Explore every episode of the podcast Threat Analysis : Cyber News for Small Business
Dive into the complete episode list for Threat Analysis : Cyber News for Small Business. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
Rows per page:
50
1–50 of 57
Title
Pub. Date
Duration
Evolving Cyber Threats Facing UK Businesses
21 Sep 2026
00:06:17
Evolving Cyber Threats Facing UK Businesses
Join Mauven MacLeod for today’s Threat Analysis as we explore significant cyber threats impacting UK businesses. We begin with TraderTraitor, a subgroup of the Lazarus Group, which has shifted focus from cryptocurrency firms to IT services providers, highlighting a strategic expansion in their attack vectors. For small businesses, this underscores the importance of cybersecurity, regardless of sector involvement. Next, we examine Head Mare’s exploit of vulnerabilities in TrueConf’s video conferencing servers using PhantomCore malware. This highlights the critical need for robust communication security amidst the rise in remote work. Finally, we cover Microsoft’s recommendation to transition from SMS-based authentication to passkeys, emphasising the importance of strengthening digital identity security. Proactive security practices, including regular audits and comprehensive patch management, are essential for enduring in today’s hostile cyber landscape.
Chapters
Intro
Mauven introduces the episode, highlighting the interconnected nature of cyber threats affecting UK businesses.
TraderTraitor’s IT Services Attack
Discussion on TraderTraitor’s shift to target IT services, urging small businesses to enhance their cybersecurity measures.
CTA
Reminder to follow the show for daily updates and share with others.
Head Mare’s PhantomCore Exploit
Examination of Head Mare’s attack on TrueConf, stressing the importance of communication security and patch management.
Microsoft’s Authentication Transition
Coverage of Microsoft’s push towards passkey authentication, advising businesses to adopt more secure identity protocols.
Outro
Summary of key points and encouragement to stay proactive in cybersecurity.
Third-Party Trust Exploited: Brevo, Clop, and RMM Abuse
18 Sep 2026
00:14:15
Third-Party Trust Exploited: Brevo, Clop, and RMM Abuse
On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious code into JavaScript assets that reached over 100,000 customer websites. WordPress administrators had backdoor plugins silently installed while logged in; regular visitors faced ClickFix credential-harvesting overlays. Meanwhile, the Clop threat group continues exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid data exfiltration, targeting UK manufacturing and engineering supply chains. A third campaign involves Settra ransomware maintaining persistence via MeshAgent, a legitimate remote monitoring tool that endpoint security often trusts by default. All three attacks share one structural weakness: reliance on third-party platforms, scripts, and tools that UK small businesses cannot directly audit or control. This briefing walks through the mechanics of each campaign, explains why supply chain compromise scales so effectively, and sets out the specific questions business owners must ask their web developers, IT providers, and managed service providers today. No patch can protect you from a script you load from someone else’s content delivery network, and no endpoint tool will flag an RMM agent it has been trained to trust. The NCSC has published supply chain guidance repeatedly; these campaigns demonstrate how rarely it is applied in practice.
Chapters
Intro
Mauven frames the common vulnerability across today’s campaigns: reliance on third-party platforms that UK small businesses cannot audit, patch, or monitor in real time.
Brevo Supply Chain Attack
On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious JavaScript that silently installed WordPress backdoor plugins on admin machines and delivered ClickFix credential-harvesting overlays to visitors across over 100,000 customer sites.
CTA
Mauven asks listeners to follow the show and share it with colleagues who need the briefing.
Clop Returns with a Custom Implant
The Clop threat group is exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid credential harvesting, database enumeration, and data exfiltration, targeting UK manufacturing and engineering businesses.
Settra Ransomware and RMM Abuse
Settra ransomware maintains persistence by installing MeshAgent, a legitimate remote monitoring tool that endpoint security trusts by default, making unauthorised access harder to detect.
The Wider Pattern
Mauven connects all three campaigns to the same structural weakness: shared platforms, scripts, and tools that businesses cannot directly control, and the persistent gap between available NCSC guidance and real-world application.
Outro
Mauven summarises the specific actions listeners must take today: audit Brevo-linked sites, confirm PTC Windchill patches, and ask MSPs which RMM agents are authorised and how unauthorised ones would be detected.
Cisco ISE Zero-Day and GhostCode OAuth Phishing Demand Immediate Action
17 Sep 2026
00:13:57
Cisco ISE Zero-Day and GhostCode OAuth Phishing Demand Immediate Action
Two critical threats require immediate attention from UK businesses today. Cisco has disclosed an authentication bypass vulnerability in its Identity Services Engine with a maximum CVSS score of 10.0, and exploitation is already confirmed as active. ISE functions as a network gatekeeper for VPN, device compliance, and access control, making this vulnerability a direct path to your network perimeter. Separately, the GhostCode phishing technique weaponises Microsoft’s legitimate OAuth device code flow to bypass multi-factor authentication entirely. The attack arrives via business contact forms, presents victims with authentic Microsoft URLs, and produces valid session tokens that persist even after password resets. Analysis of ransomware activity in Japan reveals that 80 per cent of victims had capital under one billion yen, confirming that small and medium businesses are the majority of targets, not the exception. With Windows 11 24H2 reaching end of support in October 2026, unpatched endpoints remain a consistent entry point in post-breach analysis. This briefing provides specific actions for patching, MFA hardening, conditional access policies, and session revocation.
Chapters
Introduction
Mauven introduces two urgent threats: a Cisco vulnerability with active exploitation and a phishing technique that bypasses MFA controls most organisations rely on.
Cisco ISE Authentication Bypass (CVSS 10.0)
Analysis of the critical Cisco Identity Services Engine vulnerability with confirmed active exploitation, explaining why network access control systems are high-value targets and providing immediate patching guidance.
Call to Action
Encouragement to follow the show and share with business owners and IT providers who need timely threat intelligence.
GhostCode OAuth Device Code Phishing
Detailed breakdown of the GhostCode phishing kit that abuses Microsoft’s OAuth 2.0 device authorisation flow to bypass MFA, including detection indicators and specific mitigation steps.
Ransomware Targeting of Smaller Businesses
Analysis of Cisco Talos data showing 80 per cent of ransomware victims in Japan were small and medium enterprises, challenging the assumption that smaller size reduces risk.
Windows 11 24H2 End of Support
Reminder that Windows 11 24H2 Home and Pro editions reach end of support in October 2026, with guidance on fleet assessment and update planning.
Outro
Recap of the two key takeaways: immediate patching and verification actions, and the structural reality that small businesses are primary ransomware targets.
ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day
16 Sep 2026
00:13:29
ScreenConnect Exploited, OAuth Device Phishing, and Pixel Zero-Day
CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect vulnerability, the remote access tool used by countless UK IT providers to support small business clients. Attackers are targeting managed service providers to gain indirect access to entire client portfolios. Meanwhile, the GhostCode phishing campaign is bypassing traditional defences by abusing Microsoft’s legitimate OAuth device code flow, landing in inboxes through web contact forms and requiring no fake login pages. Finally, Google has patched a zero-day privilege escalation flaw in Pixel devices that was exploited in targeted attacks. This briefing explains why these threats matter to UK SMBs, what the attack patterns look like in practice, and what concrete actions business owners and IT managers should take today. Mauven MacLeod delivers the technical detail and the operational context that turns threat intelligence into defensible decisions.
Chapters
Introduction
Mauven introduces two active threats targeting UK small businesses through legitimate infrastructure: a remotely exploited ScreenConnect flaw and an OAuth device phishing technique that bypasses traditional defences.
ScreenConnect: CISA Confirms Active Exploitation
CISA has added a critical ConnectWise ScreenConnect vulnerability to its Known Exploited Vulnerabilities catalogue. Attackers are targeting IT providers to gain indirect access to their SMB clients. Business owners are advised to verify their MSP has patched the tool and to understand the supply chain risk.
Call to Action
A reminder to follow the show and share the briefing with colleagues who need the information.
GhostCode: OAuth Device Phishing
eSentire has documented the GhostCode phishing kit, which abuses Microsoft’s OAuth device code flow to gain persistent access to Microsoft 365 accounts. The campaign impersonates procurement officers, uses web contact forms, and directs victims to legitimate Microsoft URLs, bypassing traditional phishing defences.
Pixel Zero-Day
Google’s September 2026 patch for Pixel devices includes a fix for a zero-day privilege escalation vulnerability exploited in targeted attacks. Organisations using Pixel devices should install the update immediately.
Closing Remarks
Mauven summarises the three practical actions listeners should take: verify ScreenConnect patch status with IT providers, brief staff on OAuth device code phishing indicators, and review OAuth app consents in Microsoft Entra admin centre.
Web Skimmers, IoT Botnets, and Search Engine Fraud: Trust Under Attack
15 Sep 2026
00:14:10
Web Skimmers, IoT Botnets, and Search Engine Fraud: Trust Under Attack
Three active cybercriminal campaigns are exploiting trust in routine business systems. GrelosGTM injects payment skimmers into Google Tag Manager containers on compromised e-commerce sites, bypassing traditional file integrity checks and PCI compliance tools. Two IoT malware families, KATARU and Evooo1Bot, are scanning for unpatched edge devices using vulnerabilities dating back to 2007, turning compromised routers and network appliances into proxy infrastructure. Meanwhile, criminals are creating convincing fake versions of legitimate financial portals that surface in organic search results through typosquatting and Punycode manipulation. Each campaign targets a different attack surface, but all exploit the same underlying assumption: that familiar tools, devices, and search results are inherently trustworthy. Mauven MacLeod examines the behavioural incentives that make these attacks effective and outlines practical steps UK businesses can take today to audit their Google Tag Manager containers, verify firmware on internet-facing devices, and reduce social engineering risks through simple URL management practices.
Chapters
Introduction
Overview of three active campaigns exploiting trust in marketing tools, network hardware, and search engine results.
GrelosGTM: Payment Skimming Hidden Inside a Marketing Tool
Group-IB research on a cybercriminal group injecting malicious scripts into Google Tag Manager containers on Magento e-commerce sites. Practical audit steps for UK businesses.
Call to Action
Encouragement to follow the show and share with small business owners.
KATARU and Evooo1Bot: Two IoT Botnets Scanning for Unpatched Devices
Two Mirai-derived botnets exploiting weak credentials and decades-old vulnerabilities in internet-facing edge devices. Includes FortiGate SSL-VPN intrusion campaign detail and firmware audit checklist.
Search Engine Fraud: Fake Crypto Gift Card Checkouts
Criminals creating convincing fake versions of legitimate portals that appear in organic search results through typosquatting and Punycode manipulation. Simple URL management mitigations.
Closing
Connecting thread across all three campaigns and practical takeaway: audit the things you have stopped looking at.
Revolut Social Engineering Breach and GitLab Path Traversal Exploit
14 Sep 2026
00:13:35
Revolut Social Engineering Breach and GitLab Path Traversal Exploit
A major fintech data breach demonstrates how impersonation attacks bypass technical defences entirely, whilst a maximum-severity GitLab vulnerability enters active exploitation. This episode examines Revolut’s disclosure of customer financial and passport data released following a fraudulent government agency impersonation, highlighting the procedural failures that enable social engineering at scale. We cover CISA’s addition of a GitLab path traversal flaw to the Known Exploited Vulnerabilities catalogue, the supply chain implications for UK SMBs, and practical verification procedures that prevent data disclosure to unauthorised parties. Operational updates include Microsoft’s September patches breaking Remote Desktop Services on Windows Server, and the UK government’s passkey rollout across 23 million GOV.UK accounts. The episode focuses on verification protocols, out-of-band confirmation procedures, and supply chain questioning as practical defences against non-technical attack vectors that compromise organisations with significant security resources.
Chapters
Introduction
Mauven introduces the episode focus on a fintech breach achieved through convincing impersonation rather than technical exploitation, setting up the central theme of procedural failures in data handling.
Revolut Breach via Government Impersonation
Analysis of Revolut’s data breach following a fraudulent government agency request, examining the social engineering mechanism, customer impact, verification procedure failures, and practical implementation of out-of-band confirmation protocols for UK SMBs handling data disclosure requests.
CTA
Call to action encouraging listeners to follow the show and share with colleagues handling data requests and code repositories.
GitLab Path Traversal Flaw, Actively Exploited, Maximum Severity
Coverage of CISA’s addition of a GitLab path traversal vulnerability to the Known Exploited Vulnerabilities catalogue, explanation of path traversal attack mechanics, supply chain exposure risks through developer and MSP relationships, and immediate patching requirements.
September Windows Updates and RDS
Microsoft’s September 2026 security updates breaking Remote Desktop Services functionality on Windows Server, the patching versus functionality trade-off, and recommendations for planned deployment with awareness of the known issue.
UK Government Passkey Rollout
UK government’s passkey implementation across 23 million GOV.UK accounts, the stated rationale of reducing phishing exposure and SMS verification costs, and implications for SMB authentication strategy beyond SMS-based MFA.
Outro
Summary emphasising that high-impact attacks often require minimal technical sophistication, practical actions on verification procedures and supply chain patching status, and closing remarks.
Russian State Actors Target Business Travellers via Hotel Wi-Fi
11 Sep 2026
00:16:57
Russian State Actors Target Business Travellers via Hotel Wi-Fi
This episode examines three active threat campaigns with direct SMB relevance. Russian state group APT29 (Midnight Blizzard) is conducting large-scale credential harvesting through compromised hotel and conference Wi-Fi networks across the UK and Europe, specifically targeting business travellers. The operation exploits captive portal authentication flows to harvest Microsoft 365 credentials through spoofed login pages and device code phishing that bypasses MFA. A second campaign demonstrates AI-orchestrated exploitation of PaperCut print management software, progressing from vulnerability research to remote code execution in under four hours across 440+ installations. The episode also covers a maximum-severity GitLab path traversal vulnerability and recent Conti ransomware sentencing. Analysis focuses on the systematic targeting of authentication layers, the operational risk to SMBs from compromised cloud tenancies, and the acceleration of exploit development through AI automation. Practical guidance addresses device code flow controls, conditional access policies, VPN discipline for travelling staff, and the limitations of MFA as a single defensive layer.
