This week

- Italy repels Winter Olympics DDoS attacks
- US senator questions telco response to Salt Typhoon
- ‘Vast’ Asian cyber-espionage campaign unearthed
- Russian group jumped on Office vuln in <48 hours
- UK investigating five breaches of cyber sanctions
Interesting stats
£7,500 (~$10,200) payout will be made to all Police Service of Northern Ireland (PSNI) employees affected by the organisation’s 2023 data breach.
£260 million ($354M) total cost from Jaguar Land Rover’s 2025 cyber incident, up from £196 million last quarter, according to company statements. The carmaker has not touched the £1.5 billion government-backed loan.
Five things
-
Winter Olympics: Italian authorities say they have repelled a series of “Russian origin” cyberattacks against, including diplomatic missions, hotels and facilities connected with the games. France 24 cites around 120 targets of DDoS attacks, claimed by the pro-Russian NoName057(16) group as “punishment” for Italy’s support of Ukraine. The IOC banned Russia from participating in the games. The Olympics are high-profile, high-stakes events for the host nation, and extensive planning, preparation, and monitoring will be in place to ensure the event proceeds without major incidents. Physical sabotage against railway targets seems to have been more effective.
-
Salt Typhoon: US Senator Maria Cantwell is calling for the CEOs of AT&T and Verizon to appear before Congress and answer questions about their firms’ response to the China-linked Salt Typhoon group’s compromise of their telecommunications networks. Cantwell says both firms have “chosen not to cooperate” with requests for documentation to back up claims that their networks are now secure. An independent review conducted by the Cyber Safety Review Board was left unfinished when the Trump administration disbanded the board, and, latterly, FCC chair Brendan Carr rescinded regulations that enforced controls such as multi-factor authentication. Also this week, the Norwegian Police Security Service said that Salt Typhoon had compromised devices in Norwegian organisations as part of its National Threat Assessment (PDF)
-
Diaoyu: Palo Alto Networks has uncovered a ‘vast’ cyber espionage campaign based in Asia. Security researchers say the operation breached the systems at 70 institutions across 37 countries, and conducted reconnaissance in 155 countries. This level of activity is what you would expect of a national-scale intelligence agency. While Palo also says the scale is “alarming”, what I think is remarkable here is that it’s been detected and tied together. While careful not be drawn on specific attribution, one of the puzzle pieces is metadata on a file named “diaoyu”, the Chinese word for phishing, oh, and one large Asian power is also not the target of reconnaissance. I’ll let you join the dots:

-
Microsoft Office: Security researchers are warning that it took Russian-linked threat groups less than 48 hours to start exploiting a vulnerability in Microsoft Office after an unscheduled update was released last month. This is a tight time window for organisations to react. However, it’s unclear whether the urgent nature of the update drew attention and prompted a rapid response from attackers, or was deployed urgently because Microsoft got wind of a potential forthcoming campaign. The APT28/Fancy Bear group used CVE-2026-21509 (7.8/10; advisory) to bypass local security features as part of a spear-phishing campaign targeting nine Eastern European countries.
-
Cyber sanctions: The UK is investigating five potential breaches of sanctions applied to foreign cyber actors. All five investigations involve financial services firms, according to a freedom of information request filed by Recorded Future News to HM Treasury’s Office of Financial Sanctions Implementation (OFSI). Investigations shouldn’t be unexpected — the sanctions were introduced to deter payments to hostile and criminal groups — and so may typically be encountered if or when considering making ransom payments. Regulators face limited resources and have had their hands busy with those applied to Russia following the invasion of Ukraine, but this is a sign that cyber-related sanctions have not been forgotten. Civil penalties for FS firms that breach sanctions can be £1 million or 50% of the value of the breach, whichever is higher. At the same time, criminal cases have no such cap, and senior managers and directors can face up to seven years in prison. Food for thought for any board unlucky enough to find itself on the unfortunate end of an extortion attempt.
In brief
-
⚠️ Incidents: Chinese state-sponsored actors gained control of the software update mechanism of Notepad++, allowing them to redirect the update traffic of targeted users, between June and December 2025. This is a pretty sophisticated attack with specific targets in mind. Italian university La Sapienza says it’s suffering disruption following a cyberattack. Over 110,000 students are enrolled, making La Sapienza Europe’s largest university by student population. Flickr is notifying users of a potential data breach at a third-party email service provider, which may include names, email addresses, and account activity, including IP addresses. Newsletter platform Substack is warning of a data breach affecting email addresses, phone numbers, and ‘other metadata’, following claims from an attacker to have stolen 700,000 users’ data.
-
🏴☠️ Ransomware: Iron Mountain is confirming a breach by the Everest group, but says that most of the alleged 1.4TB of data stolen by the crooks is marketing materials. Whilst that’s not a small amount of data, it is small in the context of their role as a data backup company, though even a small percentage of that which isn’t marketing materials could be quite sensitive. Romania’s national oil pipeline business Conpet has reported a cyberattack disrupting its corporate IT; operational technology was unaffected, and the Qilin ransomware gang has claimed responsibility.
-
🕵️ Threat Intel: Interesting writeup on self-replicating prompts, and questions raised by the rise of Moltbook. Conceptually simple: AI agents follow instructions; hooking them all up allows them to read others’ instructions and repeat them, just like a software worm. Krebs has a write-up and analysis of some of the Scattered Lapsus Shiny Hunters tactics and why paying them may be a bad idea. Coveware says that paying the Nitrogen ransomware group is pointless because their malware encrypts data with the wrong key, making decryption impossible.
-
🪲 Vulnerabilities: Vulnerabilities in SolarWinds Help Desk and Ivanti’s Endpoint Manager Mobile, covered last week, are now being actively exploited.
-
🧰 Guidance and tools: A new open source tool to block homoglyph attacks on the command line. This is a solved problem in browsers — where lookalike characters from, e.g., the Cyrillic alphabet are used in place of Latin ones; visually indistinguishable to humans, but very different to computes — but developers and admins may copy/paste commands from the web while installing software of diagnosing and fixing problems.
-
🛠️ Security engineering: OpenAI has launched a ‘trusted access for cyber’ programme allowing verified users access for “potentially high-risk” cyber security work.
-
🏭 Operational technology: US critical infrastructure operators can expect an update in ‘weeks’ on CIRCIA incident reporting rules.
-
🧿 Privacy: The FBI has been unable to unlock a Washington Post journalist’s iPhone with Apple’s Lockdown Mode enabled. The setting, available on Mac, iPhone and iPad, is “designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats.”
-
📜 Policy & Regulation: CISA has told US federal agencies they have one year to replace end-of-life hardware and software devices. US Senator Ron Wyden, has called out “deep concerns” with CIA activities in a two-line letter to the intelligence agency’s chief. Wyden, a member of the Senate Intelligence Committee, receives classified information about intelligence methods, and signalled a ‘gap’ in interpretations of the Patriot Act two years before Edward Snowden brought NSA mass surveillance to sharp focus.
-
🗞️ Industry news: Infosec Europe has launched a Cyber Startup Programme in conjunction with UK Cyber Flywheel, including a Cyber Startup Award where founders can pitch for support. Searchlight Cyber has appointed Michael Gianarakis as CEO, from his previous position as Chief Product Officer.
And finally
- Hat tip to McDonald’s Netherlands for reminding people over ‘change your password day’ that ‘bigmac’ is not a good enough password for your McDonald’s account. According to Have I Been Pwned, references to the popular burger appear almost 111,000 times in their database. Happy Meal and McNuggets also make appearances.