Threats — writing by Peter Bassill
Threats · page 4 of 4
Breaches, campaigns and the vulnerabilities being used right now. 58 articles
-
Operation Cronos: what disruption actually achieves
A month on from the NCA-led takedown of LockBit's infrastructure, the affiliate group is already back online and claiming new victims. What Operation Cronos achieved is real and worth defending — but it is not the dismantlement the headlines suggested.
-
What a cyber attack actually costs a small business
The financial number is the smallest part. Operational disruption, reputational damage, and regulatory consequences are the costs that compound. Plus the positive case for getting this right.
-
Know your enemy: the threats small businesses actually face
Phishing, ransomware, social engineering, malware, credential stuffing, insider mistakes, denial of service. The actual menu of threats facing UK small businesses — in plain English, without the drama.
-
23andMe, and the data with the longest half-life
Last month 23andMe disclosed that attackers used credential stuffing against accounts opted in to relative-matching to scrape data on roughly 6.9 million people. The board lesson is about which data has the longest half-life — and it is not what most firms think.
-
What the teenagers taught the Fortune 500
LAPSUS$ compromised Microsoft, Okta, Nvidia, Samsung, Vodafone, and several others in a few months. They were teenagers using social engineering and MFA fatigue. The lesson, awkwardly, is that the dominant compromise vector in 2022 is social, not technical.
-
Log4Shell, and the inventory question we cannot keep ducking
A month on from CVE-2021-44228, the headline-grabbing exploits have slowed but the underlying problem has not. The discomfort of the past month was not really about Log4j. It was about how few firms could answer the question 'where is it running?'
-
wlan0: the unlocked back door on every TV
Part 4 of 4. Once you have root on the TV, the most useful thing on the device isn't the data on it — it's the second network interface nobody disabled. What this bypasses, why the SIEM is blind to it, and what to do about it.
-
Pegasus, and the question for UK boards we have been pretending not to face
The Pegasus Project disclosures last month confirmed what specialists have privately known for years: commercial spyware is a mature, well-funded industry, and its customer list includes governments most UK firms do business with. The board question is what to do about it.
-
From the embedded browser to a shell on a smart TV
Part 3 of 4. From the AIT-triggered page load to a shell prompt. CVE-2020-6383, shell.js, SMACK, and the public Samsung Q60T root chain.
-
The lab rig: re-broadcasting HbbTV into a test bench
Part 2 of 4. What I built on the bench to study HbbTV attacks safely. Hardware, software, the AIT injection step, and the legal bit (do not transmit DVB into open air).
-
Colonial Pipeline: the CNI lesson the UK should not need to learn the hard way
Five weeks after the DarkSide ransomware attack on Colonial Pipeline shut down 45% of US East Coast fuel supply, what UK critical national infrastructure boards should be doing about it.
-
The TV in the corner: what HbbTV actually is
Part 1 of 4. A primer on HbbTV from a security researcher's bench. Why I think the smart TV mounted on the meeting-room wall is the most under-considered attack surface in any UK office in 2021.
-
Hafnium and the patch-window asymmetry
Five weeks after the Microsoft Exchange ProxyLogon disclosure, the dust is settling on what may turn out to be the most consequential mass-exploitation event of the decade. What it teaches us is structural, not tactical.