This week

- Poland ‘came close’ to grid blackout
- Dutch port hacker sentenced
- ‘Cobalt Strike’ for cloud Linux identified
- AWS CodeBreach: ^anchor your regex$
- Signal, but make it AI
Interesting stats
A few interested tidbits amongst a WEF’s length Global Cybersecurity Outlook 2026 (PDF) report:
Perception of changing cyber risk over the past year: 87% believe AI vulnerabilities have increased, 77% believe cyber-enabled fraud and phishing have increased, 65% believe supply chain disruption has increased, 58% believe exploitation of software vulnerabilities has increased, 54% believe ransomware attacks have increased.

CEO and CISO concerns differ (CEO / CISO):
- Cyber-enabled fraud and phishing / Ransomware attack
- AI vulnerabilities / Supply chain disruption
- Exploitation of software vulnerabilities / (same)

Five things
-
Poland says it came “very close to a blackout” in the final days of 2025, as defenders repelled a cyberattack against solar farms and wind turbines. Polish officials pointed the finger at Russian sabotage and the novel tactic of targeting multiple smaller generation installations rather than a single large facility. Rapidly connecting or disconnecting generation capacity or demand can destabilise a power grid, triggering safeguards or requiring operators to disconnect some parts to protect others. Operator and maintainer (O&M) contractors are often responsible for a large number of renewable generation sites. These are easier targets than, say, international energy companies, as O&M providers may be much smaller outfits and lack dedicated security personnel. The EU’s NIS2 and the UK’s cyber security and resilience bill are part of the answer here, bringing these smaller organisations in scope of regulation and requiring a consistent level of security.
-
Rotterdam port hack: The Amsterdam Court of Appeal ruled a 44-year-old Dutch national was responsible for compromising the IT systems of a major port in 2020 and 2021, and has handed him a seven-year prison sentence. The attacker convinced a port worker to run malware from a USB key, creating a backdoor into the systems of a container terminal in Antwerp, and allowing him to manage containers, gate, and personnel access. The unauthorised access was used to facilitate the import of drugs. The Court also found the same man guilty of organising the shipment of 210 kilograms of cocaine.
-
VoidLink Linux malware: Checkpoint security researchers say they have identified a new strain of Linux malware (report) that is “far more advanced than typical”. It is designed to be ‘cloud-native’, running on popular cloud services (such as AWS, GCP, Azure, and Tencent), and features over 30 modules to tailor its capabilities, including recon, lateral movement, and privilege escalation. Checkpoint believes Chinese-affiliated threat actors are developing the malware, inspired by Cobalt Strike, a similar framework developed ostensibly to test Windows machines but frequently used by attackers. It’s not been seen in active campaigns at this time, though, given its state of development, it’s reasonable to assume a sign of things to come.
-
AWS CodeBreach: Cloud security outfit Wiz identified a critical misconfiguration in AWS’s CodeBuild service that would have allowed a takeover of Amazon’s GitHub repositories. The researchers speculate that this could have allowed them to inject malicious code into the AWS Console, threatening every AWS account. Fortunately, they reported the issue, which has now been fixed. The regex pattern used to match a maintainer GitHub user ID wasn’t anchored (^ at the start, $ at the end), meaning that, with a lot of jiggery pokery, Wiz was able to register a GitHub user ID that contained an AWS maintainer’s ID as a substring, which would match during the build process. The writeup includes a recommendation for hardening your own build pipelines. Also this week, Amazon made its European Sovereign Cloud generally available, that is “entirely located” within the EU and “independently operated” by EU residents, in a segregated manner to provide assurances that data remains within the bloc.
-
Signal, but AI: Moxie Marlinspike, the pseudonymous engineer behind messaging app Signal, aims to bring private AI to the masses with his new project Confer. All chats are end-to-end encrypted using Passkeys and built on lessons learned from Signal, making them unreadable by the platform’s operator, law enforcement, or other interested parties. This is some cool engineering and thinking, and the opposite of most AI’s that are pretty hellbent at the moment on collecting as much information as possible and remember ‘your whole life’. In other AI news, this is a really interesting read on the misaligned incentives that promote availability not credibility in AI models, making it easier to sow misinformation and push foreign influence. ‘Trustworthy’ (Western) sources are often news outlets that put their content behind paywalls or are busy litigating against AI companies for scraping their content. Meanwhile, the same commercial strategy doesn’t apply to state propaganda and foreign influence campaigns, which want their content picked up.
