Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc. The UK-based think tank said in a report today that the EU should develop a new risk assessment framework that applies to all members and strengthens its own powers, without encroaching on members’ rights to set their own national security policies. It must delicately balance the need to secure the union, while maintaining the flexibility that both allows members to set domestic policies and lawmakers to account for different risk profiles across different sectors. The risks affecting telecoms will not necessarily apply to other sectors in the same way. Speaking of telecoms, currently there is only the voluntary EU Toolbox for 5G Security framework – voluntary being the operative word here, as only 10 of 27 members have fully implemented it since it launched in January 2020. On paper, it somewhat sets out to achieve what RUSI is calling for: a harmonized set of standards to mitigate 5G-related security risks affecting member states. Addressing the frustration over the lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to build a list of untrusted vendors that members must preclude from the networks of 18 critical sectors. If passed, any countries using equipment from designated vendors would be forced to rip and replace it within 36 months. The EC has already indicated that it would suggest Huawei and ZTE be listed, should the amendments pass. But before the EU gets busy listing vendors it considers high-risk, it first needs to decide what a high-risk vendor even is. There is still no official definition, nor is it a legal category, and at present, it allows countries to wangle their way around these descriptions to buy the tech they want, bypassing whatever scrutiny may come their way should the CSA amendments come into force. RUSI’s researchers used Germany, Spain, and the UK as examples of how three countries can treat foreign tech vendors, such as Huawei and ZTE, very differently. Germany’s most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) annually, and historically the Bund has opted to preserve these valuable economic ties in favor of reducing supply chain risk. Under Chancellor Friedrich Merz, this is slowly changing, although RUSI does not expect to see a material shift in the makeup of Germany’s 5G RAN stack in the near future. Chinese suppliers accounted for an estimated 59 percent of the country’s 5G RAN in 2024. Chinese equipment accounted for an estimated 32 percent of Spain’s 5G RAN in 2024, although that share is expected to shrink. The debate intensified after last year’s controversy, when Spain awarded Huawei a contract involving the storage of judicial wiretap recordings. Spain’s past procurement decisions have shown it to often favor the most cost-effective option, and its government does not share the same national security concerns about China as the UK or US, or at least not to the same degree. The UK, meanwhile, looks set to completely eradicate Chinese technology from its telecoms network by the end of next year, and has bent to the US’ vehement demands that Huawei is bad, bad news for Western geopolitical security. Real security risks RUSI stated that concerns about Chinese IT vendors “are well-founded,” and that it is true that the Chinese government can empower authorities to exercise control over companies like Huawei. This includes providing the state with data on demand, hosting Chinese Communist Party (CCP) representatives, and reporting activity that signals a threat to national security. There is an additional law that requires tech companies to not just report vulnerabilities to the country’s government within 48 hours of discovery, but also to withhold the same disclosure from China’s overseas counterparts, except for the product vendor. “This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities,” RUSI said. Factoring in all of this, the country has also demonstrated the willingness and capability to launch cyberattacks against the critical national infrastructure of political adversaries, according to RUSI. Technical security aside, China’s technological advancements introduce economic risks, too. In some cases, its vendors have developed more capable products than equivalents in the EU or US, and sold them at more attractive prices. This advantage makes it difficult for some countries to justify the extra expense on non-Chinese equipment. In building a global reliance on its products, China could then introduce “unwelcome dependencies,” or cement itself as a dominant player in crucial supply chains, RUSI noted. China has shown in recent years that it is willing to exercise this influence, such as when it threatened Germany with “consequences” for the two countries’ economic ties during the heated 5G debate of 2019. Would a high-risk designation system work? One of the reasons why the think tank is calling for a more considered risk assessment framework for the EU is that there is no guarantee that what the EC is currently proposing in its CSA amendments will have much of an effect. Issuing blanket bans on companies, or countries, does not explicitly address the underlying security issues that make products vulnerable to attack. In other words, even if China were excluded entirely from the EU members’ tech stacks, the other vendors from ‘trusted’ countries have proved that they are unable to deliver penetration-proof software, which would open the door to attacks regardless. Remember, Salt Typhoon’s high-profile attack on US telco networks took place as recently as 2024. It should also be said that CSA-esque designations could apply to US companies, as some countries in Europe see US vendors as similarly