Catalin Cimpanu
@campuscodi.risky.biz
☆ Cybersecurity reporter ★ Newsletters at Risky Business #infosec #cybersecurity https://risky.biz
-Hacker breaches Hungary's State Treasury -Russia to mandate 40 apps on all smartphones next year -Hackers hits Liechtenstein's business database -AI hallucinates 55 vulnerability reports -Pass-ta-key attack recovers passkeys from Chrome N: news.risky.biz/risky-bullet... P: risky.biz/RBNEWS596/
-Data breach at UK govt investment fund -Switzerland's IT agency was hacked -Iran water hacks spread to 12 states -Coinkite destroys inventory after hack -BeaconCRM hack impacts UK charities -Samsung bans TV proxy apps -Apple challenges the UK over backdoor request again
We're thrilled to announce IFIN has achieved 501(c)(3) recognition! Now we can get down to business. ifin-intel.org/blog/... #IFIN
It's Official: We're a Recognized Non-Profit | IFIN
IFIN has achieved 501(c)(3) status. What this means for us, and for you.
ifin-intel.org
Besides every other citizen committing crimes against humanity or working on bombs or spyware, you can add this. What a shithole country. https://scheerpost.com/2026/08/01/how-israel-became-a-haven-for-international-fraudsters-crooks-and-paedophiles/
How Israel Became A Haven For International Fraudsters, Crooks, And Paedophiles
Nate Bear Do Not Panic Israel is home to thousands of international criminals accused or found guilty in a second country for committing a wide-variety of crimes. Many of the individuals are dual-n…
scheerpost.com
Yep. Earlier this year I was interviewed by Sharyn Alfonsi of 60 Minutes about my Epstein investigation. Subsequently, CBS pulled the segment and fired the reporter. The MAGA buyout of media is aiding the Trump administration’s Epstein cover up.
Banks permitted millions in suspicious transactions tied to Epstein—and former 60 Minutes correspondent Sharyn Alfonsi had the story months ago. But the report would never air. trib.al/ZShZlIS
2/2 The "modified drone" contained an "unknown substance" and a "detonator," according to police sources speaking to German media outlet Süddeutsche Zeitung. kyivindependent.com/modified-dro... #Germany
'Modified drone' found next to Ukrainian transport plane at German airport
Flights at Germany's Leipzig/Halle Airport were suspended overnight on Aug. 5 after a "modified drone" was sighted and later found next to a Ukrainian Antonov Airlines An-124 transport aircraft. The ...
kyivindependent.com
-Hacker breaches Hungary's State Treasury -Russia to mandate 40 apps on all smartphones next year -Hackers hits Liechtenstein's business database -AI hallucinates 55 vulnerability reports -Pass-ta-key attack recovers passkeys from Chrome N: news.risky.biz/risky-bullet... P: risky.biz/RBNEWS596/
Also this: www.artsprofessional.co.uk/news/breakin... And this: www.cse.org.uk/news/beacon-...
Massive CRM used by many UK charities hacked . @campuscodi.risky.biz @grahamcluley.com BBC News - English National Ballet suffers customer data hack www.bbc.co.uk/news/article...
Massive CRM used by many UK charities hacked . @campuscodi.risky.biz @grahamcluley.com BBC News - English National Ballet suffers customer data hack www.bbc.co.uk/news/article...
English National Ballet suffers customer data hack
ENB said it was "so sorry" and is warning customers to be cautious of unexpected emails.
bbc.co.uk
New incidents have been confirmed in Clayton County, Georgia and the near city of Duchesne, Utah, at an oilfield water treatment facility were the pumps were running dry but looking normal in their dashboards
Sources: possible cyberattacks targeting water and wastewater utilities have now been reported in at least 12 US states, and Iran is the prime suspect (ABC News) Main Link | Techmeme Permalink
Microsoft will reduce NuGet API keys lifespan from 365 to 30 days -change enters into effect August 17 -On November 1, Microsoft will invalidate all old NuGet API keys created before August 17. -shorter lifespan is meant to counter supply chain attacks devblogs.microsoft.com/dotnet/stren...
