Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems Do Son
    The UK NCSC warns of rising cyberattacks on operational technology, urging organizations to secure internet-exposed industrial systems against physical disruptions. Related Posts: Google Tracks Russian Cyber Espionage Clusters OpenAI Disrupts Russian Influence Campaign Promoting Fake Think Tank NIST Asks for Help Putting People First in Cybersecurity The post NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems appeared first on Daily CyberSecurity.
     
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: H1 2026 Social Media Fraud Trends BushidoToken
    What HappenedHMRC Issues Warning to TikTok UsersOn 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.The wa
     

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

29 de Julho de 2026, 05:00

What Happened

HMRC Issues Warning to TikTok Users

  • On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.
  • The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.
  • Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.
  • The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud.

Lloyds Bank found Two Thirds of Fraud Cases Started on Meta 

  • On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp.
  • The average claim value submitted to Lloyds Bank is now above £500, an increase of about £100 from last year. Plus, victims were sending up to £66 million a year to fraudsters after falling victim to a scam advert via Meta, up from £27 million in 2023.
  • The most common scams involve fake tickets for concerts, festivals and sporting events. Meta’s Facebook Marketplace is also plagued by fake adverts for cars, bikes, campervans and mobility vehicles.
  • Other categories of fraud on Meta platforms, collected by Lloyds between March 2025 and 2026, include: wedding photobooths, tattoo deposits, vapes, wigs, Moncler jackets, football shirts, Dyson products and Amazon Alexas. Fraudulent transactions for deposits for flats, mobile phones, household furniture and gym equipment have also been observed.

UK Finance Recorded £221.5m Lost to Investment Scams

  • In June 2026, UK Finance's Annual Fraud Report recorded the highest loss total ever recorded and the highest total number of cases ever reported at 14,893, which was 26% higher than 2025.
  • Up to £221.5m was lost to scams in which victims were persuaded to transfer funds to a fake investment or fictitious fund. This figure also marked a 40% rise more than 2025.
  • The primary observed tactics involved in investment scams include traditional cold calling to pressurise victims into acting quickly to claim an opportunity before it expires, as well as adverts on social media offering unrealistic rates of returns on investments, and hand-delivered letters.
  • The types of investments fraudsters used as bait in 2026 involved gold, property, carbon credits, cryptocurrencies, land banks, and wine.

Fraudsters arrested in Nigeria following NCA intelligence sharing

  • In February 2026, the National Crime Agency (NCA) announced that seven men were arrested in Nigeria after intelligence identified an online investment scam compound targeting UK victims. These arrests were the result of co-operation between the National Crime Agency, Meta and the Nigerian Police.
  • Using hundreds of fake Facebook accounts accounts to impersonate cryptocurrency traders, the Nigeria-based scammers targeted people who used legitimate investment platforms.
  • The scam compound was also allegedly recruiting and training young people in targeting victims for future investment frauds and phishing attacks. A total of 26 phones, 42 sim cards and a laptop were seized on 13 January.

Analyst Comment 

H1 2026 reinforces the transition from email-centric fraud campaigns to social-media-powered fraud operations, with platforms increasingly serving as the primary source of victims for organised cybercriminal groups. Fraudsters are also adapting scams to the culture and user behaviour of individual platforms, such as generate short promotional videos on TikTok or listing fake items for sale on Facebook Marketplace. Rather than deploying identical scams everywhere, criminals tailor campaigns to the platform's intended purpose. Recommendation algorithms and advertising ecosystems provide fraudsters with scalable victim acquisition channels that were previously unavailable through traditional phishing campaigns.

Advances in artificial intelligence (AI) and large language models (LLMs) has also meant it is much easier for cybercriminals to carry out scams on a much larger scale than they were previously able to. Autonomous systems can enable them to send out messages at scale and contact users by telephone at scale. Plus the scam attempts are also more convincing as they can mimic voices and appearance of celebrities or even a target’s friends and family.

The scale of fraudulent activities across social media is so large, it requires vast resources and expertise to monitor, detect, and prevent. At the same time, the response from HMRC, banks, social media companies, the NCA, and international law enforcement suggests increasing recognition that combating social media fraud requires coordinated action.

The volume of fake accounts on social media used for scams does also validate the calls for increased verification and security checks on such platforms. The UK Government's proposal to introduce a national digital ID system, however, was met with fierce opposition. Up to 2.9 million people signed a UK parliament petition to show their disagreement with such a system.

