Threat Analysis is the daily cyber security briefing for people who are tired of corporate fog, vendor panic, and security theatre dressed up as strategy.
Hosted by Mauven MacLeod, it cuts through the noise around cyber threats, ransomware, data breaches, regulation, supply chain risk, and the latest bright idea from people who think a dashboard is the same thing as resilience.
Every weekday, Mauven looks at what happened, why it matters, who should be paying attention, and what small and medium sized businesses should do before the mess arrives with a press statement and a very expensive consultant.
This is not fear mongering. It is not a product pitch. It is not another cosy chat about awareness while the back door is hanging off its hinges.
It is sharp, practical threat analysis with a dry edge, a raised eyebrow, and very little patience for nonsense.
You will get clear context, useful actions, and the occasional reminder that cyber security is not magic. It is governance, discipline, evidence, and doing the basics before reality applies a boot to the backside.
Threat Analysis is part of The Small Business Cyber Security Guy network.
Site
RSS
Apple
Classements récents
Dernières positions dans les classements Apple Podcasts et Spotify.
Liens partagés entre épisodes et podcasts
Liens présents dans les descriptions d'épisodes et autres podcasts les utilisant également.
Today’s episode tackles key cybersecurity challenges facing UK small and medium enterprises. We delve into the exploits by the Russian-aligned group TA488, discuss vulnerabilities such as CVE-2026-42897, and examine the broader impact of cyber incidents beyond primary targets. Learn about the MacSync Stealer threat to macOS and the potential risks associated with Anthropic’s Claude AI models. Finally, we explore the recent CAF Bank incident affecting thousands of charities. Each section offers insights and actionable steps to bolster your organisation’s security posture amidst these evolving threats.
Chapters
Intro
Introduction to key cybersecurity issues facing UK businesses, including TA488 exploits and AI vulnerabilities.
CVE-2026-42897 and TA488
Discusses the CVE-2026-42897 vulnerability exploited by TA488 and the importance of patch management.
CTA
Encourages listeners to follow the podcast and share it with others who might benefit.
MacSync Stealer on macOS
Explores the MacSync Stealer threat via Google Ads affecting macOS users and stresses the need for education and advanced protection.
Anthropic’s Claude AI Models
Examines issues of AI containment and security with Claude AI models, urging robust governance frameworks.
CAF Bank Incident
Analyzes the cyber incident affecting CAF Bank, highlighting the importance of financial security measures and contingency plans.
Outro
Concludes with a call for vigilance and accountability in tech environments to secure against threats.
In today’s episode of Threat Analysis, Mauven MacLeod delves into critical cybersecurity challenges confronting UK small businesses. We address Russian state-sponsored email attacks targeting Microsoft Outlook with a unique ‘half-click’ method, which offers notable resilience against traditional security measures. Understanding the implications of such threats is essential for businesses to protect their digital environments and reputations.
Additionally, we examine the rise of attacks within the npm registry, impacting software development operations. This new threat utilises worm-like behaviours to infiltrate popular packages and steal credentials via blockchain transactions. These complex methods highlight the importance of thorough vigilance and robust security strategies for companies relying on open-source software.
Mauven emphasises the necessity of incorporating comprehensive security measures, combining human and technological approaches, to effectively manage and counter these evolving threats. Don’t miss out on the need for keen awareness and proactive defences in safeguarding your business.
Chapters
Intro
Mauven highlights the critical cyber threats facing UK SMBs and the importance of robust security.
Russian State-Sponsored Email Attacks Targeting Outlook
Discussion on the ‘half-click’ method used by Russian hackers in Outlook attacks, emphasising resilience and the need for awareness.
CTA
Encouragement to follow the show and share with those who need cybersecurity insights.
NPM Registry Hosting New Supply Chain Attacks
Exploration of worm-like attacks within the npm registry targeting credentials via blockchain, calling for vigilant dependency management.
Outro
Conclusion on the necessity of proactive cybersecurity measures for UK SMBs, previewing future threat analyses.
