Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack
2026-07-16T20:51:45Z•d764cedb0567ad4a015cc22a4cfb3b39045c2460d40cd4c82d05bf88f97c3eb5
621 CVEsCVE-2026-53412ai-assisted malwareasyncapichinese cyber espionagecisaclaude codedeepseekiot botnetknown exploited vulnerabilitieslegacyhivemicrosoft patch tuesdaynpm supply chainrussian apts targeting routersscattered spidersma 1000sonicwallsupply-chain compromisetencshelltfltransport for londontuxbotwindows privilege escalationzero-dayzoom
What happened
Multiple high-impact cyber incidents and advisories: UK courts sentenced two Scattered Spider members for the £29M 2024 TfL attack; researchers disclosed LegacyHive, a Windows Privilege Escalation PoC affecting fully patched systems; SonicWall confirmed active exploitation of two SMA 1000 zero-days and related flaws were added to CISA's KEV catalog; Zoom patched a critical account-takeover bug (CVE-2026-53412, CVSS 9.8). Additional notable events include a large npm supply-chain compromise of AsyncAPI packages (malware with info-stealing/crypto-theft/RAT features), a record Microsoft Patch Tue
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d764cedb0567ad4a015cc22a4cfb3b39045c2460d40cd4c82d05bf88f97c3eb5
- Enrichment time
- 2026-07-16T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.