risky, albeit for different reasons. Merz’s Germany is concerned about the relationship between the US and EU, for example, and similar concerns about dependence on Chinese technology could easily be applied to vendors in the US, should relations sour. In Spain, US cloud companies dominate, but anti-US sentiment is stronger than many realize, particularly around surveillance concerns. Those, along with higher prices from some non-Chinese suppliers, have reduced Spain’s appetite for ripping out equipment others deem high-risk. “One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China’s National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient,” RUSI stated. The think tank suggested that if it wishes to enact change through policy, the EU must gather “greater economic courage” and a willingness to approach tech procurement as a means to secure its critical infrastructure, rather than “a compliance exercise.” ®
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419. Proofpoint’s security alert comes a day after OpenAI accused China’s Moonshot AI of stealing the American models’ reasoning and other data in distillation attacks that began on July 1. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report. Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive loading screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account login information. The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. In February - as US military officials pressured Anthropic to remove Claude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.” TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages. TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com. It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info). In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they were registered or first seen, so check out those indicators, too. TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters. “Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.®
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled. Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13. Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks. At first, the activity appears to have focused on finding vulnerable servers and testing the flaw. The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands. Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory. Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot. The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them. In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers. On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password. Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts. One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded. The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. It hasn't attributed the activity to a particular crew. Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications. Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®
MI5 has warned that more than 100 UK-linked academics contributed to research projects allegedly funded to improve China's spying capabilities. The Security Service issued an unusually public espionage alert this week naming the China General Technology Research Institute (CGTRI), also translated as the China Academy of General Technology (CAGT). MI5 says the organization has "very strong ties" to China's Ministry of State Security (MSS), the country's civilian intelligence agency. According to MI5, CGTRI's "primary purpose" is to fund academic research that directly improves the MSS's technical espionage capabilities. More than 100 UK-linked academics have contributed to CGTRI-funded projects involving AI, cybersecurity, covert communications, and steganography, the agency said. Some may not have known who was ultimately financing the work. "This activity supports MSS espionage, which poses a threat to UK national security," MI5 said. MI5 isn't accusing all of the academics involved of knowingly helping Chinese intelligence. Its alert acknowledges that many institutions and individuals likely dealt with CGTRI "in good faith" because of what it describes as the organization's "obfuscated links" to the MSS. MI5 "strongly advised" UK universities to review immediately any current or planned collaboration with CGTRI and ensure that the MSS derives no further benefit from British research. Academics working with Chinese institutions are also being told to establish who is ultimately funding the research and make sure CGTRI isn't involved. Researchers may also want to brush up on the National Security Act 2023. MI5 specifically highlighted two offenses: assisting a foreign intelligence service under section 3 and obtaining a material benefit from one under section 17. Under section 3, a person can commit an offense if their conduct is likely to materially assist a foreign intelligence service with UK-related activities and they know, or "ought reasonably to know," that it is likely to do so. Section 17 separately covers accepting or retaining a material benefit when the recipient knows, or ought reasonably to know, that it came from a foreign intelligence service. Legitimate payment for lawful goods or services is excluded. Having publicly identified CGTRI's alleged links to Chinese intelligence, MI5 warned that any institution or researcher continuing to conduct work funded by the organization should seek independent legal advice. In other words, MI5 has put universities on notice: not knowing who was really behind the research money may have been understandable yesterday, but it is a considerably trickier argument today. ®
Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Joe Brinkley, who is director of offensive security research and community at Cobalt, is known as “The Blind Hacker,” and has more than two decades of experience in information security. Joe was called in several years ago by a large, national law firm that wanted him to penetration test a smaller business they were about to acquire. What he discovered was a huge security hole and an even bigger embarrassment. Brinkley had audited the same law firm the previous year. At that time, he noted a number of holes and the attorneys had dutifully spent time and money on security software from the likes of Reliaquest and Dell to remediate what he found. “I shredded them. They were not in a very good security posture,” Brinkley told us. “They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition.” Unfortunately, even with their investment, the company failed to patch its Windows machines against BlueKeep, a major remote code execution vuln that was discovered, patched, and exploited in 2019. BlueKeep affects many versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7. Related vulns called DejaBlue also affected Windows 10. BlueKeep and its related security risks involve a flaw in Windows’ Remote Desktop Protocol that allows attackers to gain entry and execute remote code via port 3389. The vuln is wormable so an attacker could make it spread from one system to another. However, none of this filtered through to become a priority for the law firm. During his pentest, Brinkley used the BlueKeep vuln to get access to the org’s systems, where he found that the passwords were stored in plain text and easy to dump into a file, no decryption necessary. The usernames on the system were cleverly designed for security by obscurity. Instead of using the user’s real name or something like “admin,” they had names like “Yellow Banana” and “Red Apple” so attackers could not guess which one had the most privileges. Brinkley had no idea who Yellow Banana was, but he found that person’s password and it was perhaps the tackiest idea of a login we’ve ever heard. The password was “r3@lg00dp@$$w0rd,” which is “realgoodpassword” with some symbols and numbers substituted for letters. Not knowing who made the security faux pas, he took the password and included a screen shot of it in a presentation he delivered on system vulnerabilities that he gave to the law firm’s execs. While he was explaining that he had managed to penetrate 2,500 of the org’s computers, the CISO suddenly dropped an f-bomb. “Why the f*** is my password on the screen?” he complained, giving away the fact that he was Yellow Banana and thought that r3@lg00dp@$$w0rd was a good idea. So what can we learn from this tale of legal embarrassment? Always patch your Windows systems as soon as new patches become available and never use a cutesy password. Enabling 2FA and encrypting the passwords would probably have helped too. ®
England's secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by exams regulator Ofqual. Twenty-seven percent of schools reported an incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24. Ofqual surveyed 3,775 secondary teachers in England in July. For questions concerning whole schools, it counted one response from the most senior participating teacher at each institution, producing a sample of up to 2,162 schools. Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2 percent of respondents. Staff data was the information most commonly compromised. Student data was affected in 13 percent of incidents, while student work was affected in one percent. Recovery times improved more clearly. Among schools reporting an incident, 66 percent said they recovered "immediately," up from 55 percent the previous academic year. A further 12 percent recovered within half a school term – roughly six or seven weeks – while one percent took longer than half a term and another one percent required at least a full term. The proportion of reported incidents causing what respondents considered "critical damage" also fell from ten to seven percent, Ofqual said. "Critical damage" was not defined. The regulator told The Register that respondents were free to interpret the question in whatever way they felt best. Ofqual could not explain what had driven the apparent improvement. When asked what cybersecurity improvements their school had made during the past year, 54 percent of teachers selected "I don't know." Among the 46 percent who identified at least one change, half said their school had introduced a cybersecurity policy, 22 percent cited new or tested backup procedures, and 20 percent said they had completed or updated an incident response plan. Teachers were divided over who bears primary responsibility for cybersecurity. Forty-six percent pointed to the IT team, while 40 percent said responsibility was shared among all staff. Just nine percent identified senior leadership. Ofqual argued that cybersecurity is a leadership responsibility rather than solely an IT problem. Mat Pullen, director of education at Jamf, said the attack frequency and recovery figures were promising, but the understanding of security responsibility was a concern. "Reducing incidents matters, but so does recovering faster," Pullen said. "Cyberattacks have closed schools for a week or longer in the past, further disrupting an education already hit by Covid and affecting the wider economy as parents take time off work. "Ultimately, cybersecurity is a shared responsibility of IT, teachers and senior leadership, and breaking down these silos keeps technology secure and lessons running." Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28 percent a year earlier. A similar proportion said the training they received was not useful. Of those who received training, 65 percent said they made no changes as a result. Ofqual's findings look considerably rosier than the government's Cyber Security Breaches Survey, published in April. That research found that 49 percent of primary schools, 73 percent of secondary schools, 88 percent of further education colleges, and 98 percent of higher education institutions had identified a breach or attempted attack during the previous 12 months. The figures are not directly comparable. Ofqual asked secondary teachers about cybersecurity "incidents," while the government survey counted identified attacks and breaches regardless of whether they succeeded. The latter also covered education institutions across the UK rather than secondary schools in England alone. Even so, the broader survey illustrated how frequently schools are targeted. Twenty-seven percent of further and higher education institutions identified attacks at least weekly, and almost half of those reporting a breach suffered an adverse impact on their systems. Successful attacks can force schools to close while systems are restored. In June, several schools across England and Wales shut temporarily while technicians investigated a malware scare. The ICO said last year that students were responsible for more than half of cyberattacks attributed to a known actor in the UK education sector. ®
Britain's data protection watchdog has acquired a new legal identity and governance structure, although the familiar ICO initials are staying put. On September 30, the Information Commission replaced the Information Commissioner as the statutory regulator. The organization itself will be known as the Information Commission's Office and will continue using the ICO name. The change is more than a bureaucratic rebrand. The former regulator was a "corporation sole," meaning its statutory powers and responsibilities were vested in one person: the Information Commissioner. Those functions have now transferred to a corporate body overseen by executive and non-executive board members. The new structure was created by the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. The government says it will modernize the watchdog's governance without changing its existing regulatory functions. The transition follows an awkward final few months under the old structure. Information Commissioner John Edwards resigned in June after an independent workplace investigation into his conduct, admitting that his position had become "untenable" and that attempts at humor had been "inappropriate and caused offense." Edwards had stepped back from his duties in April, and the ICO removed his remaining responsibilities after the investigation concluded there was "a case to answer." Paul Arnold, who assumed Edwards' statutory responsibilities before his resignation, is serving as interim chief executive of the Information Commission. Seven non-executive members have joined the new board. They appointed Maggie Carver deputy chair, and she will perform the chair's duties while the government searches for somebody to fill the job permanently. That recruitment process isn't expected to wrap up until spring 2027. The regulator has also packed its boxes and moved its headquarters from Wilmslow to Oxford Road in Manchester, which it says will give it access to a "diverse talent pool" and strengthen links with businesses and communities across the UK. For anyone dealing with the watchdog, little should change day to day. The Information Commission retains responsibility for data protection and freedom of information regulation, along with the ICO's existing powers, guidance, and public services. A new corporate strategy is also on the way, with AI, cyber resilience, children's privacy, and public services among the areas singled out for attention. Anyone attached to the old initials can relax: despite the legal and governance overhaul, even the Information Commission's Office intends to keep calling itself the ICO. ®
The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021. Gender diversity has long been an issue pervading the STEM fields, although in cybersecurity this is especially pronounced, both at senior leadership and education levels. This is despite evidence that girls regularly outperform boys in STEM subjects at UK schools when they do participate. Not only are there still fewer women students in cybersecurity courses than those opting for computer science, but the percentage of women in the senior workforce (6+ years of experience) drops further to 12 percent – a figure that has remained broadly consistent since records began. For context, the UK average across all industries for female-identifying workers is 48 percent. Across the digital workforce, as of last year’s data, the average is 30 percent. The UK government interviewed various stakeholders in the cyber industry, finding that the barriers to senior leadership positions were structural – employers are purposely excluding women at higher levels. History plays a part too – older heads remaining in their positions from back when gender diversity was a matter less discussed – but recruiters say employers are still holding women back based on their perceived family ambitions. One recruitment agent was quoted in the report as saying: “When I’ve spoken to a business and said to them ‘why don’t you hire a more diverse workforce?’ You’ll get the normal common ones of ‘well if we hire a female, she’ll get pregnant, she’ll be off for 12 months,’ which isn’t right.” Refusing to hire women based on assumptions or fears about future pregnancy is a form of illegal gender discrimination that directly violates the UK's Equality Act 2010. Other common barriers to senior positions include assumptions they did not have the requisite technical skills for the role, and that cybersecurity is still seen as “an old boys’ club.” “This tied into a broader finding that stereotypes about women not being interested in cybersecurity continued to persist,” the report noted. “A cybersecurity firm noted that during a career talk on cybersecurity, a group of girls walked out of the talk, and the careers teacher reinforced the perception that the sector did not appeal to women.” The business told the government: “I went to the careers lady ‘What was the story with the five girls that left?’ And she went ‘Oh, cyber security is not really a girl’s job’.” Jill Broom, head of cyber resilience at techUK, said the onus is on employers to work harder on breaking down the lingering stereotypes about women in cybersecurity. “Cybersecurity underpins our growth, our economy and the safety of our society, with the sector offering growing employment opportunities and career prospects,” she told The Register. “However, the underrepresentation of women in this industry remains a significant concern. “A lack of gender diversity not only limits opportunities for women to benefit from this growing sector but also risks narrowing the range of perspectives and ideas that are essential to tackling increasingly complex cyber threats. Educators and employers must work together to challenge stereotypes, break down barriers and promote cybersecurity as an accessible and inclusive career path.” Representation for other groups fared comparatively better. This past year set a new record for neurodivergent workers in the cybersecurity industry, with 22 percent of UK staff identifying as neurodivergent. The figure represents a sharp increase from 16 percent the year before, one that has grown each year consistently since the 9 percent reported in 2020, and exceeds the digital sector average of 19 percent. “Cybersecurity is the most neurodiverse sector I have ever seen, and I think personally it’s celebrated, especially internally within the sector,” one respondent from a small cybersecurity business told the report's authors. While this year’s results may prove especially welcome to the neurodiverse crowd, the report noted this may reflect the rising awareness of neurodiversity among employers, rather than a true increase in numbers. The representation of ethnic minorities also remained at 19 percent, the same proportion as in 2025’s data, although this was a modest rise from 2024, in which 13 percent were from ethnic minorities. The figure is aligned with the digital sector average of 20 percent, and exceeds the UK’s pan-industry average of 16 percent. However, the representation of these groups suffers at the senior levels. The proportion of ethnic minorities in senior positions stands at 9 percent, a low figure that has persisted for the third year running, and one that is considerably down from the 15 percent high of 2021. As for explanations, the report offered few. “Ethnicity was hardly mentioned and was not generally felt to be an issue, despite the quantitative findings suggesting ethnic diversity at senior levels has remained lower than in the 2021 to 2023 studies,” it stated. “Most commonly, participants did not offer any concrete suggestions for enabling the progression of staff from diverse backgrounds into senior cybersecurity positions. Some employers stated that career development was open to everyone and was based on merit.” For neurodivergent security pros, it was not their technical abilities holding them back, but some said a lack of soft skills may hinder them in senior-role scenarios. “They’re more than capable of doing a leadership role,” said one small cybersecurity business. “It’s just they might not be soft-skilled enough to deal with difficult teams, difficult conversations. But to be honest, I’ve seen some fantastic people who are neurodiverse in leadership roles.” Disabled people are continuously absent from the workforce too, occupying just 9 percent of UK roles and 5 percent of senior positions. This is both less than the digital sector average of 15 percent, and significantly less than the UK’s pan-industry average of 18 percent. ®
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being involved in a "distillation attack" that began July 1. The house of Altman warns that extracting its models’ reasoning at scale could help rivals train capable models without preserving the same guardrails. Model distillation is a machine learning technique that can involve using one model’s outputs to train another – in adversarial cases, by sending bulk queries designed to reproduce the larger model’s reasoning and capabilities. Both the feds and major US AI companies, including Google and Anthropic, have accused Chinese rivals - and specifically Moonshot AI - of using distillation to reproduce capabilities from American models. In a Wednesday blog, OpenAI chimed in, saying it spotted and ultimately disrupted an adversarial distillation campaign that ran nearly all of July. “The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations,” according to the blog. “Instead, they manipulated model interactions so that protected reasoning could be reproduced in forms visible to the requester in a coordinated, scaled manner that violated our terms of service.” The queries began on July 1, and while they started slowly, “we observed high-volume spikes on July 24 and 25 consisting of 16,000 requests using a relevant extraction pattern from over 4,000 users,” OpenAI said. Upon investigating the incident, the AI giant identified related “prompt-pattern activity” across more than 