Catalin Cimpanu
@campuscodi.risky.biz
📤 12436
📥 437
📝 3667
☆ Cybersecurity reporter ★ Newsletters at Risky Business
#infosec
#cybersecurity
https://risky.biz
Got to this point really fast, didn't it. Time sure flies by
add a skeleton here at some point
33 minutes ago
1
8
1
lol
add a skeleton here at some point
about 3 hours ago
0
5
1
reposted by
Catalin Cimpanu
⸻realhackhistory.org
about 13 hours ago
Doing my best “first I’m hearing of this” face for this story of a carding biathlon star.
www.espn.co.uk/olympics/sto...
loading . . .
French biathlon star Simon gets suspended ban for stealing
Biathlon star Julia Simon will be allowed to compete at next year's Winter Olympics after receiving a six-month ban, including five months suspended, for stealing money from a teammate.
https://www.espn.co.uk/olympics/story/_/id/46875500/french-biathlon-star-simon-gets-suspended-ban-stealing
1
3
2
reposted by
Catalin Cimpanu
WeRateDogs
about 24 hours ago
we need to talk about that Ring Super Bowl ad
loading . . .
907
29012
14537
reposted by
Catalin Cimpanu
Steven Nelson
2 days ago
If Bad Bunny can cover the history of Puerto Rico, colonialism, transatlantic slavery, hemispheric consciousness, as well as contemporary life and politics in under 14 minutes, you can do your 15- or 20-minute conference presentation with time to spare.
48
2818
659
This seems like a stupid hill for the IOC to die on
add a skeleton here at some point
about 6 hours ago
2
14
4
tl;dr: the ketamine he took at the Super Bowl has produced its effects
add a skeleton here at some point
about 6 hours ago
2
5
1
reposted by
Catalin Cimpanu
-Chinese APT breached all of Singapore's telcos -Microsoft announces two new security features -Hacktivist scrapes stalkerware provider -GRU info-op troops unmasked based on their medals -Russia restricts Telegram again Newsletter:
news.risky.biz/risky-bullet...
Podcast:
risky.biz/RBNEWS524/
about 10 hours ago
2
20
11
reposted by
Catalin Cimpanu
-Nigeria to publish a cybersecurity framework -US Air Force bans smart glasses -Morele hacker arrested after 8 years -JokerOTP dev arrested in the Netherlands -Russia grants political asylum to Spanish professor who helped NoName057 -Crypto scammer sentenced to 20y -US charges FanDuel fraudsters
about 10 hours ago
1
6
1
reposted by
Catalin Cimpanu
Kate from Kharkiv
1 day ago
Russia started throttling Telegram today, and the whining from their war propaganda bloggers is so rich. 😂
11
242
51
reposted by
Catalin Cimpanu
PJ Harvey Dent
1 day ago
6
7714
1525
Don't hold your breadth
about 8 hours ago
2
18
5
-Chinese APT breached all of Singapore's telcos -Microsoft announces two new security features -Hacktivist scrapes stalkerware provider -GRU info-op troops unmasked based on their medals -Russia restricts Telegram again Newsletter:
news.risky.biz/risky-bullet...
Podcast:
risky.biz/RBNEWS524/
about 10 hours ago
2
20
11
The developer of the JokerOTP phishing kit was arrested in the Netherlands today
www.politie.nl/nieuws/2026/...
about 23 hours ago
0
8
1
reposted by
Catalin Cimpanu
tlansec
8 days ago
You say "Security Feature Bypass"... I say.... "Remote Code Execution":
msrc.microsoft.com/update-guide...
loading . . .
Security Update Guide - Microsoft Security Response Center
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
1
12
6
reposted by
Catalin Cimpanu
Palomacy Pigeon & Dove Adoptions
6 days ago
Graphic by Nancy Chiu, for anyone who has a female bird. I’ve sent this to people, I’ve printed it out for vet clinics, & I want to share it here. This is not *instead of* a vet, but it’s helpful while waiting for an appointment. Thank you 4 ever, Nancy! Your art is saving lives!
www.nancychiu.com
1
18
5
reposted by
Catalin Cimpanu
AJ Vicens
2 days ago
"As AI enters the operating room, reports arise of botched surgeries and misidentified body parts"
www.reuters.com/investigatio...
loading . . .
As AI enters the operating room, reports arise of botched surgeries and misidentified body parts
Medical device makers have been rushing to add AI to their products. While proponents say the new technology will revolutionize medicine, regulators are receiving a rising number of claims of patient ...
https://www.reuters.com/investigations/ai-enters-operating-room-reports-arise-botched-surgeries-misidentified-body-2026-02-09/
1
12
12
reposted by
Catalin Cimpanu
780th Military Intelligence Brigade (Cyber)
7 days ago
How the Kremlin drafted Russia's hackers to attack the West Kyiv Independent
kyivindependent.com/how-russian-...
@kyivindependent.com
loading . . .
