Catalin Cimpanu
@campuscodi.risky.biz
📤 12429
📥 437
📝 3654
☆ Cybersecurity reporter ★ Newsletters at Risky Business
#infosec
#cybersecurity
https://risky.biz
reposted by
Catalin Cimpanu
Preeti Chhibber
about 16 hours ago
omg everybody go draw a horse this is what the internet was made for
gradient.horse
loading . . .
gradient.horse
Draw a horse, watch it run!
https://gradient.horse/
36
6299
3425
reposted by
Catalin Cimpanu
Ben Phillips
1 day ago
Plans to invade Greenland have just been cancelled after this
loading . . .
73
2824
1245
Thread
add a skeleton here at some point
about 1 hour ago
0
2
1
Yet Durov is too busy complaining about mAcRoN & eU cEnSoRsHiP to even notice
add a skeleton here at some point
about 3 hours ago
0
8
1
Has anyone looked if the Notepad++ and EmEditor incidents are related in any way?
about 3 hours ago
0
6
0
An Orange Cyberdefense report concludes that hacktivism has evolved from a form of digital protest into the realm of hybrid warfare
www.orangecyberdefense.com/global/blog/...
about 3 hours ago
2
6
3
Google Cloud has published a report looking at all the threat actors targeting companies in the Defense Industrial Base. The report goes over the main groups from all major foreign adversaries and what their main focus has been over the past decade
cloud.google.com/blog/topics/...
about 4 hours ago
1
9
8
A US judge has sentenced a Chinese national to 20 years in prison for laundering funds from Cambodian cyber scam compounds That's the maximum sentence, btw
www.justice.gov/opa/pr/man-s...
loading . . .
Man Sentenced to 20 Years in Prison for Role in $73 Million Global Cryptocurrency Investment Scam
A dual national of China and St. Kitts and Nevis was sentenced in absentia today in the Central District of California to the statutory maximum of 20 years in prison and three years of supervised rele...
https://www.justice.gov/opa/pr/man-sentenced-20-years-prison-role-73-million-global-cryptocurrency-investment-scam
about 4 hours ago
0
5
0
New report claims that after a close Orban ally bought Euronews, the TV network turned into a propaganda machine for autocratic regimes
www.euractiv.com/news/inside-...
loading . . .
Inside Euronews: How Europe’s broadcaster became an influence network | Euractiv
Conceived as Europe’s answer to CNN, the EU-funded channel has become a platform for authoritarian regimes
https://www.euractiv.com/news/inside-euronews-how-europes-broadcaster-became-an-influence-network/
about 4 hours ago
0
14
4
reposted by
Catalin Cimpanu
Barry Dorrans
about 11 hours ago
Would never ask you to verify your age
4
143
22
reposted by
Catalin Cimpanu
Conignis
about 11 hours ago
That wasn't the main objection. The main objection was loss of functionality: things like you can't create you own filters in MV3 and filter lists can't be updated in real time independent of the extension.
0
2
1
New academic research has found that Chrome's new MV3 extension API is not that bad after all "Ad blocker providers appear to have successfully navigated the MV3 update, finding solutions that maintain the core functionality of their extensions"
petsymposium.org/popets/2026/...
about 13 hours ago
2
5
0
reposted by
Catalin Cimpanu
the garbage store boy
about 15 hours ago
Wikipedia should release an Amazon Alexa like device that is just hooked up to Wikipedia, the NOAA weather APIs, and a few music services. No spyware. This shit would sell like hotcakes
1
12
2
reposted by
Catalin Cimpanu
Chesterville🌲
about 15 hours ago
No one should have to explain that anti-cheat in a pve game is effectively malware
1
15
6
Substack breach impacted 663,000 accounts, but appears to be a scrape of public data... so not a big deal at all
haveibeenpwned.com/Breach/Subst...
loading . . .
