This week

- US Cyber Command involvement in Maduro operation
- CSR Bill passes second Commons reading
- UK introduces £210M Government Cyber Action Plan
Interesting stats
10x increase in Chinese-linked cyberattacks against the Taiwanese energy sector in 2025 over 2024, 57%, the majority, were attacks on vulnerabilities in hardware and software, with 21% being Distributed Denial of Service (DDoS) attacks, and a further 18% is being classified as social engineering, according to Taiwan’s National Security Bureau. LINK
£50 million in cyber security investment was made at the UK Legal Aid Agency before its 2025 breach, which exposed sensitive case information. LINK
Five Three things
-
Venezuela: A lot of commentators have got very excited about President Trump’s acknowledgement of US Cyber Command’s involvement in the recent mission to capture Venezuelan leader Nicolás Maduro. Trump mentioned Cyber Command in proximity to comments that “The lights of Caracas were largely turned off due to a certain expertise that we have.” Is this type of capability likely coveted by US forces? Absolutely: it’s the sort of thing most nations with offensive cyber forces will have considered or drawn up plans for. However, were the lights in Caracas turned off by a US cyber-attack? I’d be surprised to see the US burn that type of high-end capability in a strike like this, and BGP theories are largely debunked. Plus, the simplest solution is often the right one: the Venezuelan grid has been underfunded for decades, with mismanagement and corruption resulting in a fragile system and frequent blackouts. It took a week to restart following an outage in 209. So it’s probably way cheaper to pay someone off, or break in and flip the metaphorical breakers, than launch a cyber-attack. Instead, I wonder if US Cyber Command’s role was focused on intelligence gathering, general systems access, or targeting, for example, the mobile phones of key individuals. That would be supremely useful, and fit with what appears to be a surgical strike
-
The UK’s Cyber Security and Resilience bill got its second reading in Parliament on the 6th January. The bill updates the Network and Information Systems regulations introduced while the UK was part of the European Union. The EU introduced their ‘NIS2’ regulations in October 2024, and the delays to comparable UK improvements have been a source of frustration. The revised UK regulations would increase the number of sectors in scope (including data centres, IT managed service providers, organisations that can control large electrical loads such as TVs or batteries, and suppliers critical to the operation of a regulated organisation, regardless of their sector). Looking back at two of the UK’s largest cyber incidents, neither Marks & Spencer nor Jaguar Land Rover is in scope. As it stands, new obligations will be introduced around incident reporting, and essential service providers will need to take their supply chains into account. The next stage is a Commons committee stage, scheduled for early February, and a call for evidence is currently open. A notable departure from the EU’s NIS2 is that the CSR does not include central or local government, though the UK already treats telco regulation separately, and so legislating separately for government is not without precedent. See also the Cyber Action Plan below.
-
Alongside the CSR’s second outing, the UK government introduced a new Government Cyber Action Plan (GCAP) with £210 million ($282M) funding to boost the security of public services. This will create a new Government Cyber Unit, overseen by the Department for Science, Innovation and Technology, and establish cyber security as a dedicated profession within the Civil Service. Admitting that previous goals were not going to be achieved, the new plan and investment are intended to give greater visibility of risks, more joined-up action and coordination, faster response to incidents, and ultimately higher government resilience. The first ‘building’ phase will run through April 2027, followed by the ‘scaling’ phase through April 2029, before an ‘improving’ phase of continual improvement. More on the plan and milestones are available on gov.uk: the first objective is to get better visibility of cyber risk; something I wholeheartedly can get behind!
In brief
-
⚠️ Incidents: The Illinois Department of Human Services (IHDS) has exposed the personal information of 700,000 state residents in two separate incidents, where information was left accessible on the Internet. In the first incident, which came to light in September last year, the names, addresses, and disability information of over 32,400 residents were leaked via a mapping service for planning applications. The second, also detected around the same time, included the names, addresses, and benefit statuses of 672,616 Medicare and Medicaid recipients. The data was accessible from April 2021 and January 2022, through September 2025 respectively. BreachedForums: The latest incarnation of notorious cybercrime forum BreachForums appears to have suffered its own breach, with a member database, dating from August 2025, and containing the data of 324,000 accounts, plus an encryption key, being leaked. Iran appears to have blocked internet access outside the country amid widespread protests. Kensington and Chelsea Council has written to residents to advise that their data may have been stolen during a November 2024 incident.
-
🪲 Vulnerabilities: Veeam has patched (advisory) a critical remote code execution vulnerability (CVE-2025-59470; 9/10; ) in its backup software. Automation platform n8n has fixed a perfect 10 (advisory) vulnerability, allowing unauthenticated file access through certain workflows (CVE-2026-21858; 10/10). TrendMicro is warning of a critical vulnerability in its on-premise Apex Central (advisory) solution that allowed attackers to execute arbitrary code with SYSTEM privileges (CVE-2025-69258; 9.8/10).
-
🧑💻 End user and consumer: IT admins may soon be able to unlstinall Microsoft Copilot.
-
🧿 Privacy: California’s Delete Request and Opt-out Platform, aka DROP launched last week and gives Californian residents a single portal to request hundreds of data brokers remove their personal information.
-
👮 Law Enforcement: Spanish law enforcement have arrested 34 people suspected of being part of Black Axe, a cybercrime gang specialising in business email compromise and attacker-in-the-middle attacks. Chinese authorities have released images of Chen Zhi arriving in China following extradition from Cambodia. Chen, who founded Prince Group, a conglomerate including banking, real estate, and hospitality operations, has been indicted by the US and is believed to be a ‘scam kingpin’. Chinese media as “leader of a major transnational gambling and fraud crime syndicate”. In November 2025, China sentenced five Myanmar mafia members to death for their parts in running scam call centres.
-
💰 Investments, mergers and acquisitions: CrowdStrike is acquiring identity management firm SGNL in a deal valued at around $740 million.
-
🗞️ Industry news: The NSA announced Tim Kosiba as its deputy director after a protracted appointment process that has taken nine months. Kosiba steps into the top civilian role at the agency after a stint in the commercial sector. Before that, he spent 25 years at the FBI and then later at the NSA.
And finally
-
If it’s not DNS, it’s a certificate: Logitech allowed a certificate used by its Options+ and G HUB macOS apps to expire this week, rendering them inoperable and resetting the configuration of keyboards, mice, webcams, and more. The certificate appears to have been used as part of the update mechanism, so built-in updates do not work, and a special ‘patch’ installer has been released to replace the expired cert.
-
Stop sign: Last year’s compromise of pedestrian crossings in Palo Alto and Menlo Park — spoofing Mark Zuckerberg and Elon Musk (vol. 8, iss. 16) — was possible because Caltrans didn’t change the manufacturer’s default password.