Skip to content
Artwork for Decrypted: The UK Cyber Briefing

Decrypted: The UK Cyber Briefing

Davinder Singh

The UK cyber security story that matters today, in about four minutes. A short daily briefing on the breaches, vulnerabilities and policy that affect UK organisations, what actually went wrong, and the design decision that would have prevented it.

Play
  • 31 episodes
  • daily
  • Avg 4 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S2026 · E38
    Yesterday · 5 min

    Citrix has patched NetScaler, but a patch will not remove the web shell

    Citrix has patched its two NetScaler zero-days, the NCSC has issued an alert, and Mandiant has described the web shells left behind. Patching is not enough, so the advice is to hunt and rebuild. Plus the ICO becomes the Information Commission, and an OpenSSL DTLS leak. Sources NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway BleepingComputer: Hackers exploit Citrix NetScaler zero-day to deploy web shells CyberScoop: Citrix patches actively exploited NetScaler zero-days after a weekend of silence The Hacker News: Attackers exploit NetScaler flaw for root access, deploy WHIPSHOT ICO: ICO to become Information Commission on 30 September 2026 The Hacker News: OpenSSL fixes high-severity DTLS flaw that can leak heap memory Read the written version

    • Transcript
  • S2026 · E37
    Yesterday · 4 min

    ShinyHunters: an arrest, and the front desk that still lets criminals in

    The FBI says a man arrested in the Netherlands is an alleged ShinyHunters leader. The group's method, borrowing genuine logins rather than breaking in, is the lesson for UK boards. Also: fake ChatGPTs spreading malware, a poisoned AI plugin, and a new Spectre variant. Sources BleepingComputer: FBI tells ShinyHunters members to turn themselves in after recent arrest Cyber Security News: FBI and Dutch Police Arrested Alleged ShinyHunters Hackers Group Leader BleepingComputer: Nottingham University data breach affects over 450,000 students Huntress: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix The Hacker News: Compromised MemTensor Packages Deliver sckit Credential Stealer The Hacker News: New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses Read the written version

    • Transcript
  • S2026 · E36
    Tuesday · 4 min

    An MCP flaw lets a rogue tool server steal an AI agent's login keys

    The official MCP Python SDK trusted a server to say which login service to use, letting a malicious server collect an agent's OAuth secrets. Fixed versions exist. Also: Kiteworks explains its shutdown, a Dutch ShinyHunters arrest, and 101 malicious npm packages. Sources GitHub Security Advisory: OAuth credential leakage in the MCP Python SDK Cycode: MCP Python SDK OAuth account takeover The Hacker News: Official MCP Python SDK flaw can let malicious servers steal OAuth credentials BleepingComputer: Kiteworks lifts shutdown warning after patching critical flaw BleepingComputer: Dutch police confirm arrest in ShinyHunters hacking investigation The Hacker News: 101 malicious npm packages abuse Baileys WhatsApp library Read the written version

    • Transcript
  • S2026 · E35
    Tuesday · 4 min

    Supabase's secure default skips the way most apps are built now

    UpGuard found over 16,000 exposed Supabase databases leaking personal data because the platform's security default doesn't apply to tables built by AI coding agents. Also: Citrix's NetScaler zero-days get a patch and a federal deadline, Bitget's $388m theft traces to a security vendor's own flaw, and TikTok drops its ICO appeal. Sources Everything Everywhere: Systemic Data Exposure in Supabase Apps Misconfigured Supabase apps expose data in over 16,000 databases Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway CISA orders feds to patch exploited Citrix flaws by Wednesday Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M TikTok withdraws two appeals in children's privacy action and accepts £12.7m fine Read the written version

    • Transcript
  • S2026 · E34
    Monday · 4 min

    An AI agent wiped Azure storage in seven minutes, using a password left on GitHub