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack
mercredi 15 juillet 2026 • Durée 15:47
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack
On 15 July 2026, Mauven MacLeod examines three active threats facing UK organisations. CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation targeting on-premises deployments, with particular exposure among professional services firms still running legacy infrastructure. The second story details a misconfigured phishing operation that exposed 218 confirmed victims across twelve countries using Adversary-in-the-Middle techniques that bypass standard multi-factor authentication, including OAuth Device Code Flow attacks against Microsoft 365 and Google Workspace users. Finally, a supply chain attack against the AsyncAPI generator repository saw an attacker exploit a misconfigured GitHub Actions workflow to publish five malicious npm packages containing the Miasma botnet loader, which executes at import time without user interaction. The briefing emphasises that none of these attacks relied on novel techniques or nation-state resources, but succeeded through known vulnerabilities, unpatched systems, and insufficient authentication controls.
Chapters
Introduction
Mauven opens the 15 July 2026 briefing, noting three stories involving confirmed victims and active exploitation, all stemming from known weaknesses rather than novel attack methods.
SharePoint Server: Three CVEs, Active Exploitation, Patch Now
CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaws affect on-premises deployments, not SharePoint Online. UK professional services firms, legal practices, and accountancy firms running legacy on-premises infrastructure face elevated risk. Mauven emphasises that KEV listing represents a late warning, not an early one, and calls for immediate patching and documented remediation.
Call to Action
Mauven encourages listeners to follow the show and share it with colleagues who would benefit from daily threat intelligence briefings.
AiTM Phishing: Three Operators Exposed, 218 Confirmed Victims
Lexfo researchers discovered a misconfigured Python HTTP server that exposed the infrastructure of three phishing operators, including one with 218 confirmed victims using OAuth Device Code Flow attacks and another operating an Adversary-in-the-Middle platform since 2018. AiTM attacks bypass standard multi-factor authentication by intercepting authenticated session tokens. Mauven explains why phishing-resistant MFA such as FIDO2 is necessary and provides specific guidance on OAuth Device Code Flow recognition and conditional access policy review.
Links
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure
mardi 14 juillet 2026 • Durée 15:07
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure
Two active phishing kits, Jalisco and OmegaLord, are defeating multi-factor authentication on Microsoft 365 accounts through adversary-in-the-middle proxying and device code abuse. At the same time, documented research shows a jailbroken AI model built a fully functional command-and-control server in six minutes with minimal human input. For UK SMBs relying on MFA as their primary Microsoft 365 defence, these developments demand immediate action. Mauven examines how commoditised MFA bypass techniques work, why they matter disproportionately to UK professional services firms, and what controls to deploy now before Microsoft’s passkeys rollout in September. Also covered: critical SAP patches, actively exploited Joomla vulnerabilities, and practical steps to take this week. This episode makes clear that MFA alone is no longer sufficient, and the window to implement additional controls is closing as attack tools become cheaper and easier to deploy.
Chapters
Introduction
Mauven introduces two critical developments: active phishing kits defeating Microsoft 365 MFA and AI-assisted attack infrastructure built in minutes. These trends signal a fundamental shift for UK businesses relying on MFA as primary defence.
Jalisco and OmegaLord: When MFA Is No Longer the Answer
Detailed examination of two operational phishing kits using adversary-in-the-middle proxying and device code abuse to defeat MFA on Microsoft 365. Explains why UK professional services firms are disproportionately exposed and outlines immediate mitigations including Conditional Access policies, FIDO2 keys, and token lifetime controls.
Call to Action
Mauven asks listeners to follow the show and share it with anyone relying solely on MFA for Microsoft 365 protection.
AI Is Doing Ninety Per Cent of the Work Now
Analysis of documented research showing a jailbroken Gemini model building a functional command-and-control server in six minutes. Discusses implications for UK SMBs as attack infrastructure becomes trivially easy to deploy at scale.
Briefly Noted: SAP and Joomla
SAP’s July 2026 patch addresses sixteen vulnerabilities including three critical flaws. Actively exploited Joomla extension vulnerabilities with CVSS 10.0 scores threaten UK SMB websites, particularly older professional services and hospitality sites.
What to Do Today
Four prioritised actions: verify Microsoft 365 Conditional Access configuration, patch Joomla extensions, review SAP July patches, and brief staff on device code authentication requests. Emphasises urgency of the MFA bypass issue.
