This week

- Five Eyes cyber agencies urge businesses to improve cyber resilience
- TfL attackers pleaded guilty to 2024 compromise
- Klue compromise leads to Salesforce data access
- Chinese company unveils Mythos-esque model
- Hospital probing medical records access of crocodile attack child
Interesting stats
58% of claims are email-related business email compromise (BEC) and funds transfer fraud (FTF), while $1 million, the average initial ransom demand (up 47%), and 70% involved both encryption and data exfiltration (“double extortion”), though 100% of UK claims were restored within ransom demands being paid, according to Coalition’s 2026 Cyber Claims Report (h/t Tony for the reminder on this one!)
Five things
-
Five A-Eyes: Leaders of the Five Eyes cyber agencies have issued a joint letter (PDF) urging businesses to take swift action to up cyber resilience and advance “business continuity, market confidence, and long-term value”. To do this, they say that business leaders should understand and assess risk, prioritise foundational cyber security practices and controls, and empower cyber leaders with authority and resources. (I didn’t have anything to do with the, but that is exactly what Cydea helps organisations to do!) The action is needed because “cyber risk assumptions can become outdated in months, not years”, and the NCSC blog post goes on to point out that “Cyber risk can no longer be treated as a purely technical issue. This is a core business risk and leadership responsibility.”
-
TfL: The two men behind a 2024 cyberattack against Transport for London have pleaded guilty this week to the incident that cost TfL £39 million. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, were both known to the police at the time and were part of the loosely affiliated Scattered Spider group. The National Crime Agency has called for more powers — so-called Cyber Crime Risk Orders (CCROs) — to use in cases like this. However, West Midlands Regional Cyber Crime Unit officers chose not to invite Flowers to the national Cyber Choices programme because he didn’t engage with officers during a visit and instead issued a cease-and-desist order. Given the evidence against the pair, it’s a sensible choice to plead guilty and avoid a lengthy trial, though one expert witness said: “They don’t seem to understand the consequences and there are real victims here losing their life savings in some case as well as corporations and their staff that are badly impacted”. (Side note, identifying and diverting talented young hackers is the problem that The Hacking Games is trying to solve.)
-
Klue, a market research company, was compromised after attackers stole a credential from a 2022 pilot programme and used this to access ‘hundreds’ of the firm’s customers’ Salesforce CRM data. The affected customers include cyber outfits like Recorded Future, Huntress, Hacker One, Tanium, Snyk, and LastPass. Klue CEO Jason Smith said the company identified the breach on 12 June, with hack-and-leak group known as Icarus taking credit and Klue saying that the group is deleting their data (presumably a ransom has been paid). In the meantime, Klue’s customers should check their logs for indicators of compromise and rotate their integration credentials (Salesforce has disabled the Klue Integration following the breach).
-
Mythos Madness: Chinese cyber company Qihoo 360 claims it’s built an AI vulnerability model that’s better than Anthropic’s Mythos. Introducing the model, CEO Zhou Hongyi described their approach as a “multi-agent swarm”, adding, “If the American approach is about cultivating a genius hacker, the 360 approach is about organizing a professional attack and defense team”. At the firm’s 14th Beijing Cybersecurity Conference, Zhou used the recent block of Mythos to foreign nationals as a reason for why China needs a sovereign capability “equivalent to a ‘cyber nuclear weapon’”. US authorities already sanctioned Qihoo 360 for supplying China’s military.
-
See you later, Alligator: Cambridge University Hospitals (CUH) is investigating a potential data protection breach after up to 40 members of staff accessed the medical records of a three-year-old boy injured in a crocodile attack. The NHS trust has reported itself to the Information Commissioner’s Office. It’s an unusual story, sure to spark water-cooler curiosity, and props to them for having monitoring in place to detect and audit this type of access.
In brief
-
⚠️ Incidents: Authorities in Brazil are investigating a rogue message sent from the country’s emergency alert system, which sources believe was caused by a cyberattack (Coincidentally, the FCC approved a set of rules to boost cyber protection of the US’ emergency alert systems). Ontario, Canada headquartered London Hydro has fessed up to a security incident resulting in the loss of customer data](https://www.theregister.com/security/2026/06/22/canadian-utility-fesses-up-to-data-breach-but-key-details-remain-off-grid/5259309). The energy company hasn’t confirmed how the data — including name, contact and contract information, and meter information — was compromised, or how many of the over 160,000 customers were affected. Tata Electronics says it suffered a breach “a few weeks ago” that may have exposed communications and specifications with key customers Apple and Tesla, who have turned to the Indian electronics company in efforts to diversify their supply chain away from China. US healthcare technology company Xsolis says attackers stole sensitive health information belonging to 1.4 million people. Japanese telco KDDI says it has detected unauthorised access to an email system it manages for 14.2 million people, including the compromise of usernames and encrypted passwords. Ukrposhta, Ukraine’s state postal company, says its mobile app is disrupted by an “enemy” cyberattack, meanwhile Ufagormolzavod, a Russian dairy company, says shipments have slowed down after they suffered a cyberattack.
