Robin’s Newsletter #397

25 January 2026. Volume 9, Issue 4
VoidLink malware written by AI? Microsoft handed over BitLocker keys to the FBI. A doozey of a Telnet bug.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 25th January 2026

  • Continuing Russia-aligned cyberattacks against NATO
  • VoidLink malware seems to be AI-written
  • UK FS sector needs to sort out the basics
  • New Report Fraud service launched
  • Microsoft handed over BitLocker keys to the FBI

Interesting stats

$30/month for so-called ‘Dark LLMs’ and  $5 for a synthetic identity including AI-generated faces and voices, according to Group-IB LINK

Thanks to Expel for their report in the CISO<>CFO disconnect (PDF). It’s almost a paper on why you should get Cydea in to help measure and communicate your cyber risk. Get in touch to discuss our affordable consulting packages and risk management platform!

What finance leaders most want their security teams to report: 

54% Strategic alignment with enterprise goals 50% Investment efficiency (cost vs. coverage) 46% Potential financial loss avoided 45% Audit readiness 45% Time savings from less manual alert review 44% Maturity vs. industry benchmarks 43% Downtime prevention

Also 

43% say security<>finance collaboration would be improved with better translation of technical risk into financial terms, and  40% say quantified risk reduction would make it easier for finance to justify an increased security budget

You know who to call 😉

€1.2 billion (£1B; $1.4B) approximate fines issued by European supervisory authorities in 2025, with  443 average number of breach notifications per day, a 22% year-on-year increase from 363, according to DLA Piper

Five things

  1. Russia: The UK’s cyber agency has warned that Russian-aligned hacktivist groups continue to target the UK and others with disruptive attacks. The NCSC report called out NoName057(16) (catchy!) as one such group that’s been active since March 2022 and Russia’s invasion of Ukraine. The group primarily operates through Telegram channels and shares DDoS attack tactics with its followers. Last week, Polish officials said they repelled an attack on their electricity grid, attributing the attack to Russia. ESET says they have obtained the malware from the attack, which they’re calling DynoWiper, and said with “medium confidence” that it bears the hallmarks of Sandworm, Russia’s GRU military intelligence agency.

  2. AI malware: New reports from suggest the VoidLink linux implant framework was the work of AI. Check Point’s researchers say they believe the malware was “authored almost entirely by artificial intelligence,” though they noted it was “not a fully AI-orchestrated attack”. A human actor seems to have used AI to generate a Spec Driven Development plan, then used it as a blueprint to code, test, and iterate on development. Core to this assertion is the analysis of development artefacts — obtained due to OpSec failures — such as the development plan that estimated 30 weeks of effort, however, 80,000 lines of code were completed in just six days. It’s worth keeping in mind that this malware hasn’t been seen ‘in the wild’, and so how effective all that AI code is unknown. While it’s a feat of efficiency, it’s not as if China-aligned groups (to which VoidLink is linked) lack the human resources to have achieved this. There is, however, a clear direction of travel, and with AI advances, what’s been created today is as bad as it will ever be.

  3. Now wash your hands: The Bank of England’s annual cyber review for last year says financial services firms need to up their game on basic security controls. Co-authored with the Prudential Regulation Authority and the Financial Conduct Authority, the thematic report draws on the results from CBEST (threat-led penetration tests) reported to the regulators in 2025. Unpatched systems, weak password polices, ineffective monitoring, poor network segregation, and poor culture and training were all called out. On the culture front, weaknesses in Helpdesk protocols, which could be abused as seen in Scattered Spider attacks on Okta and Snowflake, should give cause for concern. Getting the basics right consistently is hard (look at how hard pro athletes train). Large banks have sprawling digital footprints, though they also have the resources to address these issues. The positive is that these issues were found during regulatory testing specifically designed to improve resilience, rather than check boxes, and are being shared for the benefit of all.

  4. Report Fraud, the UK’s new ‘front door’ for citizens and businesses to report cybercrime launched this week. Operated by the City of London Police, Report Fraud is part of a wider change to how fraud and cybercrime are reported and investigated, with new real-time analytics replacing inefficient batch processing. It follows a 2022 review, which found that while these types of economic crime accounted for 40% of reported crime, police spent just 2% on combating them. The service, which replaces Action Fraud, promises to “put victims first,” with those who submit information being contacted and updated when it contributes to an investigation (when doing some heavy lifting there, maybe? Fingers crossed not!). Also this week, Home Secretary Shabana Mahmood announced a new National Police Service (NPS) that will take over responsibility for counter-terror, fraud, and organised crime investigations, and bring together the existing National Crime Agency and Regional Organised Crime Units.

