Catalin Cimpanu
@campuscodi.risky.biz
📤 12259
📥 431
📝 3453
☆ Cybersecurity reporter ★ Newsletters at Risky Business
#infosec
#cybersecurity
https://risky.biz
reposted by
Catalin Cimpanu
Zack Whittaker
1 day ago
NEW, by me: Uzbekistan publicly exposed its nationwide license plate surveillance system, no password needed. The system reveals a hundred locations where banks of cameras have been placed, including cities and rural areas; and contains raw video footage of millions of vehicles and their occupants.
loading . . .
Exclusive: Inside Uzbekistan's nationwide license plate surveillance system
The Uzbek government's national license plate scanning system was discovered exposed to the internet for anyone to access without a password.
https://techcrunch.com/2025/12/23/inside-uzbekistans-nationwide-license-plate-surveillance-system/
2
52
28
The US DOJ has seized web3adspanels[.]org, a website that served as a backend database for collecting phished credentials. The site primarily stored banking logins collected through phishing pages promoted via malicious search ads
www.justice.gov/opa/pr/justi...
about 15 hours ago
0
4
0
The South Korean government is running a trial and has mandated that all individuals undergo a mandatory facial recognition scan before receiving a new mobile phone number
koreajoongangdaily.joins.com/news/2025-12...
loading . . .
Korea begins trial of mandatory face recognition for new mobile numbers
Korea on Tuesday launched a trial period for a new policy requiring people to undergo real-time face recognition when registering a new mobile phone number, as the government aims to curb scam attempt...
https://koreajoongangdaily.joins.com/news/2025-12-23/business/industry/Korea-begins-trial-of-mandatory-face-recognition-for-new-mobile-numbers/2484371
about 16 hours ago
1
4
7
The White House has formally nominated Army Lt. Gen. Joshua Rudd as the next head of Cyber Command and the US National Security Agency. Gen. Rudd is currently serving as deputy chief of US Indo-Pacific Command
www.nextgov.com/people/2025/...
loading . . .
Trump formally taps Joshua Rudd to lead NSA, Cyber Command
The nomination marks a turning point for the electronic surveillance and hacking teams that have been without a permanent leader for eight months.
https://www.nextgov.com/people/2025/12/trump-formally-taps-joshua-rudd-lead-nsa-cyber-command/410266/
about 16 hours ago
1
4
5
The EU and the UK have renewed a deal to allow free data transfers between the EU bloc and the UK for six more years
ec.europa.eu/commission/p...
loading . . .
Commission renews decisions to allow for the free and safe flow of personal data with the UK
Today, the Commission renewed the two 2021 adequacy decisions for the free flow of personal data with the United Kingdom.
https://ec.europa.eu/commission/presscorner/detail/en/ip_25_3059
about 16 hours ago
0
5
1
reposted by
Catalin Cimpanu
Darth Putin
about 20 hours ago
American social media platforms are banned in Russia. Have you noticed Donald isn't sanctioning anyone over that?
37
1683
541
reposted by
Catalin Cimpanu
Kate Starbird
1 day ago
Nina Jankowicz: “They’re not doing this because they have any evidence of censorship — they lost a Supreme Court case that made those claims… They’re doing this because the group of researchers and advocates have stood up to liars like Donald Trump and the platforms that enable them.”
add a skeleton here at some point
11
1133
468
reposted by
Catalin Cimpanu
AC Shadows: done! ✅
about 19 hours ago
1
7
1
reposted by
Catalin Cimpanu
Dave Keating
1 day ago
It begins. The EU lawmaker who was in charge of digital affairs during 🇪🇺President von der Leyen's first term has been banned from entering the United States, because the 🇺🇸 tech giants and government don't like the EU's tech laws. What will be the 🇪🇺President's response?
loading . . .
Former EU commissioner and activists barred from US in attack on European tech regulators
State department accuses group of pressuring tech firms to censor or suppress American viewpoints through regulation of disinformation
https://www.theguardian.com/technology/2025/dec/24/us-state-department-visa-ban-former-eu-commissioner-europe
19
219
129
reposted by
Catalin Cimpanu
Don Moynihan
1 day ago
The American government is banning regulators from other countries at the request of the richest man in the world, in a display that confirms they will punish any country not willing to sell their digital sovereignty as cheaply as the US has
www.nytimes.com/2025/12/23/t...
loading . . .
