Catalin Cimpanu
@campuscodi.risky.biz
📤 13380
📥 471
📝 4673
☆ Cybersecurity reporter ★ Newsletters at Risky Business
#infosec
#cybersecurity
https://risky.biz
reposted by
Catalin Cimpanu
Wes Miller
about 19 hours ago
First rule of 2026 commencement speech?
add a skeleton here at some point
2
10
2
reposted by
Catalin Cimpanu
Joseph Menn
about 19 hours ago
The U.S. may be about to require green card applicants who live here to apply from abroad, where they can be rejected with little chance for appeal. Including spouses of U.S. citizens and highly skilled employees of companies that I expect will raise a major stink about this.
add a skeleton here at some point
0
20
13
reposted by
Catalin Cimpanu
Brian Merchant
about 19 hours ago
Counterpoint: No I will not
loading . . .
Even If You Hate AI, You Will Use Google AI Search
The search giant’s AI-crafted answers are so convenient, you’ll be sucked in—to the detriment of the web and the artists and thinkers behind it.
https://www.wired.com/story/even-if-you-hate-ai-you-will-use-google-ai-search/
205
3815
1047
Tulsi Gabbard has resigned from the role of US Director of National Intelligence. Gabbard cited her husband's cancer diagnosis as reason. Her resignation is effective June 30
www.bbc.com/news/article...
loading . . .
Tulsi Gabbard resigns as US director of national intelligence
She is leaving the role of coordinating the US intelligence agencies on 30 June in order to help her husband, who was diagnosed with bone cancer.
https://www.bbc.com/news/articles/cvgj2gkv1x1o
about 19 hours ago
4
11
4
There seems to be a bot attack on BlueSky right now I'm getting followed by hundreds of accounts with profile images of dogs and cats
about 20 hours ago
4
14
3
reposted by
Catalin Cimpanu
Microsoft Threat Intelligence
about 20 hours ago
Microsoft Defender research details a multi-stage intrusion that began with a compromised internet-facing firewall appliance and pivoted to an internal Linux host, where a vulnerable software-as-a-service (SaaS) app was exploited to run authentication attacks.
msft.it/63323vn8ft
loading . . .
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence | Microsoft Security Blog
A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack.
https://msft.it/63323vn8ft
2
9
3
reposted by
Catalin Cimpanu
Hypervisible
about 20 hours ago
It’s going great.
loading . . .
You can no longer Google the word 'disregard' | TechCrunch
After Google Search's AI update, the word "disregard" now effectively breaks the search interface.
https://techcrunch.com/2026/05/22/you-can-no-longer-google-the-word-disregard/
91
2129
979
reposted by
Catalin Cimpanu
andrew ⓕ lyons
about 21 hours ago
Looking forward to the scam email campaigns claiming people owe Iran money.
add a skeleton here at some point
1
4
1
For who's not familiar with this, the EPPO (EU prosecutor) caught Greek politicians embezzling EU agricultural funds and their reply was to limit the EPPO's reach rather than punish the politicians This is now a very common trend among all EU states on the Eastern side of the continent
add a skeleton here at some point
about 20 hours ago
1
11
3
reposted by
Catalin Cimpanu
Victoria Dahl/Victoria Helen Stone
about 22 hours ago
AI can’t even COUNT things correctly. Come on now.
add a skeleton here at some point
1
16
1
reposted by
Catalin Cimpanu
Hypervisible
5 days ago
For perverts who also want to help Meta accumulate training data for bombing people.
loading . . .
Inside Anduril and Meta’s quest to make smart glasses for warfare
It’s been a year since the duo entered the US Army’s troubled augmented-reality contest. Here’s what it looks like so far.
https://www.technologyreview.com/2026/05/18/1137412/inside-anduril-and-metas-quest-to-make-smart-glasses-for-warfare/
7
80
36
reposted by
Catalin Cimpanu
Gate 15
about 21 hours ago
The FBI issued a Public Service Announcement to warn the public about an emerging Phishing-as-a-Service (PhaaS) platform called Kali365. Read more below:
www.ic3.gov/PSA/2026/PSA...
