Salta al contenuto principale

Lorenzo ha ricondiviso questo.


-EU has a problem attracting and retaining cyber talent
-Coupang CEO resigns following breach
-NoName057 and CARR member charged in the US
-Chrome and Gogs zero-days
-UK sanctions Chinese hacking firms
-Coupang hacker was a cyber employee
-Petco takes down leaky Vetco site
-UK fines LastPass over breach
-Ransomware at HSE Ireland, again
-Russia denies military registry hack
-New PowerShell security feature

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS507/

reshared this

in reply to Catalin Cimpanu

-Crypto-exchange pleads guilty to laundering hacked funds
-More VS Code malicious extensions
-New PeerBlight and NANOREMOTE backdoors, InboxPrime AI PhaaS, PyStoreRAT, 01flip and VolkLocker RaaS
-New DroidLock Android ransomware
-Charming Kitten payroll data leaks online
-New Russian disinfo op backs Musk's EU attacks
-Salt Typhoon operators trained with Cisco back in 2010s
-Traefik misconfiguration disables TLS verification
-SOAPwn vulnerabilities
-Notepad++ fixes update hijack flaw
in reply to Catalin Cimpanu

-New ConsentFix attack
-Microsoft bug bounty expands to.... EVERYTHING [Gary Oldman voice]
-10k Docker Hub images leak secrets
-1k MCP servers exposed online
-SPAs leak 42k secrets
-We have an OWASP Agentic Top 10
-The 2025 CWE Top 25 is out

Lorenzo ha ricondiviso questo.


MITRE has published the list of Top 25 most common software vulnerabilities of 2025, also known as the CWE Top 25

cwe.mitre.org/top25/archive/20…

reshared this

in reply to Catalin Cimpanu

I once had to wait after work to catch a programmer who was using a buffer pointer after he'd freed it. QA caught it, and thought it was my code. Nope, but I figured out whose it was.

That one has been around for a long, long time.


Lorenzo ha ricondiviso questo.


Looks like Notepad++ has fixed its update system: community.notepad-plus-plus.or…

This is after reports that users received malicious Notepad++ updates containing malware: doublepulsar.com/small-numbers…

reshared this


Lorenzo ha ricondiviso questo.


Some phishers have taken inspiration from Russian cyber-espionage group UTA0355 and are using a technique that tricks users into sharing their OAuth material in a web page (UAT0355 did it via email replies)

pushsecurity.com/blog/consentf…

reshared this


Lorenzo ha ricondiviso questo.


Google is rolling out a new feature for Android users that will let them share live video with emergency services.

The new feature is being rolled out in the US and some regions in Mexico and Germany.

It will be available for Android 8 (2017) devices or higher

blog.google/products/android/e…

reshared this


Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

More research of this type

Intruder found 43k secrets across 5 million single-page apps: businesswire.com/news/home/202…

Bitsight has found more than 1,000 MCP servers exposed on the internet with no authorization in place and exposing sensitive data: bitsight.com/blog/exposed-mcp-…


Security firm Flare has scanned the Docker Hub portal and found secrets and tokens, including for production systems, in more than 10,000 images

flare.io/learn/resources/docke…


reshared this


Lorenzo ha ricondiviso questo.


CA/B Forum to sunset 11 domain validation methods used to issue TLS certificates

security.googleblog.com/2025/1…

reshared this


Lorenzo ha ricondiviso questo.


UK ICO fines LastPass £1.2m for 2022 data breach

ico.org.uk/about-the-ico/media…

reshared this


Lorenzo ha ricondiviso questo.


Looks like Twitter finally took down the NoName057 account after yesterday's indictment

x.com/Safety/status/1998528342…

reshared this


Lorenzo ha ricondiviso questo.


SOAPwn -- new bugs that can lead to RCE in .NET apps

Vulnerable applications include the Umbraco CMS, Barracuda's Service Center, the Ivanti Endpoint Manager, and more

Microsoft did not fix them

labs.watchtowr.com/soapwn-pwni…

reshared this


Lorenzo ha ricondiviso questo.


Dutch prosecutors are seeking an eight-month prison sentence for a man who launched DDoS attacks against the country's 112 emergency line.

The suspect allegedly tried to frame some business partners for the attack

om.nl/actueel/nieuws/2025/12/1…

reshared this


Lorenzo ha ricondiviso questo.


There's this image on social media about how most of the Red Bull team that helped Verstappen win his titles are now gone... but few people posting this remember this drama started from the Verstappens.

This is the definition of shooting yourself in the nuts. You should have 0 sympathy for him

reshared this


Lorenzo ha ricondiviso questo.


The Paxful cryptocurrency exchange has pleaded guilty to laundering crypto-assets linked to scams, fraud, and extortions

Will pay a $4mil fine only

justice.gov/opa/pr/virtual-ass…

reshared this


Lorenzo ha ricondiviso questo.


This constant stream of malicious VSCode extensions won't end anytime soon....

