Canadian Cyber News Rewire - #30 (01/08/26)
Wiring you into the cyber news relevant to Canada the week ending August 01 2026
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
The Canadian Cyber News Rewire is a survey of Canadian cyber and adjacent news stories from this past week (or recently). Questions or business inquiries: info[@]cyberincontext.ca.
Canadian Cyber in Context Updates
It is official: I will be defending my PhD dissertation, “Why States Hack the Planet.” I will maintain my posting with the Weekly Rewire, but I also have a busy month of writing two book chapters + prep defence, so I may be a tad quiet.
I have reopened the Canadian Cyber in Context survey. The survey helps me make decisions about the direction of the newseltter, including how much non-Canadian content should I include in the Weekly Rewire?
Canadian News
Crown corp lends up to $200M for Meta data centre gas plant in Alberta (National Observer)
Meta getting government support to build massive polluting gas plant at a data centre in Alberta.
A missing underscore sent innocent man to prison for 18 months (Ars Technica)
US law enforcement failures led to an innocent Canadian man being put in prison for 18 months. It took the innocent man’s his lawyers discovered the police’s simple mistake that cost him his freedom.
Canadians Want Surveillance Pricing Banned (The Tyee)
Banning surveillance pricing is a pretty easy win for the government to protect consumers, but cabinet doesn’t understand it because it doesn’t involve giving money to businesses and saying they’re great.
Europe is tackling the cloud oligarchy. Why isn’t Canada? (Financial Post)
An op-ed by people involved with the Canadian Anti-Monopoly Project
Canadian Forces School of Communication and Electronics Operation’s NOBLE SKYWAVE 2026 Announced (Nobleskywave.ca)
“For 13 years, Exercise NOBLE SKYWAVE has brought together Canadian Armed Forces members, allies, partners, and amateur radio operators from around the world to test their skills in High Frequency (HF) communications.”
BREAKING: Ottawa to scrap all contribution requirements for U.S. streamers (The Wire Report)
“The Liberals are preparing to eliminate all funding requirements for U.S. companies under the Online Streaming Act.” This is a major hit to Canadian sovereignty.
(Paywalled) Where data centres are proposed, Ontario voters have questions for their local candidates (National Observer)
I have been waiting for reporting like this. Data centres aren’t becoming an election issue, they already are. Parties will may have a very pro-AI and data centre stance, but that will hurt individual candidates. This will certainly lead to a lot of pressure between individual candidates and parties in Canada as they find a way to maintain a party line versus recognize the major resistance at the local level, which may cost candidates.
IBM Report: Cost of a Data Breach Report 2026 The AI tipping point (PDF)
The average cost of a breach is up compared to last year, according to IBM. Average costs went from $4.84M (USD) to $5.20M (USD). The biggest hit is the energy sector, which is not too surprising. According to IBM, firms that use AI found and contained breaches faster.
Overall report doesn’t just talk Canada, but has good info on Canada and broader trends.
The Cyber Centre and Technologies (Canadian Military Journal)
A short article by Ashar S. Ahmed which provides a nice overview and introduction to the Canadian Centre for Cyber Security
(Op-ed): AI Belongs on the Defence Side of the Cyber Ledger (Centre for International Governance Innovation)
Opinion piece by Shelly Bruce, former Chief of CSE.
CAF launches Canadian Deep Precision Strike Capability (CDPSC)
Capability must also be able to operate while faced with: electronic warfare,
cyber threats, Global Positioning System (GPS) disruption, and air defence systems.
In-person and virtual industry day planned for August 7; they are specifically interested in those who can contribute: autonomous systems, navigation, communication technologies, artificial intelligence, and supporting command-and-control and training systems.
Job Opening - Toronto Metropolitan University: Program Lead (LinkedIn)
TMU is looking for a program lead for its Catalyst Cyber Clinic programs. I am a big fan of TMU’s Rogers Cybersecure Catalyst. They’ve been leading on cyber education and awareness in Canada. Katie Gibson and the Cyber Clinic program in particular are a gold standard in Canada, so I highly recommend applying for this.
Semiconductor industry says Canada needs a better plan for sovereign silicon (Betakit)
Semiconductor industry wan’ts a seventh pillar under the AI strategy to support the Canadian semiconductor industry. Although self serving, they do have a point and there is a need to increase domestic capacity and control for key industries.
CAFCYBERCOM’s Cyber Training Unit Change of Command (LinkedIn)
CAFCYBERCOM conducts a change of command ceremony for its Cyber Training Unit (CTU). The CTU is CAFCYBERCOM’s core force generation unit, based in Kingston, but sends students to one of two colleges in Ottawa or one in the Maritimes to provide foundational cyber training before proceeding to advanced cyber training at the Royal Military College and the Canadian Forces School of Communications & Electronics in Kingston.
Canada’s Willis College Launches DND-funded Military Cybersecurity Initiative in Jordan (Yahoo Finance)
Jordan is adopting CAF Cyber Training Unit’s foundational training program curriculum
Willis College is one of three colleges that CAF cyber operators receive foundational cybersecurity training. (It is the least popular/liked one). Willis College will transfer the curriculum to Jordan and approximately 120 members fo the Jordan Armed Forces to attend Willis College for cyber foundations training.