Have I Been Pwned: Substack Data Breach
In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email ...
https://haveibeenpwned.com/Breach/Substack
about 15 hours ago
0
7
1
Security firm Defused has spotted a coordinated campaign from an initial access broker that is targeting the recent Ivanti EPMM zero-days
defusedcyber.com/ivanti-epmm-...
loading . . .
Sleeper Shells: How Attackers Are Planting Dormant Backdoors in Ivanti EPMM
A February 2026 campaign used a internal JSP path and in-memory Java class loaders to quietly seed persistent access across Ivanti EPMM deployments - then walked away. We break down the tradecraft.
https://defusedcyber.com/ivanti-epmm-sleeper-shells-403jsp
about 15 hours ago
0
4
2
reposted by
Catalin Cimpanu
Patrick Gray
about 15 hours ago
Does anyone know why Charlie Bell was shifted out of security at Microsoft and replaced by someone with a background in sales? What does this mean for Microsoft's "Secure Future Initiative"? I'm riskybusiness.01 on Signal
blogs.microsoft.com/blog/2026/02...
loading . . .
Updates in two of our core priorities - The Official Microsoft Blog
Satya Nadella, Chairman and CEO, posted the below message to employees on Viva Engage this morning. I am excited to share a couple updates in two of our core priorities: security and quality. Hayete G...
https://blogs.microsoft.com/blog/2026/02/04/updates-in-two-of-our-core-priorities/
4
17
6
reposted by
Catalin Cimpanu
Oleg Shakirov
about 21 hours ago
Singapore takes another step in the public attribution game linking UNC3886 to attacks on 4 telcos. The report includes a description w/ few technical details Incident response involved >100 defenders making it the largest such operation for Singapore
www.csa.gov.sg/news-events/...
0
1
1
reposted by
Catalin Cimpanu
Nerd House
about 23 hours ago
@discord.com
Ya'll got some BALLS. Iron, steel, maybe even adamantium or vibranium! Implementing requiring ID when you had a MAJOR data breach just months ago...you should really be focusing on security instead.
cybersecuritynews.com/discord-data...
www.theverge.com/tech/875309/...
loading . . .
Discord Data Breach - 1.5 TB of Data and 2 Million Government ID Photos Extorted
Discord has confirmed a significant data breach that exposed sensitive user information after an attacker compromised a third-party customer service provider.
https://cybersecuritynews.com/discord-data-breach-sensitive-data/
1
26
14
Yeah.... how about no Back to TeamSpeak we go... 🤣
add a skeleton here at some point
about 23 hours ago
0
16
4
Hey
#pigeonsky
.... we have another member
add a skeleton here at some point
about 23 hours ago
0
10
0
reposted by
Catalin Cimpanu
InfoSecSherpa 🏔️
1 day ago
Article: "Is Babuk Back? 🫣 Uncovering the Truth Behind Babuk Locker 2.0" by Umut Bayram from Picus Security - February 3, 2026.
cybersec.picussecurity.com/s/is-babuk-b...
0
0
2
reposted by
Catalin Cimpanu
jon greig
5 days ago
Substack got hacked but they are being tightlipped about how the breach occurred or if they were ever offered a ransom. Its unclear how many people were impacted
therecord.media/substack-dat...
loading . . .
Substack warns customers of data breach following hacker’s dark web claims
Customers of the newsletter platform Substack were notified on Wednesday of a breach, following a hacker's claims on the dark web of a trove of stolen data.
https://therecord.media/substack-data-breach-notification
1
4
3
reposted by
Catalin Cimpanu
Active Measures, LLC
1 day ago
FSB putting the word out on the street it costs less than a Kia Sorento to murder the deputy head of the GRU
5
170
34
reposted by
Catalin Cimpanu
gnida project
1 day ago
Very interesting material by
@checkfirst.network
, which has a big potential for real world applications
add a skeleton here at some point
1
17
11
reposted by
Catalin Cimpanu
Kevin Collier
1 day ago
Whenever I hear stuff like this about conservative outlets, I think of personal friends who are absolutely baffled when I tell them I've never gotten a directive to avoid any topics relevant to my beat and that it would be an incredible affront if I did.
