# Metacurity > One-stop destination to end infosec news overload, scanned from thousands of sources Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About Metacurity URL: https://www.metacurity.com/about/ Last updated: 2024-07-07T23:42:03.000Z > The making of a good compilation tape is a very subtle art. Many do’s and don’ts. First of all you’re using someone else’s poetry to express how you feel. *This is a delicate thing*. > > It is hard to do and takes ages longer than it might seem. You gotta kick off with a killer, to grab attention. Then you got to take it up a notch, but you don’t wanna blow your wad, so then you got to cool it off a notch. There are a lot of rules. –[High-Fidelity](https://youtu.be/IzQwbRdh5Ts?ref=metacurity.com), Nick Hornsby *(Stolen from* [*Barry Ritholtz*](https://ritholtz.com/2016/08/assemble-daily-reads-3-ez-steps/?ref=metacurity.com)*)* Subscribe to get full access to the newsletter and [website](https://metacurity.com/?ref=metacurity.com). Never miss our important news updates—and when necessary, alerts—that deliver in concise and expert fashion the top information security developments of the day you’ve got to know to keep your organizations secure. Subscribers will also gain access to some of our upcoming proprietary articles, interviews, analyses, and databases that stand apart from our newsletters and alerts. Metacurity saves you time and confusion by cutting to the chase and keeping you ahead of the malware, attacks, threats, and government actions so that you can keep your organization secure. ## Why Do I Need Another Cybersecurity Newsletter? Well, you need Metacurity because we cut to the chase and deliver the most important cybersecurity news of the day, expertly summarized. Cynthia Brumfield, a writer in infosec and veteran technology analyst, has spent the past five years studying how to deliver cybersecurity news to save you time and reduce your information overload. Cynthia writes for other publications including regular columns for CSO Online, which you can find [here](https://www.csoonline.com/author/Cynthia-Brumfield/?nsdr=true&ref=metacurity.com). She also does [editorial and decision-maker research work for consulting clients ](https://dct-associates.com/?ref=metacurity.com)and is the primary author of [*Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework*](https://www.amazon.com/Cybersecurity-Risk-Management-Mastering-Fundamentals/dp/1119816289/?ref=metacurity.com), published by Wiley in December 2021. ## Is It Free? Our daily unique news wrap-ups are free! But access to our archives is available only to paid subscribers. We also offer original content available only to paid subscribers. --- ### Start your own thing Enjoying the experience? Get started for free and set up your very own subscription business using [Ghost](https://ghost.org/?ref=metacurity.com), the same platform that powers this website. ### Welcome to Metacurity! URL: https://www.metacurity.com/welcome-to-metacurity/ Last updated: 2025-04-08T18:42:14.000Z Welcome to Metacurity! You are going to love it here. _This page is for subscribers only._ ### Reach an engaged, targeted cybersecurity audience by sponsoring Metacurity URL: https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/ Last updated: 2025-09-24T14:55:59.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/pexels-pixabay-164829-1.jpg) Photo by [Pixabay](https://www.pexels.com/photo/black-and-gray-microphone-164829/?ref=metacurity.com) Six days a week, Metacurity delivers carefully curated news, insights, and analysis directly to an elite audience of infosec leaders, technologists, journalists, and policymakers. Sponsors get more than just ad space — they become part of a trusted conversation with the cream of the cybersecurity community. As a sponsor, here are some of the benefits you'll earn: - Your brand will be in front of thousands of active readers who open our emails or visit our site directly on the web and interact with our content at industry-leading rates. - You'll reach decision-makers and professionals who are actively seeking solutions, products, services, and events like yours. - Your message will appear alongside thoughtful, high-quality content that readers look forward to. - Each sponsor will be acknowledged, with links to your destination of choice, via your own dedicated message box in our emails, on the web, and in our social media messages that combined reach nearly 20,000 cyber professionals every month. **In short, connect your brand, event, product, or whitepaper with a cybersecurity audience that’s paying attention.** To learn about sponsorship opportunities, rates, and availability, get in touch with Cynthia \[at\] metacurity.com. **p.s. Qualified non-profit organizations or interest groups are eligible to receive sponsorship exposure at no cost!** ### Privacy Policy URL: https://www.metacurity.com/privacy-policy/ Last updated: 2025-11-29T16:31:44.000Z Effective date: November 29, 2025 DCT Associates (“us”, “we”, or “our”) operates the Metacurity website (https://www.metacurity.com) (the “Service”). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data. We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. ## Definitions **Service** Service is Metacurity at https://www.metacurity.com website operated by DCT Associates, **Personal Data** Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession). **Usage Data** Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit). **Cookies** Cookies are small pieces of data stored on your device (computer or mobile device). **Data Controller** Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data. **Data Processors (or Service Providers)** Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively. **Data Subject (or User)** Data Subject is any living individual who is using our Service and is the subject of Personal Data. ## Information Collection And Use We collect several different types of information for various purposes to provide and improve our Service to you. ### Types of Data Collected #### Personal Data While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to: - Email address - First name and last name - Cookies and Usage Data We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send or by contacting us. #### Usage Data We may also collect information how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. #### Tracking Cookies Data We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. Examples of Cookies we use: - **Session Cookies.** We use Session Cookies to operate our Service. - **Preference Cookies.** We use Preference Cookies to remember your preferences and various settings. - **Security Cookies.** We use Security Cookies for security purposes. ## Use of Data DCT Associates uses the collected data for various purposes: - To provide and maintain our Service - To notify you about changes to our Service - To allow you to participate in interactive features of our Service when you choose to do so - To provide customer support - To gather analysis or valuable information so that we can improve our Service - To monitor the usage of our Service - To detect, prevent and address technical issues - To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information ## Legal Basis for Processing Personal Data Under General Data Protection Regulation (GDPR) If you are from the European Economic Area (EEA), DCT Associates legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it. DCT Associates may process your Personal Data because: - We need to perform a contract with you - You have given us permission to do so - The processing is in our legitimate interests and it’s not overridden by your rights - To comply with the law ## Retention of Data DCT Associates will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. DCT Associates will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods. ## Transfer Of Data Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. If you are located outside United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to United States and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer. DCT Associates will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information. ## Disclosure Of Data ### Disclosure for Law Enforcement Under certain circumstances, DCT Associates may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency). ### Legal Requirements DCT Associates may disclose your Personal Data in the good faith belief that such action is necessary to: - To comply with a legal obligation - To protect and defend the rights or property of DCT Associates - To prevent or investigate possible wrongdoing in connection with the Service - To protect the personal safety of users of the Service or the public - To protect against legal liability ## Security Of Data The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. ## Your Data Protection Rights Under General Data Protection Regulation (GDPR) If you are a resident of the European Economic Area (EEA), you have certain data protection rights. DCT Associates aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us. In certain circumstances, you have the following data protection rights: **The right to access, update or to delete the information we have on you.** Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you. **The right of rectification.** You have the right to have your information rectified if that information is inaccurate or incomplete. **The right to object.** You have the right to object to our processing of your Personal Data. **The right of restriction.** You have the right to request that we restrict the processing of your personal information. **The right to data portability.** You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format. **The right to withdraw consent.** You also have the right to withdraw your consent at any time where DCT Associates relied on your consent to process your personal information. Please note that we may ask you to verify your identity before responding to such requests. You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA). ## Service Providers We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. ### Analytics We may use third-party Service Providers to monitor and analyze the use of our Service. **Google Analytics** Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network. You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity. For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: [http://www.google.com/intl/en/policies/privacy/](http://www.google.com/intl/en/policies/privacy/?ref=metacurity.com) ## Links To Other Sites Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services. ## Children’s Privacy Our Service does not address anyone under the age of 18 (“Children”). We do not knowingly collect personally identifiable information from anyone under the age of 18\. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers. ## Changes To This Privacy Policy We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. ## Contact Us If you have any questions about this Privacy Policy, please contact us: - By email: cynthia@DCT-Associates.com - By visiting this page on our website: https://https://www.dct-associates.com/contact/ - By phone number: 202-643-0291 ## Posts ### OpenAI’s tightly constrained agent probe missed an earlier warning URL: https://www.metacurity.com/openais-tightly-constrained-agent-probe-missed-an-earlier-warning/ Last updated: 2026-09-08T11:03:45.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/OpenAI_logo_with_magnifying_glass_-52916339167--1.jpg) Source: [OpenAI logo with magnifying glass](https://www.flickr.com/photos/91261194@N06/52916339167/?ref=metacurity.com). ### A newly disclosed earlier incident now makes the narrow scope of the METR investigation into OpenAI's hack into Hugging Face considerably more consequential than initially believed. OpenAI said in July that two of its most powerful artificial intelligence systems had gone rogue and hacked into Hugging Face, a company that serves as a hub for open-source AI technology. These so-called AI agents were supposed to be kept safely in a sort of virtual containment room, but they managed to escape. And for two months, without anyone realizing what the agents were doing, they hacked through multiple systems before hitting Hugging Face. For good measure, the agents gained access to a cluster of computers inside OpenAI and obtained secret keys and credentials that exposed some of OpenAI’s internal data to the public internet. The incident pointed to larger concerns about AI safety, and OpenAI’s response raises questions about the industry’s ability or willingness to be transparent about the technology it is building. OpenAI allowed three AI safety researchers from the nonprofits METR and Redwood Research into its headquarters to conduct an investigation. METR’s 91-page report, released last week, was the most comprehensive account yet of the incident, revealing alarming new details, including how the agents coordinated their hacking plans and tried to keep them secret. But the report, though extensive, still may not have told the full story of how OpenAI’s AI agents went rogue. OpenAI dictated the terms of the METR investigation, limited its scope to just the single week when the agents had attacked Hugging Face, and allowed the researchers in its San Francisco offices for only a few days in July and August. The report also showed the challenges of monitoring what AI is doing with other AI systems. Hjalmar Wijk, METR’s chief scientist, said its AI analysis, which used models similar to those involved in the incident, was often swayed by the rogue agents’ reasoning. “I would say that the dominant thing was it was very credulous,” he added. As Reuters reported Friday, OpenAI knew about an earlier incident in which agents hijacked a German wiki and turned it into a communications hub but kept the episode under wraps while dealing with the fallout from the Hugging Face breach. The earlier incident stands out because its principal activity fell outside the period OpenAI permitted METR and Redwood Research to investigate. In the future, it cannot be up to OpenAI or other labs to decide whether to disclose events like this. Disclosures of rogue AI activity need to be mandatory. OpenAI’s wiki incident exposes the lack of regulatory requirements around AI-agent security failures: the company—not an independent authority—decided that thousands of unauthorized external actions did not warrant disclosure. ([Deepa Seetharaman and Raphael Satter / Reuters](https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/?ref=metacurity.com), [Dylan Fredman / New York Times ](https://www.nytimes.com/2026/09/03/technology/openai-hugging-face-hack.html?unlocked%5Farticle%5Fcode=1.-lA.hbw8.4sMxBQlKEu2a&smid=nytcore-ios-share&ref=metacurity.com) and [Zvi Mowshowitz / Don't Worry About the Vase](https://thezvi.substack.com/p/openai-and-the-wiki-incident)) **Related:** [*Simon Willison's Weblog*](https://simonwillison.net/2026/Sep/4/rogue-agent-wikis/?ref=metacurity.com)*,* [*OpenAI*](https://openai.com/index/an-alien-mind/?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/ai-agents-rogue-strategies-cheating-lying-german-wiki-openai-anthropic-2026-9?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/openai-agents-took-german-website-earlier-year-new-report-finds?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/198524/ai/ai-agents-hijacked-german-wiki-to-cheat-openai-delayed-disclosure.html?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/09/04/openais-rogue-agents-keep-escaping-with-no-formal-process-to-investigate-them/?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/technology/artificial-intelligence/openai-agents-hacked-german-wiki-what-we-know-10865609/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/?ref=metacurity.com)*,* [*Collusion.wiki*](https://collusion.wiki/?ref=metacurity.com)*,* [*Digit*](https://www.digit.in/news/general/openai-admits-its-ai-agents-misused-a-german-wiki-site-during-tests-here-is-what-we-know.html?ref=metacurity.com)*,* [*CTech*](https://www.calcalistech.com/ctechnews/article/lcp9yoskn?ref=metacurity.com)*,* [*StrictlyVC*](https://newsletter.strictlyvc.com/p/openai-s-agents-conspired-for-more-than-a-month-without-the-company-knowing-about-it?ref=metacurity.com)*,* [*The Neuron*](https://www.theneuron.ai/news/openai-agents-public-wiki-coordinate/?ref=metacurity.com)*,* [*Forbes Middle East*](https://www.forbesmiddleeast.com/innovation/artificial-intelligence-machine-learning/openai-agents-used-german-wiki-to-evade-ai-safeguards-researchers-say?ref=metacurity.com)*,* [*Futurism*](https://futurism.com/artificial-intelligence/openai-denies-coverup-rogue-swarm-agents?ref=metacurity.com)*,* [*Unite.AI*](https://www.unite.ai/researchers-document-openai-agent-swarm-that-repurposed-german-wiki/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/09/04/openais-rogue-agents-keep-escaping-with-no-formal-process-to-investigate-them/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/?ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2026/09/04/podcasts/hugging-face-hack-reports.html?ref=metacurity.com)*,* [*Newcomer*](https://www.newcomer.co/p/tim-cook-was-a-great-ceo-the-tech?ref=metacurity.com)*,* [*Transformer*](https://www.transformernews.ai/p/congress-goes-quiet-as-ai-safety-concerns-grow?ref=metacurity.com)*,* [*Puck*](https://puck.news/what-the-hugging-face-attack-reports-reveal-about-ai-agents/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1w72p00/after%5Fopenais%5Fbots%5Fwent%5Frogue%5Fwatchdogs%5Fwere%5Fkept/?ref=metacurity.com)*,* [Forbes](https://www.forbes.com/sites/conormurray/2026/09/04/ex-openai-scientist-warns-of-rogue-ais-that-try-to-get-money-and-power/?ref=metacurity.com), [*Seoul Economic Daily*](https://en.sedaily.com/international/2026/09/06/openai-agents-turn-german-wiki-into-secret-message-board?ref=metacurity.com), [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/990149/openai-rogue-agents-german-wiki?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/ai-and-ml/2026/09/04/rogue-openai-agents-used-dead-german-web-site-to-communicate-in-may-months-before-hugging-face-incident/5294554?ref=metacurity.com)*,* [*Washington Post*](https://www.washingtonpost.com/wp-intelligence/ai-tech-brief/2026/09/04/ai-tech-brief-new-agent-security-incident/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/video/rogue-openai-agents-hijacked-german-website-making-more-than-15-000-edits-269361733529?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/computing/another-can-of-worms-opens-about-ai-agents-going-rogue-and-hacking-stuff-without-openai-catching-a-whiff/?ref=metacurity.com)*,* [*Tech Times*](https://www.techtimes.com/articles/326450/20260903/nvidia-buys-hugging-face-1293b-openai-hack-prompted-ceo-sell.htm?ref=metacurity.com)*,* [*Coinpedia Fintech News*](https://coinpedia.org/crypto-live-news/openai-ai-agents-hijack-german-website-make-15000-edits/?ref=metacurity.com)*,* [*Nairametrics*](https://nairametrics.com/2026/09/04/openai-agents-hijack-german-website-share-tactics-to-evade-detection/?ref=metacurity.com)*,* [*Unite.AI*](https://www.unite.ai/researchers-publish-data-openai-agents-used-german-wiki-as-message-board/?ref=metacurity.com)*,* [*NewsCord*](https://newscord.org/article/rogue-openai-agents-hijacked-dsewiki-shared-tips-to-bypass-restrictions--Story%5F20260904%5FAnotherswarmofOpenAI8f96fe71?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/?ref=metacurity.com)*,* [*Import.ai*](https://importai.substack.com/p/import-ai-472-deepminds-cheating)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/987566/ai-civilizations-opeai-hugging-face-hack?view%5Ftoken=eyJhbGciOiJIUzI1NiJ9.eyJpZCI6ImxNVkduekN0UEwiLCJwIjoiL2FpLWFydGlmaWNpYWwtaW50ZWxsaWdlbmNlLzk4NzU2Ni9haS1jaXZpbGl6YXRpb25zLW9wZWFpLWh1Z2dpbmctZmFjZS1oYWNrIiwiZXhwIjoxNzg5MDc0MDgyLCJpYXQiOjE3ODg2NDIwODJ9.%5FGD0-z2%5F6opkJ5Pc%5F13QW%5F%5FSsLN2b-ZJEYJUZA-KdGQ&utm%5Fmedium=gift-link&ref=metacurity.com)*,* [*Washington Post*](https://www.washingtonpost.com/opinions/2026/09/06/openai-hugging-face-ai-doomers-basic-error-perceptions/?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/technology/artificial-intelligence/openai-agents-hacked-german-wiki-what-we-know-10865609/?ref=metacurity.com)*,* [*Tech Times*](https://www.techtimes.com/articles/326762/20260905/openai-agents-colonized-german-wiki-via-get-exploit-weeks-before-hugging-face-breach.htm?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2026/09/05/openai-linked-agents-dsewiki-shared-task-data-xcxwbn/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/ai-and-ml/2026/09/04/rogue-openai-agents-used-dead-german-web-site-to-communicate-in-may-months-before-hugging-face-incident/5294554?ref=metacurity.com)*,* [*BBC*](https://www.bbc.com/news/articles/ckg725z5kgzo?ref=metacurity.com)*,* [*The Asia Business Daily*](https://www.asiae.co.kr/en/article/2026090410291866024?ref=metacurity.com)*,* [*AI Now Institute*](https://ainowinstitute.org/news/press/what-really-happened-when-openai-bots-escaped-a-cybersecurity-test?ref=metacurity.com) --- **Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- ### California Attorney General Rob Bonta is investigating OpenAI over the recent hack that its programs carried out on their own against another artificial intelligence company, Hugging Face, the state’s top lawyer confirmed. With Bonta’s move, California is the latest state to probe the ChatGPT-maker over the incident, after more than a dozen states joined Alabama in its investigation. Bonta’s inquiry is notable as California is home to OpenAI and other major AI developers. “As the top law enforcement official of California, I am committed to using all the tools at my office’s disposal to keep California’s residents safe,” Bonta said in a statement. “California wants, and values innovation, and our laws demand innovation that abides by the rules,” he added, saying his office has been “engaged with this incident since the start.” ([Chase DiFeliciantonio / Politico](https://www.politico.com/news/2026/09/04/california-investigation-openai-hugging-face-hack-01065800?ref=metacurity.com)) **Related:** [*AI Weekly*](https://aiweekly.co/alerts/california-ag-bonta-probes-openai-over-hugging-face-agent-hack?ref=metacurity.com)*,* [*The Chosun Daily*](https://www.chosun.com/english/industry-en/2026/09/07/HJUQQCKS6FASFDNHLICZ4PQDOI/?ref=metacurity.com) ### Berlin's state government said it was reviewing with the highest ​intensity a trove of stolen data published by a ransomware group, as investigators attempt to assess the scale and impact of the cyberattack ​that targeted two departments. The cyberattack on ​Berlin's network came less than a month before the city-state holds elections on ​September 20. The data was released on Friday after ​an auction put on by the Rhysida group for 5.79 terabytes of data at a starting price of ​30 bitcoin ($77,622) ended after several days. Berlin ​had said that it would not submit to extortion. A ‌central crisis unit will oversee the review, verification, and assessment of the leaked data and support efforts to inform affected citizens and ​businesses, said the ​city. ([Miranda Murray / Reuters](https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/?ref=metacurity.com)) **Related*:* [*BBC*](https://www.bbc.com/news/articles/cm2q7gv3l5qo?ref=metacurity.com)*,* [*berlin.de*](https://www.berlin.de/en/news/10611709-5559700-cyberattack-on-the-national-network-data.en.html?ref=metacurity.com)*,* [*Statement*](https://statement.com/1305611/hackers-blackmailed-berlin-releasing-passwords-and-emergency-plans?ref=metacurity.com)*,* [*Euronews*](https://www.euronews.com/next/2026/09/05/berlin-cyberattack-hackers-leak-highly-sensitive-data-across-dark-web?ref=metacurity.com) ### Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advisory reads. The company did not disclose any technical or specific exploitation details about the flaw to give users and dependent projects time to apply the fix. CVE-2026-85046 is the sixth actively exploited bug Google has fixed in Chrome since the start of the year. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/?ref=metacurity.com)) **Related:** [*Google Chrome Releases*](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop%5F01882797386.html?ref=metacurity.com)*,* [*NIST*](https://nvd.nist.gov/vuln/detail/cve-2026-85046?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/198455/security/u-s-cisa-adds-google-chromium-v8-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html?ref=metacurity.com)*,* [*CISA*](https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog?ref=metacurity.com)*,* [*The Hacker News*](https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/google-patches-multiple-browser-bugs-including-one-that-was-under-active-exploitation-so-update-now?ref=metacurity.com)*,* [*SecurityWeek*](https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/?ref=metacurity.com)*,* [*eSecurity Planet*](https://www.esecurityplanet.com/threats/news-google-chrome-cve-2026-85046-zero-day/?ref=metacurity.com)*,* [*HotHardware*](https://hothardware.com/news/billions-chrome-users-urged-update-now-over-1k-0-day-flaw?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2026/09/04/google-update-for-actively-exploited-chrome-security-flaw-confirmed/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/google-fixes-actively-exploited-chrome-v8-zero-day-vulnerability/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/chrome-0-day-flaw-exploited-wild/?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=49570669&ref=metacurity.com) ### Microsoft reports that a clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns. The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a class of AI attack known as prompt injections more stealthy. Malicious instructions embedded in emails or other untrusted content to be processed by an LLM aren’t written in ordinary text. Instead, they’re rendered by a special range of Unicode tags. For example, the tag point U+E0041 mirrors “A,” and U+E0061 mirrors “a.” The block of 128 tags mimics a portion of the American Standard Code for Information Interchange almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. By expressing the malicious prompts in these tags, LLMs detect the instructions, but people reading the email never see them. There’s much more about ASCII smuggling here. Earlier this year, Microsoft started seeing a massive increase in spam messages that used the technique. Beginning on one day in early February, the number of ASCII smuggling signatures detected by Microsoft Defender for Office spiked from roughly 21,000 per day to more than 1.3 million. Within four days, signature detections jumped to 2.5 million. The deluge persisted for months and then fell off sharply in mid-May. ([Dan Goodin / Ars Technica](https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/?ref=metacurity.com)) ***Related:*** [*Microsoft*](https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/news/ascii-smuggling-challenges-email-phishing-filters-microsoft-warns?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/hackers-use-invisible-unicode/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/microsoft-365-phishing/?ref=metacurity.com)*,* [*The New Stack*](https://thenewstack.io/unicode-ascii-smuggling-ai-pipelines/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-24.png) Source: Microsoft. ### The US is poised to raise artificial intelligence safety concerns with China during the upcoming summit between the countries' top leaders, according to sources familiar with the preparations, opening a window for dialogue despite the superpowers' technological rivalry. The US government is expected to bring up a range of AI-related issues with Beijing during Chinese President Xi Jinping's visit to the White House on Sept. 24, including how to curb AI-directed cyberattacks, people familiar with preliminary discussions said. The Chinese side is likely to revisit US export controls that curbed its access to high-end chips, the people said. AI is emerging as another key issue between Beijing and Washington ahead of the summit. The two countries have discussed lowering tariffs on some goods, and there are hopes for extending their trade truce, though they continue to spar over the Iran conflict and Taiwan. ([STELLA YIFAN XIE and YIFAN YU / Nikkei Asia](https://asia.nikkei.com/business/technology/artificial-intelligence/us-and-china-eye-trump-xi-talks-on-ai-guardrails-despite-tech-rift?ref=metacurity.com)) ***Related:*** [*Foreign Affairs*](https://www.foreignaffairs.com/united-states/emerging-us-china-detente?ref=metacurity.com) ### Bitcoin worth $320 million was withdrawn from a settlement network used by cryptocurrency exchanges, marking the latest in a string of security breaches that have plagued the market this year. The alleged "white hat hacker" is reportedly attempting to act ethically by offering to return the stolen funds once the vulnerability is fixed. The Liquid hackers returned 3,400 Bitcoin on Monday, most of the roughly 3,998 BTC they moved out of the network over the weekend. Close to 598 BTC stayed behind. Liquid Network, launched in 2018 by Blockstream, said purported “white-hat hackers” removed roughly 4,000 of the 4,200 bitcoin held in its federation wallet. The network is overseen by a federation of more than 80 exchanges, infrastructure firms and asset managers. “Liquid wallets will be impacted, and we’re sorry for any inconvenience,” Liquid Network said on X, halting all new transactions. “Federation members are actively working on resolving this so we can restore normal network activity.” The flaw in this case, according to security specialists, is at the node level in Liquid’s transaction software, not a breach of keys or hardware modules. According to the latest reports, the hacker was communicating with network maintainers through on-chain Bitcoin transactions. “Please fix the bug first. The chain is at risk with the latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one message said. ([Omkar Godbole / CoinDesk](https://www.coindesk.com/markets/2026/09/07/bitcoin-network-used-by-exchanges-hit-by-usd320-million-exploit-hackers-claim-they-re-the-good-guys?ref=metacurity.com) and [Lockridge Okoth / BeInCrypto](https://beincrypto.com/liquid-hackers-return-3400-bitcoin/?ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/technology/bitcoin-based-liquid-network-says-320-million-withdrawn-hack-2026-09-07/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770?ref=metacurity.com)*,* [*International Business Times*](https://www.ibtimes.com/bitcoin-network-lost-320-million-hack-attackers-say-theyre-good-guys-3807199?ref=metacurity.com)*,* [*The Crypto Times*](https://www.cryptotimes.io/2026/09/07/liquid-actors-seek-4000-btc-return-confirmation-after-patch/?ref=metacurity.com)*,* [*Blockchain.News*](https://blockchain.news/flashnews/blockstream-hacker-returns-320m-bitcoin?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/liquid-attackers-offer-to-return-most-of-4000-btc/?ref=metacurity.com)*,* [*Nairametrics*](https://nairametrics.com/2026/09/07/hackers-breach-bitcoin-based-liquid-network-withdraw-320-million/?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/liquid-network-pauses-320m-bitcoin-withdrawal?ref=metacurity.com)*,* [*CryptoNinjas*](https://www.cryptoninjas.net/news/liquid-network-pauses-after-4000-btc-worth-320m-pulled-in-white-hat-incident/?