CTO at NCSC Summary: week ending November 9th
It is clear that AI will drive a generational shift in productivity - the trick is not letting it distract us from the fundamentals which ensure cyber security outcomes we seek.
Welcome to the weekly highlights and analysis of the blueteamsec (and my wider reading). Not everything makes it in, but the best bits do.
Operationally this week nothing overly of note…
In the high-level this week:
NCSC CyberUK tech talks call for papers - NCSC UK announce - “Each twenty-minute talk will take the form of an advanced briefing on innovation, future technology or a piece of research followed by five minutes for audience questions.” - - the CFP covers three focuses
Cyber applications of AI
What works: approaches that reduce harm
The evolving threat
NCSC to retire Web Check and Mail Check - NCSC UK announce - in short the services and capabilities available in commercial External Attack Surface Management (EASM) solutions now cater for these use cases.
Demystifying Zero Trust - NCSC UK demystifies - “It tackles some of the misconceptions around ZT and explains the key things to consider for implementation.”
Using Privileged Access Workstations (PAWs) in Operational Technology (OT) environments - NCSC UK publishes - “A PAW can play a critical role in enhancing the overall cyber security defences within these systems, helping to mitigate the risks of a wider system compromise leading to unauthorised control over critical systems. This is recognised in CAF principle B4.C, which emphasises that “systems and devices supporting the operation of the essential function(s) are only administered or maintained by authorised privileged users from highly trusted devices, such as Privileged Access Workstations”.”
Spoofed numbers blocked in crackdown on scammers - Home Office and The Rt Hon Lord Hanson of Flint announce - “Britain’s biggest mobile networks have committed to upgrade their network within the next year to eliminate the ability for foreign call centres to spoof UK numbers, making it clear that calls are originating from abroad – exposing scammers lies.”
Authorities from the UK, US, Canada, Australia and NZ to enhance cooperation on telecoms security - OFCOM announce - “Promotion of best practices in network defence. This can be through cooperation and signposting to international standards, such as those related to Privileged Access Workstations (PAWs), which are dedicated computing arrangements set up for work that requires high levels of security, where appropriate. It will also include more collaboration on supply chain security, including subsea cable infrastructure and radio frequency devices where appropriate.”
The Strategic Framework for a Cyber Resilient Scotland 2025 - 2030 - Scottish Government publishes - “By 2030, Scotland will be a hard target for cyber criminals to attack. Scotland will be well defended against cyber threats and able to respond and recover quickly when incidents occur.”
Industrial Resilience: Assessing the foundations of UK industry - National Preparedness Commission publishes - “The combination of elevated geopolitical tensions, threats from national and non-state actors through terrorism, cyberattack and disinformation, and natural hazards like climate change and pandemic present serious challenges to the UK’s national resilience”
Keeping the UK safe from cyber attacks starts in the classroom - Dr Ismini Vasileiou of De Montfort University outlines - “A secure and connected digital future depends on people who are prepared – and compliant – to defend it. That preparation begins in the classroom.”
Cyber security priorities for boards of directors 2025-26 - The Australian Signals Directorate’s Australian Cyber Security Centre publishes - “we encourage a focus by boards on the following areas:
Understanding whether technology used or provided to your customers is secure by design and secure by default. These security principles and practices are critical for building modern defensible architectures.
Prioritising the defence of your organisation’s most critical assets. Your organisations should operate with a mindset of ‘assume compromise’ and consider which assets or ‘crown jewels’ need the most protection.”
Finland Joins Tallinn Mechanism to Bolster Ukraine’s Cyber Resilience - State Service of Special Communication and Information Protection of Ukraine announces - “Finland has become the thirteenth nation to join the Tallinn Mechanism, an international initiative dedicated to strengthening Ukraine’s cyber resilience and digital security. The country’s participation will enhance international cooperation in countering cyber threats and create new opportunities for sharing technological solutions and expertise. Finland’s accession to the Tallinn Mechanism also opens new avenues for partnership between Finnish technology companies and their Ukrainian counterparts.”
Technical Position Paper on Confidential Computing - ANSSI publish - “Confidential Computing is not secure enough to protect data integrity and confidentiality against a hostile administrator performing targeted, active attacks. Under such a threat model, users must avoid running on shared infrastructure operated by providers they cannot trust, and are rather encouraged to leverage Confidential Computing to increase their security posture on dedicated hardware instead.”
Defense Cyber Strategy 2025 - Netherlands publish - “The Ministry of Defence must keep its own systems secure as it is a daily target of a variety of attacks.
These circumstances require insight into and control over the threat, and constant effort to keep Defence digitally secure. Furthermore, the Ministry of Defence must take into account actors who are not afraid to digitally affect Defence employees in their home environment. Moreover, the Ministry of Defence is digitally connected to the broader society, with interdependencies that can create mutual cascading effects impacting the deployability of the armed forces.”
Offensive Cyber Operations and Combat Effectiveness After Ukraine - Lawfare opines - “If there is one cyber warfare lesson Western militaries should take from the three and a half years of cyber warfighting in Ukraine, it is that the effectiveness of individual offensive cyber operations hinges on the ability to maintain a steady operational tempo throughout the entire course of a war. In the long run, quantity matters more than quality in cyberspace.”
Dynamic Scenario Library - Cross Market Operational Resilience Group publish - “This Scenario explores a sophisticated double extortion ransomware attack, resulting in the exfiltration of internal [firm] data and the encryption of core IT Infrastructure, applications and end point devices, causing Important Business Services (IBS) to be disrupted”
Define your Minimum Viable Company now to survive the next shock - PwC thought leads - “To prepare for future disruption, organisations must adopt the concept of the Minimum Viable Company (MVC). Defining your Minimum Viable Company means identifying the essential services, processes and functions that must remain operational to keep the organisation financially, operationally and strategically viable in a crisis.”
