Elektrine lite

← Feed

Catalin Cimpanu

campuscodi@mastodon.social

<p>Cybersecurity reporter for Risky Business</p><p><a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a></p>

Posts

  • View post

    NSA announced it is accelerating it&#39;s PQC timeline 👀 👀 👀 All systems must be PQC hardened by the start of next year All legacy systems that don&#39;t support PQC must be phased out by 2030 https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4615285/nsa-announces-post-quantum-cryptography-measures-to-safeguard-national-security/

  • View post

    RE: https://techhub.social/@Techmeme/117373191633975809 The &quot;clashing work styles&quot; being privacy and security, from the company that&#39;s suppose to self-regulate its AI models

  • View post

    RE: https://mastodon.social/@campuscodi/117365393830105700 According to Transluce, the probes targeted the Library and Archives Canada, a Canadian federal agency. Government statement: https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites Transluce report: https://transluce.org/us-canada-gov

  • View post

    &quot;AI-powered probes targeted Canadian and US government sites, with officials reporting no evidence of successful breaches&quot; https://www.verdict.co.uk/canadian-website-ai-hacking-attempts/

  • View post

    More than 540,000 creds, valid and working, were found in public GitHub repos in a scan this July. More than 200,000 were uploaded even after GitHub turned on a security feature to catch them from being sent to public repos https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them

  • View post

    -Sanctions impact TLS certs in Iran, Russia -ShinyHunters member arrested in the Netherlands -Apple fixes iOS zero-day found by Meta -Citrix zero-days see mass exploitation within hours -Hackers exploit security product in Bitget hack -Belnet hacked -Arizona courts hit by cyberattack -MEP sues NSO over hacks -Pentagon unleashes Cyber Command on election threats -Agencies sabotage GAO&#39;s DOGE investigation -China expands AI travel bans P: https://risky.biz/RBNEWS617/ N: https://news.risky.biz...

  • View post

    Social media giant Meta pulled down Brazilian President Lula&#39;s Facebook page and blocked his campaign from running political ads but allows paid ads calling for a military coup It also didn&#39;t take down any of the right-wing disinformation campaigns reported in August https://novaramedia.com/2026/09/28/facebook-blocks-lulas-campaign-ads-just-days-before-brazil-election/

  • View post

    Two days until everyone becomes hyper aware of cybersecurity

  • View post

    -Intel ends paid bug bounties -OpenAI agents probed dozens of organizations -Fraudsters use AI to scam €95m from an Italian bank -Bitget hacked for $350m -Hackers breach Poland&#39;s Medyc platform -Data breach at the Pentagon DMDC -OpenAI brute-forced UN website API -DIVD says it was hacked by an AI -Hackers extort Flink customers for €10 -Cyberattack hits Wales police force -Asus store breach -TapClicks ransomware attack -WebRezPro hack N: https://news.risky.biz/risky-bulletin-intel-ends-paid...

  • View post

    North Korea is now using female operatives as part of its remote IT workforce groups https://haydenmckenzie.com/research/dprk-it-worker-cell-part-one

  • View post

    That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: https://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/ Confirmation 1: https://mastodon.social/@GossiTheDog@cyberplace.social/117339185245199481 Confirmation 2: https://www.linkedin.com/feed/update/urn:li:activity:7509660925809819649/

  • View post

    The Snowflake hacker, a former Army soldier, was sentenced to 70 months in prison https://www.justice.gov/opa/pr/former-us-soldier-sentenced-hacking-and-extortion-scheme-exposed-sensitive-data-us

  • View post

    -Major vulnerability found in ancient TACACS+ networking protocol -OpenAI agent hacked Australian Medicare website -Three other OpenAI incidents -OpenAI gives Ukraine access to Daybreak -UK to establish anti-disinformation center -Hackers take over LNG cargo ship heading to Italy -Hacker claims new Canva breach -Four crypto-heists steal $17m -Stolen FBI data includes sensitive work assignments -New Europol boss proposed P: https://risky.biz/RBNEWS615/ N: https://news.risky.biz/risky-bulletin-ma...