Defensive Takeaways 

  • Reduce Public Exposure: Fraudsters increasingly use information shared on social media to personalise scams and identify potential victims. Consider making profiles private or limiting visibility to trusted contacts and if you no longer actively use a social media platform, consider deleting the account entirely.
  • Be on Guard for Scams: Sponsored advertisements should not automatically be considered legitimate. Refuse any financial rewards in exchange for your login credentials. Be cautious of investment opportunities promoted solely through social media. Assume Facebook Marketplace listings can be fraudulent.
  • Report Suspicious Activity: Reporting scams helps remove fraudulent content and supports law enforcement investigations. Useful UK reporting channels include Report Fraud and the UK NCSC's Suspicious Email Reporting Service report@phishing.gov.uk.
  • Seek Support after a Scam: Victims should not assume financial losses are unrecoverable. It can be possible to get funds returned if they contact their bank immediately, preserve screenshots and transactions records, and report the incident to Report Fraud. Further, if a victim is dissatisfied with how their bank handled their case, they can complain to the Financial Ombudsman Service.

Relevant Sources 

  1. https://www.independent.co.uk/news/uk/crime/tiktok-hmrc-tax-fraud-scam-b2989914.html
  2. https://www.thetimes.com/article/840020a8-1210-47c9-9262-e3139116b652?shareToken=771d08288cd2ac9d0ba13194f43d75a0
  3. https://www.theguardian.com/money/2026/jun/15/investment-fraud-uk-more-than-220m-lost-last-year-scams-ai
  4. https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf
  5. https://www.nationalcrimeagency.gov.uk/news/fraudsters-arrested-in-nigeria-following-nca-intelligence-sharing 

  • ✇Firewall Daily – The Cyber Express
  • Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief Samiksha Jain
    Ransomware Preparedness must become a strategic priority for organizations as cyberattacks grow more disruptive and difficult to contain, according to Richard Horne, CEO of the UK's NCSC (National Cyber Security Centre). Speaking during the FBI's Ahead of the Threat podcast, Horne urged business leaders to assess whether their organizations could continue operating if critical IT systems were unavailable for four weeks. His remarks come amid growing concerns over ransomware, AI-driven cyber t
     

Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief

Ransomware Preparedness

Ransomware Preparedness must become a strategic priority for organizations as cyberattacks grow more disruptive and difficult to contain, according to Richard Horne, CEO of the UK's NCSC (National Cyber Security Centre). Speaking during the FBI's Ahead of the Threat podcast, Horne urged business leaders to assess whether their organizations could continue operating if critical IT systems were unavailable for four weeks. His remarks come amid growing concerns over ransomware, AI-driven cyber threats, and the increasing speed at which attackers exploit known vulnerabilities.

Ransomware Preparedness Requires Planning Beyond Paying a Ransom

A key message from Horne was that organizations should not view ransom payments as a recovery strategy. Instead, effective Ransomware Preparedness depends on resilience, tested recovery plans, and executive support. According to Horne, ransomware attacks typically involve two forms of extortion. Attackers steal sensitive data and threaten to publish it, while also encrypting systems and demanding payment for decryption keys. He noted that paying criminals does not guarantee data will be deleted or systems fully restored. Referencing lessons learned from Operation Cronos, the international law enforcement operation that disrupted the LockBit ransomware group, Horne said investigators found instances where victim data remained on criminal infrastructure even after ransom payments had been made. Ransomware Preparedness

NCSC Warns Organizations About the Coming Patch Wave

The discussion also highlighted concerns about a growing Patch Wave, a term used by the NCSC to describe the anticipated surge in vulnerability disclosures and exploitation attempts fueled by artificial intelligence. FBI Cyber Division Assistant Director Brett Leatherman pointed to recent industry findings showing that attackers are exploiting known vulnerabilities faster than defenders can remediate them. Internet-facing devices and VPNs have become increasingly attractive targets, while the window between disclosure and exploitation continues to shrink. Horne stressed that organizations need long-term planning rather than short-term reactions. He encouraged businesses to develop multi-year cybersecurity roadmaps and ensure security investments remain a priority across budget cycles.

CyberUK Discussions Focused on Executive Accountability

Reflecting on discussions held during CyberUK, the UK's flagship cybersecurity conference hosted by the NCSC, Horne emphasized that cybersecurity cannot remain solely the responsibility of technical teams. He noted that many Chief Information Security Officers face challenges securing organizational support despite having visibility into technology risks. According to Horne, leadership teams must actively participate in managing cyber risk rather than treating it as an isolated IT issue. The conversation also addressed burnout among cybersecurity professionals, with both Horne and FBI officials acknowledging the operational strain placed on defenders during major incidents, including ransomware attacks and large-scale vulnerability disclosures.

