Sign in

Alexander Martin

@alexmartin.bsky.social
5.7K followers 841 following 1.5K posts

Journalist covering cybersecurity and intelligence. UK Editor at The Record from Recorded Future News. Dad of two. 🏠 Sheffield 📧 alexander.martin@therecord.media 📱 Signal: AlexanderMartin.79

PostsRepliesMedia
Reposted by Alexander Martin
Alexander Martin @alexmartin.bsky.social · 25/09/2026
New: Security researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
therecord.media
Doubts grow over claims OpenAI agent hacked Australian Medicare portal
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visit...
101
Alexander Martin @alexmartin.bsky.social · 25/09/2026
New: Security researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
therecord.media
Doubts grow over claims OpenAI agent hacked Australian Medicare portal
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visit...
101
Reposted by Alexander Martin
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Alexander Martin @alexmartin.bsky.social · 24/09/2026
I’m seeing the word “hack” used in a lot of coverage of Albanese’s announcement about OpenAI’s unauthorised access to an Australian government health website in June. As of now, the lack of technical details either from OpenAI or Canberra make that description hard to justify.
192
Alexander Martin @alexmartin.bsky.social · 23/09/2026
British Prime Minister Andy Burnham said Tuesday he has ordered security chiefs to begin work on a new national center ”to detect, attribute and disrupt” hostile state disinformation.
therecord.media
Burnham announces plan for new UK center to fight disinformation
The United Kingdom will create a new national center "to detect, attribute and disrupt” hostile state disinformation, Prime Minister Andy Burnham announced at the United Nations General Assembly.
010
Alexander Martin @alexmartin.bsky.social · 22/09/2026
Defenders cannot yet put artificial intelligence to work as freely as attackers can, a senior official at @ncsc.gov.uk said Monday. His warning comes amid concerns about the kind of cybersecurity future AI will lead to. Read more here ⤵️
therecord.media
AI is set to help cyber attackers much more than defenders, says UK official
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.
010
Alexander Martin @alexmartin.bsky.social · 22/09/2026
Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks. In some cases, alerts arrive only after a strike or do not reach residents at all. ✍️ @darynant.bsky.social
therecord.media
Russia’s internet shutdowns disrupt warnings about incoming drone attacks
Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks.
062
Alexander Martin @alexmartin.bsky.social · 15/09/2026
New: Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
therecord.media
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime,...
010
Alexander Martin @alexmartin.bsky.social · 15/09/2026
Accounts like this are so weird. Claiming to be investigative journalists, thousands of followers, writing* things that have been public or reported by others weeks ago: therecord.media/irregular-ai... And the output is just trash. _ * I have my doubts about how much they're writing themselves...
230
Alexander Martin @alexmartin.bsky.social · 14/09/2026
The U.S. National Security Agency is undertaking a fast and far-reaching reorganization in a bid to get the unique intelligence it gathers to real-world battlefields faster. Good morning! Catch-up on the weekend scoop from @martinmatishak.bsky.social here ⤵️
therecord.media
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI
The largest electronic spy agency in the world is reorganizing. And fast.
032
Alexander Martin @alexmartin.bsky.social · 11/09/2026
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations, the company said Thursday.
therecord.media
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organi...
021
Alexander Martin @alexmartin.bsky.social · 10/09/2026
Wee scoop: The new commander of the National Cyber Force stepped into the role this week, according to sources with knowledge of the appointment. The individual has not yet been avowed as routine security considerations are still being worked through.
therecord.media
UK appoints new commander of National Cyber Force
The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still be...
000
Alexander Martin @alexmartin.bsky.social · 09/09/2026
At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday.
therecord.media
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
001
Reposted by Alexander Martin
Quantian @quantian.bsky.social · 08/09/2026
Dancing very very VERY close to saying “OpenAI stole our almost-complete proof of Navier-Stokes from internal access to our ChatGPT sessions because they were desperate to scoop Anthropic” which is absolutely 100% a believable thing OpenAI would do right now cims.nyu.edu/~tristanb/st...
