Salta al contenuto principale

Lorenzo ha ricondiviso questo.


Checkout[.]com was hacked but refused to pay the ransom and instead donated the money to cybercrime research

checkout.com/blog/protecting-o…

reshared this


Lorenzo ha ricondiviso questo.


Earlier this month, a global effort was launched to mass-report Google to authorities for monopolistic behavior on Android for forcing all developers to verify themselves with the company or get blocked: keepandroidopen.org/

Yesterday, Google backed off on the new rule: android-developers.googleblog.…

reshared this

in reply to Catalin Cimpanu

Interesting. It's almost like organized mass protest can have an effect.

Lorenzo ha ricondiviso questo.


RE: mastodon.social/@campuscodi/11…

This has been confirmed today: operation-endgame.com/

Europol took down servers for the Rhadamanthys infostealer, the VenomRAT, and the Elysium botnet


There are reports that Europol seized the Rhadamantys Stealer infrastructure

x.com/club31337/status/1988353…


reshared this

in reply to Catalin Cimpanu

There is no way Europol made a CGI animation on Rhadamanthys

The trolling level is off the charts

in reply to Catalin Cimpanu

I think it's AI, likely Sora. You can see it especially in the small variances for written text - it's not perfectly stable.

Lorenzo ha ricondiviso questo.


Check Point looks at a very niche phishing group named Payroll Pirates that uses malvertising to target the users of payroll systems, credit unions, and trading platforms

cyberint.com/blog/threat-intel…

reshared this


Lorenzo ha ricondiviso questo.


AWS dug through its honeypot data and confirmed that CVE-2025-5777 (Cisco ISE RCE) and CVE-2025-5777 (memory leak in Citrix NetScaler) were exploited as zero-days before their patches.

Nothing new here except the confirmation that an APT was behind the attacks

aws.amazon.com/blogs/security/…

reshared this


Lorenzo ha ricondiviso questo.


There's a CitrixBleed 4? When was 3?

labs.watchtowr.com/is-it-citri…

reshared this


Lorenzo ha ricondiviso questo.


Ok my beloved APT crowd.... it's time to update all those APT charts

The DPRK RGB is now the RIGB

Let's go! I want new charts by next month!

reshared this


Lorenzo ha ricondiviso questo.


There are reports that Europol seized the Rhadamantys Stealer infrastructure

x.com/club31337/status/1988353…

reshared this


Lorenzo ha ricondiviso questo.


I'm really starting to get tired of these random totally unrelated AI-generated responses to every post here

reshared this

in reply to Catalin Cimpanu

Block and report.

Mastodon.social is quickly becoming the cesspit of the Fediverse.

in reply to Catalin Cimpanu

have you tried the Translate button? See if there’s an option to translate from nonsense to sense.

Lorenzo ha ricondiviso questo.


Intel sues former employee for allegedly stealing confidential data

-allegedly stole 18k files
-was laid off on July 3, given until end of month
-tried to steal files using an external HDD 8 days before layoff
-succeeded with a NAS 3 days before end of contract

mercurynews.com/2025/11/06/top…

reshared this


Lorenzo ha ricondiviso questo.


RE: techhub.social/@Techmeme/11553…

Portugal, a country famous for its abundance in water... LOL.... EXTRA BIG FAT LOL!!!


Microsoft plans to spend $10B to build a data center in the Portuguese town of Sines in partnership with Portuguese developer Start Campus and UK startup Nscale (Henrique Almeida/Bloomberg)

bloomberg.com/news/articles/20…
techmeme.com/251111/p13#a25111…


reshared this


Lorenzo ha ricondiviso questo.


Someone just told me: "There hasn't been a better time to be a cybersecurity reporter. I just open one of your newsletters and I have stories to cover for the entire week." 🤣

reshared this

in reply to Catalin Cimpanu

yes, you are doing insanely valuable work. All of you! It always makes me smile inside when I hear clients talk what they pay for threat intel, but they have never heard about #riskybusiness. 🤷‍♀️

Lorenzo ha ricondiviso questo.


A new OWASP Top 10 is close to being released, with supply chain risks entering the ranking at #3 directly

owasp.org/Top10/2025/0x00_2025…

#3

reshared this


Lorenzo ha ricondiviso questo.


Microsoft says that:

-99.6% of all employees and their devices are now using phishing-resistant multi-factor authentication (MFA)
-35k+ engineers are now working "full time on security" [big doubt!!!]

microsoft.com/en-us/security/b…

reshared this

in reply to Catalin Cimpanu

@hacks4pancakes 1. I believe it, policies were pushed out to make logging in with anything else very difficult if not impossible. It’s made setting up a new device difficult for instance because using a mobile passkey requires working Bluetooth which can be kind of a Catch-22 during OOBE
2. Count me as about half an engineer here and I don’t even work on a product with meaningful security boundaries inside; the fountain of compliance overhead is eternal. A lot of it is “defending against auditors not attackers” but I’m still net happy about it.

Lorenzo ha ricondiviso questo.


Looks like the need to fire staff to cover AI costs has hit the Windows team

RIP Windows Insider

reshared this

in reply to Catalin Cimpanu

Insider was the replacement for all the fired QA people back in the day yeah? And the code quality in the last 12 months has been shameful. I can't imagine what the future holds in this timeline, but likely won't be good. :ablobcatnod:

Lorenzo ha ricondiviso questo.