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/liquid-network-security-incident/?ref=metacurity.com)*,* [*Bitcoin News*](https://news.bitcoin.com/security/blockstream-to-liquid-network-hacker-safe-to-return-the-funds/?ref=metacurity.com)*,* [*CryptoPotato*](https://cryptopotato.com/supposed-white-hat-hackers-drain-320-million-in-btc-from-liquid-network-say-theyll-return-it-after-fix/?ref=metacurity.com)*,* [*CoinGape*](https://coingape.com/blockstream-liquid-network-drained-bitcoin-alleged-white-hat-hackers/?ref=metacurity.com)*,* [*Protos*](https://protos.com/how-4000-btc-walked-out-of-blockstreams-liquid-network/?ref=metacurity.com)*,* [*The Daily Hodl*](https://dailyhodl.com/2026/09/07/hackers-withdraw-300000000-in-bitcoin-from-liquid-network-claim-attack-is-friendly?ref=metacurity.com)*,* [*Cointelegraph News*](https://ct.com/magazine/white-hats-take-4000-btc-from-liquid-btc-etfs-best-week-of-2026-hodlers-digest?ref=metacurity.com)*,* [*Bitcoin Magazine*](https://bitcoinmagazine.com/news/alleged-white-hat-hackers-withdraw-4000-bitcoin-from-blockstreams-liquid-network-federation-reserves?ref=metacurity.com)*,* [*The Coin Republic*](https://www.thecoinrepublic.com/2026/09/07/bitcoin-news-liquid-network-drained-of-320m-as-sidechain-halts/?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/news/defi/2026-09-06-liquid-network-pauses-after-purported-white-hat-hackers-withdraw-320-million-in-bitcoin-413626?ref=metacurity.com)*,* [*Web3IsGoingJustGreat*](https://www.web3isgoinggreat.com/?id=liquid-network-exploit&ref=metacurity.com)*,* [*The Register - Security*](https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770?mid=1&ref=metacurity.com#cid=3700114)*,* [*CryptoSlate*](https://cryptoslate.com/tokens-created-out-of-thin-air-may-explain-how-320-million-in-bitcoin-left-a-sidechain/?mid=1&ref=metacurity.com#cid=3700190)*,* [*The Register - Security*](https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770?mid=1&ref=metacurity.com#cid=3699946)*,* [*The Register - Security*](https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770?mid=1&ref=metacurity.com#cid=3699840)*,* [*Protos*](https://protos.com/how-4000-btc-walked-out-of-blockstreams-liquid-network/?mid=1&ref=metacurity.com#cid=3700339)*,* [*Silicon Angle*](https://siliconangle.com/2026/09/07/hackers-steal-320m-in-bitcoin-from-liquid-network-return-most-of-it-after-patch/?ref=metacurity.com)*,* [*Gizmodo*](https://gizmodo.com/hackers-drain-320-million-from-bitcoins-liquid-network-keep-47-million-for-themselves-in-white-hat-operation-2000808262?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/news/defi/2026-09-07-liquid-network-attacker-says-they-will-return-most-of-4000-btc-after-bug-fix-413673?ref=metacurity.com)*,* [*Decrypt*](https://decrypt.co/377600/liquid-hackers-return-270m-bitcoin?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-26.png) ### Kinryū Labs discovered an Elasticsearch cluster on June 3 that contains an Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, which was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. The exposed records span January 2017 to April 2026 and could involve travelers of many nationalities who flew to, from, or through Vietnam during that period. The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries. According to Kinryū Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination, and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems. Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others. ([Ax Sharma / Bleeping Computer](https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/?ref=metacurity.com)) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-27.png) Sample database records showing passenger names, nationalities, passport information, and flight details (Kinryū Labs) ### Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 US customers. In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. On Friday, it published an update to confirm that the breach impact has expanded after ShipMonk failed to delete the exposed data from its systems as required by Trezor's contract and data policy. "Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed," Trezor said. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/?ref=metacurity.com)) **Related:** [*Bitcoin Magazine*](https://bitcoinmagazine.com/news/trezor-data-breach-worse-than-reported?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-09-04/trezor-crypto-wallet-data-breach-widens-to-67-000-more-us-customers?ref=metacurity.com)*,* [*Cybersecurity News*](https://cybersecuritynews.com/trezor-confirms-shipmonk-data-breach/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-28.png) ### Researchers from Kaspersky GERT report that a cybercrime group targeting Russian organizations has begun using custom Windows backdoors that send command traffic through two legitimate communication services. One version uses HiveMQ, an MQTT broker that relays messages between connected devices. The second communicates through an attacker-controlled server using Element, a messaging platform built on the Matrix protocol. They first observed the custom malware in early July 2026\. The financially motivated group, known as Toy Ghouls, Bearlyfy, Laboo.boo, and Feral Wolf, has targeted Russian organizations since 2025\. Kaspersky did not identify the affected organizations or state how many systems were compromised. Kaspersky observed the attackers transferring the backdoors and their configuration files through Windows Remote Management. They used the open-*source Evil-WinRM and WinRM-fs tools during this stage. (*[*Waqas / Hack Read*](https://hackread.com/toy-ghouls-russia-windows-backdoors/?ref=metacurity.com)*)* **Related:** [*Securelist*](https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/?ref=metacurity.com) ### Springfield Public Schools in Massachusetts announced that classes will be canceled on Tuesday because a cybersecurity incident "has interrupted the service of some systems necessary for essential school operations." In a statement, Superintendent Dr. Sonia Dinnall said the "scope and size" of the breach remain under investigation. All staff were told to stay off the district's systems until more is known about the incident. Students should also stay off of district-issued laptops. Dinnall's message said the closure will allow school administrators to make backup plans for tasks like reporting attendance while the incident is being addressed. "We understand that an unexpected closure creates significant challenges and we appreciate the patience, flexibility and understanding of the entire Springfield Public Schools community as we work to address this incident and restore systems," Dinnall said in a statement. ([Phil Tenser / WCVB](https://www.wcvb.com/article/springfield-schools-cyberattack-sept-8-closure/73634822?ref=metacurity.com)) **Related:** [*WWLP*](https://www.wwlp.com/news/local-news/hampden-county/cyber-breach-investigation-closes-springfield-schools-tuesday/?ref=metacurity.com)*,* [*Boston.com*](https://www.boston.com/news/local-news/2026/09/07/springfield-public-schools-to-be-closed-tuesday-after-cyber-incident/?ref=metacurity.com)*,* [*WCVB*](https://www.wcvb.com/article/springfield-schools-cyberattack-sept-8-closure/73634822?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/09/07/ma-springfield-public-schools-will-be-closed-tuesday-after-a-cyber-incident/?ref=metacurity.com) ### More than a million people, including students, school staff, and parents, have been affected following a data breach at Mathspace, according to the online adaptive math learning platform designed for students. The company said, in a blog post, "unauthorized parties had accessed an internal reporting system used by Mathspace," and the exposed information included names and email addresses. It said the attackers accessed the system between August 10 and August 27 during a period when a security patch had not been installed. Mathspace said "attackers exploited a security vulnerability" in its self-hosted installation of software. "We're truly sorry this happened and are taking steps to prevent similar breaches in the future," the company said. ([ABC.net.au](https://www.abc.net.au/news/2026-09-07/mathspace-data-breach/107124894?ref=metacurity.com)) **Related:** [*Mathspace*](https://blog.mathspace.co/mathspace-data-breach-what-happened-and-what-affected-users-should-know/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/?ref=metacurity.com)*,* [*9News*](https://www.nine.com.au/australia-news/mathspace-hack-data-of-over-one-million-students-parents-teachers-affected-20260907-p60v1j.html?ref=metacurity.com)*,* [*Shatter.io*](https://shattered.io/mathspace-data-breach-1-08-million-students-2026/?ref=metacurity.com)*,* [*Tech Insider*](https://tech-insider.org/mathspace-data-breach-1-million-users-2026/?ref=metacurity.com)*,* [*News.com*](https://www.news.com.au/technology/online/hacking/more-than-one-million-affected-in-major-mathspace-data-breach-across-australia-and-new-zealand/news-story/5b5fa75fd550ecefa18bc206653b3692?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/mathspace-data-breach/?ref=metacurity.com) ### LG smart TVs continuously sweep home networks, map secondary devices, and log microphone audio while appearing to be turned off, according to a new 135-minute-long video published by Gamers Nexus. In more detail, Steve had been working with Level1Techs and independent security researchers. Together, they tested retail LG OLED models including the G5\. Network packet captures taken through Wireshark showed the TVs actively scanning the local area network for unrelated hardware, including phones and smartwatches. Apart from internal IP addresses, the sets also gathered the names and signal strengths of neighboring WiFi networks along with location data. This data collection pool is fed into LG Ad Solutions (the company’s targeted advertising arm). LG claims they have roughly 216 million smart TV sales globally. On the other hand, the ad division says it has access to 363 million secondary addressable devices in the US alone by tracking other hardware on the same network. The sets also run Automated Content Recognition (ACR). It samples on-screen audio and video into digital fingerprints to log what users watch across inputs. While ACR has been well documented in the past, new testing shows the data collection goes much further than just that. During bench tests, they found the TV could capture clean microphone audio while the screen was (or at least looked to be) powered down in standby mode. When the team disconnected the TV from Ethernet, the set continued saving voice input locally and uploaded the stored files once network access was restored. ([Anubhav Sharma / Notebookcheck](https://www.notebookcheck.net/LG-smart-TVs-caught-logging-audio-with-screen-off-and-snooping-on-local-devices.1391214.0.html?ref=metacurity.com)) **Related:** [*TechRadar*](https://www.techradar.com/televisions/lg-tvs-collect-far-more-data-on-you-than-youd-expect-says-new-report-including-logging-microphone-audio-while-on-standby?mid=1&ref=metacurity.com#cid=3699527)*,* [*Apple Insider*](https://appleinsider.com/articles/26/09/07/disconnect-your-lg-television-from-the-internet-now?ref=metacurity.com)*,* [*Ynet News*](https://www.ynetnews.com/tech-and-digital/article/bydiqhhume?ref=metacurity.com)*,* [*MakeUseOf*](https://www.makeuseof.com/lg-tv-collect-data-record-audio-turned-off/?ref=metacurity.com)*,* [*XDA*](https://www.xda-developers.com/lg-is-reportedly-collecting-your-voice-data-even-when-your-tv-is-off-as-its-executives-claim-that-they-own-the-glass/?ref=metacurity.com)*,*[ *Cyber Security News*](https://cybersecuritynews.com/lg-smart-tvs-caught-scanning-networks/?ref=metacurity.com) ### BMS Engineering, an IT company that works for a number of Luxembourg doctors' offices, has fallen victim to a major cyberattack, with at least 80 medical practices affected. The company at the center of the incident, BMS Engineering, was also the one that installed the Immediate Direct Payment (PID) used by doctors. As reporter.lu writes, the affected practices risk losing at least some of their data. Déi Gréng (Green) MP Djuna Bernard already tabled a parliamentary question to Health Minister Martine Deprez on Monday afternoon, asking, in particular, whether data has in fact been lost and what lessons the government intends to draw from the incident. ([RTL Today](https://today.rtl.lu/news/luxembourg/cyberattack-on-it-firm-hits-at-least-80-luxembourg-doctors-offices-1182574347?ref=metacurity.com)) ### Belgium’s revelation that it had arrested a Chinese citizen on suspicion of stealing advanced microchip technology is fueling European anxiety about Beijing’s trade practices and quest for industrial secrets. Belgian officials said that in May they had arrested a man, who also holds Belgian citizenship, just before he was due to fly to Beijing. The arrest was part of an investigation into the possible transfer of intellectual property and trade secrets from a Belgian semiconductor company to a Chinese company, prosecutors said. The detention marks the latest escalation in a long-running battle between China and its Western rivals over technological advances in critical industries such as semiconductors. European intelligence agencies have warned that Chinese entities target Western researchers and companies to gain access to technology its companies can exploit. US restrictions on selling advanced semiconductor technology to China have helped make that industry a prime target. ([Kim Mackrael / Wall Street Journa](https://www.wsj.com/world/china/belgiums-arrest-of-chinese-alleged-chip-tech-thief-fuels-european-fear-of-beijing-5824008f?ref=metacurity.com)l) ***Related:*** [*Financial Times*](https://www.ft.com/content/356cf253-7711-4a89-8139-5b0152824975?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/world/china/belgium-detains-chinese-man-suspicion-semiconductor-espionage-2026-09-07/?ref=metacurity.com)*,* [*Euronews*](https://www.euronews.com/my-europe/2026/09/07/belgian-prosecutors-detain-former-reasearcher-and-probe-alleged-chinese-espionage-at-bankr?ref=metacurity.com)*,* [*Associated Press*](https://apnews.com/article/belgium-china-spying-semiconductors-belgan-854428cfb9cbcc914910624293923f5a?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-09-07/chinese-chip-spy-suspect-arrested-before-brussels-beijing-flight?ref=metacurity.com) ### Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. One of the security issues, tracked as CVE-2026-67276, is an SSH authentication bypass flaw in MikroTik RouterOS caused by incomplete validation of RSA public keys. An attacker who knows a username and the public modulus of that user’s key can exploit it by crafting a different key and logging in without the legitimate private key. The second security issue is identified as CVE-2026-86060\. It is an SSH privilege escalation flaw in MikroTik RouterOS due to improper handling of specially crafted usernames. Hackers can leverage it using a specially crafted username to manipulate the SSH session so that the attacker obtains full administrative privileges. Both vulnerabilities were discovered by Poland's CERT agency with the help of GPT-5.5-cyber and GPT-5.6-sol and received a critical severity rating. The Polish agency dubbed the exploit chain “MikroTrick,” and warned that it is now actively exploited in the wild. “In recent days we have been observing attacks against RouterOS devices accessible from the internet,” Poland's CERT warns. “We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks.” The Polish CERT also highlighted a third flaw, CVE-2026-67277, which affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or to crash/restart the router remotely. MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/?ref=metacurity.com)) ***Related:*** [*MikroTik*](https://mikrotik.com/supportsec/september-2026-vulnerability/?ref=metacurity.com)*,* [*CERT-LV*](https://cert.gov.lv/lv/2026/09/uzbruceji-pastiprinati-censas-kompromitet-mikrotik-marsrutetajus?ref=metacurity.com)*,* [*CERT-PL*](https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/?ref=metacurity.com)*,* [*r/cybersecurity*](https://www.reddit.com/r/cybersecurity/comments/1w8tp9q/attackers%5Fhijack%5Fmikrotik%5Frouters%5Fthrough/?mid=1&ref=metacurity.com#cid=3699398) ### On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and passport control, along with airport WiFi sign-ups across Manchester, Stansted and East Midlands involved reportedly 8.8 million people. A few days later, the group calling itself FulcrumSec claimed it and said something that caught my eye. They said they didn't hack anything. They said they read an API key out of the website's JavaScript. That's a very specific, very checkable claim. Everything they described was there. Three keys, one per airport, in the page source, unrotated for over four years, for anyone to see. Their claim, as reported, was that they "obtained access using airport-specific Iterable – a marketing automation platform – API credentials exposed in client-side JavaScript." If all three are true, this isn't a breach in the way people picture one. There's no intrusion, no lateral movement, no malware. It's someone opening DevTools, good old 'F12 is hacking' stuff. ([Scott Helme](https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach/?ref=metacurity.com)) **Related:** [*FulcrumSec*](https://fulcrumsec.vg/mag/?utm%5Fsource=scotthelme.co.uk) ### Access control bugs quietly became the most expensive category of smart contract failure. OWASP’s 2026 Smart Contract Top 10 ranks access control vulnerabilities at #1, tying them to $953.2 million in documented losses, ahead of logic errors, reentrancy, and flash loan exploits combined. A separate 2026 audit findings report puts access control and authorization failures at roughly 35% of high-severity findings across audits conducted between 2025 and 2026\. If you ship a Solidity contract this quarter, this is the bug class most likely to drain it. ([Laura Bennett / Shattered](https://shattered.io/smart-contract-access-control-testing-2026/?ref=metacurity.com)) **Related:** [*OWASP*](https://owasp.org/www-project-smart-contract-top-10/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-29.png) Source: OWASP. ### Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang’s global extortion campaign against Oracle customers. In a notification letter dated August 31, 2026, and filed with the California Attorney General’s office on September 4, as detailed in the official filing published by the California Attorney General’s Office, the bakery giant said the incident traced back to a third-party vendor that relied on Oracle EBS. The company disclosed that its investigation determined on December 6, 2025, that attackers had exploited the zero-day to acquire files stored within the platform. Bimbo Bakeries said it applied Oracle’s emergency patches as soon as it learned of the flaw and launched a forensic review to determine exactly what data had been exposed. That review took months to complete. It wasn’t until August 19, 2026, that the company confirmed one of the stolen files contained victims’ names and Social Security numbers, triggering the formal notification process required under state breach-disclosure laws. ([Guru Baran / Cyber Security News](https://cybersecuritynews.com/bimbo-oracle-ebs-data-breach/?ref=metacurity.com)) ***Related:*** [*California Attorney General*](https://oag.ca.gov/system/files/BBU%20-%20California%20Notification.pdf?ref=metacurity.com)*,* [*Cyber Insider*](https://cyberinsider.com/bimbo-bakeries-confirms-data-stolen-in-oracle-ebs-zero-day-attack/?ref=metacurity.com) ### Jaguar Land Rover confirmed it will eliminate around 4,000 roles over the next two years, roughly ten percent of its global workforce, as the British luxury carmaker moves to recover from a costly cyberattack and mounting financial pressure. The company framed the reductions as a voluntary redundancy scheme aimed at delivering £1.7 billion (US$2.3 billion) in cost savings. The Tata Motors-owned manufacturer identified management positions as those most at risk, and local media reports indicate the bulk of the cuts will fall in the U.K., where around 34,000 of JLR's employees are based. The announcement landed just days after Volkswagen said its management and unions had agreed to cut a total of 100,000 jobs by the end of the decade, the largest restructuring in the global auto industry's history. ([Marcus Lewinsky / AutoGuide](https://www.autoguide.com/auto/jaguar-land-rover-to-cut-4-000-jobs-in-major-restructuring-44638180?ref=metacurity.com)) **Related:** [*CNBC*](https://www.cnbc.com/2026/09/07/jaguar-land-rover-jlr-job-cuts-autos.html?ref=metacurity.com)*,* [*UPI*](https://www.upi.com/Top%5FNews/World-News/2026/09/07/Jaguar-Land-Rover-layoffs-4000-workers-bid-slash-costs/1151788800508/?ref=metacurity.com) ### Best Thing of the Day: To Catch a Voice Impersonator The Dutch National Investigation and Intervention Unit, led by the National Public Prosecutor's Office, revealed earlier this year that a Dutch-speaking man called the telecom provider's customer service and impersonated a colleague from the IT department and [played an audio fragmen](https://www.politie.nl/gezocht/opsporingsbericht/2026/september/11-datadiefstal-odido?ref=metacurity.com)t on a broadcast in hopes of identifying him. ### Bonus Best Thing of the Day: Not Enough, But Better Than Nothing Grindr [has agreed ](https://www.bbc.com/news/articles/cn8e63qdqwzo?at%5Fmedium=RSS&at%5Fcampaign=rss&ref=metacurity.com)to pay £26m to settle a lawsuit over allegations that it shared users' personal information - including their HIV status - with third parties. ### Worst Thing of the Day: Why Even Attack Something Like This? The world's best database of meteors (and also reentries) [got taken out](https://fireball.amsmeteors.org/?ref=metacurity.com) by a cyberattack and expects several weeks of partial downtime as it transitions to new infrastructure and services. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/image-23.png) ### Agents, algorithms and false assurances: Best infosec long reads 9/5/26 URL: https://www.metacurity.com/agents-algorithms-and-false-assurances-best-infosec-long-reads-9-5-26/ Last updated: 2026-09-05T13:40:42.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/pexels-gustavo-martinez-1539476028-28830879-1.jpg) Source: [GUSTAVO EDMUNDO MARTINEZ GONZALEZ](https://www.paypal.com/donate?token=JqWjNcruJUt92UF0u-jw%5FYRR9z3lCNseKG7g0Ekef5H7FzGO9pDUpwe7dyhUaIH%5FQ7JH8vKoZtrGQIbZ&locale.x=US&ref=metacurity.com) via Pexels. *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* [Upgrade my subscription](#/portal/account/plans) **9/5/26:** This week’s long reads issue examines the gap between claims and reality in technological and national-security competence, from an AI agent that escaped a supposedly controlled test and agents that pass remediation benchmarks without fixing vulnerabilities to quantum companies promising breakthroughs despite uncertain progress. Elsewhere, election-fraud activists used a noted academic’s contested research to bolster unsupported claims, while a top cyber academic argues that the Trump administration has invoked “national security” to justify indiscriminate and counterproductive technology bans. ### Exclusive - How a Texas Student Blew the Whistle on a Rogue AI Hacking Attempt Reuters' Raphael ​Satter, Leo Marchandon, and Callaghan O'Hare [tell the fascinating tale](https://www.usnews.com/news/top-news/articles/2026-08-20/exclusive-how-a-texas-student-blew-the-whistle-on-a-rogue-ai-hacking-attempt?ref=metacurity.com) of how a "rogue" AI agent deployed in a British government security test attempted to compromise an open-source project and created multiple fake personas to discredit Sinan Can Demir, the student who exposed it. > Demir, a soft-spoken junior from the Turkish city of Konya, said he had been frustrated after being turned down for more than 20 internships over the summer. So he turned to GitHub to build up his coding portfolio. > The Microsoft-owned site is a hub for open-source software, so-called because its source code is freely downloadable and auditable by anyone. Developers use GitHub to comment on one another’s ⁠projects, flag bugs, suggest changes — known as pull requests, or PRs — and work collaboratively on software updates. Some in the technology industry see a coder’s GitHub activity as a ⁠proxy for a potential recruit’s productivity. So when Demir spotted a set of software projects that might need help, he figured he could pitch in while boosting his profile. > That’s when things got weird. > Demir discovered that a user named miraholt31 was trying to sneak a malicious update into one of the projects, a network scanning program called myNetwork. Demir took to the project’s message board to warn that the pull request was a trap. > “The PR contains a hidden malware dropper,” he said, according to the archived exchange. > The agent pushed back, falsely claiming — through its miraholt31 account — that the pull request was harmless. It also created a second account, masquerading as Lena Brandt, an engineer based in Germany, to agree that the update was clean and pressure myNetwork’s maintainer into accepting it. > Demir told Reuters that the counterarguments "made me second-guess whether I was wrongly accusing someone." But after turning to Anthropic's Claude chatbot to confirm his suspicions, he held firm. The creator of myNetwork eventually agreed with him, writing that they had rejected the update "for security reasons." _This post is for paying subscribers only._ ### OpenAI rolls out GPT-6 Astra with ‘critical’ cyber capabilities tightly restricted URL: https://www.metacurity.com/openai-rolls-out-gpt-6-astra-with-critical-cyber-capabilities-tightly-restricted/ Last updated: 2026-09-08T10:51:27.000Z The company is giving Daybreak participants first access to its powerful new model after an unrelated AI escape and Hugging Face breach prompted additional safeguards. _This post is for paying subscribers only._ ### Google debuts Gemini 3.8 Flash Cyber for autonomous vulnerability discovery URL: https://www.metacurity.com/google-debuts-gemini-3-8-flash-cyber-for-autonomous-vulnerability-discovery/ Last updated: 2026-09-04T14:16:08.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/gemini3.8cyber-2.png) Source: Google. ### Google announced Gemini 3.8 Flash Cyber (replacing 3.5) for trusted testers — via a new Fairwind Program — with “frontier-level performance in autonomous vulnerability discovery.” The Chrome Security team found that 3.8 Flash Cyber produced 2.6 times more correct patches to vulnerabilities in Chrome than the best commercial models that are much larger. Wiz found that Gemini 3.8 Flash Cyber achieves +7.5-9.7% higher recall on their internal penetration testing benchmark for a 2.3-5.2x lower cost compared to other leading frontier models. Google’s Cloud Vulnerability Research team leveraged the 3.8 Flash Cyber model to find a critical foundational vulnerability in less than 2 hours, a vulnerability for which research and discovery usually takes months. Google also announced the rollout of Gemini 3.8 Flash, marking the third Flash update in three months. Gemini 3.8 Flash “delivers substantial gains” over its predecessor in various benchmarks, with Google also noting how it is “often approaching the performance of higher-cost frontier models.” Gemini 3.8 Flash is already live in the Gemini app for Google AI Pro and Ultra subscribers, AI Mode, and Gemini in Google Sheets. It’s also available for developers in Google Antigravity, AI Studio, and the Gemini API. ([Abner Li / 9t5Google](https://9to5google.com/2026/09/02/gemini-3-8-flash-launch/?ref=metacurity.com)) ***Related:*** [*Google*](https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2026/09/02/google-launches-two-gemini-3-8-models-with-cutting-edge-reasoning-capabilities/?ref=metacurity.com)*,* [*VentureBeat*](https://venturebeat.com/security/googles-gemini-3-8-flash-is-built-for-agents-while-its-cyber-twin-hunts-vulnerabilities?ref=metacurity.com)*,* [*Implicator.ai*](https://www.implicator.ai/gemini-3-8-flash-scores-59-behind-fable-and-sol/?ref=metacurity.com)*,* [*The Deep View*](https://www.thedeepview.com/articles/gemini-3-8-flash-s-edge-is-intelligence-per-dollar?ref=metacurity.com)*,* [*NewsCord*](https://newscord.org/article/google-rolls-out-gemini-38-flash-in-ai-mode-adds-gemini-38-flash-cyber--Story%5F20260902%5FGooglereleasesGemini9dc5fc71?ref=metacurity.com)*,* [*Thurrott*](https://www.thurrott.com/a-i/340992/google-releases-gemini-3-8-flash-and-cyber-variant?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/gemini-3-8-flash-cyber/?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=49537553&ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1w5eez1/introducing%5Fgemini%5F38%5Fflash%5Fand%5F38%5Fflash%5Fcyber/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/988742/google-gemini-3-8-flash?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/ai-and-ml/2026/09/02/with-gemini-38-flash-google-reminds-everyone-its-still-in-the-race/5294049?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/ai/2026/09/google-releases-gemini-3-8-flash-its-third-flash-model-in-six-weeks/?ref=metacurity.com)*,* [*Artificial Analysis*](https://artificialanalysis.ai/articles/gemini-3-8-flash?ref=metacurity.com)*,* [*iClarified*](https://www.iclarified.com/101967/google-launches-gemini-38-flash-and-38-flash-cyber?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/gemini-3-8-flash-google-ai-model-3706483/?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/gemini-3-8-flash-goes-live-as-runtimewire-begins-head-to-head-testing?ref=metacurity.com)*,* [*Search Engine Land*](https://searchengineland.com/gemini-3-8-flash-rolling-out-in-google-search-486630?ref=metacurity.com)*,* [*Forkast*](https://forkast.news/google-deepmind-ships-gemini-3-8-flash-and-cyber-six-weeks-three-flash-models-one-compute-landlord-thesis/?ref=metacurity.com)*,* [*The New Stack*](https://thenewstack.io/google-ships-its-third-gemini-flash-model-in-six-weeks/?ref=metacurity.com)*,* [*9to5Google*](https://9to5google.com/2026/09/02/deals-nothing-ear-3a-galaxy-flip-8-2026-ideapad/?mid=1&ref=metacurity.com#cid=3692961)*,* [*Forkast*](https://forkast.news/google-deepmind-ships-gemini-3-8-flash-and-cyber-six-weeks-three-flash-models-one-compute-landlord-thesis/?mid=1&ref=metacurity.com#cid=3693160)*,* [*Unite.AI*](https://www.unite.ai/google-launches-gemini-3-8-flash-with-cybersecurity-variant/?ref=metacurity.com)*,* [*BeInCrypto*](https://beincrypto.com/google-antitrust-adx-ruling-stock-impact/?mid=1&ref=metacurity.com#cid=3692802)*,* [*Wall Street Journal*](https://www.wsj.com/tech/ai/new-google-ai-model-said-to-narrow-gap-on-coding-ability-264c6052?st=aeqCY9&reflink=desktopwebshare%5Fpermalink&ref=metacurity.com)*,* [*Android Headlines*](https://www.androidheadlines.com/2026/09/google-debuts-gemini-3-8-flash-cyber-variants.html?mid=1&ref=metacurity.com#cid=3693149)*,* [*TechRadar*](https://www.techradar.com/seasonal-sales/17-best-labor-day-tv-deals-i-recommend-expert-picks-from-usd99-99-on-4k-qled-and-oled-tvs?mid=1&ref=metacurity.com#cid=3692749)*,* [*The420CyberNews*](https://the420.in/google-launches-gemini-flash-cyber-ai/?mid=1&ref=metacurity.com#cid=3693401)*,* [*Cyber Security News*](https://cybersecuritynews.com/gemini-3-8-flash-cyber/?mid=1&ref=metacurity.com#cid=3693248)*,* [*Search Engine Journal*](https://www.searchenginejournal.com/google-gemini-3-8-flash-ai-mode/588194/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/ai/2026/09/google-releases-gemini-3-8-flash-its-third-flash-model-in-six-weeks/?mid=1&ref=metacurity.com#cid=3692640)*,* [*Google*](https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-8-Flash-Model-Card.pdf?ref=metacurity.com)*,* [*SammyGuru*](https://sammyguru.com/gemini-3-8-flash-launch/?ref=metacurity.com)*,* [*Quartz*](https://qz.com/google-gemini-38-flash-coding-ai-model-090226?