Elektrine lite

← Feed

Catalin Cimpanu

campuscodi@mastodon.social

<p>Cybersecurity reporter for Risky Business</p><p><a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a></p>

Posts

  • Post #4497534

    Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository) https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/

  • Post #4496538

    Russia&#39;s Sandworm follows North Korea and Iran and adopts the fake IT job interview as a malware delivery vector https://cert.gov.ua/article/6318863

  • Post #4487458

    -Pwnie Awards 2026 winners -Metabase zero-day used in data theft attacks -Russian hackers disrupted a second power plant in Poland last year -Two US law firms pay mega ransoms -New WordPress RCE -BdThemes supply chain attack -Coweta city refuses to pay ransom -Suisun declares local emergency after cyberattack hits 911 system -More attacks on US water systems -Victoria court data leaked on dark web -Breaches at LeviStrauss, Updoc, Framework N: https://news.risky.biz/risky-bulletin-pwnie-awards-2...

  • Post #4479043

    The Silent ransom group made $28m in just two attacks ≖‿≖ https://bsky.app/profile/raphae.li/post/3msjcgdmqxk2h

  • Post #4434258

    -Meta&#39;s AI joins Anthropic and OpenAI in the hacky-hacky -AISI also loses track of AI models in a test -Cyberattack disrupts North Carolina ports -The Philippines will establish a cybersecurity agency -Ransom Cartel admin gets 16 years -Hackers target US hedge funds -Panama Metro sees cyberattack -Italy makes room for military cyber units -China launches Palo Alto Networks probe -Indiana establishes cybersecurity office N: https://news.risky.biz/risky-bulletin-metas-ai-joins-anthropic-and-o...

  • Post #4387243

    Beacon CRM got hacked Many orgs are now disclosing downstream breachs https://www.bbc.com/news/articles/cr7km34z112o https://www.artsprofessional.co.uk/news/breaking-scores-of-cultural-organisations-affected-by-possible-data-breach-after-cyber-attack https://www.cse.org.uk/news/beacon-crm-incident/

  • Post #4385662

    Microsoft will reduce NuGet API keys lifespan from 365 to 30 days -change enters into effect August 17 -On November 1, Microsoft will invalidate all old NuGet API keys created before August 17. -shorter lifespan is meant to counter supply chain attacks https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/

  • Post #4381454

    Coinkite has destroyed all its inventory of Coldcare hardware crypto-wallets after hackers exploited a bug in existing devices to steal close to $100 million from user offline hardware wallets https://blog.coinkite.com/update-sunday/

  • Post #4366337

    Live streams from the BSides Las Vegas 2026 security conference, which is taking place this week, are available on YouTube https://www.youtube.com/@BsideslvOrg/streams

  • Post #4351927

    -Russia is behind the recent hotel WiFi hacks -Anthropic models also did the hacky-hacky -npm adds publish-time malware scanning -Coldcard hacked for $70m -CyberCom to open Silicon Valley office -Iran water hacks impacted seven states -Wemix hacked again -DNC falls for BEC scam -Google pauses Google Earth genAI feature over disinformation fears -Telco data breach reporting rules under assault again -SMS blaster arrested in Malaysia P: https://risky.biz/RBNEWS595/ N: https://news.risky.biz/risky...

  • Post #4271922

    -Non-profit offers $22,000 bounty for INC ransomware group -Hackers breach the UK Department for Education -Russia charges Pavel Durov -FCC bans foreign robots and power inverters -Minnesota water attacks linked to Iran -Adform hacked to spread malware -OpenAI-Hugging Face come out -Unitel hacked ahead of IPO -SplitVPN hacked -CubePilot DNS hijacking event -KT fined $37m for breaches -CareCloud breach -ExfilSquad goes on a hacking spree N: https://news.risky.biz/risky-bulletin-non-profit-offers...

  • Post #4242056

    Bruh... there&#39;s a &quot;master key&quot; that grants access to every Cosmos DB on Azure? Wut? https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db

  • Post #4241490

    The US government has banned the import of foreign-made robots and power inverters on the grounds of national security Most of these products are produced and imported from China https://www.fcc.gov/document/fcc-adds-foreign-produced-power-inverters-and-robots-covered-list

  • Post #4190101

    -Cyberattack disrupts water utilities in 30+ Minnesota communities -New Chinese cyber contractor identified -Denmark readies secondary banking system in case of cyberattacks -North Korea busts bank hackers -Cyberattack closes US clinics -Claude chats leak online -Bank of Baroda hack in India -Frontier Airlines had 3 breaches -Microsoft releases cyber model -Tech companies launch Open Secure AI Alliance -Moonshot open-sources Kimi K3 N: https://news.risky.biz/risky-bulletin-new-chinese-cyber-con...

