reshared this
One poor crypto-bro lost $21 million last week after they leaked their private key
Talk about oopsies
reshared this
Talks from the REcon 2025 security conference, which took place in June, are available on YouTube
Recon Conference
REcon is a computer security conference with a focus on reverse engineering and advanced exploitation techniques. It is held annually in Montreal, Canada.YouTube
reshared this
Google does something really clever and now lets users recover their accounts through a family member or friends' account
blog.google/technology/safety-…
Recovery Contacts: Sign in with a little help from your friends and family
An overview of Recovery Contacts, so friends and family can verify your identity if you lose access to your Google account.Claire Forszt (Google)
reshared this
F5 says a state-sponsored hacking group stole BIG-IP source code and vulnerability reports
reshared this
-Windows 10 reaches End-of-Life
-CISA layoffs didn't touch cyber personnel
-US seizes $15 billion from cyber scam compound operator
-Secure Boot bypass impacts 200k Framework systems
-German police take down 1,400 scam sites
-South Korea to investigate KT for obstruction over a breach
-Ansell, Harvard breached
-5CA denies role in Discord hack
-Unity shop got skimmed
-4chan fined in the UK
-Calls to investigate TikTok in the UK
Podcast: risky.biz/RBNEWS491/
Newsletter: news.risky.biz/risky-bulletin-…
Risky Bulletin: Windows 10 reaches End-of-Life
In other news: CISA layoffs didn't touch cyber personnel; US seizes $15 billion from cyber scam compound operator; Secure Boot bypass impacts 200k Framework systems.Catalin Cimpanu (Risky.Biz)
reshared this
-Firefox 144 changes login storage encryption
-Also get a VPN
-California regulates AI
-UK Crypt-Key goes live
-Taiwan warns of "abnormal" social media accounts
-China offers reward for Taiwan's psychological warfare unit
-Australia, UK publish annual cyber threat reports
-SonicWall SSLVPN mass-compromise
-Another surveillance provider exposed (Cyber WAP)
-TA585 profile
-Analysis of Oct 7 DDoS attacks
-Venezuela ran info-ops in Ecuador
reshared this
Another major surveillance provider exposed: First Wap
Its product was used to track some very high-profile figures
lighthousereports.com/investig…
Surveillance Secrets - Lighthouse Reports
Trove of surveillance data challenges what we thought we knew about location tracking tools, who they target and how far they have spreadLighthouse Reports
reshared this
More reports on the same company:
motherjones.com/politics/2025/…
derstandard.at/story/310000029…
spiegel.de/wirtschaft/unterneh…
lemonde.fr/pixels/article/2025…
irpimedia.irpi.eu/surveillance…
First Wap, la discrète entreprise de cybersurveillance chargée de suivre à la trace journalistes, personnalités et cadres dirigeants
Peu connu du grand public, ce vétéran du secteur vend depuis plus de vingt ans une solution de géolocalisation, y compris à des régimes autoritaires.Damien Leloup (Le Monde)
The US seized today $15b from a mega cyber scam operator: justice.gov/usao-edny/pr/chair…
Elliptic says it tracked these funds to the the hack of Chinese mining pool LuBian in December 2020: elliptic.co/blog/15-billion-us…
Things... are getting weird
Chairman of Prince Group Indicted for Operating Cambodian Forced-Labor Scam Compounds Engaged in Cryptocurrency Fraud Schemes
25-cr-312_indictment.pdf BROOKLYN, NY - An indictment was unsealed today in federal court in Brooklyn charging Chen Zhi, also known as “Vincent,” the founder and chairman of Prince Holding Group (Prince Group), a multinational business conglomerate b…www.justice.gov
reshared this
Synacktiv looks at LinkPro, a new Linux eBPF-based rootkit it found deployed on a customer's hacked AWS infrastructure
reshared this
German and Bulgarian authorities have seized more than 1,400 websites that were used for financial crypto scams.
