Salta al contenuto principale

Lorenzo ha ricondiviso questo.


Microsoft drops Israel's surveillance contract that allowed intel services to process data from intercepted phone calls and messages sent across Palestine

blogs.microsoft.com/on-the-iss…

reshared this


Lorenzo ha ricondiviso questo.


Koi Security claims to have spotted the world's first malicious MCP server that secretly copies and stealers all emails passing through a Postmark server

koi.security/blog/postmark-mcp…

reshared this


Lorenzo ha ricondiviso questo.


More than 10,600 Ollama LLM-hosting servers are exposed on the internet: censys.com/blog/ollama-drama-i…

Almost 4,800 Firebase databases exposed on the internet and leaking their data: ice0.blog/docs/openfirebase

reshared this


Lorenzo ha ricondiviso questo.


Hi, SAP!

It's me, the EU! You haven't visited or written in a while!

What's up?!?!?!

ec.europa.eu/commission/pressc…

reshared this


Lorenzo ha ricondiviso questo.


Here's some crypto-stealing malware on Rust's Crates package repo.... just in case you're waiting for the PyPI and npm ones to show up

blog.rust-lang.org/2025/09/24/…

socket.dev/blog/two-malicious-…

reshared this


Lorenzo ha ricondiviso questo.


DomainTools has a good profile on Salt Typhoon, the Chinese APT that hacked over a dozen US telcos at the end of last year. It's actually a very old and sprawling APT, involving everything from MSS supervisors to front companies and contractors.

dti.domaintools.com/inside-sal…

reshared this


Lorenzo ha ricondiviso questo.


Eight orgs involved in FOSS and package repos have asked for more support for package repos because of the skyrocketing costs for hosting everyone's code

"In effect, public registries have become free global CDNs for commercial vendors."

openssf.org/blog/2025/09/23/op…

reshared this

in reply to Catalin Cimpanu

this seems strange. while the “Open Infrastructure is Not Free” blog is sound, I went to the about page and noted:

> The founding members are GitHub, Google, IBM, JPMorgan Chase, Microsoft, NCC Group, OWASP Foundation, and Red Hat, among others.

arent these members the perpetrators here? something seems amiss

——

anyways, best solution is prob going distributed (eg. @radicle )

Questa voce è stata modificata (6 ore fa)
in reply to Catalin Cimpanu

For a start people could use local caches instead of downloading everything again from the package registry for every CI run.

Lorenzo ha ricondiviso questo.


A love story:

-17yo Romanian teens sends bomb threats to hundreds of US schools
-US charges him
-Romania refuses extradition
-Teen sends mass-shooting threats to hundreds of Romanian schools

hotnews.ro/cine-este-tanarul-s…

reshared this


Lorenzo ha ricondiviso questo.


-US raids SIM farm in New York
-EU airport disruptions caused by ransomware
-Thieves steal gold from French museum after cyberattack
-SonicWall firmware update removes rootkit
-Jaguar ransomware incident extends to October
-Breach at car giant Stellantis
-Circle K hack upends Hong Kong operations
-South Korean asset management firms hacked
-UXLINK hacker gets phished, loses funds
-Kirk doxing app leaks user data

Podcast: risky.biz/RBNEWS482/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-GitHub to improve npm security
-TikTok to retrain algorithm on US data (yuck)
-CISA 2015 renewal unlikely
-Russia wants to minimize data collection
-Russia prepares to amp up the persecution of its own citizens
-EU looking to reduce cookie popups
-Poland threatens hack-back operations
-Romania says Russian cyber-attack could crash payment system in 3 days
-Crypto-fraud gang dismantled in EU
-New DDoS record, now at 22.2 Tbps
in reply to Catalin Cimpanu

-YiBackdoor comes to replace Latrodectus
-Malware reports on Zloader, RomCom, Gunra, and Elons ransomware
-New Naikon APT ops
-Kimsuky's sex offender campaign
-New DELMIA Apriso bugs
-Libraesva ESG zero-day
-Russia's Moldova info-ops are a sign of the future of all elections
-New Chrome extension loading technique
-Malware found in qbittorrent Docker container
-m0leCon 2025 videos
in reply to Catalin Cimpanu

are they going to be selling those shelves? They'd match my existing garage set

Lorenzo ha ricondiviso questo.


You can always count on the crypto community for a good laugh

reshared this


Lorenzo ha ricondiviso questo.


Sophos says one of its employees got phished in March but the breach was limited and contained

news.sophos.com/en-us/2025/09/…

reshared this


Lorenzo ha ricondiviso questo.


AttackIQ has published a report on the evolution of the RomCom malware, covering up to v5 of the tool, which others also call SnipBot and SingleCamper. The malware started out as an e-crime MaaS, but is now often used for APT ops against Ukraine and Europe.

attackiq.com/2025/09/23/evolut…

Questa voce è stata modificata (1 giorno fa)

reshared this


Lorenzo ha ricondiviso questo.


