Alexander Martin

@alexmartin.bsky.social

Journalist covering cybersecurity and intelligence. UK Editor at The Record from Recorded Future News. Dad of two. 🏠 Sheffield 📧 alexander.martin@therecord.media 📱 Signal: AlexanderMartin.79

New: Members of a Russia-based cyberextortion gang plotted to send operatives into US law firms, kidnap executives and even recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News. Crazy stuff in this archive. More to follow:

Leaked chats show Russian extortion gang sending ‘agents’ into US law firms

In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”

therecord.media

New: The British government is failing to measure what Russian cyberattacks, sabotage and threats to critical infrastructure are costing the country, according to a new report, which gives its own estimate of between £2 billion and £2.5 billion a year — a figure described as a floor.

Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker

A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh that burden against the cost of defending against it.

therecord.media

New: Security researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visit...

therecord.media

New: Security researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visit...

therecord.media

Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...

What does the Iran war tell us about the relationship between cyber and kinetic conflict?

The predicted wave of Iranian cyber retaliation never came

bindinghook.com

I’m seeing the word “hack” used in a lot of coverage of Albanese’s announcement about OpenAI’s unauthorised access to an Australian government health website in June. As of now, the lack of technical details either from OpenAI or Canberra make that description hard to justify.

Defenders cannot yet put artificial intelligence to work as freely as attackers can, a senior official at @ncsc.gov.uk said Monday. His warning comes amid concerns about the kind of cybersecurity future AI will lead to. Read more here ⤵️

AI is set to help cyber attackers much more than defenders, says UK official

Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.

therecord.media

Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks. In some cases, alerts arrive only after a strike or do not reach residents at all. ✍️ @darynant.bsky.social

Russia’s internet shutdowns disrupt warnings about incoming drone attacks

Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks.

therecord.media

Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations, the company said Thursday.

Anthropic caught Russia-linked spies using Claude in hacking operations

Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organi...

therecord.media

Wee scoop: The new commander of the National Cyber Force stepped into the role this week, according to sources with knowledge of the appointment. The individual has not yet been avowed as routine security considerations are still being worked through.

UK appoints new commander of National Cyber Force

The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still be...

therecord.media

At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday.

Multiple Chinese hacking groups seen using identical Chrome zero-day exploit

A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.

therecord.media

On the same day Germany formally blamed Russia for the Leipzig/Halle drone attack, and two power stations were hit with sabotage, hackers encrypted the central IT systems of a municipal utility in Bavaria. No evidence events linked, but what a day, eh?

Cyberattack encrypts systems at Bavarian municipal utility

A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.

therecord.media

Hackers embezzled at least €35 million from hundreds of notary offices in France over two years. They were so prolific that the authorities feared the criminals were issuing counterfeit notarial deeds. It might take years for those to come to light. Great reporting from @untersin.gr here ⤵️

Au cœur d’une cyberattaque sans précédent qui a ébranlé le notariat français

Des pirates ont détourné au moins 35 millions d’euros au sein de centaines d’offices notariaux pendant deux ans. Les hackeurs étaient si prolifiques que les autorités ont craint l’émission de faux act...

lemonde.fr

New: An agreement, signed Monday by Zelensky and Burnham, will make the U.K. the first foreign partner to gain access to Ukraine's Avengers AI Labs, a defense platform built around millions of images and other data gathered from the battlefield.

Ukraine to give Britain access to battlefield data to train AI

Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence s...

therecord.media

'[M]inisters would not have to publicly designate a vendor as a security risk before taking action against it... The powers would also reach beyond telecoms into managed service providers, data centers and digital infrastructure, as well as the energy, water, transport and health sectors.'

Alexander Martin@alexmartin.bsky.social · 2mo ago

New: The British government is seeking new powers that would allow it to ban technology vendors on national security grounds from supplying companies working in the country’s critical sectors — potentially doing so in secret.

New: The British government is seeking new powers that would allow it to ban technology vendors on national security grounds from supplying companies working in the country’s critical sectors — potentially doing so in secret.

UK government seeks powers to secretly block risky tech suppliers

The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.

therecord.media