Canadian Cyber News Rewire - #31 (08/08/26)
Wiring you into the cyber news relevant to Canada the week ending August 08 2026
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
The Canadian Cyber News Rewire is a survey of Canadian cyber and adjacent news stories from this past week (or recently). Questions or business inquiries: info[@]cyberincontext.ca.
Canadian Cyber in Context Updates
It is official: I will be defending my PhD dissertation, “Why States Hack the Planet” on September 11. I will maintain my posting with the Weekly Rewire, but I also have a busy month of writing two book chapters + prep defence, so I may be a tad quiet.
I have reopened the Canadian Cyber in Context survey. Thank you to those who have already taken the 30-second survey. Changes are already being integrated!
Canadian News
Telesat, MDA Space tapped for $2.3-billion Arctic satellite buildout (Betakit)
“Defence Investment Agency (DIA) has awarded a new, $2.3-billion CAD contract to Ottawa-based Telesat.” For Enhanced Satellite Communications Project – Polar (ESCP-P) project, with satellites being built by MDA Space. North and Arctic connectivity is a major concern right now. I have previously written about the need for improved connectivity in the North/Arctic, and it is a major priority in DND/CAF’s current plans.
The Government of Canada awards a military communications contract to support Arctic sovereignty and national security (Government of Canada)
The government’s announcement concerning the above.
The Warrant You’ll Never See: How US Agencies Can Access Canadian Data Without a Court (Devious Plan Blog)
Good article on how Canadians could get caught in a geofence warrant.
Privacy Commissioner of Canada welcomes efforts to modernize Privacy Act in submission to government consultation (Government of Canada)
Privacy Commissioner has released his submission on the Treasury Board of Canada Secretariat (TBS) consultation on Privacy Act modernization.
Canada’s launches Quantum Defence Innovation Secure Hub to strengthen defence capabilities (Government of Canada)
A University of Calgary-led consortium will receive $20.3 million to establish a Quantum-focused defence innovation secure hub to support the development and innovation of defence-related quantum technology.
Minister McGuinty concludes Alberta visit focused on innovation and strengthening Canada’s defence capabilities (Government of Canada)
Includes some highlights of cyber-adjacent firms, including Landing Zones Canada, which receiving support to advance their Remotely Piloted Aircraft System (RPAS) flight control software.
Job Opening: Computer Security Incident Response Team Analyst Various Roles and Levels at the Communications Security Establishment (Government of Canada)
CSE’s computer incident response team is growing. Amazing opportunity to work with Canada’s top incident responders.
US chip giant AMD to acquire Taalas (Betakit)
A story as old as time: US firm buys Canadian firm. AMD will acquire Toronto-based Taalas for $50 million. Taalas is trying to improve AI efficiency through hard-wired computation.
(Research) A Day in the Life Without American Tech (Canadian Shield Institute)
A cool project by the Canadian Shield Institute that examines what would happen if American tech was turned off overnight.
Google’s AI traffic pilot coming to Vancouver (Investigative Journalism Foundation)
Before we jump to scaremongering this, this project has been running since 2016 and been deployed in Windsor, Quebec City, and many other places. Has a proven track record and is a good example of how AI and machine learning can be used for uses other than large language models.
Company behind Olds data centre lobbying Alberta government for project approval (Peterborough Examiner)
Original proposal was denied by Alberta Utilities Commission, but the company is now lobbying the government. Its lobby filings state that they hope to “encourage a fair and timely application of the existing law for this current project and potential future projects.”
What we know about ongoing Coldcard hack that’s stolen over $100M worth of bitcoin (CBC News)
Massive attack on crypto hardware wallets. A vulnerability in the underlying software that constructed seed phrases was cracked by hackers, which allowed them to steal over $100 million in cryptocurrency. This will be devastating to those holding these because the hardware storage was unconnected to the Internet, but this didn’t matter to steal the crypto.
Coinkite has destroyed its inventory and is working with customers to protect and move money.
This FTX claims broker is now courting victims of a $155-million hack of a Canadian bitcoin firm (The Globe and Mail)
“A U.S. firm that specializes in distressed cryptocurrency investing and previously brokered close to US$1-billion of FTX bankruptcy claims is bringing together victims of the Coinkite Inc. hack for a potential lawsuit against the Toronto-based crypto wallet maker.”
Statement by the Government of Canada on the notice of settlement approval regarding the Sweet v HMK Class-Action (Government of Canada)
Government statement on class action for privacy breaches related to Government of Canada online accounts, including the Canadian Revenue Service and Service Canada, and other sites using GCKey.