Public-Private Cooperation Remains Critical

Beyond technical defenses, Horne highlighted the importance of collaboration between governments, law enforcement agencies, and the private sector. He said threat intelligence sharing creates a continuous cycle in which organizations identify threats, share findings, improve defenses, and generate new intelligence that benefits the wider cybersecurity community. Horne also pointed to growing opportunities to use artificial intelligence to accelerate threat detection and response efforts. As ransomware groups continue targeting businesses worldwide, the message from both the FBI and the NCSC was clear: organizations must invest in Ransomware Preparedness, strengthen resilience plans, and prepare for a future where cyber incidents are not a possibility but an expectation.
  • ✇Firewall Daily – The Cyber Express
  • The NHS Was Lucky. The Next Victim Might Not Be. Mihir Bagwe
    In May 2026, malicious code appeared inside packages used across NHS software projects. The software supply chain attack named Mini Shai-hulud by researchers spread through CI/CD systems, package registries, and developer tooling before anyone noticed something was wrong. It was caught quickly. Damage was limited. The UK's National Cyber Security Centre is using that near-miss to bring into focus a more urgent case. The underlying conditions that made Mini Shai-hulud possible are not unique to
     

The NHS Was Lucky. The Next Victim Might Not Be.

4 de Junho de 2026, 09:17

Software Supply Chain Attack, Supply Chain Attack, Mini Shai-Hulud, NCSC, CI/CD

In May 2026, malicious code appeared inside packages used across NHS software projects. The software supply chain attack named Mini Shai-hulud by researchers spread through CI/CD systems, package registries, and developer tooling before anyone noticed something was wrong. It was caught quickly. Damage was limited.

The UK's National Cyber Security Centre is using that near-miss to bring into focus a more urgent case. The underlying conditions that made Mini Shai-hulud possible are not unique to that attack, and subsequent similar campaigns have gone undetected for longer and spread far more widely.

The Problem Is Structural

NCSC National Resilience Officer Jack F, is not mainly interested in a particular threat actor or a CVE but in how modern software development works — because that architecture is the vulnerability.

A single application today may rely on dozens, sometimes hundreds, of third-party packages like libraries, frameworks, SDKs, and code snippets pulled in automatically when a developer runs a single install command. Node.js, Python, and Rust are singled out as especially exposed because their minimal standard libraries push developers toward external registries for even basic functionality. Once a package is in a dependency tree, it often pulls in further packages of its own — transitive dependencies that the original developer never consciously chose.

This is not a flaw in the ecosystem's design. It is the design. The efficiency gains from reusable, trusted components are real, and the NCSC is not arguing against open source development. The argument is more specific to the combination of automation, implicit trust, and scale that turns a single compromised package into a vector capable of spreading malicious code across hundreds of organizations before any single one of them detects it.

Four Techniques Defenders Need to Know

The NCSC documents four attacker techniques active in recent campaigns. The first is maintainer account compromise — attackers steal credentials or tokens that allow them to push malicious updates to a trusted, legitimate package. This is how the Axios npm attack in March 2026 worked. The maintainer account was hijacked, a malicious dependency injected, and the backdoor distributed to an estimated 80% of cloud environments before the window closed.

Read: Axios Supply Chain Attack Exposes Developers to Hidden Malware

The second technique is abandoned package takeover where attackers claim ownership of packages whose original maintainers have let their domains lapse or transferred control elsewhere. The third is typosquatting, in which, publishing packages with names that closely mimic popular legitimate ones, waiting for a developer to make a spelling error in an install command. The fourth is self-propagation, meaning, using credentials stolen from one package compromise to access or modify additional packages, creating a cascading contamination chain across an ecosystem.

All four techniques exploit the same structural feature. Once a package enters a trusted registry, downstream consumers inherit whatever trust that registry confers, automatically, at scale, with no human checkpoint.

What Defenders Are Being Asked to Do

The NCSC's immediate guidance falls into three categories. The first is visibility. Organizations must audit recent package updates and version changes, identify newly introduced or unexpected dependencies, and maintain a software bill of materials — a documented inventory of every component a codebase relies on. Without that inventory, it is impossible to know whether a compromised package is present at all.

The second is detection. Teams should monitor CI/CD activity, network traffic, and credential use for anomalies, and run dependency scanning tools against known indicators of compromise published after supply chain incidents.

And the third is remediation posture. If a compromise is suspected, automatic dependency updates should be paused immediately, new updates and versions reviewed manually before redeployment, and any potentially exposed API keys, tokens, and credentials rotated without waiting for confirmation of active exploitation. Enforcing multi-factor authentication on developer and package registry accounts is singled out specifically — the absence of universally enforced MFA on registry accounts is identified as a structural gap that maintainer account compromises directly exploit.

The NCSC also flags developer environments themselves as a soft target. Developer devices are typically less tightly controlled than managed corporate endpoints, making credential theft from developer workstations a reliable path to registry access that bypasses enterprise security controls entirely.

As supply chain attacks on PyPI and npm packages have become a near-weekly occurrence across security news feeds, rhe NCSC's guidance refers defenders to the Software Security Code of Practice as the authoritative framework for strengthening development and supply chain management. It also notes that its SSCoP implementation guidance will be updated shortly to reflect the specific attack scenarios.

