<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/cyber-attacks" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Cyber-attacks ]]></title>
                <link>https://www.itpro.com/security/cyber-attacks</link>
        <description><![CDATA[ All the latest cyber-attacks content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 22 Jul 2026 09:03:50 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ 'Perimeter defences are prime targets': Security experts issue alert over Palo Alto GlobalProtect VPN exploitation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/perimeter-defences-are-prime-targets-security-experts-issue-alert-over-palo-alto-globalprotect-vpn-exploitation</link>
                                                                            <description>
                            <![CDATA[ The flaw in Palo Alto Networks’ GlobalProtect VPN was recently upgraded from a ‘medium’ rating to ‘high’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ACKcb6JjHWkqiamFFz9yVB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:03:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:description>                                                            <media:text><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Palo Alto Networks logo and branding pictured on a smartphone screen with stock market growth graph lines in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K4w4RerpP3nTt753iZeCNL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber experts have urged users of Palo Alto Networks' GlobalProtect VPN to patch immediately amidst active exploitation of an upgraded security flaw.</p><p>A flaw in the popular VPN service, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0257" target="_blank"><u>CVE-2026-0257</u></a>, could allow attackers to bypass authentication and establish an unauthorized connection. </p><p>The vulnerability primarily affects the GlobalProtect portal and gateway for Palo Alto Networks’ PAN-OS software, and carries a CVSS score of 7.8, rating it as ‘high’ in severity.</p><p>Notably, this rating follows an upgrade, with the flaw having previously been given a ‘medium’ severity rating. Palo Alto announced the upgrade late last week amidst reports that the flaw was now being exploited in the wild. </p><p>“Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied,” the company said in an <a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank"><u>advisory</u></a>. </p><p><a href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/" target="_blank"><u>Analysis by Rapid7</u></a> shows threat actors have been exploiting the vulnerability since mid-May across several waves of attacks. </p><p>“Rapid7 MDR identified successful exploitation across numerous customers; however, we did not observe any indication of successful lateral movement from the devices,” researchers said. </p><p>“The earliest date for observed exploitation was May 17, 2026.  As of May 29, 2026,  this vulnerability has been added to the CISA KEV.”</p><p>Rapid7 noted that customers compromised in this wave of attacks had Cloud Authentication Service (CAS) disabled. Others, meanwhile, had GlobalProtect portal or gateway authentication override cookies enabled. </p><p>A patch has been issued for customers running affected appliances, according to Palo Alto. </p><p>Similarly, administrators are advised to turn off authentication override features to mitigate potential exploitation. </p><h2 id="qilin-ransomware-involved-in-globalprotect-attacks">Qilin ransomware involved in GlobalProtect attacks</h2><p><a href="https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/"><u>Analysis by Arctic Wolf Labs</u></a> suggests attacks on GlobalProtect customers could be the work of the Qilin ransomware group or affiliates. Indeed, researchers detected Qilin ransomware during several instances across June, highlighting a range of tell-tale signs. </p><p>“Post-exploitation tradecraft varies across intrusions, from rapid encryption-only operations to full double extortion, possibly suggesting multiple affiliates operating under the Qilin <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware as a service (RaaS)</a> umbrella,” the company said. </p><p>Dray Agha, senior manager for Huntress’ security operations center, said these attacks highlight the growing threats posed to <a href="https://www.itpro.com/security/27098/best-vpn-services">VPNs </a>and <a href="https://www.itpro.com/security/firewalls">firewalls</a>. </p><p>"The exploitation of this GlobalProtect vulnerability by the <a href="https://www.itpro.com/security/cyber-attacks/thousands-of-procedures-canceled-at-london-hospitals-as-qilin-releases-blood-test-data">Qilin ransomware gang</a> demonstrates that perimeter defences are prime targets,” he said. </p><p>“When threat actors can bypass VPN authentication, they are walking through the digital front door with a master key. The grace period for patching critical edge devices has practically vanished, and they must be the patching priority for all organizations".</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-risk-to-every-organization-has-increased-exponentially-the-fortibleed-campaign-just-took-a-turn-for-the-worse</link>
                                                                            <description>
                            <![CDATA[ Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">npiBchLKa4eriPG8MdEo5T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 08:09:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:description>                                                            <media:text><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:text>
                                <media:title type="plain"><![CDATA[Plaque pictured at the Foreign, Commonwealth and Development Office building in Whitehall, London. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bR33DDYEFNw8FhDqg6p8y5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>experts have issued an alert amid reports that hackers accessed login credentials belonging to UK government officials and Foreign Office staff. </p><p>The credentials, which are reportedly being sold on the dark web, were exposed as part of the ongoing FortiBleed attack campaign. </p><p>FortiBleed targets internet-facing Fortinet <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN </a>and <a href="https://www.itpro.com/security/firewalls">firewalls</a>, and is believed to have affected more than 70,000 devices spanning 194 countries since it was first uncovered last month. </p><p><a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/" target="_blank"><u>Analysis from SOCRadar</u></a>, for example, identified a vast database containing login credentials. The threat intelligence firm has since attributed FortiBleed to the Lynx/<a href="https://www.itpro.com/security/ransomware/ransomware-group-publishes-stolen-nhs-scotland-data-to-dark-web">INC ransomware</a> group.</p><p>While this database was believed to have been limited to basic usernames and passwords, reports from <a href="https://www.telegraph.co.uk/news/2026/07/05/russian-hackers-steal-government-logins/" target="_blank"><u><em>The Telegraph</em></u></a><em> </em>suggest some exposed details include privileged Fortinet credentials. </p><p>Volodymyr Diachenko, a security researcher who first uncovered the threat campaign, told the publication these credentials could give bad actors access to the Foreign Office’s “core networks” along with other government departments.</p><p>Some Foreign Office credentials are now being sold on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>, according to reports, going for up to £40,000. </p><p>Arctic Wolf CISO Adam Marrè warned that the incident could create a domino effect, impacting other government departments and also local authorities and public services. </p><p>According to <em>The Telegraph</em>, credentials at NHS trusts, energy companies, and local councils were also hosted in the illicit database. </p><p>“This major breach of email accounts of UK government officials and overseas Foreign Office workers is the latest development in the ongoing FortiBleed attack,” he said. </p><p>“While it may be tempting to think this is a simple <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks">credential-stuffing</a> operation, our threat team found the threat actors have built a highly sophisticated and repeatable credential factory,” he said. </p><p>Marrè noted that analysis of the incident conducted by Arctic Wolf shows threat actors appear to have been using automated tools to harvest logins and target gateways at “exponential speed and volume”. </p><p>“This means while today it’s the Foreign Office which has been affected, the risk to every organization has increased exponentially.”</p><h2 id="back-and-forth-on-fortibleed">Back and forth on FortiBleed</h2><p>The discovery of the FortiBleed sparked somewhat of a back and forth between Fortinet and security researchers last month. After threat intelligence firm Hudson Rock published a <a href="https://www.hudsonrock.com/fortinet" target="_blank">blog detailing the campaign</a>, Fortinet disputed some of its claims. </p><p><a href="https://www.itpro.com/security/passwords-nicked-for-nearly-74-000-fortinet-devices"><u>Fortinet told </u><u><em>ITPro </em></u><u>at the time</u></a> that the exposed credentials weren’t the result of a fresh breach, insisting that those following best practices were safe from exposure.</p><p>"Fortinet is aware of a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways. We are committed to safeguarding our customers, and we diligently and continuously monitor threat actor darknet activity,” a spokesperson for the company said. </p><p>“Based on our initial analysis, the data involved is likely a resharing of data from previous incidents, as well as brute forcing of credentials, and not related to any current incident or advisory."</p><p>Hudson Rock, meanwhile, said the campaign went “beyond simply credential reuse,” highlighting that hundreds of organizations are thought to have been affected. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are posing as Interpol to target small businesses – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-posing-as-interpol-to-target-small-business-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Small businesses are warned to think twice before clicking on links ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dfEYQHdzwBELh5bxQfdbGS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:58:23 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 21:36:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Criminals are posing as Interpol cyber crime investigators to target small businesses across Europe, Asia, the Middle East, and North America.</p><p>According to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-interpol-emails-serve-ransomware" target="_blank"><u>new research from Bitdefender</u></a>, the phishing messages claim to contain evidence that the recipients are carrying out suspicious activity, pressuring them into opening a password-protected archive.</p><p>"Based on information that has come to our attention, there may be activities involving accounts, systems or services associated with your organization that warrant further examination. We have obtained information and video material that may assist in your assessment of the matter," the emails read. </p><p>"We recommend conducting an internal review to determine whether any unauthorized, suspicious or potentially fraudulent activities have occurred. Prompt attention to such matters may help mitigate potential financial operational, reputational or regulatory risks."</p><p>Upon opening the link, recipients are directed to a <a href="https://www.itpro.com/security/proton-is-launching-its-own-private-alternative-to-google-workspace-and-microsoft-365">Proton </a>Drive-hosted file that delivers a ransomware payload hidden within multiple archive layers. Once executed, researchers said the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>seeks to encrypt files across available drives and presents victims with a ransom message.</p><p>The campaign is targeting organizations across multiple industries, including food and agriculture, legal services, pharmaceuticals, media, technology, and finance.</p><p>The ransomware is relatively simple, according to Bitdefender researchers. The code contains hardcoded values, including the password used during encryption and decryption, and lacks many of the features typically associated with large <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>operations.</p><p>Interestingly, victims are instructed to contact the attackers through a Tox chat channel to negotiate a ransom, rather than through the more usual dedicated negotiation portal or victim site.</p><p>This, researchers noted, is another indication that this is likely a custom-built operation, perhaps assembled using publicly available code and tools rather than the work of an established ransomware group.</p><h2 id="what-small-businesses-need-to-know">What small businesses need to know</h2><p>Javvad Malik, Lead CISO advisor at <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">KnowBe4</a>, said that impersonating Interpol – or law enforcement in general – is specifically designed to trigger a “rapid emotional response” and dupe victims into ignoring red flags. </p><p>"What is interesting about this campaign is that it targets small business,” he said. “These are often understaffed and have no security or even IT expertise on hand, so it's not difficult to see why people would easily fall victim to these kinds of attacks."</p><p>Bitdefender has warned small businesses to be on the alert, urging them to verify all unsolicited correspondence by reaching out through official channels to confirm whether the communication is legitimate.</p><p>"One of the biggest red flags in this campaign is the delivery method itself," researchers said. "While the attackers impersonate Interpol, legitimate law enforcement agencies don't send unsolicited emails containing Proton Drive links to password-protected files and ask organizations to review alleged evidence of wrongdoing."</p><p>They should treat password-protected archives with caution, especially when the password is included in the email. Showing file extensions on Windows devices will make it easier to spot executables masquerading as videos or documents, and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">multi-factor authentication (MFA)</a> should be used wherever possible.</p><p>Elsewhere, the company urged small businesses to ensure staff are trained to help spot tell-tale signs that communications are fraudulent. </p><p>"Small businesses are often viewed as easier targets than large enterprises," the researchers warned.</p><p>"Many operate without dedicated IT teams or cybersecurity staff. Security responsibilities are often shared among employees who already wear multiple hats, and limited budgets can make it difficult to invest in advanced security measures or ongoing training."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Simplicity and unity will win the fight against AI cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/simplicity-and-unity-will-win-the-fight-against-ai-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ How MSPs can turn the rise of AI-driven breaches into a business advantage ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KzTQsEd9o4M2HgH6FoEr8i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Jul 2026 12:58:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ VimalRaj Sampathkumar ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Fzc6sJqk4ccSXbYZkvtoGK.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:description>                                                            <media:text><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the age of AI, perimeter defense alone is no longer enough. Traditional methods for securing IT estates are horribly vulnerable to increasingly sophisticated AI tools, leading to a rapid degradation of many organizations’ defenses. </p><p>On a global scale, in April, the <a href="https://www.bbc.co.uk/news/articles/crk1py1jgzko"><u>news</u></a> broke of Claude Mythos’ limited release and the danger it could pose to cybersecurity worldwide. The hyper-powerful AI model rapidly uncovered flaws and vulnerabilities in defense systems that had lain dormant for years, threatening the integrity of banking systems, energy networks, and more.</p><p></p><p>In the UK, more than three-quarters of UK businesses have suffered a cyber incident in the past year. What’s more, 43% of UK IT decision-makers identified AI-powered attacks as the single biggest risk they face over the next 12 months, ahead of traditional threats such as ransomware, phishing, and data breaches. </p><h2 id="turning-lemons-into-lemonade">Turning lemons into lemonade</h2><p>Clearly, there’s plenty of cause for concern here – the challenge is significant, and the potential damage could reach far beyond companies’ bottom lines. But that doesn’t mean the IT industry should throw up its hands and accept the inevitable. Rather, the rapid growth in AI-driven breaches is a sign that a new approach is needed. </p><p>For managed service providers (MSPs) in particular, the evolving threat of AI presents a business opportunity rather than just another security burden. As customers seek to handle cloud patching complexity, regional compliance differences, and increasingly automated attacks, MSPs that can unify security, operations, and automation in a single offering will be best placed to improve service quality and usability – and so unlock increased profitability.</p><p>This isn’t wishful thinking: organizations are making plans to invest in technology that can help them tackle the AI challenge. AI and advanced threat preparedness is the top spending commitment for UK organizations over the next 12 to 24 months, cited by 41% of 1,500 IT decisionmakers ManageEngine recently surveyed.</p><h2 id="simpler-faster">Simpler, faster</h2><p>There is also a growing gap between how quickly organizations detect incidents and how long it takes them to recover, which is where MSPs can provide real value. The majority (94%) of UK organizations detect incidents within 24 hours, and nearly half recover within 10 days. However, 26% said recovery can extend beyond 10 days, with a smaller proportion taking more than 20 days.</p><p>In response to that inefficiency, MSPs can help by reducing tool sprawl, standardising workflows, responding quickly to incident reports, and packaging up more resilient service tiers. Clients will pay for this kind of rationalisation and streamlining, providing, as it does, a crucial way to reduce the time between a security incident and a successful resolution.</p><h2 id="putting-operational-tech-at-the-center">Putting operational tech at the center</h2><p>MSPs can also provide value in the battle against AI-driven cyberattacks by including operational technology (OT) in the development of security systems as a priority rather than an afterthought. OT is becoming part of the managed risk surface and requires the same disciplined approach MSPs already apply to IT – not least because OT software may traditionally have been seen as ‘lower-risk’, and therefore less diligently patched.</p><p>Again, the core benefit MSPs can provide clients with here is acting as the single point of contact that draws together oversight of all potential vulnerabilities. As organizations’ digital estates become ever more complex, applying security policies and automations to OT as well as back-office apps and systems can be a major headache. </p><p>MSPs with expertise across the board can not only build a unified policy to defend the entire attack surface – they can also radically simplify day-to-day management for client IT teams.</p><p>AI is turning the threat of cyber attack into a many-armed monster, hitting harder and in more places than ever before. In the face of this ramped-up threat, MSPs are uniquely placed to offer a unified, simplified service – and in that sense, the rise of AI breaches could be a real business opportunity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hacking-groups-have-the-transport-network-firmly-in-their-sights-network-rail-is-battling-a-torrent-of-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoW86jKhaGNwz8fh2EZQkX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 11:26:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:description>                                                            <media:text><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:text>
                                <media:title type="plain"><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Network Rail is fighting off millions of cyber attacks every month, according to new research, as experts warn of a rising tide of threats facing public services. </p><p>Freedom of information (FoI) requests show the organization blocked over 7.1 million malicious emails between December 2025 and March this year.  </p><p>Of the 7,129,314 email attacks blocked by Network Rail, 331,352 were phishing emails, 1,412 were <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>-laden emails, 2,066,392 were spam emails, and 4,730,158 were edge blocked emails. </p><p>This all adds up to an average of more than 800,000 attacks per day, including around 37,000 <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attempts.</p><p>“With so many people in the UK depending on public transport for their daily lives, a successful cyber attack could cause significant disruption, such as potentially stopping people from getting to work," warned Simon Edwards, CEO of SE Labs. </p><p>"Therefore, it’s vital that our public sector organizations have a dedicated cyber strategy put in place and ensure rigorous testing to identify any security holes and keep hackers at bay.”</p><p>Just last week, two members of the hacking group known as Scattered Spider pleaded guilty over their <a href="https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation">involvement in an attack on Transport for London (TfL) systems</a>. </p><p>The attack forced all 28,000 employees to attend a TfL office for a password reset and led to a reported £29 million in losses and recovery costs.</p><p>"As we've seen from the recent Scattered Spider convictions, hacking groups have the transport network firmly in their sights. A single successful cyber attack on the rail network could drive Britain to a halt, operationally and economically," said Graeme Stewart, head of public sector at Check Point. </p><p>"The transport network is also a treasure trove of personal and financial data, something unscrupulous criminals are eager to get their hands on. That’s why it's vital that our roads, rail and aviation systems are fully protected with the latest cyber defenses to keep hackers locked out."</p><h2 id="what-happened-with-the-network-rail-cyber-attack">What happened with the Network Rail cyber attack?</h2><p>In 2024, Network Rail suffered a <a href="https://www.itpro.com/security/network-rail-confirms-cyber-attack-on-wi-fi-systems-at-uk-train-stations"><u>cyber attack</u></a> on its WiFi systems that saw commuters who logged in at affected stations receive information pertaining to terrorist attacks in Europe, as well as a message stating “we love you Europe”. </p><p>The attack is believed to have taken place through a third-party service provider, Telent, which managed Network Rail's WiFi services.</p><p>More recently, train operator LNER said a <a href="https://www.itpro.com/security/cyber-attacks/lner-warns-customers-to-remain-vigilant-after-personal-data-exposed-in-cyber-attack"><u>cyber attack</u></a> had led to unauthorized access to files managed by an unnamed third-party supplier.</p><p>Travel networks, particularly rail services, are among the top targets for cyber criminals and state-sponsored groups due to the critical role they play in the British economy, according to research conducted last year. </p><p>The UK's Department for Science, Innovation and Technology (DSIT) released a <a href="https://assets.publishing.service.gov.uk/media/69144f259d50fc2fe816163a/Economic_impact_of_a_systemic_cyber_incident_rail_sector_scenario.pdf" target="_blank"><u>report</u></a> from KPMG that concluded a major attack on the rail network could cost £1.8 billion for a one-week period of disruption.</p><p>The direct financial cost to Network Rail would, it concluded, cost around £123 million, with the cost to passengers due to delays adding up to about £281.3 million. </p><p>Notably, the impact on Gross Value Added (GVA) could be as much as £1.397 billion, representing approximately 2.8% of the UK’s weekly GDP and 0.05% of annual GDP.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Duo accused of role in TfL cyber attack plead guilty after ‘lengthy, highly complex, and painstaking investigation’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation</link>
                                                                            <description>
                            <![CDATA[ Around 10 million people are believed to have been affected by the TfL cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">99isQzP3Ggse8NRDUNdd7i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 09:30:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Ross Kelly ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:description>                                                            <media:text><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:text>
                                <media:title type="plain"><![CDATA[Commuter standing on a train at a London underground tube station, which is run by Transport for London (TfL).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/74qnvFg7TZirm7UfyeNWJH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two young men have pleaded guilty to offenses under the Computer Misuse Act following a <a href="https://www.itpro.com/technology/artificial-intelligence/true-scale-of-tfl-cyber-attack-emerges-what-happened-who-was-responsible-and-how-many-people-were-impacted">cyber attack on Transport for London (TfL)</a> that caused months of disruption and millions in damages. </p><p>Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall in the West Midlands, were arrested following raids by the National Crime Agency (NCA) and City of London Police in September 2025.</p><p>The duo are alleged members of the notorious Scattered Spider cyber crime collective, believed to be responsible for a string of attacks in recent years. The group claimed responsibility for attacks on UK retailers <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack">Marks & Spencer</a> and the <a href="https://www.itpro.com/security/cyber-attacks/co-op-chief-executive-very-proud-of-cyber-attack-response-despite-huge-financial-losses">Cooperative Group</a>, as well as <a href="https://www.itpro.com/security/cyber-attacks/mgm-resorts-back-online-after-suspected-ransomware-attack">MGM Resorts</a> in the United States. </p><p>“The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries, epitomised by Scattered Spider," said Paul Foster, deputy director of the National Crime Agency and head of the NCA National Cyber Crime Unit.</p><p>Flowers was first arrested in September 2024, at which point NCA officers found evidence that the networks of US healthcare companies SSM Health Care Corporation and Sutter Health had also been infiltrated and damaged.</p><p>Investigators found a number of devices at Flowers' home, including laptops, tower computers, hard drives, and USB sticks. One Acer laptop contained a screenshot showing network connectivity to TfL infrastructure. </p><p>Flowers had also accessed an online platform selling credentials compromised in previous cyber attacks and data breaches. </p><p>Notably, the laptop contained a number of videos that Flowers had recorded, which showed Jubair accessing TfL systems during the attack. At the same time, the pair were messaging each other over Telegram, as well as communicating via an online work collaboration tool.</p><h2 id="what-happened-with-the-tfl-cyber-attack">What happened with the TfL cyber attack?</h2><p>TfL’s network was infiltrated at the beginning of September 2024, forcing all 28,000 employees to attend a TfL office for a password reset. The cyber attack caused widespread disruption for the rail operator. </p><p>Data from TfL’s Oyster refunds system was accessed while its customer refund system was also affected. Elsewhere, the attack shut down the Oyster photocard application system for children and young people. </p><p>Around 10 million people are believed to have been affected by the attack, making it one of the UK’s most devastating cyber attacks to date. </p><p>Jubair and Flowers are due to be sentenced at Woolwich Crown Court on 16 July.</p><h2 id="a-lengthy-investigation">A lengthy investigation</h2><p>Foster said the trial is the culmination of a “lengthy, highly complex and painstaking investigation” and hailed law enforcement colleagues for their role in apprehending the duo. </p><p>“The perseverance and meticulousness of our officers, and the work of our partner organizations, meant that Jubair and Flowers had no option other than to plead guilty and take responsibility for their offending," he commented.</p><p>“Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public. The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers."</p><p>The NCA is urging victims of cyber crime to use the government’s Cyber Incident Signposting Site for direction on which agencies they should report incidents to.</p><p>“Today’s result would not have been possible if TfL had not engaged with law enforcement early, so I would urge any other organization to please do the same in such circumstances," said Foster.</p><h2 id="the-rise-of-youth-hackers">The rise of youth hackers</h2><p>Upon their arrest in September 2025, Jubair and Flowers were both teenagers, prompting concerns about a <a href="https://www.itpro.com/security/cyber-crime/the-rise-of-teen-hackers-makes-for-a-good-headline-but-cyber-crime-activities-peak-later-in-life"><u>potential wave of youth-related cyber crime</u></a>. As <a href="https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack"><u><em>ITPro </em></u><u>reported at the time</u></a>, cybersecurity experts described the incident as a “wake up call” for law enforcement, educators, and society at large. </p><p>Anna Chung, principal researcher for EMEA at Palo Alto Networks, said these incidents highlight a failure to “properly engage a generation growing up in a digital-first world”. </p><p>“Young people don’t usually turn to online mischief out of malice - it’s often down to a mixture of boredom, technical skills, and a lack of boundaries,” she told <em>ITPro </em>at the time.</p><p>So what’s the solution? Chung urged schools and parents to make a concerted effort toward teaching digital ethics, making this a “part of core education”. This, she noted, could be crucial to preventing future incidents. </p><p>Chung’s warning over teen hackers is by no means the first, or likely last, that we’ll hear about in coming years. </p><p>Indeed, the UK’s <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> published a report last year which <a href="https://www.itpro.com/security/kids-hacking-for-kicks-are-causing-security-headaches-at-schools"><u>highlighted a spate of cybersecurity incidents at schools across the country</u></a>, with students bypassing network security controls and gaining access to management systems. </p><p>Nipping these types of activities in the bud are crucial, the ICO warned, largely as they have the potential to evolve into more nefarious activities. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Legacy kit behind vast majority of cyber attacks on utilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/legacy-kit-behind-vast-majority-of-cyber-attacks-on-utilities</link>
                                                                            <description>
                            <![CDATA[ With equipment and software poorly suited to withstand modern cyber threats, organizations need to do more to identify unmanaged or vulnerable systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g5wVJsihF2LFMhqkmSmkEi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BZ2z9PNptF9yx2L4peXaVE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jun 2026 10:43:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BZ2z9PNptF9yx2L4peXaVE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close-up shot of networking routers and switches connected by neatly arranged fiber optic, twisted pair, and power cables within a data center.]]></media:description>                                                            <media:text><![CDATA[A close-up shot of networking routers and switches connected by neatly arranged fiber optic, twisted pair, and power cables within a data center.]]></media:text>
                                <media:title type="plain"><![CDATA[A close-up shot of networking routers and switches connected by neatly arranged fiber optic, twisted pair, and power cables within a data center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BZ2z9PNptF9yx2L4peXaVE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than three-quarters of utilities organizations were hit by cyber attacks involving <a href="https://www.itpro.com/software/linux/360665/hackers-target-outdated-versions-of-linux-in-the-cloud">outdated software</a> or unavailable patches on <a href="https://www.itpro.com/business/digital-transformation/legacy-it-infrastructure-accounts-for-more-than-a-third-of-enterprise-power-consumption-and-its-creating-a-sustainability-nightmare-for-it-leaders">legacy equipment</a> over the last year.</p><p>At 77%, it was the most common type of cyber incident facing the sector, according to Bridewell's Cyber Security in Critical National Infrastructure Report 2026.</p><p>And the most common effect was IT disruption or outages, affecting 47% of organizations, despite the fact that 99% of respondents described themselves as resilient after their worst cyber attack. </p><p>A further 42% said incidents had resulted in increased <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> spending, while 35% experienced data loss, 34% reported revenue loss, and 32% suffered disruption to production or services.</p><p><a href="https://www.itpro.com/software/software-supply-chain-attacks-are-soaring-and-security-leaders-are-sluggish-to-react">Supply chain attacks</a> take the longest to respond to, at 9.9 hours on average, followed by data theft or disclosure at 8.4 hours and unauthorised access at 7.6 hours.</p><p>The utilities sector is particularly hampered by the need to secure ageing operational technology and infrastructure that weren't designed to withstand modern cyber threats, as critical assets can't be updated or taken offline as easily as traditional IT environments.</p><p> "Many of the systems underpinning essential utilities services were designed to operate for decades in environments that were never intended to be connected to modern digital networks," said Sam Thornton, COO at Bridewell. </p><p>Beyond <a href="https://www.itpro.com/infrastructure/six-reasons-it-pros-are-ditching-legacy-monitoring-tools">legacy infrastructure</a>, phishing and business email compromise remain widespread, affecting 76% of utilities organizations in the past year. Malware affected almost as many, at 74%, while more than seven-in-ten experienced unauthorized system access.</p><p>The main concern for utilities organizations is data protection and privacy, cited by 46% of survey respondents. Managing AI-related cyber risk and the ability to quickly detect incidents were close behind, reflecting growing concerns around emerging technologies and increasingly sophisticated attacks. </p><p>Utilities organizations are also unconfident when it comes to data breach notification requirements, cited by 42%, cybersecurity measures for data protection at 39%, and third-party due diligence at 38%.</p><p>And regulation is now the primary driver of cyber security maturity within the utilities sector, cited by 36% of respondents - ahead of both the evolving threat landscape and customer demand for improved security, and highlighting the growing influence of frameworks and compliance obligations on cyber security investment and decision-making.</p><p>"As utilities providers continue to modernize and connect operational systems, managing the gap between legacy infrastructure and modern security requirements is becoming one of the sector's biggest cybersecurity challenges," said Thornton.</p><p>Bridewell recommends that utilities organizations improve the visibility of assets across both IT and operational technology environments to identify unmanaged or vulnerable systems.</p><p>They should prioritize patch management and vulnerability remediation based on operational risk and criticality, conduct regular incident response exercises to ensure teams can respond effectively during a live cyber incident and strengthen monitoring and detection capabilities to reduce the time taken to identify and contain threats.</p><p>They should also review third-party and supply chain security arrangements to ensure critical partners meet appropriate security standards.</p><p>"In the utilities sector, the consequences of a cyber attack extend far beyond IT," said Thornton. "When critical systems are disrupted, the impact can be felt by customers, communities and the wider economy, making cyber resilience a business-critical priority."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hostile states behind three-quarters of UK critical infrastructure attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hostile-states-behind-three-quarters-of-uk-critical-infrastructure-attacks</link>
                                                                            <description>
                            <![CDATA[ NCSC CEO warns that with the rise of AI, the danger is only set to get worse ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Q5cNNxjBujgjgEiQ8ucRod</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 11:55:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:description>                                                            <media:text><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:text>
