Explore every episode of the podcast Threat Analysis : Cyber News for Small Business
Dive into the complete episode list for Threat Analysis : Cyber News for Small Business. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
Rows per page:
50
1–32 of 32
Title
Pub. Date
Duration
Cybersecurity Challenges Facing UK SMEs
31 Jul 2026
00:08:01
Cybersecurity Challenges Facing UK SMEs
Today’s episode tackles key cybersecurity challenges facing UK small and medium enterprises. We delve into the exploits by the Russian-aligned group TA488, discuss vulnerabilities such as CVE-2026-42897, and examine the broader impact of cyber incidents beyond primary targets. Learn about the MacSync Stealer threat to macOS and the potential risks associated with Anthropic’s Claude AI models. Finally, we explore the recent CAF Bank incident affecting thousands of charities. Each section offers insights and actionable steps to bolster your organisation’s security posture amidst these evolving threats.
Chapters
Intro
Introduction to key cybersecurity issues facing UK businesses, including TA488 exploits and AI vulnerabilities.
CVE-2026-42897 and TA488
Discusses the CVE-2026-42897 vulnerability exploited by TA488 and the importance of patch management.
CTA
Encourages listeners to follow the podcast and share it with others who might benefit.
MacSync Stealer on macOS
Explores the MacSync Stealer threat via Google Ads affecting macOS users and stresses the need for education and advanced protection.
Anthropic’s Claude AI Models
Examines issues of AI containment and security with Claude AI models, urging robust governance frameworks.
CAF Bank Incident
Analyzes the cyber incident affecting CAF Bank, highlighting the importance of financial security measures and contingency plans.
Outro
Concludes with a call for vigilance and accountability in tech environments to secure against threats.
In today’s episode of Threat Analysis, Mauven MacLeod delves into critical cybersecurity challenges confronting UK small businesses. We address Russian state-sponsored email attacks targeting Microsoft Outlook with a unique ‘half-click’ method, which offers notable resilience against traditional security measures. Understanding the implications of such threats is essential for businesses to protect their digital environments and reputations.
Additionally, we examine the rise of attacks within the npm registry, impacting software development operations. This new threat utilises worm-like behaviours to infiltrate popular packages and steal credentials via blockchain transactions. These complex methods highlight the importance of thorough vigilance and robust security strategies for companies relying on open-source software.
Mauven emphasises the necessity of incorporating comprehensive security measures, combining human and technological approaches, to effectively manage and counter these evolving threats. Don’t miss out on the need for keen awareness and proactive defences in safeguarding your business.
Chapters
Intro
Mauven highlights the critical cyber threats facing UK SMBs and the importance of robust security.
Russian State-Sponsored Email Attacks Targeting Outlook
Discussion on the ‘half-click’ method used by Russian hackers in Outlook attacks, emphasising resilience and the need for awareness.
CTA
Encouragement to follow the show and share with those who need cybersecurity insights.
NPM Registry Hosting New Supply Chain Attacks
Exploration of worm-like attacks within the npm registry targeting credentials via blockchain, calling for vigilant dependency management.
Outro
Conclusion on the necessity of proactive cybersecurity measures for UK SMBs, previewing future threat analyses.
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack
15 Jul 2026
00:15:47
SharePoint Exploitation, AiTM Phishing, and AsyncAPI Supply Chain Attack
On 15 July 2026, Mauven MacLeod examines three active threats facing UK organisations. CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation targeting on-premises deployments, with particular exposure among professional services firms still running legacy infrastructure. The second story details a misconfigured phishing operation that exposed 218 confirmed victims across twelve countries using Adversary-in-the-Middle techniques that bypass standard multi-factor authentication, including OAuth Device Code Flow attacks against Microsoft 365 and Google Workspace users. Finally, a supply chain attack against the AsyncAPI generator repository saw an attacker exploit a misconfigured GitHub Actions workflow to publish five malicious npm packages containing the Miasma botnet loader, which executes at import time without user interaction. The briefing emphasises that none of these attacks relied on novel techniques or nation-state resources, but succeeded through known vulnerabilities, unpatched systems, and insufficient authentication controls.
Chapters
Introduction
Mauven opens the 15 July 2026 briefing, noting three stories involving confirmed victims and active exploitation, all stemming from known weaknesses rather than novel attack methods.
SharePoint Server: Three CVEs, Active Exploitation, Patch Now
CISA has added three Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaws affect on-premises deployments, not SharePoint Online. UK professional services firms, legal practices, and accountancy firms running legacy on-premises infrastructure face elevated risk. Mauven emphasises that KEV listing represents a late warning, not an early one, and calls for immediate patching and documented remediation.
Call to Action
Mauven encourages listeners to follow the show and share it with colleagues who would benefit from daily threat intelligence briefings.
AiTM Phishing: Three Operators Exposed, 218 Confirmed Victims
Lexfo researchers discovered a misconfigured Python HTTP server that exposed the infrastructure of three phishing operators, including one with 218 confirmed victims using OAuth Device Code Flow attacks and another operating an Adversary-in-the-Middle platform since 2018. AiTM attacks bypass standard multi-factor authentication by intercepting authenticated session tokens. Mauven explains why phishing-resistant MFA such as FIDO2 is necessary and provides specific guidance on OAuth Device Code Flow recognition and conditional access policy review.
AsyncAPI npm Supply Chain: Poisoned Packages, Botnet Loader
An attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository to exfiltrate a privileged access token, then published five malicious npm packages containing the Miasma botnet loader. The malicious code executes at import time without user interaction. Mauven advises organisations to audit AsyncAPI-related dependencies, review build logs from 14 July, and verify whether technology partners have assessed their exposure.
Also Worth Noting
The NCSC has announced that certified Cyber Advisors are offering free thirty-minute consultations for small businesses. Microsoft has halted Patch Tuesday updates for some Dell devices following reports of shutdowns and overheating.
Closing Remarks
Mauven concludes by noting that all three stories involve exploitation of known weaknesses through patience and known techniques, rather than exotic capabilities. The briefing emphasises checking on-premises SharePoint deployments and treating patching as an urgent priority.
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure
14 Jul 2026
00:15:07
When MFA Stops Working: Jalisco, OmegaLord, and AI-Built Attack Infrastructure
Two active phishing kits, Jalisco and OmegaLord, are defeating multi-factor authentication on Microsoft 365 accounts through adversary-in-the-middle proxying and device code abuse. At the same time, documented research shows a jailbroken AI model built a fully functional command-and-control server in six minutes with minimal human input. For UK SMBs relying on MFA as their primary Microsoft 365 defence, these developments demand immediate action. Mauven examines how commoditised MFA bypass techniques work, why they matter disproportionately to UK professional services firms, and what controls to deploy now before Microsoft’s passkeys rollout in September. Also covered: critical SAP patches, actively exploited Joomla vulnerabilities, and practical steps to take this week. This episode makes clear that MFA alone is no longer sufficient, and the window to implement additional controls is closing as attack tools become cheaper and easier to deploy.
Chapters
Introduction
Mauven introduces two critical developments: active phishing kits defeating Microsoft 365 MFA and AI-assisted attack infrastructure built in minutes. These trends signal a fundamental shift for UK businesses relying on MFA as primary defence.
Jalisco and OmegaLord: When MFA Is No Longer the Answer
Detailed examination of two operational phishing kits using adversary-in-the-middle proxying and device code abuse to defeat MFA on Microsoft 365. Explains why UK professional services firms are disproportionately exposed and outlines immediate mitigations including Conditional Access policies, FIDO2 keys, and token lifetime controls.
Call to Action
Mauven asks listeners to follow the show and share it with anyone relying solely on MFA for Microsoft 365 protection.
AI Is Doing Ninety Per Cent of the Work Now
Analysis of documented research showing a jailbroken Gemini model building a functional command-and-control server in six minutes. Discusses implications for UK SMBs as attack infrastructure becomes trivially easy to deploy at scale.
Briefly Noted: SAP and Joomla
SAP’s July 2026 patch addresses sixteen vulnerabilities including three critical flaws. Actively exploited Joomla extension vulnerabilities with CVSS 10.0 scores threaten UK SMB websites, particularly older professional services and hospitality sites.
What to Do Today
Four prioritised actions: verify Microsoft 365 Conditional Access configuration, patch Joomla extensions, review SAP July patches, and brief staff on device code authentication requests. Emphasises urgency of the MFA bypass issue.
Outro
Mauven summarises that MFA alone is insufficient for Microsoft 365 and that Conditional Access policies and phishing-resistant authentication are now baseline requirements.