Chapters
Introduction: Active Campaigns Targeting Business Travellers
Overview of Russian state-sponsored credential harvesting via UK hotel Wi-Fi networks and AI-orchestrated PaperCut exploitation campaign. Episode positions APT29 activity as immediate SMB threat rather than purely government-sector concern.
CaptiveCrunch: APT29 Hotel Wi-Fi Credential Harvesting
Detailed analysis of Midnight Blizzard (APT29) campaign exploiting captive portal networks at hotels and conferences. Explains device code phishing technique that bypasses MFA, SMB impact from compromised Microsoft 365 tenancies, and four immediate mitigation actions including device code flow controls and conditional access policies.
Call to Action
Listener engagement request to follow show and share briefing given active campaign status.
AI-Orchestrated PaperCut Exploitation
Analysis of CVE-2026-81578 and CVE-2026-82078 exploitation campaign against PaperCut print management software. Details AI agent automation achieving remote code execution in under four hours across 440+ targets. Provides specific guidance on patch verification, internet exposure assessment, and compromise indicators.
GitLab Vulnerability and Conti Sentencing
Brief coverage of CVE-2026-85706 maximum-severity GitLab path traversal vulnerability requiring immediate patching. Notes Ukrainian national receiving four-year sentence for Conti ransomware development, with analysis positioning outcome as illustrating enforcement limitations rather than meaningful deterrent.
The Wider Pattern: Authentication Layer Under Systematic Attack
Synthesis identifying authentication layer as common target across multiple active campaigns. Argues current threat landscape reflects prioritisation failure rather than technology limitation, given documented NCSC guidance on phishing-resistant MFA and conditional access controls.
Closing: Practical Takeaways
Summary of actionable guidance: disable unnecessary device code flow, patch PaperCut installations, brief travelling staff on captive portal risks before conference season.
WatchGuard Ransomware Exploitation and Chrome Zero-Day Chain Target UK SMBs
10 Sep 2026
00:14:12
WatchGuard Ransomware Exploitation and Chrome Zero-Day Chain Target UK SMBs
Two active exploitation campaigns are affecting UK small businesses today. Ransomware operators are exploiting a critical WatchGuard Firebox vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalogue in December 2025, yet remains unpatched in many deployments nine months later. The flaw allows remote, unauthenticated code execution on internet-facing devices. Separately, four China-aligned threat actors have adopted an identical Chrome and Windows zero-day exploit chain within days of each other, enabling full system compromise through a single malicious webpage visit. The BlueMoon exploit kit combines CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Patches are available for both campaigns. Additionally, Cisco Secure Firewall Management Center is under active exploitation via two vulnerabilities that grant administrative control, with possible connections to the Qilin ransomware group. Today’s briefing provides specific remediation steps for each threat and examines why a nine-month-old vulnerability continues to find victims, highlighting fundamental patch management failures across the UK SMB sector. Mauven frames the discussion around visibility, accountability, and the compression of exploitation windows in modern threat environments.
Chapters
Introduction
Mauven opens the tenth of September 2026 briefing with two active exploitation events affecting UK small businesses: a nine-month-old WatchGuard vulnerability now used by ransomware operators, and a browser-based zero-day chain adopted by four state-aligned actors within days.
WatchGuard Firebox Ransomware Exploitation
CISA confirms ransomware gangs are actively exploiting a critical remote code execution flaw in WatchGuard Firebox appliances. The vulnerability was added to the KEV catalogue in December 2025, yet remains unpatched in many UK SMB deployments. Ransomware operators use automated scanning to find vulnerable devices. Mauven emphasises the need to verify firmware versions immediately and obtain written confirmation from managed service providers.
Call to Action
Mauven encourages listeners to follow the show and share it with colleagues who need daily threat intelligence.
BlueMoon Chrome Zero-Day Exploit Chain
Proofpoint and Volexity report on the BlueMoon exploit kit, which chains CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Four China-aligned threat actors adopted identical exploitation within days, suggesting coordinated or brokered tooling. The attack requires only visiting a compromised webpage and achieves full system compromise. Patches are available from Google and Microsoft’s September 2026 Patch Tuesday.
Cisco Secure Firewall Management Center Exploitation
Cisco Talos tracks active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center, which together grant administrative control. Possible connections to the Qilin ransomware group are noted. The vulnerability primarily affects mid-market professional services and managed security provider infrastructure.
Patch Management Reality Check
Mauven examines the operational reality of three network security products under active exploitation in the same news cycle. The continued exploitation of a nine-month-old WatchGuard vulnerability demonstrates that patch management is treated as optional despite NCSC guidance. The core issue is visibility: organisations must be able to answer which internet-facing devices and applications were updated in the last thirty days.
Closing and Practical Takeaway
Mauven summarises the immediate action items: confirm WatchGuard Firebox firmware is current and verify Chrome and Windows updates are applied across all devices. Listeners are encouraged to demand specific answers from IT providers, not vague reassurances.
In today’s briefing, Mauven examines key cybersecurity threats relevant to UK businesses. Microsoft’s record Patch Tuesday reveals 973 vulnerabilities, with 113 rated as critical, highlighting the urgency for timely updates. Two zero-day vulnerabilities pose active risks. Small and medium UK businesses often underestimate their appeal to cybercriminals, leaving systems vulnerable. Additionally, Plex Media Servers have over 36,000 exposed units due to security lapses, stressing the need for rigorous patch compliance. The emergence of the BlueMoon exploit chain underlines the danger of using outdated software, as state actors weaponise newly discovered vulnerabilities in platforms like Chrome and Windows. Maintaining up-to-date systems is imperative to prevent costly breaches and attacks. The episode concludes with a reminder that procrastination with updates can be perilous, urging businesses to prioritize security.
Chapters
Intro
Introduction to today’s cybersecurity briefing, highlighting the importance of system updates.
Microsoft’s Record Patch Tuesday
Analysis of Microsoft’s 973 vulnerabilities, including 113 critical ones and two active zero-day threats, stressing the importance of updates.
CTA
Encouragement to follow the podcast for regular updates and share with others.
Plex Media Servers Threat
Discussion on the vulnerabilities in over 36,000 exposed Plex Media Servers and the importance of patch compliance.
BlueMoon Exploit Chain
Insight into the BlueMoon exploit chain and how outdated systems are exploited by state actors, emphasising the need for current systems.
Outro
Final thoughts on the critical nature of timely system updates for business survival.
In this episode of Threat Analysis, hosted by Mauven, we delve into pressing cybersecurity threats facing UK small and medium-sized businesses (SMEs). We begin with the StyleSmuggler zero-day vulnerability targeting Magento and Adobe Commerce. Identified as CVE-2025-54236, this flaw allows unauthorised remote code execution, which underscores the importance of immediate patching. Despite Adobe’s emergency patch, many SMEs remain vulnerable due to a lack of awareness or resources.
We also explore the BigBear 2.0 phishing campaign, which successfully obtained credentials from over five thousand Microsoft 365 accounts globally. This highlights the increasing adoption of phishing-as-a-service models, making it vital for businesses to implement multifactor authentication and foster a culture of vigilance.
Mauven emphasises the need for rapid patch management and strong phishing defenses, encouraging businesses to prioritise vulnerabilities based on their potential impact. Through proactive measures and informed strategies, UK SMEs can safeguard against emerging cyber threats.
Chapters
Intro
Introduction to today’s cybersecurity threats for UK SMEs.
StyleSmuggler Zero-Day in Magento
Explanation of the StyleSmuggler vulnerability and the need for urgent patching.
CTA
Encouragement to follow and share the podcast.
BigBear Phishing Campaign Targets Microsoft 365
Details of the BigBear phishing campaign and the importance of multifactor authentication.
Implications for UK SMBs
Discussion on the necessity of strong cybersecurity measures for UK SMEs.
Outro
Conclusion emphasising proactive defense and awareness.
Mauven delves into pressing cybersecurity issues facing UK businesses. The alarming zero-day vulnerability in Magento, known as Stylesmuggler, threatens e-commerce operations with unauthorised remote code execution risks. The episode stresses the importance of immediate action, such as disabling unnecessary services and utilising robust web application firewalls until Adobe releases a patch. Additionally, the recent $320 million cryptocurrency heist from Liquid Network serves as a wake-up call for digital currency security, urging businesses to adopt offline cold storage solutions and perform comprehensive protocol audits. The episode also covers the significant data breach at Mathspace due to insufficient Metabase security, underscoring the need for encryption and third-party compliance. The vulnerability in ConnectWise’s ScreenConnect tool alerts managed service providers to engage actively with vendors for updates. Across these discussions, the emphasis remains on pre-emptive actions and maintaining robust security measures.
Chapters
Intro
Introduction to threats impacting UK businesses, focusing on Magento vulnerability.
Unpatched Magento Zero-Day Vulnerability
Details on the Magento Stylesmuggler zero-day vulnerability affecting UK e-commerce.
CTA
Call to action for listeners to subscribe and share the podcast.
Liquid Network $320M Cryptocurrency Heist
Discussion on the significant cryptocurrency heist and its implications.
Mathspace Data Breach: Lessons in Data Management
Analysis of the Mathspace data breach and its impact on data management practices.
ConnectWise ScreenConnect Vulnerability
Examination of vulnerabilities in ConnectWise’s ScreenConnect tool.
Outro
Conclusion with a focus on the importance of proactive security measures.
Access Management Failures: Teams Impersonation, Infostealer Sessions, and Leaver Risk
03 Sep 2026
00:16:03
Access Management Failures: Teams Impersonation, Infostealer Sessions, and Leaver Risk
Three separate incidents this week reveal a single, critical vulnerability across UK small businesses: access management. Microsoft Threat Intelligence has confirmed an active campaign exploiting Teams external collaboration to impersonate IT helpdesk staff, tricking employees into installing remote access tools that deploy malicious payloads. Meanwhile, new analysis shows that resetting passwords after infostealer compromise leaves authenticated session tokens active, allowing attackers continued access for days. A separate case study documents a terminated employee retaining elevated access long enough to cause hundreds of thousands in damages, purely because no formal offboarding checklist existed. The technical controls to prevent all three scenarios are available and documented. What is missing is operational discipline: caller verification before granting remote access, session revocation alongside password resets, and comprehensive leaver access audits. This episode provides specific, actionable guidance for small businesses without dedicated security teams, walking through the configuration changes, staff briefings, and process checklists required to close these gaps before they are exploited.
Chapters
Introduction
Overview of three incidents that all point to access management as the primary UK SMB vulnerability right now, with context from yesterday’s coverage and Microsoft’s new formal confirmation.
Attackers Impersonating IT Helpdesk via Microsoft Teams
Detailed breakdown of the confirmed Microsoft Teams helpdesk impersonation campaign, including the full technical chain from initial contact to lateral movement, and specific configuration and process changes required to mitigate the risk.
Call to Action
Brief listener engagement prompt.
Infostealer Sessions: The MFA Problem Nobody Is Talking About
Analysis of the session token problem in infostealer incidents, why password resets alone are insufficient, and the specific session revocation steps required in Microsoft 365 and other platforms.
The Leaver Who Kept Access
Case study of a terminated employee retaining elevated access due to absent offboarding processes, with practical guidance on access audits and leaver checklists for small businesses.
The Pattern Connecting All Three
Synthesis of the common access management gap across all three incidents and the operational discipline required to close it.
SonicWall Zero-Days, Teams Vishing Campaign, and Third-Party Identity Risk
02 Sep 2026
00:15:33
SonicWall Zero-Days, Teams Vishing Campaign, and Third-Party Identity Risk
On 2 September 2026, SonicWall disclosed two vulnerabilities in the SMA1000 remote access appliance series being actively chained together for remote code execution at the time of public disclosure. This episode provides immediate guidance for organisations running SonicWall perimeter devices, including patch verification and compromise auditing procedures. The briefing examines the Spring Ring campaign, a sustained Microsoft Teams vishing operation documented by Unit 42 that successfully targeted over 150 employees across ten companies between January and April 2026, using impersonated IT helpdesk calls to deploy remote monitoring tools and credential theft techniques including PetitPotam. Coverage includes Dropbox account compromises resulting from a Lenovo email verification flaw, illustrating third-party identity risk in business service authentication. Additional notes cover the multi-agency Sality botnet takedown after 23 years of operation, and emerging UK cyber legislation placing regulatory responsibility for AI deployment risk on end-user organisations rather than vendors.
Chapters
Introduction
Overview of three critical threat developments requiring immediate action, particularly a SonicWall zero-day exploitation event disclosed whilst under active attack.
SonicWall SMA1000: Two Chained Zero-Days Under Active Exploitation
Detailed analysis of actively exploited server-side request forgery and command injection vulnerabilities in SonicWall SMA1000 remote access appliances, with specific guidance on patch verification and compromise auditing for affected organisations.
Call to Action
Listener engagement prompt encouraging subscription and peer sharing of threat intelligence briefings.
Microsoft Teams Vishing: Spring Ring Targeted 150+ Employees Across 10 Companies
Comprehensive examination of the Spring Ring social engineering campaign using Microsoft Teams voice calls to impersonate IT helpdesk staff, including technical details of PetitPotam credential theft and practical staff briefing guidance.
Dropbox Accounts Breached via Lenovo Email Verification Flaw
Case study in third-party identity risk, covering Dropbox account compromises resulting from a vulnerability in Lenovo’s email verification process, with recommendations for identity provider auditing and multi-factor authentication.
In Brief: The Sality Botnet Is Down
Multi-agency disruption of the Sality botnet after 23 years of operation, including context on infected system remediation.
A Note on the UK Cyber Bill
Policy development update on UK cyber legislation framing regulatory responsibility for AI deployment risk on end users rather than vendors.
Closing
Summary of priority actions and episode conclusion.
