๐ง Subscribe to the podcast feed
Security News
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register) โ A working proof-of-concept exploit for CrowdStrike Falcon has been published by a well-known vulnerability researcher; given Falcon's kernel-level privileges, this is a high-priority exposure for enterprise environments.
Coder's registry infrastructure compromised to push malicious modules (BleepingComputer) โ Attackers compromised the Coder package registry to distribute malicious modules, continuing the trend of supply chain attacks targeting developer tooling and build pipelines.
ASCII smuggling crosses over from AI prompt injection to phishing evasion (Microsoft Security Blog) โ A technique originally developed for AI prompt injection โ using invisible Unicode characters to hide instructions โ has been adapted for phishing campaigns that bypass email security filters.
Large group of Serbian opposition, activist figures targeted with spyware (The Record) โ A broad targeting campaign using Pegasus spyware has been identified against Serbian opposition politicians and civil society activists, raising further concerns about commercial spyware abuse in Europe.
HPE patches critical ArubaOS-CX remote code execution flaw (BleepingComputer) โ HPE has released a patch for a critical RCE vulnerability in ArubaOS-CX; organisations running Aruba network switching infrastructure should prioritise this update.
Cisco searched for IOS XR bugs and found so many it rolled them into an update release (The Register) โ Cisco proactively audited IOS XR and discovered enough vulnerabilities to warrant a dedicated bundled release, highlighting the ongoing complexity debt in legacy network operating systems.
Did ShinyHunters breach ReliaQuest? (Dark Reading) โ An investigation is underway into whether threat group ShinyHunters compromised ReliaQuest, a managed security provider โ a sensitive target given the visibility MSPs have into their clients' environments.
French hospital fined โฌ500,000 after breach exposes data of 727,000 (BleepingComputer) โ France's CNIL fined Hรดpital privรฉ de la Loire โฌ500K following a 2025 breach that exposed data of over 727,000 patients and third parties, including health records.
Large enterprises targeted in fake Merger & Acquisition scams (Dark Reading) โ Sophisticated social engineering campaigns impersonating M&A advisors and financial executives are being used to extract wire transfers and sensitive deal documentation from large organisations.
OpenAI commits $1B in AI credits to frontline cyber defenders (The Register) โ OpenAI has pledged one billion dollars in AI compute credits to cybersecurity defenders, with a focus on smaller teams, non-profits, and threat intelligence organisations.
UK & Critical National Infrastructure
No UK-specific cyber incidents in today's 48-hour window, and no new NCSC advisories have been issued. However, the most CNI-relevant story for UK defenders is the CrowdStrike Falcon exploit proof-of-concept. CrowdStrike is deeply embedded across UK critical national infrastructure โ financial services, utilities, and government contractors โ and a working exploit for the endpoint agent itself represents a significant potential exposure at kernel level. UK security teams should monitor CrowdStrike's response and apply any guidance or patches immediately.
The energy sector targeting by direwolf (PTT Oil, Thailand) and Storm (Petrocare Construction, Canada) is also a continued reminder that CNI attack surface extends to suppliers and international partners. UK energy and transport operators with cross-border supply chain dependencies should review third-party exposure accordingly.
Ransomware Victims (48h)
20 victims ยท 9 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| direwolf | Cartrack Holdings | ๐ฟ๐ฆ ZA | Transportation |
| direwolf | PTT Oil and Retail Business | ๐น๐ญ TH | Energy & Utilities โ ๏ธ |
| incransom | myglobal.com | ๐ฒ๐พ MY | Other |
| insomnia | N*************** | ๐บ๐ธ US | Unknown |
| krybit | ligacancerguate.org (INCAN) | ๐ฌ๐น GT | Healthcare โ ๏ธ |
| medusalocker | Licindia | ๐ฎ๐ณ IN | Other |
| Panzer | Dinas Komunikasi dan Informatika | ๐ฎ๐ฉ ID | Government & Defense |
| qilin | Uak University | ๐น๐ท TR | Education |
| SilentRansomGroup | Katten Muchin Rosenman | ๐บ๐ธ US | Professional Services |
| SilentRansomGroup | P... S... | โ | Redacted |
| SilentRansomGroup | A...en | ๐ฉ๐ช DE | Redacted |
| SilentRansomGroup | Greenberg Traurig | ๐บ๐ธ US | Professional Services |
| SilentRansomGroup | G... ...g | โ | Redacted |
| SilentRansomGroup | S... M... | โ | Redacted |
| Storm | Petrocare Construction | ๐จ๐ฆ CA | Energy & Utilities โ ๏ธ |
| Storm | GSAC Auto Financing | ๐บ๐ธ US | Financial Services |
| Storm | Star Aviation, Inc | ๐บ๐ธ US | Transportation |
| Vexy Ransomware | McDonald's Ecuador | ๐ช๐จ EC | Hospitality |
| Wallstreet | America's Food Basket | ๐บ๐ธ US | Retail & E-Commerce |
| Wallstreet | Ormond Beach Florida | ๐บ๐ธ US | Municipal |