Decrypted: The UK Cyber Briefing
Where it charts
Today’s combined position on our country charts.
Ranking history
Position on the Technology, United Kingdom combined chart over the last 7 days. Toggle platforms to compare their positions. Lower rank numbers are better.
View as table
| Date | Combined Rank | Apple Podcasts |
|---|---|---|
| Oct 10 | #176 | #164 |
| Oct 8 | — | #199 |
About the show
Latest episodes
-
A Qilin arrest is welcome, but the ransomware franchise runs on unlocked doors
October 10, 2026 · 4 minA suspected core Qilin member has been handed from Japan to Germany. The arrest is good news, but the group's affiliates keep walking through legacy VPN settings and supplier dependencies. What UK organisations should design out, plus…
-
Malware in the box: cheap Android phones that arrive already compromised
October 9, 2026 · 4 minBitdefender's Midnight Mimosa research finds malware baked into the firmware of cheap MediaTek Android phones. UK product security law checks passwords, reporting and update periods, not whether the firmware is clean. Also: Citrix and…
-
A Beijing contractor ran the hacking kit, and the doors it used were a decade old
October 9, 2026 · 5 minThe NCSC and six allied countries named Integrity Technology Group as the operator behind Flax Typhoon tooling, as the FBI seized seven domains. The exploited holes were years old, which makes this a Secure by Design lesson about what UK…
-
FortiBleed is still locking admins out of their own firewalls, and the NCSC saw it coming
October 8, 2026 · 5 minThe FBI and US Secret Service say the FortiBleed campaign against Fortinet firewalls is still active, with administrators locked out and access passed to ransomware affiliates. No vulnerability is involved, which makes the Secure by Design…
-
Hijacked country registries mint real Google certificates: the trust chain nobody audits
October 8, 2026 · 5 minAttackers took over the .gh, .sl and .as registries and obtained genuine HTTPS certificates for Google and others. The lesson for UK organisations sits below the website: who controls your DNS, and who is watching certificate logs.
-
ASOS's own app became the ransom note: who can speak in your name?
October 7, 2026 · 4 minHackers used ASOS's own app to push an extortion message to customers, claiming a Snowflake compromise they have yet to evidence. The Secure by Design question for UK firms: who can speak in your name?
-
Atlassian's critical Data Center flaw: patch it, then take it off the internet
October 7, 2026 · 4 minAtlassian has warned of CVE-2026-21589, a critical unauthenticated file-access flaw in its self-hosted Data Center products. No exploitation was reported at disclosure. Also: ASOS's rogue app alert and Wikimedia's report on suspected…
-
Denmark's population register was drained through a supplier's legitimate access
October 6, 2026 · 4 minAttackers took names, addresses and personal numbers for 8.8 million people from Denmark's national register using a company's lawful access. The design lesson on throttling and monitoring applies to any UK organisation sharing identity…