Wow, 400 weeks on the trot. Thanks for subscribing! Thanks for the suggestions about how to mark the occasion — including “take a week off”: fat chance 😉
This week

- China’s “real-world” testing of capabilities against Taiwan
- Ivanti zero-days exploited across Europe
- Microsoft leadership changes signal shifting security priorities?
- Coupang fallout and row between investors and South Korean government
- Google says AI used by nation states in most stages of attack cycle
Interesting stats
750 ransomware incidents occurring in the IT sector in 2025, up from 300 attacks in 2024, according to the IT-ISAC, indicating a “strategic pivot” by cybercriminals.
83% drop in Telnet traffic, a few days before a critical vulnerability was disclosed in January, suggesting that telcos may have been tipped off, and did the world a solid.
Five things
-
China: A senior adviser to Taiwan’s National Security Council told the Munich Cyber Security Conference that they believe China is conducting “real-world testing to paralyse infrastructure” and that a secret training platform called “Expedition Cloud” replicates real power, transporting, and communications networks. I wouldn’t say that this is particularly surprising in and of itself — and I’m sure Western agencies are conducting similar simulations and developing comparable capabilities — but China is doing so on an absolutely enormous scale. Twice recently, China has also mobilised thousands of fishing vessels to form a blockade hundreds of miles long in the East China Sea. Most recently, on 11th January, the vessels stayed in place for around 30 hours. This is physical, not cyber, though the intent may partly be to overwhelm radar, targeting, and tracking systems of military equipment: drowning them in noise. Also this week, Singapore’s government said Chinese-linked group compromised Singtel, StarHub, M1, and Simba Telecom in attacks reminiscent of the Salt Typhoon campaign against US telcos.
-
Ivanti is at the centre of breaches in organisations across Europe as attackers exploit critical vulnerabilities in its Endpoint Manager Mobile product. The zero-day issues — CVE-2026-1281 and CVE-2026-1340 (both 9.8/10) — were patched at the end of January (advisory). Shadowserver scans estimate over 80 compromised instances, with the Dutch data protection regulator, and Council for the Judiciary, both confirming incidents, as well as the European Commission. GreyNoise reckons that 83% of all exploitation attempts originate from a single IP address at a so-called ‘bulletproof hosting’ provider.
-
Microsoft CEO Satya Nadella recently announced changes to security leadership at the Redmond-headquartered company. This has big implications for its Secure Future Initiative. Microsoft EVP of Security, Charlie Bell, is to take on an ‘individual contributor engineer’ role, and has been replaced by Hayete Gallot. As Tom Uren notes for Seriously Risky Business, the announcement focuses a lot on Gallot’s go-to-market experience in building brands and selling security products, rather than building secure ones. With the Cyber Security Review Board (CSRB) disbanded, do Redmond execs feel the pressure is off? Given how much of the world runs on Microsoft products, the answer matters a great deal.
-
Coupang: South Korea says that the massive data breach at Coupang was a ‘management problem’ rather than ‘advanced attack’. Officials say the failures resulted in 33.7 million people’s personal data being exposed. Korea’s Personal Information Protection Commission (PIPC) says current penalties are capped at 3% of revenue ($800 million), and some lawmakers have proposed legislation to raise them retroactively to up to 10%. While Coupang is oft-cited as ‘South Korean Amazon’, the company is actually US-headquartered. That’s leading to some friction in US-Korean relations, and some investors are raising claims that South Korean authorities acted unfairly following the incident, claiming just 3,000 accounts were actually affected.
-
AI attacks: Google says they have found evidence that state-sponsored actors are increasingly using artificial intelligence. These threat actors are using it at most stages of the attack lifecycle, though “nobody’s got everything completely worked out,” thankfully. China, North Korea, and Iran groups are all singled out for using Gemini to conduct reconnaissance and code malware functions. It all sounds like execs at intelligence agencies have had a McKinsey briefing telling them to adopt AI and told workers to ‘make it so’. There are clear efficiency gains to be made by using AI in software development and in researching and conducting outbound sales activities, so seeing these activities crop up in a parallel, malicious context feels more like natural evolution than revolution.
In brief
-
⚠️ Incidents: Netherlands telco Odido has suffered a data breach, with cybercriminals gaining access to its customer contact system and exposing the personal data of some of its 6.2 million customers. Sex toy company Tenga says an unauthorised party gained access to an employee’s email account and “order details and customer service inquiries” may have been compromised.