                                <media:title type="plain"><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The overwhelming majority of cyber attacks on critical infrastructure are coming from hostile states, the UK's cyber chief has warned.</p><p>Speaking at the Royal United Services Institute's (RUSI) Annual Security Lecture, Richard Horne, CEO of the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre </a>(NCSC), said the organization had handled more than 200 cyber incidents affecting the UK's critical national infrastructure and its supporting ecosystem over the last year. Around 75% were believed to be linked to state actors, particularly Russia, China, and Iran. </p><p>"We know that adversaries are prepositioning today, establishing footholds within technology that underpins critical national infrastructure that could enable rapid exploitation, to cause mass disruption in a time of conflict," he said.</p><p>"The highest profile example of this was a campaign often referred to as <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid">Volt Typhoon</a> against largely US critical national infrastructure, which was attributed in 2024. And we are seeing our critical infrastructure being targeted, regularly finding and stopping breaches, before their intent becomes clear."</p><p>Horne broke the threat down into 'near', 'mid,' and 'far' spaces, with the far space representing the adversary's home turf, systems, tooling, and networks. Here, he said, the UK and its allies bring pressure to bear through intelligence collection, sanctions, law enforcement action , and offensive cyber operations to disrupt and degrade their capability at source.</p><p>In the mid space, efforts are concentrated on hardening cloud, technology, and telecommunications infrastructure, and by disrupting adversary positions within those environments.</p><p>"The reality is much of this space is in private hands," he said. "Which means success here demands genuine collaboration between government and private sector, which is at the heart of our approach in the NCSC."</p><p>But, he said, it's the near space – the defense and resilience of the organizations and systems being targeted – where most action is probably required. <a href="https://www.itpro.com/technology/artificial-intelligence-ai/358279/why-it-professionals-are-concerned-about-the-rise-of">The rise of AI</a> is an important factor here, he said.</p><p>"Recent developments of frontier AI models have demonstrated their effectiveness at finding inherent vulnerabilities in the technology we rely on," he said.</p><p>"Our latest assessment shows that by 2028, it is highly likely that AI-Cyber capabilities will be used by attackers against known vulnerabilities in legacy technology in our critical national infrastructure."</p><p>British organizations should take note, said James Neilson, SVP of global at OPSWAT.</p><p>"The daily scale of hostile activity against the UK is vast, and until the NCSC revealed those figures, the threat and danger facing critical infrastructure was far greater than most businesses realized," he said. </p><p>"Many organizations neglect to secure data that moves in and out of their OT networks. By controlling data flows and scanning files in transit, organizations can detect and neutralise hidden malicious payloads before they infiltrate critical systems."</p><p>Horne called on organizations to strengthen cyber resilience by focusing on three core capabilities: understanding their exposure to threats, building stronger defences based on proven security fundamentals, and ensuring they can continue operating and recover quickly after an attack.</p><p>"By making our environment harder for adversaries to operate in, and engaging in the contest better, we can play an important part in altering potential adversaries' options and deterring conflict," he said.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-capitalizing-on-ai-hype-to-ramp-up-social-engineering-attacks-and-theyre-using-big-brands-like-anthropic-openai-and-deepseek-as-bait-to-lure-victims</link>
                                                                            <description>
                            <![CDATA[ Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bt3jnSdxJvJ3eU7nUZAaq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 11:11:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are exploiting <a href="https://www.itpro.com/technology/artificial-intelligence/businesses-finding-it-hard-to-distinguish-real-ai-from-the-hype-report-suggests">AI hype</a> to impersonate the branding of AI platforms such as ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude, according to new research. </p><p>Microsoft Threat Intelligence said it's observed an uptick in <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, malvertising, and search engine optimization (SEO)-driven attacks that ultimately lead to credential theft, financial fraud, or malware infection.</p><p>Campaigns focus on highly anticipated launches or emerging trends, using tried-and-tested tactics such as urgency-driven messaging, abuse of trusted services, and multi-stage redirection chains that require user interaction to evade detection.</p><p>"While traditional lures like invoices, payment notifications, or delivery alerts remain effective and continue to be widely used, AI-themed lures reflect a shift in <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> that is likely to persist as a long-term tactic used by threat actors, from cyber criminal groups to nation states," the company warned. </p><h2 id="chatgpt-users-in-the-crosshairs">ChatGPT users in the crosshairs</h2><p>In one example, Microsoft said it had observed a ChatGPT-themed phishing attack delivering malicious URLs which led to phishing pages that collected credit card and personal information such as names and addresses. </p><p>The emails used the sender display name ChatGPT and the subject line: “To ensure your ChatGPT Plus continues to work – please update your payment method”. </p><p>This phishing activity, which consisted of 4,500 emails sent to targets in South Africa, was part of a broader campaign using similar themes and infrastructure that delivered as many as 100,000 emails on a single day to targets in Switzerland, Austria, and South Africa. </p><p>Microsoft noted the campaign affected a broad range of industries, including higher education and professional services.</p><h2 id="thousands-targeted-in-a-claude-themed-phishing-attack">Thousands targeted in a Claude-themed phishing attack</h2><p>In another example, security experts spotted a phishing campaign impersonating Anthropic-branded services to target users with account-related lures tied to the Claude AI platform. </p><p>The campaign sent phishing emails to targets across more than 2,000 organizations, mainly in the US, UK, and India.</p><p>"The campaign used enforcement-themed messaging claiming that the recipient’s account was in violation of acceptable use policies and required immediate action," the company noted. </p><p>"The emails impersonated Anthropic’s popular AI service Claude using the display names Anthropic Teams and Anthropic PBC, masquerading as legitimate account-related communications. Subject lines followed a consistent structure of 'Claude Appeal Request' combined with date elements."</p><h2 id="deepseek-malvertising-is-a-growing-threat">DeepSeek malvertising is a growing threat</h2><p>Other examples included malvertising campaigns that use AI-themed terms such as 'Awesome AI Windows Plugin' and 'Flux Pro AI' in social engineering lures, and fake DeepSeek V4 installers on GitHub that delivered Vidar Stealer.</p><p>"Within hours of <a href="https://www.itpro.com/security/using-deepseek-at-work-security-risks">DeepSeek </a>previewing their latest version, V4, attackers created a fake GitHub organization and repository.  They copied real branding and benchmark data, added AI and SEO-search-friendly content, and pushed malicious archives that looked like installers," explained John Bruggeman, vCISO at CBTS. </p><p>"What the attacker did was not particularly exotic, but it was well timed and convincingly packaged. A user searching for the newest model could very easily end up in the wrong place, especially because the malicious repository showed up in GitHub, Google, Bing, or AI-assisted search results. The search results added legitimacy to the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>."</p><h2 id="remain-vigilant">Remain vigilant</h2><p>To counter these rising threats, Microsoft advised customers to configure automatic attack disruption in Microsoft Defender XDR, enforce <a href="https://www.itpro.com/security/how-resellers-can-win-with-smarter-multi-factor-authentication-mfa">multi-factor authentication (MFA)</a> on all accounts, use the Microsoft Authenticator app for passkeys and MFA, and scope conditional access policies to strengthen privileged accounts with <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">phishing-resistant MFA</a>.  </p><p>Other tips included:</p><ul><li>Enabling Zero-hour auto purge (ZAP) in Office 365</li><li>Configuring Microsoft Defender for Office 365 Safe Links</li><li>Invest in ‘advanced’ anti-phishing solutions</li></ul><p>"The companies that have a handle on AI governance (policies and procedures) well will be the ones that make safe AI use easy, risky AI use visible, and malicious activity hard to ignore. That means publishing a clear list of approved tools, blocking obvious lookalike domains and very recently registered domains can help stop this kind of threat," said Bruggeman. </p><p>"Monitoring suspicious downloads and sign-ins, and training employees on the AI-themed lures should also be done right now - don't think that generic phishing examples from five years ago are going to cut it today."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security professionals want leaders who have already led their organization through a major cyber incident – regardless of how things turned out ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-professionals-want-leaders-who-have-already-led-their-organization-through-a-major-cyber-incident-regardless-of-how-things-turned-out</link>
                                                                            <description>
                            <![CDATA[ Research from ISC2 reveals what makes for a good security leader ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HWGsn7t7injXFS6jDQ5rc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qncdTEoZDXGMUBNmVJ4gbm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 09:09:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qncdTEoZDXGMUBNmVJ4gbm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity professionals in discussion ]]></media:description>                                                            <media:text><![CDATA[Cybersecurity professionals in discussion ]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity professionals in discussion ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qncdTEoZDXGMUBNmVJ4gbm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity professionals are less likely to trust a boss who's never been through the mill of managing a <a href="https://www.itpro.com/security/a-prudent-approach-to-major-security-incidents">major security incident</a>.</p><p>Data from antivirus vendor Sophos suggests that <a href="https://www.itpro.com/business/careers-and-training/how-can-we-support-cisos-better">CISOs </a>have a one-in-four chance of losing their jobs after an attack. But new <a href="https://www.isc2.org/Insights/2026/05/cybersecurity-pros-want-leaders-who-have-been-through-a-major-incident">research</a> from ISC2 shows that three-quarters of security professionals reckon leaders are more credible if they've already led their organization through a major cyber incident – regardless of how things turned out. Just 9% disagreed.</p><p>Overall, the survey revealed that the most trusted security leaders are those who create confidence through transparency, consistency, and an ability to align security priorities with business outcomes. Those who can keep calm and carry on, demonstrating decisive leadership under pressure, are far more likely to earn lasting credibility with their teams and across the enterprise.</p><p>Unfortunately, though, cybersecurity bosses don't generally seem to be managing this. </p><p>Only 34% of cybersecurity professionals said they were very confident in their current <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> upper leadership, with 15% extremely confident. Three-in-ten said they had moderate confidence, 15% were only slightly confident, and 6% said they had no confidence in their cybersecurity leaders at all. </p><p>Security staff are particularly keen on leaders who can communicate risk to senior leadership and boards, with 95% of respondents reckoning this as very important.</p><p>Other big pluses included a strategic and long-term cybersecurity vision, along with the ability to effectively work with senior leadership and boards to secure budget, and being transparent about decisions and actions. </p><p>Decision-making under pressure, building and leading high-performing teams, and technical cybersecurity expertise were all very important to more than eight-in-ten –  more so than actual technical cybersecurity expertise, at 75%.</p><p>"The most important trait in a cybersecurity leader is the ability to align security strategy with business goals while earning trust through clear judgment, communication, and accountability," noted one respondent.</p><p>Bosses wanting to earn their staff's respect, said ISC2, need to be transparent about risks, priorities, and challenges. "Teams and executives are more likely to trust leaders who provide realistic assessments rather than overly optimistic narratives," the researchers said.</p><p>Keeping calm and carrying on in high-pressure incidents or periods of change also boosts a security leader's reputation, while there's much greater trust when leaders manage to create an environment where teams feel supported, heard, and accountable.</p><p>Strong cybersecurity leaders invest time in understanding business objectives and collaborating across departments, helping position security as an enabler rather than a blocker.</p><p>"For leaders who now find themselves in an environment where cybersecurity risk impacts every part of the organization, it is the ones who communicate clearly, empower their teams and demonstrate calm, decisive leadership under pressure that are far more likely to earn lasting credibility with their teams and across the enterprise," the researchers said.</p><p>"Ultimately, the most successful cybersecurity leaders are not simply those who protect systems and data, but those who create trust in their leadership when it matters most."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to protect your business from living off the land attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/how-to-protect-your-business-from-living-off-the-land-attacks</link>
                                                                            <description>
                            <![CDATA[ A greater focus on identity management and incident response is key for businesses as attackers adopt this new methodology ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NvZNXXrVXNiHAEvF2uch7L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 May 2026 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:description>                                                            <media:text><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:text>
                                <media:title type="plain"><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attacks are typically associated with data theft and extortion, but another threat can cause just as much damage. As geopolitical tensions rise across the globe, <a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>state-sponsored adversaries</u></a> are preferring to hide in systems, going unnoticed for months or years after the initial compromise. </p><p>To perform these so-called living off the land (LotL) attacks, attackers are <a href="https://www.itpro.com/security/cyber-attacks/cloudflare-warns-state-backed-hackers-are-weaponizing-legitimate-enterprise-ecosystems-as-living-off-the-land-attacks-surge"><u>weaponizing legitimate software</u></a> and infrastructure to lie in wait. This trend is seeing tactics shift away from data breaches to more sophisticated espionage and disruptive operations, according to a new report from Cloudflare. </p><p>Why are LotL attacks growing right now, and how should firms respond to this threat? </p><h2 id="living-off-the-land-attacks-long-term-campaigns">Living off the land attacks: long-term campaigns</h2><p>Cyber attacks usually take advantage of security weaknesses. However, living off the land attacks are different: They are growing in response to organizations strengthening their overall cybersecurity posture, Tony Fergusson, CISO in residence at Zscaler tells <em>ITPro</em>. “Organizations have made significant progress in their ability to detect threats and patch systems more effectively. Consequently, adversaries are being forced to be more stealthy to exploit data, and they’re doing this by leveraging legitimate tools and processes.”</p><p>With living off the land attacks, attackers deliberately avoid drawing attention to themselves by using existing and trusted tools and websites, rather than exploiting a <a href="https://www.itpro.com/security/everything-you-need-to-know-about-google-and-apples-emergency-zero-day-patches"><u>zero-day flaw</u></a> or introducing <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, says Fergusson. “They stay under the radar, blending in seamlessly with legitimate user activity, and mimic everyday operations so their presence goes unnoticed.”</p><p><a href="https://blog.cloudflare.com/2026-threat-report/" target="_blank"><u>Cloudflare’s 2026 threat report</u></a> describes a shift away from <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks"><u>brute force entry</u></a> towards high-trust exploitation, with adversaries actively targeting legitimate SaaS, IaaS, and PaaS tools such as <a href="https://www.itpro.com/business-operations/productivity/368041/25-google-workspace-tips-and-tricks-for-small-business"><u>Google Calendar</u></a>, <a href="https://www.itpro.com/hardware/storage/dropbox-is-adding-a-range-of-handy-new-ai-features-heres-what-users-can-expect"><u>Dropbox</u></a> and <a href="https://www.itpro.com/software/development/github-copilot-pricing-changes-usage-based-billing-explained"><u>GitHub</u></a> to camouflage malicious actions within normal enterprise activity. </p><p>This isn’t surprising, says Razvan Ionescu, head of offensive security services at Pentest-Tools.com. He describes how his team “consistently finds that organizations have invested heavily in signature-based detection and perimeter controls”. Yet the monitoring of legitimate administrative tooling, endpoint management platforms, cloud management consoles and scripting environments “remains thin”.</p><h2 id="state-sponsored-and-highly-targeted">State-sponsored and highly-targeted</h2><p>Living off the land attacks suit a certain type of adversary. The technique is especially attractive to “<a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers"><u>state-sponsored</u></a> and highly-targeted threat actors”, according to Dana Simberkoff, chief risk privacy and information security officer at AvePoint. </p><p>Rather than seeking immediate financial gain, attackers are aiming for <a href="https://www.itpro.com/security/uk-workers-are-shockingly-relaxed-about-selling-access-to-company-systems"><u>espionage</u></a>, strategic positioning and in some cases, <a href="https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy"><u>preparation for future disruption</u></a>. “Living off the land tactics allow these adversaries to <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid"><u>maintain access over long periods without drawing attention</u></a>,” Simberkoff explains.</p><p>Living off the land attacks allow nation states to collect strategic intelligence across diplomatic, military, economic, or technological targets, says Tracey Hannan-Jones, consulting director for information security at UBDS Digital. “By using pre-positioning, attackers gain access to critical systems, so disruption can be triggered during geopolitical tensions.” </p><p><a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>Supply chain attacks</u></a>, seeing adversaries compromising vendors to reach downstream targets, are “easy leverage”, warns Hannan-Jones.</p><p>Cloudflare’s report tracked four primary nation state adversaries over the past year: <a href="https://www.itpro.com/security/cyber-attacks/russian-ddos-whats-the-threat-to-businesses"><u>Russia,</u></a> <a href="https://www.itpro.com/security/china-has-almost-doubled-their-aggression-in-cyber-kevin-mandia-and-nicole-perlroth-warn-organizations-arent-waking-up-to-growing-apt-threats"><u>China</u></a>, <a href="https://www.itpro.com/security/two-us-nationals-sentenced-for-role-in-prolific-fake-worker-laptop-farms"><u>North Korea</u></a>, and <a href="https://www.itpro.com/security/cyber-attacks/beyond-wipers-iran-backed-cyber-attacks-and-the-threat-to-businesses"><u>Iran</u></a>. Each group approaches living off the land attacks differently based on its operational goals, Ionescu tells <em>ITPro</em>.</p><p>For example, China appears to have shifted from bulk data theft towards targeting legitimate cloud infrastructure for longer-term pre-positioning, with groups such as FrumpyToad using Google Calendar for command-and-control communication. </p><p>“The goal is to create a resilient architecture that remains nearly invisible to standard perimeter defences,” says Ionescu. “Rather than trying to exfiltrate data today, these attackers are establishing persistent footholds now to use during a future geopolitical event.”</p><h2 id="living-off-the-land-attacks-businesses-most-at-risk">Living off the land attacks: businesses most at risk</h2><p>Certain businesses are more at risk from living off the land attacks than others – especially in critical sectors and those holding data valuable to nation state adversaries. </p><p>Organizations with complex digital environments are particularly exposed, says Simberkoff. “Cloud-first enterprises, regulated industries, <a href="https://www.itpro.com/security/cyber-attacks/threat-posed-cyber-attacks-on-critical-national-infrastructure"><u>critical infrastructure</u></a> providers and companies embedded in large supply chains are at risk.”</p><p>The more identities, integrations and third party connections an organization has, the more opportunity attackers have to hide, warns Simberkoff. “Risk also increases for organizations that are strategically interesting to nation state actors, whether because of the data they hold or the role they play in a broader ecosystem.”</p><p>Government and defense are prime targets for living off the land attacks. “State actors look at pursuing intelligence and influence, accessing and stealing sensitive data, policy insight and information of geopolitical value, so they can use it against them,” says Hannan-Jones.</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/0abd7be2-413d-4665-8b77-7ed3e296a2a6/"></iframe><h2 id="stealthy-with-technology">Stealthy with technology </h2><p>Rapidly developing technology such as AI is<strong> a</strong>dding to the risk, allowing attackers to perform increasingly stealthy attacks.</p><p>The current shift is subtle. AI is making attacks “more refined”, says Simberkoff. “Instead of fully autonomous attacks, we’re seeing <a href="https://www.itpro.com/security/google-threat-intelligence-group-first-ai-zero-day-exploit-discovery"><u>AI used to support reconnaissance</u></a>, targeting and decision making. This helps attackers understand environments faster and choose techniques that look the most legitimate.”</p><p>The result is activity that increasingly resembles normal administrative behavior, which makes detection much more difficult, she warns.</p><p>Attackers can use AI to rapidly analyze public information such as organization charts, job postings, technical blogs, vendor documentation and <a href="https://www.itpro.com/business/a-cybersecurity-researcher-just-discovered-a-treasure-trove-of-leaked-accounts-more-than-184-million-logins-were-readily-available-online-with-google-meta-and-apple-users-affected"><u>leaked credentials</u></a> and infer likely tech stacks and access paths, according to Hannan-Jones. “This improves the precision of initial access attempts and reduces the need for noisy trial-and-error.”</p><h2 id="how-to-protect-your-business-from-living-off-the-land-attacks">How to protect your business from living off the land attacks</h2><p>Living off the land attacks are a concern, but there are some steps firms can take to boost their security. </p><p>Rather than trying to prevent compromise entirely, Simberkoff recommends focusing on “detecting misuse and limiting impact”. She advocates <a href="https://www.itpro.com/security/harnessing-ai-to-secure-the-future-of-identity"><u>strong identity governance</u></a>, least privilege access and “detailed logging of administrative activity”. </p><p>Ionescu underscores the importance of “understanding your own blast radius”. “Before asking what you’d detect, ask what an attacker with compromised admin credentials to your endpoint management platform, your identity provider or your cloud management console could do,” Ionescu advises. Most organizations haven’t mapped that explicitly.”</p><p>The second priority is closing the gap between “what your monitoring covers” and “where attackers actually operate”, says Ionescu. “Effective reconnaissance from an attacker’s perspective focuses on maintaining OPSEC and blending into normal traffic patterns and avoiding detection at the earliest stages of the kill chain. Your detection logic needs to match that: Anomaly detection on administrative actions, not just signature matching on known bad payloads.”</p><p>Robust <a href="https://www.itpro.com/security/why-incident-response-has-become-a-core-responsibility-for-msps"><u>incident response</u></a> is also key. Protecting your firm from living off the land attacks requires building operational playbooks for “quiet compromise”, says Hannan-Jones. “Many organizations will have <a href="https://www.itpro.com/security/ransomware/75-percent-of-uk-business-leaders-are-willing-to-risk-criminal-penalties-to-pay-ransoms"><u>playbooks for ransomware</u></a>, but very few are prepared for stealthy pre-positioning. Define what ‘suspicious admin activity’ looks like in your environment and create response runbooks for identity compromise, token theft and privileged account misuse.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hospital cyber attacks are increasingly hitting patient care ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hospital-cyber-attacks-are-increasingly-hitting-patient-care</link>
                                                                            <description>
                            <![CDATA[ New research shows only 14% are confident they can lose access to health records for 72 hours without risk to patients ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h29iyNnoQ54mDQLCyju4m5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/J5waBXzqJkYfdzZgreMJ3D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 May 2026 11:18:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/J5waBXzqJkYfdzZgreMJ3D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A patient being monitored in hospital ]]></media:description>                                                            <media:text><![CDATA[A patient being monitored in hospital ]]></media:text>
                                <media:title type="plain"><![CDATA[A patient being monitored in hospital ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/J5waBXzqJkYfdzZgreMJ3D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The main risk from hospital cyber incidents is no longer <a href="https://www.itpro.com/uk/security/data-breaches">data breaches</a> or IT disruption – it's direct threats to care delivery.</p><p>According to a Black Book Research survey of 284 European hospital <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> buyers, 82% rate their 2026 cyber attack concern as very high or extreme, while 74% believe their organization is likely or highly likely to face a major cyber event this year.</p><p>And, the researchers found, attacks are no longer viewed primarily as privacy events, compliance events, or IT disruptions – but as threats to the delivery of care.</p><p>"Europe's hospitals are operating in one of the most complex cyber-risk environments in the world: nationally connected health systems, public-sector capacity pressure, cross-border supplier ecosystems, aging infrastructure, accelerated cloud migration, strict regulatory accountability, and clinical operations that cannot go offline," said Doug Brown, founder of Black Book Research. </p><p>"Attackers know the pressure points. They are not only targeting data; they are targeting authentication, availability, recovery windows, third-party dependencies, and the fragile digital workflows that move patients through emergency departments, labs, imaging, pharmacy, theatres, ICUs, and discharge."</p><p>As a result, European hospital cybersecurity buying has shifted sharply from breach prevention toward clinical continuity. Two-thirds are investing in identity, IAM, PAM, SSO failover and break-glass access, and 57% in <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> recovery, immutable backup, and read-only clinical access.</p><p>Just over half are looking to network segmentation, zero trust, and ZTNA, 46% to incident-response retainers and crisis-response services, and 45% to third-party supplier and vendor cyber-risk management. Meanwhile, 37% are investing in medical device/IoMT security, and 29% in cyber range, downtime simulation, and resilience exercise services.</p><p>However, while 78% of survey respondents said their board receives general cybersecurity risk updates, only 31% receive cyber-resilience metrics tied to clinical continuity.</p><p>Only a quarter reported a full clinical downtime simulation within the past 12 months, and 32% said their organization had never conducted a full clinical downtime simulation, had only completed tabletop activity, or did not know when the last exercise occurred.</p><p>Worryingly, while 59% of respondents said they were confident that their hospitals could operate safely for 24 hours without core Electronic Health Record (EHR) access, that figure fell to 32% at 48 hours and just 14% at 72 hours.</p><p>"The 72-hour number should disturb every hospital board and ministry-level health technology leader in Europe. A hospital that can improvise through the first day of downtime is not necessarily resilient," said Brown. </p><p>"By day two and day three, medication reconciliation, laboratory turnaround, radiology workflow, identity access, pharmacy verification, transfer coordination, discharge planning, and backlog reconciliation become patient-safety risks. Cyber resilience is now an operational medicine issue."</p><p>The health sector is an increasingly popular target for cyber criminals, thanks to its critical nature. And many attacks have led to problems delivering patient care, including a 2024 <a href="https://www.itpro.com/security/cyber-attacks/thousands-of-procedures-canceled-at-london-hospitals-as-qilin-releases-blood-test-data">ransomware attack</a> on NHS pathology provider Synnovis, and, more recently, an <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack">attack</a> on medical technology firm Stryker being described by the firm as 'destructive, not ransomware'.</p><p>"In Europe, the cyber battleground has moved from the server room to the bedside," said Brown.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Industrial organizations under increasing fire as attackers target operational technology ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/industrial-organizations-under-increasing-fire-as-attackers-target-operational-technology</link>
                                                                            <description>
                            <![CDATA[ Firms continue to underestimate their operational technology exposure, NCC Group warns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kZJLdXsNYeqtQQymVtGzbc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YZjwEwYDJbKftH9VvKGnNZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 May 2026 11:26:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YZjwEwYDJbKftH9VvKGnNZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital technology toolkit symbol surrounded by email, internet, telephone, and communications symbols. ]]></media:description>                                                            <media:text><![CDATA[Digital technology toolkit symbol surrounded by email, internet, telephone, and communications symbols. ]]></media:text>
                                <media:title type="plain"><![CDATA[Digital technology toolkit symbol surrounded by email, internet, telephone, and communications symbols. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YZjwEwYDJbKftH9VvKGnNZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">Attacks on operational technology (OT)</a> are surging, according to new research, with industrial organizations the biggest target of <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>in every single month over the last year.</p><p>According to a new analysis from cyber security firm NCC Group, in the 12 months to March 2026, industrial organizations experienced 2,073 ransomware attacks, accounting for 30% of all ransomware activity. </p><p>Manufacturers of capital goods such as machine equipment and infrastructure were particularly hard-hit, accounting for 1,192 attacks. Within this industry, machinery was the most-targeted sub-sector, with 442 attacks, followed by construction and engineering with 394.</p><p>“Our data shows that many organizations continue to prioritize IT security while underestimating the exposure of their operational environments," said Ray Robinson, OT director at NCC Group. </p><p>"When OT systems are disrupted, the impact goes far beyond data loss - production can halt, essential services can be disrupted, and in some cases, lives can be put at risk.”</p><p>Governments worldwide are growing increasingly concerned about the issue. In the UK, <a href="https://www.itpro.com/policy-legislation/it-regulation/369630/uk-updates-nis-regulations-bringing-stricter-rules-for-msps">Network and Information Systems (NIS) Regulations</a> require operators of essential services to put proportionate technical and organizational measures in place to manage cyber risk across both IT and OT environments. </p><p>Meanwhile, the Cybersecurity Act and sector-specific guidance cover OT governance, incident reporting, resilience, and supply-chain security.  </p><p>“Regulators are increasingly clear that OT environments fall within scope of cyber resilience obligations, particularly where systems support essential services or public safety," said Katarina Sommer, global head of government affairs and analyst relations at NCC Group. </p><p>"Organizations that focus compliance efforts solely on IT risk are exposing themselves to operational, regulatory and safety consequences, so it’s key that organizations treat OT risks in the same way they approach IT security.”</p><p>Earlier this year, the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, along with US, Australian, Canadian, and European authorities, issued a new <a href="https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting"><u>guide</u></a> for OT owners and operators aimed at helping them integrate 12 security considerations into their procurement processes.</p><p>These include making sure that the product allows for security and safety logging, has strong authentication controls, protects data, is configured in a secure way by default, and is supported by established vulnerability management processes by the manufacturer.</p><p>“As cyber attackers increasingly target operational technology around the world, it has never been more vital for critical infrastructure operators to ensure security is baked into the systems they use," said Jonathon Ellison, NCSC director of national resilience and future technology.</p><h2 id="state-backed-hackers-targeting-operational-technology">State-backed hackers targeting operational technology</h2><p>Many attacks on OT systems come from nation state-affiliated actors, with the US Office of the Director of National Intelligence warning in its <a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf" target="_blank"><u>2026 </u><u><em>Annual Threat Assessment of the US Intelligence Community</em></u></a> that China, Russia, Iran, and North Korea will continue to target the sector. </p><p>US director of national intelligence, Tulsi Gabbard, said nation state-backed threat groups typically target these systems to collect intelligence, create options for future disruption, and also for financial gain. </p><p>"China and Russia present the most persistent and active threats and are continuing their R&D efforts. North Korea’s cyber program is sophisticated and agile," she said. </p><p>"In 2025 alone, North Korea’s cryptocurrency heists probably stole $2 billion which is helping to fund the regime, including further development of its strategic weapons programs."</p><p>Recent targets have included <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre">Jaguar Land Rover (JLR)</a>, US water and wastewater systems and electrical subsystems, and the Ukraine power grid.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘You deserved more consistent communication from us, and we didn’t deliver’: Instructure CEO issues apology over Canvas cyber attack disruption ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/instructure-ceo-apologizes-after-canvas-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Hundreds of academic institutions have been affected by the Canvas cyber attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pQmb4uvpmCLCWXSd2pvJLZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8ofhkDMhovJEPNPCVXNHs4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 May 2026 08:25:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8ofhkDMhovJEPNPCVXNHs4-1280-80.jpg">
                                                            <media:credit><![CDATA[ITPro/Ross Kelly]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Login page for the iOS application of academic management platform, Canvas, developed by Instructure.]]></media:description>                                                            <media:text><![CDATA[Login page for the iOS application of academic management platform, Canvas, developed by Instructure.]]></media:text>