Commentary: Time for Canada to take a fix on defence cybersecurity provisions (Policy Options)
I do not agree with Ron Lloyd on this at all and he gets a few things wrong, but agree that CPCSC as a program is holding too similar to the US’ CMMC when, at this point, we should not care about reciprocation with the US and develop a better program for Canada’s needs.
Let us also keep in mind that CPCSC is still not fully implemented and level 1 self attestation is only required for select procurements.
“This Is a Tale of Power”: The 1976 Royal Commission That Asked Whether IBM Canada Controlled the Canadian State (Hansard Files - Substack)
Great article on a story I was unaware of, but completely makes sense. Unfortunately, if the same study was conducted today, the government would likely praise Microsoft’s monopoly as it did with IBM’s.
Canada’s Strategic Exports Office (Government of Canada)
GAC, with Export Development Canada, launches the Strategic Export Office to support defence and security and civil strategic exports. Digital ecosytems is specifically mentioned under civil strategic exports.
The most recent National Cybersecurity Strategy committed Canada to supporting the growth and export of cyber, but that has largely not occured thus far before this.
Flare launches free dark web intelligence training lab (SecurityBrief Canada)
I usually don’t like to post marketing PR, but I quite like what Montreal-based Flare is doing here. Flare has launched a cybersecurity fraining lab for everyone, including students, that is free on Flare’s discord.
RCAF establishes new Security Forces occupation to meet evolving operational requirements (Government of Canada - The Maple Leaf)
The new occupation supports “advanced air and space systems that require higher levels of security.” I am curious if these people will be more at 3 Canadian Space Division or CAFCYBERCOM.
mode40 and CME Launch AeroTrace Initiative to Accelerate AI Adoption in Prairie Aerospace and Defence (PR Newswire)
mode40 and Canadian Manufacturers & Exporters launch AeroTrace Initiative to “demonstrate, validate and communicate the value of AI-enabled systems, traceability, digital-thread capabilities and operational intelligence for aviation, aerospace and defence manufacturers.”
Leading AI Development Responsibly (Government of Alberta)
Alberta launches website to market data centres to its citizens and to provide Albertans an easier means to provide feedback to the government and knowing when Town Halls are occuring. How they market AI data centres in many ways should be critiqued, this is a great initiative to provide an improved means of engaging with the public about data centres.
Canada must ‘be vigilant’ of foreign actors targeting technology: minister (Global News)
Answer is in response to intellectual property theft, particular from China. Cites Nortel as the example.
This tells me that ThinkOn actually knows what’s going on in DND/CAF and makes me happy. The CAF is increasingly using TAK at the tactical level and I envision will likely be the norm in the future despite its non-Canadian origins, so this is a great move by ThinkOn. ThinkOn is the only major Canadian cloud provider for the Canadian government.
Head of Canadian Centre for Cyber Security participated in a Black Hat panel
Western government leaders call for a focus on infrastructure resilience, not AI hype
Coverage of the above panel.
[Google Translated] Trends in digital transformation within public administrations (Government of Quebec)
Quebec’s Ministry of Cybersecurity and Digital Affairs releases report on trends in digital transformation in the government that it has been tracking. Includes info on the use of AI and agentic AI.
Share your thoughts about making consumer protections clearer for Canadians (CRTC)
The CRTC is looking for feedback on ways to improve consumer protections, including combining all four consumer protection codes (the Wireless Code, the Internet Code, the Deposit and Disconnection Code, and the Television Service Provider Code) into a single code.
Cadets Technology and Digital Learning Centre (TDLC) (Government of Canada)
Canadian Cadets are currently taking a course on Cyber Safety and Security Team Leader.
Parliamentary News & Upcoming Meetings
This section includes any House of Commons and Senate meetings that are relevant to Canadian cyber.
Parliament has begun its Summer break and will resume sitting on September 21.
Canada-Relevant News
As many issues don’t respect borders, this section is for stories that impact Canada, but may not be Canadian-sourced or focused.
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide (Wired)
Hacker Summer Camp is going on in Las Vegas, so lots of interesting stories abound like this one. I'm personally not too surprised by this one. North Korea is amateurish in its opsec and operations, but it has persistence, funding, and the capacity of a state to be able to be successful.
Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (US Justice Department)
CBC Coverage (CBC News): Canadian man behind Snowflake hacks pleads guilty. The Snowflake breach led to 165 organizations (at least) getting hit and millions being extorted.
