
For this edition of Threat Insights, we have included our Big Picture assessment of the cyber security developments we’re seeing. As usual, we have also provided a selection of recent threat insights curated by our specialists. We hope you find this valuable:
- The Big Picture
- Anthropic’s Mythos: The ‘haves’ and ‘have-nots’ creating asymmetric cyber security
- Increase in state-sponsored attacks on critical infrastructure trigger CISA initiative response
- Iran linked attackers exploit OT systems threatening U.S. critical infrastructure
- The AI supply chain risk
- AI assistants can be abused as stealth communication channels
- GitHub breach shows developer tools are a critical supply chain target
- Canvas breach ransom payment becomes reputational crisis
You can view these threat insights in full below and can download them as easily shareable PowerPoint slides.
If these developments raise questions for your organization, DNV can support you with independent, risk‑based insight and practical guidance.
Our experts work closely with industry leaders and operational teams to translate emerging threat trends into actionable resilience and security strategies.
We hope that these threat insights inform your cyber priorities, encourage discussion, and make your organization more resilient. If you would like to discuss the implications for your organization or explore next steps, please reach out to us via email.
Best regards,
DNV Cyber Threat Intelligence
Trends

Anthropic’s Mythos: The ‘haves’ and ‘have nots’ creating asymmetric cyber security
US authorities have imposed export controls and selective access on Anthropic’s Mythos and Fable models, prompting Anthropic to suspend access.
Mythos identifies unknown software vulnerabilities (zero‑days) and chains them into exploit paths autonomously. Due to its offensive potential, access was restricted to a small group of organizations under Project Glasswing. This model is now directly shaped by national export regimes, limiting where and how it can be deployed.
Fable offers Mythos-level reasoning with guardrails. Our assessment is that these currently over-block legitimate cybersecurity and adjacent work.
The result is a widening gap between the “haves” and “have-nots” in cybersecurity. If access to frontier AI is determined by jurisdiction and policy alignment, capability shifts from organizational need to regulatory eligibility. Organizations in approved frameworks may regain access, while others face prolonged or permanent restrictions.
Discuss:
- Where are we most exposed if attacks scale rapidly against known vulnerabilities?
- Are we prepared for attacks that combine multiple vulnerabilities autonomously?
- Are we ready to shift from manual, reactive security to machine-speed defence?
Recommendations:
- Move from detection to real-time response to disrupt automated attacks.
- Assume compromise and contain breaches to limit lateral movement.
- Adopt AI-enabled prioritization, response and remediation.
Machine-speed attacks require machine-speed defense

Increase in state-sponsored attacks on critical infrastructure trigger CISA initiative
Attacks on critical infrastructure by state-sponsored hackers are escalating. Eighty countries including have been attacked, with the US the most heavily targeted. The US Cybersecurity and Infrastructure Security Agency (CISA) is advising critical infrastructure operators of the importance of developing the capability to continue operations for weeks or months without access to the internet or third-party services.
The initiative is called CI Fortify and includes CISA assessments of IT operators’ incident response plans for cyberattacks. Part of CISA’s strategy centres around isolation and recovery by turning off all third party and internet connections when facing an emergency or unknown vulnerability, and approaches for recovery including manual backups when IT and OT systems are down.
There is no European equivalent of CI Fortify focusing on operating in fully disconnected conditions, where the approach is more regulatory and framework-driven.
Discuss:
- Do we have clear plans to isolate systems rapidly during an incident without halting operations?
- How dependent are we on external platforms for essential operational processes?
- Could we continue critical operations if disconnected from the internet and third‑party services for weeks?
Recommendations:
- Ensure teams are trained in manual workarounds, backups, and local control capabilities.
- Enable rapid, safe isolation from the internet and third‑party connections.
- Test incident response and recovery processes for prolonged outages.
Resilience could mean operating without the network

Iran linked attackers exploit OT systems threatening US critical infrastructure
US authorities have issued a joint advisory that Iranian‑ affiliated actors are actively exploiting OT systems across US critical infrastructure sectors including water, energy and government.
The attacks targeted internet‑exposed industrial control systems, particularly Rockwell Automation and Allen‑Bradley programmable logic controllers (PLCs). In some cases the breach caused operational disruption and financial loss.
The campaign builds on prior IRGC‑linked operations by CyberAv3ngers, signaling a sustained and escalating threat to operational technology environments. Iranian hackers are also suspected in breaches of systems monitoring fuel in storage tanks serving gas stations in the U.S.
Critical infrastructure operators in Europe need to be on the alert. Any operator can now become strategic assets in conflict, even if not ‘target’ companies.
Discuss:
- Have we tested scenarios involving a nation-state attacker targeting operational disruption?
- Is OT cyber risk clearly owned at board level?
- Are OT risks reflected in our contingency planning and financial disclosures?
- Do we have sufficient focus on recovery, not just prevention?
Recommendations:
- Eliminate direct internet exposure of OT assets and treat OT security as a board‑level resilience issue.
- Remove PLCs from public reach using secure gateways, monitor OT‑specific ports and logs for anomalous activity.
- Read DNV Cyber’s Nordic Cyber Resilience Research.
Could you be a strategic target?
Vulnerabilities