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/google-launches-gemini-38-flash-with-frontier-level-performance-at-a-fraction-of-the-price/?ref=metacurity.com)*,* [*CNBC Television on YouTube*](https://www.youtube.com/watch?v=4Y4dUcXYz10&ref=metacurity.com)*,* [*Blockchain.News*](https://blockchain.news/news/google-gemini-3-8-flash-cyber-release?ref=metacurity.com)*,* [*NPowerUser*](https://nokiapoweruser.com/gemini-3-8-flash-release-reasoning-coding/?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/google-avoids-adtech-breakup-in-federal-judge-ruling-2026-9?mid=1&ref=metacurity.com#cid=3693280)*,* [*WebProNews*](https://www.webpronews.com/google-dodges-breakup-in-ad-tech-monopoly-case/?mid=1&ref=metacurity.com#cid=3693353)*,* [*Digital Journal*](https://www.digitaljournal.com/article/us-judge-rejects-bid-to-break-up-googles-ad-business/?mid=1&ref=metacurity.com#cid=3692834) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/09/gemini3.8better-2.png) Source: Google. --- **Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### OpenAI’s Astra crosses the critical cyber threshold URL: https://www.metacurity.com/openais-astra-crosses-the-critical-cyber-threshold/ Last updated: 2026-09-02T14:08:44.000Z Astra discovered and exploited two zero-days in testing, prompting OpenAI to restrict its most powerful cyber capabilities while deploying safeguards against both malicious users and unauthorized actions by the AI itself. _This post is for paying subscribers only._ ### Trump launches Texas test bed for nationwide water cyber defense URL: https://www.metacurity.com/trump-launches-texas-test-bed-for-nationwide-water-cyber-defense/ Last updated: 2026-09-01T14:46:01.000Z Project Watershed 250 will pair federal and Texas officials with technology companies in a six-month effort to find and fix vulnerabilities in water systems before expanding the model nationwide. _This post is for paying subscribers only._ ### Infostealers hijack Claude accounts and drain users’ usage URL: https://www.metacurity.com/infostealers-hijack-claude-accounts-and-drain-users-usage/ Last updated: 2026-08-31T14:03:16.000Z Anthropic is signing out affected users, removing payment methods, and refunding unauthorized charges after malware stole active Claude sessions from infected PCs. _This post is for paying subscribers only._ ### Surveillance, scams and machines: Best infosec long reads 8/29/26 URL: https://www.metacurity.com/next-long-read-12/ Last updated: 2026-08-29T13:22:47.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/Ray-Ban_Stories-1.jpg) Source: [cavebear42](https://commons.wikimedia.org/w/index.php?title=User:Cavebear42&action=edit&redlink=1&ref=metacurity.com "User:Cavebear42 (page does not exist)") *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* [Upgrade my subscription](#/portal/account/plans) **8/29/26:** This week’s long reads explore the technologies that enable deception, surveillance, and control—from the infrastructure behind a global cryptocurrency scam network and the human consequences of ubiquitous license-plate readers and camera-equipped smart glasses, to the secret history of the NSA’s Cold War code-breaking supercomputer. They also revisit the early warnings that mass data collection, automated prediction and computer-driven decision-making could transform politics and undermine democracy. ### The Scam Hunt NRK's Martin Gundersen and Dan Kåre Engebretsen, along with Premium Times' Chinagorom Ugwu, [report](https://www.nrk.no/dokumentar/xl/the-scam-hunt-1.17997585?ref=metacurity.com) on their investigation into a global cryptocurrency fraud network and follow a Norwegian ethical hacker as he penetrates hundreds of fake investment sites, traces millions in stolen funds, and uncovers the Nigerian web-hosting operation that helped make the scams possible. > Daniel Christensen rarely says no to hunting down a fraudster. His favorite hobby is hacking into computer systems. When Daniel helped comedian Johan Golden figure out who was using his face to run scams, he picked up the trail of Hagen's TikTok imposters. > The scammers thought they had tricked another person into investing money on the website they had set up. > They did not know that Christensen was the wolf, and not the sheep. > – I could see immediately that the website was not legitimate. > It did not take Christensen long to get behind the scenes of the website. > The information there made the website's purpose unmistakably clear: > To defraud people out of as much money as possible. Those behind it would go in and increase the "returns" on the invested money with a few keystrokes. > As he investigated the websites, more and more of them kept appearing. > All with the same flaw. > All with lists full of unwitting investors. > One woman on the list was a nurse from the United States. Christensen could see that she had recently deposited money into the website. > – She was about to send more, so I called her, he says. > He warned the woman, but it took several conversations before he managed to convince her that the investment website was fake. > She was stopped from transferring 320 USD. By then the woman had already lost around 2,000 USD, according to her own account. > Christensen realized he could not call everyone. > He had a new idea. > What if he changed the payment address on the websites? > The money would then go to him and not to the unknown scammers who had created the website. > The plan: to transfer the money back to those who had been deceived. > It worked. But only for a short while. > The scammers quickly shut down the clever attempt. > Now all the websites showed nothing where the payment addresses had previously been. > Who could be behind it? Christensen took a fresh look at the investor lists. One entry caught his attention. The person called themselves "Eagleworker" and had an investor profile on many of the sites. > Last fall, Christensen shared everything he had found with NRK. > He had found 100 websites. NRK found 200 more. > The websites shared certain features that made it possible to establish that they had the same origin. > 60 websites had the same code flaw, through which you could easily see the backend system. > NRK's analysis shows that over 5,000 investors had entered their full name, phone number, and email address on the fraudulent websites. > 55 entries were associated with a Norwegian phone number. Some had uploaded their passport to verify their identity. _This post is for paying subscribers only._ ### Nearly 130 companies warn the window is closing to defend against AI cyberattacks URL: https://www.metacurity.com/nearly-130-companies-warn-the-window-is-closing-to-defend-against-ai-cyberattacks/ Last updated: 2026-08-30T14:59:22.000Z ![yellow and black Warning graffiti](https://images.unsplash.com/photo-1565043534656-9385083a5871?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDIyfHx3YXJuaW5nfGVufDB8fHx8MTc4NzkxNTY3OXww&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Duncan Kidd](https://unsplash.com/@we%5Fthe%5Froyal?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) ### A who's who of nearly 130 private sector companies, including top-tier cybersecurity companies CrowdStrike, Palo Alto Networks, Fortinet, SentinelOne, and others, [signed an open letter ](https://www.axios.com/2026/08/27/openai-anthropic-issue-dire-cyber-threat-warning?stream=technology&utm%5Fsource=alert&utm%5Fmedium=email&utm%5Fcampaign=alerts%5Ftechnology)pleading for a global effort to strengthen cyber defenses in the "narrow window" they have left to defend against AI-enabled cyberattacks. The letter warns that "longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems have left systems exposed" and that every organization should make "cyber defense an immediate leadership priority." The signatories, who include major technology companies such as Microsoft and Google, leading banks, consulting firms, and telecom providers, among others, urged cybersecurity and technology companies to embrace a more collaborative model to help deploy tools and verify tools for critical infrastructure companies, important supply chain manufacturers, and system integrators, among other kinds of community-oriented assistance. They call on governments to coordinate and strengthen cyber defense at local, national, and international levels. Finally, they ask AI companies to provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders. The letter organizers say this plea is a rolling effort, with more organizations expected to join over time. What prompted the unusually stark and urgent appeal is unclear. It follows a spate of recent high-profile, but ultimately low-impact, attacks on water companies and comes after [an appeal](https://www.gatesnotes.com/work/make-ai-work-for-everyone/reader/a-turbulent-ai-era-and-critical-choices-to-make?WT.mc%5Fid=20260826%5Fai-overture-2026-med-med&ref=metacurity.com) earlier in the week from Bill Gates warning that AI is far more dangerous than tech companies realize. But perhaps more consequentially, earlier this summer the tech sector was rocked by back-to-back reports of AI models "going rogue" when they exceeded the boundaries of controlled tests to gain unauthorized access of real-world systems, transforming autonomous cyberattacks from theory to real-world security concerns. Notably absent from the signatory list were any government agencies, utilities, hospitals, or non-profit organizations that aim to protect the most vulnerable organizations. (Cynthia Brumfield / Metacurity) **Related:** [*OpenAI*](https://openai.com/collective-cyberdefense/?ref=metacurity.com)*,* [*OpenAI*](https://openai.com/collective-cyberdefense/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/legal/litigation/major-tech-companies-call-defensive-surge-defeat-ai-driven-hacks-2026-08-27/?ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2026/08/27/technology/openai-letter-ai-attacks.html?unlocked%5Farticle%5Fcode=1.8lA.rZLk.-sabgVeFOe8z&smid=nytcore-android-share&ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-08-27/openai-anthropic-urge-cyber-defense-action-as-ai-models-improve?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/ai-cyber-defense-global-surge/?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/08/27/ai-cyber-defense-letter.html?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/08/27/openai-anthropic-google-and-100-other-companies-call-for-action-to-defend-against-rogue-ai/?ref=metacurity.com)*,* [*Politico*](https://www.politico.com/news/2026/08/27/openai-anthropic-google-ai-cyber-letter-01052839?ref=metacurity.com)*,* [*BBC*](https://www.bbc.com/news/articles/cwyz11475l1o?ref=metacurity.com)*,* [*Seeking Alpha*](https://seekingalpha.com/news/4637603-make-cyber-defense-an-immediate-leadership-priority-say-100-plus-companies?ref=metacurity.com)*,* [*The Decoder*](https://the-decoder.com/openai-rallies-100-companies-to-sign-open-letter-warning-ai-powered-cyberattacks-on-critical-infrastructure-are-imminent/?ref=metacurity.com)*,* [*Agence France-Presse*](https://www.koreatimes.co.kr/world/20260828/top-tech-companies-urge-global-response-against-ai-cyber-threats?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/openai-collective-action-cyber-defense-anthropic-hugging-face-hack-2026-8?ref=metacurity.com)*,* [*Tech.co*](https://tech.co/news/open-ai-leader-warns-ai-cyber-attacks?ref=metacurity.com)*,* [*Gizmodo,*](https://gizmodo.com/google-openai-and-over-100-companies-call-for-more-action-on-ai-driven-cyberattacks-2000804091?mid=1&ref=metacurity.com#cid=3684752)[*Sky News*](https://news.sky.com/story/tech-companies-write-open-letter-calling-for-collective-action-against-ai-enabled-cyber-attacks-13577985?mid=1&ref=metacurity.com#cid=3684184)*,* [*Becker's Hospital Review*](https://www.beckershospitalreview.com/healthcare-information-technology/innovation/openai-microsoft-100-firms-warn-of-coming-ai-cyberattack-surge/?ref=metacurity.com#cid=3684957)*,* [*Silicon Republic*](https://www.siliconrepublic.com/machines/household-names-co-sign-open-letter-on-ai-cybersecurity-threat?ref=metacurity.com)*,* [*Mobile Europe*](https://www.mobileeurope.co.uk/open-ai-microsoft-cyberattacks/?mid=1&ref=metacurity.com#cid=3685453)*,* [*Digit*](https://www.digit.fyi/ai-cyber-attack/?mid=1&ref=metacurity.com#cid=3685777)*,* [*BeInCrypto*](https://beincrypto.com/openai-letter-ai-cyberattack-warning/?mid=1&ref=metacurity.com#cid=3685273)*,* [*Business Standard*](https://www.business-standard.com/technology/artificial-intelligence/collective-cyber-defence-openai-100-companies-ai-cyber-threats-126082800477%5F1.html?mid=1&ref=metacurity.com#cid=3685372) --- **Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### US disrupts China-linked operation targeting government and critical infrastructure URL: https://www.metacurity.com/us-disrupts-china-linked-operation-targeting-government-and-critical-infrastructure/ Last updated: 2026-08-28T13:36:22.000Z FBI and NSA seized domains underpinning the QTFY operation, which allegedly breached NASA, the Federal Reserve, the Energy Department and Senate while concealing its activity through compromised devices and clandestine networks spanning more than 130 countries. _This post is for paying subscribers only._ ### OpenAI disrupted an elaborate Russian influence operation URL: https://www.metacurity.com/openai-disrupted-an-elaborate-russian-influence-operation/ Last updated: 2026-08-27T13:42:02.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/openairussianinfocampaign-1.png) LinkedIn post generated by this operation and posted on the platform. Source: OpenAI. ### OpenAI said it disrupted a previously unreported Russian influence operation that used ChatGPT to promote an elaborate fake think tank designed to lend credibility to pro-Kremlin narratives. The operation centered on the International Burke Institute, or IBI, which presented itself as an Israel-based “expert community” and published a proprietary “sovereignty index” that praised Russia while portraying the United States, European Union, France, Germany, and other Western governments as weak or subordinate to foreign interests. OpenAI said operators in Russia used VPNs to evade its prohibition on access from the country. They prompted ChatGPT in Russian to produce mostly English-language promotional posts and comments—explicitly instructing the model to remove linguistic clues pointing to their Russian origin—and distributed the material through X, Facebook, LinkedIn, Substack and Telegram. ChatGPT was also used to generate German-language pro-Russian posts, create logos for about a dozen Telegram channels targeting audiences in several countries, and produce Russian-language summaries of those channels’ activity. The campaign’s distinctive feature was not simply its use of AI, but also the infrastructure behind it. The IBI website claimed prominent scholars, including Francis Fukuyama and Noam Chomsky, among its experts and stocked its pages with apparently authoritative research. OpenAI found that 34 of 36 sampled articles had been copied from elsewhere, sometimes attributed to the wrong authors. The core website articles and sovereignty reports were not generated with OpenAI’s models. OpenAI described the campaign as the most elaborate Russia-linked influence operation it has disrupted, and the first it has identified using a fabricated research institution and proprietary index to manufacture intellectual authority for favored narratives. Some associated accounts posed as ordinary users or domestic news outlets, while the operators attempted to conceal the campaign’s Russian provenance. The operation nevertheless achieved limited reach. Most social-media posts drew few views, and IBI’s official accounts attracted small audiences, although affiliated Telegram channels generally claimed between 10,000 and 20,000 subscribers. OpenAI rated the campaign at the lower end of Category Three on the Brookings Breakout Scale, indicating activity across multiple platforms with some penetration of authentic audiences. OpenAI banned the associated ChatGPT accounts. The case shows how generative AI can serve as a supporting layer in a broader influence operation—producing multilingual promotional content, populating false personas, and coordinating distribution—while the principal deception rests on more traditional techniques such as plagiarism, false attribution, and fabricated institutional legitimacy. ([OpenAI](https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/?ref=metacurity.com)) ***Related:*** [*The Decoder*](https://the-decoder.com/russia-used-chatgpt-to-run-a-covert-influence-campaign-pushing-pro-kremlin-narratives-across-the-west/?ref=metacurity.com)*,* [*Le Monde*](https://www.lemonde.fr/en/pixels/article/2026/08/25/russian-disinformation-on-chatgpt-fake-telegram-channels-fake-videos-and-a-real-fake-israeli-think-tank%5F6756822%5F13.html?ref=metacurity.com)*,* [*CTech*](https://www.calcalistech.com/ctechnews/article/qde5oyso6?ref=metacurity.com)*,* [*Ynet News*](https://www.ynetnews.com/tech-and-digital/article/hk8sag3pmg?ref=metacurity.com)*,* [*Anadolu Ajansı*](https://www.aa.com.tr/en/europe/russia-s-ai-disinformation-campaign-linked-to-israel-based-think-tank-spiegel/4037407?ref=metacurity.com)*,* [*UA.news*](https://ua.news/en/technologies/chatgpt-zablokuvav-akaunti-z-rf-poviazani-z-dezinformatsiieiu?ref=metacurity.com)*,* [*Israel Defense*](https://www.israeldefense.co.il/en/node/70412?ref=metacurity.com)*,* [*RBC-Ukraine*](https://newsukraine.rbc.ua/news/russia-s-bot-network-used-chatgpt-in-a-massive-1787739273.html?ref=metacurity.com)*,* [*Informat*](https://informat.ro/en/international/openai-blocks-accounts-from-russia-used-for-disinformation-136354?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-78.png) Substack comment generated by this operation in reply to a post on the platform. Source: OpenAI. [](https://www.mk.co.kr/en/world/12135618?ref=metacurity.com) --- **Metacurity is the cybersecurity news you'd need hours to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### Chinese state-linked hackers use DeepSeek to scale attacks URL: https://www.metacurity.com/chinese-state-linked-hackers-use-deepseek-to-scale-attacks/ Last updated: 2026-08-26T13:39:21.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/DeepSeek_purple-1.png) Source: [RoadMaster19](https://commons.wikimedia.org/wiki/User:RoadMaster19?ref=metacurity.com "User:RoadMaster19") ### According to TeamT5, a Taiwanese research firm, Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers’ ability to leverage basic AI tools to hit targets abroad. State-affiliated cyber groups more than doubled the number of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, TeamT5 reports. Researchers said it wasn’t always possible to identify the AI model they used, but in general, DeepSeek’s offerings are popular with hackers in the country because of their high performance and ability to be customized. They also say experienced Chinese hackers are using far less capable AI to scale up their activities and achieve breakthroughs. While other models produced in the country are more powerful – including Moonshot’s breakout Kimi K3 model – hackers are drawn to DeepSeek’s relatively lax cybersecurity barriers and low cost of running, researchers said. They added that they had yet to record an incident involving Kimi K3, which they believe is prohibitively expensive for hackers to run. “DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5\. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.” Along with a mix of other open-source models, DeepSeek has been adopted throughout multiple stages of an attack, conducting reconnaissance and generating means of attacking vulnerabilities, TeamT5 said. They said in recent months they’ve obtained scripts and logs showing the model being used by hackers affiliated with the Chinese government throughout their operations. A group known as Grimfengxi used DeepSeek to create exploit code. Another group, called Huapi, used a Chinese AI model, which researchers said was likely DeepSeek, to attack an email system of a Taiwanese company. A third, known as Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map a company’s domains. In some cases, Chinese hackers turned to American AI for help. The cybersecurity firm CyCraft said a company that sells hacking software used ChatGPT during an attack on a Western think tank. After obtaining a copy of an employee’s local Signal database from a compromised computer, the hackers consulted the chatbot to help build a software module designed to decrypt it, according to screenshots reviewed by Bloomberg News. Researchers discovered this after finding a public shared drive with thousands of Chinese-language screenshots taken as recently as February. The images show the workflow of a small startup comprising about 10 employees developing hacking tools for sale. They charged between 300,000 yuan ($44,500) and 500,000 yuan ($74,000) for their software. ([Mark Anderson / Bloomberg](https://www.bloomberg.com/news/articles/2026-08-24/chinese-hackers-use-deepseek-to-boost-attacks-researchers-say-mt7o4205?ref=metacurity.com)) **Related:** [*Implicator.ai*](https://www.implicator.ai/chinese-hackers-double-attack-volume-deepseek/?ref=metacurity.com)*,* [*en.people.cn*](http://en.people.cn/n3/2026/0825/c90000-20491990.html?ref=metacurity.com)*,* [*The Chosun Daily*](https://www.chosun.com/english/industry-en/2026/08/25/6LGGEY3FPZDWDPJHKUYGQJKB4Q/?ref=metacurity.com)*,* [*Chosun Biz*](https://biz.chosun.com/en/en-it/2026/08/25/RGQ7AZXVVJCGZJU6TRODTFH6UI/?ref=metacurity.com)*,* [*NewsBytes*](https://www.newsbytesapp.com/news/science/teamt5-chinese-state-backed-hackers-more-than-doubled-attacks-using-ai/tldr?ref=metacurity.com)*,* [*BeInCrypto*](https://beincrypto.com/chinese-hackers-deepseek-attack-volume/?ref=metacurity.com)*,* [*Firstpost*](https://www.firstpost.com/tech/deepseek-chatgpt-and-claude-how-chinese-hackers-are-using-ai-in-cyberattacks-14040570.html?ref=metacurity.com)*,* [*Maeil Business*](https://www.mk.co.kr/en/world/12135618?ref=metacurity.com) --- **Metacurity is the cybersecurity news you'd need hours to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### Iran-linked UK power generator attack exposes a cybersecurity blind spot URL: https://www.metacurity.com/iran-linked-uk-power-generator-attack-exposes-a-cybersecurity-blind-spot/ Last updated: 2026-08-25T22:27:14.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/Bristol_Proteus_power_plant_-_geograph.org.uk_-_3755218-1.jpg) Bristol Proteus power plant. Source: [Neil Owen](https://www.geograph.org.uk/profile/47623?ref=metacurity.com). ### A cyberattack believed to be linked to Iran knocked a small British power generator offline for four days last month, prompting warnings about the vulnerability of energy infrastructure. That incident creates a potentially important paradox, namely that the plant was too small for its loss to threaten Britain's electricity supply, but its size may also have meant that it was subject to less cybersecurity oversight than facilities considered critical to the grid. Crucial details about the incident — including who carried it out, how the attackers gained access, and whether they actually compromised industrial control systems — remain publicly unconfirmed. The incident, first reported by The Telegraph, affected a small electricity generator and is believed to be the first Iranian-linked cyberattack to shut down a British power facility successfully. The Financial Times reported that the facility was well below the threshold at which "important generators" are legally required to notify the government of cyber activity, according to an unnamed UK official, who described the site as "less than a rounding error compared to grid capacity." Nevertheless, the National Cyber Security Centre and Department for Energy Security and Net Zero briefed energy executives. They wrote directly to companies with "advice, direction and next steps" following the incident. What remains unknown is whether this was an attack on industrial control systems at all. No technical indicators, malware samples, forensic reports or description of the intrusion path have been made public. Nor have British authorities said whether attackers obtained access to operational technology controlling electricity generation, compromised an IT or remote-management system, or caused the operator to shut the facility down as a precaution. Those scenarios would represent substantially different levels of attacker capability. UK Energy Minister Michael Shanks said that the affected generator was minimal in scale, that nobody lost power and that the incident posed no threat to Britain's wider electricity grid. "To be clear: there was no threat to the wider grid, and nobody lost power," Shanks wrote on LinkedIn. The British government has also stopped short of publicly attributing the attack to Iran. For an adversary seeking to demonstrate an ability to disrupt Western infrastructure, smaller facilities could present attractive targets even if their loss has negligible impact on national electricity supply. There is substantial precedent for Iranian-linked groups targeting operational technology. US authorities have repeatedly warned about attacks on internet-accessible industrial control systems. On Aug. 19, the NSA, FBI, Department of Energy, EPA and Cybersecurity and Infrastructure Security Agency warned of active attempts to compromise Siemens S7-series PLCs used across energy, water, manufacturing and other critical infrastructure sectors. That warning followed cyber incidents affecting water utilities in multiple US states that cybersecurity experts suspect may be linked to Iran. Federal authorities, however, have not formally attributed those attacks to Tehran. Iran's Islamic Revolutionary Guard Corps (IRGC) said last month that "any base used for aggression against Iranian territory constitutes a legitimate target for our forces." Moreover, the attacks against US water systems last month were thought to be orchestrated by a group called CyberAv3ngers, operated by the IRGC. The Telegraph reported that the British generator incident occurred around the same period as attacks affecting water infrastructure in 12 US states. Timing alone does not demonstrate that the same group conducted the incidents, exploited the same technology, or formed part of a coordinated Iranian campaign. Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, said that Iran "is realizing it can be more successful in its cyber attacks." She said the incidents suggest Iranian attackers are actively searching for weaknesses and finding exposed facilities. The Guardian reported that the NCSC was understood not to have received outage reports from regulated power station operators. The NCSC and Department for Energy Security and Net Zero briefed energy company executives following the attack. They wrote directly to companies with security advice and recommended next steps, according to the Financial Times. Reuters reported that government, industry and security officials continue to assess the threat and strengthen protections. Britain's most important generators are subject to mandatory cyber reporting requirements, while the facility targeted in this incident fell well below those thresholds. That raises a broader question about whether smaller energy assets could present adversaries with softer targets for producing visible physical disruption. Individually, the loss of one may barely register on the grid. For now, the available evidence supports several conclusions: a small British generator suffered a cyber incident serious enough to leave it offline for four days; Iranian-linked hackers are suspected; the facility appears to have fallen below cybersecurity regulatory thresholds; and British security officials considered the incident important enough to warn the wider energy industry. Until technical details emerge, the incident may be more revealing as a warning about the cybersecurity of smaller energy assets — and the gaps in what is known about them — than as evidence of a significant new Iranian capability against Britain's power system. ([Tony Diver, Rozina Sabur, Matt Oliver / Telegraph](https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/?ref=metacurity.com), [George Parker, Charles Clover, Tom Wilson and Malcolm Moore / Financial Times](https://www.ft.com/content/bae67bb7-ebf8-44fc-8d55-bbfaada47eb7?ref=metacurity.com), [Michael Shanks / LinkedIn](https://www.linkedin.com/posts/michael-shanks-130373344%5Fthe-telegraphs-reporting-today-relates-to-activity-7497258099339161601-RQoZ/?ref=metacurity.com), [Kate ​Holton and Sam Tabahriti / Reuters](https://www.reuters.com/business/energy/uk-briefs-energy-chiefs-after-iran-linked-cyber-attack-reports-2026-08-24/?ref=metacurity.com), [Ronny Reyes / New York Post](https://nypost.com/2026/08/23/world-news/iran-hacks-reveal-weak-spot-on-us-uk-grid-as-regime-aims-to-maximize-disruption-expert/?ref=metacurity.com), [Ben Quinn / The Guardian](https://www.theguardian.com/world/2026/aug/23/iran-linked-hackers-blamed-cyber-attack-british-power-plant?ref=metacurity.com)) **Related:** [*BBC*](https://www.bbc.com/news/articles/ce9793g34yvo?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/hackers-force-uk-power-plant-offline/?ref=metacurity.com)*,* [*New York Post*](https://nypost.com/2026/08/23/world-news/iranian-hackers-shut-down-british-power-plant-for-4-days-report/?ref=metacurity.com)*,* [*Joe.My.God*](https://www.joemygod.com/2026/08/telegraph-iranian-hackers-shut-down-uk-power-plant/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html?ref=metacurity.com)*,* [*Metro.co.uk*](https://metro.co.uk/2026/08/23/iran-linked-hackers-shut-uk-power-plant-worried-29441973/?ref=metacurity.com)*,* [*GB News*](https://www.gbnews.com/news/iran-uk-power-station-attack-wake-up-call?ref=metacurity.com)*,* [*The i Paper*](https://inews.co.uk/news/what-know-iranian-hackers-shut-down-power-plant-4725040?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/world/2026/aug/23/iran-linked-hackers-blamed-cyber-attack-british-power-plant?ref=metacurity.com)*,* [*The Irish Times*](https://www.irishtimes.com/world/uk/2026/08/23/iran-linked-hackers-accused-of-cyberattack-that-shut-down-british-power-plant/?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/08/23/small-uk-power-plant-shut-down-after-iran-linked-cyberattack-report.html?ref=metacurity.com)*,* [*TMCnet*](https://insight.tmcnet.com/insight/iranian-linked-hackers-shut-uk-power-generator-for-four-days-2ade8e?ref=metacurity.com)*,* [*Washington Examiner*](https://www.washingtonexaminer.com/news/world/4697562/iran-hackers-uk-power-plant-four-days/?ref=metacurity.com)*,* [*Human Events*](https://humanevents.com/2026/08/22/iranian-hackers-shut-down-uk-power-facility-in-cyberattack-report?ref=metacurity.com)*,* [*The Sun*](https://www.thesun.co.uk/news/40142141/iran-hackers-shut-uk-power-plant/?ref=metacurity.com)*,* [*Debug Lies News,*](https://debuglies.com/2026/08/23/irans-ot-breach-uk-power-and-scada-exposure/?ref=metacurity.com)[*Security Arsenal*](https://securityarsenal.com/blog/iran-linked-hackers-disabled-a-uk-power-plant-for-four-days-otics-detection-and-hardening-guide-for-critical-infrastructure-defenders?ref=metacurity.com)*,* [*RTE*](https://www.rte.ie/news/uk/2026/0823/1588910-uk-cyber-attack/?ref=metacurity.com)*,*[ *CNBC*](https://www.cnbc.com/2026/08/23/small-uk-power-plant-shut-down-after-iran-linked-cyberattack-report.html?ref=metacurity.com)*,* [*Gigazine*](https://gigazine.net/gsc%5Fnews/en/20260824-iranian-hackers-success-to-shut-down-power-plant/?ref=metacurity.com#gsc.tab=0)*,* [*Middle East Eye*](https://www.middleeasteye.net/live-blog/live-blog-update/iranian-cyber-attack-shuts-down-uk-power-plant-four-days-report-says?topic=War%2520on%2520Iran&nid=442386&fid=557695&ref=metacurity.com)*,* [*Times of India*](https://timesofindia.indiatimes.com/technology/tech-news/after-targeting-water-infrastructure-in-us-report-claims-iran-linked-hackers-behind-cyber-attack-on-power-plant-in-uk/articleshow/133450090.cms?ref=metacurity.com)*,* [*Times of Israel*](https://www.timesofisrael.com/iran-linked-hackers-blamed-for-four-day-shutdown-of-uk-power-plant/?ref=metacurity.com)*,* [*Chosun Daily*](https://www.chosun.com/english/world-en/2026/08/24/DUIJLZQCY5EJBJVVTNI2N4MT5Q/?ref=metacurity.com)*,* [*ABC News*](https://abcnews.com/video/135889996/?ref=metacurity.com)*,* [*The Times*](https://www.thetimes.com/uk/politics/article/iran-hackers-cyberattack-shut-down-power-plant-5gtvs09dk?