Lloyd's Register
The American Club
Panama Consulate
London Shipping Law Center
Home ShipmanagementClassification Societies DNV Cyber Threat Insights, June 2026

DNV Cyber Threat Insights, June 2026

by admin
23 views

For this edition of Threat Insights, we have included our Big Picture assessment of the cyber security developments we’re seeing.  As usual, we have also provided a selection of recent threat insights curated by our specialists. We hope you find this valuable:

You can view these threat insights in full below and can download them as easily shareable  PowerPoint slides.

If these developments raise questions for your organization, DNV can support you with independent, risk‑based insight and practical guidance.

Our experts work closely with industry leaders and operational teams to translate emerging threat trends into actionable resilience and security strategies.

We hope that these threat insights inform your cyber priorities, encourage discussion, and make your organization more resilient. If you would like to discuss the implications for your organization or explore next steps, please reach out to us via email.

Best regards,

DNV Cyber Threat Intelligence

The Big Picture
Anthropic is in the spotlight for its advanced AI model Claude Mythos 5, which was available to Project Glasswing members, and its release of Fable 5 which is essentially the same powerful model, but with guardrails included for the wider public. After reports of jailbreaking these guardrails, authorities in the US effectively banned the use of both models to anyone who is not an American citizen. This in turn led Anthropic to pull both models from the market, essentially making them completely unavailable. These actions illustrate growing anxieties among policymakers that AI is an exponential accelerator of cyber offence.

What is not new is the drive toward automation. Attackers have long sought to scale the exploitation of known vulnerabilities. But what is new is the increasing speed, adaptability, and accessibility of these capabilities, supported by generative AI. The concern is that AI capabilities is advancing faster than organization’s ability to govern or control it.Our intelligence shows that adversaries are maturing from AI-augmented operations to adaptive, industrial‑scale exploitation, combining automated vulnerability discovery, exploitation, and just-in-time modification of source code to evade detection. While threat actors in general are experimenting with agents to operationalize autonomous attacks, the more immediate implication is the growing ability to operate at scale and speed beyond what most defensive functions were designed to manage.

While most attack paths still rely on known vulnerabilities and human‑defined workflows, the more significant shift will occur when agentic AI becomes capable of autonomously discovering and chaining unknown vulnerabilities without human intervention (i.e., Mythos). Whether or not this inflection point is imminent, current developments suggest the gap between offensive innovation and defensive adaptation is widening.

Attack surfaces continue to expand through highly interconnected digital ecosystems, where SaaS platforms, developer environments, and operational technology create complex and often weakly governed trust relationships. As a result, cyber risk is increasingly shaped by dependences and exposures that sit outside direct organizational control. This expansion is being actively exploited by state‑linked actors, who are increasingly positioning access not just for espionage, but for operational and economic disruption, marking a shift from isolated incidents towards more systemic forms of risk.

Trends

Anthropic’s Mythos: The ‘haves’ and ‘have nots’ creating asymmetric cyber security

US authorities have imposed export controls and selective access on Anthropic’s Mythos and Fable models, prompting Anthropic to suspend access.

Mythos identifies unknown software vulnerabilities (zero‑days) and chains them into exploit paths autonomously. Due to its offensive potential, access was restricted to a small group of organizations under Project Glasswing. This model is now directly shaped by national export regimes, limiting where and how it can be deployed.

Fable offers Mythos-level reasoning with guardrails. Our assessment is that these currently over-block legitimate cybersecurity and adjacent work.

The result is a widening gap between the “haves” and “have-nots” in cybersecurity. If access to frontier AI is determined by jurisdiction and policy alignment, capability shifts from organizational need to regulatory eligibility. Organizations in approved frameworks may regain access, while others face prolonged or permanent restrictions.

Discuss:

  • Where are we most exposed if attacks scale rapidly against known vulnerabilities?
  • Are we prepared for attacks that combine multiple vulnerabilities autonomously?
  • Are we ready to shift from manual, reactive security to machine-speed defence?