This batch hid its payload, a Rust-based trojan, as PNG files inside the dependencies folder

reversinglabs.com/blog/malicio…

reshared this


Lorenzo ha ricondiviso questo.


A popular reverse proxy and ingress controller shipped misconfigured versions for the past five months.

The Traefik setting that enabled TLS verification was actually disabling it across the board.

aisle.com/blog/cve-2025-66491-…

reshared this


Lorenzo ha ricondiviso questo.


Pffff... the Coupang insider, who allegedly stole the company's data, was apparently a cybersecurity employee

koreajoongangdaily.joins.com/n…

reshared this

in reply to Catalin Cimpanu

The Coupang CEO also resigned following the hack and police raids: koreatimes.co.kr/business/comp…

That's the third South Korean CEO to resign after a breach after the KT and SK Telecom ones


Lorenzo ha ricondiviso questo.


Security firm Flare has scanned the Docker Hub portal and found secrets and tokens, including for production systems, in more than 10,000 images

flare.io/learn/resources/docke…

reshared this


Lorenzo ha ricondiviso questo.


The Justice Department charged a former product manager at Accenture Federal Services with falsely misleading government customers about the security posture of a cloud product offered by the company.

nextgov.com/cybersecurity/2025…

reshared this

in reply to Catalin Cimpanu

presumably they falsely claimed something or mislead customers. It would be unlikely although awesome if they were expected to mislead and did so falsely. Which would kinda make it the truth

Lorenzo ha ricondiviso questo.


RE: flipboard.com/@retrowarehouse/…

If any font needs to be banned, it should be Trebuchet MS...

Inter all the things!!!!

reshared this


Lorenzo ha ricondiviso questo.


The ENISA yearly survey is out: enisa.europa.eu/publications/n…

Yo, EU! Patch your stuff!

reshared this


Lorenzo ha ricondiviso questo.


A new US startup named Operation Bluebird has asked the US Patent and Trademark Office to vacate old Twitter trademarks, claiming that Elon Musk has abandoned them

reuters.com/technology/us-star…

reshared this


Lorenzo ha ricondiviso questo.


A crypto CEO "web2 security is not strong" while his industry lost billions in hacks over the past years must be the definition of tone deaf

reshared this



Arnad: 50 Valdostani infuriati acchiappano un ladro d'appartamento e lo picchiano con diversi oggetti tra cui un piccone e gli fratturano il bacino. L'altro ladro s'è dato

È un tranquillo venerdì sera ad Arnad, in Valle d’Aosta. Ma la serata viene funestata da due ladri che si introducono in una abitazione nella frazione Sisane, tentando di forzare una cassaforte.

I due, però, vengono colti in flagrante dal vicinato che li ha sentiti e ha chiamato le forze dell’ordine. Nel frattempo, però, parte anche il passaparola tramite cellulare che ha portato in breve tempo molti residenti in strada e, al tentativo di fuga dei malviventi, almeno 50 persone si sono lanciate al loro inseguimento.

Se uno dei ladri è riuscito a dileguarsi, per l’altro – un 40enne – invece le cose sono andate diversamente: i cittadini lo hanno bloccato mentre tentava la fuga verso il bosco, lo hanno accerchiato e picchiato con un piccone fino a procurargli la frattura del bacino. L’uomo è stato poi trasportato in ospedale; la lesione è stata giudicata guaribile in 30 giorni.

quotidianopiemontese.it/2025/1…

@Valle d'Aosta

reshared this


Lorenzo ha ricondiviso questo.


-Linux adds PCIe encryption to secure cloud servers
-Europol cracks down on Violence-as-a-Service providers
-ICC designates cyberspace as a genocide enabler
-Cambodia busts SMS blaster warehouse
-Police raid Coupang offices
-New Khashoggi lawsuit filed in France
-Aeroflot hack originated from contractor network
-FTC denies SpyFone CEO petition
-Meta agrees to use less personal data for ads in EU

Podcast: risky.biz/RBNEWS506/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-New Chrome and Firefox versions
-Patch Tuesday security updates are out
-NDAA 2026 comes with cyber provisions
-New Zealand notifies Lumma victims
-Poland arrests three Ukrainian hackers
-Russia arrests NFCGate hackers
-Spain arrests 19yo hacker
-React2Shell exploitation hits IoT space
-Telegram cracked down on crime channels since Oct '24
-New malware: GhostFrame PhaaS, Spiderman PhaaS, ChimeraWire, DeadLock ransomware, Broadside botnet, GhostPenguin Linux backdoor
-ZeroBoot exploit

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


The point of entry for the Aeroflot hack (from July) appears to have been Bakka Soft, an IT company that developed the airline's mobile and web apps

thebell.io/istoriya-bolshogo-v…

reshared this


Lorenzo ha ricondiviso questo.


New Zealand's cybersecurity agency is notifying more than 26,000 users who have been infected with the Lumma Stealer

ncsc.govt.nz/news/nz-cyber-age…

reshared this


Lorenzo ha ricondiviso questo.


