Lorenzo ha ricondiviso questo.

Filings: Waymo pulls its ~4K robotaxis from highways after finding 13+ instances of the cars driving into highway sections under construction (Sean O'Kane/TechCrunch)

techcrunch.com/2026/06/18/waym…
techmeme.com/260618/p31#a26061…

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Canada’s spy agency allowed to remove a botnet from Canadian devices
-A bunch of Fortinet creds leak online
-Supply chain attack hits Mastra AI framework
-Europol disrupts SocGolish
-Popa botnet linked to Israeli firm
-Aztec Connect hacked twice in a week
-Kodak hit by ShinyHunters
-South Korean startup data leaked online
-Texas Parks and Wildlife has a breach
-Apple sabotages its own Hide My Email feature

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS579/

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Mastodon admins can now force 2FA
-reCAPTCHA adds hand gesture verification
-AMD disables TSME for consumer CPUs
-Canada launches bug bounty program
-Bulgaria approved surveillance tech to oppressive regimes
-Second wave of GlobalSign revocations in Russia
-Another WordPress plugin supply chain attack
-TeamPCP traced to South Africa
-New GitBait group
-Most cyber activity coming out of Asia is scams
-Telegram's cybercrime crackdown barely makes a dent

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-More AI tools in the cyber underground as crimz worry for their own jobs
-BreachForums evolution
-New AryStinger botnet
-USB worm+clipper combo spotted in the wild
-New GentleKiller EDR killer
-New OXLOADERGentleKiller
-New Prinz Eugen ransomware
-Joomla plugin zero-day
-Splunk bug exploited in the wild
-F5 releases out-of-band NGINX security updates
-RoguePlanet gets a CVE, but no patch
-Firefox AI abused to steal emails
-Accenture buys Dragos, runZero, NetRise
Lorenzo ha ricondiviso questo.

Google has tracked TeamPCP to one individual in South Africa

PAN believes the main TeamPCP hacker uses the name ResoluteXBF in some underground communities

cyberscoop.com/teampcp-breaks-…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

New, from me: 'Popa' Botnet Linked to Publicly Traded Israeli Firm

"For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]."

krebsonsecurity.com/2026/06/po…

There is an incredible amount of interesting data and findings in the reports on Popa released this week. For example, the proxy detection service Spur told me they recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

#proxy #popa #botnet #lg #samsung

Questa voce è stata modificata (3 giorni fa)
in reply to BrianKrebs

Many readers have been asking if this or that app for their TV is bundled with residential proxy software. Many of the apps in question -- as well as publisher/component names to look for -- are detailed in links throughout the story. But for the sake of simplicity, here they are:

Qurium's report: qurium.org/forensics/finding-p…

Synthient: synthient.com/blog/popa-from-s…

Spur: spur.us/blog/how-proxy-provide…

Nokia Deepfield: github.com/deepfield/public-re…

Include Security: blog.includesecurity.com/2026/…

Infoblox: infoblox.com/blog/threat-intel…

Firefox guarda al futuro con Nova, HDR e VPN mobile (mentre la quota di mercato continua a scendere)

@GNU/Linux Italia

linuxeasy.org/firefox-futuro-n…

Mozilla svela la roadmap di Firefox con Nova, HDR su Linux e Windows, VPN mobile e nuove funzioni AI controllabili dagli utenti.
L'articolo Firefox guarda al futuro con Nova, HDR e VPN mobile (mentre la quota di mercato continua

Lorenzo ha ricondiviso questo.

Dutch police take down 15k SocGolish sites

politie.nl/en/news/2026/juni/1…

reshared this

Lorenzo ha ricondiviso questo.

"Accenture, a global leader in OT cybersecurity services and delivery focused on OT for a decade, is acquiring a majority stake in Dragos at a $3.2B valuation, and all of runZero and NetRise, bringing the combined business value to $4.125B."

dragos.com/blog/dragos-joins-f…

reshared this

Lorenzo ha ricondiviso questo.

Canada has launched a vulnerability disclosure program for the government's IT networks

The program launched in March on the HackerOne program and has already received 160 reports

cyberincontext.ca/p/canadian-g…

reshared this

Lorenzo ha ricondiviso questo.

AMD has disabled a security feature that encrypts a CPU's memory for consumer chipsets

The Transparent Secure Memory Encryption (TSME) feature will only be available for the Pro versions of AMD CPUs going forward

The feature was designed to protect a CPU's memory in the case of cold boot attacks

arstechnica.com/security/2026/…

reshared this

in reply to Catalin Cimpanu

A reference in the linked #WP article: "Bonshor, Gavin. "AMD openSIL Planned to Replace AGESA Firmware in Client and Server in 2026". www.anandtech.com. Archived from the original on 2023-05-20. Retrieved 2023-05-20." - web.archive.org/web/2023052014…
#wp
Lorenzo ha ricondiviso questo.

