Lorenzo ha ricondiviso questo.

Firefox users... you dirty little privileged c***s!

You're living in the tech bro future utopia!


Mozilla says its Firefox 150 release includes fixes for 271 vulnerabilities identified using early access to Anthropic's Mythos Preview (Lily Hay Newman/Wired)

wired.com/story/mozilla-used-a…
techmeme.com/260421/p37#a26042…


reshared this

Lorenzo ha ricondiviso questo.

Kaspersky has a report out on Lotus Wiper, which it believes was the malware behind the Petroleos de Venezuela "ransomware" attack in December of last year

They don't specifically say it, but they imply it very obviously. They also don't mention the US once.

The timeline they provide also seems to hint this might have been used against the energy and utilities sector in Venezuela, which might have led to those blackouts? Maybe?

securelist.com/tr/lotus-wiper/…

Questa voce è stata modificata (13 ore fa)

reshared this

It's not just Anthropic using this dark pattern. I checked my Mac and found #1Password installing similar extension bridges to browsers I've never installed. They should notify users of these changes during installation and never install for software that is not present.

$ cd ~/Library/Application\ Support
$ find . -name "com.1password.1password.json" | egrep "Arc|Microsoft"
./Microsoft Edge Beta/NativeMessagingHosts/com.1password.1password.json
./Microsoft Edge Dev/NativeMessagingHosts/com.1password.1password.json
./Microsoft Edge Canary/NativeMessagingHosts/com.1password.1password.json
./Microsoft Edge/NativeMessagingHosts/com.1password.1password.json
./Arc/User Data/NativeMessagingHosts/com.1password.1password.json

EDIT - updated find results to reflect 1Password-installed manifests


Can confirm this for Arc, Brave, Edge, Chromium, and Vivaldi on my machine:

#Anthropic secretly installs spyware when you install Claude Desktop
thatprivacyguy.com/blog/anthro…


Questa voce è stata modificata (13 ore fa)
Lorenzo ha ricondiviso questo.

Interesting story of an Irish company falling victim to BEC fraud. Criminals hijacked an employee’s email account in the victim company. They then used that account to send payment instructions to the company’s outsourced financial admin company. The victim company lost €2 million.

The victim company is now suing the payments company on the basis that the payment company should have spotted that the emails were fraudulent

m.independent.ie/irish-news/co…

Questa voce è stata modificata (1 giorno fa)

reshared this

Lorenzo ha ricondiviso questo.

Can confirm this for Arc, Brave, Edge, Chromium, and Vivaldi on my machine:

#Anthropic secretly installs spyware when you install Claude Desktop
thatprivacyguy.com/blog/anthro…

Lorenzo ha ricondiviso questo.

Cynthia Kaiser, senior vice president of Halcyon’s ransomware research center and former FBI Cyber Deputy Director, calls on Congress to designate ransomware groups who attack hospitals and critical infrastructure as terrorist organizations

youtube.com/live/58UVfeHWMzc

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A CEPS study that looked at anti-piracy blocking across the EU indirectly blamed the second rise of pirated content we're seeing these days to rightsholders splitting their content across a bazillion platforms

ceps.eu/ceps-publications/the-…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A hacker is selling data from France's ANTS, the agency that deals with vehicle registration, driving licence, and identity documents

clubic.com/actualite-580066-le…

Confirmed by authorities yesterday: interieur.gouv.fr/actualites/c…

reshared this

Lorenzo ha ricondiviso questo.

A cluster of 26 malicious iOS apps have been uploaded on the Chinese version of the Apple App Store

The apps redirected users to phishing pages posing as legitimate cryptocurrency services

securelist.com/fakewallet-cryp…

reshared this

Lorenzo ha ricondiviso questo.

The third security firm employee who worked with the BlackCat ransomware has also pleaded guilty now

justice.gov/opa/pr/florida-man…

reshared this

Lorenzo ha ricondiviso questo.

The Onion have finally completed their takeover of InfoWars, and it's everything I wanted and more.

theonion.info/

Lorenzo ha ricondiviso questo.

Vercel says its recent breach originated at Context[.]ai, a third-party AI tool used by a Vercel employee.

