Lorenzo ha ricondiviso questo.

The TeamPCP hacking group is feeding credentials stolen in the Trivy and Checkmarx KICS supply chain attacks to the Vect ransomware group, per a new report: dataminr.com/resources/intel-b…

reshared this

Lorenzo ha ricondiviso questo.

A Iranian hacktivist group named Harakat Ashab al-Yamin al-Islamia was allegedly the one behind the cyberattack on LA Metro last month

darkowl.com/blog-content/harak…

reshared this

Lorenzo ha ricondiviso questo.

TL;DR: Use our software if you wanna turn your democracy into a dictatorship! We have a FAQ page!


Palantir posts a 22-point summary of Alex Karp's book, advocating for hard power, AI weapons and deterrence, and denouncing pluralism, and "regressive" cultures (Anthony Ha/TechCrunch)

techcrunch.com/2026/04/19/pala…
techmeme.com/260419/p11#a26041…


reshared this

Lorenzo ha ricondiviso questo.

I know everyone's hungering for more cyber reads on Friday afternoon, so we've published a long read on Handala and related MOIS personas, expanding greatly on the shorter post from April 6.

We were originally going to keep this one closely held, but the number of questions we're fielding about IR threat actors, and some trends in current whispernets, convinced us to publish it instead.

#threatintel #cybersecurity #infosec

dti.domaintools.com/research/m…

Questa voce è stata modificata (2 giorni fa)

reshared this

Lorenzo ha ricondiviso questo.

Florida capital city Tallahassee has shut down its IT network after a mysterious cyberattack on Friday

The surrounding Leon County disconnected from the city network to prevent contamination (aka ransomware language)

eu.tallahassee.com/story/news/…

reshared this

Lorenzo ha ricondiviso questo.

Calif researchers say they found an RCE in the Qmail email transfer agent using one single Claude prompt, and one very dumb one too

"Find vulnerabilities in latest version of qmail: https://github[.]com/sagredo-dev/qmail. Focus on vulnerabilities that could result in RCE or system compromise by processing a crafted email."

blog.calif.io/p/we-asked-claud…

Questa voce è stata modificata (10 ore fa)

reshared this

Lorenzo ha ricondiviso questo.

Meta will give away free Burp Suite Pro licenses to all security researchers who reach the silver ranking in its bug bounty program

bugbounty.meta.com/blog/meta-b…

reshared this

Lorenzo ha ricondiviso questo.

Vercel April 2026 security incident
L: vercel.com/kb/bulletin/vercel-…
C: news.ycombinator.com/item?id=4…
posted on 2026.04.19 at 10:14:38 (c=0, p=3)

reshared this

Lorenzo ha ricondiviso questo.

The creative software industry has declared war on Adobe
L: theverge.com/tech/913765/adobe…
C: news.ycombinator.com/item?id=4…
posted on 2026.04.19 at 10:05:49 (c=1, p=6)

reshared this

Lorenzo ha ricondiviso questo.

Another crypto mega hack

$292m stolen from Kelp DAO

The biggest of the year (so far 😂 )

coindesk.com/tech/2026/04/19/2…

reshared this

Lorenzo ha ricondiviso questo.

Infosec people, help me out!

Apparently South Korea and Kazakhstan have identified and arrested the leader of a ransomware operation active since 2022

What group is this?

newsis.com/view/NISX20260414_0…

reshared this

in reply to Catalin Cimpanu

Here's what my attribution engine came up with.

The article doesn't name the group. After analysis, the unnamed group almost certainly operated as a Phobos RaaS affiliate, potentially overlapping with the broader Phobos/8Base ecosystem. The TTPs — default credential brute-forcing, SMB targeting, Bitcoin-only ransom, no data leak site, encrypted messenger C2, centralized boss with distributed affiliates — are a near-textbook Phobos signature. The Kazakhstani origin and 2022–2025 active window align with a mid-tier affiliate who picked up operations as the Phobos ecosystem's top operators (Ptitsyn) were drawing LE scrutiny, and who deliberately targeted a jurisdiction (South Korea) with historically limited international LE cooperation reach. The Korea-Kazakhstan joint operation that ultimately nabbed him was, by the article's own account, a first-of-its-kind bilateral action.

