Robin’s Newsletter #420

5 July 2026. Volume 9, Issue 27
Antrhopic models available agin, while others can be used to create ransomware. EU-US data transfers in jeopardy following Supreme Court ruling.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 5th July 2026

  • Anthropic reaches agreement with US gov to restore access
  • DeepSeek will ‘happily’ create ransomware for you
  • EU-US data transfers in jeopardy following Supreme Court ruling
  • Cyber company sued over potential hallucinations, poor research attribution
  • Is it time to look at cyber security mission creep?  

Interesting stats

9% (a big drop from 2025’s 29%) of organisations are open to a purely automated security scanning approach, in part because 78% of security teams report “critical false negatives” from such tools, according to Cobalt.

37% increase in Google’s electricity use in 2025, mostly down to AI, according to the Mountain View company’s sustainability report.

55% (2025: 58%) of 1,200 IT and security professionals have been asked to keep a breach quiet, according to Bitdefender.

70% of UK consumers say they won’t tolerate more than one day of disruption following a cyber incident, according to TalkTalk Business, which also found that  32% of those surveyed would stop using a service following a breach, with only  4% saying an incident wouldn’t influence their future behaviour.

£488,000 ($653,000) is the average loss from a cyber incident, according to Grant Thornton, who say  79% admit cyber risk ownership remains unclear and only  7% of boards have cyber expertise.

Five things

  1. (and 2.) AI Cyber Roundup: The White House has lifted its ban on Anthropic’s latest Mythos and Fable models, after the Claude maker agreed to “proactively detect and address security risks associated with the models”. It comes hot on the heals of Anthropic accusing China’s Alibaba of conducting a distillation attack against its models (and Alibaba banning employees from using Claude). Anthropic has painted itself into somewhat of a corner with its warnings over the capabilities of its newest models, and pushing for them to be regulated. Meanwhile, other models, such as DeepSeek, another Chinese model, lack the same level of safeguards. Researchers from Check Point say they have identified over 1,800 malicious software samples attributed to DeepSeek that have been uploaded to VirusTotal in the past year. One such sample was a browser-based ransomware sample that could be “transformed into a fully functional attack with minimal effort”. Also this week, Sysdig says it believes a large-language model (LLM) conducted a JadePuffer ransomware intrusion, performing reconnaissance on the victim, stealing credentials, moving laterally, establishing persistence, and elevating privilege so it could encrypt data. The direction of travel is clear here: the big, main (Western) models — your ChatGPT, Claude, and Gemini (sorry, CoPilot) — are not likely to be the threat here. Instead, it will be others, and particularly smaller, more specialised, local models that may lead to the sorts of attacks Five Eyes intelligence agencies warned about last week.

  2. EU-US Data Transfers: The US Supreme Court granted President Trump powers to remove the heads of ‘independent’ US agencies and regulators this week, potentially undermining the legal framework governing the transfer of personal data from the EU. The European Commission adopted the EU-US Data Privacy Framework in 2023, and it requires an independent US body to provide oversight. If the President can hire/fire the heads of organisations like the Federal Trade Commission (FTC) at will, then the independence of those bodies can be called into question, something activist Max Schrems has vowed to file a legal case arguing. Schrems has form: having won against Meta and invalidated the previous EU-US Privacy Shield framework.

  3. Attribution: MeetingTV is suing Koi Security, recently acquired by Palo Alto Networks, over (now deleted) claims that its Zoomcorder meeting recording service was a “public-facing front” for a Chinese espionage operation. According to MeetingTV, Koi’s security researchers did not approach the company for comment before publishing their research and have refused to supply information about the “Twitter X Video Downloader” browser extension, which Koi says links Zoomcoreder to the Zoom Stealer campaign. It’ll be interesting to see how the case plays out. The lawsuit claims the threat intel report was generated by AI and may have hallucinated the link. The damages sustained because security controls now block the company’s services are pretty tangible and should give TI firms something to think about in edge cases.

  4. Mission Creep: This paper, due to be published in the University of Illinois Law Review, is an interesting read. It argues that “Cybersecurity is experiencing mission creep” with many public policy issues being reframed as ‘cyber’ issues. Think misinformation, child social media safety, and so on. I’m quite sympathetic to the position: a lot of ‘cybercrime’ is confidence scams that are happy to be carried out in cyberspace rather than in person. The Internet and technology have made it much easier for criminals to reach a global audience, while de-risking their capture by perpetrating these crimes across borders from locations lacking extradition treaties. Is the cyber label an aberration, caused by tech outpacing lawmakers’ understanding? Would we benefit from a more conscious effort to move issues away from technology and back into the domain of their consequences?

In brief

And finally

  • A good read, from Bruce Schneier, who makes the historic comparison to L0pht group’s congressional testimony against the AI threat that Five Eyes intelligence agencies warned about last week, as AI reduces the skill needed to conduct cyber-attacks.
Robin
  Artificial Intelligence (AI) Mythos China Ransomware EU-US Data Transfer CitrixBleed Geofence Geolocation