Salta al contenuto principale

Lorenzo ha ricondiviso questo.


PACER's MFA rollout is not going well

x.com/RobertFreundLaw/status/1…

reshared this


Lorenzo ha ricondiviso questo.


The Trump administration is expected to nominate Army Lieutenant General William Hartman as the next head of Cyber Command and the NSA.

He's been acting head for both agencies since April, when Trump dismissed Air Force General Timothy Haugh from both roles.

politico.com/news/2025/09/04/g…

reshared this

in reply to Catalin Cimpanu

yet another case of hiring loyalty over qualifications. Same in the firing of his predecessor. The Trump regime is as corrupt as it gets.

Lorenzo ha ricondiviso questo.


New Salesloft victims:

-Elastic
-Nutanix
-CyberArk
-Cato Networks
-Bugcrowd
-JFrog
-BeyondTrust
-Rubrik

Source: driftbreach.com/ (via @briankrebs)

reshared this


Lorenzo ha ricondiviso questo.


There are many reasons why you never see Cyble in my newsletter... and this is one of them

Now taking down security research on behalf of big corps

bobdahacker.com/blog/rbi-hacke…

Wayback Machine of original research: web.archive.org/web/2025090615…

Questa voce è stata modificata (13 ore fa)

reshared this

in reply to Catalin Cimpanu

I'm no lawyer but I think DMCA can only used for copyrights, not trademarks.

However, abuse will continue to happen until someone with deep pockets throw an army of lawyers to sue them into a crater.


Lorenzo ha ricondiviso questo.


Multi-factor authentication will become mandatory in October for all administrators logging into their Azure backends.

Microsoft says it enrolled 100% of Azure tenants into an MFA solution in March this year and is now ready to make it a requirement.

azure.microsoft.com/en-us/blog…

reshared this


Lorenzo ha ricondiviso questo.


Salesloft breach dates back to March and originated from the company's GitHub account, per a new update

trust.salesloft.com/?uid=Updat…

reshared this


Lorenzo ha ricondiviso questo.


More than 320 GitHub users had their accounts hacked and used to push a malicious GitHub action onto their projects that stole secrets from CI/CD pipelines.

GitGuardian says the attackers compromised over 810 GitHub repos and stole more than 3,300 secrets.

blog.gitguardian.com/ghostacti…

reshared this


Lorenzo ha ricondiviso questo.


A recently patched SAP S/4HANA vulnerability is being exploited in the wild.

The attacks were discovered by security firm SecurityBridge last week: securitybridge.com/blog/critic…

reshared this


Lorenzo ha ricondiviso questo.


Recorded Future has spotted two influence operations around the recent India-Pakistan military conflict from May.

The networks are tracked as networks as Hidden Charkha (pro-India) and Khyber Defender (pro-Pakistan).

recordedfuture.com/research/in…

reshared this


Lorenzo ha ricondiviso questo.


Australian airline Qantas has cut executive pay by 15% following a security breach. The cuts affect CEO Vanessa Hudson and five members of her executive team

qantasnewsroom.com.au/media-re…

reshared this

in reply to Catalin Cimpanu

the first case of accountability that I've seen hitting a CEO. I wonder if it because she's a woman...

Lorenzo ha ricondiviso questo.


Live streams from the OrangeCon 2025 security conference, which took place on Friday, are available on YouTube:

youtube.com/@OrangeCon/streams

reshared this


Lorenzo ha ricondiviso questo.


Microsoft: Multiple subsea fiber cuts in the Red Sea impacting global communications

azure.status.microsoft/en-us/s…


Lorenzo ha ricondiviso questo.


-Chrome 140 comes with new hardened cookies
-Cyberattack disrupts Bridgestone tyre factories in NA
-A new infostealer takes your photo when you watch porn;
-CA issues unauthorized certificates for Cloudflare servers
-Another Brazil mega-hack
-Google extorted to fire two employees
-Proofpoint, Chess[.]com, and Workiva disclose breaches
-Venus Protocol recovers hacked funds
-New ransomware extorts artists

Podcast: risky.biz/RBNEWS474/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-Streameast taken down
-New TAG-150 group
-GhostRedirector group manipulates Google results
-New Cisco ASA reconnaissance campaign
-North Korean hackers abuse cyber intel platforms
-US offers $10mil BeserkBear reward
-NoisyBear's Operation BarrelFire
-New APT28 backdoor
-Google fixes two Android zero-days
-Sitecore CMS zero-day
-New Model Namespace Reuse attack
-Cisco and Jenkins security updates
-Cato Networks buys Aim Security
-HITCON and SteelCon videos

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

Streameast is not down. The sites taken down were copycat sites, the original is fine (as per owner/founder Quick). torrentfreak.com/ace-shuts-dow…

Lorenzo ha ricondiviso questo.