#cybersecurity
@andyjabbour.bsky.social
1
3
2
reposted by
Catalin Cimpanu
-Microsoft ends SMS MFA for personal accounts -GitHub hacked via VS Code extension -CISA to let researchers submit new KEV entries -SMS blaster detained at Eurovision -Grafana hack linked to TanStack incident Newsletter:
news.risky.biz/risky-bullet...
Podcast:
risky.biz/RBNEWS567/
1 day ago
2
22
11
reposted by
Catalin Cimpanu
-Armenia faces waves of disinformation -Dems want answers on CISA leak -White House postpones AI security EO -Ukraine detains infostealer operator -Execs plead guilty for tech support scams -Kimwolf admin arrested in Canada -First VPN takedown -Coruna found on npm -Ghost CMS sites are getting hacked
1 day ago
2
5
1
reposted by
Catalin Cimpanu
Paul Gowder
5 days ago
My 1999 self would weep at how totally broken the internet has become. AI slop, social media walled gardens that rot the brain, surveillance pricing and advertising, every single goddamn website has an endless cloudflare captcha loop before you get to read anything. Burn it all down.
51
2242
490
reposted by
Catalin Cimpanu
Ron Deibert
1 day ago
Greece 🇬🇷 has witnessed a flurry of corruption and espionage against journalists, but the journalists are relentless and principled and the truth will eventually come out through the courts and through public interest investigations.
www.dnews.gr/eidhseis/new...
loading . . .
Citizen Lab’s Ron Deibert: “Accountability may be delayed, but the truth will emerge” - Dnews
Greece’s spyware scandal remains a live test case for Europe’s rule of law, according to Ron Deibert, founder and director of Citizen Lab, who warned in Athens that the global expansion of the commerc...
https://www.dnews.gr/eidhseis/news-in-english/589746/citizen-lab-s-ron-deibert-accountability-may-be-delayed-but-the-truth-will-emerge
0
16
5
-Microsoft ends SMS MFA for personal accounts -GitHub hacked via VS Code extension -CISA to let researchers submit new KEV entries -SMS blaster detained at Eurovision -Grafana hack linked to TanStack incident Newsletter:
news.risky.biz/risky-bullet...
Podcast:
risky.biz/RBNEWS567/
1 day ago
2
22
11
Jacob Butler, aka “Dort,” 23, of Ottawa, Canada, was arrested for running the Kimwolf DDoS botnet
www.justice.gov/usao-ak/pr/c...
1 day ago
0
7
2
An automated campaign has tried to backdoor more than 5,500 GitHub repositories via malicious commits that deploy a GitHub Action The Action ran a bash script that stole CI secrets, cloud credentials, SSH keys, and other tokens
safedep.io/megalodon-ma...
loading . . .
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
Over 5,700 malicious commits were pushed to GitHub repositories on May 18, 2026, replacing GitHub Actions workflows with base64-encoded secret exfiltration payloads. The "megalodon" campaign targeted ...
https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
1 day ago
1
8
5
CISA will let third-parties submit reports about actively exploited vulnerabilities so it can add them to the KEV database
www.cisa.gov/news-events/...
1 day ago
0
8
5
reposted by
Catalin Cimpanu
International Cyber Digest
1 day ago
‼️🚨 BREAKING: Kash Patel's apparel website is reportedly hosting ClickFix malware, according to multiple visitors. A fake Cloudflare verification page is tricking users into pasting "verification" commands that execute an infostealer targeting Keychain, browser data, tokens, and crypto wallets.
30
539
285
After countless rumors that the White House was publishing an executive order on Friday on AI security, officials have postponed it hours before it was set to be signed
cyberscoop.com/trump-postpo...
loading . . .
Trump postpones executive order focused on AI security
Under a draft executive order, the NSA, Treasury Department and other federal agencies would get 90-days to test new models for cybersecurity and national security concerns.
https://cyberscoop.com/trump-postpones-executive-order-focused-on-ai-security/
1 day ago
0
5
3
The Dutch consumer protection agency has asked national and EU regulators to take action against Google, Meta, and TikTok for not removing malicious ads from their platforms, and not replying to reports
www.consumentenbond.nl/nieuws/2026/...
CERT-PL accused Meta of this a year ago too
loading . . .
