惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
D
Docker
GbyAI
GbyAI
宝玉的分享
宝玉的分享
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Vercel News
Vercel News
博客园_首页
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
S
SegmentFault 最新的问题
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
V
V2EX
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
IT之家
IT之家
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber
Anatomy of a retail ransomware attack: Tabletop simulates...
John Leyden · 2026-06-22 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

An “Enter the War Room” incident response exercise sheds light on the rising access vectors and disruption and reputation-damaging activities attackers employ today.

Attacks on AI systems and disinformation starred as key elements of a ransomware tabletop exercise CSO participated in during this month’s Infosecurity Europe conference.

The “Enter the War Room” exercise — organised and run by cybersecurity vendor Semperis — featured a scenario focused on a cyberattack against a fictional supermarket chain, BlueCart.

CSO took part as one of eight members of a red team of supposed national state–linked attackers (APT 64, AKA Checkout Chaos) that was as much interested in thrashing the reputation of the supermarkets it targeted and causing disruption as in making money.

Last year we took part in a comparable exercise, also organised by Semperis, but on the opposite team as a media advisor to a blue team defending the systems of a fictional water utility from attack.

Rules of engagement

Ransomware tabletop exercises place participants in a realistic but fictional cyberattack scenario where each team takes 10-minute turns to devise their attack and defence plans before reporting their findings to the other side.

Each turn involves an attack-response cycle with Semperis acting as game master. The whole exercise lasted around two hours.

Like many tabletop exercises, this particular simulation was designed to get participants to think outside the box, improve cross-team communications, and develop improved incident response capabilities by exposing blind spots.

Each team was made up of seven participants from public and private sector organisations, including former hackers, security consultants, and incident response execs. Unlike the 2025 edition of the event, the names and identities of those who participated was kept confidential this year.

Data leak on aisle two

As the target of this year’s “Enter the War Room” exercise, grocery retailer BlueCart has an AI-enhanced supply chain command centre, designed to provide visibility across inventory, logistics, and fulfilment. The system has a key role in keeping shelves stocked and deliveries moving.

Logistics, scheduling, warehouse operations, and store fulfilment have been centralised in a new technology and operations centre.

The red team began with reconnaissance to find a supplier or logistics partner that already has trusted connectivity into the AI command centre, then use that foothold to reach shared portals, APIs, or remote-access tooling.

A combination of stolen credentials from developers, weak MFA enforcement, and over-privileged service accounts were used to hack into planning and inventory systems and steal loyalty card data — three of several access vectors typically employed today. The attackers also attempted to break into BlueCart’s Active Directory environment using a combination of phishing and credential theft.

The attackers also sought to exploit the retailer’s poorly segmented building-management network to disrupt heating, cooling, and ventilation operations.

The blue team of defenders decided to rebuff ransomware demands, which the attackers responded to by leaking loyalty scheme data to cause reputational damage against BlueCart.

False alerts and misinformation

The attackers generated thousands of false alerts to confuse the work of security operations analysts and hinder response. To counteract this, the defenders established out-of-band communications channels.

Continuing their attempts to disrupt BlueCoat’s operations, the attackers disrupted payroll operations. Using job losses due to a move to AI-powered operations, attackers took to social media sites such as Reddit and 4chan in attempts to rage bait hacktivists into getting involved with attacks on BlueCoat.

The attackers also created a deepfake of BlueCart’s CEO — made to look as if filmed on his private yacht — saying the job cut will allow BlueCoat to make increased profits and expand its operations.

Fake delivery orders for inappropriate goods, such as sex toys, and perishable items such as ice cream were generated by the attackers.

The blue team said it had established a honeypot so the attackers were only ever in that environment and never had access to its real environment nor customer data.

Testing the relative merits of these claims and counter claims — which seemed at times like a rap battle rather than a game with structured rules such as chess — was beyond the scope of the exercise.

The tabletop exercise offered an immersive experience without featuring any analysis of technical data, such as exercise-specific log files.

Post-mortem

Speaking after the exercise, Guido Grillenmeier, principal technologist at Semperis, explained that Enter the War Room was not a technical tabletop exercise but a way for participants to “broaden their minds and have fun.”

The scenario was designed to hone cyber incident preparedness in a similar way to how war games are used to train military forces during peacetime.

Simon Hodgkinson, strategic advisor at Semperis, said the exercise illustrated how real preparedness and resilience depends more on people and process than on tools.

“The blue team were well structured, thinking about how to minimise the financial and reputational impact on the business and recognising that, should the red team detonate destructive capability, they would need to prioritise and stand up a minimal viable business,” Hodgkinson said.

“The red team were innovative, using techniques like deception to distract the blue team so they could achieve their objective.” Hodgkinson added. “Despite the motivation not being financial they did take the opportunity to make money through media manipulation and shorting stock.”

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.