  5. Microsoft handed over BitLocker encryption keys for three devices to the FBI last year; Redmond says it receives around 20 such requests a year. This is a ‘feature’ of cloud services and why digital sovereignty (often) matters. 

In brief

  • ⚠️ Incidents: Sports clothing company Under Armour is investigating a potential data breach that may have affected 72 million people. Have I Been Pwned obtained the dataset and sent out notifications, saying the data appears to include names, email addresses, genders, DOB, and postal or ZIP code. 

  • 🏴‍☠️ Ransomware: Matt Kapko has an interesting article — the thin line between saving a company and funding a crime — looking at the ins and outs of ransomware negotiations.

  • 🪲 Vulnerabilities: Fortinet says a “very similar” issue to a December vulnerability (advisory) is being exploited. See also Telnetbelow.

  • 🧑‍💻 End user and consumer: LastPass is warning users of a phishing campaign asking users to back up their password vaults. Microsoft is gearing up to roll out brand impersonation warnings to Teams calls.

  • 🛠️ Security engineering: Luxembourg’s Computer Incident Response Centre (CIRCL) has launched a decentralised vulnerability numbering system. The Global CVE Allocation System maintains compatibility with the existing US CVE system, administered by MITRE, that came close to running out of funding last year. NIST is reevaluating its role in analysing vulnerabilities and providing the National Vulnerability Database (NVD), which has been struggling to keep pace with the increasing volume of submissions. NIST has cut more than 700 jobs since Trump came to office in 2025. Interesting paper: Private Links, Public Leaks: Consequences of Frictionless User Experience on the Security and Privacy Posture of SMS-Delivered URLs, Danish et al., investigate the implications of frictionless SMS login links (PDF) that service providers offer as a frictionless login experience. TL;DR They found 177 services exposing PII and 125 services with low entropy (essentially guessable or incrementing URLs) that expose a wider user base.

  • 🧿 Privacy: The US Supreme Court is to consider if geofence warrants are constitutional. US courts have been split on the practices, which have been used for years at this point and may constitute unreasonable searches (a violation of 4th Amendment rights), in which police submit a location to tech companies, such as Google, and request data on which users were present at that time and place. 

  • 📜 Policy & Regulation: The European Commission has proposed a new EU cybersecurity package, including revised Cybersecurity Act, that would give the power to conduct bloc-wide risk assessments and block suppliers on national security grounds (think Huawei or ZTE  from 5G networks), simplify product and service certification, and bolster ENISA’s role in responding to incidents. China’s Foreign Ministry spokesperson Guo Jiakun told reporters the plans amounted to “blatant protectionism” and warned Beijing would take “necessary measures” to protect Chinese firms.

  • 💰 Investments, mergers and acquisitions: Claroty has closed a $150 million Series F funding round for its cyber-physical systems protection platform. 

  • 🗞️ Industry news: Former CISA director Jen Easterly has been appointed CEO of RSAC Conference, leading to reports that White House officials were considering cancelling their appearances, and CISA pulling out to “ensure maximum impact and good stewardship of taxpayer dollars”. It’s hard not to see this as politically motivated, though Easterly describes herself as a lifelong independent. Vulnerabilities: The Global CVE Allocation System maintains compatibility with the existing US CVE system, administered by MITRE, that came close to running out of funding last year. NIST is reevaluating its role in analysing vulnerabilities and providing the National Vulnerability Database (NVD), which has been struggling to keep pace with the increasing volume of submissions. NIST has cut more than 700 jobs since Trump came to office in 2025.

And finally

  • Telnet: A trivial-to-exploit vulnerability in the telnet server shipped with popular Linux distributions has been patched. CVE-2026-24061 (9.8/10), a remote-authentication bypass, allows an attacker to sign in to a vulnerable GNU InetUtils telnetd server by setting a USER environment variable to “-f root”. The user environment gets passed as an unsanitised variable when spawning ‘/user/bin/login’. The bug was introduced in March 2015, and while telnet’s encrypted cousin, SSH, is the go-to nowadays, there are still plenty of legacy bits of kit that can’t or don’t support modern crypto algorithms or simply rely on telnet for administration.
Robin

  Robin's Newsletter - Volume 9

  Poland Russia Grid Operational technology Electricity Hacktivist NoName057(16) Malware Artificial Intelligence (AI) CBEST Financial Services Basic hygiene Report Fraud Microsoft Encryption BitLocker Risk Quantification CFO Security Budget Telnet