Daily brief at 7am Melbourne. Unsubscribe any time.

Saturday 23 May 2026

Inside the Week Law Enforcement Tore Down the Cybercrime Infrastructure Stack

Law enforcement dismantled a criminal VPN used by 25 ransomware groups, arrested a Kimwolf botnet operator, and seized 800 servers from a bulletproof hoster — a rare good week for the takedown scoreboard.

Lead story

Inside the Week Law Enforcement Tore Down the Cybercrime Infrastructure Stack

Three separate law enforcement actions dropped within 48 hours this week, and taken together they represent something more than routine policing: a co-ordinated push to dismantle the plumbing that underpins modern cybercrime.

The headliner: "First VPN" is gone. A joint operation led by France and the Netherlands — with support from the FBI and several other nations — dismantled a criminal VPN service that investigators say was used by at least 25 ransomware groups for network reconnaissance, initial access brokering, and anonymising data exfiltration. Law enforcement agencies didn't just seize infrastructure; they reportedly intercepted VPN traffic and arrested the service's administrator. The FBI described First VPN as a critical enabler for ransomware intrusions across critical infrastructure sectors in North America and Europe.

The significance here goes beyond one takedown. Criminal VPNs have historically been a blind spot — investigators can seize botnets, arrest coders, burn malware infrastructure. But the anonymisation layer, the thing that makes all of it harder to attribute, has been far harder to touch. Cracking the traffic is the loud claim in this announcement, and if true, it has implications for how other services in this category assess their own exposure.

Meanwhile, the Netherlands FIOD went even further upstream. Financial crime investigators arrested two men and seized 800 servers belonging to a bulletproof hosting firm they say actively enabled cyberattacks, disinformation campaigns, and interference operations. Bulletproof hosters are the landlords of cybercrime — they take money, ask no questions, and ignore abuse complaints. Taking 800 servers offline at once removes a lot of capacity from multiple criminal ecosystems simultaneously.

And in Canada, a face finally has handcuffs. Jacob Butler, 23, from Ottawa, was arrested and charged with building and operating the Kimwolf botnet — an IoT-targeting DDoS-for-hire service that infected close to two million devices and was used to launch massive distributed denial-of-service attacks over the past six months. KrebsOnSecurity had publicly named Butler back in February after he allegedly retaliated against the journalist and a security researcher with DDoS attacks, doxing, and swatting. The US Department of Justice is seeking extradition.

Why this week's trifecta matters. Criminal infrastructure — VPNs, hosters, botnets — exists in a kind of legal grey zone between the operators who build malware and the organisations that deploy it. Historically, charges have landed on the latter two categories while the enablers keep operating. When all three layers get hit in the same week, it suggests improving intelligence-sharing and a more deliberate strategy to go after the supply side of ransomware, not just arrest the people who pull the trigger.

What to watch next. The First VPN takedown's traffic interception claim is the one that will get stress-tested. Criminal forums are already dissecting what law enforcement could have seen, and other anonymisation services will be reviewing their own exposure. Whether the arrests lead to co-operating witnesses — and what those witnesses know about ransomware operators — is the thread worth following.

For Australian organisations: ransomware groups using this infrastructure have historically targeted critical infrastructure sectors. ACSC's current advisory guidance on third-party network access and VPN hygiene is directly relevant if your incident response playbooks haven't been reviewed recently.

Also today

Cisco Patches a Perfect 10: Secure Workload REST API Flaw

Cisco has patched a maximum-severity vulnerability in its Secure Workload product — a zero-trust microsegmentation platform used in enterprise data centres. CVE-2026-20223 scores a perfect 10.0 on the CVSS scale. The flaw stems from insufficient validation on REST API endpoints, meaning an unauthenticated remote attacker could query sensitive data without any credentials. Cisco says no workaround exists and urges immediate patching. Secure Workload is widely deployed in financial services and healthcare environments, including in Australian enterprises, making this a patch-now situation for anyone running the affected versions.

The Hacker News

Drupal SQL Injection Flaw Under Active Attack Days After Disclosure

A critical SQL injection vulnerability in Drupal — tracked as CVE-2026-9082 — is already being actively exploited, just days after the content management system's maintainers disclosed it. Security firms are reporting attacks against thousands of Drupal-powered websites. The flaw is rated "highly critical" and allows remote attackers to manipulate database queries. Drupal remains a popular CMS for government and education websites in Australia, making this exposure particularly relevant for public sector web teams. Patches are available and organisations should treat this as urgent given how quickly exploit activity followed disclosure.

SecurityWeek

Ubiquiti's UniFi OS Has Three CVSS 10.0 Vulnerabilities

Ubiquiti has shipped emergency patches for three maximum-severity flaws in UniFi OS — the operating system that runs its popular networking gear including routers, switches, and access points. All three can be exploited remotely without authentication. UniFi hardware is ubiquitous in small businesses, co-working spaces, and home labs globally. The scale of deployment means the attack surface is enormous. If your UniFi controller or devices are internet-facing and haven't been updated, they should be treated as compromised until patched. Ubiquiti has pushed updates and owners should check the console immediately.

