Salta al contenuto principale

Lorenzo ha ricondiviso questo.


One poor crypto-bro lost $21 million last week after they leaked their private key

Talk about oopsies

cointelegraph.com/news/hyperli…

reshared this


Lorenzo ha ricondiviso questo.


Talks from the REcon 2025 security conference, which took place in June, are available on YouTube

youtube.com/@reconmtl/videos

reshared this


Lorenzo ha ricondiviso questo.


Google does something really clever and now lets users recover their accounts through a family member or friends' account

blog.google/technology/safety-…

reshared this

in reply to Catalin Cimpanu

🤦
dangerous, it gives G**gle even more data for profiling, drawing connections of trust.

Lorenzo ha ricondiviso questo.


F5 says a state-sponsored hacking group stole BIG-IP source code and vulnerability reports

sec.gov/Archives/edgar/data/10…

reshared this


Lorenzo ha ricondiviso questo.


-Windows 10 reaches End-of-Life
-CISA layoffs didn't touch cyber personnel
-US seizes $15 billion from cyber scam compound operator
-Secure Boot bypass impacts 200k Framework systems
-German police take down 1,400 scam sites
-South Korea to investigate KT for obstruction over a breach
-Ansell, Harvard breached
-5CA denies role in Discord hack
-Unity shop got skimmed
-4chan fined in the UK
-Calls to investigate TikTok in the UK

Podcast: risky.biz/RBNEWS491/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-Firmware update bricks Jeeps
-Firefox 144 changes login storage encryption
-Also get a VPN
-California regulates AI
-UK Crypt-Key goes live
-Taiwan warns of "abnormal" social media accounts
-China offers reward for Taiwan's psychological warfare unit
-Australia, UK publish annual cyber threat reports
-SonicWall SSLVPN mass-compromise
-Another surveillance provider exposed (Cyber WAP)
-TA585 profile
-Analysis of Oct 7 DDoS attacks
-Venezuela ran info-ops in Ecuador
in reply to Catalin Cimpanu

-New UAC-0239 and UNC-RUS-ZIC APTs
-Patch Tuesday is out
-3 Microsoft zero-days
-RMPocalypse attack
-Pixnapping attack
-LatentBreak attack
-Half of satellite traffic is unencrypted
-LevelBlue acquires Cybereason
in reply to Catalin Cimpanu

I read the article about UNC-RUS-ZIC when it came out. It seems highly suspect to me. The attribution is vague at best, the other "details" are merely four-line paragraphs _devoid of details_. What made you chose this article for the newsletter?
in reply to Catalin Cimpanu

Wow. Framework is not having a good few weeks 😯🤦‍♂️

Lorenzo ha ricondiviso questo.


Another major surveillance provider exposed: First Wap

Its product was used to track some very high-profile figures

lighthousereports.com/investig…


Lorenzo ha ricondiviso questo.


The US seized today $15b from a mega cyber scam operator: justice.gov/usao-edny/pr/chair…

Elliptic says it tracked these funds to the the hack of Chinese mining pool LuBian in December 2020: elliptic.co/blog/15-billion-us…

Things... are getting weird

reshared this


Lorenzo ha ricondiviso questo.


Synacktiv looks at LinkPro, a new Linux eBPF-based rootkit it found deployed on a customer's hacked AWS infrastructure

synacktiv.com/en/publications/…

reshared this

in reply to Catalin Cimpanu

nice technical overview at a level I rarely see for Linux rootkits. Thanks for sharing!

Lorenzo ha ricondiviso questo.


Chinese authorities have issued bounties for 18 Taiwanese military members.

Police in China's Fujian province claim the 18 are part of Taiwan's "psychological warfare unit" that spread disinformation and propaganda on Taiwan's independence

reshared this


Lorenzo ha ricondiviso questo.


German and Bulgarian authorities have seized more than 1,400 websites that were used for financial crypto scams.