Exchange Auth Bypass, PaperCut Data Theft, and Softaculous Supply Chain Attack
01 Sep 2026
00:16:07
Exchange Auth Bypass, PaperCut Data Theft, and Softaculous Supply Chain Attack
Nearly 22,000 Microsoft Exchange servers remain unpatched for a critical authentication bypass vulnerability allowing complete mailbox takeover. PaperCut print management software, deployed across thousands of UK offices, is actively exploited for data theft days after a patch was released. A 33-hour BGP hijack of Softaculous infrastructure may have poisoned the hosting supply chain for small business websites. This briefing provides specific verification steps for IT providers, explains why the window between patch release and exploitation continues to shrink, and connects these incidents to wider supply chain and social engineering threats including Teams vishing campaigns and fake CAPTCHA attacks. For UK small businesses running on-premises Exchange, PaperCut installations, or shared hosting websites, today’s combination represents direct and immediate exposure requiring same-day action.
Chapters
Introduction
Three active threats with direct paths into UK small business environments: 22,000 unpatched Exchange servers, active PaperCut exploitation for data theft, and a 33-hour BGP hijack of Softaculous infrastructure.
CVE-2026-62911: Exchange Authentication Bypass
High-severity vulnerability allowing unauthenticated attackers to hijack all user mailboxes on 22,000 internet-exposed Exchange servers. Verification steps for IT providers and the organisational failure behind persistent Exchange patching delays.
Listener Call to Action
Encouragement to follow the show and share with those running on-premises Exchange or shared hosting sites.
PaperCut Zero-Day Exploitation and Active Data Theft
Two PaperCut vulnerabilities patched last week now actively exploited for data theft campaigns. The shrinking window between patch release and exploitation, and why data theft differs from ransomware in detection and response.
Softaculous BGP Hijack and Supply Chain Exposure
Explanation of BGP hijacking mechanism and the 33-hour interception of Softaculous traffic affecting shared hosting infrastructure. Supply chain attack implications for small business websites and required audit steps.
Wider Threat Context
Connections between today’s threats and broader patterns including Teams vishing campaigns, ClickFix fake CAPTCHA attacks, and the shift from perimeter to user-focused initial access vectors.
Closing Actions and Summary
Three immediate actions: verify Exchange patch status, confirm PaperCut updates and check for prior compromise, audit shared hosting credentials and installations. Service level agreement implications if IT providers cannot respond within one working day.
Airport Breach, Terminal Attacks, and Defender Alert Fatigue
31 Aug 2026
00:16:08
Airport Breach, Terminal Attacks, and Defender Alert Fatigue
Manchester Airports Group has suffered a confirmed data breach larger than initially disclosed, with 86GB of validated customer and travel records now in threat actor hands. UK businesses with corporate travel through Manchester, Stansted, or East Midlands face immediate phishing risk. Meanwhile, the TerminalFix campaign bypasses email defences entirely by tricking users into executing malicious PowerShell commands through fake Cloudflare CAPTCHA overlays on compromised websites. Microsoft Defender’s broken status alerts, with official guidance to ignore warnings, create a window where genuine malware could disable endpoint protection undetected. Mauven examines the gap between initial breach disclosures and validated impact, the social engineering techniques that route around traditional defences, and why session token theft from infostealer malware cannot be resolved by password resets alone. Practical guidance includes staff briefings on travel data targeting, application control policies for Windows Terminal, and management-layer monitoring to compensate for unreliable user-facing alerts.
Chapters
Introduction
Overview of three active threats affecting UK businesses: a confirmed airport breach with validated stolen data, a social engineering campaign designed to bypass email defences, and a Microsoft Defender issue creating alert fatigue.
Manchester Airports Group Breach
FulcrumSec claims 86GB data theft from Manchester Airports Group, with independently validated customer and travel records. Analysis of the disclosure gap, targeting risks for corporate travel, and practical steps for businesses with MAG connections.
Call to Action
Encouragement to follow the show and share the episode with UK business contacts who need awareness of the Manchester Airports situation.
TerminalFix Campaign
Microsoft’s analysis of TerminalFix, a ClickFix variant using fake Cloudflare CAPTCHA overlays on compromised websites to trick users into executing malicious PowerShell commands through Windows Terminal, bypassing email-based defences entirely.
Microsoft Defender Alert Fatigue
Latest Defender update causes false ‘antivirus is turned off’ alerts, with Microsoft advising users to ignore warnings. Implications for security culture and the need for management-layer monitoring during the issue.
Infostealer Session Theft
Anthropic confirms Claude session token theft via infostealer malware, illustrating broader principle that stolen session cookies remain valid after password resets and require explicit session revocation across all platforms.
Closing
Summary of common theme across stories: existing defences do not address current attack vectors. Three immediate actions for UK businesses: brief staff on MAG breach targeting, educate on terminal-based social engineering, and implement management-layer Defender monitoring.
Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants
28 Aug 2026
00:17:37
Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants
This episode examines three active threats targeting UK small businesses through infrastructure that is often managed inattentively. PaperCut print management servers face active zero-day exploitation with no official vendor patch available, forcing organisations to choose between unvalidated emergency fixes or taking systems offline. A Microsoft Teams vishing campaign, running since January 2026, uses social engineering and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor for ransomware operators. Research into ZBT router firmware reveals three pre-installed implants, including DARKLANTERN, an unauthenticated backdoor offering root shell access. The episode also covers critical ServiceNow vulnerabilities, over 8,300 unpatched Gitea instances facing active exploitation, and CISA’s observation that most exploited vulnerabilities in 2026 should have been eradicated decades ago. The common thread is infrastructure that organisations do not actively monitor: print servers, router firmware, and remote access tools that staff use without scrutiny. Mauven provides specific, actionable guidance for each threat, emphasising that the surfaces receiving least attention from defenders are those being studied most carefully by attackers.
Chapters
Introduction
Overview of three active threats targeting infrastructure that UK small businesses manage inattentively: a print server zero-day, an eight-month Teams vishing campaign, and firmware implants in routers.
PaperCut Zero-Day: Active Exploitation, No Official Patch
PaperCut print management servers face active zero-day exploitation with no validated vendor patch. The software, widely deployed in UK SMBs, has administrative access to networked devices and was previously exploited by ransomware groups in 2023. Organisations must choose between applying an unvalidated emergency patch or taking servers offline.
Call to Action
Brief listener engagement request.
Microsoft Teams Vishing: GoGRPC Backdoor and the Ransomware Pipeline
Zscaler research details an eight-month campaign using Microsoft Teams vishing and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor. Attackers impersonate IT support, gain remote access, and sell network access to ransomware operators. The attack exploits normalised IT support behaviours.
Firmware Implants in the Supply Chain: ZBT Routers
VulnCheck identifies three firmware implants in ZBT routers distributed globally: SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS. DARKLANTERN provides unauthenticated root shell access via UDP port 9992. The implants were present in firmware before devices reached customers, representing a hardware-layer supply chain compromise.
ServiceNow, Gitea, and the CISA Observation
Three maximum-severity vulnerabilities patched in ServiceNow AI Platform. Over 8,300 internet-exposed Gitea instances remain unpatched against actively exploited remote code execution flaws. CISA notes that most exploited vulnerabilities in 2026 should have been eradicated decades ago, citing organisational culture failures.
Closing Remarks
The common thread across all threats is infrastructure inattention. Print servers, router firmware, and remote access tools that organisations do not actively monitor are precisely the surfaces attackers study most carefully. Practical guidance emphasises active management of unglamorous infrastructure.
NCSC Edge Device Warning, Manchester Airports Breach, and Teams Vishing
27 Aug 2026
00:13:59
NCSC Edge Device Warning, Manchester Airports Breach, and Teams Vishing
Today’s briefing examines three urgent threats to UK small businesses. The NCSC has issued a fresh alert on internet-exposed edge devices, highlighting persistent failures in patch management and configuration that attackers are actively exploiting. Manchester Airports Group has confirmed a breach affecting 8.7 million UK customers, creating significant downstream phishing risk through compromised travel data. Zscaler research details an ongoing Microsoft Teams vishing campaign deploying the GoGRPC backdoor, demonstrating how ransomware operations have industrialised initial access through collaboration platforms. The episode provides specific, actionable guidance for each threat, from verifying patch dates on VPN appliances to configuring Quick Assist controls and preparing staff for contextualised spear-phishing. We also note the arrest of two individuals connected to TeamPCP supply chain attacks. Each story is framed through the operational gaps that enable these threats, with practical steps UK SMBs can implement today.
Chapters
Introduction
Overview of three urgent threats: NCSC edge device alert, Manchester Airports data breach, and industrialised ransomware access via Microsoft Teams.
NCSC Alert on Internet-Exposed Edge Devices
Analysis of the NCSC advisory on disruptive incidents linked to unpatched VPNs, firewalls, and edge devices. Covers operational failures in patch management, specific checks for UK SMBs, and the critical Fortinet EMS vulnerability CVE-2026-35616.
Call to Action
Invitation to follow the show and share with colleagues.
Manchester Airports Group Data Breach
Examination of the 8.7 million customer breach, the downstream spear-phishing risk from exposed travel data, and practical steps for businesses whose staff or customers may be affected.
Microsoft Teams Vishing Campaign and GoGRPC Backdoor
Detailed analysis of Zscaler research on Teams-based social engineering delivering the GoGRPC backdoor. Covers the attack pattern, configuration controls for Quick Assist, and staff training requirements.
TeamPCP Supply Chain Arrests
Brief note on arrests connected to developer supply chain attacks, highlighting ongoing exposure for UK SMBs using third-party software.
Closing Summary and Actions
Consolidated practical guidance: verify patch dates, configure Quick Assist controls, brief staff on Teams vishing, and assess Manchester Airports exposure.
Ubiquiti UniFi Max-Severity Flaws and Gitea Active Exploitation
26 Aug 2026
00:13:26
Ubiquiti UniFi Max-Severity Flaws and Gitea Active Exploitation
Three maximum-severity vulnerabilities have been disclosed in Ubiquiti’s UniFi network products, all exploitable remotely without authentication. Separately, CISA has confirmed active exploitation of a critical code injection flaw in Gitea, the self-hosted Git service widely used for internal code repositories. Both disclosures highlight a persistent gap in how UK businesses secure infrastructure that sits behind the public perimeter. UniFi kit manages internal networks and physical security systems across thousands of SMBs, yet firmware updates often lag months behind current versions. Gitea servers hold development code, credentials, and API keys, but are frequently treated as lower-priority assets despite their access to production environments. The observed Gitea exploitation involves cryptominer deployment, but the real risk is remote code execution on systems that touch sensitive infrastructure. This episode examines why trusted infrastructure receives less scrutiny than customer-facing systems, and why that gap creates exploitable exposure. Mauven provides specific patch guidance, incident response steps, and asset inventory priorities for both vulnerabilities.
Chapters
Intro
Mauven introduces episode thirty-nine, focusing on infrastructure vulnerabilities that receive insufficient security attention despite supporting critical business operations.
Ubiquiti UniFi: Three Max-Severity Flaws
Three maximum CVSS score vulnerabilities disclosed in UniFi Network Application and UniFi Protect, all exploitable remotely without authentication. Covers authentication bypass and command injection risks, UK SMB deployment patterns, and immediate patching requirements.
CTA
Brief call to action encouraging listeners to follow the podcast and share with colleagues managing network infrastructure.
Gitea RCE: CISA Confirms Active Exploitation
CISA adds critical Gitea code injection vulnerability to Known Exploited Vulnerabilities catalogue following confirmed cryptominer deployment. Discusses risks to self-hosted Git repositories, credential exposure, and the need for log analysis and repository auditing.
The Trusted Infrastructure Problem
Analysis of why infrastructure supporting operations rather than serving customers receives less security scrutiny, creating exploitable gaps. Covers NCSC guidance on vulnerability management and notes a ClickFix phishing campaign using npm mirror infrastructure.
Outro
Summary of patch requirements and asset review priorities for both UniFi and Gitea. Closing remarks and episode credits.
ClickFix Malware, Check Point Bypass, and Zimbra Campaign Hits 270 Servers
25 Aug 2026
00:16:17
ClickFix Malware, Check Point Bypass, and Zimbra Campaign Hits 270 Servers
Three active threats demand immediate attention from UK small businesses today. ClickFix social engineering campaigns have matured into a multi-vector malware ecosystem using MSI packages, NodeJS execution, and fake CAPTCHA lures to deliver persistent backdoors across Windows and macOS systems. Attackers are abusing legitimate Windows tools and storing command-and-control addresses in blockchain smart contracts, making traditional network defences less effective. Check Point has confirmed active exploitation of CVE-2026-16232, a critical authentication bypass in SmartConsole that grants unauthenticated remote attackers full administrative access to firewall management servers. Organisations using managed service providers for firewall infrastructure need specific answers about exposure windows and remediation status. A remote code execution vulnerability in Zimbra Collaboration Suite has already compromised over 270 email servers, with the campaign ongoing. This episode provides actionable guidance on endpoint monitoring configuration, management server security reviews, and supplier due diligence for email hosting platforms. None of these threats are theoretical. All three are actively exploiting UK organisations today.
Chapters
Introduction
Mauven introduces three active threats affecting UK small businesses: a mature social engineering malware ecosystem, a critical firewall management authentication bypass under active exploitation, and an email server vulnerability with over 270 confirmed compromises.
ClickFix: The Social Engineering Technique That Grew Up
Analysis of ClickFix malware campaigns using MSI packages with DLL sideloading, NodeJS execution, and fake CAPTCHA lures. Coverage includes PavinLoader’s blockchain-based command-and-control infrastructure, cross-platform macOS variants, and fraudulent SysScan websites. Practical guidance on endpoint protection configuration and staff awareness training.
Call to Action
Encouragement to follow the show and share threat intelligence with professional networks to close the gap between awareness and action.
Check Point SmartConsole: Authentication Bypass Under Active Exploitation
Detailed examination of CVE-2026-16232 and accompanying privilege escalation vulnerabilities in Check Point SmartConsole. Focus on exploitation conditions, attack chains, and specific questions UK SMBs must ask managed service providers about exposure and remediation.