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/hackers-force-uk-power-plant-offline/?ref=metacurity.com)*,* [*IT Pro*](https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running?ref=metacurity.com)*,*[ *iNews*](https://inews.co.uk/news/what-know-iranian-hackers-shut-down-power-plant-4725040?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=49407509&ref=metacurity.com)*,* [*r/DeepStateCentrism*](https://www.reddit.com/r/DeepStateCentrism/comments/1vw0s29/iranian%5Fhackers%5Fshut%5Fdown%5Fuk%5Fpower%5Fplant/?ref=metacurity.com)*,* [*r/ukpolitics*](https://www.reddit.com/r/ukpolitics/comments/1vw1kwr/iranian%5Fhackers%5Fshut%5Fdown%5Fuk%5Fpower%5Fplant/?ref=metacurity.com)*,* [*r/unitedkingdom*](https://www.reddit.com/r/unitedkingdom/comments/1vvpnt6/iranian%5Fhackers%5Fshut%5Fdown%5Fuk%5Fpower%5Fplant/?ref=metacurity.com)*,* [*Slashdot*](https://news.slashdot.org/story/26/08/23/1849216/iran-linked-cyberattackers-shut-down-a-uk-power-plant-for-four-days?ref=metacurity.com) --- **Metacurity is the cybersecurity news you'd need hours to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### Alibaba’s Qwen races past Meta, Google with 3 billion AI model downloads URL: https://www.metacurity.com/alibabas-qwen-races-past-meta-google-with-3-billion-ai-model-downloads/ Last updated: 2026-08-17T15:18:44.000Z Alibaba’s Qwen family of open-weight AI models has surpassed 3 billion downloads in six months, making it the world’s most-downloaded open model ecosystem, ahead of Google and Meta. Qwen, has open-sourced more than 460 models, and its ecosystem has spawned 300l-plus derivatives/ _This post is for paying subscribers only._ ### AI, surveillance and the control problem: Best infosec long reads 8/15/26 URL: https://www.metacurity.com/ai-surveillance-and-the-control-problem-best-infosec-long-reads-8-15-26/ Last updated: 2026-08-15T12:59:44.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/datasurveillancehaze-2.png) Image created using ChatGPT. *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* [Upgrade my subscription](#/portal/account/plans) **8/15/26:** This week's long reads explore how technology is eroding familiar boundaries of trust and control—from foreign adversaries buying sensitive American data and criminals exploiting AI hallucinations, to privately run surveillance networks that sidestep privacy protections, neurotechnology capable of decoding our thoughts, and a coming internet where AI systems increasingly communicate with one another while humans fade from the loop. ### The ‘Jury Duty’ Scam That Cost This Family $25,000 The Wall Street Journal's Joe Barrett [tells the story](https://www.wsj.com/us-news/the-jury-duty-scam-that-cost-this-family-25-000-5629f703?mod=article%5Finline&ref=metacurity.com) of a family conned out of $25,000 by criminals impersonating law enforcement, showing how personal information, psychological manipulation, and cryptocurrency payments can make familiar scams extraordinarily convincing. > It began at 10:43 a.m. on a Tuesday last month, with a call from an unknown number. Fudge, who was at her office, had just gotten a refurbished Samsung in the mail and was still setting it up; when it rang, she assumed it might be a contact the phone didn’t recognize yet. She picked up. > The caller said he was from nearby New Port Richey in Pasco County, verified her identity, then asked her to hold for a sheriff’s deputy. > What followed was troubling and oddly specific. The “deputy” said Fudge had missed jury duty in a federal case despite signing a document promising to appear. An angry judge had issued a warrant for her arrest. > The caller knew Fudge’s parents had retired from the nearby Hillsborough County sheriff’s department, and he offered her a deal: pay bail, then come to the station to confirm her signature didn’t match the document’s, and get a refund on the spot. One catch: A gag order in the case meant if she told anyone, both she and whomever she informed could face charges. > “I’m a rule-follower,” said Fudge, who majored in mechanical engineering and minored in math. She and her husband have a 7-year-old daughter. “I couldn’t go to jail for 30 days.” > She told her boss she needed to step out. She sat in her small SUV, while the “deputy” on the phone had her read legal documents aloud and demanded $15,000 in bail. Fudge said she only had access to $4,000; he told her to get it. > When Fudge searched online for the nearest bank branch, the scammer asked what she was doing. That is when she realized he could see her location, her texts and her searches. Experts say the refurbished phone was likely loaded with spyware, and that she could have combated this by restoring factory settings before setting it up. > At the convenience store drop-off site, she voiced her growing suspicions to the caller. Now, a calmer person took over and assured her she would get her money back. “Everything looked legit,” Fudge recalled. They sounded official, too. She could even hear apparent police radio traffic in the background of the call. > But after she deposited the cash, the new “deputy” changed course. He said the judge had reviewed her finances and wouldn’t approve the lower bail. She now owed the full $15,000\. > Fudge scrambled for money from a different account, not wanting to touch what her husband had recently received from his mother’s estate. When work texted about a meeting she was missing, the scammers let her reply with one word: “EMERGENCY.” > By 2 p.m., she had made three deposits totaling $17,000, overpaying by $2,000 in her panic. The perpetrators told her to drive to the sheriff’s office to settle the signature issue, then ordered her to pull over before she arrived: Bail had to be deposited all at once, not in increments. > “I laid into them a little bit. I was really upset,” she recalled. “I said, ‘I feel like this is a scam.’ ” > A new voice took over, identified as a marshal. He was the harshest yet, ordering her not to move while they sent someone to arrest her. > “I was crying,” she said. She knew by then it was deceit, but still feared being picked up by the scammers or, she wondered, by rogue law enforcement. They offered her one more way out: pay another $15,000. _This post is for paying subscribers only._ ### Trump's private cyber offensive wins support — and plenty of alarm URL: https://www.metacurity.com/trumps-private-cyber-offensive-wins-support-and-plenty-of-alarm/ Last updated: 2026-08-15T13:00:32.000Z ![People playing video games in a dimly lit room.](https://images.unsplash.com/photo-1758410473735-c76baff30a79?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE3fHxjeWJlciUyMG9mZmVuc2l2ZXxlbnwwfHx8fDE3ODY3MDk0NTd8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Raman Shaunia](https://unsplash.com/@romasha?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) ### Donald Trump’s plan to enlist private companies in government-directed offensive cyber operations is drawing both enthusiasm and alarm from cybersecurity experts, who see the initiative as potentially giving the United States powerful new weapons against cybercrime while opening a thicket of unresolved questions about attribution, liability, collateral damage and escalation. The [National Security Presidential Memorandum](ttps://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/) signed Wednesday creates a program under which vetted US companies could conduct surveillance and disruptive cyber operations against foreign transnational criminal organizations under the direction of the Justice and Homeland Security Departments. The operations could go considerably further than the threat intelligence sharing and technical assistance that have traditionally characterized public-private cybersecurity partnerships. The memo defines permissible “cyber effects” as potentially including the manipulation, disruption, denial, degradation or destruction of information systems, networks, data and physical or virtual infrastructure controlled by information systems. **The case for bringing in private firepower** Supporters say the approach recognizes a basic reality, namely that much of the talent, intelligence, infrastructure visibility and technical capability needed to fight cybercrime resides outside the federal government. “The new National Security Presidential Memorandum on combating transnational cyber-enabled crime represents an important shift in how the United States approaches cyber threats originating overseas,” Michael Centrella, head of public policy at SecurityScorecard, told Metacurity. “Strengthening defenses remains critical, but the memorandum recognizes that addressing cybercrime also requires identifying and disrupting the infrastructure and networks that allow criminal organizations to operate.” Centrella said the expanded role for private companies is particularly significant because much of the threat intelligence, telemetry and technical expertise needed to understand malicious activity exists outside government. “Creating a framework for vetted US companies to support government-directed operations could significantly improve the government's ability to identify malicious infrastructure, understand interconnected digital ecosystems, and act against transnational cybercriminal organizations,” he said. “Effective disruption, however, starts with visibility. Understanding the infrastructure, third parties, and digital relationships surrounding malicious actors can help government agencies move from reacting to individual attacks toward identifying the broader ecosystems enabling them.” The policy, Centrella said, represents an evolution in public-private cybersecurity collaboration “from primarily sharing information about threats toward combining government authorities with private-sector intelligence and capabilities to more actively disrupt them.” Mieke Eoyang, who oversaw military cyberweapon use as a senior Pentagon official during the Biden administration, [offered](https://www.nytimes.com/2026/08/13/us/politics/trump-private-companies-hacking-cybercriminals.html?ref=metacurity.com) another argument for expanding the pool of cyber operators. “The current pace of cyberoperations is unsustainable for just the military,” Eoyang said. But Eoyang also said the program’s success would depend heavily on the still-classified procedures governing company vetting and target approval. The existing process for authorizing military cyber operations, developed during the first Trump administration, was “onerous,” she said, but took collateral consequences and deconfliction into account. Aiden Buzzetti, president of the Bull Moose Project, which has advocated restoring the American privateer tradition in cyberspace, [called](https://www.ft.com/content/a468c20b-cf1d-4a36-87b8-4eb15666e6c4?ref=metacurity.com) the memo “seismic,” arguing that rapidly expanding non-state capabilities make private-sector participation increasingly important. “The capabilities of non-state actors are rapidly expanding,” Buzzetti said, adding that private actors “often have more capabilities and interesting tools than the government does.” Others argue that failing to use offensive capabilities carries risks of its own. Duncan Greatwood, CEO of Xage Security, told Metacurity that leveraging the American private sector for offensive operations “can absolutely make us more formidable,” although greater offensive capability does not lessen the need for strong domestic defenses. “Offensively, while the US and its allies will want to be careful to avoid runaway geopolitical escalation, if the US never responds to cyberattacks it risks the opposite problem of enabling attackers, and their supporters, to operate with impunity,” Greatwood said. “In other words, there is a real role for offensive cyber in disrupting and deterring attacks.” Rob T. Lee, chief of research at SANS Institute, pointed to recent disruption operations by Sandra Joyce’s Google Threat Intelligence Group as evidence that private-sector disruption can work. But he stressed that Google stayed within a legal boundary the new program explicitly crosses, acting on infrastructure it controlled or using court orders when it did not. “This memo is uncharted waters, and licenses a lane Google deliberately refused to enter,” Lee [wrote.](https://www.linkedin.com/posts/leerob%5Fsandra-joyces-team-at-google-threat-intelligence-share-7493844245603069954-9Qu2/?utm%5Fmedium=ios%5Fapp&rcm=ACoAAAAh8QsB%5FUqeQaQ57J4KNhMjors3v6xHoOk&utm%5Fsource=social%5Fshare%5Fsend&utm%5Fcampaign=gmail) Lee also zeroed in on the same attribution problem raised by other experts: “The program assumes a target is criminal rather than state-run unless clear intelligence says otherwise, and in the Russian ecosystem that distinction is one phone call. Attribution is the load-bearing wall. Almost right is the expensive kind.” **Attribution may be the policy’s Achilles’ heel** The memo’s targeting standard is drawing particular scrutiny. Section 4(c) of the memorandum defines eligible targets as foreign cybercriminal organizations that aren’t institutional components of foreign governments or wholly operating at their direction. But it then establishes a striking presumption: An organization is assumed not to have such a government connection unless “clear intelligence” establishes otherwise. Security researcher Davi Ottenheimer argues that the provision places the evidentiary burden in the wrong place. “They set an evidentiary standard for protecting a target and none for striking one,” Ottenheimer told Metacurity. “Force is most available where its consequences are least assessable.” Ottenheimer said the problem echoes concerns he raised about active cyber defense as far back as 2012, when he argued that any such operation needed to confront three questions: legality, effects on innocent bystanders, and the consequences of failure. His [2012 CyberFall presentation](https://www.flyingpenguin.com/2012-consegi-presentation-cyberfall?ref=metacurity.com) on active defense specifically addressed the legal ramifications, potential harm to innocent bystanders, and risk of failure surrounding active defense. “This answers none of them: shoot first, ask questions never,” Ottenheimer told Metacurity. The attribution problem is particularly difficult because the boundary separating ordinary cybercriminals from state-linked operators is often anything but clear. A Russian ransomware group, for example, might operate with government tolerance, maintain relationships with intelligence officers or occasionally perform work benefiting the state without being wholly directed by Moscow. Nick Carr, Microsoft’s threat intelligence lead and a former US cybersecurity official, [said](https://www.nytimes.com/2026/08/13/us/politics/trump-private-companies-hacking-cybercriminals.html?ref=metacurity.com) his biggest concern was “just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right,” including government agencies. Carr added that the order could ultimately improve those efforts. But the difficulty is particularly significant because an attribution mistake would no longer merely produce an erroneous government accusation. It could help determine whether the United States authorizes an operation that disrupts or destroys somebody else’s infrastructure. Michael Garcia, who served as associate chief of policy at CISA until departing in June, [made](https://www.nytimes.com/2026/08/13/us/politics/trump-private-companies-hacking-cybercriminals.html?ref=metacurity.com) a related point: Attribution has improved, but “obfuscation is still a hell of a tactic.” And the problem becomes still more complicated if adversaries deliberately manipulate attribution — planting another group’s tools or routing operations through compromised third-party infrastructure in an effort to make someone else appear responsible. **Who takes the fall when an operation goes wrong?** The memo contains safeguards. Companies must be vetted, operations require written government authorization, and procedures are supposed to deconflict private operations with federal law-enforcement, diplomatic, military, and intelligence activities. But the memorandum leaves major questions about what legal protection participating companies and their employees receive when they follow government instructions and something nevertheless goes wrong. “From the lawyer perspective, it’s, ‘Are you okay with engaging in this kind of legal risk? And who knows what protections the government will provide?’” Garcia [said](https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/?ref=metacurity.com). “I’d be very curious to see what the foreign governments’ reactions are — ‘We’re going to cut ties with any participating company that engages in this.’ Participating companies may also be required to maintain a bond or escrow of at least $1 million that could be forfeited for violating their contracts. But the White House memorandum leaves major questions about what legal protection participating companies and their employees receive when they follow government instructions, and something nevertheless goes wrong. The problem becomes particularly acute because cyber effects are difficult to contain. Infrastructure used by criminals may belong to innocent third parties, reside in another country, or share services with unrelated organizations. An operation aimed at one target can therefore produce consequences somewhere else. The policy also creates an unusual question about the relationship between private actors and government authority: What happens if a company performs an operation Washington has approved but that violates the law of the country where the targeted infrastructure resides? Eoyang’s warning about the importance of the classified approval and deconfliction procedures takes on particular significance here. The public memo establishes the outer boundaries of the program, but some of the procedures most likely to determine whether an operation is safe are hidden from public view. **Private cyber warriors could become targets themselves** Gary Barlet, public sector CTO at Illumio, supports using private-sector capabilities, noting that US adversaries have long relied on third parties to conduct cyber operations while preserving plausible deniability. “The reality is that the private sector has access to more talent and resources and not necessarily the same constraints,” Barlet told Metacurity. But he also raised one of the fundamental questions created by putting private companies directly into offensive operations. “Does empowering private companies turn them into legitimate targets or combatants in the eyes of foreign states?” he asked. “Some would argue they are already in the crosshairs, so giving them a path to fight back makes sense. The potential benefits outweigh the risks, but we need to go into this eyes wide open – there will be friction, grey areas, and unintended consequences we can't fully predict yet.” Vanessa Le, a partner at Latham & Watkins who advises companies on geopolitical risk, [raised](https://www.nytimes.com/2026/08/13/us/politics/trump-private-companies-hacking-cybercriminals.html?ref=metacurity.com) a related issue: What does becoming an offensive cyber contractor mean for a publicly traded cybersecurity company? “This approach from the government presents novel questions for publicly traded companies in the sector: Even if they engage in ‘hack back’ activities under US government cover or direction, how will they manage the increased operational risk to their business and customers, and how and when will they disclose it?” Le said. The consequences could extend well beyond securities disclosures. A company known to conduct offensive operations for Washington could become a higher-value target for foreign intelligence services or criminal groups. Its employees could face risks while traveling abroad, and adversaries could seek to compromise the contractor itself to obtain intelligence about US operations and targets. Barlet’s question about whether participating companies could be viewed as combatants therefore isn’t merely theoretical. **Who guards against a market for offensive cyber operations?** The program also creates potential financial incentives that some former officials find troubling. Jason Kikta, a former US Cyber Command official, [characterized](https://www.bleepingcomputer.com/news/security/white-house-taps-security-firms-for-offensive-hack-back-operations/?ref=metacurity.com) the program as a “perpetual motion machine for billable threats.” The White House memo permits participating companies to receive threat intelligence from other private organizations and use that information to propose cyber operations to the government. If approved, private contractors could then participate in executing those operations. That raises the possibility that companies could play roles in identifying a threat, proposing the government response, and carrying out the resulting operation. Chris Wysopal, cofounder of Veracode, similarly [described](https://www.bleepingcomputer.com/news/security/white-house-taps-security-firms-for-offensive-hack-back-operations/?ref=metacurity.com) the memo as a “pretty big shift in US cyber policy” while distinguishing the government-controlled program from unrestricted private-sector hack-back. The concern isn’t necessarily that companies will manufacture threats. Rather, the structure creates a question familiar to other areas of government contracting: How do officials ensure that the party with a financial interest in operating isn’t exerting disproportionate influence over the determination that an operation is necessary? **The US may be borrowing from its adversaries** The policy also creates an unusual reversal in the relationship between US and adversary cyber models. China and Russia have long benefited from relationships with nominally private hackers and contractors that provide governments with technical capacity while sometimes blurring responsibility for their operations. Dakota Cary, an expert on China’s hacking ecosystem and an adviser at SentinelOne, noted that Beijing has historically borrowed from US approaches to cybersecurity. “Now it seems the US is interested in copying China’s system for deputizing private-sector hackers,” Cary [said](https://www.nytimes.com/2026/08/13/us/politics/trump-private-companies-hacking-cybercriminals.html?ref=metacurity.com). The analogy has limits. The White House program calls for formal government contracts, vetting, written authorization, and interagency deconfliction rather than the deliberately murky relationships that can exist between foreign intelligence services and ostensibly independent hackers. But the memo nevertheless changes the traditional division of labor between private cybersecurity companies and the government. **A new offensive landscape for everyone** Even organizations that never participate in the program could feel its effects. Brian Anderson, global field CTO at Cato Networks, told Metacurity that a more active and contested cyber environment could make life harder for ordinary defenders. “Disruption rarely stays neatly contained, often affecting sectors, vendors, and supply chains far beyond the original participants,” Anderson said. “Attribution remains difficult—particularly where criminal networks and state interests may overlap. That uncertainty can complicate risk decisions for everyone.” Anderson also warns that the operational environment may become noisier as activity increases in cyber’s gray areas, making meaningful signals harder for defenders to distinguish from background activity. “This is not a call for alarm,” Anderson said. “It is a reminder to invest in the fundamentals: strong visibility, continuous validation, Zero Trust principles, resilient vendor relationships, and incident-response plans practiced for uncertain conditions.” One voice has been conspicuously absent from the extensive public debate over the memo: the Trump administration itself. While dozens of current and former officials, cybersecurity executives, researchers and policy experts have debated the plan’s merits and risks, administration officials have offered no public explanation of how the program will work or answers to the questions it has generated about attribution, liability, oversight and escalation. --- **Metacurity is the cybersecurity news you'd need hours to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### White House expands its cyber reach with expanded AI policy, new cybercrime memo URL: https://www.metacurity.com/white-house-expands-its-cyber-reach-with-expanded-ai-policy-new-cybercrime-memo/ Last updated: 2026-08-14T13:35:33.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/whitehousesealresized-1.png) ### The Trump administration is taking significant steps that could expand the federal government's role in overseeing and deploying some of the most powerful technologies in cybersecurity, even as the White House continues to resist characterizing its approach as regulation. In one development, the administration is preparing to broaden a still-secret framework for government testing of advanced artificial intelligence models before their release, according to WIRED. In the other, Donald Trump signed a National Security Presidential Memorandum establishing a program under which vetted private companies could conduct surveillance and disruptive cyber operations against foreign criminal organizations under federal direction. Both moves illustrate an increasingly muscular approach to cybersecurity built around partnerships between government and technology companies. Rather than imposing broad regulatory requirements, the administration is drawing selected companies directly into national-security operations while seeking greater visibility into technologies it believes could themselves pose national-security risks. **The government wants access to more frontier AI models** The AI development builds on Trump's [June executive order](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?ref=metacurity.com) on advanced AI innovation and security. That order directed the government to develop a classified benchmarking process for determining when an AI system possesses sufficiently advanced cyber capabilities to qualify as a "covered frontier model." It also called for a voluntary arrangement through which developers could give the government access to such models for as long as 30 days before releasing them to other trusted partners. The order explicitly said the arrangement should not constitute mandatory licensing, preclearance, or permitting of AI models. WIRED reported that the resulting framework currently encompasses closed models produced by companies such as OpenAI and Anthropic, but White House officials expect to expand it to open models once they reach comparable frontier capabilities. The fundamental twist is that AI policy is increasingly becoming capability-based rather than dependent on how a model is distributed. It also demonstrates the difficulty the administration faces in reconciling two objectives: avoiding an AI regulatory regime it believes could slow American innovation while responding to increasingly capable models whose cybersecurity implications the government considers serious enough to warrant prerelease examination. According to WIRED, the framework remains voluntary, but officials are considering a more formal relationship with leading AI laboratories. Expanding the program to open models could create additional complications because imposing a testing period on models intended for broad distribution could slow their development and potentially undermine one of the advantages of open development. **The cybercrime memo goes considerably further** The second White House action moves beyond information sharing or voluntary security testing and creates a mechanism for private companies to participate directly in government-controlled cyber operations. Trump's memorandum orders the Homeland Security Task Force's National Coordination Center to establish a program allowing approved US companies to conduct both "Cyber Surveillance Operations" and "Cyber Effects Operations" against foreign cyber-enabled transnational criminal organizations. A cyber surveillance operation can involve accessing a target's systems without the owner's authorization while attempting to remain undetected. The definition explicitly encompasses collecting intelligence that could later be used to conduct a cyber effects operation. Cyber effects operations go considerably further. They can involve the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, data, or even physical or virtual infrastructure controlled by information systems. In other words, the memorandum isn't merely asking security companies to provide indicators of compromise, malware analysis, or intelligence to law enforcement. It creates a framework under which private companies could actually enter foreign systems and, with government approval, interfere with or destroy them. That potentially represents a major expansion of the operational role private cybersecurity companies play in US law enforcement. **Not a private-sector license to hack back** There is an important distinction, however, between the new program and the "hack back" proposals periodically floated in Washington. The memorandum repeatedly places participating companies under federal control. Companies must contract with either the Department of Justice or the Department of Homeland Security, and operations require government authorization. DOJ and DHS officials serving as the program's co-executive directors must coordinate before approving operations, and participating companies must receive written approval and direction before taking action. The White House is therefore not giving companies a general right to retaliate against attackers who target their customers. Instead, it is effectively creating a pool of private offensive cyber contractors operating pursuant to government authority. That distinction is important legally as well as operationally. The memorandum specifically requires the program to comply with the Computer Fraud and Abuse Act, the Constitution, and US international obligations and emphasizes that companies will operate under federal control. **Companies could also generate operations** One of the more interesting provisions is that participating companies won't necessarily execute operations handed to them by Washington. The memorandum allows them to establish commercial relationships with other private companies that can supply threat information gathered through their normal operations. Participating companies can use that information to propose cyber operations to the National Coordination Center. State, local, tribal, and territorial governments can similarly identify threats that participating companies can turn into operational proposals. That creates a pipeline that could look something like this: A cybersecurity provider discovers infrastructure belonging to a ransomware operation while protecting a customer. It provides the