Breached upstream: the fortnight attackers arrived as trusted traffic
One poisoned open-source scanner cascades into a tier-1 network vendor and the European Commission. Ransomware at a single software supplier disrupts most Dutch hospitals. And a state actor turns thousands of home routers into a silent credential-harvesting layer.
Executive summary
- Attackers broke in upstream and arrived as trusted traffic. Credentials stolen via a trojanised open-source security scanner were used to clone 300+ private repositories at a tier-1 network vendor and take 340 GB from the EU's web-hosting platform across 71 organisations.
- One vendor became a national single point of failure. Ransomware at ChipSoft, whose EHR platform serves roughly 80% of Dutch hospitals, forced patient-portal disconnections across the country, with the crew claiming around 100 GB of stolen data.
- The defence window is compressing to hours. One crew was documented exploiting two flaws about a week before each was publicly disclosed and moving from access to ransomware within days, sometimes 24 hours, while a state actor quietly ran DNS hijacking through 18,000+ compromised routers in over 120 countries.
Key findings
Ransomware at one EHR vendor disrupts most Dutch hospitals
ChipSoft, whose HiX electronic health record platform serves roughly 80% of hospitals in the Netherlands plus Belgian institutions, was hit by ransomware, forcing it to disable portal and mobile connections while eleven hospitals disconnected patient portals as a precaution. The crew behind it claimed roughly 100 GB of stolen data. Healthcare's dependency graph is the vulnerability.
Poisoned scanner cascades into Cisco source code and the European Commission
Credentials stolen via trojanised releases of the Trivy open-source scanner were used to clone more than 300 private repositories at Cisco, including unreleased AI product source, and to breach the EU's Europa hosting platform: roughly 340 GB across 71 client organisations, entered weeks earlier with a stolen cloud API key. One upstream compromise, two continents of blast radius.
7.7 TB of police records leaked from an unprotected transfer system
An extortion group published over 337,000 files taken from a third-party discovery-transfer system at the Los Angeles City Attorney's Office: officer personnel and disciplinary records, internal-affairs investigations, unredacted complaints with witness names, and medical records. The system reportedly lacked password protection because outside counsel needed access. Convenience became the breach.
Ransomware crew documented exploiting flaws before public disclosure
Vendor research detailed a China-based, financially motivated actor chaining zero-day and n-day exploits against internet-facing systems, including mail and managed-file-transfer platforms, each exploited about a week before public disclosure, then moving from access to data theft and ransomware within days, in some incidents 24 hours. Heavy impact fell on healthcare, education and professional services.
State actor's router botnet ran DNS hijacking across 120+ countries
A joint industry-government disclosure exposed a Russian military-linked campaign compromising consumer and small-business routers since at least May 2025 to hijack DNS and harvest credentials through adversary-in-the-middle nodes: 18,000+ unique IPs at peak, 200+ organisations affected, with foreign ministries and cloud providers among the targets. The infrastructure between your users and your cloud is attack surface.
The broader pattern
- Software supply chain is the initial access of the quarter. A security tool's own update channel handed attackers CI/CD credentials that opened a network vendor and an EU institution; pin, verify and monitor what your pipelines pull.
- Vendor concentration is a clinical risk. When one EHR supplier serves 80% of a country's hospitals, that supplier's SOC is effectively national infrastructure; contractually demand detection evidence, not just uptime.
- Pre-disclosure exploitation breaks patch-first defence. When flaws are worked a week before the CVE exists, behavioural detection on internet-facing systems is the only control that fires in time.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Audit what your CI/CD pipelines pull, and pin it. The scanner compromise spread through trusted tooling; version-pin dependencies, verify signatures and alert on new outbound destinations from build systems.
Rotate credentials that ever lived in pipelines or repositories. Stolen CI/CD and API keys drove both marquee breaches; assume historic exposure and rotate, then monitor the old keys for attempted use.
Demand a ransomware-readiness statement from your EHR and core SaaS vendors. Concentrated vendors are your availability risk; ask for their containment SLAs and test your portal-down procedures.
Inventory third-party file-transfer and discovery systems holding your data. An unprotected transfer tool leaked 7.7 TB of police records; anything reachable without authentication is already public, it just has not been published yet.
Put behavioural detection on internet-facing mail, MFT and edge systems. With exploitation preceding disclosure, the signature does not exist yet; anomalous process, egress and identity behaviour is the tell.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
When the attacker arrives as your scanner's update, your vendor's session or your router's DNS, the question is not whether the perimeter held but whether anything noticed the behaviour change. Blacklight baselines every identity, pipeline and egress path it ingests, so a build system cloning at 50x its normal rate, a vendor account touching new data, or resolver traffic shifting to new infrastructure is investigated and contained autonomously, reasoning trail included.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entry of 6 April 2026) · CERT-EU statement on the Europa platform breach (3 April 2026) · Dutch healthcare CERT (Z-CERT) confirmation of the ChipSoft incident · Microsoft threat-intelligence reporting of 6 April 2026 · joint industry-government disclosure on router DNS hijacking (7 April 2026, incl. UK NCSC) · public breach disclosures and security-press reporting (The Record, TechCrunch, BleepingComputer, SANS ISC), 30 March – 12 April 2026 · Poland KSC Act commentary · MITRE ATT&CK v15. Attacker-claimed figures are labelled as claims.