Zimbra RCE: 270 Servers Down, Campaign Ongoing
Coverage of the ongoing Zimbra Collaboration Suite remote code execution campaign affecting over 270 instances. Discussion of supply chain risks through managed hosting providers and the operational impact of email server compromise. Guidance on verification and patching.
Closing Remarks
Mauven identifies the common thread across all three threats: attackers exploiting configuration gaps and awareness failures rather than extraordinary techniques. Recap of actionable steps for endpoint monitoring, supplier verification, and staff training.
Zimbra Zero-Click RCE, Check Point Bypass, and Device Code Phishing
24 Aug 2026
00:18:07
Zimbra Zero-Click RCE, Check Point Bypass, and Device Code Phishing
This episode examines three active threats demanding immediate attention from UK small businesses. First, a zero-click remote code execution vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) under active exploitation by Russian-linked threat actors, with a three-day federal patch deadline from CISA. Second, an authentication bypass flaw in Check Point SmartConsole (CVE-2026-16232) allowing unauthenticated remote attackers full administrative access to exposed management servers. Third, a vishing and device code phishing campaign by the Helix data extortion group that requires no malware and leaves minimal forensic trace. The episode emphasises that all three threats exploit the gap between what organisations have configured and what they actually review. Practical actions include patching Zimbra immediately, verifying Check Point management interfaces are IP-restricted, enabling Microsoft 365 unified audit logging, and training staff on device code phishing recognition. The common thread is organisational discipline: knowing what is running in your environment, how it is configured, and whether anyone is reviewing the evidence of activity within it.
Chapters
Introduction
Mauven introduces three threats for 24 August 2026: two confirmed, actively exploited vulnerabilities with patches available, and a social engineering campaign that leaves no malware trace. The third threat is identified as the most dangerous for UK small businesses reliant on endpoint detection alone.
Zimbra Zero-Click RCE Under Active Exploitation
CISA has added CVE-2025-66376, a zero-click remote code execution flaw in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities catalogue with a three-day federal patch deadline. The vulnerability is being exploited by Russian-linked threat actor Void Blizzard (LAUNDRY BEAR) in a systematic credential harvesting operation targeting government, defence, transportation, and financial sector organisations across NATO member states. UK small businesses, particularly legal firms, accountancy practices, and professional services running on-premises email, must patch immediately, verify Zimbra deployment status, restrict internet access if patching cannot occur immediately, and review access logs for anomalous activity.
Call to Action
Listeners are encouraged to follow the show and share the briefing with colleagues who can act on the information presented.
Check Point SmartConsole Authentication Bypass
Check Point has confirmed active exploitation of CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that allows unauthenticated remote attackers full administrative access to exposed Management Servers. Exploitation has been confirmed against customers with management interfaces exposed to the internet without IP restrictions. UK organisations using Check Point products must apply security updates immediately, verify all management interfaces are IP-restricted with documentation, review access logs for authentication attempts from unexpected sources, and confirm managed service providers have patched all deployments.
Helix Vishing and Device Code Phishing
ReliaQuest has documented a data extortion group named Helix running a three-stage attack requiring no malware: vishing calls impersonating managers using open-source research from LinkedIn and company websites, device code phishing directing employees to enter codes into legitimate Microsoft authentication pages to grant attackers persistent access tokens, and automated SharePoint exfiltration. The campaign leaves no endpoint detection evidence and is only visible in Microsoft 365 unified audit logs. UK small businesses must brief all staff on device code phishing, establish verbal verification procedures for credential-related requests, enable unified audit logging in Microsoft 365, and consider Conditional Access policies restricting device code authentication flows.
The Pattern This Week
All three threats exploit the gap between what organisations have configured and what they have reviewed. Zimbra instances not audited since deployment, management interfaces opened for remote access and never locked down, and Microsoft 365 audit logs not being read represent ordinary accumulated drift rather than exotic failures. The adversaries target organisations that have not implemented basic controls, and the discipline required to close these gaps is organisational rather than technical.
Conclusion
The practical takeaway is to answer three questions immediately: is Zimbra running anywhere in your environment, is any network device management interface accessible from the internet without IP restriction, and is unified audit logging enabled in your Microsoft 365 tenant. If the answers are unknown, organisations must find out today.
Teams Impersonation and Rust Supply Chain Attacks Hit UK SMBs
21 Aug 2026
00:13:22
Teams Impersonation and Rust Supply Chain Attacks Hit UK SMBs
This episode examines two unconnected but similarly exploitative campaigns targeting UK small businesses in August 2026. The first, SynkLoader, uses Microsoft Teams to impersonate IT helpdesk staff, delivering memory-resident malware through plausible maintenance requests. The attack succeeds because default Teams external access settings allow unrestricted messages from unknown tenants. The second involves a coordinated supply chain attack against three legitimate Rust programming language packages, injecting malicious code through a typosquatted dependency that executes during software builds. Both campaigns exploit trust in familiar channels rather than technical vulnerabilities. Mauven MacLeod explains why these attacks work, what they reveal about default configurations in SMB environments, and provides actionable steps: restricting Teams external federation, establishing clear IT contact protocols, auditing Rust dependencies for the malicious proc-macro1 package, and questioning software vendors about supply chain verification. The episode emphasises that effective defence requires deliberately changing insecure defaults, not advanced security tooling.
Chapters
Introduction
Mauven introduces two active campaigns targeting UK small businesses through trusted channels: a Teams-based helpdesk impersonation attack and a Rust programming language supply chain compromise. Both exploit default configurations rather than technical vulnerabilities.
SynkLoader: When Your IT Helpdesk Comes to You
Analysis of SynkLoader malware delivered via Microsoft Teams helpdesk impersonation. The attack uses MSI installers to deploy multi-language, memory-resident malware that bypasses endpoint detection, establishes command-and-control access, and captures credentials through fake lock screens. Succeeds because default Teams external access settings allow unrestricted external messages.
Call to Action
Encouragement to follow the show and share with colleagues who would benefit from daily threat intelligence briefings.
Rust Supply Chain: The Dependency You Did Not Know You Had
Examination of a coordinated supply chain attack against three legitimate Rust packages through a typosquatted dependency called proc-macro1. Malicious code executed during software builds, potentially compromising both bespoke software and commercial products. Highlights the gap in SMB software procurement processes around supply chain verification.
The Wider Picture
Connects both campaigns through their exploitation of trust in familiar channels and legitimate-seeming sources. Emphasises that effective attacks against small businesses rely on familiarity rather than technical sophistication, and that changing insecure defaults requires deliberate decisions.
Closing
Recap of practical actions: verify Teams external federation settings and question IT providers about software supply chain verification processes. Two questions that reveal the current security posture.
MLflow Exploitation, NetScaler Emergency Patch, and European Banking Trojan
20 Aug 2026
00:14:38
MLflow Exploitation, NetScaler Emergency Patch, and European Banking Trojan
CISA has confirmed active exploitation of a critical MLflow vulnerability, demanding immediate action from any organisation running AI or machine learning infrastructure. The server-side request forgery flaw allows attackers to access internal systems, and deployment patterns mean the platform often sits outside normal security review cycles. Separately, Citrix has issued an urgent advisory for NetScaler Gateway and ADC vulnerabilities, with language reflecting high exploitation likelihood. The perimeter-facing nature of these widely deployed remote access solutions makes them priority targets. Finally, the Manic Android banking trojan is spreading across Europe with a relay-based exfiltration capability that partially defeats network controls, raising BYOD security questions for UK small businesses. The NCSC has also published new guidance on managing agentic AI cyber risk, connecting to broader concerns about autonomous systems acting on behalf of users without adequate security review.
Chapters
Introduction
Mauven opens with three stories requiring immediate action: a CISA-confirmed active exploitation, an urgent Citrix advisory, and a European banking malware threat relevant to UK businesses.
MLflow Under Active Exploitation
CISA adds MLflow to the Known Exploited Vulnerabilities catalogue following confirmed active attacks. The server-side request forgery vulnerability affects AI and machine learning deployments that often sit outside normal security review cycles, creating exposure many organisations may not be aware of.
Call to Action
Listeners are encouraged to follow the show and share the briefing, particularly with those managing IT for small businesses who need urgent awareness of the MLflow exploitation.
Citrix NetScaler Emergency Advisory
Citrix issues urgent patching guidance for NetScaler Gateway and ADC vulnerabilities. The perimeter-facing nature of these widely deployed products, combined with Citrix’s deliberate use of emergency language, signals high exploitation risk requiring immediate verification with IT providers.
Manic Android Malware in Europe
The Manic banking trojan spreads across Europe with relay-based exfiltration capability that routes stolen data through nearby infected devices, partially defeating network controls. BYOD practices in UK small businesses create exposure when personal Android devices access work accounts.
NCSC Guidance on Agentic AI
The NCSC publishes guidance on managing cyber risk from autonomous AI systems that act on behalf of users. Prompt injection attacks against agentic AI tools represent an escalating threat as these systems gain access to business accounts and services.
Closing
Mauven connects the common thread across all stories: security gaps emerge when deployment outpaces security review. The practical priority is knowing what runs in your environment, who manages it, and how responsibility is verified.
Critical Windows RCE Under Active Exploit, Clop Custom Tooling, and MFA Bypass Phishing
19 Aug 2026
00:17:56
Critical Windows RCE Under Active Exploit, Clop Custom Tooling, and MFA Bypass Phishing
This episode covers three active threats with credible paths to UK small businesses. First, CISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation against network-reachable systems. Second, Clop ransomware has returned with purpose-built tooling targeting PTC Windchill in manufacturing supply chains, deploying custom web shells designed for credential harvesting and data exfiltration. Third, the Mirage2FA phishing-as-a-service platform is bypassing multifactor authentication through adversary-in-the-middle session token theft, with over four thousand confirmed Microsoft 365 victims. Mauven explains the technical mechanisms behind each threat, identifies the specific organisations at risk, and provides actionable steps that require no budget approval: verifying Windows patch status for IKE Extension, questioning manufacturing suppliers about Windchill patching, and reviewing Microsoft 365 conditional access policies to detect session anomalies. The episode also notes FBI confirmation of Medusa ransomware breaching over five hundred US critical infrastructure organisations using living-off-the-land techniques. All three primary threats demonstrate that speed of response, supplier questioning, and configuration review matter more than technology spending for most small business cyber resilience.
Chapters
Introduction
Mauven introduces three threats with credible UK small business impact: a Windows vulnerability under active exploitation, Clop ransomware with custom tooling, and an MFA-bypassing phishing platform.
Windows IKE Extension RCE: CISA KEV Addition
CISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue. The flaw is network-reachable, requires no authentication, and allows arbitrary code execution. Mauven explains why active exploitation status demands immediate Windows patch verification, particularly for organisations using Windows-based VPN solutions.
Support the Show
Brief call to action encouraging listeners to follow the show and share with business owners who need operational threat intelligence.
Clop Returns with Purpose-Built Tooling
Clop ransomware is targeting PTC Windchill in manufacturing and engineering supply chains using custom-developed web shells. ReliaQuest analysis confirms the toolkit includes credential harvesting, database enumeration, and Java-based exfiltration components. Mauven explains the supply chain exposure risk and recommends questioning suppliers about Windchill patching status.
Mirage2FA Phishing-as-a-Service Bypasses MFA
Mirage2FA operates as an adversary-in-the-middle proxy, capturing authenticated Microsoft 365 session tokens after users complete MFA. ANY.RUN analysis identifies over four thousand victims. Mauven explains why MFA alone is insufficient without conditional access policies detecting impossible travel and anomalous session use.
Medusa Ransomware Context
FBI confirms Medusa ransomware has breached over five hundred US critical infrastructure organisations since June 2021 using phishing, unpatched vulnerabilities, and living-off-the-land techniques. Mauven notes the tactics are internationally relevant and the confirmed victim count likely understates true impact.
Summary and Actions
Three actions requiring no budget: verify Windows IKE Extension patch deployment, question manufacturing suppliers about PTC Windchill patching, and review Microsoft 365 conditional access configuration to detect session token theft. Mauven emphasises that difficulty having these conversations is itself diagnostic of resilience gaps.
Windows Task Host Ransomware Exploitation and Microsoft Copilot Injection Flaw
18 Aug 2026
00:14:01
Windows Task Host Ransomware Exploitation and Microsoft Copilot Injection Flaw
Two Microsoft vulnerabilities demand immediate attention from UK small businesses running Windows endpoints and Microsoft 365. CISA has confirmed active ransomware exploitation of the Windows Task Host privilege escalation flaw, four months after its initial disclosure. This vulnerability allows attackers who have gained initial access to escalate to system-level privileges, enabling lateral movement and full ransomware deployment. Separately, Microsoft has disclosed CVE-2026-24301, a command injection vulnerability in Copilot that enables information disclosure across the entire Microsoft 365 data estate. Because Copilot operates within user permission contexts, the vulnerability exposes whatever data those users can access, including financial records, HR files, and confidential client information. Researchers have also documented C2Looper, a Rust-based backdoor that uses GitHub for command-and-control traffic and connects to ClickFix infection chains. Together, these developments illustrate a complete ransomware kill chain from initial access through privilege escalation to deployment. Organisations must confirm Windows patch status today, review Copilot access permissions against the principle of least privilege, and brief staff on ClickFix lures that present as fake browser error messages.
Chapters
Introduction
Overview of two Microsoft vulnerabilities affecting Windows endpoints and Microsoft 365, both requiring immediate action. CISA has confirmed ransomware exploitation of the Windows Task Host flaw, whilst Microsoft has disclosed a command injection vulnerability in Copilot.
Windows Task Host Ransomware Exploitation
Analysis of the Windows Task Host privilege escalation vulnerability, now confirmed by CISA as actively exploited by ransomware groups. Explains how attackers use the flaw to escalate from low-privilege access to system-level control, enabling lateral movement and full estate compromise. Four months have passed since disclosure.
Call to Action
Encouragement to follow the show and share it with others who need threat intelligence information.
