This week

- DeepDelve shines light on misaligned compliance platform incentives
- FedRAMP evaluator thought Microsoft government cloud “a pile of shit”
- $858 million Amazon GDPR fine overturned
- Feds seize Iran-linked domains behind Stryker cyberattack
- Sophisticated iOS exploits end up in the hands of cybercriminals
Interesting stats
77% of 2025 ransomware intrusions include data theft to increase leverage, up from 57% in 2024, and data-only extortion incidents are increasing in frequency too: 15% of 2025 incidents, up from 2% in 2020, according to data from Google/Mandiant.
Since the start of the Iran war, Akamai has observed a 65% increase in automated reconnaissance traffic, 45% increase in credential harvesting attempts, 52% increase in infrastructure scanning, 70% increase in botnet-driven discovery traffic, and 38% increase in reconnaissance against potential DDoS targets.
$500 million per year in revenue generated by North Korea’s 100,000 strong fake IT worker ‘army’ spread across 40 countries, estimated by IBM.
Five things
-
Misaligned incentives? Delve, a startup that promises “compliance in days, security that lasts”, is facing questions over its practices and relationships with their-party audit firms. In a lengthy anonymous post, ‘DeepDelver’ alleges that the firm generates reports for auditors to rubber-stamp, that ‘integrations’ are mostly forms requiring the user to upload evidence manually, and that reports are heavily templatised and feature the same descriptions, tests, and audit conclusions — in one case 99.8% of reports feature the same sentence. Delve’s rebuke is similarly anonymous, despite its promise of transparency. Last year, Delve announced a $32 million Series A round at a $300 million valuation, as interest in compliance automation platforms has soared. Regardless of the truth of the allegations, the incentives in compliance ecosystems like ‘SOC 2’ don’t promote strong security. Rather, these platforms are often a ‘startup tax’ for companies wanting to sell to enterprise buyers. Users click next through screens, hook up a few integrations, generate a pretty bland report, and the receiving enterprise buyer checks a box to say they’ve seen a thing. I think (and indeed — full disclosure — my bet with Cydea’s platform) is that we need to move to a clearer understanding and articulation of risk, rather than compliance.
-
Zero Trust: Internal documents from the Federal Risk and Authorization Management Program dating from 2024 suggest that US government workers thought Microsoft’s “lack of proper detailed security documentation” left them with a “lack of confidence in assessing the system’s overall security posture”. One evaluator said, “The package is a pile of shit.” Despite the concerns, Redmond still received a seal of approval for their Government Community Cloud High cloud-based services. The damning writeup from ProPublica casts doubts on the security of Microsoft’s federal services — or their ability to communicate them sufficiently — and draws attention to the conflicts of interest in the FedRAMP programme, where assessors may be hired and paid for by the applying firm. (A common theme, with compliance platforms, above!) Given that GCC High is intended to store and process the US’s most sensitive data, it’s sure to raise more than a few eyebrows. Similarly, in 2024, the Cyber Safety Review Board issued a similarly damning report (PDF) into security practices at Microsoft. But with such market dominance, where else can government-scale customers go?
-
Amazon Advertising: A Luxembourg court has overturned a $858 million GDPR fine against Amazon. Referring the case back to the regulator (National Commission for Data Protection (CNPD)), the court did not find that the GDPR breaches were illegitimate; rather, CNPD failed to determine whether these failings were intentional or whether other measures could have been taken. CNPD didn’t rule out issuing a smaller penalty, but noted that this “action has led to Amazon’s practices being brought into full compliance”.
-
Stryker: The FBI has seized two websites linked to Handala, the pro-Iranian threat actor that claimed responsibility for a cyber-attack on US medical tech supplier Stryker last week. The destructive attack, which abused the company’s legitimate device management tools from Microsoft, was apparently in retaliation for US strikes on Iran. CISA has urged organisations to harden device administration: use least privilege for roles and don’t use admin accounts for day-to-day operations; enforce phishing-resistant MFA; and configure ‘multi-admin approval’ for Microsoft InTune. The advice mirrors Microsoft’s guidance issued following the attack. Malicious reconnaissance and activity have spiked following US/Israeli-Iranian hostilities (see Interesting Stats, above).
