❌

Reading view

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc. The UK-based think tank said in a report today that the EU should develop a new risk assessment framework that applies to all members and strengthens its own powers, without encroaching on members’ rights to set their own national security policies. It must delicately balance the need to secure the union, while maintaining the flexibility that both allows members to set domestic policies and lawmakers to account for different risk profiles across different sectors. The risks affecting telecoms will not necessarily apply to other sectors in the same way. Speaking of telecoms, currently there is only the voluntary EU Toolbox for 5G Security framework – voluntary being the operative word here, as only 10 of 27 members have fully implemented it since it launched in January 2020. On paper, it somewhat sets out to achieve what RUSI is calling for: a harmonized set of standards to mitigate 5G-related security risks affecting member states. Addressing the frustration over the lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to build a list of untrusted vendors that members must preclude from the networks of 18 critical sectors. If passed, any countries using equipment from designated vendors would be forced to rip and replace it within 36 months. The EC has already indicated that it would suggest Huawei and ZTE be listed, should the amendments pass. But before the EU gets busy listing vendors it considers high-risk, it first needs to decide what a high-risk vendor even is. There is still no official definition, nor is it a legal category, and at present, it allows countries to wangle their way around these descriptions to buy the tech they want, bypassing whatever scrutiny may come their way should the CSA amendments come into force. RUSI’s researchers used Germany, Spain, and the UK as examples of how three countries can treat foreign tech vendors, such as Huawei and ZTE, very differently. Germany’s most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) annually, and historically the Bund has opted to preserve these valuable economic ties in favor of reducing supply chain risk. Under Chancellor Friedrich Merz, this is slowly changing, although RUSI does not expect to see a material shift in the makeup of Germany’s 5G RAN stack in the near future. Chinese suppliers accounted for an estimated 59 percent of the country’s 5G RAN in 2024. Chinese equipment accounted for an estimated 32 percent of Spain’s 5G RAN in 2024, although that share is expected to shrink. The debate intensified after last year’s controversy, when Spain awarded Huawei a contract involving the storage of judicial wiretap recordings. Spain’s past procurement decisions have shown it to often favor the most cost-effective option, and its government does not share the same national security concerns about China as the UK or US, or at least not to the same degree. The UK, meanwhile, looks set to completely eradicate Chinese technology from its telecoms network by the end of next year, and has bent to the US’ vehement demands that Huawei is bad, bad news for Western geopolitical security. Real security risks RUSI stated that concerns about Chinese IT vendors “are well-founded,” and that it is true that the Chinese government can empower authorities to exercise control over companies like Huawei. This includes providing the state with data on demand, hosting Chinese Communist Party (CCP) representatives, and reporting activity that signals a threat to national security. There is an additional law that requires tech companies to not just report vulnerabilities to the country’s government within 48 hours of discovery, but also to withhold the same disclosure from China’s overseas counterparts, except for the product vendor. “This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities,” RUSI said. Factoring in all of this, the country has also demonstrated the willingness and capability to launch cyberattacks against the critical national infrastructure of political adversaries, according to RUSI. Technical security aside, China’s technological advancements introduce economic risks, too. In some cases, its vendors have developed more capable products than equivalents in the EU or US, and sold them at more attractive prices. This advantage makes it difficult for some countries to justify the extra expense on non-Chinese equipment. In building a global reliance on its products, China could then introduce “unwelcome dependencies,” or cement itself as a dominant player in crucial supply chains, RUSI noted. China has shown in recent years that it is willing to exercise this influence, such as when it threatened Germany with “consequences” for the two countries’ economic ties during the heated 5G debate of 2019. Would a high-risk designation system work? One of the reasons why the think tank is calling for a more considered risk assessment framework for the EU is that there is no guarantee that what the EC is currently proposing in its CSA amendments will have much of an effect. Issuing blanket bans on companies, or countries, does not explicitly address the underlying security issues that make products vulnerable to attack. In other words, even if China were excluded entirely from the EU members’ tech stacks, the other vendors from ‘trusted’ countries have proved that they are unable to deliver penetration-proof software, which would open the door to attacks regardless. Remember, Salt Typhoon’s high-profile attack on US telco networks took place as recently as 2024. It should also be said that CSA-esque designations could apply to US companies, as some countries in Europe see US vendors as similarly risky, albeit for different reasons. Merz’s Germany is concerned about the relationship between the US and EU, for example, and similar concerns about dependence on Chinese technology could easily be applied to vendors in the US, should relations sour. In Spain, US cloud companies dominate, but anti-US sentiment is stronger than many realize, particularly around surveillance concerns. Those, along with higher prices from some non-Chinese suppliers, have reduced Spain’s appetite for ripping out equipment others deem high-risk. “One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China’s National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient,” RUSI stated. The think tank suggested that if it wishes to enact change through policy, the EU must gather “greater economic courage” and a willingness to approach tech procurement as a means to secure its critical infrastructure, rather than “a compliance exercise.” ®

