A botnet exploited vulnerabilities in SPF DNS record configurations, compromising 13,000 MikroTik devices and spoofing around 20,000 web domains to spread malware. The result was a widespread spoofing attack carrying malware-laden attachments. It is recommended to avoid permissive SPF configurations, regularly check DNS records, and use Hosted SPF services with Macros in order to prevent such attacks.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.