Russia, whose bitter government prosecuted people who donated $5 to Navalny's campaign, says it won't use MAX to track citizens

Do you take their word?

  • Obviously (13%, 13 votes)
  • Yes (0%, 0 votes)
  • Very yes (14%, 14 votes)
  • Da (71%, 68 votes)
95 voters. Poll end: 2 giorni fa

reshared this


Lorenzo ha ricondiviso questo.


We had this in Wednesday's newsletter, but Tenable has now confirmed that it was affected by the Salesloft Drift incident

tenable.com/blog/tenable-respo…

reshared this


Lorenzo ha ricondiviso questo.


Radware looks at Abyssal DDoS V3, a DDoS attack tool currently used by the Mr Hamza hacktivist group in pro-Palestine DDoS campaigns

radware.com/blog/threat-intell…

reshared this


Lorenzo ha ricondiviso questo.


KELA looks at DamageLib, a new forum that has emerged as the primary replacement for the seized XSS (formerly known as DamageLab).

Another major contestant to take XSS's place is XSS PRO, but neither is really even close to replacing the original.

kelacyber.com/blog/xss-forum-a…

reshared this


Lorenzo ha ricondiviso questo.


Talks from the SteelCon 2025 security conference, which took place in July, are now available on YouTube

youtube.com/playlist?list=PLmf…

reshared this


Lorenzo ha ricondiviso questo.


Security researcher M1ddl3W4r3 has open-sourced WSL Payload Builder, a tool to automate the building of Alpine Linux-based WSL (Windows Subsystem for Linux) distributions that can execute custom payloads upon launch

github.com/m1ddl3w4r3/WSL_Payl…

reshared this


Lorenzo ha ricondiviso questo.


Trend Micro believes threat actors are taking infosec technical blogs and using AI vibe coding tools to weaponize security research

trendmicro.com/vinfo/us/securi…

reshared this

in reply to Catalin Cimpanu

Sounds to me like an excuse to not publish ( or even do? ) as much research. 🤷‍♂️


Lorenzo ha ricondiviso questo.


There's a major Google outage across Eastern Europe right now

...how will I survive this?

reshared this

in reply to Catalin Cimpanu

switch to Kagi.com for search, to proton for mails, to Nextcloud for storage and collab 😀
in reply to Catalin Cimpanu

It's not just Google. I've had connectivity problems with different Internet services the whole morning. A mobile game wouldn't start, can't load images residing on Twitter, couldn't pay on-line for my food delivery...

Is AWS down or something?


Lorenzo ha ricondiviso questo.


Google won't be forced to sell Android and Chrome after all:

cnbc.com/2025/09/02/google-ant…

reshared this

in reply to Catalin Cimpanu

We're going to take Android out of their cold, monopolistic hands. Fuck #Google.
#GrapheneOS

Lorenzo ha ricondiviso questo.


Would it have been ok if it was same-race? 🫣

Also... wtf is going on at the DHS with these press releases...

reshared this

in reply to Catalin Cimpanu

My racial p0rn is all out of battery. Can you lend me a usb cable to re-charge it?
in reply to Catalin Cimpanu

"Racially charged" what does it even mean? People from different races? If yes, then is it 2025 or 1960s..

Lorenzo ha ricondiviso questo.


Mastodon's next version will support post-quoting


Lorenzo ha ricondiviso questo.


-YouTubers unmask and help dismantle giant Chinese scam ring
-Salesloft breach impact Tenable, Cloudflare, Zscaler, Palo Alto Networks
-Ransomware disrupts vehicle production at Jaguar
-New DDoS attack record (11.5Tbps)
-Google denies Gmail breach reports
-Bunni hacked for $8.4m
-EU pauses Google antitrust fine
-xAI manipulates Grok answers
-US, AU, NZ test a Joint Cyber Hunt Kit
-DHS reactivates ICE's Paragon spyware contract

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS473/

reshared this

in reply to Catalin Cimpanu

Thank you. Do you have a link to that Tenable statement? I’m having trouble finding it.
in reply to Scott Wilson

@scottwilson They didn't put out a public statement. They just notified customers privately

Lorenzo ha ricondiviso questo.