  •  

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

  •  

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can

  •  

Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing

A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a China-aligned group it tracks as TA419. Proofpoint’s security alert comes a day after OpenAI accused China’s Moonshot AI of stealing the American models’ reasoning and other data in distillation attacks that began on July 1. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US,” Proofpoint threat-intelligence analyst Mark Kelly said in a Thursday report. Beginning July 8, TA419 sent phishing emails spoofing Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy, and then Heidi Crebo-Rediker, a prominent economist and foreign policy expert, to even more American AI policy experts at think tanks, universities, and law firms. The suspected spies’ emails invited their targets to join a fake AI policy advisory committee or contribute to a Senate foreign relations committee report on AI export controls and supply chains. If the American AI expert replied, the Beijing-linked crew responded with a shortened URL promising to share additional details, but in reality pointing to an attacker-controlled domain. This page conducts a Cloudflare Turnstile check behind a phony OneDrive loading screen, and then redirects the victim to an attacker-in-the-middle (AitM) credential phishing page that steals the victim’s cloud account login information. The July 2026 campaigns used driftshare[.]co as the first-stage domain and globalfileshareplatform[.]com as the second-stage domain. In February - as US military officials pressured Anthropic to remove Claude’s safeguards - the Chinese spies spoofed a senior Anthropic employee to phish an AI policy analyst at a US think tank. This email used the subject line: “Request for Feedback on Military Integration of Claude.” TA419’s phishing chain targets Microsoft 365/Entra ID through the first-party OfficeHome application (client_id=4765445b-32c6-49b0-83e6-1d93765276ca). It’s built on open source Frameless BitB, which contains a Browser-in-the-Browser (BitB) overlay, an Evilginx phishlet to intercept usernames, passwords, and session cookies for Microsoft 365, and server-side substitution rules that inject the kit into proxied pages. TA419 typically uses Cloudflare’s content delivery network to hide the backend hosting IP address for its domains, and its credential phishing domains are usually themed around file sharing sites and cloud services - such as msfile[.]online and onecloudfilesync[.]com. It also impersonates specific organizations, including the Japan-Taiwan Exchange Association (tw-koryu[.]org), The Heritage Foundation (heritiages[.]org and heritiage[.]org), and Japanese Minister of Defense Shinjirō Koizumi’s official website (shinjirou[.]info). In total, the crew uses dozens of phishing and spoofed-sender domains, and phony email addresses. Proofpoint includes all of the ones it discovered in 2026, plus the timeline of when they were registered or first seen, so check out those indicators, too. TA419 and other Beijing-aligned crews will likely continue targeting AI and other policy experts working on technologies of interest to the Chinese government, according to the threat hunters. “Organizations in the scope of TA419 activity should consider phishing-resistant, origin-bound authentication such as passkeys,” they recommend.®

  •  

Microsoft catches hackers exploiting Zimbra bug before disclosure

Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled. Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13. Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks. At first, the activity appears to have focused on finding vulnerable servers and testing the flaw. The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands. Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory. Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot. The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them. In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers. On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password. Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts. One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded. The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. It hasn't attributed the activity to a particular crew. Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications. Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®

