First up, some celebrations are in order: I’ve been writing this infosec newsletter every week since 24th June 2018: Happy 8th Anniversary to Robin’s Newsletter 🥳
This week

- FIFA’s World Cup broadcast systems were accessible to self-registered agent accounts
- FortiBleed campaign compromised over 70,000 Fortinet devices
- Unpatchable BootROM exploit affecting iPhone 11-era models discovered
- Three Microsoft secure boot certificates expire this coming week
- Fable ‘jailbreak’ amounted to “fix this code”
Interesting stats
$3.5 billion lost to imposter scams in 2025, a 3x increase since 2020, according to the FTC
200+ UK CNI cyber incidents in the year to May 2026, with 75% of them believed to link to state actors, according to NCSC
30% of all offences across the Asia and South Pacific (ASP) region relate to cybercrime, according to Interpol
Five things
-
FIFA doesn’t appear to have very good segregation between its private apps. Security researcher BobDaHacker was able to register as a player’s agent, and then use that account to gain access to live TV broadcast and tournament management systems (blog post). FIFA didn’t respond to their vulnerability reports, though they fixed the issue in hours. Major sporting tournaments are targets for all sorts of threat actors, and (cyber) security is usually taken very seriously. This type of scenario was one I ran as a board-level IR tabletop for a major UK broadcaster, and it is easy to see why politically or financially motivated actors might want to subvert or sabotage a major broadcast. The response time is good, but the lack of a mechanism to report vulnerabilities and the Micky Mouse approach to authorisation suggest a cyber programme in need of a boost at FIFA. They’re lucky it was an ethical security researcher who only briefly considered rick-rolling the world.
-
FortiBleed: Security researchers have discovered credentials for over 70,000 Fortinet devices after gaining access to a Russian-speaking threat actor’s command and control system. The scale of the breach is huge, affecting major organisations in tech, logistics, defence, and pretty much every other sector across 194 countries worldwide. The number of devices is roughly half of the total Fortinet devices indexed by Shodan. The access appears to have been gained by brute-forcing passwords, but the threat actors then used this access to capture SSL VPN logins and run them through a 45-GPU password-cracking cluster to gain further access into the victim’s environment. If you’re a Fortinet customer, it’s time to roll incident response. You can check your inclusion on Hudson Rock’s checker and follow NCSC’s advice if you suspect you have been compromised.
-
usbliter8: Researchers have found a BootROM exploit affecting Apple A12 and A13 chips, which run the Synopsys DesignWare USB controller. ‘Usbliter8’, which cannot be patched because the code is burned into the chip’s silicon during manufacturing of iPhone 11-era devices, allows an actor with physical access to the device to gain control of the SecureROM and run untrusted code. This is unlikely to be a concern for most individuals, who probably don’t need to be concerned, but it will be of interest to law enforcement and intelligence agencies seeking to access locked devices.
-
Three Secure Boot certificates will expire this coming week, on 24th June, and need to be replaced to protect against UEFI boot kits. Microsoft has been rolling out new certs to replace those issued in 2011, following the 2023 Logo Fail vulnerability. Microsoft users can check they’re up to date in Windows Security > Device Security > Secure Boot, looking for a green tick. Linux users may need to look out for new shims for their favoured release.
-
Mythos madness: Details are emerging over the ‘jailbreak’ that resulted in the Anthropic’s latest models being subject to US export controls. Katie Moussouris says the report she has seen (presumably ‘the Amazon one’) boils down to re-prompting the model to “fix this code” and the stepping through a manual process to create scripts that test the patches the Fable 5 created. (Fable refused to “review the code for security issues”). Hardly groundbreaking. Nor something that isn’t achievable with other models. Moussouris is well-placed to comment: she was a member of the technical expert group that spent years renegotiating the Wassenaar Arrangement to exclude defensive cyber activities from the unintended consequences of overly broad export controls. Meanwhile, US and European diplomats discussed a “trusted partner” scheme that would allow and protect access to cutting-edge AI models on the sidelines of the G7 Summit this week.
In brief
-
⚠️ Incidents: Microsoft forgot to renew the certificate for
connectivity.office.com, causing errors for IT admins looking to check firewall rule configurations and other connection issues. Texas Parks & Wildlife, a state government department handling hunting and fishing licenses, says its suffered a breach affecting 3 million river’s licenses and passports, plus email addresses, phone numbers, and postal addresses. -
🏴☠️ Ransomware: Kodak is investigating a breach of its systems and a “limited amount of company data”, with cybercrime group ShinyHunters claiming responsibility on its leak site.
-
🕵️ Threat Intel: Google says it’s uncovered a Chinese-linked espionage campaign. UNC6508 targeted organisations running REDCap (Research Electronic Data Capture) servers to steal information from academia, medicine, military, cyber, and foreign policy, dating back to September 2023. Estonia is screening all emails to government officials that originate from .ru domains. Microsoft has linked the Mastra AI supply chain attack to North Korea actors it calls Sapphire Sleet.
-
🪲 Vulnerabilities: F5 has released out-of-band security patches for its NGINX web server product to address two critical code execution vulnerabilities (CVE-2026-42530 and -42055; both 9.2/10; respective advisories).
-
🏭 Operational technology: California Water Service is investigating claims from an Iran-linked group, Handala, that it gained access to the organisation’s systems. The screenshots posted by the threat actor appear to show IT-related customer relationship management software, rather than operational technology controlling the supply of water.
-
🧿 Privacy: Buying vs tapping: Advertising intelligence, or Adint, is now one of the major sources of government surveillance, according to a survey of 11 European intelligence agency regulators. Google has notified advertisers that it intends to use IP Addresses in the European Economic Area, the UK, and Switzerland for advertising “measurement and personalisation”. Under GDPR, IP addresses are seen as personal data, and are not as easily changed as (for example) clearing cookies. Apple plans to change its Hide My Email service to use @private.icloud.com, making it easier for websites and apps to identify and potentially block signups using the privacy service.
-
📜 Policy & Regulation: The EU has granted Ukraine access to the EU Cybersecurity Reserve, a pool of approved private companies that can be deployed in response to large-scale CNI and government cyber incidents.
-
👮 Law Enforcement: Operation Endgame: International law enforcement has cleaned almost 15,000 WordPress websites infected with the SocGholish malware linked to the Russian Evil Corp cybercrime group.
-
💰 Investments, mergers and acquisitions: Accenture made a massive bet on operational technology (OT) cyber security this week, announcing $4.18 billion investments, with a majority stake in Dragos ($3.25b), and buying outright runZero and NetWise to roll attack surface and supply chain data and functionality into the new group. AI agent governance startup NewCore has emerged from stealth with $66 million in funding; the company, which has around 50 staff, fewer than 10 customers, and ‘intends’ to start charging this summer, is sitting on a $300 million valuation. SpaceX is to acquire Cursor in a $60 billion all-stock transaction. Training firm mthree has acquired Capslock for an undisclosed sum.
-
🗞️ Industry news: MS-ISAC, the US state and local government cyber intelligence sharing group run by CIS, says more than 10,000 local jurisdictions can no longer afford to participate, after DHS suddenly pulled federal funding for the program last year. UK Information Commissioner John Edwards has resigned over ‘inappropriate humour’.