnerability in Windows Defender crossing into commodity ransomware operations, and an attack targeting remote management tools used by IT providers. BlueHammer: From Zero-Day to Ransomware Commodity Analysis of CISA’s KEV addition for BlueHammer, a privilege escalation flaw in Microsoft Defender now exploited in commodity ransomware operations. Covers the transition from targeted attacks to volume-based campaigns, the operational playbook of ransomware-as-a-service groups, and the practical patching actions UK SMBs must take immediately. CTA Brief call to action encouraging listeners to follow the show and share it with business owners and operations managers who need actionable threat intelligence. SimpleHelp RMM: The Attack That Comes Through Your IT Provider Detailed examination of CVE-2026-48558, an authentication bypass in SimpleHelp remote monitoring and management software. Explains how attackers exploit RMM tools to gain technician-level access to managed client systems, the malware deployed (TaskWeaver and Djinn Stealer), and the supply chain risk this represents for UK SMBs. What UK SMBs Should Do Today Direct, actionable guidance for UK small businesses: specific questions to ask IT providers about BlueHammer patching, SimpleHelp vulnerability status, RMM access log reviews, and incident disclosure processes. Outro Closing summary emphasising the gap between patch availability and deployment, urging businesses to actively verify patching status with their IT providers rather than assume it has been handled. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://securelist.com/gentlemen-raas-h1-2026/ https://www.blackpoint.io/blog/simplehelp-rmm-exploitation-cve-2026-48558
Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild Oracle E-Business Suite vulnerability CVE-2026-46817 is under active exploitation, with confirmed activity from threat intelligence firm Defused. Nissan’s recent breach of its Oracle PeopleSoft instance underscores the broader risk to Oracle’s enterprise portfolio. UK small businesses face exposure through supply chain relationships with payroll bureaus, accountancy firms, and manufacturers running Oracle systems. Meanwhile, newly documented threat actor DriveSurge operates a pay-per-install initial access broker model, compromising legitimate websites to deliver malware through fake browser updates and ClickFix social engineering. The campaign bypasses email security controls entirely, infecting users through normal web browsing. Additional concerns include active exploitation of Langflow (CVE-2026-55255) and the Miasma Mini Shai-Hulud supply chain campaign now targeting Backstage npm packages. Today’s briefing provides specific, actionable steps: verify Oracle patch status with suppliers, implement web filtering against zTDS infrastructure, brief staff on fake browser update prompts, and audit dependencies in development pipelines. These are email-and-call actions, not budget-heavy projects. Chapters Introduction Mauven opens with two active threat stories: exploitation of Oracle E-Business Suite and a drive-by attack campaign bypassing email controls through compromised websites. Both pose immediate risks to UK small businesses through supply chain and web browsing vectors. Oracle EBS Active Exploitation CVE-2026-46817 in Oracle E-Business Suite is under confirmed exploitation. Nissan’s PeopleSoft breach demonstrates sustained threat actor attention to Oracle’s enterprise platforms. UK small businesses face exposure through payroll bureaus, accountancy firms, and manufacturers. Practical steps include verifying patch status directly with suppliers and documenting responses in writing. Mid-Roll Call to Action Brief listener prompt to follow the show and share the briefing with relevant contacts. DriveSurge Drive-By Campaign DriveSurge, a newly documented initial access broker, compromises legitimate websites to deliver malware via fake browser updates and ClickFix prompts. The campaign uses zTDS traffic distribution and bypasses standard email security. Recommended defences include web filtering against zTDS infrastructure and staff briefing on fake update prompts. Langflow and Miasma Mini Shai-Hulud Updates CVE-2026-55255 in Langflow is under active exploitation, with lower-scored CVE-2026-33017 seeing wider use due to easier exploitation. The Miasma Mini Shai-Hulud campaign now targets Backstage npm packages. Organisations using AI frameworks or modern CI/CD pipelines should audit patch status and dependencies. Closing Summary Mauven summarises practical actions in order of urgency: verify Oracle patch status with suppliers, brief staff on fake browser updates, confirm web filtering covers zTDS, and audit development dependencies. All actions require communication and follow-up, not significant budget. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.ncsc.gov.uk/collection/supply-chain-security https://www.oracle.com/security-alerts/cpujun2026.html https://silentpush.com/blog/drivesurge-campaign https://sysdig.com/blog/langflow-cve-exploitation https://socket.dev/blog/miasma-mini-shai-hulud-backstage