Attackers used the compromised Context[.]ai account to pivot to the employees Google Workspace account, then to some work systems from where they stole env files

vercel.com/kb/bulletin/vercel-…

reshared this

Lorenzo ha ricondiviso questo.

End of an Apple era: Tim Cook to step back, John Ternus named CEO
https://mashable.com/article/apple-tim-cook-john-ternus-ceo?utm_source=flipboard&utm_medium=activitypub

Posted into All the Biggest Apple News in One Place @all-the-biggest-apple-news-in-one-place-Mashable

reshared this

Lorenzo ha ricondiviso questo.

AI token subsidies seem to be ending across the industry.

GitHub Copilot has paused new signups on a number of plans, removed Opus from $10-a-month subscriptions, and plans to move users to token/API-based billing later this year.

Usage quotas are also being reduced and users will hit limits sooner.

github.blog/changelog/2026-04-…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Russia's Defense Ministry posted a list of companies across Europe that are reportedly linked to the production of the drones Ukraine fires at Russia. According to Russian Security Council Deputy Chairman Medvedev, these sites are "potential targets." t.me/mod_russia/62686

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Data breach at Vercel
-New malware tries to sabotage Israel's water system but fails because it's buggy
-US government wants Mythos access
-Supreme Court hacker gets no prison time
-Ransomware kingpin arrested in Kazakhstan
-Kelp DAO hacked for $292m
-Rhea Finance hacked for $18.4m
-Tallahassee down after cyberattack
-BlueSky says DDoS attack caused outage
-Failed startups are selling their internal chats to AI labs

Podcast: risky.biz/RBNEWS553/
Newsletter: news.risky.biz/tries-to-sabota…

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Sandboxed GPU process coming to Firefox
-DOJ refuses to help France's probe into X and Musk
-Russia introduces mandatory border device searches
-US wants Mythos access
-US bill would require age verification at OS level
-FISA S702 gets a 10-day extension
-DraftKings hacker sentenced to prison
-Scattered Spider member pleads guilty
-South Korea warns of Midnight, Endpoint ransomware attacks
-North Korea is recruiting foreigners for its remote IT worker schemes

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Malware reports on Nexcorium IoT botnet, Black Shrantac and BravoX ransomware, BORZ C2, FaceFish rootkit, SHub Stealer
-UNC1069 goes back to spear-phishing
-TeamPCP gives stolen creds to Vect ransomware group
-Hafnium APT member to be extradited to US
-BlueHammer, RedSun enter active exploitation
-Protobuf.js RCE
-EU age verification app has vulns
-Chrome exploit leaks online
-New FP-DSS attack on AMD chips
-Meta gives Burp Suite Pro to bug bounty hunters
-New MITRE Fight Fraud Framework
Questa voce è stata modificata (1 giorno fa)
Lorenzo ha ricondiviso questo.

The TeamPCP hacking group is feeding credentials stolen in the Trivy and Checkmarx KICS supply chain attacks to the Vect ransomware group, per a new report: dataminr.com/resources/intel-b…

reshared this

Lorenzo ha ricondiviso questo.

A Iranian hacktivist group named Harakat Ashab al-Yamin al-Islamia was allegedly the one behind the cyberattack on LA Metro last month

darkowl.com/blog-content/harak…

reshared this

Lorenzo ha ricondiviso questo.

TL;DR: Use our software if you wanna turn your democracy into a dictatorship! We have a FAQ page!


Palantir posts a 22-point summary of Alex Karp's book, advocating for hard power, AI weapons and deterrence, and denouncing pluralism, and "regressive" cultures (Anthony Ha/TechCrunch)

techcrunch.com/2026/04/19/pala…
techmeme.com/260419/p11#a26041…


reshared this

Lorenzo ha ricondiviso questo.

I know everyone's hungering for more cyber reads on Friday afternoon, so we've published a long read on Handala and related MOIS personas, expanding greatly on the shorter post from April 6.

We were originally going to keep this one closely held, but the number of questions we're fielding about IR threat actors, and some trends in current whispernets, convinced us to publish it instead.

#threatintel #cybersecurity #infosec

dti.domaintools.com/research/m…

Questa voce è stata modificata (4 giorni fa)

reshared this