This week

- Accenture downplays data breach
- Linux virtual machine escape vulnerability nets $250K payout
- UK financial regulators given powers over AWS, GCP, Microsoft and Oracle
- EU sues four member states for not implementing NIS2
- HalluSquatting and GhostCommit tactics against AI coding assistants and agents
Interesting stats
2,279 victims claimed by cybercriminal actors in Q2 2026, a 7% increase over Q1 2026, and 43% year-on-year increase from Q2 2025, with 40% of attacks are being conducted by one of five main ransomware groups, according to GuidePoint.
Five things
-
Accenture has experienced what it calls an “isolated matter” that has been “remediated at source”, carefully avoiding the words ‘data’ and ‘breach’, following an “Accenture Data Breach” listing on a cybercrime forum. The criminal claims 35GB of internal data includes source code, SSH keys, personal access tokens, and cloud credentials are included from the consulting and digital transformation firm. Spokesperson Peter Soh downplayed events, saying “There is no impact to Accenture operations and service delivery.” Time will tell what it means for Accenture’s customers.
-
Januscape: Google has paid $250,000 for a Linux vulnerability that allows a guest virtual machine user to escape to the host operating system. The vulnerability, CVE-2026-53359 (write-up), lay dormant for around 16 years and can be used to break out of the container, for example, in a cloud environment, and take over other VMs running on the same physical host. It can also be used on Red Hat-based distros to gain root privileges from an unprivileged user. For most cloud customers, your provider will patch the issue, though there may be some disruption.
-
The Mills Review, on behalf of the UK’s Financial Conduct Authority, has urged ministers to boost the regulator’s powers, saying “While AI has the potential to improve access, personalisation and efficiency, it could also amplify risks associated with fraud, cybersecurity, consumer harm and market concentration.” On Friday, the Bank of England and Financial Conduct Authority were both given “direct powers” over “critical third parties” to regulate AWS, Google Cloud, Oracle, and Microsoft. The tech giants welcomed the move — presumably you have scaled compliance functions at this point to handle multiple regulators in every jurisdiction anyway — and they will now have to conduct stress tests of systems and report cyber incidents and outages.
-
NIS2: The European Commission is taking Ireland, Spain, France, and the Netherlands to court for failing to implement its flagship critical infrastructure cyber security legislation. It’s been a long road, with few meeting the original 2024 deadline to transpose the directive into domestic law. NIS2 is an update to the original Network and Information Security Directive, published in 2016, extending the scope of those it covers and clarifying what compliance entails. Ireland says that its National Cyber Security Bill is almost finalised, while Spain, France, and the Netherlands hadn’t commented at the time of press.
-
Security researchers have devised a new technique they’re calling HalluSquatting (hallucination squatting). HalluSquatting takes advantage of AI assistants’ and agents’ tendency to hallucinate the names of tools and resources, registering these identifiers in popular registries and repositories and seeding them with prompt-injection commands to install backdoors and other malicious software. Ghostcommit similarly slips prompts into repositories by hiding the instructions in images, which are skipped by AI code checking tools but subsequently picked up by coding assistants like Claude Code.
In brief
-
⚠️ Incidents: GitLost: GitHub’s Agentic Workflows are vulnerable to prompt injection, allowing code from a private repository to be published as public comments on an issue. Japanese telco KDDI says over 12 million people are affected by last month’s breach of an email platform used by five ISPs, including the passwords of over 7.6 million of those users. US insurer AssuranceAmerica says it’s suffered a breach of personal and driver’s license information affecting 6.9 million people. The insurer identified the breach in mid-March after attackers “targeted one of the Company’s employees”. Threat actors gained access to Dutch retailer Miinto’s internal ordering system and accessed an unknown number of records. Philips Hue has released an update that bricks customers’ Hue Bridge Pro devices. The electronics company is offering replacements for those affected by firmware 2071353020; however, users are frustrated with the prospect of re-pairing all of their smart lights. The US Army has fixed two websites that were compromised to display pro-Kurdish messages on the 404 error pages.
-
🏴☠️ Ransomware: ShinyHunters has stolen data on 2.3 million people associated with Moody Bible Institute, including name, gender, dates of birth, physical and email addresses, phone number, and marital status. Medtronic has begun notifying over 3.8 million people of an April breach that it originally said didn’t appear to have “connections to our customers”.
-
🕵️ Threat Intel: Proofpoint says that a Chinese group has been targeting ‘dozens’ of universities running the RoundCyber email system to gain access to academics’ mailboxes, and potentially onwards to other accounts and systems. Threat actors are exploiting a critical authentication bypass (CVE-2026-20896; 9.8/10; advisory) in Gitea, with the official Docker image’s default configuration being vulnerable. Progress Software is emailing its ShareFile customers and telling them to shutdown their servers following a “credible external security threat” for those who use Storage Zone Controllers. Australia’s cyber security agency is warning of a global campaign exploiting content management systems, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE.
-
🪲 Vulnerabilities: Ubiquiti has patched seven critical vulnerabilities in UniFi OS, including a max-severity command injection issue (CVE-2026-50764; 10/10; advisory).
-
🛠️ Security engineering: France’s cyber security agency, ANSSI, will stop certifying security products that lack quantum-safe cryptography from 2027.
-
🧿 Privacy: Sainsbury’s will roll out facial recognition tech to up to 200 stores by the end of 2026 to help combat shoplifting. The UK supermarket says 90% of people identified by a trial of the Facwatch system did not return to the store. Facewatch’s customers also include Budgens, Spar, and Sports Direct. Privacy campaigners have branded the move “shameful” and urged shoppers to take their business elsewhere.
-
📜 Policy & Regulation: The European Commission has published a plan to reduce reliance on foreign artificial intelligence, though it admits that it lacks scaled domestic cloud and AI businesses. Still, the EU is worried that frontier models are governed by “provider-specific and often non-European decisions” and that “contingency measures in case of restricted or withdrawn access” are needed.
-
👮 Law Enforcement: Law enforcement agencies have arrested 5,811 suspects and seized $293 million in assets in Operational First Light 2026, which spanned a whopping 97 countries. The operation, which identified over 142,000 victims, was coordinated by INTERPOL and funded by China’s Ministry of Public Security.
-
💰 Investments, mergers and acquisitions: Barracuda has acquired Evo Security to bolster its SMB services.
-
🗞️ Industry news: The NSA is reviving its Tailored Access Operations unit. NCSC has revealed plans to build an AI ‘Cyber Shield’ to defend the UK by scanning and fixing vulnerabilities at a national scale. Over 60 businesses have signed up to the UK government’s Cyber Resilience Pledge.
And finally
- A former DigitalMint employee, tasked with negotiating with ransomware gangs, has been handed a 70-month federal prison sentence for colluding with Alphv/BlackCat ransomware operators. Angelo Martino “provided the cybercriminals with confidential negotiation information to maximize the ransoms in exchange for a portion of the ransom payments,” with him helping to extract $75 million in ransom payments from the organisation’s he was meant to be helping.