Understanding Mini Shai-Hulud and Cisco’s Zero-Day Vulnerabilities In today’s episode of Threat Analysis, Mauven MacLeod delves into two significant cybersecurity threats impacting UK small and medium businesses. The Mini Shai-Hulud supply chain attack targets the development community by exploiting npm packages, risking developers’ credentials and threatening software integrity. Microsoft emphasises the importance of rigorous dependency audits to prevent malicious exploitation. Additionally, a zero-day vulnerability CVE-2026-20245 in Cisco’s Catalyst SD-WAN Manager is discussed. This allows attackers to escalate privileges through default passwords, compromising network security. The necessity of proactive cybersecurity measures, including multi-factor authentication and robust monitoring systems, is highlighted to safeguard businesses from these threats. Chapters Intro Mauven introduces the episode, highlighting critical threats for UK businesses. Mini Shai-Hulud Supply Chain Attack Discusses how Mini Shai-Hulud uses npm packages to access developer credentials, emphasising the need for vigilant software audits. CTA Encourages listeners to follow the show for updates and share with peers. CVE-2026-20245: Cisco’s Zero-Day Explores the Cisco vulnerability, stressing the dangers of default passwords and the importance of intrusion detection systems. Outro Reiterates the importance of proactive cybersecurity measures and invites listeners to return for future episodes. Links https://www.microsoft.com/security/blog https://www.cisco.com/security/advisories https://blog.npmjs.org
Emerging Cyber Threats to UK SMEs In this episode of Threat Analysis, Mauven MacLeod dives into two pressing cybersecurity threats affecting UK small and medium businesses. The first is the Mistic backdoor, linked to the notorious Woodgnat, which employs the cunning technique of sideloading. This method uses legitimate software to conceal malicious activity, posing significant risks such as data leaks and financial loss. Mauven discusses the importance of a robust security posture and offers practical advice on staying protected. The second threat is the widespread FortiBleed campaign targeting Fortinet FortiGate devices through advanced techniques like credential stuffing and password spraying. The campaign highlights vulnerabilities found in legacy systems and underscores the need for up-to-date device management and strong authentication protocols. Listeners are encouraged to assess and fortify their cybersecurity defences actively. The episode closes with a reminder: awareness is key, but proactive measures are essential to safeguarding your business. Chapters Intro Mauven introduces today’s cybersecurity topics, focusing on threats to UK businesses. Mistic Backdoor Unveiled Discussion on the Mistic backdoor’s impact, sideloading techniques, and security recommendations. CTA Listeners are encouraged to follow the podcast and share it with others. FortiGate Under Siege Analysis of the FortiBleed campaign targeting Fortinet devices, with tips to enhance network security. Outro Recap of the threats discussed and a call to take proactive security measures. Links https://arcticwolf.com/resources/blogs https://www.fortiguardlabs.com https://www.ncsc.gov.uk
Understanding the Mistic Backdoor Threat to UK SMBs In this episode of Threat Analysis, Mauven MacLeod explores the emerging threat landscape for UK small and medium businesses, focusing on the Mistic backdoor. This malware, linked to the ransomware access broker KongTuke, poses significant risks to crucial sectors such as insurance, education, IT, and professional services. The discussion highlights how Mistic operates stealthily within compromised systems, bypassing many traditional security measures and exacerbating vulnerabilities in supply chains. Additionally, the episode delves into broader cybersecurity concerns, including the critical vulnerability CVE-2026-20230 in Cisco Unified Communications Manager and privacy issues arising from London’s use of live facial recognition technology. Mauven provides actionable steps for SMBs to strengthen their defences, emphasising the