                                <media:title type="plain"><![CDATA[Login page for the iOS application of academic management platform, Canvas, developed by Instructure.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8ofhkDMhovJEPNPCVXNHs4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The parent company behind academic management tool Canvas has issued an apology over disruption caused by a recent cyber attack, which impacted hundreds of institutions. </p><p>In a <a href="https://www.instructure.com/incident_update" target="_blank"><u>blog post</u></a> on 11 May, Steve Daly, CEO of Instructure, said the company plans to introduce sweeping changes in the wake of the breach, insisting that Canvas is “fully operational and remains safe to use”. </p><p>Daly added that Instructure will continue providing assistance and guidance for institutions affected by the cyber attack. </p><p>“Rebuilding trust takes time,” he said. “We’re going to earn it back through consistent action and honest communication. We’re in this for you and your community.”</p><p>The apology comes after hundreds of schools and universities across the UK, Canada, Australia, US, and New Zealand were <a href="https://www.itpro.com/security/cyber-attacks/universities-worldwide-still-struggling-with-fallout-from-canvas-cyber-attack"><u>disrupted by a cyber attack waged by the ShinyHunters threat group</u></a>. </p><p>The cloud-based academic management system is used by more than 8,000 institutions globally and has around 30 million active users.</p><p>Instructure first detected a breach on 1 May, but told customers it had taken steps to contain the incident. </p><p>In an advisory at the time, CISO Steve Proud warned data, including names, email addresses, student ID numbers, and messages between users had been impacted - which Daly confirmed in his recent blog post. </p><p>“This incident involved unauthorized access to part of our environment. The data fields involved include information like usernames, email addresses, course names, enrolment information and messages,” Daly wrote.</p><p>“Core learning data”, which includes course content, credentials, and student submissions, was not compromised in the breach, he added. </p><h2 id="canvas-cyber-attack-escalation">Canvas Cyber attack escalation</h2><p>While Proud noted that the incident had largely been contained, the incident was compounded when ShinyHunters waged a follow-up attack, which saw user login portals defaced with a ransom note. </p><p>ShinyHunters claims to have gained access to around 3.65TB of Instructure data during the attack, which includes upwards of 275 million records from over 8,800 institutions. </p><p>Analysis of ShinyHunters activity ranks it as one of the most notorious ransomware groups in recent years. The group has claimed responsibility for a slew of attacks on major organizations such as <a href="https://www.itpro.com/security/cyber-attacks/salesforce-issues-customer-alert-as-shinyhunters-group-claims-experience-cloud-breach">Salesforce</a>, Ticketmaster, and <a href="https://www.itpro.com/security/cyber-attacks/atandt-hacker-says-firm-paid-nearly-dollar400000-to-have-stolen-data-deleted">AT&T</a>. </p><p>According to Daly, the Canvas attack saw ShinyHunters exploit a support ticket vulnerability in its Free for Teacher environment. The company has moved swiftly to contain the breach. </p><p>“We temporarily disabled Free for Teacher while we complete a full security review,” he said. “We know that’s disruptive, and we didn’t make that call lightly. But keeping the entire Canvas platform secure has to come first.”</p><h2 id="we-didn-t-deliver">“We didn’t deliver”</h2><p>In his blog post, Daly said Instructure will continue providing updates and apologized for the company’s communication throughout. </p><p>“Over the past few days, many of you dealt with real disruption,” he wrote. Stress on your teams. Missed moments in the classroom. Questions you couldn’t get answered.”</p><p>“You deserved more consistent communication from us, and we didn’t deliver,” Daly added. “I’m sorry for that.”</p><p>The attack on Canvas comes during a busy period for academic institutions, with students in the midst of exams. </p><p>A slew of reports have detailed significant disruption for students on both sides of the Atlantic over the last week, with <a href="https://www.bbc.co.uk/news/articles/ce3pq0136eqo" target="_blank"><em>BBC </em>coverage</a> noting that Mississippi State University was forced to postpone exams. </p><p>As <em>ITPro reported</em>, students at the University of Oxford were unable to access papers and were forced to email lecturers for documents and results. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Universities worldwide still struggling with fallout from Canvas cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/universities-worldwide-still-struggling-with-fallout-from-canvas-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ ShinyHunters threat group has claimed responsibility for the attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L5NVaKG7ArwVkTWNR2rMPD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yYmusCNU2mdyZm2tibLqoV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 May 2026 10:10:41 +0000</pubDate>                                                                                                                                <updated>Mon, 11 May 2026 10:11:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yYmusCNU2mdyZm2tibLqoV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Student working on a laptop computer in a university library, with other students working at desks in background.]]></media:description>                                                            <media:text><![CDATA[Student working on a laptop computer in a university library, with other students working at desks in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Student working on a laptop computer in a university library, with other students working at desks in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yYmusCNU2mdyZm2tibLqoV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Universities across the world are still experiencing difficulties after a cyber attack on the Canvas academic platform caused widespread disruption for staff and students. </p><p>Canvas is a cloud-based academic management system developed by Instructure, and is used by more than 8,000 institutions globally and around 30 million active users. </p><p>Staff and students at universities in the US, Canada, Australia, and the UK were severely disrupted when the platform was breached, with a ransom note allegedly from the ShinyHunters threat group appearing on login portals.  </p><p>A host of UK-based academic institutions, including the Universities of Birmingham, Oxford, and <a href="https://information-services.ed.ac.uk/learning-technology/short-courses-platform/canvas-cybersecurity-incident-may-2026" target="_blank"><u>Edinburgh</u></a> were among those impacted in the breach.</p><p>Sources told <em>ITPro </em>that operations at the University of Birmingham are back online in the wake of the incident. However, the University of Oxford has warned students and staff that Canvas remains offline, with no confirmed date of return. </p><p><em>ITPro </em>approached both institutions for confirmation, but did not receive a response by time of publication. </p><h2 id="what-happened-with-the-canvas-cyber-attack">What happened with the Canvas cyber attack?</h2><p>Instructure initially confirmed a breach occurred on 1 May, but had taken steps to contain and remediate the incident. <a href="https://status.instructure.com/incidents/9wm4knj2r64z" target="_blank"><u>According to the company</u></a>, data exposed in the incident is believed to include “certain identifying information”, such as:</p><ul><li>Names</li><li>Email addresses</li><li>Student ID numbers</li><li>Messages between users</li></ul><p>Instructure’s chief information security officer (CISO), Steve Proud, <a href="https://status.instructure.com/incidents/9wm4knj2r64z" target="_blank"><u>said </u></a>the company found “no evidence that passwords, dates of birth, government identifiers, or financial information were involved”.</p><p>On 2 May, Proud noted that the incident had been largely contained. However, ShinyHunters reportedly breached the company in a follow-up attack, defacing Canvas login portals at hundreds of institutions. </p><p>Analysis of the incident by <a href="https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure" target="_blank"><u>Halcyon </u></a>noted that ShinyHunters injected an HTML file that altered login screens, displaying a warning that the group will publish stolen data on 12 May if the company fails to pay a ransom. </p><p>On its leak site, ShinyHunters claims to have gained access to a sizable amount of company data – spanning 275 million records from 8,809 institutions, amounting to 3.65TB. </p><p>ShinyHunters ranks among one of the most prolific ransomware groups in recent years, having claimed responsibility for <a href="https://www.itpro.com/security/cyber-attacks/salesforce-issues-customer-alert-as-shinyhunters-group-claims-experience-cloud-breach"><u>large-scale attacks on Salesforce customers</u></a>, as well as AT&T and Ticketmaster. </p><p>Researchers at Halcyon noted that the group does not employ encryption during attack, but instead operates under a “pay or leak” extortion model. </p><p>“The group maintains a loosely decentralized structure with operational overlap among Scattered Spider (UNC3944), LAPSUS$, and Scattered LAPSUS$ Shiny Hunters (SLSH),” researchers said in a <a href="https://www.halcyon.ai/ransomware-alerts/education-sector-in-the-crosshairs-shinyhunters-extortion-campaign-against-instructure"><u>blog post</u></a> detailing the incident.</p><p><em>ITPro </em>has approached Instructure for comment. </p><h2 id="critical-timing-for-shinyhunters">Critical timing for ShinyHunters</h2><p>The attack on Canvas comes at a critical time for institutions globally, with students preparing for exam season. </p><p>According to reports from <a href="https://www.bbc.co.uk/news/articles/ce3pq0136eqo" target="_blank"><u><em>BBC News</em></u></a>, Mississippi State University was forced to postpone exams on Friday due to the incident. A meteorology student told the broadcaster that students were nearing exam deadlines when the platform was taken down. </p><p>The university has been engaging with students via email and told students it was affected by a “nationwide security incident”. </p><p>Sources told <em>ITPro </em>that students at the University of Oxford have been experiencing similar difficulties, with some unable to access papers and having to email lecturers for attached documents. </p><p>Universities in a host of other US states, as well as in Canada, New Zealand, and Australia have also experienced significant disruption. </p><p>The University of Sydney, for example, told students that Canvas was unavailable on Friday and warned students not to log in. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Claude users beware, hackers are using a fake website to dupe developers and deliver malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/claude-users-beware-hackers-are-using-a-fake-website-to-dupe-developers-and-deliver-malware</link>
                                                                            <description>
                            <![CDATA[ 'Beagle' is deployed through a Dynamic Link Library (DLL) sideloading chain, and gives attackers remote access to the system ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QFnS23ZWZmYxkq5Kk2FrWd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 May 2026 09:32:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:description>                                                            <media:text><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:text>
                                <media:title type="plain"><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A fake Claude AI website is spreading a trojanized 'Claude‑Pro' Windows installer that secretly distributes a newly-identified backdoor.</p><p>The domain mimics the official site for <a href="https://www.itpro.com/software/development/claude-code-flaws-left-ai-tool-wide-open-to-hackers-heres-what-developers-need-to-know">Anthropic’s Claude AI tool</a>, and visitors who download the ZIP archive are sent a copy of Claude that appears to install and runs as expected. </p><p>However, <a href="https://www.malwarebytes.com/blog/scams/2026/04/fake-claude-site-installs-malware-that-gives-attackers-access-to-your-computer" target="_blank"><u>researchers at Malwarebytes</u></a> found it deploys a PlugX-like <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>chain, dubbed Beagle, that gives attackers remote access to the system.</p><p>The ZIP contains an MSI installer that installs to a path designed to mimic a legitimate Anthropic installation, complete with a reference to Squirrel, the update framework that real Electron-based applications like Claude use. </p><p>A tell-tale giveaway for developers is that this contains a misspelling: ‘Cluade’.</p><p>While the legitimate application runs in the foreground, the VBScript quietly copies three files from the SquirrelTemp directory into the Windows Startup folder.</p><p>"This is a textbook DLL sideloading attack, a technique catalogued by MITRE as T1574.002. NOVUpdate.exe is a legitimately signed G DATA antivirus updater. When it executes, it attempts to load a library called avk.dll from its own directory," researchers explained.. </p><p>"Normally, this would be a genuine G DATA component, but here the attacker has substituted a malicious version. Signed sideloading hosts like this can complicate detection because the parent executable may appear benign to endpoint security tools. </p><p>Victims are kept in the dark, because after deploying the payload files, the VBScript writes a small batch file called <em>~del.vbs.bat</em> that waits two seconds, then deletes both the original <a href="https://www.itpro.com/software/development/farewell-vbscript-microsoft-confirms-plans-to-begin-phasing-out-the-programming-language-later-this-year">VBScript </a>and the batch file itself. </p><p>"This means the dropper is gone from disk by the time a user or analyst goes looking for it. The only artifacts that persist are the sideloading files in the Startup folder and the running NOVUpdate.exe process," Malwarebytes said. </p><p>"The script also wraps the entire malicious payload section in an On Error Resume Next statement, silently swallowing any errors so that failures in the deployment do not produce visible error dialogs that might alert the victim."</p><h2 id="what-is-dll-sideloading">What is DLL sideloading?</h2><p>DLL sideloading is a technique favored by PlugX, a malware family that Sophos has been tracking for 14 years.</p><p>As the firm <a href="https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor" target="_blank"><u>points out</u></a>, PlugX has multiple variants and has been associated with several threat actor groups, meaning that attribution isn't clear-cut. </p><p>On top of this, ShadowPad, another backdoor employing DLL sideloading, has a number of code overlaps with PlugX, to the extent that it could be considered an evolution of it.</p><p>"Most of the techniques described here are relatively well known and have been seen before, from spoofing a legitimate installer website to side loading using a signed executable. Interestingly enough what is unusual is that it also installs a working copy of Claude which is rather large," said Max Gannon, cyber intelligence team manager at Cofense.</p><p>"The installation and usage of a program that is resource intensive can also help to disguise other ongoing background activity. The use of a legitimate program, cleanup utilities, running in memory, and persistence mechanisms all indicate that the threat actors distributing this malware intend it for long term persistence and use."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2026 in IoT attacks: the biggest threats so far and what businesses can do ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/iot-attacks-the-biggest-attacks-so-far-and-what-businesses-can-do</link>
                                                                            <description>
                            <![CDATA[ Internet of Things devices are more useful than ever – but security is still playing catch-up ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aFfZ6vAwc6aFdQZMPYvtkJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 May 2026 16:56:30 +0000</pubDate>                                                                                                                                <updated>Fri, 15 May 2026 15:45:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:description>                                                            <media:text><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>From industrial robots to fitness trackers, <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot"><u>Internet of Things (IoT)</u></a> devices track real-time data to underpin smart systems and allow for <a href="https://www.itpro.com/business/business-strategy/what-does-data-driven-mean-in-business"><u>data-driven</u></a> decision-making.</p><p>From the most advanced applications, such as <a href="https://www.itpro.com/technology/will-autonomous-robotics-leap-forward-in-2026">autonomous robots</a> on factory floors, to thermostats, security cameras, and even network-connected <a href="https://www.itpro.com/hardware/printers">printers</a>, IoT devices are widespread and hugely beneficial to businesses.</p><p>But along with their benefits, <a href="https://www.itpro.com/cloud/cloud-security/iot-security-strategy-an-arms-race-for-businesses"><u>IoT devices also introduce new risks</u></a> by expanding an organization’s perimeter and acting as easy entry points for enterprise systems. </p><p>Once attackers compromise a vulnerable device, they can steadily and <a href="https://www.itpro.com/security/stealthy-malware-the-threats-hiding-in-plain-sight"><u>stealthily</u></a> push further into an organization’s systems, bringing down critical infrastructure. Threat actors may also seek to take persistent control of IoT devices to form <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet"><u>botnets</u></a>. </p><p>An IoT botnet is a network of compromised IoT devices that attackers remotely manipulate to launch large-scale cyber attacks, typically in the form of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>distributed denial of service (DDoS) attacks</u></a>.</p><p>In October 2025, <a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/defending-the-cloud-azure-neutralized-a-record-breaking-15-tbps-ddos-attack/4470422" target="_blank"><u>Microsoft Azure was hit</u></a> with a record-breaking multi-vector, cloud DDoS attack that peaked at 15.72 Tbps and 3.64 billion packets per second. It targeted a single edge device in Australia and was later linked to the Aisuru IoT botnet, notorious for exploiting compromised home routers and surveillance cameras. Although the threat was neutralized, the attack goes to show the scale at which endpoint devices can be weaponized. The campaigns are often strikingly fast and unprecedented.</p><p>True to form, the attacks carry on in 2026. </p><p>In January, RondoDox, a <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros"><u>Linux</u></a>-based IoT botnet, moved swiftly to exploit a critical remote code execution vulnerability in HPE OneView, launching over 40,000 automated attacks that targeted government, financial, and industrial systems. The rapid assault led the US <a href="https://www.itpro.com/security/what-is-cisa"><u>Cybersecurity and Infrastructure Security Agency (CISA)</u></a> to list the flaw as a known exploited vulnerability. </p><p>Cybersecurity firm <a href="https://blog.checkpoint.com/research/patch-now-active-exploitation-underway-for-critical-hpe-oneview-vulnerability/#:~:text=Check%20Point%20Research%20identified%20active%2C%20large%2Dscale%20exploitation%20of%20CVE%2D2025%2D37164%2C%20a%20critical%20remote%20code%20execution%20vulnerability%20affecting%20HPE%20OneView"><u>Check Point’s investigation</u></a> into the botnet’s activity revealed it operated from a single Dutch IP address, highlighting the sophisticated nature of the attack. In terms of attack frequency, the United States saw the largest number of attacks, followed by Australia, France, Germany, and Austria.</p><p>The month of January also saw the Kimwolf botnet, the Android variant of the Aisuru <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, grow to over two million infected hosts. Most infections stemmed from vulnerabilities in residential proxy networks, giving attackers access to devices on internal networks. Prime targets included Android TVs and streaming devices with exposed Android Debug Bridge (ADB) services. </p><p>Later in March, a new malware strain called KadNap made its presence felt. <a href="https://www.lumen.com/blog/en-us/silence-hops-kadnap-botnet" target="_blank"><u>Identified by Black Lotus Labs</u></a>, the threat research and operations unit at Lumen, KadNap infiltrated over 14,000 edge devices with the majority being Asus routers. KadNap’s threat lies in its ability to enlist infected devices in the Doppelgänger proxy service, providing bad actors with a means to execute anonymous DDoS campaigns.</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/9ef7f02f-466f-4466-ae02-cbd718efa275/"></iframe><h2 id="law-enforcement-activity-and-shifting-attacks">Law enforcement activity and shifting attacks</h2><p><a href="https://www.itpro.com/security/cyber-crime/the-fbi-has-seized-the-ramp-hacking-forum-but-will-the-takedown-stick-history-tells-us-otherwise"><u>Law enforcement takedowns</u></a> of cyber groups are a recurring feature of the cybersecurity landscape and 2026 has been no exception to this rule. Agencies in the US, Germany‌, and Canada launched a <a href="https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks" target="_blank"><u>coordinated action</u></a> to quash a cluster of IoT botnets – Aisuru, KimWolf, JackSkid, and Mossad. Collectively, these botnets are estimated to have infected more than 3 million devices worldwide.</p><p>IoT attacks are relentless. They are, at best, a constant test of cyber vigilance.</p><p>Following the outbreak of the US-Iran war, <a href="https://www.itpro.com/security/cyber-attacks/beyond-wipers-iran-backed-cyber-attacks-and-the-threat-to-businesses"><u>Iranian hacking groups</u></a> have shifted their focus to surveillance cameras with internet connectivity in Israel and other Middle Eastern countries, according to Check Point researchers.</p><p>“Starting February 28, we observed a spike in targeting of IP cameras in several countries in the Middle East including Israel, UAE, Qatar, Bahrain, Kuwait and Lebanon, while also similar activity occurred against Cyprus,” Check Point stated in its recent <a href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/" target="_blank"><u>report</u></a>. </p><p>“The attack infrastructure we track combines specific commercial VPN exit nodes (Mullvad, ProtonVPN, Surfshark, NordVPN) and virtual private servers (VPS), and is assessed to be employed by multiple Iran-nexus actors.”</p><h2 id="how-to-secure-devices-on-your-network">How to secure devices on your network</h2><p>For enterprises, IoT is part of a growing attack surface that calls for stronger safeguards. Device authentication, <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a>, and <a href="https://www.itpro.com/security/cyber-crime/dns-security-101-safeguarding-your-business-from-cyber-threats"><u>DNS filtering</u></a> are some practical measures you can take to limit exposure to IoT attacks. </p><p>Regularly patching software and firmware adds another layer of security by preventing hackers from taking advantage of known vulnerabilities. Opting out of non-essential, optional, or rarely-used online features further expands your devices’ safety net. </p><p>Your passwords, by far, matter more than any other security setting. Remember, it takes just one rogue IoT device to spread malware like wildfire. The risks keep multiplying – especially when your watch, phone, and desktop share the same network. Using a different password for each device and application is a simple yet impactful shield against credential-based attacks. </p><p>More devices than ever are now smart and connected. Keeping your security just as smart by proactively securing your edge devices is an imperative, not an optional test.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware of emails threatening a code of conduct review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/beware-of-emails-threatening-a-code-of-conduct-review</link>
                                                                            <description>
                            <![CDATA[ A widespread phishing campaign has targeted tens of thousands of employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">77y4eje5T825eD49NpbPGa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 May 2026 09:34:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has <a href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/" target="_blank">issued an alert</a> over a large-scale credential theft campaign that uses lures centered around corporate codes of conduct.</p><p>The emails were related to internal compliance or regulatory issues, with display names such as 'Internal Regulatory COC', 'Workforce Communications', and 'Team Conduct Report'.</p><p>Subject lines included 'Internal case log issued under conduct policy' and 'Reminder: employer opened a non-compliance case log'.</p><p>The emails were sent using a legitimate email delivery service, likely originating from a cloud-hosted <a href="https://www.itpro.com/security/ransomware/ransomware-gangs-are-sharing-virtual-machines-to-wage-cyber-attacks-on-the-cheap-but-it-could-be-their-undoing">Windows virtual machine (VM)</a>. </p><p>The accusations and repeated time-bound action prompts created a sense of urgency, Microsoft researchers said. Similarly, the emails were based on polished, enterprise-style HTML templates with structured layouts and authenticity statements, making them appear more credible than most phishing emails.</p><p>The bodies of the messages claimed that a code of conduct review had been initiated, referenced organization-specific names embedded within the text, and instructed recipients to open a PDF attachment to see the materials of the case. </p><p>When clicked, users were first directed to one of two attacker-controlled domains - acceptable-use-policy-calendly[.]de or compliance-protectionoutlook[.]de. </p><p>The landing pages displayed a <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for">Cloudflare CAPTCHA</a>, presented as checking that the user was coming 'from a valid session', and that likely served as a gating mechanism to impede automated analysis and sandbox detonation. </p><p>According to Microsoft, the attack chain ultimately led to a legitimate sign-in experience that formed part of an <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AiTM)</a> phishing flow. </p><p>Unlike traditional credential harvesting, AiTM attacks intercept authentication traffic in real time, <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypassing multifactor authentication (MFA)</a>. </p><p>As a result, the attackers were able to proxy the authentication session and capture authentication tokens that could provide immediate account access. </p><p>"<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, and authentication abuse to remain effective against evolving security controls," the researchers warned. </p><h2 id="what-industries-are-affected">What industries are affected?</h2><p>Between 14 and 16 April this year, the Microsoft Defender Research team said it spotted a series of campaigns targeting more than 35,000 users across over 13,000 organizations in 26 countries. Most targets - 92% - were located in the US. </p><p>The campaign didn't focus on a single vertical but instead impacted a broad range of industries, most notably healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%).</p><p>Microsoft said organizations should review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365 to check for essential defenses and the ability to monitor and respond to threat activity. They should also invest in user awareness training and phishing simulations. </p><p>Enabling Zero-hour auto purge (ZAP) in Defender for Office 365 is advised to quarantine sent mail in response to newly acquired threat intelligence. Users are also urged to retroactively neutralize malicious phishing, spam, or <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>messages that have already been delivered to mailboxes.</p><p>It's also worth manually checking for, and purging, unwanted emails containing URLs and/or Subject fields that are similar, but not identical, to those of known bad messages.</p><p>Organizations should enable password-less authentication methods or use authenticator apps, researchers said, and strengthen privileged accounts with phishing resistant MFA.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/north-korean-hackers-are-duping-freelance-developers-with-fake-interviews-to-steal-cryptocurrency-and-deliver-malware-sophos-warns-the-nickel-alley-group-is-using-linkedin-upwork-and-fiverr-to-target-victims</link>
                                                                            <description>
                            <![CDATA[ A fake interview process uses coding tests and repo downloads to deliver malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VLS4GwTGb87a7DRvRmQrAm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Apr 2026 11:06:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">North Korean hackers</a> are targeting software developers in a new malware campaign that uses a fake interview process to steal cryptocurrency.</p><p>The campaign targets developers, especially those in the finance and technology industries, with profiles on freelance websites such as Upwork or Fiverr. It offers well-paid job opportunities and targets specific, high-value individuals.</p><p>It uses typosquatting or compromised legitimate npm repositories that victims are persuaded to inadvertently download and execute. </p><p>Researchers at the Sophos Counter Threat Unit have attributed the campaign to Nickel Alley, a threat group operating on behalf of the North Korean government. </p><p>"The group notoriously targets professionals in the technology sector by advertising fake job opportunities, deceiving prospective candidates through a fake job interview process, and ultimately delivering malware," the company said in an <a href="https://www.sophos.com/en-us/blog/nickel-alley-strategy-fake-it-til-you-make-it" target="_blank"><u>advisory</u></a>.</p><p>As part of its attacks, Nickel Alley often creates a fake LinkedIn company page to build credibility, with a coordinating <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>account for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>delivery. </p><p>The website homepage is generic and advertises 'tech talent' and managed service solutions. However, different domains are included on the LinkedIn company page and the GitHub account – which researchers noted shows inconsistency and lack of attention to detail. </p><h2 id="nickel-alley-ramping-up-operations">Nickel Alley ramping up operations</h2><p>The advisory from Sophos comes after a June 2025 X post warned of a campaign involving targeted emails promoting job opportunities at the fake Astra Byte Sync company. </p><p>The threat actors hadn't actually built the website at the time the emails were sent, meaning that the site simply displayed the hosting provider’s default page. </p><p>Over the last year, the group has used the popular <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix </a>tactic to deliver PyLangGhost RAT malware via fake job skills assessment tasks. </p><p>This involved the attacker-controlled web interface presenting an error informing the victim that they must run a command locally to fix the issue – a command that instead initiated a series of actions leading to PyLangGhost RAT. </p><p>It previously used a GoLang-based version known as GoLangGhost RAT. </p><p>Meanwhile, in October, Sophos analysts uncovered a targeted attack where the threat actors convinced a victim to download, or clone, the content of a GitHub repository and execute the code locally using the 'npm install' and 'npm start' commands. </p><p>The GitHub account masquerades as a software development company specializing in full stack web development and blockchain solutions, and contains links to an 'official' company website and a <a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks">fake LinkedIn company page</a>. </p><p>While the main aim of these attacks appears to be cryptocurrency theft, Sophos said the threat group has also made it clear that it plans to use initial access for further supply chain compromise or corporate espionage. </p><p>"Additionally, the threat group has strategically selected follow-on payloads based on profiling victims’ system. Software developers, especially those in the finance and technology industries, are at elevated risk due to Nickel Alley’s targeting profile," Sophos warned.</p><p>"Organizations should monitor command execution and network traffic that spawns from Node.js processes, as it may indicate malware retrieval. As a general security practice, organizations should encourage employees to report suspicious unsolicited social media or email-based recruitment contact."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/threat-actors-ditch-spray-and-pray-attacks-in-shift-to-targeted-exploitation</link>
                                                                            <description>
                            <![CDATA[ A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aXZoaaEbmpsecTfCYFaZAL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SDJ7bts4q7L4Ni743DoLPD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Apr 2026 11:19:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SDJ7bts4q7L4Ni743DoLPD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI ransomware and cyber crime concept image showing a digitized human eye observing networks with computer code.]]></media:description>                                                            <media:text><![CDATA[AI ransomware and cyber crime concept image showing a digitized human eye observing networks with computer code.]]></media:text>
                                <media:title type="plain"><![CDATA[AI ransomware and cyber crime concept image showing a digitized human eye observing networks with computer code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SDJ7bts4q7L4Ni743DoLPD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are shifting away from high-volume “spray and pray” threat campaigns toward more targeted attacks to “maximize impact against fewer victims”. </p><p>That’s according to new research from SonicWall, which recorded a 20% increase in the number of compromised organizations across the UK last year, even as broader <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>volumes fell by 87%. </p><p>SonicWall noted that smaller businesses are among those most likely to be targeted in “big game hunting” ransomware campaigns. Figures published by the firm show ransomware was used in 88% of <a href="https://www.itpro.com/security/smb-security-gaps-drive-new-opportunities-for-channel-players">SMB breaches</a>, for example. </p><p>That marks a stark contrast to larger enterprises, in which just 39% of cases involved ransomware. </p><p>“The UK data for 2025 highlights ransomware is evolving into Big Game Hunting,” said Spencer Starkey, executive VP for EMEA at SonicWall. </p><p>“On the surface, the 87% drop in overall attack volume might look like progress, but the reality is more alarming. More organisations are being successfully hit, and attackers are doing it with far greater precision."</p><h2 id="targeting-zombie-tech">Targeting “zombie tech”</h2><p>SonicWall noted that threat actors are prioritizing attacks on organizations with less mature security environments, but also those operating on outdated infrastructure, or “zombie tech”. </p><p>Researchers highlighted a single decade-old vulnerability in Hikvision IP cameras accounted for 67 million attempted cyber attacks in the UK alone last year, representing 20% of all intrusion activities observed by the firm. </p><p>This single case underlines the risks posed to enterprises by vulnerabilities flying under the radar, according to SonicWall – and it comes at a time when flaws are being exploited at an even quicker pace. </p><p>Around 80% of IT leaders said they believe their organisation can detect a breach within eight hours, yet SonicWall findings show attackers can remain undetected for an average of around 181 days. </p><p>Automated threats are also growing, posing even bigger challenges for security teams. AI-enabled attacks increased by 89% in 2025, researchers noted, and bots are now generating 36,000 scans per second, scouring the web for potential vulnerabilities. </p><p>“Zombie Tech continues to haunt UK networks. We’re seeing millions of attacks tied to a single long-known vulnerability, alongside continued exploitation of issues first disclosed more than a decade ago,” Starkey said. </p><p>“Threats are becoming more sophisticated at the top end, while remaining highly exploitable at the base and organizations must address both.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beyond wipers: Iran-backed cyber attacks and the threat to businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/beyond-wipers-iran-backed-cyber-attacks-and-the-threat-to-businesses</link>
                                                                            <description>
