Canadian Cyber News Rewire - 18/07/26
Wiring you into the cyber news relevant to Canada the week ending July 18
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
Canadian Cyber in Context Updates
The Canadian Cyber News Rewire is a survey of Canadian cyber and adjacent news stories from this past week (or recently). Questions or business inquiries: info[@]cyberincontext.ca
In May, I was on a panel discussing the role of digital sovereignty and the security of critical infrastructure in Canada and NATO. You can watch the full panel here (CPAC).
Canadian News
I already thought this was already reported, but Reuters has obtained the email from the Office of the Superintendent of Financial Institutions to the financial industry.
Across Canada, the fight against artificial intelligence goes offline (The Globe and Mail)
Good article on data centres, particularly AI data centres, and the growing resistance to them. This is more than data centres = bad. The article goes into the larger anxieties, risks, and fears about how AI is upending our society and the lack of action by government and society to address the repercussions is making things worse.
“A former government scientist faces criminal charges after allegedly downloading thousands of work files from the Department of Natural Resources to external storage drives to further a new career in China, court records show.” He is charged with two counts of unauthorized use of a computer and one count of breach of trust.
1Password launches AI token spend management (Betakit)
“1Password said this will give organizations a unified view of their AI token usage across leading providers, beginning with Anthropic, Cursor, and OpenAI.” I usually don’t like to include vendor announcements as free advertisement, but I feel like 1Password has been a bit ahead of the curve on shifting towards AI support and administrative tools.
Canada’s securities regulators bolster cybersecurity guidance (The Globe and Mail)
“The Canadian Securities Administrators, an umbrella organization made up of provincial and territorial securities regulators, issued updated guidance Wednesday after reviewing the cybersecurity practices of 73 registered firms. The review included firms registered as investment fund managers, portfolio managers and exempt market dealers.”
Macdonald-Laurier Institute targeted, but important to keep in mind that they’re not the only ones; they’re just media-savvy. I know I have quite a few think tank folk following me: reach out to Alexandra Posadzki if you know your org was also targeted.
Canada signs United Nations Convention against Cybercrime (Global Affairs Canada)
The UN Convention against Cybercrime isn’t universally popular, but it will be welcomed by many in Canada.
IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets (Bloomberg)
Canadian cybersecurity firm accuses former contractor of sharing trade secrets concerning a previously unknown flaw used to hack iPhones with a rival firm Paradigm Shift Technology. Suit filed in Georgia.
Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation (The Record)
This isn’t the pot calling the kettle black. The Senator in question, Ron Wyden, is one of the strongest advocates for stronger cybersecurity and privacy. Nevertheless, Wyden's concerns are 100% the same as Canada's and everyone else's about US technology. Interesting how sovereignty concerns are framed, eh?
Black prisoners are assigned harsher living conditions in Ontario jails—thanks to AI (The Breach)
This is not surprising at all, and you are likely to find similar applications of AI, and it is a glimpse of how AI will be used to dehumanize and make things worse for people and rationalize racist and unfair practices that do nothing but confirm racism on part of the judicial system. “Black prisoners in Ontario’s jails are being assigned to harsher living conditions than other prisoners, through the use of an artificial intelligence (AI) tool that claims to predict their behaviour.”
Federal government announced 63 Quebec-based companies to receive $13.85 million as part o the rEgional Artficial Inteliigence Initiative.
Good intro article on growing importance of data centres by a Junior Research Fellow at the NATO Association of Canada.
Widow loses nearly $1M after falling for AI deepfake video of Canadian prime minister (Cybernews)
This was reported originally a month or so back, but including again as it is reported elsewhere. 86-year-old woman falls victim to deepfake crypto scam off of Facebook. Keep in mind that Facebook/Meta receives revenue from these paid advertisements and thus profits from such scams.
Cyber Intel Brief: The Gentlemen Ransomware Group Claims TKMS/Atlas Elektronik Breach )(Dataminr)
Canada recently announced a major deal with TKMS for submarines, so I am surprised this has not crossed my feed until now. TKMS has been hit with an extortion attempt due to a subsidiary being hit.
Alberta and Quebec join forces to put AI to work (Government of Alberta)
Alberta and Quebec to collaborate on AI adoption and public service modernization.
“Canada’s anti-money laundering watchdog believes a “substantial portion” of the country’s cash-to-cryptocurrency brokers are knowingly helping criminals launder money and evade international sanctions.”
Events
BSides Ottawa folk are fantastic people; highly recommend any event put on by them.
Parliamentary News & Upcoming Meetings
This section includes any House of Commons and Senate meetings that are relevant to Canadian cyber.
Parliament has begun its Summer break and will resume sitting on September 21.
Canada-Relevant News
As many issues don’t respect borders, this section is for stories that impact Canada, but may not be Canadian-sourced or focused, to differentiate from the previous section, which is 100% focused on Canada.
Targeting and Compromise of French Entities Using the Turla Instrusion Set (PDF)
Good report from France on FSB use of Turla malware.
There is a reason why Kaspersky has always had a poor reputation in the West, but this really doesn’t help them at all.
Ongoing coverage of Russia hacking cameras.
SonicWall customers under threat as attackers exploit 2 zero-days (Cyberscoop)
Using two zero days used to be an indication of an APT. These days it’s nothing special.
Over 5,800 arrests, USD 293 million intercepted in global fraud bust (Interpol)
Interpol coordinated an anti-fraud operation across 97 countries that led to the arrest of 5,811 people.
Ernst & Young discloses data breach after support system hack (Bleeping Computer)
All of the big consulting firms are getting hit lately.
Microsoft Patches a Record 570 Security Flaws (Krebs on Security)
A whopping 570 security flaws were fixed in Microsoft’s recent patch deployment, which sets a record and highlights the growing advances in using AI in software development.
