This week
This week marks Cydea’s 7th birthday. I founded the company back I n2019 to bring the world more positive security. Over 30 people have been part of the team in that time, delivering over 250 projects to customers starting with every letter of the alphabet but X (please get in touch if you can help with this! 😉). A big thank you to all colleagues, customers, and collaborators past and present!

- ID Scan source of 150 million breached driver’s licenses
- Backlash against LG harvesting data from smart TVs for advertising purposes
- Revolut handed over customer data to fraudulent requestor
- Apple’s ‘audio intelligence’ feature tests its privacy footing
- Peers question why CSRB doesn’t include personal liability for execs
Interesting stats
85% of CISOs told Proofpoint that ensuring the safe use of AI assistance, copilots, and other automation is a top priority over the next two years, 8/10 of them say they’re being expected to do so without receiving a proportional increase in resources LINK … meanwhile… 10% chance that AI “could kill all humans” in the next decade, says one of Anthropic’s top safety researchers
Five things
-
ID Scan has confirmed it is the source of a data breach comprising 150 million drivers’ licenses. The original compromise apparently occurred over a year ago, and the Louisiana-based company says the information includes full names, license numbers, and other government-issued identity documents provided to verify people’s identities. This is a staggeringly large breach, and the fact that it was ongoing for so long also suggests pretty poor monitoring within the firm’s production infrastructure.
-
Smart TVs from LG are harvesting audio and watching habit data to target ads. “Automatic content recognition” has been a known thing for a while, and works by analysing the content on the screen, meaning it can detect things you may be playing from an HDMI source, not just reporting the channel selected in the EPG. This is a whole new class of potentially invasive techniques, including the apparent buffering of audio recordings while the device is offline to upload once a connection is reestablished. LG has refuted the claims, saying audio is only recorded following a ‘wake word’ or when a button on the remote is pressed. I haven’t verified the claims; however, the wake word/button doesn’t appear to be pressed in the video published by the security researchers. Most tellingly, regardless of the claims, LG’s terms (and industry marketing videos) say they “own the glass” in its TVs and all the data associated with what you watch on them in your living room.
-
Challenger bank Revolut handed over sensitive customer data to threat actors who sent fraudulent requests from emails on a legitimate government domain. The fintech says the number of customers affected is “limited”, but not how many or by what. The information included names, DoB, post, email, and phone contact information, plus identity documents, account statements and transaction histories. Thousands of law enforcement and other government agencies globally may have legitimate reasons to request data. This is a failure to verify the requestor’s authenticity properly.
-
Apple debuted a new ‘audio intelligence’ feature for its newest smartwatches that will listen to conversations and provide high-level recaps. The Cupertino-based company has gone to great lengths to try and reassure people that the feature is optional and audio recordings aren’t stored or shared. Apple has made privacy a point of differentiation from competitors like Google, so this feature jars with that positioning.
-
Cyber Security and Resilience Bill: Peers in the House of Lords have questioned why personal liability doesn’t feature in the UK’s forthcoming cyber legislation. Punishment for non-compliance is proposed to be up to £17 million, or 4% of annual turnover (whichever is greater). But Baronesses Kidron and Ludford backed looking at changes to introduce personal civil liability for CNI executives who are complicit, through deliberate action or careless neglect, in failing to adequately secure their organisations. Adding to the debate, Lord Clement-Jones said: “If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it.” I agree: culture starts at the top, and an additional tool in the enforcement toolbox seems useful.
In brief
-
Reporting and other requirements of the EU’s Cyber Resilience Act came into force last week. Products with digital elements sold within the EU must submit early warning of any actively exploited vulnerabilities within 24 hours of becoming aware, with a more detailed notification following within 72 hours. The remaining regulations, such as maintaining a mandatory software bill of materials (SBOM), will take effect next year.
-
The UK National Audit Office says cyber security is a major threat to the UK food supply chains following an investigation in the wake of high-profile cyber attacks against Marks & Spencer and the Co-op last year. “The way the food supply chain has developed over time has prioritised efficiency, [reducing cost]… However, it leaves the supply chain more vulnerable to disruptions.” NAO is calling on Defra and industry to work together on cyber resilience and learn from approaches taken in other countries.
-
Google says that cybercriminal groups focussed on data theft are looking for proprietary AI data and models to extort payment from their victims. As with any intellectual property, there is value here, and I think that AI models are more portable and potentially easier to integrate than, say, a stolen code base.
-
The FBI has published a Cyber Strategy (PDF) to guide how the agency will fight cybercrime. The strategy is built around four ‘pillars’: investigate, disrupt, and impose code on cyber adversaries; support victims; use partnerships to increase impact; and attract and build top talent and technical tools.
-
CIA Deputy Director Michael Ellis says that cyber operations provided a “flawless intelligence picture” that enabled the US capture of Venezuelan President Nicolás Maduro in January this year. That likely involved gaining access to intelligence on Maduro’s bunker, staffing rotas, or CCTV and other monitoring systems that let the US military build patterns of life and track exactly where the president was.
-
Jaguar Land Rover plans to cut 4,000 jobs over the next two years. The move follows a shutdown caused by a cyberattack last year, but is primarily driven by other economic and industry factors, not the incident: rising competition from China, Brexit, US tariffs, and a lack of electric vehicles in its line-up.
-
A bunch of AI-related stories: Researchers say OpenAI agents uploaded 2,000 malicious packages to RubyGems in May. Anthropic says that it’s detected and disrupted Russia’s _Midnight Blizzard_ using Claude in a campaign to compromise hotel Wi-Fi provides. In the same report, the Claude maker said users had managed to defeat safeguards intended to prevent the AI from helping with the development of biological weapons. The US has accused six Chinese firms of conducting “industrial-scale distillation against US AI models” to cut costs of their own AI model development. Anthropic chief Dario Amodei called for the pace of AI model development to slow down. Sam Altman and Elon Musk followed suit. I think that ceased being a possibility when AI became a ‘US vs China’ national interest thing. See also, 10% chance self-learning models decide we’re surplus to requirements in the next decade, above. Just another week in artificial intelligence!
-
Vulnerabilities: AI has killed security through obscurity: Microsoft’s Patch Tuesday contains fixes for 972 vulnerabilities, including 112 critical-severity issues. Adobe has fixed a critical zero-day in Magento and Adobe Commerce platforms (CVE-2026-75650; 10/10; advisory). SAP has fixed a maximum severity issue dubbed ‘OVERPASS’ in its SAP Kernel code (CVE-2026-44756; 10/10; advisory). GitLab also has a max-severity path traversal vulnerability that may allow unauthenticated attackers to read credentials and secrets (CVE-2026-85706; 10/10; advisory).
And finally
- Starting next month, US airlines won’t be obliged to provide meal vouchers or hotels for delays or cancellations to flights resulting from a cyberattack.