The Future of CISA - Project on Technology and National Security think tanks - “While the creation of the Cybersecurity and Infrastructure Security Agency (CISA) aimed to resolve the leadership issue, it has struggled to establish itself as the nation’s primary cyber defender. This challenge is heightened by the acceleration of Artificial Intelligence (AI), which provides attackers with vastly more powerful tools for intrusions aimed at causing physical-world effects (theft, extortion, destruction) across critical sectors.”
Investigation shows KT concealed malware infections, security failures leading to hacking breach - Yonhap News Agency reports - “The joint government-private investigation team, which is examining KT’s recent cyberattack linked to illegal micro base stations, said the company learned between March and July of 2024 that 43 of its servers had been infected with so-called BPFDoor malware and other malicious code.”
Reporting on/from China
Xi Jinping cracks joke about spying with phones given to South Korean president - The Guardian reports - “The Chinese president presented two Xiaomi smartphones fitted with Korean-made displays to Lee, who said: “Is the communication line secure?” .. Pointing at the phones, still in their boxes, Xi replied: “You should check if there is a backdoor” – a reference to pre-installed software that could allow third-party monitoring.
That Time When China’s Leader Joked About Espionage - The New York Times reports
Chinese hackers who entered Singapore on fraudulent work permits were found with data of foreign governments - Channel News Asia reports - “While the hackers attempted to avoid government sites, one of their laptops contained messages discussing vulnerable domains, including five Australian, Argentine and Vietnamese government domains, while another contained a confidential email between officers of Kazakhstan’s Ministry of Foreign Affairs and Ministry of Industry and Infrastructure Development.”
A Researcher Came Knocking, and Taught China a Lesson in How to Manage Vulnerabilities -- and Researchers - Natto Thoughts outlines - “The 2020 TCL backdoor incident seems to have had a profound impact on the Chinese government and on Chinese companies with a global presence. The incident arguably taught them how to handle vulnerabilities in their products exposed by overseas independent researchers. It also drove home to them the importance of harnessing and nurturing the skills of their own vulnerability researchers.”
Germany Mulls Paying Deutsche Telekom to Replace Huawei Gear - Bloomberg reports - “Germany is considering using public funds to pay Deutsche Telekom AG and other telecom operators to replace Huawei Technologies Co. equipment, people familiar with the matter said.” … “The costs to replace Huawei equipment in Germany would exceed €2 billion, one of the people said, and the government would use defense or infrastructure money to pay telecom operators under one scenario.”
China Debuts Ultrafast Oscilloscope in Drive to Break Tech Barriers - Caixin Global reports - “China’s semiconductor equipment industry marked a new milestone Wednesday with the debut of an ultra-high-speed oscilloscope that its developer says breaks foreign technological barriers and delivers five times the performance of existing domestic models.”
China solves ‘century-old problem’ with new analog chip that is 1,000 times faster than high-end Nvidia GPUs - Live Science reports - “researchers from Peking University said their device tackled two key bottlenecks: the energy and data constraints digital chips face in emerging fields like artificial intelligence (AI) and 6G, and the “century-old problem” of poor precision and impracticality that has limited analog computing.”
AI
Security Community Slams MIT-linked Report Claiming AI Powers 80% of Ransomware - Socket reports - “The paper’s authors include Michael Siegel and Sander Zeijlemaker from MIT Sloan, and Vidit Baxi and Sharavanan Raajah from Safe Security, a company that markets an AI-driven cyber risk quantification platform. The paper’s concluding section urges organizations to “embrace AI in cyber risk management” to enhance resilience.” … “The MIT paper isn’t an isolated case. Similar claims are appearing across the security industry, often tied to surveys or marketing campaigns rather than incident data.”
Practical LLM Security Advice from the NVIDIA AI Red Team - NVIDIA shares - “Our top three most significant findings are execution of LLM-generated code leading to remote code execution, insecure permissions on RAG data stores enabling data leakage and/or indirect prompt injection, and active content rendering of LLM outputs leading to data exfiltration.”
Language Models are Injective and Hence Invertible - Sapienza University of Rome, EPFL and University of Athens publish - “we operationalize injectivity: we introduce SIPIT, the first algorithm that provably and efficiently reconstructs the exact input text from hidden activations, establishing linear-time guarantees and demonstrating exact invertibility in practice”
Scaling Security Testing by Addressing the Reachability Gap - Max Planck Institute for Security and Privacy publish - “This approach results in increased code coverage and leads to the discovery of a previously unknown vulnerability in a widely used open source project”
Identity Management for Agentic AI - OpenID publish - “This whitepaper is for stakeholders at the intersection of AI agents and access management. It outlines the resources already available for securing today’s agents and presents a strategic agenda to address the foundational authentication, authorization, and identity problems pivotal for tomorrow’s widespread autonomous systems.”
What GreyNoise Learned from Deploying MCP Honeypots - GreyNoise research - “GreyNoise’s MCP honeypot experiment found no evidence of targeted attacks on AI middleware. MCPs are being noticed, but not pursued — yet. “
Advances in Threat Actor Usage of AI Tools - Google outlines - “details how government-backed threat actors and cyber criminals are integrating and experimenting with AI across the industry throughout the entire attack lifecycle. Our findings are based on the broader threat landscape.”
