Risky Bulletin: Targeted supply chain attack hits DAEMON Tools
9 min
•May 6, 202625 days agoSummary
This episode covers a major supply chain attack on DAEMON Tools that distributed malware for nearly a month, a critical cPanel zero-day exploited for over two months affecting 44,000+ servers, and Australia's new Cyber Incident Review Board. Additional stories include arrests of international cybercriminals, AI safety policy shifts under the Trump administration, and Oracle's move to monthly security updates.
Insights
- Supply chain attacks remain highly effective with DAEMON Tools malware reaching thousands of hosts despite limited secondary payload deployment, indicating attackers are becoming more selective in their targeting
- Zero-day vulnerabilities can persist unpatched for extended periods (64 days in cPanel case), creating massive exploitation windows that affect tens of thousands of systems before remediation
- Governments are establishing formal cybersecurity review boards and critical infrastructure resilience programs in response to evolving threats, signaling a shift toward proactive defense frameworks
- AI safety regulations are becoming a geopolitical battleground, with the Trump administration reversing course on oversight and pressuring tech companies to remove restrictions on government use
- International cybercrime operations are increasingly coordinated across borders, with scam centers, VOIP fraud schemes, and state-sponsored hacking campaigns operating with relative impunity
Trends
Supply chain attacks targeting software distribution channels as primary infection vectorsExtended zero-day exploitation windows (60+ days) before patches, creating systemic vulnerability exposureGovernment establishment of formal cyber incident review boards and post-incident learning frameworksCritical infrastructure resilience planning for disconnected/isolated network operations during armed conflictDeregulation of AI safety controls and removal of restrictions on government access to AI toolsInternational law enforcement coordination against cybercriminals with multi-month investigations and extraditionsAI agent exploitation through prompt injection and encoding techniques (Morse code bypasses)State-sponsored targeting of refugee and defector populations through compromised gaming platformsBluetooth-based physical tracking of law enforcement officers through unencrypted device identifiersSMS-based MFA bypass through remote access trojans targeting mobile-to-desktop sync applications
Topics
Supply Chain Attack - DAEMON ToolscPanel Zero-Day Vulnerability ExploitationMalware Distribution and Backdoor DeploymentCyber Incident Review BoardsCritical Infrastructure DefenseAI Safety Regulation and Government OversightInternational Cybercrime and ExtraditionRansomware Attacks on HealthcareVOIP Fraud and Banking CompromiseAI Agent Prompt Injection AttacksMFA Bypass TechniquesState-Sponsored Hacking CampaignsGeolocation Data PrivacyLaw Enforcement Device SecurityMonthly Security Update Cycles
Companies
DAEMON Tools
Website compromised in targeted supply chain attack; malware-bundled installers distributed for nearly a month
Kaspersky
Security firm that identified and analyzed the DAEMON Tools supply chain attack and malware payload
cPanel
Critical vulnerability secretly exploited as zero-day for 64 days; 44,000+ servers compromised before patch
Telstra
Australian telco whose global CISO Narelle Devine chairs the new Cyber Incident Review Board
CISA
US agency launched CI Fortify project to help critical infrastructure operators defend against armed conflict attacks
Oracle
Switched from quarterly to monthly security updates, citing AI as reason for increased release frequency
Axon
Police equipment manufacturer; devices lack MAC address randomization, allowing tracking of law enforcement officers
Microsoft
PhoneLink app targeted by CloudZ remote access trojan to steal SMS-based one-time passcodes for MFA bypass
Cisco Talos
Security research team that discovered CloudZ malware targeting Microsoft PhoneLink application
Cochava
Data broker banned by FTC from selling precise geolocation data without explicit user consent
Collective Data Solutions
Subsidiary of Cochava; also banned from selling geolocation data in FTC settlement
ESET
Security firm analyzing North Korean hacking campaign targeting Chinese gaming platform near North Korea border
Reuters
Won Pulitzer Prize for Beat Reporting on Meta's fraudulent ad ecosystem and cybersecurity investigations
Associated Press
AP staff won Pulitzer Prize with independent reporter Yael Grauer for US tech companies aiding China surveillance
Meta
Subject of Reuters Pulitzer Prize-winning investigation into fraudulent ad ecosystem
People
Katalin Kim Panu
Prepared the Risky Bulletin episode content
Claire Aird
Read and presented the Risky Bulletin episode
Narelle Devine
Chairs Australia's new Cyber Incident Review Board
Gavril Sandu
Romanian national extradited to US for complex VOIP banking fraud scheme dating to late 2000s
Denis Zolotoriov
Latvian national sentenced to 8.5 years for 54 ransomware attacks including targeting hospitals and 911 systems
Lin
23-year-old Taiwanese student who hacked railway network radio systems, causing emergency brake activation
Raphael Satter
Won Pulitzer Prize for Beat Reporting on Meta's fraudulent ad ecosystem
AJ Vichens
Won Pulitzer Prize for National Affairs reporting on Meta's fraudulent ad ecosystem
Yael Grauer
Won Pulitzer Prize with AP staff for reporting on US tech companies aiding China mass surveillance
Full Transcript