All these reports on the Moldovan disinfo campaigns would have been extremely useful a month ago....

Dear infosec/disinfo research firms, stop publishing crucial info at the very last moment

Signed, a bunch of LEO people annoying me in DMs

reshared this


Lorenzo ha ricondiviso questo.


New DELMIA bugs disclosed after another was exploited in early Sep

"Both findings chain together: the unauth account creation gives an attacker credentials, and those credentials are then used to authenticate and abuse the file upload to drop a web shell."

projectdiscovery.io/blog/remot…

reshared this


Lorenzo ha ricondiviso questo.


The Python Software Foundation warns of a phishing campaign targeting PyPI users. The phishing domain is pypi-mirror[.]org, a variation of the main pypi[.]org domain.

blog.pypi.org/posts/2025-09-23…

reshared this


Lorenzo ha ricondiviso questo.


Poland has threatened to hack back any country that cripple its critical infrastructure.

Minister of Digital Affairs Krzysztof Gawkowski says the country has the possibilities to respond.

portalsamorzadowy.pl/polityka-…

reshared this


Lorenzo ha ricondiviso questo.


Romania's national bank governor warned against the transition to a digital euro without a cash alternative or proper cybersecurity defenses.

Mugur Isărescu says that a Russian cyber-attack could block all payments in the country within three days.

hotnews.ro/avertismentul-lui-m…

reshared this

in reply to Catalin Cimpanu

Digital money without a physical cash alternative would be a disaster for personal freedom - and you don't even need any Russian attacks for that.

Lorenzo ha ricondiviso questo.


GitHub will require a FIDO-based two-factor authentication method to publish updates to npm packages.

The company will also deprecate legacy long-lived npm tokens and roll out new ones that last only seven days.

github.blog/security/supply-ch…

reshared this

in reply to Catalin Cimpanu

hm, i wonder if they mean passkeys? restricting publishing to those who can afford hardware security tokens seems like adding barriers to developers when software passkeys are also reliable and secure
in reply to Catalin Cimpanu

Sounds like if you have any packages there just start publishing PoC exploits instead of updates.

Lorenzo ha ricondiviso questo.


The press release for that Secret Service UN SIM farm raid is here: secretservice.gov/newsroom/rel…

Some images are below:

reshared this

in reply to Catalin Cimpanu

Very interesting photos. Taken with an iPhone, and transmitted to the recipient using Signal. I didn't know the Secret Service used Signal!

Lorenzo ha ricondiviso questo.


North Korean espionage group Kimsuky used "sex offender notices" to lure victims into running its malware

logpresso.com/ko/blog/2025-09-…

reshared this


Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

Check Point has a report on this same campaign and group, which they track as Nimbus Manticore

research.checkpoint.com/2025/n…


An Iranian cyber-espionage group is using fake LinkedIn jobs to target employees of EU telcos and defense organizations.

According to security firm Prodaft, one of the group's most recent campaigns has infected 34 devices across 11 organizations.

catalyst.prodaft.com/public/re…


reshared this


Lorenzo ha ricondiviso questo.


Talks from the m0leCon 2025 security conference, which took place earlier this month, are available on YouTube

youtube.com/playlist?list=PLU9…

reshared this


Lorenzo ha ricondiviso questo.


Russia prepares to amp up the persecution of its own citizens

The government wants to create a database of people who continue to visit and access the sites of "foreign agents"... aka foreign media who don't parrot the government's lies

news.ru/vlast/v-gosdume-zaduma…


Lorenzo ha ricondiviso questo.


MAX, Russia's newly anointed official national messenger, now has 32 million users, per Kommersant

kommersant.ru/doc/8058240

reshared this

in reply to Catalin Cimpanu

That is quite a few existing X users that were automagically enrolled.

The bot accounts in St. Petersburg are happy per reports.


Lorenzo ha ricondiviso questo.


There is light at the end of the tunnel... hang in there folks!

reshared this

in reply to Catalin Cimpanu

Hopefully this means making something like Do not track in browsers mandatory and not just letting tracking cookies be set without consent.
in reply to Catalin Cimpanu

Cookie banners are malicious compliance by surveillance capitalists. Are we sure ‘simplifying’ doesn’t mean caving to the tactic and reducing privacy rights?

Lorenzo ha ricondiviso questo.


EU cyber agency says airport software held to ransom by criminals

bbc.com/news/articles/cqjeej85…

reshared this


Lorenzo ha ricondiviso questo.


The Pentagon wants to shorten the hiring window for cybersecurity talent to only 25 days

The department currently averages 70 days for a new hire

cyberscoop.com/dod-cyber-workf…

reshared this

in reply to Catalin Cimpanu

In fairness, it should be a lot quicker to hire people when you're more concerned about their ideological purity and political reliability than whether they're technically competent.
in reply to Catalin Cimpanu

They hired people only for 70 days and want to reduce that to 25? No wonder nobody wants to work for them...

