Catalin Cimpanu
@campuscodi.risky.biz
📤 12119
📥 422
📝 3214
☆ Cybersecurity reporter ★ Newsletters at Risky Business
#infosec
#cybersecurity
https://risky.biz
reposted by
Catalin Cimpanu
Have I Been Pwned
about 10 hours ago
New sensitive breach: Hungarian political party TISZA suffered a breach of its TISZA Világ platform last month, exposing 200k records, later published online. Data included email, name, phone & physical address. 41% were already in
@haveibeenpwned.com
. More:
haveibeenpwned.com/Breach/Tisza
loading . . .
Have I Been Pwned: TISZA Világ Data Breach
In November 2025, data breached from the Hungarian political party TISZA was extensively redistributed online. Stemming from a compromise of the TISZA Világ service the previous month, the breach expo...
https://haveibeenpwned.com/Breach/Tisza
0
6
7
reposted by
Catalin Cimpanu
ISS Piss Tracker
about 20 hours ago
The piss tank on the ISS is now 61% full.
1
23
8
reposted by
Catalin Cimpanu
Joe Uchill
about 18 hours ago
Not the most important thing, here, but some outlet sent reporter Harry Cockburn to cover swingers on a cruise ship.
add a skeleton here at some point
0
16
6
reposted by
Catalin Cimpanu
Tess
about 17 hours ago
You would get so much XP from clearing this place
add a skeleton here at some point
1
23
1
reposted by
Catalin Cimpanu
NY Times Pitchbot
1 day ago
It is sad, but not surprising, that the president of Mexico is wasting her time on frivolous matters like suing the man who groped her. by Andrew Cuomo
20
2355
211
reposted by
Catalin Cimpanu
mcc
2 days ago
STOP having "conversations" with ChatGPT and START talking to your stuffed animals like a normal person
add a skeleton here at some point
30
5507
2218
reposted by
Catalin Cimpanu
Daniel Gordon
2 days ago
add a skeleton here at some point
1
11
3
reposted by
Catalin Cimpanu
Techmeme
2 days ago
The US Congressional Budget Office says it has identified a security incident; sources say the CBO has been hacked by a suspected foreign actor (Washington Post)
Main Link
|
Techmeme Permalink
0
16
3
reposted by
Catalin Cimpanu
Jake Williams
2 days ago
21st Century Phrenology being sold as actual science.
add a skeleton here at some point
3
45
9
reposted by
Catalin Cimpanu
Sarah Gooding
2 days ago
This is wild. 99% of the code is legit, with just 20 malicious lines buried in thousands of lines of working code. cc:
@campuscodi.risky.biz
add a skeleton here at some point
0
7
6
Someone uploaded malware on NuGet in 2023 that destroys systems in 2027 and 2028 That's quite the long game!!!
socket.dev/blog/9-malic...
2 days ago
0
8
3
Russian authorities have filed charges against a 20-year-old man for deliberately searching the internet for extremist content—Ukraine's Azov battalion. This is Russia's first case for such a crime under a law that entered into effect in September.
ura.news/news/1053030...
loading . . .
«Первый случай в области»: молодого свердловского медика судят по новой статье
Читайте на URA.RU
https://ura.news/news/1053030611
2 days ago
0
6
1
-Top UK mobile carriers will block spoofed phone numbers starting next year -Six telcos to participate -Network upgrades underway -Telcos will mark calls coming from abroad to prevent scams -Also roll out "advanced call tracing technology" to let police hunt down scammers
www.gov.uk/government/n...
loading . . .
Spoofed numbers blocked in crackdown on scammers
Scammers who fake their numbers to trick the public out of their cash will be exposed in a major upgrade of mobile networks.
https://www.gov.uk/government/news/spoofed-numbers-blocked-in-crackdown-on-scammers
2 days ago
1
11
5
Google is rolling out a dedicated form to allow businesses listed on Google Maps to report threat actors who post bad reviews and demand ransoms to remove the negative comments.
blog.google/technology/s...
2 days ago
0
3
4
-Malvertising as entry point -Didn't pay ransom -Recovery cost the state $1.5mil
gov.nv.gov/Newsroom/PRs...
add a skeleton here at some point
2 days ago
2
7
5
Five members of the Bai crime family were sentenced to death this week in China for their role in Myanmar scam compounds
www.spp.gov.cn/spp/zdgz/202...