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime - .NET Blog
NuGet API key durations will be reduced to 30 days starting August 17th. This change will significantly strengthen the integrity of the NuGet supply chain.
devblogs.microsoft.com
Coinkite has destroyed all its inventory of Coldcare hardware crypto-wallets after hackers exploited a bug in existing devices to steal close to $100 million from user offline hardware wallets blog.coinkite.com/update-sunday/
Update, Sunday.
An update on the COLDCARD firmware vulnerability, customer support, affected inventory, migration options, and the work ahead.
blog.coinkite.com
“The litigation has revealed a clear pattern: Uber’s lawyers scour women’s private communications, medical records, therapy notes …They grill the women about those issues, their sex lives and their behavior on the night of the incident.” www.nytimes.com/2026/08/04/b...
Uber’s Strategy for Fighting Sexual Assault Suits: ‘What Were You Wearing?’
The ride-hailing giant promised to handle legal claims “in a way that is best for the survivor.” Its lawyers are pursuing a far more aggressive strategy.
nytimes.com
New npm worm ChainDrop appears to be having a great time in the ecosystem right now www.stepsecurity.io/blog/chaindr... socket.dev/blog/popular... safedep.io/keyv-npm-sup...
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2 - StepSecurity
A self-propagating worm is publishing compromised versions of dozens of npm packages using stolen maintainer credentials. See the affected packages and what to do now.
stepsecurity.io
After nine months of work, I’ve launched the Cyber Incident Registry, a new way to explore cyber disruptions by incident, affected organization, location, ransomware group and critical infrastructure sector. The Registry is designed to follow incidents beyond the initial headlines and connect […]
Original post on infosec.exchange
infosec.exchange
They might just as well go and ask in a subreddit at this stage
A senior officer in US Central Command’s (CENTCOM) intelligence branch emailed a broad group of military analysts seeking “new creative and unconventional ways to pressure and punish Iran.” A second source indicated a similar request went out the prior week.
EA’s CEO got an $8 million raise thanks to how well Battlefield 6 performed — four months after the devs responsible for making the game got laid off. https://t.co/KZKhVBOL6O
Live streams from the BSides Las Vegas 2026 security conference, which is taking place this week, are available on YouTube www.youtube.com/@BsideslvOrg...
BSidesLV
Recordings of Security BSides Las Vegas sessions, selected sessions of sister conferences and other Information Security related educational materials.
youtube.com
Bluesky oldheads will remember that brief period of time when the conservative trolls tried to storm the place and were flummoxed by the idea they would have to organically grow an audience and that someone who didn't want to talk to them could nuke every interaction they ever had from orbit
Bluesky is a "liberal bubble" because fascist chuds can't get traction without algorithmic assistance and because people here trained themselves to block "debate me" trybois the instant they roll up
Bluesky's new CEO Toni Schneider on the platform's reputation for being a liberal bubble: "Yes, we definitely want that to change. It is already changing. It certainly wasn’t designed to attract one specific group of people."
New, by me: Samsung has banned smart TV apps that enlist owners' internet connections into residential proxy networks, which are increasingly linked to cybercrime. Samsung told me it's also removing apps containing resproxy code. Bypass for ad-blockers: web.archive.org/web/20260803...
Samsung bans smart TV apps that share users' internet connections with strangers | TechCrunch
New security research offers a rare view inside residential proxy networks, which rely on apps that share a person's internet connection with someone else.
techcrunch.com
Court docs: an FBI agent has been charged with amassing ~$1M worth of cryptocurrency, largely by making unauthorized withdrawals from a criminal target overseas (Devlin Barrett/New York Times) Main Link | Techmeme Permalink
sorry babe I can't hang out I've got to wage ideological warfare on the Internet.
I don't think people are ready for this kind of joke yet.
-Russia is behind the recent hotel WiFi hacks -Anthropic models also did the hacky-hacky -npm adds publish-time malware scanning -Coldcard hacked for $70m -CyberCom to open Silicon Valley office -Iran water hacks impacted seven states P: risky.biz/RBNEWS595/ N: news.risky.biz/risky-bullet...