Robin’s Newsletter #411

3 May 2026. Volume 9, Issue 18
Cyber Security Breaches Survey 25/26 shows long way to go for UK biz. OpenAI matches Anthropic in cyber tests. CopyFail affects all Loinux distros.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 3rd May 2026

  • Half of UK businesses haven’t implemented MFA
  • GPT-5.5 on par with Mythos in cyber tests
  • Ransomware attacks exploit cPanel vulnerability
  • CopyFail local privilege escalation affects all Linux distros

Interesting stats

$2.1 billion lost by Americans to social media scams in 2025, according to the FTC.

$3.4 billion in US state privacy fines issued to companies in 2025, a  1.9x increase over 2024, and more than the previous five years combined, according to Gartner.

See also: Cyber breaches survey (below).

Five Four things

  1. The UK’s Cyber security breaches survey 2025/2026 was released this week, showing that 43% of businesses, and 28% of charities experienced a breach or attack in the last 12 months. Phishing remains the most common type of attack, and thankfully, ransomware has declined to 1% from 3% in the previous two periods. Cyber remains a priority for 7/10 businesses, down from a high of 8/10 coming out of the Covid pandemic. Around 1/3 have board-level responsibility. Just 30% have conducted a risk assessment covering cyber security in the last year. (If you’re in the majority who haven’t, this is basic hygiene stuff, and Cydea can help you: get in touch!). It may also surprise you to hear that over 1/2 have not implemented multi-factor authentication, 1/4 don’t backup data securely, and 1/5 haven’t implemented malware protection. 

  2. GPT-5.5 has matched Mythos in tests conducted by the UK’s AI Security Institute. The OpenAI model passed an average of 71.4% of ‘expert’ tasks, compared with Antropic’s much-hyped scored 68.6%, within the margin of error. AISI says that the advances we’re seeing are not “a breakthrough specific to one model,” rather “a byproduct of more general improvements” across autonomy, reasoning and coding. After throwing shade at Anthropic for holding back Mythos, OpenAI CEO Sam Altman said that their Cyber model would similarly be restricted. When it comes to AISI’s testing, it’s worth keeping in mind that ranges, such as The Last Ones lack any defenders of detection: they can be as noisy in their exploits as they like. It’s not a real-world comparison, but it is a clear direction of travel. I wonder if deception tech, like canaries, will become increasingly important in an AI world of ‘infinite interns’ probing every avenue?

  3. cPanel, a popular web hosting control panel system, has a critical authentication bypass vulnerability, (CVE-2026-41940; 9.8/10; advisory) that threat actors have begun exploiting. Over 1.5 million websites may use cPanel or the WP Squared variant (specifically for WordPress). Unsanitised username and password data is written to a session file on the affected server, which, via a second step, causes the system to think the user is authenticated, skipping the password verification stage and lets the attacker in. The fix (released on Tuesday) needs to be applied by the hosting company, not by each individual website. A wave of ‘Sorry’ ransomware attacks against affected websites has been observed. Hopefully, most are unsophisticated ‘brochureware’ marketing sites, unconnected to their organisation’s main IT environments.

  4. CopyFail: Researchers have found a high-severity local privilege escalation vulnerability (CVE-2026-31431; 7.8/10; advisory) that affects nearly all Linux distributions released since 2017. The issue stems from a problem in the crypto subsystem of the Linux kernel, and means that “a local user can write 4 controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root.” Theori, the company that discovered the vulnerability, are turning it into a bit of a PR exercise with its own website and, quelle surprise, their AI ‘assisted’ the discovery. However, the underlying issue is severe and warrants attention. While not remotely exploitable — you need a local user account — it could be chained with other vulnerabilities to gain root access. Sysadmins should prioritise patching shared hosts and boxes in continuous integration environments that process pull requests. The CERT-EU advisory links to the main Linux distribution pages and their patch status.

In brief

And finally

Robin
  Cyber Security Breaches Survey Cyber Risk Assessment Privacy Artificial Intelligence (AI) CopyFail Linux Geofence Geolocation