Bleeping Computer

Megalodon Poisoned 5,500+ GitHub Repos in Six Hours

Researchers have documented a new automated campaign called Megalodon that pushed malicious commits to over 5,500 GitHub repositories in a single six-hour window. Using throwaway accounts with convincing bot-style names — build-bot, auto-ci, pipeline-bot — the attackers injected GitHub Actions workflows containing base64-encoded bash payloads designed to exfiltrate CI/CD secrets and environment variables. The speed and scale are unprecedented: over 5,700 malicious commits in one campaign. While GitHub has been cleaning up, this represents a step-change in automated supply chain poisoning. Organisations with public repositories should audit their recent Actions workflow history for unexpected modifications.

The Hacker News

FBI Warns: Kali365 Phishing Kit Hijacks Microsoft 365 Via OAuth Tokens

The FBI has published an advisory about Kali365, a Telegram-based phishing-as-a-service kit that first appeared in April and has already been used in significant Microsoft 365 compromises. Rather than harvesting passwords, Kali365 abuses Microsoft's legitimate device authorisation flow to trick targets into granting persistent OAuth tokens to attacker-controlled applications. Once the token is granted, the attacker has persistent access even if the victim changes their password or has MFA enabled. Microsoft 365 is broadly deployed across Australian enterprise and government, and this technique bypasses the MFA controls most organisations believe are protecting them.

The Record

Ghostwriter Targets Ukrainian Government with Prometheus Phishing Campaign

Belarus-aligned threat actor Ghostwriter — also tracked as UAC-0057 and UNC1151 — has launched a fresh phishing campaign against Ukrainian government organisations, according to CERT-UA. The lures impersonate Prometheus, a legitimate Ukrainian online learning platform, to deliver malware via convincing emails to public servants. Ghostwriter has a long history of combining credential theft with information operations, and its targeting of government workers fits its mandate to undermine Ukrainian institutional resilience. The campaign is a reminder that state-aligned actors adapt their lures to current events and trusted platforms rather than using obviously suspicious themes.

The Hacker News

China's Webworm Abuses Discord and Microsoft Graph to Compromise EU Governments

A Chinese advanced persistent threat group called Webworm has been observed using Discord channels and the Microsoft Graph API as command-and-control infrastructure in intrusions against European government networks. The technique — sometimes called "living off trusted services" — makes malicious traffic blend in with legitimate cloud API calls that most network monitoring tools allow through by default. The group supplemented the approach with SoftEther VPN SOCKS proxies to further obscure attacker-to-victim communications. It's a well-worn playbook that keeps getting mileage because defenders rarely block legitimate cloud services, and attribution becomes harder when the C2 is a Discord server.

Dark Reading

Trump Cancels AI Safety Testing Order After Top Tech CEOs Decline to Attend

The Trump administration abruptly cancelled a planned Executive Order signing event on AI safety testing after several major AI company CEOs declined invitations to attend, according to reports. The White House subsequently framed the EO itself as a potential innovation "blocker" — a notable reversal from the event that was ostensibly ready to go. The episode is significant for AI governance watchers: it suggests that executive branch AI policy in the US remains highly susceptible to industry lobbying and personal dynamics. Australia's AI safety approach — currently being shaped through the government's AI Frontiers Framework — is heading in a different direction, emphasising mandatory guardrails for high-risk use cases.

Ars Technica

Trail of Bits Hardens GitHub Actions Static Analyser After YAML Anchor Gap

Security firm Trail of Bits has published details of hardening work done on zizmor, its open-source static analyser for GitHub Actions workflows. The work was prompted by a real-world attack chain: in March 2026, attackers exploited a pull_request_target misconfiguration in the Aqua Security Trivy action to steal secrets and backdoor LiteLLM on PyPI. When GitHub added support for YAML anchors in September 2025, zizmor initially couldn't reason about anchored values — a gap that could let misconfigurations slip through analysis. The post is a useful read for any team running zizmor in CI, or anyone building security tooling on top of GitHub Actions parsing.

Trail of Bits

How BYOVD Attackers Make Hardware-Gated Drivers Exploitable Without the Hardware

A detailed technical write-up in The Hacker News unpacks a significant nuance in Bring Your Own Vulnerable Driver (BYOVD) attacks: many Windows kernel drivers are conditionally reachable, theoretically requiring specific hardware to interact with. Researchers explain how attackers can bypass these hardware gates from user mode using device object impersonation and IOCTL replay techniques, dramatically expanding the pool of drivers useful for privilege escalation. The implication for defenders is sobering — the "this driver is only dangerous if you have the hardware" assumption is often wrong, and vulnerable driver blocklists need to account for this expanded exploitability.

The Hacker News

SpaceX Files to Go Public in What Would Be the Largest IPO in US History

SpaceX has filed its S-1 prospectus for a public listing, targeting a valuation that analysts say could make it the largest IPO in American history. The filing claims a $28 trillion total addressable market — a number that requires some imagination — and includes a pay package for Elon Musk tied to establishing a Mars colony. The risk factors section alone runs to 36 pages. For the tech industry, the listing has broader significance: it will test whether public markets will price Musk-affiliated ventures at the same multiples venture capital has, and whether SpaceX's Starlink division — increasingly significant to Australian regional connectivity — will be broken out or valued separately.

TechCrunch

Sources consulted