381556449
Alexander Martin @alexmartin.bsky.social · 08/09/2026
On the same day Germany formally blamed Russia for the Leipzig/Halle drone attack, and two power stations were hit with sabotage, hackers encrypted the central IT systems of a municipal utility in Bavaria. No evidence events linked, but what a day, eh?
therecord.media
Cyberattack encrypts systems at Bavarian municipal utility
A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.
043
Alexander Martin @alexmartin.bsky.social · 07/09/2026
AI has done plenty for my “politicians being daft about technology” scrapbook, but nothing will ever beat the debate in 1924 when MPs grilled the government over “the invention known as the death ray.” One MP asked: “Are the Government taking steps to prevent the use of this diabolical device?”
api.parliament.uk
AIR "DEATH RAY." (Hansard, 22 May 1924)
AIR "DEATH RAY." (Hansard, 22 May 1924)
264
Alexander Martin @alexmartin.bsky.social · 07/09/2026
Hackers embezzled at least €35 million from hundreds of notary offices in France over two years. They were so prolific that the authorities feared the criminals were issuing counterfeit notarial deeds. It might take years for those to come to light. Great reporting from @untersin.gr here ⤵️
lemonde.fr
Au cœur d’une cyberattaque sans précédent qui a ébranlé le notariat français
Des pirates ont détourné au moins 35 millions d’euros au sein de centaines d’offices notariaux pendant deux ans. Les hackeurs étaient si prolifiques que les autorités ont craint l’émission de faux act...
152
Alexander Martin @alexmartin.bsky.social · 03/09/2026
@isaacs.bsky.social Heya Isaac, I saw you mentioned emails to you can get lost in a sea of spam and was wondering if it would it be possible for me to DM you here for an odd little journalistic investigation I'm working on (about npm and SBOMs)? Very grateful for your time if so! Thank you!
000
Alexander Martin @alexmartin.bsky.social · 01/09/2026
What use is the word "hybrid" here?
110
Alexander Martin @alexmartin.bsky.social · 27/08/2026
Two men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year.
therecord.media
Australia charges two men for TeamPCP supply-chain hacking spree
Two men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year.
012
Alexander Martin @alexmartin.bsky.social · 27/08/2026
New: Manchester Airports Group — a public-private partnership which operates three of England’s busiest airports — said Thursday it was hit by a cyberattack affecting data belonging to about 8.7 million customers.
therecord.media
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
A spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information ...
011
Alexander Martin @alexmartin.bsky.social · 25/08/2026
New: An agreement, signed Monday by Zelensky and Burnham, will make the U.K. the first foreign partner to gain access to Ukraine's Avengers AI Labs, a defense platform built around millions of images and other data gathered from the battlefield.
therecord.media
Ukraine to give Britain access to battlefield data to train AI
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence s...
083
Reposted by Alexander Martin
Paul F Scott @paulfscott.bsky.social · 25/08/2026
'[M]inisters would not have to publicly designate a vendor as a security risk before taking action against it... The powers would also reach beyond telecoms into managed service providers, data centers and digital infrastructure, as well as the energy, water, transport and health sectors.'
041
Alexander Martin @alexmartin.bsky.social · 25/08/2026
New: The British government is seeking new powers that would allow it to ban technology vendors on national security grounds from supplying companies working in the country’s critical sectors — potentially doing so in secret.
therecord.media
UK government seeks powers to secretly block risky tech suppliers
The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.
074
Alexander Martin @alexmartin.bsky.social · 19/08/2026
euractiv.com
Ukrainian arrested in Croatia over Nord Stream sabotage | Euractiv
The scuba diver is 'strongly suspected of jointly causing explosions', German prosecutors say
110
Alexander Martin @alexmartin.bsky.social · 18/08/2026
Cheery news.