Recommendations:

  • Move from detection to real-time response to disrupt automated attacks.
  • Assume compromise and contain breaches to limit lateral movement.
  • Adopt AI-enabled prioritization, response and remediation.

 Machine-speed attacks require machine-speed defense

Increase in state-sponsored attacks on critical infrastructure trigger CISA initiative

Attacks on critical infrastructure by state-sponsored hackers are escalating. Eighty countries including have been attacked, with the US the most heavily targeted. The US Cybersecurity and Infrastructure Security Agency (CISA) is advising critical infrastructure operators of the importance of developing the capability to continue operations for weeks or months without access to the internet or third-party services.

The initiative is called CI Fortify and includes CISA assessments of IT operators’ incident response plans for cyberattacks. Part of CISA’s strategy centres around isolation and recovery by turning off all third party and internet connections when facing an emergency or unknown vulnerability, and approaches for recovery including manual backups when IT and OT systems are down.

There is no European equivalent of CI Fortify focusing on operating in fully disconnected conditions, where the approach is more regulatory and framework-driven.

Discuss:

  • Do we have clear plans to isolate systems rapidly during an incident without halting operations?
  • How dependent are we on external platforms for essential operational processes?
  • Could we continue critical operations if disconnected from the internet and third‑party services for weeks?

Recommendations:

  • Ensure teams are trained in manual workarounds, backups, and local control capabilities.
  • Enable rapid, safe isolation from the internet and third‑party connections.
  • Test incident response and recovery processes for prolonged outages.

Resilience could mean operating without the network 

Iran linked attackers exploit OT systems threatening US critical infrastructure

US authorities have issued a joint advisory that Iranian‑ affiliated actors are actively exploiting OT systems across US critical infrastructure sectors including water, energy and government.

The attacks targeted internet‑exposed industrial control systems, particularly Rockwell Automation and Allen‑Bradley programmable logic controllers (PLCs). In some cases the breach caused operational disruption and financial loss.

The campaign builds on prior IRGC‑linked operations by CyberAv3ngers, signaling a sustained and escalating threat to operational technology environments. Iranian hackers are also suspected in breaches of systems monitoring fuel in storage tanks serving gas stations in the U.S.

Critical infrastructure operators in Europe need to be on the alert. Any operator can now become strategic assets in conflict, even if not ‘target’ companies.

Discuss:

  • Have we tested scenarios involving a nation-state attacker targeting operational disruption?
  • Is OT cyber risk clearly owned at board level?
  • Are OT risks reflected in our contingency planning and financial disclosures?
  • Do we have sufficient focus on recovery, not just prevention?

Recommendations:

Could you be a strategic target?

Vulnerabilities

The AI supply chain risk

Cloud platform Vercel disclosed an internal security incident in which attackers gained access via Context.ai, a third‑party AI tool used by an employee that had been compromised.

The attack chain began with the theft of OAuth tokens following the Context.ai breach, which allowed the threat actor to impersonate the AI service and access the employee’s Google Workspace account without triggering Multi-Factor Authentication (MFA).

Threat actors claiming affiliation with ShinyHunters attempted to sell the alleged stolen data.

The case highlights a growing trend of risk from trust delegated to vendors, reinforcing the need for tighter governance of third‑party AI and other SaaS. A supply chain compromise can cascade across multiple companies, amplifying impact far beyond the original breach vector.

Discuss:

  • How many third‑party SaaS and AI tools have OAuth access to our core systems? Do we actively govern and audit those permissions?
  • If a supplier were compromised, how far could they move inside our environment without triggering detection?
  • Are we treating SaaS and AI integrations as part of our critical supply chain risk?

Recommendations:

  • Enforce strict control over OAuth and third‑party app access.
  • Monitor for abnormal token usage and SaaS activity
  • Read DNV’s recent research on Nordic Cyber Resilience including advice on supply chain resilience

 If trusted AI tools can be hijacked, where does your perimeter actually lie?