  • ✇Firewall Daily – The Cyber Express
  • NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands Samiksha Jain
    The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases,
     

NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

Agentic AI Deployment

The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured approach toward adopting agentic AI, highlighting the growing cyber and operational risks associated with highly autonomous AI systems. In a new guidance document co-authored with international partners, the NCSC said businesses should avoid rushing into large-scale deployments of agentic AI tools without understanding the security implications. The guidance recommends starting with low-risk use cases, limiting system privileges, and maintaining strong human oversight throughout deployment. The advisory comes as organizations increasingly experiment with AI systems capable of making decisions, accessing tools, and carrying out actions with limited human involvement.

What Is Agentic AI?

Unlike traditional generative AI systems that primarily create text, images, or predictions, agentic AI systems are designed to independently pursue goals. These systems can access data sources, remember context, make decisions, interact with software tools, and even create sub-agents to complete tasks. According to the NCSC, this added autonomy is what makes agentic AI useful for areas such as cyber defense, workflow automation, and operational efficiency. However, it also introduces a wider attack surface and increases the difficulty of monitoring system behavior. The agency noted that many security risks linked to AI are not entirely new. Concerns around access control, supply chain security, monitoring, and incident response already exist in traditional IT systems. Agentic AI systems also inherit existing large language model risks, including prompt injection and jailbreaking attacks. However, the NCSC warned that the autonomy of agentic AI systems could amplify these issues, especially if organizations deploy them without proper safeguards.

Why Agentic AI Raises Security Risks

The guidance outlines several risks tied to agentic AI deployments. One of the main concerns is broader access to systems and sensitive data. AI agents may interact with external tools, APIs, or databases in ways that traditional AI applications do not. The NCSC also highlighted the possibility of unpredictable behavior. Since AI agents interpret goals autonomously, they may take actions that differ from human expectations or exceed their intended scope. Another challenge involves visibility and oversight. Autonomous systems can operate at speeds that make meaningful human review difficult, particularly in enterprise environments where multiple systems and workflows are interconnected. The guidance further noted that explaining the behavior of agentic AI systems can be more difficult than understanding conventional AI models. The combination of decision-making, tool usage, and autonomous actions creates additional complexity during incident investigations or compliance reviews.

NCSC Calls for Incremental Agentic AI Deployment

To reduce risks, the NCSC urged organizations to adopt agentic AI gradually instead of deploying it across critical systems from the outset. The guidance recommends tightly controlled pilot deployments focused on clearly defined, low-risk tasks. Organizations are also encouraged to assess whether AI is genuinely necessary before integrating autonomous agents into existing workflows. “If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment,” the guidance stated. The agency stressed that organizations should never grant unrestricted access to sensitive data or critical infrastructure. Maintaining visibility into AI system behavior and preserving meaningful human control were identified as key requirements for safe deployment.

Human Accountability Remains Essential

Despite the growing capabilities of autonomous AI systems, the NCSC emphasized that humans remain fully accountable for how these technologies are used. The guidance states that organizations should clearly define who is responsible for approving AI access, monitoring system behavior, reviewing incidents, and shutting systems down when necessary. Security teams were also advised to integrate agentic AI risk management into existing cybersecurity and governance frameworks instead of treating AI security as a separate process. Recommended practices include applying least-privilege access controls, limiting system scope, avoiding long-lived credentials, monitoring unusual behavior, and planning for incidents involving AI misuse or loss of control.

Path Forward

While warning about the risks, the NCSC acknowledged that agentic AI could deliver significant operational benefits, particularly for repetitive and low-risk tasks. The agency said organizations should focus on responsible and scalable adoption strategies built around existing cybersecurity practices and strong governance controls. The guidance ultimately encourages businesses to move carefully, test systems incrementally, and prepare for potential failures before expanding the role of autonomous AI systems across enterprise environments.
  • ✇Firewall Daily – The Cyber Express
  • NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface Samiksha Jain
    Organisations worldwide are being urged to prepare for a vulnerability patch wave, as security experts warn that advances in artificial intelligence (AI) could rapidly expose long-standing weaknesses across software systems. The warning comes from National Cyber Security Centre (NCSC), which says businesses must act now to strengthen their environments before a surge of critical updates arrives. In a blog, Chief Technology Officer Ollie Whitehouse highlighted that years of accumulated technic
     

NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface

vulnerability patch wave

Organisations worldwide are being urged to prepare for a vulnerability patch wave, as security experts warn that advances in artificial intelligence (AI) could rapidly expose long-standing weaknesses across software systems. The warning comes from National Cyber Security Centre (NCSC), which says businesses must act now to strengthen their environments before a surge of critical updates arrives. In a blog, Chief Technology Officer Ollie Whitehouse highlighted that years of accumulated technical debt are now becoming a major cybersecurity risk. Technical debt refers to unresolved flaws and compromises in software that arise when organisations prioritise speed or short-term delivery over long-term resilience. According to Whitehouse, artificial intelligence is accelerating the problem. Skilled attackers are increasingly able to use AI tools to identify and exploit vulnerabilities at scale, forcing what the NCSC describes as a “correction” across the technology ecosystem. This is expected to trigger a vulnerability patch wave, with a high volume of security updates affecting open source, commercial, proprietary, and software-as-a-service platforms.

