The Tor Browser will remove all of the Firefox AI features that Mozilla has been recently adding
blog.torproject.org/new-alpha-…
New Alpha Release: Tor Browser 15.0a4 | Tor Project
Tor Browser 15.0a4 is now available from the Tor Browser download page and also from our distribution directory.blog.torproject.org
reshared this
Microsoft revokes 200 certs that were being used to sign malware used in attacks with the Ryhisida ransomware
This is another way to disrupt ransomware operations without going through the courts... cheaper too
reshared this
Revoking certs is a good way to disrupt *anybody* the central authority doesn't like.
Nobody seems concerned about this.
I would have expected EtherHiding to be more popular, but two years later, it's just ClearFake, a botnet I haven't heard anything about in ages, and now some North Korean hackers
cloud.google.com/blog/topics/t…
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains
North Korea threat actor UNC5342 is leveraging the EtherHiding technique in espionage and financially motivated operations.Mandiant (Google Cloud)
reshared this
reshared this
CPU side-channel research is so off into the distance that I only understand 30% of the words now
New Training Solo attack here:
vusec.net/projects/training-so…
Training Solo - vusec
On the Limitations of Domain Isolation Against Spectre-v2 Attacks TL;DR We present Training Solo, the first systematic analysis of self-training Spectre-v2 attacks that break the core assumption behind domain isolation—even when implemented perfectly…VUSec Systems Security Research Group at VU University Amsterdam
reshared this
Russian bulletproof hosting provider BearHost, aka Voodoo Servers, has exit-scammed and cited "political reasons"
reshared this
Struts Devmode in 2025? Pre-Auth Bugs in AEM Forms | Searchlight
Vulnerabilities in AEM Forms The Searchlight Cyber Research Team discovered and disclosed three critical vulnerabilities in Adobe Experience Manager Forms to Adobe in late April 2025.Shubham Shah (Searchlight Cyber)
reshared this
MEP targeted by spyware files complaint against Hungary’s Viktor Orbán
“There are indications that the Hungarian secret service is behind the attack,” German MEP Daniel Freund said.
reshared this
reshared this
It's Cisco disco time!
trendmicro.com/en_us/research/…
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.Trend Micro - United States (US)
reshared this
reshared this
One poor crypto-bro lost $21 million last week after they leaked their private key
Talk about oopsies
reshared this
Talks from the REcon 2025 security conference, which took place in June, are available on YouTube
Recon Conference
REcon is a computer security conference with a focus on reverse engineering and advanced exploitation techniques. It is held annually in Montreal, Canada.YouTube
reshared this
Google does something really clever and now lets users recover their accounts through a family member or friends' account
blog.google/technology/safety-…
Recovery Contacts: Sign in with a little help from your friends and family
An overview of Recovery Contacts, so friends and family can verify your identity if you lose access to your Google account.Claire Forszt (Google)
reshared this
F5 says a state-sponsored hacking group stole BIG-IP source code and vulnerability reports
reshared this
-Windows 10 reaches End-of-Life
-CISA layoffs didn't touch cyber personnel
-US seizes $15 billion from cyber scam compound operator
-Secure Boot bypass impacts 200k Framework systems
-German police take down 1,400 scam sites
-South Korea to investigate KT for obstruction over a breach
-Ansell, Harvard breached
-5CA denies role in Discord hack
-Unity shop got skimmed
-4chan fined in the UK
-Calls to investigate TikTok in the UK
Podcast: risky.biz/RBNEWS491/
Newsletter: news.risky.biz/risky-bulletin-…
Risky Bulletin: Windows 10 reaches End-of-Life
In other news: CISA layoffs didn't touch cyber personnel; US seizes $15 billion from cyber scam compound operator; Secure Boot bypass impacts 200k Framework systems.Catalin Cimpanu (Risky.Biz)
reshared this
-Firefox 144 changes login storage encryption
-Also get a VPN
-California regulates AI
-UK Crypt-Key goes live
-Taiwan warns of "abnormal" social media accounts
-China offers reward for Taiwan's psychological warfare unit
-Australia, UK publish annual cyber threat reports
-SonicWall SSLVPN mass-compromise
-Another surveillance provider exposed (Cyber WAP)
-TA585 profile
-Analysis of Oct 7 DDoS attacks
-Venezuela ran info-ops in Ecuador
reshared this
Another major surveillance provider exposed: First Wap
Its product was used to track some very high-profile figures
lighthousereports.com/investig…
Surveillance Secrets - Lighthouse Reports
Trove of surveillance data challenges what we thought we knew about location tracking tools, who they target and how far they have spreadLighthouse Reports
reshared this
More reports on the same company:
motherjones.com/politics/2025/…
derstandard.at/story/310000029…
spiegel.de/wirtschaft/unterneh…
lemonde.fr/pixels/article/2025…
irpimedia.irpi.eu/surveillance…
First Wap, la discrète entreprise de cybersurveillance chargée de suivre à la trace journalistes, personnalités et cadres dirigeants
Peu connu du grand public, ce vétéran du secteur vend depuis plus de vingt ans une solution de géolocalisation, y compris à des régimes autoritaires.Damien Leloup (Le Monde)
The US seized today $15b from a mega cyber scam operator: justice.gov/usao-edny/pr/chair…
Elliptic says it tracked these funds to the the hack of Chinese mining pool LuBian in December 2020: elliptic.co/blog/15-billion-us…
Things... are getting weird
Chairman of Prince Group Indicted for Operating Cambodian Forced-Labor Scam Compounds Engaged in Cryptocurrency Fraud Schemes
25-cr-312_indictment.pdf BROOKLYN, NY - An indictment was unsealed today in federal court in Brooklyn charging Chen Zhi, also known as “Vincent,” the founder and chairman of Prince Holding Group (Prince Group), a multinational business conglomerate b…www.justice.gov
reshared this
Synacktiv looks at LinkPro, a new Linux eBPF-based rootkit it found deployed on a customer's hacked AWS infrastructure
reshared this
German and Bulgarian authorities have seized more than 1,400 websites that were used for financial crypto scams.
