This week

- Ransomware payments dropped in 2024
- 50+ orgs affected by React2shell vuln
- Coupang CEO steps down, former employee main suspect
- Highly targeted ‘ConsentFix’ campaign detected
- Gartner says agentic browsers aren’t worth the risk
Interesting stats
2/3 organisations are planning to increase their cyber security investments in the next 12 months, according to Marsh, with
1/4 planning over a
25% boost to spending. LINK
The same report from Marsh shows that companies’ measurement of cyber risk is, well, a bit of a mess:

10,456 Docker Hub images leaked one or more secrets, including tokens to access production systems, cloud platforms, code pipelines, and ~4,000 of these were AI platform API tokens, according to Flare. LINK
Five things
-
Ransomware data from the US Treasury Department’s Financial Crimes Enforcement Network (FinCEN) suggests ransomware contracted in 2024 from a high in 2023. Treasury data show a 33% drop in payments from $1.1 billion in 2023 to $734 million in 2024. The number of reported incidents declined by only 2%, from 1,512 to 1,476. It’s a promising decrease, following the creation of the International Counter Ransomware Taskforce in 2023 and sustained sanctions and law enforcement focus. Still, it’s too early to see whether it is a sustained decline and whether we have reached ‘peak ransomware’. Manufacturing, then financial services, and finally healthcare were the top three targeted sectors. RANSOMWARE, REPORT (PDF)
-
React2shell fallout continues, with Palo Alto Networks’ Unit 42 saying that they have confirmed more than 50 organisations that have been affected. The activity is from an initial access broker “with ties to” the Chinese Ministry of State Security. China is known to contract out work to its private sector, but there have also been cases where employees at these organisations are ‘moonlighting’ for personal gain. Not one to be left out, the North Korean’s have been observed exploiting React2shell to drop their ‘EtherRAT’ remote access trojan to compromise Linux hosts. On Friday, Wiz told reports that they have seen commodity crypto miners being dropped on affected hosts, and that 50% of React Server instances accessible on the internet remain unpatched. React2shell (CVE-2025-55182) is a pre-authentication, remote code execution vulnerability in the server component of the popular React application framework. Since a patch was made available on 3rd December, two further vulnerabilities allowing denial-of-service or source code exposure have been identified. It’s likely to be a busy Christmas for those using the framework, who may also be subject to holiday code freezes, hampering response efforts. CHINA, N KOREA, UNPATCHED, ADVISORY, NEW ISSUES
-
The CEO of South Korea’s largest e-commerce site, Coupang, has resigned following a data breach affecting two-thirds of the country’s population. Initial reports from the company suggest the breach occurred back in June and went undetected until recently. South Korean police raided Coupang’s headquarters this week and seized devices as part of an independent investigation into the incident. The primary suspect is a 43-year-old Chinese national who joined the firm in 2022 and left in 2024. Investors have raised concerns that senior executives also sold stock days before the company announced the breach, though this was part of pre-planned share sale. RESIGNATION, SUSPECT, SHARE SALE
-
ConsentFix: Researchers at Push Security have identified a novel evolution of ‘ClickFix’ attacks they are calling ‘ConsentFix’. Both methods rely on a user copying and pasting something generated by the attacker to execute a command. The campaign appears highly targeted and uses conditional loading based on the user’s email address. If it’s on a target list, the attack proceeds; otherwise, the user is redirected to the original website and any further requests from that IP address are ignored. The prompt to ‘verify you are human’ is embedded on both malicious and some compromised high-reputation websites. ClickFix typically prompts a victim to open a command prompt and run a command. In contrast, ConsentFix uses a specially crafted URL to grant access to the victim’s Microsoft account via the Azure CLI. Consent Fix bypasses phishing for credentials, MFA tokens, or passkeys and grants the attacker access by abusing the Azure CLI OAuth app. Well done, Adam, Luke and the team. CLICKFIX
-
Agentic Browsers: Gartner thinks that organisations “must block AI browsers for now” in a new research note warning off agentic browsers like OpenAI’s Atlas and Perplexity’s Comet. Google is planning a separate Gemini model for its agency Chrome capabilities. The ‘User Alignment Critic’ will be isolated so it cannot be poisoned and will review the steps being taken against the user’s objective, stepping in or making the browser replan if the action is deemed unsafe. GARTNER, GOOGLE
In brief
-
⚠️ Incidents: Porsche drivers in Russia were left stuck last week after their cars lost satellite signal from their Vehicle Tracking System (VTS), causing the immobiliser to kick in. It’s not thought the incident was malicious; rather, it was an issue with a locally procured system. Porsche pulled out of the Russian market following the invasion of Ukraine. Petco has taken down its Vetco Clinics website after it was found to be exposing customer data, including customer names, addresses, contact details, extensive information about the animals and their health, and signed consent forms. TechCrunch identified the issue, whereby you can generate PDF copies of documents by entering a customer identifier, which is a sequential number. US credit check agency 700Credit, which specialises in services for car dealerships, has suffered a breach in which attackers stole the names, addresses, dates of birth, and Social Security numbers of at least 5.6 million people. PORSCHE, PETCO, 700CREDIT