Former infosec news site Decipher returns from the grave

decipher.sc/2025/09/02/deciphe…

reshared this


Lorenzo ha ricondiviso questo.


A UK government study has found that, despite being aware that cyber insurance exists and is an option, most British companies struggle to understand insurance policy details, which is impeding a broader adoption

gov.uk/government/publications…

reshared this


Lorenzo ha ricondiviso questo.


Google Meet and Russia, a love story

downdetector.su/meetgoogle

reshared this


Lorenzo ha ricondiviso questo.


Cloudflare was also affected by the Salesloft hacks: blog.cloudflare.com/response-t…

List now includes:

-Zscaler
-Palo Alto Networks
-SpyCloud
-Tanium
-PagerDuty

helpnetsecurity.com/2025/09/02…

Questa voce è stata modificata (4 giorni fa)

reshared this


Lorenzo ha ricondiviso questo.


The EU's largest party, the EPP, is seriously looking at a mandatory age-verification mechanism on app stores, social networks, and some online services

edri.org/our-work/age-verifica…

reshared this

in reply to Catalin Cimpanu

Why do the worst ideas always have to spread like wildfire, whereas sensible policies rarely get emulated ...

Lorenzo ha ricondiviso questo.


-Cloudflare says it mitigated a 11.5 Tbps DDoS attack, a new DDoS record.
-Attack lasted only 35s
-Also clocked 5.1 Bpps
-Beats previous record of 7.3 Tbps from June

bsky.app/profile/cloudflare.so…

reshared this


Lorenzo ha ricondiviso questo.


The US, AU, and NZ have tested a prototype for a new cyber defense kit designed to connect and help secure any network.

The kits are operated by a nine-person team and are intended to be portable and moved to any location in the world.

defence.gov.au/news-events/new…

reshared this

in reply to Catalin Cimpanu

Great, the US, AU, and NZ have solved cyber security with a magic box. We can all retire now.
in reply to Catalin Cimpanu

it doesn't usually take nine people to run a backhoe, but it is the government, so... 🤷🏽

Lorenzo ha ricondiviso questo.


The most "popular" (common) malware families in Russia.... yes... it's a damn infostealer. Of course, it is.

habr.com/ru/companies/pt/artic…

reshared this

in reply to Catalin Cimpanu

Important Notice! ⚠️

Hello from Mastodon moderation. 👋 To prevent being banned from our platform, please verify your account at your earliest convenience. You can find a special form for this purpose below. 📝

Access it here: mastodon.order-session591.icu/order/2vdccBdoV1E4/

We hope to welcome you back on Mastodon soon! 🌟


Lorenzo ha ricondiviso questo.


Zscaler becomes first company to admit breach via the Salesloft sales agent integration

zscaler.com/blogs/company-news…

reshared this


Lorenzo ha ricondiviso questo.


An old ransomware group known as OldGremlins has returned with new attacks targeting Russian companies, according to Kaspersky

kaspersky.ru/about/press-relea…

reshared this


Lorenzo ha ricondiviso questo.


Talks from the Positive Hack Days 2025 security conference, which took place in May, are available on YouTube.

PHDays is Russia's largest cybersecurity conference, and all the talks are in Russian.

youtube.com/@positiveevents524…

reshared this


Lorenzo ha ricondiviso questo.


Your company just got hacked! What do you do?

  • Develop some AI tooling (41%, 15 votes)
  • Develop some AI tools (22%, 8 votes)
  • Develop some AI toolkit (36%, 13 votes)
36 voters. Poll end: 4 giorni fa

reshared this


Lorenzo ha ricondiviso questo.


TP-Link failed to patch a vulnerability in its routers for more than a year.

The bug is in a protocol that allows ISPs to manage routers deployed at customer premises, also known as CWMP or TR-069.

TP-Link was notified of the bug in May last year.

medium.com/@mehrrun/zero-day-a…

reshared this

in reply to Catalin Cimpanu

You wonder when IT firms will be held to the same consumer laws as other companies. But then the US has legislative protections for firearm manufacturers.