                            <![CDATA[ What’s the real risk to business in the US and UK during this critical situation? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZSqjakTNDPMf7AhXB8NrHC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Apr 2026 10:54:47 +0000</pubDate>                                                                                                                                <updated>Fri, 10 Apr 2026 10:57:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:description>                                                            <media:text><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the last few years, the threat from Iran-based cyberattacks has been quietly growing. The country was not previously seen as the most <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>capable nation state</u></a>, compared to its fellow <a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>CRINK</u></a> adversaries, but when Israel and the US hit Iran with airstrikes at the end of February, along with <a href="https://www.csis.org/analysis/how-will-cyber-warfare-shape-us-israel-conflict-iran" target="_blank"><u>cyber operations</u></a>, the threat began to escalate.</p><p>At the start of March, the UK <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Center (NCSC)</u></a> issued a <a href="https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east" target="_blank"><u>warning</u></a> that there “is almost certainly a heightened risk of indirect cyber threat” for organizations who have a presence or supply chains in the Middle East. </p><p>Then in mid-March, a suspected <a href="https://industrialcyber.co/medical/suspected-iran-linked-cyberattack-hits-medical-technology-giant-stryker-amid-middle-east-tensions/" target="_blank"><u>Iran-linked cyberattack</u></a> disrupted global systems at medical technology giant <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack"><u>Stryker</u></a>. </p><p>US-based security firm DigiCert <a href="https://www.washingtonpost.com/business/2026/03/29/iran-us-war-israel-data-centers-hacking/2fd3a7e0-2b24-11f1-a0f2-3ba4c9fe08ac_story.html" target="_blank"><u>has tracked</u></a> 5,800 cyberattacks mounted by 50 different groups tied to Iran. So what’s the real threat to business in the US and UK during the current critical situation?</p><h2 id="the-current-threat">The current threat</h2><p>From a tactical point of view, Iran’s plan is to “leverage global economic pain through any means”, according to Ian Thornton-Trump, CISO at Inversion6. </p><p>This includes cyber attacks to allow the regime to stay in power, he explains. “Iran aims to survive and extract concessions by weaponizing vulnerabilities in energy supply chains and chokepoints, with cyber operations as cost‑effective force multipliers.”</p><p>Adding to complexity, it isn’t always clear who is perpetrating attacks. Using proxies and cyber fronts helps Iran “maintain legal and attributional fog”, complicating retaliation and “keeping the country below thresholds that would unify great‑power opposition”, according to Thornton-Trump.</p><p>Handala – the group that <a href="https://www.aljazeera.com/news/2026/3/11/iran-linked-hackers-hit-medical-giant-stryker-in-retaliatory-cyberattack" target="_blank"><u>claimed it had attacked Stryker</u></a> in retaliation for US strikes – is widely regarded as a <a href="https://www.wired.com/story/handala-hacker-group-iran-us-israel-war/" target="_blank"><u>front for Iran's Ministry of Intelligence</u></a>. In the March attack, the hacking collective claimed to have wiped more than 200,000 devices and forced Stryker to shut down offices in dozens of countries. This attack is relevant to businesses, experts say.</p><p>“We need to be alert to how it weaponised Microsoft Intune, the same legitimate device management tool in widespread use in UK business, to trigger mass remote wipes,” says Rob Anderson, head of reactive consulting services at Reliance Cyber.</p><h2 id="covert-attacks">Covert attacks</h2><p>Wipers are a long-time tactic of Iran, and will continue to pose issues. But another thing to be aware of is how the nationwide internet outage since 28 February is impacting the cyber environment in Iran, according to the US <a href="https://www.csis.org/analysis/how-will-cyber-warfare-shape-us-israel-conflict-iran" target="_blank"><u>Center for Strategic and International Studies</u></a>. </p><p>The current blackout could “function as a defensive cyber tool for the regime to reduce the effectiveness of additional cyber intrusions and information operations from outside the country”, it said. At the same time, connectivity loss complicates attribution of future cyber incidents, obscuring whether disruptions originate from state-imposed controls or external cyberattacks.</p><p>Meanwhile, there is another immediate cyber threat from “the activation of long-standing access within Western networks”, according to Ruth Wandhofer, head of European markets at Blackwired.</p><p>For businesses across the globe, the real threat is “a long tail of proxy actors, diaspora hacktivists and pre-planted access that was quietly embedded in Western networks long before the first missile flew”, agrees Anderson. “These cells don't need Tehran online to act. Despite the blackout, approximately 60 hacktivist groups, including pro-Russian collectives activated outside Iran within days of the strikes.”</p><p>For years, Iranian-aligned actors have “quietly implanted <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, <a href="https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025"><u>compromised credentials</u></a> and maintained <a href="https://www.itpro.com/security/stealthy-malware-the-threats-hiding-in-plain-sight"><u>persistent footholds</u></a> in sectors such as healthcare, logistics, aviation and energy”, Wandhofer says.</p><p>At the same time, Iran-linked hackers are still using traditional techniques such as wiper malware, <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a>, credential theft and remote access tools. “But they are now deployed in coordinated campaigns – as seen in the Stryker attack,” says Wandhofer.</p><p>Iran could also ramp up its use of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>distributed denial of service (DDoS)</u></a> attacks, which are not necessarily sophisticated, but can be disruptive. </p><p>Travis DeForge, director of cyber security at Abacus describes how Iran-linked adversaries could hit public sector and <a href="https://www.itpro.com/security/cyber-attacks/threat-posed-cyber-attacks-on-critical-national-infrastructure"><u>critical services</u></a> with DDoS. “Not only is it extremely disruptive, they also get a big pay-off in propaganda value.”</p><h2 id="business-targets-for-iran-backed-hackers">Business targets for Iran-backed hackers</h2><p>Any public sector or critical infrastructure organization is a target for Iran, as is any company with a presence in the Middle East, according to DeForge. “That can extend to obvious supply chain links,” he adds.</p><p>Energy, healthcare, defense supply chains and financial services top the list. US defense contractors, government vendors and businesses with Israeli ties face “the sharpest direct exposure”, says Anderson. “But critical infrastructure such as hospitals, ports, water plants and railways are squarely in scope too.”</p><p>Iran amplifies kinetic pressure by “probing for cascading failure in digitally-interconnected energy and trade systems”, says Thornton-Trump, “These include port operations and shipping lanes to refineries and grids, accelerating market panic and political pressure on its adversaries.”</p><p><a href="https://attack.mitre.org/groups/G0049/"><u>OilRig</u></a> and other Iran‑linked groups show a persistent focus on energy, finance, telecoms and supply‑chain infiltration techniques, according to Thornton-Trump. He says threat intelligence overviews show evolution towards “<a href="https://www.itpro.com/security/cyber-attacks/vast-majority-breaches-enabled-preventable-gaps-identity-weaknesses-palo-alto-networks"><u>identity‑centric</u></a> cloud intrusions, wipers, and psychological ops aligned to crises”.</p><p>Businesses throughout the UK and US are both at risk from Iran cyber-attacks. However, the US is “the primary target by some distance”, says Anderson. “It carries the vast majority of identified asset exposure, with healthcare and government the most affected sectors.”</p><p>The UK's risk is more indirect, but shouldn't be dismissed. “With Iranian actors going after cloud identity infrastructure, the <a href="https://www.itpro.com/security/supply-chain-and-ai-security-in-the-spotlight-for-cyber-leaders-in-2026">supply chain risk</a> travels fast and doesn't respect geography,” Anderson warns.</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/d27ed604-4541-4b22-acce-3c5ab40e5fc9/"></iframe><h2 id="protecting-your-business">Protecting your business</h2><p>The risk of attack is growing, but most firms can boost resilience by ensuring foundational <a href="https://www.itpro.com/security/strategies-for-guarding-against-emerging-cyber-risks-and-invisible-threats">security hygiene</a>. “The to-do list isn't glamorous, but it is urgent,” according to Anderson. “Patch systems, keep firewalls current, enforce <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue"><u>multi-factor authentication</u></a> (MFA) and remove stale accounts. Scrutinise who holds privileged access to device management platforms such as Intune.”</p><p>With supply chains likely to be hit, the security of partner organizations must also be re-examined, with greater due diligence applied to third-party risk and access controls, according to DeForge.</p><p>As with any threat, businesses should “treat cyber conflict as a board-level operational risk”, says Wandhofer. Immediate priorities include “reducing <a href="https://www.itpro.com/business/digital-transformation/it-leaders-are-throwing-money-away-with-legacy-systems-enterprises-report-usd370-million-in-losses-each-year-due-to-outdated-tech"><u>reliance on legacy systems</u></a>, improving <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>patch management</u></a> and addressing <a href="https://www.itpro.com/software/open-source/86-percent-of-enterprise-codebases-contain-open-source-vulnerabilities"><u>known vulnerabilities</u></a> that <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do"><u>attackers frequently exploit</u></a>”, she says.</p><p><a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help"><u>CISOs</u></a> in energy, maritime, finance, and water should “assume targeted system probing during kinetic peaks,” says Thornton-Trump. He recommends MFA on remote access, removing publicly-exposed operational technology and eradicating <a href="https://www.itpro.com/security/thousands-of-it-administrators-are-using-admin-as-their-default-password"><u>default credentials</u></a>, as well as ensuring segmentation and “immutable backups”. </p><p>Firms should have an incident response plan in place and expect identity‑centric intrusions from Iran-linked attackers such as <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>APT</u></a> 33 and 34, Thornton-Trump warns. “Harden cloud and <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business"><u>identity and access management</u></a> and monitor for wiper precursors and proxy‑linked information ops designed to induce panic.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zephyr Energy hackers swiped £700,000 after redirecting a contractor payment ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/zephyr-energy-hackers-swiped-gbp700-000-after-redirecting-a-contractor-payment</link>
                                                                            <description>
                            <![CDATA[ Payment to a Zephyr Energy contractor was siphoned off, but the incident has been contained and new security measures implemented ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m6aEtDpzcUUX6suSr8UbWg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MY2WgJEVTBewbYoYNy8qFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Apr 2026 10:17:04 +0000</pubDate>                                                                                                                                <updated>Fri, 10 Apr 2026 10:45:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MY2WgJEVTBewbYoYNy8qFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Email security attack concept image showing mail symbol with a red warning symbol imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Email security attack concept image showing mail symbol with a red warning symbol imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Email security attack concept image showing mail symbol with a red warning symbol imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MY2WgJEVTBewbYoYNy8qFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Oil and gas firm Zephyr Energy has reported that one of its US subsidiaries has suffered a cyber intrusion that allowed the attackers to siphon off hundreds of thousands of pounds.</p><p>The London-headquartered company said the incident saw a contractor payment diverted to an account controlled by threat actors. The company confirmed around £700,000 was lost in the incident. </p><p>"Upon discovery of the incident, the company immediately notified the relevant law enforcement authorities and is working with the corresponding banks and consultants to attempt to recover the diverted funds," the company said in a <a href="https://polaris.brighterir.com/public/zephyr_energy/news/rns_widget/story/xo91ymx" target="_blank"><u>regulatory filing</u></a> with the London Stock Exchange.</p><p>Zephyr noted that the incident has been contained and IT systems have been thoroughly assessed by a leading cybersecurity consultancy. </p><p>Operations and corporate activities are continuing as normal, but its own internal IT teams are keeping a close eye on company systems. </p><p>"While Zephyr uses industry standard practices in relation to its technology and payment systems, additional layers of security have been implemented as a result of this attack," it added.</p><p>"The company's board of directors can confirm that the company has more than sufficient working capital to ensure that this isolated matter will not impact the company's ability to perform its ongoing operations."</p><h2 id="zephyr-energy-attack-what-happened">Zephyr Energy attack: What happened?</h2><p>There's no information on how the attack actually took place, but it has all the hallmarks of a <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> incident. </p><p>Via <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns, hackers typically gain access to email inboxes or accounting systems that enables them to change bank details during payment or invoice processing, in what's known as an <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AiTM)</a> attack.</p><p>Earlier this year, Microsoft <a href="https://www.itpro.com/security/cyber-attacks/microsoft-warns-of-rising-aitm-phishing-attacks-on-energy-sector" target="_blank"><u>warned</u></a> that AiTM campaigns targeting cloud collaboration platforms such as Microsoft SharePoint and OneDrive were on the rise. </p><p>The tech giant specifically highlighted energy companies among those at highest risk of targeting. </p><p>At the time, Microsoft’s Defender Research Team said attackers were abusing SharePoint file sharing services to deliver phishing payloads, and had succeeded in compromising a number of accounts. </p><p>In terms of mitigation, because the sign-in session is compromised, simply resetting passwords doesn't work. The company outlined a series of steps that organizations should take to mitigate risks, including:</p><ul><li>Using conditional access policies, especially risk-based access policies</li><li>Implementing continuous access evaluation</li><li>Investing in advanced anti-phishing solutions</li><li>Continuous monitoring for suspicious or anomalous activities</li></ul><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Hasbro hack so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/everything-we-know-about-the-hasbro-hack-so-far</link>
                                                                            <description>
                            <![CDATA[ The toy-maker keeps running thanks to business continuity plans, but nature of attack remains unclear ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pq7yt8ovg9sPv6isiVGHmW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TtnikUHZqpREnPmBqPrYie-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Apr 2026 11:55:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TtnikUHZqpREnPmBqPrYie-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Illuminated Hasbro sign at Comic-Con International in San Diego, California.]]></media:description>                                                            <media:text><![CDATA[Illuminated Hasbro sign at Comic-Con International in San Diego, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Illuminated Hasbro sign at Comic-Con International in San Diego, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TtnikUHZqpREnPmBqPrYie-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hasbro has had to pull systems offline after a hacking incident hit the toy maker. </p><p>The corporate website for Hasbro continues to be offline, with the company saying it may take weeks to recover, though its wider operations remain open. The famous company's brands include Play-Doh, Monopoly, and Peppa Pig, among many others. </p><p>Hasbro has yet to respond to <em>ITPro </em>for comment, but told the <em>BBC</em>: "While this is an unfortunate incident, Hasbro's business operations remain open. We have taken swift action to protect our systems and data."</p><p>Further details about the nature of the incident, the criminals behind the attack, and whether customer data has been accessed have yet to be released, with Hasbro saying its investigation was ongoing and includes an external security company. </p><h2 id="hasbro-hack-what-happened">Hasbro hack: What happened? </h2><p>In a <a href="https://www.sec.gov/Archives/edgar/data/46080/000004608026000013/has-20260401.htm" target="_blank"><u>filing</u></a> yesterday with the US Securities and Exchange Commission, Hasbro said it spotted unauthorized access to its network on 28 March.</p><p>"Upon discovery, the Company promptly activated its security incident response protocols, implemented containment measures, including proactively taking certain systems offline, and launched an investigation with the assistance of third-party <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>professionals," the company said in the filing. </p><p>Hasbro said its investigation was ongoing, and the full scope of the impact wasn't yet clear. As yet, Hasbro hasn't revealed whether customer data has been affected, but said it was working to "identify and review the files potentially impacted." </p><p>"The Hasbro incident is a clear reminder that global brands with expansive digital ecosystems are increasingly exposed, not just through customer platforms but across internal systems and supply chains," <a href="https://cybernews.com/news/hasbro-cyberattack-systems-offline-order-delays-recovery-weeks/"><u>said</u></a> Darren Williams, CEO of BlackFog. </p><p>Williams added that the biggest risk now is whether any data was stolen. </p><p>"For companies like Hasbro, the combination of customer data, licensing agreements, and intellectual property makes any stolen information highly valuable," he said. </p><h2 id="business-continuity">Business continuity</h2><p>Despite the corporate website remaining offline, the business continues to operate. </p><p>"The company has implemented and continues to implement business continuity plans to enable it to continue to take orders, ship product and conduct other key operations while it resolves this situation," Hasbro said in the filing. </p><p>"The need to run these interim measures may continue for several weeks before the situation is fully resolved and may result in some delays."</p><p><a href="https://www.linkedin.com/in/tdearing/"><u>Trevor Dearing</u></a>, director of critical infrastructure at <a href="http://www.illumio.com/"><u>Illumio</u></a>, said it's clear that Hasbro had <a href="https://www.itpro.com/strategy/29648/how-to-create-a-business-continuity-plan"><u>business continuity plans</u></a> in place, letting operations stay up and running even when some systems are taken offline. </p><p>"Last year, we saw the significant impact on the retail industry when businesses have halted operations," Dearing added. "Unlike many organizations, Hasbro has shown that having the right protocols and preparations in place means that a cyber incident doesn’t have to be a disaster."</p><p>Dearing added: "Security today is about knowing that breaches are inevitable, but disasters are optional. We need to see more of this kind of resilience, where essential services remain operational while the root cause is investigated and resolved. This realization is key to maintaining trust and continuity during a cyber attack."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The build pipeline is becoming the new frontline’: Axios npm compromise highlights growing software supply chain risks, experts warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-build-pipeline-is-becoming-the-new-frontline-axios-npm-compromise-highlights-growing-software-supply-chain-risks-experts-warn</link>
                                                                            <description>
                            <![CDATA[ Cyber criminals exploited a hijacked maintainer account to compromise one of the world's most widely used JavaScript libraries ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FtT83GNxmPjbmsmBPsDEnS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Apr 2026 10:32:11 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Apr 2026 14:13:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Attackers have compromised the npm account of Axios and published malicious versions to spread <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">remote access trojans (RATs)</a> to millions of developers.</p><p>Axios is a JavaScript HTTP client and is one of the most popular packages on npm, with more than 100 million weekly downloads. It manages requests between clients, such as browsers or Node.js apps, and servers.</p><p>On Monday, two malicious updates, <em>axios@1.14.1</em> and <em>axios@0.30.3</em>, were published, apparently through the compromise of the npm account of axios’ primary maintainer Jason Saayman. </p><p>The updates were identified almost immediately by several security firms and remained live for around two or three hours. The malicious versions introduce a dependency that executes during installation and deploys a cross‑platform remote access trojan (RAT) targeting macOS, Windows, and <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Linux</a>. </p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>communicates with a command and control (C2) server to retrieve platform‑specific second‑stage payloads, researchers noted. After execution, it deletes itself and replaces its own package.json with a clean version to evade forensic detection.</p><p>According to StepSecurity, the malicious dependency was staged 18 hours in advance, with separate payloads pre-built for all three operating systems. Both release branches were poisoned within 39 minutes of each other.</p><p>StepSecurity added that within two seconds of npm install, the malware was already calling home to the attacker's server before npm had even finished resolving dependencies -– making this one of the most operationally-sophisticated supply chain attacks ever documented against a top-10 npm package.</p><p>Because there were no git tags, any manual audit of the <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>repo would have failed to show anything was wrong.</p><h2 id="axios-npm-incident-highlights-supply-chain-dangers">Axios npm incident highlights supply chain dangers</h2><p>Ilkka Turunen, field CTO at Sonatype, said the latest npm-related incident highlights the growing dangers faced by developers globally, with threat actors ramping up attacks. </p><p>“Attackers have figured out they don’t need to compromise the code people trust if they can compromise the trust around it," Turunen said. </p><p>"In this case, the malicious capability was introduced through a staged dependency and designed to erase its own tracks, which made the attack harder to spot and slower to understand. That’s not just malware — it shows a more deliberate and mature playbook."</p><p>Anyone who installed either version before the takedown should assume their system is compromised and is advised to immediately quarantine hosts, implement their full incident response playbook, and rotate all exposed secrets. </p><p>It's not known who is responsible for the compromise, although many researchers are throwing suspicion on a North Korean actor known as UNC1069 that focuses on stealing cryptocurrency via centralized exchanges (CEX), software developers at financial institutions, tech firms, and venture capital funds. </p><p>The supply chain attack marks the latest in a string of attempts to exploit trust in <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> ecosystems, according to Upwind security researcher Avital Harel.</p><p>"The build pipeline is becoming the new frontline. Attackers know that if they can compromise the systems that build and distribute software, they can inherit trust at scale," Harel commented. </p><p>"Organizations should be looking much more closely at CI/CD systems, package dependencies, and developer environments, because that’s increasingly where attackers are placing their bets." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian sentenced to jail for his part in ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/russian-sentenced-to-jail-for-his-part-in-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Aleksei Volkov operated as an initial access broker, helping cybercrime groups, including the Yanluowang ransomware group ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AnhsFhZvLzDoJ6zSYYPReP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KpS95oHnuSP6NJZBCVzd7N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Mar 2026 11:06:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KpS95oHnuSP6NJZBCVzd7N-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Flag of russia]]></media:description>                                                            <media:text><![CDATA[Flag of russia]]></media:text>
                                <media:title type="plain"><![CDATA[Flag of russia]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KpS95oHnuSP6NJZBCVzd7N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A 26-year-old Russian citizen has been sentenced to 81 months in prison for his part in helping major <a href="https://www.itpro.com/security/26009/why-cybercrime-will-always-need-humans">cybercrime</a> groups to extort tens of millions of dollars.</p><p>Aleksei Volkov was involved in dozens of ransomware attacks throughout the US, causing more than $9 million in actual losses and over $24 million in intended losses. </p><p>He assisted major cybercrime groups, including the Yanluowang ransomware group, charging up to $1,000 for access to business networks, as well as a percentage of the profits.</p><p>He had at least eight confirmed victims, two of which paid hackers a total of around $1.5 million to unlock their systems; Volkov's cut of this was more than $256,000. </p><p>Volkov operated as an initial access broker, gaining unauthorized access to computer networks and systems, and then selling it on to other cyber threat actors such as ransomware groups. These groups used that access to encrypt victims' data and then made ransom demands, to be paid in Bitcoin, of between $300,000 and $15 million.</p><p>"The conspirators demanded that the victims pay them a ransom in cryptocurrency – sometimes in the tens of millions of dollars – in exchange for restoring the victims' access to the data and promising not to publicly disclose the hack or release victims' stolen data on a 'leak' website," said the Department of Justice. </p><p>"In some cases, the victims paid the ransom, and in others the conspirators posted the victims' confidential data on the leak site. If the victims paid the ransom, Volkov received a share of the money."</p><p>Between July 2021 and November 2022, Volkov helped the Yanluowang ransomware gang with initial access and also launched <a href="https://www.itpro.com/security/distributed-denial-of-service-ddos/367500/ddos-attacks-surge-to-record-numbers-in-2022">distributed denial-of-service (DDoS) attacks</a>. The victims included US banks, telecommunications companies, and engineering firms in Pennsylvania, California, Michigan, Illinois, Georgia, and Ohio.  </p><p>The Yanluowang ransomware group was first spotted in October 2021 by Symantec's Threat Hunter Team, and had been operational since August that year. But the group <a href="https://www.itpro.com/security/ransomware/369435/yanluowang-ransomware-leaks-suggest-pseudo-chinese-persona-revil-links">disbanded</a> at the end of 2022 when its leak site was hacked, and thousands of messages on the group's discussion channels were uploaded to a website. </p><p>After an investigation by the FBI, Volkov, also known as chubaka.kor, was arrested in Rome in January 2024, and extradited to the US. There, last November, he pleaded guilty to unlawful transfer of a means of identification, trafficking in access information, access device fraud, and aggravated identity theft, as well as two counts of computer fraud and conspiracy to commit money laundering.</p><p>He agreed to pay more than $9 million to his known victims to compensate them for their actual losses, and also to forfeit the equipment he used for his crimes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stryker hackers struck by FBI in domain seizure campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/stryker-hackers-struck-by-fbi-in-domain-seizure-campaign</link>
                                                                            <description>
                            <![CDATA[ The domain seizures come hot on the heels of Handala's devastating attack on the medical tech firm ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">F32BN9VnmASzRxdGYHJNwD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Mar 2026 11:45:23 +0000</pubDate>                                                                                                                                <updated>Fri, 20 Mar 2026 12:12:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:description>                                                            <media:text><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:text>
                                <media:title type="plain"><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has seized domains linked to Iranian cyber espionage activities, including those run by the group behind the Stryker attack. </p><p>Seized domains belonging to Handala – Handala-Hack and Handala-Redwanted – now feature notifications advising visitors that the sites have been seized by </p><p>The move by the FBI follows a <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack"><u>highly disruptive attack</u></a> by Handala on medical technology firm Stryker earlier this month. </p><p>Handala claimed to have wiped more than 200,000 systems, servers, and mobile devices, and to have extracted 50 terabytes of critical data.</p><p>Stryker develops a range of medical technology products, including surgical equipment, and has offices in 79 countries globally. </p><p>The incident had a particular impact on employees based in Ireland, according to reports, which represents one of the company’s largest innovation centers outside of the US. </p><p>The domain seizures follow a <a href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization" target="_blank"><u>warning</u></a> from <a href="https://www.itpro.com/security/what-is-cisa">CISA </a>that organizations should harden their endpoint management system configurations in the wake of the Stryker attack.</p><p>Enterprises should use principles of least privilege when designing administrative roles, enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene, the security agency noted. </p><p>Elsewhere, organizations were urged to configure access policies to require Multi Admin Approval in Microsoft Intune – software exploited by Handala during the Stryker attack.</p><h2 id="intensified-cyber-espionage-campaigns">Intensified cyber espionage campaigns</h2><p>Handala is one of a number of “hacktivist” groups that have emerged in recent years, and has been active since at least 2023. </p><p>Threat intelligence reports on the group show it often utilizes “wiper” <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>techniques to destroy company data – which it used during the attack on Stryker. </p><p>“The Handala Hacking Team is notable for employing a wide range of sophisticated tactics and techniques, including data theft, phishing extortion, website defacement, and destructive attacks leveraging custom wiper malware that targets Windows and Linux environments,” Cisco Talos and Splunk’s Threat Research Team said in a 2024 <a href="https://www.splunk.com/en_us/blog/security/handalas-wiper-threat-analysis-and-detections.html" target="_blank"><u>blog post</u></a>.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why cyber attacks on critical national infrastructure are such a huge threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/threat-posed-cyber-attacks-on-critical-national-infrastructure</link>
                                                                            <description>
                            <![CDATA[ Cyber attacks targeting national infrastructure are becoming increasingly prevalent – what are the underlying goals behind these attacks and how damaging are they? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8jZojNPg4FWVV7YnuaHZci</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Mar 2026 13:21:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:description>                                                            <media:text><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:text>
                                <media:title type="plain"><![CDATA[A digital display of the world map, in shades of blue and outlined in red with labels to denote threats, representing attacks on critical national infrastructure (CNI).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iMQq7qLmeZD4jQtCkC2btd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attackers are increasingly targeting <a href="https://www.itpro.com/infrastructure/data-centres/data-centers-finally-get-critical-national-infrastructure-designation-in-the-uk"><u>critical national infrastructure (CNI)</u></a>, such as energy grids, water supply, or telco networks. Although the target may only be a small part of a country’s infrastructure network, the goal is often far more wide reaching and such attacks can pose a significant security risk.</p><p>National infrastructure comprises the essential elements, such as power, transport and water, that a country needs in order to function and ensure the well-being of the population. Examples include high-voltage power transmission cables, telecommunication networks, hospitals and transport hubs, such as airports.</p><p>A recent example of an infrastructure attack was the cyberattack against <a href="https://www.itpro.com/security/cyber-attacks/a-cyber-attack-has-caused-chaos-at-airports-across-europe-heres-everything-we-know-so-far"><u>Collins’ ARINC cMUSE check-in and boarding software</u></a> on Friday, 19 September 2025. As a consequence of the cyberattack, passengers were unable to board planes at several airports throughout Europe.</p><p>The ultimate goal of the attack was not taking down Collins Aerospace, but the widespread disruption that it caused. By disrupting the life of the civilian population, malicious actors are making people feel vulnerable, causing them to question the ability of the government to safely run the country.</p><p>“Cyber attacks can go in various directions to create unsecureness in a population, so that we don't trust the things that work all the time,” says Kim Larsen, chief information security officer at Keepit and a former delegate for the Danish government in NATO and EU cybersecurity committees. </p><p>“We've seen ships pulling anchors over cables in the Eastern Sea, and that is probably most likely to test infrastructure. We have also seen <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>distributed denial of service attacks</u></a> towards critical infrastructure; tax department and defense departments around Europe – that is probably to test how stable we are on the more physical side.”</p><h2 id="cyber-attacks-for-widespread-disruption">Cyber attacks for widespread disruption</h2><p>The attacks targeting national infrastructure are varied and multifaceted. While physical attacks on CNI could see malicious groups sever undersea internet cables or use drones to disrupt the airspace above airports, cyber attacks on CNI have often come in the form of DDoS attacks that cause a critical server to fail, or <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware attacks</u></a> such as the <a href="https://www.itpro.com/security/ransomware/359466/colonial-pipeline-ransomware-attack"><u>2021 breach of Colonial Pipeline</u></a>. In many ways, these attacks are an escalating arms race between the attackers and security teams.</p><p>In recent years, hackers have been exploiting the fact that more infrastructure has become either directly connected to the internet or indirectly linked to it in some way.</p><p>“We saw a lot of information gathering before the <a href="https://www.itpro.com/security/ransomware/off-the-shelf-ransomware-is-spurring-a-new-era-in-the-ukraine-war"><u>Ukraine war</u></a> started, but when the attack went physical, cyber attacks lowered for quite a long time,” says Larsen. “It's now increasing again, and has been for quite a while with hybrid attacks.”</p><p>The anonymizing nature of the internet means that the identities of the attackers or where they are located may never be known for certain – unless the attackers come forward and reveal themselves. Most often it is <a href="https://www.itpro.com/security/cyber-attacks/cloudflare-warns-state-backed-hackers-are-weaponizing-legitimate-enterprise-ecosystems-as-living-off-the-land-attacks-surge"><u>state-sponsored hacking</u></a>, with <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware groups</u></a> and other threat actors based in <a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>CRINK</u></a> behind many <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threats (APTs)</u></a>.</p><p>“In the world of cyber it's always diffused, because you can hide yourself. I remember back in the day that there were a lot of attacks to critical infrastructure coming from an IP address in Beijing,” says Larsen. </p><p>“Well, if it's Chinese, they are probably more than clever enough to actually shadow their trace. On the other hand, sometimes an attack angle is to show who you are and that you're capable of doing something.”</p><p>The geopolitical sphere is currently rife with tensions due to the number of military actions taking place. Although the UK is not at war, neither is it at peace. The term ‘unpeace’ is sometimes used to describe a period of strife and dissension.</p><p>Almost all (95%) of CNI organizations in the UK experienced a cyber attack in 2024, according to cybersecurity firm Bridewell, with CNI respondents reporting low confidence in their ability to repel <a href="https://www.itpro.com/security/securing-the-supply-chain-why-zero-trust-and-recovery-readiness-are-non-negotiable"><u>supply chain attacks</u></a>. It’s hard to track the exact scale of attacks on CNI, as firms can be reluctant to publicly disclose incidents and when high-risk vulnerabilities are discovered, they may be kept private for reasons of national security.</p><p>It’s sometimes unclear whether critical national infrastructure is being disrupted due to cyber attacks or simply failures in the network. For example, a power cut might be due to a substation fault or a cyber attack. Initial reports of the <a href="https://www.itpro.com/security/cyber-attacks/blackouts-in-spain-and-portugal-could-be-a-cyber-attack"><u>blackouts in Spain and Portugal</u></a> suggested they were caused by a cyber attack and <a href="https://www.itpro.com/security/spain-reconsiders-possibility-of-hackers-causing-blackouts"><u>Spanish authorities investigated the possibility</u></a>. However, it was subsequently confirmed the incident occured due to a surge in voltage with which grid was unable to cope.</p><p>Ultimately, what infrastructure attacks are doing is causing disruption. When amplified by coverage on social media, this can have the secondary effect of destabilizing business operations and government.</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/b6147684-d254-40d8-9409-5f76f5abd749/"></iframe><h2 id="responding-to-the-rising-threat">Responding to the rising threat</h2><p>The escalating cyber attacks against national infrastructure has driven the UK’s <a href="https://www.npsa.gov.uk/"><u>National Security Protection Agency (NSPA)</u></a> to identify CNI in particular need of protection. These include telecommunications, emergency services, energy, healthcare, transportation and water. The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a> is responsible for the cybersecurity of CNI. </p><p>The privatization of certain aspects of national infrastructure, such as telecommunication providers and water companies, adds a further regulatory complication. Information sharing and collaboration between organizations are vital in order to better protect national infrastructure against cyberattacks, and in some countries it’s possible to operate this as a more centralized operation than in others.</p><p>“Governments need to be transparent on the threats that they actually see, and to segment what is true, what is not true and what is serious,” says Larsen. “Then they can work with the industry on getting a solid cybersecurity trusted framework.”</p><p>A holistic approach to security, combining physical security with cybersecurity, creates a more robust security posture. For example, if high-voltage power-transmission cables are buried underground, then it is far more difficult for them to be physically interfered with.