This week

- Half of UK businesses haven’t implemented MFA
- GPT-5.5 on par with Mythos in cyber tests
- Ransomware attacks exploit cPanel vulnerability
- CopyFail local privilege escalation affects all Linux distros
Interesting stats
$2.1 billion lost by Americans to social media scams in 2025, according to the FTC.
$3.4 billion in US state privacy fines issued to companies in 2025, a 1.9x increase over 2024, and more than the previous five years combined, according to Gartner.
See also: Cyber breaches survey (below).
Five Four things
-
The UK’s Cyber security breaches survey 2025/2026 was released this week, showing that 43% of businesses, and 28% of charities experienced a breach or attack in the last 12 months. Phishing remains the most common type of attack, and thankfully, ransomware has declined to 1% from 3% in the previous two periods. Cyber remains a priority for 7/10 businesses, down from a high of 8/10 coming out of the Covid pandemic. Around 1/3 have board-level responsibility. Just 30% have conducted a risk assessment covering cyber security in the last year. (If you’re in the majority who haven’t, this is basic hygiene stuff, and Cydea can help you: get in touch!). It may also surprise you to hear that over 1/2 have not implemented multi-factor authentication, 1/4 don’t backup data securely, and 1/5 haven’t implemented malware protection.
-
GPT-5.5 has matched Mythos in tests conducted by the UK’s AI Security Institute. The OpenAI model passed an average of 71.4% of ‘expert’ tasks, compared with Antropic’s much-hyped scored 68.6%, within the margin of error. AISI says that the advances we’re seeing are not “a breakthrough specific to one model,” rather “a byproduct of more general improvements” across autonomy, reasoning and coding. After throwing shade at Anthropic for holding back Mythos, OpenAI CEO Sam Altman said that their Cyber model would similarly be restricted. When it comes to AISI’s testing, it’s worth keeping in mind that ranges, such as The Last Ones lack any defenders of detection: they can be as noisy in their exploits as they like. It’s not a real-world comparison, but it is a clear direction of travel. I wonder if deception tech, like canaries, will become increasingly important in an AI world of ‘infinite interns’ probing every avenue?
-
cPanel, a popular web hosting control panel system, has a critical authentication bypass vulnerability, (CVE-2026-41940; 9.8/10; advisory) that threat actors have begun exploiting. Over 1.5 million websites may use cPanel or the WP Squared variant (specifically for WordPress). Unsanitised username and password data is written to a session file on the affected server, which, via a second step, causes the system to think the user is authenticated, skipping the password verification stage and lets the attacker in. The fix (released on Tuesday) needs to be applied by the hosting company, not by each individual website. A wave of ‘Sorry’ ransomware attacks against affected websites has been observed. Hopefully, most are unsophisticated ‘brochureware’ marketing sites, unconnected to their organisation’s main IT environments.
-
CopyFail: Researchers have found a high-severity local privilege escalation vulnerability (CVE-2026-31431; 7.8/10; advisory) that affects nearly all Linux distributions released since 2017. The issue stems from a problem in the crypto subsystem of the Linux kernel, and means that “a local user can write 4 controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root.” Theori, the company that discovered the vulnerability, are turning it into a bit of a PR exercise with its own website and, quelle surprise, their AI ‘assisted’ the discovery. However, the underlying issue is severe and warrants attention. While not remotely exploitable — you need a local user account — it could be chained with other vulnerabilities to gain root access. Sysadmins should prioritise patching shared hosts and boxes in continuous integration environments that process pull requests. The CERT-EU advisory links to the main Linux distribution pages and their patch status.
In brief
-
⚠️ Incidents: Energy and utility sector service provider Itron has notified the SEC of an ‘intruder’ in its systems, but that the activity was not in the “customer-hosted portion of its systems”, which includes connected meters for gas, electricity, water, and the like. Medtronic has confirmed a breach claimed by ShinyHunters, who say they have stolen 9 million records from the medical device company. US mailing company Pitney Bowes has suffered a breach of “certain records in our Salesforce [CRM]” stemming from a phishing attack that stolen employee credentials, which Have I Been Pwnd puts at around 8.2 million unique email addresses. Appsec biz Checkmarx said it believed LAPSUS$ has stolen data from its private GitHub repository (it’s been a bad six weeks for Checkmarx). Moldova’s National Health Insurance Company, CNAM, says data was exfiltrated during a recent incident, with the country’s cyber agency suggesting it could affect around one-third of CNAM’s database. Canonical says that the Ubuntu website and other infrastructure were offline this week following a “sustained, cross-border Distributed Denial of Service (DDoS) attack” which is being linked to pro-Iran hacktivist group The Islamic Cyber Resistance in Iraq. Edtech company Instructure says it is investigating the impact of a recent cyber incident that may affect its popular Canvas learning management system.
-
🕵️ Threat Intel: Victims of threat actor Vect should not pay the cybercriminals in hope of getting their data back, according to Check Point, which says the malware is a wiper, and destroys all files larger than 128kb. Attackers are exploiting a pre-authentication SQL injection vulnerability in LiteLLM to gain access to the system and “credentials it manages” (CVE-2026-42208; advisory). CrowdStrike says that two threat groups affiliated with The Com — it’s calling Cordial Spider and Snarky Spider — are replicating tactics used by Scattered Spider, particularly against retail and hospitality, and financial, legal, and technology services sectors, with social engineering and voice-phishing attacks. The FBI is warning logistics firms of cyber-enabled cargo theft, which has surged 60% year-over-year, with estimated losses in the US and Canada at $725 million. Write up on the attack flow of ConsentFix v3 technique.
-
🪲 Vulnerabilities: Google has patched a ‘perfect 10’ vulnerability in its Gemini CLI application, where “attacker-controlled content was silently accepted as trusted configuration and executed before any sandbox was initialized” (No CVE; 10/10; advisory).
-
🧰 Guidance and tools: Five eyes cyber agencies have published guidance on safely deploying AI agents, encouraging organisations to use existing governance and architecture principles. (Side note, Cydea recently published an AI Scenario Pack and blog post on AI risk that you may find interesting).
-
🛠️ Security engineering: Robinhood’s new user registration emails were hijacked and abused to send phishing emails because the investment company did not properly sanitise input fields used to show recent login information.
-
🧿 Privacy: The US Supreme Court has indicated that geofence searches for mobile devices located near a crime scene may soon require a warrant.
-
👮 Law Enforcement: A 15-year-old has been detained on suspicion of selling data stolen from France Titres (ANTS) (vol. 9, iss. 17).
-
🗞️ Industry news: Big 4 consulting firm PwC has announced a partnership with Google to provide outsourced security operations services targeted at smaller and mid-size enterprises.
And finally
- I hope you’re having an enjoyable public holiday (in the UK) and would be very grateful if you let me know what you like, and anything you feel could be better, about this newsletter. Thank you!