Officials recorded more than 866,000 attempts to access the sites over the ten days after they were seized, which highlighted the attackers' success
bafin.de/SharedDocs/Veroeffent…
Schlag gegen Cyberkriminelle
Die Generalstaatsanwaltschaft Karlsruhe, das Landeskriminalamt Baden-Württemberg und die Finanzaufsicht BaFin informieren über einen Schlag gegen international agierende Cyberkriminelle.BaFin
reshared this
Strange, I saw no mention of this in the Bulgarian news outlets I'm following...
BTW, 86k-per-day requests to a web site (most of them automated) is nothing special. Literally *anything* running on *any* port (not just 80 or 443) will get HTTP GET requests quite often.
Microsoft Oct 2025 Patch Tuesday is out with fixes for 3 actively exploited zero-days
rawcdn.githack.com/campuscodi/…
-CVE-2025-24990 — Windows Agere Modem Driver Elevation of Privilege Vulnerability
-CVE-2025-59230 — Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
-CVE-2025-47827 — Secure Boot bypass in IGEL OS before 11
reshared this
RE: mastodon.social/@campuscodi/11…
I just realized this might screw up a lot of infostealers in the coming weeks. Chrome also does this regularly. Let's see how quick they adapt this time.
reshared this
RE: infosec.exchange/@agreenberg/1…
Research home page, if you wanna read the paper: satcom.sysnet.ucsd.edu/
🛰️ SATCOM Security
Research project homepage for SATCOM Security: papers, source code, and recent satellite communications vulnerabilities.satcom.sysnet.ucsd.edu
reshared this
Firefox 144 is out with hardened encryption for locally stored passwords
reshared this
Infosec drama, part 283,293: FuzzingLabs accuses Gecko Security of stealing two CVEs and backdating blogs
reshared this
"Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites."
Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps
reshared this
Security firm DarkTower has discovered four different Telegram emoji packs that contain bank logos and are likely used in cybercrime channels as a way to order phishing pages.
getdarktower.com/telegram-emoj…
Telegram Emoji Packs - DarkTower
Trevor Wilson Introduction A Telegram Emoji Pack is a collection of custom static or animated images that users can add to the messenger to personalize their communication.infomedia (DarkTower)
reshared this
Mozilla has started the development of a free VPN feature for Firefox users.
This will be a separate product from Mozilla VPN, the company's commercial OS-level VPN.
connect.mozilla.org/t5/discuss…
Re: New Experiment: Firefox VPN Beta
I think about common case is that some special sites need to be open with VPN. While the other sites should be accessed as normal, without VPN.connect.mozilla.org
reshared this
ah and the famous "trust me bro"
i mean mozilla is anything but "trustable" when it come to privacy or security or moral these days.
-Microsoft revamps Edge's "IE Mode" after zero-day attacks
-FBI seizes Salesforce extortion site
-New round of CISA layoffs
-Apple doubles bug bounty rewards
-White House rescinds NSA&CyberCom chief nomination
-FCC warns of future crackdown on Chinese gear
-Fast Track breach targeted crypto casino operators
-Another Paragon victim identified
-Chrome will revoke old site permissions
-YouTube gives 2nd chance to banned channels
Newsletter: news.risky.biz/microsoft-revam…
Podcast: risky.biz/RBNEWS490/
Microsoft revamps Edge's "IE Mode" after zero-day attacks
In other news: FBI seizes Salesforce extortion site; new round of CISA layoffs; Apple doubles bug bounty rewards.Catalin Cimpanu (Risky.Biz)
reshared this
-Scam compound raided in Cambodia
-PowerSchool hacker sentencing is this week
-Spain arrests major phishing provider
-RDP attack wave targets US
-Aisuru botnet gets US-heavy
-New Brotherhood leak site
-New ChaosBot and ClayRat malware
-New APT35 leaks
-DPRK IT workers now target architects
-New Gladinet zero-day
-New Oracle EBS bug
-NSO has US owners now
Catalin Cimpanu reshared this.