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse
13 Jul 2026
00:15:41
Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse
This briefing examines three concurrent threats that share a common vulnerability: neglected infrastructure. The NCSC and eight international partners issued a joint advisory on Russian state actors (FSB-linked Static Tundra and Berserk Bear) exploiting poorly configured network edge devices to establish persistent access in critical infrastructure. The same techniques work on any misconfigured router, including those deployed in UK SMEs. Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details, recalling the MOVEit compromise of 2023. Finally, Stormshield documented a phishing campaign impersonating DocuSign to install legitimate Remote Monitoring and Management tools (specifically Atera) as attacker infrastructure. Across all three incidents, the entry point is not sophisticated exploitation but basic configuration oversights: unchanged default credentials, unpatched firmware, unverified document signing workflows. UK small businesses using managed service providers, file transfer systems, or document signing tools face immediate exposure if they have not recently audited which remote access tools are authorised, verified router configurations, or trained staff to validate DocuSign notifications through the portal rather than email links.
Chapters
Introduction
Mauven introduces three apparently unrelated threats that share a single operating principle: attackers exploiting unlocked doors rather than breaking through reinforced ones.
Russian State Actors Targeting Network Edge Devices
A nine-country joint advisory warns of FSB-linked actors exploiting misconfigured routers for persistent access. The technique works on any poorly configured device, not just critical infrastructure. UK SMEs must verify that default credentials are changed, remote management interfaces are disabled, and firmware is current.
Call to Action
Listeners are encouraged to follow the show and share it with others who need threat intelligence.
Progress ShareFile Emergency Shutdown
Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details. Given Progress’s MOVEit breach history, UK SMEs using ShareFile must immediately verify whether they are affected and document what data transits through the platform.
DocuSign Impersonation and RMM Tool Abuse
Stormshield documented a phishing campaign impersonating DocuSign to install legitimate RMM tools (Atera) as attacker infrastructure. Because the payload is legitimate software, endpoint detection often fails to flag it. UK SMEs must train staff to verify DocuSign notifications through the portal, maintain an authorised RMM tool list, and treat any DocuSign prompt requesting software installation as malicious.
Conclusion
The three threats share a common vulnerability: organisations have not recently audited their own infrastructure. The action item for UK SMEs is to verify router configurations, file transfer system deployments, and authorised RMM tools this week, not next quarter.
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
10 Jul 2026
00:16:56
Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
This episode examines three current UK cyber security incidents that share a troubling characteristic: all were preventable. Mauven MacLeod analyses the seven-step ransomware chain exploiting unpatched Citrix NetScaler appliances (CVE-2025-5777), documented by Huntress across multiple UK organisations. The briefing covers SilabRAT, a subscription-based Remote Access Trojan sold for £3,900 monthly that clones browser sessions to bypass multi-factor authentication, posing particular risk to finance teams and managed service providers. The episode also examines an NHS Forth Valley data breach caused by a misdirected email, representing the most common breach category reported to the ICO. Additional coverage includes GigaWiper destructive malware and active exploitation of Check Point VPN vulnerabilities (CVE-2026-50751) associated with Qilin ransomware. The analysis emphasises the systemic gap between awareness and action, providing specific verification steps for UK small and medium businesses.
Chapters
Introduction: The Common Thread of Prevention Failures
Mauven introduces three unrelated but preventable security incidents affecting UK organisations with existing IT support and best-practice solutions. The episode examines systemic failures in closing known security gaps.
CitrixBleed 2: Seven-Step Ransomware Chain
Analysis of the seven-step attack chain exploiting CVE-2025-5777 in Citrix NetScaler appliances, documented by Huntress across multiple UK organisations. Covers the automated exploitation process, Dragonforce ransomware deployment, and the disproportionate risk to UK mid-market professional services firms.
Call to Action
Brief encouragement to follow the show and share with business owners who need threat intelligence briefings.
SilabRAT: Credential Theft by Subscription
Examination of SilabRAT Remote Access Trojan, available for £3,900 monthly, which clones browser profiles and sessions to bypass multi-factor authentication. Covers Hidden Virtual Network Computing capabilities, targeting of finance teams, and supply chain risks through compromised managed service providers.
NHS Forth Valley: An Email Incident Without an Attacker
Analysis of a maternity patient data breach at NHS Forth Valley caused by misdirected email, representing the most common breach category in ICO statistics. Discusses the need for documented verification processes before sending bulk emails containing sensitive data.
On the Radar: GigaWiper and Check Point VPN
Brief coverage of GigaWiper destructive malware and active exploitation of CVE-2026-50751 in Check Point Remote Access VPN since May 2026, associated with Qilin ransomware. Emphasises immediate patch verification requirements.
Conclusion: The Gap Between Awareness and Action
Summary emphasising that the common thread across all incidents is the failure to act on known risks. Provides specific action items for verifying patch status of NetScaler and Check Point VPN systems.
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways
09 Jul 2026
00:14:06
RoguePlanet Zero-Day, Vidar Supply Chain Infiltration, and CE Plus Pathways
A delayed patch for the RoguePlanet zero-day in Windows Defender has finally arrived, but working exploit code was publicly available for weeks before Microsoft closed the vulnerability. Mauven examines what that exposure window means for UK SMBs and why confirming patch deployment today is not optional. The Vidar infostealer campaign has quietly evolved beyond phishing emails into developer toolchains, with malicious Go modules staged across more than two hundred GitHub repositories designed to appear credible and actively maintained. Socket’s Operation Muck and Load research reveals how attackers are using commit farming and typosquatting to compromise software supply chains, particularly targeting payment SDK names. Finally, the NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification that may reduce friction for smaller organisations pursuing verified assessment. Mauven explores what this policy shift signals about the growing expectation for Plus-level certification in public sector contracts and supply chain assurance. Three practical actions close the episode: verify the RoguePlanet patch has been applied, implement dependency verification for developers pulling open-source packages, and review the NCSC pathways guidance if you hold basic Cyber Essentials certification.
Chapters
Introduction
Mauven previews three stories: a delayed zero-day patch, an infostealer campaign migrating into developer toolchains, and an underreported NCSC policy update with practical implications for UK small businesses.
RoguePlanet Zero-Day Patched, Weeks Late
Microsoft has patched the RoguePlanet zero-day in Windows Defender, but exploit code was publicly available for weeks before the fix arrived. Mauven explains the exposure risk, emphasises the urgency of confirming patch deployment, and advises reviewing any anomalous Defender behaviour during the vulnerability window.
Mid-Episode CTA
Mauven encourages listeners to follow the show and share Threat Analysis with colleagues who need daily UK threat intelligence briefings.
Vidar Infostealer Moves Into Developer Supply Chains
The Vidar infostealer campaign has evolved from phishing emails to compromising developer toolchains. Socket’s Operation Muck and Load research identified malicious Go modules staged across 222 GitHub repositories using commit farming to appear credible. Seventeen typosquatted packages targeting payment SDKs were published on 7 July. Mauven details practical verification steps for developers pulling open-source dependencies.
NCSC Cyber Essentials Pathways
The NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification. Mauven contextualises the policy update, explains why Plus certification is increasingly required for public sector contracts and supply chain assurance, and advises organisations holding basic certification to review the new pathways guidance.
Closing Actions and Outro
Mauven summarises three priority actions: confirm the RoguePlanet patch has been applied, brief developers on dependency verification, and read the NCSC Cyber Essentials Pathways blog. Closing remarks reinforce the importance of understanding vulnerability windows and consistent threat awareness.
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch
08 Jul 2026
00:13:28
Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch
Ubiquiti has released security updates addressing seven critical vulnerabilities in UniFi OS, including one rated CVSS 10.0 that permits unauthenticated remote code execution. The widespread deployment of UniFi hardware in UK small business networks makes this a priority patching event. Separately, CISA has added an Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies after confirming active exploitation in the wild. ColdFusion remains widely deployed in UK professional services, legal and accountancy firms, and public sector environments, often in legacy web applications where platform visibility is poor. Finally, an ongoing phishing campaign delivering AsyncRAT and Remcos trojans continues to target finance, procurement, and operations staff using macro-enabled Excel attachments and fileless execution techniques. Mauven MacLeod provides specific guidance on how to verify patching status with IT providers, configure email filtering to block macro-enabled attachments, and enforce Office macro policy across business environments.
Chapters
Introduction
Mauven opens the eighth of July briefing with a direct question about firmware version awareness, highlighting seven critical Ubiquiti UniFi OS vulnerabilities including one rated CVSS 10.0, a CISA emergency patch order for Adobe ColdFusion, and an ongoing phishing campaign targeting finance and procurement staff.
