This week

- YellowKey busts BitLocker, decrypting hard drives and granting SYSTEM access
- OpenAI announces Daybreak cyber programme combining defensive, offensive tooling
- UK Regulators remind financial services to up their cyber games
- TeamPCP behind latest wave of Shai-Hulud software supply chain attacks
- UK Government signals reform of Computer Misuse Act
Interesting stats
40% of global ransomware attacks are accompanied by threats of physical violence, according to Semperis.
Five things
-
BitLocker Bust: YellowKey is an “insane” vulnerability that defeats Windows BitLocker. The exploit involves plugging in a specially crafted USB key, and then (re)booting the device into Windows Recovery. Upon doing so, instead of prompting for a BitLocker key, a command prompt is displayed with SYSTEM privileges. It’s unclear, and perhaps most interesting, that the
\System Volume Information\FsTxdirectory on the USB drive can affect the legitimate one in the Windows Recovery partition. To exploit the issue, you need to have physical access to the device. That limits exposure, though it will surely be of interest in intelligence or law enforcement environments, or to attackers with unattended access to devices (during travel, for example). At the moment, it means that lost or stolen Windows computers, even if encrypted, may be trivially unlocked, potentially constituting a reportable security incident, especially if they contain local copies of personal data. -
Daybreak: OpenAI has announced Daybreak, an initiative to “accelerate cyber defenders and continuously secure software”. This is most relevant to tech companies and those developing their own software. If you’re largely a consumer of SaaS or on-prem software from vendors, there’s less here for you. That’s because Daybreak is focused on finding or triaging vulnerabilities in code bases, and then generating and patching the issues that it finds. If you’re not writing code, this isn’t for you. Daybreak combines three models with different levels of hoops required to obtain access: GPT-5.5 for general use, GPT-5.5 with Trusted Access for Cyber for defensive work, and finally GPT-5.5-Cyber, with revised guardrails that allow offensive work like penetration testing. At some point, AI like this will become very good at decompiling and understanding executables. Then I can see plenty of security researchers, large organisations, and, yes, threat actors, turning their attention to proprietary software too.
-
UK FS Regulation: The Bank of England, FCA, and HM Treasury have issued a joint statement on Frontier AI models and cyber resilience. The statement says that they judge regulated firms should be taking steps to improve governance, vulnerability management, third-party management, protection, and incident response. The regulators note that this shouldn’t introduce “new expectations”, rather it “reinforces existing messages”. However, the rapid evolution of technology and AI will make it seem like new requirements for many smaller firms.
-
Software supply-chain: TeamPCP is believed to be behind a new wave of Shai-Hulud software supply chain attacks on TanStack and Mistral AI npm packages. TanStack’s report says the attackers gained access through three steps: “the pull_request_target “Pwn Request” pattern, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of an OIDC token from the GitHub Actions runner process.”
-
Computer Misuse: The UK government has announced that it will rewrite the Computer Misuse Act, paving the way for a public interest defence that would protect security researchers. CMA reform is well overdue, with many facing potential legal risk from broad definitions of ‘attempting to gain access’ to a system without proper authorisation, which don’t reflect how technology works.
In brief
-
⚠️ Incidents: Best Western Hotels is warning “certain customers” that names, telephone numbers, email and home addresses, reservation details, and special requests, after unauthorised access by an attacker over six months at a third-party. Škoda has disclosed a data breach affecting, with attackers gaining access to the data of an undisclosed number of customers who used the automaker’s
shop.skoda-auto.dee-commerce portal. -
🏴☠️ Ransomware: Pennsylvania headquartered West Pharmaceutical has reported a ransomware attack to the SEC that “temporarily disrupted the Company’s business operations globally”. Foxconn, the world’s largest electronics manufacturer and supplier to tech companies like Apple and Google, says some of its North American factories were disrupted by a ransomware attack, claimed by the ‘Nitrogen’ group, who say they stole 8TB of data.
-
🕵️ Threat Intel: Symantec says that the Iranian-linked MuddyWater group has been targeting high-profile South Korean organisations in a campaign with espionage and intelligence objectives. Microsoft write up of how Russia’s Secret Blizzard has turned its Kazuar malware into a peer-to-peer botnet, improving stealth.
-
🪲 Vulnerabilities: Fortinet has addressed two critical vulnerabilities in FortiAuthenticator and FortiSandbox, stemming from improper access control and missing authorisation, respectively (CVE-2026-44277 & CVE-2026-26083; both 9.1/10; authenticator, sandbox advisories). Popular open-source email server software Exim has fixed a critical vulnerability allowing unauthenticated remote attackers to execute arbitrary code (CVE-2026-45185; 9.8/10; advisory). Cisco is warning that threat actors are actively exploiting a ‘perfect10’ critical authentication bypass vulnerability in its Catalyst SD-WAN Controller (CVE-2026-20182; 10/10; advisory). Another Linux vulnerability in the Dirty Frag class, Fragnasia is a privilege escalation bug allowing local users to gain root access (CVE-2026-46300; 7.8/10; writeup). Nginx maintainers have patched a critical denial of service, or potential RCE, vulnerability in its http rewrite module (CVE-2026-42945; 9.2/10; advisory).
-
🧑💻 End user and consumer: Google is adding an optional “Intrusion Logging” feature to Android’s Advanced Protection Mode to help investigate spyware attacks. Signal is adding social engineering warnings to its app to protect users.
-
🧰 Guidance and tools: NCSC has launched guidance on the adoption of Agentic AI: TL;DR: apply the same basic principles you do to anything else, like least-privilege, secure configuration, and monitoring.
-
🧿 Privacy: Congressman Frank Pallone, Jr. has written to 25 retailers asking if and how they use personal data to set prices in so-called surveillance pricing tactics.
-
📜 Policy & Regulation: The ICO fined South Staffordshire Water £936,900 this week for a 2022 Cl0p ransomware incident. The attackers gained initial access and went undetected, two years before the incident, which was mistakenly attributed to Thames Water at the time (vol. 5, iss. 34). An employee opening a malicious attachment to a phishing email provided the initial foothold. However, poor patching and vulnerability management (some devices were running Windows Server 2003) and detection (a year after the incident, only 5% of the company’s IT environment was being monitored) contributed.
-
💰 Investments, mergers and acquisitions: AI-powered detection and response startup Exaforce has closed a $125 million Series B funding round, valuing the firm at $725 million.
-
🗞️ Industry news: Cisco has announced better-than-expected “record revenue” in its quarterly results, and then laid off 4,000 people (5%) of its workforce.
And finally
- As we approach eight years of Robin’s Newsletter, can I ask a couple of favours? 1. Send this on to someone you think would benefit from subscribing. Your recommendation is important and carries a lot of weight. 2. If you want to understand your organisation’s cyber risk, or are embarking on a security programme, I’d love for Cydea to be considered. Hit reply now and give me a heads-up: I’ll make sure we look after you. Thank you!