Robin’s Newsletter #408

12 April 2026. Volume 9, Issue 15
Mythos madness. Russian DNS hijacking. US warns energy, water, of Iranian threat actors.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 12th April 2026

  • Mythos madness: resources to find vulnerabilities outweighs fixes 25:1
  • Russian DNS hijacking campaign disrupted
  • US energy, utilities warned over Iran OT campaign

Interesting stats

$20.877 billion in total losses in 2025, from  1,008,587 complaints, averaging  $20,699 each, a  26% increase over 2024’s numbers, according to the FBI’s Internet Crime Report 2025 (PDF). The most impactful five categories of loss are: $8.7B Investment scams,  $3.1B Business Email Compromise,  $2.1B Tech/Customer support,  $1.3B Personal Data Breach, and  $0.9B Confidence/Romance scams. 

Five Three things

  1. Mythos Madness: Anthropic released a preview of its new Claude Mythos frontier model this week. Twelve partners will get access in what’s being called Project Glasswing (which has its own dark mode website). Anthropic says this is necessary because of the new model’s power, which it wants to put towards “defensive security work” after discovering “thousands” of zero-day vulnerabilities in recent weeks, including in “every major operating system and web browser”. What’s interesting here is its ability to chain together research techniques to identify vulnerabilities and then develop and test exploits. The partner orgs, including Apple, Microsoft, and Google, will have access to run Mythos as part of their own security programmes. The news sent cyber stocks tumbling, as traders worried about AI disruption to the sector. Ironically, CrowdStrike’s stock was down 4% on Friday, despite its involvement in Glasswing. While it does feel like we’re at, or approaching, an inflection point, a bunch of this is ‘having infinite interns’ to do massively parallel work. While it’s interesting that Claude Mythos found a 27-year-old vulnerability in OpenBSD, Anthropic apparently spent a lot to find it. Some researchers in groups I’m part of are talking about reproducing the findings in existing models, leading some to call the ’not releasing’ of the model a marketing stunt (see also: The Exploit below). Moreover, if someone had dropped a similar level of resources on security testing at any point since 1999, they’d likely have come up with stuff. Finding vulnerabilities in open source projects that are notoriously under-resourced isn’t going to be hard: the commercial incentives aren’t there. And so while Anthropic are committing $100 million in usage credits to find vulnerabilities, the $4 million to open source teams to fix them seems well out of whack. It’s only great to find the stuff if we can also fix it. After the hype and bow wave of vulnerabilities, I hope we can land in a place where software is materially more secure than it is today — fixing at source — and organisations won’t need to divert so many resources to urgent system patching.

Refusal to launch (source: The Exploit)

  1. Russia-linked threat actors have been compromising routers manufactured by TP-Link and MikroTik according to national cyber agencies. Activity was first observed in May 2025 and escalated after NCSC released a warning in August. The group, APT28 (aka Fancy Bear), which is “almost certainly” the Russian General Staff Main Intelligence Directorate (GRU), used its unauthorised access to change the router’s configuration and to carry out DNS hijacking attacks against users connected to these devices. The changes redirect victims to fraudulent login pages to steal credentials for email and other IT accounts, and can also reveal useful intelligence about frequently visited sites and services. Microsoft says that it has identified 200 organisations and 5,000 individuals that may have been swept up in the campaign. In the US, the FBI obtained a warrant to disrupt the compromise and harden affected routers under the codename Operation Masquerade (DNSMasq is a popular Linux DNS server, and the name may be a nod to this). NCSC’s advisory has details of the targeted models and other TTPs.

  2. Iran is targeting energy and wastewater facilities in the United States, according to six federal agencies in an advisory published this week. The warning from the likes of the FBI, CISA and NSA said that the campaign was focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, with a view to disrupt operational technology processes and cause financial loss. The techniques don’t seem particularly sophisticated: the threat actors are using Rockwell Automation’s Studio 5000 Logix Designer to connect to Internet-exposed PLCs, such as CompactLogix and Micro850 series devices, and alter their project files to manipulate what data is displayed. That’s echoed with the #1 step to prevent attacks: disconnect the PLC from the public-facing internet. Overall, this is expected behaviour for two countries ‘at war’ with each other, and while Iran may struggle to project military force to US shores, cyberspace is more easily traversed.

In brief

And finally

  • Requiring remote interviewees to say “Kim Jong Un is a fat ugly pig” seems to be a pretty effective way to weed out North Korean IT workers. It won’t work forever, but it’s interesting to see a presumed example of one such imposter trying to gain fraudulent employment and access to the company. 
Robin
  Anthropic Claude North Korea Artificial Intelligence (AI) Russia Iran Operational Technology (OT) Programmable Logic Controllers (PLC) Water Energy DNS Hijacking Vulnerability Disclosure