This week

- UK Gov reviewing “home defence” resilience plans; granting itself powers to block foreign tech.
- Alabama AG opens investigation into OpenAI hacking spree
- Manchester Airport Group data breach affects 8.7 million passengers
Interesting stats
X% your personal estimated identifiability, according to a diagnostic tool created by a researcher to show how identifiable you are (or aren’t!), based on common fingerprinting techniques used by data brokers and ad tracking firms to follow you around the internet: Glassbox.
~Five~ Three things
-
The UK government is revising “home defence” plans and will urge citizens to store bottled water and tinned food to boost resilience against extreme weather events and cyber threats. The government also made amendments to the Cyber Security and Resilience Bill, currently at committee stage in the House of Lords, to give itself powers to block technology suppliers deemed to be a national security risk. The powers change those used to keep Huawei gear out of the UK’s 5G core networks and allow the government to order a company (e.g., a telco, water, or electricity company) not to use a specific vendor. The vendor wouldn’t need to be notified and can be subject to non-disclosure, preventing public discussion of the order. In a similar move, this week the Trump Administration banned foreign-made equipment from power generation and electricity management systems, because “certain foreign actors are increasingly creating and exploiting vulnerabilities”.
-
Alabama has launched an investigation into OpenAI’s compromise of Hugging Face, with the state’s attorney general citing the alleged “complete lack of oversight and adequate safeguards” in a subpoena to the AI firm. OpenAI has admitted that its agents managed to gain internet access 11 days before it started attacking Hugging Face on 11 July, and the company didn’t notice the issue until over a week later on 19 July, all the time a ‘squad’ of around 700 agents were communicating on an improvised message board, via “disallowed internet access” but for which OpenAI staff decided there was no need to stop the test.
-
Manchester Airport Group, which owns Manchester, London Stansted, and East Midlands airports, says attackers have stolen the personal data of 8.7 million passengers. While “at no point has passenger safety or aviation security been compromised,” data captured for car park, lounge and fast-track bookings, and airport wi-fi access was accessed. Payment and bank details were not held on the affected system. A group calling itself FulcrumSec has claimed responsibility and says it pilfered 86GB of data.
In brief
-
Cyber security company ReliaQuest has confirmed ShinyHunters gained “read-only” access to its Okta SSO tenant, but other security controls blocked that unauthorised access to data and applications. The attack comes after RQ posted a (now-deleted) blog post detailing the current tactics used by the cybercrime group.
-
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a “major incident” following the Qilin ransomware gang adding the DOJ unit to its leak site. The ATF says it was a compromise of a “standalone computer system”; however, it also contained “information about targets of ATF investigations”.
-
HIV charity George House Trust is warning that cybercriminals may have stolen “sensitive and personal” health information during a recent cyber incident, though there is “no sign” of the data being misused at this time.
-
Over 100 internet-exposed systems were targeted during July attacks against US water and wastewater systems, according to CISA. See Cydea’s OT risk advisory for CNI companies.
-
CISA has given federal agencies just three days to patch a max-severity Oracle vulnerability. CVE-2026-21962 (10/10; advisory) was originally patched in January, and now added to CISA’s KEV list.
-
Ubiquiti has patched three ‘perfect 10’ vulnerabilities: an input validation in its video surveillance application, authentication bypass on UniFi OS devices, and command injection on its UniFi Talk VOIP system (CVE-2026-77537, -77550, and -77554 respectively; all 10/10; advisory)).
-
ServiceNow has also patched three perfect-10s covering code injection, SQL injection, and privilege escalation in its Now Platform PaaS offering (CVE-2026-18885, -18886, and -74820; all 10/10; advisory).
-
Printer management software PaperCut has patched two vulnerabilities being exploited in attacks (CVE-2026-82078, -81578; both 8.8/10; advisory).
-
Australian law enforcement have charged two men in Perth, Western Australia with 14 offences relating to the TeamPCP supply chain attacks.
-
The right-wing populist party Reform UK says it will scrap the UK’s General Data Protection Regulation (GDPR), if elected to government, and replace it with a New Zealand-style model. Reform says any changes will meet EU adequacy requirements, meaning they must have similar protections, so I don’t see how something similar can make a dent in the “suffocating EU red tape” they’re worried about.
And finally
- AliExpress has been caught using an audio fingerprinting technique to profile and track site visitors. Audio fingerprinting is a bit old-hat, and there are plenty of other methods that can pretty accurately fingerprint you as you browse around the web. (See Glassbox, above). Related to ad tracking: Monitor vendors like LG and Samsung are bringing new ‘smart monitors’ to market that run the same operating systems with ‘automatic content recognition’ (ACR) as their smart TVs, potentially paving the way for advertising to you based on the content you view on your computer monitor. No thanks.