Ubiquiti UniFi OS: Seven Critical Flaws, One at Maximum Severity
Seven critical vulnerabilities in Ubiquiti UniFi OS have been disclosed, including a CVSS 10.0 command injection flaw permitting unauthenticated remote code execution. Given the widespread deployment of UniFi hardware in UK SMB networks and typically flat network architectures, successful exploitation provides attackers with perimeter-level access. Mauven advises requesting written confirmation of firmware updates from IT providers or checking firmware versions directly if self-managed.
Call to Action
Mauven encourages listeners to follow the show and share the episode with others who may have unpatched Ubiquiti infrastructure.
Adobe ColdFusion: Actively Exploited, CISA Emergency Patch Deadline
CISA has added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies by the end of the week. The flaw permits remote code execution and is confirmed exploited in the wild. ColdFusion remains widely deployed in UK professional services, legal, accountancy, and public sector environments, often in legacy web applications with poor platform visibility. Mauven recommends requesting written confirmation of patching from hosting providers and suppliers.
On the Radar: AsyncRAT and Remcos Phishing Campaign
An ongoing phishing campaign delivers AsyncRAT and Remcos remote access trojans via macro-enabled Excel attachments, using fileless execution techniques including steganography to evade signature-based detection. The campaign specifically targets finance, procurement, and operations staff who routinely receive Excel files from external parties. Mauven recommends disabling macro execution by default, deploying Attack Surface Reduction rules, configuring email gateways to quarantine macro-enabled files, and briefing staff in targeted functions.
Closing Summary
Mauven summarises three actionable items: obtain written confirmation of UniFi firmware updates, verify ColdFusion patching status with suppliers, and enforce Office macro policy with appropriate email filtering. None require significant budget, only deliberate follow-through.
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge
07 Jul 2026
00:16:25
Teams Impersonation, Multi-Stage Phishing, and the UK Cyber Pledge
This episode examines three active threat vectors affecting UK businesses in July 2026. First, a sophisticated Microsoft Teams impersonation campaign documented by Unit 42, in which attackers pose as IT helpdesk staff to deploy EtherRAT remote access trojans without requiring any technical vulnerability. Second, a global phishing operation delivering AsyncRAT and Remcos through multi-stage infection chains that use steganography and fileless execution to evade detection, targeting finance, HR, and procurement functions. Third, the UK government’s new voluntary cyber pledge, signed by sixty organisations including two currently managing recovery from significant recent breaches. The episode also covers UAT-7810’s operational relay box networks and the NCSC’s Cyber Shield initiative. Practical mitigations include restricting Teams external access, blocking Office macros by default, implementing helpdesk verification processes, and ensuring endpoint protection uses behavioural detection rather than signature matching alone. Each recommendation is actionable within the current week and addresses documented attack patterns actively being exploited against UK small and medium businesses.
Chapters
Introduction
Overview of three stories: two active threats requiring immediate attention and one piece of UK government policy that merits closer examination beyond the press release.
Teams Helpdesk Scam: EtherRAT
Unit 42 research documenting attackers impersonating IT helpdesk on Microsoft Teams to deploy EtherRAT. The attack requires no technical vulnerability, only a helpful employee. Covers Teams external access configuration, verification processes, and remote access tool auditing.
Call to Action
Reminder to follow the show and share with colleagues who would benefit from daily threat intelligence.
Multi-Stage Phishing: AsyncRAT and Remcos
SpiderLabs research on global phishing delivering AsyncRAT and Remcos through Excel attachments, HTA scripts, PowerShell, and steganography-concealed payloads. Targets finance, HR, and procurement. Emphasises macro blocking and behavioural detection requirements.
UK Cyber Pledge: Sixty Signatories
Examination of the UK government’s voluntary cyber pledge signed by sixty organisations, including two currently managing recovery from significant breaches. Discusses the difference between pledges and contractual security requirements.
UAT-7810 ORB Networks
Cisco Talos research on operational relay box networks built using compromised small business infrastructure. Explains why edge device security matters beyond direct targeting.
NCSC Cyber Shield
NCSC blog post on Cyber Shield, a sovereign AI-driven cyber defence initiative. Distinguishes between national-scale infrastructure projects and immediate operational threats.
Summary and Actions
Prioritised action list: restrict Teams external access, block Office macros, communicate helpdesk verification policy, confirm behavioural detection capability, and review supplier security contracts.
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
06 Jul 2026
00:12:08
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score of 10.0, affecting legacy installations across SMB websites, internal applications, and shared hosting environments managed by MSPs. Second, a criminal group designated CL-CRI-1147 and tracked as Pink is conducting voice phishing campaigns that impersonate IT helpdesks to extract credentials and bypass multi-factor authentication. Once inside, the group exfiltrates data from SharePoint and OneDrive, then issues a seventy-two-hour ransom demand. The tactic closely mirrors operations by UNC3753, documented by Google Cloud Threat Intelligence. Both threats exploit different attack surfaces but share a common trait: neither discriminates by organisation size. Mauven provides specific procedural guidance for patching, MSP coordination, staff briefings on vishing, and audit log monitoring to detect bulk data downloads before ransom demands arrive.
Chapters
Introduction
Mauven introduces two current threats facing UK small businesses: an actively exploited Adobe ColdFusion vulnerability and a criminal vishing operation. Both target SMBs without discrimination based on size or sophistication.
Adobe ColdFusion CVE-2026-48282: Patch It Today, Not This Week
Analysis of CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed under active exploitation. Covers CVSS 10.0 scoring, unauthenticated remote code execution, exposure through legacy systems and MSP-managed environments, and immediate patching requirements.
Call to Action
Brief audience prompt to follow the show and share the briefing with colleagues who need current threat intelligence.
Pink (CL-CRI-1147): When the Threat Just Calls You Up
Examination of the Pink criminal group’s vishing operation that impersonates IT helpdesks to extract credentials and bypass MFA. Details the exfiltration timeline, procedural defences, staff briefing requirements, and technical monitoring for SharePoint and OneDrive bulk downloads.
The Pattern Worth Noting
Structural analysis connecting the Adobe vulnerability, vishing campaigns, and emerging ClickFix malware ecosystem. All three exploit different attack surfaces but converge on the same principle: automated and human-driven threats do not filter targets by organisation size.
Closing
Summary of two actionable steps: verify and patch ColdFusion installations immediately, and brief staff on the vishing rule that IT will never request credentials or MFA approval by phone.
Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown
03 Jul 2026
00:14:53
Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown
This briefing examines three significant threats to UK small and medium businesses in July 2026. First, Cisco Talos’s analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft 365 device code authentication flows to bypass multi-factor authentication. The technique, productised for affiliate use, requires immediate Conditional Access policy review. Second, Blackpoint Cyber’s documentation of Avalon, a multi-stage ransomware framework using spoofed legal documents, Proton Drive hosting, and memory-only execution to evade detection. Third, the NetNut botnet takedown by Google and the FBI, involving two million compromised residential devices used as proxy infrastructure. The operational implications extend beyond the headline: unpatched IoT devices and routers continue to provide access via vulnerabilities from 2017 and 2018. Each attack is designed to appear normal within legitimate business operations. The briefing provides three concrete actions: restrict device code authentication in Entra ID, establish verification procedures for password-protected archives, and audit firmware on internet-facing devices. These measures address the gap between assumed and actual security control effectiveness in small business environments.
Chapters
Introduction
Mauven introduces three threat items for 3rd July 2026, prioritised by risk to UK SMBs. Two are active attack campaigns with direct exposure, one is a law enforcement action with under-reported operational implications.
ARToken M365 Phishing Platform
Analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft device code authentication flows. The technique bypasses MFA by abusing legitimate authentication processes. Direct mitigation requires restricting device code flows through Conditional Access policies in Entra ID.
Call to Action
Listener engagement prompt encouraging follows and sharing.
Avalon Ransomware Framework
Blackpoint Cyber’s analysis of Avalon, a multi-stage attack framework using spoofed legal documents hosted on Proton Drive, password-protected ISO archives, and memory-only execution. Targets professional services with plausible social engineering. Requires staff training, behavioural endpoint detection, and ISO mounting restrictions.
The NetNut Botnet Takedown
Google and FBI action against NetNut residential proxy botnet involving two million compromised devices. Discusses how compromised devices provide cover for credential stuffing and fraud, and notes active propagation of similar botnets via vulnerabilities from 2017 and 2018. Emphasises firmware update and credential hygiene on internet-facing devices.
Broader Pattern Note
All three threats share a common characteristic: they are designed to appear normal within legitimate business operations. The security gap lies between assumed and actual control effectiveness, closed through visibility rather than additional tools.
Outro
Closing summary with practical question for IT providers regarding Conditional Access policies. Sign-off and production credit.