Links
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse
lundi 13 juillet 2026 • Durée 15:41
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse
This briefing examines three concurrent threats that share a common vulnerability: neglected infrastructure. The NCSC and eight international partners issued a joint advisory on Russian state actors (FSB-linked Static Tundra and Berserk Bear) exploiting poorly configured network edge devices to establish persistent access in critical infrastructure. The same techniques work on any misconfigured router, including those deployed in UK SMEs. Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details, recalling the MOVEit compromise of 2023. Finally, Stormshield documented a phishing campaign impersonating DocuSign to install legitimate Remote Monitoring and Management tools (specifically Atera) as attacker infrastructure. Across all three incidents, the entry point is not sophisticated exploitation but basic configuration oversights: unchanged default credentials, unpatched firmware, unverified document signing workflows. UK small businesses using managed service providers, file transfer systems, or document signing tools face immediate exposure if they have not recently audited which remote access tools are authorised, verified router configurations, or trained staff to validate DocuSign notifications through the portal rather than email links.
Chapters
Introduction
Mauven introduces three apparently unrelated threats that share a single operating principle: attackers exploiting unlocked doors rather than breaking through reinforced ones.
Russian State Actors Targeting Network Edge Devices
A nine-country joint advisory warns of FSB-linked actors exploiting misconfigured routers for persistent access. The technique works on any poorly configured device, not just critical infrastructure. UK SMEs must verify that default credentials are changed, remote management interfaces are disabled, and firmware is current.
Call to Action
Listeners are encouraged to follow the show and share it with others who need threat intelligence.
Progress ShareFile Emergency Shutdown
Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details. Given Progress’s MOVEit breach history, UK SMEs using ShareFile must immediately verify whether they are affected and document what data transits through the platform.
DocuSign Impersonation and RMM Tool Abuse
Stormshield documented a phishing campaign impersonating DocuSign to install legitimate RMM tools (Atera) as attacker infrastructure. Because the payload is legitimate software, endpoint detection often fails to flag it. UK SMEs must train staff to verify DocuSign notifications through the portal, maintain an authorised RMM tool list, and treat any DocuSign prompt requesting software installation as malicious.
Links
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
vendredi 10 juillet 2026 • Durée 16:56
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
This episode examines three current UK cyber security incidents that share a troubling characteristic: all were preventable. Mauven MacLeod analyses the seven-step ransomware chain exploiting unpatched Citrix NetScaler appliances (CVE-2025-5777), documented by Huntress across multiple UK organisations. The briefing covers SilabRAT, a subscription-based Remote Access Trojan sold for £3,900 monthly that clones browser sessions to bypass multi-factor authentication, posing particular risk to finance teams and managed service providers. The episode also examines an NHS Forth Valley data breach caused by a misdirected email, representing the most common breach category reported to the ICO. Additional coverage includes GigaWiper destructive malware and active exploitation of Check Point VPN vulnerabilities (CVE-2026-50751) associated with Qilin ransomware. The analysis emphasises the systemic gap between awareness and action, providing specific verification steps for UK small and medium businesses.
Chapters
Introduction: The Common Thread of Prevention Failures
Mauven introduces three unrelated but preventable security incidents affecting UK organisations with existing IT support and best-practice solutions. The episode examines systemic failures in closing known security gaps.
CitrixBleed 2: Seven-Step Ransomware Chain
Analysis of the seven-step attack chain exploiting CVE-2025-5777 in Citrix NetScaler appliances, documented by Huntress across multiple UK organisations. Covers the automated exploitation process, Dragonforce ransomware deployment, and the disproportionate risk to UK mid-market professional services firms.
Call to Action
Brief encouragement to follow the show and share with business owners who need threat intelligence briefings.
SilabRAT: Credential Theft by Subscription
Examination of SilabRAT Remote Access Trojan, available for £3,900 monthly, which clones browser profiles and sessions to bypass multi-factor authentication. Covers Hidden Virtual Network Computing capabilities, targeting of finance teams, and supply chain risks through compromised managed service providers.