importance of robust vendor audits, advanced threat detection, and well-prepared incident response plans, aligning with guidance from the National Cyber Security Centre. Chapters Intro Mauven introduces the focus on the Mistic backdoor and its relevance to UK SMBs. Mistic Backdoor Threat Exploration of the Mistic backdoor’s tactics, connection to KongTuke, and its impact on key sectors. The Broader Context Discussion on Cisco’s vulnerability and the implications of facial recognition technology in London. What Should You Do? Actionable cybersecurity measures for SMBs, including vendor audits and threat detection enhancements. CTA Encouragement to follow the show and share it with others needing the briefing. Outro Summary of today’s insights and the importance of proactive cybersecurity strategies. Links https://www.bleepingcomputer.com https://theregister.com
Klue Supply Chain Breach and AI Cybersecurity Warnings In this episode of Threat Analysis, Mauven MacLeod explores a pressing supply chain attack that targets Salesforce environments through Klue’s backend systems. The breach, executed by the Icarus threat group, highlights the vulnerabilities of OAuth tokens and the implications for UK small businesses. Mauven discusses the importance of reviewing security practices to prevent data exposure. The episode also features a warning from the Five Eyes alliance about the potential risks associated with AI in cybersecurity. As AI technology evolves, safeguarding against its misuse becomes crucial. Tune in for essential insights and strategies to navigate these challenges. Chapters Intro Mauven introduces the focus on a crucial supply chain attack and AI-related cybersecurity threats. Klue Supply Chain Attack Hits Salesforce Environments Details the Icarus group’s attack on Klue, impacting Salesforce and the importance of OAuth token security. CTA Encourages listeners to follow the show for regular updates on cybersecurity threats. Five Eyes Warn of AI Escalating Cybersecurity Threats Highlights the Five Eyes alliance’s warning on AI exacerbating cybersecurity threats and the need for robust oversight. Outro Concludes with the interconnected nature of modern business threats and the importance of enhanced security measures. Links https://www.salesforce.com/news/stories/understanding-oauth-security/ https://www.techradar.com/news/lastpass-breach-what-you-need-to-know https://www.cisa.gov/news/five-eyes-cybersecurity
Key Cyber Threats Impacting UK Businesses Join Mauven MacLeod for today’s Threat Analysis, a briefing focused on the latest cyber threats facing UK businesses. The episode covers the sophisticated attack on 3CXDesktopApp, which exploits supply chain vulnerabilities through trojanised installers. We also delve into the FortiBleed campaign, highlighting the increased risk posed by attacks on Fortinet FortiGate firewalls. The AryStinger botnet is examined, demonstrating how outdated hardware can become a security liability. Finally, the episode discusses AI risks, emphasised by recent NCSC publications, underscoring the evolving role of AI in cybersecurity. Stay informed to protect your business from these modern threats. Chapters Intro Introduction to key cyber threats impacting UK businesses. 3CXDesktopApp Intrusion Discussion on trojanised installers and supply chain vulnerabilities. CTA Encouragement to follow and share the podcast for daily updates. FortiBleed Campaign Examination of attacks on Fortinet firewalls and SSL VPN gateways. AryStinger Botnet Analysis of the botnet hijacking outdated D-Link routers. AI Risks Exploration of AI’s role in cybersecurity and related threats. Outro Summary and emphasis on staying informed about cyber threats. Links https://www.ncsc.gov.uk
Active Splunk Exploit and npm Supply Chain Campaign CISA has confirmed active exploitation of a critical Splunk Enterprise vulnerability, with a patch deadline of 22 June 2026 for US federal agencies. UK organisations face the same threat but lack a legal mandate. Separately, over 140 npm packages in the mastra ecosystem were compromised through account takeover, pushing typosquatted dependencies that harvest credentials on installation. A second npm attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating SSH keys and cloud credentials via DNS. A third attack targeted PyPI’s Microsoft DurableTask client through a stolen GitHub account. The Okendo Reviews widget, used by over 18,000 e-commerce brands, was also found to contain malicious JavaScript in May 2026. These attacks share a common thread: patient exploitation of trust frameworks in developer tooling and monitoring platforms. Mauven