In brief
-
⚠️ Incidents: Instagram has “fixed an issue that let an external party request password reset emails,” after reports that 17 million people’s data had been stolen. Software distributor Pax8 has confirmed a strategic account executive emailed a spreadsheet containing internal pricing information on 1,800 partners to 40 recipients. The data included Microsoft licensing for the partner’s customers, renewal times, pricing, and more that could be useful to competitors. New York-based Bluspark, a global shipping system provider, left its API exposed, allowing a researcher to create their own admin account and view customer data dating back to 2007. ShinyHunters is apparently extorting GrubHub after stolen customer data was stolen from the food delivery company. The Canadian Investment Regulatory Organisation says it lost the data of 750,000 investors during an August 2025 data breach.
-
🏴☠️ Ransomware: The AZ Monica hospital in Belgium has reported having to transfer critical care patients following a ransomware attack. The University of Hawaii Cancer Centre suffered a ransomware incident in August 2025, affecting a research project, and chose to pay to obtain a decryption and prevent the disclosure of personal information.
-
🕵️ Threat Intel: Void Blizzard threat actors, linked to Russia, have been posing as charities to target people in Ukraine’s military. Scammers are using fake ‘reply’ comments on LinkedIn as phishing lures. DeadLock ransomware group is using smart contracts to distribute and rotate proxy server details for command and control, according to Group-IB, which says the technique mirrors tactics used by North Korean actors. Initial access malware Gootloader is evading detection by chunking its payload into 500-1,000 ZIP archives that are concatenated back together.
-
🪲 Vulnerabilities: Many bluetooth headphones, including those from Google, have incorrect implemented Fast Pair, leaving devices vulnerable to a forced pairing attack — dubbed Whisper Pair — that can be used to eavesdrop if the headset has a microphone and is in range, or track the location of devices at longer distances.
-
🧰 Guidance and tools: Mandiant has open-sourced a tool called AuraInspector that helps detect Salesforce misconfigurations, and also a rainbow table for (the now deprecated) Microsoft NTLMv1 password hashes.
-
🛠️ Security engineering: Vulnerabilities in NeMo, Uni2TS, and FlexTok), Python AI and ML libraries often used with Hugging Face models, may allow remote code execution via poisoned metadata of other packages. The issues stem from another library, Hydra, developed by Meta, used to manage model configurations.
-
🏭 Operational technology: NCSC has published new guidance on securing connectivity to operational technology environments. The principles (PDF) are a collaborative effort from more than 10 national agencies and include conducting a comprehensive risk assessment and considering just-in-time access provision.
-
🧿 Privacy: The FTC has barred General Motors from selling the location data of millions of drivers without their consent. The FTC’s order bans GM from sharing consumers’ geolocation and driver behaviour data for five years. The UK government has u-turned on its proposed requirement for digital ID to be part of all right-to-work checks.
-
📜 Policy & Regulation: Germany and Israel have signed a new security cooperation agreement, establishing joint AI and innovation centres, with Germany admitting it has a “strong interest” in how Israel has built its ‘cyber dome’ to detect and respond to cyber attacks. The European Union’s Cybersecurity Act proposes phasing out of “high risk” Chinese-made equipment (think Huawei, ZTE, etc) from specific critical infrastructure networks, such as telcos, solar, and security scanners. This move is an evolution of similar bans by the US and UK. However, telcos continue to warn over costs and the lack of alternatives — 90% of solar panels installed in the EU are manufactured in China — present practical hurdles.
-
👮 Law Enforcement: Ukrainian and German authorities have scooped up two suspected members of the Black Basta ransomware group and placed the alleged ringleader of the group on Interpol’s most wanted list. Microsoft and international law enforcement have seized RedVDS’ infrastructure, used to conduct fraud.
-
💰 Investments, mergers and acquisitions: CrowdStrike is acquiring Seraphic Security for $420 million, a browser security platform that adds telemetry, DLP, AI, and other protections.
-
🗞️ Industry news: Wikipedia has signed a deal with major AI firms for high-speed ‘Enterprise’ access to the online encyclopaedia’s data.
And finally
- A bug in a security update for Microsoft Windows is preventing some devices from shutting down, per El Reg, questioning has Copilot become sentient?