The AI supply chain risk
Cloud platform Vercel disclosed an internal security incident in which attackers gained access via Context.ai, a third‑party AI tool used by an employee that had been compromised.
The attack chain began with the theft of OAuth tokens following the Context.ai breach, which allowed the threat actor to impersonate the AI service and access the employee’s Google Workspace account without triggering Multi-Factor Authentication (MFA).
Threat actors claiming affiliation with ShinyHunters attempted to sell the alleged stolen data.
The case highlights a growing trend of risk from trust delegated to vendors, reinforcing the need for tighter governance of third‑party AI and other SaaS. A supply chain compromise can cascade across multiple companies, amplifying impact far beyond the original breach vector.
Discuss:
- How many third‑party SaaS and AI tools have OAuth access to our core systems? Do we actively govern and audit those permissions?
- If a supplier were compromised, how far could they move inside our environment without triggering detection?
- Are we treating SaaS and AI integrations as part of our critical supply chain risk?
Recommendations:
- Enforce strict control over OAuth and third‑party app access.
- Monitor for abnormal token usage and SaaS activity
- Read DNV’s recent research on Nordic Cyber Resilience including advice on supply chain resilience
If trusted AI tools can be hijacked, where does your perimeter actually lie?

AI assistants can be abused as stealth communication channels
ISecurity researchers have identified a new attack method in which AI assistants such as Microsoft Copilot or xAI Grok can be abused as covert communication channels after a system is compromised.
Malware running on an infected device can send normal‑looking prompts to these trusted services, instructing them to retrieve content from attacker‑controlled sources. The responses may contain hidden commands that allow the malware to continue operating.
Since this traffic appears legitimate and is typically allowed in enterprise environments, it can bypass traditional monitoring and remain undetected, enabling attackers to persist and operate discreetly within compromised systems.
Discuss:
- Do we treat AI traffic as inherently trusted, and have we visibility into usage across endpoints?
- If a device were already compromised, could attackers use approved AI tools to operate undetected inside our environment?
- Are we addressing how attackers might misuse legitimate tools post‑breach, not just how they gain initial accessed systems?
Recommendations:
- Monitor and baseline AI service usage across endpoints.
- Restrict access to approved AI tools and control outbound connections.
- Detect and block abnormal automated interactions with AI services.
The importance of visibility

GitHub breach shows developer tools are a critical supply chain target
GitHub, the Microsoft-owned software platform used by millions of developers, confirmed a major breach in May 2026 after attackers compromised an employee device through a poisoned Visual Studio Code extension.
The attack allowed access to thousands of internal repositories. While customer systems are not yet confirmed to be affected, internal repositories may contain sensitive operational and customer-related information.
The incident highlights a growing risk of attacks targeting developer tools and platforms as part of the software supply chain, where a single compromised tool can expose critical systems and potentially disrupt entire digital ecosystems.
Discuss:
- Do we know which developer tools, extensions, and plugins our teams rely on? How trusted and controlled are those ecosystems?
- Are we monitoring for suspicious activity within IDEs, repositories, and build environments?
- If a core platform like GitHub or a developer tool were compromised, what would be the impact on our operations, products, or customers?
Recommendations:
- Proactively scan for secrets within their codebase that may be weaponized by adversaries and eliminate any practice of storing sensitive credentials in plaintext.
- Pin exact dependency versions using cryptographic hashes or lockfiles to guarantee repeatable builds and block malicious code injection.
If developer tools can’t be trusted, can our business remain secure?

Canvas breach ransom payment becomes reputational crisis
The education platform Canvas, operated by Instructure, suffered a major cyber breach affecting up to 9,000 institutions and exposing data such as names, emails, student IDs, and private messages.
The incident caused immediate disruption, taking the platform offline during exams and halting coursework across universities.
Instructure ultimately reached an agreement with attackers, allegedly paying a ransom to prevent data release. While this may have been intended reduced immediate impact on those who’s data was stolen, it introduces reputational risk, does not reduce the threat as data may still be held, and raises questions scrutiny governance and preparedness. The breach highlights how reliance on shared platforms can amplify operational disruption.
Discuss:
- How should organizations balance immediate operational impact against long‑term reputational risk when deciding whether to pay a ransom?
- Are we overly dependent on single third‑party platforms whose failure could disrupt core operations across the organization?
- How prepared are we to manage stakeholder trust if a cyber incident affects customers?
Recommendations
- Enforce strong identity controls across SaaS platforms, including MFA, least‑privilege access, and regular rotation of tokens and credentials.
- Validate strict isolation between environments
- Implement continuous monitoring for abnormal activity such as bulk data access, unusual logins, or configuration changes.
Paying a ransom does not remove the threat
iew previous editions of threat insights:
DNV Cyber gathers and analyses intelligence from both open sources and our own resources. View our threat insights and security advisories. Our threat intelligence service provides deeper insights and curates intelligence specifically for your business.