Germany's cybersecurity agency has conducted a security audit of ten password managers and found that three of them can access a user's stored passwords—Google Chrome, mSecure, and PassSecurium

bsi.bund.de/DE/Service-Navi/Pr…

reshared this

in reply to Catalin Cimpanu

Wouldn't it be more worrying if the password managers *couldn't* access the passwords that the user has stored in them?
in reply to Catalin Cimpanu

interesting selection of software. Are some of those particularly popular in Germany? There are (at least) a couple of fairly big ones missing

Lorenzo ha ricondiviso questo.


Cydome has spotted Broadside, a new variant of the Mirai IoT malware.

The botnet is targeting TBK DVRs, commonly used by the maritime sector, including on some vessels.

cydome.io/cydome-identifies-br…

reshared this


Lorenzo ha ricondiviso questo.


What in the hell is going on with Mastodon embedded content. Why are those widgets becoming tinier and tinier?

reshared this

in reply to Catalin Cimpanu

I kind of wish the mastodon UI was more liquid than ice. Lots of wasted space on the edges.

Lorenzo ha ricondiviso questo.


Europol arrests 193 in crackdown against Violence-as-a-Service platforms.

Unclear if any of the arrests are TheCom members

europol.europa.eu/media-press/…

reshared this


Lorenzo ha ricondiviso questo.


The International Criminal Court will investigate genocide and war crimes that have been enabled through cyberspace (hacks, leaks, social media posts)

The ICC published its new policy and has put cyber on the same footing as crimes committed through other means

icc-cpi.int/news/icc-office-pr…

reshared this


Lorenzo ha ricondiviso questo.


Per Sysdig, North Korean hackers are now exploiting React2Shell to drop EtherRAT, a remote access trojan that uses Ethereum smart contracts as C2

sysdig.com/blog/etherrat-dprk-…

reshared this


Lorenzo ha ricondiviso questo.


RE: techhub.social/@Techmeme/11568…

Coupang also filed a complaint over the hack against a former employee, identified as a Chinese national


South Korean media: police raided Coupang's HQ, searching for evidence related to a historic data breach that compromised 30M+ people's personal information (Jane Lanhee Lee/Bloomberg)

bloomberg.com/news/articles/20…
techmeme.com/251209/p10#a25120…


reshared this


Lorenzo ha ricondiviso questo.


Koi Security researchers have discovered a malicious VSCode theme (Bitcoin Black) and extension (Codo AI) that captures a user's screen and sends it to attackers, in the hopes of capturing passwords and crypto-wallet seed phrases

koi.ai/blog/the-vs-code-malwar…

reshared this


Lorenzo ha ricondiviso questo.


Meta told the EU it will use less personal data for ads

...and those dummies believed it!!!

ec.europa.eu/commission/pressc…

reshared this

in reply to Catalin Cimpanu

at this stage, keeping face and not being bullied may be the best outcome. One can debate the effectiveness of EU laws, but at this point in history I prefer a government that insists on token guardrails to one that strips basic protections in every walk of life.

Lorenzo ha ricondiviso questo.


Dear lord... this Assassin's Creed game has some of the best nature and weather effects I've seen 😍

reshared this


Lorenzo ha ricondiviso questo.


Does nobody monitor that grid? How do you even steal that much power?

bloomberg.com/news/articles/20…

reshared this

in reply to Catalin Cimpanu

When I was in Taipei years ago there was a whole homewares market tucked under a overpass bridge and lifting power off the overhead cables with car jumper leads wired into dozens of power-boards. Hundreds of lamps under there, would have added up to thousands of watts.

I was talking to a guy who worked for their power utility and he reckoned about 20% of grid power was stolen.


Lorenzo ha ricondiviso questo.


"Three Ukrainian men found with an arsenal of hacking equipment were arrested in Poland, amid concerns they could be plotting to orchestrate cyberattacks on the country’s IT infrastructure."

tvpworld.com/90441395/ukrainia…

reshared this

in reply to Catalin Cimpanu

Press release by the Police srodmiescie.policja.gov.pl/rs/… "Znaleźli podejrzane przedmioty mogące służyć _nawet_ do ingerencji w strategiczne systemy informatyczne kraju, " - They found suspicious devices that could be used _even_ to affect strategic national IT systems.

Weird phrasing. Since the department responsible for handling scams, theft and fraud is leading it I think it's similar to the US news some time ago. IMO NatSec was added for flavor.

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


The US State Department is offering a $10 million reward for an Iranian couple who works for a contractor for Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).

The couple allegedly works for the company behind the Emennet Pasargad hacktivist group.

rewardsforjustice.net/rewards/…

reshared this


Lorenzo ha ricondiviso questo.


A Chinese think tank has published a hit piece on seven cybersecurity and policy experts specializing in Chinese cyber operations

guancha.cn/xinzhiguanchasuo/20…

reshared this