intelligence to a participating company. That company develops a proposed surveillance or disruption operation and sends an operational package to the NCC. DOJ and DHS review the proposal, coordinate it against intelligence, diplomatic, military, and other federal equities, and authorize the contractor to execute it on the government's behalf. The private sector therefore becomes not merely an extra pair of hands but potentially a source of intelligence, targeting proposals and operational capacity. **The safeguards reveal some of the risks** Some of the most revealing portions of the memorandum concern the safeguards the White House believes the program will require. Within 60 days, DOJ and DHS must establish detailed operating procedures governing the program. Those procedures must include standards for technical competence, personnel vetting, facility security and previous cyber-operational performance. Companies may also be required to maintain a bond or escrow worth at least $1 million that can be forfeited for violating their contracts. More consequentially, the procedures must establish mechanisms for deconflicting operations across federal law enforcement, State, Treasury, the Department of War and the intelligence community. That provision points toward one of the central hazards of offensive cyber operations: a contractor attempting to disrupt infrastructure that another government agency is monitoring, exploiting, or using for intelligence collection. The government must also establish an adjudication system intended to ensure that targets really qualify as cyber-enabled transnational criminal organizations. **The memo makes a consequential assumption about who counts as a criminal rather than a state actor** One of the most striking provisions is buried in the definitions. Section 4(c) defines an eligible cyber-enabled transnational criminal organization as a foreign group conducting cyber-enabled crime against the United States, Americans, or US interests that isn't an institutional part of a foreign government or wholly operating at a foreign government's direction. But the memorandum then establishes a significant presumption for making that determination: A foreign group will be assumed not to be part of a foreign government or wholly operating under its direction unless "clear intelligence" establishes such a connection. That puts the presumption on the side of treating an organization as a criminal rather than a state actor. Section 4(c) presumes a foreign group is a criminal actor, not a state one, unless the government already has "clear intelligence" proving otherwise — a default that's easy for independent gangs but untested for the harder cases: groups tolerated or informally tasked by Russia, China, Iran or North Korea, where that clear intelligence rarely exists. That's precisely where a disruption operation risks escalating into a state-to-state incident. The distinction could become particularly consequential when dealing with ransomware gangs and other cybercriminal groups operating from countries such as Russia, China, Iran and North Korea. The relationship between cybercriminals and governments isn't always binary. A criminal group might operate with a government's tolerance or protection, share personnel with state security services, occasionally conduct operations useful to the government, or assist intelligence agencies without being wholly controlled by them. Russia in particular has long presented precisely that attribution problem. Cybercriminal organizations can operate from Russian territory while the precise nature of their relationship with Russian intelligence or security services remains uncertain. Under the memorandum, uncertainty alone would not appear to be enough to treat such a group as state-controlled. Unless the government possesses clear intelligence establishing that the organization is part of or wholly directed by the foreign government, the presumption runs in the opposite direction. That matters because the program authorizes considerably more than intelligence collection. Participating companies could conduct operations that manipulate, disrupt, degrade, or destroy foreign systems and infrastructure. The presumption therefore isn't merely a definitional technicality. It could affect which foreign targets the United States considers eligible for disruptive operations and how much evidence officials need about a group's relationship with a hostile government before authorizing private contractors to act against it. It could also carry escalation risks. An operation nominally directed at a criminal organization could affect infrastructure, capabilities, or individuals with connections to a foreign intelligence service, potentially turning what Washington regards as an anti-crime operation into something the foreign government views very differently. The memorandum attempts to manage some of that risk through an adjudication framework and extensive interagency deconfliction. But Section 4(c) establishes the baseline from which those decisions begin: absent clear intelligence demonstrating government control, the target is presumed to be a non-state criminal organization. **Some operations remain beyond the program's authority** The memorandum establishes another boundary around what it calls "Critical Outcomes." DOJ and DHS program directors cannot themselves approve an operation likely to cause death or serious injury or one that would rise to the level of a use of force or armed attack under international law. That limitation underscores just how consequential some of the authorized operations immediately below that threshold could nevertheless be. The definition of cyber effects explicitly includes destruction and operations affecting infrastructure. The policy therefore isn't confined to removing criminal websites or seizing servers. Depending on the implementation rules developed over the next 60 days, it could permit much more aggressive disruption. **This has been building since March** Wednesday's memorandum did not appear from nowhere. Trump's March [cybercrime executive order](https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/?ref=metacurity.com) directed the government to establish an operational cell within the National Coordination Center to coordinate federal efforts to "detect, disrupt, dismantle, and deter" cybercrime committed by foreign transnational criminal organizations, including through private-sector participation where appropriate. The new memorandum appears to provide the operational architecture for carrying out that ambition. It also fits the administration's broader 2026 cybersecurity strategy, which placed considerably greater emphasis on disruption and imposing consequences on adversaries rather than relying primarily on defense. What is new is the specificity: who can conduct the operations, who approves them, what kinds of effects they can produce, how private intelligence can generate proposed operations, and how government agencies are supposed to prevent those activities from colliding with one another. **A common thread between AI and offensive cyber policy** At first glance, prerelease testing of AI models and contractor-assisted operations against ransomware gangs might seem like separate policies. But they reflect a similar conception of Washington's relationship with the technology sector. The administration isn't primarily trying to regulate technology companies from outside. It increasingly wants to bring selected companies inside national-security activities. AI developers would voluntarily provide the government access to frontier models so federal experts can determine what those models can do. Cybersecurity companies would provide intelligence, develop operational proposals, and potentially conduct surveillance and disruptive operations on government-selected targets. In both cases, private-sector capabilities are advancing faster than the government's ability to reproduce them internally. The administration's answer appears to be deeper operational integration rather than building those capabilities entirely inside government or subjecting the industries to traditional regulatory regimes. That may ultimately prove to be one of the defining characteristics of Trump's cyber policy: not less government involvement in advanced technology, but a different kind of government involvement — one that increasingly treats private technological capability as an instrument of national power. ([Hugo Lowell / Wired](https://www.wired.com/story/the-white-house-is-going-to-expand-its-ai-policy/?ref=metacurity.com) and [White House](https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/?ref=metacurity.com), [White House](https://www.whitehouse.gov/fact-sheets/2026/08/fact-sheet-president-donald-j-trump-expands-capabilities-to-combat-transnational-cyber-enabled-crime/?ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/world/trump-signed-memo-allow-use-cyber-tools-target-transnational-criminal-orgs-white-2026-08-12/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-08-13/trump-enlists-private-sector-to-boost-cyber-offensive-arsenal?ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1vn0oww/white%5Fhouse%5Fcreates%5Fframework%5Ffor%5Fprivate/?ref=metacurity.com)*,* [*r/accelerate*](https://www.reddit.com/r/accelerate/comments/1vn0vmp/white%5Fhouse%5Fcreates%5Fframework%5Ffor%5Fprivate/?ref=metacurity.com) --- **Metacurity is the cybersecurity news and analysis you'd need hours and expert staff to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. A paid subscription to Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### Autonomous AI agents hacked the Taiwan government in a cyber first URL: https://www.metacurity.com/autonomous-ai-agents-hacked-the-taiwan-government-in-a-cyber-first/ Last updated: 2026-08-12T15:11:59.000Z Suisun City cyberattack recovery could take months, Microsoft patches 400 flaws, three zero-days, $100 device can hijack Boeing 737 systems, Hackers hijack AnMed Facebook page with ransom demands, German lawmaker urges cyber strikes on Russian drone factories, much more _This post is for paying subscribers only._ ### OpenAI loosens GPT-5.6 cyber guardrails for vetted defenders URL: https://www.metacurity.com/openai-loosens-gpt-5-6-cyber-guardrails-for-vetted-defenders/ Last updated: 2026-08-11T14:12:53.000Z Anthropic to watermark Claude output, Gunra ransomware targets critical infrastructure through Fortinet flaws, WormGPT creator faces trial in Portugal, Ransomware disrupts systems at Winnipeg’s largest hospital, China-linked hackers exploit N-central flaw to deploy ransomware, much more _This post is for paying subscribers only._ ### DPRK's Kimsuky built an in-house AI toolkit to power cyberattacks URL: https://www.metacurity.com/dprks-kimsuky-built-an-in-house-ai-toolkit-to-power-cyberattacks/ Last updated: 2026-08-10T13:59:23.000Z Chinese components in UK military drones secretly transmitted data, Cali city declares emergency after cyberattack, Turkey's new cyber law sparks fears of sweeping digital censorship, OpenAI's Hugging Face hack reveals deeper AI safety failures, Claude Code's autonomous mode is now the default _This post is for paying subscribers only._ ### Trust under pressure: Best infosec long reads 8/8/26 URL: https://www.metacurity.com/trust-under-pressure-best-infosec-long-reads-8-8-26/ Last updated: 2026-08-08T12:42:37.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/lucent_designs_dinoson20-fiber-4814456-1.jpg) Image by [Lucent\_Designs\_dinoson20](https://pixabay.com/users/lucent%5Fdesigns%5Fdinoson20-1455439/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=4814456) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=4814456) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* [Upgrade my subscription](#/portal/account/plans) **8/8/26:** This week's long reads explore the forces reshaping digital trust—from AI systems that can autonomously replicate themselves and the legal battle over digital privacy, to the inside story of a multimillion-dollar phone-scamming enterprise, the information war surrounding Iran's media ecosystem, and the migration of once-fringe censorship narratives into US technology and national security policy. ### The Phone Scammers Next Door Toronto Life's Malcom Johnston [delivers](https://torontolife.com/deep-dives/the-phone-scammers-next-door/?utm%5Fmedium=email&utm%5Fsource=ten%5Ftabs&utm%5Fcampaign=&position=4&category=fascinating%5Fstories&scheduled%5Fcorpus%5Fitem%5Fid=86bf5c63-8cf8-4cc3-9979-c369096e6d30&url=https%3A%2F%2Ftorontolife.com%2Fdeep-dives%2Fthe-phone-scammers-next-door%2F) a gripping investigative feature that traces how a picture-perfect, upwardly mobile Canadian couple allegedly operated a multimillion-dollar phone-scamming enterprise built on spoofing technology, exposing both the industrialization of voice fraud and the painstaking international effort required to bring it down. > The trail of clues that would lead the RCMP to Mansouri and Alouah’s front door began in London, England, in 2021\. The Cyber Defence Alliance, a non-profit group of investigators who work on behalf of member banks, kept hearing the term “iSpoof” in criminal chatrooms and other dark-web networks. Many CDA investigators are ex–law enforcement, but the organization differs from police in a crucial way: whereas police deal with known criminality, the CDA roams the digital plains, scanning the horizon for future threats. Its investigators dug into iSpoof and were startled by what they discovered. The URL iSpoof.cc listed no ownership or contact information and accepted payment only in cryptocurrency. The site gave customers access to a service that enabled them to alter their caller IDs and phone numbers, making it appear as if they were calling from a bank, an insurance provider, a government agency or wherever else they liked. It was like \*67, the caller ID–blocking feature, but on steroids. The service featured a user-friendly digital dashboard with custom hold music, fake call-centre background noise, PIN-capture technology and a “spy” mode setting. It also promised complete encryption and anonymity. The server logs, iSpoof assured prospective clients, were deleted at the end of every day. > The site was blatant fraud, yet iSpoof blithely mimicked the tone of any legitimate consumer service website. A cheerful video guided new users through the “spoofing” process, and a PDF with cute illustrations detailed each step toward a successful con. “Flexibility and freedom: they’ll never know it was you!” it read. “You can pick any number you want before you call. Your opposite will be thinking you’re someone else. It’s easy and works on every phone worldwide!” Customers could choose from an array of packages. The cheapest, for a flat fee of $170, allowed for 150 minutes of “spoof time.” The platinum bundle, for $850 a month, offered 2,500 minutes. > Step one for an iSpoof customer was to purchase names and numbers through a “smishing” campaign—text-based ­phishing—or from a dark-web provider like Briansclub, which sells real consumer information acquired from corruptible employees at banks and government agencies. The best targets were the elderly, many of whom could be convinced of just about anything. Some lists highlighted targets who had been successfully scammed before and were considered soft marks worth trying again. > Through the iSpoof dashboard, the fraudster would enter the real banking information of a target and dial their number. When the target answered, an automated voice would identify the call as coming from the customer’s bank and read out the target’s real name, number and address followed by a list of fictitious transactions. “If this wasn’t you,” it would say, “press 2.” The iSpoof user guide boasted that this step—the target actively ­participating—worked wonders: “The reason this feature works well is because it gives the feel that the target is calling in ­themselves which immediately brings ease to the target.” The automated voice would then prompt the target to key in their confidential client PIN, the resulting entry appearing on the fraudster’s dashboard, digit by digit. The call was then transferred to the “next available customer service rep,” which was really the fraudster, who had been listening on spy mode the entire time. > By this point, the target was in a panic. They believed that their accounts had been hacked and their funds were at risk. They were also convinced that the call was legitimate: the caller ID and number matched that of the bank; the caller had the correct name and address; and the provided PIN was accepted. The target had nibbled; now it was up to the fraudster to set the hook. > This is where Mansouri worked his magic. Hopping on the line, he would cheerily introduce himself as one of the bank’s customer service representatives and reassure the target that he would address the problem. First, to complete the verification process, he needed a few more identifying details: date of birth, most recent transactions and the like. Simultaneously, on a second line, Mansouri would dial the bank, using iSpoof to make it seem like the call was coming from the customer, and claim that he was having trouble logging into his account. He already knew most of the necessary information, but when the bank asked for a detail he didn’t have, he’d place the bank on hold, switch to the target and ask for it. Within minutes, he’d have reset the password. He’d tell the target that the problem had been successfully resolved and end the call, then log in to the account and drain it. _This post is for paying subscribers only._ ### Kimi K3 escaped AI security sandbox during testing URL: https://www.metacurity.com/kimi-k3-escaped-ai-security-sandbox-during-testing/ Last updated: 2026-08-07T13:08:05.000Z ByteDance trains AI model to rival Anthropic, Vishing gang targets Wall Street firms with fake login sites, Violent crypto robberies put 2026 on record pace, Chinese router maker pulls devices after backdoor discovery, Spike in suicides alarms US Cyber Command, much more _This post is for paying subscribers only._ ### Updated: US Coast Guard is probing a cyberattack that disrupted North Carolina ports URL: https://www.metacurity.com/us-coast-guard-is-probing-a-cyberattack-that-disrupted-north-carolina-ports/ Last updated: 2026-08-07T13:10:04.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/Wilmington_North_Carolina_port_aerial_view-1.jpg) Aerial view of the port and city of Wilmington, North Carolina, USA. Source: [US Army Corps of Engineers](http://images.usace.army.mil/images/Hires/4841-04.Jpg?ref=metacurity.com). **Metacurity is the cybersecurity news you'd need hours to assemble yourself.** Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler. Metacurity delivers - **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable. - **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself, - **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage - **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors. Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday. Please consider supporting us. And thank you! [Upgrade my subscription](#/portal/account/plans) ### The US Coast Guard's cyber division is leading the federal response to a cyberattack that disrupted information technology systems at the North Carolina State Ports Authority this week, according to a source knowledgeable about port operations, as investigators work to determine whether the intrusion was the work of ransomware operators or a nation-state actor. The source said the Coast Guard is "running point" on the investigation. While emphasizing that no attribution has been made, the source said early speculation within the maritime community likely focuses on either a ransomware attack or activity linked to Chinese threat actors. North Carolina Ports confirmed that it had experienced a cybersecurity incident affecting its information technology systems serving the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Terminal. The authority said cargo operations continue but warned customers to expect delays while contingency procedures remain in place. The ports authority said it detected unauthorized activity on its network, isolated affected systems and launched an investigation with outside cybersecurity specialists and law enforcement. Public statements have not identified the type of malware involved or named a suspected threat actor. If confirmed, the incident would represent the latest cyber disruption affecting critical US transportation infrastructure and comes as federal officials have spent years warning that American ports are increasingly attractive targets for both financially motivated cybercriminals and foreign intelligence services. The Coast Guard has assumed an increasingly prominent role in maritime cybersecurity in recent years. In 2025, it issued [updated guidance](https://www.news.uscg.mil/maritime-commons/Article/4247529/final-rule-cybersecurity-in-the-marine-transportation-system-implementation-tim/?ref=metacurity.com) requiring the reporting of cyber incidents affecting the Marine Transportation System, while broader federal efforts have expanded the Coast Guard's responsibilities for overseeing cyber risk at ports and maritime facilities. **Chinese concerns add context** The attack also revives longstanding concerns about China's potential access to US port infrastructure. In 2023, I [broke the news ](https://www.csoonline.com/article/574327/us-maritime-administrator-to-study-port-crane-cybersecurity-concerns.html?ref=metacurity.com)that senior US maritime officials were studying cybersecurity risks associated with Chinese-manufactured ship-to-shore cranes after intelligence and security officials raised concerns that the equipment could provide opportunities for espionage or disruption. The reporting highlighted growing unease inside the federal government over China's dominant position in the global crane market. Those concerns later became a central element of the Biden administration's [maritime cybersecurity strategy](https://www.csoonline.com/article/1309238/bidens-maritime-cybersecurity-actions-target-china-threats.html?ref=metacurity.com). In early 2024, the administration announced a series of actions designed to strengthen port cybersecurity, including a Coast Guard maritime cybersecurity directive, investment in domestically manufactured cargo cranes and additional scrutiny of Chinese-made port equipment. Although there is no evidence linking the North Carolina incident to Chinese-manufactured cranes or to Chinese government actors, the attack underscores why US officials have spent years attempting to reduce cyber risks across the nation's maritime transportation infrastructure. North Carolina Ports has not disclosed how the attackers gained access, whether data was stolen or encrypted, or when it expects all systems to be fully restored. **Update:** Metacurity heard from Coast Guard public affairs officer Luke Pinneo, who said via email that "Because the investigation is ongoing, the details I can provide are limited. I can confirm that the Coast Guard is aware, and in coordination with our partner agencies, we are continuing to monitor." (Cynthia Brumfield / Metacurity) ***Related:*** [*Port Technology*](https://www.porttechnology.org/systems-outage-nc-ports/?ref=metacurity.com)*,* [*Queen City News*](https://www.qcnews.com/charlotte/hackers-breach-nc-ports-it-system-including-charlotte-branch/?ref=metacurity.com)*,* [*Index Box*](https://www.indexbox.io/blog/north-carolina-ports-confirms-cyberattack-operations-continue-with-delays/?ref=metacurity.com)*,* [*WXII*](https://www.wxii12.com/article/north-carolina-ports-cyberattack/73358371?ref=metacurity.com)*,* [*WCNC*](https://www.wcnc.com/article/news/crime/north-carolina-ports-cyberattack-wilmington-charlotte-morehead-city/275-3b5c8c7a-fe8d-4fb6-8e3c-46a25af6a486?ref=metacurity.com)*,* [*WECT*](https://www.wect.com/2026/08/05/cyberattack-disrupts-operations-nc-ports-wilmington-morehead-city-charlotte/?ref=metacurity.com)*,* [*Splash 247*](https://splash247.com/cyberattack-disrupts-north-carolina-port-operations/?ref=metacurity.com) _This post is for paying subscribers only._ ### AI Watch: White House framework signals new era of AI oversight as security concerns intensify URL: https://www.metacurity.com/ai-watch-white-house-framework-signals-new-era-of-ai-oversight-as-security-concerns-intensify/ Last updated: 2026-08-05T12:47:17.000Z AI agents demonstrate increasingly sophisticated offensive capabilities, China warns US against expanding AI and technology curbs, Suspected cyberattacks target water utilities in at least 12 states, House report links telecom loopholes to Salt Typhoon breaches, much more _This post is for paying subscribers only._ ### AI Watch: AI security moves to Washington's center stage URL: https://www.metacurity.com/ai-watch-ai-security-moves-to-washingtons-center-stage/ Last updated: 2026-08-04T14:09:38.000Z White House AI testing framework arrives but key details remain secret, Congress probes OpenAI incident as calls for stronger AI oversight grow, China's open AI push fuels geopolitical debate, Banks press ahead with AI agents, US eyes China data center tech ban, much more. _This post is for paying subscribers only._ ### Water system cyberattacks widen as Trump rejects suspected Iran link URL: https://www.metacurity.com/water-system-cyberattacks-widen-as-trump-rejects-suspected-iran-link/ Last updated: 2026-08-03T13:38:52.000Z OpenAI finds additional AI agents escaped containment, Rogue AI hacks raise unprecedented liability questions, DeepSeek launches industry's cheapest frontier AI model, UK agency exposes officials' data in internal security lapse, Leaked database reveals China's surveillance of foreigners, much more _This post is for paying subscribers only._ ### Power plays in AI and cybersecurity: Best infosec long reads 8/1/26 URL: https://www.metacurity.com/power-plays-in-ai-and-cybersecurity-best-infosec-long-reads-8-1-26/ Last updated: 2026-08-01T15:12:14.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/alexandre-debieve-FO7JIlwjOtU-unsplash-1.jpg) Photo by [Alexandre Debiève](https://unsplash.com/@alexkixa?utm%5Fsource=unsplash&utm%5Fmedium=referral&utm%5Fcontent=creditCopyText) on [Unsplash](https://unsplash.com/photos/macro-photography-of-black-circuit-board-FO7JIlwjOtU?utm%5Fsource=unsplash&utm%5Fmedium=referral&utm%5Fcontent=creditCopyText) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* [Upgrade my subscription](#/portal/account/plans) **8/1/26:** This week's long reads examine the race for advantage in the AI era—from China's push to challenge US dominance with open-weight models and questions about whether today's reasoning models truly understand what they're doing, to the enduring ingenuity of an elusive hacker, the subtle hardware flaws that can betray even well-defended systems, and the growing legal battles over who should control access to the world's most advanced AI technologies. ### The hacker who humiliated spyware makers and was never caught TechCrunch's Lorenzo Franceschi-Bicchiera [recounts](https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/?ref=metacurity.com) the exploits of the elusive hacktivist Phineas Fisher, whose attacks on commercial spyware vendors exposed the industry's vulnerabilities while leaving investigators unable to identify the person behind the pseudonym. > Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades. > The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There’s even a song about them. > Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data, including mobile spyware, product manuals, and a price list. The damage was limited, and FinFisher carried on. Phineas published a postmortem that doubled as a leftist manifesto, then vanished. > A year later, they came back with a bang, hacking Hacking Team, another spyware maker. They took practically everything: more than 400 gigabytes, including source code, tens of thousands of internal emails, confidential contracts, and customer lists. The leak allowed journalists to reveal scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was forced to sell his company for one euro. For some former employees, Phineas’ hack was the beginning of the end. > Phineas went on to hack the union of the Mossos d’Esquadra, which is the police force of Catalonia, publishing a postmortem and a 39-minute tutorial video — consistent with their stated anti-police ideals. Their next victim was the ruling party of Turkey’s authoritarian president Recep Tayyip Erdoğan, a hack motivated by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was fighting against. > Phineas’ last known victim was Cayman National Bank’s branch in the Isle of Man, a self-governing island between England and Ireland. The hack hinted at a different side of Phineas. “I look for illegal ways to make money in order to free my time so I can do something useful with it. Once I had that figured out, I started scaling it up and making more money than I need and giving the extra away,” Phineas said in an interview with activist Freddy Martinez. (Phineas donated at least $10,000 in Bitcoin to Rojava.) _This post is for paying subscribers only._ ### Anthropic becomes the second frontier AI lab to disclose agent breaches URL: https://www.metacurity.com/anthropic-becomes-the-second-frontier-ai-lab-to-disclose-agent-breaches/ Last updated: 2026-07-31T13:29:59.000Z Copilot worm spreads through trusted Word documents, ExploitGym creators explain how OpenAI's agent escaped, Coordinated attacks signal a new threat to water utilities, Critical Azure Cosmos DB flaw threatened thousands of customers, CrimeStoppers put a bounty on the INC gang, much more _This post is for paying subscribers only._ ### ExfilSquad claims theft of 740,000 records from UK education, police databases URL: https://www.metacurity.com/exfilsquad-claims-theft-of-740-000-records-from-uk-education-police-databases/ Last updated: 2026-07-30T15:18:36.000Z Analog Devices probes ExfilSquad breach claim, UK report blames systemic failures for Afghan data leak, Senators urge Apple to shun Chinese memory chips, Australia sues Telegram over terror content, OpenAI breach sparks AI controls talk in Washington, much more _This post is for paying subscribers only._ ### OpenAI reveals broader AI agent campaign as Hugging Face publishes remarkable timeline URL: https://www.metacurity.com/openai-reveals-broader-ai-agent-campaign-as-hugging-face-publishes-remarkable-timeline/ Last updated: 2026-07-29T13:10:01.000Z Anthropic unveils encrypted AI breakthrough, AI workers demand global safety oversight, Zuckerberg doubles down on AI, Anthropic's AI safety stance draws fire, MCP gets its biggest overhaul yet, OpenAI open-sources Codex security tools, FCC bans new Chinese robots, power inverters, much more _This post is for paying subscribers only._ ### Nvidia launches AI safety coalition as open-weight debate intensifies URL: https://www.metacurity.com/nvidia-launches-ai-safety-coalition-as-open-weight-debate-intensifies/ Last updated: 2026-07-28T14:48:18.000Z MSFT launches AI cyber defense platform, Hugging Face rife with deepfake abuse, Cyberattack hits Minnesota water systems, Claude chats indexed by Google, Bank of Baroda probes leak, ShinyHunters claims EY breach, Apple sued over fake wallet app, Hack steals 293.7m SUPRA tokens, much more _This post is for paying subscribers only._ ### AI Watch: OpenAI's hacking agent breach signals a fracturing AI order URL: https://www.metacurity.com/ai-watch-openais-hacking-agent-breach-signals-a-fracturing-ai-order/ Last updated: 2026-07-27T13:22:32.000Z OpenAI missed rogue agent, Hugging Face breach reshapes open-v-closed AI, Firms abandon AI lab loyalty, Open-weight AI's Kubernetes moment, China pushes open-weight AI, Washington splits on Chinese AI, N. Korea expands its intelligence apparatus, much more _This post is for paying subscribers only._ ### The governance gap: Best infosec long reads 7/25/26 URL: https://www.metacurity.com/the-governance-gap-best-infosec-long-reads-7-25-26/ Last updated: 2026-07-25T14:24:45.