Robin's Newsletter - Volume 8
Volume 8 of Robin’s Newsletter covers the year 2025.
December 2025
December 2025
Vol. 8, Iss. 52
Vol. 8, Iss. 51
Robin’s Newsletter #392
Pornhub viewing history swiped. Venezuela state oil company attack blamed on US. China acused of October breach at FCDO.
Vol. 8, Iss. 50
Robin’s Newsletter #391
Have we reached peak ransomware? 50+ orgs affected by React2shell fallout. Highly-targeted 'ConsentFix' campaign.
Vol. 8, Iss. 49
Robin’s Newsletter #390
Critical vuln in React. 'Performative' action taken against scam compound in Myanmar. No E2EE for smart toilet camera.
November 2025
November 2025
Vol. 8, Iss. 48
Robin’s Newsletter #389
Shai-Hulud NPM worm back. Gainsight CEO downplays breach. Three London councils struggle with 'cyber issue'. Poetic AI jailbreaks.
Vol. 8, Iss. 47
Robin’s Newsletter #388
Supply-chain woes for 200 Salesforce customers. WhatsApp user base enumerated by researchers. Organised crime bought a bank for Christmas.
Vol. 8, Iss. 45
Robin’s Newsletter #387
AI-powered cyber-espionage campaigns, JLR incident impacts UK GDP, Cyber Security and Resilience Bill unveiled.
Vol. 8, Iss. 45
Robin’s Newsletter #386
Overblown AI malware hype. Rogue cyber security pros moonlighting as ransomware affiliates. Meta profiteering from scammers.
Vol. 8, Iss. 44
Robin’s Newsletter #385
The human cost of MOD's Afghan data breach. Surprise deregulation of US telcos. New dependency bypass technique on npm developers.
October 2025
October 2025
Vol. 8, Iss. 43
Robin’s Newsletter #384
AWS outage knocks out thousands of customers; JLR incident estimated to cost UK economy £1.9B; ICO decided not to investigate MOD Afghan breach.
Vol. 8, Iss. 42
Robin’s Newsletter #383
‘Sophisticated’ threat had ‘long-term’ access to F5. 'Nationally significant' attacks against UK up 50%. NK hiding malware in smart contracts.
Vol. 8, Iss. 41
Robin’s Newsletter #382
Discord data breach includes government ID verification info. It's trivilially easy to influence an LLM. JLR restarts operations.
Vol. 8, Iss. 40
Robin’s Newsletter #381
Medusa's mistaken cyber correspondent. Home Office submits new TCN tagreting British Apple customers. US Government shutdown cyber impact.
September 2025
September 2025
Vol. 8, Iss. 39
Robin’s Newsletter #380
JLR secures line of credit for supply chain. US Secret Service uncovers 100,000 SIM farm. NCA arrests man in Collins Aerospace attack.
Vol. 8, Iss. 38
Robin’s Newsletter #379
European air travel disrupted by Collins Aerospace attack. Shai-Hulud npm worm infects 180+ packages. Microsoft's Entra ID verification clanger.
Vol. 8, Iss. 37
Robin’s Newsletter #378
JLR says data taken as supply chain worries grow. US wraps up is disinformation cooperation centre. Switzerland considering ID requirements for VPNs.
Vol. 8, Iss. 36
Robin’s Newsletter #377
JLR production disruption. Anthropic's $1.5B settlement. Sainbury's using live facial recognition.
August 2025
August 2025
Vol. 8, Iss. 35
Robin’s Newsletter #376
Salt Typhoon comp'd over 200 organisations. Anthropic says cybercrims run ransomware ops using Claude. SK Telecom lacked pretty much any security.
Vol. 8, Iss. 34
Robin’s Newsletter #375
US intel chief says UK walking back E2EE backdoor (for US citizens?) Interpol arrests 1,200 in African cybercrime crackdown. Accenture to acquire CyberCX.
Vol. 8, Iss. 33
Robin’s Newsletter #374
Second UK government Afghan resettlement data breah. Colt telecom turns off some services to contain incident. Some speed cameras in the Netherlands are offline.
Vol. 8, Iss. 32
Robin’s Newsletter #373
Bouygues telecom breach affects 6.4M. Microsoft Exchange vulnerability allows cloud takeover. Thai hospital fined for patient record food wrappers.
Vol. 8, Iss. 31
Robin’s Newsletter #372
Hacktivists ground dozens of Russian flights. Palo Alto acquires CyberArk for $25 billion. OpenAI rolls back conversation sharing feature.
July 2025
July 2025
Vol. 8, Iss. 30
Robin’s Newsletter #371
SharePoint shells for China. Clorox's $380M help desk lawsuit. And massive surges in UK VPN signups following Online Safety Act checks come into effect.
Vol. 8, Iss. 29
Robin’s Newsletter #370
Data on 6.5M Co-op members stolen. UK MoD kept Afghan data breach a secret using super-injunction. Salt Typhoon all up in National Guard's network.
Vol. 8, Iss. 28
Robin’s Newsletter #369
Four arrested in UK retail cyber attacks. Critical Citrix Bleed 2 vulnerability. Would you like fries with that? McDonald's 123456 password.
Vol. 8, Iss. 27
Robin’s Newsletter #368
Sinoloa cartel used compromised mobile devices, CCTV, to identify and kill FBI informants. Qantas breached by Scattered Spider. Canada bans Hikvision.
