Sergiu Gatlan

@serghei.bsky.social

Cybersecurity/tech reporter @BleepingComputer / serghei.ro

Periodic reminder that if you are being asked by a captcha to type any kind of combinations of keys & especially if they look like shortcut key stroke combinations it is an attack called ClickFix. Basically the prompt is to fool you into downloading & installing malicious software. Stay vigilant!

Nicolai von Ondarza@nvondarza.bsky.social · 2w ago

This is new and completely wierd. To proof that I am not an AI, cloudflare now wants me to enter something in the terminal, of unknown origin. Sorry, no way.

Cloudflare trying to prompt me to enter stuff in the windows terminal to proof I am not a robot...

NEW: After a purported crackdown on scam compounds last year, researchers now say at least 25 new scamming sites have opened or expanded in Myanmar. Satellite images show trees being razed and land cleared, with large compounds appearing months later

Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere

Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.

wired.com

It's unusual for former FSB employees to be arrested outside of Russia (and extradited) these days. But what's also unusual about Denis Obrezko -- charged with the "Laundry Bear" hack of computers in the U.S. and Europe-- is how careless he appeared to have been online. www.rferl.org/a/russia-hac...

An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.

What’s unusual about the arrest of Denis Obrezko is how relatively rare it is for Russian hackers to be detained abroad these days. What’s also unusual: Obrezko used to work for Russia’s FSB. And it a...

rferl.org

New out of Boston: A suspected Russian hacker who was arrested last year in Thailand at the FBI's behest is now in U.S. custody and has been charged ​with facilitating a campaign of cyberattacks carried out by a Russia-aligned ‌group called Void Blizzard. www.reuters.com/legal/govern...

US charges suspected Russian hacker with facilitating cyber campaign

A suspected Russian hacker is now in U.S. custody following his arrest in Thailand last year and has been charged ​with facilitating a campaign of cyberattacks carried out by a Russia-aligned ‌group t...

reuters.com

🚨 NEW 🚨 The Justice Department gagged Apple from talking about surveillance on a senior Republican staffer that's been going on for at least the last three years. Apple fought the non-disclosure orders and won. It's now informed the target. www.forbes.com/sites/the-wi...

The FBI Gagged Apple About Surveilling A Republican Aide. Apple Took It To Court And Won.

The DOJ served Apple with repeated gag orders related to extensive surveillance of a senior Republican Congressional staffer in a Qatari-influence investigation.

forbes.com

Microsoft's digital crimes unit said it would pursue security researchers who "irresponsibly" disclose 0day. But it's simple: Redmond can't dictate what researchers do with bugs. If you can't entice hackers to disclose bugs via your preferred channels, that's a you problem! (aka skill issue)

Are Microsoft arguing that releasing proof of concept is a crime if you don't get their approval first? Because this seems to lump a security researcher not going along with their preferred disclosure process in with "criminal activity".

consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity – coordinating as needed with law enforcement around the world.
Catalin Cimpanu@campuscodi.risky.biz · 2mo ago

Microsoft has published a blog addressing all the zero-days disclosed by Nightmare Eclipse: www.microsoft.com/en-us/msrc/b... This comes after both GitHub and GitLab took down the researcher's accounts, and after the researcher was also doxxed on Twitter yesterday

Huawei has not explained why no CVE has been issued for the vulnerability that caused Luxembourg’s nationwide telecoms outage. Ten months later, it remains unclear whether the vuln was ever fully patched, how many operators may have been exposed or whether similar systems remain vulnerable today.

Alexander Martin@alexmartin.bsky.social · 3mo ago

Scoop: An attack exploiting a previously unknown vulnerability in Huawei enterprise router software caused a nationwide telecoms outage in Luxembourg last year, according to multiple sources briefed on the matter, disrupting mobile, landline and emergency communications for more than three hours.

The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.

US govt seeks Instructure testimony on massive Canvas cyberattack

The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.

bleepingcomputer.com