SesameOp: Novel backdoor uses OpenAI Assistants API for command and control - Microsoft identifies - “[we] uncovered a new backdoor that is notable for its novel use of the OpenAI Assistants Application Programming Interface (API) as a mechanism for command-and-control (C2) communications. Instead of relying on more traditional methods, the threat actor behind this backdoor abuses OpenAI as a C2 channel as a way to stealthily communicate and orchestrate malicious activities within the compromised environment. To do this, a component of the backdoor uses the OpenAI Assistants API as a storage or relay mechanism to fetch commands, which the malware then runs.”
Magentic Marketplace: an open-source simulation environment for studying agentic markets - Microsoft researches - “Results revealed significant variation in manipulation resistance across models. Sonnet-4 was resistant to all attacks, and none of the manipulative strategies affected any of the customers’ choices. Gemini-2.5-Flash was generally resistant, except for strong prompt injections, where mean payments to unmanipulated agents were affected as a result. GPT-4o, GPTOSS-20b and Qwen3-4b were very vulnerable to prompt injection: all payments were redirected to the manipulative agent under these conditions.”
Artificial Intelligence (AI) – Judicial Guidance (October 2025) - England and Wales Courts and Tribunals Judiciary publishes - “The refreshed guidance adds to the glossary of common terms and expands on the risks of bias in training data and AI hallucinations which generate incorrect or misleading information. It provides further advice on confidentiality, reminding judicial office holders not to enter private information into public AI tools, and signposts where to report any inadvertent disclosures as data incidents.”
Cyber proliferation
Italian political consultant says he was targeted with Paragon spyware - Tech Crunch reports - “Francesco Nicodemo, a consultant who works with left-wing politicians in Italy, has gone public as the latest person targeted with Paragon spyware in the country.”
Brussels Admits: Substantial EU Funds Have Gone to Spyware Manufacturers - Heise reports - “The EU Commission has announced that it will “immediately” stop funding individuals or organizations involved in “serious professional misconduct.” This follows an investigation by Follow the Money (FtM) which revealed that EU funds amounting to millions of euros have been directly channeled to commercial spyware firms in recent years.”
Targeting the EU - Netzpolitik reports - “The quality of the data varies. Data brokers sometimes present their data sets as larger than they really are, for example by adding fake advertising IDs to real location data. It is therefore possible that the data records available to us with 2.6 million different advertising IDs are actually based on fewer than 2.6 million different devices. Nevertheless, our investigation shows how individuals and institutions can be targeted even with inaccurate data.”
Bounty Hunting
Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says - Chicago Sun Times reports - “Employees of DigitalMint, a company that specializes in negotiating ransoms in cyber attacks, were part of a small crew the feds say conducted five hacks that scored more than $1 million.”
SMS Blaster and IMSI-catcher News from Lebanon, Cambodia, Switzerland and the Philippines - CommRisk reports - “Swiss police announced the arrest of a suspect driving an SMS blaster around Muttenz, near Basel, on October 14. The suspect is a 52 year old Chinese national. The device sent smishing messages that impersonated well-known organizations such as the Post Office and the Migros supermarket chain.”
LabHost sentencing - Rechtspraak summarises - “Probationary sentence: 300 days, of which 226 days are conditional, general sentence, probationary period: 3 years. Probationary sentence: 180 hours.”
Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody - Krebs on Security reports - “A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of millions of dollars from U.S. businesses was arrested in Italy and is now in custody in the United States,”
Treasury Sanctions DPRK Bankers and Institutions Involved in Laundering Cybercrime Proceeds and IT Worker Funds - US Department of Treasury announces - “the Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned eight individuals and two entities for their role in laundering funds derived from a variety of illicit Democratic People’s Republic of Korea (DPRK) schemes, including cybercrime and information technology (IT) worker fraud.”
Market Incentives
Meta is earning a fortune on a deluge of fraudulent ads, documents show - Reuters reports - “Meta projected 10% of its 2024 revenue would come from ads for scams and banned goods, documents seen by Reuters show. And the social media giant internally estimates that its platforms show users 15 billion scam ads a day.”
M&S profits almost wiped out after cyber hack hit sales - BBC reports - “The hack was “an extraordinary moment in time,” it said, as it revealed statutory profit before tax - a figure that reflects all costs for a period - slumped 99% from £391.9m to £3.4m for the first half of the year, compared with the year prior.” … “M&S said in the second half of the year it forecast profits would recover to the levels seen in 2024, “as the residual effects of the incident continue to reduce in the coming months.”
Reflections this week are around the Microsoft and Google reporting on AI usage and the importance of context and perspective.
Yes, AI is being adopted by various parties with varying impact. The use of AI is a productivity enhancer for both offense and defence and thus this is expected.
Some of the integrations with AI systems for offensive/malicious use cases are extremely noisy however e.g. via API calls to cloud services from rogue processes etc. or calls to GPUs to run local inference. These behaviours are anomalous and provide low cost detection opportunities.
In summary we should not be surprised but we should have perspective and be prepared.
What changes the game may be AlphaGo move 37 surprises (i.e. achieving cyber outcomes in unexpected ways - but even then speaking to some Go players they were not overly wowed).
But until then we should not be surprised that technology is being used as a productivity enhancer and in the cyber security context can be used surface and exploit latent vulnerability and attack surface or to work at machine speed instead of human speed. I say this because of work at a former employer over half a decade showed there was viability for machine learning in offensive cyber even before the generative AI explosion.
What it does underline is the risk of a forced correction and the need for cyber security resilience which addresses the fundamentals - be it through architectures (PAWs), provable technical controls (memory safety / phishing resistant MFA) as well as scalable detection and mitigations (code fixing through AI) and other means.
It is clear that AI will drive a generational shift in productivity (as computers, mobile phones, the Internet, cloud etc. have before) - the trick is not letting it distract us from the fundamentals that will ensure cyber security outcomes we seek however...