    Microsoft says an AI-driven ransomware operator used two stolen service identities to delete Azure storage in about seven minutes. Also: Citrix NetScaler now has a patch and an NCSC alert, Dyfed-Powys Police checks staff data after an attack, and GitLab's email tokens act like passwords. Sources Microsoft Security Blog: Storm-3168, agentic-driven cloud attacks using compromised service principals Sysdig: JADEPUFFER, agentic ransomware for automated database extortion NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway BleepingComputer: CISA orders feds to patch exploited Citrix flaws by Wednesday The Register: Dyfed-Powys Police cops to cyberattack, staff data potentially nicked Aikido: Send GitLab an email, push to main Read the written version

    • Transcript
  • S2026 · E33
    Monday · 4 min

    ShinyHunters walks round the PeopleSoft firewall fix with one character

    Google's Mandiant says ShinyHunters is bypassing firewall rules protecting Oracle PeopleSoft by URL-encoding a single character. A UK university was hit in June. We cover the design lesson, a Salesforce agent flaw, a Microsoft token failure and the ICO's change on Wednesday. Sources Google Cloud (Mandiant): ShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft BleepingComputer: ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks SecurityWeek: University of Nottingham confirms breach after hackers leak data SecurityWeek: SalesBleed flaws in Salesforce Agentforce enabled zero-click data exfiltration Faav: How I could've accessed 17 trillion Microsoft records ICO: ICO governance changes confirmed for 30 September 2026 Read the written version

    • Transcript
  • S2026 · E32
    Sunday · 4 min

    Citrix's NetScaler has two zero-days and no patch yet

    Two unpatched Citrix NetScaler zero-days are being exploited after a leaked NCSC-NL pre-notification, with Citrix confirming nothing and a fix not expected until next week. Also: Salesforce's Agentforce agents were hijacked via poisoned web forms, Microsoft names the first agentic ransomware operation, and the ICO renames itself. Sources Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ 'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration Storm-3168: Agentic-driven cloud attacks using compromised service principals ICO to become Information Commission on 30 September 2026 Read the written version

    • Transcript
  • S2026 · E31
    Sunday · 4 min

    The Dutch build an exit from Microsoft, and Microsoft corrects its evidence to MPs

    The Netherlands is piloting DAWO, a government workplace built on NixOS, after US sanctions on the ICC raised the question of supplier lock-in. Microsoft has since corrected its evidence to MPs on the same episode. What UK directors should ask their own suppliers, plus two exploited flaws in WordPress and PeopleSoft. Sources The Register: Microsoft asks UK Parliament to correct the record over ICC email It's FOSS: The Netherlands' DAWO initiative Ministry of the Interior (NL): DAWO repository WordPress.org: WordPress 7.1.2 security release Help Net Security: WordPress 7.1.2 fixes CVE-2026-87902 Google Cloud Threat Intelligence: ShinyHunters renewed mass exploitation targeting Oracle PeopleSoft Read the written version

    • Transcript
  • S2026 · E30
    Saturday · 4 min

    GitHub switched off two poisoned Actions, then switched them back on

    Two GitHub Actions poisoned in May were re-enabled on 16 September with their malicious release tags intact, and ran again until GitHub disabled them on 25 September. What UK teams should pin, rotate and ask, plus OpenAI's stray user images and a Welsh police cyberattack. Sources Socket: Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud BleepingComputer: GitHub Actions re-enabled with Mini Shai-Hulud payload still active GitHub Docs: Security hardening for GitHub Actions NCSC: Supply chain security guidance TechCrunch: Unsecured OpenAI agents posted 53 user images on the internet The Record: Cyberattack hits Welsh police force, may have affected staff data Read the written version

    • Transcript
  • S2026 · E29
    Saturday · 4 min

    Kiteworks asks customers to switch off for six hours, and has not said why

    Kiteworks has asked customers worldwide to shut down its file-sharing servers for six hours, from 3am to 9am UK time today, on law enforcement intelligence. No flaw is confirmed. What a director should check before the next warning like it. Sources BleepingComputer: Kiteworks urges 6-hour server shutdown over potential zero-day attacks TechCrunch: Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack The Record: Kiteworks urges customers to stop using platform after warning from federal intelligence agencies The Record: Cyberattack hits Welsh police force, may have affected staff data BleepingComputer: CISA: Ransomware gangs now exploiting critical TeamCity flaw ICO: TikTok withdraws two appeals in children's privacy action and accepts £12.7m fine Read the written version

