Robin’s Newsletter #422

19 July 2026. Volume 9, Issue 29
EU fingers Russia in Poland grid attack. Australian health data breah. Using prompt injection against adversaries in 'context bombing'.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 19th July 2026

  • EU blames Russia for Poland grid attack
  • Australian medical records breached at large provider
  • Adversaries using spoofed app IDs to probe Entra creds
  • South Korea is building a cyber vulnerability AI
  • Using prompt injection against attackers in context bombing

Interesting stats

55pp decrease (to 5%) in successful admin privilege escalation, and  35pp decrease (to 1%) in establishing persistence across five models and 152 attack runs by Tracebit, when using ‘context bombing’ prompt injections to help defence (see Five Things, below). LINK

570 security issues addressed in Microsoft’s July Patch Tuesday update, including  59 critical vulnerabilities, of which  48 of these criticals were remote code execution (RCE) flaws. The bumper update is the result of Microsoft using AI to find bugs

$100 and 1 hour were all that a lecturer at Manchester Metropolitan University needed to poison an open-weight AI model. 

Five things

  1. The EU and UK have blamed Russia for attacks on Poland’s electricity grid and water treatment facilities, naming the Federal Security Service (FSB) ‘Centre 16’ as the culprit, and have imposed sanctions on ten individuals. France has released details of the Turla Intrusion Set and a broader coalition of Western allies, led by the United States, has published a guide on improving router hygiene (PDF). The guide includes some specific steps to harden Cisco devices and lock down SNMP. The Sandworm group has also begun using fake CAPTCHA’s and ‘ClickFix’ tactics against Ukrainian targets. Russia’s attempts to compromise power grids shouldn’t come as a huge surprise: cyberwarfare differs from its kinetic counterparts in that it often involves pre-positioning or ‘defending forward’ to gain access to the infrastructure of potential targets in advance to map them out and understand how the systems work, in much the same way as aerial and satellite imagery is used to provide intelligence for kinetic attacks. It’s always useful to have tangible examples to point at rather than hypotheticals, and energy and utilities organisations should pay attention.

  2. Australians’ medical records were accessed by a “malicious actor” on 23 June, after an incident at Partnered Health, one of the country’s largest healthcare providers. A company spokesperson would not disclose the number of people affected by the data compromise, which includes treatment details, medical notes, referral letters, pathology results, insurance details, names, addresses, dates of birth, and more.

  3. Proofpoint says that attackers are testing Microsoft Entra credentials and circumventing conditional access policies by faking the ‘client ID’ of an OAuth application, resulting in blank entries in Entra’s logs that security teams may overlook. In one campaign earlier in the year, Proofpoint said 3.7 million fake client IDs were used in attempts against 2 million users. Security teams can look for Entra error code AADSTS700016, which shows an unrecognised application ID was detected. (Even better, Microsoft could screen for these before passing them through for authentication and save everyone a bunch of effort!)

  4. South Korea is developing its own AI model to help find security bugs that it hopes to have online by the end of the year. The move follows the US suspending access to models like Anthropic’s Mythos to foreign nationals. 

  5. The folks at Tracebit (shout out to Andy 👋) have found that defenders can use prompt injections to foil attackers using AI in their attacks. So-called context bombing works by including instructions to trigger guardrails or refusals from LLMs. For example, alongside credentials or API keys, asking for steps to produce anthrax spores or about ‘Tank Man’ to defat Chinese models. The Tracebit team have had some positive results in their testing (see Stats, above).

In brief

And finally

  • The US has launched a clearinghouse, dubbed Gold Eagle, to facilitate the disclosure, prioritisation, and remediation of vulnerabilities discovered by AI. CISA  is involved, but the Treasury Department leads Gold Eagle. Feels like something that could squarely have fit within CISA’s wheelhouse.
Robin
  Russia Operational Technology Electricity Grid Cyberwarfare Health Data Entra Artifical Intelligence (AI) Prompt Injection Context Bombing ClickFix