  • Post #4173932

    RE: https://mastodon.social/@campuscodi/116999208190841327 Make that 30+ now: https://mn.gov/mnit/media/blog/?id=38-761869

  • Post #4171718

    The number of Minnesota towns that reported hacks of their water systems is up to four -Braham: https://dysruptionhub.com/braham-minnesota-water-cyberattack/ -Maple Plain: https://dysruptionhub.com/maple-plain-water-cyber-incident/ -Plymouth: https://dysruptionhub.com/plymouth-minnesota-water-cyberattack/ -St. Paul: https://dysruptionhub.com/south-st-paul-water-cyber-incident/

  • Post #4170520

    Pop star Ariana Grande has sued two hackers for stealing and unreleasing unreleased music and studio footage. The hackers allegedly stole the materials from her photographers and producers. https://www.tmz.com/2026/07/27/ariana-grande-sues-hackers/

  • Post #4169794

    The Danish central bank is building a secondary payment system that will activate in case of a cyberattack that cripples the country&#39;s normal banking sector https://gfmag.com/news/denmark-readies-emergency-reserve-bank/

  • Post #4169740

    Binance has changed an internal policy and appears to intentionally delay all law enforcement requests related to scammers and money laundering investigations https://www.nytimes.com/2026/07/28/us/binance-crypto-crime.html

  • Post #4168619

    North Korean authorities have arrested a cybercrime group who hacked two of the country&#39;s banks The group was led by discharged veterans from North Korea&#39;s intelligence service, as well as students recruited from two Pyongyang universities https://www.dailynk.com/english/north-korea-elite-bank-hacking-ring-arrested/

  • Post #4150438

    New spyware mystery just dropped: AngrySpark spyware, used against one target in the UK: https://medium.com/@billmarczak/an-angry-spark-or-a-triangle-in-disguise-ac32852a1be3 Some infrastructure overlaps with Operation Triangulation against Kaspersky: https://medium.com/@billmarczak/an-angry-spark-or-a-triangle-in-disguise-ac32852a1be3

  • Post #4145531

    Moonshot AI releases the Kimi K3 model weights and technical report https://huggingface.co/moonshotai/Kimi-K3 https://github.com/MoonshotAI/Kimi-K3/blob/main/k3_tech_report.pdf

  • Post #4145201

    The Cloud Security Alliance has released a post-mortem of the OpenAI hack of Hugging Face HF apparently reviewed and cleared the report https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem

  • Post #4135608

    -RCE bug in popular Java JSON library -Scam compounds expand in Myanmar despite crackdown -Google has a new APT naming scheme -Bug lets you swap executable of legitimate macOS apps -RubyGems API leak -Kimi lags behind Western cyber models -Dependabot gets a 3-day cooldown -Signal disappearing messages now cover calls too -Social media networks are hiding their data from academics -US lawmakers propose AI Kill Switch Act P: https://risky.biz/RBNEWS592/ N: https://news.risky.biz/risky-bulletin-a-...

  • Post #4110485

    XCharge EV charging stations can be hacked via the charging port because the connector apparently runs SSH with root/root as the default creds https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers

  • Post #4109028

    Moonshot&#39;s Kimi K3 AI model performs significantly below the cyber capabilities of AI models released by US frontier labs Kimi guardrails also failed to stop users from developing exploits https://www.aisi.gov.uk/blog/preliminary-assessment-of-kimi-k3s-cyber-capabilities

  • Post #4101854

    US lawmakers have proposed a bill that would force AI companies to build killswitches to shut down or throttle powerful AI models The bill was proposed a week after OpenAI admitted to losing control of two models that ended up hacking AI platform Hugging Face https://lieu.house.gov/media-center/press-releases/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can

  • Post #4076145

    Google has a new APT naming scheme https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/

  • Post #4061591

    -Western cyber agencies warn of Russian hacks of Zimbra servers -US accuses Moonshot AI of distillation attacks -Iran is targeting more PLC vendors -Google adds selfie video login -Thailand&#39;s Ministry of Finance hacked with an AI agent -Stadler Rail held for ransom for $12m -Breaches at Origin Energy, UpBound, Chick-fil-A -Wanchain hacked for $10m -AFX Trade hacked for $24m -Verus hacked for $7.5m, second time this year P: https://risky.biz/RBNEWS591/ N: https://news.risky.biz/risky-bulleti...

  • Post #4036780

    CISA has updated its &quot;Iran attacks PLCs&quot; advisory to add info about attacks on Siemens and Schneider Electric devices Initial attacks only targeted Rockwell and Allen-Bradley PLCs New TTPs and IOCs added too https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a