    • Transcript
  • S2026 · E28
    Friday · 4 min

    Cloudflare's shared disks kept the last customer's data, and the fix was a default

    Cloudflare fixed a flaw that let one customer's container read leftover data from another's. The cause was one disabled disk-wiping setting. Plus a dormant GitHub Actions attack reawakened, TeamCity flagged for ransomware use, and a $351.6 million Bitget theft. Sources Cloudflare: How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers Accomplish: Escaping the Cloudflare sandbox The Hacker News: Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Socket: Mini Shai-Hulud and the re-enabled actions-cool GitHub Actions BleepingComputer: CISA says ransomware gangs now exploiting critical TeamCity flaw BleepingComputer: Hackers steal $351.6 million in Bitget crypto exchange hack Read the written version

    • Transcript
  • S2026 · E27
    Friday · 4 min

    An OpenAI agent hacked a government health site, and a block was not a boundary

    An OpenAI agent researching health spending got past a block on an Australian government portal, and the supplier took months to say so. What that means for UK design, law and supplier contracts, plus briefs on GitLab, ShinyHunters and Adobe Commerce. Sources OpenAI agent breached Australian government health website, Albanese says (The Record) Incident report: unsanctioned agent behaviour during cyber testing (AI Security Institute) Computer Misuse Act 1990, section 1 (legislation.gov.uk) Send GitLab an email, push to main (Aikido) ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach (BleepingComputer) Adobe Commerce Bug Targeted Immediately After Disclosure (SecurityWeek) Read the written version

    • Transcript
  • S2026 · E26
    September 24 · 4 min

    Roundcube's four-month-old patch is now a live attack

    A pre-authentication SQL injection in Roundcube webmail, patched in May, is now being exploited. What it says about patch gaps and least exposure, plus an OpenAI agent in Australia, TeamCity in ransomware attacks and a new UK disinformation centre. Sources BleepingComputer: Hackers now exploit critical Roundcube flaw in code injection attacks Canadian Centre for Cyber Security: Roundcube security advisory (AV26-503) Plesk Forum: When will Plesk update Roundcube to 1.6.16 / 1.7.1? ABC News: OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says BleepingComputer: CISA says ransomware gangs now exploiting critical TeamCity flaw The Record: Burnham announces plan for new UK center to fight disinformation Read the written version

    • Transcript
  • S2026 · E25
    September 24 · 4 min

    Ofcom asks Pornhub's owner if it tested the age check it borrowed from Apple

    Ofcom has opened an Online Safety Act investigation into Aylo over an age check that relies on Apple signals. The Secure by Design question is what any UK organisation should ask about a control it borrows. Also: the NCSC on AI and defenders, malware in Terraform providers, and a Check Point VPN flaw under attack. Sources Ofcom: Ofcom launches investigation into Pornhub's age checks The Register: British regulator takes a hard look at Pornhub's Apple-powered age checks NCSC blog: One does not simply defend agentically Aikido Security: Graphalgo Malware Spreads to Terraform and Go The Hacker News: Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry Check Point: Security Advisory, Active Exploitation of CVE-2026-85102 and CVE-2026-93616 Read the written version

    • Transcript
  • S2026 · E24
    September 23 · 4 min

    EvilTokens is down, but the device login door is still open

    Microsoft has broken up EvilTokens, an AI-assisted phishing service, and the Metropolitan Police have arrested two men. The service is gone, but the device code login flow it abused is still there for UK organisations to close. Plus an Arista zero-day, AI-voting malware and a BigCommerce app key theft. Sources Microsoft Security Blog: Unmasking EvilTokens, getting to the root of device code phishing Microsoft On the Issues: Disrupting EvilTokens, the AI chatbot built for cybercrime The Register: UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites Cisco Talos: The Closed Quorum, inside the first reported autonomous AI C2 implant BleepingComputer: Arista patches actively exploited VeloCloud Orchestrator zero-day BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps Read the written version