Not getting this via email? Subscribe:
Think someone else would benefit? Share:
All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.
Have a lovely Saturday…
Ollie
Cyber threat intelligence
Who is doing what to whom and how allegedly.
Reporting on Russia
Curly COMrades: Evasion and Persistence via Hidden Hyper-V Virtual Machines
Victor Vrabie details this alleged Russian operation and trade craft - this will be useful to detection engineering and hunt teams to ensure they have coverage against the capability.
This investigation, conducted with support from the Georgian CERT functioning under the Operative-Technical Agency of Georgia, uncovered new tools and techniques used by the Curly COMrades threat actor. They established covert, long-term access to victim networks by abusing virtualization features (Hyper-V) on compromised Windows 10 machines to create a hidden remote operating environment.
Russian Cybercrime & State Militarization: Marching Together in the Digital Age
Anastasia Sentsova provides some strategic insight into the alleged alignment between criminal and state cyber objectives and activity.
This research examines that convergence. By analyzing Russia’s militarization strategy alongside official volunteer programs and Russian cybercrime, we aim to map how “digital soldiers” are recruited and assess the likely effects on public opinion and escalation risk in the information environment. It’s a journey through the state’s digital fingerprints — its language, slogans, and familiar symbols — where its presence quietly reveals itself. Because even when cyber operations try to appear “independent,” the state’s voice inevitably slips through.
In our attempt to answer whether Russian cybercriminals are marching in step with the state, we’ll lay out the evidence. Think of it as building a conspiracy board: we’ll keep the tone analytical, with a light sprinkle of sarcasm at the author’s discretion to keep readers engaged. Consider it an occupational hazard: when the state speaks half in bureaucracy and half in slogans, sometimes the only accurate translation is irony.
..
First things first. Do we think the Russian state is involved in hacktivist activity? Yes**.** Based on the evidence we’ve laid out, our level of confidence is high.
https://analyst1.com/wp-content/uploads/2025/11/Russian-Cybercrime-State-Militarization-1.pdf
Reporting on China
China-linked Actors Maintain Focus on Organizations Influencing U.S. Policy
Symantec and Carbon Black detail an alleged Chinese operation which is notable due to victimology.
The TTPs have previously been linked to multiple Chinese actors such as Kelp, Space Pirates, and APT41.
APT41 is one of the longest-running Chinese espionage groups.
Attackers were aiming to establish a persistent and stealthy presence on the network. They gained access for several weeks in April 2025.
The threat actors appeared determined to establish persistence and maintain long-term access to the network when they gained access to it for several weeks in April 2025. Evidence of various techniques, including the use of a legitimate vetysafe.exe component to sideload a malicious DLL (sbamres.dll.), point to the attackers being based in China. A copy of this malicious DLL was previously used in attacks linked to the China-based threat actors known as Space Pirates. A variant of this component, with a different filename, was also used by the Chinese APT group Kelp (aka Salt Typhoon) in a separate incident. Additionally, the technique was also used by Earth Longzhi, which is believed to be a subgroup of the long-standing Chinese threat group APT41.
https://www.security.com/threat-intelligence/china-apt-us-policy
VShell post-exploitation tool
NVISO identify the scale of this alleged Chinese leveraged tool in offensive cyber operations.
VShell is a cyber intrusion tool that acts as a backdoor in networks worldwide, primarily used by Chinese-speaking threat actors for long-term espionage activities. In a months-long investigation, more than 1,500 active VShell servers were uncovered, each single one capable of giving attackers remote control over compromised victim networks. While multiple threat groups use VShell, Chinese-speaking actors are its most prolific operators, targeting critical sectors from government and healthcare to military and research.
..
Several intrusions involving VShell malware have been publicly attributed to UNC5174, a suspected initial access broker linked to China’s Ministry of State Security1 . This actor has been repeatedly observed exploiting public-facing systems. However, the widespread and public availability of VShell alongside our observation of usage by multiple state-aligned and independent actors demonstrate that VShell’s deployment cannot be exclusively attributed to UNC5174. Through this research, NVISO assesses that VShell should be considered as another tool within the broader attacker ecosystem. While tooling like VShell develops and changes over the years, espionage driven activity remains firmly seated as an important threat to both public and private organizations
https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool
Reporting on North Korea
Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Varian
Alexandru-Cristian Bardaș details an evolution in alleged North Korean capability which is suspected of being delivered via phishing..
In recent weeks, our Threat Labs researchers have uncovered two new toolsets that show just how adaptive the DPRK’s operations have become. Kimsuky, known for its espionage-style campaigns, deployed a new backdoor we’ve named HttpTroy, while Lazarus introduced an upgraded version of its BLINDINGCAN remote access tool.
Both attacks reveal the same underlying pattern: stealthy code and layered obfuscation.
..
While the exact delivery mechanism remains unknown, telemetry indicates that the samples was obtained via an internet download, packaged within a ZIP archive named “250908_A_HK이노션_SecuwaySSL VPN Manager U100S 100user_견적서”. Given the nature of the filename, it is highly probable that the archive was distributed through a phishing email.
https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis
Dissecting the Infection Chain: Technical Analysis of the Kimsuky JavaScript Dropper
Reporting on Iran
Crossed wires: a case study of Iranian espionage and attribution
Saher Naumaan details this alleged Iranian operation which shows they continue to try and build repour through social engineering prior to the end game..
Between June and August 2025, Proofpoint began tracking a previously unidentified threat actor dubbed UNK_SmudgedSerpent targeting academics and foreign policy experts.
UNK_SmudgedSerpent leveraged domestic political lures, including societal change in Iran and investigation into the militarization of the IRGC.