Officials recorded more than 866,000 attempts to access the sites over the ten days after they were seized, which highlighted the attackers' success
bafin.de/SharedDocs/Veroeffent…
Schlag gegen Cyberkriminelle
Die Generalstaatsanwaltschaft Karlsruhe, das Landeskriminalamt Baden-Württemberg und die Finanzaufsicht BaFin informieren über einen Schlag gegen international agierende Cyberkriminelle.BaFin
reshared this
Strange, I saw no mention of this in the Bulgarian news outlets I'm following...
BTW, 86k-per-day requests to a web site (most of them automated) is nothing special. Literally *anything* running on *any* port (not just 80 or 443) will get HTTP GET requests quite often.
Microsoft Oct 2025 Patch Tuesday is out with fixes for 3 actively exploited zero-days
rawcdn.githack.com/campuscodi/…
-CVE-2025-24990 — Windows Agere Modem Driver Elevation of Privilege Vulnerability
-CVE-2025-59230 — Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
-CVE-2025-47827 — Secure Boot bypass in IGEL OS before 11
reshared this
RE: mastodon.social/@campuscodi/11…
I just realized this might screw up a lot of infostealers in the coming weeks. Chrome also does this regularly. Let's see how quick they adapt this time.
reshared this
RE: infosec.exchange/@agreenberg/1…
Research home page, if you wanna read the paper: satcom.sysnet.ucsd.edu/
🛰️ SATCOM Security
Research project homepage for SATCOM Security: papers, source code, and recent satellite communications vulnerabilities.satcom.sysnet.ucsd.edu
reshared this
Firefox 144 is out with hardened encryption for locally stored passwords
reshared this
Infosec drama, part 283,293: FuzzingLabs accuses Gecko Security of stealing two CVEs and backdating blogs
reshared this
"Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites."
Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps
reshared this
Security firm DarkTower has discovered four different Telegram emoji packs that contain bank logos and are likely used in cybercrime channels as a way to order phishing pages.
getdarktower.com/telegram-emoj…
Telegram Emoji Packs - DarkTower
Trevor Wilson Introduction A Telegram Emoji Pack is a collection of custom static or animated images that users can add to the messenger to personalize their communication.infomedia (DarkTower)
reshared this
Mozilla has started the development of a free VPN feature for Firefox users.
This will be a separate product from Mozilla VPN, the company's commercial OS-level VPN.
connect.mozilla.org/t5/discuss…
Re: New Experiment: Firefox VPN Beta
I think about common case is that some special sites need to be open with VPN. While the other sites should be accessed as normal, without VPN.connect.mozilla.org
reshared this
ah and the famous "trust me bro"
i mean mozilla is anything but "trustable" when it come to privacy or security or moral these days.
-Microsoft revamps Edge's "IE Mode" after zero-day attacks
-FBI seizes Salesforce extortion site
-New round of CISA layoffs
-Apple doubles bug bounty rewards
-White House rescinds NSA&CyberCom chief nomination
-FCC warns of future crackdown on Chinese gear
-Fast Track breach targeted crypto casino operators
-Another Paragon victim identified
-Chrome will revoke old site permissions
-YouTube gives 2nd chance to banned channels
Newsletter: news.risky.biz/microsoft-revam…
Podcast: risky.biz/RBNEWS490/
Microsoft revamps Edge's "IE Mode" after zero-day attacks
In other news: FBI seizes Salesforce extortion site; new round of CISA layoffs; Apple doubles bug bounty rewards.Catalin Cimpanu (Risky.Biz)
reshared this
-Scam compound raided in Cambodia
-PowerSchool hacker sentencing is this week
-Spain arrests major phishing provider
-RDP attack wave targets US
-Aisuru botnet gets US-heavy
-New Brotherhood leak site
-New ChaosBot and ClayRat malware
-New APT35 leaks
-DPRK IT workers now target architects
-New Gladinet zero-day
-New Oracle EBS bug
-NSO has US owners now
Catalin Cimpanu reshared this.