CVE-2026-24301 Microsoft Copilot Command Injection
Examination of the newly disclosed command injection vulnerability in Microsoft Copilot. Explains how Copilot’s deep integration with Microsoft 365 data means the vulnerability exposes entire organisational data estates through user permission contexts. Addresses the risk of default enablement and the need for permissions audits.
C2Looper and Ransomware Delivery Chains
Overview of C2Looper, a Rust-based backdoor that uses GitHub for command-and-control traffic, and its connection to ClickFix infection chains. Describes the complete ransomware kill chain from initial access through privilege escalation, emphasising the importance of staff awareness training on ClickFix techniques.
Conclusion
Practical summary of required actions: confirm Windows patch status immediately, review Copilot access permissions, apply least privilege principles, and brief staff on ClickFix lures this week.
Clop, ShinyHunters, and SAP: When Supplier Risk Becomes Attack Surface
14 Aug 2026
00:14:02
Clop, ShinyHunters, and SAP: When Supplier Risk Becomes Attack Surface
Three distinct threat campaigns broke on 14 August 2026, and each one targets the same vulnerability: supplier and third-party infrastructure. Clop ransomware claimed 89GB of Shell data via managed file transfer platforms, continuing a six-year pattern of targeting MFT tools across supply chains. ShinyHunters exposed 1.6 million RingCentral accounts while simultaneously running OAuth abuse campaigns against Salesforce and other SaaS platforms, weaponising legitimate integrations and voice phishing. A maximum-severity SAP Commerce Cloud vulnerability moved from patch release to active exploitation in just three days. Meanwhile, supplier breaches at the Crown Office and Procurator Fiscal Service in Scotland and Trezor’s logistics partner reinforce the same pattern: organisations with sound internal controls are being compromised through third-party infrastructure they don’t directly manage. This briefing explains why managed file transfer platforms, OAuth connections, and unpatched supplier software represent the dominant attack surface in 2026, and provides actionable steps for UK small businesses to identify and close these exposure gaps before threat actors exploit them.
Chapters
Introduction
Three separate threat streams reveal a unified pattern: organisations with well-managed internal environments are being compromised through supplier infrastructure, SaaS integrations, and third-party software.
Clop Claims Shell: The Method Is Six Years Old
Clop ransomware claimed 89GB of Shell data via PTC FlexPLM and Windchill platforms. Team Cymru analysis shows Clop has run nine campaigns over six years, systematically targeting managed file transfer tools across supply chains.
Call to Action
Encouragement to follow the show and share with colleagues who may underestimate their exposure to supplier-based threats.
ShinyHunters Pivots from Data Theft to SaaS Infiltration
ShinyHunters breached RingCentral, exposing 1.6 million accounts, while simultaneously running OAuth abuse campaigns against Salesforce and other SaaS platforms using voice phishing, supply chain compromise, and credential theft.
SAP Commerce Cloud: Maximum Severity, Already Exploited
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud moved from patch release to active exploitation in three days, compressing response windows and exposing retailers and e-commerce operators.
The Pattern Underneath Today’s Stories
Clop, ShinyHunters, and the SAP campaign all exploit third-party and supplier exposure. Additional breaches at Crown Office Scotland and Trezor’s logistics partner reinforce that supplier risk is the dominant attack surface in 2026.
Closing
Practical takeaways: map supplier access, audit OAuth connections, patch on severity rather than schedule, and brief staff on voice phishing tactics targeting legitimate application approval processes.
Today’s episode tackles key cybersecurity challenges facing UK small and medium enterprises. We delve into the exploits by the Russian-aligned group TA488, discuss vulnerabilities such as CVE-2026-42897, and examine the broader impact of cyber incidents beyond primary targets. Learn about the MacSync Stealer threat to macOS and the potential risks associated with Anthropic’s Claude AI models. Finally, we explore the recent CAF Bank incident affecting thousands of charities. Each section offers insights and actionable steps to bolster your organisation’s security posture amidst these evolving threats.
Chapters
Intro
Introduction to key cybersecurity issues facing UK businesses, including TA488 exploits and AI vulnerabilities.
CVE-2026-42897 and TA488
Discusses the CVE-2026-42897 vulnerability exploited by TA488 and the importance of patch management.
CTA
Encourages listeners to follow the podcast and share it with others who might benefit.
MacSync Stealer on macOS
Explores the MacSync Stealer threat via Google Ads affecting macOS users and stresses the need for education and advanced protection.
Anthropic’s Claude AI Models
Examines issues of AI containment and security with Claude AI models, urging robust governance frameworks.
CAF Bank Incident
Analyzes the cyber incident affecting CAF Bank, highlighting the importance of financial security measures and contingency plans.
Outro
Concludes with a call for vigilance and accountability in tech environments to secure against threats.
In today’s episode of Threat Analysis, Mauven MacLeod delves into critical cybersecurity challenges confronting UK small businesses. We address Russian state-sponsored email attacks targeting Microsoft Outlook with a unique ‘half-click’ method, which offers notable resilience against traditional security measures. Understanding the implications of such threats is essential for businesses to protect their digital environments and reputations.
Additionally, we examine the rise of attacks within the npm registry, impacting software development operations. This new threat utilises worm-like behaviours to infiltrate popular packages and steal credentials via blockchain transactions. These complex methods highlight the importance of thorough vigilance and robust security strategies for companies relying on open-source software.
Mauven emphasises the necessity of incorporating comprehensive security measures, combining human and technological approaches, to effectively manage and counter these evolving threats. Don’t miss out on the need for keen awareness and proactive defences in safeguarding your business.
Chapters
Intro
Mauven highlights the critical cyber threats facing UK SMBs and the importance of robust security.
Russian State-Sponsored Email Attacks Targeting Outlook
Discussion on the ‘half-click’ method used by Russian hackers in Outlook attacks, emphasising resilience and the need for awareness.
CTA
Encouragement to follow the show and share with those who need cybersecurity insights.
NPM Registry Hosting New Supply Chain Attacks
Exploration of worm-like attacks within the npm registry targeting credentials via blockchain, calling for vigilant dependency management.
Outro
Conclusion on the necessity of proactive cybersecurity measures for UK SMBs, previewing future threat analyses.
Cyber Threats: Helpdesk Attacks and WordPress Risks
28 Jul 2026
00:07:04
Cyber Threats: Helpdesk Attacks and WordPress Risks
Mauven MacLeod presents today’s Threat Analysis, focusing on pressing cyber threats faced by UK small and medium businesses. She explores two major issues: vishing attacks exploiting Microsoft Teams and vulnerabilities in WordPress. Vishing attacks target companies through Microsoft Teams, where attackers impersonate IT helpdesk staff and deploy the GoGRPC backdoor. This can lead to ransomware attacks, compromising sensitive company data. Mauven emphasises the importance of staff awareness and technological safeguards to mitigate risks. The episode also highlights critical vulnerabilities in WordPress Core, affecting versions 6.9.0 to 7.0.1. These vulnerabilities allow unauthorised remote code execution, potentially leading to total site takeovers. Businesses are urged to apply patches immediately to protect their websites and customer data. The National Cyber Security Centre underlines the urgency of this action. Mauven stresses that these insights should lead to a comprehensive cybersecurity strategy, incorporating regular updates, employee training, and robust security policies.
Chapters
Intro
Mauven introduces the episode’s focus on cyber threats targeting UK businesses: Microsoft Teams vishing attacks and WordPress vulnerabilities.
Helpdesk Hijackers: Microsoft Teams Vishing Attacks
Discussion of vishing attacks via Microsoft Teams, where attackers exploit helpdesk impersonations to deploy the GoGRPC backdoor, posing risks to UK businesses.
CTA
A call to action for listeners to follow the podcast for daily briefings and share it with others who might benefit.
WordPress Vulnerabilities: wp2shell Threat
Overview of critical vulnerabilities in WordPress versions 6.9.0 to 7.0.1, allowing remote code execution. Emphasises the need for immediate patches.
Implications for UK SMBs
The importance of integrating cybersecurity into business culture, ensuring systems and staff are well-prepared against current threats.
Outro
Mauven wraps up with a reminder to remain vigilant and to use these insights to strengthen business security.
In today’s episode, Mauven MacLeod tackles pressing vulnerabilities affecting UK small and medium businesses. Microsoft’s Defender for Endpoint is under scrutiny due to bugs that leave Linux systems unprotected. From installation issues on hardened RHEL systems to deactivation on restart, these glitches pose significant security risks. Attention is drawn to Java Spring Boot’s exposed endpoints revealing sensitive data, underscoring GDPR compliance risks. The discussion moves to critical vulnerabilities, CVE-2026-16461 and 8450, and their severe implications. Finally, Google’s cybercrime taxonomy offers new insights into defending against threats. It’s an urgent call to action for businesses to address these threats promptly.
Chapters
Intro
Introduction to the urgency of addressing security vulnerabilities for UK businesses.
Microsoft Defender for Endpoint
Analysis of vulnerabilities in Microsoft Defender, affecting Linux systems and RHEL installations.
Java Spring Boot Vulnerabilities
Exposed heapdump endpoints in Java Spring Boot pose risks of data exposure and GDPR violations.
Microsoft Security Response
Critical vulnerabilities CVE-2026-16461 and CVE-2026-8450 discussed with potential impacts.
Google’s Cybercrime Taxonomy
Google’s new cybercrime taxonomy aids in understanding and targeting specific threats effectively.
Outro
Final thoughts on the need for urgent action to secure business systems against vulnerabilities.
In today’s episode of Threat Analysis, Mauven MacLeod explores two significant cyber threats impacting UK small and medium-sized businesses: the Mistic backdoor and the FortiBleed campaign. Both threats exploit vulnerabilities requiring immediate attention. The Mistic backdoor, potentially operated by the notorious access broker Woodgnat, uses sideloading attacks to infiltrate systems. This method often goes unnoticed and has been a staple in cybercriminal activities for years, affecting industries like professional services and healthcare. Mauven emphasises the importance of meaningful conversations with IT teams to mitigate such risks and secure vendor relationships effectively. The episode then shifts focus to the FortiBleed campaign, which targets Fortinet’s FortiGate firewalls. These essential components of network security are under significant threat as FortiBleed employs an immediate credential theft strategy. This can escalate from potential risk to an operational crisis rapidly. Mauven advises businesses to apply necessary patches promptly and enhance network monitoring protocols to detect unusual activities. Both threats underscore the necessity for proactive cybersecurity measures.
Chapters
Intro
Mauven introduces the episode’s focus on two cyber threats, Mistic backdoor and FortiBleed, highlighting the urgency for UK businesses to address these vulnerabilities.
Mistic Backdoor: Initial Access and Credential Theft
Discussion on Mistic backdoor’s sideloading attacks by Woodgnat. Emphasises the need for businesses to engage with IT teams to mitigate risks and secure systems effectively.
CTA
Encouragement to follow the podcast for daily updates and share with others who could benefit from the information.
FortiBleed Campaign: A Primer on Credential Harvesting
Analysis of the FortiBleed campaign targeting Fortinet FortiGate firewalls. Highlights the urgent requirement for applying patches and enhancing network monitoring protocols.
Outro
Reinforces the necessity for vigilance and proactive measures in cybersecurity strategies. Encourages continual threat assessment and response.
UK SMBs Face Ransomware Re-Extortion and Langflow Threats
22 Jul 2026
00:07:07
UK SMBs Face Ransomware Re-Extortion and Langflow Threats
In this episode of Threat Analysis, Mauven MacLeod explores critical cyber threats that UK small and medium-sized businesses (SMBs) must be aware of. The discussion begins with the increasing trend of ransomware re-extortion, where attackers demand additional payments even after receiving a ransom. Proofpoint reports show over a third of victims are affected by this tactic, highlighting the necessity for robust cybersecurity measures. The episode also covers a significant vulnerability in Langflow, as identified by CISA, which allows remote code execution and is being actively exploited. Mauven stresses the importance of immediate patching to secure AI systems against potential breaches. Additionally, the new JADEPUFFER ransomware poses a risk to AI models critical to business operations. Lastly, a vulnerability in Adobe’s Chrome extension exposes WhatsApp chats to unauthorised access, underscoring the need for secure communication policies. Join Mauven for insights into these pressing cybersecurity challenges.
Chapters
Intro
Introduction to the episode’s focus on critical cyber threats for UK SMBs.
Ransomware Re-Extortion
Discussion on the trend of ransomware re-extortion affecting over a third of victims.
CTA
Encouragement to follow the podcast for regular updates.
Langflow RCE Vulnerability
Exploration of a critical vulnerability in Langflow allowing remote code execution.
JADEPUFFER Ransomware
Examination of JADEPUFFER ransomware targeting AI models and infrastructure.
Adobe Chrome Extension Vulnerability
Coverage of a security flaw in Adobe’s Chrome extension impacting WhatsApp security.
Outro
Conclusion with a call to action to strengthen cybersecurity defences.
Protecting Against Ransomware and Evolving Cyber Threats
21 Jul 2026
00:06:33
Protecting Against Ransomware and Evolving Cyber Threats
In today’s briefing, Mauven MacLeod delves into imperative cybersecurity updates impacting UK businesses. The Qilin ransomware gang is actively exploiting a critical flaw in Palo Alto Networks’ GlobalProtect VPN, posing significant risks even to small enterprises. This episode underscores why businesses of all sizes must prioritise security updates to guard against cybercriminals. Additionally, Mauven discusses the emerging Jadepuffer group targeting AI technologies and the HOLLOWGRAPH campaign, which ingeniously utilises Microsoft 365 calendars for sinister purposes. The episode highlights the necessity for vigilant, proactive security practices and the importance of continuous education in the face of evolving threats.
Chapters
Intro
Mauven introduces the episode, focusing on the Qilin ransomware gang exploiting a VPN flaw and emphasising the need for all businesses to be vigilant.
Qilin Ransomware Exploits VPN Flaw
Analysis of the Qilin ransomware exploiting a critical VPN vulnerability and its implications for businesses of all sizes.
CTA
Encouragement to follow the podcast for regular updates.
Evolving Ransomware Tactics and Jadepuffer
Discussion on Jadepuffer targeting AI models and the importance of staying ahead of sophisticated cyber threats.
