Robin’s Newsletter #402

1 March 2026. Volume 9, Issue 9
7,000 strong robo vacuum drone army. AI distillation attacks, copyright claims, and issues abound. Perfect 10 Cisco SD-WAN vuln.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

If you’re heading to RSA Conference 2026, then drop me a message — it’d be great to meet up — and I’m organising something for the Sunday before if you’re in town early.

I’ll also be headlining the European Cyber Resilience Summit at County Hall in London this coming Tuesday.

This week

Need to Know, 1st March 2026

  • Guy wanted to control his robo vacuum; got an army of 7,000
  • Anthropic complains about distillation attacks, copyright, while researchers reproduce ‘near verbatim’ texts
  • Critical Cisco SD-WAN vulnerability needs patching right now
  • SonicWall sued over compromised cloud backups
  • Interesting technique paving the way for post-quantum HTTPS

Interesting stats

29 minutes (-65%) the average time for financially-motivated threat actors to breakout from initial access to other systems, with  82% (up from 51% in 2020) of detections being ‘malware-free’, according to CrowdStrike’s Global Threat Report 2026 (PDF

1% (442) of 40,000 vulnerabilities published in 2025 were exploited, according to VulnCheck

$820 million extorted by ransomware gangs in 2025, an  8% drop from 2024, as just  28% of victims choose to pay (an all-time low), but  $59,556 median payment more than quadrupled (2024: $12,738), according to Chainalysis

Five things

  1. Evil Robo Maid: Tech tinkerer Sammy Azdoufal was trying to control his robot vacuum cleaner with his PS5 controller when he found he had access to around 7,000 of them around the globe. It seems the security behind DJI’s Romo may have been… extremely lacking. Azdoufal had been building an app to control his own Romo and had extracted the device’s private token used to communicate with DJI. But when he used that token, DJI’s API could return data for all of their devices. That included approximate location, video and microphone feeds, battery levels, and other status information for any of the company’s robot vacuum customers. He could access live video feeds and plot out the interior plans of customers’ homes. Zero authentication. Zero segregation. This thing must have gone through no security testing at all. While that all suggests a largely ineffective security programme and disregard for user privacy, DJI engineers did fix the issue within 48 hours. Very odd. (H/T Russel).

  2. AI, Distillation attacks, and copyright: New research shows that large language models can replicate copies of novels from their training data. That undermines claims made by Google (and other labs) that “there is no copy of the training data—whether text, images, or other formats—present in the model itself.” Prompting modes from OpenAI, Google, Anthropic, and xAI with text from novels like Game of Thrones and Harry Potter resulted in “near-verbatim” text replication. This is an important consideration as AI crawlers go around hoovering up lots of content, or learning from users’ requests. If you knew part of a document, uploaded to a model, or in training data, can you prompt an LLM to reproduce it? Relatedly, this week, Anthropic accused Chinese AI firms of distillation attacks on its foundational model. DeepSeek, Moonshot and MiniMax apparently ran “industrial-scale campaigns” to extract key information that underpins Claude. OpenAI has also accused DeepSeek of similar behaviour. Anthropic’s suggestions for detecting and preventing distillation attacks are a bit lacklustre, though perhaps there is proprietary juicy stuff they aren’t sharing. For its part, Chinese prosecutors are facing a growing number of domestic IP theft cases.

  3. Cisco SD-WAN vulnerability: Five Eyes cyber agencies are warning of an ‘advanced’ threat actor exploiting Cisco Catalyst SD-WAN systems, which warranted emergency action: by publication time, federal agencies should have patched all their affected devices. Cisco says activity relating to the ‘perfect 10’ vulnerability (CVE-2026-20127; 10/10; advisory) has been traced back to 2023. The issue in the networking giant’s SD-WAN Controller could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. Patching is the only option; there are no workarounds.

  4. SonicWall sued: Marquis Software Solutions is suing SonicWall for gross negligence and misrepresentation. Marquis suffered a ransomware attack that impacted operations at 74 of the company’s banking customers. Incident responders traced the method of entry to credentials stolen from a compromised SonicWall cloud backup. Marquis claims their devices were fully patched and required MFA, and that SonicWall has been cagey about how attackers bypassed the second factor. It’ll be interesting to see where the courts decide liability lies in this case.

  5. Merkel Trees: An interesting read here about how Google and Cloudflare are planning to secure post-quantum HTTPS connections, without a significant slowdown in performance. Quantum-resistant certificates are about 40 times larger than the majority of certificates used today, which would introduce significant overhead on every web request. TL;DR: enter Merkel Trees, a technique that uses hashes and other clever maths to verify with only a fraction of the total information. More on Merkel Trees here.

