Robin’s Newsletter #410

26 April 2026. Volume 9, Issue 17
UK Cyber Pledge for Cyber Essentials in supply chains. China 'on equal' footing with US on offensive cyber. Post-quantum crypto in ransomware.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 26th April 2026

  • UK Cyber Pledge brings Cyber Essentials to supply chains
  • Dutch intelligence: China ‘on equal footing’ with US offensive cyber
  • Vercel app hosting customer creds stolen in breach from free AI tool 
  • First ransomware strains seen using post-quantum crypto algorithms
  • UK Biobank data set seen for sale on Chinese e-commerce site

Interesting stats

100 countries have spyware capabilities to break into personal computers and phones, up from 80 in 2023, according to NCSC estimates. 

Five things

  1. Cyber Pledge: NCSC CEO Richard Horne told CYBERUK attendees that criminal threats (like ransomware) remain the most common risk for organisations, but that the most serious come “directly or indirectly” from nation-state actors like China, Iran, and Russia. Horne says NCSC handles around four ‘nationally significant’ cyber incidents every week. Against this backdrop, Security Minister Dan Jarvis announced a £90 million ($122 million) investment over three years to boost national cyber security. Jarvis also called on businesses to sign up to a voluntary Cyber Resilience Pledge. Those who do undertake to: make cyber a board responsibility; sign up to NCSC’s Early Warning Service, and require Cyber Essentials across their supply chains. Supply chains present network effects that could lead to the kind of shift the government are clearly hoping for. Cyber Essentials is designed to prevent common cybercriminal threats and has been shown to drastically reduce cyber insurance claim rates. Dealing with common threats would free the NCSC to focus on the bigger, nationally significant stuff.

  2. China: National cyber agencies release report detailing the shifting tactics, techniques, and procedures (TTPs) used by ‘China-nexus’ threat actors. In particular, the group say that these China-nexus actors are making use of large-scale “covert networks” of compromised devices. These covert networks provide a low-cost means of denying their activities. The report goes on to say that some of. These networks are created and maintained by commercial companies in China, which seek to compromise thousands of small office/home office (SOHO) routers. Also this week, Dutch military intelligence said that it believes “China now probably stands on an equal footing with the United States in the area of offensive cyber capabilities”.

  3. Vercel: The company behind Next.js, and which also hosts web applications, says that customer credentials were stolen during a recent incident. The “limited subset” of customers has been notified and told to rotate their credentials. This incident stands out because of the root cause: a Vercel employee using the free plan of Context.ai’s automation platform granted full OAuth permissions to their Vercel Google Workspace account. Context.ai suffered a breach in March, and attackers used these OAuth tokens to gain access to Vercel’s environment. Such broad permissions should be avoided where possible (adopt least privilege needed to get the job done!). And it’s also why having the ability to detect what SaaS apps and permissions users are using is so important: Vercel had no contractual relationship with Context, one of their users just decided the tool would make their work easier. To make matters worse, while investigating the incident, Vercel says it has identified a second, previously undetected compromise.

  4. Kyber ransomware is now using quantum-safe cryptography to encrypt victims files. There’s little benefit for cybercriminals to use quantum over standard crypto at the moment. This is bragging rights and marketing.

  5. UK Biobank, a non-profit, has suspended access to its data set, sourced from volunteers, after the medical data of 500,000 Britons was spotted for sale on Chinese e-commerce site Alibaba. Science minister Ian Murray told the House of Commons that “This was not a leak. This was a legitimate download by a legitimately accredited organisation”, which seems to be rooted in the technicality of it not being a ‘break in’ and instead a failure of policy and procedural controls: either way, the outcome is the same. The Chinese government has helped to remove the data from sale (because of course it did!)

In brief

And finally

  • Vitaly Kamluk, a security researcher at SentinelOne, told Black Hat Asia that he believes they have found evidence of Fast 16, a potential cyberweapon that pre-dates Stuxnet by five years. Fast 16 targeted 2005-era computers, and will not run on multi-core processors or operating systems newer than Windows XP. The malware targeted engineering and physics simulation programmes, including one known to be used by Iran in its nuclear weapons programme.
Robin
  UK Cyber Pledge Cyber Essentials China Covert networks OAuth Post-Quantum Cryptography Ransomware Medical data Passkeys Electric Vehicles (EV) Electricity Grid