Alexander Martin

@alexmartin.bsky.social

Journalist covering cybersecurity and intelligence. UK Editor at The Record from Recorded Future News. Dad of two. 🏠 Sheffield 📧 alexander.martin@therecord.media 📱 Signal: AlexanderMartin.79

An artificial intelligence agent built by Anthropic created fake online personas, planted malicious code in a real software project, and sent phishing emails to real developers during a U.K. government security evaluation, all without human instruction, according to Britain’s AI Security Institute.

Anthropic AI agent faked identities, phished real developers in UK government hacking test

An artificial intelligence agent built by Anthropic independently planted malicious code in a real software project and sent phishing emails to developers during a U.K. government security evaluation,...

therecord.media

NEW: I really enjoyed speaking to General Sir Jim Hockenhull a few weeks ago and am grateful the fruits of that conversation can now be published. His message to the British public is stark: “War isn’t going to happen as an away game. If there is a conflict, it will be happening here.”

Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence

As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.

therecord.media

NEW: I really enjoyed speaking to General Sir Jim Hockenhull a few weeks ago and am grateful the fruits of that conversation can now be published. His message to the British public is stark: “War isn’t going to happen as an away game. If there is a conflict, it will be happening here.”

Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence

As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.

therecord.media

The “encryption” hasn’t been weakened. Your privacy — and that of child abusers, terrorists, etc — is protected. If you don’t want police to be able to tackle those uses of iCloud with a warrant, then you might need to let Apple bring back its client-side scanning proposals.

⚡🇵🇸😞🇪🇺🇨🇦 Sandrew@sandrew-0.bsky.social · yesterday

Weakening #encryption to allow the spooks & police in allows criminals & enemies in too, just as the USA can't keep foreign spies out of their 'lawful' phone surveillance system. Governments and companies can't keep secrets, look at all the intrusions & data breaches. #Privacy

In hindsight, I think the term exceptional access is better than lawful access. A backdoor could hypothetically be lawful access. But we're still not talking about a backdoor here. A backdoor is a covert mechanism intended to allow the bypassing of a normal authentication system. That ain't this.

Alexander Martin@alexmartin.bsky.social · yesterday

Sigh. As the FT reports: “Apple has launched a new legal challenge against the UK’s latest attempt to create a ‘backdoor’ to access encrypted customer data…” 👏 lawful 👏 access 👏 is 👏 not 👏 a 👏 backdoor 👏

A new ransomware group (who I'm not giving the publicity of naming) is brazenly offering journalists early access to their data leak site in order to increase pressure on victims to make an extortion payment. I'm unaware of other recipients but the message looks mass-sent.

Bild

I find it weird that a large part of Anthropic’s disclosure is based on Claude’s chain-of-thought outputs, yet I’ve seen no other reports noting Anthropic’s own research found this output to be rarely accurate. Surely tech journalism can do better?

Anthropic says its AI hacked real-world companies in three incidents

Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.

therecord.media

I find it weird that a large part of Anthropic’s disclosure is based on Claude’s chain-of-thought outputs, yet I’ve seen no other reports noting Anthropic’s own research found this output to be rarely accurate. Surely tech journalism can do better?

Anthropic says its AI hacked real-world companies in three incidents

Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.

therecord.media

Another one for the increasingly blurred lines between criminal and state-sponsored hacking groups. Tools and infrastructure used by North Korea’s infamous Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations...

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entan...

therecord.media

So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

proofpoint.com

Just hours before Angola's largest telecoms operator, Unitel, made it stock market debut it was hit by a cyberattack. From what we can tell, it looks more like an attack on the company's internal systems than a volumetric DDoS. The timing is suspect.

Cyberattack hits Angola’s largest telco hours before landmark stock debut

Angola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.

therecord.media

ICYMI: Andy Burnham reappointed Britain’s cybersecurity minister (unusually for Burnham, a Starmer ally) to a government post last week, holding the existing policy steady even as he abolished the department that ran it.

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

therecord.media

ICYMI: Andy Burnham reappointed Britain’s cybersecurity minister (unusually for Burnham, a Starmer ally) to a government post last week, holding the existing policy steady even as he abolished the department that ran it.

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

therecord.media

Who is likely to get the cyber (information resilience) brief as PUS at DCMS? Of the below, Foxcroft most likely. Peacock previously covered different brief at DCMS. Mackenzie a new peer whose background is in arts. I suspect there's more to come as the team seems thin given the expanded brief.

Bild

Really interesting from @sgclark92.bsky.social. Always fascinating to see these massive costings be made (both by GSMA and Commission) without attempts to cost inaction. Very rare to see that done, DSIT's¹ work over the CSRB a rare example. __ ¹ F

Huawei ban to cost the EU up to €40 billion, says industry

The price tag for replacing telecom equipment from the Chinese manufacturer is hotly contested, and telecom operators want compensation.

politico.eu

A great thread here, but there are some big issues from a journalist's point of view. OpenAI's announcement is a mix of capability disclosure and marketing, and the lack of professional incident response rigour in how the report is drafted makes it very suspect.

Post nicht verfügbar.

New: Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs, the department announced Monday.

Hackers were inside South Korea's diplomat training system for 9 months

Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry ...

therecord.media