UNK_SmudgedSerpent used benign conversation starters, health-themed infrastructure, OnlyOffice file hosting spoofs, and Remote Management & Monitoring (RMM) tools.
Throughout the investigation, UNK_SmudgedSerpent demonstrated tactics resembling several Iranian actors: TA455 (C5 Agent, Smoke Sandstorm), TA453 (Charming Kitten, Mint Sandstorm), and TA450 (MuddyWater, Mango Sandstorm).
Overlapping TTPs prevent high confidence attribution, but several hypotheses could explain the nature of the relationship between UNK_SmudgedSerpent and other Iranian groups.
Reporting on Other Actors
Certified OysterLoader: Tracking Rhysida ransomware gang activity via code-signing certificates
Aaron Walton highlights once again that malvertising is being leveraged by criminal actors for initial access.
There’s an ongoing malicious ad campaign delivering a malware called OysterLoader, previously known as Broomstick and CleanUpLoader
The malware is an initial access tool (IAT) that gets onto devices to run a backdoor to gain access to the device and network
The malware is being leveraged by the Rhysdia ransomware gang
How your devices could be implanted and what to do about it
The Australian Signals Directorate’s Australian Cyber Security Centre provides detail of any on going operation and how to surface.
Cyber actors are installing an implant dubbed ‘BADCANDY’ on Cisco IOS XE devices that are vulnerable to CVE-2023-20198. Variations of the BADCANDY implant have been observed since October 2023, with renewed activity notable throughout 2024 and 2025.
BADCANDY is a low equity Lua-based web shell, and cyber actors have typically applied a non-persistent patch post-compromise to mask the device’s vulnerability status in relation to CVE-2023-20198. In these instances, the presence of the BADCANDY implant indicates compromise of the Cisco IOS XE device, via CVE-2023-20198.
https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy
Remote access, real cargo: cybercriminals targeting trucking and logistics
Ole Villadsen and Selena Larson provide insight Hollywood-esq cyber enabled crime capers which are allegedly occurring.
Cybercriminals are compromising trucking and freight companies in elaborate attack chains to steal cargo freight.
Cargo theft is a multi-million-dollar criminal enterprise, and digital transformation has led to an increase in cyber-enabled theft.
Threat actors compromise these companies and use their access to bid on cargo shipments, to then steal and sell them.
The threat actors typically deliver remote monitoring and management (RMM) tools, aligning with the broader trend of cybercriminals adopting these as a first-stage payload across the threat landscape.
APT-C-60 Attack Update
JP CERT detail the operations of this alleged state actor - noteworthy for the direct sending of VHDX files for which I can’t think of a legitimate business use case for allowing via e-mail - the result of which is it should be trivial to block.
The attack confirmed by JPCERT/CC was similar to the attack that occurred around August 2024, in that it involved targeted emails posing as job seekers and addressed to organizations’ recruiting staff. Last year’s attack used a method to have victims download a VHDX file from Google Drive, but in this attack, a malicious VHDX file was sent directly as an attachment. When the recipient of the email clicked on the LNK file contained within the VHDX file, a malicious script was executed via the legitimate Git file
https://blogs.jpcert.or.jp/ja/2025/10/APT-C-60_update.html
Malicious Infrastructure Finds Stability with aurologic GmbH
Recorded Future shine a light which will hopefully drive a displacement activity.
Although it is not possible to confirm why so many of aurologic’s known downstream customers form such a large concentration of high-risk hosting networks, the fact that the company serves as a common link between multiple suspected TAEs is significant.
https://assets.recordedfuture.com/insikt-report-pdfs/2025/cta-2025-1106.pdf
Analysis of NGate malware campaign
CERT Poland detail and analyse this campaign which will require a response from the financial services industry..
NGate is a Android NFC relay kit used to cash out ATMs with victims’ own cards. It’s delivered via phishing plus a “bank support” call that pressures the user to install an app, tap the card to the phone, and enter the PIN. The app runs in reader mode to capture EMV APDUs and the PIN, then exfiltrates them via a simple framed TCP protocol to a hard-coded C2; the same family also ships a payment-category HCE service, enabling an emitter role at the ATM. Configuration is stored as an XOR-encrypted asset with a key derived from the APK signing cert (SHA-256), which in this sample resolves to a live, plaintext C2. Bottom line: once the card is tapped and the PIN is entered, the attacker can relay the session and withdraw cash.
https://cert.pl/en/posts/2025/11/analiza-ngate/
Clop ransomware: dissecting network
Ravenfile highlights the value of cross incident infrastructure analysis..
Out of 96 IPs, it is found that 41 Subnet IPs have been re-used by Clop (Cl0p) Ransomware Group, which was present during MOVit Exploitation
https://theravenfile.com/2025/11/04/clop-ransomware-dissecting-network/
Discovery
How we find and understand the latent compromises within our environments.
You are worker #41: Lophiid Honeypot Caught an Automated AI Attack Swarm
Niels Heinen evidences the value of cyber deception in surfacing malicious activity which may otherwise go unnoticed..
Lophiid recently gained the ability to emulate the Ollama and llama.cpp APIs. In my personal honeypot deployments, I’m now emulating the full API of both tools.
Here’s how it works:
The emulation is built with Lophiid content scripts. These scripts essentially expose Lophiid backend logic to Javascript, allowing for flexible and dynamic handling of incoming requests.
It supports both streaming and non-streaming requests.
To appear legitimate, my honeypots will pass an attacker’s first 10 generation requests through to a real LLM. This is controlled by a session-based counter that resets after a configurable period.