Microsoft published last week a dedicated page for recommended Intune security configurations
learn.microsoft.com/en-us/intu…
Configure Microsoft Intune for increased security - Microsoft Intune
Learn how to improve your security posture with Microsoft Intune.learn.microsoft.com
reshared this
Argentina arrested its first suspect on an Interpol Red Notice
...it was a Nigerian romance scammer
reshared this
non ho quella pattumiera di X
google.com/url?sa=t&source=web…
Cayó en Ezeiza el rompecorazones nigeriano: primera captura mundial con alerta plateada de Interpol
El sospechoso está acusado de ser uno de los líderes de una organización internacional dedicada a las estafas virtuales que se hizo de un botín de US$8.000.000Gabriel Di Nicola (LA NACION)
Clop's extortion streak:
Accellion FTA platform (2020)
SolarWinds Serv-U FTP (2021)
GoAnywhere MFT platform (2023)
MOVEit Transfer (2023)
Cleo file transfer (2024)
E-Business Suite (2025)
reshared this
Trend Micro's ZDI has reported 13 vulnerabilities in the Ivanti Endpoint Manager that are still unpatched after the vendor requested an extension until March next year
reshared this
Spain has arrested the person behind the GXC phishing service.
Per authorities, the guy was living in Spain under a digital nomad visa and was constantly moving between different homes across the country
reshared this
I haven't seen any evidence that Pavel Durov is an arsehole.
If you're going to post takes like this, please elaborate on whether you would want the same measures Durov describes being enacted against Mastodon.
The line of reasoning that goes 'this encrypted app hosts <bad content>' is exactly the line authoritarians of all stripes use to shut down any form of free internet.
Also he's using mildly right-coded speech, but so what, he's correct.
This is a neat question from a recent Sophos survey on ransomware attacks on healthcare orgs
news.sophos.com/en-us/2025/10/…
The State of Ransomware in Healthcare 2025
292 IT and cybersecurity leaders reveal the ransomware realities for healthcare establishments today.Sophos News
reshared this
What repercussions has the ransomware attack had on the people in your IT/cybersecurity team, if any?
...I can't imagine a ransomware attack not resulting in just a tiny bit of "increased pressure" from senior leaders.
"Oh, we're under a ransomware attack? Not to worry, all in good time, folks. No need to work overtime, we'll get around to fixing things eventually."
I'm not sure I'd be able to respond to the question without clarification. Are they talking about increased pressure during the attack, or increased pressure after the next quarterly financial report? Constant pressure or only while stuff is on fire?
Second zero-day in Gladinet file-sharing servers this year
huntress.com/blog/gladinet-cen…
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371)
Huntress has observed in-the-wild exploitation of a Local File Inclusion vulnerability in Gladinet CentreStack and Triofox products.Bryan Masters (Huntress)
reshared this
Talks from the Balkan Computer Congress 2025 security conference, which took place last September, are available on YouTube
reshared this
-EU scraps Chat Control vote
-Ukraine establishes a Cyber Force
-CISA workers reassigned to immigration enforcement
-Teenagers arrested for Kido hack
-Salesforce will not pay the ransom
-US Court halts FCC data breach rules
-California enacts tracking opt-out law
-China cleanses its internet of bad feelings
-All MySonicWall customers impacted by recent breach
-Discord breach impacted only 70k
-Kasatkin case starts in France
Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS489/
Risky Bulletin: EU scraps Chat Control vote
In other news: Ukraine establishes a Cyber Force; CISA workers reassigned to immigration enforcement; teenagers arrested for Kido hack.Catalin Cimpanu (Risky.Biz)
reshared this
-Apple removes ICE activity archiving app
-Another Paragon victim identified in Italy
-TwoNet targets OT/ICS networks
-Crimson Collective goes after AWS environments
-Velociraptor now abused in attacks
-Storm-2657 profile
-New CipherWolf RaaS
-New Kryptos ransomware
-RondoDox botnet grows massive
-CamoLeak vuln
-ASCII attack on LLMs
-Framelink Figma RCE
-China's vulnerability research ecosystem
-New UTA0388 APT
-C2A buys VigilantOps
Catalin Cimpanu reshared this.
Em
in reply to Catalin Cimpanu • • •Tris
in reply to Em • • •Em
in reply to Tris • • •🦄 🅃🅁🄰🄽🅂🄸🄲🄾🅁🄽 🏳️⚧️
in reply to Em • • •@Em0nM4stodon @InfoSecSherpa For non-onion related browsing should you want to use extensions, #Librewolf is an option. They remove the crap Mozilla keeps putting in Firefox and it works great.
librewolf.net/
LibreWolf Browser
librewolf.netRegendans
in reply to Catalin Cimpanu • • •VessOnSecurity
in reply to Catalin Cimpanu • • •The Turtle
in reply to Catalin Cimpanu • • •Tariq
in reply to Catalin Cimpanu • • •this is such a sad situation
Firefox adding crap only for everyone else to remove it.
it increases workload for no good reason
and increases the risk of error
again, for no good reason
Sean Payne
in reply to Catalin Cimpanu • • •