Google says hackers are calling financial firm employees to hack and extort victims (TechCrunch)
Meta Caught Paying Nazis to Post on Facebook (Futurism)
Literal Nazis were part of Facebook’s content monetization program. This is not surprising because many hate groups and criminal organizations operate on Facebook. Stop using Facebook. Facebook is just for disinformation campaigns and causing harm.
New Mexico court orders Meta to pay $567M to address platforms’ harms to young people (CBC News)
Meta orderd to pay another $567 million to address harms to young people. Meta produces a lot of harm and profits off of it. That’s not me saying it, that’s the courts.
Microsoft wins ‘lamest vendor’ at Pwnie Awards 2026 for threatening security researchers with legal action (ThisWeekinSecurity)
There are now official metrics where we can officially call Microsoft the most lame. Spread the word.
Canadian Cyber Threat Intelligence
Any relevant cyber threat intelligence to Canada will be posted here. I only list the Canadian Centre for Cyber Security’s (CCCS) alerts & guidance here, not all advisories; follow the full feed here.
Cyber threat bulletin: Non-state activity targeting Canadian operational technology (Canadian Centre for Cyber Security)
Canadian bulletin in response to rising attacks on critical infrastructure including recent Iranian attacks on water infrastructure.
How the Canadian Centre for Cyber Security used frontier AI to accelerate detection engineering (Canadian Centre for Cyber Security)
Communications Security Establishment and the Cyber Centre will begin to release reports on how they’re using AI at the Forntier AI Lab.
Protect your organization from malware - ITSAP.00.057 (Canadian Centre for Cyber Security)
Part of the Cyber Centre’s awareness series.
Security considerations for electronic vote tabulators - ITSM.10.102 (Canadian Centre for Cyber Security)
Guidance document cocnerning electronic voting machines.
Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages (HackRead)
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers (DarkReading)
Samsung’s recommendation: Rent out your TV’s Internet connection (Mnemonic)
Why worry about AI when Samsung is giving threat actors access to your TV and network?
Canadian Events
Ottawa - October 17 - OWASP Ottawa Day 2026 (Google Forms)
The Ottawa chapter of the Open Worldwide Application Security Project (OWASP) has opened its call for papers for its OWASP Ottawa Day.
I was invited to submit and present, so I hope to see some of you in October!
Ottawa - November 19-20 - BSides Ottawa (Bsides Ottawa)
I have been working with the BSides Ottawa folk to help put together the Policy Village for the past couple of years and will be doing so again this year.
INCYBER is quickly becoming one of the go-to conferences for cyber in Canada. I will likely be attending this event.
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
AI News
Due to the pace of AI and amount of news each week, this section will be dedicated to important AI news to keep the other sections more focused.
Apple seeks preliminary injunction against OpenAI in trade secrets case (Reuters)
This could lead to massive hurt for OpenAI.
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree (Wired)
More evidence of criminal negligence.
Meta becomes latest firm to say its AI hacked another company (BBC News)
Meta joins other AI companies in not understanding what a sandbox is. Let us hope that the criminal behaviour is actually punished, but I think we all know that’s not going to happen. These companies implement the absolute worst and lazy controls, and then are surprised that they break. These are not serious people, but serial arsonists who do not care about the consequences of their action except to market their product.
White House finalizes AI framework behind closed doors (Axios)
Whitehouse announced it met its deadline to establish a voluntary to evaluate AI models, but they haven’t publicly released it.
Incident Report: unsanctioned agent behaviour during cyber testing (UK AI Security Institute)
The UK’s AI Security Institute also hacked innocent people during their tests. This test is even more criminally negligent compared to the others because AISI intentionally gave internet access with no guardrails and no monitoring. This is negligence and stupidity on a level that should have nothing to do with AI or the government. I am starting to think there are no legitimate security experts in the field of AI. This is gross negligence on an international scale at this point.
ByteDance targets mega AI model that could match Mythos scale, FT reports (Reuters)
You should assume that most major AI or frontier AI firms are developing a cybersecurity model.
United States News
Trump administration drafting ban on Chinese data center devices, sources say (Reuters)
This will have a major impact on industry. If NATO or Five Eyes allies respond in kind, this will make data centres and advanced communications technology in general even more expensive.
Cyberattack disrupts operations at NC Ports in Wilmington, Morehead City and Charlotte (WECT News) [h/t Catalin Cimpanu]
North Carolina Ports IT systems hit with cyber attack that disrupts operations at 3 ports. No attribution yet, but many people are already thinking Iran.