U.S. Bars 5 European Tech Regulators and Researchers
https://www.nytimes.com/2025/12/23/technology/trump-rubio-european-tech-disinformation-digital-services-act.html
11
491
222
reposted by
Catalin Cimpanu
Casey Newton
1 day ago
The US just banned a guy from the country (Imran Ahmed) for pointing out that X is full of hate speech
add a skeleton here at some point
5
204
77
reposted by
Catalin Cimpanu
Lorenzo Franceschi-Bicchierai
1 day ago
What's up with all these "secret location" Barcelona offensive cybersecurity conferences?
6
11
3
Russia is looking to ban Call of Duty
www.gazeta.ru/social/news/...
loading . . .
https://www.gazeta.ru/social/news/2025/12/10/27376129.shtml
2 days ago
4
4
2
reposted by
Catalin Cimpanu
Steve Herman
3 days ago
Politico - At least six career staffers at the Cybersecurity and Infrastructure Security Agency were suspended with pay this summer after organizing a polygraph test that the agency’s acting director, Madhu Gottumukkala, failed.
www.politico.com/news/2025/12...
loading . . .
Acting CISA director failed a polygraph. Career staff are now under investigation.
At least six career staff were placed on leave after DHS opened an investigation into whether they misled the agency’s acting director, Madhu Gottumukkala, into taking the test.
https://www.politico.com/news/2025/12/21/cisa-acting-director-madhu-gottumukkala-polygraph-investigation-00701996?utm_source=dlvr.it&utm_medium=twitter
11
301
162
reposted by
Catalin Cimpanu
Firefox for Web Developers
7 days ago
Something that hasn't been made clear: Firefox will have an option to completely disable all AI features. We've been calling it the AI kill switch internally. I'm sure it'll ship with a less murderous name, but that's how seriously and absolutely we're taking this. …
77
573
253
A ransomware attack has hit ANAR, Romania's water management agency. The incident impacted over 1,000 systems, such as Windows workstations, GIS servers, and databases.
romania.europalibera.org/a/apele-roma...
loading . . .
Apele Române, supuse unui atac cibernetic major. Atacatorii cer bani pentru repornirea sistemelor
Administrația Națională „Apele Române” (ANAR) și zece administrații bazinale de apă din țară au fost vizate de un atac cibernetic de tip ransomware care a afectat aproximativ 1.000 de sisteme informat...
https://romania.europalibera.org/a/apele-romane-atac-cibernetic/33629322.html
3 days ago
1
7
2
reposted by
Catalin Cimpanu
780th Military Intelligence Brigade (Cyber)
6 days ago
Amazon Caught North Korean IT Worker By Tracing Keystroke Data |
www.bloomberg.com/news/newslet...
@bloomberg.com
loading . . .
Amazon Caught North Korean IT Worker By Tracing Keystroke Data
Security personnel tracked connections from a contractor.
https://www.bloomberg.com/news/newsletters/2025-12-17/amazon-caught-north-korean-it-worker-by-tracing-keystroke-data
0
7
5
reposted by
Catalin Cimpanu
Sherwood News
10 days ago
$10 billion of investment. Code names to disguise projects and companies. Mixed opinions. Skyrocketing property values. And enough tax breaks to pay every state cop in Louisiana for seven years.
https://sherwood.news/tech/hyperion/
loading . . .
The power play behind Hyperion, Mark Zuckerberg’s colossal data center being built in rural Louisiana
$10 billion of investment. Code names to disguise projects and companies. Mixed opinions. Skyrocketing property values. And enough tax breaks...
https://sherwood.news/tech/hyperion/
0
6
3
reposted by
Catalin Cimpanu
Zack Whittaker
5 days ago
Are you a security researcher or journalist? We want to hear from you — please take this survey! Dissent Doe at
DataBreaches.net
, and yours truly at
this.weekinsecurity.com
, are running this survey to explore the state of legal demands and criminal threats in cybersecurity.
loading . . .