</p><p>Redundancy measures, either on-site or off-site, may be mandated for certain types of infrastructure. Any new national infrastructure <a href="https://www.itpro.com/infrastructure/data-centres/data-centers-finally-get-critical-national-infrastructure-designation-in-the-uk"><u>including data centers</u></a> needs a secure by design approach, with cybersecurity teams involved from the outset. Meanwhile, the security of existing infrastructure needs to be thoroughly tested and reviewed, with a risk-informed approach to enhancement of defenses if required.</p><p>Wars and heightened geopolitical tensions mean that cyber attacks against CNI are likely to become more frequent in the coming years. If threat actors succeed in causing major disruption to national infrastructure, the impacts will be felt widely. To mitigate against this, relevant organizations need to carry out risk assessments to highlight areas where improved security is needed.  </p><p>With mitigations where required, and an appropriately robust security posture in place, cyber attacks against CNI will be less damaging. For new infrastructure projects, it is now more important than ever to consider physical and cybersecurity, and the interface between these, from the outset.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'It's destructive, not ransomware': Security experts weigh in on motivation behind Stryker cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The attack on medical tech company Stryker has severely impacted operations globally ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uAEPy85heifUdKbTPUHP9Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/So4cFobEWd4kjqH4MbFRyA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 12:37:46 +0000</pubDate>                                                                                                                                <updated>Thu, 12 Mar 2026 12:38:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/So4cFobEWd4kjqH4MbFRyA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of medical technology company Stryker pictured on a building facade in Warsaw, Poland.]]></media:description>                                                            <media:text><![CDATA[Logo of medical technology company Stryker pictured on a building facade in Warsaw, Poland.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of medical technology company Stryker pictured on a building facade in Warsaw, Poland.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/So4cFobEWd4kjqH4MbFRyA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have warned that the cyber attack on Stryker signals a step change in politically-motivated attacks, with a particular focus on destruction rather than extortion. </p><p>Operations at the medical technology firm have been severely impacted in a cyber attack claimed by Iranian-linked threat group, Handala. The group claims to have wiped thousands of systems across the company’s global operations and stolen around 50 terabytes of data. </p><p>“In this operation, over 200,000 systems, servers, and mobile devices have been wiped and 50 terabytes of critical data have been extracted,” the group claimed in a statement online. </p><p>Stryker develops a range of products, including surgical equipment, neurotechnology, and orthopedic implants, with offices in 79 countries and over 50,000 employees worldwide. </p><p>The impact of the attack has been felt globally, with reports suggesting operations in Ireland have been severely disrupted. </p><p>Stryker employs around 4,000 employees in Cork, which the company <a href="https://www.stryker.com/ie/en/about/our-locations/cork.html" target="_blank"><u>describes </u></a>as its “biggest innovation and manufacturing hub outside the US”.</p><p>"Nobody can work,” a source told the <a href="https://www.irishmirror.ie/news/irish-news/stryker-cyber-attack-thousands-irish-36850017" target="_blank"><u><em>Irish Mirror</em></u></a>. “The entire company has been brought to a standstill”</p><h2 id="stryker-confirms-attack">Stryker confirms attack</h2><p>Stryker has <a href="https://www.linkedin.com/posts/stryker_a-message-to-our-customers-stryker-is-experiencing-activity-7437540918695706625-ZeNo/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAALaFlIB3G0zftVnXqlA-AAtC99kdJhiuxs" target="_blank"><u>confirmed </u></a>it is dealing with “global network disruption” across its Microsoft environment, which is believed to be the entry point for the group. </p><p>One employee told <a href="https://www.bleepingcomputer.com/news/security/medtech-giant-stryker-offline-after-iran-linked-wiper-malware-attack/" target="_blank"><u><em>BleepingComputer </em></u></a>that staff have been ordered to remove work-related applications from personal devices, in particular the company portal for mobile device management software Microsoft Intune and Microsoft Teams. </p><p>Targeting of Microsoft products is a common tactic for Handala, which has been active since at least December 2023. </p><p>A 2024 threat intelligence report from Cisco Talos and Splunk’s Threat Research Team specifically highlighted the group’s activities on this front, typically using “wiper” <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> to destroy company data. </p><p>“The Handala Hacking Team is notable for employing a wide range of sophisticated tactics and techniques, including data theft, phishing extortion, website defacement, and destructive attacks leveraging custom wiper malware that targets Windows and Linux environments,” the duo said in a <a href="https://www.splunk.com/en_us/blog/security/handalas-wiper-threat-analysis-and-detections.html" target="_blank"><u>blog post</u></a>. </p><h2 id="the-target-matters">“The target matters”</h2><p>Stryker noted in its statement that there’s “no indication of ransomware” involved in the attack. However, this aspect of the attack provides an insight into the underlying motivations, according to Huntress <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>Chris Henderson. </p><p>In this instance, the attack is “destructive, not <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>” and is a politically-motivated attack aimed solely at causing widespread disruption. </p><p>“The target matters. Stryker manufactures critical medical devices used in operating rooms and ICUs worldwide,” Henderson said. </p><p>“When a supplier of this scale goes offline, it doesn't just impact their employees; it creates ripple effects across hospitals, surgical centers, and healthcare providers who depend on their equipment and support infrastructure.”</p><p>Skip Sorrells, Field CTO-CISO at Claroty, echoed Henderson’s comments, noting that even prior to the Iran conflict hacktivist activities have been ramping up globally.</p><p>Security agencies including <a href="https://www.itpro.com/security/what-is-cisa">CISA </a>and the UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> have issued repeated warnings over the rise of hacktivist groups over the last two years. </p><p>In particular, pro-Russian hacktivist groups identified by the NCSC were found to be <a href="https://www.itpro.com/security/cyber-attacks/ncsc-names-and-shames-pro-russia-hacktivist-group-amid-escalating-ddos-attacks-on-uk-public-services">targeting local government agencies and critical infrastructure</a>. Critical sectors like healthcare are now firmly in the crosshairs, according to Sorrells. </p><p>“Attacks like this unfortunately aren’t surprising,” he said. “Even before the latest geopolitical tensions, hacktivist activity targeting healthcare and other critical infrastructure had been steadily increasing, and that trend makes organizations like medical device manufacturers and hospitals more likely to be caught in the crossfire.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The rise of PhaaS: what businesses should know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-rise-of-phaas-what-businesses-should-know</link>
                                                                            <description>
                            <![CDATA[ With phishing as a service (PhaaS) on the rise, which new kits should firms know about and how can leaders avoid being caught out? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZJmDoSAx6ZaBbWr73hedmG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 12:35:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:description>                                                            <media:text><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:text>
                                <media:title type="plain"><![CDATA[A cartoon graphic depicting phishing as a service, shown as bugs, keys, fingerprints, bitcoins, shields, eyes, etc surrounding a fish hook. All are placed on a light grey background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vwb8TLBgSxGdDgEKAcxuKZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Phishing is a simple tactic, but it works. It’s therefore no surprise that phishing as a service (PhaaS) –  which allows adversaries to perform the attacks at scale – is on the rise.</p><p>The number of <a href="https://www.itpro.com/security/phishing/phishing-as-a-service-kits-growth-2025-barracuda"><u>known PhaaS kits</u></a> doubled last year, according to new research. Across the year, 90% of high-volume phishing campaigns leveraged PhaaS kits, <a href="https://blog.barracuda.com/2026/01/07/threat-spotlight-phishing-kits-evolved-2025" target="_blank"><u>researchers at Barracuda</u></a> found. The new kits are sophisticated, evasive and stealthy. </p><p>Which PhaaS kits should firms know about, and how can businesses avoid being caught out by phishing attacks? </p><h2 id="phaas-kits">PhaaS kits</h2><p>The fast-growing availability of PhaaS kits gives cybercriminals with limited technical capabilities the means to breach companies. Using PhaaS kits, the volume of attacks adversaries are able to deliver is “astounding”, says Harry Mason, head of client services at Mason Infotech. </p><p>Of the notable kits now available, he calls out GhostFrame, which creates an invisible iframe on webpages to hide malicious activity. “By the time this was discovered in December, it had already been used in over a million attacks.”</p><p>Tycoon 2FA and Typhoon are also prominent examples of PhaaS. Other kits include Quantum Route Redirect, which steals <a href="https://www.itpro.com/desktop-software/19337/office-365-review"><u>Microsoft 365</u></a> credentials, and <a href="https://www.itpro.com/security/phishing/whisper2fa-phishing-attacks-microsoft-365-barracuda"><u>Whisper 2FA</u></a> that steals <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue"><u>multi-factor authentication</u></a> (MFA) codes in real time.</p><p>Another prominent kit is Greatness, which targets Microsoft 365 credentials through <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa"><u>adversary-in-the-middle</u></a> techniques. </p><p>A new phishing kit named Spiderman, identified in December 2025, targets customers of major European banks. It works via fraudulent login pages that “perfectly mimic” legitimate financial institutions to steal login credentials, according to Matt Hull, global head of threat intelligence at NCC Group.</p><p>At the same time, an adversary-in-the-middle platform named Mamba 2FA has grown in popularity. Hull says Mamba 2FA has been on the rise since late 2023 and is noted for its operational efficiency.</p><p>Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University, highlights <a href="https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web"><u>EvilProxy</u></a> as a kit that bypasses MFA using reverse-proxy methods. “These platforms provide customer support for cybercriminals, as well as comprehensive dashboards, automated credential harvesting and real-time victim tracking,” he says.</p><p>The sale and distribution of PhaaS offerings typically takes place through Telegram channels and private groups, says Hull. “This allows PhaaS operators to share updates and set up user-friendly cryptocurrency payment systems using automated bots.”</p><h2 id="stealing-credentials">Stealing credentials</h2><p>PhaaS kits are primarily used to steal credentials and hijack authenticated sessions, allowing attackers to take over email, cloud and business systems. “While often framed as ‘email phishing’, the real impact is account compromise, which can lead to business email compromise, financial fraud, data theft – and in some cases <a href="https://www.itpro.com/security/ransomware/the-top-ransomware-trends-for-businesses"><u>ransomware access</u></a>,” Hull says.</p><p>Increasingly, PhaaS is being deployed for initial access operations, where stolen credentials are sold to ransomware groups. “Alternatively, these credentials can be used to establish persistent access within corporate networks,” adds Curran.</p><p><a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it"><u>MFA bypass</u></a> has become a standard feature, with kits employing adversary-in-the-middle techniques to intercept one-time codes in real-time, he <em>tells ITPro</em>.</p><p>PhaaS is also becoming part of <a href="https://www.itpro.com/security/securing-the-supply-chain-why-zero-trust-and-recovery-readiness-are-non-negotiable"><u>supply chain attacks</u></a>, where compromised vendor credentials provide entry points into multiple downstream organizations, according to Curran. “Session hijacking capabilities allow attackers to maintain access even after passwords are changed.”</p><h2 id="phaas-targets">PhaaS targets</h2><p>No one is immune from the cybercriminals harnessing PhaaS. Experts say phishing attacks can impact any firm, regardless of size. </p><p>There's a common misconception, especially among SMBs, that they’re “not big or important enough to be a phishing target”, says Christophe Tafani-Dereeper, staff cloud security researcher and advocate at Datadog. “But in our experience, phishing attacks are ubiquitous, targeting organizations at almost every level. Nearly everyone will receive one at some point.”</p><p>PhaaS kits are “indiscriminate by design”, agrees Curran. Yet he acknowledges that some sectors face an increased risk. For example, healthcare and professional services firms are prime targets due to their valuable data and transaction capabilities. </p><p>At the same time, the subscription model of PhaaS means attackers can maintain campaigns across multiple sectors simultaneously, testing <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a> approaches until they find a successful method. “Any organization with an online presence and valuable data or financial access is now within reach of these industrialised phishing operations,” Curran warns.</p><h2 id="phaas-evolution">PhaaS evolution</h2><p>In the future, phishing attacks will become even easier for criminals as PhaaS platforms are supercharged by technology such as <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a>.</p><p>Cybercriminals are already leveraging AI to hide their phishing websites, says Tafani-Dereeper. “When someone who's not a targeted victim visits the phishing website, they are shown a legitimate-looking page masquerading as a local business,” he explains. “We've seen dozens of variations across a large number of domains, which makes us believe this is tied to one or multiple PhaaS platforms.”</p><p>Further down the line, Curran predicts AI-generated content that adapts in real-time based on victim interactions. “This would be able to create convincing conversational phishing attempts via multiple channels simultaneously.”</p><p>He thinks <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected"><u>deepfake technology</u></a> will be used more widely, allowing attackers to impersonate individuals through voice and video with “alarming authenticity”.</p><p>In the PhaaS industry itself, Mason predicts the same kind of developments seen in SaaS markets: “An introduction of 'tiered' subscriptions for kits, better customer service and, in some areas, planned obsolescence to make the act of committing cybercrime more expensive.”</p><p>The business model could also shift towards profit sharing arrangements rather than subscriptions, aligning incentives between kit developers and attackers, he adds. “Integration with other criminal services such as automated money laundering and ransomware deployment will create comprehensive ‘attack-as-a-service’ ecosystems.”</p><h2 id="business-action">Business action</h2><p>Stealthy and sophisticated PhaaS kits pose a growing threat, but experts say the solution is fairly simple: a combination of technical and human-centric security measures. </p><p>As a foundational defense, Tafani-Dereeper recommends implementing “phishing-resistant authentication methods” in critical systems such as Microsoft 365 or Google Workspace. </p><p>For example, <a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2"><u>Microsoft Entra ID passkeys</u></a> and <a href="https://support.google.com/a/answer/13529161?hl=en"><u>Google Workspace passkeys</u></a> will help to enhance security and “make the user experience more seamless”, he says. </p><p>Alongside this, regular employee training is essential. Rather than focusing on the area once a year, ongoing simulations using current PhaaS tactics should be used to build genuine <a href="https://www.itpro.com/security/how-businesses-can-make-cybersecurity-training-stick"><u>recognition skills</u></a>, Curran advises. “Ultimately, organizations must recognize that technical defences alone are insufficient against industrialised social engineering. Building a security-conscious culture is equally critical.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Salesforce issues customer alert as ShinyHunters group claims Experience Cloud breach  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/salesforce-issues-customer-alert-as-shinyhunters-group-claims-experience-cloud-breach</link>
                                                                            <description>
                            <![CDATA[ Threat actors are using a modified version of the AuraInspector tool, according to Salesforce ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AP9dvCZ46ZYq4paqA5QGE9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QbKo3kcYEzKDffRkPHvNzc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Mar 2026 11:20:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QbKo3kcYEzKDffRkPHvNzc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Salesforce logo illuminated on a sign on the company&#039;s exhibitor stall at the China International Import Expo.]]></media:description>                                                            <media:text><![CDATA[Salesforce logo illuminated on a sign on the company&#039;s exhibitor stall at the China International Import Expo.]]></media:text>
                                <media:title type="plain"><![CDATA[Salesforce logo illuminated on a sign on the company&#039;s exhibitor stall at the China International Import Expo.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QbKo3kcYEzKDffRkPHvNzc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Salesforce has issued a warning over an ongoing campaign targeting customers using misconfigured Experience Cloud platforms. </p><p>In an <a href="https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/" target="_blank"><u>advisory </u></a>last week, the CRM giant said a “known threat actor group” has been observed using a modified malicious version of the AuraInspector tool, which as part of the Salesforce Aura framework to identify security misconfigurations in Experience Cloud sites.</p><p>Originally developed by Mandiant, threat actors are using the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> tool to “perform mass scanning of public-facing Experience Cloud sites” and extract data. </p><p>“While the original Aura Inspector is limited to identifying vulnerable objects by probing API endpoints that these sites expose (specifically the /s/sfsites/aura endpoint), the actor has developed a custom version of the tool capable of going beyond identification to actually extract data — exploiting overly permissive guest user settings,” the company said. </p><p>Salesforce emphasized that the incident was not caused by a “vulnerability inherent to our platform”, but instead due to a customer-configured guest user setting. </p><p>This is because an exposed Salesforce Experience site accepts guest user profiles to provide access to publicly available data. </p><p>However, the company noted that misconfigured profiles with excessive permissions could allow a threat actor to “directly query Salesforce CRM objects” without logging in. </p><p>Charles Carmakal, CTO at Mandiant, said the company is aware of the AuraInspector misuse and is working with Salesforce to mitigate risks. </p><p>“We are aware of a threat actor attempting to identify misconfigurations within the Salesforce Experience Cloud instances,” he told <em>ITPro</em>. </p><p>“We are working closely with Salesforce and our customers to provide the necessary telemetry and detection rules to mitigate potential risk."</p><h2 id="shinyhunters-claims-responsibility">ShinyHunters claims responsibility</h2><p>The “known threat actor group” cited by Salesforce appears to be ShinyHunters, with the group claiming responsibility for the attacks. </p><p>According to reports from <a href="https://www.theregister.com/2026/03/09/shinyhunters_claims_more_highprofile_victims/" target="_blank"><u><em>The Register</em></u></a>, the threat group claims to have stolen data from upwards of 400 websites and around 100 “essential high profile companies”. </p><p>Companies cited by the group included Snowflake, LastPass, Okta, AMD, and Salesforce. The group told the publication that the campaign has been ongoing “for several months now”. </p><h2 id="what-can-salesforce-customers-do">What can Salesforce customers do?</h2><p>In its advisory, Salesforce detailed a number of steps customers can take to mitigate potential risks, including:</p><ul><li>Enforcing a “least privilege” access model</li><li>Conduct an audit of guest user permissions</li><li>Set Org Wide Defaults to “Private”</li><li>Switch off portal user visibility and site user visibility</li></ul><p>Salesforce also advised customers to disable self-registration unless explicitly required. This is because guest data can be used to create portal accounts, thereby enabling “broader data access”.</p><p>“In addition to checking for unusual query volumes, review your Aura Event Monitoring logs for anomalous access patterns — such as queries targeting objects not intended to be public, unexpected spikes from unfamiliar IP addresses, or access outside normal business hours,” Salesforce said. </p><p>“If you suspect your environment may have been affected, contact Salesforce Support and complete the guest user audit steps outlined above rather than relying on log volume alone.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloudflare warns state-backed hackers are ‘weaponizing legitimate enterprise ecosystems’ as ‘living off the land’ attacks surge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cloudflare-warns-state-backed-hackers-are-weaponizing-legitimate-enterprise-ecosystems-as-living-off-the-land-attacks-surge</link>
                                                                            <description>
                            <![CDATA[ Chinese, North Korean, and Russian-backed threat groups now favor longer-term compromises over brute force attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tDHyWXyTh5PSUqWYrFAqbV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Mar 2026 09:23:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>State-sponsored attackers are weaponizing legitimate software and infrastructure to lie in wait, shifting tactics away from data breaches to more sophisticated espionage and disruptive operations.  </p><p>That's according to a new report from Cloudflare that walked through a series of attacks from Chinese hacks against Google Calendar to North Korean IT worker scams – including a tactic that makes use of AI. </p><p>In that attack, the hackers snuck past traditional perimeter defenses by finding credentials hidden in code using secret scanning tools, such as TruffleHog. </p><p>"Once these keys to the kingdom were harvested, the actor leveraged generative AI in real time to navigate unfamiliar, complex SaaS environments," the report said. </p><p>Examples like this underline how <a href="https://www.itpro.com/security/cyber-crime/trend-micro-vibe-crime-agentic-ai-cyber-crime">AI is supporting cyber crime</a> operations, the report noted, making it easier for hackers to target legitimate tools and weaponize them against victims. </p><p>"The accessibility of <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">generative AI large language models (LLMs)</a> both increases unwitting user risk and significantly lowers the barrier to entry for highly effective operations," researchers said . </p><p>"Adversaries have moved beyond technically elegant code to 'offense by the system,' leveraging a victim’s own cloud, <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a>, and <a href="https://www.itpro.com/infrastructure/ai-infrastructure-global-divide">AI infrastructure</a> to fund and scale missions."</p><h2 id="nation-state-attackers-shift-tactics">Nation-state attackers shift tactics</h2><p>Cloudflare said it has tracked four primary state actors over the last year, namely Russia, China, North Korea, and Iran. The security firm said it was seeing a blurring of strategic goals, with digital strikes increasingly backing up military actions in conflicts. </p><p>China, for example, has shifted away from bulk data theft to targeting legitimate infrastructure such as the cloud for longer-term compromises and strategic "pre positioning" tactics that are ideal for espionage and disruptive operations. </p><p>"By weaponizing legitimate enterprise ecosystems – such as FrumpyToad’s use of Google Calendar for C2 or PunyToad’s exploitation of F5 and VMware vCenter and ESXi – Beijing has created a resilient, living-off-the-cloud architecture that allows for rapid data exfiltration while remaining nearly invisible to standard perimeter defenses," the report noted. </p><p>Notorious Chinese state-backed hacker groups such as Salt Typhoon have employed living off the land techniques extensively over the last two years, most notably during <a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach">attacks on US State National Guard networks</a> and <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-us-congress-email-cyber-attack">US congressional email systems</a>. </p><p>Meanwhile, in Russia, groups like NastyShrew use "high-reputation cloud services" to mask their activities in order to continue targeting Ukrainian critical systems. </p><p>That includes tactical communication apps used by the Ukrainian military, and Cloudflare suggested that was "possibly in support of physical operations."</p><h2 id="the-rise-of-north-korean-it-workers">The rise of North Korean IT workers</h2><p>Cloudflare has also observed what it calls the "industrialization" of a scheme run by North Korea in which AI and other tools are used to <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">pose as American workers to get jobs as remote IT workers</a>. </p><p>"These operatives infiltrate Western organizations by leveraging fraudulent identities and AI-driven deepfakes to bypass video interviews, ultimately funneling hundreds of millions of dollars in revenue back to the regime," the report notes. </p><p>Alongside using AI, threat actors often <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-on-linkedin-security-experts-warn-operatives-are-stealing-profiles-to-apply-for-jobs-and-infiltrate-firms">set up digital personas on LinkedIn</a> and GitHub for more legitimacy – sometimes even "renting" the accounts of real American citizens.  </p><p>Once employed, these North Korean workers use <a href="https://www.itpro.com/security/cyber-crime/us-charges-14-members-of-north-korean-it-worker-scam-that-bagged-usd88-million-in-six-years">American-based "laptop farms"</a> that are accessed via remote management and monitoring software from overseas. </p><p>As <em>ITPro </em>previously reported, the number of fake IT worker scams has surged over the last 18 months, prompting security agencies and the FBI to <a href="https://www.itpro.com/security/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it-workers-wreak-havoc">issue advisories on how to tackle the issue</a>. </p><p>Cloudflare said it's possible to spot such behavior, however, and urged organizations to bolster identity checks. </p><p>"Despite these sophisticated tactics, several high-fidelity detection indicators have emerged, including 'impossible travel' login alerts, the presence of mouse-jiggling software, and specific video metadata micro-artifacts consistent with real-time deepfake rendering,” the company said. </p><p>Notably, Cloudflare advised shifting away from traditional perimeter defenses in favor of <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> biometric verification and stricter geofencing for remote management tools. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian DDoS: what’s the threat to businesses? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/russian-ddos-whats-the-threat-to-businesses</link>
                                                                            <description>
                            <![CDATA[ The UK National Cyber Security Centre (NCSC) has issued a warning that Russian-aligned hacktivist groups are targeting organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ccTmK5nKuUhmHLYMEQgLEd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WaAZGD2aJwzNdfFfUmokSn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Mar 2026 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WaAZGD2aJwzNdfFfUmokSn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Russian flag, overlaid on a glowing blue digital image of binary code.]]></media:description>                                                            <media:text><![CDATA[The Russian flag, overlaid on a glowing blue digital image of binary code.]]></media:text>
                                <media:title type="plain"><![CDATA[The Russian flag, overlaid on a glowing blue digital image of binary code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WaAZGD2aJwzNdfFfUmokSn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a> has <a href="https://www.itpro.com/security/cyber-attacks/ncsc-names-and-shames-pro-russia-hacktivist-group-amid-escalating-ddos-attacks-on-uk-public-services"><u>issued a warning</u></a> that Russian-aligned hacktivist groups are targeting organizations. The alert describes how <a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Russia-based adversaries</u></a> including <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/noname057(16)" target="_blank"><u>NoName057(16)</u></a> have been attempting to disrupt operations, taking websites offline and disabling services. </p><p>The hacktivist groups are using <a href="https://www.itpro.com/security/cyber-attacks/how-to-recover-from-a-ddos-attack-and-what-they-can-teach-businesses"><u>distributed denial of service</u></a> (DDoS) attacks – in which websites are flooded with traffic to take them offline – against governments as well as critical infrastructure firms across NATO member states and other European countries.</p><p>Why has this warning been issued and what can organizations do to boost their defenses in response?</p><h2 id="familiar-name">Familiar name</h2><p>NoName057(16) has been around since 2022, emerging shortly after Russia invaded Ukraine. Its self-declared mission is to counteract open hostility towards <a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do"><u>Russia,</u></a> targeting NATO-aligned countries, says Darren Anstee, chief technology officer for security at NETSCOUT. </p><p>Renowned for widespread cyber operations and enabling like-minded individuals to disrupt online services on “an exceptionally large scale”, NoName057(16) has garnered notoriety for developing and distributing the DDoSia attack tool, Anstee tells <em>ITPro.</em></p><p>Similar to many hacktivist collectives, NoName057(16) leverages a crowdsourced model, where it utilizes its DDoSia toolkit to mobilise thousands of volunteers via Telegram adds Jamie Collier, lead advisor, Europe at Google Threat Intelligence Group. This “fluid model” has led to challenges in disrupting its efforts, he says. </p><p>Indeed, the hacktivist collective shows no sign of slowing down, even after it was hunted by law enforcement. By consistently promoting its operations online, NoName057(16) has positioned itself as “one of the most visible and persistent hacktivist entities” – despite <a href="https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network"><u>law enforcement action</u></a> against the group, says Daniel dos Santos, senior, director, and head of research at Forescout.</p><p>He describes how Forescout analyzed a dataset of hacktivist attacks from 2024: “This single group was responsible for 90% of the activity we observed”.</p><p>Unlike other hacktivist groups that exhibit selective targeting strategies, NoName057(16) has adopted a “broad and high-frequency attack approach”, often carrying out multiple attacks a day across different industries and countries, says dos Santos. “Some attacks targeted the same organizations repeatedly, either due to their strategic value, or to demonstrate the group’s continued ability to inflict damage.”</p><p>The threat to organizations is “significant” because the group is “very successful with DDoS attacks”, says dos Santos. “These attacks often take websites offline for some time, disrupting businesses and affecting their customers.”</p><h2 id="inexperienced-and-technically-unskilled">Inexperienced and technically unskilled</h2><p>The threat from hacktivist groups such as NoName057(16) is quite different to that from other adversaries. The use of DDoS – especially as a primary operation – has historically been a key indicator that a group is inexperienced or technically unskilled, says Marley Smith, principal intelligence specialist at the World Ethical Data Foundation. “Even though they are targeting critical infrastructure, the organizations on the receiving end of these attacks are usually those with exposed assets, or those whose employees have poor security practices in place.”</p><p>However, “unskilled” in this context does not mean “unthreatening” or even “un-resourced”, says Smith. “It means the lead actors are not developing and refining their own bespoke <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>. Instead, they are more likely to use a simpler, more user-friendly threat apparatus designed for a maximum impact-to-effort ratio.”</p><p>Taking this into account, the goal of these groups is to “drum up as much fear as possible”, or “cause a public outcry” in the hope that the bad press will “coerce governments to turn a blind eye to Russia’s crimes in the future”, Smith explains.</p><p>NoName057(16) is just one example of a pro-Russian hacktivist group. Others include Dienet, Overflame, Red Wolf Cyber and Server Killers, says Anstee. “These hacktivists operate not for financial gain, but to advance ideological goals, aiming to generate media coverage of successful attacks to raise the profile of their points of view.”</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/dd292200-93b9-4e0b-86e3-492606241c36/"></iframe><h2 id="mitigating-russian-ddos-attacks">Mitigating Russian DDoS attacks</h2><p>The threat is real and growing, especially for nations targeted by Russian hacktivist groups. The NCSC advises UK organizations and businesses to understand the services they run online and the potential weak points that might expose them to risk from DDoS style attacks. “It advises them to discuss risks and mitigations with their own upstream internet service providers or hosts and to ensure that services can be rapidly scaled to deal with sudden spikes in requests, or data received that can be indicative of an attack,” says Cian Heasley, principal consultant, Acumen Cyber.  </p><p>Along with these mitigations and preparations, the NCSC recommends having an <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response plan</a> in place covering business continuity in a DDoS attack scenario.</p><p>This is in addition to removing <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot"><u>operational technology (OT)</u></a> connections to the public internet; identifying public-facing assets and removing unintentional exposures. Meanwhile, firms should use <a href="https://www.itpro.com/security/how-to-create-a-secure-password-policy"><u>strong passwords</u></a>, apply principles of least privilege for remote access networks, segment IT and OT and maintain manual backups for systems, the NCSC advises.</p><p>It’s “an old adage”, but you can’t secure what you can’t see, says Anstee. “Comprehensive, consistent visibility across the network and application layers – for all infrastructures, whether on premises or in the cloud – allows cybersecurity teams to know what ‘normality’ looks like, so when there is an attack, they can more quickly identify where there’s an impact, and work out what should be done to ensure service continuity.”</p><p>In addition, Smith advises “avidly reading the news”. “Keep up-to-date on attacks in your country and industry, and on the vulnerabilities discovered in the applications you use. Actively engage with your employees and their habits to close the human-sized gap in your defenses.”</p><p>At the same time, organizations can obtain lists of known “bad internet addresses” associated with denial of service attacks online, or from their security providers, as well as lists of open proxy services that adversaries use to disguise where attacks are coming from, says Heasley. “These can be blocked at the firewall level or through access control lists so traffic never reaches servers that can be overwhelmed.”</p><p>In cases where attacks cannot be easily mitigated, geoblocking can be put in place, Heasley advises. “This would mean UK organizations only accept incoming connections from internet addresses that can be resolved to the UK itself, limiting potential malicious traffic while still allowing some national connectivity.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerability ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/security-agencies-issue-warning-over-critical-cisco-catalyst-sd-wan-vulnerability</link>
                                                                            <description>