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat
01 Jul 2026
00:13:38
Ransomware Group Defeats Endpoint Protection and Microsoft 365 Phishing Threat
The Gentlemen ransomware group has emerged as a top-ten global threat actor by deploying zero-day driver exploits to disable endpoint security tools before launching encryption attacks. Using a vulnerable Kontron driver and the Bring Your Own Vulnerable Driver technique, the group neutralises detection systems silently, often gaining hours of undetected access through compromised VPN and firewall appliances. Meanwhile, the ARToken phishing-as-a-service platform automates Microsoft 365 account takeover through device code phishing and Primary Refresh Token persistence. Standard multi-factor authentication does not prevent these attacks, as the OAuth authentication flows are legitimate. The platform includes automated email and SharePoint exfiltration, plus integrated business email compromise tooling that industrialises payment redirection fraud. UK small businesses using Microsoft 365 face direct exposure, particularly in professional services, accountancy, and financial sectors where client data and payment processes rely on email systems. The NCSC has published guidance on restricting device code flow and monitoring for these attacks, yet implementation remains inconsistent even in critical national infrastructure environments.
Chapters
Introduction
Overview of two urgent threat developments: a ransomware group defeating endpoint security and an automated Microsoft 365 phishing platform bypassing multi-factor authentication.
The Gentlemen Ransomware Group and Zero-Day Driver Exploits
Analysis of The Gentlemen’s rise to top-ten threat status through Bring Your Own Vulnerable Driver techniques, their use of a Kontron driver zero-day to disable endpoint protection, and their systematic approach to network reconnaissance and ransomware deployment.
Call to Action
Encouragement to share the briefing and subscribe for daily updates.
ARToken: Automated Microsoft 365 Account Takeover
Detailed examination of the ARToken phishing-as-a-service platform, its device code phishing methodology, Primary Refresh Token persistence, automated data exfiltration, and integrated business email compromise workflows that bypass standard MFA.
NCSC Penetration Testing Findings
Brief discussion of persistent security gaps identified in critical national infrastructure, including default credentials, insufficient segmentation, and poor patch management.
Closing Recommendations
Summary of immediate actions: enable tamper protection, verify monitoring procedures, restrict device code flow in Microsoft 365, and implement out-of-band payment verification.
Cyber Threats: Helpdesk Attacks and WordPress Risks
28 Jul 2026
00:07:04
Cyber Threats: Helpdesk Attacks and WordPress Risks
Mauven MacLeod presents today’s Threat Analysis, focusing on pressing cyber threats faced by UK small and medium businesses. She explores two major issues: vishing attacks exploiting Microsoft Teams and vulnerabilities in WordPress. Vishing attacks target companies through Microsoft Teams, where attackers impersonate IT helpdesk staff and deploy the GoGRPC backdoor. This can lead to ransomware attacks, compromising sensitive company data. Mauven emphasises the importance of staff awareness and technological safeguards to mitigate risks. The episode also highlights critical vulnerabilities in WordPress Core, affecting versions 6.9.0 to 7.0.1. These vulnerabilities allow unauthorised remote code execution, potentially leading to total site takeovers. Businesses are urged to apply patches immediately to protect their websites and customer data. The National Cyber Security Centre underlines the urgency of this action. Mauven stresses that these insights should lead to a comprehensive cybersecurity strategy, incorporating regular updates, employee training, and robust security policies.
Chapters
Intro
Mauven introduces the episode’s focus on cyber threats targeting UK businesses: Microsoft Teams vishing attacks and WordPress vulnerabilities.
Helpdesk Hijackers: Microsoft Teams Vishing Attacks
Discussion of vishing attacks via Microsoft Teams, where attackers exploit helpdesk impersonations to deploy the GoGRPC backdoor, posing risks to UK businesses.
CTA
A call to action for listeners to follow the podcast for daily briefings and share it with others who might benefit.
WordPress Vulnerabilities: wp2shell Threat
Overview of critical vulnerabilities in WordPress versions 6.9.0 to 7.0.1, allowing remote code execution. Emphasises the need for immediate patches.
Implications for UK SMBs
The importance of integrating cybersecurity into business culture, ensuring systems and staff are well-prepared against current threats.
Outro
Mauven wraps up with a reminder to remain vigilant and to use these insights to strengthen business security.
Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack
30 Jun 2026
00:12:58
Windows Defender Flaw Hits Commodity Ransomware; RMM Tools Under Attack
Two critical threats demand immediate attention from UK small businesses today. First, the BlueHammer vulnerability in Microsoft Defender has transitioned from targeted zero-day attacks to commodity ransomware operations, a shift that dramatically expands the pool of threat actors capable of exploiting it. CISA’s addition of BlueHammer to its Known Exploited Vulnerabilities catalogue confirms active exploitation in the wild, with the flaw enabling attackers to escalate privileges to SYSTEM level and deploy ransomware across entire networks. Second, Blackpoint Cyber has documented an active intrusion chain exploiting CVE-2026-48558, an authentication bypass in SimpleHelp remote monitoring and management software. This attack vector is particularly concerning because it targets the tools IT providers use to manage client systems, turning the trust relationship between businesses and their managed service providers into an attack surface. The operational implication is clear: attackers are systematically exploiting the privileged access that IT management tools provide, bypassing direct targeting in favour of supply chain compromise. Patches exist for both vulnerabilities. The gap between availability and deployment is where ransomware operators operate. UK SMBs should contact their IT providers today to confirm patching status and ask specific questions about RMM tool security. This briefing provides actionable guidance on exactly what to ask and why it matters.
Chapters
Introduction
Mauven introduces today’s two threat stories: the BlueHammer vulnerability in Windows Defender crossing into commodity ransomware operations, and an attack targeting remote management tools used by IT providers.
BlueHammer: From Zero-Day to Ransomware Commodity
Analysis of CISA’s KEV addition for BlueHammer, a privilege escalation flaw in Microsoft Defender now exploited in commodity ransomware operations. Covers the transition from targeted attacks to volume-based campaigns, the operational playbook of ransomware-as-a-service groups, and the practical patching actions UK SMBs must take immediately.
CTA
Brief call to action encouraging listeners to follow the show and share it with business owners and operations managers who need actionable threat intelligence.
SimpleHelp RMM: The Attack That Comes Through Your IT Provider
Detailed examination of CVE-2026-48558, an authentication bypass in SimpleHelp remote monitoring and management software. Explains how attackers exploit RMM tools to gain technician-level access to managed client systems, the malware deployed (TaskWeaver and Djinn Stealer), and the supply chain risk this represents for UK SMBs.
What UK SMBs Should Do Today
Direct, actionable guidance for UK small businesses: specific questions to ask IT providers about BlueHammer patching, SimpleHelp vulnerability status, RMM access log reviews, and incident disclosure processes.
Outro
Closing summary emphasising the gap between patch availability and deployment, urging businesses to actively verify patching status with their IT providers rather than assume it has been handled.
Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild
29 Jun 2026
00:14:22
Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild
Oracle E-Business Suite vulnerability CVE-2026-46817 is under active exploitation, with confirmed activity from threat intelligence firm Defused. Nissan’s recent breach of its Oracle PeopleSoft instance underscores the broader risk to Oracle’s enterprise portfolio. UK small businesses face exposure through supply chain relationships with payroll bureaus, accountancy firms, and manufacturers running Oracle systems. Meanwhile, newly documented threat actor DriveSurge operates a pay-per-install initial access broker model, compromising legitimate websites to deliver malware through fake browser updates and ClickFix social engineering. The campaign bypasses email security controls entirely, infecting users through normal web browsing. Additional concerns include active exploitation of Langflow (CVE-2026-55255) and the Miasma Mini Shai-Hulud supply chain campaign now targeting Backstage npm packages. Today’s briefing provides specific, actionable steps: verify Oracle patch status with suppliers, implement web filtering against zTDS infrastructure, brief staff on fake browser update prompts, and audit dependencies in development pipelines. These are email-and-call actions, not budget-heavy projects.
Chapters
Introduction
Mauven opens with two active threat stories: exploitation of Oracle E-Business Suite and a drive-by attack campaign bypassing email controls through compromised websites. Both pose immediate risks to UK small businesses through supply chain and web browsing vectors.
Oracle EBS Active Exploitation
CVE-2026-46817 in Oracle E-Business Suite is under confirmed exploitation. Nissan’s PeopleSoft breach demonstrates sustained threat actor attention to Oracle’s enterprise platforms. UK small businesses face exposure through payroll bureaus, accountancy firms, and manufacturers. Practical steps include verifying patch status directly with suppliers and documenting responses in writing.
Mid-Roll Call to Action
Brief listener prompt to follow the show and share the briefing with relevant contacts.