Prioritising External Attack Surfaces

As part of preparing for the vulnerability patch wave, the NCSC advises organisations to first focus on their external attack surfaces. Internet-facing systems, cloud services, and exposed infrastructure present the highest risk when new vulnerabilities are disclosed. The guidance recommends a perimeter-first approach. Organisations should secure outward-facing technologies before moving deeper into internal systems. This reduces the likelihood that attackers can exploit newly discovered weaknesses during the vulnerability patch wave. Where resources are limited, priority should be given to patching systems that are directly exposed to the internet. Critical security infrastructure should follow next. However, the NCSC cautions that patching alone will not solve every issue. Legacy and end-of-life systems remain a major concern. Many of these technologies no longer receive security updates, leaving organisations vulnerable even during a vulnerability patch wave. In such cases, businesses may need to replace outdated systems or bring them back into supported environments, especially if they are externally accessible.

Preparing for Faster and Large-scale Patching

The expected vulnerability patch wave will require organisations to rethink how they manage updates. The NCSC is urging businesses to prepare for faster, more frequent, and large-scale deployment of security patches, including across supply chains. Several key measures have been recommended:
  • Enable automatic updates wherever possible to reduce operational burden
  • Adopt secure “hot patching” to apply fixes without service disruption
  • Ensure internal processes support rapid and large-scale updates
  • Use risk-based prioritisation models such as Stakeholder Specific Vulnerability Categorisation (SSVC)
Whitehouse noted that organisations must be ready to accelerate patching timelines when critical vulnerabilities are actively exploited, particularly those affecting internet-facing systems. At the core of this approach is an “update by default” policy. This means applying software updates as quickly as possible, ideally through automated processes. While this may not always be feasible for safety-critical or operational technology systems, the NCSC says it should form the foundation of modern vulnerability management strategies.

Beyond Vulnerability Patch Wave: Addressing Systemic Risks

The NCSC emphasises that the vulnerability patch wave is only part of a broader cybersecurity challenge. Patching addresses immediate risks, but it does not eliminate the underlying causes of technical debt. Technology vendors are being encouraged to build more secure systems from the outset. This includes adopting memory safety and containment technologies such as CHERI, which can reduce the likelihood of exploitable vulnerabilities. For organisations operating critical services, strengthening cybersecurity fundamentals is equally important. Frameworks such as Cyber Essentials and sector-specific resilience models can help reduce the impact of breaches and improve overall security posture. Additional guidance has also been issued for high-risk environments, covering areas such as privileged access workstations, cross-domain security architecture, and threat detection through observability and proactive hunting.

Organisations Urged to Act Now

The NCSC has made it clear that preparation cannot be delayed. The anticipated vulnerability patch wave is expected to impact organisations of all sizes and sectors. Businesses are advised to review their vulnerability management processes, assess their exposure, and ensure their supply chains are also ready to respond. Larger organisations, in particular, are encouraged to seek assurance from both commercial and open-source partners. As Whitehouse concluded, readiness for the vulnerability patch wave will depend on proactive planning, strong fundamentals, and the ability to respond quickly at scale.
  • ✇Firewall Daily – The Cyber Express
  • China-Linked Cyber Actors Turn to Massive Covert Botnets to Evade Detection Ashish Khaitan
    A newly issued cybersecurity advisory highlights an evolution in the tactics, techniques and procedures (TTPs) employed by China-Nexus threat actors. The report, released with support from the UK Cyber League and coordinated by the National Cyber Security Centre (NCSC-UK) alongside international partners, sheds light on how Chinese threat actors are relying on large-scale covert networks of compromised devices to conduct malicious cyber operations. A Strategic Shift in China-Nexus TTPs  In rec
     

China-Linked Cyber Actors Turn to Massive Covert Botnets to Evade Detection

China-Nexus

A newly issued cybersecurity advisory highlights an evolution in the tactics, techniques and procedures (TTPs) employed by China-Nexus threat actors. The report, released with support from the UK Cyber League and coordinated by the National Cyber Security Centre (NCSC-UK) alongside international partners, sheds light on how Chinese threat actors are relying on large-scale covert networks of compromised devices to conduct malicious cyber operations.