June 2025
June 2025
Vol. 8, Iss. 26
Robin’s Newsletter #367
WhatsApp banned on House-issued devices. Patient death linked to Qilin ransomware attack. Canadian telco compromised by Salt Typhoon.
Vol. 8, Iss. 25
Robin’s Newsletter #366
Israeli/Iran cyberspace heating up. Scattered Spider turns to insurance industry. 23andMe fined £2.3M by ICO.
Vol. 8, Iss. 24
Robin’s Newsletter #365
Whole Foods supplier disruption. Google outage caused by poor error handling. DarkGaboon ransoming Russian companies. US ATC runs on Win95.
Vol. 8, Iss. 23
Robin’s Newsletter #364
More retail cyber attack news. Meta, Yandex caught de-anonymising Android users. Vendors to collaborate on threat actor naming.
Vol. 8, Iss. 22
Robin’s Newsletter #363
German authorities ID Trickbot, Conti ringleader. Australia passes law requiring ransom payment notifications. Vietnam blocks Telegram.
May 2025
May 2025
Vol. 8, Iss. 21
Robin’s Newsletter #362
Global infostealer, ransomware infrastrucutre takedown. TCS investigating role in M&S incident. Anthropic's AI blackmails developer in test.
Vol. 8, Iss. 20
Robin’s Newsletter #361
M&S insurance claim may top £100M. Coinbase flips script on extortion attempt. OpenAI instructed to retain output log data.
Vol. 8, Iss. 19
Robin’s Newsletter #360
China 'becoming a cyber superpower'. SignalGate twist: it wasn't Signal. SK Telecom breach could result in $5B revenue loss.
Vol. 8, Iss. 18
Robin’s Newsletter #359
Co-op, Harrods join M&S as victims of Scattered Spider breaches. Spanish power outage not a cyberattack. RDP lets you login with old creds.
April 2025
April 2025
Vol. 8, Iss. 17
Robin’s Newsletter #358
M&S Cyber incident. Lots of data from FBI, Verizon, IBM, Mandient. Calls for greater harmonisation of cyber rules.
Vol. 8, Iss. 16
Robin’s Newsletter #357
MITRE CVE funding secured, for now. Florida lawmakers want in on E2EE backdoor. Silicon Valley traffic crossings hacked to play spoof Zuck, Musk audio.
Vol. 8, Iss. 15
Robin’s Newsletter #356
Black Basta ransomware group chat logs leaked. Attackers accessed 150,000 emails at US Treasury bureau. Yes, Oracle was breached.
Vol. 8, Iss. 14
Robin’s Newsletter #355
Oracle quietly starts admitting breach. Cred stuffing against Aussie superannuation funds. Will ransomware gangs put prices up with Trump's tariffs?
March 2025
March 2025
Vol. 8, Iss. 13
Robin’s Newsletter #354
SignalGate is about opesec and governance, not Signal. Oracle continues to deny breach as customers confirm sample data.
Vol. 8, Iss. 12
Robin’s Newsletter #353
Alphabet to buy Wiz for $32B. Oracle denies cloud platform compromise. Clearview AI class action lawsuit grants plaintiffs company stake.
Vol. 8, Iss. 11
Robin’s Newsletter #352
Apple/UK gov hearing held in private. Garantex founder arrested on holiday in India. American fraud losses up 25%.
Vol. 8, Iss. 10
Robin’s Newsletter #351
Silk Typhoon shift focus to tech supply chains. Apple launches legal challenge over UK backdoor request. Scammers sending fake, physical ransom notes.
Vol. 8, Iss. 9
Robin’s Newsletter #350
FBI points finger at North Korea for $1.5B crypto-heist. US deprioritises Russia cyber threat. 7,000 people freed from scam centres in Myanmar.
February 2025
February 2025
Vol. 8, Iss. 8
Robin’s Newsletter #349
Apple disables ADP in UK amidst E2EE fight with UK gov. Trump seeks control of independent agencies. $1.4B stolen from Bybit cryptocurrency exchange.
Vol. 8, Iss. 7
Robin’s Newsletter #348
DOGE and the 'most consequential' breach in history. Salt Typhoon seen in five more telcos. AI Summaries are mostly inaccurate.
Vol. 8, Iss. 6
Robin’s Newsletter #347
UK demands Apple break iCloud encryption. Hurricane-style categorisation of cyber incidents. Meta torrented pirated books to train AI models.
Vol. 8, Iss. 5
Robin’s Newsletter #346
DeepSeek buzz, bans, breaches. NAO says UK gov won't achieve 2025 cyber pledge.
January 2025
January 2025
Vol. 8, Iss. 4
Robin’s Newsletter #345
Trump administration dismisses CSRB, halts cyber dimplomacy efforts. Impact of PowerSchools breach still unknown. EU power grid vulnerabilities.
Vol. 8, Iss. 3
Robin’s Newsletter #344
UK launches ransomware consultation. FTC takes action against GoDaddy for poor security practices. Doom PDF.
Vol. 8, Iss. 2
Robin’s Newsletter #343
Ivanti zero-day exploits. US Treasury breach targeted foreign investment committee. Minor changes needed to manipulate AI models for misinformation.
Vol. 8, Iss. 1
Robin’s Newsletter #342
UN approves cybercrime convention. Clop threatens Cleo breach names. Sanctions for Chinese firm links to Flax Typhoon. Doom as a CAPTCHA.