Claude can now use your passwords to carry out tasks for you (Yahoo Finance)
This is a really bad idea. Don’t do this.
Canadian Cyber Threat Intelligence
Any relevant cyber threat intelligence to Canada will be posted here. I only list the Canadian Centre for Cyber Security’s (CCCS) alerts here, not all advisories; follow the full feed here.
WordPress Core “wp2shell” RCE flaws get public exploits, patch now (Bleeping Computer)
I feel like any WordPress exploit is bad, but this is a particularly bad one.
Canada joins allies in releasing guidance on how to protect oneself against Russian hacking of routers
Identity Attacks Overtake Exploits as Top Ransomware Cause (DarkReading)
I don’t think any analyst is surprised by this. Phishing and low-skill entries remain the most common vector of attack.
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
United States News
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance (Wired)
Police left the livestreams of their drones exposed, which was shared with Wired. It’s very rare to get police drone footage, so this is very interesting and revealing reporting. Drone use by police is also on the rise in Canada as well. I do not think to the degree in the US quite yet, but most major police departments in Canada will likely have drones.
Department of Defence institutes a 60-day review of CMMC. Many are concerned this will lead to significant changes, but it is more likely to provide a review and a breather to prepare for the change in the CMMC standard from NIST SP 800-171 Revision 2 to Revision 3. This whole ordeal is motivating me to write “CPCSC is better than CMMC.”
New York to impose the country’s first statewide moratorium on data centres (CTV News)
“New York will block the construction of any new large data centres for up to a year so the state can create rules to protect the environment and energy grid from the power-hungry facilities that fuel artificial intelligence technology.”
They wanted to hold Exxon accountable. Then they got hacked. (Grist)
“A decade after climate activists’ emails were breached, a court case is shedding new light on who allegedly orchestrated the hacking.” Corporations hiring private hackers to go after other parties in a lawsuit is something that regularly occurs, way more often than you may think.
A bit of a nonsensical statement, but Gold Eagle is related to the recent executive order (Congress) on AI and cybersecurity.
““GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. Open-source software partners and American critical infrastructure companies built a coordinated system to receive and patch cyber vulnerabilities at a speed and scale never seen before using the existing authorities and resources of the federal government.”
Coca-Cola suspended production at its Fairlife dairy after a ransomware attack (TechCrunch)
“U.S. beverage maker Coca-Cola said one of its dairy subsidiaries was hacked and that it’s shutting down its operations for the foreseeable future… Fairlife’s operations in Canada are unaffected.”
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores (Wired)
San Fransico Attorney’s Office sent cease and desist letters to Apple and Google, claiming they are aware of the problem, but insufficiently taking action.
US Congressman Introduces new Bill to Allow President to Issue Letters of Marque (US Congress)
Text not available yet, but these bills pop up every year or so and usually go nowhere. There were some concerns last year about the US going ahead with this, but they later made it clear they weren’t interested in private actors conducting cyber attacks. With this administration, things could quickly change, so this remains something to watch.
US companies face rise in cyber attacks (Reuters)
Canadian trends usually mirror US trends because we’re often caught up in the same attacks due to our integration and
United Kingdom and European Union News
“A cyberattack that threatened to cut heating to half a million people in Poland last winter was formally attributed Monday to Russia’s Federal Security Service (FSB), as the United Kingdom and European Union imposed their first coordinated package of cyber sanctions against Russian hackers.”
EU leaders eye social media ban for children under age 13 (The Record)
A social media ban for those under 13 is odd, since most websites already restrict access and require you to be over 12. President Ursula von der Leyen envisions giving gradual access to children once they turn 13, “depending on the proof given by the platforms that they are age-appropriate and safe for teenagers.”
These are not serious people making serious policy proposals. This might be one of the most nonsensical plans for a social media ban.
Increasingly it seems that Palantir sucks for anything not defense/security related: “In private briefings we obtained, senior NHS leaders went even further, complaining that Palantir’s software has a “poor user experience”. Kanthan Theivendran, an orthopaedic surgeon at a trust in Birmingham, stopped using Palantir’s flagship waiting-list app because he couldn’t edit the data: “It’s just a waste of time,” he told us.”
Interesting case where a password manager is nearly identical down to the code and manual of a Russian password manager.
Europe revives law allowing big tech to scan for CSAM (The Record)
“The European Parliament has voted to bring back a rule giving big tech permission to scan users’ messages to hunt for child sexual abuse material (CSAM), a process that critics call Chat Control.”
Romania’s land registry database was deleted after a failed extortion attempt. This is likely to have major economic impact.
UK’s communications regulator is investigating TikTok for failing to protect children.
UK’s Burnham drops digital ID scheme to prioritise cost of living, say allies (Reuters)
This was one of the more controversial proposals in the recent push to remove privacy from the Internet.
France orders internet providers to block access to Polymarket prediction site (France24)
Keep in mind that Polymarket is technically banned in the United States as well.
Other International News
Cyberattack on Japan’s largest cold-chain operator disrupts KFC, supermarket supplies (The Record)
Keep in mind that food distribution and production is considered critical infrastructure. “Nichirei Logistics Group, which transports frozen and refrigerated food for about 5,000 customers across Japan, said it experienced a system outage on Monday.”
Abbott investigates two separate cyber incidents, says no operations affected (Reuters)
Unclear where the incident took place as Abbott Laboratories is an international company, but reporting is from India.
HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs (Ars Technica)
I feel like this is one we can all support and get behind.
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign (OpenSourceMalware) [h/t Catalin Cimpanu)
North Korea linked to an ongoing supply chain campaign.
Kenya investigating cybersecurity incident affecting president’s website (Reuters)
Attacks targeting African governments are on the rise.