A Strategic Shift in China-Nexus TTPs 

In recent years, cybersecurity experts have observed a clear transition in China-Nexus TTPs. Rather than relying on dedicated, individually controlled infrastructure, Chinese threat actors are now leveraging expansive networks of compromised devices, commonly referred to as covert networks or botnets. These networks are primarily composed of Small Office/Home Office (SOHO) routers, Internet of Things (IoT) devices, and other internet-connected hardware. According to the advisory, the majority of China-Nexus actors are believed to be using such covert networks, with multiple networks operating simultaneously and often shared among different groups. These networks are continuously updated, making them highly adaptable and difficult to track. Any organization targeted by Chinese threat actors could be affected. For example, the group known as Volt Typhoon has used these covert networks to pre-position cyber capabilities within critical infrastructure, while Flax Typhoon leveraged similar methods for espionage operations.

How Covert Networks Operate 

Although botnets are not new, China-Nexus actors are now deploying them at an unprecedented scale and with strategic intent. These covert networks allow attackers to mask their identity, route malicious traffic through multiple nodes, and reduce the risk of attribution. Typically, an attacker accesses the network via an entry point, or “on-ramp,” and routes activity through numerous compromised devices—called traversal nodes—before exiting near the target. This multi-hop approach obscures the origin of the attack. These networks support every stage of a cyber operation, from reconnaissance and scanning to malware delivery, command-and-control communication, and data exfiltration. They are also used for general browsing, enabling threat actors to research vulnerabilities and refine TTPs without revealing their identity. The presence of legitimate users on some networks further complicates attribution. 

Real-World Examples and Scale 

Evidence suggests that some covert networks used by China-Nexus actors are developed and maintained by Chinese cybersecurity firms. One notable example is the “Raptor Train” network, which infected over 200,000 devices globally in 2024. It was reportedly managed by Integrity Technology Group, a company also linked by the FBI to activities associated with Flax Typhoon. Another example includes the KV Botnet used by Volt Typhoon, which primarily exploited outdated Cisco and NetGear routers. These devices were particularly vulnerable because they had reached “end-of-life” status, meaning they no longer received security updates. The scale and adaptability of these networks present a major challenge. As Paul Chichester, NCSC Director of Operations, stated: “Botnet operations represent a significant hreat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyberattacks.”

Challenges for Network Defenders 

Cybersecurity researchers have long been aware of such threats, but the evolving nature of China-Nexus TTPs introduces new difficulties. A key issue identified by Mandiant Intelligence in May 2024 is “indicator of compromise (IOC) extinction.” Traditional defenses, such as static IP blocklists, are becoming less effective because attackers can operate from vast, constantly changing pools of devices.  As compromised nodes are patched or removed, new ones are quickly added, making these networks highly dynamic. This fluidity undermines conventional detection and mitigation strategies. 

Defensive Measures and Best Practices 

The advisory outlines several steps organizations can take to defend against China-Nexus covert networks: 

For all organizations: 

  • Maintain a clear inventory of network edge devices. 
  • Establish baselines for normal network activity, particularly VPN access. 
  • Monitor for unusual connections, including those from consumer broadband ranges. 

For higher-risk organizations: 

  • Use IP allow lists instead of blocklists for VPN access. 
  • Apply geographic and behavioral profiling of incoming connections. 
  • Adopt zero-trust security models. 
  • Enforce SSL machine certificates. 
  • Reduce exposure of internet-facing systems. 
  • Explore machine learning tools to detect anomalies. 

For the most at-risk entities: 

  • Treat China-Nexus covert networks as advanced persistent threats (APTs). 
  • Map and monitor known covert networks using threat intelligence. 
  • ✇Firewall Daily – The Cyber Express
  • FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks Ashish Khaitan
    The Russian-linked threat group APT28 has continued to leverage vulnerable network devices to carry out large-scale DNS hijacking campaigns, enabling adversary-in-the-middle attacks. Recent developments show that these operations have drawn direct intervention from U.S. authorities.  The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a network of compromised routers controlled by Russia’s military intelligence unit, widely known as APT28. According to
     

FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks

APT28

The Russian-linked threat group APT28 has continued to leverage vulnerable network devices to carry out large-scale DNS hijacking campaigns, enabling adversary-in-the-middle attacks. Recent developments show that these operations have drawn direct intervention from U.S. authorities.  The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a network of compromised routers controlled by Russia’s military intelligence unit, widely known as APT28. According to findings aligned with prior reporting from the NCSC, the group has been exploiting routers to intercept communications, harvest credentials, and target individuals and organizations of intelligence interest. 