Officials recorded more than 866,000 attempts to access the sites over the ten days after they were seized, which highlighted the attackers' success

bafin.de/SharedDocs/Veroeffent…

reshared this

in reply to Catalin Cimpanu

Strange, I saw no mention of this in the Bulgarian news outlets I'm following...

BTW, 86k-per-day requests to a web site (most of them automated) is nothing special. Literally *anything* running on *any* port (not just 80 or 443) will get HTTP GET requests quite often.


Lorenzo ha ricondiviso questo.


Microsoft Oct 2025 Patch Tuesday is out with fixes for 3 actively exploited zero-days

rawcdn.githack.com/campuscodi/…

-CVE-2025-24990 — Windows Agere Modem Driver Elevation of Privilege Vulnerability
-CVE-2025-59230 — Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
-CVE-2025-47827 — Secure Boot bypass in IGEL OS before 11

reshared this


Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

I just realized this might screw up a lot of infostealers in the coming weeks. Chrome also does this regularly. Let's see how quick they adapt this time.

reshared this


Lorenzo ha ricondiviso questo.


RE: infosec.exchange/@agreenberg/1…

Research home page, if you wanna read the paper: satcom.sysnet.ucsd.edu/


Researchers pointed a satellite dish at the sky for 3 years and monitored what unencrypted data it picked up. The results were shocking: They obtained thousands of T-Mobile users' phone calls and texts, military and law enforcement secrets, much more: 🧵👇wired.com/story/satellites-are…

reshared this


in reply to Catalin Cimpanu

I just don't understand why anyone, even Firefox would want to store passwords in the browser?
in reply to Catalin Cimpanu

I'd still rather use a third-party password manager like Bitwarden.

Lorenzo ha ricondiviso questo.


Infosec drama, part 283,293: FuzzingLabs accuses Gecko Security of stealing two CVEs and backdating blogs

x.com/FuzzingLabs/status/19777…

reshared this


Lorenzo ha ricondiviso questo.


"Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites."

Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps

pixnapping.com/

reshared this

in reply to Catalin Cimpanu

“Pixnapping forces sensitive pixels into the rendering pipeline and overlays semi-transparent activities on top of those pixels via Android intents. To induce graphical operations on these pixels, our instantiations use Android’s window blur API. To measure rendering time, our instantiations use VSync callbacks.”

Lorenzo ha ricondiviso questo.


Security firm DarkTower has discovered four different Telegram emoji packs that contain bank logos and are likely used in cybercrime channels as a way to order phishing pages.

getdarktower.com/telegram-emoj…

reshared this


Lorenzo ha ricondiviso questo.


Mozilla has started the development of a free VPN feature for Firefox users.

This will be a separate product from Mozilla VPN, the company's commercial OS-level VPN.

connect.mozilla.org/t5/discuss…

reshared this

in reply to Catalin Cimpanu

Is it in partnership with Mullvad again? If so then I’d be somewhat interested but maybe not if it isn’t.
in reply to Catalin Cimpanu

ah and the famous "trust me bro"

i mean mozilla is anything but "trustable" when it come to privacy or security or moral these days.


Lorenzo ha ricondiviso questo.


-Microsoft revamps Edge's "IE Mode" after zero-day attacks
-FBI seizes Salesforce extortion site
-New round of CISA layoffs
-Apple doubles bug bounty rewards
-White House rescinds NSA&CyberCom chief nomination
-FCC warns of future crackdown on Chinese gear
-Fast Track breach targeted crypto casino operators
-Another Paragon victim identified
-Chrome will revoke old site permissions
-YouTube gives 2nd chance to banned channels