                            <![CDATA[ Threat actors have been exploiting the vulnerability to achieve root access since 2023 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W3nhLCHBdhW9sQ8LSdtdbU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Feb 2026 10:12:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:description>                                                            <media:text><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security agencies are warning that a maximum-severity flaw in Cisco Catalyst SD-WAN Controller has been exploited in the wild for years.</p><p>An advisory from CISA noted that threat actors have compromised SD-WANs to add a malicious rogue peer, allowing them to conduct a range of follow-on actions to achieve root access and maintain persistent access.</p><p>"Based on collaboration with international partners and CISA’s forensic analysis, the ease with which these vulnerabilities can be exploited demands immediate action from all federal agencies," said Madhu Gottumukkala, the acting director of the US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a>. </p><p>"We urge all entities to implement the measures outlined in this Emergency Directive without delay. CISA leadership and all (excepted) staff remain committed to fulfilling our mission while protecting the American people.” </p><p>Successful exploitation of <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" target="_blank"><u>CVE-2026-20127</u></a>, which has a CVSS score of 10, could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. </p><p>Using this account, an attacker could access NETCONF, allowing them to manipulate network configuration for the SD-WAN fabric. </p><p>Cisco Catalyst SD-WANs that have management interfaces exposed to the internet are at most risk of compromise. </p><p>"CISA’s guidance is a clear signal that adversaries are aiming for the control plane, not just individual endpoints. The vulnerability being discussed allows an attacker to reach sensitive management functions without going through normal access checks," said Nick Tausek, lead security automation architect at Swimlane. </p><p>"What makes this especially serious is how quickly a compromised management path can translate into broad influence over how sites connect, which routes are preferred, and what policies are enforced across networks." </p><h2 id="cisco-catalyst-sd-wan-best-practices">Cisco Catalyst SD-WAN best practices</h2><p>According to Cisco, the first thing to check for is any control connection peering event identified in Cisco Catalyst SD-WAN logs, as this may indicate an attempt at initial access via CVE-2026-20127. </p><p>All such peering events require manual validation to confirm their legitimacy, with particular focus on vManage peering types. </p><p>The company warned unauthorized peer connections may appear superficially normal but occur at unexpected times, originate from unrecognized IP addresses, or involve device types inconsistent with the environment's architecture.</p><p>Organizations should move quickly to inventory SD-WAN components, confirm which are internet-facing, and map all management access methods - web UI, SSH, NETCONF, APIs - including which networks and admin accounts can reach them, said Moshe Hassan, VP of research and innovation at Upwind.</p><p>Elsewhere, organizations are urged to restrict management access to known-good sources, Allowlisting trusted IPs/admin networks only, removing public exposure, and segmenting management interfaces behind <a href="https://www.itpro.com/uk/software/vpn">VPN</a>/jump hosts. </p><p>Unsolicited access to management ports and unusual management-plane traffic should be blocked.</p><p>"Patch exposed systems first, or block until you can. Prioritize patching any internet-reachable appliances immediately. If patching can’t happen fast enough, temporarily block management protocols from the internet, disable unused services, and deploy compensating controls (ACLs/IPS rules) until updates are in place," he said.</p><p>"Watch for unexpected new peers/devices in the <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">SD-WAN</a> fabric, suspicious changes to configuration or policy, anomalous admin activity, and unusual lateral connections within the management plane."</p><p>Cisco has published a hardening guide <a href="https://sec.cloudapps.cisco.com/security/center/resources/Cisco-Catalyst-SD-WAN-HardeningGuide" target="_blank"><u>here</u></a>.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vast majority of breaches enabled by preventable gaps, identity weaknesses says Palo Alto Networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/vast-majority-breaches-enabled-preventable-gaps-identity-weaknesses-palo-alto-networks</link>
                                                                            <description>
                            <![CDATA[ Identity controls and better understanding of threat surface are key to rebuffing increasingly threatening cyber attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jMQGbFuJ3ArUEA5ehhEHbk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qqCnL6Mg4ATgEBpvadSuQi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Feb 2026 11:38:51 +0000</pubDate>                                                                                                                                <updated>Tue, 17 Feb 2026 12:03:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qqCnL6Mg4ATgEBpvadSuQi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A visualization of a green padlock surrounded by open orange padlocks, to represent identity attacks.]]></media:description>                                                            <media:text><![CDATA[A visualization of a green padlock surrounded by open orange padlocks, to represent identity attacks.]]></media:text>
                                <media:title type="plain"><![CDATA[A visualization of a green padlock surrounded by open orange padlocks, to represent identity attacks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qqCnL6Mg4ATgEBpvadSuQi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprises are falling prey to cyber attacks largely due to lack of oversight, preventable errors, and poor identity controls, even as AI attacks become a reality.</p><p>This is according to Palo Alto Networks’ <em>Global Incident Response Report 2026, </em>produced by its Unit 42 cyber threat intelligence team, which sourced data from over 750 attacks reported to the organization between October 2024 and September 2025.</p><p>In the past year alone, researchers found weak identity controls played a meaningful role in 90% of cyber incidents, with attackers leaning on identity as the most reliable entry point and mechanism for lateral movement.</p><p>Indeed, in nearly two-thirds (65%) of cases attackers used identity-based attacks as the initial access point for enterprise systems, with 33% of attacks beginning with phishing and social engineering.</p><p>Within this subset of cases, session hijacking and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it"><u>MFA bypass</u></a> techniques allowed threat actors to quickly access victims’ systems. Attackers also used tried-and-tested entry techniques including using previously <a href="https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025"><u>stolen credentials</u></a> (13%), brute force attacks (8%), and insider attacks (8%) to breach systems.</p><p>Researchers analyzed over 680,000 cloud identities and discovered that 99% of users, services, and roles had excessive permissions, enabling attackers to easily complete lateral movement through corporate networks after compromising an account.</p><h2 id="back-to-basics-with-identity-security">Back to basics with identity security</h2><p>Chris George, managing director EMEA at Unit 42, told <em>ITPro</em> that leaders must thoroughly examine their existing identity policies and to be “brilliant at the basics” to close these preventable gaps.</p><p>“What user accounts do you have? What is your password policy? How are you making sure that you're choosing non-brute-forceable passwords? How are you looking at the permissions?”</p><p>Mastering the basics may be the bare minimum for businesses, as the number of machine identities they have to manage balloon with the deployment of AI agents.</p><p>In October <em>ITPro</em> heard from Haider Pasha, EMEA CISO at Palo Alto Networks, who noted that <a href="https://www.itpro.com/security/agentic-ai-poses-major-challenge-for-security-professionals-says-palo-alto-networks-emea-ciso"><u>agentic AI will seriously complicate identity security</u></a> and requires rigorous oversight to be used safely.</p><p>George told <em>ITPro</em> that his team has observed over-provisioning of AI copilots, allowing attackers to obtain leaked information by crafting malicious prompts.</p><p>“[W]hen we get to the whole agentic side of things, and we've got AI agents that are going to be in their tens, hundreds of thousands, then if each single agent has got a connection to something and has got permission to do things, how are you managing the security around that?”</p><p>In the future, George said, threat actors may replicate the kind of <a href="https://www.itpro.com/security/cyber-attacks/us-telco-confirms-hackers-breached-systems-in-stealthy-state-backed-cyber-campaign-and-remained-undetected-for-nearly-a-year"><u>‘living off the land’</u></a> techniques we’re currently seeing used against mobile device management (MDM) tools and leaders must ensure their AI systems aren’t compromised.</p><p>But he added that even more sophisticated methods such as the malicious use of <a href="https://www.itpro.com/security/deepfake-business-risks-are-growing-what-leaders-need-to-know"><u>deepfakes</u></a> rely on the age-old processes of <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec"><u>business email compromise</u></a>, for which we have established security protocols.</p><p>Incidents included in the report’s data cover a wide range of enterprises, including enterprises in the Fortune 500, government organizations, and SMBs, across over 50 countries.</p><iframe allow="" height="200px" width="100%" id="" style="" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/b6147684-d254-40d8-9409-5f76f5abd749/"></iframe><h2 id="the-attack-surface-is-widening">The attack surface is widening</h2><p>There’s evidence that attackers are widening the net in a bid to achieve greater success against victims, with 87% of intrusions found to involve attacks on two or more attack surfaces and 67% involving activity across three or more.</p><p>After identity, the most common attack surface was endpoints at 61% and network at 50%. Researchers found in nearly half (48%) of all investigations, browser activity was also targeted, an increase from the 44% measured in 2024.</p><p>For example, researchers cited an incident involving the <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers"><u>ClickFix</u></a> attack technique, in which threat actors used <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-fake-tool-installers-to-dupe-victims-and-ai-tools-like-chatgpt-are-a-key-target"><u>SEO poisoning</u></a> to trick an employee at an international industrial firm to execute malicious code. The goal was to run <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> in <a href="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit"><u>system memory</u></a>, in order to install an <a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses"><u>infostealer</u></a> on the employee’s work device.</p><p>Supply chain attacks are another severe risk for enterprises. Attackers are increasingly exploiting SaaS environments, which rely on a complex web of interdependencies and permissions linked by APIs and OAuth apps, as well as legitimate vendor tools and open source dependencies.</p><p>Almost a quarter (23%) of incidents tracked by researchers in 2025 involved SaaS applications, compared to just 6% in 2022, while 39% of command and control (C2) techniques linked directly to remote access tools with administrator privileges.</p><p>Addressing these vulnerabilities will mean taking stock of all systems, permissions, and interdependencies to build a holistic view of one’s attack surface. But George told <em>ITPro</em> that many organizations still struggle with simply cataloguing their systems, let alone protecting them.</p><p>“You see, actually, in conversations we've had with the board, they say ‘we didn't even know we had the affected system, because we just don't have it documented’.</p><p>“There's a concept of a CMDB – a configuration management database, a list of everything in the company that they own. I’ve very rarely seen anything that's been 100% complete and kept up to date.”</p><p>To start with, he said, leaders have to strategize where they can make the most impact in the short term and then think about more radical overhaul.</p><h2 id="ai-has-become-a-force-multiplier-for-good-and-for-ill">AI has become a force multiplier – for good and for ill</h2><p>In addition to traditional attack methods, researchers found threat actors are increasingly using AI to <a href="https://www.itpro.com/security/they-are-able-to-move-fast-now-ai-is-expanding-attack-surfaces-and-hackers-are-looking-to-reap-the-same-rewards-as-enterprises-with-the-technology"><u>enhance the speed and severity of attacks</u></a>.</p><p>The report noted that AI, particularly models hosted on adversary infrastructure, has been used to discover unpatched vulnerabilities just 15 minutes after a <a href="https://www.itpro.com/security/the-cve-system-isnt-working-what-next"><u>CVE</u></a> is published, as well as to reduce the manual work needed to run <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> campaigns.</p><p>In lab tests conducted in 2025, Unit 42 was able to use AI to reduce time-to-exfiltration to just 25 minutes. In the real world, attackers are on a similar trajectory, having reduced the figure from 4.8 hours to just 72 minutes from 2024 to 2025.</p><p>AI is also used to improve grammar for phishing lures, as well as to produce attack strategies. This lines up with recent reports by other organizations such as Google Threat Intelligence Group, which <a href="https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models"><u>recently found APTs are using public AI models</u></a> to translate and localize social engineering messages. </p><p>To counter the threat, Palo Alto Networks recommended organizations deploy automated patching, AI-driven security detection and response tools, as well as better monitoring of API calls and <a href="https://www.itpro.com/technology/artificial-intelligence/gartner-says-40-percent-of-enterprises-will-experience-shadow-ai-breaches-by-2030-educating-staff-is-the-key-to-avoiding-disaster"><u>internal AI use</u></a>.</p><p>For example, George pointed to the 72 minutes it now takes attackers to move from initial access to data exfiltration – a time frame that can’t be countered without some form of automation.</p><p>With greater controls over AI deployment and a focus on leveraging its benefits to empower security teams, he argued that there’s clear hope for defenders.</p><p>“AI is, and it will, change the world – there is a huge amount of opportunity.</p><p>“But I could say that about every technological change throughout history and I think we should be taking lessons from all of those and refining our approach.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security expert warns Salt Typhoon is becoming 'more dangerous' after Norwegian authorities lift lid on critical infrastructure hacking campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/salt-typhoon-norway-cyber-espionage-warning</link>
                                                                            <description>
                            <![CDATA[ The Chinese state-backed hacking group has waged successful espionage campaigns against an array of organizations across Norway. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5cKy9DBAE3N95B5r2F82im</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uvuxUyoNcxZTsTdMdbPFKG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Feb 2026 10:51:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uvuxUyoNcxZTsTdMdbPFKG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chinese hacker concept image symbolizing the Salt Typhoon threat group, with a man typing on keyboard with People&#039;s Republic of China (PRC) flag in background.]]></media:description>                                                            <media:text><![CDATA[Chinese hacker concept image symbolizing the Salt Typhoon threat group, with a man typing on keyboard with People&#039;s Republic of China (PRC) flag in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Chinese hacker concept image symbolizing the Salt Typhoon threat group, with a man typing on keyboard with People&#039;s Republic of China (PRC) flag in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uvuxUyoNcxZTsTdMdbPFKG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Chinese-backed hacking group known as Salt Typhoon has waged successful espionage campaigns against an array of organizations across Norway, according to the Norwegian Police Security Service. </p><p>No details have been published on which companies were targeted or how long the attackers were able to maintain access. </p><p>However, the report warned Chinese security and intelligence services are increasingly carrying out intelligence operations in Norway, including cyber operations and the collection of human intelligence.</p><p>"In 2026, China will collect intelligence, reconnoiter Norwegian digital infrastructure and threaten groups and individuals to prevent them from criticizing the Chinese Communist Party," the <a href="https://www.pst.no/wp-content/uploads/2026/02/National-Threat-Assessment-2026.pdf" target="_blank"><u>report </u></a>reads.</p><p>"An increasing number of operations are likely to be carried out by commercial <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>contractors and individuals who are not trained intelligence personnel but act on behalf of Chinese security and intelligence services."</p><p>Norwegian authorities warned any organizations holding sensitive information to be on the alert, particularly those operating in national infrastructure domains. </p><p>Salt Typhoon has mainly focused on targets in the US and Canada, but analysis shows the group is expanding operations globally. In September last year, the <a href="https://www.itpro.com/security/cyber-attacks/fbi-warns-indiscriminate-salt-typhoon-hacking-campaign-has-hit-organizations-in-more-than-80-countries">FBI warned the group had hit organizations in as many as 80 countries</a> altogether. </p><p>The <a href="https://www.itpro.com/security/what-is-cisa">US Cybersecurity and Infrastructure Security Agency (CISA)</a> said it was mainly targeting telecommunications, government, transportation, lodging, and military infrastructure networks.</p><p>Salt Typhoon typically targets large backbone routers of major telecommunications providers and network infrastructure companies, as well as provider edge (PE) and customer edge (CE) routers. </p><p>They also leverage compromised devices and trusted connections to pivot into other networks, modifying routers to maintain persistent, long-term access to networks.</p><h2 id="salt-typhoon-is-getting-bolder">Salt Typhoon is getting bolder</h2><p>Pete Luban, Field CISO at AttackIQ, warned the group is becoming “more dangerous with each successful infiltration” and has established itself as a key adversary for national security agencies globally. </p><p>Salt Typhoon gained notoriety after <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-hacker-group-recorded-conversations-of-very-senior-us-political-figures"><u>compromising email systems belonging to “very senior” US political figures</u></a> as part of an intelligence gathering campaign. </p><p>These long-running campaigns have become a hallmark of the group, which also managed to <a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach"><u>avoid detection in US National Guard networks for nearly a year</u></a>. </p><p>"Continued access into internal systems allows threat actors to establish long-term surveillance and position themselves to carry out destructive attacks with little to no advanced warning," Luban said. </p><p>"However, breaches like these also deal indirect damage by undermining the security of intelligence sharing networks. If Salt Typhoon can sow seeds of doubt into these networks, it could force allies to limit or restrict information sharing, ultimately weakening collective security."</p><p>Organizations are advised to identify where vulnerabilities might exist in their infrastructure and mitigate them before threat actors can exploit them. </p><p>These networks should be segmented from internet-facing systems, while enforcement of zero-trust access controls can also help contain any damages caused by Salt Typhoon if defenses are breached.</p><p>The report also warned that Chinese intelligence services are recruiting Norwegian nationals to gain access to sensitive and classified information.</p><p>Often, those being recruited don't know they're working for Chinese intelligence, thinking they're employed by a think tank, an international company, a consultancy firm or similar.</p><p>"Sources are initially asked to provide non-public information in exchange for payment, such as details on the activities or plans of companies, public sector organisations of political institutions," it said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google issues warning over ShinyHunters-branded vishing campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns</link>
                                                                            <description>
                            <![CDATA[ Related groups are stealing data through voice phishing  and fake credential harvesting websites ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zHr8MESTqLrM7FdPM6unGB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Feb 2026 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:description>                                                            <media:text><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:text>
                                <media:title type="plain"><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Threat Intelligence Group (GTIG) has identified a group with all the hallmarks of ShinyHunters using <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">voice phishing</a> (vishing) and fake credential harvesting websites to steal sensitive data. </p><p>In an advisory, the tech giant warned the group primarily gains access to corporate environments by obtaining single sign-on (SSO) credentials and <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> codes. </p><p>Once inside, the attackers target cloud-based SaaS applications to exfiltrate sensitive data and internal communications that they can use in subsequent extortion demands.</p><p>Google is currently <a href="https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft" target="_blank"><u>tracking</u></a> the activity under several threat clusters, including UNC6661, UNC6671, and UNC6240.</p><p>Last month, for example, UNC6661 pretended to be IT staff and called employees at targeted organisations, claiming that the company was updating MFA settings. </p><p>The threat actor then directed employees to victim-branded credential harvesting sites to capture credentials and MFA codes, with victims thereafter registering their own device for MFA. </p><p>According to Google, threat actors moved laterally through victim customer environments to exfiltrate data from various <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>platforms.</p><p>While the attacks are targeted, analysis suggests that subsequent access is probably opportunistic, determined by the specific permissions and applications accessible via the individual compromised SSO session. Google stressed that the activity isn't the result of a security vulnerability in vendors' products or infrastructure. </p><p>"In some cases, they have appeared to target specific types of information. For example, the threat actors have conducted searches in cloud applications for documents containing specific text including 'poc', 'confidential', 'internal', 'proposal', 'salesforce', and 'vpn' or targeted personally identifiable information (PII) stored in Salesforce," researchers said. </p><p>"Additionally, UNC6661 may have targeted Slack data at some victims' environments, based on a claim made in a ShinyHunters-branded data leak site (DLS) entry."</p><h2 id="valuable-intelligence">Valuable intelligence</h2><p>Cory Michal, CSO at AppOmni, praised the level of operational detail in the report, and particularly the volume and specificity of indicators of compromise that weren’t previously public.</p><p>This intelligence could prove vital for organizations that find themselves in the crosshairs moving forward, Michael noted.</p><p>“Publishing concrete domains, tooling names/artifacts, and workflow-level signals gives defenders something they can deploy immediately at scale (email/web filtering, OAuth/app controls, identity telemetry detections, and retro-hunting),” he said.</p><p>“It helps the ecosystem disrupt infrastructure and tradecraft faster by enabling consistent blocking and takedown actions across many organizations rather than each team rediscovering the same indicators in isolation.”</p><h2 id="what-can-enterprises-do-to-protect-themselves">What can enterprises do to protect themselves?</h2><p>Google has published <a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas" target="_blank"><u>guidance</u></a> on hardening, logging, and detection against the threats. </p><p>Organizations responding to an active incident should focus on rapid containment steps, such as severing access to infrastructure environments, SaaS platforms, and the specific identity stores typically used for lateral movement and persistence. </p><p>Long-term defense, meanwhile, requires a transition toward phishing-resistant MFA, such as FIDO2 security keys or passkeys, which are more resistant to <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> than push-based or SMS authentication.</p><p>“Companies should treat this as both a hunt and prevent problem: First, take the IoCs in the report and run them through your detection-and-response workflows (SIEM/SOAR, email security, web proxy/DNS, EDR, and SaaS audit logs) to identify any historical or active exposure," Michal added. </p><p>Michael added they should add continuous monitoring for look-alike domain registrations that incorporate their company name or common brands that they use for login, support, and HR. </p><p>"In many of these campaigns, those newly registered domains are a leading indicator, they show up before the first vishing call, so catching and blocking them early (and tightening your help desk/MFA enrollment controls in parallel) can meaningfully reduce the chance the intrusion ever gets to the “mass download and extortion” stage,” he said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affected ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/notepad-hackers-remained-undetected-and-pushed-malicious-updates-for-six-months-heres-whos-responsible-how-they-did-it-and-how-to-check-if-youve-been-affected</link>
                                                                            <description>
                            <![CDATA[ Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Z8JWmAJVxKDr3msciCHySN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T88XCMBKcwGSg5qaEXtdDR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Feb 2026 11:15:21 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Feb 2026 11:15:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T88XCMBKcwGSg5qaEXtdDR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chinese hackers concept image showing People&#039;s Republic of China (PRC) flag in background with shadowed hands typing on a laptop keyboard in foreground.]]></media:description>                                                            <media:text><![CDATA[Chinese hackers concept image showing People&#039;s Republic of China (PRC) flag in background with shadowed hands typing on a laptop keyboard in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Chinese hackers concept image showing People&#039;s Republic of China (PRC) flag in background with shadowed hands typing on a laptop keyboard in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T88XCMBKcwGSg5qaEXtdDR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Threat actors remained undetected for months and distributed malicious updates to Notepad++ users after breaching the popular text editor software, developers have revealed.</p><p>In a <a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" target="_blank"><u>blog post</u></a>, lead developer Don Ho said a preliminary investigation into the incident showed hackers went undetected for around six months, with those responsible believed to be a state-affiliated threat group. </p><p>“The incident began from June 2025. Multiple independent security researchers have assessed that the threat actor is likely a <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier">Chinese state-sponsored group</a>, which would explain the highly selective targeting observed during the campaign,” he wrote. </p><p>Ho added that the “infrastructure-level compromise” allowed threat actors to “intercept and redirect update traffic”, with the source of the incident stemming from a hosting provider rather than vulnerabilities within the <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software itself. </p><p>“Traffic from certain targeted users was selectively redirected to attacker-controlled served malicious update manifests,” Ho explained. </p><p>The confirmation follows several weeks of speculation over a potential breach. In early December, security researcher Kevin Beaumont penned a <a href="https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9" target="_blank"><u>blog post</u></a> revealing he’d heard from three separate organizations who’d all experienced security incidents with Notepad++.</p><h2 id="how-notepad-was-breached">How Notepad++ was breached</h2><p>According to Ho, details on the “exact technical mechanism” behind the breach are yet to be determined pending a comprehensive probe. </p><p>What we do know so far is that Notepad++ was operated through a shared hosting server and that the incident began in June 2025. </p><p>Through this compromised server, attackers were able to manipulate requests from WinGUp, Notepad++’s native updater tool. It’s from here that threat actors were able to redirect users to <a href="https://www.itpro.com/security/a-malicious-mcp-server-is-silently-stealing-user-emails">malicious servers</a>. </p><p>The now-former hosting provider confirmed this shared server was compromised until 2 September 2025. Yet despite losing server access, attackers “maintained credentials to internal services” which enabled them to continue distributing malicious updates to users until 2 December. </p><p>“Remediation and security hardening” updates were completed by 2 December, according to Ho, which blocked further activity. </p><h2 id="who-s-behind-the-notepad-breach">Who’s behind the Notepad++ breach?</h2><p>A separate investigation by Rapid7 Labs attributed the breach to a Chinese APT group, Lotus Blossom. </p><p>According to researchers, the state-affiliated group has been active since 2009 and has a reputation for “targeted espionage campaigns” against organizations in Southeast Asia and Central America. </p><p>“Our investigation identified a security incident stemming from a sophisticated compromise of the infrastructure hosting Notepad++, which was subsequently used to deliver a previously undocumented custom backdoor, which we have dubbed Chrysalis,” the company noted in an <a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/" target="_blank"><u>advisory</u></a>. </p><h2 id="what-users-need-to-know">What users need to know</h2><p>As Beaumont noted in his December blog post, Notepad++ issued an update to release version 8.8.8 in November. This patch aimed to “harden the Notepad++ Updater from being hijacked to deliver something… note Notepad++”.</p><p>While Beaumont advised users to confirm they’re running a version of the software from 8.8.8 or higher, developers have since urged users to ensure they’re running 8.9.1 or higher.</p><p>“I recommend downloading v8.9.1 (which includes the relevant security enhancement) and running the installer to update your Notepad++ manually,” Ho said. </p><p>“With these changes and reinforcements, I believe the situation has been fully resolved. Fingers crossed.”</p><p>In terms of <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting">indicators of compromise (IOCs)</a>, Ho noted in his blog post that there are none to share at present. </p><p>That doesn’t mean users are left complete in the dark, however. Rapid7’s advisory on the campaign does include IOCs for users who want to clarify whether devices have been targeted. </p><p>Cassius Edison, COO of Closed Door Security, said the severity of the breach is “hard to understate” and users should take immediate steps to establish if they’re impacted. </p><p>“It’s vital that users ensure their software is updated to the latest version, especially on systems connected to larger networks,” he said. </p><p>“The maintainer for Notepad++ has switched to a new host for updates, and has started to implement stricter verification of update binaries on the client side, which should hopefully mitigate any further hijacking attempts moving forward."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft warns of rising AitM phishing attacks on energy sector ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/microsoft-warns-of-rising-aitm-phishing-attacks-on-energy-sector</link>
                                                                            <description>
                            <![CDATA[ The campaign abused SharePoint file sharing services to deliver phishing payloads and altered inbox rules to maintain persistence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bt6xNvsN2W3SWsSesfhL95</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Jan 2026 11:10:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The energy sector should be on the alert for a new multi‑stage <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary‑in‑the‑middle (AitM)</a> campaign, Microsoft has warned.</p><p>Cloud collaboration platforms, particularly Microsoft SharePoint and OneDrive, are popular with threat actors thanks to their widespread presence in enterprise environments. </p><p>They offer built-in legitimacy, flexible file‑hosting capabilities, and authentication flows that attackers can take over and use to hide their presence. </p><p>This latest <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> campaign, <a href="https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/" target="_blank">Microsoft said</a>, abused SharePoint file sharing services to deliver phishing payloads. Emails with the subject line “NEW PROPOSAL – NDA” appeared legitimate, coming from a previously-compromised email address belonging to a trusted organization. </p><p>A number of user accounts have already been compromised, according to the Microsoft Defender Research team. </p><p>Victims clicking on a link included in the email were redirected to a fake login page, which collected their credentials. The attackers also altered inbox rules to mark all emails as "read", making their activity harder to detect. </p><p>They were then able to make use of trusted internal identities from the target to conduct large‑scale phishing attacks, both within the organization and externally, significantly expanding the scope of the campaign. </p><p>In one example, this phishing campaign involved more than 600 emails with a different phishing URL, which were sent to the compromised user’s contacts within and outside the organization, as well as distribution lists. </p><p>The attackers then made further efforts to avoid suspicion.</p><p>"The attacker read the emails from the recipients who raised questions regarding the authenticity of the phishing email and responded, possibly to falsely confirm that the email is legitimate," said the Microsoft team. </p><p>"The emails and responses were then deleted from the mailbox. These techniques are common in any BEC attacks and are intended to keep the victim unaware of the attacker’s operations, thus helping in persistence."</p><h2 id="tackling-adversary-in-the-middle-attacks">Tackling adversary-in-the-middle attacks </h2><p>Microsoft highlighted the operational complexity of AiTM campaigns, saying that password resets alone are not enough to fix the problem. </p><p>Impacted organizations must, said the firm, make sure that they've revoked active session cookies, reversed the changes to MFA settings made by the attacker on the compromised user’s accounts and removed the altered inbox rules. </p><p>"While AiTM phishing attempts to circumvent <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA</a>, implementation of MFA still remains an essential pillar in identity security and highly effective at stopping a wide variety of threats. </p><p>MFA is the reason that threat actors developed the AiTM session cookie theft technique in the first place," the team said.</p><p>The researchers also advised organizations to work with their identity provider to ensure security controls like MFA are in place. </p><p>They added: "Organizations should also consider complementing MFA with conditional access policies, where sign-in requests are evaluated using additional identity-driven signals like user or group membership, IP location information, and device status, among others." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC names and shames pro-Russia hacktivist group amid escalating DDoS attacks on UK public services ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/ncsc-names-and-shames-pro-russia-hacktivist-group-amid-escalating-ddos-attacks-on-uk-public-services</link>
                                                                            <description>
