This week

- Pornhub premium users’ viewing histories swiped
- Venezuela blames state oil company attack on the US
- UK Foreign Office system breached in October
Interesting stats
$3.4 billion in cryptocurrency stolen in 2025, with over $2 billion being attributed to North Korean attackers, up $681 million over their 2024 ‘haul’, according to Chainalysis. LINK 1,800 suspected North Korean scammers blocked from job applications at Amazon in 2025. LINK … North Korea uses these funds to, amongst other things, fund their nuclear weapons programme.
Five Three things
-
Pornhub’s premium users’ email addresses, search histories, and viewing habits have been stolen by ShinyHunters, who are demanding a ransom from the Canadian company. The information about Pornhub’s paying members may be sensitive and give away sexual preferences. In many ways, it’s not dissimilar to the Ashley Madison breach ten years ago. Pornhub says the information was stolen from web analytics platform Mixpanel, which it has not worked with since 2021. Meanwhile, Mixpanel asserts that it has no evidence that the data originated in its systems, instead saying it stems from a Pornhub company account compromised in 2023. Oddly specific. Either way, Mixpanel has been at the centre of high-profile breaches, and almost a month on, many questions remain about their breach, with the company remaining tight-lipped over details. PORNHUB, MORE, MIXPANEL QS
-
Venezuela’s state-owned oil company Petroleos de Venezuela (PDVSA) has suffered a cyberattack, with details about the extent of the impact being unclear. PDVSA says the attack targeted administrative systems, while four sources who spoke to Reuters say production and shipping operations were at a standstill. PDVSA blamed the attack on the United States, which seized a PDVSA tanker last week, saying that this “attempt at aggression adds to the public strategy of the U.S. government to take over Venezuelan oil by force and piracy”. The attack itself sounds like ransomware. It’s unclear whether the attack is standard cybercriminal activity — a coincidence coinciding with increasing US military activity in the region — or whether there is merit to the allegations (which probably say more about the current state of US foreign policy). If I were to offer up a third option, it’d be a blinder from a third-party foreign power aiming to stoke tensions and destabilise. PDVSA, MORE
-
FCDO: The UK’s Foreign Office was the victim of a breach in October 2025. Trade minister Chris Bryant confirmed on Friday that “there certainly has been a hack at the FCDO,” however, he wouldn’t be drawn on attribution, adding he wasn’t able to say “whether it is directly related to Chinese operatives or indeed the Chinese state”. Tabloid newspaper The Sun first reported the story, suggesting that visa application details had been exposed. However, FCDO investigations have concluded that there is “a low risk of any individual actually being affected”, which makes that sound unlikely. The breach appears to stem from a vulnerability in an FCDO system. Described as a ‘technical issue’ in one of FCDO’s sites, Bryant says the team “managed to close the hole, as it were, very quickly”. IT stacks up that Chinese intelligence may want to know about UK foreign policy, or potentially who is applying for visas. FCDO, MORE
In brief
-
⚠️ Incidents: JLR says that personal data of current and former employees was stolen during the August 2025 cyber attack. French authorities are investigating an intrusion at France’s Interior Ministry after a post on BreachForums claimed to have compromised multiple email accounts and stolen confidential information. The University of Sydney has reported a data breach affecting 20,000 staff, students, and alumni. An internal code repository used by the University was compromised and contained historical data from before September 2018. NHS technology supplier DXS International have disclosed an incident to the ICO and London Stock Exchange. NHS and NCSC are involved in the response, and they understand that no patient services are being impacted. JLR, FRANCE, SYDNEY, DXS INT’L
-
🏴☠️ Ransomware: Ryan Clifford Goldberg and Kevin Tyler have pleaded guilty to taking part in ransomware attacks. It’s notable because cyber security firms employed the pair as incident responders at the time. They used ALPHV/BlackCat ransomware to cause losses exceeding $9.5 million. Ukrainian national Artem Aleksandrovych Stryzha has pleaded guilty to multiple crimes involving the Nefilim ransomware. Stryzha’s co-conspirator remains at large. GOLDBERG/TYLER, NEFILIM
-
🕵️ Threat Intel: Amazon says that they have seen Russia’s APT44 (aka Sandworm) shifting their focus from exploiting vulnerabilities, which potentially exposes them to detection, to targeting misconfigured edge networking devices hosted by customers in AWS. Sticking with Russia, Denmark says that two attacks — on a water utility in 2024 and Danish websites ahead of elections in November this year — were carried out by two pro-Russian groups as “instruments of its hybrid war against the West.” RUSSIA, DENMARK
-
🪲 Vulnerabilities: A pair of perfect-10’s to round out 2025: Cisco says a zero-day vulnerability in its AsyncOS is being exploited to compromise Cisco Security Email Gateway and Secure Email and Web Manager solutions. CVE-2025-20393 (10/10) affects SEG and SEWM when ‘Spam Quarantine’ is enabled and they are exposed to the internet. Cisco believes China’s APT41 is targeting a vulnerability for which no patch is yet available. Restrict access/turn off the feature are your options at the moment. HPE is warning of a critical vulnerability in its OneView infrastructure management solution. CVE-2025-37164 (10/10) affects all versions before v11.00 and allows unauthenticated remote code execution. Sonicwall is warning customers of a zero-day vulnerability in the management console of its SMA1000 appliance. CVE-2025-40602 (6.6/10) scores low, but can be chained with other recent critical vulnerabilities to achieve unauthenticated remote code execution. CISCO, HPE (ADVISORY), SONICWALL (ADVISORY)
-
🧑💻 End user and consumer: Google is shuttering its dark web notifications a year after launch because users found there wasn’t much help available to do anything about it. That may be true, but in some cases knowing that data is out there is insight enough, just not enough for a consumer-grade service. Koi security says a range of Chrome and Edge browser extensions, promoted by Google and Microsoft respectively, capture AI chat conversations and forward them on to the developer. Urban VPN Proxy / Browser Guard / Ad Blocker has sizeable (not in a good way) privacy policies that promote “AI protection”; however, the parent company is a marketing firm. DARK WEB, URBAN
-
🧰 Guidance and tools: NIST has released a draft Cybersecurity Framework Profile for Artificial Intelligence, designed to ‘secure, defend and thwart’ risk in AI systems. The AI CSF profile maps onto NIST’s existing Cybersecurity Frameworks. AI CSF
-
🛠️ Security engineering: Microsoft is finally deprecating the RC4 encryption algorithm. By ‘mid-2026’, AES-SHA1 will be the default, and administrators will need to turn on RC4 support if required in their environments. RC4 is the favourite of attackers because its weaknesses make it easy to break in, for example, ‘Kerberoasting’ attacks to get hold of credentials. RC4
-
👮 Law Enforcement: The FBI and counterparts in Germany and Finland have taken down cryptocurrency exchange E-Note for allegedly laundering funds for cybercrime groups. ENOTE
-
🗞️ Industry news: Lieutenant General Sir Rob Magowan will take command of the UK’s cyber and specialist operations command (CSOC) in March 2026. CSOC
And finally
- As we approach the end of the year, I’d like to thank you for reading, and especially if you’ve shared or encouraged others to subscribe to. I really appreciate the time and trust you give me. If I may be a little cheeky… can I ask you for any feedback and, maybe, that you might share this link and your thoughts with your network?
For those of you celebrating, I wish you the happiest holidays and time to relax and recharge with those nearest and dearest to you.