Roundup: Iranian Spooks Track US Troops Via Ad Data, macOS Malware Plays Dead, and a Textile Firm Goes Bust After Six Weeks of Ransomware Hell
A grab-bag of stories that didn't quite get their own headlines this week, but probably should have.
Dutch police look close to home in Odido breach
Netherlands law enforcement suspects local cybercriminals were behind the recent intrusion at telecom operator Odido. Rather than pointing fingers abroad, investigators are focusing on domestic hacking groups who may have done the dirty work themselves.
Lidl customers caught in supplier breach
A third-party IT vendor connected to supermarket chain Lidl was compromised, resulting in customer data walking out the door. Shoppers in Belgium and the Netherlands are being notified. Supply chain attacks continue to be an extremely effective way to punch above your weight as an attacker.
German textile company collapses after six-week ransomware blackout
ZEGO Textilveredelungszentrum, a German textile finishing firm, has filed for insolvency after a cyberattack forced production offline for six straight weeks. Six weeks. The business simply couldn't survive it financially. A stark reminder that ransomware isn't just an IT problem.
Japan's biggest taxi operator pulls the plug on dispatch systems
Nihon Kotsu, Japan's largest taxi network, took its IT and dispatch infrastructure offline after detecting a breach. Booking services went dark while response teams scrambled. A ransomware group called AiLock is suspected, though attribution at this stage remains tentative.
CrashStealer: the macOS malware hiding in plain sight
Researchers have identified a new macOS infostealer written in C++, imaginatively named CrashStealer. It disguises itself as a crash reporting tool and mimics native macOS password prompts to hoover up credentials and sensitive data. The kind of thing that slips past users precisely because it looks like something the OS would legitimately ask for.
Iran using ad tech and roaming data to monitor US military phones
This one's genuinely unsettling. According to the Financial Times, Iranian-linked threat actors are exploiting commercial advertising metadata and cellular roaming protocols to track the movements of US military personnel. Location data and device identifiers baked into ad networks are apparently sufficient to keep tabs on where service members are going. The ad industry's data practices remain a gift that keeps on giving, mostly to people who shouldn't have it.
CISA publishes CVD how-to guide
CISA and international partners have put out a joint framework for building Coordinated Vulnerability Disclosure programmes. It covers handling incoming bug reports, setting up legal safe harbours for researchers, and working constructively with the security community. Useful reading for any organisation that doesn't yet have a formal disclosure process, which is still far too many of them.
WhatsApp-connected AI agent vulnerable to remote code execution
A researcher found an architectural flaw in an OpenClaw AI agent integrated with WhatsApp that allows an attacker to trigger arbitrary code execution on the host system simply by sending a crafted message. The agent bypassed validation and executed system commands on demand. AI agents with access to real infrastructure and inadequate sandboxing is a theme that's going to generate a lot of these stories.
Spirals ransomware hits Asian IT firm
A newly spotted ransomware strain called Spirals has been used against an IT services company in Asia. The group behind it combines encryption with data exfiltration, which is now table stakes for ransomware operators. The threat actor remains unidentified.
Cybercriminals claim 1TB haul from naval defence supplier
A group calling itself The Gentlemen has posted Thyssenkrupp Marine Systems and subsidiary Atlas Elektronik to its leak site, claiming to have lifted more than a terabyte of data. Thyssenkrupp confirmed a breach at an isolated North American unit but insisted the affected environment was segregated from core systems and held no classified military information. Whether that assessment holds up remains to be seen.