This week

- UK Cyber Pledge brings Cyber Essentials to supply chains
- Dutch intelligence: China ‘on equal footing’ with US offensive cyber
- Vercel app hosting customer creds stolen in breach from free AI tool
- First ransomware strains seen using post-quantum crypto algorithms
- UK Biobank data set seen for sale on Chinese e-commerce site
Interesting stats
100 countries have spyware capabilities to break into personal computers and phones, up from 80 in 2023, according to NCSC estimates.
Five things
-
Cyber Pledge: NCSC CEO Richard Horne told CYBERUK attendees that criminal threats (like ransomware) remain the most common risk for organisations, but that the most serious come “directly or indirectly” from nation-state actors like China, Iran, and Russia. Horne says NCSC handles around four ‘nationally significant’ cyber incidents every week. Against this backdrop, Security Minister Dan Jarvis announced a £90 million ($122 million) investment over three years to boost national cyber security. Jarvis also called on businesses to sign up to a voluntary Cyber Resilience Pledge. Those who do undertake to: make cyber a board responsibility; sign up to NCSC’s Early Warning Service, and require Cyber Essentials across their supply chains. Supply chains present network effects that could lead to the kind of shift the government are clearly hoping for. Cyber Essentials is designed to prevent common cybercriminal threats and has been shown to drastically reduce cyber insurance claim rates. Dealing with common threats would free the NCSC to focus on the bigger, nationally significant stuff.
-
China: National cyber agencies release report detailing the shifting tactics, techniques, and procedures (TTPs) used by ‘China-nexus’ threat actors. In particular, the group say that these China-nexus actors are making use of large-scale “covert networks” of compromised devices. These covert networks provide a low-cost means of denying their activities. The report goes on to say that some of. These networks are created and maintained by commercial companies in China, which seek to compromise thousands of small office/home office (SOHO) routers. Also this week, Dutch military intelligence said that it believes “China now probably stands on an equal footing with the United States in the area of offensive cyber capabilities”.
-
Vercel: The company behind Next.js, and which also hosts web applications, says that customer credentials were stolen during a recent incident. The “limited subset” of customers has been notified and told to rotate their credentials. This incident stands out because of the root cause: a Vercel employee using the free plan of Context.ai’s automation platform granted full OAuth permissions to their Vercel Google Workspace account. Context.ai suffered a breach in March, and attackers used these OAuth tokens to gain access to Vercel’s environment. Such broad permissions should be avoided where possible (adopt least privilege needed to get the job done!). And it’s also why having the ability to detect what SaaS apps and permissions users are using is so important: Vercel had no contractual relationship with Context, one of their users just decided the tool would make their work easier. To make matters worse, while investigating the incident, Vercel says it has identified a second, previously undetected compromise.
-
Kyber ransomware is now using quantum-safe cryptography to encrypt victims files. There’s little benefit for cybercriminals to use quantum over standard crypto at the moment. This is bragging rights and marketing.
-
UK Biobank, a non-profit, has suspended access to its data set, sourced from volunteers, after the medical data of 500,000 Britons was spotted for sale on Chinese e-commerce site Alibaba. Science minister Ian Murray told the House of Commons that “This was not a leak. This was a legitimate download by a legitimately accredited organisation”, which seems to be rooted in the technicality of it not being a ‘break in’ and instead a failure of policy and procedural controls: either way, the outcome is the same. The Chinese government has helped to remove the data from sale (because of course it did!)
In brief
-
⚠️ Incidents: Social media network Mastodon was hit by a distributed denial-of-service (DDoS) attack this week, a few days after competitor BlueSky also face a similar incident forced it offline. AI vibe coding platform Loveable made a configuration change in February that ‘accidentally’ made some private projects, public and revealed their chats, source code, credentials, and databases. France Titres, the government agency responsible for issuing identity and registration documents, says it suffered a data breach on one of its portals, exposing the login ID, full name, email, date of birth, unique account ID, and some other personal information; the threat actor claims they stole between 18 million and 19 million records. Cosmetics company Rituals has suffered an “unauthorized download” or members’ data this month, and is investigating the root cause and extent of the data breach. Bitwarden has confirmed that its command line application was compromise during a “limited window” and that it has “no evidence that end user vault data was accessed”. Alarm company ADT says a “limited set” of customer information was stolen from its systems, Shiny Hunters have claimed responsibility and says it has 10 million records, while ADT has promised to contact affected individuals and offer them identity protection.
-
🕵️ Threat Intel: Kaspersky says new malware dubbed Lotus Wiper was used against Venezuela’s energy and utilities sector in an “extremely targeted” attack prepared over months. UK and US cyber agencies are warning of Firestarter malware on Cisco firewall devices that survives patch updates and software reboots. BlackFile, a group believed to be linked to The Com (of ScatteredSpider fame), has been targeting retail and hospitality organisations and impersonating IT Helpdesk staff to gain unauthorised access and extort money from victims.
-
🪲 Vulnerabilities: Microsoft has fixed a high-severity vulnerability in ASP.NET Core that could lead to SYSTEM privileges on Linux and macOS devices (CVE-2026-40372; 9.1/10; advisory).
-
🧑💻 End user and consumer: Anthropic’s Claude Desktop silently installs browser extensions and sets itself up for access for web browsers that are not yet even installed, without prompting the user for permission. NCSC is encouraging consumers to adopt passkeys for authentication and ‘leave passwords in the past’.
-
🧰 Guidance and tools: Windows admins rejoice: you can now uninstall Copilot on enterprise devices.
-
🛠️ Security engineering: Another supply chain attack against the npm ecosystem, this time sixteen Namaste packages have been compromised used in AI tooling.
-
🏭 Operational technology: A Chinese security researcher demonstrated a weakness in an EV charging system to turn off a port at a charger in Shanghai. Disrupting chargers across an entire city or region simultaneously could destabilise electricity grids.
-
🧿 Privacy: House Republicans have introduced federal privacy legislation, similar to that in Virginia and Kentucky, while Democrats suggest that the Secure Data Act would protect corporations, not consumers.
-
📜 Policy & Regulation: Former assistant FBI director for cyber, Cynthia Kaiser, has called on US lawmakers to ‘close the gap’ between “the severity of [ransomware] and the consequences that follow”. Kaiser says that prosecutors should bring murder charges against cybercriminals who attack hospitals and lead to patient deaths.
-
👮 Law Enforcement: Scattered Spider ‘ringleader’ Tyler Robert Buchanan (aka tylerb) of Dundee, Scotland, has pleaded guilty to wire fraud and aggravated identity theft in the United States.
-
🗞️ Industry news: Sean Plankey has written to President Trump asking him to withdraw his nomination to lead CISA, saying “After thirteen months since my initial nomination, it has become clear that the Senate will not confirm me.”
And finally
- Vitaly Kamluk, a security researcher at SentinelOne, told Black Hat Asia that he believes they have found evidence of Fast 16, a potential cyberweapon that pre-dates Stuxnet by five years. Fast 16 targeted 2005-era computers, and will not run on multi-core processors or operating systems newer than Windows XP. The malware targeted engineering and physics simulation programmes, including one known to be used by Iran in its nuclear weapons programme.