This week

- Internet blackouts in Iran
- NCSC warns of potential retaliatory hacktivist activity
- Data centres, CCTV are super important
- LLMs make it trivial to unmask pseudonymous profiles
- Cybercriminals get hands on potential NSA exploit framework
Interesting stats
Of 418 public law enforcement actions better 2021 and mid2025: 37% were aged 35-44, 30% were 25-34, 21% 18-24, and <5% were under 18. … Unsure if that just means middle-aged folks are more likely to get caught 🤔
90 zero-day exploits used in 2025, up from 78 in 2024, according to Google, who say 18 were definitely or likely used by commercial spyware vendors, and 15 likely used by state-sponsored actors.
Five things
-
Iran war: ‘Cyber’ has played a part in US and Israeli strikes against Iran that led to the death of the Supreme Leader, Ayatollah Ali Khamenei. I’ve held off a week writing about this because there is a lot that is (still) unknown. US Cyber Command says it was among “first movers” and disrupted communications and sensors. I suspect this is likely targeted at specific government and military networks, similarly to the recent capture of the Venezuelan president by US forces. There’s a playbook. Some reports suggest that the Internet blackout was the result of cyber-attacks — citing connectivity at ~1% of typical levels — however it’s worth noting that Iran has used blackouts in this way during previous crises, as noted by CNBC. TV broadcasts, and a popular prayer app, were hijacked to urge Iranian’s to fight against the regime.
-
Iran response: NCSC and other government cyber agencies are warning organisations to review their cyber posture ahead of potential Iranian retaliatory action in cyberspace. NCSC says most organisations in the UK need not worry (though it urges them to keep an eye on the rapidly evolving situation), however, specific mention is made for those with Middle Eastern supply chains and those previously targeted by Iran-linked hacktivists in DDoS attacks and industrial control systems in energy and utilities sectors.
-
Iran learnings: Two things that the Iran war brings into focus: firstly, data centres, recently named critical infrastructure under, for example, NIS regulations, are targets. Amazon says that three of its AWS data centres in the UAE and Bahrain were hit by Iranian drone strikes this week. Your organisation’s threat model and exposure to this type of risk may vary, but the controls to manage this high-impact, low-probability risk are fundamentally different to other ‘supply chain disruption’ risks. Contractual SLAs aren’t going to help, and there may be sovereignty or regulatory considerations that make rebuilding in a different AWS region impractical. Secondly, CCTV systems are critical to strikes like this, providing an intelligence goldmine without exposing human assets in the field. One camera, the FT reports, proved especially helpful in establishing the ‘pattern of life’ for the protection officers assigned to protect Iran’s supreme leader. It also casts new light on the rationale behind Western diktats to remove Chinese-manufactured CCTV cameras from military bases: every accusation is an admission.
-
Pseudonyms and privacy: A new paper (PDF) suggests that the advent of large language models has made it trivial to correlate pseudonymous social media users with their real identities. De-anonymisation results were as high as 68%, and up to 90% accurate. Previously, analysing writing styles at scale was deemed to be sufficient protection for ‘burner’ accounts. This research challenges that assumption and was conducted across Hacker News and LinkedIn profiles, and, secondly, amongst Reddit profiles. The ability to do this at scale (and implicitly at low cost) is the interesting thing here, and potentially of concern to people who may have deliberately segregated their lives: you’d be lucky to remove that content. It’s not unlike cybercriminals’ early use of blockchain, ostensibly because it’s ‘private’ (from banks) but then realising that every transaction is on a public ledger.
“The average online user has long operated under an implicit threat model where they have assumed pseudonymity provides adequate protection because targeted deanonymization would require extensive effort. LLMs invalidate this assumption.”
- Coruna: A possible US exploit framework may have leaked, been used by a Russian espionage group, and is now in the hands of Chinese cybercriminals. The kit traces its roots back to ‘Operation Triangulation’, which Kaspersky reported as targeting themselves and Russian government officials in 2023. Apple has since patched the vulnerabilities. Whereas kinetic weapons are ‘use once’, using a cyber weapon or a zero-day exploit against a sophisticated adversary can give them everything they need to reproduce it and use it for their own means.
In brief
-
⚠️ Incidents: The FBI is “identified and addressed” suspicious activities detected on its network which, according to CNN, was a compromise of a system used to manage wiretapping and surveillance warrants. The incident is reminiscent of the Salt Typhoon incident involving similar data held by US telcos. Who is getting counter-intelligence heat is useful for foreign intelligence agencies. Attackers gained access to 15.8 million administrative files](https://www.theregister.com/2026/03/03/french_medical_leak/) being processed by Cegedim Santé on behalf of France’s health ministry; around 165,000 contained free-text notes written by doctors, which in “very limited cases” contain sensitive medical history. Cognizant firm TriZetto, an American healthcare provider, has disclosed a breach affecting 3.4 million people; the attackers had access for a year before it was detected. Transport for London says that its 2024 breach affected over 7 million people, not the 5,000 that it originally suggested.
-
🕵️ Threat Intel: Scammers are targeting customers of popular email platforms, with a lure saying they will be adding a ‘support ICE’ button to their emails.
-
🪲 Vulnerabilities: Cisco’s cough Secure Firewall Management Center (FMC) has two ‘perfect 10’ vulns, respectively authentication bypass (CVE-2026-20079; 10/10; advisory) and remote code execution (CVE-2026-20131; 10/10; advisory) bugs that an unauthenticated actor can exploit.
-
🧑💻 End user and consumer: Later this year, in September, Google Chrome will move to a fortnightly release cycle. LastPass is warning users of a phishing campaign targeting their vault passwords, that spoofs an email chain with their support team.
-
🧿 Privacy: The ICO is asking questions of Meta after reports that their smart glasses are sending sensitive and intimate footage to outsourced workers charged with reviewing the scenes. While Meta’s privacy policy says this may happen to improve the service, a typical user isn’t expecting their trip to the toilet to be sent to a human for review. If you pay for ProtonMail with a credit card, that information can end up in the hands of the FBI.
-
📜 Policy & Regulation: The Trump administration has released a cyber strategy (PDF) promising to protect CNI, ‘shape adversary behaviour’, and build talent and capacity, amongst six pillars. At just seven pages long, Eric Geller notes for Cybersecurity Dive that it “offers no details” on implementation, and that it provides little detail in general.
-
👮 Law Enforcement: The FBI has seized the LeakBase cybercrime forum, in conjunction with Europol and other partners, and its database of 142,000 users will be used for “evidentiary purposes”.
-
💰 Investments, mergers and acquisitions: A bit random, but Accenture has acquired Speedtest.net and DownDetector owner Ookla for $1.2 billion.
-
🗞️ Industry news: Amidst market panic stemming from Claude Code Security, which sent security stocks South, CrowdStrike just posted a record quarter, with 23% year-on-year revenue growth, and a 24% increase in ARR.
And finally
- Easy come, easy crypto: South Korean police seized, and then lost, $5 million cryptocurrency after posting a photo showing the wallet, and a recovery phrase, giving everything needed to move the funds elsewhere.