This week

- Medusa ransomware gang tries to turn a BBC cyber correspondent
- Hundreds of Red Hat customer environment details stolen
- Oracle customers receiving extortion demands via email
- Home Office submits new TCN to Apple targeting British users
- US Government shutdown impact on CISA, cyber schemes
Interesting stats
75% of UK transatlantic internet traffic comes ashore via two cables in Bude, Cornwall (see Policy & Regs, below).
4% of UK goods exports are produced by JLR. LINK
1% of companies say they’re ‘completely ready’ for the US DOD’s new Cybersecurity Maturity Model Certification (CMMC) scheme, which takes effect in just over a month. LINK
Five things
-
“We can retire you”: Representatives of the Medusa ransomware gang tried to pressure a BBC Cyber correspondent into acting on their behalf. Joe Tidy thinks that the cybercriminals mistook his ‘Cyber Correspondent’ role for someone in the IT or security teams with privileged access. Instead, Tidy led the group along for a few days to understand how they operated, then published his findings on the BBC News website. The group initially offered Tidy 15% of whatever ransom they achieved, before revising this up to 25% and offering to escrow a £55,000 down payment, sums that the criminals said would ‘retire him’. It’s an interesting insight into how some groups are attempting to gain access to their targets’ environments. INSIDER THREAT
-
Red Hat: A group calling itself the ‘Crimson Collective’ claims to have gained access to Red Hat’s private GitLab repositories and stolen 570GB of data. The group claims to have accessed over 28,000 repositories and gained access to hundreds of ‘Customer Engagement Reports’, which typically contain details of how customer environments are configured. (See also Red Hat’s critical vulnerability, below.) RED HAT
-
Oracle: Google says that actors linked to the Clop ransomware gang are attempting to extort Oracle customers. Cybercriminals are sending emails to business leaders claiming to have stolen data from Oracle’s E-Business Suite relating to their organisation. In one instance, the attackers reportedly demanded $50 million. In a brief blog post, Oracle states that it’s aware of the emails and that its ongoing investigation has identified the potential use of previously disclosed vulnerabilities. ORACLE (BLOG POST)
-
Apple vs Home Office: FT sources say the UK government has issued a new ‘technical capability notice’ to Apple, demanding it create a “backdoor” to access encrypted iCloud data. Whereas a widely reported previous request from January sought global access, this new order specifically targets the data of British users only. A spokesperson for Apple said the company is “gravely disappointed that the protections provided by ADP are not available to our customers in the UK”, before reiterating that Apple has “never built a back door or master key to any of our products or services and we never will.” The reference to ADP (Advanced Data Protection) is a feature Apple disabled for UK users earlier this year, widely seen as a ‘canary in the coal mine’ as it is not allowed to discuss details of TCNs. January’s TCN put the UK and US governments in a diplomatic spat before it was “dropped”. Creating such a backdoor in encryption would presumably weaken the security of all Apple users globally, unless separate software were deployed. This is still a mess. I expect Apple to appeal the notice again. FT (ALTERNATIVE), MORE
-
US Government shutdown: Congressional leaders were unable to agree on a deal for US federal funding, resulting in a shutdown of the US government, which has some knock-on cyber security impacts. The Cybersecurity and Infrastructure Security Agency (CISA) has furloughed 65% of its 2,500 staff this week. The ~900 that remain at work (but without pay) are mostly focused on national security and in detection and response roles. The Cybersecurity Information Sharing Act (abbreviated as CISA 2015), which provides protections to businesses sharing cyber threat information, has expired. Also, the State and Local Cybersecurity Grant Program, which provides $1 billion in funding to state and local organisations to protect critical infrastructure, expired. FURLOUGH, CISA & GRANTS
In brief
-