                            <![CDATA[ Russia-linked hacktivists are increasingly trying to cause chaos for UK organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jqeUd8AcbExEp3jjXdxNS4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jan 2026 10:55:05 +0000</pubDate>                                                                                                                                <updated>Tue, 20 Jan 2026 10:55:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:description>                                                            <media:text><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do">Pro-Russia hacktivists</a> are targeting local government and critical infrastructure in the UK, the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has warned.</p><p>In an advisory this week, the security agency issued an alert over increased <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attacks</a> by state-aligned groups. These attacks are driven by ideology over Western support for Ukraine, rather than financial gain, and aren't directly controlled by the state.  </p><p>"We continue to see Russian-aligned hacktivist groups targeting UK organizations, and although denial-of-service attacks may be technically simple, their impact can be significant," said NCSC director of national resilience Jonathon Ellison. </p><div class="product"><a data-dimension112="fd674251-247e-4b0a-b8df-3cc5748ab88c" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="fd674251-247e-4b0a-b8df-3cc5748ab88c" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="fd674251-247e-4b0a-b8df-3cc5748ab88c" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>“By overwhelming important websites and online systems, these attacks can prevent people from accessing the essential services they depend on every day."</p><p>In particular, the NCSC cites the NoName057(16) group, active since March 2022, and operating mainly through Telegram channels. It uses GitHub, along with other websites and repositories, to host the proprietary DDoS tool, DDoSia, and to share tactics, techniques, and procedures (TTPs) with its followers.</p><p>NoName057(16) has carried out numerous attacks against government bodies and the private sector in countries perceived as hostile to Russian geopolitical interests, including frequent DDoS attempts against UK local authorities.</p><p>“NoName057(16) consistently targets organisations where availability is closely tied to public trust, particularly local government websites, civic services, and other public-facing infrastructure," said Christiaan Beek, senior director of threat intelligence and analytics at Rapid7.</p><p>"While the group presents itself as a grassroots hacktivist collective, the timing of its campaigns and the close alignment of its targeting with Russian geopolitical objectives mean we cannot rule out some level of state encouragement, coordination, or tacit approval."</p><h2 id="russian-hacktivists-are-an-ever-present-threat">Russian hacktivists are an ever-present threat</h2><p>Russian hacktivism isn't a new problem. In 2023, the NCSC published an alert on the risk posed by state-aligned adversaries following the Russian invasion of Ukraine. </p><p>In December, alongside international partners, it co-sealed an advisory which called out pro-Russian hacktivist groups for targeting government and private sector entities.  </p><p>The NCSC <a href="https://www.ncsc.gov.uk/news/pro-russia-hacktivist-activity-continues-to-target-uk-organisations&site=ncsc" target="_blank"><u>advises</u></a> organizations to take preventative action – with the first steps being to discover weak points and look for help from upstream service providers. </p><p>To deal with attacks which can’t be handled upstream – or only once detected and blocked – they should make sure their service can rapidly scale.</p><p>Similarly, the agency said organizations should define a response plan, covering graceful degradation of services, dealing with changing tactics, retaining administrative access during an attack and having a scalable fallback plan for essential services. </p><p>Gary Barlet, public sector CTO at Illumio, welcomed the focus on mitigation as well as prevention.</p><p>"We need a new way of dealing with DoS attacks. For too long, we have focused solely on prevention, and this approach has not worked," he said.</p><p>"The NCSC’s advice signals a change by recommending that plans include retaining administrative access and implementing full-scale backup plans. However, there needs to be an entire mindset shift within critical infrastructure organizations to focus on prioritizing impact mitigation and maintaining service and operational uptime.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scattered Spider evolved massively in 2025 – here’s what to expect in 2026 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/scattered-spider-evolved-massively-heres-what-to-expect</link>
                                                                            <description>
                            <![CDATA[ If 2025 was the year of Scattered Spider, 2026 could see the hacking collective ramp up further ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wvKg8w3jMgt3siVw6K8RsH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jan 2026 12:01:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:description>                                                            <media:text><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of a circuitboard lined with red lines in the shape of a spider, representing the Scattered Spider threat group.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EC3BuBnLtE6s8TqRFjZodG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>During 2025, the <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer"><u>Scattered Spider</u></a> hacking collective has been linked with numerous devastating attacks, including <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-finally-gets-click-and-collect-up-and-running-again"><u>Marks and Spencer,</u></a> <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre"><u>Jaguar Land Rover</u></a> and <a href="https://www.itpro.com/security/co-op-cyber-attack"><u>the Co-op</u></a>. </p><p>Over the course of the year, Scattered Spider has also been impacted by multiple <a href="https://www.itpro.com/security/ransomware/scattered-spider-the-ransomware-group-behind-the-mgm-cyber-attack-is-still-on-a-rampage-and-authorities-are-ramping-up-efforts-to-catch-them"><u>law enforcement takedowns</u></a> but the organization keeps evolving and splintering off, despite this increased scrutiny. Later in 2025, it emerged that Scattered Spider collaborated with parallel threat groups <a href="https://www.itpro.com/security/cyber-crime-group-claims-successful-attack-on-security-firm-crows-about-it-on-telegram-but-it-was-all-an-elaborate-honeypot"><u>ShinyHunters</u></a> and <a href="https://www.itpro.com/security/cyber-attacks/the-scattered-lapsus-usd-hunters-group-is-targeting-zendesk-customers-heres-what-you-need-to-know"><u>LAPSUS$</u></a> to form a unified collective.</p><p>As Scattered Spider’s activities continue to ramp up, the collective’s changing tactics need to be on every businesses’ radar. Based on the group’s evolution in 2025, what can organizations expect in 2026?</p><h2 id="scattered-spider-attacks-throughout-2025">Scattered Spider attacks throughout 2025</h2><p>Throughout the year, Scattered Spider’s strategy has remained consistent: <a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees"><u>tricking help desks</u></a> and employees into offering access, then jumping straight into cloud apps to steal sensitive data. </p><p>“Once they have the data, they use extortion to pressure companies into paying up,” Trend Micro’s Forward Threat Research team tells <em>ITPro</em>. “It is simple, it works, and they doubled down on it all year.”</p><p>Scattered Spider has evolved its focus over the course of the year. It kicked off 2025 by targeting <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas"><u>software as a service (SaaS)</u></a> platforms, with campaigns targeting Klaviyo and HubSpot using <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> infrastructure hosted on lookalike domains to harvest credentials from corporate users.</p><p>In April, it <a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-have-rocked-uk-retailers-heres-how-you-can-stay-safe"><u>hit UK retailers</u></a>, including Marks and Spencer, Harrods and the Co-op Group. </p><p>From May to June, <a href="https://www.itpro.com/security/cyber-attacks/north-face-cartier-among-latest-retail-cyber-attack-victims-heres-what-we-know-so-far"><u>Cartier and North Face</u></a>, as well as Erie Insurance and Philadelphia Insurance also reported breaches consistent with Scattered Spider’s tactics.</p><p>After wreaking havoc on the retail and insurance sectors, the group quickly shifted to aviation. In June, Hawaii’s Hawaiian Airlines and Canada’s WestJet were attacked, while Australian airline <a href="https://www.bbc.co.uk/news/articles/cd6gnyl9923o" target="_blank"><u>Qantas</u></a> reported a breach of a third-party contact center system. In July, the FBI <a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees"><u>publicly warned</u></a> that Scattered Spider was targeting airlines with <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a> attacks.</p><p>The group tends to focus on one industry at a time, says Aniket Pachchhapur, cybersecurity consultant at GRC Solutions. “Scattered Spider consistently leverages help desk social engineering to penetrate whatever industry it targets. Over time, the group has gravitated toward high-value sectors with widely used outsourced IT services, but it adapts quickly to new targets as defenses stiffen.”</p><p>In all cases the group is known to use a "dual extortion" technique, first demanding a ransom. If that is not paid, they leak the data, says Jake Addison, SOC manager at Reliance Cyber. </p><h2 id="scattered-spider-s-rebrand">Scattered Spider's rebrand</h2><p>Rebranding is another favored tactic. If 2024 put Scattered Spider on the map, 2025 was the year it learned to reinvent itself, says Ed Williams, vice president of EMEA Consulting at Trustwave, a LevelBlue company. </p><p>Rather than disappearing, the group has evolved into a broader extortion ecosystem, now operating under the “Scattered LAPSUS$ Hunters” label. This umbrella identity combines elements of Scattered Spider, ShinyHunters and LAPSUS$, allowing multiple operators to “present a unified front when advantageous”, he says.</p><p>Scattered Spider and the wider cyber-criminal community, the Com, show how modern cyber crime has become “fluid, <a href="https://www.itpro.com/security/cyber-crime/15-year-old-revealed-as-key-player-in-scattered-lapsus-usd-hunters"><u>youth-driven</u></a> and brand-agnostic”, says Rik Ferguson, VP of security intelligence at Forescout. “What we’re seeing now is not a single ‘gang’, but a loose collective that rebrands, regroups and recruits at speed, which is exactly what we observed in LAPSUS$ when we started tracking them back in 2022.”</p><p>The recent alignment with ShinyHunters and LAPSUS$ is “less a merger and more a reflection of how these crews swap members, tooling and tactics, while keeping the pressure on high-value targets”, according to Ferguson.</p><h2 id="law-enforcement-takedowns">Law enforcement takedowns</h2><p>With Scattered Spider’s attack radius surging, it’s no surprise law enforcement has stepped up in response. Arrests in the US and UK have been tied to some of the highest-profile attacks, and agencies have begun calling out the Com as a major emerging crime network.</p><p>Even so, these groups are “loose and flexible”, according to Trend Micro’s Forward Threat Research team: “Even when a few members get taken down, the overall operation keeps moving, almost like swapping players on a team, rather than shutting it down.”</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/9ef7f02f-466f-4466-ae02-cbd718efa275/"></iframe><p>In September 2025, Scattered Lapsus$ Hunters announced a temporary withdrawal from illicit activities on BreachForums, citing mounting law enforcement pressure and recent arrests as reasons for stepping back. However, in November 2025 the cybersecurity firm ReliaQuest observed Scattered Lapsus$ Hunters apparently <a href="https://www.itpro.com/security/cyber-attacks/the-scattered-lapsus-usd-hunters-group-is-targeting-zendesk-customers-heres-what-you-need-to-know"><u>targeting Zendesk users</u></a> via a phishing campaign.</p><p>That same month, the group claimed responsibility for breaching over 200 companies via Gainsight integrations within Salesforce, per <a href="https://techcrunch.com/2025/11/21/google-says-hackers-stole-data-from-200-companies-following-gainsight-breach/"><u><em>TechCrunch</em></u></a> reporting.</p><p>Law enforcement takedowns have impacted the collective, but only at a surface level, says Williams. “Their public Telegram channels were removed at least a dozen times this year, yet they consistently rebuilt, often within hours. Instead of deterring activity, disruptions have actually amplified the collective’s reliance on spectacle.”</p><h2 id="scattered-spider-continues-to-evolve">Scattered Spider continues to evolve</h2><p>Through 2026, it is likely Scattered Spider will continue its methodology of either targeting companies within a particular sector, or focussing on a larger SaaS application such as Salesforce, says Addison. </p><p>From a tactics standpoint, the group has doubled down on social engineering, now at a greater scale, says Williams. Automated spear-phishing tools, some abusing services such as Google Voice, have enabled the threat group to “run high-volume identity harvesting campaigns with minimal manual effort”, he says.</p><p>Scattered Spider is also heightening its focus on insider access as a means to compromise networks, according to Addison. He cites the example of an <a href="https://www.itpro.com/security/cyber-attacks/crowdstrike-insider-attack-wake-up-call"><u>attack on security company Crowdstrike</u></a>, which dismissed an employee after screenshots of their work device were found posted on Telegram by the collective.</p><p>The group has talked about launching its own <a href="https://www.itpro.com/security/ransomware/the-top-ransomware-trends-for-businesses"><u>ransomware as a service</u></a> this year, as well as floating the idea of an extortion as a service operation for any threat actors wishing to leverage the Scattered LAPSUS$ Hunters brand in their own attacks. “So we may see these being launched in 2026,” says Aiden Sinnot, principal threat researcher at Sophos.</p><p>As companies upgrade their security throughout 2026, identity and SaaS security should be a priority, according to Trend Micro’s Forward Threat Research team. “These attackers continue to prove they do not need advanced <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> to break into critical environments.”</p><p>Taking this into account, stronger verification for help desk requests, phishing resistant MFA for admins and tight controls on <a href="https://www.itpro.com/security/data-breaches/third-party-data-breaches-global-statistics">third-party SaaS integrations</a> will also go a long way. “And honestly, training people on how to handle suspicious phone calls or push spam is just as important,” Trend Micro’s researchers advise. </p><p>As part of IT help desk impersonation, Scattered Spider is known to <a href="https://www.itpro.com/security/why-remote-desktop-tools-are-facing-an-onslaught-of-cyber-threats">install remote tools for access</a>. Addison recommends that IT teams use as small a subset of trusted tools as possible, and ensure defenders are monitoring, alerting and blocking any others.</p><p>Scattered Spider is known to monitor communication platforms such as Teams and Slack, impersonating compromised user accounts to facilitate further information gathering. With this in mind, ensure that no sensitive data such as passwords is ever shared via these platforms, Addison advises. “And where possible video call people to verify that they are who they say.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are AI cyber threats overhyped? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/are-ai-cyber-threats-overhyped</link>
                                                                            <description>
                            <![CDATA[ As cyber teams turn to the threats posed by AI, rising attacks by state-sponsored groups and ransomware gangs remain the biggest threat ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vbrBVjY68ytrxbiJynqogD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M7tM2QS8kMpFQQmqNhUnJg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jan 2026 12:26:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M7tM2QS8kMpFQQmqNhUnJg-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The text &quot;Are AI cyber threats overhyped?&quot; against a stylized background of green dots representing code on a dark background. The words &quot;AI cyber threats&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:description>                                                            <media:text><![CDATA[The text &quot;Are AI cyber threats overhyped?&quot; against a stylized background of green dots representing code on a dark background. The words &quot;AI cyber threats&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:text>
                                <media:title type="plain"><![CDATA[The text &quot;Are AI cyber threats overhyped?&quot; against a stylized background of green dots representing code on a dark background. The words &quot;AI cyber threats&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M7tM2QS8kMpFQQmqNhUnJg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/d27ed604-4541-4b22-acce-3c5ab40e5fc9/"></iframe><p>We’re just over a week into 2026 but already, enterprise cybersecurity teams will be hard at work repelling attacks – and business leaders will be worrying about the year ahead.</p><p>On the one hand, we’re told that AI tools are beginning to empower security teams to go further and faster. On the other, the use of AI by hackers to launch attacks also appears to be on the rise.</p><p>All of this is happening against a backdrop of rising geopolitical tensions and continual attacks by state-sponsored hacking groups against businesses. How will all this come together in 2026 and beyond?</p><p>In this episode, Jane and Rory are joined by Jamie Collier, lead advisor in Europe at Google Threat Intelligence Group, to explore the risks – both novel and ordinary – enterprises face in 2026.</p><h2 id="highlights">Highlights</h2><p>"I think one of the big reflections for me is just the extent to which threat actors are adapting to what I would call modern infrastructure. We think about the way that a lot of these traditional attacks have worked, we've seen that typical hack moving through the network, escalating privileges, etc. When we look towards defending cloud, SaaS, these sorts of spaces, it's a very different space, a lot more emphasis on identity and that is providing, effectively, a bypass to a lot of those complex threat operations where these threat actors can just really log in."</p><p>"The most obvious way that for actors are using AI is probably the most boring in terms of it's just different levels of automation of their attack life cycle. It's crafting phishing emails. It's conducting reconnaissance. I think that sort of goes without saying, and actually a lot of that is in areas we're not necessarily going to fully see, because they're going to be doing that with their own models, etc."</p><p>"There is a lot more to North Korea than just IT workers, right? We see also very big targeting of software developers, we see cryptocurrency remains a primary target, and I think given that their kind of dual objective of financial motivated operations and strategic intelligence gathering, it actually exposes a lot of organizations to all sorts of different types of North Korean threats that range from tailored targeting, to employment fraud, to initial access to cryptocurrency theft, ransomware, supply chain compromise."</p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know" target="_blank">NCSC issues urgent warning over growing AI prompt injection risks – here’s what you need to know</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-experts-have-been-warning-about-ai-powered-ddos-attacks-now-theyre-becoming-a-reality" target="_blank">Cyber experts have been warning about AI-powered DDoS attacks – now they’re becoming a reality</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-us-congress-email-cyber-attack" target="_blank">Salt Typhoon attack on US congressional email system ‘exposes how vulnerable core communications systems remain to nation-state actors’</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/openai-chatgpt-atlas-ai-browser-prompt-injection-attack-risk" target="_blank">OpenAI says prompt injection attacks are a serious threat for AI browsers – and it’s a problem that’s ‘unlikely to ever be fully solved'</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/openai-turns-to-red-teamers-to-prevent-malicious-chatgpt-use-as-company-warns-future-models-could-pose-high-security-risk" target="_blank">OpenAI turns to red teamers to prevent malicious ChatGPT use as company warns future models could pose 'high' security risk</a></li><li><a href="https://www.itpro.com/security/a-flaw-in-googles-new-gemini-cli-tool-couldve-allowed-hackers-to-exfiltrate-data" target="_blank">A flaw in Google’s new Gemini CLI tool could’ve allowed hackers to exfiltrate data</a></li><li><a href="https://www.itpro.com/business/google-says-leading-ai-malware-strains-are-nowhere-near-good-enough-yet-but-that-wont-last-long-as-hackers-refine-techniques" target="_blank">Google says you shouldn't worry about AI malware – but that won’t last long as hackers refine techniques</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat" target="_blank">North Korean IT workers: The growing threat</a></li><li><a href="https://www.itpro.com/business/business-strategy/north-korean-hackers-targeting-developers-open-source-malware-36000" target="_blank">North Korean hackers continue targeting developers in open source malware campaign - and experts say as many as 36,000 victims have been snared so far</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026" target="_blank">CRINK attacks: which nation state hackers will be the biggest threat in 2026?</a></li></ul><h2 id="subscribe">Subscribe </h2><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154" target="_blank"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ" target="_blank"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://uk.linkedin.com/company/itpro-uk" target="_blank"><u>Join us on LinkedIn</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Salt Typhoon attack on US congressional email system ‘exposes how vulnerable core communications systems remain to nation-state actors’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/salt-typhoon-us-congress-email-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The Salt Typhoon campaign marks the latest in a string of attacks on US government communications networks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pscbcTCeM42F4YCpbhU5i8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/76io5ZvXUvjqDygtAD726R-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 12:49:29 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Jan 2026 12:50:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/76io5ZvXUvjqDygtAD726R-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The US House of Representatives chamber pictured empty during a press tour.]]></media:description>                                                            <media:text><![CDATA[The US House of Representatives chamber pictured empty during a press tour.]]></media:text>
                                <media:title type="plain"><![CDATA[The US House of Representatives chamber pictured empty during a press tour.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/76io5ZvXUvjqDygtAD726R-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Chinese state-backed threat group Salt Typhoon is believed to have gained access to email systems used by US Congressional Committee staff. </p><p>According to reports from the <a href="https://www.ft.com/content/44f730c4-7de3-4a09-88dd-41ea9c373dcb" target="_blank"><u><em>Financial Times</em></u></a>, the threat group is thought to have compromised accounts belonging to staff working on the House China Committee. </p><p>Aides working at the Foreign Affairs Committee, Armed Services Committee, and Intelligence Committee are also believed to have been impacted by the attacks. </p><p>Sources told the <em>FT </em>the incident was first discovered in December. </p><p>Exact details on the scope of the incident are yet to be confirmed. A person familiar with the matter told the publication it remains unclear whether the group fully accessed email communications.</p><h2 id="salt-typhoon-has-cyber-agencies-on-alert">Salt Typhoon has cyber agencies on alert</h2><p>The campaign marks the latest in a string of attacks by Salt Typhoon on US government email systems and telecommunications networks. </p><p>A previous attack saw the threat group access and <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-hacker-group-recorded-conversations-of-very-senior-us-political-figures"><u>record telephone conversations of “very senior” American political figures</u></a>, according to Anne Neuberger, deputy national security advisor for cyber and emerging technology under the Biden administration. </p><p>This particular campaign saw the group compromise major US telecoms companies, including Verizon, Lumen Technologies, and AT&T. </p><p>Salt Typhoon activities have escalated over the last three years, with security agencies on both sides of the Atlantic issuing repeated warnings about the threat posed by the group. </p><p>An advisory from the FBI in September noted the group had hit organizations in more than 80 countries as <a href="https://www.itpro.com/security/cyber-attacks/fbi-warns-indiscriminate-salt-typhoon-hacking-campaign-has-hit-organizations-in-more-than-80-countries"><u>part of an “indiscriminate” hacking campaign</u></a>. </p><p>In mid-2025, it was revealed the threat group also <a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach"><u>compromised US state National Guard networks</u></a>. An investigation by the US Department of Defense (DoD) found hackers breached and laid low in compromised networks for almost a year. </p><p>The DoD warned the group may have accessed sensitive information pertaining to military and law enforcement operations. </p><h2 id="deeply-concerning-attacks">“Deeply concerning” attacks</h2><p>Benjamin Schilz, CEO at Wire, said the latest campaign “exposes how vulnerable core communications systems remain to nation-state actors”</p><p>“The Salt Typhoon espionage campaign highlights a sustained, state-backed assault on U.S. communications infrastructure by China’s Ministry of State Security,” he said. </p><p>“Regardless of whether lawmakers’ emails were accessed, the fact this activity went undetected for years is deeply concerning.</p><p>“Persistent access of this nature creates the potential to intercept unencrypted communications, including calls, messages, and voicemails across the U.S. population, posing a serious national security risk,” Schilz added.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacked London council warns 100,000 households at risk of follow-up scams ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/kensington-and-chelsea-council-cyber-attack-data-breach</link>
                                                                            <description>
                            <![CDATA[ The council is warning residents they may be at increased risk of phishing scams in the wake of the cyber attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wZ7G9ZrPZjmFuj5WHFTupd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 12:04:34 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Jan 2026 13:55:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:description>                                                            <media:text><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:text>
                                <media:title type="plain"><![CDATA[Fallen leaves pictured on the pavement outside residential townhouses in London&#039;s Kensington Gardens area, part of the Kensington and Chelsea Council district.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FAsuGpEyETVLrjxktBXe5B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A London council has written to hundreds of thousands of residents to warn them that criminals may use details leaked via a cyber attack last year to target them for scams. </p><p>At the end of November, Kensington and Chelsea was one of a <a href="https://www.itpro.com/security/cyber-attacks/hammersmith-and-fulham-council-cyber-attacks"><u>trio of west London councils that suffered an outage</u></a> that was quickly <a href="https://www.itpro.com/security/cyber-attacks/ncsc-called-in-as-london-councils-grapple-with-cyber-attacks"><u>attributed to a cyber attack</u></a>. </p><p>A week later, the council confirmed that personal <a href="https://www.itpro.com/security/hacking/data-was-likely-leaked-in-council-hack"><u>data was likely leaked</u></a>, though it stressed it was only "historical data". </p><p>Now, a spokesperson for the council has said the attackers had "criminal intent", with the council's <a href="https://www.rbkc.gov.uk/newsroom/we-are-responding-cyber-security-issue" target="_blank"><u>website</u></a> adding that sensitive data and personal information that could impact residents had been accessed by the attackers. </p><p>Council leader Elizabeth Campbell said the "serious" breach required action from the council, with an update in the middle of December saying 100,000 households had already been contacted with warnings following the attack. </p><p>A spokesperson told <em>ITPro </em>the letters were sent out at the beginning of December, and the message references the attack of "two weeks ago". </p><p>"We decided to go out immediately and say to people this is what's happened, this data has been copied and it has been taken and you should be aware therefore you are at risk," she told the <a href="https://www.bbc.co.uk/news/articles/ce3knggd1lwo" target="_blank"><u><em>BBC</em></u></a>. </p><h2 id="written-warning">Written warning</h2><p>In a copy of the letter shared with <em>ITPro </em>by the council, recipients are advised to be wary of scam messages, check online accounts for unusual activity, and report any suspicious activity to the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>.</p><p>"Like any local authority, it was always possible that our systems could come under attack and therefore we had invested significantly in our digital, data and technology services over many years," Campbell said in the letter. </p><p>"This meant that we had a cyber defence system that was able to spot this attack quickly and protect much of our infrastructure, and the infrastructure of others, as best as possible."</p><p>Campbell added: "Despite this, we do believe that some data has been copied and taken. It is important to say we still have access to this information, but it is possible a copy could end up in the public domain. As a priority we are checking if this contains any personal or financial details of residents, customers, and service users. This may take months and we will update residents at every step."</p><p>The council is now "going through all the documentation" to spot any specific risks and will contact individuals directly if affected, though it noted that work may take months. </p><p>Similarly, the local authority said it was checking which details in files may have been accessed, admitting that work may yield nothing, but said "we want to make sure we turn over every stone."</p><h2 id="what-happened">What happened</h2><p>The attack began on the morning of 24 November, and was immediately spotted by staff at Kensington and Chelsea, who took steps to isolate systems. </p><p>A week later, that council admitted some data had been accessed, including sensitive information; however, it stressed the data wasn't encrypted by the attackers, such as in a <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attack, and therefore remained accessible to the council. </p><p>Hammersmith and Fulham Council and Westminster City Council were the other two local authorities hit by the outage, as the three organizations share some systems. </p><p>Hammersmith has said it so far appears its systems were not compromised, while Westminster earlier this month <a href="https://www.bbc.co.uk/news/articles/czrke560ze3o.amp" target="_blank"><u>confirmed</u></a> that "limited data" had been breached. </p><p>Keven Knight, CEO of Talion, told <em>ITPro </em>last year that councils are a prime target for cyber criminals, largely due to the scope of personal and financial information they hold on residents.</p><p>"This is the type of information that can’t be changed easily. This means it's now in the hands of a threat actor, and victims will be exposed to an increased risk of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>," he said.</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> has been informed of the incident, and the Metropolitan Police and NCSC are investigating. So far, there's no indication who is behind the attack. </p><p>"The Met is leading an investigation and we are working alongside them with the national cyber security centre and the NCC Group," a spokesperson for Kensington and Chelsea council said. </p><p>"We are taking steps to work through the data in accordance with ICO and legal rules."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacker offering US engineering firm data online after alleged breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hacker-offering-us-engineering-firm-data-online-after-alleged-breach</link>
                                                                            <description>
                            <![CDATA[ Data relating to Tampa Electric Company, Duke Energy Florida, and American Electric Power was allegedly stolen ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jh9aTUhGsytBhJ5PDe8U6k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dyefxvMjRzV26cLHKKchw3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Jan 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dyefxvMjRzV26cLHKKchw3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing a yellow-colored alert symbol pictured against a jet black background.]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing a yellow-colored alert symbol pictured against a jet black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing a yellow-colored alert symbol pictured against a jet black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dyefxvMjRzV26cLHKKchw3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A cyber criminal is claiming to have seized data from Florida-based engineering firm Pickett and Associates relating to three US utilities.</p><p>Pickett provides transmission and distribution power line design, aerial surveying, and LiDAR services to major utilities and mining firms across the US and the Caribbean.</p><p>The hacker in question is now <a href="https://x.com/MonThreat/status/2006989633322692633" target="_blank"><u>offering</u></a> around 139 GB of engineering data - 892 files - about Tampa Electric Company, Duke Energy Florida, and American Electric Power on a <a href="https://www.itpro.com/business/google-is-scrapping-its-dark-web-report-feature-heres-everything-you-need-to-know-and-some-alternative-options">dark web</a> forum. </p><p>There's an asking price of 6.5 bitcoin, or a little under $600,000.</p><p>The data is claimed to include more than 800 classified raw LiDAR point cloud files in .las format, ranging from 100 MB to 2 GB in size, along with full coverage of transmission line corridors and substations, including layers for bare earth, vegetation, conductors, and structure.</p><p>Also apparently up for sale are high-resolution orthophotos in .ecw format, microStation design files and PTC settings, large vegetation feature files in .xyz format and preserved folder structures from active projects.</p><p>"This dataset contains real, operational engineering data from active projects of major utilities and is suitable for infrastructure analysis, modelling, risk assessment of specialized research," the hacker said. </p><p>Tampa Electric Company has around 860,000 business and residential customers in West Central Florida, while Duke Energy Florida has about two million. American Electric Power, meanwhile, boasts nearly 5.6 million customers across 11 states. </p><p><em>ITPro </em>approached Pickett and Associates for comment, but did not receive a response by time of publication.</p><h2 id="german-solar-company-data-up-for-grabs">German solar company data up for grabs</h2><p>The same criminal is also offering what's claimed to be an internal database belonging to Hamburg, Germany-based solar energy firm Enerparc AG. The data is claimed to include information about solar projects in Spain’s Mallorca and Alicante regions. </p><p>According to <a href="https://assets.sophos.com/X24WTUEQ/at/75tnw38cqsnrrv56wpwc78k/sophos-state-of-ransomware-critical-infrastructure-2024.pdf" target="_blank"><u>research</u></a> from Sophos, 67% of energy, oil or gas and utilities firms suffered a ransomware attack in 2024, up from 55% in 2020. </p><p>This time last year, TrustWave <a href="https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/2025_Trustwave_Energy_Utilities_Risk_Radar_Report.pdf" target="_blank"><u>said</u></a> that ransomware attacks targeting the energy and utilities sectors rose by 80% in 2024. </p><p>Energy firms are frequently targeted by hacktivists and nation state actors including Russia, China, Iran and North Korea, with China's <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid">Volt Typhoon</a> hitting a number of power utilities in 2023. </p><p>All in all, US critical infrastructure operators reported almost 4,900 <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threats in 2024.</p><h2 id="critical-industries-in-the-crosshairs">Critical industries in the crosshairs</h2><p>According to recent <a href="https://www.kelacyber.com/resources/research/escalating-ransomware-threats-to-national-security/" target="_blank"><u>research</u></a> from security firm Kela, global <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks against critical industries rose by 34% in 2025. </p><p>The US was the most-affected country, accounting for 21% of global incidents, followed by Canada, Germany, the UK, and Italy.</p><p>"In critical industries, such disruptions can have national-level consequences, undermining essential operations and eroding public trust," commented Lin Levi, Kela threat intelligence team lead.</p><p>"To protect critical services, governments and critical industry sectors must prioritize proactive preventative measures and maintain continuous real-time monitoring to detect and respond to cyber threats."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon says Russian-backed threat groups were responsible for five-year-long attacks on edge devices – and it shows a ‘clear evolution in tactics’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/amazon-says-russian-backed-threat-groups-were-responsible-for-five-year-long-attacks-on-edge-devices-and-it-shows-a-clear-evolution-in-tactics</link>
                                                                            <description>