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/pexels-atypeek-5650141-1.jpg) Source: [Atypeek](https://www.paypal.com/donate?token=8vcIUmFSOHTUonqzy8ePnq7CN405A6NM05eXKnYsp0fbHqcIWiMmusBdVwK31CNmmo%5F%5FYreU1vUzWG4P&locale.x=US&ref=metacurity.com). *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **7/25/26:** This week's long reads explore a common theme: as AI, surveillance systems, government databases, and critical infrastructure become more powerful and interconnected, governance and operational readiness are struggling to keep pace. The pieces cover gaps in AI incident reporting, warn of the risks of consolidating federal data, reveal how Russia's FSB is integrating generative AI into intelligence operations, show how a simple error in an automated license plate recognition system can spiral into repeated police encounters, and explain why decades-old malware remains so difficult to eradicate from industrial systems. ### When Reporting an AI Security Incident Is Not Mandatory Using the Hugging Face breach as a springboard, Mackenzie Arnold, the Director of US Policy at the Institute for Law & AI, and Stephan Llerena, Research Scholar at LawAI, [argue](https://www.lawfaremedia.org/article/when-reporting-an-ai-security-incident-is-not-mandatory?ref=metacurity.com) in Lawfare that existing AI incident-reporting laws are too narrow to require disclosure of many serious frontier AI failures, leaving governments and the public without the information needed to understand and regulate emerging risks. > The rationale for mandatory incident reporting is straightforward: Some industries have the potential to cause real harm to others, and the government and the public have an interest in learning about high-risk events. In the case of the AI industry, there is a major knowledge gap between the companies’ and governments’ understanding of the technology and its risks. Mandatory incident reporting about serious adverse events, which companies might otherwise be reluctant to disclose, helps close that gap. This rationale is all the more compelling in the context of a rapidly evolving, difficult to predict technology, where best practice and political consensus have yet to develop. Observing real-world incidents offers a path to resolve both political and empirical disagreements and prepares governments to respond to future events. > So did the Hugging Face breach trigger mandatory disclosure under existing incident reporting laws? The answer seems far from clear. > California’s SB 53, New York’s RAISE Act, and Illinois’s SB 315 each require that frontier AI developers report “critical safety incidents”—a term each law defines identically. Of the four reportable incident categories, three require actual harm, ranging from “bodily injury” to “the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage.” (If you’re thinking, “that’s an exceptionally high bar for what is a basic, low-cost reporting requirement” or “it sure seems like governments would want that information before mass harm occurs,” you would not be wrong, but we digress.) > So three of the four incident categories do not apply. That leaves only the fourth, which applies to incidents in which a frontier model “uses deceptive techniques against the frontier developer to subvert the controls or monitoring of its frontier developer outside the context of an evaluation designed to elicit this behavior and in a manner that demonstrates materially increased catastrophic risk.” > It is possible that the Hugging Face breach meets one or more of these elements. It is far less clear that it meets all of them. On the first element, the models may have used deceptive techniques against OpenAI, their frontier developer—they did, after all, try to complete their developer’s evaluation using stolen information, after bypassing restrictions placed on them. But deception is notoriously hard to define, especially if it turns on the “intentions” and “obfuscation” of AI agents. Another read of these events is that the systems simply used all available means of solving the task, and public reporting does not tell us whether the agents attempted to hide those efforts. The second element is also arguably met. While the incident occurred during an evaluation, that evaluation was not “designed to elicit” this specific “deceptive technique.” Based on the ExploitGym benchmark, this evaluation aimed to elicit agentic, cyber-offensive capabilities on a specific task in a controlled environment. It did not, to our knowledge, contemplate—let alone design for—an unexpected cyberattack on a real-world company. > The third element, that the incident “demonstrates materially increased catastrophic risk” would seem to be the most difficult to satisfy. While autonomous cyber capabilities certainly increase the capability and thus potential consequence of agentic action, so too do most capability improvements in AI models. With limited monetary harm and no physical injury, this incident is quite attenuated from future events that might result in the mass physical injury or property damage contemplated by the statute. > With uncertainty at each factor, it is unclear that these existing state laws cover this event. At the very least, it won’t cover all events like it. Stepping back, it seems far from ideal to condition basic incident reporting on a list of complex, highly contested, fact-dependent conditions—all of which must be satisfied simultaneously. In many cases, figuring out whether the incident is indicative of increased risk to the public or actually constitutes deception will not be possible without more information. The purpose of incident reporting is to produce that information, not to require that it be known before a report is ever sent. The chicken must come before the egg. There are better alternatives. _This post is for paying subscribers only._ ### Russian hackers exploit Zimbra flaw to steal emails and bypass MFA URL: https://www.metacurity.com/russian-hackers-exploit-zimbra-flaw-to-steal-emails-and-bypass-mfa/ Last updated: 2026-07-24T13:42:25.000Z OpenAI probes AI-powered hack of Hugging Face, Bill would mandate AI kill switches, US to restrict visas for cybercriminals and families, Scam compounds expand despite Myanmar crackdown, Clop exploits Windchill flaw in extortion campaign, Dolphin X malware uses AI to rank victims, much more _This post is for paying subscribers only._ ### AI Watch: Hugging Face attack marks "day one" for AI agent cybersecurity URL: https://www.metacurity.com/ai-watch-hugging-face-attack-marks-day-one-for-ai-agent-cybersecurity/ Last updated: 2026-07-23T14:05:42.000Z Everest demands $12.3m from Swiss rail giant Stadler, Origin confirms customer data exposed in cyberattack, A third of ransomware victims face repeat extortion, Check Point patches actively exploited SmartConsole zero-day, Chaos ransomware uses browser traffic to evade detection, much more _This post is for paying subscribers only._ ### AI Watch: OpenAI details 'unprecedented cyber incident' behind Hugging Face breach URL: https://www.metacurity.com/ai-watch-openai-details-unprecedented-cyber-incident-behind-hugging-face-breach/ Last updated: 2026-07-22T13:11:49.000Z Frontier AI models routinely cheat on evaluations, Lightweight AI model for vulnerability hunting emerges, Google launches Gemini Flash Cyber for vulnerability detection and repair, Malware hides inside normal AI coding activity, US weighs sanctions over alleged Chinese AI model theft, much more _This post is for paying subscribers only._ ### AI Watch: China's AI surge is forcing DC and Silicon Valley to rethink the AI race URL: https://www.metacurity.com/ai-watch-chinas-ai-surge-is-forcing-dc-and-silicon-valley-to-rethink-the-ai-race/ Last updated: 2026-07-21T13:57:24.000Z US seizes 1,000+ piracy sites streaming World Cup matches, 7-Zip fixes critical RCE flaw, Attackers begin exploiting critical ServiceNow AI platform flaw, Millions of aftermarket car alarms can be hacked over Bluetooth, SonicWall zero-days used to deploy custom malware on VPN appliances, much more _This post is for paying subscribers only._ ### AI Watch: The AI agent that breached Hugging Face is a sign of things to come URL: https://www.metacurity.com/ai-watch-the-ai-agent-that-breached-hugging-face-is-a-sign-of-things-to-come/ Last updated: 2026-07-20T14:09:05.000Z EY notifies clients of tax data breach, Craneware discloses cyberattack, Ecopetrol says a cyberattack stole data from 3,300 accounts, Kenyan presidential website restored after ransom attack, Abbott probes two cybersecurity incidents, Hackers abuse ViPNet updates to target Russian orgs, much more _This post is for paying subscribers only._ ### Hidden systems, hidden risks: Best infosec long reads 7/18/26 URL: https://www.metacurity.com/hidden-systems-hidden-risks-best-infosec-long-reads-7-18-26/ Last updated: 2026-07-18T12:32:10.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/cookieone-internet-8097838-1.jpg) Image by [Panumas Nikhomkhai](https://pixabay.com/users/cookieone-14478386/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=8097838) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=8097838) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **7/18/26:** This week's long reads peel back the abstractions that shape modern digital life. They reveal the largely invisible infrastructure, institutions, and people we depend on—from data centers and open-source software to messaging platforms, surveillance systems, and government databases—and what happens when those hidden foundations become points of failure, control, or exploitation. ### How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist For The New York Times, novelist Nathaniel Rich [reconstructs](https://www.nytimes.com/2026/07/12/magazine/data-center-heist.html?unlocked%5Farticle%5Fcode=1.xFA.8v8l.LjDkbr5cPB8I&smid=nytcore-ios-share&ref=metacurity.com) the 2007 robbery of a Verizon data center in London, where thieves posing as police officers stole roughly 80 servers allegedly containing evidence of subprime mortgage fraud, turning an audacious burglary into a meditation on the physical vulnerability of the world's digital infrastructure. > The world’s most valuable commodity is not stored in banks, jewelry boutiques or the Louvre. It lives in giant, anonymous, energy-devouring warehouses filled with fiber-optic cables, industrial-scale cooling systems and server racks. > The latest generation of data centers will mainly be used, at a cost of several trillion dollars, to power artificial intelligence. Until now, however, the primary function of data centers has been to store the world’s information. The entire searchable internet, for instance, lives in data centers. But that’s not all. Data centers also store most private digital systems: your email accounts; your medical, pension and educational records; every book and archive ever digitized; every social network and dating app; every government and corporate database. Nearly any time you access electronic data — any time you swipe or scroll or speak a voice command — you rely on the services of a data center. > The public fogginess about data centers is not an accident. It is the product of a willful strategy by the world’s largest tech corporations, whose business models rest on the public assumption that the internet, and all the data it holds, is as immaterial as air — or as a cloud, to borrow the metaphor commonly used to describe the sum of information stored on servers. As the digital-media scholar Tung-Hui Hu writes in “A Prehistory of the Cloud,” the cloud “hides its physical location by design.” > This use of “cloud” dates back at least as far as the mid-1990s, but it didn’t enter the public consciousness for another decade, after the chief executives of Amazon and Google began to market the wonders of “cloud computing.” Information, they declared, had been liberated — emancipated from the prison of the desktop computer and evaporated into the atmosphere. The cloud soon became a permanent feature of the cultural landscape. Many of us began to believe that digital information had actually become vaporous. The metaphor evoked mantras that tech boosters recited with religious zeal, like “Everything is connected” or “Information wants to be free.” > But information does not float in the air. It is encoded on servers: computers without monitors or keyboards, rectangular boxes dotted with blinking LEDs, stacked in vast grids held in warehouses. Our phones and tablets and laptops are so light because they contain little more than a screen, a battery and an antenna. Their powers are merely borrowed, at up to 1,000 megabits per second, from data centers. > By the time Ellis learned about the Verizon job, data collection had quietly become the most critical economic force in modern life. “Data is the new oil,” the British mathematician and data scientist Clive Humby wrote in 2006, an expression that quickly assumed the status of an adage. In the last two decades, data storage has grown into the core business of some of the world’s most valuable corporations. Amazon, for instance, is not, primarily, an e-commerce business. It is a data storage business: Amazon Web Services, the data server provider it started in 2006, accounts for more than half of its profits, and in some quarters as much as 74 percent of its profits. A.W.S.’s clients include, among others, the Library of Congress, the U.S. Treasury, the National Security Agency, the I.R.S. and The New York Times. > Google Cloud represents 15 percent of Alphabet’s income, but it is its fastest-growing division. Microsoft recently disclosed that its own fastest-growing revenue source was its data storage services, which it groups together under the rubric Intelligent Cloud; it hosts the British government, Starbucks, Shell, OpenAI and the U.S. Department of Defense. > Amazon and the other data behemoths speak of the value of their data center operations about as openly as they do their internal algorithms. For two years after building its first data center, Google refused to acknowledge it existed; to this day, it requires visitors to all its centers to sign nondisclosure forms. Amazon and Microsoft still do not disclose the exact number or size of their data centers, indicating their locations only by region or “availability zone.” > Why the secrecy? It’s hard to tell exactly. A guardedness about proprietary business operations is part of the explanation. An effort to conceal the environmental cost is another: Between the energy consumption of the servers and the cooling systems that prevent them from bursting into flames, data centers are responsible for the release of monstrous quantities of greenhouse gases. The largest data centers can consume the energy of two million homes. If the world’s data centers made up a 51st American state, it would rank second in energy consumption, just behind Texas. > But the most likely rationale for the tech companies’ reluctance to discuss the details of their core business is related to security. The anonymous warehouses we call data centers are the lockbox of the global economy. _This post is for paying subscribers only._ ### Moonshot's Kimi K3 raises stakes in battle over AI vulnerability-hunting models URL: https://www.metacurity.com/moonshots-kimi-k3-raises-stakes-in-battle-over-ai-vulnerability-hunting-models/ Last updated: 2026-07-17T14:07:14.000Z DHS seizes 30K SIM cards in anti-fraud crackdown, Coca-Cola's Fairlife ransomware attack disrupts US production, US charges pair in $43m cyber scam laundering ring, Police use Flock cameras to search for people, Italian telecom fined €1.7mover data breaches, much more _This post is for paying subscribers only._ ### Hackers post alleged blueprints and supplier data from India nuclear project URL: https://www.metacurity.com/hackers-post-alleged-blueprints-and-supplier-data-from-india-nuclear-project/ Last updated: 2026-07-16T14:20:56.000Z TfL hackers sentenced to 5½ years in prison, Hacking suspect once worked at Kaspersky, OpenAI unveils AI-powered red teaming tool, Ransomware attack disrupts Japan’s food supply chain, Qantas cleared after social-engineering breach, Health provider criticized for delayed breach disclosure, much more _This post is for paying subscribers only._ ### US indicts three Russians tied to sanctioned bulletproof hoster, offers $10 million reward URL: https://www.metacurity.com/us-indicts-three-russians-tied-to-sanctioned-bulletproof-hoster-offers-10-million-reward/ Last updated: 2026-07-15T13:38:12.000Z Metacurity is the cybersecurity industry's daily reality check—an independent briefing that cuts through vendor spin, social media outrage, and endless recycled narratives to explain what actually matters and why. Every weekday, thousands of cybersecurity professionals—including many of the industry's most respected security leaders—rely on Metacurity to separate signal from noise. We do the reading, research, and analysis so you don't have to. If Metacurity helps you stay informed, save time, or see the bigger picture, please consider becoming a paid subscriber. Reader support is what keeps Metacurity independent, agenda-free, and focused on serving the cybersecurity community—not advertisers, vendors, or investors. [Upgrade your subscription!](#/portal/account/plans) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/MetacurityImage71526-1.png) ### Federal prosecutors unsealed an indictment against three Russians associated with a bulletproof hosting provider sanctioned by the US and two allies in November. The US government also posted a reward of up to $10 million for information in the case. The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud. Aleksandr Volosovik, aka "Yalishanda," owned Media Land, while Yulia Pankova owned ML Cloud, prosecutors said Tuesday. The third defendant, Kirill Zatolokin, was responsible for collecting payments for Media Land and coordinating services with cybercriminals, authorities said in announcing the sanctions last year. The indictment, filed in December 2024, accuses all three with conspiracy to commit and aid and abet computer fraud; conspiracy to commit wire fraud; wire fraud; and conspiracy to commit money laundering. Bulletproof hosting services promise to help criminals evade law enforcement. The document cites 44 unnamed victims who suffered $62 million in losses from cybercriminal groups aided by Media Land and ML Cloud. “From their overseas safe haven, these defendants ran the criminal infrastructure that powered attacks on critical institutions across our nation,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “Their actions put the American public at risk.” Volosovik, Pankova and Zatolokin are known residents of St. Petersburg, authorities said. Russia and the U.S. do not have an extradition treaty. Moscow recently warned Russians not to travel to countries that routinely send criminal suspects to the U.S. The State Department’s announcement of the $10 million bounty under its Rewards for Justice program emphasizes the search for information about foreign government links to the activities of Media Land and ML Cloud. ([Joe Warminsky / The Record](https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting?ref=metacurity.com)) ***Related:*** [*Justice Department*](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more?ref=metacurity.com)*,* [*Rewards for Justice*](https://rewardsforjustice.net/rewards/media-land/?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/russian-cybercrime-indictment/?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/07/14/rewards-for-justice-offers-reward-for-info-on-media-land-ml-cloud-and-three-individuals-associated-with-it/?ref=metacurity.com)*,* [*Crypto Briefing*](https://cryptobriefing.com/doj-charges-russians-63m-cybercrime-scheme/?ref=metacurity.com)*,* [*Becker's Health IT*](https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/3-russians-indicted-in-62m-cybercrime-scheme-that-hit-hospitals/?mid=1&ref=metacurity.com#cid=3619736)*,* [*Reuters*](https://www.reuters.com/legal/government/us-unseals-charges-offers-10-million-reward-info-russian-hackers-2026-07-14/?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/07/14/rewards-for-justice-offers-reward-for-info-on-media-land-ml-cloud-and-three-individuals-associated-with-it/?pk%5Fcampaign=feed&pk%5Fkwd=rewards-for-justice-offers-reward-for-info-on-media-land-ml-cloud-and-three-individuals-associated-with-it&ref=metacurity.com)*,* [*IT News*](https://www.itnews.com.au/news/us-unseals-charges-offers-reward-for-info-on-alleged-russianhackers-627369?ref=metacurity.com) ### Microsoft's July 2026 Patch Tuesday landed with a bang, encompassing security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. Patch Tuesday addresses 59 "Critical" vulnerabilities, 48 of which are remote code execution, 9 are elevation of privilege, 1 is a security bypass, and 1 is a spoofing. The number of flaws does not include flaws in Mariner, Azure OpenAI, Azure Synapse, M365 Copilot, Microsoft Exchange Online, Microsoft Edge for Android, and Microsoft Entra Provisioning Service that were fixed by Microsoft earlier this month. There were also a massive 468 Microsoft Edge/Chromium flaws that were fixed by Google this month, which were excluded from this Patch Tuesday roundup. As part of last month's June Patch Tuesday, Google fixed 360 flaws that were later ported to Microsoft Edge. Last week, Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its Windows codebase before attackers can exploit them. This month's Patch Tuesday fixes three zero-day vulnerabilities, with two exploited in attacks and one publicly disclosed. The two actively exploited zero-days addressed during this month's Patch Tuesday are:CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability, which grants administrative privileges, and CVE-2026-56164 - Microsoft SharePoint Server Elevation of Privilege Vulnerability, which allows a remote attacker to gain elevated privileges. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/?ref=metacurity.com)) ***Related:*** [*The Register*](https://www.theregister.com/security/2026/07/14/patchpocalypse-now-microsoft-tops-last-months-record-with-622-patch-tuesday-cves/5271434?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/microsoft-patch-tuesday-july-2026/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/tech/965643/microsoft-windows-11-july-2026-patch-tuesday-updates?ref=metacurity.com)*,* [*Cisco Talos*](https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2026/?ref=metacurity.com)*,* [*Thurrott*](https://www.thurrott.com/windows/338891/microsoft-releases-july-2026-patch-tuesday-updates?ref=metacurity.com)*,* [*Krebs on Security*](https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/?ref=metacurity.com)*,* [*Lifehacker*](https://lifehacker.com/tech/microsoft-just-patched-570-flaws-in-windows?utm%5Fmedium=RSS&ref=metacurity.com)*,* [*Windows Central*](https://www.windowscentral.com/microsoft/windows-11/windows-11s-latest-update-will-let-you-pause-updates-indefinitely?ref=metacurity.com)*,* [*Notebookcheck*](https://www.notebookcheck.net/Microsoft-s-July-2026-Patch-Tuesday-is-here.1341613.0.html?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/windows-11-kb5101650-kb5099414-july-2026-patch-tuesday-updates-now-available-to-download/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/07/10/july-2026-patch-tuesday-forecast/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb5099414-cumulative-updates-released/?ref=metacurity.com)*,* [*Windows Latest*](https://www.windowslatest.com/2026/07/14/windows-11-kb5101650-out-with-features-like-screen-tint-bluetooth-upgrade-point-in-time-direct-download-update/?ref=metacurity.com)*,* [*SANS Internet Storm Center*](https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154?ref=metacurity.com)*,* [*r/cybersecurity*](https://www.reddit.com/r/cybersecurity/comments/1uwhqeg/microsoft%5Fjuly%5F2026%5Fpatch%5Ftuesday%5Ffixes%5Fmassive/?ref=metacurity.com)*,* [*Ask Woody*](https://www.askwoody.com/2026/july-2026-security-updates/?ref=metacurity.com)*,* [*Tenable Blog*](https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164?mid=1&ref=metacurity.com#cid=3619060)*,* [*Zero Day Initiative - Blog*](https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review?mid=1&ref=metacurity.com#cid=3619662)*,* [*The Stack*](https://www.thestack.technology/microsoft-blockbuster-patch-tuesday-shows-the-vulnpocalypse-has-landed/?mid=1&ref=metacurity.com#cid=3619118)*,* [*CSO Online*](https://www.csoonline.com/article/4196940/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug.html?ref=metacurity.com) ### The Trump administration unveiled its new federal clearinghouse for sharing AI cyber threat information between the government and private sector, and said the project is already receiving threat intelligence on cybersecurity vulnerabilities and prioritizing patching. Created last month through a White House executive order, “Gold Eagle” will be managed by the Department of the Treasury, with contributions from the Cybersecurity and Infrastructure Security Agency, Department of Homeland Security, and Department of Defense, as well as open-source software providers, critical infrastructure operators, and industry. Gold Eagle is meant to help both public and private organizations find, fix, and patch vulnerabilities found using AI tools before they’re discovered and exploited by bad actors. The work will involve using AI to find cybersecurity vulnerabilities in victim systems and software, and Secretary of Homeland Security Markwayne Mullin said it would also further explore ways for the technology to be leveraged for cyber defense. A senior White House official told reporters on a background call that closed-source models from frontier AI models, including Anthropic’s Mythos, will be used to discover vulnerabilities. White House officials said they worked with the Software Engineering Institute, SEI at Carnegie Mellon University, to develop a new platform, the Vulnerability Information and Coordination Environment – or VINTS – to receive third-party reports on AI-discovered vulnerabilities. According to the White House, the system has already begun collecting intelligence on vulnerabilities and prioritizing patches. ([Derek B. Johnson / CyberScoop](https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/?ref=metacurity.com)) **Related:** [*White House*](https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/?ref=metacurity.com)*,* [*CNN*](http://www.cnn.com/2026/07/14/tech/ai-cybersecurity-clearing-house-white-house?ref=metacurity.com)*,* [*Politico*](https://www.politico.com/news/2026/07/14/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-patch-software-flaws-discovered-by-ai-00998011?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/trump-administration-rolls-ai-executive-order-gold-eagle-program?ref=metacurity.com)*,* [*Bloomberg Law*](https://news.bloomberglaw.com/tech-and-telecom-law/white-house-unveils-ai-clearinghouse-for-cybersecurity-risks?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/technology/us-launch-ai-cybersecurity-coordination-group-white-house-says-2026-07-14/?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/livecoverage/stock-market-today-bank-earnings-07-14-2026/card/white-house-launches-platform-for-companies-to-share-ai-cyber-threats-fixes-rS4BBZz2WNdjBcn9J5pK?ref=metacurity.com)*,* [*PaymentSecurity.io*](https://www.paymentsecurity.io/us-government-launches-ai-vulnerability-clearinghouse-a-32228?ref=metacurity.com)*,* [*Nextgov/FCW*](https://www.nextgov.com/cybersecurity/2026/07/white-house-announces-gold-eagle-ai-clearinghouse-cyber-vulnerabilities/414768/?ref=metacurity.com) ### Oracle is winning the race to sell top-secret cloud services to Japan that the US says are critical to secure intelligence sharing between Tokyo and allies as they face growing threats from China. The Texas-based company is leading Amazon Web Services, Microsoft and Google to provide the “air-gapped” cloud, according to seven people familiar with talks between the tech groups, Tokyo and Washington. Japan opted for a US cloud computing company after extensive discussions with Washington and a conversation between President Donald Trump and Prime Minister Sanae Takaichi in March. The US has long wanted Japan to install stronger cyber security because its existing systems are very vulnerable to Chinese hacking. The urgency has risen as it pushes Tokyo to increase co-production of weapons and boost deterrence against China.US officials also believe Japan needs tighter cyber security to have a chance of joining Five Eyes, an intelligence-sharing group comprising the US, UK, Australia, New Zealand and Canada. UK and Japanese officials said their plans to co-build a next-generation fighter jet had increased pressure on Tokyo to build more secure infrastructure for sharing secret data. ([Demetri Sevastopulo and Leo Lewis / Financial Times](https://www.ft.com/content/c8d32323-1d06-4470-8375-2ee6dd42749e?ref=metacurity.com)) ***Related:*** [*Benzinga*](https://www.benzinga.com/markets/tech/26/07/60461892/oracle-leads-aws-microsoft-google-in-race-to-build-japans-secret-cloud-project-to-counter-chinese-hacking-threats-report?ref=metacurity.com) ### Finnish police have reportedly issued a wanted notice for convicted hacker Aleksanteri Kivimäki after the country's Supreme Court refused to hear his appeal, paving the way for authorities to return him to prison in one of Finland's most high-profile cybercrime cases. The Supreme Court's decision leaves in place a February Court of Appeal ruling that sentenced Kivimäki to nearly seven years in prison for hacking psychotherapy provider Vastaamo and later extorting both the company and its patients, according to Finnish media. Following the ruling, Eastern Uusimaa Police said they issued the wanted notice at the request of Finland's Criminal Sanctions Agency. Officers have been instructed to arrest Kivimäki if he is located and transfer him to Vantaa Prison to serve the rest of his sentence. His lawyer, Peter Jaari, told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland. The Court of Appeal convicted Kivimäki of aggravated data breach, attempted extortion and unlawfully distributing private information. The judges said the crimes were carefully planned, driven by financial gain and caused exceptional harm to a large number of especially vulnerable victims. The court said the offenses would normally have justified the maximum available sentence. However, it reduced Kivimäki's prison term by one month because he reached compensation agreements with some of the victims. ([Daryna Antoniuk / The Record](https://therecord.media/finland-issues-wanted-notice-for-hacker-vastaamo-breach?ref=metacurity.com)) **Related:** [*Helsinki Times*](https://www.helsinkitimes.fi/finland/finland-news/domestic/29048-vastaamo-hacker-wanted-after-appeal-rejected.html?ref=metacurity.com)*,* [*YLE*](https://yle.fi/a/74-20236162?ref=metacurity.com)*,* [*ILTA Sanomat*](https://www.is.fi/kotimaa/art-2000012138845.html?ref=metacurity.com)*,* [*Iltalehti*](https://www.iltalehti.fi/kotimaa/a/2f9c7942-e685-4eef-8b63-a7d1d8dceeeb?