"New Outlook takes 10 seconds to go from notification to the respective mail"

windowslatest.com/2026/06/15/m…

reshared this

in reply to Catalin Cimpanu

"But it's only 10 seconds, are you in this much hurry?!"

That was a reply from a fan boy when I pointed out a previous thing that now needed too many steps to do what previous version did with trivial interaction.

Imagine having used light switches all your life. But then LightSwitch365 comes and you have to keep it pressed 10 seconds to turn on the lights.

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Microsoft has discovered a cryptocurrency clipper that is being spread via an USB worm and has a Tor-based C2

This is either an overengineered tool or North Korea

microsoft.com/en-us/security/b…

Lorenzo ha ricondiviso questo.

#ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices.
welivesecurity.com/en/eset-res…
Gentlemen was one of the most active RaaS gangs in Q1 2026. Unlike the majority of top-tier gangs, which target the US [🇺🇸], Gentlemen goes after victims across Southeast Asia, South America, and Western Europe.
Gentlemen operators develop and maintain a suite of EDR killers, combining an in-house tool, GentleKiller, with externally sourced tooling (HexKiller, ThrottleBlood, and HavocKiller). The gang applies a standardized set of defense evasion techniques across its portfolio.
GentleKiller is Gentlemen’s most prevalent EDR killer. We found eight distinct variants of the tool, each impersonating a different legitimate product. Across all builds, GentleKiller targets more than 400 processes, which we mapped with the help of AI to 48 products.
We hypothesized that GentleKiller was an internal tool in February 2026, and the recent leak of Gentlemen data confirmed our suspicions. The leaked data also allowed us to link one of Gentlemen’s affiliates to a credential stealer we named OxideHarvest.
IoCs available in our GitHub repo: github.com/eset/malware-ioc/tr…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Almost 40% of the detected cybercrime activity coming out of Asia is online scam-related

interpol.int/en/News-and-Event…

reshared this

Prock un completo Process Explorer per Linux

@GNU/Linux Italia

linuxeasy.org/prock-process-ex…

Prock porta su Linux un process explorer moderno con alberi di processi, grafici, segnali, porte e preferenze avanzate.
L'articolo Prock un completo Process Explorer per Linux proviene da Linux Easy.
E' vietato riprodurre questo articolo senza autorizzazione.
Questo feed RSS è destinato ai

FreeBSD 15.1 Rilasciato: cosa cambia nella nuova versione

@GNU/Linux Italia

linuxeasy.org/freebsd-15-1-ril…

FreeBSD 15.1 migliora sicurezza, storage, rete, virtualizzazione e strumenti di sistema con molte novità pratiche.
L'articolo FreeBSD 15.1 Rilasciato: cosa cambia nella nuova versione proviene da Linux Easy.
E' vietato riprodurre questo articolo senza

Lorenzo ha ricondiviso questo.

Another supply chain attack in the WordPress ecosystem, this one at ShapedPlugin

An attacker compromised its build pipeline to add a backdoor to its commercial plugins.

The free versions distributed through WordPress[.]org were not affected.

wordfence.com/blog/2026/06/psa…

reshared this

Lorenzo ha ricondiviso questo.

Mastodon 4.6 released today. It lets me force 2FA on accounts.

Also, heads up, I am going to force 2FA on accounts.

Note: this is only applicable to: infosec.exchange
infosec.space
ioc.exchange
convo.casa

Questa voce è stata modificata (4 giorni fa)
Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

If you've lost track of all the BreachForums clones... KELA has you covered

kelacyber.com/blog/breachforum…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Telegram's cybercrime moderation is working, but the criminal groups are very very persistent and annoying, so it barely made a dent in two years

blog.openmeasures.io/p/telegra…

reshared this

Lorenzo ha ricondiviso questo.

Zero-day in JCE, one of Joomla's most popular WYSIWYG editors

joomlacontenteditor.net/news/j…

This has been abused to drop web shells since the start of the month

mysites.guru/jce-hack/

reshared this

Lorenzo ha ricondiviso questo.

CSAM generation is now openly "critical for national security." So yeah, America is going about as expected.


The US government has intervened in a lawsuit on the side of X, saying Grok is "critical for national security" wired.com/story/doj-lawyers-ar…

reshared this

Lorenzo ha ricondiviso questo.

A threat actor has hijacked the npm account of the Mastra TypeScript framework and inserted malware in all its 116 libraries

TanStack repeat underway

endorlabs.com/learn/mastra-npm…

reshared this