                            <![CDATA[ Russian-backed hacker groups are exploiting misconfigured edge devices – now preferring that tactic over hunting down traditional vulnerabilities to gain access to company networks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KPvcf4K6R3rXxXStfbPF9H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZkuGfPqG9kpZRACFyAJBaT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Dec 2025 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZkuGfPqG9kpZRACFyAJBaT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon logo pictured against an orange backdrop at the Amazon corporate headquarters in Seattle, Washington state.]]></media:description>                                                            <media:text><![CDATA[Amazon logo pictured against an orange backdrop at the Amazon corporate headquarters in Seattle, Washington state.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon logo pictured against an orange backdrop at the Amazon corporate headquarters in Seattle, Washington state.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZkuGfPqG9kpZRACFyAJBaT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-warfare/367461/five-eyes-nations-warn-against-impending-russian-cyber-attacks">Russian-backed hacker groups</a> are exploiting misconfigured edge devices – now preferring that tactic over hunting down traditional vulnerabilities to gain access to company networks. </p><p>That's according to an end-of-year report by Amazon Threat Intelligence, which included details of a nearly five-year-long campaign by Russian state-sponsored hackers that AWS said marked a pivot in tactics. </p><p>Now, the primary initial access vector has become misconfigured customer network edge devices, according to AWS Security <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>CJ Moses, with a decline in traditional vulnerability exploitation. </p><p>"This tactical adaptation enables the same operational outcomes, credential harvesting, and lateral movement into victim organizations’ online services and infrastructure, while reducing the actor’s exposure and resource expenditure," Moses noted in a <a href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-identifies-russian-cyber-threat-group-targeting-western-critical-infrastructure/" target="_blank"><u>post on the AWS security blog</u></a>. </p><p>Amazon isn't the first to spot a shift to edge devices. <a href="https://www.itpro.com/security/edge-devices-are-now-your-weakest-link-vpns-firewalls-and-routers-were-the-leading-source-of-initial-compromise-in-30-percent-of-incidents-last-year-heres-why"><u>Sophos noted</u></a> in April that edge devices like firewalls and routers were the main initial attack vector for 30% of incidents last year, while governmental security agencies <a href="https://www.itpro.com/security/five-eyes-cyber-agencies-issue-guidance-on-edge-device-vulnerabilities"><u>issued guidance about vulnerabilities in edge devices</u></a> back in February.</p><p>Last year, Fortinet's FortiGate edge devices were <a href="https://www.itpro.com/security/thousands-of-fortinets-fortigate-edge-devices-were-exposed-in-a-chinese-backed-hacking-campaign"><u>exploited by China-backed hackers</u></a>, and the FBI <a href="https://www.itpro.com/security/thousands-of-fortinets-fortigate-edge-devices-were-exposed-in-a-chinese-backed-hacking-campaign"><u>warned</u></a> that Ubiquity EdgeRouters were targeted via a wide-ranging hacking campaign.</p><h2 id="how-the-edge-campaign-unfolded">How the edge campaign unfolded</h2><p>According to Amazon, hackers targeted enterprise routers, VPN concentrators and remote access gateways, network management appliances, and cloud-based project management systems, as well as collaboration and wiki platforms. </p><p>Moses said the evidence suggested that the hackers were using packet capture and traffic analysis to target network edge devices. This involves attackers compromising an edge device hosted on AWS, capturing packets to harvest credentials, and then using those to penetrate an organization's services or infrastructure, gaining access to wider systems. </p><p>AWS telemetry suggested the attackers maintained persistent connections, allowing for data to be stolen. </p><p>"Targeting the 'low-hanging fruit' of likely misconfigured customer devices with exposed management interfaces achieves the same strategic objectives [as vulnerability exploitation], which is persistent access to critical infrastructure networks and credential harvesting for accessing victim organizations’ online services," Moses added.</p><p>Notably, the company revealed those attacks included customer network edge devices hosted on AWS. </p><p>"This was not due to a weakness in AWS; these appear to be customer misconfigured devices. Network connection analysis shows actor-controlled IP addresses establishing persistent connections to compromised <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>instances operating customers’ network appliance software," Moses noted. </p><p>That said, AWS did take action. For example, the cloud giant notified affected customers that they were compromised, fixed compromised EC2 instances, and alerted network alliance vendors. </p><p>"Through coordinated efforts, since our discovery of this activity, we have disrupted active threat actor operations and reduced the attack surface available to this threat activity subcluster," Moses added. </p><p>To protect edge devices against this style of attacks, organizations must secure and monitor their edge devices, Moses advised, keeping watch for unexpected packet capture files or utilities and enforcing strong authentication – in particular those working in the energy sector or critical national infrastructure. </p><h2 id="a-clear-evolution-in-tactics">A 'clear evolution in tactics'</h2><p>This particular string of attacks dates back to 2021 and appears to be associated with Russia's Main Intelligence Directorate, Moses said. </p><p>Similarly, the campaign focused primarily on critical national infrastructure in the West, targeting the energy sector and its supply chain in particular. </p><p>Moses traced a timeline back to 2021's WatchGuard exploitation, saying that's when Amazon first spotted the hackers targeting misconfigured devices. </p><p>That continued in the next few years with misconfigured devices targeted alongside exploits such as the <a href="http://itpro.co.uk/security/zero-day-exploit/368086/exploitation-of-atlassian-confluence-zero-day-surges-fifteen-fold"><u>Confluence</u></a> and <a href="https://www.bleepingcomputer.com/news/security/new-veeam-rce-flaw-lets-domain-users-hack-backup-servers/" target="_blank"><u>Veeam</u></a> flaws, but by 2025 the hackers' success with edge devices led to that taking centre stage with zero-day exploitation activity declining.</p><p> "The campaign demonstrates a clear evolution in tactics," Moses said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK government confirms October cyber breach: Everything we know so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/uk-government-confirms-october-cyber-breach-everything-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ Details around Foreign Office hack remain sparse and government says it's unclear who is behind the attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">irazv9nGQJrtXVwmYR45tN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Dec 2025 12:47:17 +0000</pubDate>                                                                                                                                <updated>Mon, 22 Dec 2025 12:48:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:description>                                                            <media:text><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government has confirmed reports that its Foreign Office was hacked – but won't say whether or not China was behind the operation. </p><p>Last week, the <em>Sun</em> <a href="https://www.thesun.co.uk/news/37681625/china-hackers-stole-secret-files-foreign-office/" target="_blank">reported </a>that Chinese hacking group Storm 1849 had breached the UK Foreign, Commonwealth and Development Office (FCDO) in October and stolen tens of thousands of files — potentially including personal information including details about visa applicants. </p><p>Indeed, a separate report from Sky news suggested it was a Home Office system targeted, which was run by the FCDO. </p><p>A government spokesperson admitted the attack: "We have been working to investigate a cyber incident. We take the security of our systems and data extremely seriously." </p><h2 id="limited-confirmation">Limited confirmation</h2><p>A day later British trade department minister Chris Bryant confirmed the attack while speaking to various media outlets – but said he couldn't say who was behind the attack or whether China was involved. </p><p>"There certainly has been a hack," Bryant told Times Radio, according to <a href="https://www.reuters.com/world/uk/uk-government-was-hacked-october-minister-confirms-2025-12-19/"><u>Reuters</u></a>. "I'm not able to say whether it is directly related to Chinese operatives, or indeed, the Chinese state."</p><p>Bryant told <a href="https://news.sky.com/story/foreign-office-has-been-hacked-but-ministers-fairly-confident-individual-data-not-at-risk-13485472" target="_blank"><u><em>Sky News</em></u></a><em> </em>that the government became aware of the attack in October and didn't believe individual data had been accessed, adding it remained unclear who was behind the incident. </p><p>He suggested that the reporting around the hack was "a bit more speculation than accurate," accusing the <em>Sun </em>of "slightly over-egging the kind of details that are available at this stage."</p><p>However, Bryant also admitted that the government could share "remarkably little" about the incident despite investigating for several weeks. He did say that the "hole" was closed quickly, and that the attackers exploited a "technical issue", Sky noted. </p><p>Bryant added: "And we're fairly confident that there's a low risk of any individual actually being affected by this."</p><h2 id="china-or-not">China or not? </h2><p>The <em>Sun </em>report pinned the blame on China and the Storm 1849 hacking group, noting that it has been previously accused of targeting the UK government via attacks against MPs and the <a href="https://www.itpro.com/security/cyber-attacks/security-experts-raise-questions-about-uk-cyber-funding-in-wake-of-electoral-commission-hack"><u>Electoral Commission</u></a>. </p><p>In October, Prime Minister Starmer was <a href="https://www.reuters.com/world/uk/starmer-denies-trying-appease-china-says-spying-case-dropped-legal-grounds-2025-10-08" target="_blank"><u>forced to deny</u></a> that his government was hoping to appease China, after a spying case involving the country was dropped. Earlier in December, <a href="https://www.reuters.com/world/uk/uks-starmer-warns-china-poses-security-threats-urges-deeper-business-ties-2025-12-01/" target="_blank"><u>Starmer admitted</u></a> that China posed  "national security threats" to the UK. </p><p>The Chinese embassy in the UK said via a spokesperson, per <a href="https://news.sky.com/story/foreign-office-has-been-hacked-but-ministers-fairly-confident-individual-data-not-at-risk-13485472" target="_blank"><u><em>Sky News</em></u></a>: "We strongly oppose such false accusations targeting China. China is a staunch defender of cybersecurity and one of the major victims of cyber espionage and attacks."</p><h2 id="attacks-on-the-uk">Attacks on the UK</h2><p>The incident follows serious hacks against major British businesses and institutions, including the ransomware attack against the <a href="https://www.itpro.com/security/british-library-cyber-attack-fallout-highlights-public-sector-security-weaknesses"><u>British Library in 2023</u></a> and major retailers <a href="https://www.itpro.com/security/co-op-cyber-attack"><u>M&S and Co-op this year</u></a>. Jaguar Land Rover was also knocked offline, halting car production, <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-u-turns-on-cyber-attack-containment-claims-admits-some-data-has-been-affected"><u>following a cyber attack this year</u></a>.</p><p>The <a href="https://www.itpro.com/security/british-library-cyber-attack-fallout-highlights-public-sector-security-weaknesses"><u>public sector is particularly at risk</u></a>, experts told <em>ITPro </em>last year, as lower budgets make it harder to fill security professional roles. </p><p>Indeed, <a href="https://www.itpro.com/security/cyber-attacks/security-experts-raise-questions-about-uk-cyber-funding-in-wake-of-electoral-commission-hack?utm_source=chatgpt.com"><u>industry experts have called</u></a> for the government to increase its security budget amid the rise in attacks, in particular as hackers have started to <a href="https://www.itpro.com/security/hackers-are-lying-low-in-networks-to-wage-critical-infrastructure-attacks-heres-how-they-do-it?utm_source=chatgpt.com"><u>target critical national infrastructure</u></a>.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CRINK attacks: which nation state hackers will be the biggest threat in 2026? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026</link>
                                                                            <description>
                            <![CDATA[ The past year has seen a number of attacks performed by China, Russia, Iran and North Korea (CRINK) ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7sUkhUJMjvtJhCpZTrpYRo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DLxjABjPkUcaH7dcPD3o2D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Dec 2025 08:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 22 Dec 2025 11:41:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DLxjABjPkUcaH7dcPD3o2D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract map of the world overlaid with colorful geometric shapes, to represent the fractured regulatory landscape businesses face in 2025.]]></media:description>                                                            <media:text><![CDATA[An abstract map of the world overlaid with colorful geometric shapes, to represent the fractured regulatory landscape businesses face in 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract map of the world overlaid with colorful geometric shapes, to represent the fractured regulatory landscape businesses face in 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DLxjABjPkUcaH7dcPD3o2D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Throughout 2025 <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>nation state adversaries</u></a> have carried out a large number of notable attacks, with incidents attributed to China, <a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do"><u>Russia</u></a>, <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iran</u></a> and <a href="https://www.itpro.com/business/business-strategy/north-korean-hackers-targeting-developers-open-source-malware-36000"><u>North Korea</u></a> – also known as CRINK. In August, UK and US officials <a href="https://www.ncsc.gov.uk/news/uk-allies-expose-china-tech-companies-enabling-cyber-campaign"><u>publicly linked</u></a> three technology companies based in China with a global malicious cyber campaign targeting critical networks. </p><p>Russia is engaged in <a href="https://www.gov.uk/government/news/uk-smashes-russian-cybercrime-networks-responsible-for-attacks-on-uk-businesses"><u>rampaging cyber attacks</u></a> in Ukraine and abroad, hitting critical sectors such as energy as part of its geopolitical aims. Iran is becoming a more formidable adversary, while <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat"><u>North Korean IT workers</u></a> have been infiltrating an increasing number of firms in the US and Europe.</p><p>Going into 2026, the landscape is shifting slightly, so which of the CRINK attackers is the biggest threat to businesses?</p><h2 id="china-in-the-lead">China in the lead</h2><p>Experts concur that <a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats"><u>China is a leading threat</u></a> to UK and US businesses, but it might not pose the most pressing risk. </p><p>China represents the most “persistent, long-term threat” to western firms, says Philip Ingram, MBE, a former colonel in British military intelligence. This due to its “focus on harvesting as much data as it can, stealing IP and proprietary data via stealthy, long-dwell operations”, he says.</p><p>China-nexus operations aiming to influence its future ability to understand and manipulate western thinking “consistently surpasses the volume of other nations”, according to Ingram. </p><p>He paints a scary picture of China adversarial activity: “They are on a massive data harvesting mission, storing anything and everything they can find, in order to create a lake of data they can analyse when <a href="https://www.itpro.com/security/cyber-security/370298/what-is-steal-now-crack-later-quantum-computing"><u>quantum computing challenges</u></a> are overcome.”</p><p>However, this is a more long term risk. Russia presents the highest immediate threat of “catastrophic operational disruption for <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat"><u>critical national infrastructure (CNI)</u></a>”, Ingram adds.</p><p>At the same time, he warns, Iran-backed groups are growing more sophisticated, leveraging <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected"><u>AI in social engineering</u></a> and focusing on targets in the Middle East, Israel and the US and UK to support regional political objectives. </p><h2 id="a-relative-threat">A relative threat</h2><p>The threat posed by nation state adversaries is relative, based on the country and industry a firm operates in. “If you are in Ukraine and Eastern Europe, the biggest risk is Russia,” according to Ian Thornton-Trump, CISO at Inversion6.</p><p>“For US critical infrastructure, the biggest risk is China; if you’re an Iranian dissident, it’s the Iranian intelligence services and their surveillance capabilities: and if you have anything to do with Bitcoin it’s North Korea.”</p><p>While all firms can be a target of nation state attacks, a few sectors are at a more obvious risk. Organizations targeted by Chinese nation state activity include those within CNI such as energy and utilities, either directly, or indirectly via the supply chain, says Darrel Lang, cyber threat intelligence analyst at Bridewell “This serves the national objectives set by the Chinese Communist Party (CCP) to develop and assert domestic economic and technological dominance, where <a href="https://www.itpro.com/security/cyber-attacks/we-need-to-talk-about-operational-technology"><u>pre-positioned backdoor accesses</u></a> are the primary objective. Theft of intellectual property is now secondary.”</p><p>On top of CNI and the supply chain, nation states are also targeting the AI ecosystem, says Ingram. Semiconductor manufacturers, AI model developers, and companies with large, proprietary training datasets are at risk from nation states and China-backed adversaries in particular, he warns. </p><p>This is likely to continue into 2026, with China continuing its successful <a href="https://www.itpro.com/security/cyber-attacks/fbi-warns-indiscriminate-salt-typhoon-hacking-campaign-has-hit-organizations-in-more-than-80-countries"><u>“Typhoon” campaigns</u></a> seeking to embarrass western governments and “take as much intellectual property as possible”, says Thornton-Trump. </p><p>At the moment, the Iranian regime is “confined to the home front” to focus on dissidents, Thornton-Trump says. Yet he thinks it’s probable the nation “will execute some large cyber-attacks” to “keep Hamas, Hezbollah and the Houthis in awe of the Regime”. </p><p>North Korea is still largely focused on money, specifically cryptocurrencies, says Thornton-Trump. He thinks 2026 will reveal the extent to which the <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1"><u>IT supply chain</u></a> has been compromised at a global level by the <a href="https://www.itpro.com/security/cyber-crime/us-citizen-charged-with-aiding-north-korean-hackers-moonlighting-as-tech-workers"><u>North Korean IT workers scheme</u></a> – which famously <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think"><u>impacted security firm KnowBe4</u></a> in 2024. </p><p>“Some researchers believe it’s been in place as early as 2014 and the amount of intellectual property stolen from IT companies could be extraordinary.”</p><h2 id="types-of-crink-attacks">Types of CRINK attacks </h2><p>While nation state adversaries often focus on specific targets, there is no single tactic, technique and procedure (TTP) to look out for going into 2026, says Lang. “Chinese nation-state groups have demonstrated the capability to secure initial access via numerous methods, often tailored on the basis of prior reconnaissance activity,” he says. </p><p>However, key attack vectors that must be considered are supply chain compromise, <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-fake-tool-installers-to-dupe-victims-and-ai-tools-like-chatgpt-are-a-key-target"><u>SEO poisoning</u></a> and exploits of public facing applications, Lang suggests. “These techniques enable low-noise approaches to a target network and a minimalist footprint from which they can conduct long-term actions on objectives.”</p><p>Often, the means of nation states gaining access are simple and well-trodden. Most recently, <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a>, in particular <a href="https://www.itpro.com/security/what-is-a-toad-attack"><u>vishing</u></a>, has been making a comeback, says Andy Swift, cybersecurity assurance technical director, Six Degrees. “<a href="https://www.itpro.com/security/is-remote-work-really-insecure"><u>Complexities of remote work</u></a> and supply chains in the modern workplace have created space for this type of attack to thrive and a number of organizations are finding themselves without guidance or policy.”</p><p>The most important thing to understand is that nation state actors “generally <a href="https://www.itpro.com/security/cyber-attacks/states-dont-do-hacking-for-fun-ncsc-expert-urges-businesses-to-follow-geopolitics-as-defensive-strategy"><u>don’t perform random attacks</u></a> and will have specific objectives”, says Thornton -rump. “It could be anything from compromising endpoints to building a bot net for <a href="https://www.itpro.com/security/critical-networks-face-unprecedented-threat-as-ddos-attacks-are-getting-shorter-and-more-intense"><u>distributed denial of service (DDoS)</u></a> attacks – or a specific goal for espionage purposes. It all comes down to detecting the attack, containing it, and pushing the threat actor out of the network.”</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><h2 id="how-to-prepare-for-crink-in-2026">How to prepare for CRINK in 2026</h2><p>While China seems to be shifting its tactics and ramping up, experts say 2026 could see much of the same from all nation states, with adversaries increasingly using technology such as AI to supercharge attacks. AI will help to increase speed, scale and believability, as well as supporting traditional <a href="https://en.wikipedia.org/wiki/Human_intelligence_(intelligence_gathering)#:~:text=NATO%20defines%20HUMINT%20as%20%22a,persons%20having%20access%20to%20information."><u>human intelligence</u></a> type operations, says Ingram. </p><p>With this in mind, Ingram advises getting the basics right, shoring up <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business"><u>identity and access management</u></a> and employing a <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> mindset.</p><p>Thornton-Trump emphasizes the benefits of a threat intelligence program, alongside optimum detection capabilities. “If it’s likely you will need to go toe-to-toe with nation state adversaries, you have to gear-up – be able to detect initial compromise and quickly act,” he says. “The critical piece here is to have a very high signal-to-noise ratio to detect even subtle activity that could be an indication of compromise.”</p><p>Extermination, a term used for removing the various footholds adversaries may have in the network, is another step to take, adds Thornton-Trump. </p><p>“You need a well-resourced and trained threat hunting team with expertise in reverse engineering. CRINK is likely to possess never-seen-before <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> capabilities so expect to discover things that are rare and unique. Facing off against nation state actors is probably the toughest job in cyber and bringing in outside help, such as law enforcement and even intelligence agencies, may need to be part of the response playbook.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS supplier DXS International confirms cyber attack – here’s what we know so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/nhs-supplier-dxs-international-confirms-cyber-attack-heres-what-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ The NHS supplier says front-line clinical services are unaffected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CEoPtB9Ycevt6gaxLmi9Ei</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zoxC2QCJSmiHZA84Xve6qE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Dec 2025 11:15:00 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Dec 2025 11:15:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zoxC2QCJSmiHZA84Xve6qE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NHS logo displayed on a smartphone screen in white lettering on a blue background.]]></media:description>                                                            <media:text><![CDATA[NHS logo displayed on a smartphone screen in white lettering on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[NHS logo displayed on a smartphone screen in white lettering on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zoxC2QCJSmiHZA84Xve6qE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NHS software supplier DXS International has disclosed a cyber attack on its internal systems. </p><p>The company provides clinical support solutions for clinical commissioning groups, doctors, nurses and pharmacists as part of their workflow and during patient consultations. </p><p>Its products integrate with core NHS systems, and in some cases are hosted on the NHS’ Health and Social Care Network (HSCN). </p><p>The company says it supports around 10% of all NHS referrals in England. Its ExpertCare solution, for example, helps clinicians quickly understand prescription needs for cardiovascular diseases, and is used by around 2,000 GPs, overseeing the care of around 17 million patients.</p><p>In a filing with the London Stock Exchange, DXS International <a href="https://www.londonstockexchange.com/news-article/market-news/dxs-international-plc-aqse-dxsp-notice-of-cyber-security-incident/17379494" target="_blank"><u>said</u></a> it had discovered a security incident affecting its office servers in the early hours of Sunday, 14 December.</p><p>"Once discovered, the data security breach was immediately contained by means of a joint effort by DXS’s internal <a href="https://www.itpro.com/security/cybersecurity-teams-are-understaffed-overworked-and-underfunded-and-it-s-taking-a-massive-toll-on-mental-health">IT security teams</a> in close cooperation with NHS England," said the firm. </p><p>"The Board has appointed an external cyber security specialist agency whose thorough investigations are underway to establish the nature and extent of the incident."</p><p>The company said there's been "minimal" impact on its services, with front-line clinical services unaffected and operational.</p><p>DXS has notified the relevant regulators, authorities, and law enforcement agencies, including the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a>, and is fully cooperating with their investigations. It's also working with various NHS bodies</p><p>“We, along with the National Cyber Security Centre and law enforcement partners, are working with an NHS supplier who is investigating a cyber incident,"  an NHS England spokesperson told <em>ITPro</em>. “We are not aware of any patient services being impacted.”</p><h2 id="dxs-international-the-latest-nhs-supplier-hit">DXS International the latest NHS supplier hit</h2><p>Attacks on NHS suppliers are becoming increasingly common, with threat actors viewing third-party providers as a potentially lucrative source of data. </p><p>Earlier this year, Birmingham-based software provider Advanced Computer Software Group was handed a <a href="https://www.itpro.com/security/data-breaches/advanced-computer-software-group-ico-fine"><u>£3 million fine</u></a> by the Information Commissioner's Office (ICO) for security failings that led to a ransomware attack on the NHS.</p><p>In another example, thousands of procedures were canceled at London hospitals after an <a href="https://www.itpro.com/security/cyber-attacks/thousands-of-procedures-canceled-at-london-hospitals-as-qilin-releases-blood-test-data">attack on blood testing company Synnovis</a>. The attack was claimed by Russian-speaking ransomware group Qilin.</p><p>Last month, the government proposed new laws to strengthen cybersecurity in public services, including the NHS. </p><p>Medium and large companies providing services like <a href="https://www.itpro.com/business-operations/business-management/367834/best-it-management-tools">IT management</a>, IT help desk support, and cybersecurity will be regulated for the first time, required to report incidents promptly, and implement more robust recovery plans.</p><p>As a result, critical suppliers such as those providing healthcare diagnostics to the NHS will have to meet tighter security requirements, and enforcement will be toughened up.</p><p>"The reforms will make fundamental updates to our approach to addressing the greatest risks and harms, such as new powers to designate critical suppliers," said national chief information security officer for health and care at the Department of Health and Social Care, Phil Huggins.</p><p>"Working with the healthcare sector, we can drive a step change in cyber maturity and help keep services available, protect data, and maintain trust in our systems in the face of an evolving threat landscape."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The future of threat detection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-future-of-threat-detection</link>
                                                                            <description>
                            <![CDATA[ To fight sophisticated threats, cybersecurity teams will need to unify data like never before ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kQ3sK7bL5MtDjLW4pmS3tG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fFxVX9G7ChwSaaQBh3dmnk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Dec 2025 07:31:00 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Dec 2025 16:10:11 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fFxVX9G7ChwSaaQBh3dmnk-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The text &quot;The future of threat detection&quot; against a web of connected, red crosses on a dark grey background. The word &quot;threat detection&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:description>                                                            <media:text><![CDATA[The text &quot;The future of threat detection&quot; against a web of connected, red crosses on a dark grey background. The word &quot;threat detection&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:text>
                                <media:title type="plain"><![CDATA[The text &quot;The future of threat detection&quot; against a web of connected, red crosses on a dark grey background. The word &quot;threat detection&quot; are in yellow, the rest are in white. In the bottom-right corner, the ITPro Podcast logo is shown.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fFxVX9G7ChwSaaQBh3dmnk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/eed487c5-bcc5-4245-a864-8519c2e32f0d/"></iframe><p>Cybersecurity teams are facing a double edged sword of challenges and opportunities. On the one hand, AI tools offer a great deal of autonomous working and the promise of automating some of the more laborious tasks that a cybersecurity team has to undertake. </p><p>On the other hand, attackers are also using AI to launch large scale attacks such as sophisticated phishing campaigns and identity theft. To fight this threat, cybersecurity teams will need to unify data like never before and take advantage of as many new technologies and processes as they can.</p><p>How can they go about this? And what does a unified cybersecurity strategy really look like in 2026?</p><p>In this episode, Rory is joined by Mandy Andress, chief information security officer at Elastic, to explore how businesses can evolve their threat detection and security posture, as well as how AI is lowering the barrier to entry for attackers.</p><h2 id="highlights-2">Highlights</h2><p>"Of course, it all started with phishing messages. It used to be really easy to identify a phishing message, and AI was able to fix that and solve a lot of the language challenges and grammar and the punctuation challenges."</p><p>"So we talk about zero trust, we talk about least privilege, and none of those foundational elements have changed. I think in some cases, they've become even more critical, certainly least privileged, as you're looking at system accounts and and non-human identities and agents and really focusing on what they can and cannot do what they can and cannot access. From a threat actor perspective, those are our perfect lateral movement capabilities, 'let me be able to take over an agent and have it do what I want it to do' versus what it's potentially expected to be doing."</p><p>"We're starting to see augmenting of analysts, we're starting to see some autonomous workflows, but we're still taking the approach of how we have been looking at things and then adding on or expanding some capabilities. There will be a point in maybe five, seven years out that we are going to need to make a fundamental shift in our approach to continue to build and leverage all of the advantages that we would be able to have."</p><p>"The key way for success in today's environment is you need to understand what is happening. You need to have a very holistic, comprehensive view of both what is happening and what exists in your environment, and bringing in as much context, telemetry understanding as possible, </p><h2 id="footnotes-2">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/in-the-age-of-ai-threats-the-future-of-security-is-unified">In the age of AI threats, the future of security is unified</a></li><li><a href="https://www.itpro.com/software/development/ai-generated-code-is-now-the-cause-of-one-in-five-breaches-but-developers-and-security-leaders-alike-are-convinced-the-technology-will-come-good-eventually">AI-generated code is now the cause of one-in-five breaches – but developers and security leaders alike are convinced the technology will come good eventually</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/ai-generated-code-risks-what-cisos-need-to-know">AI-generated code risks: What CISOs need to know</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/agentic-ai-carries-huge-implications-for-security-teams-heres-what-leaders-should-know">Agentic AI carries huge implications for security teams - here's what leaders should know</a></li><li><a href="https://www.itpro.com/security/the-ncsc-touts-honeypots-and-cyber-deception-tactics-as-the-key-to-combating-hackers-but-they-could-lead-to-a-false-sense-of-security">The NCSC touts honeypots and ‘cyber deception’ tactics as the key to combating hackers — but they could ‘lead to a false sense of security’</a></li></ul><h2 id="subscribe-2">Subscribe </h2><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154" target="_blank"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ" target="_blank"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://uk.linkedin.com/company/itpro-uk" target="_blank"><u>Join us on LinkedIn</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco says Chinese hackers are exploiting an unpatched AsyncOS zero-day flaw – here's what we know so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cisco-says-chinese-hackers-are-exploiting-an-unpatched-asyncos-zero-day-flaw-heres-what-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ The zero-day vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager appliances – here's what we know so far. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5LMxwYAnxTREWwNiSWa9Zf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Wjkyryzytyf6eV4b3zSVee-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 11:51:54 +0000</pubDate>                                                                                                                                <updated>Thu, 18 Dec 2025 11:53:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Wjkyryzytyf6eV4b3zSVee-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco logo and branding pictured at the networking company&#039;s vendor stall at Mobile World Congress (MWC) 2023.]]></media:description>                                                            <media:text><![CDATA[Cisco logo and branding pictured at the networking company&#039;s vendor stall at Mobile World Congress (MWC) 2023.]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco logo and branding pictured at the networking company&#039;s vendor stall at Mobile World Congress (MWC) 2023.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Wjkyryzytyf6eV4b3zSVee-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco </a>has issued a warning to customers after revealing China-linked hackers are exploiting a new high-severity zero day flaw in some security products. </p><p>Products targeted in the campaign include Cisco AsyncOS Software for Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and Cisco Secure Email and Web Manager, formerly known as Cisco Content Security Management Appliance (SMA).</p><p>Cisco Secure Email and Web Manager centralizes management and reporting functions across a number of Cisco ESAs and Web Security Appliances (WSAs), offering centralized services such as spam quarantine, policy management, reporting, tracking, and configuration management.</p><p>The currently unpatched vulnerability, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20393" target="_blank"><u>CVE-2025-20393</u></a>, has a CVSS score of 10.0.</p><p>Cisco said it became aware of the issue on December 10, and that the activity has been ongoing since at least late November. It's been hitting appliances with certain non-standard configurations that leave some ports open to the internet. </p><p>It's not known how many customers have been affected.</p><p>The attack involves a custom persistence mechanism that Cisco is tracking as “AquaShell”, along with additional tooling meant for reverse tunneling and purging logs.</p><p>"This attack allows the threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance," the firm said. </p><p>"The ongoing investigation has revealed evidence of a persistence mechanism planted by the threat actors to maintain a degree of control over compromised appliances."</p><p>Cisco is attributing the attacks to a group tracked as UAT-9686, a <a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats">Chinese-nexus advanced persistent threat (APT) actor</a>. </p><p>"We have observed overlaps in tactics, techniques and procedures (TTPs), infrastructure, and victimology between UAT-9686 and other Chinese-nexus threat actors Talos tracks," said the company's Talos researchers. </p><p>"Tooling used by UAT-9686, such as AquaTunnel (aka ReverseSSH), also aligns with previously disclosed Chinese-nexus APT groups such as APT41 and UNC5174. Additionally, the tactic of using a custom-made web-based implant such as AquaShell is increasingly being adopted by highly sophisticated Chinese-nexus APTs."</p><h2 id="how-to-mitigate-aquashell-threats">How to mitigate AquaShell threats</h2><p>AquaShell is a lightweight <a href="https://www.itpro.com/software/development/why-python-is-the-programming-language-of-choice-for-ai-developers">Python </a>backdoor that is embedded into an existing file within a Python-based web server that can receive encoded commands and execute them in the system shell.</p><p>If customers identify an appliance as having the web management interface or the Spam Quarantine port exposed to and reachable from the internet, Cisco said it strongly recommends following a multi-step process to restore the appliance to a secure configuration, when possible.</p><p>If this can't be done, customers should contact Cisco's Technical Assistance Center to check whether the appliance has been compromised. If it has, rebuilding the appliances is, currently, the only way to eradicate the threat actor's persistence mechanism from the appliance.</p><p>Cisco also strongly recommends restricting access to the appliance and implementing robust access control mechanisms to make sure that ports are not exposed to unsecured networks.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>