010
Alexander Martin @alexmartin.bsky.social · 18/08/2026
For journalists covering policy, regulations are basically the equivalent of murders for police and crime reporters. Fortunately, it's much less unseemly to revel in what great copy they can make. Top work here from @sgclark92.bsky.social!
politico.eu
Ice cream makers as ‘critical infrastructure’? EU’s new cybersecurity law suffers wobbly rollout
What merits extra EU protection from cyber attacks is turning into a confusing question for bureaucrats and businesses alike.
031
Alexander Martin @alexmartin.bsky.social · 18/08/2026
Irregular faces criticism over ‘spin’ in AI hacking postmortem
therecord.media
Irregular faces criticism over ‘spin’ in AI hacking postmortem
The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that securit...
010
Alexander Martin @alexmartin.bsky.social · 13/08/2026
📅May: Thomas Lind, 🇺🇸 official, US needs “to bring in the private sector … that does not mean hack back, that does not mean letters of marque.” Sean Cairncross, 🇺🇸 official, “…private sector ... engaging in cyber offensive campaigns — that's not what we're talking about.” 📅 August:
therecord.media
Trump taps cyber firms to go on offensive against criminals
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.
023
Alexander Martin @alexmartin.bsky.social · 13/08/2026
Germany’s cabinet approved legislation Wednesday that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.
therecord.media
Germany moves to give spy agencies hacking and sabotage powers
Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in th...
173
Alexander Martin @alexmartin.bsky.social · 12/08/2026
Got to love stories about unverifiable incidents sourced to a single entity selling a solution to that exact sort of incident.
ft.com
China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack
AI agents ran simultaneous reconnaissance and break-ins in display of new phase of cyberwarfare
020
Alexander Martin @alexmartin.bsky.social · 12/08/2026
New: Britain's criminal records office has been reprimanded by the country’s data protection regulator after being repeatedly breached over nearly two years, exposing the personal data of thousands of people including victims of domestic violence.
therecord.media
Three intrusions at UK criminal records office went undetected for two years
Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.
000
Alexander Martin @alexmartin.bsky.social · 10/08/2026
Poland’s cybersecurity authorities have revealed that a previously unknown cyberattack disrupted systems at a combined heat and power plant during last winter’s cold snap, threatening to leave tens of thousands of people exposed to freezing weather.
therecord.media
Poland uncovers second heat plant cyberattack that went hidden for months
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
052
Alexander Martin @alexmartin.bsky.social · 10/08/2026
Crikey. Ransomware criminals compromising remote monitoring and management consoles is never one to ignore. Kaseya and SecureConnect were really big incidents. Now it looks like the China-linked Storm-1175 is going to be hitting N-central users and then the downstream businesses too.
therecord.media
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.
011
Alexander Martin @alexmartin.bsky.social · 07/08/2026
Irregular — the cybersecurity evaluation firm behind tests in which AI models from Anthropic, OpenAI and Meta compromised real-world computer systems — has declined to say whether any of its other clients were also affected by the same underlying flaw.
therecord.media
Irregular, firm behind AI hacking incidents, won't say if there were more
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”
011
Reposted by Alexander Martin
Matt Burgess (WIRED) @mattburgess1.bsky.social · 06/08/2026
NEW: For nearly two years, researcher Vangelis Stykas has had access to North Korean hackers’ servers. His work shows they pulled off intrusions in 1,640 companies across 57 countries
wired.com
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
0219
Alexander Martin @alexmartin.bsky.social · 06/08/2026
Caught a cinema screening of this last night. It's absolutely excellent, loved it, 10/10.
041
Reposted by Alexander Martin
Jonathan Foyle @jonathanfoyle.bsky.social · 04/08/2026
Engaging piece therecord.media/interview-ji...
therecord.media
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.