EC moet ingrijpen bij online platforms om misleidende advertenties
30 Europese consumentenorganisaties roepen de Europese Commissie op in te grijpen bij Meta, TikTok en Google. Onderzoek van 13 van deze organisaties laat zien dat de platforms malafide adverteerders n...
https://www.consumentenbond.nl/nieuws/2026/europese-commissie-moet-ingrijpen-bij-meta-tiktok-en-google-om-misleidende-advertenties
1 day ago
0
10
4
A hacking campaign is planting FakeCaptcha pages and malware on websites built with the Ghost CMS. The attacks began this month and are exploiting a vulnerability disclosed in February
blog.xlab.qianxin.com/ghost-cms-ma...
2 days ago
0
5
6
Group IB looks at the top 5 largest data trading platforms in the Chinese underground—Exchange Market (交易市场, Deepmix), Chang’An Sleepless Night (长安不夜城), Aiqianjin (爱钱进), Yiqun Data (义群数据), and the Phoenix Overseas Resources (凤凰海外资源)
www.group-ib.com/blog/lead-da...
2 days ago
1
5
0
The government of the US territory of the Northern Mariana Islands was hit by a cyberattack that impacted email services
dysruptionhub.com/cnmi-email-c...
loading . . .
Northern Mariana Islands government email accounts hit by cyberattack
CNMI officials say a cyberattack affected some government email accounts as OIT works to restore access.
https://dysruptionhub.com/cnmi-email-cyberattack/
2 days ago
0
3
1
Authorities in France and the Netherlands have seized the servers of a VPN service used by cybercrime gangs:
www.europol.europa.eu/media-press/...
FBI has also released a list of IPs used by the service:
www.ic3.gov/CSA/2026/260...
2 days ago
0
6
3
Grafana links hack to TanStack supply chain attack (same as GitHub)
add a skeleton here at some point
2 days ago
0
1
1
Rakesh Krishnan has published an analysis of some of the leaked GitHub repo code
theravenfile.com/2026/05/20/g...
2 days ago
0
5
2
Russia has hacked BlueSky accounts to post pro-Kremlin and anti-Ukraine propaganda. The hacks have been going on since April. BlueSky has been suspending accounts until owners could step in and resecure them It's a Matryoshka op
www.nytimes.com/2026/05/21/b...
loading . . .
Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda
https://www.nytimes.com/2026/05/21/business/bluesky-russia-hacking-accounts.html
2 days ago
1
20
10
After we had the NGINX Rift vulnerability disclosed last week, there's now another RCE in the NGINX server, this one named NGINX-PoolSlip. Details will be published 30 days after a patch is released, to prevent exploitation, which is now happening against NGINX Rift
x.com/nebusecurity...
2 days ago
1
7
0
Around a third of Russian companies are using Western software acquired before 2022, before Russia's invasion of Ukraine. Most of the software doesn't receive technical support and security updates
www.kommersant.ru/doc/8673186
2 days ago
0
9
2
reposted by
Catalin Cimpanu
👻
2 days ago
"Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda The company said it was fighting Russian efforts to hijack real users’ accounts to post fake content, an apparently novel tactic." 🎁 article
loading . . .
Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda
https://www.nytimes.com/2026/05/21/business/bluesky-russia-hacking-accounts.html?unlocked_article_code=1.kFA.EndN.WvJSkcxIv5DR&smid=url-share
1
438
344
The Nx Dev Tools CEO confirms that his company's Nx Console VS Code extension served as the initial entry point for the GitHub repo hack:
x.com/jeffbcross/s...
Nx incident:
github.com/nrwl/nx-cons...
Step Security report:
www.stepsecurity.io/blog/nx-cons...
2 days ago
0
4
2
Microsoft has open-sourced RAMPART, an agent test framework for encoding adversarial and benign scenarios as repeatable tests that can run in a CI/CD
www.microsoft.com/en-us/securi...
loading . . .
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow | Microsoft Security Blog
The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing...
https://www.microsoft.com/en-us/security/blog/2026/05/20/introducing-rampart-and-clarity-open-source-tools-to-bring-safety-into-agent-development-workflow/
2 days ago
0
9
3
reposted by
Catalin Cimpanu
Kat Tenbarge
3 days ago
I see his point. Zero times two is still zero.
add a skeleton here at some point
19
1008
151
reposted by
Catalin Cimpanu
The New York Times
3 days ago
Breaking News: James Murdoch is buying New York magazine, Vox Media’s podcast network and the Vox website for more than $300 million, a dramatic expansion in U.S. media for the younger son of the media mogul Rupert Murdoch.
loading . . .
