Robin’s Newsletter #424

9 August 2026. Volume 9, Issue 32
More AI agent incidents surface. Iranian attacks on US water expand. $88 million stolen via flaw in hardware cryptocurrency wallets.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

A slightly cut-down format this week as I’m travelling.

Interesting stats

85% (2024: 17.7%) of Resilience’s incurred losses stem from exploiting human error (phishing, social engineering, transfer fraud), according to the insurance company who attribute the rise to AI making traditional techniques more effective against victims.

1/3 of dangerous AI coding agent requests were approved by humans in the loop, according to 40,000 runs of a simple online game published by a Belgian software developer.

26% is the average success rate for AI patch generation — using both ChatGPT 5.5 and Claude Opus 4.8 — that fully resolves the vulnerability, without materially changing application behaviour, according to researchers at 1Password. 

In brief

  • Irregular is the common denominator between the attacks conducted by OpenAI, Anthropic, and Meta AI agents during testing. The “first frontier security lab” seems to be the one responsible for the poor security surrounding frothier model evaluations, describing all three as subject to “the exact same evaluation-environment issue”. Irregular wasn’t responsible for the tests carried out by the UK’s AI Security Institute, which admitted that it too had accidentally unleashed AI agent cyberattacks on the world. During 10 out of the 122 test runs carried out by AISI, the agent being tested took “autonomous, unsanctioned action on the live internet, targeting real people and organisations”. Chinese model maker Kimi also says that its Kimi K3 model has been rummaging around the internet and breaking into organisations. Remarkably, in all of these cases, those in charge of testing the models are not properly monitoring and supervising the tests. And also that they’ll be so open about their potential crimes.

  • US Water attacks have expanded to twelve states, resulting in some temporary disruption and ‘boil water notices’ while manual processes kicked in and safety tests were carried out. Consumer impact has been limited, though I’m sure that this campaign, widely reported to be carried out by Iran-linked groups, will be seen as a significant shot across the bow by US agencies. The US is distinct in its large volume of small, municipal water companies that have long been identified as a potential cyber risk, including the exposure of thousands of programmable logic controllers (PLCs) and control systems that are unnecessarily exposed to the internet.

  • Pass-ta-key: Researchers at Palo Alto Networks have developed a technique to abuse Google’s Password Manager, extract passkeys and bypass user verification on devices with an existing malware infection. The malware can use Chrome and the device’s Trusted Platform Module (TPM) to sign a request to Google’s cloud authenticator, without needing admin privileges, user interaction, or even unlocking the device. Obviously, in this instance the device is already compromised with malware, but gaining access to Passkey private keys can allow an attacker to authenticate from another device and maintain that access without risking further detection. 

  • ExfilSquad has published the contact data of over 100,000 police officers on the dark web that it stole from a compromise of the UK’s Police National Legal Database (PNLD). The full names, organisations, and email addresses of police officers, staff, criminal justice professionals, and government partners have been exposed.

  • North Carolina Ports suffered a cyber security incident on Tuesday that forced a shift to manual operations. A spokesperson told Recorded Future News that “the breach has been contained, and we are now in the recovery process” and “following a normal operating schedule”.

  • Apple has launched a new legal challenge against a UK government Technical Capability Notice for it to ‘backdoor’ its encryption to access customers’ iCloud data. 

  • Microsoft says that a Russia-linked group, believed to be the country’s Foreign Intelligence Service (SVR), has been compromising hotel Wi-Fi networks and using captive portal login pages to steal Microsoft credentials and infect devices with espionage malware. 

  • Attackers have stolen 31,000 records detailing the beneficial owners of companies formed in Liechtenstein, a small European country popular with financial services for its historical role as a tax haven.

  • Attackers compromised 440 npm packages, which Wiz says are present in more than 46% of all cloud environments. The packages pushed a version of the Mini Shai-Hulud malware that TeamPCP open-sourced earlier this year, which harvests CI/CD credentials, AI config files, and cryptocurrency wallets, amongst other sensitive information.

  • Three flaws in Apple’s iCloud Private Relay can cause WebKit to make connections that circumvent Apple’s proxy and reveal the user’s IP address.

  • Law enforcement: Maksim Silnikau, 40, a Belarusian cybercriminal, has received a 16-year prison sentence for his role running the Ransom Cartel ransomware gang. Also this week, Connor Moucka, a Canadian, has pleaded guilty to a role in the compromise of 165 Snowflake customer data lakes, from which he earned $495,000 by extorting his victims.

And finally

  • Coldcard: More than $88 million in Bitcoin was stolen from users of a hardware wallet. Coinkite, manufacturer of the Coldcard, which is meant to protect cryptocurrency by storing it in an offline wallet, says that a firmware issue is to blame for a weakness in how they generated cryptographic seeds to protect users’ funds. Rather than using the hardware random number generator in the device, a deterministic software version was used with no entropy. Knowing the UID, timer state and call history results in a deterministic seed for the wallet. Apparently, the flaw was due to a rewrite of the wallet’s code years ago to strip out GPL open source code. Cryptocurrency users view hardware wallets as the gold standard to protect their value, leaving more than a couple scratching their heads and wondering who and what to trust. (Banks solved this problem?). I suspect whoever stole the funds did it because they could, rather than to benefit from the funds: blockchain transactions are traceable, making it easy to follow the stolen money.
Robin
  Artifical Intelligence (AI) Software supply chain Water Critical National Infrastructure (CNI) Iran Passkeys Irregular Surveillance Technical Capability Notice (TCN) Shai-Hulud Cryptocurrency