This week
Infosecurity Europe 2026 was a blast — thanks to those of you who came to say hi — here’s my roundup video.

- Meta’s chatbot used to hijack Instagram accounts
- Anthropic expands Project Glasswing access
- Open source AI models used to create self-propagating, evolving malware
- Twenty Dashlane password vaults stolen during API brute force attack
Interesting stats
31% of breaches now start with software vulnerabilities, rather than stolen passwords, and 48% of all breaches now involve ransomware, though payouts are shrinking, while 40% higher click rates on mobile devices make them more attractive for phishing attempts than desktop clients, according to Verizon
Four things
-
Meta’s AI support chatbot allowed attackers to takeover high profile Instagram accounts associated with the Obama White House and US Space Force, amongst others last weekend, and deface them with pro-Iranian propaganda. Two factors are at play here. Firstly, using a VPN to obtain an IP address near the victim’s normal location. Secondly, and perhaps more bizarrely, the chatbot would happily associate a new email address with the account, which can then be used to reset the password. We’ve seen a growing number of examples of AI chatbots being coerced into doing things they aren’t intended to do (like Chipotle’s being used for coding). However, chatbots are ultimately just API wrappers, which suggests that, in this case, policy enforcement is not handled in Meta’s APIs themselves, or that the chatbot can otherwise circumvent security layers.
-
Anthropic has had a busy week. Mythos access has expanded to more than fifteen countries. Around 150 organisations now have access to the model under Project Glasswing, where the Claude maker says “a successful attack on their codebase could be catastrophic,” and “we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security.” The UK’s Prudential Regulation Authority says that AI cyber risk is ‘top of the list’ of threats. Outgoing PRA CEO Sam Woods told the FT that the likes of Mythos require banks to undertake a significant “reordering [of] their tech programmes to make space for all this,” while also identifying higher-risk software components. In addition to filing paperwork for a potential IPO, Anthropic also suffered a string of outages (see Incidents below).
-
AI Malware: Meanwhile, researchers at the University of Toronto have published research that advanced models, like Mythos or OpenAI’s GPT 5.5-Cyber, are not needed to cause issues. They’ve used free open source models to create self-propagating code that can exploit known vulnerabilities and misconfigurations. The ‘parasitic’ worm uses the infected device’s compute to run the model and propagate itself, rendering centralised guardrails and controls irrelevant. The full report (PDF) contains a lot of preamble about the ethical considerations here.
-
Dashlane says that its system managed to detect and mostly contain a large brute force campaign to obtain users’ password vaults. Getting access to these vaults is obviously attractive to threat actors, as it could allow them to access all of a user’s accounts. The attackers “targeted the API endpoints for device registration” with a “large volume of automated requests”. In 20 cases, they generated a valid token, allowing them to download the user’s encrypted vault. Unless the attackers have the user’s master password, it’s very unlikely they’ll be able to decrypt its contents.
In brief
-
⚠️ Incidents: Claude maker Anthropic suffered multiple outages this week, with one on Monday lasting almost five hours, the same day as it filed paperwork ahead of an expected initial public offering. An Anthropic spokesperson confirmed that the outages affected the main Claude.ai chatbot, Claude Code, Cowork, and API access. Technology companies report productivity gains from switching to AI-assisted (or even driven) development; this is a reminder of the concentration risk. Russia’s Federal Security Service (FSB) says it uncovered a “large-scale” foreign intelligence operation that used ‘malicious software’ against the electronic devices of high-ranking Russian officials. The UN’s World Food Programme is investigating a breach that could expose the sensitive information of 600,000 Palestinian households in Gaza. The “unauthorised parties” had access to a self-registration application used exclusively in Gaza to request food and cash assistance. The City of York Council emailed hundreds of Blue Badge holders without using blind carbon copy (BCC), meaning all recipients could see each other’s email addresses and status as qualifying disabled residents. A former IBM cyber executive says the company was “routinely hacked by foreign state actors” and that breaches were not disclosed to affected parties, in a lawsuit filed in 2020 but unsealed this week, with an IBM spokesperson saying the DOJ had ‘declined’ to intervene and that “IBM is confident that our actions followed the letter of the law” (not exactly a strong denial!). Attackers exploited a security vulnerability in an Oxford University careers platform provided by Group GTI to steal names, email addresses, and some encrypted passwords.
-
🏴☠️ Ransomware: ‘Don’t compromise Commonwealth of Independent States’ rule very much intact in 2026, after an affiliate of Nova ransomware infected a major Uzbekistan-headquartered oilfield services company — the ransomware gang has issued an apology and offered to clean up the mess ‘free of charge’. ShinyHunters has claimed responsibility for a data breach at DentaQuest (part of Sun Life) affecting up to 2.6 million accounts, including name, telephone, email, and date of birth information, as well as government-issued IDs and health insurance information.