Lorenzo ha ricondiviso questo.


CISA wants more international involvement in cyber vulnerability catalog, official says

nextgov.com/cybersecurity/2025…

reshared this


Lorenzo ha ricondiviso questo.


Security researcher Mehmet Ergene has published the Microsoft Vulnerable Driver Block Lists after Microsoft stopped publishing the list in a browsable web page

github.com/Cyb3r-Monk/Microsof…

reshared this


Lorenzo ha ricondiviso questo.


An Iranian cyber-espionage group is using fake LinkedIn jobs to target employees of EU telcos and defense organizations.

According to security firm Prodaft, one of the group's most recent campaigns has infected 34 devices across 11 organizations.

catalyst.prodaft.com/public/re…

reshared this


Lorenzo ha ricondiviso questo.


Hackers have stolen $2 million worth of NGP tokens from the New Gold Protocol DeFi platform

theblock.co/post/371191/ngp-ex…

reshared this


Lorenzo ha ricondiviso questo.


LinkedIn will resume training generative AI models on data from EU users after a year-long halt

news.bloomberglaw.com/business…


Lorenzo ha ricondiviso questo.


There's been a hostile takeover of the RubyGems package repository, with some rando dude having full control of everything now

old.reddit.com/r/ruby/comments…

in reply to Catalin Cimpanu

years ago a client asked me about moving to Ruby. My response was simple: why? I'd read on it a bit and couldn't see any reason to switch, or benefit. Still can't.

Lorenzo ha ricondiviso questo.


A teenage boy suspected of involvement in the 2023 cyberattacks that disrupted the two largest Las Vegas casino companies has surrendered to authorities, according to the Las Vegas Metropolitan Police Department (LVMPD).

casino.org/news/teen-suspect-s…

reshared this


Lorenzo ha ricondiviso questo.


Cyberattack disrupts European airports including Heathrow, Brussels

reuters.com/en/cyberattack-cau…

reshared this


Lorenzo ha ricondiviso questo.


Oh no...

"A bombshell report claims a Chinese-backed tech firm may have harvested brain data from top athletes, including Ferrari F1 driver Charles Leclerc."

crash.net/f1/news/1082055/1/ch…

reshared this

in reply to Catalin Cimpanu

This (and the lengthy original report as well) sounds like a tremendous pile of paranoid bullshit.

Lorenzo ha ricondiviso questo.


-Pentagon has +70K cyber staff
-Hackers steal SonicWall firewall configs
-DeepSeek returns flawed code on purpose for minorities
-UK arrests two Scattered Spider members
-Hackers steal SonicWall firewall configs
-Leak at DHS I&A
-Hackers extort med-evac service
-Tails 7 is out
-Firefox 143 is out
-Brazil passes age verification law
-Moldova establishes disinfo agency
-ICE signs new phone-hacking contract

Podcast: risky.biz/RBNEWS480/
Newsletter: news.risky.biz/risky-bulletin-…

in reply to Catalin Cimpanu

-Congress to hold hearing on online radicalization /s
-Suspect charged in UK political honeytrap scandal
-GOLD SALEM and ShinyHunters profiles
-Shai-Hulud worm reaches 500 packages
-New CoinbaseCartel extortion group
-SystemBC botnet returns
-CopyCop info-ops infrastructure expands
-TA415 abuses VSCode tunnels
-Pixie Dust is still exploitable
-Chrome zero-day
-Companies pull out of ATT&CK evaluations
-Netskope increases IPO
-Case Theme User exploitation
-ShadowLeak ChatGPT zero-click attack

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


Ransomware stats for summer 2025

emsisoft.com/en/blog/46903/sum…

reshared this


Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

Security firm UpGuard has also identified at least 17 major companies impacted the the token thefts

upguard.com/breaches/identifyi…


That Shai-Hulud npm worm has now reached 500 packages: socket.dev/blog/ongoing-supply…

Also, doesn't seem to run on Windows (via Step Security)


Questa voce è stata modificata (6 giorni fa)

reshared this


Lorenzo ha ricondiviso questo.


Bcrypt cracking table, updated by SpecOps for modern GPU gear

specopssoft.com/blog/bcrypt-is…

reshared this

in reply to Catalin Cimpanu

Public comms are hard.

Every time SpecOps comes out with one of these tables, we (the password hasing community) try to get them to include a disclaimer in the next one: that these statistics only apply to randomly generated passwords. And every year, we get ignored.

"P@ssw0rd!" isn't going to take 230,000 years to crack! But how many people are going to walk away from this table believing that?

It is a bad sign that the word "random" doesn't even appear in the article.

Questa voce è stata modificata (6 giorni fa)