Checkout[.]com was hacked but refused to pay the ransom and instead donated the money to cybercrime research
checkout.com/blog/protecting-o…
Protecting our Merchants: Standing up to Extortion
Our statement detailing an incident concerning a legacy system. We outline our commitment to transparency, accountability, and planned investment in cyber security research.www.checkout.com
reshared this
Earlier this month, a global effort was launched to mass-report Google to authorities for monopolistic behavior on Android for forcing all developers to verify themselves with the company or get blocked: keepandroidopen.org/
Yesterday, Google backed off on the new rule: android-developers.googleblog.…
Android developer verification: Early access starts now as we continue to build with your feedback
News and insights on the Android platform, developer tools, and events.Android Developers Blog
reshared this
RE: mastodon.social/@campuscodi/11…
This has been confirmed today: operation-endgame.com/
Europol took down servers for the Rhadamanthys infostealer, the VenomRAT, and the Elysium botnet
reshared this
Check Point looks at a very niche phishing group named Payroll Pirates that uses malvertising to target the users of payroll systems, credit unions, and trading platforms
cyberint.com/blog/threat-intel…
Payroll Pirates: The Widespread Malvertising Network
A Deep Dive into an extensive malvertising campaign targeting US banks, credit unions and more.Dean Fenster (Cyberint)
reshared this
AWS dug through its honeypot data and confirmed that CVE-2025-5777 (Cisco ISE RCE) and CVE-2025-5777 (memory leak in Citrix NetScaler) were exploited as zero-days before their patches.
Nothing new here except the confirmation that an APT was behind the attacks
aws.amazon.com/blogs/security/…
Amazon discovers APT exploiting Cisco and Citrix zero-days | Amazon Web Services
The Amazon threat intelligence team has identified an advanced threat actor exploiting previously undisclosed zero-day vulnerabilities in Cisco Identity Service Engine (ISE) and Citrix systems.Amazon Web Services
reshared this
There's a CitrixBleed 4? When was 3?
labs.watchtowr.com/is-it-citri…
Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101)
There’s an elegance to vulnerability research that feels almost poetic - the quiet dance between chaos and control.Sina Kheirkhah (@SinSinology) (watchTowr Labs)
reshared this
There are reports that Europol seized the Rhadamantys Stealer infrastructure
reshared this
Block and report.
Mastodon.social is quickly becoming the cesspit of the Fediverse.
Intel sues former employee for allegedly stealing confidential data
-allegedly stole 18k files
-was laid off on July 3, given until end of month
-tried to steal files using an external HDD 8 days before layoff
-succeeded with a NAS 3 days before end of contract
mercurynews.com/2025/11/06/top…
'Top Secret' files among those allegedly misappropriated by software engineer losing job at Santa Clara chip giant Intel
At first he did not succeed in making off with a trove of Silicon Valley computer chip giant’s trade secrets, but then he tried again.ebaron@bayareanewsgroup.com (The Mercury News)
reshared this
RE: techhub.social/@Techmeme/11553…
Portugal, a country famous for its abundance in water... LOL.... EXTRA BIG FAT LOL!!!
reshared this
reshared this
Microsoft says that:
-99.6% of all employees and their devices are now using phishing-resistant multi-factor authentication (MFA)
-35k+ engineers are now working "full time on security" [big doubt!!!]
microsoft.com/en-us/security/b…
Latest progress update on Microsoft’s Secure Future Initiative | Microsoft Security Blog
Read more about the key updates and milestones of Microsoft's Secure Future Initiative in the November 2025 SFI progress report.Charlie Bell (Microsoft Security Blog)
reshared this
2. Count me as about half an engineer here and I don’t even work on a product with meaningful security boundaries inside; the fountain of compliance overhead is eternal. A lot of it is “defending against auditors not attackers” but I’m still net happy about it.

Bank of England has confirmed the Jaguar Land Rover ransomware attack impacted the UK's GDP growth, as the government first claimed back in August
bankofengland.co.uk/monetary-p…
Monetary Policy Report - November 2025
Our quarterly report sets out the economic analysis and inflation projections that the Monetary Policy Committee uses to make its interest rate decisions.www.bankofengland.co.uk
reshared this
While AI companies are allowed to slurp everything they want, Quad9 warns that legal fees are drowning DNS resolvers, which are now being targeted by copyright owners to enforce blocks on piracy sites
quad9.net/news/blog/when-enfor…
Quad9 | A public and free DNS service for a better security and privacy
A public and free DNS service for a better security and privacyQuad9
like this
reshared this
-Myanmar blows up KK Park scam compound
-Yanluowang ransomware IAB pleads guilty
-US CBO hacked by foreign APT
-Singapore to punish scammers with cane beatings
-Chrome will remove XSLT support for security reasons
-Hungary opposition party hacked, blamed on Russians
-WaPo breach linked to Oracle zero-day
-Tinder to rummage through your photos
-Akamai reports disruptions in Russia
-ICC, Austria replace MSFT software
Podcast: risky.biz/RBNEWS502/
Newsletter: news.risky.biz/risky-bulletin-…
Risky Bulletin: Yanluowang ransomware IAB pleads guilty
In other news: US CBO hacked by foreign APT; Singapore to punish scammers with cane beatings; Chrome will remove XSLT support for security reasons.Catalin Cimpanu (Risky.Biz)
reshared this
-Samsung zero-day delivers Landfall spyware
-Silent Lynx targets Azerbaidjan
-DarkHotel keeps hammering Japan
-Konni APT wipes victim Android phones
-Whisper Leak attack
-KubeVirt security audit
-QNAP security updates
-LangGraph RCE
-Monsta FTP RCE
-Django SQLi
-ASP.NET request smuggling
-RunC vuln allows container breakout
-Loads of new tools: GMSGadget, NoMoreStealers, VenomC2, DonPwner, Blade, MAD-CAT
Two weeks ago, there were weird reports online of explosions at KK Park, Myanmar's largest scam compound, and people fleeing the streets.