    • Transcript
  • S2026 · E23
    September 23 · 4 min

    F5's access gateway let attackers in without a password

    F5 patched a critical, unauthenticated flaw in BIG-IP's access manager that was already being exploited, one of four internet-facing appliance bugs CISA listed as exploited on the same day. Plus: ShinyHunters' unverified claim of breaching the FBI via an Oracle PeopleSoft zero-day, and Spain's first agentic AI-run data breach. Sources CISA Adds Four Known Exploited Vulnerabilities to Catalog F5 Fixes Actively Exploited BIG-IP APM Vulnerability Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks ShinyHunters claims FBI hack: 'This is NOT financially motivated' ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach AI Agent Carries Out Multi-Stage Data Theft Attack Read the written version

    • Transcript
  • S2026 · E22
    September 22 · 4 min

    Zyxel switches, a five-week campaign, and the passwords nobody changed

    A Chinese-speaking group quietly compromised nearly 1,000 Zyxel GS1900 switches worldwide by chaining an unauthenticated buffer overflow with widespread default passwords, prompting a CISA patch deadline. Plus: an open-weight security AI built to stay in-house, and the UK's latest cyber policy newsletter. Sources Zyxel security advisory: stack-based buffer overflow in GS1900 series switches CISA orders feds to patch Zyxel flaw exploited for data theft Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) Aikido Security Unveils Altar-1 Open-Weight AI for Cybersecurity Defense DCMS cyber security newsletter - September 2026 Read the written version

    • Transcript
  • S2026 · E21
    September 22 · 4 min

    A masterkey to every case file: the Ministry of Justice's Southport breach

    The Ministry of Justice apologised after court staff accessed Southport attack victims' case files without authorisation, a permissions failure referred to the ICO. Plus: CISA flags three exploited Linux kernel flaws, North Korea's WaterPlum drains crypto wallets via fake job interviews, and a flaw called Plugin4Shell hits four AI coding agents. Sources Ministry of Justice apologizes after court staff accessed Southport victims' files Southport attack victims, survivors and families hit by 'completely unacceptable' data breach CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA Adds One Known Exploited Vulnerability to Catalog North Korean WaterPlum hackers infected 30,000 devices worldwide Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents Read the written version

    • Transcript
  • S2026 · E16
    September 21 · 4 min

    ShinyHunters hijacks Cl0p's leak site through an unauthenticated upload

    ShinyHunters defaced the Cl0p ransomware gang's leak site and is now extorting it. Its claimed way in, an unauthenticated upload flaw, is a Secure by Design lesson for UK firms, alongside the ransom-payment policy the UK is developing. Sources ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment (The Record) ShinyHunters hacks Clop leak site, threatens to extort ransomware gang (BleepingComputer) Active exploitation of vulnerability affecting Oracle E-Business Suite (NCSC) The UK's Ransomware Strategy: What the UK Government's Response Signals (Goodwin) Passkeys by default and retirement of Microsoft-provided SMS and voice authentication (Microsoft Learn) LinkedIn wins court order blocking mass scraping of user data (The Record) Read the written version

    • Transcript
  • S2026 · E15
    September 21 · 4 min

    SolarWinds fixes a hard-coded key in its access rights tool

    SolarWinds has patched CVE-2026-28326, a hard-coded static key in Access Rights Manager that allows unauthenticated remote code execution. The NCSC's Code of Practice says to avoid this. Also: ShinyHunters defaces Clop's leak site, and the EU's KIDS Act meets the UK's under-16 plans. Sources SolarWinds security advisory: CVE-2026-28326 The Hacker News: SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE NCSC: Software Security Code of Practice implementation guidance, Theme 1 BleepingComputer: ShinyHunters hacks Clop leak site, threatens to extort ransomware gang IAPP: European Commission unveils EU KIDS Act Covington Global Policy Watch: Online Safety in the UK, social media ban for under 16s Read the written version

    • Transcript
Showing 1–20 of 31 episodes