Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

No.

#Internet

Lorenzo ha ricondiviso questo.

Tulsi Gabbard has resigned from the role of US Director of National Intelligence.

Gabbard cited her husband's cancer diagnosis as reason. Her resignation is effective June 30

bbc.com/news/articles/cvgj2gkv…

reshared this

Firefox Nova: Mozilla conferma il grande redesign del browser per il 2026

@GNU/Linux Italia

linuxeasy.org/firefox-nova-moz…

Mozilla conferma il redesign Firefox Nova 2026 con nuove funzioni privacy, interfaccia moderna, schede verticali e prestazioni migliorate.
L'articolo Firefox Nova: Mozilla conferma il grande redesign del browser per il 2026 proviene da

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Microsoft ends SMS MFA for personal accounts
-GitHub hacked via VS Code extension
-CISA to let researchers submit new KEV entries
-SMS blaster detained at Eurovision
-Grafana hack linked to TanStack incident
-Northern Mariana Islands cyberattack
-Russia hacks BlueSky accounts for disinfo ops
-Trump Mobile leaked user data
-Patel's store gets hacked
-Dutch asks EU for help against Meta and TikTok bad ads

Newsletter: news.risky.biz/risky-bulletin-…
Podcast: risky.biz/RBNEWS567/

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Apple blocked 1.1b new fraudulent accounts
-Russia's growing software security issues
-Armenia faces waves of disinformation
-Dems want answers on CISA leak
-White House postpones AI security EO
-Ukraine detains infostealer operator
-Execs plead guilty for tech support scams
-Kimwolf admin arrested in Canada
-First VPN takedown
-Coruna found on npm
-Ghost CMS sites are getting hacked
-Megalodon campaign hits GitHub
-New Android carrier billing fraud campaign

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

-Spammers abuse Microsoft internal email
-New CypherLoc screenlocker
-Operation Dragon Whistle targets China
-UAC-0244 targets Ukrainian drone operators
-Google API keys live for 23mins after deletion
-Apple fixes unrestricted filesystem access bug
-Security audit of n8n templates
-Google exposes major Chromium bug
-New PinTheft vulnerability
-Another Linux LPE
-NGINX-PoolSlip RCE
-Two Windows Defender zero-days
-Cisco patches major CSW bug
-Drupal fixes highly-critical SQLi
-ZionSiphon analysis
Lorenzo ha ricondiviso questo.

An automated campaign has tried to backdoor more than 5,500 GitHub repositories via malicious commits that deploy a GitHub Action

The Action ran a bash script that stole CI secrets, cloud credentials, SSH keys, and other tokens

safedep.io/megalodon-mass-gith…

reshared this

Lorenzo ha ricondiviso questo.

After countless rumors that the White House was publishing an executive order on Friday on AI security, officials have postponed it hours before it was set to be signed

cyberscoop.com/trump-postpones…

reshared this

Lorenzo ha ricondiviso questo.

The Dutch consumer protection agency has asked national and EU regulators to take action against Google, Meta, and TikTok for not removing malicious ads from their platforms, and not replying to reports

consumentenbond.nl/nieuws/2026…

CERT-PL accused Meta of this a year ago too

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

today, almost 4 years later, the bug is finally public:
issues.chromium.org/issues/400…

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

A hacking campaign is planting FakeCaptcha pages and malware on websites built with the Ghost CMS.

The attacks began this month and are exploiting a vulnerability disclosed in February

blog.xlab.qianxin.com/ghost-cm…

reshared this

in reply to Catalin Cimpanu

The media in this post is not displayed to visitors. To view it, please go to the original post.

possibly similar, but we have seen some fake Cloudflare captcha screens that ask users to copy the contents of their clipboard into a Windows run window. The clipboard contains malicious powershell or rundll32 commands that attempt to download malware via webdav http from legitimate websites that are infected and hosting it.
Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Group IB looks at the top 5 largest data trading platforms in the Chinese underground—Exchange Market (交易市场, Deepmix), Chang’An Sleepless Night (长安不夜城), Aiqianjin (爱钱进), Yiqun Data (义群数据), and the Phoenix Overseas Resources (凤凰海外资源)

group-ib.com/blog/lead-data-ob…

reshared this

Lorenzo ha ricondiviso questo.

The government of the US territory of the Northern Mariana Islands was hit by a cyberattack that impacted email services

dysruptionhub.com/cnmi-email-c…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Authorities in France and the Netherlands have seized the servers of a VPN service used by cybercrime gangs: europol.europa.eu/media-press/…

FBI has also released a list of IPs used by the service:
ic3.gov/CSA/2026/260521.pdf

reshared this

Lorenzo ha ricondiviso questo.

Grafana links hack to TanStack supply chain attack (same as GitHub)

grafana.com/blog/grafana-labs-…

reshared this

Lorenzo ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Rakesh Krishnan has published an analysis of some of the leaked GitHub repo code

theravenfile.com/2026/05/20/gi…

reshared this

Lorenzo ha ricondiviso questo.

After we had the NGINX Rift vulnerability disclosed last week, there's now another RCE in the NGINX server, this one named NGINX-PoolSlip.

Details will be published 30 days after a patch is released, to prevent exploitation, which is now happening against NGINX Rift

x.com/nebusecurity/status/2057…

reshared this

Lorenzo ha ricondiviso questo.

Around a third of Russian companies are using Western software acquired before 2022, before Russia's invasion of Ukraine.

Most of the software doesn't receive technical support and security updates

kommersant.ru/doc/8673186

reshared this

Lorenzo ha ricondiviso questo.

The Nx Dev Tools CEO confirms that his company's Nx Console VS Code extension served as the initial entry point for the GitHub repo hack: x.com/jeffbcross/status/205723…

Nx incident: github.com/nrwl/nx-console/sec…

Step Security report: stepsecurity.io/blog/nx-consol…

reshared this