-
🕵️ Threat Intel: A threat actor is using Steam Community profile comments to facilitate command and control over infected WordPress websites. McAfee says every day between 2,000 and 3,000 Minecraft users are being infected by the WeedHack infostealer malware, typically via compromised mods and SEO poisoning. A Chinese-speaking threat actor (TA4922 aka Silver Fox) is using Atlas backdoor in a campaign against European entities in Germany, Italy, and the UK, using payroll, tax filing, and other financial lures. Five Eyes intelligence officials also warned of Chinese intelligence posing as recruiters to acquire non-public information. Palo Alto has released IOCs for Pink, a helpdesk social engineering actor, which Google believes could be a rebrand of UNC6671/BlackFile.
-
🪲 Vulnerabilities: Acer is working on patches for two critical zero-day vulnerabilities in its Wave 7 wifi routers, that allow unauthenticated attackers to access plaintext credentials remotely, and a hardcoded cryptographic key that can be used to gain persistent backdoor access (CVE-2026-49200, 49201 respectively; both 10/10; advisory). Cisco is warning of a improper input validation vulnerability that can ultimately lead to privilege escalation to root access in Unified Communications Manager (Unified CM) suite (CVE-2026-20230; 8.6/10; advisory). Sticking with more Cisco, no patches or workaround are currently available for a similar input validation zero-day in Catalyst SD-WAN (CVE-2026-20245; 7.8/10; advisory).
-
🛠️ Security engineering: A threat actor took control of the official Red Hat NPM channel and used it to distribute malware across over 30 affected packages. If you rely on the official images, or other Red Hat support packages, you’ll need to be rolling IR. Proof of concept exploit code for a VS Code zero-day has also been released, which compromises GitHub authentication tokens when a developer clicks a specially crafted link.
-
🏭 Operational technology: CISA is warning of a (potential Iranian) threat actor targeting automated tank gauges to manipulate or disable monitoring of, for example, fuel and other bulk liquid tanks, such as those at petrol stations or farms. The ATGs may be unnecessarily exposed to the internet and use default passwords. Changing the tank readings may prevent operations to replenish liquids. UK trade body the Cold Chain Federation (CCF) is urging government to take the risk of cyber attacks to food supply chains more seriously. The potential disruption from cyber, fuel shortages, and extreme weather should be an “immediate national priority”, given that the UK imports around one-third of its food.
-
🧿 Privacy: AT&T and Verizon have lost an appeal to overturn fines for selling customers’ geolocation data without their consent. The FCC issued penalties totalling $104 million to AT&T and Verizon in 2024 over violations dating back before 2018.
-
📜 Policy & Regulation: The European Union has proposed two laws aimed at curbing its reliance on US and Chinese supply chains: the Chips Act 2.0 and Cloud and AI Development Act (CADA) should “help widen choice in core technologies for EU businesses, citizens and public administrations”, with an estimated 80% of key digital products, services, and infrastructure reliant on foreign countries. President Trump issued an executive order requiring early access to new AI models for US government evaluation and select CNI operators for up to 30 days. I’m unsure who’ll do the evaluation, though, given how many roles have been gutted from the US cyber agencies amid further substantial funding cuts announced this week.
-
💰 Investments, mergers and acquisitions: Cyera is eyeing a $12 billion valuation in a Series G round targeting north of $300 million. For those keeping track, that’s an 80x multiple, on $150 million ARR, while the data storage outfit is still loss-making. Both CrowdStrike and Palo Alto Networks have reported ARR increases of over 30% on during their respective investor [calls](https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-reports-fiscal-third-quarter-2026-financial-results.
-
🗞️ Industry news: Microsoft has walked back on ‘responsible disclosure’ language and veiled legal threats following backlash from security researchers in an ongoing feud between it and pseudonymous actor Nightmare Eclipse. NSA is tipped to appoint existing employees David Imbordino, Holly Baroody, and Bruce Jones to senior leadership positions. Anonymous sources say President Trump is considering Palantir CTO Shyam Sankar to lead the vacant CISA director role, though this is disputed by the White House. Meanwhile, a report by policy experts and former military brass recommends a dedicated US Cyber Force, at the same level as the Army or Navy, with 30,000 personnel, for $11 billion. Interestingly, that’s roughly half the 61,000 people the DOD currently has involved in cyber operations.
And finally
- The US may have been using GPS satellites as a ‘numbers station’ to communicate secret codes to assets around the globe for nearly 20 years. The GPS specification includes a 176-bit data field — “Subframe 4, Page 17” — that drew the attention of security researcher Steven Murdoch, who was suspicious of the data’s randomness. Numbers stations, traditionally broadcast on shortwave radio, are used by intelligence agencies to communicate with people in circumstances where direct contact would be risky.