@campuscodi@mastodon.social
@campuscodi@mastodon.social avatar

campuscodi

@campuscodi@mastodon.social

Cybersecurity reporter for Risky Business

#infosec #cybersecurity #security

This profile is from a federated server and may be incomplete. Browse more on the original instance.

campuscodi, to random
@campuscodi@mastodon.social avatar

"Merry-Go-Round is the name HUMAN researchers have given to two independent rings of websites that operate and redirect traffic among each other in pop-under tabs, racking up digital ad impressions that are concealed from the user."

https://www.humansecurity.com/learn/blog/satori-threat-intelligence-alert-merry-go-round-conceals-ads-from-users-and-brands

campuscodi, to random
@campuscodi@mastodon.social avatar

Microsoft not saying a peep about the Recall privacy scandal is a huge tell of how much the company is focused on security

We should have had a statement by now that Recall is either re-engineered or removed

campuscodi, to random
@campuscodi@mastodon.social avatar

Recorded Future has published a report on a cyber-espionage campaign carried out by Russian APT group BlueDelta that primarily targeted Ukrainian and European organizations with a tangent to Russia's war in Ukraine.

The final payload in this campaign was the Headlace infostealer.

The campaign started in late 2023 and is ongoing.

https://www.recordedfuture.com/grus-bluedelta-targets-key-networks-in-europe-with-multi-phase-espionage-camp

campuscodi, to random
@campuscodi@mastodon.social avatar

Cloudflare has shut down accounts on its platform used by a Russian threat actor known as FlyingYeti to launch phishing attacks on Ukrainian users and organizations.

https://blog.cloudflare.com/disrupting-flyingyeti-campaign-targeting-ukraine

campuscodi, to random
@campuscodi@mastodon.social avatar

OpenAI says it disrupted five influence networks that were using its systems for info-ops

https://openai.com/index/disrupting-deceptive-uses-of-AI-by-covert-influence-operations/

campuscodi, to random
@campuscodi@mastodon.social avatar

US authorities have issued an arrest warrant for an 18-year-old student for launching cyberattacks that disrupted the STAAR online exams in the state of Texas

https://www.houstonchronicle.com/neighborhood/spring-klein/article/klein-cyberattack-staar-testing-19481598.php

campuscodi, to random
@campuscodi@mastodon.social avatar

Indian authorities have arrested five suspects on charges of trafficking unwitting job seekers into Southeast Asian scam compounds

https://therecord.media/india-arrests-human-trafficking-southeast-asia-scam-compounds

campuscodi, to random
@campuscodi@mastodon.social avatar

WatchTowr Labs has published a write-up on that Check Point zero-day from yesterday

https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/

campuscodi, to random
@campuscodi@mastodon.social avatar

The European Court of Human Rights (ECHR) has ruled that a Polish surveillance law violates the European Convention on Human Rights.

The ECHR ruled that Poland's secret surveillance program violated the personal privacy of its targets and did not provide an avenue of appeal.

The court also found the program did not undergo reviews by an independent body and was subject to political influence.

https://notesfrompoland.com/2024/05/29/polish-surveillance-law-violates-human-rights-rules-european-court/

campuscodi, to random
@campuscodi@mastodon.social avatar

Activision has won a lawsuit against EngineOwning, a company that makes cheats for Call of Duty games.

The judge awarded Activision a default judgement of $14.4 million and has ordered EngineOwning to stop making cheats and turn over its website to Activision.

https://www.theverge.com/2024/5/29/24166932/activision-call-of-duty-cheat-creator-lawsuit-engineowning

campuscodi, to random
@campuscodi@mastodon.social avatar

According to the FBI, commercial VPN solutions that used the 911 S5 botnet infrastructure include MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN, and ShineVPN

https://www.ic3.gov/Media/Y2024/PSA240529

campuscodi, to random
@campuscodi@mastodon.social avatar

A malware strain named Chalubo wiped more than 600,000 ActionTec routers at the end of last year

Lumen report here: https://blog.lumen.com/the-pumpkin-eclipse/

Lumen doesn't name the victim, but based on my amateurish OSINT skills, this looks like a US telco (if someone else can confirm plz :clippy: )

campuscodi, to random
@campuscodi@mastodon.social avatar

Home-made bomb explodes in an apartment in Romania.

It's unclear what the bomb was for, but this comes after Romanian authorities detained a man suspected of espionage on behalf of Russia and as Russian sabotage efforts are intensifying across Europe

https://stirileprotv.ro/stiri/actualitate/cine-este-barbatul-mort-in-timp-ce-construia-o-bomba-in-casa-la-fetesti-zse-uita-pe-youtube-cum-sa-si-faca-bombe.html

campuscodi, to random
@campuscodi@mastodon.social avatar

The US National Institute of Standards and Technology says it hired a new contractor to help the agency deal with the backlog of unprocessed entries in the National Vulnerability Database.