DNS Hijacking and Adversary-in-the-Middle Tactics 

APT28’s operations include DNS hijacking, a technique that manipulates how domain names are resolved into IP addresses. By altering DNS settings, often at the router level, attackers redirect legitimate traffic through malicious infrastructure. This enables adversary-in-the-middle (AitM) attacks, where victims unknowingly connect to spoofed services. These malicious endpoints are designed to imitate legitimate platforms, allowing attackers to intercept login sessions and extract sensitive data, including passwords, OAuth tokens, and emails. Both the FBI and the NCSC have noted that these attacks can impact browser sessions and desktop applications alike, increasing the scale and effectiveness of credential harvesting.

U.S. Operation Targets APT28 Infrastructure 

The disruption effort, publicly disclosed by the Department of Justice, targeted a network of small office/home office (SOHO) routers compromised by APT28, also known as Fancy Bear, Sofacy, Sednit, STRONTIUM, Forest Blizzard, and Pawn Storm. The group is widely attributed to Russia’s GRU Unit 26165.  Since at least 2024, APT28 actors have exploited known vulnerabilities to gain access to thousands of TP-Link routers globally. After stealing credentials, they modified router configurations to redirect DNS traffic to malicious servers under their control. These operations were initially indiscriminate. However, the attackers implemented automated filtering mechanisms to identify DNS queries of intelligence value. For selected targets, the malicious DNS resolvers returned fraudulent records for domains, particularly those mimicking Microsoft Outlook services, to facilitate adversary-in-the-middle attacks against encrypted traffic.  Through this approach, APT28 was able to harvest unencrypted passwords, authentication tokens, emails, and other sensitive data from devices connected to compromised routers.

Official Statements on the Threat 

U.S. officials described the campaign as both persistent and dangerous. Assistant Attorney General John A. Eisenberg stated, “The GRU’s predatory use of networks in American homes and businesses for its malicious cyber operations remains a serious and persistent threat.”  U.S. Attorney David Metcalf added, “Russian military intelligence once again hijacked Americans’ hardware to commandeer critical data,” emphasizing that the government would continue to respond aggressively to nation-state cyber threats.  FBI officials also stressed the scale of the campaign. Assistant Director Brett Leatherman noted that compromised routers were used globally for espionage, while Special Agent Ted E. Docks highlighted that devices across more than 23 U.S. states had been weaponized. 

How the FBI Disrupted the DNS Hijacking Network 

As part of the court-authorized operation, referred to as Operation Masquerade, the FBI deployed technical measures to neutralize the U.S. portion of APT28’s infrastructure.  According to court documents: 
  • The FBI sent commands to compromised routers to collect evidence of APT28 activity. 
  • Reset DNS settings, removing malicious resolvers and restoring legitimate ISP configurations.
  • Blocked the actors’ ability to regain unauthorized access. 
The operation was carefully tested on affected TP-Link devices to ensure that it did not disrupt normal functionality or collect user content. Importantly, the remediation steps can be reversed by users through factory resets or manual configuration changes. 

Continued Router Exploitation and Infrastructure Tactics 

These developments align closely with earlier findings from the NCSC, which documented how APT28 used Virtual Private Servers (VPSs) as malicious DNS infrastructure. Two main clusters were identified: 
  • Cluster One: Focused on modifying DHCP DNS settings in SOHO routers, enabling selective DNS hijacking and adversary-in-the-middle attacks.  
  • Cluster Two: Involved forwarding DNS traffic through a layered infrastructure, with some operations targeting high-value devices, including those in Ukraine.  
APT28’s activity has also included exploitation of vulnerabilities such as CVE-2023-50224 in TP-Link routers, allowing attackers to extract credentials and reconfigure DNS settings via crafted HTTP requests.

Targeted Services and Indicators 

APT28’s DNS hijacking campaigns have frequently targeted Microsoft Outlook-related domains, including: 
  • autodiscover-s.outlook[.]com  
  • imap-mail.outlook[.]com  
  • outlook.live[.]com  
  • outlook.office[.]com  
  • outlook.office365[.]com  
These targets reflect a clear focus on email-based intelligence gathering. Supporting infrastructure includes numerous malicious IP ranges and identifiable server configurations, such as unusual SSH ports and “dnsmasq-2.85” DNS services. 

