Salta al contenuto principale

Lorenzo ha ricondiviso questo.


The Tor Browser will remove all of the Firefox AI features that Mozilla has been recently adding

blog.torproject.org/new-alpha-…

in reply to Catalin Cimpanu

this is such a sad situation

Firefox adding crap only for everyone else to remove it.

it increases workload for no good reason

and increases the risk of error

again, for no good reason

in reply to Catalin Cimpanu

Good, but will they also start building official ARM-compatible binaries so that Raspberry Pi-type users can start having low-cost privacy features as well?

Lorenzo ha ricondiviso questo.


Microsoft revokes 200 certs that were being used to sign malware used in attacks with the Ryhisida ransomware

This is another way to disrupt ransomware operations without going through the courts... cheaper too

bsky.app/profile/threatintel.m…

reshared this

in reply to Catalin Cimpanu

Revoking certs is a good way to disrupt *anybody* the central authority doesn't like.

Nobody seems concerned about this.


Lorenzo ha ricondiviso questo.


I would have expected EtherHiding to be more popular, but two years later, it's just ClearFake, a botnet I haven't heard anything about in ages, and now some North Korean hackers

cloud.google.com/blog/topics/t…

reshared this


Lorenzo ha ricondiviso questo.


I thought I was having a light day at work... but I just forgot to open my email client 😑

reshared this


Lorenzo ha ricondiviso questo.


CPU side-channel research is so off into the distance that I only understand 30% of the words now

New Training Solo attack here:

vusec.net/projects/training-so…

Questa voce è stata modificata (6 ore fa)

reshared this


Lorenzo ha ricondiviso questo.


Russian bulletproof hosting provider BearHost, aka Voodoo Servers, has exit-scammed and cited "political reasons"

resecurity.com/es/blog/article…

reshared this


Lorenzo ha ricondiviso questo.


According to CISA, this Adobe Experience Manager bug detailed here is now under active exploitation: slcyber.io/assetnote-security-…

reshared this


Lorenzo ha ricondiviso questo.


MEP targeted by spyware files complaint against Hungary’s Viktor Orbán

“There are indications that the Hungarian secret service is behind the attack,” German MEP Daniel Freund said.

politico.eu/article/spyware-ta…

reshared this


Lorenzo ha ricondiviso questo.


Do you remember where you were during the Great YouTube Outage of 2025?

reshared this


Lorenzo ha ricondiviso questo.


It's Cisco disco time!

trendmicro.com/en_us/research/…

reshared this


Lorenzo ha ricondiviso questo.


I'm generally surprised that the North Korean regime hasn't set up cyber scam compounds with its own citizens after seeing the success across Cambodia and Myanmar

reshared this

in reply to Catalin Cimpanu

Too many workers outside the hermit kingdom to manage.
Questa voce è stata modificata (19 ore fa)

Lorenzo ha ricondiviso questo.


One poor crypto-bro lost $21 million last week after they leaked their private key

Talk about oopsies

cointelegraph.com/news/hyperli…

reshared this


Lorenzo ha ricondiviso questo.


Talks from the REcon 2025 security conference, which took place in June, are available on YouTube

youtube.com/@reconmtl/videos

reshared this


Lorenzo ha ricondiviso questo.


Google does something really clever and now lets users recover their accounts through a family member or friends' account

blog.google/technology/safety-…

reshared this

in reply to Catalin Cimpanu

🤦
dangerous, it gives G**gle even more data for profiling, drawing connections of trust.

Lorenzo ha ricondiviso questo.


F5 says a state-sponsored hacking group stole BIG-IP source code and vulnerability reports

sec.gov/Archives/edgar/data/10…

reshared this


Lorenzo ha ricondiviso questo.