11 Ming crime family members were sentenced to death in Sep.
www.spp.gov.cn/spp/zdgz/202...
2 days ago
2
5
4
The lede that I and the Yonhap team missed here is that KT apparently hid a second breach from authorities... and they'll likely get fined into the ground, just like SK Telekom South Korean telcos are slowly turning to be some of shadiest companies around
add a skeleton here at some point
2 days ago
1
4
0
This explains why they've been declining to take down anything I reported over the past 2-3 years. This is downright criminal behavior. In any normal country, Zuckerberg would be charged and Meta servers taken offline just like Europol dismantled those scam networks this week
add a skeleton here at some point
2 days ago
2
29
10
reposted by
Catalin Cimpanu
Tim Karr
2 days ago
Meta annually earns $16 billion (with a "b") on ads built to defraud people. It's so bad that Meta itself admits that its advertising tools and platforms have made it a pillar of the global scam economy. Reporting by Reuters.
www.reuters.com/investigatio...
4
104
55
BPFDoor found on the network of hacked South Korean telco KT
en.yna.co.kr/view/AEN2025...
loading . . .
(LEAD) Investigation shows KT concealed malware infections, security failures leading to hacking breach | Yonhap News Agency
(ATTN: UPDATES with more details in paras 14-15; ADDS photo) SEOUL, Nov. 6 (Yonhap) -- K...
https://en.yna.co.kr/view/AEN20251106006051320
2 days ago
0
2
3
Four Pakistani senators have fallen victim to online scammers, losing between $1,700 and $3,000 to schemes requesting money for various projects. The lawmakers blamed the country's cybercrime investigations agency for failing to act and investigate the cases.
tribune.com.pk/story/257611...
loading . . .
Four senators reveal they were targeted by scammers | The Express Tribune
Multiple senators revealed they had been defrauded, sensitive portions of agenda held privately
https://tribune.com.pk/story/2576116/four-senators-reveal-they-were-targeted-by-scammers
2 days ago
0
3
1
reposted by
Catalin Cimpanu
Ian Dunt
3 days ago
Vital piece of investigative reporting from Sky. They've uncovered the X algorithm which feeds users extremist right wing material from the moment they join the site. It is a far-right radicalisation engine, by design.
news.sky.com/story/the-x-...
loading . . .
Elon Musk is boosting the British right - and this shows how
Elon Musk is boosting the British right - and this shows how
https://news.sky.com/story/the-x-effect-how-elon-musk-is-boosting-the-british-right-13464487#
226
5962
3819
reposted by
Catalin Cimpanu
Jeff Horwitz
2 days ago
Meta earns $3.5 billion every six months from showing Faceboon and Instagram users 15 billion “higher legal risk” scam ad impressions a day, internal documents state. That haul vastly exceeds how much the company expects regulators To fine it for running scam ads.
www.reuters.com/investigatio...
loading . . .
https://www.reuters.com/investigations/meta-is-earning-fortune-deluge-fraudulent-ads-documents-show-2025-11-06/
42
1399
800
A South Korean activist specialized in North Korean human rights affairs has been hacked. Hackers infected their PC with malware and then sent malicious links to the target's KakaoTalk contacts. South Korean police suspect a North Korean APT group
koreajoongangdaily.joins.com/news/2025-11...
loading . . .
Human rights activist's computer hacked — possibly by North Koreans
Police are investigating a suspected malware attack linked to a North Korean hacking group after a human rights activist reported their computer had been used to send an infected file to multiple cont...
https://koreajoongangdaily.joins.com/news/2025-11-05/national/socialAffairs/Human-rights-activists-computer-hacked--possibly-by-North-Koreans/2437544
2 days ago
0
4
1
AhnLab looks at the new Cephalus ransomware, a strain first seen in August. The group leverages RDP accounts for initial access and operates a dark web leak site that hasn't been updated in more than two months, suggesting the group might have disbanded already.
asec.ahnlab.com/en/90878/
2 days ago
0
1
2
Proofpoint has spotted a new Iranian APT group—UNK_SmudgedSerpent. The group's TTPs overlap with many other Iranian groups, showing some sort of collaboration, personnel movement, or similar training/contractors.
www.proofpoint.com/us/blog/thre...
loading . . .
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report. Key findings Between June and August 2025,
https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution
2 days ago
0
3
1
Two US senators have introduced a bill that would require US companies and federal agencies to report the number of workers they fired and replaced with AI technology. The data would be compiled by the Dept. of Labor and released via a public report.
www.warner.senate.gov/public/index...
loading . . .