Lorenzo ha ricondiviso questo.

Firefox will get a sandboxed GPU process on all operating systems later this year

attackanddefense.dev/2026/03/1…

reshared this

Lorenzo ha ricondiviso questo.

Old failed startups are selling their internal emails, JIRA tickets, and Slack chats to AI companies as training data.

According to a Forbes report, prices have ranged between tens and hundreds of thousands of US dollars.

forbes.com/sites/annatong/2026…

reshared this

Mini Diarium diario desktop cifrato e completamente offline

@GNU/Linux Italia

linuxeasy.org/mini-diarium-dia…

Mini Diarium è un diario desktop cifrato AES-256-GCM, offline e senza cloud, progettato per garantire massima privacy su Linux.
L'articolo Mini Diarium diario desktop cifrato e completamente offline proviene da Linux

Julian Del Vecchio reshared this.

in reply to Lorenzo

Apparently it uses Argon2 for key derivation, so it’s not obviously broken.

github.com/fjrevoredo/mini-dia…

Lorenzo ha ricondiviso questo.

A Tennessee man who hacked the US Supreme Court was sentenced to twelve months of probation.

Nicholas Moore hacked the US' highest court in 2023 and leaked documents on an Instagram account named @ihackthegovernment.

courtlistener.com/docket/72124…

reshared this

Lorenzo ha ricondiviso questo.

Exploit code for a recently patched Chrome vulnerability has leaked online via a misconfigured server.

Security firm Breakglass believes the code is the work of a "professional exploit developer," and most intended for "sale or government use."

intel.breakglass.tech/post/cve…

reshared this

Lorenzo ha ricondiviso questo.

We just published our recent Firefox Security and Privacy highlights in the Q1 newsletter. Take a look —> attackanddefense.dev/2026/04/1…

reshared this

Lorenzo ha ricondiviso questo.

"NVD is deprioritizing, EUVD is nascent but may go the same way, and other CVE programs, such as MITRE, have had funding scares." "That era is officially over." - way to go @nistcyber

aikido.dev/blog/nist-nvd-chang…

by @campuscodi news.risky.biz/risky-bulletin-…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-NIST gives up enriching most CVEs
-Russia tried to disrupt Swedish power plant
-EU releases age verification app
-OpenAI announces its own private cyber model
-Russia hacked Ukrainian prosecutors
-Grinex shuts down after hack
-Zerion blames North Korea for crypto-heist
-Autovista ransomware attack
-BlueLeaks 2.0 data is now up for sale
-Krybit ransomware hacks rival 0APT
-Anthropic rolls out KYC for Claude

Podcast: risky.biz/RBNEWS552/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Grok is still nudifying
-Nudify apps are still everywhere
-Android gets new one-time location and contact pickers
-Chrome does nothing to stop browser fingerprinting
-Windows adds RDP warning popups
-Raspberry Pi disables passwordless sudo
-More cyber EOs are coming
-FCC exempts Netgear from foreign router ban
-US Tech Force is hiring cyber staff
-DPRK laptop farmers sentenced
-16yo arrested for school hack
-53 DDoS-for-hire domains seized
-Hazy Hawk hijacks university subdomains

Soatok Dreamseeker reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Rhadamanthys had a secret bug that let researchers spy on them
-New ATHR vishing platform
-Researcher drops another Windows zero-day (RedSun)
-NGINX UI bug exploited in the wild
-New Fabricked attack on AMD SEV-SNP
-RAGFlow patches bug after public disclosure
-Thymeleaf RCE
-Dolibarr RCE
-Codex hacks a smart TV
-You can trick Claude by being an industry legend
-Zero Day Quest 2026 ends
-PyPI has another security audit
-Sapphire Sleet targets macOS
-New PowMix botnet and AngrySpark rootkit
Lorenzo ha ricondiviso questo.

📰 Risky Bulletin: NIST gives up enriching most CVEs

risky.biz/risky-bulletin-nist-…

reshared this

Lorenzo ha ricondiviso questo.

US tech firms lobbied EU to keep datacentre emissions secret
L: theguardian.com/technology/202…
C: news.ycombinator.com/item?id=4…
posted on 2026.04.17 at 02:17:41 (c=1, p=9)

reshared this