Carleton University team launches platform for digital twin of Canada (The Globe and Mail)
Digital twinning is on the rise to promote better engineering, which raises implications for a need for better cybersecurity in development environments.
CPKC’s automated replacement for human inspectors missed dozens of defects: U.S. agency (Investigative Journalism Foundation)
“U.S. Federal Railroad Administration (FRA) concluded remote, automated and human-free safety inspection was “not in the public interest and consistent with railroad safety at this time.” This is emblematic of many automated systems in general at the moment where the rush to deploy is too quick based on technology that is still too early in development.
Government of Canada invests $2.7 million to strengthen Northeastern Ontario’s defence sector (Government of Canada)
Includes a $1.2 million investment into SKADI Cyber Defense Corporation to help advance and commercialize its Frostbow AI Cyber Defense system.
Not sure how I feel about a Canadian company using “defense” instead of “defence”
Minister Sidhu establishes Strategic Exports Office to strengthen Canada’s global competitiveness (Government of Canada)
Includes a few major Canadian cyber/cyber-adjacent companies, including: OpenText (software), CAE (big in simulation), Telesat (SatComs), MDA Space (Space, increasingly important in SatComs).
New Training Opportunities for Government of Canada Employees: (Talent Canada)
Only available for IT-classified or acting IT employees in the government of Canada. New courses include CompTia Cloud Cert Training (Deadline August 21); IT Security Risk Management Boot Camp (Deadline August 28); Beedie School of Business Technology Leadership program (Deadline August 7); uOttawa Cyber Range: Information Security Crisis Exercise (Deadline August 22)
Canada Research Chair in Information Law and Policy Teresa Scassa: Unpacking the roles and responsibilities under Canada’s proposed Protecting Privacy and Consumer Data Act (Substack)
Professor Teresa Scassa breaks down the proposed Protecting Privacy nad Consumer Data Act.
Targeting the taps: Why foreign hackers are striking Quebec’s water plants (CBC News)
Coverage of Canadian water plants being hit. Maybe not as much as US plants being hit, but Canadian plants and critical infrastructure are also being hit.
Data centre proposal in Sault Ste. Marie, Ont. met with opposition (CBC News)
More local opposition to data centres.
KPMG Canada and OpenAI form strategic alliance (KPMG)
KPMG Canada enters into alliance with OpenAI. I suppose they want to release faked reports as well? All the big consulting firms are rushing to use AI and releasing lots of slop and inaccurate reports because of it. The big consulting firms are washed and broken and shoudn’t be used. They’re all just running through stuff through AI anyways.
Nova Scotia Digital Transformation of Provincial Court Underway (Nova Scotia)
Nova Scotia has started a digital transformation of its court system, which will include multiple online filing systems.
Hackers Target Bitcoin’s Safest Hiding Place in Ongoing Attack (Bloomberg)
Canada-based Coinkite notified its users of a security flaw in its coldcard devices that allowed a compromise of the keys to compromise their cryptocurrency wallets. This was previously thought of as one of the safest storage as it was not connected to the internet, but the encryption and keys which underpin everything were compormised which collapsed the entire system.
Canadian Events
Ottawa - October 17 - OWASP Ottawa Day 2026 (Google Forms)
The Ottawa chapter of the Open Worldwide Application Security Project (OWASP) has opened its call for papers for its OWASP Ottawa Day.
I was invited to submit and present, so I hope to see some of you in October!
INCYBER is quickly becoming one of the go-to conferences for cyber in Canada. I will likely be attending this event
Parliamentary News & Upcoming Meetings
This section includes any House of Commons and Senate meetings that are relevant to Canadian cyber.
Parliament has begun its Summer break and will resume sitting on September 21.
Canada-Relevant News
As many issues don’t respect borders, this section is for stories that impact Canada, but may not be Canadian-sourced or focused.
Ongoing coverage of OpenAI’s Model Failure
Discovering cryptographic weaknesses with Claude (Anthropic)
Anthropic article detailing how Claude Mythos was used to figure out how to weaken a post-quantum cryptography algorithm under consideration for standardization and to break a weakened version of the widely used AES standard.
Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security (Nvidia)
“NVIDIA and founding members form new alliance to build and share open tools that promote responsible use of and trust in AI.” Major initiative with a lot of companies on board.
Canadian AI darling Cohere is amongst those that joined the initiative.
Tons of Peoples’ Claude Chats and Creations are Exposed on Google (404Media)
Many Claude users using public share links don’t realize that it allows them to show up in Google searches.
Data Centers Are Easy to Build. Powering Them Is Complicated, Slow, and Expensive (404Media)
While this holds true for all data centres, it is particularly true for AI data centres, which have power loads way higher than cloud data centres. A big problem is the spikes and drops in power in addition to the gross amount of power required.
AI Companies Are Trying to Hide a Staggering Amount of Debt (Futurism)
If not a bubble, then why bubble shaped? The problem is that the core of companies that the entire industry has developed around is so unbelievably in debt to drive AI adoption and growth.
