Tim and I posted a 5 minute video round-up of RSAC 2026, covering our thoughts on the cyber security market and insights from the expo hall, which you may find interesting.
This week

- LiteLLM compromised via TeamPCP/Trivy supply chain attack
- TeamPCP goes to war with Iran
- Iran-linked Handala nabs FBI director Kash Patel’s personal emails
- US FCC bans ‘foreign-made’ wi-fi routers
- Anthropic is holding back its latest model over cyber exploit concerns
Interesting stats
1.5x faster patch time for Macs than Windows devices, and 8.1x faster for iOS over Android, according to Omnissa.
Zero people using Lockdown Mode have been compromised with mercenary spyware, since the feature was introduced four years ago, according to Apple.
Five things
-
TeamPCP/Trivy/LiteLLM: It’s got worse for users of Aqua Security’s Trivy vulnerability scanner, as the security firm acknowledged the TeamPCP attackers had regained access in an updated blog post. The malicious software steals credentials and authentication tokens and injects itself into other software packages. It’s unclear what the group’s ultimate aim is, beyond harvesting as many credentials as possible. Ultimately, the supply-chain attack managed to compromise LiteLLM, a popular Python package used to communicate with AI services, which could affect thousands of companies. While LiteLLM dealt with the issue in just over two hours, daily downloads are around 3 million. The self-propagating nature of TeamPCP’s malware is not dissimilar to the Shai-Hulud worm seen in the second half of 2025. Targeting continuous integration/deployment (CI/CD) pipelines is a way to rapidly scale their infection, especially since many developers pull the latest version of a given package each time.
-
TeamPCP’s Wiper: Not content with software supply chain compromises, TeamPCP also fancies inserting itself into the US/Israel—Iran war. If their most recent malware detects that the timezone or locale on a victim’s machine is set to Iran, it will act as a crude wiper. Matching Iran and finding Kubernetes, then the script tries to wipe every node in the cluster; if no Kubernetes is found, it runs a good ol’ fashioned
rm -rfto delete the hard drive’s contents. It’s not sophisticated stuff. -
Kash Patel: Handala, and Iran-linked threat group, compromised the personal gmail account of FBI director Kash Patel. Confirming the breach, an FBI spokesperson was quick to point out that this was Patel’s personal email, and that the agency had “taken all necessary steps to mitigate potential risks associated with this activity”. The photographs and email released by the group date up to 2019, and it’s unclear if that’s when they lost access or if they are keeping more recent information for themselves at present. Presumably, the intent is to embarrass the US government and show that they are not out of reach. The FBI is offering up to $10 million in rewards for information relating to Handala, who has also been linked to the breach of US medical device manufacturer Stryker.
-
Router Ban: The US Federal Communications Commission has moved to ban all routers “produced in a foreign country” over security fears. The Departments of Defense and Homeland Security are able to grant exceptions. It’s a step up from previous bans, such as Huawei from telco networks, or concerns over Chinese ownership of consumer brands like TP-Link. The new rules will require manufacturers to register with the FCC and manufacture their products in America. Netgear, a US-headquartered firm that manufactures overseas, for example, will have to apply for approval. If you have a foreign-manufactured device, it’s fine, no need to throw it away. The concern here is that there are millions of these devices — essentially in every home — that foreign powers may use in attacks against the US: Chinese firms are obliged to report vulnerabilities to the Chinese state before wider disclosure. Changing that balance won’t happen overnight and will, ultimately, result in higher prices for US consumers.
-
Mythos: Anthropic accidentally leaked the name and some capabilities of its newest artificial intelligence model after human error resulted in draft website content being accessible to the internet. The post describes Mythos (or Capybara) as “by far the most powerful AI model we’ve ever developed.” No surprise there: newer, better models are being released all the time. What’s raising eyebrows are paragraphs where Anthropic worries about the cyber security implications, because Mythos is “currently far ahead of any other AI model in cyber capabilities,” and “it presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders.” Cyber stocks dropped following the news, with Tenable faring worse, dropping 9%.