  •  

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

  •  

MI5 warns UK academics their research may have helped Chinese spies

MI5 has warned that more than 100 UK-linked academics contributed to research projects allegedly funded to improve China's spying capabilities. The Security Service issued an unusually public espionage alert this week naming the China General Technology Research Institute (CGTRI), also translated as the China Academy of General Technology (CAGT). MI5 says the organization has "very strong ties" to China's Ministry of State Security (MSS), the country's civilian intelligence agency. According to MI5, CGTRI's "primary purpose" is to fund academic research that directly improves the MSS's technical espionage capabilities. More than 100 UK-linked academics have contributed to CGTRI-funded projects involving AI, cybersecurity, covert communications, and steganography, the agency said. Some may not have known who was ultimately financing the work. "This activity supports MSS espionage, which poses a threat to UK national security," MI5 said. MI5 isn't accusing all of the academics involved of knowingly helping Chinese intelligence. Its alert acknowledges that many institutions and individuals likely dealt with CGTRI "in good faith" because of what it describes as the organization's "obfuscated links" to the MSS. MI5 "strongly advised" UK universities to review immediately any current or planned collaboration with CGTRI and ensure that the MSS derives no further benefit from British research. Academics working with Chinese institutions are also being told to establish who is ultimately funding the research and make sure CGTRI isn't involved. Researchers may also want to brush up on the National Security Act 2023. MI5 specifically highlighted two offenses: assisting a foreign intelligence service under section 3 and obtaining a material benefit from one under section 17. Under section 3, a person can commit an offense if their conduct is likely to materially assist a foreign intelligence service with UK-related activities and they know, or "ought reasonably to know," that it is likely to do so. Section 17 separately covers accepting or retaining a material benefit when the recipient knows, or ought reasonably to know, that it came from a foreign intelligence service. Legitimate payment for lawful goods or services is excluded. Having publicly identified CGTRI's alleged links to Chinese intelligence, MI5 warned that any institution or researcher continuing to conduct work funded by the organization should seek independent legal advice. In other words, MI5 has put universities on notice: not knowing who was really behind the research money may have been understandable yesterday, but it is a considerably trickier argument today. ®

  •  

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Joe Brinkley, who is director of offensive security research and community at Cobalt, is known as “The Blind Hacker,” and has more than two decades of experience in information security. Joe was called in several years ago by a large, national law firm that wanted him to penetration test a smaller business they were about to acquire. What he discovered was a huge security hole and an even bigger embarrassment. Brinkley had audited the same law firm the previous year. At that time, he noted a number of holes and the attorneys had dutifully spent time and money on security software from the likes of Reliaquest and Dell to remediate what he found. “I shredded them. They were not in a very good security posture,” Brinkley told us. “They spent probably a half a million dollars to get patching and get through these things because they were trying to go through a merger and acquisition.” Unfortunately, even with their investment, the company failed to patch its Windows machines against BlueKeep, a major remote code execution vuln that was discovered, patched, and exploited in 2019. BlueKeep affects many versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7. Related vulns called DejaBlue also affected Windows 10. BlueKeep and its related security risks involve a flaw in Windows’ Remote Desktop Protocol that allows attackers to gain entry and execute remote code via port 3389. The vuln is wormable so an attacker could make it spread from one system to another. However, none of this filtered through to become a priority for the law firm. During his pentest, Brinkley used the BlueKeep vuln to get access to the org’s systems, where he found that the passwords were stored in plain text and easy to dump into a file, no decryption necessary. The usernames on the system were cleverly designed for security by obscurity. Instead of using the user’s real name or something like “admin,” they had names like “Yellow Banana” and “Red Apple” so attackers could not guess which one had the most privileges. Brinkley had no idea who Yellow Banana was, but he found that person’s password and it was perhaps the tackiest idea of a login we’ve ever heard. The password was “r3@lg00dp@$$w0rd,” which is “realgoodpassword” with some symbols and numbers substituted for letters. Not knowing who made the security faux pas, he took the password and included a screen shot of it in a presentation he delivered on system vulnerabilities that he gave to the law firm’s execs. While he was explaining that he had managed to penetrate 2,500 of the org’s computers, the CISO suddenly dropped an f-bomb. “Why the f*** is my password on the screen?” he complained, giving away the fact that he was Yellow Banana and thought that r3@lg00dp@$$w0rd was a good idea. So what can we learn from this tale of legal embarrassment? Always patch your Windows systems as soon as new patches become available and never use a cutesy password. Enabling 2FA and encrypting the passwords would probably have helped too. ®

