Robin’s Newsletter #403

8 March 2026. Volume 9, Issue 10
Iran war: cyber's role in blackouts, broadcasts, and CCTV. Plus LLMs make identifying pseudonymous profiles trivial.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 8th March 2026

  • Internet blackouts in Iran
  • NCSC warns of potential retaliatory hacktivist activity
  • Data centres, CCTV are super important
  • LLMs make it trivial to unmask pseudonymous profiles
  • Cybercriminals get hands on potential NSA exploit framework

Interesting stats

Of 418 public law enforcement actions better 2021 and mid2025: 37% were aged 35-44,  30% were 25-34,  21% 18-24, and  <5% were under 18. … Unsure if that just means middle-aged folks are more likely to get caught 🤔

90 zero-day exploits used in 2025, up from  78 in 2024, according to Google, who say  18 were definitely or likely used by commercial spyware vendors, and  15 likely used by state-sponsored actors.

Five things

  1. Iran war: ‘Cyber’ has played a part in US and Israeli strikes against Iran that led to the death of the Supreme Leader, Ayatollah Ali Khamenei. I’ve held off a week writing about this because there is a lot that is (still) unknown. US Cyber Command says it was among “first movers” and disrupted communications and sensors. I suspect this is likely targeted at specific government and military networks, similarly to the recent capture of the Venezuelan president by US forces. There’s a playbook. Some reports suggest that the Internet blackout was the result of cyber-attacks — citing connectivity at ~1% of typical levels — however it’s worth noting that Iran has used blackouts in this way during previous crises, as noted by CNBC. TV broadcasts, and a popular prayer app, were hijacked to urge Iranian’s to fight against the regime.

  2. Iran response: NCSC and other government cyber agencies are warning organisations to review their cyber posture ahead of potential Iranian retaliatory action in cyberspace. NCSC says most organisations in the UK need not worry (though it urges them to keep an eye on the rapidly evolving situation), however, specific mention is made for those with Middle Eastern supply chains and those previously targeted by Iran-linked hacktivists in DDoS attacks and industrial control systems in energy and utilities sectors.

  3. Iran learnings: Two things that the Iran war brings into focus: firstly, data centres, recently named critical infrastructure under, for example, NIS regulations, are targets. Amazon says that three of its AWS data centres in the UAE and Bahrain were hit by Iranian drone strikes this week. Your organisation’s threat model and exposure to this type of risk may vary, but the controls to manage this high-impact, low-probability risk are fundamentally different to other ‘supply chain disruption’ risks. Contractual SLAs aren’t going to help, and there may be sovereignty or regulatory considerations that make rebuilding in a different AWS region impractical. Secondly, CCTV systems are critical to strikes like this, providing an intelligence goldmine without exposing human assets in the field. One camera, the FT reports, proved especially helpful in establishing the ‘pattern of life’ for the protection officers assigned to protect Iran’s supreme leader. It also casts new light on the rationale behind Western diktats to remove Chinese-manufactured CCTV cameras from military bases: every accusation is an admission.

  4. Pseudonyms and privacy: A new paper (PDF) suggests that the advent of large language models has made it trivial to correlate pseudonymous social media users with their real identities. De-anonymisation results were as high as 68%, and up to 90% accurate. Previously, analysing writing styles at scale was deemed to be sufficient protection for ‘burner’ accounts. This research challenges that assumption and was conducted across Hacker News and LinkedIn profiles, and, secondly, amongst Reddit profiles. The ability to do this at scale (and implicitly at low cost) is the interesting thing here, and potentially of concern to people who may have deliberately segregated their lives: you’d be lucky to remove that content. It’s not unlike cybercriminals’ early use of blockchain, ostensibly because it’s ‘private’ (from banks) but then realising that every transaction is on a public ledger.

“The average online user has long operated under an implicit threat model where they have assumed pseudonymity provides adequate protection because targeted deanonymization would require extensive effort. LLMs invalidate this assumption.”

  1. Coruna: A possible US exploit framework may have leaked, been used by a Russian espionage group, and is now in the hands of Chinese cybercriminals. The kit traces its roots back to ‘Operation Triangulation’, which Kaspersky reported as targeting themselves and Russian government officials in 2023. Apple has since patched the vulnerabilities. Whereas kinetic weapons are ‘use once’, using a cyber weapon or a zero-day exploit against a sophisticated adversary can give them everything they need to reproduce it and use it for their own means.

In brief

And finally

Robin
  Iran Artifical Intelligence (AI) CCTV Data centres Pseudonymisation Deanonymisation Coruna Exploits Eternal Blue Meta Salt Typhoon