Contents
Dear reader,
Summer is usually a quiet period for many organisations across the Bailiwick, but here at GCSC we’re still busy. Here in Guernsey, the team are busy managing the final stage of the office fit out, and we hope to be able to welcome you to our new home at Marie Randall House by the end of the summer. In the meantime you’ll often find us at the Digital Greenhouse. We’re also working with Soteria Communications on some upcoming events to support some of Guernsey’s key industries, and make sure we’re learning from local needs and focusing on what matters most to you: more details to follow shortly.
Internally, GCSC operates under a contract with the States of Guernsey, overseen by the Committee for Home Affairs. Behind the scenes our legal mandate comes from the Government of Jersey under Ministerial Delegation to me. This isn’t ideal as it can be a bit unclear. From 1 September this mandate will come from dedicated legislation which has been specifically written to accommodate delivery in both islands, with a specific legal power to deliver services in the Bailiwick of Guernsey. One of the best things about this is arrangement is that it avoids duplication for business, as we can support you consistently across the Channel Islands. It’s a much stronger footing and gives us a better foundation for supporting islanders across the Bailiwick, including strong provisions for data governance to give you confidence that if you tell us about an incident, it stays with us. We don’t tell the public, regulators or Government if you have an incident - that’s your call.
To those of you who came to our launch event, have already engaged with us, or who have benefitted from our work, I’d like to thank you. We’re learning as we develop and every piece of input and feedback we recieve along the way is valuable. It does truly feel like the pace has picked up, and that we’re working together to make the Bailiwick more secure against a world of ever-evolving threats.
Until next time,

GCSC in the Community
GCSC is working with Soteria Communications to plan a series of engagement events and incident response simulations this October. More details to be announced soon.
Those who attended our launch will be familiar with Soteria from our guest speaker Lynne Capie, who highlighted the importance of community in building resilience:
Her presentation also launched GCSC’s growing “Community of Cyber Influence” — a network of individuals from all backgrounds who align with GCSC’s mission and want to play a part.
The upcoming events will include engagement with this group, so if you are interested in signing up, tap the button below:
You can also find out more about Soteria’s cyber simulation events here.
GCSC’s home is taking shape

A view of the GCSC Operations Centre development over summer
GCSC office development continues, with work expected to finish by the end of summer.
The office now includes space for staff, a meeting room where we can welcome casual and informal visitors, and a boardroom for larger meetings and events.
The office will also include a bank of screens that will allow the team team to monitor the island’s overall security posture, keep an eye on developing threats, check live feeds, and review internal system statuses.
GCSC would like to thank Spaces, Vision Networks, Quantum and Amalgamated Facilities Management (thank you Martin!) for their work toward establishing the operations centre.
Phish of the Month

Photo by Julio Lopez on Unsplash
This regular series explores specific examples of phishing attacks that have caught our attention.
This week’s pick is a bit of a departure from classic phishing attacks (we’ve recently published an in-depth case study on one of those which you can read here). This example demonstrates a highly effective attack against agentic AI systems, which all starts with a single email.
MemGhost
What it is:
MemGhost is a tool developed by security researchers to demonstrate an email-driven attack dubbed “stealth memory injection.” This is a type of memory poisoning that tricks an AI agent into retaining false information about a user. This impacts all subsequent activity without the user’s knowledge.
How it works:
A specially crafted email is sent to someone who uses an AI assistant for inbox tasks. It contains credible-looking instructions aimed at the AI assistant, not the user. For example: “routine note to self from the owner.”
The AI assistant writes the new instructions to core memory but does not alert the user of any changes. It presents a normal email summary.
The new instructions persist across all future sessions and may not be noticed until it is too late. Changes made could lead to financial loss, jeopardise safety and compromise personal data.
Why it matters:
Adoption of agentic AI is rapidly increasing and this demonstrates how easily an AI model’s decision-making can be quietly compromised with big consequences. MemGhost showed an 87.5% end-to-end success rate against OpenClaw running GPT-5.4 while successfully bypassing common defences against classic prompt attacks.
What you can do:
This is a good reminder that not all phishing attacks target humans. The emails generated by MemGhost looked trustworthy, would pass traditional security tests and most existing AI-security controls, and did not lead to immediately obvious compromise.
You should always risk assess adoption of agentic AI for business and personal use and be sure to regularly audit the stored memories of any model currently in use.
Read the original paper via arvix.org:
Cyber Security in the News
WordPress Remote Code Execution (RCE) Discovered
Searchlight Cyber discovered a Remote Code Execution (RCE) vulnerability in WordPress this July, a web-templating platform estimated to power over 500 million websites globally.
The vulnerability occurs under ‘pre-authentication’ attack conditions. This is considered to be the most severe form of RCE, as it allows the threat actor to exploit the vulnerable system without any sort of password or access token.
Dubbed ‘wp2shell’, the anonymous exploit impacts the following versions of WordPress:
Versions 6.9.0 - 6.9.4
Versions 7.0.0 - 7.0.1
Versions older that 6.8.5 are not affected.
You can protect yourself now by updating to 7.0.2 (or updating to 6.9.5 if you’re using version 6.9). You can also block anonymous API access to your site. Searchlight Cyber offer a straightforward check on their website to determine if you are affected, and we have validated the site behaviour.)
Read more on Wp2shell using the button below via Searchlight Cyber.
Identity Attacks Overtake Exploits as Top Ransomware Cause
Sophos published its State of Ransomware 2026 report this month, which revealed some interesting findings. The key takeaway was that identity compromise has overtaken vulnerability exploitation as the leading root cause of ransomware attacks.
Email-based attacks (phishing and directly malicious emails) accounted for a combined 50% of ransomware cases while 23% involved compromised credentials. One of the most notable findings is that Multi-Factor Authentication was present in 97% of attacks involving compromised credentials, yet attackers still succeeded.
The report highlights the importance of using layered identity defences including advanced email filtering, anti-spoofing protocols, phishing training, and regular monitoring of breached credentials.
You can read more on the report using the button below.
Jobs in Cyber
Are you recruiting for a cyber role locally? Tell us at [email protected] and we’ll share your job listing with the community.
Cyber Manager, Risk Assurance Services
A specialist Cyber Manager role has opened within the Risk Assurance team of this well-respected global audit firm.
Tools of the Month
Each month, we provide a roundup of tools that our team have found useful, and which could be useful to cyber security professionals. If you’ve found a helpful tool you’d like to share, please email us and we’ll include it in a future newsletter.
Threat Actor Username Search
This tool will check a username against a database of more than 3 million documented threat actor handles observed on platforms associated with cyber crime activity. This can provide some strong leads for threat intelligence gathering and also help you assess if something is a risk in the first place. As a bonus, it even has an API so you can link to other tooling:
https://threatactorusernames.com/api/search?q=usernameTap the button below to access the web app:
The Periodic Table of DFIR
An interactive visual reference of 118 Digital Forensics and Incident Response (DFIR) tools organised into nine specialisms. A high-resolution printable poster is available and you can view an interactive online demo can be viewed using the button below.
Did you know? GCSC can also check potentially malicious files for you in our sandbox, but please let us know before sending them over.