NHS Forth Valley: An Email Incident Without an Attacker
Analysis of a maternity patient data breach at NHS Forth Valley caused by misdirected email, representing the most common breach category in ICO statistics. Discusses the need for documented verification processes before sending bulk emails containing sensitive data.
Links
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways
jeudi 9 juillet 2026 • Durée 14:06
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways
A delayed patch for the RoguePlanet zero-day in Windows Defender has finally arrived, but working exploit code was publicly available for weeks before Microsoft closed the vulnerability. Mauven examines what that exposure window means for UK SMBs and why confirming patch deployment today is not optional. The Vidar infostealer campaign has quietly evolved beyond phishing emails into developer toolchains, with malicious Go modules staged across more than two hundred GitHub repositories designed to appear credible and actively maintained. Socket’s Operation Muck and Load research reveals how attackers are using commit farming and typosquatting to compromise software supply chains, particularly targeting payment SDK names. Finally, the NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification that may reduce friction for smaller organisations pursuing verified assessment. Mauven explores what this policy shift signals about the growing expectation for Plus-level certification in public sector contracts and supply chain assurance. Three practical actions close the episode: verify the RoguePlanet patch has been applied, implement dependency verification for developers pulling open-source packages, and review the NCSC pathways guidance if you hold basic Cyber Essentials certification.
Chapters
Introduction
Mauven previews three stories: a delayed zero-day patch, an infostealer campaign migrating into developer toolchains, and an underreported NCSC policy update with practical implications for UK small businesses.
RoguePlanet Zero-Day Patched, Weeks Late
Microsoft has patched the RoguePlanet zero-day in Windows Defender, but exploit code was publicly available for weeks before the fix arrived. Mauven explains the exposure risk, emphasises the urgency of confirming patch deployment, and advises reviewing any anomalous Defender behaviour during the vulnerability window.
Mid-Episode CTA
Mauven encourages listeners to follow the show and share Threat Analysis with colleagues who need daily UK threat intelligence briefings.
Vidar Infostealer Moves Into Developer Supply Chains
The Vidar infostealer campaign has evolved from phishing emails to compromising developer toolchains. Socket’s Operation Muck and Load research identified malicious Go modules staged across 222 GitHub repositories using commit farming to appear credible. Seventeen typosquatted packages targeting payment SDKs were published on 7 July. Mauven details practical verification steps for developers pulling open-source dependencies.
Links
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch
mercredi 8 juillet 2026 • Durée 13:28
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch
Ubiquiti has released security updates addressing seven critical vulnerabilities in UniFi OS, including one rated CVSS 10.0 that permits unauthenticated remote code execution. The widespread deployment of UniFi hardware in UK small business networks makes this a priority patching event. Separately, CISA has added an Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies after confirming active exploitation in the wild. ColdFusion remains widely deployed in UK professional services, legal and accountancy firms, and public sector environments, often in legacy web applications where platform visibility is poor. Finally, an ongoing phishing campaign delivering AsyncRAT and Remcos trojans continues to target finance, procurement, and operations staff using macro-enabled Excel attachments and fileless execution techniques. Mauven MacLeod provides specific guidance on how to verify patching status with IT providers, configure email filtering to block macro-enabled attachments, and enforce Office macro policy across business environments.
Chapters
Introduction
Mauven opens the eighth of July briefing with a direct question about firmware version awareness, highlighting seven critical Ubiquiti UniFi OS vulnerabilities including one rated CVSS 10.0, a CISA emergency patch order for Adobe ColdFusion, and an ongoing phishing campaign targeting finance and procurement staff.
Ubiquiti UniFi OS: Seven Critical Flaws, One at Maximum Severity
Seven critical vulnerabilities in Ubiquiti UniFi OS have been disclosed, including a CVSS 10.0 command injection flaw permitting unauthenticated remote code execution. Given the widespread deployment of UniFi hardware in UK SMB networks and typically flat network architectures, successful exploitation provides attackers with perimeter-level access. Mauven advises requesting written confirmation of firmware updates from IT providers or checking firmware versions directly if self-managed.
Call to Action
Mauven encourages listeners to follow the show and share the episode with others who may have unpatched Ubiquiti infrastructure.