Survey about legal and criminal threats experienced by journalists and security researchers
Researchers who try to responsibly disclose leaks, vulnerabilities, and other security breaches or mishaps may face legal threats or lawsuits. Similarly, journalists may find themselves threatened wit...
https://forms.gle/vENo7Znh1wdUAxpe6
2
22
28
reposted by
Catalin Cimpanu
Gary Whitta
5 days ago
Incredible words from real boxer Anthony Joshua after he knocked Jake Paul the fuck out lol
108
8347
2007
Russia is responsible for destructive and disruptive cyberattacks against Denmark PDF:
www.fe-ddis.dk/globalassets...
loading . . .
https://www.fe-ddis.dk/globalassets/fe/dokumenter/2025/-russia-responsible-for-cyber-attacks-.pdf
6 days ago
1
16
5
reposted by
Catalin Cimpanu
-Belarus deploys spyware on journalists' phones -Suspect arrested for installing malware on ferry boat -France arrests Interior Ministry hacker -new Cisco and SonicWall zero-days -DPRK stole $2b this year Podcast:
risky.biz/RBNEWS510/
Newsletter:
news.risky.biz/risky-bullet...
6 days ago
2
11
3
reposted by
Catalin Cimpanu
-Former Israeli PM hacked -FTC orders Nomad Bridge to return user funds -TikTok reported for tracking users across the web -US still Tor's biggest sponsor -Russia also explores social media ban for kids -MIVD makes cyber takedowns a priority -Dutch police arrests deepfake scammer
6 days ago
1
4
1
reposted by
Catalin Cimpanu
-US seizes E-Note exchange -India dismantles SMS factory -17 malicious Firefox add-ons -Google sues Darcula PhaaS -Device-code phishing activity surges -New Kimwolf botnet infets 1.83m deviecs -RansomHouse uses double encryption -Malware reports on Stealka, AuraStealer, CountLoader, GachiLoader
6 days ago
1
3
1
reposted by
Catalin Cimpanu
The Shadowserver Foundation
6 days ago
We added fingerprinting of Fortinet devices with FortiCloud SSO enabled to our Device Identification reporting (at least 25K IPs seen globally). While not necessarily vulnerable to CVE-2025-59718/CVE-2025-59719 if you get a report from us regarding exposure, please verify/patch!
2
16
8
reposted by
Catalin Cimpanu
Tuffy
6 days ago
I’m old enough to remember when coinbase argued it was outside of federal securities regulators’ purview
add a skeleton here at some point
3
55
14
-Belarus deploys spyware on journalists' phones -Suspect arrested for installing malware on ferry boat -France arrests Interior Ministry hacker -new Cisco and SonicWall zero-days -DPRK stole $2b this year Podcast:
risky.biz/RBNEWS510/
Newsletter:
news.risky.biz/risky-bullet...
6 days ago
2
11
3
reposted by
Catalin Cimpanu
evacide
6 days ago
The US TikTok sale has been signed. The company will be controlled by a joint venture including Oracle, Silver Lake, Andreessen Horowitz, Abu Dhabi-based MGX. Adding a UAE company really makes it clear that this was never about national security concerns.
www.axios.com/2025/12/18/t...
loading . . .
Scoop: TikTok signs deal for sale of U.S. unit after yearslong saga
The deal would end a yearslong saga to force TikTok's Chinese parent ByteDance to sell the company's U.S. operation.
https://www.axios.com/2025/12/18/tiktok-sale
94
2984
1357
A Washington Times report claims that the alleged NSA hack of China's National Time Service Center might be an attempted US ploy to disrupt Chinese missile launches in the event of a military conflict
www.washingtontimes.com/news/2025/de...
loading . . .
Hack of Chinese state time center hints at U.S. advanced missile defense
China’s Ministry of State Security intelligence service disclosed in October that the U.S. National Security Agency has been engaged in a three-year cyber campaign to break into the official National ...
https://www.washingtontimes.com/news/2025/dec/17/hack-chinese-state-time-center-hints-us-advanced-missile-defense/
7 days ago
0
5
3
Looks like the Aisuru botnet group created another botnet named Kimwolf that they are now using for DDoS attacks -1.83m infected systems -most are Android devices -uses EtherHiding and Tor
blog.xlab.qianxin.com/kimwolf-botn...
loading . . .
Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices
Background On October 24, 2025, a trusted partner in the security community provided us with a brand-new botnet sample. The most distinctive feature of this sample was its C2 domain, 14emeliaterrace...
https://blog.xlab.qianxin.com/kimwolf-botnet-en/
7 days ago
0
4
0
The US government has remained the Tor Project's largest sponsor despite the organization's efforts to diversify its funding. The project raised $7.3 million last year, of which, $2.5 million came from the US government.
blog.torproject.org/financials-b...