provides actionable steps for UK businesses to verify patch status, audit dependency chains, review DNS monitoring capability, and confirm e-commerce widget remediation before the weekend. Chapters Intro Mauven introduces two active threats requiring immediate attention: a CISA advisory on exploited enterprise software and a coordinated developer ecosystem compromise campaign. Response capability drops over weekends, making Friday advisories particularly dangerous. npm Supply Chain Surge Microsoft Threat Intelligence confirmed compromise of over 140 npm packages via account takeover, pushing typosquatted dayjs dependency. A second attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating credentials via DNS. A third targeted PyPI’s DurableTask client. Okendo Reviews widget injected with malicious JavaScript in May 2026 affected 18,000 e-commerce brands. CTA Listener call to action: follow the show and share with colleagues who need threat intelligence. Splunk Enterprise Under Active Exploit CISA added Splunk Enterprise vulnerability to KEV catalogue with 22 June 2026 patch deadline for US agencies. UK organisations lack legal mandate but face identical risk. Compromised monitoring platforms allow attackers to suppress alerts and manipulate log data from a trusted internal position. ICO Leadership Change John Edwards resigned as Information Commissioner. Leadership transition creates institutional uncertainty around enforcement priorities, though legal obligations remain unchanged. What To Do Before Monday Immediate actions: verify Splunk patch status, audit recent npm and PyPI package updates, confirm Okendo widget remediation if present in May 2026, and implement or plan outbound DNS monitoring to close exfiltration blind spots. Outro Attackers exploit trust in packages, monitoring tools, and institutional frameworks. They are patient, sophisticated, and aware that Friday advisories are often deferred. Do not give them the weekend. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.ncsc.gov.uk/collection/supply-chain-security
DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch Three active threats demand immediate attention from UK small and medium businesses. Symantec researchers have documented DragonForce ransomware concealing command-and-control infrastructure inside Microsoft Teams relay servers using a custom backdoor that exploits anonymous visitor tokens. The intrusion evaded detection for over two weeks by routing malicious traffic through legitimate Microsoft infrastructure. CISA has added a maximum-severity Joomla Content Editor vulnerability (CVE-2024-43233) to its Known Exploited Vulnerabilities catalogue, confirming active exploitation of an unauthenticated remote code execution flaw widely present in UK business websites. A publicly disclosed privilege escalation zero-day in Microsoft Defender, named RoguePlanet, remains unpatched while attackers actively deploy footholds through phishing and social engineering campaigns. Mauven examines why perimeter defences cannot catch infrastructure-layer threats, what behavioural anomaly monitoring actually means in practice, and why patch management discipline should not depend on regulatory deadlines. This briefing provides specific technical actions for Joomla users, questions to ask managed security providers, and interim controls for the Defender zero-day. Chapters DragonForce Conceals Command Infrastructure Inside Microsoft Teams Symantec documents a two-week ransomware intrusion using custom malware to route attacks through Microsoft Teams relay servers, evading perimeter defences by hiding inside legitimate traffic. The technique exploits TURN servers and anonymous visitor tokens, requiring behavioural anomaly monitoring rather than edge security to detect. CISA Adds Maximum-Severity Joomla Vulnerability to Exploitation Catalogue CVE-2024-43233, a CVSS 10.0 unauthenticated remote code execution flaw in the Joomla Content Editor plugin, is under active exploitation. The vulnerability affects a widely deployed extension common in UK small business websites. CISA has set a Friday patch deadline for federal agencies. RoguePlanet Privilege Escalation Zero-Day in Microsoft Defender Remains Unpatched A publicly disclosed privilege escalation vulnerability in Microsoft Defender, part of the Nightmare Eclipse research chain, has no available patch. Microsoft has confirmed work is underway. The flaw enables attackers who gain initial access through phishing or social engineering to escalate to full system control on Windows endpoints. Priority Actions and Patch Management Discipline Immediate actions include checking and patching Joomla JCE installations, asking managed security providers about internal anomaly monitoring capabilities, and applying least privilege controls while awaiting the Defender patch. A brief note covers an updated Cisco SD-WAN advisory affecting additional device models. Links https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.ncsc.gov.uk/
DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites Three critical threats demand immediate attention from UK small businesses today. DragonForce ransomware has deployed a custom backdoor that tunnels command-and-control traffic through Microsoft Teams relay infrastructure, exploiting implicit trust in cloud services. Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are being actively exploited in the wild, raising serious questions for businesses relying on managed security providers. Meanwhile, over 1.2 million WordPress sites have been compromised through a supply chain attack targeting OptinMonster, TrustPulse, and PushEngage plugins. CISA has also added a critical LiteSpeed cPanel vulnerability to its Known Exploited Vulnerabilities catalogue, affecting countless UK websites on shared hosting. Mauven MacLeod walks through the behavioural and operational gaps these threats expose, and provides four concrete actions businesses can take today: checking FortiSandbox patch status with managed security providers, verifying LiteSpeed plugin updates with hosting providers, auditing WordPress admin accounts, and reviewing Microsoft Teams external tenant access configurations. None of these actions require large budgets, but all require the willingness to ask direct questions of service providers. Chapters DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites Mauven introduces three urgent threats: a sophisticated backdoor exploiting Microsoft Teams infrastructure, critical Fortinet vulnerabilities being actively exploited, and a WordPress supply chain attack compromising over a million sites. She explains why DragonForce’s Backdoor.Turn tool exploits implicit trust in Microsoft Teams relay traffic, details the pattern of Fortinet security product vulnerabilities, covers CISA’s urgent warning on LiteSpeed cPanel flaws, and reveals a supply chain attack through Awesome Motive’s CDN affecting OptinMonster, TrustPulse, and PushEngage plugins. The briefing concludes with four immediate actions: checking FortiSandbox patch status, verifying LiteSpeed updates, auditing WordPress admin accounts, and reviewing Teams external access settings. Links https://www.ncsc.gov.uk/collection/cloud-security https://defused.com/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://sansec.io/
One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation Two critical vulnerabilities demand immediate attention from UK businesses today. Researchers have disclosed SearchLeak, a prompt injection vulnerability chain in Microsoft 365 Copilot Enterprise that allows attackers to steal data from mailboxes, OneDrive, and SharePoint with a single malicious link. The attack exploits Copilot’s AI assistant functionality to exfiltrate sensitive information without further user interaction. Meanwhile, Cisco Talos reports active exploitation of authentication bypass vulnerabilities in Cisco Catalyst SD-WAN infrastructure by the sophisticated threat actor UAT-8616, who is deploying multiple command-and-control frameworks including Sliver and Godzilla for persistent network access. Most UK SMBs don’t run SD-WAN directly but face indirect exposure through managed service providers. Both threats target infrastructure that organisations trust by default but rarely examine closely. The episode provides specific verification steps for IT providers and MSPs, emphasising the gap between vendor patches and organisational verification as the primary source of security incidents. Chapters Introduction Mauven opens with an urgent warning about a one-click data theft vulnerability affecting Microsoft 365 Copilot Enterprise users, then previews coverage of active Cisco SD-WAN exploitation. SearchLeak: M365 Copilot as a Data Theft Tool Analysis of the SearchLeak vulnerability chain in Microsoft 365 Copilot Enterprise. The prompt injection attack allows attackers to use specially crafted URLs to instruct Copilot to search and exfiltrate data from mailboxes, OneDrive, and SharePoint. Microsoft has patched the vulnerability, but verification of deployment through MSPs is critical. Recommendations include confirming patch status, reviewing Copilot licence assignments, applying least privilege access controls, and exercising caution with links triggering Copilot