Robin’s Newsletter #418

21 June 2026. Volume 9, Issue 25
FIFA agent account caught offside. Upto half of Fortinet firewall credentials appear to have been compromised. 'Fix this code' is a jailbreak?
Join hundreds of subscribers who get this first, every Sunday. Subscribe

First up, some celebrations are in order: I’ve been writing this infosec newsletter every week since 24th June 2018: Happy 8th Anniversary to Robin’s Newsletter 🥳

This week

Need to Know, 21st June 2026

  • FIFA’s World Cup broadcast systems were accessible to self-registered agent accounts
  • FortiBleed campaign compromised over 70,000 Fortinet devices
  • Unpatchable BootROM exploit affecting iPhone 11-era models discovered
  • Three Microsoft secure boot certificates expire this coming week
  • Fable ‘jailbreak’ amounted to “fix this code”

Interesting stats

$3.5 billion lost to imposter scams in 2025, a  3x increase since 2020, according to the FTC

200+ UK CNI cyber incidents in the year to May 2026, with  75% of them believed to link to state actors, according to NCSC

30% of all offences across the Asia and South Pacific (ASP) region relate to cybercrime, according to Interpol 

Five things

  1. FIFA doesn’t appear to have very good segregation between its private apps. Security researcher BobDaHacker was able to register as a player’s agent, and then use that account to gain access to live TV broadcast and tournament management systems (blog post). FIFA didn’t respond to their vulnerability reports, though they fixed the issue in hours. Major sporting tournaments are targets for all sorts of threat actors, and (cyber) security is usually taken very seriously. This type of scenario was one I ran as a board-level IR tabletop for a major UK broadcaster, and it is easy to see why politically or financially motivated actors might want to subvert or sabotage a major broadcast. The response time is good, but the lack of a mechanism to report vulnerabilities and the Micky Mouse approach to authorisation suggest a cyber programme in need of a boost at FIFA. They’re lucky it was an ethical security researcher who only briefly considered rick-rolling the world.

  2. FortiBleed: Security researchers have discovered credentials for over 70,000 Fortinet devices after gaining access to a Russian-speaking threat actor’s command and control system. The scale of the breach is huge, affecting major organisations in tech, logistics, defence, and pretty much every other sector across 194 countries worldwide. The number of devices is roughly half of the total Fortinet devices indexed by Shodan. The access appears to have been gained by brute-forcing passwords, but the threat actors then used this access to capture SSL VPN logins and run them through a 45-GPU password-cracking cluster to gain further access into the victim’s environment. If you’re a Fortinet customer, it’s time to roll incident response. You can check your inclusion on Hudson Rock’s checker and follow NCSC’s advice if you suspect you have been compromised.

  3. usbliter8: Researchers have found a BootROM exploit affecting Apple A12 and A13 chips, which run the Synopsys DesignWare USB controller. ‘Usbliter8’, which cannot be patched because the code is burned into the chip’s silicon during manufacturing of iPhone 11-era devices, allows an actor with physical access to the device to gain control of the SecureROM and run untrusted code. This is unlikely to be a concern for most individuals, who probably don’t need to be concerned, but it will be of interest to law enforcement and intelligence agencies seeking to access locked devices.

  4. Three Secure Boot certificates will expire this coming week, on 24th June, and need to be replaced to protect against UEFI boot kits. Microsoft has been rolling out new certs to replace those issued in 2011, following the 2023 Logo Fail vulnerability. Microsoft users can check they’re up to date in Windows Security > Device Security > Secure Boot, looking for a green tick. Linux users may need to look out for new shims for their favoured release.

  5. Mythos madness: Details are emerging over the ‘jailbreak’ that resulted in the Anthropic’s latest models being subject to US export controls. Katie Moussouris says the report she has seen (presumably ‘the Amazon one’) boils down to re-prompting the model to “fix this code” and the stepping through a manual process to create scripts that test the patches the Fable 5 created. (Fable refused to “review the code for security issues”). Hardly groundbreaking. Nor something that isn’t achievable with other models. Moussouris is well-placed to comment: she was a member of the technical expert group that spent years renegotiating the Wassenaar Arrangement to exclude defensive cyber activities from the unintended consequences of overly broad export controls. Meanwhile, US and European diplomats discussed a “trusted partner” scheme that would allow and protect access to cutting-edge AI models on the sidelines of the G7 Summit this week.

In brief

And finally

  • Thanks again for reading and sharing your comments. It’s always great to hear from people via email, LinkedIn, or at events.  If you’ve made it this far, please recommend at least one person to subscribe. (Thank you!)
Robin
  Artificial Intelligence (AI) Anthropic Mythos FIFA Broadcast Authorization Fortinet FortiBleed UEFI Secure Boot