How the Kremlin drafted Russia's hackers to attack the West
Muleshoe, population 5,000, sits in the Texas Panhandle, next to the New Mexico state line, and about as far away from Ukraine as anywhere can be. A small, arid town linked to the outside world by a ...
https://kyivindependent.com/how-russian-spies-revived-local-hacker-gangs-to-attack-ukraine-and-the-west/
0
2
1
EU approves Google's acquisition of Wiz
ec.europa.eu/commission/p...
loading . . .
Commission approves Google\'s acquisition of Wiz
The European Commission has unconditionally approved, under the EU Merger Regulation, the proposed acquisition by Google of Wiz. The Commission concluded that the transaction would raise no competitio
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_333
1 day ago
0
3
2
reposted by
Catalin Cimpanu
Zack Whittaker
2 days ago
SCOOP: A hacktivist has scraped more than half a million payment records from a company that makes consumer-grade spyware and other phone tracking apps, exposing customers' email addresses and partial card numbers. TechCrunch verified the scraped data is authentic. By
@lorenzofb.bsky.social
and me:
loading . . .
Exclusive: Hacktivist scrapes over 500,000 stalkerware customers' payment records
More than half-a-million people who bought access to phone surveillance and social media snooping apps had their email address and partial payment card numbers published online.
https://techcrunch.com/2026/02/09/hacktivist-scrapes-over-500000-stalkerware-customers-payment-records/
0
31
21
reposted by
Catalin Cimpanu
Karl Bode
2 days ago
I finally have a newsletter! It's called The Fine Print* and I'll be writing about tech, media, politics, consumer rights (and whatever else I damn-well please). It's free, but if you have disposable income, you can support independent reporting for just $50/year or $4/month.
loading . . .
The Fine Print*
A newsletter by Karl Bode covering tech, media, politics, and consumer rights.
https://karlbode.com/
18
245
72
reposted by
Catalin Cimpanu
Preeti Chhibber
2 days ago
omg everybody go draw a horse this is what the internet was made for
gradient.horse
loading . . .
gradient.horse
Draw a horse, watch it run!
https://gradient.horse/
35
6835
3685
reposted by
Catalin Cimpanu
Ben Phillips
3 days ago
Plans to invade Greenland have just been cancelled after this
loading . . .
143
6403
2538
Thread
add a skeleton here at some point
1 day ago
0
3
1
Yet Durov is too busy complaining about mAcRoN & eU cEnSoRsHiP to even notice
add a skeleton here at some point
1 day ago
0
13
2
Has anyone looked if the Notepad++ and EmEditor incidents are related in any way?
1 day ago
1
8
0
An Orange Cyberdefense report concludes that hacktivism has evolved from a form of digital protest into the realm of hybrid warfare
www.orangecyberdefense.com/global/blog/...
1 day ago
2
10
6
Google Cloud has published a report looking at all the threat actors targeting companies in the Defense Industrial Base. The report goes over the main groups from all major foreign adversaries and what their main focus has been over the past decade
cloud.google.com/blog/topics/...
1 day ago
1
13
10
A US judge has sentenced a Chinese national to 20 years in prison for laundering funds from Cambodian cyber scam compounds That's the maximum sentence, btw
www.justice.gov/opa/pr/man-s...
loading . . .
Man Sentenced to 20 Years in Prison for Role in $73 Million Global Cryptocurrency Investment Scam
A dual national of China and St. Kitts and Nevis was sentenced in absentia today in the Central District of California to the statutory maximum of 20 years in prison and three years of supervised rele...
https://www.justice.gov/opa/pr/man-sentenced-20-years-prison-role-73-million-global-cryptocurrency-investment-scam
1 day ago
0
5
0
New report claims that after a close Orban ally bought Euronews, the TV network turned into a propaganda machine for autocratic regimes
www.euractiv.com/news/inside-...
loading . . .
Inside Euronews: How Europe’s broadcaster became an influence network | Euractiv
Conceived as Europe’s answer to CNN, the EU-funded channel has become a platform for authoritarian regimes
https://www.euractiv.com/news/inside-euronews-how-europes-broadcaster-became-an-influence-network/
1 day ago
0
17
6
reposted by
Catalin Cimpanu
Barry Dorrans
1 day ago
Would never ask you to verify your age
4
151
23
reposted by
Catalin Cimpanu
Conignis
1 day ago
That wasn't the main objection. The main objection was loss of functionality: things like you can't create you own filters in MV3 and filter lists can't be updated in real time independent of the extension.
0
2
1
New academic research has found that Chrome's new MV3 extension API is not that bad after all "Ad blocker providers appear to have successfully navigated the MV3 update, finding solutions that maintain the core functionality of their extensions"
petsymposium.org/popets/2026/...
1 day ago
2
5
0
reposted by
Catalin Cimpanu
the garbage store boy
2 days ago
Wikipedia should release an Amazon Alexa like device that is just hooked up to Wikipedia, the NOAA weather APIs, and a few music services. No spyware. This shit would sell like hotcakes
1
12
2
reposted by
Catalin Cimpanu
Chesterville🌲
2 days ago
No one should have to explain that anti-cheat in a pve game is effectively malware
1
16
6
Substack breach impacted 663,000 accounts, but appears to be a scrape of public data... so not a big deal at all
haveibeenpwned.com/Breach/Subst...
loading . . .