Microsoft published last week a dedicated page for recommended Intune security configurations
learn.microsoft.com/en-us/intu…
Configure Microsoft Intune for increased security - Microsoft Intune
Learn how to improve your security posture with Microsoft Intune.learn.microsoft.com
reshared this
Argentina arrested its first suspect on an Interpol Red Notice
...it was a Nigerian romance scammer
reshared this
non ho quella pattumiera di X
google.com/url?sa=t&source=web…
Cayó en Ezeiza el rompecorazones nigeriano: primera captura mundial con alerta plateada de Interpol
El sospechoso está acusado de ser uno de los líderes de una organización internacional dedicada a las estafas virtuales que se hizo de un botín de US$8.000.000Gabriel Di Nicola (LA NACION)
Clop's extortion streak:
Accellion FTA platform (2020)
SolarWinds Serv-U FTP (2021)
GoAnywhere MFT platform (2023)
MOVEit Transfer (2023)
Cleo file transfer (2024)
E-Business Suite (2025)
reshared this
Trend Micro's ZDI has reported 13 vulnerabilities in the Ivanti Endpoint Manager that are still unpatched after the vendor requested an extension until March next year
reshared this
Spain has arrested the person behind the GXC phishing service.
Per authorities, the guy was living in Spain under a digital nomad visa and was constantly moving between different homes across the country
reshared this
I haven't seen any evidence that Pavel Durov is an arsehole.
If you're going to post takes like this, please elaborate on whether you would want the same measures Durov describes being enacted against Mastodon.
The line of reasoning that goes 'this encrypted app hosts <bad content>' is exactly the line authoritarians of all stripes use to shut down any form of free internet.
Also he's using mildly right-coded speech, but so what, he's correct.
This is a neat question from a recent Sophos survey on ransomware attacks on healthcare orgs
news.sophos.com/en-us/2025/10/…
The State of Ransomware in Healthcare 2025
292 IT and cybersecurity leaders reveal the ransomware realities for healthcare establishments today.Sophos News
reshared this
What repercussions has the ransomware attack had on the people in your IT/cybersecurity team, if any?
...I can't imagine a ransomware attack not resulting in just a tiny bit of "increased pressure" from senior leaders.
"Oh, we're under a ransomware attack? Not to worry, all in good time, folks. No need to work overtime, we'll get around to fixing things eventually."
I'm not sure I'd be able to respond to the question without clarification. Are they talking about increased pressure during the attack, or increased pressure after the next quarterly financial report? Constant pressure or only while stuff is on fire?
Second zero-day in Gladinet file-sharing servers this year
huntress.com/blog/gladinet-cen…
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371)
Huntress has observed in-the-wild exploitation of a Local File Inclusion vulnerability in Gladinet CentreStack and Triofox products.Bryan Masters (Huntress)
reshared this
Talks from the Balkan Computer Congress 2025 security conference, which took place last September, are available on YouTube
reshared this
-EU scraps Chat Control vote
-Ukraine establishes a Cyber Force
-CISA workers reassigned to immigration enforcement
-Teenagers arrested for Kido hack
-Salesforce will not pay the ransom
-US Court halts FCC data breach rules
-California enacts tracking opt-out law
-China cleanses its internet of bad feelings
-All MySonicWall customers impacted by recent breach
-Discord breach impacted only 70k
-Kasatkin case starts in France
Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS489/
Risky Bulletin: EU scraps Chat Control vote
In other news: Ukraine establishes a Cyber Force; CISA workers reassigned to immigration enforcement; teenagers arrested for Kido hack.Catalin Cimpanu (Risky.Biz)
reshared this
-Apple removes ICE activity archiving app
-Another Paragon victim identified in Italy
-TwoNet targets OT/ICS networks
-Crimson Collective goes after AWS environments
-Velociraptor now abused in attacks
-Storm-2657 profile
-New CipherWolf RaaS
-New Kryptos ransomware
-RondoDox botnet grows massive
-CamoLeak vuln
-ASCII attack on LLMs
-Framelink Figma RCE
-China's vulnerability research ecosystem
-New UTA0388 APT
-C2A buys VigilantOps
Catalin Cimpanu reshared this.