Mitigation and Security Recommendations 

Both the FBI and the NCSC recommend immediate steps to mitigate risks associated with DNS hijacking and adversary-in-the-middle attacks: 
  • Replace end-of-life or unsupported routers  
  • Update firmware to the latest available versions  
  • Verify DNS settings to ensure they point to legitimate resolvers  
  • Disable or secure remote management interfaces  
  • Implement firewall rules to limit exposure  
  • Enable multi-factor authentication (MFA) to reduce credential abuse  
  • Users are also encouraged to monitor their networks and report suspected compromises to appropriate authorities. 
  • ✇Security Boulevard
  • What the UK Cyber Security & Resilience Bill Means for Security Practitioners SecurityExpert
    The UK Cyber Security & Resilience Bill is progressing through Parliament Royal Assent expected later in 2026. The UK's Cyber Security and Resilience Bill is working its way through Parliament, and if you haven't started paying serious attention yet, now is the time. Introduced to the House of Commons in November 2025, the Bill represents the most significant overhaul of UK cyber regulation since the NIS Regulations in 2018, and its implications for security practitioners are immediate an
     

What the UK Cyber Security & Resilience Bill Means for Security Practitioners

25 de Março de 2026, 20:58

The UK Cyber Security & Resilience Bill is progressing through Parliament Royal Assent expected later in 2026.

The UK's Cyber Security and Resilience Bill is working its way through Parliament, and if you haven't started paying serious attention yet, now is the time. Introduced to the House of Commons in November 2025, the Bill represents the most significant overhaul of UK cyber regulation since the NIS Regulations in 2018, and its implications for security practitioners are immediate and practical.


What's Actually Changing
At its core, the Bill expands the existing Network and Information Systems regulatory framework. It brings more organisations into scope, imposes stricter incident notification requirements, and hands regulators substantially more enforcement power. Secondary legislation and statutory Codes of Practice will follow, but the primary architecture of what you'll be working within is already taking shape.

One of the most significant shifts for practitioners working in or alongside managed services is the creation of a new regulated entity category: the Relevant Managed Service Provider (RMSP). For the first time, MSPs providing services to in-scope sectors face direct regulatory obligations. If your organisation is an MSP, or relies heavily on one, your compliance exposure has materially changed.


⚠ Key Point - Incident Reporting Timelines
 The Bill introduces two-stage incident reporting: an initial notification within 24 hours and a full report within 72 hours, with copies sent to the NCSC. Your detection, triage, and escalation workflows need to meet these timelines under real pressure, not just on paper.

Penalties That Command Attention
The financial exposure for non-compliance is substantial and should feature prominently in any board-level conversation about investment in cyber controls.

Maximum Penalty Structure

  • Standard maximum penalty - £10m or 2% of global turnover
  • Higher maximum (serious breaches) - £17m or 4% of worldwide turnover
  • Continuing contraventions (daily) - Up to £100,000 per day
  • Extended ceiling (exceptional cases) - Up to 10% of worldwide turnover

These are not hypothetical. Regulators will also gain cost recovery powers, able to levy periodic fees to fund their oversight activities. Expect more active enforcement, not passive monitoring.


UK vs NIS2: Don't Assume Alignment
If your organisation already operates under the EU's NIS2 framework, a critical warning: the UK Bill and NIS2 share objectives but diverge in material ways. Reporting thresholds differ, customer notification requirements differ, and the sectors in scope are structured differently. A NIS2-aligned incident response playbook will not automatically satisfy UK obligations.

Practitioners managing cross-border environments will need jurisdiction-specific runbooks. A single process attempting to satisfy both simultaneously risks failing both under pressure.
Supply Chain Risk Is Now Statutory

The Bill introduces the concept of designated "critical suppliers" organisations whose compromise could cause major disruption to the economy or wider society, even if they are not themselves regulated entities. These suppliers will receive formal written notice and will have the right to make representations or appeal.

Secondary legislation will likely impose specific supply chain security obligations on regulated entities potentially including contractual requirements, security assessments, and continuity planning mandates. The era of passing a questionnaire and considering supply chain risk managed is ending.


🔗 Supply Chain Reality Check
Without consolidated visibility across cloud platforms, SaaS providers, and outsourced partners, your compliance posture is built on assumptions, not evidence. The Bill will expose that gap when regulators come calling.

What Practitioners Should Do Now
The Bill has passed its Report Stage in the Commons and is heading to the House of Lords. Royal Assent is expected later in 2026. Waiting for the final text before acting is not a defensible position.
  • Determine whether your organisation or key MSPs fall into newly in-scope categories, including data centres with Rated IT Load above 1 MW
  • Review incident detection and escalation workflows against the 24-hour initial notification requirement
  • Map divergence between your current NIS/NIS2 compliance posture and what the UK Bill will require
  • Audit your supplier assurance programme, move beyond annual questionnaires towards continuous oversight
  • Engage legal, compliance, and operational teams together; this cannot be owned by security alone
  • Monitor the Bill's progress and watch for secondary legislation, which will contain the operational detail

The regulatory environment for UK cyber security is shifting substantially. The organisations best placed when the Bill receives Royal Assent will be those treating this as a live operational project, not a future compliance task.

Track the Bill's progress via the UK Parliament Bills tracker and the House of Commons Library briefing.

The post What the UK Cyber Security & Resilience Bill Means for Security Practitioners appeared first on Security Boulevard.

❌
❌