-
🕵️ Threat Intel: Palo Alto says a new macOS ‘ClickFix’ campaign is tricking users into running terminal commands that downloads, mounts, and launches the Atomic macOS Infostealer malware. Google says it has uncovered new ‘StockStay’ malware belonging to the Russian Turla group (aka Secret Blizzard, or Venomous Bear). StockStay has been in development since December 2022 and primarily used against targets in Ukraine, though samples have also been seen in Italy, the Netherlands, Poland, and Germany. Push Security says threat actors are targeting cyber security firms with fake OpenAI invitations, inviting users to join a ‘poisoned tenant’ in the hope they will submit sensitive information to an attack-controlled instance.
-
🪲 Vulnerabilities: Squidbleed: A vulnerability in the Squid proxy server, affecting installations that handle plaintext HTTP, or terminate HTTPS requests, and have access to outbound FTP servers, leaked memory affects all versions up to 7.6 (CVE-2026-47729; 6.5/10; advisory). CISA has added three critical Ubiquiti vulnerabilities to its KEV list (CVE-2026-34908, -34909, -34910 were patched in May).
-
🧑💻 End user and consumer: Microsoft has pushed the end date of its Windows 10 Extended Security Updates programme back by 12 months, to 12 October 2027.
-
🧰 Guidance and tools: The White House has shortened its deadline to move to post-quantum cryptography for “high-value assets” and “high-impact systems” to safely exchange encryption keys and create digital signatures by 31 December 2030 and 2031, respectively.
-
🛠️ Security engineering: Akrites: An industry group has been formed to tackle the growing number of vulnerabilities in open source projects. Led by the Linux Foundation, other members include Anthropic, Microsoft, AWS, IBM, OpenAI, Cisco, and major US banks. Mozilla’s Zero Day Initiative says a seemingly benign GitHub repository could result in the compromise of developer workstations despite containing no malicious code. The attack relies on a Python package that refuses execution unless it’s been initialised and, during that step, a command is retrieved from a DNS TXT record. Because the initialisation command is suggested as a way to overcome stalled execution, AI systems like Claude Code automatically run it when trying to recover from the error.
-
🏭 Operational technology: Deutsche Bahn, Germany’s state-owned rail operator, suffered a nationwide communications failure that left trains at a standstill in the early hours of Wednesday morning. The disruption occurred during the “scheduled replacement of a technical component”, rather than a cyberattack, but highlights the fragility of the critical network. Australia’s Security and Intelligence Organisation (ASIO) says that nation-state actors gained unauthorised access to a “critical infrastructure provider” and were mapping out the environment to ensure persistence so that operations could be sabotaged at a future point. NIST has published guidance (PDF) on for water utilities using remote access solutions, unsurprisingly including MFA, logging, network segregation, and regular updates.
-
🧿 Privacy: The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)has cancelled a controversial geolocation contract with Penlink that used ad-surveillance tech to track Americans. An interesting long-read on a 2016 initiative between the UK’s Bristol City Council and Avon and Somerset Police force to combine data sets and score the local population of 300,000 against a variety of risk factors. The collaboration doesn’t appear to have been a resounding success, lithesome models to detect child sexual abuse being quietly abandoned and other ‘predictive policing’ models achieving less than 10% accuracy, and insiders worrying that, while “legal gateways” existed to share the data, “Legality is not the same as legitimacy”. The chief of Avon and Somerset Police has gone on to lead the College of Policing, which is overseeing the £75 million PoliceAI initiative.
-
📜 Policy & Regulation: The Federal Communications Commission (FCC) has voted to increase oversight of subsea cables, including bans on certain Chinese vendors, and regulation to “address vulnerabilities related to principal equipment, third-party service providers and other areas of concern”.
-
👮 Law Enforcement: Europol, Microsoft, and industry partners successfully mounted a takedown of SocGholish, Amaday (a botnet) and StealC (an infostealer), three cybercrime tools that shared 326 servers and 142 domains.
-
💰 Investments, mergers and acquisitions: AI governance and control startup Runlayer has raised $30 million Series A funding for its platform to identify prompt injection, block data exfiltration, and nudge employees to approved tools.
-
🗞️ Industry news: Oracle says AI “adoption and deployment” contributed to its 21,000 layoffs in the past year. The tech giant, whose debt has soared to $120 billion as it invests in AI data centres, noted that the departures may result in “reduced productivity” and “shortages of sufficiently skilled employees”. Sounds like it’s going great. CISA, which has been without a permanent director since January 2025, ‘needs about 600 new hires’, as reports surface that President Trump has met with a nominee for the role to lead America’s cyberdefence agency.
And finally
- Using employee benefits and time off for phishing tests is a surefire way to lose credibility in your security programme, especially if it means your organisation’s CEO has to start giving media statements. That’s what Canadian healthcare outfit Newfoundland and Labrador Health Services learned the hard way this week. Ron Johnson, interim CEO, said, “We acknowledge the approach taken in this particular exercise was not appropriate, and we sincerely apologize to employees, physicians, and union representatives,” after a phishing test promised employees additional time off.