In brief

  • ⚠️ Incidents: Optimizely suffered a voice phishing incident that allowed attackers access to its systems and to steal “basic business contain information.” The ad-tech firm seems to have a reasonable system configuration, with a spokesperson telling Bleeping Computer that “the threat actor… was unable to escalate privileges, install software, or create any backdoors”. French online DIY business ManoMano has suffered a data breach at a third-party provider resulting in 38 million individuals being affected. The company, which also operated in Belgium, Spain, Italy, Germany, and the UK, says full names, emails, phone numbers, and customer service communications have been accessed, but that no credentials were compromised, or modifications made to its systems. Sounds like a customer service provider got popped.

  • 🏴‍☠️ Ransomware: Air Côte d’Ivoire has confirmed a ransomware attack from 8th February; INC ransomware claims to have stolen 208GB of data from the West African airline.

  • 🕵️ Threat Intel: Low-skilled attackers are using gen AI to run campaigns that compromise devices, according to AWS, which says they have seen cybercrims pop over 600 FortiGate firewalls in a little over a month. In this specific campaign, once the attackers gained access, using some pretty rough-and-ready scripts, they set out to dump Active Directory creds. The really interesting thing here is the scale that they achieved. Google says it caught Chinese group using Google Sheets as command and control mechanism in a campaign targeting telcos and government agencies. Scattered Lapsus$ Hunters are auditioning women in the hopes that female voices may boost the success of their social engineering attacks, with “success and hit rate” leading to payments between $500-$1,000. Diesel Vortex is the name being given to a group targeting American and European logistics companies that managed to phish more than 1,600 credentials over five months. The logins to freight and fuel card systems allowed the attackers to potentially divert shipments and commit fraud.

  • 🪲 Vulnerabilities: SolarWinds has patched four critical vulnerabilities in its Serv-U FTP software: broken access control, type confusion, and insecure direct object reference issues all lead to remote code execution as root (CVE-2025-40538/40540/40539/40541; all 9.1/10; advisory). ZyXel is warning of a command injection vulnerability income of its routers and wifi devices (CVE-2025-13942; 9.8/10; advisory). Trend Micro has fixed two critical RCE vulnerabilities in its Apex One endpoint detection and response agent (CVE-2025-71210/71211; both 9.8/10; advisory). Juniper PTX Series routers also have a vulnerability allowing unauthenticated remote code execution, resulting in an ‘out-of-cycle’ patch (CVE-2026-21902; 9.3/10; advisory).

  • 🛠️ Security engineering: That Google API token you’re using for Google Maps embed on your website may also give access to Gemini’s endpoint, allowing folks to query the AI assistant as if they are you. Google says they’ve worked to fix the issue — stemming from the silent introduction of these permissions — but it’s always good to periodically check what permissions have been scoped! Vinext: vibe-hacking replacements, such as Cloudflare’s Next.js replacement, which it knocked out in one week for <$1,500, may meet functional requirements, but vulnerabilities exist in the ‘negative space’ between requirements—good read here.

  • 👮 Law Enforcement: Former L3 Harris executive Peter Williams has received an 87-month prison sentence for selling zero-day exploits to a Russian broker, and the US has sanctioned the buyer. Williams admitted to two counts of theft of trade secrets from the Trenchant division of L3 Harris, where he worked, with prosecutors saying he engaged in several deals with the Russian broker, Operation Zero, netting himself $1.3 million and causing around $35 million in losses for his company.

  • 🗞️ Industry news: Madhu Gottumukkala is moving to a new role in DHS, with Nick Anderson stepping in to replace Gottumukkala as acting director for CISA. Morale and mission at America’s cyber security agency is at a low point, with lawmakers on either side of the aisle agreeing that it has suffered under the Trump administration. That’s not good for all of us. Senator Ron Wyden blocked Lt. Gen. Joshua Rudd’s appointment to head US Cyber Command and the National Security Agency this week, on the basis that Rudd has no background in either cyber operations or signals intelligence, and for ‘vague’ answers about his understanding of NSA’s legal authorities. The post has lacked a permanent appointment for the last year.

And finally

Robin
  DJI Internet of Things (IOT) Large Language Models (LLMs) Artificial Intelligence (AI) Distillation attacks Copyright Cisco SonicWall Merkel Trees Quantum Cryptography