On September 22, Boston Scientific published the final summary of CrowdStrike’s investigation into the August 25 cyberattack that disrupted its manufacturing, order processing, and shipping worldwide. CrowdStrike determined that the attacker gained access through an external-facing network device and then reached a limited portion of the company’s on-premises IT environment. It found no evidence of compromise in Boston Scientific’s supervisory control and data acquisition (SCADA) environments or in business systems tied to manufacturing maintenance. Manufacturing was disrupted anyway.
That gap, between where an attacker was and what stopped working, ran through everything I covered on this week’s episode of CyberSecureOT. Berlin’s attackers claim 5.7 terabytes of data left the network before two departments were isolated. An Iranian state-linked group is handing developers trojanized coding challenges. A sandbox flaw exposed AI automation platforms. None of these incidents required breaking into a controller. Each shows how much operational consequence now sits in enterprise IT, developer laptops, and the tools around them.
IT-OT dependency turns an edge device into a production outage
Boston Scientific disclosed the incident in an SEC filing on August 26 and, as Industrial Cyber reported, staff at its manufacturing facility in Cork, Ireland were sent home. By September 9, the company said manufacturing, order fulfillment, and shipping had been fully restored, with its distribution network at or above normal levels. It said existing implanted cardiac devices were unaffected, while new activations of its LATITUDE remote monitoring system had been disrupted.
On the show, I said the attackers likely came in through an edge device or compromised credentials, and that the full picture was not yet known. The CrowdStrike summary has since confirmed the external-facing network device. My working theory for the production halt was that the intruders reached an ERP or inventory management system, and that once that planning layer froze, an automated, FDA-validated manufacturing process had nothing to run on. The published summary does not name the affected systems, so that remains my assessment rather than a finding. What the summary does establish is that investigators found no evidence the attacker reached the plant-floor control environment, and manufacturing was disrupted regardless.
Jacob Krell of Suzu Labs framed the leverage well in his comments to Industrial Cyber: “The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for.” For cardiac devices, which are scheduled for specific procedures, a missed ship date can mean a canceled surgery. Most of the company’s updates measured recovery in shipping and backlog terms, with the LATITUDE disruption given comparatively little space. We may never learn whether any patient was harmed, but even one delayed procedure matters. No group has claimed the attack, and CrowdStrike found no evidence that data was accessed, staged, or exfiltrated.
Berlin shows why refusing the ransom does not end the incident
Berlin’s case is the opposite problem: the data left first. Forensic investigators placed the exfiltration between August 7 and 12, and the Senate Departments for Urban Development, Building and Housing and for Mobility, Transport, Climate Protection and the Environment were cut off from the state network, the Landesnetz, on August 14. The state government confirmed that the Rhysida group claimed responsibility, claimed 5.7 terabytes of stolen data, and put it up for auction with a minimum bid of 30 bitcoin, roughly two million euros. Berlin refused to pay, in what Industrial Cyber tracked as a record month for ransomware attacks worldwide. Rhysida published a first data package on September 4 and, according to the state, a second on September 6 that included access credentials.
Deutsche Welle reported that the attackers got in after an employee in the transport administration interacted with a phishing email. That fits Rhysida’s documented playbook. The joint FBI, CISA, and MS-ISAC advisory on the group, which Industrial Cyber covered when it was issued, lists phishing, external remote services such as VPNs, and the Zerologon vulnerability (CVE-2020-1472) as the group’s access routes. Zerologon was disclosed in 2020. If it is still unpatched anywhere in your environment, it should be at the top of the list, because it hands an unauthenticated attacker domain admin privileges.
This is why I keep saying the old incident response playbook is dead. Berlin may be operational again, but the data is out, and those contact lists and credentials will be recycled into targeted phishing and business email compromise, including against downstream government contractors. Refusing to pay is defensible. It just does not close the incident. The one bright spot: Interior Senator Iris Spranger said the election environment was secure, and Berlin held its state election on September 20. If you are not aggressively segmenting your networks, isolating your backups, and assuming a breach, you are not doing security. You are playing the lottery.
The developer workstation becomes an access path
The third story targets the people who write the software. On September 1, Kaspersky’s findings attributed two new cross-platform remote access trojans, NodeRabbit and PollCat, to Nimbus Manticore, an Iranian group best known for career-themed lures against defense, aviation, and telecommunications targets. Posing as a talent acquisition specialist, the operators sent a software engineer a coding challenge with a three-hour deadline and told the candidate to fix the frontend and leave the server file alone. The first line of that server file imported a trojanized package, colorized_terminal, bundled directly in the archive’s node_modules folder rather than published to npm. The implant launched the moment the package loaded, with persistence built for Windows, Linux, and macOS.
Developers are targeted for what they hold: SSH keys, cloud tokens, and access to the dependency graph. Submitting code samples has been a normal part of getting hired for roughly 15 years, so nobody trained developers to treat a coding test as a threat. The urgency does the rest.
I owe listeners one correction. On the show, we folded two campaigns together. The blockchain-based command and control I described, which resolves its servers through Tron, Aptos, and BNB Smart Chain transactions and delivers a DEV#POPPER-linked RAT, came from compromised beta releases of @joyfill/components and @joyfill/layouts published on July 28, documented by StepSecurity and Socket. That incident has not been attributed to Nimbus Manticore, which Kaspersky found using Azure-hosted infrastructure. What the two share is import-time execution, which slips past scanners that only watch install scripts. Put colorized_terminal, pretty-log, and the 2773 beta versions of the Joyfill packages into your SIEM and SOAR detections.
Sandboxes for AI agents inherit the same trust problem
The last layer is the sandbox itself. In August, Endor Labs disclosed GHSA-864f-rcv7-6rh4, a critical type confusion flaw in isolated-vm, a Node.js library with more than a million weekly downloads that AI and automation platforms such as n8n, Activepieces, and Mastra AI use to run untrusted code. The ExternalCopy feature checks a transfer list once and trusts that check on a second pass. A getter can swap the value in between, a time-of-check, time-of-use condition that lets sandboxed code corrupt host memory and escape. Fixes shipped on August 8 in versions 7.0.1 and 6.2.0.
Put that next to the recruitment campaign. If an AI agent in a vulnerable sandbox is asked to evaluate a poisoned coding challenge, the host and everything it connects to is what gets compromised. That is my scenario, not an observed attack, but it is why I treat the developer’s workstation, the runtime, and the AI tools assisting them as potential hostile vectors.
Dependency maps decide the next outage
Every incident this week came down to fundamentals: an exposed network device, a phishing email, a trusted package nobody inspected. Watch whether Berlin’s review of more than 1.2 million files finds further exfiltration and how the credentials released on September 6 get reused. Watch whether Boston Scientific’s disclosures say more about which systems its production depended on. And watch patch uptake for isolated-vm across AI automation platforms. Asset owners should know which operational functions depend on which enterprise systems before an attacker finds out for them. Developers taking a coding test from someone they do not know should run it in an isolated, disposable virtual machine. A fake $200,000 salary should not become your company’s real breach.
Catch it all in the latest episode of CyberSecureOT.


