Ben Read

@benread.bsky.social

CTI ‪@wizsecurity.bsky.social‬ Adjuct at @jhu.edu - SAIS Nonresident Fellow at @atlanticcouncil.bsky.social - Cyber Statecraft Previously NSC44, Mandiant, Google Go Mammoths

Oh what the actual FUCK? How on earth is this good for anyone? It’s just reducing corporate transparency and putting anyone who does due diligence or AML work in an impossible position! This is genuinely outrageous and totally flying under the radar.

FinCEN Permanently Ends Beneficial Ownership Reporting Requirements for Millions of Small Business Owners

Will Delete Information Previously Reported by U.S. PersonsWASHINGTON––Today, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) is issuing a final rule that permanently removes the requirement for U.S. companies and U.S. persons to report beneficial ownership information to FinCEN under the Corporate Transparency Act.  The final rule is effective on its publication in the Federal Register. FinCEN today also announced that it will delete previously reported information by U.S. persons—now exempt from the reporting requirements—from the beneficial ownership information database. “Today’s action is a victory for common sense and American small businesses,” said Secretary of the Treasury Scott Bessent. “President Trump promised to cut red tape, and this final rule delivers. Treasury is eliminating a burdensome reporting requirement for millions of law-abiding business owners without compromising our national security.” The final rule:adopts the exemptions set out in the interim final rule issued in March 2025, making the rollback of beneficial ownership reporting by U.S. companies permanent;exempts U.S. persons who have obtained FinCEN IDs from any obligation to update or correct the information they originally provided to FinCEN to obtain their FinCEN IDs;eliminates the requirement for foreign companies to report U.S. person “company applicants” (i.e., the individuals who helped those foreign companies register to do business in the United States);exempts foreign pooled investment vehicles registered in the United States from reporting the beneficial ownership information of a U.S person in control of the investment vehicle; andconfirms that FinCEN will delete information about any individuals—company applicants, beneficial owners, or recipients of a FinCEN ID—that FinCEN reasonably believes is a U.S. person (e.g., the information is linked to a U.S. passport or U.S. driver’s license).Under the final rule, foreign entities that are reporting companies will still be required to report beneficial ownership information for foreign individuals. In addition to the final rule, FinCEN has issued Frequently Asked Questions, and will be updating guidance on FinCEN.gov to reflect the final rule. ###

home.treasury.gov

Video of an ICE agent pulling a gun on a wife and mother, who is a US citizen born and raised in the area, near Bailey's Crossroads in Northern Virginia yesterday. Chillingly, they claimed she “almost ran them over” until she told them she had video proving that was a lie.

This is absolutely WILD. Here's the dashboard video posted by @fritschner.bsky.social. Fast forward to about 1 minute. An ICE officer jumps out of a van and pulls a gun on this woman immediately before lying and claiming she "almost ran us over." *profanity warning if watching in public.

Aaron Fritschner@fritschner.bsky.social · 3w ago

Video of an ICE agent pulling a gun on a wife and mother, who is a US citizen born and raised in the area, near Bailey's Crossroads in Northern Virginia yesterday. Chillingly, they claimed she “almost ran them over” until she told them she had video proving that was a lie.

Great story here by my former colleague @bobmcmillan.bsky.social on built-in backdoors in consumer devices that allow nation-state hackers to create huge residential proxy networks. Bob spent months talking my ear off about this. This story is worth your time. www.wsj.com/tech/cyberse...

Exclusive | How Hackers Found a Back Door Into the American Living Room

Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a massive global threat.

wsj.com

Russia and China consider new steps to expand their digital cooperation including on software development and satellite Internet and declare adherence to cyber norms. In this post, I review the relevant sections of the recent joint statement from Beijing fromcyberia.substack.com/p/putin-and-...

Putin and Xi Plan for Co(de)dependence

Russia and China consider expanding their digital cooperation per the joint statement following recent talks in Beijing.

fromcyberia.substack.com

After this week's Github breach, we checked in on hacker group TeamPCP's victim count: their supply chain attacks have tainted more than 500 pieces of software (a thousand-plus different version) and breached hundreds of companies. This is out of control. www.wired.com/story/teampc...

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.

wired.com

Congratulations, Virginia! Republicans are trying to tilt the midterm elections in their favor, but they haven’t done it yet. Thanks for showing us what it looks like to stand up for our democracy and fight back.

🚨 500+ malicious PRs. One campaign. Wiz Research traced 6 waves of prt-scan starting 3 weeks earlier. AI-powered, automated attacks exploiting pull_request_target. Low success rate—but real npm + cloud creds hit. Full story: www.wiz.io/blog/six-acc...

prt-scan: AI-Powered GitHub Actions Supply Chain Attack | Wiz Blog

Wiz Research traces six waves of pull_request_target exploitation to one actor, starting three weeks before public disclosure. 500+ malicious PRs, 10% success.

wiz.io