7 days ago
0
8
3
reposted by
Catalin Cimpanu
Mark Kelly
7 days ago
New espionage/e-crime crossover blog from the team on the continued rise of device code phishing by state-aligned and financially motivated groups.
add a skeleton here at some point
1
7
3
Chinese APTs and their parent MSS bureau
nattothoughts.substack.com/p/the-many-a...
7 days ago
0
7
1
The ForumTroll cyber-espionage group has targeted political experts and scholars working at major Russian universities and research institutions This is the group that deployed Memento Labs' (HackingTeam) Dante spyware earlier this year via Chrome zero-days
securelist.com/operation-fo...
loading . . .
A new campaign by the ForumTroll APT group
Kaspersky's GReAT experts have uncovered a new wave of cyberattacks by the ForumTroll APT group, targeting Russian political scientists and delivering the Tuoni framework to their devices.
https://securelist.com/operation-forumtroll-new-targeted-campaign/118492/
7 days ago
0
0
0
SafeBreach has uncovered new operations from an Iranian hacking group tracked as Prince of Persia and Infy, which it was believed to have ceased activity back in 2022
www.safebreach.com/blog/prince-...
loading . . .
Unmasking the Evolving Iranian Prince of Persia | SafeBreach
New research unmasks the evolving Iranian "Prince of Persia" APT, detailing new Tonnerre v50 malware, C2 shift to Telegram, and increased scale.
https://www.safebreach.com/blog/prince-of-persia-a-decade-of-an-iranian-nation-state-apt-campaign-activity
7 days ago
0
1
1
reposted by
Catalin Cimpanu
Slashdot
8 days ago
Senators Count the Shady Ways Data Centers Pass Energy Costs On To Americans
https://hardware.slashdot.org/story/25/12/17/036250/senators-count-the-shady-ways-data-centers-pass-energy-costs-on-to-americans?utm_source=rss1.0mainlinkanon&utm_medium=feed
loading . . .
Senators Count the Shady Ways Data Centers Pass Energy Costs On To Americans
U.S. senators are probing whether Big Tech data centers are driving up local electricity bills by socializing grid upgrade costs onto residents. Some of the tactics they're using include NDAs, shell companies, and lobbying. Ars Technica reports: In letters (PDF) to seven AI firms, Senators Elizabet...
https://hardware.slashdot.org/story/25/12/17/036250/senators-count-the-shady-ways-data-centers-pass-energy-costs-on-to-americans?utm_source=rss1.0mainlinkanon&utm_medium=feed
0
8
5
reposted by
Catalin Cimpanu
780th Military Intelligence Brigade (Cyber)
7 days ago
Google sues alleged Chinese scam group behind massive U.S. text message phishing ring
www.nbcnews.com/tech/securit...
@nbcnews.com
loading . . .
Google sues Chinese scam ring over E-ZPass and USPS phishing texts
Google says the group’s tools enabled scammers with little technical skill to impersonate agencies like the IRS and the USPS at a massive scale.
https://www.nbcnews.com/tech/security/google-sues-chinese-scam-ring-e-zpass-usps-phishing-texts-rcna249469
2
3
1
The RansomHouse ransomware group is now using two keys to encrypt files
unit42.paloaltonetworks.com/ransomhouse-...
loading . . .
From Linear to Complex: An Upgrade in RansomHouse Encryption
Operators behind RansomHouse, a ransomware-as-a-service (RaaS) group, have upgraded their encryption methods from single-phase to complex and layered.
https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/
7 days ago
0
1
0
reposted by
Catalin Cimpanu
Karl Bode
7 days ago
I'd like you to notice how while Carr was dragged before Congress yesterday to address his ham-fisted attempts to censor a comedian, NOBODY asked him ANY questions about his efforts to completely destroy consumer protection and media consolidation limits. The press couldn't care less, either.
loading . . .
F.C.C. Chair Says Agency ‘Isn’t Independent,’ Breaking From Tradition
https://www.nytimes.com/2025/12/17/technology/fcc-brendan-carr-senate-hearing.html
11
433
133
DataDog has launched
pathfinding.cloud
, a database of IAM permissions and permission sets that allow privilege escalation in AWS.
pathfinding.cloud
7 days ago
0
3
1
reposted by
Catalin Cimpanu
ESET Research
7 days ago
#ESETresearch
has discovered a new 🇨🇳-aligned APT group,
#LongNosedGoblin
. This group focuses on cyberespionage and targets mainly governmental entities in Southeast Asia and Japan.
www.welivesecurity.com/en/eset-rese...
