This week

- Iran-linked group attacks US medical-tech firm in retaliatory cyberattack
- McKinsey’s AI compromised in under two hours
- 150 malicious packages with ‘invisible code’ uploaded to GitHub
- A look inside a Cambodian scam centre
- Google completes its acquisition of Wiz
Interesting stats
800 million accounts suspended by Twitter/X over 12 months in a fight against “massive” scale manipulation campaigns, according to the company, which has 300 million monthly active users.
Cloud initial access vectors, H2 2025: 44.5% software exploits, 27.2% weak/absent credentials, 21.0% misconfiguration, according to Google’s Cloud Threat Horizons Report (PDF)

Sticking with Google… $17.1 million bug bounty payments made in 2025, for 747 vulnerability reports, according to Mountain View.
Five things
-
Escalation: An Iran-linked group called ‘Handala Hack Team’ has claimed responsibility for a cyberattack against US medical device manufacturer Stryker. A message on Twitter/X, claiming to be from Handala, says that the attack was retaliation for US strikes against Minab school, amongst other ‘cyber assaults’ against Iran. In an SEC filing, Stryker says it is unsure of its recovery timeline and does not know whether the incident will have a material impact on its business. The filing says the incident was not ransomware or malware, suggesting the disruption was likely caused by gaining access to and abusing the company’s Microsoft Intune device management system. Various threat intel firms say there is an overlap between Handala and APT34, Iran’s Islamic Revolutionary Guard Corps (IRGC).
-
Cyber security firm CodeWall says that it compromised McKinsey’s in-house artificial intelligence chatbot, Lilli, and gained access to the filenames of sensitive information and other messages. McKinsey “fixed the issue within hours,” though, interestingly, CodeWall’s discovery also took only hours and was suggested by their AI red teaming tool itself. The content of files themselves was separate, but the identities and messages of McKinsey’s 40,000 staff and a bunch of other AI agents were accessible, including details of mergers and acquisitions and sensitive strategies, as well as — perhaps most importantly — the system prompts and guardrails that steer its behaviour and output. I’ve seen lots of discussion about the integrity of models and training data, but the far easier way may be to alter the system prompts to achieve an end goal. After all, these configuration messages are typically not displayed to users. If you’re building AI products, would you detect such changes?
-
Over 150 packages have been uploaded to GitHub in March that use ‘invisible characters’ to hide malicious code in editors and from security tools. Threat actors are using Public Use Areas, Unicode characters intended for emojis, symbols, and so on, to appear as whitespace. This is sneaky, though, assume security tools (and IDEs) will focus on detecting and displaying these characters in some way. Certainly, on the tooling side, there is a commercial incentive to do so.
-
Fake meeting rooms and other props litter the inside of the abandoned scam centre in Cambodia. The Guardian have been doing a great job of covering these scam centres, their scale, and the human cost. It’s a glimpse into the inner workings of organised crime, with each room seating around 30 people, and foam-lined boxes help cut out background noise. Investment fraud, romance scams, and more schemes cost individuals billions in losses every year, with some estimates putting it at around 50% of Cambodia’s formal GDP.
-
Google has completed its acquisition of Wiz for $32 billion. The deal is the largest acquisition of a venture-backed startup, ever. Here’s an interesting interview with Shardul Shah, a partner at shareholder Index Ventures, and board director at Wiz, who says Wiz made an attractive target because of its prominence at the “centre of thee tailwinds: AI, cloud, and security spend.”
In brief
-
⚠️ Incidents: A whistleblower says that a former Department of Government Efficiency, DOGE employee stole databases from work at Social Security Administration and planned to use the “two tightly restricted databases” at his new employer. Canadian retailer Loblaw says that attackers compromised part of its IT network and accessed some basic customer information, including names, phone numbers and email addresses. Coffee giant Starbucks has disclosed an employee data breach affecting 889 ‘Partner Central’ accounts from 19 January to 11 February 2026 (Starbucks calls employees partners). The incident was discovered on 6 February, and it’s unclear why it took an additional five days to remove the attackers. A flaw in Companies House (the UK’s company registry) web filing system allowed any other user to view and modify sensitive information, including directors’ personal details, and even file tax information (h/t Matt).
-
🏴☠️ Ransomware: Chinese EV charger manufacturer ELECQ says that customer data may have been stolen in a ransomware attack affecting its cloud systems.
-
🕵️ Threat Intel: Salesforce says a “known threat actor group” is scanning for misconfigured Salesforce Experience Cloud setups via the
/s/sfsites/auraAPI endpoint (advisory); ShinyHunters says they are the group and have “stolen data from almost 400 websites,” before listing known compromises at Snowflake and Okta. Zombie ZIP is the name being given to an EDR and AV bypass technique where the file headers of a payload are altered so the scanner things they are uncompressed and fails to identify suspicious signatures. Technical write-up on Coruna, the nation-state MacOS and iOS exploit kit revealed by Google earlier this month. IBM says that it has seen ‘unsophisticated’ Slopoly malware used as part of a ransomware attack, which they conclude is likely written by generative AI. -
🪲 Vulnerabilities: Veeam has patched four critical remote code execution vulnerabilities in its Backup & Replication product (CVE-2026-21666, 21667, 21669, and 21708; all 9.9/10; advisory).
-
🧑💻 End user and consumer: WhatsApp has introduced ‘parent-managed’ accounts for children, and features restrictions on various platform features.
-
🧰 Guidance and tools:
-
🛠️ Security engineering: Amazon is requiring senior engineers to sign off “Gen-AI assisted changes” after identifying “novel GenAI usage for which best practices and safeguards are not yet fully established” as a contributing factor to a spate of recent outages and downtime incidents.
-
👮 Law Enforcement: US authorities have charged a third incident responder for their role in an insider scheme. Angelo Martino, formerly of DigitalMint, shared information with the BlackCat (ALPHV) ransomware gang while working as a ransomware negotiator. Accomplices Kevin Tyler Martin (also of DigitalMint) and Ryan Goldberg (formerly of Sygnia) have already pleaded guilty.
-
💰 Investments, mergers and acquisitions: OpenAI has acquired AI security startup Promptfoo to bring automated red-teaming and security evaluations to its agentic workflows.
-
🗞️ Industry news: Former Mimecast COO Ed Jennings has been appointed Darktrace CEO, their third in 18 months, amidst a US growth push. General Joshua Rudd has been confirmed as head of US Cyber Command and the National Security Agency.
And finally
- A Swiss e-voting pilot failed to count 2,048 ballots after three USB keys used to decrypt the results failed to work. The votes made up less than 4% of the ballots cast, and would not have changed any results, the incident has delayed the confirmation of the results, suspended the pilot programme, and the public prosecutor’s office has started criminal proceedings over the violation of voters’ rights.