Have I Been Pwned: Substack Data Breach
In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email ...
https://haveibeenpwned.com/Breach/Substack
2 days ago
0
7
2
Security firm Defused has spotted a coordinated campaign from an initial access broker that is targeting the recent Ivanti EPMM zero-days
defusedcyber.com/ivanti-epmm-...
loading . . .
Sleeper Shells: How Attackers Are Planting Dormant Backdoors in Ivanti EPMM
A February 2026 campaign used a internal JSP path and in-memory Java class loaders to quietly seed persistent access across Ivanti EPMM deployments - then walked away. We break down the tradecraft.
https://defusedcyber.com/ivanti-epmm-sleeper-shells-403jsp
2 days ago
0
4
2
reposted by
Catalin Cimpanu
Patrick Gray
2 days ago
Does anyone know why Charlie Bell was shifted out of security at Microsoft and replaced by someone with a background in sales? What does this mean for Microsoft's "Secure Future Initiative"? I'm riskybusiness.01 on Signal
blogs.microsoft.com/blog/2026/02...
loading . . .
Updates in two of our core priorities - The Official Microsoft Blog
Satya Nadella, Chairman and CEO, posted the below message to employees on Viva Engage this morning. I am excited to share a couple updates in two of our core priorities: security and quality. Hayete G...
https://blogs.microsoft.com/blog/2026/02/04/updates-in-two-of-our-core-priorities/
4
17
6
reposted by
Catalin Cimpanu
Oleg Shakirov
2 days ago
Singapore takes another step in the public attribution game linking UNC3886 to attacks on 4 telcos. The report includes a description w/ few technical details Incident response involved >100 defenders making it the largest such operation for Singapore
www.csa.gov.sg/news-events/...
0
1
1
reposted by
Catalin Cimpanu
Nerd House
2 days ago
@discord.com
Ya'll got some BALLS. Iron, steel, maybe even adamantium or vibranium! Implementing requiring ID when you had a MAJOR data breach just months ago...you should really be focusing on security instead.
cybersecuritynews.com/discord-data...
www.theverge.com/tech/875309/...
loading . . .
Discord Data Breach - 1.5 TB of Data and 2 Million Government ID Photos Extorted
Discord has confirmed a significant data breach that exposed sensitive user information after an attacker compromised a third-party customer service provider.
https://cybersecuritynews.com/discord-data-breach-sensitive-data/
1
26
14
Yeah.... how about no Back to TeamSpeak we go... 🤣
add a skeleton here at some point
2 days ago
0
16
4
Hey
#pigeonsky
.... we have another member
add a skeleton here at some point
2 days ago
0
10
0
reposted by
Catalin Cimpanu
InfoSecSherpa 🏔️
2 days ago
Article: "Is Babuk Back? 🫣 Uncovering the Truth Behind Babuk Locker 2.0" by Umut Bayram from Picus Security - February 3, 2026.
cybersec.picussecurity.com/s/is-babuk-b...
0
0
2
reposted by
Catalin Cimpanu
jon greig
6 days ago
Substack got hacked but they are being tightlipped about how the breach occurred or if they were ever offered a ransom. Its unclear how many people were impacted
therecord.media/substack-dat...
loading . . .
Substack warns customers of data breach following hacker’s dark web claims
Customers of the newsletter platform Substack were notified on Wednesday of a breach, following a hacker's claims on the dark web of a trove of stolen data.
https://therecord.media/substack-data-breach-notification
0
4
3
reposted by
Catalin Cimpanu
Active Measures, LLC
2 days ago
FSB putting the word out on the street it costs less than a Kia Sorento to murder the deputy head of the GRU
5
184
35
reposted by
Catalin Cimpanu
gnida project
2 days ago
Very interesting material by
@checkfirst.network
, which has a big potential for real world applications
add a skeleton here at some point
1
17
11
reposted by
Catalin Cimpanu
Kevin Collier
2 days ago
Whenever I hear stuff like this about conservative outlets, I think of personal friends who are absolutely baffled when I tell them I've never gotten a directive to avoid any topics relevant to my beat and that it would be an incredible affront if I did.
add a skeleton here at some point
3
33
6
reposted by
Catalin Cimpanu
-SmarterTools hacked via its own product -Dutch DPA and European Commission hacked via Ivanti zero-days -Senegal held for ransom -state actor behind Signal phishing campaign in Germany -Flickr 3rd party breach Podcast:
risky.biz/RBNEWS523/
Newsletter:
news.risky.biz/risky-bullet...
2 days ago
1
14
7
reposted by
Catalin Cimpanu
-China executes scam compound execs -DDoSer arrested in Poland -Northwestern hacker pleads guilty -Nigerian scammer gets 8 years -Profiles on DSLRoot and GhostSocks profile, two proxy services -DKIM replay attacks in the wild -17% of OpenClaw skills are malicious -ClawHub to scan skills using VT
2 days ago
1
8
3
reposted by
Catalin Cimpanu
Dave Lee
3 days ago
Ai.com
spent god knows how much on their Super Bowl ad, and….
7
111
30
Load more
feeds!
log in