James Murdoch Buys Half of Vox Media
The media scion is buying Vox Media’s podcast network, New York magazine and Vox.com for more than $300 million.
https://nyti.ms/4tJW4UM
65
287
317
reposted by
Catalin Cimpanu
Gravel Influencer
3 days ago
Fresh new American dystopia headline just dropped
www.thegamer.com/grammacracke...
8
6594
2213
Chinese SMS Blaster Scammer Attacks Eurovision in Vienna
commsrisk.com/chinese-sms-...
2 days ago
0
5
0
Oh.... they already did it to Google Docs... where copy-pasting text is now a chore thanks to their stupid AI trying to hijack everything
add a skeleton here at some point
2 days ago
1
16
7
A malicious npm package is delivering the Coruna iOS exploit kit Yes, that Coruna exploit kit! From Operation Triangulation
safedep.io/art-template...
loading . . .
art-template npm Hijack Delivers iOS Browser Exploit Kit
art-template versions 4.13.3 through 4.13.6 were compromised via maintainer account takeover. The browser bundle injects scripts that deliver a full iOS exploit kit: WebAssembly type confusion, JIT he...
https://safedep.io/art-template-npm-supply-chain-compromise/
2 days ago
0
17
6
The Drupal security update is out It's an SQLi that apparently impacts 5% of all Drupal sites out there Most Drupal sites are also impacted by other security issues from Symfony and Twig, which Drupal also uses
www.drupal.org/sa-core-2026...
3 days ago
0
7
4
The Drupal patches for that security bug will soon be out:
x.com/drupalsecuri...
They are apparently related to Symfony issues:
github.com/symfony/symf...
loading . . .
Releases · symfony/symfony
The Symfony PHP framework. Contribute to symfony/symfony development by creating an account on GitHub.
https://github.com/symfony/symfony/releases
3 days ago
1
1
1
reposted by
Catalin Cimpanu
-Microsoft takes down MSaaS used by ransomware gangs -CISA contractor leaks GovCloud keys -Vulnerability exploitation is now the dominant entry vector -Drupal readies security updates for "highly critical" bug Podcast:
risky.biz/RBNEWS566/
Newsletter:
news.risky.biz/risky-bullet...
3 days ago
1
11
9
reposted by
Catalin Cimpanu
-Huawei zero-day behind Post Luxembourg hack -ChimeraZ targets France -RXNT breach impacts Congress -7-Eleven confirms breach -Musk loses OpenAI lawsuit -Twitter limits visibility for non-paying users -Discord rolls out E2EE -Red Hat releases Hardened Images -Firefox 151 is out -Telcos form new ISAC
3 days ago
1
4
3
reposted by
Catalin Cimpanu
liz ten eleven
4 days ago
LOL GITHUB BREACH
8
82
22
reposted by
Catalin Cimpanu
Ron Deibert
3 days ago
Demo of a Chinese 🇨🇳 video surveillance system that purports to track all foreign visitors, including journalists, integrating video feeds with other data (e.g., pictures from ski passes) to conduct mass surveillance and social network analysis 👇 The new normal...
open.substack.com/pub/netaskar...
loading . . .
Sharp Eyes: Mass surveillance of foreigners in China - Part 1
A publicly exposed web front reveals new details on a tracking system for foreigners and delivers many insight into the capabilities of security organs to track individuals in real time.
https://open.substack.com/pub/netaskari/p/sharp-eyes-how-to-track-a-foreigner?r=6xklz&utm_campaign=post-expanded-share&utm_medium=web
1
24
21
-Microsoft takes down MSaaS used by ransomware gangs -CISA contractor leaks GovCloud keys -Vulnerability exploitation is now the dominant entry vector -Drupal readies security updates for "highly critical" bug Podcast:
risky.biz/RBNEWS566/
Newsletter:
news.risky.biz/risky-bullet...
3 days ago
1
11
9
SGLang fails to patch another set of security flaws after it also failed to patch bugs at the end of April
kb.cert.org/vuls/id/777338
4 days ago
0
0
0
People should start treating Google Search as IE ...as a useless product and stop using it
add a skeleton here at some point
4 days ago
1
19
6
Load more
feeds!
log in