In brief
-
⚠️ Incidents: The Dutch Ministry of Finance has confirmed an incident of unauthorised access to its systems on 19th March; a spokesperson said that “Services to citizens and businesses provided by the Tax and Customs Administration, Customs, and Benefits have not been affected.” Puerto Rico’s Department of Transportation cancelled all drivers licence appointments due to a cyber attack. The European Commission says a “cyber-attack” affected “part of our cloud infrastructure,” as attackers claim to have stolen data, seemingly from the Commission’s web platform. A hacktivist group calling itself APT Iran claims to have stolen 375 terabytes of data from defence giant Lockheed Martin.
-
🏴☠️ Ransomware: Spain’s Port of Vigo has disconnected parts of its network and is managing operations manually due to a ransomware attack. Co-Op CEO Shirine Khoury-Haq will step down following reports of a toxic workplace culture and a rise in estimated costs from its 2025 cyberattack, reducing profits by £107 million (up from £80 million in September) and an additional £21 million in non-recurring costs.
-
🕵️ Threat Intel: A service called WebinarTV is scraping Zoom meeting links and storing recordings of meetings and generating AI summaries without meeting organiser’s knowledge. Threat actors are posting fake Visual Studio Code (VS Code) security alerts to GitHub Discussions in attempts to trick developers into downloading malicious packages.
-
🪲 Vulnerabilities: TP-Link is warning customers to upgrade their Archer NX routers due to a missing authentication check that allows attackers to upload new firmware onto the affected devices (CVE-2025-15517; 8.6/10; advisory). Citrix is warning about two vulnerabilities in its NetScaler ADC and NetScaler Gateway products; insufficient input validation, and a race condition leading to session confusion (CVE-2026-3055 & CVE-2026-4368 respectively; 9.3/10 & 7.7/10; advisory).
-
🛠️ Security engineering: Google has released a public preview of a dark web intelligence service using its Gemini AI agents to distil “eight to 10 million events a day” with 98% accuracy. Sticking with Mountain View, cryptographers are warning that “2029” will be ‘Q Day’ when quantum computers can break existing algorithms like RSA and elliptic curve. No reason was provided for why Google brought forward the date.
-
🏭 Operational technology: An unspecified incident at Intoxalock, an alcohol breathalyser company, suffered an outage, leaving some drivers unable to start their vehicles (the devices are mandatory in some US states where convicted of a DUI offence).
-
🧿 Privacy: Hong Kong authorities can now demand suspects provide phone passcodes and computer passwords if they are suspected of breaching the national security law. Six Democrats are petitioning Director of Intelligence Tulsi Gabbard to confirm if US intelligence agencies consider VPN users as foreigners. Such a designation could strip US citizens of constitutional rights that protect them from warrantless government surveillance.
-
📜 Policy & Regulation: The US Treasury is running a consultation on a potential cyber insurance backstop (notice (PDF) akin to the terrorism risk insurance program (TRIP) introduced in the wake of the 9/11 terror attacks.
-
👮 Law Enforcement: A federal court in Indiana sentenced Aleksei Volkov, 26, of St. Petersburg, Russia, to 81 months in prison for charges relating to his work as an initial access broker for the Yanluowang cybercrime group. Volkov was arrested in Rome and extradited to the US. Volkov must also pay $91 million in restitution to the victim companies. Russian authorities have detained a suspected administrator of LeakBase, a cybercrime forum, following a Western law enforcement operation targeting the platform. Hambardzum Minasyan, an Armenian national, appeared in an Austin federal court this week, charged with developing the RedLine infostealer malware.
-
💰 Investments, mergers and acquisitions: Airbus is to acquire Ultra Cyber from defence group Cobham for an undisclosed sum; Ultra, formerly part of Ultra Electronics, was snapped up by PE-backed Cobham for £2.6 billion in 2021.
And finally
- Congrats to UK startup Geordie AI for winning the RSAC 2026 Innovation Sandbox competition 👏