Robin’s Newsletter #396

18 January 2026. Volume 9, Issue 3
Poland ‘came close’ to grid blackout, Dutch port hacker sentenced, and Signal... but make it AI
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 18th January 2026

  • Poland ‘came close’ to grid blackout
  • Dutch port hacker sentenced
  • ‘Cobalt Strike’ for cloud Linux identified
  • AWS CodeBreach: ^anchor your regex$
  • Signal, but make it AI

Interesting stats

A few interested tidbits amongst a WEF’s length Global Cybersecurity Outlook 2026 (PDF) report:

Perception of changing cyber risk over the past year: 87% believe AI vulnerabilities have increased,  77% believe cyber-enabled fraud and phishing have increased, 65% believe supply chain disruption has increased,  58% believe exploitation of software vulnerabilities has increased, 54% believe ransomware attacks have increased.

Perception of increase or decreer in cyber risk over the past year (source: WEF)

CEO and CISO concerns differ (CEO / CISO):

  1. Cyber-enabled fraud and phishing / Ransomware attack
  2. AI vulnerabilities / Supply chain disruption
  3. Exploitation of software vulnerabilities / (same)

Ranking of CEOs’ and CISOs’ cyber risk concerns for their organisations (source: WEF)

Five things

  1. Poland says it came “very close to a blackout” in the final days of 2025, as defenders repelled a cyberattack against solar farms and wind turbines. Polish officials pointed the finger at Russian sabotage and the novel tactic of targeting multiple smaller generation installations rather than a single large facility. Rapidly connecting or disconnecting generation capacity or demand can destabilise a power grid, triggering safeguards or requiring operators to disconnect some parts to protect others. Operator and maintainer (O&M) contractors are often responsible for a large number of renewable generation sites. These are easier targets than, say, international energy companies, as O&M providers may be much smaller outfits and lack dedicated security personnel. The EU’s NIS2 and the UK’s cyber security and resilience bill are part of the answer here, bringing these smaller organisations in scope of regulation and requiring a consistent level of security.

  2. Rotterdam port hack: The Amsterdam Court of Appeal ruled a 44-year-old Dutch national was responsible for compromising the IT systems of a major port in 2020 and 2021, and has handed him a seven-year prison sentence. The attacker convinced a port worker to run malware from a USB key, creating a backdoor into the systems of a container terminal in Antwerp, and allowing him to manage containers, gate, and personnel access. The unauthorised access was used to facilitate the import of drugs. The Court also found the same man guilty of organising the shipment of 210 kilograms of cocaine.

  3. VoidLink Linux malware: Checkpoint security researchers say they have identified a new strain of Linux malware (report) that is “far more advanced than typical”. It is designed to be ‘cloud-native’, running on popular cloud services (such as AWS, GCP, Azure, and Tencent), and features over 30 modules to tailor its capabilities, including recon, lateral movement, and privilege escalation. Checkpoint believes Chinese-affiliated threat actors are developing the malware, inspired by Cobalt Strike, a similar framework developed ostensibly to test Windows machines but frequently used by attackers. It’s not been seen in active campaigns at this time, though, given its state of development, it’s reasonable to assume a sign of things to come.

  4. AWS CodeBreach: Cloud security outfit Wiz identified a critical misconfiguration in AWS’s CodeBuild service that would have allowed a takeover of Amazon’s GitHub repositories. The researchers speculate that this could have allowed them to inject malicious code into the AWS Console, threatening every AWS account. Fortunately, they reported the issue, which has now been fixed. The regex pattern used to match a maintainer GitHub user ID wasn’t anchored (^ at the start, $ at the end), meaning that, with a lot of jiggery pokery, Wiz was able to register a GitHub user ID that contained an AWS maintainer’s ID as a substring, which would match during the build process. The writeup includes a recommendation for hardening your own build pipelines. Also this week, Amazon made its European Sovereign Cloud generally available, that is “entirely located” within the EU and “independently operated” by EU residents, in a segregated manner to provide assurances that data remains within the bloc.

  5. Signal, but AI: Moxie Marlinspike, the pseudonymous engineer behind messaging app Signal, aims to bring private AI to the masses with his new project Confer. All chats are end-to-end encrypted using Passkeys and built on lessons learned from Signal, making them unreadable by the platform’s operator, law enforcement, or other interested parties. This is some cool engineering and thinking, and the opposite of most AI’s that are pretty hellbent at the moment on collecting as much information as possible and remember ‘your whole life’. In other AI news, this is a really interesting read on the misaligned incentives that promote availability not credibility in AI models, making it easier to sow misinformation and push foreign influence. ‘Trustworthy’ (Western) sources are often news outlets that put their content behind paywalls or are busy litigating against AI companies for scraping their content. Meanwhile, the same commercial strategy doesn’t apply to state propaganda and foreign influence campaigns, which want their content picked up.

In brief

And finally

  • A bug in a security update for Microsoft Windows is preventing some devices from shutting down, per El Reg, questioning has Copilot become sentient?
Robin

  Robin's Newsletter - Volume 9

  Poland Russia Grid Operational technology Electricity Solar Wind Renewable NIS2 Resilience Port Drug trafficking Organised Crime Cloud Linux Cobalt Strike Amazon Web Services (AWS) Regular Expression Signal Artificial Intelligence (AI) Privacy