interactions. Call to Action Reminder to follow the show and share with colleagues who need daily threat intelligence. Cisco SD-WAN: Active Exploitation by UAT-8616 Cisco Talos reports active exploitation of CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Controller and Manager. The sophisticated threat actor UAT-8616 is deploying Sliver, Godzilla, AdaptixC2, and Behinder for persistent access to network infrastructure. Most UK SMBs face indirect exposure through managed service providers running this infrastructure. Actions include immediate patching for direct users, verification calls to MSPs regarding their infrastructure and patching status, contract review for incident disclosure terms, and monitoring for anomalous routing changes. Supply Chain Pressure Continues Brief coverage of Arch Linux locking down AUR signups after malicious commits, and Unit 42 analysis of updated obfuscation techniques in Gremlin Stealer infostealer targeting browser credentials. Closing Mauven emphasises that both threats target infrastructure organisations trust without close examination. Final action items: contact IT providers or MSPs to verify M365 patch status and Cisco SD-WAN infrastructure security posture. Links https://www.cisco.com/c/en/us/support/web/security-advisories.html https://www.ncsc.gov.uk/
AI Phishing, Clinical Data Theft, and the CC Field Mistake Mauven MacLeod examines three incidents that illustrate how UK businesses are actually compromised in 2026. Google has sued a Chinese phishing operation selling AI-generated SMS fraud toolkits via Telegram, producing messages now indistinguishable from legitimate communications. Novo Nordisk disclosed that attackers accessed pseudonymised clinical trial data after a phishing email breach, demonstrating that even large pharmaceutical firms remain vulnerable. Plymouth City Council exposed hundreds of email addresses by using CC instead of BCC in a message to families, triggering an ICO report. Across all three stories, the common thread is not sophisticated exploits but phishing, human error, and procedural failure. Mauven walks through practical mitigations: phishing-resistant MFA, link-checking tools, verification protocols for payment requests, tested incident response plans, least-privilege access for special category data, and using proper email platforms instead of manual BCC. The episode also notes Microsoft’s resolution of a year-long Windows update deployment issue affecting centrally managed devices. None of these threats require nation-state resources. All of them are preventable with controls that already exist in published guidance. Chapters Introduction Mauven opens the 12 June 2026 briefing, noting that all three stories involve phishing or human error rather than exotic threats. Google Sues AI Phishing Operation Google has filed suit against Outsider Enterprise, a Chinese group selling AI-generated phishing toolkits via Telegram. AI now produces messages indistinguishable from legitimate communications. Mauven explains why traditional awareness training is failing and recommends phishing-resistant MFA, link-checking tools, verified callback protocols, and low-friction reporting processes. Novo Nordisk Clinical Data Breach Novo Nordisk disclosed that attackers accessed pseudonymised clinical trial participant data following a phishing email. Mauven emphasises that size is no defence, walks through UK GDPR notification requirements for special category data, and urges tested incident response plans, least-privilege access, and documented data protection contacts. Plymouth Council CC Field Error Plymouth City Council exposed hundreds of email addresses by using CC instead of BCC in a message to home-schooling families, then reported the breach to the ICO. Mauven explains Article 33 notification obligations and recommends process defaults, email marketing platforms, and brief team training. Windows Update Fix Microsoft resolved a known issue preventing Windows updates from installing via network share since May 2025. Unpatched devices remain a ransomware entry point. Closing Summary Mauven recaps the common thread across all stories and urges listeners to verify their suspicious message reporting loop. Promotes the Daily Threat Analysis Substack, Corrine Jefferson’s Daily CVE Update, and Graham Falkner’s practical security assessments. Links https://blog.thesmallbusinesscybersecurityguy.co.uk https://www.ncsc.gov.uk/guidance/phishing https://www.bleepingcomputer.com https://www.theregister.com https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-data-breaches/ https://www.ncsc.gov.uk/guidance/bulk-email