-
🏴☠️ Ransomware: A group called Green Blood Group says it has stolen 139GB of data from the government of Senegal. The data allegedly includes citizen database records, including biometric data, as well as immigration documents. The Directorate of File Automation (DAF) has warned Senegal’s 19.5 million residents that it has had to suspend operations and that the “integrity” of data “remains intact.” Conpet, Romania’s oil pipeline operator, says that Qilin cybercriminals stole company data in last week’s incident.
-
🕵️ Threat Intel: Attackers exploiting vulnerabilities in SolarWinds Web Help Desk are using legit tools, like ZoHo remote assistance and incident response tool Velociraptor for command and control. Link previews in messaging apps like WhatsApp, Slack, and Teams, can leak information from AI chats, in a zero-click manner, allowing exfiltration without any user interaction. Claude LLM artefacts are being abused to deliver malicious commands in a ClickFix campaign that installs infostealer malware and which are promoted in web search results. Threat actors targeting users of Trezor and Ledger cryptocurrency wallets are sending out physical letters with QR codes as lures. Google says that Defence sector employees are the focus of state-linked actors in “direct to individual” campaigns that target their personal devices and accounts, rather than corporate networks.
-
🪲 Vulnerabilities: BeyondTrust has patched a critical pre-authentication remote code execution vulnerability (CVE-2026-1731; 9.9/10; advisory) that is being actively exploited in the wild. Microsoft’s February 2026 Patch Tuesday (advisory) includes fixes to 58 vulnerabilities, including six already being exploited as we note in this Cydea risk advisory, and an Outlook issue that can be triggered from the preview pane with no user interaction.
-
🧑💻 End user and consumer: Russia’s communications regulator has “slowed down” Telegram access, as Putin’s regime pushes citizens to move to a state-backed app called Max. Posting AI-generated caricatures of yourself to social media, while fun, can also — rather obviously, I’d think — expose useful information about you that could be used to socially engineer you or, worse, tailor cold sales emails ;-)
-
🛠️ Security engineering: Microsoft is warning that Secure Boot certificates expire in June and October 2026, and that devices that don’t update will enter a “degraded security state”. Most PCs will have automatically received new certificates, and Microsoft has been working with OEMs and manufacturers to roll out new certs for some time. Discord’s age verification check can be bypassed using a web-based tool that renders a 3D model; there’s also been a lot of pushback from users amid the global rollout of age checks and the company’s ability to protect the information it collects.
-
🧿 Privacy: Microsoft Windows is to get user consent prompts for things like file system access, cameras and microphones, and other permissions. There’s been backlash against Amazon’s Ring doorbell company and the curtailment of a partnership with Flock since a Super Bowl ad, ostensibly about using the network of cameras to find lost pets, backfired. People realised that the same tech can be used as a surveillance dragnet. OpenAI researcher Zoë Hitzig has resigned and penned a NY Times essay saying that, with the introduction of targeted ads, the company has “stopped asking the questions I’d joined to help answer”, and is “building an economic engine that creates strong incentives to override its own rules.”
-
📜 Policy & Regulation: ‘Cyber defence runs through Silicon Valley’ was the message for attendees at the Munich Cyber Security Conference. While governments and political blocs strive for digital sovereignty, never before has less of the technology they rely on been under their control, and, presently, like it or not, it’s mostly in the hands of US tech companies. CISA will shutter some of its programmes to “focus on its priorities,” according to anonymous staffers speaking about a recent agency town hall led by executive assistant director Nick Andersen. CISA has faced layoffs and workforce reductions since the Trump administration took office.
-
💰 Investments, mergers and acquisitions: Israeli startup Vega has closed a $120 million Series B funding round for its ‘security analytics mesh’ that aims to centralise detections, not data. Proofpoint has acquired AI security startup Acuvity for an undisclosed sum to bolster AI monitoring in web browsers, MCP servers, and locally installed tools.
And finally

- CHAI (Command Hijacking against embodied AI): An interesting paper (PDF) here essentially looking at prompt injection (or ‘command hijacking’) against robotic systems — think driverless vehicles, drones, and so on — concluding that the researchers can “craft universal signs that flip high-level decisions in three representative agents: drone emergency landing, Driv-eLM driving, and CloudTrack tracking, with success rates up to 93%…”