This week
I’ve been away this weekend helping at a large Scout camp for young people, so this week is an abridged round-up before I go and sort out our group’s kit (fortunately mostly dry, as the weather was kind!).
Interesting stats
57% (2025: 49%) of UK businesses report a basic cyber skills gap, and 53% of cyber firms expect to grow their workforce in 2026, with 145,900 individuals being employed in cyber across the UK, and £30,001-£35,000 being the median graduate salary, 15 months after graduating, according to DCMS & DSIT.
Five things
-
FBI v. ShinyHunters: The FBI has declared a “cyber security incident” internally, telling staff that personally identifiable information, including names, addresses, job titles, and Social Security numbers, has been exposed during the breach claimed by the ShinyHunters cybercrime group. The BBC and Reuters report, respectively, that blood and urine and psychiatric reports have also been stolen. This is, as Lawfare put it, a counterintelligence disaster. Notably, the FBI hasn’t notified Congress yet, which is required for a ‘major incident’ that may harm US national security. ShinyHunters maintain they don’t want money; rather, they want the FBI to change a threat intelligence report describing the group’s activities. Dutch National Police arrested one of the alleged ringleaders on 15th September, and the FBI says “a large amount of information was found on his laptop”, going further and suggesting other members of the group turn themselves in. In a video, FBI Cyber Division Assistant Director Brett Leatherman said, “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
-
OpenAI: OpenAI says it will not released its GPT-6.1 ‘Astra’ model because efforts to address “model laziness” meant it “it didn’t quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it’s done,” according to head of safety systems Saachi Jain. It comes as the frontier lab acknowledged that it’s informed ‘more than 100 organisations’ about incidents involving its AI agents, and a technology safety group filed a lawsuit claiming the company violated California’s Comprehensive Computer Data Access and Fraud Act (CDAFA). OpenAI has delayed its planned initial public offering until it’s confident that it can “make confident safety decisions,” according to CEO Sam Altman. A new fundraise, reportedly of $30 billion on a $1.4 trillion valuation, would bridge the gap. Notably, though, Altman also said this prioritisation of safety was so that the next stage would be “without people debating what percentage chance we’re going to do all these bad things in the world”. It’ll be interesting to see if it’s confidently walking the walk, or (not) talking the talk that wins out. Side note: If you’re a developer using AI then it’s worth checking where your agents are storing any screenshots or images they’re generating: around 13,000 (and growing) internal screenshots, potentially containing sensitive data, that have been uploaded to public repositories of 343 companies by AI agents trying to be helpful.
-
Mass Surveillance: Flock, the controversial automatic license plate readers (ALPR) deployed in many US cities, has been ruled ‘indiscriminate mass surveillance’ by a federal judge in Oklahoma. Meanwhile, the United States Postal Service (USPS) is running a pilot to put cameras on its delivery vans. A spokesperson told 404 Media that the pilot will “assess whether vehicle-mounted cameras can help identify roadway conditions and support community safety”. In the UK, British Transport Police (BTP) ran a £320,000, six-month pilot of live facial recognition technology at London railway stations and, across 18 deployments and 500,000 facial scans, got only a single alert which turned out to be a false positive. BTP says it will extend the trial for a further four months.
-
Meta mistrust: Researchers have extracted internal files and prompts behind Meta’s Muse personal AI assistant and found that, surprise surprise, it’s prompted to build profiles on everyone in your life. That is, in some way, the point of the assistant, though it draws attention due to Meta’s sketchy past with the data it collects and how it has processed and shared that data for commercial purposes. Facebook is hugely data-hungry. Each file is part of the assistant’s ‘memory’ and is updated hourly with information on where the person lives, what they do, recurring conversation themes, relationship history, and important dates like “the trip in March, the argument that got resolved”. Remember, if you’re not paying for it, you’re the product. And so too are your nearest and dearest.
-
Bye-bye ‘er’! The UK’s data protection regulator has had an overhaul, following the Data (Use and Access) Act 2025, the Information Commissioner’s Office has been replace with the Information Commission, which is to be known as the Information Commission’s Office. This is more about the organisation’s governance than responsibilities: most folks will not notice any difference, though the ICO will be moving to a new location in Manchester.
And finally
- To-do list: patch: Citrix Netscaler ADC/Gateway (CVE-2026-88771 and 88772; both 9.5/10; advisory); Fortinet FortiMail (CVE-2026-104286; 9.8/10; advisory); Dell Container Storage Modules (CSM) quintuple-whammy (CVE-2026-63688, 63692, 67269, 54472, 61421, 67273; 10, 10, 9.9, 9.8, 9.8, 9.6 /10 respectively; advisory); GitLab AI Gateway (CVE-2026-90970; 9.9/10; advisory); MikroTik RouterOS (CVE-2026-84411; 9.8/10; vendor sec. info).