Bank of England has confirmed the Jaguar Land Rover ransomware attack impacted the UK's GDP growth, as the government first claimed back in August

bankofengland.co.uk/monetary-p…

reshared this


Lorenzo ha ricondiviso questo.


While AI companies are allowed to slurp everything they want, Quad9 warns that legal fees are drowning DNS resolvers, which are now being targeted by copyright owners to enforce blocks on piracy sites

quad9.net/news/blog/when-enfor…


Lorenzo ha ricondiviso questo.


-Myanmar blows up KK Park scam compound
-Yanluowang ransomware IAB pleads guilty
-US CBO hacked by foreign APT
-Singapore to punish scammers with cane beatings
-Chrome will remove XSLT support for security reasons
-Hungary opposition party hacked, blamed on Russians
-WaPo breach linked to Oracle zero-day
-Tinder to rummage through your photos
-Akamai reports disruptions in Russia
-ICC, Austria replace MSFT software

Podcast: risky.biz/RBNEWS502/
Newsletter: news.risky.biz/risky-bulletin-…

reshared this

in reply to Catalin Cimpanu

-Ransomware in VS Code extensions
-Samsung zero-day delivers Landfall spyware
-Silent Lynx targets Azerbaidjan
-DarkHotel keeps hammering Japan
-Konni APT wipes victim Android phones
-Whisper Leak attack
-KubeVirt security audit
-QNAP security updates
-LangGraph RCE
-Monsta FTP RCE
-Django SQLi
-ASP.NET request smuggling
-RunC vuln allows container breakout
-Loads of new tools: GMSGadget, NoMoreStealers, VenomC2, DonPwner, Blade, MAD-CAT
in reply to Catalin Cimpanu

It seems to be ransomware in everything until proven otherwise.

Lorenzo ha ricondiviso questo.


Two weeks ago, there were weird reports online of explosions at KK Park, Myanmar's largest scam compound, and people fleeing the streets.

I thought some internal military groups were fighting for control, but it appears the junta is demolishing the park outright

irrawaddy.com/news/myanmars-cr…

reshared this

in reply to Catalin Cimpanu

This is a gigantic scam complex, with 250 buildings

24 of 250 have been demolished with dynamite by the local border force

vietnam.vn/en/myanmar-tien-han…


Lorenzo ha ricondiviso questo.


Singapore passes law to punish scammers and money mules with cane beatings 😀)

straitstimes.com/singapore/pol…

reshared this


Lorenzo ha ricondiviso questo.


Australia sanctions North Korean hackers (one person and four entities)

-Park Jin Hyok (WannaCry dude)
-Kimsuky
-Lazarus Group
-Andariel
-Chosun Expo

Presser: foreignminister.gov.au/ministe…

Sanction details: dfat.gov.au/news/news/one-pers…

reshared this


Lorenzo ha ricondiviso questo.


Singaporean authorities have sentenced three Chinese nationals to 2 years and 4 months prison for hacking-related charges

The three hacked into online gambling sites to cheat on games and steal personal data

police.gov.sg/Media-Hub/News/2…

reshared this


Lorenzo ha ricondiviso questo.


Microsoft has discovered a side-channel attack (Whisper Leak) on the network communications between AI chatbots and their backend LLMs

microsoft.com/en-us/security/b…

reshared this


Lorenzo ha ricondiviso questo.


Konni APT wipes victims' Android smartphones via the Google find my device hub

genians.co.kr/en/blog/threat_i…

reshared this


Lorenzo ha ricondiviso questo.


"Akamai is aware of content and connectivity filtering within Russia. Although we have not yet seen wholesale blocking of our platform for users, Russian network operator actions and actions by the Russian government may impact delivery to some users within some networks."

akamai.com/blog/edge/2025/nov/…

reshared this


Lorenzo ha ricondiviso questo.


Google Chrome will deprecate and remove XSLT support (the XML CSS thing) by late-2026

Cites security reasons

developer.chrome.com/docs/web-…

reshared this


Lorenzo ha ricondiviso questo.


Creeper alert: Tinder to use AI to get to know users, tap into their Camera Roll photos

techcrunch.com/2025/11/05/tind…

reshared this


Lorenzo ha ricondiviso questo.


Hungary's main opposition party has suffered a major security breach. Hackers leaked more than 200,000 user records from the TISZA party's mobile app.

hungarytoday.hu/yet-another-ti…

TISZA leader Péter Magyar blamed the hack on Russian hackers.

facebook.com/peter.magyar.102/…

Questa voce è stata modificata (6 giorni fa)

reshared this


Lorenzo ha ricondiviso questo.


#spiritbox live Rock am Ring 2025 #metal:parrot_metal:​​:headbanger:youtube.com/watch?v=RcfTAPeCak…

Lorenzo reshared this.


Lorenzo ha ricondiviso questo.


Buon compleanno @informapirata!

Cifra tonda o ricordo male? 😂

@caffeitalia


Lorenzo ha ricondiviso questo.


[ITA] Denis Roio - Codice 22/08/2025


Imprenditore e hacktivist, Denis Roio, sull'origine delle culture digitali
raiplay.it/programmi/codice-la…

Originally published on

Questa voce è stata modificata (1 mese fa)

reshared this