HOLLOWGRAPH Campaign Risks
Overview of the HOLLOWGRAPH campaign using Microsoft 365 calendars for espionage, urging businesses to reassess security measures.
Outro
Concluding remarks on the importance of staying informed and proactive against digital threats.
ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing
20 Jul 2026
00:15:43
ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing
Three critical threats demand immediate attention today. A remote code execution vulnerability in ServiceNow’s AI Platform (CVE-2026-6875) is now actively exploited in the wild, requiring urgent patch verification from direct users and managed service providers alike. Meanwhile, a vishing campaign running since April has been successfully defeating Microsoft 365 passkey enrolment through carefully scripted social engineering, targeting UK SMBs who adopted phishing-resistant MFA but failed to brief staff on the human attack vector. The third story examines FortiBleed, an industrial-scale FortiGate credential harvesting operation exposed when attackers left their staging server accessible, revealing 36 rented GPUs running distributed password cracking as a production workflow. The episode also covers the Cruciferra crypter service, which offers high-quality endpoint evasion as a purchased feature, and the Hugging Face breach involving an autonomous AI agent. Each story includes specific, actionable guidance for UK organisations, with particular emphasis on the ServiceNow vulnerability requiring same-day verification from users and their supply chain.
Chapters
Introduction
Mauven flags three threats requiring immediate action, particularly a ServiceNow vulnerability that has moved from patch-available to actively exploited. The episode will cover required responses for ServiceNow users, Microsoft 365 passkey vishing, and industrial-scale FortiGate credential harvesting.
CVE-2026-6875: ServiceNow AI Platform RCE Under Active Exploitation
Critical remote code execution vulnerability in ServiceNow AI Platform confirmed under active exploitation. Direct users must verify patch status immediately. Indirect exposure through managed service providers presents significant risk to UK SMBs. Specific guidance provided on what questions to ask providers and when patch confirmation is required.
Call to Action
Brief encouragement to follow the show and share with colleagues who need the briefing.
O-UNC-066: Vishing Actors Defeating Microsoft 365 Passkey Enrolment
Campaign active since April uses phone-based social engineering to register attacker-controlled passkeys to victim Microsoft 365 accounts. Attackers use domains containing ‘passkey’, impersonate Microsoft support, and guide targets through fake enrolment while simultaneously registering their own credentials. Three-part mitigation: restrict enrolment policies in Entra, brief staff on the attack pattern, and focus training on reception and finance staff most likely to receive calls.
FortiBleed: Industrial-Scale VPN Credential Harvesting
Exposed attacker staging server reveals large-scale FortiGate credential harvesting using 36 rented GPUs for distributed password cracking. Operation uses credential reuse, brute force, and GPU-accelerated hash cracking as an industrial workflow. Likely feeds initial access broker market serving ransomware operators. Guidance provided on verifying patch status, rotating credentials, and reviewing authentication logs.
Also on the Radar
Two additional items: Cruciferra crypter service offering high-quality endpoint evasion including BYOVD-based EDR tampering as a purchased feature, and Hugging Face breach involving autonomous AI agent access to production infrastructure and credentials. Both items flag direction of travel rather than immediate operational response.
Closing Summary
Recap of required actions: ServiceNow patch verification today, Microsoft 365 Entra policy review and staff briefing on vishing, FortiGate patch status and credential rotation. Emphasises that attackers operate at industrial scale while effective defences require consistent follow-through on straightforward measures.
FortiSandbox Exploit, Windows Zero-Day, and ClickFix Infrastructure at Scale
17 Jul 2026
00:14:21
FortiSandbox Exploit, Windows Zero-Day, and ClickFix Infrastructure at Scale
CISA added critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed in-the-wild exploitation. The US federal patching deadline is Sunday, but active exploitation means UK organisations should treat this as immediate priority. A newly published Windows local privilege escalation vulnerability called LegacyHive works on fully patched systems with no fix available, creating serious risk when combined with active ClickFix campaigns delivering initial access. ClickFix techniques now support at least five concurrent malware operations including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A Huntress case study documents how one ClickFix compromise spread to eleven hosts before detection. The episode provides specific, actionable guidance for SMBs: verify FortiSandbox patch status with IT providers today, brief staff on ClickFix lures immediately, review user permissions to execute scripts, and ensure endpoint detection monitors for HTA execution and PowerShell spawning from browser processes. The convergence of mature exploit infrastructure, public zero-day proof-of-concept, and active campaigns targeting European users represents a significant immediate threat to UK small business networks.
Chapters
Introduction
Mauven opens the seventeenth of July briefing with three urgent stories. Two require immediate technical action before the weekend, whilst the third demands procedural response to an unpatched vulnerability.
FortiSandbox Active Exploitation
CISA confirmed active exploitation of critical FortiSandbox command injection vulnerabilities, ordering US federal agencies to patch by Sunday. FortiSandbox is a threat analysis appliance, not the firewall, creating particular concern as the security tool itself becomes attack surface. Guidance covers immediate patching requirements, how to verify MSP compliance, and the importance of asset inventory for unknown Fortinet deployments.
Call to Action
Brief appeal to follow the show and share with colleagues who need threat intelligence.
LegacyHive Zero-Day Vulnerability
A public proof-of-concept for Windows local privilege escalation called LegacyHive works on fully patched systems with no available fix. The vulnerability requires initial access first, which current ClickFix campaigns are actively providing across European targets. Defence recommendations focus on preventing initial compromise through application allow-listing, endpoint detection configuration, and staff awareness of ClickFix techniques.
ClickFix Campaign Infrastructure
At least five distinct malware operations now use ClickFix delivery techniques, including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A detailed Huntress case study shows one ClickFix compromise spreading to eleven hosts. Practical guidance includes immediate staff briefing, permission reviews to block arbitrary script execution, and verification that managed detection providers monitor relevant observable behaviours.
Conclusion
The convergence of mature ClickFix infrastructure, public Windows zero-day exploitation capability, and continuing Fortinet vulnerability exploitation represents the gap between published guidance and implemented defences. Two immediate actions: verify FortiSandbox patch status and brief staff on ClickFix lures before Friday.
Social Engineering, Trojanised Tools, and Supply Chain Attacks
16 Jul 2026
00:16:50
Social Engineering, Trojanised Tools, and Supply Chain Attacks
This episode examines three contemporary threats exploiting trusted channels. Following the sentencing of two Scattered Spider members for the Transport for London breach, we analyse why social engineering remains devastatingly effective against organisations of all sizes. We then review a Russian campaign distributing trojanised WebEx and Zoom installers delivering Starland RAT, demonstrating how legitimate software becomes an attack vector. Finally, we cover the AsyncAPI npm supply chain compromise, where GitHub Actions vulnerabilities enabled injection of Miasma v3 worm into packages with valid provenance attestations. The common thread: attackers succeed not through technical brilliance, but by exploiting routine trust in familiar processes. We provide actionable guidance on helpdesk authentication procedures, software download verification, and dependency chain auditing. Additional coverage includes CISA’s Oracle E-Business Suite KEV listing and the approaching Windows 10 end-of-support deadline. Presented by Mauven MacLeod with behavioural analysis and concrete defensive measures for UK small businesses.
Chapters
Introduction
Opening remarks establishing the episode’s central theme: trusted channels being weaponised through social engineering, trojanised software, and compromised dependencies.
Scattered Spider Sentencing
Analysis of two British Scattered Spider members receiving five-and-a-half-year sentences for the Transport for London breach, focusing on the social engineering techniques used and practical implications for SMB helpdesk procedures.
Call to Action
Audience engagement request encouraging listeners to follow the show and share with business owners.
Trojanised WebEx and Zoom
Examination of Russian actor UAT-11795 distributing backdoored collaboration software installers through phishing and search poisoning, delivering Starland RAT with credential theft and cryptocurrency targeting capabilities.
AsyncAPI npm Supply Chain Compromise
Technical breakdown of the AsyncAPI organisation compromise via GitHub Actions vulnerability, resulting in Miasma v3 worm delivery through four npm packages with valid provenance attestations and novel execution timing.
Also on the Radar
Brief coverage of CISA’s Oracle E-Business Suite KEV addition and the approaching Windows 10 end-of-support deadline for Home and Pro editions.
Closing Remarks
Summary emphasising verification over assumption, with specific guidance on questioning helpdesk authentication procedures.
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack
15 Jul 2026
00:15:47
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack
On 15 July 2026, Mauven MacLeod examines three active threats facing UK organisations. CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation targeting on-premises deployments, with particular exposure among professional services firms still running legacy infrastructure. The second story details a misconfigured phishing operation that exposed 218 confirmed victims across twelve countries using Adversary-in-the-Middle techniques that bypass standard multi-factor authentication, including OAuth Device Code Flow attacks against Microsoft 365 and Google Workspace users. Finally, a supply chain attack against the AsyncAPI generator repository saw an attacker exploit a misconfigured GitHub Actions workflow to publish five malicious npm packages containing the Miasma botnet loader, which executes at import time without user interaction. The briefing emphasises that none of these attacks relied on novel techniques or nation-state resources, but succeeded through known vulnerabilities, unpatched systems, and insufficient authentication controls.
Chapters
Introduction
Mauven opens the 15 July 2026 briefing, noting three stories involving confirmed victims and active exploitation, all stemming from known weaknesses rather than novel attack methods.
SharePoint Server: Three CVEs, Active Exploitation, Patch Now
CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaws affect on-premises deployments, not SharePoint Online. UK professional services firms, legal practices, and accountancy firms running legacy on-premises infrastructure face elevated risk. Mauven emphasises that KEV listing represents a late warning, not an early one, and calls for immediate patching and documented remediation.
Call to Action
Mauven encourages listeners to follow the show and share it with colleagues who would benefit from daily threat intelligence briefings.
AiTM Phishing: Three Operators Exposed, 218 Confirmed Victims
Lexfo researchers discovered a misconfigured Python HTTP server that exposed the infrastructure of three phishing operators, including one with 218 confirmed victims using OAuth Device Code Flow attacks and another operating an Adversary-in-the-Middle platform since 2018. AiTM attacks bypass standard multi-factor authentication by intercepting authenticated session tokens. Mauven explains why phishing-resistant MFA such as FIDO2 is necessary and provides specific guidance on OAuth Device Code Flow recognition and conditional access policy review.
AsyncAPI npm Supply Chain: Poisoned Packages, Botnet Loader
An attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository to exfiltrate a privileged access token, then published five malicious npm packages containing the Miasma botnet loader. The malicious code executes at import time without user interaction. Mauven advises organisations to audit AsyncAPI-related dependencies, review build logs from 14 July, and verify whether technology partners have assessed their exposure.
Also Worth Noting
The NCSC has announced that certified Cyber Advisors are offering free thirty-minute consultations for small businesses. Microsoft has halted Patch Tuesday updates for some Dell devices following reports of shutdowns and overheating.
Closing Remarks
Mauven concludes by noting that all three stories involve exploitation of known weaknesses through patience and known techniques, rather than exotic capabilities. The briefing emphasises checking on-premises SharePoint deployments and treating patching as an urgent priority.
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure
14 Jul 2026
00:15:07
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure
Two active phishing kits, Jalisco and OmegaLord, are defeating multi-factor authentication on Microsoft 365 accounts through adversary-in-the-middle proxying and device code abuse. At the same time, documented research shows a jailbroken AI model built a fully functional command-and-control server in six minutes with minimal human input. For UK SMBs relying on MFA as their primary Microsoft 365 defence, these developments demand immediate action. Mauven examines how commoditised MFA bypass techniques work, why they matter disproportionately to UK professional services firms, and what controls to deploy now before Microsoft’s passkeys rollout in September. Also covered: critical SAP patches, actively exploited Joomla vulnerabilities, and practical steps to take this week. This episode makes clear that MFA alone is no longer sufficient, and the window to implement additional controls is closing as attack tools become cheaper and easier to deploy.
Chapters
Introduction
Mauven introduces two critical developments: active phishing kits defeating Microsoft 365 MFA and AI-assisted attack infrastructure built in minutes. These trends signal a fundamental shift for UK businesses relying on MFA as primary defence.
Jalisco and OmegaLord: When MFA Is No Longer the Answer
Detailed examination of two operational phishing kits using adversary-in-the-middle proxying and device code abuse to defeat MFA on Microsoft 365. Explains why UK professional services firms are disproportionately exposed and outlines immediate mitigations including Conditional Access policies, FIDO2 keys, and token lifetime controls.
Call to Action
Mauven asks listeners to follow the show and share it with anyone relying solely on MFA for Microsoft 365 protection.
AI Is Doing Ninety Per Cent of the Work Now
Analysis of documented research showing a jailbroken Gemini model building a functional command-and-control server in six minutes. Discusses implications for UK SMBs as attack infrastructure becomes trivially easy to deploy at scale.
Briefly Noted: SAP and Joomla
SAP’s July 2026 patch addresses sixteen vulnerabilities including three critical flaws. Actively exploited Joomla extension vulnerabilities with CVSS 10.0 scores threaten UK SMB websites, particularly older professional services and hospitality sites.
What to Do Today
Four prioritised actions: verify Microsoft 365 Conditional Access configuration, patch Joomla extensions, review SAP July patches, and brief staff on device code authentication requests. Emphasises urgency of the MFA bypass issue.
Outro
Mauven summarises that MFA alone is insufficient for Microsoft 365 and that Conditional Access policies and phishing-resistant authentication are now baseline requirements.
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse
13 Jul 2026
00:15:41
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse
This briefing examines three concurrent threats that share a common vulnerability: neglected infrastructure. The NCSC and eight international partners issued a joint advisory on Russian state actors (FSB-linked Static Tundra and Berserk Bear) exploiting poorly configured network edge devices to establish persistent access in critical infrastructure. The same techniques work on any misconfigured router, including those deployed in UK SMEs. Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details, recalling the MOVEit compromise of 2023. Finally, Stormshield documented a phishing campaign impersonating DocuSign to install legitimate Remote Monitoring and Management tools (specifically Atera) as attacker infrastructure. Across all three incidents, the entry point is not sophisticated exploitation but basic configuration oversights: unchanged default credentials, unpatched firmware, unverified document signing workflows. UK small businesses using managed service providers, file transfer systems, or document signing tools face immediate exposure if they have not recently audited which remote access tools are authorised, verified router configurations, or trained staff to validate DocuSign notifications through the portal rather than email links.
