Robin’s Newsletter #377

7 September 2025. Volume 8, Issue 36
JLR production disruption. Anthropic's $1.5B settlement. Sainbury's using live facial recognition.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Cydea: Simon Goldsmith, CISO at OVO, is my guest in the latest episode of Communicating Cyber. From bullet holes to boiling frogs, we chat about systems thinking, storytelling, and context to help make cyber security meaningful. ▶️ Watch Ep05 now.

Need to Know, 7th September 2025

  • JLR cyber attack disruption expected to last ‘til October
  • Sainsbury’s trialling use of live facial recognition to fight shoplifters
  • Anthropic $1.5B payout for training on pirated books
  • Fina CA issued Cloudflare certs without authority 
  • PromptLock ransomware was NYU research project

Interesting stats

£188.2 million revenue generated by Huaewei Technologies UK in the year to 31st December 2024, down from  £1.28 billion in 2018, following the UK government’s ban on its kit from key critical national infrastructure systems. HUAWEI

5% growth estimate this year for the cyber insurance market, revised down from 6% by SwissRe following ‘market imbalances’ that saw insurers making concessions on premiums and their security control expectation. $15.6 billion in cyber insurance premiums are expected to be written. SWISSRE

15% reduction in bonuses for Qantas CEO and Executive Management “reflect[ing] their shared accountability” for the Australian airline’s July cyber incident. QANTAS

Five things

  1. Jaguar Land Rover: Production has been “severely disrupted” at Jaguar Land Rover this week following a cyber security incident. The carmaker disclosed the incident on Monday through a filing from its parent, Tata Motors, in India. The attackers have been linked to the same group behind the incident at Marks & Spencer earlier this year. The disruption is expected to last until October, with multiple companies in JLR’s supply chain also telling their staff to stay home. JLR, M&S, OCTOBER

  2. Sainsbury’s, Britain’s second largest supermarket, is trialling live facial recognition in a bid to tackle shoplifters. Privacy campaigners describe the move as ‘Orwellian’ and ‘disproportionate’, with reports of innocent shoppers being added to ‘secret watchlists’ curated by Sainsbury’s and its supplier, Faceatch. Shoplifting reportedly cost UK retailers £2.2 billion last year. SAINSBURYS

  3. Anthropic has agreed to destroy copies of 500,000 books that the company pirated to train its artificial intelligence models, and pay each author $3,000. The total settlement is $1.5 billion, believed to be the largest publicly reported copyright litigation settlement in history. Meta, and other AI outfits have used similar tactics: I wonder if similar settlements will be coming their way soon? And does it even matter for the AI firms? Have they already got the benefit? ANTHROPIC

  4. Doh.doh.doh.doh: Certificate authority Fina issued twelve certificates for Cloudflare’s 1.1.1.1 DNS service four months ago, potentially allowing the holder to decrypt DNS over HTTPS traffic. Fina says the certificates were “issued for internal testing… in the production environment”. Cloudflare says it did not authorise the certificates or have knowledge of the testing.  Certificate authorities operate on trust, and events like this can seriously undermine the trust of individual CAs. FINA

  5. Researchers at New York University have claimed responsibility for PromptLock, as part of their Ransomware 3.0 paper. ESET recently discovered an AI ransomware sample on VirusTotal, prompting speculation that cybercriminals may have used it in an undisclosed attack. Now, the NYU team says they’ve engineered the code to only run inside a lab environment and have uploaded it to VirusTotal to see if it’s flagged as malicious by endpoint security solutions. PROMPTLOCK, PAPER (PDF)

In brief

  • 💡 Interesting reads: The FT on the rise of the Chief Trust Officer (CTrO [Awful abbreviation]), which is a bit of a combo of data protection office, CISO, and AI governance. Tampa General Hospital gave a presentation on how it has quantified its cyber risk to turn security decisions in dollars and cents. CTrO, TAMPA CRQ

  • ⚠️ Incidents: An estimated 4,500 Chess.com users have been affected by a data breach of a file transfer system operated by the company. Attackers gained access on 5th June and maintained access through 18th June, before being detected the following day. Personal data is thought to have been exposed. Canadian financial services firm Wealthsimple has suffered a data breach. Attackers stole the personal data of “less than 1%” of Wealthsimple’s 3 million clients, including account numbers, date of birth, and government ID information provided during registration. The company states that the compromise involved a software package from a “trusted third party.” A spokesperson for Wealthsimple confirmed that the third party was “not related to Salesforce”. CHESS.COM, WEALTHSIMPLE

  • 🕵️ Threat Intel: LegalPwn: Researchers at Pangea say they have had success jailbreaking LLMs by embedding instructions within legal disclaimers, or telling the LLM that it will violate copyright restrictions if it parses the malicious code. LEGALPWN

  • 🪲 Vulnerabilities: CISA has added a vulnerability in SiteCore’s content management system to its known exploited vulnerabilities (KEV) list. CVE-2025-53690 relates to deserialisation of untrusted data and can lead to remote code execution. SITECORE (ADVISORY)

  • 💰 Investments, mergers and acquisitions: Varonis has acquired AI email security company SlashNext for a deal rumoured at $150 million. Varnish CEO Yaki Faitelson says the deal will “[connect] the dots between email, identity, and data” and “dramatically” increase the value of his firm’s MDDR service. Cato Networks has acquired Aim Security for an undisclosed sum, to bring together Cato’s secure access service edge (SASE) platform and Aim’s gen AI protections. SLASHNEXT, AIM

  • 🗞️ Industry news: CISA has appointed Nicholas Andersen as executive assistant director of cybersecurity. Palo Alto Networks has been affected by the Salesloft Drift breach. Customers and prospects received a generic, verging on phishing-like email notes. ANDERSEN, PALO ALTO

And finally

  • Google says that a so-called “urgent warning” asking all 2.5 billion Gmail users to reset their passwords is “entirely false” and denies any major breach. GMAIL
Robin

  Robin's Newsletter - Volume 8

  Huawei Cyber insurance Qantas Jaguar Land Rover (JLR) Sainsbury's Anthropic Piracy Copyright Artificial Intelligence (AI) Cloudflare Fina Certificate Authority Trust PromptLock Ransomware LegalPwn