  •  

r/netsec monthly discussion & tool thread

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

submitted by /u/albinowax
[link] [comments]
  •  

How Financial Services Companies Can Modernize Their Software Supply Chain

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

  •  

England's schools are getting better at mopping up cyber incidents

England's secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by exams regulator Ofqual. Twenty-seven percent of schools reported an incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24. Ofqual surveyed 3,775 secondary teachers in England in July. For questions concerning whole schools, it counted one response from the most senior participating teacher at each institution, producing a sample of up to 2,162 schools. Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2 percent of respondents. Staff data was the information most commonly compromised. Student data was affected in 13 percent of incidents, while student work was affected in one percent. Recovery times improved more clearly. Among schools reporting an incident, 66 percent said they recovered "immediately," up from 55 percent the previous academic year. A further 12 percent recovered within half a school term – roughly six or seven weeks – while one percent took longer than half a term and another one percent required at least a full term. The proportion of reported incidents causing what respondents considered "critical damage" also fell from ten to seven percent, Ofqual said. "Critical damage" was not defined. The regulator told The Register that respondents were free to interpret the question in whatever way they felt best. Ofqual could not explain what had driven the apparent improvement. When asked what cybersecurity improvements their school had made during the past year, 54 percent of teachers selected "I don't know." Among the 46 percent who identified at least one change, half said their school had introduced a cybersecurity policy, 22 percent cited new or tested backup procedures, and 20 percent said they had completed or updated an incident response plan. Teachers were divided over who bears primary responsibility for cybersecurity. Forty-six percent pointed to the IT team, while 40 percent said responsibility was shared among all staff. Just nine percent identified senior leadership. Ofqual argued that cybersecurity is a leadership responsibility rather than solely an IT problem. Mat Pullen, director of education at Jamf, said the attack frequency and recovery figures were promising, but the understanding of security responsibility was a concern. "Reducing incidents matters, but so does recovering faster," Pullen said. "Cyberattacks have closed schools for a week or longer in the past, further disrupting an education already hit by Covid and affecting the wider economy as parents take time off work. "Ultimately, cybersecurity is a shared responsibility of IT, teachers and senior leadership, and breaking down these silos keeps technology secure and lessons running." Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28 percent a year earlier. A similar proportion said the training they received was not useful. Of those who received training, 65 percent said they made no changes as a result. Ofqual's findings look considerably rosier than the government's Cyber Security Breaches Survey, published in April. That research found that 49 percent of primary schools, 73 percent of secondary schools, 88 percent of further education colleges, and 98 percent of higher education institutions had identified a breach or attempted attack during the previous 12 months. The figures are not directly comparable. Ofqual asked secondary teachers about cybersecurity "incidents," while the government survey counted identified attacks and breaches regardless of whether they succeeded. The latter also covered education institutions across the UK rather than secondary schools in England alone. Even so, the broader survey illustrated how frequently schools are targeted. Twenty-seven percent of further and higher education institutions identified attacks at least weekly, and almost half of those reporting a breach suffered an adverse impact on their systems. Successful attacks can force schools to close while systems are restored. In June, several schools across England and Wales shut temporarily while technicians investigated a malware scare. The ICO said last year that students were responsible for more than half of cyberattacks attributed to a known actor in the UK education sector. ®

  •  

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any

  •  

UK privacy watchdog starts over with new board and Manchester HQ

Britain's data protection watchdog has acquired a new legal identity and governance structure, although the familiar ICO initials are staying put. On September 30, the Information Commission replaced the Information Commissioner as the statutory regulator. The organization itself will be known as the Information Commission's Office and will continue using the ICO name. The change is more than a bureaucratic rebrand. The former regulator was a "corporation sole," meaning its statutory powers and responsibilities were vested in one person: the Information Commissioner. Those functions have now transferred to a corporate body overseen by executive and non-executive board members. The new structure was created by the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. The government says it will modernize the watchdog's governance without changing its existing regulatory functions. The transition follows an awkward final few months under the old structure. Information Commissioner John Edwards resigned in June after an independent workplace investigation into his conduct, admitting that his position had become "untenable" and that attempts at humor had been "inappropriate and caused offense." Edwards had stepped back from his duties in April, and the ICO removed his remaining responsibilities after the investigation concluded there was "a case to answer." Paul Arnold, who assumed Edwards' statutory responsibilities before his resignation, is serving as interim chief executive of the Information Commission. Seven non-executive members have joined the new board. They appointed Maggie Carver deputy chair, and she will perform the chair's duties while the government searches for somebody to fill the job permanently. That recruitment process isn't expected to wrap up until spring 2027. The regulator has also packed its boxes and moved its headquarters from Wilmslow to Oxford Road in Manchester, which it says will give it access to a "diverse talent pool" and strengthen links with businesses and communities across the UK. For anyone dealing with the watchdog, little should change day to day. The Information Commission retains responsibility for data protection and freedom of information regulation, along with the ICO's existing powers, guidance, and public services. A new corporate strategy is also on the way, with AI, cyber resilience, children's privacy, and public services among the areas singled out for attention. Anyone attached to the old initials can relax: despite the legal and governance overhaul, even the Information Commission's Office intends to keep calling itself the ICO. ®