Tracking Lateral Movement — Named Pipes, Scheduler, Services, Registry, and DCOM (Event IDs)
Akash Patel (Dean) walks through how to corelate Windows event IDs to detect lateral movement. Another wonderful example detection engineering possibilities.
Tracking Lateral Movement: PowerShell Remoting, WMIC, Explicit Credentials, NTLM Relay Attacks, Credential Theft and Reuse (Event IDs)
Akash Patel (Dean) also walks through on how do something similar for these Windows lateral movement techniques.
Graph API Overwhelm
alphaf0x provides a practical walk through on how to deal with cloud scale detection and discovery…
In this series I will be documenting my research on Microsoft Graph API OpenAPI schema, how to parse its 10,000+ available endpoints and how to determine opportunities for noise reduction as well as detection engineering. If you also felt overwhelmed by this log source, I hope you will find it useful.
In this introductory post, I will briefly explain what Graph API is and how to ingest it. I will also touch on common challenges that security teams might face when looking to ingest this source.
https://www.alphaf0x.com/posts/graph-api/
Hunting for EDR-Freeze
Axelarator provides a useful guide for those going hunting during rabbit/duck season. It also shows the value of actually doing detection engineering of discrete capabilities.
Although there were only a handful of logs to look at, there were enough patterns to help hunt for this activity without relying on hard-coded file names or paths.
https://blog.axelarator.net/hunting-for-edr-freeze/
Defence
How we proactively defend our environments.
Identity Management for Agentic AI
OpenID publish an excellent overview and outline of the future challenges..
Critical future challenges exist:
Agent identity fragmentation should be avoided. Vendors could develop proprietary agentic identity systems, which would reduce developer velocity by forcing repeated one-off integrations. It would also compromise security by creating multiple security models, each with different risks and vulnerabilities. • User impersonation by agents should be replaced by delegated authority. Currently, agents often act indistinguishably from users, creating accountability gaps and security risks. True delegation requires explicit “on-behalf-of” flows where agents prove their delegated scope while remaining identifiable as distinct from the user they represent.
Scalability problems exist in human oversight & user consent. Users will face thousands of authorization requests as agents proliferate, creating security risks from reflexive approval. Preemptive authorization and scoping of flexible agents are at odds with least privilege.
Recursive delegation creates risks. Agents spawning sub-agents or communicating tasks to other agents create complex authorization chains without clear scope attenuation mechanisms.
…
https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf
A Defender’s Guide to Privileged Account Monitoring
Bhavesh Dhake, Will Silverstone, Matthew Hitchcock and Aaron Fletcher spell out an approach for privileged account monitoring..
A concise defense-in-depth approach is required, where you should assume breach and implement layer controls so failure of one control is caught by the next layer of defense:
Verify every request (Zero Trust).
Require multifactor authentication (MFA) for all administrative paths.
Enforce privileged access management (PAM) with credential rotation and session recording.
Administer only from privileged access workstations (PAWs) on a segmented management network.
Tune security information and event management (SIEM) for privileged anomalies to reduce dwell time and radius.
https://cloud.google.com/blog/topics/threat-intelligence/privileged-account-monitoring
Threat activity targeting Azure Blob Storage
Microsoft provide insight on what threats are manifesting and how to detect and protect based on their observations..
we outline some of the unique threats associated with the data storage layer, including relevant stages of the attack chain for Blob Storage to connect these risks to actionable Azure Security controls and applicable security recommendations. We also provide threat detections to help contain and prevent Blob Storage threat activity with Microsoft Defender for Cloud’s Defender for Storage plan
A Comprehensive Survey of Threat Intelligence Research: A Measurement-Based Study
Keisuke Furumoto, Tomohiro Morikawa, Antti Kolehmainen, Bilhanan Silverajan, Takeshi Takahashi and Daisuke Inoue bring some academic rigour with this release.
In this paper, in addition to describing various threat intelligence sources, we analyze research trends based on taxonomies for research purpose, research approach, and research datasets. We provide an extensive review of over 200 studies related to cyber threat intelligence published between 2001 and 2025 and examine the trends of representative research.
The survey shows that there are issues related to datasets, such as the evaluation results depending on which vendors are included in the dataset. Therefore, we also conduct a measurement study to provide a detailed description of collected datasets. To the best of our knowledge, this is the irst study to conduct a measurement study on a dataset to uncover insights for constructing a well-balanced dataset. We also identify open issues and challenges that need to be addressed in the future.
https://dl.acm.org/doi/abs/10.1145/3772280
Incident Writeups & Disclosures
How they got in and what they did.
How an Attacker Drained $128M from Balancer Through Rounding Error Exploitation
Dikla Barda, Roaman Zaikin & Oded Vanunu show why you want assurance (such as via formal verification) over critical code paths..
The attack leveraged a rounding error vulnerability in the _upscaleArray function that, when combined with carefully crafted batchSwap operations, allowed the attacker to artificially suppress BPT (Balancer Pool Token) prices and extract value through repeated arbitrage cycles. The exploitation occurred primarily during attacker smart contract deployment, with the constructor executing 65+ micro-swaps that compounded precision loss to devastating effect.
Open VSX security update, October 2025
Eclipse Foundation provide an update on their response to this incident within their eco-system.
Earlier this month, our team was alerted to a report from Wiz identifying several extension publishing tokens inadvertently exposed by developers within public repositories. Some of these tokens were associated with Open VSX accounts.
Upon investigation, we confirmed that a small number of tokens had been leaked and could potentially be abused to publish or modify extensions. These exposures were caused by developer mistakes, not a compromise of the Open VSX infrastructure. All affected tokens were revoked immediately once identified.