add a skeleton here at some point
3
33
6
reposted by
Catalin Cimpanu
-SmarterTools hacked via its own product -Dutch DPA and European Commission hacked via Ivanti zero-days -Senegal held for ransom -state actor behind Signal phishing campaign in Germany -Flickr 3rd party breach Podcast:
risky.biz/RBNEWS523/
Newsletter:
news.risky.biz/risky-bullet...
1 day ago
1
14
7
reposted by
Catalin Cimpanu
-China executes scam compound execs -DDoSer arrested in Poland -Northwestern hacker pleads guilty -Nigerian scammer gets 8 years -Profiles on DSLRoot and GhostSocks profile, two proxy services -DKIM replay attacks in the wild -17% of OpenClaw skills are malicious -ClawHub to scan skills using VT
1 day ago
1
8
3
reposted by
Catalin Cimpanu
Dave Lee
1 day ago
Ai.com
spent god knows how much on their Super Bowl ad, and….
7
111
30
reposted by
Catalin Cimpanu
⸻realhackhistory.org
1 day ago
NoName057(16) again explicitly asking Telegram followers physically located in countries “unfriendly to Russia” but who want to help Russia to get in contact with NoName057(16). This goes beyond the voluntary botnet DDoSia as signing up for that does not require sending messages on Telegram.
0
9
3
-SmarterTools hacked via its own product -Dutch DPA and European Commission hacked via Ivanti zero-days -Senegal held for ransom -state actor behind Signal phishing campaign in Germany -Flickr 3rd party breach Podcast:
risky.biz/RBNEWS523/
Newsletter:
news.risky.biz/risky-bullet...
1 day ago
1
14
7
This Seattle defense is absolutely fantastic 😍
1 day ago
2
10
0
EU Commission discloses an attempted cyberattack on its MDM system
ec.europa.eu/commission/p...
2 days ago
1
20
10
The Green Blood group is holding Senegal's government for ransom. It claims to have stolen 139TB of data from the country's Department for the Automation of Records (DAF), which holds extremely sensitive information on all the country's population.
gambiaj.com/senegals-fil...
2 days ago
0
12
6
Microsoft held an AMA session and updated its guide to help sysadmins safely replace Secure Boot certificates that are set to expire this June.
techcommunity.microsoft.com/event/window...
techcommunity.microsoft.com/blog/windows...
2 days ago
0
10
9
A state-sponsored threat actor is targeting the Signal users in Germany in a complex phishing campaign According to Germany's cybersecurity agency, targets include high-ranking politicians, the military, and investigative journalists
www.bsi.bund.de/SharedDocs/C...
3 days ago
0
20
17
Dutch data protection agency was hacked via the two recent Ivanti zero-days disclosed earlier this month
www.tweedekamer.nl/kamerstukken...
3 days ago
2
20
16
reposted by
Catalin Cimpanu
Mrs. Betty Bowers
3 days ago
NSA's whistleblower report is about contacts between foreign intelligence and someone close to Trump. Instead of acting on this information to protect the United States, Gabbard tipped off the White House and squashed an internal investigation to protect Trump.
www.theguardian.com/us-news/2026...
loading . . .
NSA detected phone call between foreign intelligence and a person close to Trump
Whistleblower says that Tulsi Gabbard blocked agency from sharing report and delivered it to White House chief of staff
https://www.theguardian.com/us-news/2026/feb/07/nsa-foreign-intelligence-trump-whistleblower
112
1527
812
reposted by
Catalin Cimpanu
Techmeme
3 days ago
South Korean cryptocurrency exchange Bithumb says it accidentally sent $44B worth of bitcoin to customers as promotional rewards and has recovered 99.7% of it (Hyunjoo Jin/Reuters)
Main Link
|
Techmeme Permalink
4
12
4
reposted by
Catalin Cimpanu
Helen Shang
4 days ago
I'm at the Olympics and the entire stadium booed JD Vance. 😌
238
12783
2086
reposted by
Catalin Cimpanu
Colin Childs🍁
4 days ago
Discord trying to get me to buy nitro for other people when ive never bought it for myself is.. bold.
