Robin’s Newsletter #388

23 November 2025. Volume 8, Issue 47
Supply-chain woes for 200 Salesforce customers. WhatsApp user base enumerated by researchers. Organised crime bought a bank for Christmas.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 23rd November 2025

  • Another Salesforce ecosystem provider compromised
  • WhatsApp user base enumerated by Austrian researchers
  • SEC drops SolarWinds lawsuit
  • Cloudflare outage resulted from a file size issue
  • Organised crime group bought itself a bank for Christmas

Interesting stats

7% increase in CISO pay, though only  4% increase in security budgets, based on a survey of 560 CISOs in the US and Canada by IANS Research. LINK

2x compute capacity every 6 months for the next 4-5 years,  1,000x overall increase in that period, according to an internal Google all-hands meeting. LINK

Five things

  1. Salesforce/Gainsight breach: Shiny Lapsus$ Hunters (SLH) have claimed responsibility for a compromise at Gainsight, a customer service platform that integrates with Salesforce. It’s understood that at least 200 Salesforce customers have been compromised, including Atlassian, CrowdStrike, DocuSign, LinkedIn, and Verizon. An SLH representative claimed to have had access inside Gainsight for “nearly 3 months”, adding that they “do not like Salesforce at all”. Gainsight’s applications and integrations with other technology platforms, such as Zendesk, HubSpot, and Salesforce, have been removed as a precautionary measure. The prior Salesloft breach, which also affected Salesforce customers, apparently “enabled entry points” into many systems like this, according to the attackers. Salesforce has developed a large ecosystem of third-party providers, particularly on top of the firm’s eponymous CRM solution. The quality and security of these third-party solutions are what are being tested here, with Salesloft and Gainsight both falling victim to SLH. BREACH, MORE, THIRD-PARTY

  2. WhatsAppening with all those requests? Researchers in Austria exploited flaws in WhatsApp to scrape details on what appears to be all 3.5 billion WhatsApp users. The claim amounts to being the “largest data leak in history” (though as ethical researchers from the University of Vienna, they are presumably not selling or disliking the info!) The Meta-owned messaging company did not block or rate-limit the researchers as they queried an API with 63 billion potential phone numbers to see if accounts existed, at a rate of over 100 million accounts per hour (7,000/s). Among all those accounts, 57% had a profile picture, and 29% had public profile text that the researchers could retrieve. The API in question is used to find known contacts in your address book. Meta has since added throttling and other security protections to this API, but it’s a bit of a fundamental fail. And while it’s clear that profile pictures and text are public, users don’t expect them to be wholesale available like this. WHATSAPP, PAPER

  3. SolarWinds lawsuit: The Securities and Exchange Commission (SEC) has dropped its lawsuit against SolarWinds and its CISO, Timothy G. Brown, following the ‘Sunburst’ incident in 2020. The SEC says that it was an “exercise of its discretion.” SolarWinds said the company is “clearly delighted”, as I’m sure Brown is. The SEC brought the case alleging that SolarWinds misled investors about its security posture and downplayed the severity of the attack. Sunburst was a state-sponsored attack, attributed to Russia’s foreign intelligence service, that compromised the source code of SolarWinds’ Orion device management system and used it to deploy malware. The legal action, along with a suit against Uber’s security chief, prompted many CISOs to consider the need for ‘D&O’ insurance to protect their personal assets. SOLARWINDS, MORE

  4. Cloudflare suffered an outage this week that disrupted other large Internet and tech companies like X/Twitter and OpenAI. Initially, the company pinned the cause on a “hyper-scale DDoS attack,” however, they walked this back after identifying the root cause as a file that had doubled in size. Cloudflare’s bot management system uses the file in question to store threat signatures and regulate traffic across its network. The file’s rapid increase in size exceeded a limit coded into these systems, causing the software to fail. OUTAGE, CAUSE, POST-MORTEM

  5. Dirty laundry: How far does organised crime go to launder its ill-got gains? This fascinating read from the UK’s National Crime Agency and Operation Destabilise says they’ll buy themselves a bank. On Christmas Day 2024, a Russian organised crime group bought a 75% controlling stake in Keremet, a Kyrgyz bank that it used to facilitate cross-border and cryptocurrency payments for cybercriminals, and transactions tied to Russia’s military-industrial base. It was also the receipt of funds from street-level drug gangs and other criminals. KEREMET, OP. DESTABILISE

Startup spotlight

As part of my pledge to support the UK cyber ecosystem, I’ll be featuring a different UK cyber startup each week.