To improve detection going forward, we introduced a token prefix format in collaboration with MSRC to enable easier and more accurate scanning for exposed tokens across public repositories.
https://blogs.eclipse.org/post/mika%C3%ABl-barbero/open-vsx-security-update-october-2025
Cloud Backup Security Incident Investigation Complete and Strengthened Cyber Resilience
SonicWall gives some specific communication around this event..
In early September, SonicWall detected suspicious activity related to the downloading of backup firewall configuration files stored in a specific cloud environment. Our incident response team immediately activated our established response protocols, engaged Mandiant, a leading cybersecurity response firm, and notified our global partners and customers directly about the incident and remediation steps to protect their customers.
..
The Mandiant investigation is now complete. Their findings confirm that the malicious activity – carried out by a state-sponsored threat actor - was isolated to the unauthorized access of cloud backup files from a specific cloud environment using an API call. The incident is unrelated to ongoing global Akira ransomware attacks on firewalls and other edge devices.
Vulnerability
Our attack surface.
RDSEED Failure on AMD “Zen 5” Processors
AMD PRNG here failed badly..
AMD was notified of a bug in “Zen 5” processors that may cause the RDSEED instruction to return 0 at a rate inconsistent with randomness while incorrectly signaling success (CF=1), indicating a potential misclassification of failure as success. This issue was initially reported publicly via the Linux kernel mailing list and was not submitted through AMD’s Coordinated Vulnerability Disclosure (CVD) process.
AMD has determined that the 16-bit and 32-bit forms of the RDSEED instruction on “Zen 5” processors are affected. The 64-bit form of RDSEED is not affected. AMD plans to release mitigations for this vulnerability. Please see the details below.
Until the microcode patch is deployed, the following software workaround options could be used:
Use the 64-bit form of RDSEED
Mask the CPUID Fn0000_0007_EBX[18] RDSEED from software discovery. For example, by adding clearcpuid=rdseed to the boot command line; or with the -rdseed option on the qemu command line for a VM
Software can treat RDSEED returning 0 equivalent to when CF=0. Retry RDSEED later until a non-zero value is returned with CF=1
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html
Defeating KASLR by Doing Nothing at All
Seth Jenkins shows there is still challenges in ASLR implementations - a subject close to my heart. It is almost like in some instances the claims of randomness were missing test cases to measure..
Even on devices where the kernel location is randomized in the physical address space, linear mapping non-randomization still softens the kernel considerably to attempts at exploitation. This is particularly because techniques that involve spraying memory (either kernel structures or even userland mmap’s!) can land at predictable physical addresses - and those physical addresses are easily referenceable in kernel virtual address space through the linear map. That potentially gives an attacker a methodology for placing kernel data structures or even simply attacker-controlled userland memory at a known kernel virtual address
https://googleprojectzero.blogspot.com/2025/11/defeating-kaslr-by-doing-nothing-at-all.html
Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
Gábor Selján shows that fuzzing still has the ability to surface some consequential vulnerabilities - including remote memory revelation!
we detail the findings of our fuzzing campaign, which targeted Windows
GDIusing theEMFformat and led to the discovery of these security vulnerabilities.
CVE-2025-53766, classified as critical severity and may allow remote attackers to execute arbitrary code on affected systems;
CVE-2025-47984, also rated important and can result in the unauthorized disclosure of sensitive information over the network.
Is Your Bluetooth Chip Leaking Secrets via RF Signals?
From March but worth a call out for the quality of the work by Yanning Ji, Elena Dubrova and Ruize Wang
In this paper, we present a side-channel attack on the hardware AES accelerator of a Bluetooth chip used in millions of devices worldwide, ranging from wearables and smart home products to industrial IoT. The attack leverages information about AES computations unintentionally transmitted by the chip together with RF signals to recover the encryption key. Unlike traditional side-channel attacks that rely on power or near-field electromagnetic emissions as sources of information, RF-based attacks leave no evidence of tampering, as they do not require package removal, chip decapsulation, or additional soldered components. However, side-channel emissions extracted from RF signals are considerably weaker and noisier, necessitating more traces for key recovery. The presented profiled machine learning-assisted attack can recover the full encryption key from 90,000 traces captured at a one-meter distance from the target device, with each trace being an average of 10,000 samples per encryption. This is a twofold improvement over the correlation analysis-based attack on the same AES accelerator.
The conference IEEE International Symposium on Multiple-Valued Logic is also worth noting due to some other interesting papers
Analog CMOS Spiking Neural Network for Time-Series Signal Recognition
Hybrid Fingerprinting for Effective Detection of Cloned Neural Networks
Decompressing Dilithium’s Public Key with Fewer Signatures Using Side Channel Analysis
Solving AES-SAT Using Side-Channel Hints: A Practical Assessment
https://eprint.iacr.org/2025/559
Four Bytes, One Lie: A SMAP-Free Confidence Trick on Kernel Pointers
Hyeonjin Choi shows that the value of being able to analyse even the most subtle behavioural variance in order to achieve exploitability..
More then a conventional vulnerability report; it is case study showing how a tiny, seemingly insignificant piece of data can undermine an OS’s trust assumptions and enable privilege escalation.
..
The vulnerability is appears to be an Out-of-Bounds Write, but it is subject to specific constraints. While the attacker does not have control over the index, the vulnerability permits writing 4 arbitrary bytes at a fixed offset (+0xC) into the next heap chunk within the same Low Fragmentation Heap (LFH) bucket.
..
So why does this Out-of-Bounds Write occur? In the next section, we will trace the root cause and understand how a type mismatch leads to a write primitive that crosses pool boundaries within a single LFH bucket.
https://www.oobs.io/posts/four-bytes-one-lie/
Offense
Attack capability, techniques and trade-craft.
