Robin’s Newsletter #400

15 February 2026. Volume 9, Issue 7
China, the future of Microsoft, the latest Coupang fallout, and more!
Join hundreds of subscribers who get this first, every Sunday. Subscribe

Wow, 400 weeks on the trot. Thanks for subscribing! Thanks for the suggestions about how to mark the occasion — including “take a week off”: fat chance 😉

This week

Need to Know, 15th February 2026

  • China’s “real-world” testing of capabilities against Taiwan
  • Ivanti zero-days exploited across Europe
  • Microsoft leadership changes signal shifting security priorities?
  • Coupang fallout and row between investors and South Korean government
  • Google says AI used by nation states in most stages of attack cycle

Interesting stats

750 ransomware incidents occurring in the IT sector in 2025, up from  300 attacks in 2024, according to the IT-ISAC, indicating a “strategic pivot” by cybercriminals.

83% drop in Telnet traffic, a few days before a critical vulnerability was disclosed in January, suggesting that telcos may have been tipped off, and did the world a solid.

Five things

  1. China: A senior adviser to Taiwan’s National Security Council told the Munich Cyber Security Conference that they believe China is conducting “real-world testing to paralyse infrastructure” and that a secret training platform called “Expedition Cloud” replicates real power, transporting, and communications networks. I wouldn’t say that this is particularly surprising in and of itself — and I’m sure Western agencies are conducting similar simulations and developing comparable capabilities — but China is doing so on an absolutely enormous scale. Twice recently, China has also mobilised thousands of fishing vessels to form a blockade hundreds of miles long in the East China Sea. Most recently, on 11th January, the vessels stayed in place for around 30 hours. This is physical, not cyber, though the intent may partly be to overwhelm radar, targeting, and tracking systems of military equipment: drowning them in noise. Also this week, Singapore’s government said Chinese-linked group compromised Singtel, StarHub, M1, and Simba Telecom in attacks reminiscent of the Salt Typhoon campaign against US telcos.

  2. Ivanti is at the centre of breaches in organisations across Europe as attackers exploit critical vulnerabilities in its Endpoint Manager Mobile product. The zero-day issues — CVE-2026-1281 and CVE-2026-1340 (both 9.8/10) — were patched at the end of January (advisory). Shadowserver scans estimate over 80 compromised instances, with the Dutch data protection regulator, and Council for the Judiciary, both confirming incidents, as well as the European Commission. GreyNoise reckons that 83% of all exploitation attempts originate from a single IP address at a so-called ‘bulletproof hosting’ provider.

  3. Microsoft CEO Satya Nadella recently announced changes to security leadership at the Redmond-headquartered company. This has big implications for its Secure Future Initiative. Microsoft EVP of Security, Charlie Bell, is to take on an ‘individual contributor engineer’ role, and has been replaced by Hayete Gallot. As Tom Uren notes for Seriously Risky Business, the announcement focuses a lot on Gallot’s go-to-market experience in building brands and selling security products, rather than building secure ones. With the Cyber Security Review Board (CSRB) disbanded, do Redmond execs feel the pressure is off? Given how much of the world runs on Microsoft products, the answer matters a great deal.

  4. Coupang: South Korea says that the massive data breach at Coupang was a ‘management problem’ rather than ‘advanced attack’. Officials say the failures resulted in 33.7 million people’s personal data being exposed. Korea’s Personal Information Protection Commission (PIPC) says current penalties are capped at 3% of revenue ($800 million), and some lawmakers have proposed legislation to raise them retroactively to up to 10%. While Coupang is oft-cited as ‘South Korean Amazon’, the company is actually US-headquartered. That’s leading to some friction in US-Korean relations, and some investors are raising claims that South Korean authorities acted unfairly following the incident, claiming just 3,000 accounts were actually affected.

  5. AI attacks: Google says they have found evidence that state-sponsored actors are increasingly using artificial intelligence. These threat actors are using it at most stages of the attack lifecycle, though “nobody’s got everything completely worked out,” thankfully. China, North Korea, and Iran groups are all singled out for using Gemini to conduct reconnaissance and code malware functions. It all sounds like execs at intelligence agencies have had a McKinsey briefing telling them to adopt AI and told workers to ‘make it so’. There are clear efficiency gains to be made by using AI in software development and in researching and conducting outbound sales activities, so seeing these activities crop up in a parallel, malicious context feels more like natural evolution than revolution. 

In brief

And finally

Cartoon command hijacking example (source: Burbano et al)

  • CHAI (Command Hijacking against embodied AI): An interesting paper (PDF) here essentially looking at prompt injection (or ‘command hijacking’) against robotic systems — think driverless vehicles, drones, and so on — concluding that the researchers can “craft universal signs that flip high-level decisions in three representative agents: drone emergency landing, Driv-eLM driving, and CloudTrack tracking, with success rates up to 93%…”
Robin
  China Taiwan Ivanti Microsoft Microsoft Secure Futures Initiative Coupang Investor Secure Boot Consent Prompts Digital Sovereignty