
teissTalk host Geoff White was joined by Sarah Armstrong Smith, Chief Security Advisor, Microsoft as lead guest; Garry Scobie, Deputy Chief Information Security Officer, The University of Edinburgh; and Jamie Moles, Senior Technical Marketing Manager, ExtraHop.
Over 24 trillion telemetry signals are analysed by Microsoft every 24 hours. The company has spotted a huge spike in nation state activity earlier last year – many of them attributed to Russia. In terms of targets, there has been a move away from government espionage to IT operators. Ukraine has always been Russia’s training ground for developing malware, but attacks really started to increase against critical infrastructure there this January.
Fox Blade, a never-before-seen piece of “wiper” malware against Ukrainian infrastructure was unleashed some hours before the military attack on Ukraine was launched. As a result, within three hours, Microsoft’s virus detection systems had been updated to block the code.
Thankfully, the fact that the Russian state showed its willingness to push boundaries and become increasingly destructive prior to the war led to Nato and allied nations ramping up collaboration in sharing threat intelligence between states and across the public and private sectors before the outbreak of the war. Although cyber attacks by Russia against Ukraine are much weaker than anticipated, a massive cyber-attack is still not off the table. (Microsoft, as a commercial entity, never attributes attacks but gives them names of the elements in the Periodic Table.)
Russia doesn’t seem to have deployed a range of cyber weapons in the war that they certainly are in the possession of. A lot of what Ukraine has is Soviet legacy infrastructure, which works in the favour of the Russians. For malicious actors, it’s a prerequisite to have a deep understanding of the infrastructure they seek to attack, and former Soviet states, unlike western public and private entities, do certainly have that knowledge.

Criminals try to take advantage of the window between breaching a network and the victims patching up their vulnerabilities. Microsoft has seen a lot of scanning going on around the Log4J incident. In the absence of open-source inventories, companies were scanning their systems for open-source code. And so did cyber threat actors, including nation states (e.g., Hafnium).
Open-source log really matters. Software that you buy use GPL licences to access open source when they add them to their main product. However, you can easily buy a closed-source product without realising it has open-source modules. It would be IT’s task to go through all the license agreements and have a clear picture of what is installed, but it is rather cumbersome.
Log4J is in more than a billion devices including servers, workstations, car navigation systems and GPS platforms. Log4J has become ubiquitous and a backdoor to a shocking number of networks thanks to it being a logging tool that is commonly added to Java installs. We’ve already been aware of open-source vulnerabilities for the last couple of years. In 2018, a survey found an average of 19 vulnerabilities in 330 Android apps, which already were on the Common Vulnerability and Exposure database.
There have also been publications of vulnerable GitHub projects and projects containing open-source code that have been hijacked by cyber criminals.
Users and owners of software that contain open-source code both have a role to play in tackling the problem. But it’s certainly key that developers who choose to utilise open source are accountable for how it’s used, as well as for due diligence, testing, patching and security and response plans associated with them.
Watch it on-demand here.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543