America’s Cyber Forces Grapple With Cluster of Deaths by Suicide (Bloomberg)
The US Cyber Forces have been busier than ever, but haven’t received the support they need.
CISA still finds water system controls exposed online amid multistate hacks (NextGov)
Anyone in cyber knows this has always been a thing and won’t change anytime soon.
Hackers targeted another Georgia water system. Officials say the water supply was not affected (WSB-TV Atlanta)
New water systems found to be targeted by hackers. Water supply not affected, but some of these attacks have led to boil water advisorys and more manual operations. This is unlikely to be fully resolved anytime soon.
Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record)
This is also the case in Canada as well.
New Amazon Data Center Is Set to Have the Most Polluting Power Plant in the U.S. (NYTimes)
Gas-powered power plants to provide power for AI data centres is all the rage right now. This is not an American thing either, this is becoming a thing in Canada as well and at least one major data centre in Alberta will have similar infrastructure.
CYBERCOM 2.0 (Youtube)
Pete Hegseth puts out a video explaning the next phase of development for USYCBERCOM. Don’t tell me why it is a video, the Hegseth is a demented loser. Essentially saying they’re focusing on force generation/recruitment and reduction of bureaucracy. Reduction of bureaucracy is likely code for approving more reckless offensive cyber operations.
Military device manufacturer discloses cyber incident to SEC (The Record)
IEH corporation produces a range of specialized military products used in military satellites, missiles, and jets.
US cyber ambassador nominee Cassady confirmed in Senate (The Record)
Honestly did not expect them to refill this role due to the US administration’s disdain for cyber governance. The previous Bureau of Cyberspace and Digital Policy was broken up, so it’s unclear exactly what this ambassador will be doing.
Water utilities group partners with DEF CON offshoot for Water Watch Center (The Record)
United Kingdom and European Union News
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks (Techcrunch)
This is a focus on Poland, but this is likely the case for a lot of countries that have not prioritized security in their digital modernization.
Cyberattack hits Liechtenstein’s register of people behind companies and foundations (The Canadian Press)
Approximately 31,000 people potentially affected in this attack. There could be a lot of reasons for this attack, both criminal and state-based.
[Google Translated] Cyberattack on SharePoint server (Government of Switzerland)
Switzerland’s Federal Office for Information Technology and Telecommunications had 200 sharepoint accounts compromised, but no evidence there was any data exfiltration.
[Google Translated] The Hungarian State Treasury was hit by a cyberattack, according to experts, from Russian servers (Telex)
A hacker hits Hungary’s treasury. Although Russian servers were used, this does not neccesarily mean Russian responsibility, but this is well within Russian capabilities and priorities.
UK’s Cyber security breaches survey: 2026/2027 (Government of UK)
The UK has partnered with Ipsos to conduct a survey of UK buinesses, education institutions and charities concerning cyberattacks and breaches.
Commission publishes study supporting the Review of the Digital Decade Policy Programme (European Commission)
A review of the EU’s Digital Decade Policy Programme found that it remained “fit for purpose,” but is insufficient in reflecting emerging priorities like cybersecurity and sovereignty.
Valve notifies Steam hardware customers of a data breach (BleepingComputer)
Supply chain hit affects Valve customers as its shipping partner was hacked and hackers stole significant information on its customers. The steam machine is in heavy demand, so it is not farfetched to belive this could be an effort to identify where they’re going. Or could be a coincidence.
Follow-Up Report of the December 2025 Energy Sector Incident (Poland CERT)
Report on the Russian attacks against Polish energy infrastructure, which is now up to two power plants being attacked by Russia.
Other International News
Cybersecurity bill sponsored by Villafuerte, Poe passes 2nd reading (Inquirer.net) [h/t Catalin Cimpanu]
Including this because Canada has been heavily involved with the Philippines in cybersecurity. This includes CAFCYBERCOM in addition to other activities. As a result, I predict Canada will be involved in some capacity to support standing up this organization.
Australia’s privacy tsar warns new laws may be needed for smart glasses (PerthNow)
Privacy advocates globally are increasingly concerned about the gaps in laws that allow pervert glasses to be worn to secretly film people without consent.
[Google Translated] Data recovery company CEO sentenced to prison for partnering with hackers to target ransomware victims (News1 Korea)
Insider threats exist everywhere, but I think it is rare for the CEO to be directly invovled. The CEO and marketing manager were both sentence to three years in prison.
Feature your business in Canadian Cyber in Context through sponsorship or advertising.
Media of the Week
Go follow Kevin Beaumont on Bluesky or Infosec.Exchange if you aren’t already