I thought some internal military groups were fighting for control, but it appears the junta is demolishing the park outright
reshared this
This is a gigantic scam complex, with 250 buildings
24 of 250 have been demolished with dynamite by the local border force
vietnam.vn/en/myanmar-tien-han…
Myanmar to demolish 150 buildings at 'scam nest' KK Park
(CLO) On November 9, the Myanmar military said it was demolishing about 150 buildings in the scam den area called KK Park, following a crackdown in October.Công Luận (vietnam.vn)
Singapore passes law to punish scammers and money mules with cane beatings 😀)
straitstimes.com/singapore/pol…
Law passed for scammers, mules to be caned after victims in Singapore lose almost $4b since 2020
Scammers face between six and 24 strokes of the cane, while mules face a discretionary 12 strokes. Read more at straitstimes.com.David Sun (ST)
reshared this
Australia sanctions North Korean hackers (one person and four entities)
-Park Jin Hyok (WannaCry dude)
-Kimsuky
-Lazarus Group
-Andariel
-Chosun Expo
Presser: foreignminister.gov.au/ministe…
Sanction details: dfat.gov.au/news/news/one-pers…
reshared this
Singaporean authorities have sentenced three Chinese nationals to 2 years and 4 months prison for hacking-related charges
The three hacked into online gambling sites to cheat on games and steal personal data
police.gov.sg/Media-Hub/News/2…
Three Men Sentenced For Offences In Relation To Illegal Cyber Activities
On 5 November 2025, three Chinese nationals, Yan Peijian (“Yan”), 39, Huang Qinzheng (“Huang”), 37, and Liu Yuqi (“Liu”), 33, were convicted and sentenced to imprisonment for their roles in a global cybercrime syndicate that conducted illegal cyber a…Singapore Police Force
reshared this
Microsoft has discovered a side-channel attack (Whisper Leak) on the network communications between AI chatbots and their backend LLMs
microsoft.com/en-us/security/b…
Whisper Leak: A novel side-channel attack on remote language models | Microsoft Security Blog
Understand the risks of encrypted AI traffic exposure and explore practical steps users and cloud providers can take to stay secure. Learn more.Geoff McDonald (Microsoft Security Blog)
reshared this
Konni APT wipes victims' Android smartphones via the Google find my device hub
genians.co.kr/en/blog/threat_i…
State-Sponsored Remote Wipe Tactics Targeting Android Devices
The Konni APT campaign has caused damage by remotely resetting Google Android-based devices, resulting in the unauthorized deletion of personal data.Genians (www.genians.co.kr)
reshared this
"Akamai is aware of content and connectivity filtering within Russia. Although we have not yet seen wholesale blocking of our platform for users, Russian network operator actions and actions by the Russian government may impact delivery to some users within some networks."
reshared this
Google Chrome will deprecate and remove XSLT support (the XML CSS thing) by late-2026
Cites security reasons
developer.chrome.com/docs/web-…
Removing XSLT for a more secure browser
Prepare for Chrome deprecating and removing XSLT from the browser.Chrome for Developers
reshared this
Creeper alert: Tinder to use AI to get to know users, tap into their Camera Roll photos
techcrunch.com/2025/11/05/tind…
Tinder to use AI to get to know users, tap into their Camera Roll photos | TechCrunch
Tinder is testing an AI feature that learns about you from your Camera Roll photos.Sarah Perez (TechCrunch)
reshared this
Hungary's main opposition party has suffered a major security breach. Hackers leaked more than 200,000 user records from the TISZA party's mobile app.
hungarytoday.hu/yet-another-ti…
TISZA leader Péter Magyar blamed the hack on Russian hackers.
facebook.com/peter.magyar.102/…
Péter Magyar
Kedves Barátaim! Eddig is tudtuk, hogy az oroszok nemcsak a spájzban vannak, hanem már jelen vannak a nappalinkban, vagy épp a Külügyminisztérium szerverein és a Karmelita füstös szobáiban is. A...www.facebook.com
reshared this
youtube.com/watch?v=RcfTAPeCak…- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
informapirata ⁂ likes this.
informapirata ⁂ reshared this.
[ITA] Denis Roio - Codice 22/08/2025
Imprenditore e hacktivist, Denis Roio, sull'origine delle culture digitali
raiplay.it/programmi/codice-la…
Originally published on
Codice - La vita è digitale - RaiPlay
Quali sono le rotte del mondo connesso e qual è il progetto umano nell'Era digitale?RaiPlay
Lorenzo likes this.
reshared this
Phil 🇺🇦💙💛🇺🇸 ❤️🏳️🌈❤️🏳
in reply to Catalin Cimpanu • • •