Newsletter: news.risky.biz/microsoft-revam…
Podcast: risky.biz/RBNEWS490/

reshared this

in reply to Catalin Cimpanu

-Nigerian scammer arrested in Argentina
-Scam compound raided in Cambodia
-PowerSchool hacker sentencing is this week
-Spain arrests major phishing provider
-RDP attack wave targets US
-Aisuru botnet gets US-heavy
-New Brotherhood leak site
-New ChaosBot and ClayRat malware
-New APT35 leaks
-DPRK IT workers now target architects
-New Gladinet zero-day
-New Oracle EBS bug
-NSO has US owners now

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


Microsoft published last week a dedicated page for recommended Intune security configurations

learn.microsoft.com/en-us/intu…

reshared this

in reply to Catalin Cimpanu

Is 'don't use InTune because the authors have no idea what the principle of least privilege means, put a huge pile of things that handle untrusted code in high-privilege modes, and then tell you "it's a management system not a security system, don't use it for security" when you object to it being rolled out across all devices' one of them?

Lorenzo ha ricondiviso questo.


Argentina arrested its first suspect on an Interpol Red Notice

...it was a Nigerian romance scammer

x.com/interpolwanted/status/19…

reshared this

in reply to Catalin Cimpanu

non ho quella pattumiera di X

google.com/url?sa=t&source=web…


Lorenzo ha ricondiviso questo.


Clop's extortion streak:

Accellion FTA platform (2020)
SolarWinds Serv-U FTP (2021)
GoAnywhere MFT platform (2023)
MOVEit Transfer (2023)
Cleo file transfer (2024)
E-Business Suite (2025)

via: orangecyberdefense.com/global/…

reshared this


Lorenzo ha ricondiviso questo.


Trend Micro's ZDI has reported 13 vulnerabilities in the Ivanti Endpoint Manager that are still unpatched after the vendor requested an extension until March next year

zerodayinitiative.com/advisori…

reshared this


Lorenzo ha ricondiviso questo.


Spain has arrested the person behind the GXC phishing service.

Per authorities, the guy was living in Spain under a digital nomad visa and was constantly moving between different homes across the country

web.guardiacivil.es/es/destaca…

reshared this


Lorenzo ha ricondiviso questo.


Telegram founder and general a-hole Pavel Durov, whose IM network hosts hundreds of groups where info-ops coordinate their activity and pay for content, is annoyed that democracies are fighting back against the damage he, personally, has helped usher in in many autocratic regimes
Questa voce è stata modificata (3 giorni fa)

reshared this

in reply to Catalin Cimpanu

I haven't seen any evidence that Pavel Durov is an arsehole.

If you're going to post takes like this, please elaborate on whether you would want the same measures Durov describes being enacted against Mastodon.

The line of reasoning that goes 'this encrypted app hosts <bad content>' is exactly the line authoritarians of all stripes use to shut down any form of free internet.

Also he's using mildly right-coded speech, but so what, he's correct.


Lorenzo ha ricondiviso questo.


This is a neat question from a recent Sophos survey on ransomware attacks on healthcare orgs

news.sophos.com/en-us/2025/10/…

Questa voce è stata modificata (4 giorni fa)

reshared this

in reply to Catalin Cimpanu

What repercussions has the ransomware attack had on the people in your IT/cybersecurity team, if any?


...I can't imagine a ransomware attack not resulting in just a tiny bit of "increased pressure" from senior leaders.

"Oh, we're under a ransomware attack? Not to worry, all in good time, folks. No need to work overtime, we'll get around to fixing things eventually."

I'm not sure I'd be able to respond to the question without clarification. Are they talking about increased pressure during the attack, or increased pressure after the next quarterly financial report? Constant pressure or only while stuff is on fire?


Lorenzo ha ricondiviso questo.


Second zero-day in Gladinet file-sharing servers this year

huntress.com/blog/gladinet-cen…

reshared this


Lorenzo ha ricondiviso questo.


Talks from the Balkan Computer Congress 2025 security conference, which took place last September, are available on YouTube

youtube.com/playlist?list=PLyH…

reshared this


Lorenzo ha ricondiviso questo.


