Ninjasignal Q1 2026 Wtf Roundup
NINJASIGNAL Q1 2026: THE WTF ROUNDUP
Four months in. The year has aged eleven. Pull up a chair.
So I have been keeping a small ledger. A scrap of paper, really. Every time something happened in cyber this quarter that made me put the cup down and say no. surely not. surely they didn't, I added a tally mark. The paper is now structurally compromised. I am writing this on the back of it.
Here is the thing nobody is saying clearly enough, so I will: the categories collapsed in Q1 2026. Not metaphorically. Operationally. Breach and war converged. Telco and espionage turned out to be the same noun. AI tooling and supply chain compromise became, on closer inspection, two ways of pronouncing the same word. We have been pretending these are different filing cabinets and they have, for some time now, been one filing cabinet on fire.
Let me walk you through it. Try not to flinch.
JANUARY. The year opened — opened — with a coordinated attack on Poland's energy grid that had quietly begun the previous December, because of course it did. The holidays are when the lights go out. We know this. The attackers know this. Only the org chart pretends otherwise.
ShinyHunters then claimed Crunchbase, because if you cannot trust the database of who funded whom, reader, what can you trust. They followed it up by lifting ten million records from Hinge, Match, and OkCupid in a single move, which means roughly half the romantic ambitions of the Western world are now sitting in the same directory as somebody's PowerShell history. Eurail had 1.3 terabytes taken including passport numbers, so if you booked a romantic train through the Alps last year, congratulations: your itinerary is now part of a different romance entirely.
And then — and this is the bit I want you to feel — the Conduent breach quietly grew. Disclosed last April at "around 4 million affected." In February it was revised. To 25.9 million. The number of affected human beings increased by twenty-one-point-nine million people while the rest of us were watching the news cycle. This is the undisclosed feature of modern breach disclosure that no vendor wants on a slide: the breach gets bigger after you stop looking at it. Like mould. Like grief. Like a houseplant nobody was watering.
FEBRUARY. Singapore had to admit, with the bureaucratic calm of a country that has its act together, that every single one of its four major telecoms had been quietly owned by UNC3886 for months. They mounted an eleven-month counter-operation called CYBER GUARDIAN to evict them. Eleven. Months. To evict. Houseguests. From a network. If your incident response timeline is measured in fiscal quarters, friend, it is no longer incident response. It is cohabitation.
France's Ministry of Economy disclosed that someone had wandered into the national bank account registry with stolen credentials and had a look around 1.2 million accounts. In any sensible country this would be a crisis. In 2026 it was a Tuesday. The European Commission and the Dutch government got popped through Ivanti zero-days, which at this point should just be reclassified as a recurring subscription.
A ransomware attack closed all 35 clinic locations of the University of Mississippi Medical Center and forced clinicians back to pen and paper, thereby demonstrating, conclusively, that the most resilient information system ever invented by the human species remains, and I cannot stress this enough, a biro.
PayPal sent breach letters dated February 10 about an incident that began in July 2025. A seven-month detection gap. Seven months. The industry has, collectively, decided to look at the floor when this comes up at parties.
MARCH. Telus in Canada had 700 terabytes stolen by ShinyHunters. Seven. Hundred. Terabytes. That is not a breach, reader, that is a house move. You do not exfiltrate 700TB without a removal van and a reasonable man named Steve to do the heavy lifting.
Stryker — the medical device company — was hit by an Iran-linked group called Handala in what was, charmingly, not a ransomware attack but a kind of vibes-based attack in which they just took everything down for a while and waited for the meaning to land. Foster City, California, had to pause all public services outside of emergency response because of ransomware, which is the municipal equivalent of phoning in sick to civilisation. Foster City is closed today. We are taking a personal day.
Qilin hit Die Linke, a German political party, who publicly attributed the attack to Russian hybrid warfare, which is either entirely correct or extremely good comms, and the genuinely upsetting bit is that in 2026 both can be true at once. The European Commission got popped again, this time on its public cloud, in case you thought February was a one-off.
APRIL. And here, friends, is where I have to ask you to hold something steady because the category changes.
Anthropic announced Mythos — a model so good at finding zero-days they put it in witness protection with twelve corporate handlers and called the safehouse Project Glasswing. They then, in what I can only describe as a structural triumph of irony, leaked the announcement of Mythos. The myth leaked. Days later they leaked half a million lines of Claude Code source for about three hours, the way a man drops a tray of glasses and pretends he meant to. And in that leaked code, somebody noticed an exploit that bypasses Claude's safeguards if you give it a command with more than fifty subcommands. Fifty. The model gives up around forty-seven the way you give up reading the cookie banner. Bureaucratic exhaustion as an attack class. There is a metaphor in here for the entire modern enterprise and I refuse to unpack it because I would not survive the unpacking.
Then OX Security dropped a ten-CVE family of command-injection flaws in Anthropic's MCP STDIO transport, meaning that the entire AI agent ecosystem you have been hearing about for a year — LangChain, LangFlow, Flowise, LiteLLM, Cursor, Windsurf — has been running on a configuration-to-RCE pipe for the better part of twelve months. Different researchers kept independently rediscovering the same flaw, like the cast of Memento taking turns to find the body.
North Korean threat actors, meanwhile, who have spent the previous quarter pulling off historic crypto heists weekly, are now reportedly doing it with AI assistance. Because of course they are. The defenders got Mythos in a safehouse. The attackers got whatever's on Hugging Face this morning.
THE SHAPE OF IT.
Sit with this. The CVE programme, twenty-seven years old, is forecast to hit 100,000 entries this year — roughly one new vulnerability every ten seconds, around the clock, forever. Median enterprise patch time is still twenty days. Median time-to-exploitation is now measured in hours, sometimes single digits of hours. The gap between disclosure and exploitation is no longer a window. It is a climate.
What we are watching, in real time, is the moment the speed of attack passed the speed of human bureaucracy and never came back. Every process we built — change advisory boards, patch windows, quarterly reviews, the whole apparatus of let's discuss this on Tuesday — was designed for a world that no longer exists. The world that exists now eats the boardroom while the boardroom is still scheduling the meeting about whether to convene the boardroom.
If you are a defender reading this: you have my sympathy and roughly forty-three minutes before the next thing.
If you are a vendor reading this: your booth at RSA is going to be a lot of forest-green lighting and the words AI-native and I am, in advance, not interested.
If you are a board member reading this: the answer to "are we exposed" is yes. The answer to "to what" is most of it. The answer to "can we fix this by Q3" is no — you can fix the culture by Q3. The systems will take longer. The mindset will take longest of all.
Four months down. Eight to go. Hold on to something nailed in.
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·