-Windows 10 reaches End-of-Life
-CISA layoffs didn't touch cyber personnel
-US seizes $15 billion from cyber scam compound operator
-Secure Boot bypass impacts 200k Framework systems
-German police take down 1,400 scam sites
-South Korea to investigate KT for obstruction over a breach
-Ansell, Harvard breached
-5CA denies role in Discord hack
-Unity shop got skimmed
-4chan fined in the UK
-Calls to investigate TikTok in the UK

Podcast: risky.biz/RBNEWS491/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-Firmware update bricks Jeeps
-Firefox 144 changes login storage encryption
-Also get a VPN
-California regulates AI
-UK Crypt-Key goes live
-Taiwan warns of "abnormal" social media accounts
-China offers reward for Taiwan's psychological warfare unit
-Australia, UK publish annual cyber threat reports
-SonicWall SSLVPN mass-compromise
-Another surveillance provider exposed (Cyber WAP)
-TA585 profile
-Analysis of Oct 7 DDoS attacks
-Venezuela ran info-ops in Ecuador
in reply to Catalin Cimpanu

-New UAC-0239 and UNC-RUS-ZIC APTs
-Patch Tuesday is out
-3 Microsoft zero-days
-RMPocalypse attack
-Pixnapping attack
-LatentBreak attack
-Half of satellite traffic is unencrypted
-LevelBlue acquires Cybereason
in reply to Catalin Cimpanu

I read the article about UNC-RUS-ZIC when it came out. It seems highly suspect to me. The attribution is vague at best, the other "details" are merely four-line paragraphs _devoid of details_. What made you chose this article for the newsletter?
in reply to Catalin Cimpanu

Wow. Framework is not having a good few weeks 😯🤦‍♂️

Lorenzo ha ricondiviso questo.


Another major surveillance provider exposed: First Wap

Its product was used to track some very high-profile figures

lighthousereports.com/investig…


Lorenzo ha ricondiviso questo.


The US seized today $15b from a mega cyber scam operator: justice.gov/usao-edny/pr/chair…

Elliptic says it tracked these funds to the the hack of Chinese mining pool LuBian in December 2020: elliptic.co/blog/15-billion-us…

Things... are getting weird

reshared this


Lorenzo ha ricondiviso questo.


Synacktiv looks at LinkPro, a new Linux eBPF-based rootkit it found deployed on a customer's hacked AWS infrastructure

synacktiv.com/en/publications/…

reshared this

in reply to Catalin Cimpanu

nice technical overview at a level I rarely see for Linux rootkits. Thanks for sharing!

Lorenzo ha ricondiviso questo.


Chinese authorities have issued bounties for 18 Taiwanese military members.

Police in China's Fujian province claim the 18 are part of Taiwan's "psychological warfare unit" that spread disinformation and propaganda on Taiwan's independence

reshared this


Lorenzo ha ricondiviso questo.


German and Bulgarian authorities have seized more than 1,400 websites that were used for financial crypto scams.

Officials recorded more than 866,000 attempts to access the sites over the ten days after they were seized, which highlighted the attackers' success

bafin.de/SharedDocs/Veroeffent…

reshared this

in reply to Catalin Cimpanu

Strange, I saw no mention of this in the Bulgarian news outlets I'm following...

BTW, 86k-per-day requests to a web site (most of them automated) is nothing special. Literally *anything* running on *any* port (not just 80 or 443) will get HTTP GET requests quite often.


Lorenzo ha ricondiviso questo.


Microsoft Oct 2025 Patch Tuesday is out with fixes for 3 actively exploited zero-days

rawcdn.githack.com/campuscodi/…

-CVE-2025-24990 — Windows Agere Modem Driver Elevation of Privilege Vulnerability
-CVE-2025-59230 — Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
-CVE-2025-47827 — Secure Boot bypass in IGEL OS before 11

reshared this


Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

I just realized this might screw up a lot of infostealers in the coming weeks. Chrome also does this regularly. Let's see how quick they adapt this time.

reshared this


Lorenzo ha ricondiviso questo.