DriveSurge Drive-By Campaign
DriveSurge, a newly documented initial access broker, compromises legitimate websites to deliver malware via fake browser updates and ClickFix prompts. The campaign uses zTDS traffic distribution and bypasses standard email security. Recommended defences include web filtering against zTDS infrastructure and staff briefing on fake update prompts.
Langflow and Miasma Mini Shai-Hulud Updates
CVE-2026-55255 in Langflow is under active exploitation, with lower-scored CVE-2026-33017 seeing wider use due to easier exploitation. The Miasma Mini Shai-Hulud campaign now targets Backstage npm packages. Organisations using AI frameworks or modern CI/CD pipelines should audit patch status and dependencies.
Closing Summary
Mauven summarises practical actions in order of urgency: verify Oracle patch status with suppliers, brief staff on fake browser updates, confirm web filtering covers zTDS, and audit development dependencies. All actions require communication and follow-up, not significant budget.
Understanding Mini Shai-Hulud and Cisco's Zero-Day Vulnerabilities
26 Jun 2026
00:05:44
Understanding Mini Shai-Hulud and Cisco’s Zero-Day Vulnerabilities
In today’s episode of Threat Analysis, Mauven MacLeod delves into two significant cybersecurity threats impacting UK small and medium businesses. The Mini Shai-Hulud supply chain attack targets the development community by exploiting npm packages, risking developers’ credentials and threatening software integrity. Microsoft emphasises the importance of rigorous dependency audits to prevent malicious exploitation. Additionally, a zero-day vulnerability CVE-2026-20245 in Cisco’s Catalyst SD-WAN Manager is discussed. This allows attackers to escalate privileges through default passwords, compromising network security. The necessity of proactive cybersecurity measures, including multi-factor authentication and robust monitoring systems, is highlighted to safeguard businesses from these threats.
Chapters
Intro
Mauven introduces the episode, highlighting critical threats for UK businesses.
Mini Shai-Hulud Supply Chain Attack
Discusses how Mini Shai-Hulud uses npm packages to access developer credentials, emphasising the need for vigilant software audits.
CTA
Encourages listeners to follow the show for updates and share with peers.
CVE-2026-20245: Cisco’s Zero-Day
Explores the Cisco vulnerability, stressing the dangers of default passwords and the importance of intrusion detection systems.
Outro
Reiterates the importance of proactive cybersecurity measures and invites listeners to return for future episodes.
In this episode of Threat Analysis, Mauven MacLeod dives into two pressing cybersecurity threats affecting UK small and medium businesses. The first is the Mistic backdoor, linked to the notorious Woodgnat, which employs the cunning technique of sideloading. This method uses legitimate software to conceal malicious activity, posing significant risks such as data leaks and financial loss. Mauven discusses the importance of a robust security posture and offers practical advice on staying protected. The second threat is the widespread FortiBleed campaign targeting Fortinet FortiGate devices through advanced techniques like credential stuffing and password spraying. The campaign highlights vulnerabilities found in legacy systems and underscores the need for up-to-date device management and strong authentication protocols. Listeners are encouraged to assess and fortify their cybersecurity defences actively. The episode closes with a reminder: awareness is key, but proactive measures are essential to safeguarding your business.
Chapters
Intro
Mauven introduces today’s cybersecurity topics, focusing on threats to UK businesses.
Mistic Backdoor Unveiled
Discussion on the Mistic backdoor’s impact, sideloading techniques, and security recommendations.
CTA
Listeners are encouraged to follow the podcast and share it with others.
FortiGate Under Siege
Analysis of the FortiBleed campaign targeting Fortinet devices, with tips to enhance network security.
Outro
Recap of the threats discussed and a call to take proactive security measures.
Understanding the Mistic Backdoor Threat to UK SMBs
24 Jun 2026
00:06:40
Understanding the Mistic Backdoor Threat to UK SMBs
In this episode of Threat Analysis, Mauven MacLeod explores the emerging threat landscape for UK small and medium businesses, focusing on the Mistic backdoor. This malware, linked to the ransomware access broker KongTuke, poses significant risks to crucial sectors such as insurance, education, IT, and professional services. The discussion highlights how Mistic operates stealthily within compromised systems, bypassing many traditional security measures and exacerbating vulnerabilities in supply chains. Additionally, the episode delves into broader cybersecurity concerns, including the critical vulnerability CVE-2026-20230 in Cisco Unified Communications Manager and privacy issues arising from London’s use of live facial recognition technology. Mauven provides actionable steps for SMBs to strengthen their defences, emphasising the importance of robust vendor audits, advanced threat detection, and well-prepared incident response plans, aligning with guidance from the National Cyber Security Centre.
Chapters
Intro
Mauven introduces the focus on the Mistic backdoor and its relevance to UK SMBs.
Mistic Backdoor Threat
Exploration of the Mistic backdoor’s tactics, connection to KongTuke, and its impact on key sectors.
The Broader Context
Discussion on Cisco’s vulnerability and the implications of facial recognition technology in London.
What Should You Do?
Actionable cybersecurity measures for SMBs, including vendor audits and threat detection enhancements.
CTA
Encouragement to follow the show and share it with others needing the briefing.
Outro
Summary of today’s insights and the importance of proactive cybersecurity strategies.
Klue Supply Chain Breach and AI Cybersecurity Warnings
23 Jun 2026
00:02:25
Klue Supply Chain Breach and AI Cybersecurity Warnings
In this episode of Threat Analysis, Mauven MacLeod explores a pressing supply chain attack that targets Salesforce environments through Klue’s backend systems. The breach, executed by the Icarus threat group, highlights the vulnerabilities of OAuth tokens and the implications for UK small businesses. Mauven discusses the importance of reviewing security practices to prevent data exposure. The episode also features a warning from the Five Eyes alliance about the potential risks associated with AI in cybersecurity. As AI technology evolves, safeguarding against its misuse becomes crucial. Tune in for essential insights and strategies to navigate these challenges.
Chapters
Intro
Mauven introduces the focus on a crucial supply chain attack and AI-related cybersecurity threats.
Klue Supply Chain Attack Hits Salesforce Environments
Details the Icarus group’s attack on Klue, impacting Salesforce and the importance of OAuth token security.
CTA
Encourages listeners to follow the show for regular updates on cybersecurity threats.
Five Eyes Warn of AI Escalating Cybersecurity Threats
Highlights the Five Eyes alliance’s warning on AI exacerbating cybersecurity threats and the need for robust oversight.
Outro
Concludes with the interconnected nature of modern business threats and the importance of enhanced security measures.
Join Mauven MacLeod for today’s Threat Analysis, a briefing focused on the latest cyber threats facing UK businesses. The episode covers the sophisticated attack on 3CXDesktopApp, which exploits supply chain vulnerabilities through trojanised installers. We also delve into the FortiBleed campaign, highlighting the increased risk posed by attacks on Fortinet FortiGate firewalls. The AryStinger botnet is examined, demonstrating how outdated hardware can become a security liability. Finally, the episode discusses AI risks, emphasised by recent NCSC publications, underscoring the evolving role of AI in cybersecurity. Stay informed to protect your business from these modern threats.
Chapters
Intro
Introduction to key cyber threats impacting UK businesses.
3CXDesktopApp Intrusion
Discussion on trojanised installers and supply chain vulnerabilities.
CTA
Encouragement to follow and share the podcast for daily updates.
FortiBleed Campaign
Examination of attacks on Fortinet firewalls and SSL VPN gateways.
AryStinger Botnet
Analysis of the botnet hijacking outdated D-Link routers.
AI Risks
Exploration of AI’s role in cybersecurity and related threats.
Outro
Summary and emphasis on staying informed about cyber threats.
Active Splunk Exploit and npm Supply Chain Campaign
19 Jun 2026
00:10:02
Active Splunk Exploit and npm Supply Chain Campaign
CISA has confirmed active exploitation of a critical Splunk Enterprise vulnerability, with a patch deadline of 22 June 2026 for US federal agencies. UK organisations face the same threat but lack a legal mandate. Separately, over 140 npm packages in the mastra ecosystem were compromised through account takeover, pushing typosquatted dependencies that harvest credentials on installation. A second npm attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating SSH keys and cloud credentials via DNS. A third attack targeted PyPI’s Microsoft DurableTask client through a stolen GitHub account. The Okendo Reviews widget, used by over 18,000 e-commerce brands, was also found to contain malicious JavaScript in May 2026. These attacks share a common thread: patient exploitation of trust frameworks in developer tooling and monitoring platforms. Mauven provides actionable steps for UK businesses to verify patch status, audit dependency chains, review DNS monitoring capability, and confirm e-commerce widget remediation before the weekend.