-
🕵️ Threat Intel: Researchers at Varonis have identified a new phishing kit dubbed Spiderman that steals credentials, multi-factor authentication (MFA) tokens, and credit card data. The kit creates convincing replica websites of major banks and crypto exchanges in five European countries. Palo Alto Networks’ Unit 42 says that a Hamas-affiliated group is targeting government entities across the Middle East with AshTag malware embedded in documents. Researchers at Huntress say that the Akira ransomware group and others are targeting hypervisors, following a ‘surge’ in related incidents. Hypervisors tend not to be as well-secured as the servers they run or other endpoints, and may lack typical endpoint security controls, making them an easy target. SPIDERMAN, ASHTAG, HYPERVISORS
-
🪲 Vulnerabilities: The Apache Foundation has fixed a ‘perfect 10’ vulnerability in its Tika system that processes metadata from files. CVE-2025-66516 (10/10) ties back to a prior issue in which attackers could embed malicious payloads in PDF documents. Ivanti Endpoint Manager has a critical vulnerability. CVE-2025-10573 (9.6/10) allows unauthenticated actors to unroll fake endpoints into the Endpoint Manager solution and poison the administrator dashboard. Attackers can bypass Fortinet’s FortiCloud SSO authentication to gain access to FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager systems. CVE-2025-59718 (9.8/10; OS, Proxy, SwitchManager) and CVE-2025-59719 (9.8/10; Web) involve cryptographic signature weaknesses that can be exploited via specially crafted SAML messages. SAP’s December security updates include three critical severity issues, including CVE-2025-42880 (9.9/10), a code injection issue in SAP Solution Manager. TIKA (ADVISORY, IVANTI (ADVISORY), FORTINET (ADVISORY), SAP (ADVISORY)
-
🧑💻 End user and consumer: Both Google and Apple have released software updates to protect users against sophisticated attacks. The issues were discovered by their in-house security researchers, and the release notes suggest that some devices may have been compromised before the patches were made available. While neither explicitly links their respective updates, the fact that they were identified by Apple’s security engineering team and Google’s Threat Analysis Group, both of which track nation-state and spyware zero-day attacks, suggests there may be a nexus here, making the updates noteworthy. Spanish-speaking Android users are being targeted by DroidLock malware that attempts to extort money from victims. The malware does not encrypt data; rather, it blocks user interaction and can change the device PIN and biometric information to render the device unusable. GOOGLE & APPLE, DROIDLOCK
-
🛠️ Security engineering: NCSC’s blog post on prompt injection is a good primer on the topic. It unpacks how AI attacks compare to SQL injection attacks against a database, and why conflating command and data means the problem may not be solved any time soon. Security vs usability: The UK’s Legal Aid Agency (LAA) is returning to pre-breach operations, six months after an incident that saw case information dating back to 2010 compromised. But law firms providing legal aid have been frustrated by the access, which is now granted via an AWS Secure Browser that replaces the previous user/pass method. In some cases, multiple MFA codes are required, and it can take up to six minutes to log in. Concurrency issues have also plagued the system, with some users being booted out and losing work. PROMPT INJECTION, LAA
-
🏭 Operational technology: CISA has released version 2.0 of its Cross-Sector Cybersecurity Performance Goals (CPGs), which it hopes will guide water works and other critical infrastructure operators in protecting their systems. I’m all for the new ‘govern’ goal category and emphasis on improving accountability and risk management. CISA says that “These enhancements are designed to promote accountability, improve risk management, and support strategic cybersecurity governance across sectors.” CPG, CPG 2.0
-
🧿 Privacy: Canada’s Privacy Commissioner has begun a probe into facial recognition systems built into billboards after Toronto residents noticed a disclaimer on two billboards at the city’s Union Station. Cineplex Digital Media (CDM) owns the billboards and says it only analyses the age and gender of passers-by, with no identifying information stored by the system. The UK ICO has fined LastPass £1.2 million for a 2022 breach affecting 1.6 million British users. BILLBOARDS, LASTPASS
-
📜 Policy & Regulation: The UK government has “heard the criticisms” and is looking to create a “statutory defence” in the Computer Misuse Act (CMA) for security researchers acting in good faith. This is the same sort of reform that Portugal has recently passed, that makes exception for acts like identifying vulnerabilities as “not punishable during to public interest in cybersecurity”. CMA, PORTUGAL
-
🗞️ Industry news: Insurer Coalition has announced special coverage for attacks using synthetic identities, or ‘deepfakes’. COALITION
And finally
- Pro-Russian cybercrime group CyberVolk has released a ransomware-as-a-service offering with some fundamental flaws. SentinelOne says that the reportedly Indian-based group uses the same key to encrypt all files, and that a plaintext copy of this is left in a ‘system_backup.key’ file in the system’s %TEMP% folder. If a victim wants to decrypt their files, they can use that key to do so without paying the ransom demands. CYBERVOLK