Robin’s Newsletter #385

2 November 2025. Volume 8, Issue 44
The human cost of MOD's Afghan data breach. Surprise deregulation of US telcos. New dependency bypass technique on npm developers.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 2nd November 2025

  • Threats to life, family, and colleagues in MOD Afghan data breach
  • FCC to rescind January telco cyber regulation
  • New wave of npm attacks circumvents dependency checks
  • Swedish electricity transmission operator data breach
  • No Twitter breach, but you may need to reenrol MFA

Interesting stats

40 victims/month of the Qilin ransomware gang in the second half of 2025, with  1/4 victims are in the manufacturing sector,  1/5 in the professional and scientific sector, and  1/10 being wholesale trade firms, according to Cisco. LINK

Anti stats: ~80% of ransomware attacks are AI driven~ err, no they’re not. The MIT paper, seemingly funded by vendor Safe Security, has been pulled after a take-down by Kevin Beaumont and widespread backlash. It talked about Emotet (defunct for many years) as an AI-powered ransomware actor, amongst many, many egregious errors. @GossiTheDog, LinkedIn (copy of the paper) (h/t Marcus)

Five things

  1. MOD Afghan data breach: Evidence submitted to the Defence Committee on Friday detailed the human impact of the MOD’s Afghan data breach. Threats to the lives of individuals, their families, and colleagues linked to the breach were documented from 231 individuals who spoke with researchers from Refugee Legal Support and were assisted by academics from Lancaster and York universities. Of them, 49 said family or colleagues had been killed in Afghanistan, 105 had their homes raided by the Taliban, and 100 had received direct threats to their own lives. In total, 87% reported some personal risk stemming from an incident in which a MOD staffer accidentally emailed a spreadsheet containing 33,000 entries. The majority were Afghan nationals who had supported UK forces in the 20 years following the 9/11 terrorist attacks. The UK government went to significant lengths to keep the breach under wraps, with Defence Secretary Ben Wallace obtaining a super injunction, suppressing knowledge of or reporting by the media and Parliament, while running a secret relocation scheme that has cost over £850 million ($1.2 billion), with numbers also being excluded from official statistics. JLR has gotten much attention for being the most economically significant attack on the UK economy recently, but the direct and indirect costs of this breach and relocation scheme are not far behind. MOD

  2. Telco deregulation: The US Federal Communications Commission (FCC) has announced plans to remove cyber regulations introduced after Chinese attackers gained access to multiple telcos to steal Presidential and Vice Presidential communications. FCC Secretary Marlene Dortch said telcos had taken voluntary steps and that the “vague and amorphous” ruling “applies the same inflexible, across-the-board cybersecurity requirements to all telecommunications carriers without regard to their risk, size, or organizational posture.” FCC

  3. PhantomRaven: More npm attacks, this time it’s new malware dubbed PhantomRaven, involving 126 packages, that uses a new technique researchers are calling Remote Dynamic Dependencies (RDD). Dependencies are loaded from additional code hosted on a remote server, rather than being detailed upfront or in post-install scripts. They are hidden from most tools that map or investigate package dependencies. PhantomRaven steals GitHub tokens, cloud creds, SSH keys, and other sensitive data. NPM

  4. Sweden’s electricity transmission system operator says a breach claimed by a ransomware gang only affected a file transfer appliance. “The electricity supply has not been affected,” said Svenska kratnät CISO Cem Göcgören. The Everest cybercriminals are threatening to leak ‘hundreds of gigabytes’ of internal data that they claim to have stolen. Svenska kraftnät is working with law enforcement and national cyber authorities to investigate the breach. SWEDEN

  5. Social media PSA: If you use a YubiKey or a passkey with X/Twitter, you have two weeks to re-enrol your MFA token, with the social network clarifying that “re-enrolling your security key will associate them with x.com, allowing us to retire the Twitter domain.” Also, LinkedIn will start sharing your data to train AI and with Microsoft for targeted advertising this coming Monday, 3rd November. You can opt out. TWITTER, LINKEDIN (OPT-OUT)

Startup spotlight

As part of my pledge to support the UK cyber ecosystem, I’ll be featuring a different UK cyber startup each week.

This week it’s Threatnet, an early-stage business, finding product market fit and gaining initial customers:

  • What do they do? Threatnet is a next-generation credential monitoring platform that analyses billions of data sources across both the clear and dark web to give security teams deep, actionable insight into attacker behaviour.
  • Who is it for? Mid-to-large enterprises with sizeable workforces, reliance on internal systems, and high-value executives vulnerable to credential exposure.
  • Where can you find out more? WEB, LINKEDIN

If you’re a UK-based cyber security startup interested in being featured in a ‘Startup Spotlight’ in my weekly newsletter, please fill out this form for consideration. It’s not a paid thing; just trying to support our ecosystem 🚀

