Robin’s Newsletter #404

15 March 2026. Volume 9, Issue 11
Iran-linked group retaliatory cyberattack against US med-tech co, Stryker. Malciious code hiding in the whitespace. Google completes Wiz acquisition.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 15th March 2026

  • Iran-linked group attacks US medical-tech firm in retaliatory cyberattack
  • McKinsey’s AI compromised in under two hours
  • 150 malicious packages with ‘invisible code’ uploaded to GitHub
  • A look inside a Cambodian scam centre
  • Google completes its acquisition of Wiz

Interesting stats

800 million accounts suspended by Twitter/X over 12 months in a fight against “massive” scale manipulation campaigns, according to the company, which has  300 million monthly active users.

Cloud initial access vectors, H2 2025: 44.5% software exploits,  27.2% weak/absent credentials,  21.0% misconfiguration, according to Google’s Cloud Threat Horizons Report (PDF)

H2 2025 Distribution of Initial Access Vectors Exploited in Google Cloud (source: Google)

Sticking with Google… $17.1 million bug bounty payments made in 2025, for  747 vulnerability reports, according to Mountain View.

Five things

  1. Escalation: An Iran-linked group called ‘Handala Hack Team’ has claimed responsibility for a cyberattack against US medical device manufacturer Stryker. A message on Twitter/X, claiming to be from Handala, says that the attack was retaliation for US strikes against Minab school, amongst other ‘cyber assaults’ against Iran. In an SEC filing, Stryker says it is unsure of its recovery timeline and does not know whether the incident will have a material impact on its business. The filing says the incident was not ransomware or malware, suggesting the disruption was likely caused by gaining access to and abusing the company’s Microsoft Intune device management system. Various threat intel firms say there is an overlap between Handala and APT34, Iran’s Islamic Revolutionary Guard Corps (IRGC).  

  2. Cyber security firm CodeWall says that it compromised McKinsey’s in-house artificial intelligence chatbot, Lilli, and gained access to the filenames of sensitive information and other messages. McKinsey “fixed the issue within hours,” though, interestingly, CodeWall’s discovery also took only hours and was suggested by their AI red teaming tool itself. The content of files themselves was separate, but the identities and messages of McKinsey’s 40,000 staff and a bunch of other AI agents were accessible, including details of mergers and acquisitions and sensitive strategies, as well as — perhaps most importantly — the system prompts and guardrails that steer its behaviour and output. I’ve seen lots of discussion about the integrity of models and training data, but the far easier way may be to alter the system prompts to achieve an end goal. After all, these configuration messages are typically not displayed to users. If you’re building AI products, would you detect such changes?

  3. Over 150 packages have been uploaded to GitHub in March that use ‘invisible characters’ to hide malicious code in editors and from security tools. Threat actors are using Public Use Areas, Unicode characters intended for emojis, symbols, and so on, to appear as whitespace. This is sneaky, though, assume security tools (and IDEs) will focus on detecting and displaying these characters in some way. Certainly, on the tooling side, there is a commercial incentive to do so.

  4. Fake meeting rooms and other props litter the inside of the abandoned scam centre in Cambodia. The Guardian have been doing a great job of covering these scam centres, their scale, and the human cost. It’s a glimpse into the inner workings of organised crime, with each room seating around 30 people, and foam-lined boxes help cut out background noise. Investment fraud, romance scams, and more schemes cost individuals billions in losses every year, with some estimates putting it at around 50% of Cambodia’s formal GDP.

  5. Google has completed its acquisition of Wiz for $32 billion. The deal is the largest acquisition of a venture-backed startup, ever. Here’s an interesting interview with Shardul Shah, a partner at shareholder Index Ventures, and board director at Wiz, who says Wiz made an attractive target because of its prominence at the “centre of thee tailwinds: AI, cloud, and security spend.”

In brief

And finally

  • A Swiss e-voting pilot failed to count 2,048 ballots after three USB keys used to decrypt the results failed to work. The votes made up less than 4% of the ballots cast, and would not have changed any results, the incident has delayed the confirmation of the results, suspended the pilot programme, and the public prosecutor’s office has started criminal proceedings over the violation of voters’ rights.
Robin
  Iran Artifical Intelligence (AI) Public Use Areas Scam centre Cambodia Cloud Misinformation Bug Bounty