Chapters
Intro
Mauven introduces two active threats requiring immediate attention: a CISA advisory on exploited enterprise software and a coordinated developer ecosystem compromise campaign. Response capability drops over weekends, making Friday advisories particularly dangerous.
npm Supply Chain Surge
Microsoft Threat Intelligence confirmed compromise of over 140 npm packages via account takeover, pushing typosquatted dayjs dependency. A second attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating credentials via DNS. A third targeted PyPI’s DurableTask client. Okendo Reviews widget injected with malicious JavaScript in May 2026 affected 18,000 e-commerce brands.
CTA
Listener call to action: follow the show and share with colleagues who need threat intelligence.
Splunk Enterprise Under Active Exploit
CISA added Splunk Enterprise vulnerability to KEV catalogue with 22 June 2026 patch deadline for US agencies. UK organisations lack legal mandate but face identical risk. Compromised monitoring platforms allow attackers to suppress alerts and manipulate log data from a trusted internal position.
ICO Leadership Change
John Edwards resigned as Information Commissioner. Leadership transition creates institutional uncertainty around enforcement priorities, though legal obligations remain unchanged.
What To Do Before Monday
Immediate actions: verify Splunk patch status, audit recent npm and PyPI package updates, confirm Okendo widget remediation if present in May 2026, and implement or plan outbound DNS monitoring to close exfiltration blind spots.
Outro
Attackers exploit trust in packages, monitoring tools, and institutional frameworks. They are patient, sophisticated, and aware that Friday advisories are often deferred. Do not give them the weekend.
DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch
17 Jun 2026
00:10:45
DragonForce Hides in Teams, Joomla at Maximum Severity, and RoguePlanet Waits for a Patch
Three active threats demand immediate attention from UK small and medium businesses. Symantec researchers have documented DragonForce ransomware concealing command-and-control infrastructure inside Microsoft Teams relay servers using a custom backdoor that exploits anonymous visitor tokens. The intrusion evaded detection for over two weeks by routing malicious traffic through legitimate Microsoft infrastructure. CISA has added a maximum-severity Joomla Content Editor vulnerability (CVE-2024-43233) to its Known Exploited Vulnerabilities catalogue, confirming active exploitation of an unauthenticated remote code execution flaw widely present in UK business websites. A publicly disclosed privilege escalation zero-day in Microsoft Defender, named RoguePlanet, remains unpatched while attackers actively deploy footholds through phishing and social engineering campaigns. Mauven examines why perimeter defences cannot catch infrastructure-layer threats, what behavioural anomaly monitoring actually means in practice, and why patch management discipline should not depend on regulatory deadlines. This briefing provides specific technical actions for Joomla users, questions to ask managed security providers, and interim controls for the Defender zero-day.
Chapters
DragonForce Conceals Command Infrastructure Inside Microsoft Teams
Symantec documents a two-week ransomware intrusion using custom malware to route attacks through Microsoft Teams relay servers, evading perimeter defences by hiding inside legitimate traffic. The technique exploits TURN servers and anonymous visitor tokens, requiring behavioural anomaly monitoring rather than edge security to detect.
CISA Adds Maximum-Severity Joomla Vulnerability to Exploitation Catalogue
CVE-2024-43233, a CVSS 10.0 unauthenticated remote code execution flaw in the Joomla Content Editor plugin, is under active exploitation. The vulnerability affects a widely deployed extension common in UK small business websites. CISA has set a Friday patch deadline for federal agencies.
RoguePlanet Privilege Escalation Zero-Day in Microsoft Defender Remains Unpatched
A publicly disclosed privilege escalation vulnerability in Microsoft Defender, part of the Nightmare Eclipse research chain, has no available patch. Microsoft has confirmed work is underway. The flaw enables attackers who gain initial access through phishing or social engineering to escalate to full system control on Windows endpoints.
Priority Actions and Patch Management Discipline
Immediate actions include checking and patching Joomla JCE installations, asking managed security providers about internal anomaly monitoring capabilities, and applying least privilege controls while awaiting the Defender patch. A brief note covers an updated Cisco SD-WAN advisory affecting additional device models.
DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites
16 Jun 2026
00:10:55
DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites
Three critical threats demand immediate attention from UK small businesses today. DragonForce ransomware has deployed a custom backdoor that tunnels command-and-control traffic through Microsoft Teams relay infrastructure, exploiting implicit trust in cloud services. Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are being actively exploited in the wild, raising serious questions for businesses relying on managed security providers. Meanwhile, over 1.2 million WordPress sites have been compromised through a supply chain attack targeting OptinMonster, TrustPulse, and PushEngage plugins. CISA has also added a critical LiteSpeed cPanel vulnerability to its Known Exploited Vulnerabilities catalogue, affecting countless UK websites on shared hosting. Mauven MacLeod walks through the behavioural and operational gaps these threats expose, and provides four concrete actions businesses can take today: checking FortiSandbox patch status with managed security providers, verifying LiteSpeed plugin updates with hosting providers, auditing WordPress admin accounts, and reviewing Microsoft Teams external tenant access configurations. None of these actions require large budgets, but all require the willingness to ask direct questions of service providers.
Chapters
DragonForce Hides in Teams, Fortinet Flaws, and a Million Compromised WordPress Sites
Mauven introduces three urgent threats: a sophisticated backdoor exploiting Microsoft Teams infrastructure, critical Fortinet vulnerabilities being actively exploited, and a WordPress supply chain attack compromising over a million sites. She explains why DragonForce’s Backdoor.Turn tool exploits implicit trust in Microsoft Teams relay traffic, details the pattern of Fortinet security product vulnerabilities, covers CISA’s urgent warning on LiteSpeed cPanel flaws, and reveals a supply chain attack through Awesome Motive’s CDN affecting OptinMonster, TrustPulse, and PushEngage plugins. The briefing concludes with four immediate actions: checking FortiSandbox patch status, verifying LiteSpeed updates, auditing WordPress admin accounts, and reviewing Teams external access settings.
In today’s episode, Mauven MacLeod tackles pressing vulnerabilities affecting UK small and medium businesses. Microsoft’s Defender for Endpoint is under scrutiny due to bugs that leave Linux systems unprotected. From installation issues on hardened RHEL systems to deactivation on restart, these glitches pose significant security risks. Attention is drawn to Java Spring Boot’s exposed endpoints revealing sensitive data, underscoring GDPR compliance risks. The discussion moves to critical vulnerabilities, CVE-2026-16461 and 8450, and their severe implications. Finally, Google’s cybercrime taxonomy offers new insights into defending against threats. It’s an urgent call to action for businesses to address these threats promptly.
Chapters
Intro
Introduction to the urgency of addressing security vulnerabilities for UK businesses.
Microsoft Defender for Endpoint
Analysis of vulnerabilities in Microsoft Defender, affecting Linux systems and RHEL installations.
Java Spring Boot Vulnerabilities
Exposed heapdump endpoints in Java Spring Boot pose risks of data exposure and GDPR violations.
Microsoft Security Response
Critical vulnerabilities CVE-2026-16461 and CVE-2026-8450 discussed with potential impacts.
Google’s Cybercrime Taxonomy
Google’s new cybercrime taxonomy aids in understanding and targeting specific threats effectively.
Outro
Final thoughts on the need for urgent action to secure business systems against vulnerabilities.
One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation
16 Jun 2026
00:10:05
One-Click Data Theft via M365 Copilot and Active Cisco SD-WAN Exploitation
Two critical vulnerabilities demand immediate attention from UK businesses today. Researchers have disclosed SearchLeak, a prompt injection vulnerability chain in Microsoft 365 Copilot Enterprise that allows attackers to steal data from mailboxes, OneDrive, and SharePoint with a single malicious link. The attack exploits Copilot’s AI assistant functionality to exfiltrate sensitive information without further user interaction. Meanwhile, Cisco Talos reports active exploitation of authentication bypass vulnerabilities in Cisco Catalyst SD-WAN infrastructure by the sophisticated threat actor UAT-8616, who is deploying multiple command-and-control frameworks including Sliver and Godzilla for persistent network access. Most UK SMBs don’t run SD-WAN directly but face indirect exposure through managed service providers. Both threats target infrastructure that organisations trust by default but rarely examine closely. The episode provides specific verification steps for IT providers and MSPs, emphasising the gap between vendor patches and organisational verification as the primary source of security incidents.
Chapters
Introduction
Mauven opens with an urgent warning about a one-click data theft vulnerability affecting Microsoft 365 Copilot Enterprise users, then previews coverage of active Cisco SD-WAN exploitation.