In brief

  • ⚠️ Incidents: Russia’s food safety agency experienced a distributed denial-of-service attack last week that disrupted systems used to track the movement of agricultural products and food shipments across the country. Iran says the personal data of students and staff at its Ravin Academy, a school that teaches cyber security to intelligence agency recruits. Someone snuck into a Cellebrite and shared details of the company’s abilities to unlock Android phones. American business process outsourcing company Conduent has confirmed that a 2024 breach affected over 10.5 million people and has begun sending notifications to affected individuals. US telecoms provider Ribbon has disclosed that state-sponsored attackers “gained access to the company’s IT network” in December 2024. A Ribbon spokesperson confirmed that the breach had affected three of the company’s customers, which include Fortune 500 firms and the US Department of Defense. “We have terrible security practices and are completely unmeritocratic,” reads a mass email sent to University of Pennsylvania alumni, students, staff, and others after the university’s email system was compromised this week. The aim of the intruders appears to be deterring financial donations, closing “please stop giving us money”. Merkle, a subsidiary of marketing giant Dentsu, is writing to current and former staff after bank, payroll, and other personal data were stolen. EY left a 4TB unencrypted database backup in a publicly accessible cloud storage bucket. The backup included API keys, cached authentication tokens, session tokens, service account passwords, and user credentials, amongst what is presumably a lot of other data on the firm or its clients. RUSSIA, IRAN, CELLEBRITE, CONDUENT, RIBBON, PENNSYLVANIA, DENTSU, EY

  • 🕵️ Threat Intel: Snigdha Poonam’s long read for The Guardian looks at the context and how ‘scamming became the new farming’ for some districts in India. INDIA

  • 🧑‍💻 End user and consumer: The Herodotus Android banking trojan mimics human behaviour, delaying text input into US, UK, Turkish, Polish, and other countries’ banking and cryptocurrency apps, to avoid detection. Google Chrome will start warning users before connecting to sites that use unencrypted HTTP. The ability to always use secure connections has been an opt-in option for some time. HERODOTUS, CHROME

  • 🧰 Guidance and tools: If you still run Microsoft Exchange, CISA and the NSA have published guidance on how to do it securely. German sysadmins may wish to take note: the country’s cyber agency says 92% of the nation’s Exchange servers are running out-of-support versions. EXCHANGE, GERMANY

  • 🛠️ Security engineering: OpenAI has announced a private beta of its automated bug hunting, patching, and remediation project dubbed Aardvark. OPENAI

  • 🏭 Operational technology: Canada’s national cyber agency is warning that hacktivists have breached water, energy, and agriculture CNI sites in recent weeks. Internet-exposed industrial control systems have enabled the break-ins. ICS systems being remotely accessible can be extremely helpful to CNI operators with large, geographically distributed networks to monitor, but these systems should not be on the open internet. HACKTIVISTS

  • 🧿 Privacy: US Immigration and Customs Enforcement (ICE) “does not provide the opportunity for individuals to decline or consent to the collection and use of biometric data/photograph collection,” according to internal documents. ICE’s Mobile Fortify app is being used to capture details of individuals, with the data apparently being held for 15 years. A human rights group has submitted a formal complaint over the appointment of Niamh Sweeney, a former Meta employee, to Ireland’s Data Protection Commission (DPC) FORTIFY, DPC

  • 👮 Law Enforcement: Peter Williams, former general manager at defence contractor L3Harris’s Trenchant division, has pleaded guilty to selling zero-day exploits to a Russian broker. Russian police say they’ve arrested three individuals suspected of developing the Meduza Stealer malware. Traditionally, Russian authorities have been quite… tolerant of cybercriminals operating in the country. Either these guys didn’t pay their dues, or it’s further evidence of a shift to curb or control such groups. WILLLIAMS, MEDUZA

  • 💰 Investments, mergers and acquisitions: Threat intel firm Searchlight Cyber has acquired four-person, Luxembourg-based Intangic to add risk quantification and third-party capabilities to its business. Francisco Partners will purchase Apple MDM and security firm Jamf and take the company into private ownership, in a $2.2 billion deal. INTANGIC, JAMF

  • 🗞️ Industry news: F5 told an earnings call that it expects its recent disclosure that nation-state threat actors compromised its network to affect revenues, as customers delay or cancel renewals. Nothing surprising here, but it will be an interesting case study in revenue impact. F5

And finally

  • Lock picking: I know some of you are into lock picking and thought you’d be interested in this case where Florida-based Proven Industries unsuccessfully sued YouTube lock picker Trevor McNally after they baited him into testing their locks. LINK, VIDEO
Robin

  Robin's Newsletter - Volume 8

  Ministry of Defence (MOD) Afghanistan Federal Communications Commission (FCC) Node package manager (npm) Software supply-chain Sweden Critical National Infrastructure (CNI) Electricity Transmission Twitter LinkedIn Privacy Scammers India Microsoft Exchange OpenAI Canada Hacktivists Meduza Russia F5