15,000 users. OpenAI fully disrupted the campaign on July 28, we’re told. While OpenAI said that it's unclear whether all of the operators during the July time period were linked to just one rival AI company, the “core cluster” of the theft came from Moonshot AI, which developed Kimi. The Register reached out to Moonshot AI for comment and did not receive an immediate response. We also asked OpenAI which of its models were targeted during the July campaign, but did not hear back. It’s worth noting that, in late July, US President Donald Trump’s Assistant for Science and Technology Michael Kratsios also accused Moonshot AI of creating its Kimi K3 model by distilling Anthropic’s Fable. Anthropic’s Claude Opus 5.5 model, released a week ago, comes with a defense against distillation called "preserved thinking" that it introduced with Fable 5.1. “Adversarial distillation poses safety and national security risks,” OpenAI said on Wednesday, echoing earlier gripes from American companies and government officials. “Extracted reasoning could be used to train another model without preserving the safeguards applied to the original model’s user-facing outputs,” OpenAI added. “At scale, distillation can also accelerate the transfer of advanced capabilities without requiring the same investment in safety. These concerns become heightened as models gain capabilities in dual use domains.” In response, OpenAI said it banned the model-copying accounts tightened signup and infrastructure controls and expanded monitoring efforts. It also “closed a pathway that allowed someone who already possessed another user's encrypted reasoning to replay it and recover its contents,” and worked with service providers to ensure that this type of distillation activity didn’t just move to third-party services. Additionally, OpenAI shared the details of its investigation with other AI firms, through the Frontier Model Forum, and government information-sharing programs.®
A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. Titan is an internal analytics platform, and Redmond restricts access via its web interface to Microsoft employees. Faav, with an assist from an AI hackbot he built called Antares, found that he could access Titan’s API through an Azure Cloud Services host because Titan didn’t check the signature on a login token. Microsoft has since locked down the API and paid Faav a $5,000 bug bounty for his research. He says the breakthrough came after 10 days of authentication errors, when he returned to the problem after finishing Friday’s schoolwork and finally managed to execute SQL as a Titan admin after 1 AM Saturday. “It was 2 AM,” Faav said in a blog about his findings. “I wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again.” He also notes that he rewrote his blog post at Microsoft’s request, cut sections and numbers, and reworded the impact prior to publication. “We appreciate the opportunity to investigate the findings reported by Faav,” Microsoft said in a statement provided to Faav for his blog. “Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.” A boy and his bot The research began on August 25 when Antares found Titan’s public API. For the next 10 days, the human and bot tested the service’s JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs), eventually finding an unsigned token that could reach Titan’s local user lookup - but not a UPN that Titan recognized. Early on September 5, Faav changed the unsigned token’s UPN from an email-formatted identity to admin. Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL. The takeaway, according to Faav: Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check. The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room. Despite all the access-control logic existing in the app, the one missing piece made it all pointless. If you’re a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth. This gave Faav access to Titan’s platform metadata database, and from there he could query application tables directly. The metadata contained: About 25,000 account and email records. 17,990 employee email records. 15,001 employee organization records. 355 database configurations. 20,979 virtual-dataset SQL definitions. 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions. Titan’s user and usage directory exposed employee job titles, departments, and management hierarchy, which the researcher notes could be useful for social-engineering attacks - “though I never tested or demonstrated that,” he added. He also found a Bing analytics sample and tested two rows that contained search info, identifiers, and high-level location information, such as country- or state-level details. Faav said the location values did not contain precise user locations. 17.3 trillion data rows Then he hit the jackpot, testing 56 routing values from an archived configuration and discovering 30 were still active. “Each routing value pointed to a backend configuration, and each configuration contained one or more databases, so the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names,” the bug hunter wrote. The total comes to about 17.3 trillion rows, which Faav says is a storage estimate derived from metadata and likely includes historical, duplicated, and derived data. “But quite the high number nonetheless.” Between September 6 and September 8, Microsoft asked the teen to stop testing and requested his IP address to confirm no nefarious activity beyond the bug bounty research. A day later, Redmond locked down the endpoint and told Faav the “report prompted immediate investigation and remediation to address the remaining exposure.” Microsoft awarded the bug hunter $5,000 for his work on September 17.®