SearchLeak: M365 Copilot as a Data Theft Tool
Analysis of the SearchLeak vulnerability chain in Microsoft 365 Copilot Enterprise. The prompt injection attack allows attackers to use specially crafted URLs to instruct Copilot to search and exfiltrate data from mailboxes, OneDrive, and SharePoint. Microsoft has patched the vulnerability, but verification of deployment through MSPs is critical. Recommendations include confirming patch status, reviewing Copilot licence assignments, applying least privilege access controls, and exercising caution with links triggering Copilot interactions.
Call to Action
Reminder to follow the show and share with colleagues who need daily threat intelligence.
Cisco SD-WAN: Active Exploitation by UAT-8616
Cisco Talos reports active exploitation of CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Controller and Manager. The sophisticated threat actor UAT-8616 is deploying Sliver, Godzilla, AdaptixC2, and Behinder for persistent access to network infrastructure. Most UK SMBs face indirect exposure through managed service providers running this infrastructure. Actions include immediate patching for direct users, verification calls to MSPs regarding their infrastructure and patching status, contract review for incident disclosure terms, and monitoring for anomalous routing changes.
Supply Chain Pressure Continues
Brief coverage of Arch Linux locking down AUR signups after malicious commits, and Unit 42 analysis of updated obfuscation techniques in Gremlin Stealer infostealer targeting browser credentials.
Closing
Mauven emphasises that both threats target infrastructure organisations trust without close examination. Final action items: contact IT providers or MSPs to verify M365 patch status and Cisco SD-WAN infrastructure security posture.
AI Phishing, Clinical Data Theft, and the CC Field Mistake
13 Jun 2026
00:12:54
AI Phishing, Clinical Data Theft, and the CC Field Mistake
Mauven MacLeod examines three incidents that illustrate how UK businesses are actually compromised in 2026. Google has sued a Chinese phishing operation selling AI-generated SMS fraud toolkits via Telegram, producing messages now indistinguishable from legitimate communications. Novo Nordisk disclosed that attackers accessed pseudonymised clinical trial data after a phishing email breach, demonstrating that even large pharmaceutical firms remain vulnerable. Plymouth City Council exposed hundreds of email addresses by using CC instead of BCC in a message to families, triggering an ICO report. Across all three stories, the common thread is not sophisticated exploits but phishing, human error, and procedural failure. Mauven walks through practical mitigations: phishing-resistant MFA, link-checking tools, verification protocols for payment requests, tested incident response plans, least-privilege access for special category data, and using proper email platforms instead of manual BCC. The episode also notes Microsoft’s resolution of a year-long Windows update deployment issue affecting centrally managed devices. None of these threats require nation-state resources. All of them are preventable with controls that already exist in published guidance.
Chapters
Introduction
Mauven opens the 12 June 2026 briefing, noting that all three stories involve phishing or human error rather than exotic threats.
Google Sues AI Phishing Operation
Google has filed suit against Outsider Enterprise, a Chinese group selling AI-generated phishing toolkits via Telegram. AI now produces messages indistinguishable from legitimate communications. Mauven explains why traditional awareness training is failing and recommends phishing-resistant MFA, link-checking tools, verified callback protocols, and low-friction reporting processes.
Novo Nordisk Clinical Data Breach
Novo Nordisk disclosed that attackers accessed pseudonymised clinical trial participant data following a phishing email. Mauven emphasises that size is no defence, walks through UK GDPR notification requirements for special category data, and urges tested incident response plans, least-privilege access, and documented data protection contacts.
Plymouth Council CC Field Error
Plymouth City Council exposed hundreds of email addresses by using CC instead of BCC in a message to home-schooling families, then reported the breach to the ICO. Mauven explains Article 33 notification obligations and recommends process defaults, email marketing platforms, and brief team training.
Windows Update Fix
Microsoft resolved a known issue preventing Windows updates from installing via network share since May 2025. Unpatched devices remain a ransomware entry point.
Closing Summary
Mauven recaps the common thread across all stories and urges listeners to verify their suspicious message reporting loop. Promotes the Daily Threat Analysis Substack, Corrine Jefferson’s Daily CVE Update, and Graham Falkner’s practical security assessments.
In today’s episode of Threat Analysis, Mauven MacLeod explores two significant cyber threats impacting UK small and medium-sized businesses: the Mistic backdoor and the FortiBleed campaign. Both threats exploit vulnerabilities requiring immediate attention. The Mistic backdoor, potentially operated by the notorious access broker Woodgnat, uses sideloading attacks to infiltrate systems. This method often goes unnoticed and has been a staple in cybercriminal activities for years, affecting industries like professional services and healthcare. Mauven emphasises the importance of meaningful conversations with IT teams to mitigate such risks and secure vendor relationships effectively. The episode then shifts focus to the FortiBleed campaign, which targets Fortinet’s FortiGate firewalls. These essential components of network security are under significant threat as FortiBleed employs an immediate credential theft strategy. This can escalate from potential risk to an operational crisis rapidly. Mauven advises businesses to apply necessary patches promptly and enhance network monitoring protocols to detect unusual activities. Both threats underscore the necessity for proactive cybersecurity measures.
Chapters
Intro
Mauven introduces the episode’s focus on two cyber threats, Mistic backdoor and FortiBleed, highlighting the urgency for UK businesses to address these vulnerabilities.
Mistic Backdoor: Initial Access and Credential Theft
Discussion on Mistic backdoor’s sideloading attacks by Woodgnat. Emphasises the need for businesses to engage with IT teams to mitigate risks and secure systems effectively.
CTA
Encouragement to follow the podcast for daily updates and share with others who could benefit from the information.
FortiBleed Campaign: A Primer on Credential Harvesting
Analysis of the FortiBleed campaign targeting Fortinet FortiGate firewalls. Highlights the urgent requirement for applying patches and enhancing network monitoring protocols.
Outro
Reinforces the necessity for vigilance and proactive measures in cybersecurity strategies. Encourages continual threat assessment and response.
UK SMBs Face Ransomware Re-Extortion and Langflow Threats
22 Jul 2026
00:07:07
UK SMBs Face Ransomware Re-Extortion and Langflow Threats
In this episode of Threat Analysis, Mauven MacLeod explores critical cyber threats that UK small and medium-sized businesses (SMBs) must be aware of. The discussion begins with the increasing trend of ransomware re-extortion, where attackers demand additional payments even after receiving a ransom. Proofpoint reports show over a third of victims are affected by this tactic, highlighting the necessity for robust cybersecurity measures. The episode also covers a significant vulnerability in Langflow, as identified by CISA, which allows remote code execution and is being actively exploited. Mauven stresses the importance of immediate patching to secure AI systems against potential breaches. Additionally, the new JADEPUFFER ransomware poses a risk to AI models critical to business operations. Lastly, a vulnerability in Adobe’s Chrome extension exposes WhatsApp chats to unauthorised access, underscoring the need for secure communication policies. Join Mauven for insights into these pressing cybersecurity challenges.
Chapters
Intro
Introduction to the episode’s focus on critical cyber threats for UK SMBs.
Ransomware Re-Extortion
Discussion on the trend of ransomware re-extortion affecting over a third of victims.
CTA
Encouragement to follow the podcast for regular updates.
Langflow RCE Vulnerability
Exploration of a critical vulnerability in Langflow allowing remote code execution.
JADEPUFFER Ransomware
Examination of JADEPUFFER ransomware targeting AI models and infrastructure.
Adobe Chrome Extension Vulnerability
Coverage of a security flaw in Adobe’s Chrome extension impacting WhatsApp security.
Outro
Conclusion with a call to action to strengthen cybersecurity defences.
Protecting Against Ransomware and Evolving Cyber Threats
21 Jul 2026
00:06:33
Protecting Against Ransomware and Evolving Cyber Threats
In today’s briefing, Mauven MacLeod delves into imperative cybersecurity updates impacting UK businesses. The Qilin ransomware gang is actively exploiting a critical flaw in Palo Alto Networks’ GlobalProtect VPN, posing significant risks even to small enterprises. This episode underscores why businesses of all sizes must prioritise security updates to guard against cybercriminals. Additionally, Mauven discusses the emerging Jadepuffer group targeting AI technologies and the HOLLOWGRAPH campaign, which ingeniously utilises Microsoft 365 calendars for sinister purposes. The episode highlights the necessity for vigilant, proactive security practices and the importance of continuous education in the face of evolving threats.
Chapters
Intro
Mauven introduces the episode, focusing on the Qilin ransomware gang exploiting a VPN flaw and emphasising the need for all businesses to be vigilant.
Qilin Ransomware Exploits VPN Flaw
Analysis of the Qilin ransomware exploiting a critical VPN vulnerability and its implications for businesses of all sizes.
CTA
Encouragement to follow the podcast for regular updates.