  •  

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

  •  

Fewer women than ever in UK's 'old boys' club' cyber industry

The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021. Gender diversity has long been an issue pervading the STEM fields, although in cybersecurity this is especially pronounced, both at senior leadership and education levels. This is despite evidence that girls regularly outperform boys in STEM subjects at UK schools when they do participate. Not only are there still fewer women students in cybersecurity courses than those opting for computer science, but the percentage of women in the senior workforce (6+ years of experience) drops further to 12 percent – a figure that has remained broadly consistent since records began. For context, the UK average across all industries for female-identifying workers is 48 percent. Across the digital workforce, as of last year’s data, the average is 30 percent. The UK government interviewed various stakeholders in the cyber industry, finding that the barriers to senior leadership positions were structural – employers are purposely excluding women at higher levels. History plays a part too – older heads remaining in their positions from back when gender diversity was a matter less discussed – but recruiters say employers are still holding women back based on their perceived family ambitions. One recruitment agent was quoted in the report as saying: “When I’ve spoken to a business and said to them ‘why don’t you hire a more diverse workforce?’ You’ll get the normal common ones of ‘well if we hire a female, she’ll get pregnant, she’ll be off for 12 months,’ which isn’t right.” Refusing to hire women based on assumptions or fears about future pregnancy is a form of illegal gender discrimination that directly violates the UK's Equality Act 2010. Other common barriers to senior positions include assumptions they did not have the requisite technical skills for the role, and that cybersecurity is still seen as “an old boys’ club.” “This tied into a broader finding that stereotypes about women not being interested in cybersecurity continued to persist,” the report noted. “A cybersecurity firm noted that during a career talk on cybersecurity, a group of girls walked out of the talk, and the careers teacher reinforced the perception that the sector did not appeal to women.” The business told the government: “I went to the careers lady ‘What was the story with the five girls that left?’ And she went ‘Oh, cyber security is not really a girl’s job’.” Jill Broom, head of cyber resilience at techUK, said the onus is on employers to work harder on breaking down the lingering stereotypes about women in cybersecurity. “Cybersecurity underpins our growth, our economy and the safety of our society, with the sector offering growing employment opportunities and career prospects,” she told The Register. “However, the underrepresentation of women in this industry remains a significant concern. “A lack of gender diversity not only limits opportunities for women to benefit from this growing sector but also risks narrowing the range of perspectives and ideas that are essential to tackling increasingly complex cyber threats. Educators and employers must work together to challenge stereotypes, break down barriers and promote cybersecurity as an accessible and inclusive career path.” Representation for other groups fared comparatively better. This past year set a new record for neurodivergent workers in the cybersecurity industry, with 22 percent of UK staff identifying as neurodivergent. The figure represents a sharp increase from 16 percent the year before, one that has grown each year consistently since the 9 percent reported in 2020, and exceeds the digital sector average of 19 percent. “Cybersecurity is the most neurodiverse sector I have ever seen, and I think personally it’s celebrated, especially internally within the sector,” one respondent from a small cybersecurity business told the report's authors. While this year’s results may prove especially welcome to the neurodiverse crowd, the report noted this may reflect the rising awareness of neurodiversity among employers, rather than a true increase in numbers. The representation of ethnic minorities also remained at 19 percent, the same proportion as in 2025’s data, although this was a modest rise from 2024, in which 13 percent were from ethnic minorities. The figure is aligned with the digital sector average of 20 percent, and exceeds the UK’s pan-industry average of 16 percent. However, the representation of these groups suffers at the senior levels. The proportion of ethnic minorities in senior positions stands at 9 percent, a low figure that has persisted for the third year running, and one that is considerably down from the 15 percent high of 2021. As for explanations, the report offered few. “Ethnicity was hardly mentioned and was not generally felt to be an issue, despite the quantitative findings suggesting ethnic diversity at senior levels has remained lower than in the 2021 to 2023 studies,” it stated. “Most commonly, participants did not offer any concrete suggestions for enabling the progression of staff from diverse backgrounds into senior cybersecurity positions. Some employers stated that career development was open to everyone and was based on merit.” For neurodivergent security pros, it was not their technical abilities holding them back, but some said a lack of soft skills may hinder them in senior-role scenarios. “They’re more than capable of doing a leadership role,” said one small cybersecurity business. “It’s just they might not be soft-skilled enough to deal with difficult teams, difficult conversations. But to be honest, I’ve seen some fantastic people who are neurodiverse in leadership roles.” Disabled people are continuously absent from the workforce too, occupying just 9 percent of UK roles and 5 percent of senior positions. This is both less than the digital sector average of 15 percent, and significantly less than the UK’s pan-industry average of 18 percent. ®

  •  
❌