1/7
loading . . .
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions.
https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/
1
6
7
The DomainTools security team looks at recent APT35 leaks showing how the group operates with extreme government oversight and bureaucracy, rather than a group of loose canon hackers
dti.domaintools.com/the-apt35-du...
loading . . .
The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation - DomainTools Investigations | DTI
APT35/Charming Kitten's leaked documents expose the financial machinery behind state-sponsored hacking. Learn how bureaucracy, crypto micro-payments, and administrative ledgers sustain Iranian cyber o...
https://dti.domaintools.com/the-apt35-dump-episode-4-leaking-the-backstage-pass-to-an-iranian-intelligence-operation/
7 days ago
0
8
6
reposted by
Catalin Cimpanu
Randall Gross
7 days ago
Russia is following the Pakistani model of disruption and destabilization in Europe, using proxies and spinning up the crazies to attack the EU. AP has a map
apnews.com/projects/rus...
loading . . .
Russia wants to drain Europe's security resources with sabotage campaign, officials say | AP News
The Associated Press has tracked 145 cases of sabotage and disruption that Western officials blame on Russia since its 2022 invasion of Ukraine. They say Moscow wants to drain Europe’s investigative r...
https://apnews.com/projects/russian-europe-sabotage/
2
112
45
A Latvian crew member was detained for installing a RAT on an Italian ferry
add a skeleton here at some point
7 days ago
2
15
5
After a wave of criticism, GitHub has postponed a plan to increase prices for GitHub Actions
github.blog/changelog/20...
loading . . .
Update to GitHub Actions pricing - GitHub Changelog
Update: We’ve read your posts and heard your feedback. We’re postponing the announced billing change for self-hosted GitHub Actions to take time to re-evaluate our approach. We are continuing to…
https://github.blog/changelog/2025-12-16-coming-soon-simpler-pricing-and-a-better-experience-for-github-actions/
7 days ago
0
7
1
Google's Wiz division has awarded $320,000 to security researchers for 11 exploits used during the ZeroDay Cloud hacking contest last week
www.wiz.io/blog/wiz-zer...
7 days ago
0
3
1
French authorities said they arrested the man who hacked their Ministry of Interior email servers. He's a known hacker who was already convicted this year. Anyone has any ideas who this could be? cc:
@gabrielthierry.bsky.social
www.rfi.fr/en/france/20...
loading . . .
France detains suspect over interior ministry cyberattack as probe widens
French authorities have detained a 22-year-old man over a cyberattack on the email servers of the French interior ministry that compromised files containing criminal records. An investigation is under...
https://www.rfi.fr/en/france/20251218-france-detains-suspect-over-interior-ministry-cyberattack-as-probe-widens
7 days ago
1
7
2
Sweet... a SonicWall zero-day to go with that Cisco zero-day right before your Xmas holiday
psirt.global.sonicwall.com/vuln-detail/...
7 days ago
2
9
3
React2Shell used as initial access vector for Weaxor ransomware deployment
www.s-rminform.com/latest-think...
loading . . .
React2Shell used as initial access vector for Weaxor ransomware deployment
S-RM has responded to an incident where a threat actor used the recently disclosed critical vulnerability known as React2Shell (CVE-2025-55182) to gain access to a corporate network and deploy ransomw...
https://www.s-rminform.com/latest-thinking/react2shell-used-as-initial-access-vector-for-weaxor-ransomware-deployment
7 days ago
0
5
2
reposted by
Catalin Cimpanu
Raphael Satter
7 days ago
Big story here and among the many scoops in it is the allegation that China is quietly handing out passports and tolerating dual nationality for specialists recruited to replicate ASML’s EUV machines at a secret factory in Shenzhen.
www.reuters.com/world/china/...
loading . . .
Exclusive: How China built its ‘Manhattan Project’ to rival the West in AI chips
In a high-security Shenzhen laboratory, Chinese scientists have built a prototype of a machine capable of producing cutting-edge semiconductor chips that power artificial intelligence, smartphones and...
https://www.reuters.com/world/china/how-china-built-its-manhattan-project-rival-west-ai-chips-2025-12-17/
0
15
10
Load more
feeds!
log in