Denmark scraps next week's Chat Control vote (was scheduled for Tuesday, Oct 14)
deutschlandfunk.de/eu-staaten-…
"Chatkontrolle" - EU-Staaten erzielen keine Einigung
Die EU-Staaten haben erneut keine Einigung auf eine sogenannte Chatkontrolle im Kampf gegen sexualisierte Gewalt gegen Kinder erzielt.Die Nachrichten
reshared this
- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
Here's the German government's statement on not supporting Chat Control, calling it a "taboo for the rule of law."
bmjv.de/SharedDocs/Zitate/DE/2…
Zitat
Anlasslose Chatkontrolle muss in einem Rechtsstaat tabu sein. Private Kommunikation darf nie unter Generalverdacht stehen.“Bundesministerium der Justiz
reshared this
reshared this
PAN's Unit42 looks at IUAM ClickFix Generator, a new phishing kit designed around using ClickFix-based phishing pages.
unit42.paloaltonetworks.com/cl…
The ClickFix Factory: First Exposure of IUAM ClickFix Generator
Unit 42 discovers ClickFix phishing kits, commoditizing social engineering. This kit presents a lowered barrier for inexperienced cybercriminals.Amer Elsad (Unit 42)
reshared this
Trend Micro says that a botnet named RondoDox that launched earlier this year has grown to a massive size and is now exploiting more than 50 vulnerabilities across 30+ different vendors
trendmicro.com/en_us/research/…
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Trend™ Research and ZDI Threat Hunters have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.Trend Micro - United States (US)
reshared this
A Russian hacktivist group named TwoNet claimed the hack of a water treatment facility that ended up being just a Forescout honeypot
forescout.com/blog/anatomy-of-…
Anatomy of a Hacktivist Attack: Russia-Aligned Group Targets OT/ICS
How do hacktivist groups attack utilities? Vedere Labs research uncovers the techniques of a Russian group’s attempt on a decoy water facility.Forescout Research - Vedere Labs (Forescout Technologies, Inc.)
reshared this
Looks like California has learned something from the EU Cookie Banner disaster
reshared this
Norwegian telecommunications company Telenor has been sued for human rights abuses.
Plaintiffs claim the company's subsidiary, CelcomDigi, unlawfully shared customer data with the Myanmar military junta.
Myanmar data lawsuit hits Telenor, raising questions for CelcomDigi
Alleged data disclosures said to have led to arrests, torture, execution by junta.Qistina Nadia Dzulqarnain (Malaysiakini)
reshared this
The first hearing in the case of Daniil Kasatkin, the Russian basketball player accused to be part of the Conti ransomware group, took place yesterday. Notes from the hearing are below:
pwned.substack.com/p/on-ne-lim…
« On ne l’imagine pas basketteur le jour et hacker la nuit »
Arrêté le 23 juin à Roissy à la demande de la justice américaine, Daniil Kasatkin conteste son extradition devant la chambre de l'instruction.Gabriel Thierry (Pwned)
reshared this
Recent Nezha abuse linked to an unnamed Chinese APT
"What began with a creative way to drop a web shell onto the system quickly escalated into a multi-stage attack that demonstrated a clear focus on stealth and persistence. Tools, malware, IP addresses, domains, and victim demographics all appear to point towards a capable China-nexus threat actor who has been underreported on."
huntress.com/blog/nezha-china-…
The Crown Prince, Nezha: A New Tool Favored by China-Nexus Threat Actors
Beginning in mid-2025, Huntress discovered a new tool being used to facilitate webserver intrusions known as Nezha, which up until now hasn’t been publicly reported on.Jai Minton (Huntress)
reshared this
Krypt3ia
in reply to Catalin Cimpanu • • •