0
6
1
reposted by
Catalin Cimpanu
780th Military Intelligence Brigade (Cyber)
4 days ago
Denmark’s military intelligence service has launched a campaign to recruit cybersecurity specialists for offensive cyber operations Risky Business
news.risky.biz/risky-bullet...
@campuscodi.risky.biz
loading . . .
Denmark recruits hackers for offensive cyber operations
In other news: Coinbase has another insider breach; CISA tells agencies to remove old edge devices; Microsoft has a new security chief.
https://news.risky.biz/risky-bulletin-denmark-recruits-hackers-for-offensive-cyber-operations/
1
8
4
reposted by
Catalin Cimpanu
Moira Donegan
6 days ago
Really nuts how many men were like "Me Too went too far, and I need to email Jeffrey Epstein about it."
129
15257
2924
reposted by
Catalin Cimpanu
Joe Slowik
4 days ago
“‘NoName057(16)’? More like ‘No talent ass-clown’”
1
6
1
reposted by
Catalin Cimpanu
Tim Onion
4 days ago
Once again, it turns out “fully autonomous” means “a guy in the Philippines.”
loading . . .
It Turns Out Waymos Are Being Controlled by Workers in the Philippines
During a Congressional hearing, Waymo's chief safety officer, Mauricio Peña, was grilled over the company's reliance on overseas workers.
https://futurism.com/advanced-transport/waymos-controlled-workers-philippines
629
22290
7875
reposted by
Catalin Cimpanu
-Denmark recruits hackers for offensive cyber operations -Coinbase has another insider breach -CISA tells agencies to remove old edge devices -Microsoft has a new security chief -Russian hackers targeted Olympics, again Podcast:
risky.biz/podcasts/
Newsletter:
news.risky.biz/risky-bullet...
5 days ago
4
15
8
reposted by
Catalin Cimpanu
-No killswitch detected in Chinese smart meters -Trump admin abuses administrative subpoenas -US telecoms invoke client-attorney privilege to block Salt Typhoon docs -Fake Dubai prince scam nets $2.5m -Scam network impersonates law firms -Incognito Market admin sentenced to 30y
5 days ago
1
4
1
reposted by
Catalin Cimpanu
Upandaway
4 days ago
"Another senior Reform figure said they had been told that Rogers “had a state department slush fund to get Maga-style things going in various places”, adding that she was keen to “fund European organisations to undermine government policies”."
www.ft.com/content/f869...
loading . . .
US government to fund Maga-aligned think-tanks and charities in Europe
State department grants to spread ‘American values’ are part of Washington’s 250th anniversary celebrations
https://www.ft.com/content/f8696da1-5fe6-4218-be9c-5309bd9a6ae5
0
5
5
reposted by
Catalin Cimpanu
Ryan Mac 🙃
5 days ago
While reporting this, I had something happen that's never happened. A comms rep for one of the co's disputed my reporting and said what I was telling them was untrue because it was not in Grok, xAI's chatbot. I was looking directly at the files. And this person was using AI to challenge the truth.
add a skeleton here at some point
203
9569
3475
-Denmark recruits hackers for offensive cyber operations -Coinbase has another insider breach -CISA tells agencies to remove old edge devices -Microsoft has a new security chief -Russian hackers targeted Olympics, again Podcast:
risky.biz/podcasts/
Newsletter:
news.risky.biz/risky-bullet...
5 days ago
4
15
8
Load more
feeds!
log in