Robin’s Newsletter #394

4 January 2026. Volume 9, Issue 1
Ransomware attack against Romania's water agency. MongoDB vulnerability being exploited. Browser extensions for corporate espionage?
Join hundreds of subscribers who get this first, every Sunday. Subscribe

Happy New Year! I hope you had a relaxing and enjoyable time in the last couple of weeks and are feeling refreshed for the year ahead. It’s hard to believe this is the ninth year of writing this newsletter! Let’s dive back in an get you up to speed…

This Week

Need to Know, 4th January 2026

  • UK Cyber Strategy Refresh
  • US announces AI research centres
  • Warnings over MongoBleed vulnerability
  • Ransomware attack against Romanian water agency
  • Zoom Stealer browser extensions nab meeting intel

Interesting Stats

72 known physical attacks to steal cryptocurrency in 2025. Reporting is sporadic, but the threat of kidnap or violence if you hold large amounts of cryptocurrency is real… It’s almost like we invented banks to store and protect people’s valuable commodities. LINK

Five Things

  • UK Cyber strategy: The UK will likely refresh its national cyber security strategy in 2026. Lawfare has a good history of how this has evolved since the first was published in 2009 under the last Labour government. Former UK Cyber Ambassador Conrad Prince, writing for RUSI, has suggested narrowing the focus to cyber resilience rather than broader ‘cyber power’ and offensive military capability. I think focus is a good thing, though the ability to ‘release the hounds’ in response to large-scale cyber-attacks is a potentially attractive deterrent to retain. There’s plenty of work to do on the defensive side of the fence: A year ago, the National Audit Office (NAO) found ‘significant gaps’ in 58 critical departmental IT systems and that the government would not meet goals to be resilient to cyber-attack by 2025. It’s good to reflect on how different all landscapes — threats, geopolitics, regulation, technology — are in 2026 compared to 2009, and to develop a strategy that reflects changing norms, UK, EU, and wider regulatory frameworks, and industry initiatives. LAWFARE, RUSI, NAO

  • US AI Research Centres: NIST and MITRE are stumping up $20 million to establish two new artificial intelligence research centres focused on advanced manufacturing and critical infrastructure. The research centres will consider how to protect from AI-enabled threats, as well as “drive the development and adoption” of AI-powered tools. The US has a sprawling CNI sector, with tens of thousands of municipal drinking water systems alone, many of which struggle with cyber resourcing or rely on volunteer efforts. Finding ways to boost capability and capacity through technology and people would be a win for overall national cyber resilience. AI RESEARCH, VOLUNTEERS

  • MongoBleed: CISA says that a high vulnerability in MongoDB is being actively exploited, after a security researcher dropped exploit code for it on Christmas Day. (Dick move, if you ask me.) CVE-2025-14847 (8.7/10) was patched on 19th December, and can be exploited by creating tens of thousands of unauthenticated connections per minute to a MongoDB Server, potentially exposing database passwords, AWS keys, and other secrets. MONGOBLEED, ADVISORY

  • Romania’s water industry has been operating manually since a ransomware attack on 20th December spread through over ten organisations, encrypting around 1,000 systems. Administrația Națională Apele Române (Romanian Waters) is responsible for drinking water, dams, waterways, and other systems in the country. Incident responders believe the attackers used Windows BitLocker to ‘live off the land’ and encrypt the systems without using malware. ROMANIA

  • Zoom Stealer: Security researchers have uncovered eighteen malicious Chrome, Firefox, and Edge extensions that collect online meeting data from 28 video conferencing platforms. The meeting IDs, passwords, topics, descriptions, and more are relayed to a China-linked threat actor. This data may be useful intelligence for corporate espionage. While it’s not the content of the meetings, the metadata itself is often highly valuable, showing who is talking to whom (and potentially about what, and how to join). It’s why China was breaking into US lawful intercept systems, and also a core part of the NSA programmes revealed by Edward Snowden. ZOOM STEALER

In brief

  • ⚠️ Incidents: Hacktivists have scraped 86 million music files and metadata totalling 300 terabytes from Spotify. An attacker claims to have stolen details on 40 million subscribers from Condé Nast, and leaked 2.3 million records relating to the magazine WIRED as proof, while claiming the publisher “does not care about the security of their users’ data”. La Poste, France’s post office, suffered a distributed denial of service (DDOS) attack three days before Christmas, rendering online services inaccessible and delaying some deliveries. SPOTIFY, CONDE NAST, LA POSTE

  • 🕵️ Threat Intel: ClickFix: ‘ErrTraffic’, a new cybercrime service, automates ClickFix-style attacks on compromised websites. The platform allows setting conditions to target users which, if met, cause the website to ‘glitch’ or fonts to render incorrectly. A pop-up prompts the website visitor to download an ‘update’ or run a command to fix the issue. CLICK FIX

  • 🧿 Privacy: South Korea will require facial recognition when signing up for new mobile phone numbers. Sticking with South Korea, commerce giant Coupang will split $1.17 billion amongst the 33.7 million victims of its recent data breach. FACIAL RECOGNITION, COUPANG

  • 👮 Law Enforcement: Authorities in Georgia have arrested the former head of the country’s security service on bribery charges. Prosecutors allege that Grigol Liluashvili received around $1.4 million through relatives to shield scam call centres from government investigation. GEORGIA

  • 💰 Investments, mergers and acquisitions: ServiceNow is buying asset and exposure management outfit Armis for $7.75 billion in cash. ARMIS

  • 🗞️ Industry news: OpenAI is looking for a ‘head of preparedness’ to tackle emerging threats and “tracking and preparing for frontier capabilities that create new risks of severe harm”. The role pays $555,000. OPENAI

And Finally

  • Congrats to the National Crime Agency’s Gavin Webb, who received an OBE in the King’s New Year Honours for his role coordinating Operation Cronos, the international effort that led to the disruption of LockBit in 2024. CRONOS
Robin

  Robin's Newsletter - Volume 9

  UK Cyber Strategy Artificial Intelligence (AI) MongoDB Romania Ransomware Critical National Infrastructure (CNI) Water Espionage Browser Extensions