RE: infosec.exchange/@agreenberg/1…

Research home page, if you wanna read the paper: satcom.sysnet.ucsd.edu/


Researchers pointed a satellite dish at the sky for 3 years and monitored what unencrypted data it picked up. The results were shocking: They obtained thousands of T-Mobile users' phone calls and texts, military and law enforcement secrets, much more: 🧵👇wired.com/story/satellites-are…

reshared this


in reply to Catalin Cimpanu

I just don't understand why anyone, even Firefox would want to store passwords in the browser?
in reply to Catalin Cimpanu

I'd still rather use a third-party password manager like Bitwarden.

Lorenzo ha ricondiviso questo.


Infosec drama, part 283,293: FuzzingLabs accuses Gecko Security of stealing two CVEs and backdating blogs

x.com/FuzzingLabs/status/19777…

reshared this


Lorenzo ha ricondiviso questo.


"Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites."

Tested to steal data from Gmail, Google Accounts, Signal, Google Authenticator, Venmo, and Google Maps

pixnapping.com/

reshared this

in reply to Catalin Cimpanu

“Pixnapping forces sensitive pixels into the rendering pipeline and overlays semi-transparent activities on top of those pixels via Android intents. To induce graphical operations on these pixels, our instantiations use Android’s window blur API. To measure rendering time, our instantiations use VSync callbacks.”

Lorenzo ha ricondiviso questo.


Security firm DarkTower has discovered four different Telegram emoji packs that contain bank logos and are likely used in cybercrime channels as a way to order phishing pages.

getdarktower.com/telegram-emoj…

reshared this


Lorenzo ha ricondiviso questo.


Mozilla has started the development of a free VPN feature for Firefox users.

This will be a separate product from Mozilla VPN, the company's commercial OS-level VPN.

connect.mozilla.org/t5/discuss…

reshared this

in reply to Catalin Cimpanu

Is it in partnership with Mullvad again? If so then I’d be somewhat interested but maybe not if it isn’t.
in reply to Catalin Cimpanu

ah and the famous "trust me bro"

i mean mozilla is anything but "trustable" when it come to privacy or security or moral these days.


Lorenzo ha ricondiviso questo.


-Microsoft revamps Edge's "IE Mode" after zero-day attacks
-FBI seizes Salesforce extortion site
-New round of CISA layoffs
-Apple doubles bug bounty rewards
-White House rescinds NSA&CyberCom chief nomination
-FCC warns of future crackdown on Chinese gear
-Fast Track breach targeted crypto casino operators
-Another Paragon victim identified
-Chrome will revoke old site permissions
-YouTube gives 2nd chance to banned channels

Newsletter: news.risky.biz/microsoft-revam…
Podcast: risky.biz/RBNEWS490/

reshared this

in reply to Catalin Cimpanu

-Nigerian scammer arrested in Argentina
-Scam compound raided in Cambodia
-PowerSchool hacker sentencing is this week
-Spain arrests major phishing provider
-RDP attack wave targets US
-Aisuru botnet gets US-heavy
-New Brotherhood leak site
-New ChaosBot and ClayRat malware
-New APT35 leaks
-DPRK IT workers now target architects
-New Gladinet zero-day
-New Oracle EBS bug
-NSO has US owners now

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


Microsoft published last week a dedicated page for recommended Intune security configurations

learn.microsoft.com/en-us/intu…

reshared this

in reply to Catalin Cimpanu

Is 'don't use InTune because the authors have no idea what the principle of least privilege means, put a huge pile of things that handle untrusted code in high-privilege modes, and then tell you "it's a management system not a security system, don't use it for security" when you object to it being rolled out across all devices' one of them?

Lorenzo ha ricondiviso questo.


Argentina arrested its first suspect on an Interpol Red Notice

...it was a Nigerian romance scammer

x.com/interpolwanted/status/19…

reshared this

in reply to Catalin Cimpanu

non ho quella pattumiera di X

google.com/url?sa=t&source=web…


Lorenzo ha ricondiviso questo.