Adobe ColdFusion: Actively Exploited, CISA Emergency Patch Deadline
CISA has added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies by the end of the week. The flaw permits remote code execution and is confirmed exploited in the wild. ColdFusion remains widely deployed in UK professional services, legal, accountancy, and public sector environments, often in legacy web applications with poor platform visibility. Mauven recommends requesting written confirmation of patching from hosting providers and suppliers.
Links
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge
mardi 7 juillet 2026 • Durée 16:25
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge
This episode examines three active threat vectors affecting UK businesses in July 2026. First, a sophisticated Microsoft Teams impersonation campaign documented by Unit 42, in which attackers pose as IT helpdesk staff to deploy EtherRAT remote access trojans without requiring any technical vulnerability. Second, a global phishing operation delivering AsyncRAT and Remcos through multi-stage infection chains that use steganography and fileless execution to evade detection, targeting finance, HR, and procurement functions. Third, the UK government’s new voluntary cyber pledge, signed by sixty organisations including two currently managing recovery from significant recent breaches. The episode also covers UAT-7810’s operational relay box networks and the NCSC’s Cyber Shield initiative. Practical mitigations include restricting Teams external access, blocking Office macros by default, implementing helpdesk verification processes, and ensuring endpoint protection uses behavioural detection rather than signature matching alone. Each recommendation is actionable within the current week and addresses documented attack patterns actively being exploited against UK small and medium businesses.
Chapters
Introduction
Overview of three stories: two active threats requiring immediate attention and one piece of UK government policy that merits closer examination beyond the press release.
Teams Helpdesk Scam: EtherRAT
Unit 42 research documenting attackers impersonating IT helpdesk on Microsoft Teams to deploy EtherRAT. The attack requires no technical vulnerability, only a helpful employee. Covers Teams external access configuration, verification processes, and remote access tool auditing.
Call to Action
Reminder to follow the show and share with colleagues who would benefit from daily threat intelligence.
Multi-Stage Phishing: AsyncRAT and Remcos
SpiderLabs research on global phishing delivering AsyncRAT and Remcos through Excel attachments, HTA scripts, PowerShell, and steganography-concealed payloads. Targets finance, HR, and procurement. Emphasises macro blocking and behavioural detection requirements.
UK Cyber Pledge: Sixty Signatories
Examination of the UK government’s voluntary cyber pledge signed by sixty organisations, including two currently managing recovery from significant breaches. Discusses the difference between pledges and contractual security requirements.
UAT-7810 ORB Networks
Cisco Talos research on operational relay box networks built using compromised small business infrastructure. Explains why edge device security matters beyond direct targeting.
Links
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
lundi 6 juillet 2026 • Durée 12:08
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score of 10.0, affecting legacy installations across SMB websites, internal applications, and shared hosting environments managed by MSPs. Second, a criminal group designated CL-CRI-1147 and tracked as Pink is conducting voice phishing campaigns that impersonate IT helpdesks to extract credentials and bypass multi-factor authentication. Once inside, the group exfiltrates data from SharePoint and OneDrive, then issues a seventy-two-hour ransom demand. The tactic closely mirrors operations by UNC3753, documented by Google Cloud Threat Intelligence. Both threats exploit different attack surfaces but share a common trait: neither discriminates by organisation size. Mauven provides specific procedural guidance for patching, MSP coordination, staff briefings on vishing, and audit log monitoring to detect bulk data downloads before ransom demands arrive.
Chapters
Introduction
Mauven introduces two current threats facing UK small businesses: an actively exploited Adobe ColdFusion vulnerability and a criminal vishing operation. Both target SMBs without discrimination based on size or sophistication.
Adobe ColdFusion CVE-2026-48282: Patch It Today, Not This Week
Analysis of CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed under active exploitation. Covers CVSS 10.0 scoring, unauthenticated remote code execution, exposure through legacy systems and MSP-managed environments, and immediate patching requirements.
Call to Action
Brief audience prompt to follow the show and share the briefing with colleagues who need current threat intelligence.