Bypassing WiFi Client Isolation
Ben Knight brings a reality check..
To bypass client isolation the objective is to establish direct communication between us (the attacker) and a victim client on the network by manually transmitting frames and sniffing the victims response packets. This circumvents the access point and any client isolation protections it may be implementing.
..
Client isolation on Open, WPA-Personal and WPA2-Personal networks isn’t an effective security control to defend WiFi clients.
https://pulsesecurity.co.nz/articles/bypassing-wifi-client-isolation
Evading Elastic Security: Linux Rootkit Detection Bypass
MatheuZ does the next chess move between offense and defensive research and capability on Linux..
This article demonstrates how to systematically evade these defenses. We present a comprehensive case study of developing a Linux rootkit that successfully bypasses Elastic Security’s detection mechanisms through obfuscation, fragmentation, and staged execution techniques. All content is strictly for educational purposes only.
https://matheuzsecurity.github.io/hacking/bypassing-elastic/
SilentButDeadly
Loosehose releases this capability which detection engineers will want coverage of but which once again show the value of true signal flowing through observability / telemetry systems.
SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using Windows Filtering Platform (WFP). This version focuses solely on network isolation without process termination.
https://github.com/loosehose/SilentButDeadly
EDR-Redir V2: Blind EDR With Fake Program Files
Zero Salarium is back with another technique which should be relatively easy to detect..
At this point, Windows Defender will always see the folder C:\TMP\TEMPDIR as the parent folder of its operating folder.
https://www.zerosalarium.com/2025/11/EDR-Redir-V2-Blind-EDR-With-Fake-Program-Files.html
BOF Spawn
NtDallas provides a turn-key BOF which detection engineering teams and EDR vendors will want to ensure coverage of.
BOF Spawn is a Beacon Object File for Cobalt Strike that implements process spawning and shellcode injection Draugr stack spoofing with indirect syscalls. This tool combines multiple evasion techniques to bypass userland hooks, call stack analysis, and memory scanners
https://github.com/NtDallas/BOF_Spawn/
Exploitation
What is being exploited..
New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Unit42 detail an in the wild exploit which they alleged is from a commercial supplier.
LANDFALL was embedded in malicious image files (DNG file format) that appear to have been sent via WhatsApp. This method closely resembles an exploit chain involving Apple and WhatsApp that drew attention in August 2025. It also resembles an exploit chain that likely occurred using a similar zero-day vulnerability (CVE-2025-21043) disclosed in September. Our research did not identify any unknown vulnerabilities in WhatsApp.
https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/
Tooling and Techniques
Low level tooling and techniques for attack and defence researchers…
CHERIoT 1.0 Specification Released
CHERI Alliance publishes..
CHERIoT 1.0 provides a stable, hardware-enforced platform for building memory safe, compartmentalised systems in the microcontroller class. The specification defines the instruction set architecture, language extensions, and the complete compilation and relocation model, enabling developers to build software that is safeguarded against buffer overflows and use after free errors, even in hand written assembly.
https://cheri-alliance.org/cheriot-1-0-specification-released/
How CHERIoT uses Sealing
David Chisnall shows the value of being able to address and add capability at an architectural level.
Sealing is one of the oldest parts of CHERI and one of the most powerful. When I joined the project in 2012 it was integral to the early prototype call-gate mechanism. You can find this version in our 2014 tech report. It included
CSealCodeandCSealDatainstructions that assembled a pair of capabilities that could be used with theCCallinstruction to perform a cross-compartment call.
https://cheriot.org/rtos/sealing/2025/11/06/sealing.html
Attacking macOS XPC Helpers: Protocol Reverse Engineering
Tony Gorez walks through the end to end of how to approach surfacing application specific attack surfaces via this IPC mechanism to then surfacing viable research targets.
https://tonygo.tech/blog/2025/how-to-attack-macos-application-xpc-helpers
Beating XLoader at Speed: Generative AI as a Force Multiplier for Reverse Engineering
Alexey Bukhteyev evidences there is value in applying AI to reverse engineering in the real world.
[We] demonstrated a new way to use ChatGPT for malware analysis directly from the web interface. By exporting IDA data and analyzing it in the ChatGPT cloud, we showed that deep static reverse engineering with AI is possible without relying on Model Context Protocol (MCP) or a live disassembler session. This approach not only removes the dependency on local heavy tooling, but also makes the results reproducible, easier to share, and more collaborative across research teams.
https://research.checkpoint.com/2025/generative-ai-for-reverse-engineering/
Footnotes
Some other small (and not so small) bits and bobs which might be of interest.
Annual, quarterly and monthly reports
Nothing overly of note this week
Select-Then-Compute: Encrypted Label Selection and Analytics over Distributed Datasets using FHE
BSI TR -03185-2 Secure Software Lifecycle for Open Source Software
Relating Natural Language Aptitude to Individual Differences in Learning Programming Languages
Preparing for cyberattacks is good; preventing them is better
Artificial intelligence
Books
Nothing overly of note this week
Events
IEEE International Symposium on Multiple-Valued Logic, was in June - various relevant security papers
Hybrid Fingerprinting for Effective Detection of Cloned Neural Networks
Decompressing Dilithium’s Public Key with Fewer Signatures Using Side Channel Analysis
Solving AES-SAT Using Side-Channel Hints: A Practical Assessment
Is Your Bluetooth Chip Leaking Secrets via RF Signals?
Finally finally the NCSC’s podcast series.
Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them.
This newsletter is subject to the NCSC website terms and conditions which can be found at https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions and you can find out more about how will treat your personal information in our privacy notice at https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.