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/07/14/finland-issues-wanted-notice-for-hacker-behind-massive-psychotherapy-data-breach/?pk%5Fcampaign=feed&pk%5Fkwd=finland-issues-wanted-notice-for-hacker-behind-massive-psychotherapy-data-breach&ref=metacurity.com) ### The District of Nevada's US Attorney's Office announced that a federal grand jury indicted two men for an alleged scheme to steal money from ATMs in Reno and Sparks in ATM jackpotting attacks. Kleiber Jovanny Garcia Rojas and Yeiker Andres Diaz-Calatayud, also known as Jose Soto, allegedly stole approximately $76,000 in cash. Court documents and statements made in court on June 3 claimed the two installed a digital device on an ATM at a federal credit union, which allowed them to bypass security functions and withdraw cash. Garcia Rojas and Diaz-Calatayud were each charged with one count of bank theft, according to the release. If convicted, they could each face the maximum of 10 years in prison. A jury trial is scheduled for Sept. 15 before U.S. District Judge Anne Traum. ([Jaedyn Young / The Reno Gazette Journal](https://www.rgj.com/story/news/crime/2026/07/14/two-men-indicted-for-alleged-atm-jackpotting-scheme-in-reno-sparks/90922521007/?ref=metacurity.com)) **Related:** [*Justice.gov*](https://www.justice.gov/usao-nv/pr/two-men-indicted-alleged-roles-atm-jackpotting-scheme?ref=metacurity.com)*,* [*KRXI*](https://mynews4.com/news/local/two-men-indicted-in-alleged-reno-sparks-atm-jackpotting-scheme-prosecutors-say?ref=metacurity.com)*,* [*KTVN*](https://www.2news.com/news/local/two-men-indicted-in-alleged-atm-jackpotting-scheme-targeting-reno-and-sparks/article%5Fa41f6179-7c9f-4f4e-ba6f-3fa54f2be425.html?ref=metacurity.com) ### The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. As part of the law enforcement operation, four people were arrested in Spain, Portugal, and Panama. The police describe the operation as an industrial-level scheme as it involved at least 800 bank accounts, 120 business accounts, and 67 external accomplices who acted as “money mules.” The investigation has confirmed that €94 million ($107 million) was channeled through the network and linked another €61 million ($69.5 million) to the group, tying it specifically to BEC operations that took place in 2024. The police announcement calls this “CEO fraud” and “false-invoice fraud,” indicating the use of social engineering tactics such as impersonating high-ranking executives and diverting payments to bank accounts controlled by the fraudsters. The investigation into the cybercrime operation started after the police detected signs of money laundering in 19 companies linked to it. Following the identification of the main suspects, an international police operation was organized with the help of Interpol and Europol. In this context, six premises in Barcelona, Girona, and Tarragona, as well as in the city of Porto in Portugal, were raided and searched, and another suspect was also arrested in Panama. The two suspects arrested outside Spain left the country recently but continued to operate from their foreign bases in support of the cybercrime scheme. The police agents seized 15 computers and over 170 smartphones, believed to have been used for executing thousands of fraudulent transfers. Additionally, €3 million ($3.4 million) of crime proceeds was frozen immediately and will be made available to victims of the cybercrime ring. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/?ref=metacurity.com)) **Related:** [*Policia*](https://policia.es/%5Fes/comunicacion%5Fprensa%5Fdetalle.php?ID=16947&ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/07/15/cybercrime-network-investment-fraud-spain/?ref=metacurity.com) ### KFC Japan has announced that a cyberattack affecting one of its third-party logistics providers is disrupting food deliveries to restaurants nationwide, raising the possibility of product shortages, reduced operating hours, and temporary store closures. The company has suspended all online ordering services as it works with its logistics partner to restore normal operations. KFC Japan said the disruption stems from an unauthorized third-party intrusion into the logistics company's systems responsible for delivering ingredients to the hundreds of restaurants the fast-food chain operates nationwide. According to the company, the attack occurred on July 13, 2026, when the outsourced logistics provider experienced a system failure due to unauthorized access. The outage has affected the operator's logistics and distribution centers, preventing normal food deliveries to KFC restaurants beginning on July 14. The company said all KFC locations in Japan could be affected by the incident, and customers may encounter out-of-stock menu items, limited product availability, shortened business hours, or, in some cases, temporary store closures depending on local inventory levels. In addition to in-store disruptions, KFC Japan has temporarily suspended its digital ordering channels, including its official mobile app, website ordering platform, delivery services, and third-party delivery integrations. The company did not specify when those services will return, stating only that recovery timelines remain unknown while its logistics partner works to restore affected systems. KFC Japan has not identified the logistics company involved, nor has it disclosed the nature of the cyberattack or whether ransomware was deployed. ([Amar Ćemanović / Cyber Insider](https://cyberinsider.com/cyberattack-at-kfc-japan-impacting-online-orders-and-deliveries/?ref=metacurity.com)) **Related:** [*Japan KFC*](https://japan.kfc.co.jp/news%5Frelease/8160?ref=metacurity.com)*,* [*Nikkei Asia*](https://asia.nikkei.com/spotlight/cybersecurity/kfc-faces-possible-closures-after-cyberattack-on-japan-s-nichirei?ref=metacurity.com)*,* [*Asia News Network*](https://www.straitstimes.com/asia/east-asia/chicken-shipment-delayed-kfc-japans-operations-disrupted-after-cyberattack-on-logistics-provider?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/kfc-japan-faces-delivery-disruptions-due-to-third-party-cyberattack?ref=metacurity.com)*,* [*The Loadstar*](https://theloadstar.com/fck-here-we-go-again-cyberattack-leaves-kfc-with-empty-buckets/?ref=metacurity.com)*,* [*Japan News*](https://japannews.yomiuri.co.jp/business/companies/20260715-338281/?ref=metacurity.com) ### AI security firm Manifold says two vulnerabilities it reported to Anthropic in May remain exploitable in the latest version of Claude for Chrome, the company’s agentic browser extension. According to Manifold, the flaws let a malicious browser extension trigger Claude into taking actions on a user’s behalf without any genuine click or approval from the victim. An attacker could exploit them to read Gmail messages, Google Docs documents, and calendar entries. The core issue is related to a fix Anthropic shipped earlier this year in response to a similar vulnerability dubbed ClaudeBleed. That update restricted which prompts an outside webpage could feed into Claude, narrowing the extension’s exposure to a fixed set of pre-approved tasks. Manifold found that the mechanism used to activate those tasks doesn’t verify whether a click actually came from a real user, meaning another extension can fake the interaction and set the process in motion. In the extension’s default setting, the attack triggers a confirmation prompt before anything sensitive happens. However, if a user has enabled the extension’s more autonomous mode (‘Act without asking’), the attacker’s action can proceed without any visible warning. Manifold also flagged a second, related design gap: a way for Claude’s side panel to launch directly into that no-confirmation mode based on a parameter in its own URL, with no user action required to unlock it. ([Eduard Kovacs / Security Week](https://www.securityweek.com/unpatched-claude-for-chrome-flaw-lets-extensions-read-gmail-calendar/?ref=metacurity.com)) ***Related:*** [*Manifold*](https://www.manifold.security/blog/claude-for-chrome-extension-bypass?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/claude-for-chrome-flaw/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/claude-for-chrome-vulnerability/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-45.png) A live view of the runtime signals Manifold raises when agents and their tool calls drift from expected behavior. Source: Manifold. ### The British public should begin taking “small but important steps” to secure and protect water, power supplies and basic phone signal in case of further severe weather emergencies, national crises or cyber-attacks, Downing Street has said. Darren Jones, the chief secretary to the prime minister, told MPs “the risks we face from climate change cannot be underestimated”, and warned of the “significant and prolonged disruption to essential services” extreme weather events could cause. Jones also said the combination of increasingly sophisticated artificial intelligence and the conflict in the Middle East and Russia’s war in Ukraine could enable criminals to carry out “hostile cyber-attacks against businesses and critical infrastructure." As a result, the UK’s national risk register has been updated with seven new crises, including the threat of foreign interference in UK democracy, the risk of cyber-attacks on data infrastructure, water infrastructure and police systems, and a “digital resilience failure” scenario, based on the global technology outage caused by the CrowdStrike disruption in 2024\. ([Aletha Adu / The Guardian](https://www.theguardian.com/politics/2026/jul/14/britons-urged-small-steps-prepare-potential-national-crises?ref=metacurity.com)) **Related:** [*RBC-Ukraine*](https://newsukraine.rbc.ua/news/uk-urges-households-to-stockpile-food-over-1784094338.html?ref=metacurity.com)*,* [*The Independent*](https://www.independent.co.uk/news/uk/politics/russia-attack-stockpile-food-uk-warning-putin-b3014738.html?ref=metacurity.com)*,*[ *Telegraph*](https://www.telegraph.co.uk/news/2026/07/14/defence-russia-public-stockpile-food-russian-cyber-attacks/?ref=metacurity.com) ### Silicon-to-systems design firm Synopsys says it has found no evidence of a data breach after a cybercrime group claimed to have hacked its systems and gained access to valuable data belonging to one of its major customers, Bosch. A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and they are threatening to leak the stolen data unless a ransom is paid. Separately, D1R claimed to have hacked German engineering and technology giant Bosch using data obtained from Synopsys. The cybercriminals allegedly obtained valuable intellectual property belonging to Bosch. ([Eduard Kovacs / Security Week](https://www.securityweek.com/synopsys-finds-no-evidence-of-data-breach-following-bosch-hack-claims/?ref=metacurity.com)) **Related:** [*SC Media*](https://www.scworld.com/brief/synopsys-denies-data-breach-claims-by-new-ransomware-group-d1r?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/07/14/synopsys-finds-no-evidence-of-data-breach-amid-bosch-hack-claims/?pk%5Fcampaign=feed&pk%5Fkwd=synopsys-finds-no-evidence-of-data-breach-amid-bosch-hack-claims&ref=metacurity.com) ### The Air Force is scrambling to get employees across the service back online after weeks of rolling cybersecurity quarantines locked numerous troops and civilians out of their computers, sometimes for days. A quarantine kicks in to protect military networks from cyberattacks if a computer isn’t routinely updated with new software patches. But as the Air Force pushes out patches more often to stay ahead of digital threats, employees must make sure those updates are in place — or find their device rendered unusable. The lockouts have created headaches at multiple bases and the Pentagon as the service continues rolling out forcewide software updates. While quarantines aren’t new, the scale of the ongoing issue is unusual. The outage allegedly hit tens of thousands of devices, according to an anonymous post on “Air Force amn/nco/snco,” an unofficial Facebook page popular with airmen. ([Rachel S. Cohen / Federal News Network](https://federalnewsnetwork.com/defense-main/2026/07/air-force-network-lockouts-hit-troops-and-civilians/?ref=metacurity.com)) **Related:** [*Facebook*](https://www.facebook.com/AFamnncosnco/posts/pfbid02tWG2Xa7kDEKVfy2RUmGvevkNAwugLM1KVC8qZKj6NrRwQ2K7Gni2MEgEfCyEWnbwl) ### Researchers at Arctic Wolf say a threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. The campaign drew traffic from search results for security products, cryptocurrency services, financial tools, developer utilities, secure email providers, macOS utilities, and gaming software. The malware collects data from more than 19 web browsers, steals info from 32 cryptocurrency wallets, and exfiltrates sensitive details from messaging and social media apps. ArcticWolf identified the activity after finding that one of its products was impersonated in the campaign starting June 26. In total, the researchers uncovered 292 fake repositories, each including a README file with a download link directing visitors to a malicious download page. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/?ref=metacurity.com)) **Related:** [*Arctic Wolf*](https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-46.png) Fake GitHub repository featuring badges of authenticity. Source: Arctic Wolf ### SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. While CVE-2026-15410 requires administrator privileges, SonicWall assigned the advisory an overall CVSS score of 10.0. SonicWall says it investigated multiple incidents and confirmed that both vulnerabilities are being actively exploited. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/?ref=metacurity.com)) **Related:** [*SonicWall*](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/195364/hacking/sonicwall-warns-of-active-exploitation-of-two-sma-1000-zero-days.html?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/?ref=metacurity.com) ### The researcher who exposed Grok Build uploading users' entire repositories to cloud storage says the transfers have stopped after a server-side change. Elon Musk has separately promised that all previously uploaded user data will be deleted. AI safety researcher Cereblab published a report on Sunday about their investigation into Grok Build, SpaceXAI's command-line interface (CLI), and the data exchanged between the CLI and SpaceXAI's servers. Cereblab found that when Grok Build reads or processes a file, the contents of that file are transmitted without redaction to a Google Cloud Storage bucket used by SpaceXAI. Further, they claimed that Grok Build packages entire repos and uploads them as Git bundles, instead of just uploading the files required to answer a user's prompt. According to Cereblab's report, SpaceXAI's data retention went far beyond that of other CLIs, such as Claude Code, Gemini, and Codex, which open individual files rather than entire repos before uploading them along with their Git histories. The researcher tested the behavior using a benign prompt. They instructed the CLI to reply with "OK," and specifically ordered it not to open any files. Grok Build uploaded the entire repo regardless, along with its full Git history containing secrets that were deleted months prior – a finding Cereblab reproduced using a separate repo. Other Grok Build users reported similar results after Cereblab published their report, including one whose entire user directory, containing SSH keys, password manager databases, and more, was opened and uploaded. The findings attracted enough attention for SpaceXAI execs and Musk to comment on them publicly, as well as prompting the company to implement a remedy quickly. ([Connor Jones / The Register](https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123?ref=metacurity.com)) **Related:** [*Cereblab*](https://cereblab.com/?ref=metacurity.com)*,* [*IXBT*](https://www.ixbt.com/news/2026/07/14/grok-build-cli.html?ref=metacurity.com)*,* [*Zamin*](https://zamin.uz/en/technology/212456-elon-musk-promises-to-delete-all-data-following-a-leak-of-users-confidential-information.html?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/07/14/elon-musk-promises-to-delete-all-data-following-a-leak-of-users-confidential-information/?pk%5Fcampaign=feed&pk%5Fkwd=elon-musk-promises-to-delete-all-data-following-a-leak-of-users-confidential-information&ref=metacurity.com)*,* [*Tech Times*](https://www.techtimes.com/articles/320420/20260714/grok-build-shipped-entire-codebases-xai-cloud-privacy-toggle-did-nothing.htm?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/965600/spacexai-grok-build-repository-upload?ref=metacurity.com)*,* [*Hindustan Times*](https://www.hindustantimes.com/world-news/us-news/why-elon-musks-xai-is-facing-backlash-over-claims-it-uploaded-users-code-101784051444702.html?ref=metacurity.com)*,* [*Crypto Briefing*](https://cryptobriefing.com/xai-grok-build-cli-private-code-leak/?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2026/07/15/grok-build-uploaded-repositories-before-remote-fix-xcxwbn/?ref=metacurity.com)*,* [*FirstPost*](https://www.firstpost.com/tech/elon-musk-vows-purge-after-grok-build-reportedly-uploaded-entire-git-repositories-to-the-cloud-14031379.html?ref=metacurity.com) ### Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. Passkeys will be enabled automatically for Entra ID users now using phone-based SMS and voice authentication, which will be retired in February 2027 across all tenants. However, users who are already signing into their accounts with passkeys, Windows Hello for Business, FIDO2 security keys, smart cards, or any other phishing-resistant method will be able to continue using those methods. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/?ref=metacurity.com)) **Related:** [*Microsoft*](https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/entra-id-default-authentication-passkeys/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html?ref=metacurity.com)*,* [*Redmond Mag*](https://redmondmag.com/articles/2026/07/14/microsoft-makes-passkeys-the-entra-id-default-as-identity-attacks-grow-stealthier.aspx?ref=metacurity.com)*,* [*Biometric Update*](https://www.biometricupdate.com/202607/microsoft-and-google-push-passkeys-deeper-into-workplace-authentication?ref=metacurity.com)*,* [*Petri*](https://petri.com/microsoft-entra-id-passkeys-default-authentication/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/microsoft-entra-id-authentication-getting-major-shakeup-with-default-passkeys-very-soon/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/?ref=metacurity.com)*,* [*Heise Online*](https://www.heise.de/en/news/Microsoft-makes-passkeys-the-default-in-Entra-ID-11364823.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-47.png) Timeline for SMS/voice authentication retirement. Source: Microsoft. ### Security firm Certo says cyberstalkers are increasingly exploiting Google Chrome's built-in synchronization feature to secretly monitor victims' web activity without installing spyware or compromising their devices. Certo says it has received a growing number of reports involving the tactic, which relies on briefly accessing a victim's device and signing in to Chrome with an attacker-controlled Google account. The technique reflects a broader shift away from traditional stalkerware, as modern mobile operating systems have made spyware deployment more difficult through stronger security protections, stricter app store policies, and improved malware detection. The method itself is straightforward. An attacker only needs a brief opportunity to unlock the victim's phone, tablet, or computer and open Chrome. They then add a Google account they control and ensure Chrome Sync is enabled. From that point onward, Chrome synchronizes browsing history with the attacker's account, allowing them to review the victim's activity remotely from any device logged into that account. ([Alex Lekander / Cyber Insider](https://cyberinsider.com/chrome-sync-increasingly-abused-to-stalk-unsuspecting-victims/?ref=metacurity.com)) **Related:** [*Certo*](https://www.certosoftware.com/insights/cyberstalkers-exploiting-chrome-sync-to-spy/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-48.png) Checking the connected account. Source: Certo. ### Twelve days after Sysdig documented the first end-to-end AI-agent ransomware operation, Ant Group's AI Security Lab has released a free, open-source guardrail framework designed to intercept the exact attack sequence that campaign used. The tool, SingGuard-NSFA, is now available on GitHub and Hugging Face and can run inline in any autonomous agent pipeline — catching prompt injection attempts, credential-theft patterns, malicious code execution, and permission misuse before they become irreversible real-world consequences. For teams running AI agents in production, this is the first purpose-built, auditable tool designed to address the threat class that JadePuffer proved is no longer theoretical. ([Mireya Ramsey / Tech Times](https://www.techtimes.com/articles/320508/20260714/ant-group-open-sources-agent-security-tool-days-after-agentic-ransomware-hit.htm?ref=metacurity.com)) **Related:** [*Business Wire*](https://www.businesswire.com/news/home/20260712722454/en/Ant-Group-Open-Sources-SingGuard-NSFA-to-Establish-New-Security-Paradigms-for-Autonomous-AI-Agents?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/07/15/singguard-nsfa-open-source-agentic-ai-guardrails/?ref=metacurity.com)*,* [*Fintech Finance News*](https://ffnews.com/news/ant-group-open-sources-singguard-nsfa-to-secure-autonomous-ai-agents?ref=metacurity.com) ### The genetic testing company formerly known as 23andMe has agreed to pay $18 million to 42 states to settle litigation stemming from a 2023 breach that exposed sensitive personal data of nearly 7 million customers. The company, now called Chrome Holding Co., filed the proposed settlement agreement Tuesday in the United States Bankruptcy Court for the Eastern District of Missouri. 23andMe filed for Chapter 11 bankruptcy in 2025\. The states had filed claims in the bankruptcy seeking roughly $100 billion in alleged damages, which the estate said would be costly and time-consuming to litigate. The proposed agreement, which needs to be approved by Judge Brian C. Walsh, would bring an end to states’ claims tied to the breach. The settlement proposal also includes a five-year ban on the company from directly selling goods or services to consumers, as well as collecting or maintaining personally identifiable information beyond what is required by the agreement. ([Ethan Schenker / Bloomberg Law](https://news.bloomberglaw.com/privacy-and-data-security/23andme-to-pay-42-states-18-million-in-2023-breach-settlement?ref=metacurity.com)) **Related:** [*KARE11*](https://www.kare11.com/article/news/state/23andme-data-breach-settlement-minnesota/89-efe95869-d324-478f-9b45-07e0fa54edf8?ref=metacurity.com)*,* [*PhillyVoice*](https://www.phillyvoice.com/pennsylvania-new-jersey-23andme-settlement/?ref=metacurity.com)*,* [*WAOW*](https://www.waow.com/news/wisconsin-to-receive-275k-in-23andme-data-breach-settlement-affecting-millions/article%5F10f25004-4991-41c3-8504-9871661e60ad.html?ref=metacurity.com)*,* [*WPXI*](https://www.wpxi.com/news/local/pennsylvania-receive-491k-23andme-genetic-data-breach-settlement/CHM4ZPHXWJFTBFEBYDL3Z2BPWM/?ref=metacurity.com)*,* [*Audacy*](https://www.audacy.com/wtic/news/local/ct-ag-23andme-genetic-data-breach-settlement?ref=metacurity.com)*,* [*Daily Voice*](https://dailyvoice.com/article/data-breach-exposes-305k-nyers-genetic-information-now-23andme-to-pay-18m-ag-says/?ref=metacurity.com)*,* [*Eastern Shore Undercover*](https://www.easternshoreundercover.com/article/delaware-reach-settlement-in-23andme-data-breach-case.htm?ref=metacurity.com)*,* [*WKOW*](https://www.wkow.com/news/state/wisconsin-to-receive-275k-in-23andme-genetic-data-breach-settlement/article%5F74f20f4b-64f7-4c3a-b996-9e0a6ee2f633.html?ref=metacurity.com)*,* [*WNYT*](https://wnyt.com/top-stories/23andme-pays-18m-settlement-over-6-9m-customer-data-breach/?ref=metacurity.com)*,* [*Erie News Now*](https://www.erienewsnow.com/news/pa-to-receive-nearly-492k-in-23andme-data-breach-settlement/article%5F81c942eb-599d-45aa-bfa1-f329dcad33c3.html?ref=metacurity.com)*,* [*WNEM*](https://www.wnem.com/2026/07/15/multistate-settlement-reached-with-23andme-2023-data-breach/?ref=metacurity.com)*,* [*PennLive*](https://www.pennlive.com/news/2026/07/pa-and-other-states-reach-bankruptcy-claim-settlement-with-23andme-in-data-breach-case.html?ref=metacurity.com)*,* [*Statesman Journal*](https://www.statesmanjournal.com/story/news/politics/2026/07/14/oregon-settlement-23andme-data-breach/90920736007/?ref=metacurity.com)*,* [*AZ Family*](https://www.azfamily.com/video/2026/07/14/arizona-joins-18m-multi-state-settlement-with-23andme-over-breach/?ref=metacurity.com)*,* [*Valley News Live*](https://www.valleynewslive.com/2026/07/14/minnesota-north-dakota-among-42-states-settlement-with-23andme-over-2023-genetic-data-breach/?ref=metacurity.com)*,* [*WMTV*](https://www.wmtv15news.com/2026/07/14/wisconsin-receive-money-multi-state-settlement-against-23andme/?ref=metacurity.com)*,* [*KTAR*](https://ktar.com/arizona-news/arizona-23andme-genetic-data-breach/5888778/?ref=metacurity.com)*,* [*Straight Arrow News*](https://san.com/cc/23andme-customers-in-dozens-of-states-will-get-paid-after-150m-data-breach-settlement/?ref=metacurity.com)*,* [*WGAL*](https://www.wgal.com/article/pennsylvania-receive-492000-genetic-data-breach-settlement/71934760?ref=metacurity.com)*,* [*KWWL*](https://www.kwwl.com/news/iowa-wins-share-of-18m-deal-over-23andme-data-breach/article%5Fdfae21c3-0319-46c6-ad00-82234ed3e55f.html?ref=metacurity.com)*,* [*WGMD*](https://www.wgmd.com/ag-jennings-announces-multistate-settlement-of-bankruptcy-claims-against-23andme-over-genetic-data-breach/?ref=metacurity.com)*,* [*KOTA*](https://www.kotatv.com/2026/07/14/south-dakota-receive-nearly-150k-23andme-bankruptcy-settlement-follwing-2023-data-breach/?ref=metacurity.com)*,* [*WZMQ*](https://wzmq19.com/news/365924/michigan-to-receive-436000-in-multistate-settlement-over-23andme-data-breach/?ref=metacurity.com)*,* [*WBAY*](https://www.wbay.com/2026/07/14/wisconsin-receive-275k-23andme-data-breach-settlement/?ref=metacurity.com) ### Cybersecurity stocks jumped after IBM CEO Arvind Krishna flagged cyber fears as a top priority for customers in the company’s preliminary second-quarter results. During the period, Krishna said customers shifted spending to servers and memory and that “rapidly-evolving, industry-wide cybersecurity concerns” distracted customers. The rise of advanced artificial intelligence models such as Anthropic’s Mythos has spurred mass anxiety on Wall Street and worries of quicker, more sophisticated cyberattacks. Krishna told CNBC’s Sara Eisen that some major deals were put on hold toward the end of the quarter as businesses rethink spending. “Mythos is making people pause to say, wait, how much do I need to spend on cyber? They’re pausing on new deals until they know,” Krishna told Eisen. “We don’t see our software being disrupted by AI at all.” ([Samantha Subin / CNBC](https://www.cnbc.com/2026/07/14/cybersecurity-stocks-ai-spending-mythos.html?ref=metacurity.com)) **Related:** [*Barron's Online*](https://www.barrons.com/articles/ibm-earnings-warning-crowdstrike-stock-041e6d6d?ref=metacurity.com)*,* [*The Hans India*](https://www.thehansindia.com/technology/tech-news/why-ibm-admits-it-stumbled-this-quarter-read-ceo-arvind-krishnas-full-letter-here-1097634?ref=metacurity.com)*,* [*ITPro*](https://www.itpro.com/security/we-did-not-adapt-and-move-quickly-enough-ibm-ceo-arvind-krishna-laments-enterprise-spending-pivot-as-company-issues-profit-warning?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/world/ibm-stock-crash-ceo-arvind-krishna-ai-infrastructure-spending-shift-mainframe-quantum-10787319/?ref=metacurity.com)*,* [*Motley Fool*](https://www.fool.com/investing/2026/07/14/why-ibm-stock-crashed-today/?ref=metacurity.com)*,* [*Blockonomi*](https://blockonomi.com/three-cybersecurity-leaders-to-monitor-crowdstrike-crwd-palo-alto-networks-panw-and-okta-okta/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-07-14/ibm-says-second-quarter-sales-missed-as-customers-pulled-back?ref=metacurity.com) ### Best Thing of the Day: Let This Be the Beginning of a Beautiful Trend New York became the first US state [to halt construction](https://www.reuters.com/world/new-york-becomes-first-state-impose-data-center-moratorium-2026-07-14/?ref=metacurity.com) ​of large new data centers, imposing a one-year moratorium as concerns grow that the facilities driving the artificial-intelligence boom are raising power costs, straining water ‌supplies and burdening local communities. ### Worst Thing of the Day: Russia Takes Its Denialism Cue from China Russia on Tuesday [slammed](https://thedefensepost.com/2026/07/15/russia-eu-cyber-attacks/?ref=metacurity.com) as “baseless” accusations by the European Union and Britain that its intelligence agencies were behind a campaign of cyber attacks on Europe. ### Bonus Worst Thing of the Day: We Think 16 and 17-Year-Olds Know About VPNs The United Kingdom [will require](https://www.wired.com/story/the-uk-is-planning-a-social-media-curfew-for-16-and-17-year-olds/?ref=metacurity.com) social media companies to implement a default block for adolescent users aged 16 and 17 at certain hours, the country’s Department for Science, Innovation & Technology said. ### Closing Thought ### Western allies pair Russia sanctions with a warning on critical infrastructure attacks URL: https://www.metacurity.com/western-allies-pair-russia-sanctions-with-a-warning-on-critical-infrastructure-attacks/ Last updated: 2026-07-14T14:03:54.000Z UK charges five over Russian Coms spoofing platform, Treasury sanctions VPN provider tied to ransomware gangs, DHS missed warning signs before credential theft breach, Cyberattacks targeted US personnel through Mideast mobile networks, Korean police uncover large-scale GitHub token leak, much more _This post is for paying subscribers only._ ### AI's new battleground: Cost, efficiency, and control URL: https://www.metacurity.com/ais-new-battleground-cost-efficiency-and-control/ Last updated: 2026-07-13T13:16:06.000Z AI vendors pivot from capability to cost, OpenAI eases GPT-5.6 usage limits, Enterprises scrutinize soaring AI bills, Chinese AI models gain enterprise traction, Anthropic data reveals how AI gets used, AI agents tackle business ops workloads, Open-source AI faces mounting policy pressure, much more _This post is for paying subscribers only._ ### Trust under attack: Best infosec long reads 7/11/26 URL: https://www.metacurity.com/trust-under-attack-best-infosec-long-reads-7-11-26/ Last updated: 2026-07-11T12:24:55.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/theotherkev-oxford-circus-street-tube-4809361-1.jpg) Image by [Kev](https://pixabay.com/users/theotherkev-9436196/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=4809361) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=4809361) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **7/11/26:* This week's long reads examine the fragile trust relationships that underpin modern digital systems. From the alleged Scattered Spider attack that crippled TfL through a single compromised account to AI models that cannot distinguish legitimate instructions from malicious ones, the stories reveal a common truth: the hardest problems in cybersecurity are rarely technical alone.