Chapters
Introduction
Mauven introduces three apparently unrelated threats that share a single operating principle: attackers exploiting unlocked doors rather than breaking through reinforced ones.
Russian State Actors Targeting Network Edge Devices
A nine-country joint advisory warns of FSB-linked actors exploiting misconfigured routers for persistent access. The technique works on any poorly configured device, not just critical infrastructure. UK SMEs must verify that default credentials are changed, remote management interfaces are disabled, and firmware is current.
Call to Action
Listeners are encouraged to follow the show and share it with others who need threat intelligence.
Progress ShareFile Emergency Shutdown
Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details. Given Progress’s MOVEit breach history, UK SMEs using ShareFile must immediately verify whether they are affected and document what data transits through the platform.
DocuSign Impersonation and RMM Tool Abuse
Stormshield documented a phishing campaign impersonating DocuSign to install legitimate RMM tools (Atera) as attacker infrastructure. Because the payload is legitimate software, endpoint detection often fails to flag it. UK SMEs must train staff to verify DocuSign notifications through the portal, maintain an authorised RMM tool list, and treat any DocuSign prompt requesting software installation as malicious.
Conclusion
The three threats share a common vulnerability: organisations have not recently audited their own infrastructure. The action item for UK SMEs is to verify router configurations, file transfer system deployments, and authorised RMM tools this week, not next quarter.
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
10 Jul 2026
00:16:56
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
This episode examines three current UK cyber security incidents that share a troubling characteristic: all were preventable. Mauven MacLeod analyses the seven-step ransomware chain exploiting unpatched Citrix NetScaler appliances (CVE-2025-5777), documented by Huntress across multiple UK organisations. The briefing covers SilabRAT, a subscription-based Remote Access Trojan sold for £3,900 monthly that clones browser sessions to bypass multi-factor authentication, posing particular risk to finance teams and managed service providers. The episode also examines an NHS Forth Valley data breach caused by a misdirected email, representing the most common breach category reported to the ICO. Additional coverage includes GigaWiper destructive malware and active exploitation of Check Point VPN vulnerabilities (CVE-2026-50751) associated with Qilin ransomware. The analysis emphasises the systemic gap between awareness and action, providing specific verification steps for UK small and medium businesses.
Chapters
Introduction: The Common Thread of Prevention Failures
Mauven introduces three unrelated but preventable security incidents affecting UK organisations with existing IT support and best-practice solutions. The episode examines systemic failures in closing known security gaps.
CitrixBleed 2: Seven-Step Ransomware Chain
Analysis of the seven-step attack chain exploiting CVE-2025-5777 in Citrix NetScaler appliances, documented by Huntress across multiple UK organisations. Covers the automated exploitation process, Dragonforce ransomware deployment, and the disproportionate risk to UK mid-market professional services firms.
Call to Action
Brief encouragement to follow the show and share with business owners who need threat intelligence briefings.
SilabRAT: Credential Theft by Subscription
Examination of SilabRAT Remote Access Trojan, available for £3,900 monthly, which clones browser profiles and sessions to bypass multi-factor authentication. Covers Hidden Virtual Network Computing capabilities, targeting of finance teams, and supply chain risks through compromised managed service providers.
NHS Forth Valley: An Email Incident Without an Attacker
Analysis of a maternity patient data breach at NHS Forth Valley caused by misdirected email, representing the most common breach category in ICO statistics. Discusses the need for documented verification processes before sending bulk emails containing sensitive data.
On the Radar: GigaWiper and Check Point VPN
Brief coverage of GigaWiper destructive malware and active exploitation of CVE-2026-50751 in Check Point Remote Access VPN since May 2026, associated with Qilin ransomware. Emphasises immediate patch verification requirements.
Conclusion: The Gap Between Awareness and Action
Summary emphasising that the common thread across all incidents is the failure to act on known risks. Provides specific action items for verifying patch status of NetScaler and Check Point VPN systems.
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways
09 Jul 2026
00:14:06
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways
A delayed patch for the RoguePlanet zero-day in Windows Defender has finally arrived, but working exploit code was publicly available for weeks before Microsoft closed the vulnerability. Mauven examines what that exposure window means for UK SMBs and why confirming patch deployment today is not optional. The Vidar infostealer campaign has quietly evolved beyond phishing emails into developer toolchains, with malicious Go modules staged across more than two hundred GitHub repositories designed to appear credible and actively maintained. Socket’s Operation Muck and Load research reveals how attackers are using commit farming and typosquatting to compromise software supply chains, particularly targeting payment SDK names. Finally, the NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification that may reduce friction for smaller organisations pursuing verified assessment. Mauven explores what this policy shift signals about the growing expectation for Plus-level certification in public sector contracts and supply chain assurance. Three practical actions close the episode: verify the RoguePlanet patch has been applied, implement dependency verification for developers pulling open-source packages, and review the NCSC pathways guidance if you hold basic Cyber Essentials certification.
Chapters
Introduction
Mauven previews three stories: a delayed zero-day patch, an infostealer campaign migrating into developer toolchains, and an underreported NCSC policy update with practical implications for UK small businesses.
RoguePlanet Zero-Day Patched, Weeks Late
Microsoft has patched the RoguePlanet zero-day in Windows Defender, but exploit code was publicly available for weeks before the fix arrived. Mauven explains the exposure risk, emphasises the urgency of confirming patch deployment, and advises reviewing any anomalous Defender behaviour during the vulnerability window.
Mid-Episode CTA
Mauven encourages listeners to follow the show and share Threat Analysis with colleagues who need daily UK threat intelligence briefings.
Vidar Infostealer Moves Into Developer Supply Chains
The Vidar infostealer campaign has evolved from phishing emails to compromising developer toolchains. Socket’s Operation Muck and Load research identified malicious Go modules staged across 222 GitHub repositories using commit farming to appear credible. Seventeen typosquatted packages targeting payment SDKs were published on 7 July. Mauven details practical verification steps for developers pulling open-source dependencies.
NCSC Cyber Essentials Pathways
The NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification. Mauven contextualises the policy update, explains why Plus certification is increasingly required for public sector contracts and supply chain assurance, and advises organisations holding basic certification to review the new pathways guidance.
Closing Actions and Outro
Mauven summarises three priority actions: confirm the RoguePlanet patch has been applied, brief developers on dependency verification, and read the NCSC Cyber Essentials Pathways blog. Closing remarks reinforce the importance of understanding vulnerability windows and consistent threat awareness.
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch
08 Jul 2026
00:13:28
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch
Ubiquiti has released security updates addressing seven critical vulnerabilities in UniFi OS, including one rated CVSS 10.0 that permits unauthenticated remote code execution. The widespread deployment of UniFi hardware in UK small business networks makes this a priority patching event. Separately, CISA has added an Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies after confirming active exploitation in the wild. ColdFusion remains widely deployed in UK professional services, legal and accountancy firms, and public sector environments, often in legacy web applications where platform visibility is poor. Finally, an ongoing phishing campaign delivering AsyncRAT and Remcos trojans continues to target finance, procurement, and operations staff using macro-enabled Excel attachments and fileless execution techniques. Mauven MacLeod provides specific guidance on how to verify patching status with IT providers, configure email filtering to block macro-enabled attachments, and enforce Office macro policy across business environments.
Chapters
Introduction
Mauven opens the eighth of July briefing with a direct question about firmware version awareness, highlighting seven critical Ubiquiti UniFi OS vulnerabilities including one rated CVSS 10.0, a CISA emergency patch order for Adobe ColdFusion, and an ongoing phishing campaign targeting finance and procurement staff.
Ubiquiti UniFi OS: Seven Critical Flaws, One at Maximum Severity
Seven critical vulnerabilities in Ubiquiti UniFi OS have been disclosed, including a CVSS 10.0 command injection flaw permitting unauthenticated remote code execution. Given the widespread deployment of UniFi hardware in UK SMB networks and typically flat network architectures, successful exploitation provides attackers with perimeter-level access. Mauven advises requesting written confirmation of firmware updates from IT providers or checking firmware versions directly if self-managed.
Call to Action
Mauven encourages listeners to follow the show and share the episode with others who may have unpatched Ubiquiti infrastructure.
Adobe ColdFusion: Actively Exploited, CISA Emergency Patch Deadline
CISA has added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies by the end of the week. The flaw permits remote code execution and is confirmed exploited in the wild. ColdFusion remains widely deployed in UK professional services, legal, accountancy, and public sector environments, often in legacy web applications with poor platform visibility. Mauven recommends requesting written confirmation of patching from hosting providers and suppliers.
On the Radar: AsyncRAT and Remcos Phishing Campaign
An ongoing phishing campaign delivers AsyncRAT and Remcos remote access trojans via macro-enabled Excel attachments, using fileless execution techniques including steganography to evade signature-based detection. The campaign specifically targets finance, procurement, and operations staff who routinely receive Excel files from external parties. Mauven recommends disabling macro execution by default, deploying Attack Surface Reduction rules, configuring email gateways to quarantine macro-enabled files, and briefing staff in targeted functions.
Closing Summary
Mauven summarises three actionable items: obtain written confirmation of UniFi firmware updates, verify ColdFusion patching status with suppliers, and enforce Office macro policy with appropriate email filtering. None require significant budget, only deliberate follow-through.
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge
07 Jul 2026
00:16:25
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge
This episode examines three active threat vectors affecting UK businesses in July 2026. First, a sophisticated Microsoft Teams impersonation campaign documented by Unit 42, in which attackers pose as IT helpdesk staff to deploy EtherRAT remote access trojans without requiring any technical vulnerability. Second, a global phishing operation delivering AsyncRAT and Remcos through multi-stage infection chains that use steganography and fileless execution to evade detection, targeting finance, HR, and procurement functions. Third, the UK government’s new voluntary cyber pledge, signed by sixty organisations including two currently managing recovery from significant recent breaches. The episode also covers UAT-7810’s operational relay box networks and the NCSC’s Cyber Shield initiative. Practical mitigations include restricting Teams external access, blocking Office macros by default, implementing helpdesk verification processes, and ensuring endpoint protection uses behavioural detection rather than signature matching alone. Each recommendation is actionable within the current week and addresses documented attack patterns actively being exploited against UK small and medium businesses.
Chapters
Introduction
Overview of three stories: two active threats requiring immediate attention and one piece of UK government policy that merits closer examination beyond the press release.
Teams Helpdesk Scam: EtherRAT
Unit 42 research documenting attackers impersonating IT helpdesk on Microsoft Teams to deploy EtherRAT. The attack requires no technical vulnerability, only a helpful employee. Covers Teams external access configuration, verification processes, and remote access tool auditing.
Call to Action
Reminder to follow the show and share with colleagues who would benefit from daily threat intelligence.
Multi-Stage Phishing: AsyncRAT and Remcos
SpiderLabs research on global phishing delivering AsyncRAT and Remcos through Excel attachments, HTA scripts, PowerShell, and steganography-concealed payloads. Targets finance, HR, and procurement. Emphasises macro blocking and behavioural detection requirements.
UK Cyber Pledge: Sixty Signatories
Examination of the UK government’s voluntary cyber pledge signed by sixty organisations, including two currently managing recovery from significant breaches. Discusses the difference between pledges and contractual security requirements.
UAT-7810 ORB Networks
Cisco Talos research on operational relay box networks built using compromised small business infrastructure. Explains why edge device security matters beyond direct targeting.
NCSC Cyber Shield
NCSC blog post on Cyber Shield, a sovereign AI-driven cyber defence initiative. Distinguishes between national-scale infrastructure projects and immediate operational threats.
Summary and Actions
Prioritised action list: restrict Teams external access, block Office macros, communicate helpdesk verification policy, confirm behavioural detection capability, and review supplier security contracts.
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
06 Jul 2026
00:12:08
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score of 10.0, affecting legacy installations across SMB websites, internal applications, and shared hosting environments managed by MSPs. Second, a criminal group designated CL-CRI-1147 and tracked as Pink is conducting voice phishing campaigns that impersonate IT helpdesks to extract credentials and bypass multi-factor authentication. Once inside, the group exfiltrates data from SharePoint and OneDrive, then issues a seventy-two-hour ransom demand. The tactic closely mirrors operations by UNC3753, documented by Google Cloud Threat Intelligence. Both threats exploit different attack surfaces but share a common trait: neither discriminates by organisation size. Mauven provides specific procedural guidance for patching, MSP coordination, staff briefings on vishing, and audit log monitoring to detect bulk data downloads before ransom demands arrive.
Chapters
Introduction
Mauven introduces two current threats facing UK small businesses: an actively exploited Adobe ColdFusion vulnerability and a criminal vishing operation. Both target SMBs without discrimination based on size or sophistication.
Adobe ColdFusion CVE-2026-48282: Patch It Today, Not This Week
Analysis of CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed under active exploitation. Covers CVSS 10.0 scoring, unauthenticated remote code execution, exposure through legacy systems and MSP-managed environments, and immediate patching requirements.
Call to Action
Brief audience prompt to follow the show and share the briefing with colleagues who need current threat intelligence.
Pink (CL-CRI-1147): When the Threat Just Calls You Up
Examination of the Pink criminal group’s vishing operation that impersonates IT helpdesks to extract credentials and bypass MFA. Details the exfiltration timeline, procedural defences, staff briefing requirements, and technical monitoring for SharePoint and OneDrive bulk downloads.
The Pattern Worth Noting
Structural analysis connecting the Adobe vulnerability, vishing campaigns, and emerging ClickFix malware ecosystem. All three exploit different attack surfaces but converge on the same principle: automated and human-driven threats do not filter targets by organisation size.