⚠️ Incidents: A battery fire at a data centre in Daejeon, South Korea, took out 647 government websites. Two Dutch teens have been arrested on suspicion of ‘state interference’ by carrying wi-fi sniffers for Russia threat actors near Europol and Eurojust sites. Harrods has disclosed a second data breach this year, with attackers making off with 430,000 customer records and ‘sensitive e-commerce information’ from a third-party. Afghan authorities have shut down internet and mobile services, disconnecting millions of residents and businesses. Canadian airline WestJet has confirmed that threat actors stole the information of 1.2 million people during a June security incident: names, contact info, and some reservation information were taken; no credit card or account credentials were compromised. Motility, a US software company that develops software used by approximately 7,000 car dealerships, appears to have suffered an incident that resulted in the exposure of sensitive information belonging to 766,000 individuals. Sticking with the automotive sector, Renault in the UK is warning customers of a breach at one of its suppliers, with names, genders, phone numbers, emails, addresses, and vehicle registrations all potentially exposed. FIRE, WI-FI, HARRODS, AFGHANISTAN, WESTJET, MOTILITY, RENAULT
-
🏴☠️ Ransomware: Scattered LAPSUS$ Hunters has created a leak site claiming it stole around 1 billion customer records from Salesforce customers. The series of breaches, via vendor Salesloft, has been gaining headlines in recent months, and now the attackers appear to be escalating their demands on the victims to pay up. Japan may be days away from running out of Asahi beer, after the brewery suffered a ransomware attack that halted its operations in the country. SALESFORCE, ASAHI
-
🕵️ Threat Intel: Okta says North Korea is expanding its IT worker scheme to target AI, finance, and healthcare organisations outside of the US. NK IT WORKER
-
🪲 Vulnerabilities: Intel and AMD CPUs paired with DDR4 RAM are vulnerable to physical attacks —dubbed Battering RAM and Wiretap — due to their use of deterministic, rather than probabilistic encryption techniques. Given the pre-requisites, I suspect this isn’t something many people will need to worry about, but it’s cool, deep, geeky research if you’re into that kinda thing. Red Hat’s OpenShift AI service has a critical vulnerability (CVE-2025-10725; 9.9/10) that allows an account with ‘minimal privileges’ to steal data, disrupt services, and control the system. INTEL/AMD, RED HAT (ADVISORY)
-
🧑💻 End user and consumer: Google Drive’s desktop client is getting AI-powered ransomware detection, and will pause syncing, protecting files synchronised to the company’s cloud storage. GOOGLE DRIVE
-
🏭 Operational technology: NCSC, in collaboration with Australian, US, Canadian, New Zealand, Netherlands, and German peers, has released OT security guidance built around five principles: maintaining a ‘definitive record’ of systems; establishing an OT ISMS; taking risk-based decisions; documenting connectivity; and understanding third-party risk scenarios. OT GUIDANCE
-
🧿 Privacy: US Senator Ted Cruz was the sole objector and blocker to a bipartisan bill that would have extended privacy protections afforded to lawmakers to every US citizen. Cruz claimed — without evidence — that the bill would prevent law enforcement from sharing information on pedophiles, while the bill permits and exempts police and the press, respectively, from carrying out the exact activities Cruz was objecting to. CRUZ
-
📜 Policy & Regulation: A parliamentary committee says the UK is “too timid” in protecting subsea cables. Suspicious activity around subsea cables and vessels dragging their anchors, resulting in significant damage, has been a common report in recent years. SUBSEA CABLES
-
👮 Law Enforcement: Interpol says that 260 romance scam and sextortion suspects were arrested during the two-week Operation Contender 3.0. The cybercriminals are responsible for defrauding almost 1,500 victims, and the operation spanned 14 African countries. Zhimin Qian, 47, a Chinese national, has pleaded guilty to offences under the Proceeds of Crime Act. Qian fled China to the UK in 2018 using a false identity after running a Ponzi scheme that defrauded 128,000 people. Her guilty plea follows a Met Police raid that uncovered multiple laptops holding the keys to 61,000 Bitcoin, now worth a staggering £5.5 billion ($6.9 billion). SCAMMERS, PONZI
And finally
- Bullet timeout: A ‘stray bullet’ caused an outage for 25,000 Texans after it severed a fibre optic cable. The telecommunications company Spectrum confirmed the incident, which affected residents in Dallas, Irving, Plano, Arlington, Austin, and San Antonio, disrupting phone, internet, and TV services. BULLET