Clop's extortion streak:

Accellion FTA platform (2020)
SolarWinds Serv-U FTP (2021)
GoAnywhere MFT platform (2023)
MOVEit Transfer (2023)
Cleo file transfer (2024)
E-Business Suite (2025)

via: orangecyberdefense.com/global/…

reshared this


Lorenzo ha ricondiviso questo.


Trend Micro's ZDI has reported 13 vulnerabilities in the Ivanti Endpoint Manager that are still unpatched after the vendor requested an extension until March next year

zerodayinitiative.com/advisori…

reshared this


Lorenzo ha ricondiviso questo.


Spain has arrested the person behind the GXC phishing service.

Per authorities, the guy was living in Spain under a digital nomad visa and was constantly moving between different homes across the country

web.guardiacivil.es/es/destaca…

reshared this


Lorenzo ha ricondiviso questo.


Telegram founder and general a-hole Pavel Durov, whose IM network hosts hundreds of groups where info-ops coordinate their activity and pay for content, is annoyed that democracies are fighting back against the damage he, personally, has helped usher in in many autocratic regimes
Questa voce è stata modificata (4 giorni fa)

reshared this

in reply to Catalin Cimpanu

I haven't seen any evidence that Pavel Durov is an arsehole.

If you're going to post takes like this, please elaborate on whether you would want the same measures Durov describes being enacted against Mastodon.

The line of reasoning that goes 'this encrypted app hosts <bad content>' is exactly the line authoritarians of all stripes use to shut down any form of free internet.

Also he's using mildly right-coded speech, but so what, he's correct.


Lorenzo ha ricondiviso questo.


This is a neat question from a recent Sophos survey on ransomware attacks on healthcare orgs

news.sophos.com/en-us/2025/10/…

Questa voce è stata modificata (4 giorni fa)

reshared this

in reply to Catalin Cimpanu

What repercussions has the ransomware attack had on the people in your IT/cybersecurity team, if any?


...I can't imagine a ransomware attack not resulting in just a tiny bit of "increased pressure" from senior leaders.

"Oh, we're under a ransomware attack? Not to worry, all in good time, folks. No need to work overtime, we'll get around to fixing things eventually."

I'm not sure I'd be able to respond to the question without clarification. Are they talking about increased pressure during the attack, or increased pressure after the next quarterly financial report? Constant pressure or only while stuff is on fire?


Lorenzo ha ricondiviso questo.


Second zero-day in Gladinet file-sharing servers this year

huntress.com/blog/gladinet-cen…

reshared this


Lorenzo ha ricondiviso questo.


Talks from the Balkan Computer Congress 2025 security conference, which took place last September, are available on YouTube

youtube.com/playlist?list=PLyH…

reshared this


Lorenzo ha ricondiviso questo.


-EU scraps Chat Control vote
-Ukraine establishes a Cyber Force
-CISA workers reassigned to immigration enforcement
-Teenagers arrested for Kido hack
-Salesforce will not pay the ransom
-US Court halts FCC data breach rules
-California enacts tracking opt-out law
-China cleanses its internet of bad feelings
-All MySonicWall customers impacted by recent breach
-Discord breach impacted only 70k
-Kasatkin case starts in France

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS489/

reshared this

in reply to Catalin Cimpanu

-Telenor sued for passing data to Myanmar junta
-Apple removes ICE activity archiving app
-Another Paragon victim identified in Italy
-TwoNet targets OT/ICS networks
-Crimson Collective goes after AWS environments
-Velociraptor now abused in attacks
-Storm-2657 profile
-New CipherWolf RaaS
-New Kryptos ransomware
-RondoDox botnet grows massive
-CamoLeak vuln
-ASCII attack on LLMs
-Framelink Figma RCE
-China's vulnerability research ecosystem
-New UTA0388 APT
-C2A buys VigilantOps

Catalin Cimpanu reshared this.