Closing
Summary of two actionable steps: verify and patch ColdFusion installations immediately, and brief staff on the vishing rule that IT will never request credentials or MFA approval by phone.
Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown
03 Jul 2026
00:14:53
Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown
This briefing examines three significant threats to UK small and medium businesses in July 2026. First, Cisco Talos’s analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft 365 device code authentication flows to bypass multi-factor authentication. The technique, productised for affiliate use, requires immediate Conditional Access policy review. Second, Blackpoint Cyber’s documentation of Avalon, a multi-stage ransomware framework using spoofed legal documents, Proton Drive hosting, and memory-only execution to evade detection. Third, the NetNut botnet takedown by Google and the FBI, involving two million compromised residential devices used as proxy infrastructure. The operational implications extend beyond the headline: unpatched IoT devices and routers continue to provide access via vulnerabilities from 2017 and 2018. Each attack is designed to appear normal within legitimate business operations. The briefing provides three concrete actions: restrict device code authentication in Entra ID, establish verification procedures for password-protected archives, and audit firmware on internet-facing devices. These measures address the gap between assumed and actual security control effectiveness in small business environments.
Chapters
Introduction
Mauven introduces three threat items for 3rd July 2026, prioritised by risk to UK SMBs. Two are active attack campaigns with direct exposure, one is a law enforcement action with under-reported operational implications.
ARToken M365 Phishing Platform
Analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft device code authentication flows. The technique bypasses MFA by abusing legitimate authentication processes. Direct mitigation requires restricting device code flows through Conditional Access policies in Entra ID.
Call to Action
Listener engagement prompt encouraging follows and sharing.
Avalon Ransomware Framework
Blackpoint Cyber’s analysis of Avalon, a multi-stage attack framework using spoofed legal documents hosted on Proton Drive, password-protected ISO archives, and memory-only execution. Targets professional services with plausible social engineering. Requires staff training, behavioural endpoint detection, and ISO mounting restrictions.
The NetNut Botnet Takedown
Google and FBI action against NetNut residential proxy botnet involving two million compromised devices. Discusses how compromised devices provide cover for credential stuffing and fraud, and notes active propagation of similar botnets via vulnerabilities from 2017 and 2018. Emphasises firmware update and credential hygiene on internet-facing devices.
Broader Pattern Note
All three threats share a common characteristic: they are designed to appear normal within legitimate business operations. The security gap lies between assumed and actual control effectiveness, closed through visibility rather than additional tools.
Outro
Closing summary with practical question for IT providers regarding Conditional Access policies. Sign-off and production credit.
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat
01 Jul 2026
00:13:38
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat
The Gentlemen ransomware group has emerged as a top-ten global threat actor by deploying zero-day driver exploits to disable endpoint security tools before launching encryption attacks. Using a vulnerable Kontron driver and the Bring Your Own Vulnerable Driver technique, the group neutralises detection systems silently, often gaining hours of undetected access through compromised VPN and firewall appliances. Meanwhile, the ARToken phishing-as-a-service platform automates Microsoft 365 account takeover through device code phishing and Primary Refresh Token persistence. Standard multi-factor authentication does not prevent these attacks, as the OAuth authentication flows are legitimate. The platform includes automated email and SharePoint exfiltration, plus integrated business email compromise tooling that industrialises payment redirection fraud. UK small businesses using Microsoft 365 face direct exposure, particularly in professional services, accountancy, and financial sectors where client data and payment processes rely on email systems. The NCSC has published guidance on restricting device code flow and monitoring for these attacks, yet implementation remains inconsistent even in critical national infrastructure environments.
Chapters
Introduction
Overview of two urgent threat developments: a ransomware group defeating endpoint security and an automated Microsoft 365 phishing platform bypassing multi-factor authentication.
The Gentlemen Ransomware Group and Zero-Day Driver Exploits
Analysis of The Gentlemen’s rise to top-ten threat status through Bring Your Own Vulnerable Driver techniques, their use of a Kontron driver zero-day to disable endpoint protection, and their systematic approach to network reconnaissance and ransomware deployment.
Call to Action
Encouragement to share the briefing and subscribe for daily updates.
ARToken: Automated Microsoft 365 Account Takeover
Detailed examination of the ARToken phishing-as-a-service platform, its device code phishing methodology, Primary Refresh Token persistence, automated data exfiltration, and integrated business email compromise workflows that bypass standard MFA.
NCSC Penetration Testing Findings
Brief discussion of persistent security gaps identified in critical national infrastructure, including default credentials, insufficient segmentation, and poor patch management.
Closing Recommendations
Summary of immediate actions: enable tamper protection, verify monitoring procedures, restrict device code flow in Microsoft 365, and implement out-of-band payment verification.
Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack
30 Jun 2026
00:12:58
Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack
Two critical threats demand immediate attention from UK small businesses today. First, the BlueHammer vulnerability in Microsoft Defender has transitioned from targeted zero-day attacks to commodity ransomware operations, a shift that dramatically expands the pool of threat actors capable of exploiting it. CISA’s addition of BlueHammer to its Known Exploited Vulnerabilities catalogue confirms active exploitation in the wild, with the flaw enabling attackers to escalate privileges to SYSTEM level and deploy ransomware across entire networks. Second, Blackpoint Cyber has documented an active intrusion chain exploiting CVE-2026-48558, an authentication bypass in SimpleHelp remote monitoring and management software. This attack vector is particularly concerning because it targets the tools IT providers use to manage client systems, turning the trust relationship between businesses and their managed service providers into an attack surface. The operational implication is clear: attackers are systematically exploiting the privileged access that IT management tools provide, bypassing direct targeting in favour of supply chain compromise. Patches exist for both vulnerabilities. The gap between availability and deployment is where ransomware operators operate. UK SMBs should contact their IT providers today to confirm patching status and ask specific questions about RMM tool security. This briefing provides actionable guidance on exactly what to ask and why it matters.
Chapters
Introduction
Mauven introduces today’s two threat stories: the BlueHammer vulnerability in Windows Defender crossing into commodity ransomware operations, and an attack targeting remote management tools used by IT providers.
BlueHammer: From Zero-Day to Ransomware Commodity
Analysis of CISA’s KEV addition for BlueHammer, a privilege escalation flaw in Microsoft Defender now exploited in commodity ransomware operations. Covers the transition from targeted attacks to volume-based campaigns, the operational playbook of ransomware-as-a-service groups, and the practical patching actions UK SMBs must take immediately.
CTA
Brief call to action encouraging listeners to follow the show and share it with business owners and operations managers who need actionable threat intelligence.
SimpleHelp RMM: The Attack That Comes Through Your IT Provider
Detailed examination of CVE-2026-48558, an authentication bypass in SimpleHelp remote monitoring and management software. Explains how attackers exploit RMM tools to gain technician-level access to managed client systems, the malware deployed (TaskWeaver and Djinn Stealer), and the supply chain risk this represents for UK SMBs.
What UK SMBs Should Do Today
Direct, actionable guidance for UK small businesses: specific questions to ask IT providers about BlueHammer patching, SimpleHelp vulnerability status, RMM access log reviews, and incident disclosure processes.
Outro
Closing summary emphasising the gap between patch availability and deployment, urging businesses to actively verify patching status with their IT providers rather than assume it has been handled.
Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild
29 Jun 2026
00:14:22
Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild
Oracle E-Business Suite vulnerability CVE-2026-46817 is under active exploitation, with confirmed activity from threat intelligence firm Defused. Nissan’s recent breach of its Oracle PeopleSoft instance underscores the broader risk to Oracle’s enterprise portfolio. UK small businesses face exposure through supply chain relationships with payroll bureaus, accountancy firms, and manufacturers running Oracle systems. Meanwhile, newly documented threat actor DriveSurge operates a pay-per-install initial access broker model, compromising legitimate websites to deliver malware through fake browser updates and ClickFix social engineering. The campaign bypasses email security controls entirely, infecting users through normal web browsing. Additional concerns include active exploitation of Langflow (CVE-2026-55255) and the Miasma Mini Shai-Hulud supply chain campaign now targeting Backstage npm packages. Today’s briefing provides specific, actionable steps: verify Oracle patch status with suppliers, implement web filtering against zTDS infrastructure, brief staff on fake browser update prompts, and audit dependencies in development pipelines. These are email-and-call actions, not budget-heavy projects.
Chapters
Introduction
Mauven opens with two active threat stories: exploitation of Oracle E-Business Suite and a drive-by attack campaign bypassing email controls through compromised websites. Both pose immediate risks to UK small businesses through supply chain and web browsing vectors.
Oracle EBS Active Exploitation
CVE-2026-46817 in Oracle E-Business Suite is under confirmed exploitation. Nissan’s PeopleSoft breach demonstrates sustained threat actor attention to Oracle’s enterprise platforms. UK small businesses face exposure through payroll bureaus, accountancy firms, and manufacturers. Practical steps include verifying patch status directly with suppliers and documenting responses in writing.
Mid-Roll Call to Action
Brief listener prompt to follow the show and share the briefing with relevant contacts.
DriveSurge Drive-By Campaign
DriveSurge, a newly documented initial access broker, compromises legitimate websites to deliver malware via fake browser updates and ClickFix prompts. The campaign uses zTDS traffic distribution and bypasses standard email security. Recommended defences include web filtering against zTDS infrastructure and staff briefing on fake update prompts.
Langflow and Miasma Mini Shai-Hulud Updates
CVE-2026-55255 in Langflow is under active exploitation, with lower-scored CVE-2026-33017 seeing wider use due to easier exploitation. The Miasma Mini Shai-Hulud campaign now targets Backstage npm packages. Organisations using AI frameworks or modern CI/CD pipelines should audit patch status and dependencies.
Closing Summary
Mauven summarises practical actions in order of urgency: verify Oracle patch status with suppliers, brief staff on fake browser updates, confirm web filtering covers zTDS, and audit development dependencies. All actions require communication and follow-up, not significant budget.
Understanding Mini Shai-Hulud and Cisco's Zero-Day Vulnerabilities
26 Jun 2026
00:05:44
Understanding Mini Shai-Hulud and Cisco’s Zero-Day Vulnerabilities
In today’s episode of Threat Analysis, Mauven MacLeod delves into two significant cybersecurity threats impacting UK small and medium businesses. The Mini Shai-Hulud supply chain attack targets the development community by exploiting npm packages, risking developers’ credentials and threatening software integrity. Microsoft emphasises the importance of rigorous dependency audits to prevent malicious exploitation. Additionally, a zero-day vulnerability CVE-2026-20245 in Cisco’s Catalyst SD-WAN Manager is discussed. This allows attackers to escalate privileges through default passwords, compromising network security. The necessity of proactive cybersecurity measures, including multi-factor authentication and robust monitoring systems, is highlighted to safeguard businesses from these threats.
Chapters
Intro
Mauven introduces the episode, highlighting critical threats for UK businesses.
Mini Shai-Hulud Supply Chain Attack
Discusses how Mini Shai-Hulud uses npm packages to access developer credentials, emphasising the need for vigilant software audits.
CTA
Encourages listeners to follow the show for updates and share with peers.
CVE-2026-20245: Cisco’s Zero-Day
Explores the Cisco vulnerability, stressing the dangers of default passwords and the importance of intrusion detection systems.
Outro
Reiterates the importance of proactive cybersecurity measures and invites listeners to return for future episodes.
In this episode of Threat Analysis, Mauven MacLeod dives into two pressing cybersecurity threats affecting UK small and medium businesses. The first is the Mistic backdoor, linked to the notorious Woodgnat, which employs the cunning technique of sideloading. This method uses legitimate software to conceal malicious activity, posing significant risks such as data leaks and financial loss. Mauven discusses the importance of a robust security posture and offers practical advice on staying protected. The second threat is the widespread FortiBleed campaign targeting Fortinet FortiGate devices through advanced techniques like credential stuffing and password spraying. The campaign highlights vulnerabilities found in legacy systems and underscores the need for up-to-date device management and strong authentication protocols. Listeners are encouraged to assess and fortify their cybersecurity defences actively. The episode closes with a reminder: awareness is key, but proactive measures are essential to safeguarding your business.
Chapters
Intro
Mauven introduces today’s cybersecurity topics, focusing on threats to UK businesses.
Mistic Backdoor Unveiled
Discussion on the Mistic backdoor’s impact, sideloading techniques, and security recommendations.
CTA
Listeners are encouraged to follow the podcast and share it with others.
FortiGate Under Siege
Analysis of the FortiBleed campaign targeting Fortinet devices, with tips to enhance network security.
Outro
Recap of the threats discussed and a call to take proactive security measures.
Understanding the Mistic Backdoor Threat to UK SMBs
24 Jun 2026
00:06:40
Understanding the Mistic Backdoor Threat to UK SMBs
In this episode of Threat Analysis, Mauven MacLeod explores the emerging threat landscape for UK small and medium businesses, focusing on the Mistic backdoor. This malware, linked to the ransomware access broker KongTuke, poses significant risks to crucial sectors such as insurance, education, IT, and professional services. The discussion highlights how Mistic operates stealthily within compromised systems, bypassing many traditional security measures and exacerbating vulnerabilities in supply chains. Additionally, the episode delves into broader cybersecurity concerns, including the critical vulnerability CVE-2026-20230 in Cisco Unified Communications Manager and privacy issues arising from London’s use of live facial recognition technology. Mauven provides actionable steps for SMBs to strengthen their defences, emphasising the importance of robust vendor audits, advanced threat detection, and well-prepared incident response plans, aligning with guidance from the National Cyber Security Centre.
Chapters
Intro
Mauven introduces the focus on the Mistic backdoor and its relevance to UK SMBs.
Mistic Backdoor Threat
Exploration of the Mistic backdoor’s tactics, connection to KongTuke, and its impact on key sectors.
The Broader Context
Discussion on Cisco’s vulnerability and the implications of facial recognition technology in London.
What Should You Do?
Actionable cybersecurity measures for SMBs, including vendor audits and threat detection enhancements.
CTA
Encouragement to follow the show and share it with others needing the briefing.
Outro
Summary of today’s insights and the importance of proactive cybersecurity strategies.