043
Alexander Martin @alexmartin.bsky.social · 05/08/2026
An artificial intelligence agent built by Anthropic created fake online personas, planted malicious code in a real software project, and sent phishing emails to real developers during a U.K. government security evaluation, all without human instruction, according to Britain’s AI Security Institute.
therecord.media
Anthropic AI agent faked identities, phished real developers in UK government hacking test
An artificial intelligence agent built by Anthropic independently planted malicious code in a real software project and sent phishing emails to developers during a U.K. government security evaluation,...
043
Reposted by Alexander Martin
Bob @bobherc.bsky.social · 05/08/2026
Great work from @alexmartin.bsky.social on this really great interview that is worth your time:
011
Reposted by Alexander Martin
Alexander Martin @alexmartin.bsky.social · 04/08/2026
NEW: I really enjoyed speaking to General Sir Jim Hockenhull a few weeks ago and am grateful the fruits of that conversation can now be published. His message to the British public is stark: “War isn’t going to happen as an away game. If there is a conflict, it will be happening here.”
therecord.media
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.
084
Alexander Martin @alexmartin.bsky.social · 04/08/2026
“War isn't going to happen as an away game. If there is a conflict, it will be happening here.”
therecord.media
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.
011
Alexander Martin @alexmartin.bsky.social · 04/08/2026
An interesting comment on intelligence success and failure from General Sir Jim Hockenhull, regarding the Russian invasion of Ukraine, in this interview: therecord.media/interview-ji...
031
Alexander Martin @alexmartin.bsky.social · 04/08/2026
NEW: I really enjoyed speaking to General Sir Jim Hockenhull a few weeks ago and am grateful the fruits of that conversation can now be published. His message to the British public is stark: “War isn’t going to happen as an away game. If there is a conflict, it will be happening here.”
therecord.media
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.
084
Alexander Martin @alexmartin.bsky.social · 04/08/2026
Leaving aside their specific (later) proposals, Levy and Robinson's explanation of the problem here -- and why it is different from a backdoor -- should be the starting point of this discussion: www.lawfaremedia.org/article/prin...
lawfaremedia.org
Principles for a More Informed Exceptional Access Debate
This is part of a series of essays from the Crypto 2018 Workshop on Encryption and Surveillance. In any discussion of cyber security, details matter.
011
Alexander Martin @alexmartin.bsky.social · 04/08/2026
The “encryption” hasn’t been weakened. Your privacy — and that of child abusers, terrorists, etc — is protected. If you don’t want police to be able to tackle those uses of iCloud with a warrant, then you might need to let Apple bring back its client-side scanning proposals.
110
Alexander Martin @alexmartin.bsky.social · 04/08/2026
In hindsight, I think the term exceptional access is better than lawful access. A backdoor could hypothetically be lawful access. But we're still not talking about a backdoor here. A backdoor is a covert mechanism intended to allow the bypassing of a normal authentication system. That ain't this.
000
Alexander Martin @alexmartin.bsky.social · 04/08/2026
Sigh. As the FT reports: “Apple has launched a new legal challenge against the UK’s latest attempt to create a ‘backdoor’ to access encrypted customer data…” 👏 lawful 👏 access 👏 is 👏 not 👏 a 👏 backdoor 👏
ft.com
Apple launches legal challenge to UK attempt to access encrypted user data
iPhone maker files complaint over latest government demand to connect to cloud backups of British users
3104
Alexander Martin @alexmartin.bsky.social · 01/08/2026
A new ransomware group (who I'm not giving the publicity of naming) is brazenly offering journalists early access to their data leak site in order to increase pressure on victims to make an extortion payment. I'm unaware of other recipients but the message looks mass-sent.
1158
Reposted by Alexander Martin
Alexander Martin @alexmartin.bsky.social · 31/07/2026
I find it weird that a large part of Anthropic’s disclosure is based on Claude’s chain-of-thought outputs, yet I’ve seen no other reports noting Anthropic’s own research found this output to be rarely accurate. Surely tech journalism can do better?
therecord.media
Anthropic says its AI hacked real-world companies in three incidents
Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.
1286