Warner, Hawley to Introduce Bipartisan Legislation to Track Number of Jobs Lost to AI
WASHINGTON –Today, U.S. Sens. Mark R. Warner (D-VA) and Josh Hawley (R-MO) announced they will introduce the AI-Related Job Impacts Clarity Act. This legislation would require major companies an...
https://www.warner.senate.gov/public/index.cfm/pressreleases?id=FD838E66-72CE-49E0-A4AD-90896C8576BC
2 days ago
2
11
5
Find the Floof. Spot the cat. 😼
bigjobby.com/floof/
loading . . .
Find the Floof — Intense Cat-Finding Puzzle
Spot the cat before the tiles reshuffle (2s → 3s → 4s). Three rounds of escalating chaos. Think fast, click faster.
https://bigjobby.com/floof/
2 days ago
1
5
1
"temporary" lol
add a skeleton here at some point
2 days ago
1
22
2
NVISO has linked VShell to UNC5174, a cyber contractor for the Chinese MSS
www.nviso.eu/blog/nviso-a...
2 days ago
0
5
2
reposted by
Catalin Cimpanu
Rayna 🤓🇪🇺👩💻📚✍️
3 days ago
Lol
add a skeleton here at some point
1
19
4
reposted by
Catalin Cimpanu
Techmeme
3 days ago
The AI boom is driving coordinated innovation in the US as it builds fabs and energy infrastructure that could have lasting value even if the bubble bursts (Ben Thompson/Stratechery)
Main Link
|
Techmeme Permalink
4
6
4
reposted by
Catalin Cimpanu
Alexandra Paulus
3 days ago
New Policy Analysis: Europe's cybersecurity heavily relies on the United States. My key points: 1. Europe's dependencies on the US in the field of cybersecurity extend well beyond software updates, SaaS, and cloud services and would persist even if a EuroStack were developed. /1
2
17
11
reposted by
Catalin Cimpanu
The Last Linda
3 days ago
🌺 DAY 5 - RATS ⬇️
#RemembranceDay
#AnimalsInWar
#rats
#LestWeForget
#CanadaRemembers
1
3
1
Repeat after me: Do not fill in and sync your government ID data to your Google account
blog.google/products/chr...
loading . . .
Chrome now helps you fill in passport, driver’s license, vehicle information and more.
Chrome already saves you time every day by securely filling in your addresses, passwords and payment information. Today, we’re making it even more helpful. For desktop u…
https://blog.google/products/chrome/enhanced-autofill/
3 days ago
1
58
26
CISA's election day monitoring room was not stood up yesterday for the first time in years According to Bloomberg, remaining CISA election security staff, who have not been fired, have been "prohibited" from contacting state election officials.
www.bloomberg.com/news/article...
loading . . .
US Elections Face Security Test as DHS Cuts Local Cyber Support
As voters across the US from New York City to New Jersey and Virginia prepare to cast ballots Tuesday, election officials are operating with sharply reduced support from a federal government agency th...
https://www.bloomberg.com/news/articles/2025-11-03/us-elections-face-security-test-as-dhs-cuts-local-cyber-support
3 days ago
3
63
33
reposted by
Catalin Cimpanu
Greg Otto
3 days ago
NEW: After all of that, a federal judge has reimposed a sentence on Paige Thompson, the former Amazon Web Services engineer convicted in the 2019 Capital One data breach that compromised the personal information of more than 100 million people.
cyberscoop.com/court-reimpo...
loading . . .
Court reimposes original sentence for Capital One hacker
A federal judge has reimposed a sentence on Paige Thompson, the former Amazon Web Services engineer convicted in the 2019 Capital One data breach that compromised the personal information of more than...
https://cyberscoop.com/court-reimposes-original-sentence-for-capital-one-hacker/
0
1
5
reposted by
Catalin Cimpanu
Eric Geller
3 days ago
CISA's filing in the shutdown layoffs lawsuit provides the first confirmed count of laid-off employees in the Stakeholder Engagement Division:
storage.courtlistener.com/recap/gov.us...
(h/t
www.nextgov.com/people/2025/...
) CISA says employees are exempt from injunction b/c they're not in a union.