AI assistants can be abused as stealth communication channels

ISecurity researchers have identified a new attack method in which AI assistants such as Microsoft Copilot or xAI Grok can be abused as covert communication channels after a system is compromised.

Malware running on an infected device can send normal‑looking prompts to these trusted services, instructing them to retrieve content from attacker‑controlled sources. The responses may contain hidden commands that allow the malware to continue operating.

Since this traffic appears legitimate and is typically allowed in enterprise environments, it can bypass traditional monitoring and remain undetected, enabling attackers to persist and operate discreetly within compromised systems.

Discuss:

  • Do we treat AI traffic as inherently trusted, and have we visibility into usage across endpoints?
  • If a device were already compromised, could attackers use approved AI tools to operate undetected inside our environment?
  • Are we addressing how attackers might misuse legitimate tools post‑breach, not just how they gain initial accessed systems?

Recommendations:

  • Monitor and baseline AI service usage across endpoints.
  • Restrict access to approved AI tools and control outbound connections.
  • Detect and block abnormal automated interactions with AI services.

The importance of visibility

GitHub breach shows developer tools are a critical supply chain target

GitHub, the Microsoft-owned software platform used by millions of developers, confirmed a major breach in May 2026 after attackers compromised an employee device through a poisoned Visual Studio Code extension.

The attack allowed access to thousands of internal repositories. While customer systems are not yet confirmed to be affected, internal repositories may contain sensitive operational and customer-related information.

The incident highlights a growing risk of attacks targeting developer tools and platforms as part of the software supply chain, where a single compromised tool can expose critical systems and potentially disrupt entire digital ecosystems.

Discuss:

  • Do we know which developer tools, extensions, and plugins our teams rely on? How trusted and controlled are those ecosystems?
  • Are we monitoring for suspicious activity within IDEs, repositories, and build environments?
  • If a core platform like GitHub or a developer tool were compromised, what would be the impact on our operations, products, or customers?

Recommendations:

  • Proactively scan for secrets within their codebase that may be weaponized by adversaries and eliminate any practice of storing sensitive credentials in plaintext.
  • Pin exact dependency versions using cryptographic hashes or lockfiles to guarantee repeatable builds and block malicious code injection.

If developer tools can’t be trusted, can our business remain secure? 

Canvas breach ransom payment becomes reputational crisis

The education platform Canvas, operated by Instructure, suffered a major cyber breach affecting up to 9,000 institutions and exposing data such as names, emails, student IDs, and private messages. 

The incident caused immediate disruption, taking the platform offline during exams and halting coursework across universities.

Instructure ultimately reached an agreement with attackers, allegedly paying a ransom to prevent data release. While this may have been intended reduced immediate impact on those who’s data was stolen, it introduces reputational risk, does not reduce the threat as data may still be held, and raises questions scrutiny governance and preparedness. The breach highlights how reliance on shared platforms can amplify operational disruption.

Discuss:

  • How should organizations balance immediate operational impact against long‑term reputational risk when deciding whether to pay a ransom?
  • Are we overly dependent on single third‑party platforms whose failure could disrupt core operations across the organization?
  • How prepared are we to manage stakeholder trust if a cyber incident affects customers?

Recommendations

  • Enforce strong identity controls across SaaS platforms, including MFA, least‑privilege access, and regular rotation of tokens and credentials.
  • Validate strict isolation between environments
  • Implement continuous monitoring for abnormal activity such as bulk data access, unusual logins, or configuration changes.

 Paying a ransom does not remove the threat

iew previous editions of threat insights:

DNV Cyber gathers and analyses intelligence from both open sources and our own resources. View our threat insights and security advisories. Our threat intelligence service provides deeper insights and curates intelligence specifically for your business.

You may also like

Leave a Comment