Microsoft Introduces its own Cybersecurity AI: Introducing MAI-Cyber-1-Flash inside MDASH (Microsoft)
Microsoft doesn’t have a good track record with its AI, so I don’t think anyone has a lot of high hopes or expectations, but it’s at least more competition for cybersecurity-related models.
Google Earth’s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images (404Media)
Google creates a disinformation tool. Google has integrated an AI image manipulator into Google Earth, which makes creating fake satellite images very easy.
Iran struck Amazon data centers again amid widening war, satellites show (Ars Technica)
Digital infrastructure is dual-use infrastructure if used by the military and could be considered legitimate targets under international law.
Canadian Cyber Threat Intelligence
Any relevant cyber threat intelligence to Canada will be posted here. I only list the Canadian Centre for Cyber Security’s (CCCS) alerts & guidance here, not all advisories; follow the full feed here.
Protect your devices from SMS blasters (ITSAP.00.104) (Canadian Centre for Cyber Security)
Google’s solution to hacker name confusion? Yet another naming system (Cyberscoop)
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit (Proofpoint)
Half-click exploits are not new by any means, but I have to question if there is a start of a trend here.
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs (CISA)
Cyber threat bulletin: Non-state activity targeting Canadian operational technology (Canadian Centre for Cyber Security)
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability (Lava)
Going Beyond Zero: A New Paradigm For Enterprise Security (Google)
Google is innovating on zero-trust security to try to contend with new trends and AI.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication (Unit42)
Palo Alto Network’s Unit42 finds vulnerability in Google’s passkey system.
Microsoft Teams vishing attacks lead to Chaos ransomware attacks (Bleeping Computer)
Canada is one of the primary targets.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft (Microsoft)
Microsoft is saying Russia is hitting all of those hotel wi-fis for credential farming.
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
United States News
“The U.S. government has charged Samuel Tunick with allegedly typing in a passcode to wipe his phone before officers could search it.” US government shakedowns of people and citizens at the border are increasing.
Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran (NYTimes)
This might be the largest cyber attack, or one of the largest, on US critical infrastructure to date. The attacker is unknown, but there is a limited set of APTs who would be seeking to conduct such an attack on the US.
This is hitting approximately 7 states already; Minnesota just might be the epicentre or where it is first being reported.
Ariana Grande Suing Alleged Hackers Over Leaks (TMZ)
Hack-and-leak operations will target anyone, with public figures more likely to be targeted.
Republicans shunned the nation’s cyber agency. They’re urgently trying to save it. (Politico)
Republicans learn that cybersecurity doesn’t care about politics and Trump admin tries to rebuild election security infrastructure it gutted as midterms near (CNN)
FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap (TechCrunch)
Tech healthcare companies have a terrible track record for keeping data private.
Research Article: Before a Cyber Force, Fix Cyber Governance (War on the Rocks)
Good article addressing the bit of a hot mess cyber governance is in the US and how making a Cyber Force or branch wouldn’t necessarily fix this.
Cyber Command plans Silicon Valley office to drive innovation (The Record)
Will be co-located at first with the Defense Innovation Unit (DIU) before expanding. The fact that this is not through the DIU is interesting, but it appears that it will support the Cyber Innovation Warfare Center and drive CYBERCOM 2.0 to find a way to make up the current perceived initiative gap in the cyber strategic environment.
US military may require some troops in Mideast to surrender cell phones, sources say (Reuters)
Iran has leveraged ad and cellphone data to target US forces in the region.
Contrary to reporting, the US is not just banning humanoid robots, but is a much larger ban on “advanced robotic devices” and power inverters.
Small Towns Shouldn’t Have to Defend America’s Water Supply From Iran (NYTimes)
Former CISA Director Jen Easterly pens great opinion article. Cyber civil defence is only growing in importance.
United Kingdom and European Union News
UKCT Report: “One Network, Two Systems: The Research Security Risks of UK/China University Cyber Partnerships” (Natto Thoughts - Substack)
An analysis of UK-China institutional cyber collaboration.
Russia Charges Telegram’s Founder With Facilitating Terrorism (NYTimes)
Russia has been slowly ramping up pressure on Telegram over the past few months as Russia tries to push its entire populace onto platforms they control so it can watch all of its citizens.
Hackers steal sensitive data from UK Department for Education and police (The Guardian)
Appears to be the work of an extortionist group, ExfilSquad, and not Scattered Spider, which some early chatter seemed to suggest.
How police are trying to divert teen hackers away from crime (BBC News)
The UK seems to have had a particular problem with teen hackers, so it developed this program to help with that and it appears to be making progress.
Denmark Readies Emergency Reserve Bank to Fight Cyberattacks (Global Finance) [h/t Sherpa Intelligence]
“To counter major cyber threats, Danmarks Nationalbank is pioneering an offline emergency payment system.”
Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations (The Record)
This is a bad one and will lead to all of these businesses being targeted.
Other International News
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn (The Record)
A concerning trend, which reverses policy. A lot of potential danger from this with the proliferation of tools.
About 900,000 Origin Energy customers affected by hack as company admits it was warned weeks before public told (The Guardian)
A tale as old as cyber: Company ignores warnings until things get even worse.