This week it’s SecuraNova, an early-stage business, finding product market fit and gaining initial customers:

  • What do they do? We solve the problem of slow, inflexible, and costly security testing by delivering expert-led assessments at industry-leading speed, quality, and value.
  • Who is it for? Enterprise organisations, particularly those in regulated sectors, and potential MSP partners
  • Where can you find out more? WEB, LINKEDIN

If you’re a UK-based cyber security startup interested in being featured in a ‘Startup Spotlight’ in my weekly newsletter, please fill out this form for consideration. It’s not a paid thing; just trying to support our ecosystem 🚀

In brief

  • ⚠️ Incidents: French B2B telco Eurofiber says cybercriminals gained access to company data via a ticketing system last week. DoorDash, a US food delivery company, fell victim to a social engineering attack that gave attackers access to the names, emails, phone numbers, and physical addresses of an undisclosed number of customers, workers, and merchants. The French social security service Pajemploi has reported a data breach that may have exposed the personal data of 1.2 million individuals. Russian insurer VSK suffered a substantial outage this week following a cyberattack that affected its website, mobile app, and other systems. VSK has around 33 million B2C and 0.5 million B2B customers. Spanish airline Iberia is notifying customers of a data breach at a supplier, during which 77GB of customer data was allegedly stolen, including names, email addresses, and loyalty card information. EUROFIBER, DOORDASH, PAJEMPLOI, VSK, IBERIA

  • 🏴‍☠️ Ransomware: LG has confirmed a ransomware attack against one of its battery manufacturing facilities. The South Korean electronics giant says the facility is now operating normally, and its HQ and other operations were not affected. LG

  • 🕵️ Threat Intel: MI5 has warned UK lawmakers of Chinese spies using fake LinkedIn profiles to gain intelligence and influence over UK politicians and their aids. The message content isn’t surprising, but the overt delivery is perhaps a sign of the changing times. ShinySp1d3r: The ShinyHunters and Scattered Spider groups have joined forces to create a new ransomware-as-a-service (RaaS) operation. The malware contains some novel functions that prevent data from being logged to the Windows Event Viewer and overwrite deleted files by writing random data to fill up the disk. Amazon is warning of a rise in ‘cyber-enabled kinetic targeting’ — using compromised CCTV or other systems to aid the targeting of missiles and other kinetic attacks by foreign adversaries. MI5, SHINYSP1D3R, KINETIC

  • 🪲 Vulnerabilities: Google has released an emergency patch for Chrome to address a high-severity type confusion vulnerability that was being exploited in the wild (CVE-2025-13223; 8.8/10). Fortinet has patched another zero-day vulnerability in its FortiWeb firewall. The OS command injection issue (CVE-2025-58034; 7.2) requires an authenticated user to exploit. Grafana’s enterprise product has an issue where SCIM user provisioning is enabled, and can be used to escalate privileges (CVE-2025-41115; 10/10). CHROME ([ADVISORY](security advisory)), FORTINET (ADVISORY), GRAFANA (ADVISORY)

  • 🧿 Privacy: US airline industry data broker ARC will stop selling personal, flight, and payment card information to the US government this year. The sale allowed government agencies to search around 50% of flight tickets without needing a warrant. ARC

  • 📜 Policy & Regulation: Comments from law firms around the UK government’s plan to ban ransom payments for CNI organisations miss that cybercriminals are looking for an easy return on investment: yes, they could take data and try to monetise it elsewhere, but that’s a lot more effort. RANSOM PAYMENTS  

  • 👮 Law Enforcement: The US, UK, and Australia have sanctioned a Russian ‘bulletproof’ hosting provider called Media Land. The hosting company allegedly provided services to ransomware gangs, including LockBit, BlackSuit, and Play, and such providers regularly tout their services as being beyond the reach of law enforcement. Two British teenagers suspected to be part of the Scattered Spider group, and charged with an attack on Transport for London (TfL) in 2024, have pleaded not guilty. MEDIA LAND, TFL

  • 💰 Investments, mergers and acquisitions: Runlayer,  a startup focusing on model context protocol security, has closed an $11 million seed round, and claims to have eight unicorns or large public companies as customers. Guardio, known for its data breach browser extension, has raised $80 million in funding to expand and improve the security of code produced by Vibe-coding AI assistants. Guardio claims 500,000 paying customers and $100 million in ARR. Palo Alto Networks is acquiring Chronosphere, a cloud observability platform, for $3.35 billion, making an expansion into broader IT monitoring. RUNLAYER, GUARDIO, CHRONOSPHERE

  • 🗞️ Industry news: Anti-virus: New Zealand’s Kawaiicon installed CO2 monitoring to aid con-goers in making risk-based decisions about attendance and precautions they’d like to take. CO2 can serve as a proxy for ventilation and higher levels of airborne viruses. KAWAIICON

And finally

  • Ukraine’s electronic warfare experts are downing “invincible” Russian Kh-47M2 Kinzhal ballistic missiles by bombarding the missile’s location receiver with a Ukrainian song “Our Father Is Bandera” and positioning coordinates that make the missile think it’s in Peru. The sudden turn to correct course causes the fuselage to break apart. MISSILES

  • The International Association of Cryptologic Research (IACR) says it’s unable to validate the results of its most recent annual leadership election because one of its trustees has lost their private key. IACR

Robin

  Robin's Newsletter - Volume 8

  Salesforce Gainsight WhatsApp Meta API Rate-Limiting Securities and Exchange Commission (SEC) SolarWinds SUNBURST Solorigate Cloudflare Outage Cross-border Payments Organised Crime Banking Money Laundering Data broker Bulletproof Hosting Ransom Payments Electronic Warfare