NIST staff slowed down the pace of new NVD entries in mid-February, citing a need to re-organize and the increasing volume of vulnerabilities.

The agency now says it expects the backlog to be cleared by the end of the fiscal year.

https://www.nist.gov/itl/nvd

campuscodi, to random
@campuscodi@mastodon.social avatar
campuscodi, to random
@campuscodi@mastodon.social avatar

Japanese authorities have arrested a 25-year-old man for allegedly creating ransomware using generative AI tools

https://japannews.yomiuri.co.jp/society/crime-courts/20240528-188598/

campuscodi, to random
@campuscodi@mastodon.social avatar

Microsoft plans to deprecate TLS server authentication certificates with 1024-bit RSA keys by the end of the year.
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/tls-server-authentication-deprecation-of-weak-rsa-certificates/ba-p/4134028

campuscodi, to random
@campuscodi@mastodon.social avatar
campuscodi, to random
@campuscodi@mastodon.social avatar

HN Security has found three vulnerabilities in the Eclipse ThreadX real-time operating system—formerly known as the Microsoft Azure RTOS (before it was transferred over to the Eclipse Foundation).

https://security.humanativaspa.it/multiple-vulnerabilities-in-eclipse-threadx/

campuscodi, to random
@campuscodi@mastodon.social avatar

A coalition of international law enforcement agencies have taken down servers from multiple malware-loader botnets

Listed "victims" include:

-IcedID
-SystemBC
-Pikabot
-Smokeloader
-Bumblebee
-Trickbot

LEA calls the campaign Operation Endgame: https://operation-endgame.com/

Europol: https://www.europol.europa.eu/media-press/newsroom/news/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem

campuscodi, to random
@campuscodi@mastodon.social avatar

Netflix says it has now awarded more than $1 million to security researchers via its bug bounty program

https://netflixtechblog.medium.com/a-whistledown-exclusive-netflixs-journey-to-one-million-in-bug-bounty-and-beyond-9087ffebc3e1

campuscodi, to random
@campuscodi@mastodon.social avatar

Check Point has released a security update to patch a zero-day exploited in its VPN and security appliances.

Tracked as CVE-2024-24919, the zero-day is an information disclosure that allows threat actor to retrieve data from appliances.

https://support.checkpoint.com/results/sk/sk182336

Security firm Mnemonic says it observed threat actors use the vulnerability to enumerate and extract password hashes, including the accounts used to connect to Active Directory.

https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/

campuscodi,
@campuscodi@mastodon.social avatar

The attacks are related to a security advisory it released earlier this week, where it warned about mysterious attacks on its VPN products.

campuscodi, to random
@campuscodi@mastodon.social avatar

Newsletter: https://news.risky.biz/risky-biz-news-ir-reports-are-not-protected-documents-multiple-judges-rule/
Podcast: https://risky.biz/RBNEWS294/

-IR reports are not protected documents, multiple judges rule
-US sanctions Chinese nationals behind 911S5 proxy botnet
-MediSecure asks for a government bailout
-Check Point VPNs are under attack
-Ransomware hits Russian delivery service CDEK
-Ransomware hits Belgian ride-sharing app Mpact
-Rav-Rx paid a ransomware gang
-Data leak exposes Google Search internal docs
-OpenAI creates Safety Board
-Pegasus widely used in Rwanda

campuscodi,
@campuscodi@mastodon.social avatar

Plus:

-Thailand launches Cyber Command unit
-US govt agencies to adopt RPKI
-Scattered Spider membership estimated ~1K
-New NL NCSC head
-Anatsa malware found on the Play Store
-Malware reports on Kiteshield Packer and Rebirth botnet
-Synapse ransomware avoids Iranian systems
-APT reports on Sapphire Werewolf, Blind Eagle, Moonstone Sleet
-PoCs released for Apple, FortiSIEM bugs
-Major RCE in TP-Link gaming routers
-Internet Archive under DDoS attack

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • Leos
  • thenastyranch
  • ngwrru68w68
  • magazineikmin
  • khanakhh
  • rosin
  • mdbf
  • Youngstown
  • slotface
  • everett
  • GTA5RPClips
  • kavyap
  • DreamBathrooms
  • normalnudes
  • InstantRegret
  • Durango
  • osvaldo12
  • ethstaker
  • cubers
  • tacticalgear
  • tester
  • provamag3
  • cisconetworking
  • modclub
  • anitta
  • megavids
  • lostlight
  • All magazines