Evolving Ransomware Tactics and Jadepuffer
Discussion on Jadepuffer targeting AI models and the importance of staying ahead of sophisticated cyber threats.
HOLLOWGRAPH Campaign Risks
Overview of the HOLLOWGRAPH campaign using Microsoft 365 calendars for espionage, urging businesses to reassess security measures.
Outro
Concluding remarks on the importance of staying informed and proactive against digital threats.
ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing
20 Jul 2026
00:15:43
ServiceNow RCE Under Active Exploitation, Plus M365 Passkey Vishing
Three critical threats demand immediate attention today. A remote code execution vulnerability in ServiceNow’s AI Platform (CVE-2026-6875) is now actively exploited in the wild, requiring urgent patch verification from direct users and managed service providers alike. Meanwhile, a vishing campaign running since April has been successfully defeating Microsoft 365 passkey enrolment through carefully scripted social engineering, targeting UK SMBs who adopted phishing-resistant MFA but failed to brief staff on the human attack vector. The third story examines FortiBleed, an industrial-scale FortiGate credential harvesting operation exposed when attackers left their staging server accessible, revealing 36 rented GPUs running distributed password cracking as a production workflow. The episode also covers the Cruciferra crypter service, which offers high-quality endpoint evasion as a purchased feature, and the Hugging Face breach involving an autonomous AI agent. Each story includes specific, actionable guidance for UK organisations, with particular emphasis on the ServiceNow vulnerability requiring same-day verification from users and their supply chain.
Chapters
Introduction
Mauven flags three threats requiring immediate action, particularly a ServiceNow vulnerability that has moved from patch-available to actively exploited. The episode will cover required responses for ServiceNow users, Microsoft 365 passkey vishing, and industrial-scale FortiGate credential harvesting.
CVE-2026-6875: ServiceNow AI Platform RCE Under Active Exploitation
Critical remote code execution vulnerability in ServiceNow AI Platform confirmed under active exploitation. Direct users must verify patch status immediately. Indirect exposure through managed service providers presents significant risk to UK SMBs. Specific guidance provided on what questions to ask providers and when patch confirmation is required.
Call to Action
Brief encouragement to follow the show and share with colleagues who need the briefing.
O-UNC-066: Vishing Actors Defeating Microsoft 365 Passkey Enrolment
Campaign active since April uses phone-based social engineering to register attacker-controlled passkeys to victim Microsoft 365 accounts. Attackers use domains containing ‘passkey’, impersonate Microsoft support, and guide targets through fake enrolment while simultaneously registering their own credentials. Three-part mitigation: restrict enrolment policies in Entra, brief staff on the attack pattern, and focus training on reception and finance staff most likely to receive calls.
FortiBleed: Industrial-Scale VPN Credential Harvesting
Exposed attacker staging server reveals large-scale FortiGate credential harvesting using 36 rented GPUs for distributed password cracking. Operation uses credential reuse, brute force, and GPU-accelerated hash cracking as an industrial workflow. Likely feeds initial access broker market serving ransomware operators. Guidance provided on verifying patch status, rotating credentials, and reviewing authentication logs.
Also on the Radar
Two additional items: Cruciferra crypter service offering high-quality endpoint evasion including BYOVD-based EDR tampering as a purchased feature, and Hugging Face breach involving autonomous AI agent access to production infrastructure and credentials. Both items flag direction of travel rather than immediate operational response.
Closing Summary
Recap of required actions: ServiceNow patch verification today, Microsoft 365 Entra policy review and staff briefing on vishing, FortiGate patch status and credential rotation. Emphasises that attackers operate at industrial scale while effective defences require consistent follow-through on straightforward measures.
FortiSandbox Exploit, Windows Zero-Day, and ClickFix Infrastructure at Scale
17 Jul 2026
00:14:21
FortiSandbox Exploit, Windows Zero-Day, and ClickFix Infrastructure at Scale
CISA added critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalogue following confirmed in-the-wild exploitation. The US federal patching deadline is Sunday, but active exploitation means UK organisations should treat this as immediate priority. A newly published Windows local privilege escalation vulnerability called LegacyHive works on fully patched systems with no fix available, creating serious risk when combined with active ClickFix campaigns delivering initial access. ClickFix techniques now support at least five concurrent malware operations including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A Huntress case study documents how one ClickFix compromise spread to eleven hosts before detection. The episode provides specific, actionable guidance for SMBs: verify FortiSandbox patch status with IT providers today, brief staff on ClickFix lures immediately, review user permissions to execute scripts, and ensure endpoint detection monitors for HTA execution and PowerShell spawning from browser processes. The convergence of mature exploit infrastructure, public zero-day proof-of-concept, and active campaigns targeting European users represents a significant immediate threat to UK small business networks.
Chapters
Introduction
Mauven opens the seventeenth of July briefing with three urgent stories. Two require immediate technical action before the weekend, whilst the third demands procedural response to an unpatched vulnerability.
FortiSandbox Active Exploitation
CISA confirmed active exploitation of critical FortiSandbox command injection vulnerabilities, ordering US federal agencies to patch by Sunday. FortiSandbox is a threat analysis appliance, not the firewall, creating particular concern as the security tool itself becomes attack surface. Guidance covers immediate patching requirements, how to verify MSP compliance, and the importance of asset inventory for unknown Fortinet deployments.
Call to Action
Brief appeal to follow the show and share with colleagues who need threat intelligence.
LegacyHive Zero-Day Vulnerability
A public proof-of-concept for Windows local privilege escalation called LegacyHive works on fully patched systems with no available fix. The vulnerability requires initial access first, which current ClickFix campaigns are actively providing across European targets. Defence recommendations focus on preventing initial compromise through application allow-listing, endpoint detection configuration, and staff awareness of ClickFix techniques.
ClickFix Campaign Infrastructure
At least five distinct malware operations now use ClickFix delivery techniques, including ACR Stealer, Starland RAT, TELEPUZ, Potemkin Loader, and TTF campaign payloads. A detailed Huntress case study shows one ClickFix compromise spreading to eleven hosts. Practical guidance includes immediate staff briefing, permission reviews to block arbitrary script execution, and verification that managed detection providers monitor relevant observable behaviours.
Conclusion
The convergence of mature ClickFix infrastructure, public Windows zero-day exploitation capability, and continuing Fortinet vulnerability exploitation represents the gap between published guidance and implemented defences. Two immediate actions: verify FortiSandbox patch status and brief staff on ClickFix lures before Friday.
Social Engineering, Trojanised Tools, and Supply Chain Attacks
16 Jul 2026
00:16:50
Social Engineering, Trojanised Tools, and Supply Chain Attacks
This episode examines three contemporary threats exploiting trusted channels. Following the sentencing of two Scattered Spider members for the Transport for London breach, we analyse why social engineering remains devastatingly effective against organisations of all sizes. We then review a Russian campaign distributing trojanised WebEx and Zoom installers delivering Starland RAT, demonstrating how legitimate software becomes an attack vector. Finally, we cover the AsyncAPI npm supply chain compromise, where GitHub Actions vulnerabilities enabled injection of Miasma v3 worm into packages with valid provenance attestations. The common thread: attackers succeed not through technical brilliance, but by exploiting routine trust in familiar processes. We provide actionable guidance on helpdesk authentication procedures, software download verification, and dependency chain auditing. Additional coverage includes CISA’s Oracle E-Business Suite KEV listing and the approaching Windows 10 end-of-support deadline. Presented by Mauven MacLeod with behavioural analysis and concrete defensive measures for UK small businesses.
Chapters
Introduction
Opening remarks establishing the episode’s central theme: trusted channels being weaponised through social engineering, trojanised software, and compromised dependencies.
Scattered Spider Sentencing
Analysis of two British Scattered Spider members receiving five-and-a-half-year sentences for the Transport for London breach, focusing on the social engineering techniques used and practical implications for SMB helpdesk procedures.
Call to Action
Audience engagement request encouraging listeners to follow the show and share with business owners.
Trojanised WebEx and Zoom
Examination of Russian actor UAT-11795 distributing backdoored collaboration software installers through phishing and search poisoning, delivering Starland RAT with credential theft and cryptocurrency targeting capabilities.
AsyncAPI npm Supply Chain Compromise
Technical breakdown of the AsyncAPI organisation compromise via GitHub Actions vulnerability, resulting in Miasma v3 worm delivery through four npm packages with valid provenance attestations and novel execution timing.
Also on the Radar
Brief coverage of CISA’s Oracle E-Business Suite KEV addition and the approaching Windows 10 end-of-support deadline for Home and Pro editions.
Closing Remarks
Summary emphasising verification over assumption, with specific guidance on questioning helpdesk authentication procedures.