Pink (CL-CRI-1147): When the Threat Just Calls You Up
Examination of the Pink criminal group’s vishing operation that impersonates IT helpdesks to extract credentials and bypass MFA. Details the exfiltration timeline, procedural defences, staff briefing requirements, and technical monitoring for SharePoint and OneDrive bulk downloads.
The Pattern Worth Noting
Structural analysis connecting the Adobe vulnerability, vishing campaigns, and emerging ClickFix malware ecosystem. All three exploit different attack surfaces but converge on the same principle: automated and human-driven threats do not filter targets by organisation size.
Links
Podcasts Similaires Basées sur le Contenu
Découvrez des podcasts liées à Threat Analysis : Cyber News for Small Business. Explorez des podcasts avec des thèmes, sujets, et formats similaires. Ces similarités sont calculées grâce à des données tangibles, pas d'extrapolations !
AsyncAPI npm Supply Chain: Poisoned Packages, Botnet Loader
An attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository to exfiltrate a privileged access token, then published five malicious npm packages containing the Miasma botnet loader. The malicious code executes at import time without user interaction. Mauven advises organisations to audit AsyncAPI-related dependencies, review build logs from 14 July, and verify whether technology partners have assessed their exposure.
Also Worth Noting
The NCSC has announced that certified Cyber Advisors are offering free thirty-minute consultations for small businesses. Microsoft has halted Patch Tuesday updates for some Dell devices following reports of shutdowns and overheating.
Closing Remarks
Mauven concludes by noting that all three stories involve exploitation of known weaknesses through patience and known techniques, rather than exotic capabilities. The briefing emphasises checking on-premises SharePoint deployments and treating patching as an urgent priority.
Outro
Mauven summarises that MFA alone is insufficient for Microsoft 365 and that Conditional Access policies and phishing-resistant authentication are now baseline requirements.
Conclusion
The three threats share a common vulnerability: organisations have not recently audited their own infrastructure. The action item for UK SMEs is to verify router configurations, file transfer system deployments, and authorised RMM tools this week, not next quarter.
On the Radar: GigaWiper and Check Point VPN
Brief coverage of GigaWiper destructive malware and active exploitation of CVE-2026-50751 in Check Point Remote Access VPN since May 2026, associated with Qilin ransomware. Emphasises immediate patch verification requirements.
Conclusion: The Gap Between Awareness and Action
Summary emphasising that the common thread across all incidents is the failure to act on known risks. Provides specific action items for verifying patch status of NetScaler and Check Point VPN systems.
NCSC Cyber Essentials Pathways
The NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification. Mauven contextualises the policy update, explains why Plus certification is increasingly required for public sector contracts and supply chain assurance, and advises organisations holding basic certification to review the new pathways guidance.
Closing Actions and Outro
Mauven summarises three priority actions: confirm the RoguePlanet patch has been applied, brief developers on dependency verification, and read the NCSC Cyber Essentials Pathways blog. Closing remarks reinforce the importance of understanding vulnerability windows and consistent threat awareness.
On the Radar: AsyncRAT and Remcos Phishing Campaign
An ongoing phishing campaign delivers AsyncRAT and Remcos remote access trojans via macro-enabled Excel attachments, using fileless execution techniques including steganography to evade signature-based detection. The campaign specifically targets finance, procurement, and operations staff who routinely receive Excel files from external parties. Mauven recommends disabling macro execution by default, deploying Attack Surface Reduction rules, configuring email gateways to quarantine macro-enabled files, and briefing staff in targeted functions.
Closing Summary
Mauven summarises three actionable items: obtain written confirmation of UniFi firmware updates, verify ColdFusion patching status with suppliers, and enforce Office macro policy with appropriate email filtering. None require significant budget, only deliberate follow-through.
NCSC Cyber Shield
NCSC blog post on Cyber Shield, a sovereign AI-driven cyber defence initiative. Distinguishes between national-scale infrastructure projects and immediate operational threats.
Summary and Actions
Prioritised action list: restrict Teams external access, block Office macros, communicate helpdesk verification policy, confirm behavioural detection capability, and review supplier security contracts.
Closing
Summary of two actionable steps: verify and patch ColdFusion installations immediately, and brief staff on the vishing rule that IT will never request credentials or MFA approval by phone.