0
9
7
reposted by
Catalin Cimpanu
Kevin Rothrock
3 days ago
The EU is preparing to further tighten visa rules for Russian citizens, effectively ending the issuance of multi-entry Schengen permits in most cases. But visa issuance remains a national competence, meaning that the European Commission cannot impose a total, sweeping ban on Russian visitors.
loading . . .
EU set to further tighten visa rules for Russians
Russians will generally only be eligible for single-entry visas once new rules take effect.
https://www.politico.eu/article/eu-visa-rules-russians-schengen-war-in-ukraine/
0
39
9
reposted by
Catalin Cimpanu
Kevin Beaumont
3 days ago
Much like there’s employees of anti-ransomware companies doing ransomware attacks, there will end up being employees of GenAI cybersecurity companies who do GenAI based cyber attacks. The financial incentive is there to set fire to things, the industry will love it too.
3
28
8
reposted by
Catalin Cimpanu
Natto Thoughts
3 days ago
Researcher @sick.codes found a vulnerability in TCL TVs and reached out to TCL. What happened next? New analysis from Natto Thoughts - how a single disclosure reshaped China’s approach to cybersecurity and control.
nattothoughts.substack.com/p/what-a-nar...
0
1
2
reposted by
Catalin Cimpanu
andy jabbour
3 days ago
DOJ: The US 'sanctioned two entities and eight individuals involved in supporting (North Korea's) illicit schemes to launder funds, including those derived from
#cybercrime
and information technology (IT) worker fraud.'
www.state.gov/releases/off...
@gate15.bsky.social
@campuscodi.risky.biz
loading . . .
Disrupting Illicit DPRK Bankers and Institutions Laundering Cybercrime and IT Worker Funds - United States Department of State
Today, the United States sanctioned two entities and eight individuals involved in supporting the Democratic People’s Republic of Korea’s (DPRK) illicit schemes to launder funds, including those deriv...
https://www.state.gov/releases/office-of-the-spokesperson/2025/11/disrupting-illicit-dprk-bankers-and-institutions-laundering-cybercrime-and-it-worker-funds/
0
0
2
reposted by
Catalin Cimpanu
-US indicts two rogue cybersecurity employees for ransomware attacks -Hackers extort massage parlor visitors -Balancer hacked for $128 million -Cargo thieves use hackers to go after trucking and freight companies Podcast:
risky.biz/RBNEWS500/
Newsletter:
news.risky.biz/risky-bullet...
3 days ago
1
27
11
reposted by
Catalin Cimpanu
-UPenn hack gets feisty -Major breach in Poland, at SuperGrosz -Hack exposes Kansas City dirty cops -Twitter to show more user info -US to face-scan all foreign travelers -Australia expands kids social media ban to Reddit and Kick -SMS blaster detained in Cambodia -Scammers arrested in Europe
3 days ago
1
7
1
reposted by
Catalin Cimpanu
Ciaran Martin
10 days ago
A cyber work of art from
@doublepulsar.com
0
76
23
reposted by
Catalin Cimpanu
☽ Mythic ☾
10 days ago
Do you got any games on your phone?
#pigeonsky
#pigeon
0
44
11
-US indicts two rogue cybersecurity employees for ransomware attacks -Hackers extort massage parlor visitors -Balancer hacked for $128 million -Cargo thieves use hackers to go after trucking and freight companies Podcast:
risky.biz/RBNEWS500/
Newsletter:
news.risky.biz/risky-bullet...
3 days ago
1
27
11
reposted by
Catalin Cimpanu
Sarah McLaughlin
4 days ago
Tanzanian citizens received mass texts from authorities this week to warn them that sharing messages that cause distress could result in treason charges.
loading . . .
Tanzanian opposition claims security forces are secretly dumping bodies after election violence
Authorities in Tanzania faced mounting concern Tuesday over killings during crackdowns on protests surrounding last week’s election, with the largest opposition party alleging that security forces wer...
https://www.ctvnews.ca/world/article/tanzanian-opposition-claims-security-forces-are-secretly-dumping-bodies-after-election-violence/
0
10
5
reposted by
Catalin Cimpanu
Eric Geller
4 days ago
@ddimolfetta.bsky.social
looks at the consequences of layoffs and furloughs on the NSA's hacking and espionage missions, which may be faltering as people leave or sit at home:
www.nextgov.com/people/2025/...
5
45
32
reposted by
Catalin Cimpanu
realhackhistory.org
4 days ago
I regret to inform everyone that Russia aligned hacktivists are at it again with the weird shit.
0
10
2
Load more
feeds!
log in