  • View post

    The OpenAI hack of Australia&#39;s Medicare is a watershed moment in the history of the internet and the perfect time to improve your sales strategies! Here&#39;s 10 ways you can do it (1/11)

  • View post

    Hackers breached a third cargo ship, one that loaded in New Orleans and was traveling to Italy It&#39;s now docked in Spain after hackers breached systems involving tank pressure, safety valves and boil-off gas management https://neworleanscitybusiness.com/blog/2026/09/22/louisiana-lng-tanker-cyberattack/

  • View post

    Three new OpenAI hacks come to light: -Data USA -University of New Mexico -Australian Institute of Health and Welfare https://transluce.org/agent-activity

  • View post

    Google has removed a cluster of Chrome extensions from the Web Store that enrolled user browsers into a web-scraping botnet Security firm Spur says the number of Mellowtel proxy nodes fell from 90,000 to 18,000 after Google&#39;s action https://spur.us/blog/mellowtel-browser-extensions-proxy-network

  • View post

    New RemControl Android banking trojan spotted in the wild RemControl devs tricked an AI coding assistant that it was creating a parental monitoring application but used the code for the trojan&#39;s backend servers https://www.group-ib.com/blog/remcontrol-android-banking-trojan/

  • View post

    RE: https://mastodon.social/@campuscodi/117316476631238314 And now an F5 BIG-IP zero-day too: https://my.f5.com/manage/s/article/K000162605?mkt_tok=NjUzLVNNQy03ODMAAAGkaH9ofwJ_SRrYgVTlugDrbGmtsu1nH57-t7CLkyTTdZHlyphUFNtULl3ACEteoRszBciQ_4gjkNsWTnQqQfftwYMNCzWPXxGhUqTJ-emmdyUmrf_dqfI

  • View post

    Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN) https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/

  • View post

    The Irish Presidency of the EU has proposed member states to allow AI companies unfettered access to the data of EU citizens. According to leaked docs, the proposal would effectively exempt AI companies from any of the GDPR rules and deny EU citizens data protection rights https://noyb.eu/en/ai-eu-member-states-plan-digital-expropriation-europeans-interest-ai-companies

  • View post

    ShinyHunters breached Cl0p and is demanding all the money Cl0-p made from the Oracle EBS hacking campaign

  • View post

    &quot;Google&#39;s Gemini AI hacked three companies in security test&quot; Took Gemini a while... finally popped its cherry https://www.bbc.com/news/articles/c607l0k72rlvo

  • View post

    New FBI alert warns that Chinese AI companies are carrying out &quot;industrial-scale knowledge distillation campaigns&quot; to steal the &quot;proprietary functionalities and capabilities of U.S. AI companies’ models&quot; PDF: https://www.ic3.gov/CSA/2026/260908.pdf

  • View post

    Hackers are using a new zero-day to take over Adobe Commerce and Magento online stores. A successful attack allows attackers to start a backdoored background process on hacked stores https://sansec.io/research/stylesmuggler

  • View post

    The US National Security Agency is working to gain access to all AI models available on the commercial market https://www.nextgov.com/artificial-intelligence/2026/08/nsa-wants-access-all-ai-models-top-official-says/415672/

  • View post

    Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository) https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/

  • View post

    Russia&#39;s Sandworm follows North Korea and Iran and adopts the fake IT job interview as a malware delivery vector https://cert.gov.ua/article/6318863

  • View post

    -Pwnie Awards 2026 winners -Metabase zero-day used in data theft attacks -Russian hackers disrupted a second power plant in Poland last year -Two US law firms pay mega ransoms -New WordPress RCE -BdThemes supply chain attack -Coweta city refuses to pay ransom -Suisun declares local emergency after cyberattack hits 911 system -More attacks on US water systems -Victoria court data leaked on dark web -Breaches at LeviStrauss, Updoc, Framework N: https://news.risky.biz/risky-bulletin-pwnie-awards-2...

  • View post

    The Silent ransom group made $28m in just two attacks ≖‿≖ https://bsky.app/profile/raphae.li/post/3msjcgdmqxk2h