-EU scraps Chat Control vote
-Ukraine establishes a Cyber Force
-CISA workers reassigned to immigration enforcement
-Teenagers arrested for Kido hack
-Salesforce will not pay the ransom
-US Court halts FCC data breach rules
-California enacts tracking opt-out law
-China cleanses its internet of bad feelings
-All MySonicWall customers impacted by recent breach
-Discord breach impacted only 70k
-Kasatkin case starts in France

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS489/

reshared this

in reply to Catalin Cimpanu

-Telenor sued for passing data to Myanmar junta
-Apple removes ICE activity archiving app
-Another Paragon victim identified in Italy
-TwoNet targets OT/ICS networks
-Crimson Collective goes after AWS environments
-Velociraptor now abused in attacks
-Storm-2657 profile
-New CipherWolf RaaS
-New Kryptos ransomware
-RondoDox botnet grows massive
-CamoLeak vuln
-ASCII attack on LLMs
-Framelink Figma RCE
-China's vulnerability research ecosystem
-New UTA0388 APT
-C2A buys VigilantOps

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


Denmark scraps next week's Chat Control vote (was scheduled for Tuesday, Oct 14)

deutschlandfunk.de/eu-staaten-…

reshared this

in reply to Catalin Cimpanu

youtube.com/watch?v=Xb6F6kIqlx…

Lorenzo ha ricondiviso questo.


Here's the German government's statement on not supporting Chat Control, calling it a "taboo for the rule of law."

bmjv.de/SharedDocs/Zitate/DE/2…

reshared this

in reply to Catalin Cimpanu

🎉 didn’t expect that for Germany to be honest land was also very surprised that Austria also on the list of non supporters.

Lorenzo ha ricondiviso questo.


Is Google gonna return just BleepingComputer links for every infosec term now? Did all the other sites die out?

reshared this


Lorenzo ha ricondiviso questo.


PAN's Unit42 looks at IUAM ClickFix Generator, a new phishing kit designed around using ClickFix-based phishing pages.

unit42.paloaltonetworks.com/cl…

reshared this

in reply to Catalin Cimpanu

I was just reading about this and bumped into Croatian IT news site which is infected and targets macOS:

Lorenzo ha ricondiviso questo.


Trend Micro says that a botnet named RondoDox that launched earlier this year has grown to a massive size and is now exploiting more than 50 vulnerabilities across 30+ different vendors

trendmicro.com/en_us/research/…

reshared this


Lorenzo ha ricondiviso questo.


A Russian hacktivist group named TwoNet claimed the hack of a water treatment facility that ended up being just a Forescout honeypot

forescout.com/blog/anatomy-of-…


in reply to Catalin Cimpanu

i always found stupid that EU did not mandate the browser to do this in the first place, ya know like a DNT but this time backed by law.

Lorenzo ha ricondiviso questo.


Norwegian telecommunications company Telenor has been sued for human rights abuses.

Plaintiffs claim the company's subsidiary, CelcomDigi, unlawfully shared customer data with the Myanmar military junta.

malaysiakini.com/news/757219


Lorenzo ha ricondiviso questo.


The first hearing in the case of Daniil Kasatkin, the Russian basketball player accused to be part of the Conti ransomware group, took place yesterday. Notes from the hearing are below:

pwned.substack.com/p/on-ne-lim…

reshared this


Lorenzo ha ricondiviso questo.


Recent Nezha abuse linked to an unnamed Chinese APT

"What began with a creative way to drop a web shell onto the system quickly escalated into a multi-stage attack that demonstrated a clear focus on stealth and persistence. Tools, malware, IP addresses, domains, and victim demographics all appear to point towards a capable China-nexus threat actor who has been underreported on."

huntress.com/blog/nezha-china-…


in reply to Catalin Cimpanu

I don't understand why a problem with Front Door would be a massive problem in Azure; wouldn't everyone just use the windows?