Robin’s Newsletter #405

22 March 2026. Volume 9, Issue 12
Delve compliance reports called into question. US evaluators lacked confidence in Microsoft cloud. Feds seize Iran-linked domains in Stryker attack.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 22nd March 2026

  • DeepDelve shines light on misaligned compliance platform incentives
  • FedRAMP evaluator thought Microsoft government cloud “a pile of shit”
  • $858 million Amazon GDPR fine overturned
  • Feds seize Iran-linked domains behind Stryker cyberattack
  • Sophisticated iOS exploits end up in the hands of cybercriminals

Interesting stats

77% of 2025 ransomware intrusions include data theft to increase leverage, up from  57% in 2024, and data-only extortion incidents are increasing in frequency too:  15% of 2025 incidents, up from  2% in 2020, according to data from Google/Mandiant.

Since the start of the Iran war, Akamai has observed a  65% increase in automated reconnaissance traffic,  45% increase in credential harvesting attempts,  52% increase in infrastructure scanning,  70% increase in botnet-driven discovery traffic, and  38% increase in reconnaissance against potential DDoS targets.

$500 million per year in revenue generated by North Korea’s  100,000 strong fake IT worker ‘army’ spread across 40 countries, estimated by IBM.

Five things

  1. Misaligned incentives? Delve, a startup that promises “compliance in days, security that lasts”, is facing questions over its practices and relationships with their-party audit firms. In a lengthy anonymous post, ‘DeepDelver’ alleges that the firm generates reports for auditors to rubber-stamp, that ‘integrations’ are mostly forms requiring the user to upload evidence manually, and that reports are heavily templatised and feature the same descriptions, tests, and audit conclusions — in one case 99.8% of reports feature the same sentence. Delve’s rebuke is similarly anonymous, despite its promise of transparency. Last year, Delve announced a $32 million Series A round at a $300 million valuation, as interest in compliance automation platforms has soared. Regardless of the truth of the allegations, the incentives in compliance ecosystems like ‘SOC 2’ don’t promote strong security. Rather, these platforms are often a ‘startup tax’ for companies wanting to sell to enterprise buyers. Users click next through screens, hook up a few integrations, generate a pretty bland report, and the receiving enterprise buyer checks a box to say they’ve seen a thing. I think (and indeed — full disclosure — my bet with Cydea’s platform) is that we need to move to a clearer understanding and articulation of risk, rather than compliance.

  2. Zero Trust: Internal documents from the Federal Risk and Authorization Management Program dating from 2024 suggest that US government workers thought Microsoft’s “lack of proper detailed security documentation” left them with a “lack of confidence in assessing the system’s overall security posture”. One evaluator said, “The package is a pile of shit.” Despite the concerns, Redmond still received a seal of approval for their Government Community Cloud High cloud-based services. The damning writeup from ProPublica casts doubts on the security of Microsoft’s federal services — or their ability to communicate them sufficiently — and draws attention to the conflicts of interest in the FedRAMP programme, where assessors may be hired and paid for by the applying firm. (A common theme, with compliance platforms, above!) Given that GCC High is intended to store and process the US’s most sensitive data, it’s sure to raise more than a few eyebrows. Similarly, in 2024, the Cyber Safety Review Board issued a similarly damning report (PDF) into security practices at Microsoft. But with such market dominance, where else can government-scale customers go?

  3. Amazon Advertising: A Luxembourg court has overturned a $858 million GDPR fine against Amazon. Referring the case back to the regulator (National Commission for Data Protection (CNPD)), the court did not find that the GDPR breaches were illegitimate; rather, CNPD failed to determine whether these failings were intentional or whether other measures could have been taken. CNPD didn’t rule out issuing a smaller penalty, but noted that this “action has led to Amazon’s practices being brought into full compliance”. 

  4. Stryker: The FBI has seized two websites linked to Handala, the pro-Iranian threat actor that claimed responsibility for a cyber-attack on US medical tech supplier Stryker last week. The destructive attack, which abused the company’s legitimate device management tools from Microsoft, was apparently in retaliation for US strikes on Iran. CISA has urged organisations to harden device administration: use least privilege for roles and don’t use admin accounts for day-to-day operations; enforce phishing-resistant MFA; and configure ‘multi-admin approval’ for Microsoft InTune. The advice mirrors Microsoft’s guidance issued following the attack. Malicious reconnaissance and activity have spiked following US/Israeli-Iranian hostilities (see Interesting Stats, above).

  5. DarkSword & Coruna: More details are emerging of two iOS exploit kits. DarkSword could silently compromise older devices running Apple’s mobile operating system by having a victim simply visit a malicious website; no interaction required. Coruna, a more feature-rich exploit framework, was originally been developed by L3Harris/Trenchant for a Five Eyes customers, with former exec Peter Williams being sentenced to 87 months prison-time for selling exploits to a Russian broker. As well as Russian ties, Coruna also appears to have been used by Chinese groups, potentially with ambitions of running a more financially motivated side-hustle, with functionality to steal cryptocurrency added at some point. Apple has released emergency patches to fix the vulnerabilities and protect users, including special updates for devices that can’t run Cupertino’s latest software. That someone used these kits with apparent disregard for detection suggests that the threat actors aren’t too concerned about them being burned and fixed. It’s a departure from more considered, targeted intelligence-agency origins. Worryingly, that cavalier attitude suggests there may be plenty more available to buy on the dark market.

In brief

And finally

Looping around the Med (source: Le Monde)

Robin
  Delve Compliance Microsoft FedRAMP Iran iOS Dark Sword Coruna Exploit North Korea Strava