Robin’s Newsletter #415

31 May 2026. Volume 9, Issue 22
Microsoft zero-day beef escalates. Farage's Russia hacking claims 'baseless'. Novel browser side-channel attack.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

We’ve still got a few spaces for anyone wanting to join us for breakfast this Wednesday, 3 June, in Canary Wharf. I’ll also be hosting a table talk on mandatory incident reporting that day. Plus a variety of other Cydea events around Infosecurity Europe.

Need to Know, 31st May 2026

  • Researcher promises ‘bone shattering’ Microsoft vulnerability in July
  • Browser side-channel attack revealed website access
  • Anthropic’s Project Glasswing update
  • GCHQ boss says orgs need to 10x their cyber prioritisation
  • Farage’s Russia hacking claims are baseless, says former NCSC chief

Interesting stats

52% of knowledge workers admit to using unapproved AI tools, and  24% say they do it regularly, while  90% of executives have confidence in their organisation’s visibility into AI tools, according to Okta

68% of UK businesses expect to increase cyber investment over the next 12 months, according to Barclays, who add that 2026 spend to date is  £505,000 on average, or  £1.3 million for larger businesses (250+ employees),  £134,000 for small businesses (10-49 employees), an £15,000 for micro businesses (1-9 employees).

Five things

  1. Microsoft has escalated its beef with a security researcher known as Nightmare Eclipse, called zero-day released “never justifiable”. A blog post on ‘coordinated vulnerability disclosure’ names the six different zero-day vulnerabilities dropped in recent months by the security researcher, who claims that Microsoft refused to communicate with them, deleted their Microsoft account used for bug reporting, and “humiliated” them in front of people. The six issues, three of which are currently unpatched, represent serious flaws in Microsoft products, including the ability to bypass BitLocker device encryption. It’s unclear if they’re a current/former Microsoft employee, but they seem to know an awful lot about the inner workings of the Windows operating system. Nightmare Eclipse has promised to drop ‘bone shattering’ information on 14 July. Microsoft releases security updates on the second Tuesday of every month, so the timing is deliberate and intended to occur at a point of maximum potential disruption. Given the specifics cited by Nightmare Eclipse, though, I’d imagine Microsoft must know, or be able to identify, who this researcher is. Watch this space.

  2. FROST, or fingerprinting remotely using OPFS-based SSD timing, is a new side-channel attack from security researchers at Graz University of Technology, Austria. The paper (PDF) builds on work showing “that variations in SSD access time can be used to leak information about user activity” to understand what websites a user is accessing and applications they have open. Using the  File System Access API, the attacker’s website can measure SSD (disk) contention when accessing files on the same drive as the operating system. The victim needs to visit a special website, but no further user interaction is required, making it a potentially stealthy way to monitor user activity surreptitiously. The good news is that it also requires around a 1GB file to function, making it stand out somewhat. Here’s a good reason to routinely close your tabs ;-)

  3. Anthropic has published an update on Project Glasswing, the early access programme to its Mythos cyber security model. Looking at the data, less than 7% of the candidate findings discovered by Mythos are being disclosed to maintainers. These are vulnerabilities it has deemed high- or critical-severity issues, a classification it gets right roughly two-thirds (62.4%) of the time when a human validates results. Anthropic “looks forward” to making Mythos available to the public, once “the far stronger safeguards we need” are developed. The focus on the main open-source projects that underpin much of the Internet is a good start and should leave us all in a more secure position. But while finding vulnerabilities in code you have access to is one thing, I think the larger issue will be when models can reverse-engineer compiled software and look for vulnerabilities. I’d wager there are many assumptions and a lot of security through obscurity built into the proprietary software used by many organisations. In the meantime, it’s bug bounty hunters facing the biggest disruption as reward payouts plummet, and some organisations shutter their programmes altogether. It would be great if we could quickly redeploy that talent into organisations to fix, rather than break, their software. Perhaps the evolution of HackerOne and BugCrowd is to pivot to a fix-as-a-service model instead of a find-as-a-service model? Though IBM has pledged $5 billion to fix open-source software vulnerabilities.

Anthropic’s open source vulnerability dashboard showing all severity vulnerabilities identified by Mythos preview (source: Anthropic)

  1. GCHQ director Anne Keast-Butler said action must be taken for “hard-wiring security into new technologies, protecting supply chains and making cyber security 10 times more urgent.” The comments were part of an inaugural annual address at Bletchley Park, the agency’s original home and site of World War II code-breaking efforts. Russia, Keast-Butler said, conducts daily hybrid attacks “from the seabed to cyberspace.”. China received a more muted mention, citing its rise as “a science and tech superpower”.

  2. Nigel Farage’s claims that Russia hacked his mobile and leaked information about a £5 million ‘gift’ from a cryptocurrency billionaire are “without any merit”, says former NCSC chief Ciaran Martin. While the Reform party leader says ‘counter-espionage experts’ have conducted an investigation, Martin points out that not a shred of evidence to substantiate the claims has been provided, and that the very attack itself wouldconstitute “unprecedentedly aggressive intervention” in UK politics. Russian actors would be unlikely to leave a calling card. A proper investigation would require quite substantial analysis of the device, plus presumably logs from Farage’s bank, and maybe wider intelligence feeds that a private company wouldn’t have access to.

In brief

And finally

  • Security researcher Elad Meged found a great way to get himself speaking opportunities at security conferences: finding a vulnerability in the software that many use to process their call for paper applications. The (now fixed) cross-site scripting (XSS) and cross-site request forgery (CSRF) issues triggered in the context of the conference organiser and could allow him to approve his talk.
Robin
  Microsoft Vulnerability Disclosure Side-Channel Geopolitics Russia