-
DarkSword & Coruna: More details are emerging of two iOS exploit kits. DarkSword could silently compromise older devices running Apple’s mobile operating system by having a victim simply visit a malicious website; no interaction required. Coruna, a more feature-rich exploit framework, was originally been developed by L3Harris/Trenchant for a Five Eyes customers, with former exec Peter Williams being sentenced to 87 months prison-time for selling exploits to a Russian broker. As well as Russian ties, Coruna also appears to have been used by Chinese groups, potentially with ambitions of running a more financially motivated side-hustle, with functionality to steal cryptocurrency added at some point. Apple has released emergency patches to fix the vulnerabilities and protect users, including special updates for devices that can’t run Cupertino’s latest software. That someone used these kits with apparent disregard for detection suggests that the threat actors aren’t too concerned about them being burned and fixed. It’s a departure from more considered, targeted intelligence-agency origins. Worryingly, that cavalier attitude suggests there may be plenty more available to buy on the dark market.
In brief
-
⚠️ Incidents: Companies House has reported itself to the UK Information Commission and says that issues with its WebFiling platform (which allowed any logged-in user to see data of any other) likely stemmed from an October update. This suggests pretty poor testing on behalf of Companies House, though at least limits the timeframe over which “dates of birth, residential addresses and company email addresses” may have been exposed. Telus Digital, the process outsourcing arm of Canadian Telus Corp., has confirmed an incident claimed by ShinyHunters that may include personal data from at least 24 of Telus’ customers. ShinyHunters themselves claim to have stolen 1 petabyte of information, including call centre recordings. Identity protection company Aura has suffered a voice phishing attack that resulted in the exposure of sensitive data of 20,00 current, and 15,000 former, customers. Threat actors have compromised ‘virtually all versions’ of Aqua Security’s Trivy vulnerability scanner in a software supply-chain attack that will see many users having to rotate any secrets and keys used to conduct authenticated scans. Trivy maintainer Itay Shakury advises that “If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately”.
-
🏴☠️ Ransomware: Medusa ransomware gang has claimed responsibility for an attack on the University of Mississippi Medical Center (UMMC), that saw nine days of disruption to medical procedures and the closure of 35 clinic locations. Per Jonathan Greig at The Record, IMMC is “Mississippi’s only children’s hospital, only Level I trauma center, only Level IV neonatal intensive care unit and the state’s only organ transplant programs.”
-
🕵️ Threat Intel: British officials believe China is exploiting UK freedom of information legislation to build a ‘mosaic’ of data points that could reveal sensitive defence and security information. CISA is warning that a critical vulnerability in Microsoft Sharepoint (CVE-2026-20963), patched in January 2026, is now being actively exploited. Cybercriminals are distributing Android Perseus malware by masquerading as iPTV apps that can play pirate TV and sports content; the malware scans notes saved on the victim’s device for sensitive information like passwords, credentials, cryptocurrency recovery phases, and other financial information.
-
🪲 Vulnerabilities: ConnectWise has patched a critical vulnerability in its ScreenConnect remote administration tool that could otherwise allow unauthorised access and privilege escalation (CVE-2026-3564; 9/0/10; advisory). Oracle’s Identity Manager and Web Services Manager have received out-of-band security updates to fix a critical unauthenticated RCE vulnerability (CVE-2026-21992; 9.8/10; advisory); these sorts of out-band-updates are well-worth paying attention to, and an Oracle spokesperson has decline to comment if the vulnerability has been exploited to compromise customer environments. Ubiquiti has addressed a critical path traversal vulnerability in its UniFi Network Application (CVE-2026-22557; 10/10; advisory).
-
🛠️ Security engineering: The Linux Foundation has announced a programme to help weed out AI slop bug reports from their projects, and big tech firms have committed $12.5 million to get the ball rolling.
-
🧿 Privacy: An interesting read here on why there are no street view images in North Oaks, Minnesota, the ‘unmappable city’. FBI Director Kash Patel says that his agency has started buying Americans’ location information again from data brokers, calling it “valuable intelligence for us.” It’s controversial because the FBI doesn’t need a warrant, but it’s not unconstitutional, as it’s a commercially available product. Essex Police has suspended its use of live facial recognition over concerns about bias. Researchers at Cambridge University found the system was more likely to identify men than women, and significantly more likely to identify Black participants than those from other ethnic groups.
-
📜 Policy & Regulation: Japan has decided that its Self-Defense Force can conduct offensive cyber operations, starting from 1st October.
-
👮 Law Enforcement: Cameron Nicholas Curry, a 27-year-old from North Carolina, has been found guilty of six counts of extortion against his former employer. Curry, aka ‘Loot’, used his insider access to steal sensitive company and employee data and coerce $2.5 million in payments from the victim.
And finally
- Strava SIGINT: Strava, the popular run-tracking app, has left one French navy officer red-faced, after their workout gave away the position of the aircraft carrier Charles de Gaulle. The run shows them running laps of the carrier’s deck, while it sails through the Eastern Mediterranean. (It’s not the first time Strava’s given up military secrets).