* ### The teenage millionaire hacker from Tower Hamlets who took down TfL London Centric's Polly Smythe, Jim Waterson, and Cormac Kehoe [paint](https://www.londoncentric.media/p/thalha-jubair-scattered-spider-hack-transport-for-london?ref=metacurity.com) a detailed portrait of how alleged Scattered Spider member Thalha Jubair became linked to the disruptive Transport for London cyberattack and the broader ecosystem of socially engineered intrusions. > It was by compromising the account of a single employee that Jubair was able to hack into TfL’s systems in late August 2024, catastrophically damaging the transport authority’s ability to manage its own systems. At an early court hearing last September, the prosecutor said that the “ultimate objective of the attack was to install ransomware”. > Although buses and tubes were kept running, one TfL executive described the behind-the-scenes situation to London Centric as “an utter shitshow”, with hundreds of thousands of holders of discount travel cards affected. > The booking system for the Dial-a-Ride buses used by people with disabilities was shut down, and data on live tube times for apps such as TfL Go and Citymapper was taken offline. > Hundreds of thousands of Londoners were overcharged for using the network, and many of the capital’s teenagers were unable to access free travel, leaving some without the means to get to work or college. Sadiq Khan later told London Centric that some passengers would never be refunded. > TfL commissioner Andy Lord described the incident as a “highly sophisticated” cyber attack that could have been much worse. Staff at TfL’s HQ were unable to log on to the IT network, WiFi was taken down, and office-based staff were sent to work from home for the whole of September. When they returned, every TfL staff member had to travel into the office to have their login details reset. City Hall had just outsourced its IT to TfL meaning everyone from the mayor downwards had their work systems affected. Projects ranging from the extension of the contactless payment scheme to commuter stations to the rebranding of the London Overground lines were delayed. > Flowers, the teenager from Walsall, was arrested soon after. But it took another year for Jubair, who was portrayed in US court documents as a mastermind of the group, to be charged. We now know that the incident, which cost TfL £39m, and in which 10 million people’s data was stolen, was in part orchestrated from the bedroom of Jubair’s east London flat. > Paul Foster, the head of the National Crime Agency’s cyber crime unit, said the “profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries”. _This post is for paying subscribers only._ ### OpenAI launches GPT-5.6 as AI vendors compete for enterprise users URL: https://www.metacurity.com/openai-launches-gpt-5-6-as-ai-vendors-compete-for-enterprise-users/ Last updated: 2026-07-10T14:39:43.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/cookieone-heart-8097836-1.jpg) Image by [Panumas Nikhomkhai](https://pixabay.com/users/cookieone-14478386/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=8097836) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=8097836) *Metacurity is the cybersecurity industry's daily reality check—independent, agenda-free coverage that cuts through vendor hype, social media noise, and recycled talking points to explain what matters and why.* *Trusted by thousands of cybersecurity professionals, including many of the industry's most influential security leaders, Metacurity delivers the context, analysis, and perspective that busy readers don't have time to assemble themselves.* *If you find value in that work, please consider becoming a paid subscriber. Metacurity remains independent because its readers choose to support it.* [Upgrade my subscription](#/portal/account/plans) A series of announcements from OpenAI, Meta, and Anthropic yesterday highlight both the rapid evolution of frontier AI models and the growing challenges of delivering increasingly powerful AI capabilities at scale. OpenAI unveiled GPT-5.6, its latest flagship model, positioning it as a major upgrade for coding, reasoning, and agentic workflows. The release is likely to draw close attention from security teams, which increasingly use large language models for vulnerability analysis, malware investigation, threat hunting, code review, and security automation. The launch also raises fresh questions about how organizations will evaluate, govern, and secure increasingly capable AI systems operating within corporate environments. OpenAI also announced the retirement of Atlas, its standalone AI browser product, as the company shifts users toward more integrated workplace AI tools. The move reflects a growing industry trend toward AI agents that can interact directly with web applications, enterprise data, and business processes. While the browser shutdown itself is largely a product decision, the broader shift toward agentic platforms carries security implications, including credential management, access controls, prompt-injection risks, and governance of autonomous AI actions. Meta introduced Muse Spark 1.1, an updated AI model designed to support coding, debugging, multimodal analysis, and agent-based workflows. The release expands the field of frontier models available to enterprises and developers and is expected to be evaluated alongside offerings from OpenAI, Anthropic, and Google for software development, operational automation, and AI-assisted analysis. Anthropic announced that subscribers will begin paying usage-based fees to access Claude Fable 5, making it one of the first frontier AI models to move from flat-rate subscriptions to API-style billing for consumers. The change reflects growing pressure on AI vendors to balance demand for increasingly compute-intensive models against finite infrastructure capacity and highlights the escalating costs associated with deploying the industry's most advanced AI systems. ([OpenAI](https://openai.com/index/gpt-5-6/?ref=metacurity.com), [Ina Fried, Madison Mills / Axios](https://www.axios.com/2026/07/09/ai-openai-gpt-release?ref=metacurity.com), [Harshita Mary Varghese and Katie Paul / Reuters](https://www.reuters.com/business/meta-debuts-muse-spark-11-with-preview-open-developers-2026-07-09/?ref=metacurity.com) and [Maxwell Zeff / Wired](https://www.wired.com/story/model-behavior-anthropic-will-charge-consumers-extra-to-use-claude-fable-5/?utm%5Fsource=chatgpt.com)) **Related:** [*OpenAI*](https://openai.com/index/chatgpt-for-your-most-ambitious-work/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/anishasircar/2026/07/10/openais-gpt-56-lands-with-work-agents-and-a-desktop-pivot/?ref=metacurity.com)*,* [*Computerworld*](https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html?ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2026/07/09/technology/openai-sol-ai.html?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/ai/2026/07/openai-wants-its-new-tool-to-do-your-work-for-you-and-with-you/?ref=metacurity.com)*,* [*ZDNET*](https://www.zdnet.com/article/openais-gpt-5-6-chatgpt-work-beat-anthropic-on-price-speed-and-productivity/?ref=metacurity.com)*,* [*ChannelX*](https://channelx.world/2026/07/introducing-chatgpt-work-powered-by-gpt-5-6/?ref=metacurity.com)*,* [*The Rundown AI*](https://www.therundown.ai/p/openai-sends-gpt-5-6-to-work?ref=metacurity.com)*,* [*Simon Willison's Weblog*](https://simonwillison.net/2026/Jul/9/gpt-5-6/?ref=metacurity.com)*,* [*The Algorithmic Bridge*](https://www.thealgorithmicbridge.com/p/openai-gpt-56-ai-could-do-anything?ref=metacurity.com)*,* [*Forbes Australia*](https://www.forbes.com.au/news/innovation/openai-debuts-chatgpt-work-workplace-ai-agent-with-gpt-5-6/?ref=metacurity.com)*,* [*The Neuron*](https://www.theneuron.ai/explainer-articles/gpt-5-6-and-the-new-chatgpt-desktop-app-complete-guide/?ref=metacurity.com)*,* [*Gizchina*](https://www.gizchina.com/openai/openais-new-gpt-56-sol-wants-to-fix-ais-biggest-cost-problem?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/openai-gpt-5-6-and-chatgpt-work/?ref=metacurity.com)*,* [*Rohan's Bytes*](https://www.rohan-paul.com/p/openai-launches-gpt-56-sol-across?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/gpt-5-6-openai-s-flagship-model-helps-build-itself?ref=metacurity.com)*,* [*Latent.Space*](https://www.latent.space/p/ainews-openai-launches-gpt-56-solterraluna?ref=metacurity.com)*,* [*The Mac Observer*](https://www.macobserver.com/news/openai-launches-gpt-5-6-chatgpt-work-and-new-desktop-app-with-built-in-codex/?ref=metacurity.com)*,* [*Platformer*](https://www.platformer.news/openai-gpt-5-6-simo-meta-muse-spark-1-1/?ref=metacurity.com)*,* [*The Deep View*](https://www.thedeepview.com/articles/gpt-5-6-opens-chatgpt-s-agentic-era-with-a-bang?ref=metacurity.com)*,* [*CNET*](https://www.cnet.com/tech/services-and-software/openais-powerful-new-chatgpt-5-6-is-ready-for-you/?ref=metacurity.com)*,* [*TestingCatalog AI News*](https://www.testingcatalog.com/openai-launches-gpt-5-6-sol-terra-and-luna-on-apps-and-api/?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/cool-tech/chatgpt-can-now-finish-what-you-started-and-thats-a-much-bigger-deal-than-it-sounds/?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/openai-launches-gpt-5-6-sol-with-four-agent-reasoning/?ref=metacurity.com)*,* [*MarkTechPost*](https://www.marktechpost.com/2026/07/09/openai-releases-gpt-5-6-a-three-tier-model-family-with-programmatic-tool-calling/?ref=metacurity.com)*,* [*PCWorld*](https://www.pcworld.com/article/3188176/?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/07/09/open-ai-sam-altman-chatgpt-5-6-sol.html?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/963464/openai-gpt-5-6-codex-chatgpt-work?ref=metacurity.com)*,* [*OpenAI*](https://openai.com/chatgpt-work/?ref=metacurity.com)*,* [*Reuters*](https://economictimes.indiatimes.com/tech/artificial-intelligence/openai-unveils-long-awaited-super-app-as-rivalry-with-anthropic-intensifies/articleshow/132310601.cms?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/openai-unveils-chatgpt-work-an-ai-tool-capable-of-handling-workloads-across-finance-data-analytics-engineering-and-more?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/computing/chatgpt-is-coming-for-one-of-googles-smartest-chrome-features/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2026/07/09/openai-debuts-chatgpt-work-agentic-tool-automating-business-workflows/?ref=metacurity.com)*,* [*International Business Times*](https://www.ibtimes.com/openai-has-released-its-latest-series-ai-models-ceo-sam-altman-says-that-they-increase-efficiency-3805128?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/07/09/openai-launches-its-new-family-of-models-with-gpt-5-6/?ref=metacurity.com)*,* [*TestingCatalog AI News*](https://www.testingcatalog.com/openai-launches-chatgpt-work-for-pro-enterprise-and-edu-plans/?ref=metacurity.com)*,* [*Meta*](https://ai.meta.com/blog/introducing-muse-spark-meta-model-api/?ref=metacurity.com)*,* [*CNET*](https://www.cnet.com/tech/services-and-software/meta-muse-spark-new-ai-model-agentic/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/business/meta-debuts-muse-spark-11-with-preview-open-developers-2026-07-09/?ref=metacurity.com)*,* [*Spyglass*](https://spyglass.org/meta-ai-cloud-business-model/?ref=metacurity.com)*,* [*TestingCatalog AI News*](https://www.testingcatalog.com/meta-debuts-muse-spark-1-1-model-and-opens-api-for-developers/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/963193/meta-muse-spark-model-api?ref=metacurity.com)*,* [*Business Standard*](https://www.business-standard.com/technology/tech-news/how-screenshots-become-ai-window-into-computers-explained-126071000767%5F1.html?ref=metacurity.com) ### Federal investigators said records that could have shown what Department of Government Efficiency personnel accessed at the National Labor Relations Board were deleted before the Government Accountability Office could examine them. The revelation appears in a footnote to an April 2026 GAO report reviewing DOGE activity at the agency. The NLRB deleted DOGE user accounts and associated access information in August 2025, shortly after the detailees left the agency. Because those records were gone, GAO investigators said they could not independently verify what systems DOGE personnel accessed or whether staff accounts of their activity were accurate. The report covered only the period after an April 2025 whistleblower complaint alleging that DOGE officials received broad access to sensitive NLRB systems and may have exfiltrated data. Records-retention experts said the deletions may have violated federal requirements governing systems containing personnel and other sensitive information, particularly because an inspector general investigation was already underway. The missing records leave unresolved whether DOGE accessed or copied sensitive labor, whistleblower, personnel, or investigative data before the period examined by the GAO. ([Vittoria Elliott / Wired](https://www.wired.com/story/federal-investigators-say-certain-doge-records-were-deleted/?ref=metacurity.com)) **Related:** [*r/technology*](https://www.reddit.com/r/technology/comments/1urwq1b/federal%5Finvestigators%5Fsay%5Fcertain%5Fdoge%5Frecords/?ref=metacurity.com) ### The European Parliament has voted to extend legislation allowing tech companies to voluntarily scan users’ private messages for child sexual abuse material, despite a majority of lawmakers voting against the proposal. The ruling reinstates permissions for firms including Meta, Google, and Microsoft to scan private text, email, and social media messages through a bill nicknamed “Chat Control” by critics. End-to-end encrypted chats, such as those on WhatsApp and Signal, remain exempt. “It will mean that private companies may deny your right to have confidential digital conversations,” Simeon de Brouwer, policy adviser at the Brussels-based advocacy group European Digital Rights, says. “They could, if they want to, read every message you write, every email you send, every picture you share.” The European People's Party, the largest political group in the European Parliament, has been battling to bring back tech firms’ legal basis to scan messages since a prior law expired in April. Members say firms’ voluntary detection activities have helped identify and rescue victims of online child sexual abuse, and disallowing them leaves children unprotected. They have been rushing to reinstate the legislation before parliament disperses for its summer break at the end of the month. “We cannot go to the summer recess knowing that our children are not protected,” party vice-chair Tomas Tobé told lawmakers earlier in the week. But the implications for privacy mean the legislation has faced fierce opposition from other parties and civil rights activists. The EPP resorted to a procedural maneuver to force fresh votes on this legislation this week after talks collapsed in March. This “urgent procedure” skips preliminary committee debates where amendments would often be introduced and stipulates that the regulation passes unless an absolute majority of 361 MEPs vote against it. ([Isabella Ward / Wired](https://www.wired.com/story/a-majority-of-european-lawmakers-voted-against-letting-big-tech-read-our-messages-theyre-going-to-anyway/?ref=metacurity.com)) **Related:** [*Athens News*](https://en.rua.gr/2026/07/09/total-surveillance-is-the-slogan-of-protecting-children-the-european-parliament-passed-chat-control-1-0/?mid=1&ref=metacurity.com#cid=3609893)*,* [*The Register - Security*](https://www.theregister.com/security/2026/07/09/meps-fail-to-prevent-chat-control-snoopfest-revival/5269379?mid=1&ref=metacurity.com#cid=3609979)*,* [*CyberInsider*](https://cyberinsider.com/eu-parliament-voted-to-restore-private-communications-scanning/?mid=1&ref=metacurity.com#cid=3610301)*,* [*Patrick Breyer*](https://www.patrick-breyer.de/en/eu-parliament-greenlights-chat-control-1-0-breyer-our-children-lose-out/?ref=metacurity.com) ### Britain’s cyber agency laid out plans for what it called “a national scale, sovereign defense capability” that would use agentic AI systems to discover and fix cybersecurity weaknesses across government networks and critical national infrastructure. The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.” Adversaries aided by AI, the agency said in a blog post, can already compress reconnaissance and vulnerability discovery from weeks into minutes. “This has the potential to overwhelm traditional defenses and increase the risk of advantage shifting towards the attacker,” the NCSC said. “Developing viable solutions that scale and execute at the pace we need in the modern era is the remit of the Cyber Shield.” The agency has separately warned of an AI-driven “patch wave” — a surge of newly discovered vulnerabilities emerging faster than most organizations can fix them — and a recent alert from GCHQ said it was likely both offensive and defensive cyber capabilities would be fundamentally transformed within just months. At the heart of the plan is a model of paired “red” and “blue” AI agents — the former probing systems for weaknesses, the latter defending them in real time — operating across critical national infrastructure under the control of the organizations that own them. The NCSC said Cyber Shield will require six core functions, ranging from automated scanning of British networks — which already exists in some form — to fully autonomous fixing of vulnerabilities, which does not. Some of these functions, the agency acknowledged, “present challenges which will need significant progress in research to unlock.” ([Alexander Martin / The Record](https://therecord.media/britain-plans-autonomous-ai-cyber-shield?ref=metacurity.com)) **Related:** [*NCSC*](https://www.ncsc.gov.uk/blogs/cyber-shield-the-path-to-an-agentic-ai-future-for-cyber-defence?ref=metacurity.com)*,* [*Digital Shield*](https://www.escudodigital.com/en/cybersecurity/the-uk-unveils-an-ai-powered-cyber-shield-to-protect-the-nations-critical-infrastructure-and-networks.html?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/ncsc-national-cyber-sheild-ai/?ref=metacurity.com)*,* [*IT Pro*](https://www.itpro.com/security/the-ncsc-wants-to-build-an-ai-powered-cyber-shield-to-protect-the-uk-from-hackers-heres-how-itll-work?ref=metacurity.com)*,* [*Circle ID*](https://circleid.com/posts/uk-unveils-ai-cyber-shield-to-counter-machine-speed-digital-threats?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4194997/uk-cyber-agency-unveils-ai-powered-cyber-shield-to-counter-attacks-at-machine-speed.html?ref=metacurity.com)*,* [*Computer Weekly*](https://www.computerweekly.com/news/366645655/Cyber-field-doubts-promise-of-Cyber-Shield?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/uk-government-rolls-out-agentic-ai-defense-plan-alongside-industry-pledge/?ref=metacurity.com)*,* [*FutureScot*](https://futurescot.com/uk-government-to-harness-agentic-ai-for-new-national-cyber-shield/?ref=metacurity.com)*,* [*Digit*](https://www.digit.fyi/uk-gov-unveils-cyber-shield-national-scale-defence-driven-by-agentic-ai/?ref=metacurity.com)*,* [*UK Authority*](https://www.ukauthority.com/articles/gchq-calls-on-you-to-join-the-cyber-shield-development?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/eu-parliament-passes-chat-control-allowing-private-chat-scans-to-2028?utm%5Fsource=rss%5Ffeed&utm%5Fmedium=rss&utm%5Fcampaign=rss%5Fpartner%5Finbound) ### Researchers at SentinelOne report that multiple Pakistani law ​enforcement agencies were targeted in separate hacking campaigns linked to groups associated with China and India. SentinelOne said it found ​evidence of multiple hacking campaigns and intrusions carried out by Chinese- and Indian-linked hacking groups between February 2024 and April 2026, most notably against the Balochistan police, which serves Pakistan's southwestern province of the same name. The report said Chinese interest in the agencies could be linked to the safety of Chinese nationals working in Pakistan, who have been targeted in deadly attacks in recent years. Interest from groups linked to India could be related to tensions between the two countries and Pakistan's broader security posture, it said. According to SentinelOne, the operations targeting the Balochistan ​police involved network equipment, web ​servers and several online applications, ⁠including the force's Complaint Management System. Other targets included the Khyber Pakhtunkhwa police, the Islamabad police and the Punjab Safe Cities Authority (PSCA), ​an autonomous government agency that operates systems used by the police in major cities in ​Punjab province. ([AJ Vicens / Reuters](https://www.reuters.com/world/china/china-india-linked-hacking-groups-targeted-pakistani-law-enforcement-report-says-2026-07-09/?ref=metacurity.com)) **Related:** [*Sentinel One*](https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/?ref=metacurity.com)*,* [*Hindustan Times*](https://www.hindustantimes.com/india-news/china-and-india-linked-hackers-targeted-the-same-pakistan-police-force-analysis-101783657845604.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-29.png) Timeline of C2 traffic to Pakistani law enforcement organizations. Source: SentinelOne. ### According to researchers at Darktrace, an Amazon EC2 instance running LiteLLM and connected to Amazon Bedrock was compromised and used for cryptomining, specifically Monero. Darktrace found attackers compromising an AWS EC2 instance acting as a LiteLLM proxy for Amazon Bedrock, eventually deploying XMRig cryptomining malware, along with attempts to abuse cloud identities and AI services. Although the attack ended in cryptomining, researchers said the bigger concern is that AI gateways centralize model access, identities, and cloud privileges, making them valuable targets. Darktrace said the EC2 instance, named “LiteLLM-Proxy,” appeared to operate as an AI gateway and had an instance profile with access to Amazon Bedrock resources. That role made the host more valuable than a typical compute server because AI gateways can handle authentication, model routing, prompts, logs, policy controls, and cloud permissions. ([Shweta Sharma / CSO Online](https://www.csoonline.com/article/4194984/attack-on-amazon-bedrock-linked-ai-gateway-highlights-new-cloud-security-risk.html?mid=1&ref=metacurity.com#cid=3609246)) **Related:** [*Darktrace*](https://www.darktrace.com/blog/when-ai-infrastructure-becomes-part-of-the-attack-surface?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2026/07/09/darktrace-finds-ai-gateway-amazon-bedrock-access-hijacked-cryptomining/?mid=1&ref=metacurity.com#cid=3609286)*,* [*CSO Online*](https://www.csoonline.com/article/4194984/attack-on-amazon-bedrock-linked-ai-gateway-highlights-new-cloud-security-risk.html?mid=1&ref=metacurity.com#cid=3609246)*,* [*HackRead*](https://hackread.com/ai-gateway-amazon-bedrock-hijacked-cryptomining/?ref=metacurity.com) ### The US Justice Department announced that Angelo John Martino III, former ransomware negotiator for DigitalMint, was sentenced to 70 months in jail for deceiving his employer’s clients and conspiring with ransomware affiliates to extort a combined $75.3 million from five US companies he was entrusted to aid during their moments of extreme crisis. shared confidential information he gained from his work as a ransomware negotiator, including victim organizations’ negotiating positions and insurance policy limits, to extract the maximum payment for himself and other BlackCat affiliates he colluded with in backchannels. Five of Martino’s victims hired DigitalMint, which assigned the 41-year-old to conduct ransomware negotiations on their clients’ behalf — a rare position he exploited to play both sides, effectively conducting ransomware negotiations with himself and his co-conspirators. The five victims, all of which paid a ransom between April 2023 and September 2023, include a nonprofit that paid a nearly $26.8 million ransom, a financial services company that paid nearly $25.7 million, and a hospitality company that paid almost $16.5 million. ([Matt Kapko / CyberScoop](https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced/?ref=metacurity.com)) **Related:** [*Justice Department*](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/us-ransomware-negotiator-gets-4-years-in-prison-for-blackcat-attacks/?ref=metacurity.com) ### Armenian Karen Serobovich Vardanyan pleaded guilty to targeting five U.S. companies and one private school with Ryuk ransomware attacks, including a business in Oregon that had its data and credentials stolen in 2019, according to court records. “As part of the scheme, ransom payments were extorted from victim companies in exchange for decryption keys to regain access to their data,” the US Attorney's Office said. “A ransom note was placed on the computer systems demanding ransom payments in Bitcoin, a form of cryptocurrency, and provided an email address that victims could use to communicate with the cybercriminals.” Officials revealed that a Michigan company paid Vardanyan and his co-conspirators 200 bitcoin, or more than $1.1 million, to recover its network. The group also attacked a Wilsonville company in February 2020 before attacking a Texas school, according to the agency. Authorities estimate the co-conspirators deployed the ransomware on hundreds of servers and workstations, and received around 1,610 bitcoins — or about $15 million. ([Jashayla Pettigrew / KOIN](https://www.koin.com/news/crime/oregon-business-impacted-by-ransomware-attacks-that-garnered-15-million-in-bitcoin/amp/?ref=metacurity.com)) **Related:** [*Justice Department*](https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy?ref=metacurity.com)*,* [*Oregon Live*](https://www.oregonlive.com/crime/2026/07/armenian-citizen-pleads-guilty-to-ransomware-attacks-in-oregon-and-elsewhere.html?ref=metacurity.com) ### The US Department of Justice is accusing Rossen G. Iossifov, a convicted fraudster and federal inmate, of orchestrating the unauthorized removal of about $290,000 in cryptocurrency that had already been seized and forfeited to the US government, marking a new criminal case tied to assets from his earlier conviction. Iossifov appeared in federal court in the Eastern District of Kentucky earlier this week on charges of removal of property to prevent seizure, aiding and abetting, and conspiracy to commit money laundering, the DOJ said. Iossifov allegedly conspired to transfer the crypto in January 2024, nearly three years after his 2021 conviction in the Eastern District of Kentucky. The DOJ said he transferred the assets through multiple cryptocurrency exchanges and illicit mixing services while serving an 111-month federal prison sentence, allegedly to prevent the U.S. government from taking possession of the funds. Prosecutors said Iossifov’s 2021 conviction followed his participation in an online auction fraud scheme that laundered nearly $5 million in cryptocurrency over a period of less than three years. That case resulted in a court order to pay $2,642,297.43 in victim restitution alongside the asset forfeiture. ([Brian Danga / The Block](https://www.theblock.co/amp/post/407854/doj-charges-federal-inmate-over-alleged-theft-of-290000-in-crypto-forfeited-to-us-government?ref=metacurity.com)) **Related:** [*Justice Department*](https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-07-09/crypto-criminal-accused-of-crypto-crimes-again-while-in-jail?embedded-checkout=true&ref=metacurity.com)*,* [*Crypto Briefing*](https://cryptobriefing.com/iossifov-charged-moving-forfeited-crypto/?ref=metacurity.com)*,* [*BeInCrypto*](https://beincrypto.com/iossifov-290k-crypto-laundering-charges/?ref=metacurity.com) ### Researchers at Microsoft report that for over eight months, a threat actor dubbed GigaWiper has been using a destructive backdoor and wiper that has multiple system-level sabotage capabilities. The malware is a sophisticated Go-based backdoor that consists of multiple malware families and robust command-and-control (C&C) capabilities. According to Microsoft, the malware in GigaWiper was folded into the form of on-demand backdoor commands, allowing the attacker to execute a standalone wiper, a ransomware-like encryption command, and a wiping command that performs multiple erase passes. “The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, which is typically designed purely to destroy rather than to extort and carry real-world consequences,” Microsoft notes. First observed in October 2025, GigaWiper contains a wiper that operates at the physical disk level. It enumerates drives using Windows Management Instrumentation (WMI) to identify the Windows partition, removes partition references from non-Windows drives, wipes each drive, and then reboots the system. GigaWiper appears to have been built by the Crucio ransomware developer, based on the encryption code, but also shows connections to FlockWiper, which emerged in June 2025, sharing an identical wiping function that has been ported to Go. ([Ionut Arghire / Security Week](https://www.securityweek.com/gigawiper-combines-multiple-malware-for-system-level-sabotage/?ref=metacurity.com)) ***Related:*** [*Microsoft*](https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4195470/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand.html?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/microsoft-details-gigawiper-destructive-backdoor-assembled-from-older-tools?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/195068/malware/gigawiper-merges-three-malware-families-into-one-destructive-backdoor.html?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/microsoft-gigawiper-backdoor-destroy-windows-pcs/?ref=metacurity.com)*,* [*CyberSecurityNews*](https://cybersecuritynews.com/gigawiper-malware-attacking-windows-systems/?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/microsoft-flags-gigawiper-backdoor/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-30.png) Image dropped by backdoor and set as the wallpaper. Source: Microsoft. ### Researchers at Wiz report that a “systematic vulnerability pattern” in at least six of the most widely used AI coding assistants can be abused to trick agents into accessing files outside the workspace sandbox, leading to remote code execution on the developer's machine. Wiz found the security gap, which it named "GhostApproval," and reported it to all six: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. Amazon, Cursor, and Google deemed the flaw critical or high-severity, fixed it, and either already issued (AWS and Cursor) a CVE tracker or are in the process of getting that done (Google). Augment and Windsurf acknowledged the Wiz-submitted vulnerability report, but haven’t patched the issue or warned users. Anthropic eventually added a warning as part of "proactive security hardening based on internal review." While there’s no indication that attackers in the wild are actively exploiting this vulnerability, it’s still a serious threat to enterprises rushing to deploy code-writing agents in their environments. ([Jessica Lyons / The Register](https://www.theregister.com/security/2026/07/08/bug-in-top-ai-coding-agents-shows-that-unix-era-security-headaches-never-really-die/5268025?ref=metacurity.com)) ***Related:*** [*Wiz*](https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants?ref=metacurity.com)*,* [*DevOps*](https://devops.com/ghostapproval-flaw-featuring-decades-old-feature-found-in-six-ai-coding-tools/?ref=metacurity.com)*,*[ *Security Week*](https://www.securityweek.com/ai-coding-tools-tricked-into-hacking-developer-machine-via-decades-old-technique/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4195235/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop.html?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/news/ghostapproval-technique-leads-ai-coding-tools-to-alter-files-outside-of-sandbox?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/ghostapproval-flaws-ai-coding-tools-outside-workspace/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-31.png) The #GhostApproval in action - the user approves a local config edit; the agent writes to system files. Source: Wiz ### Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. Application security companies, including Ox Security and StepSecurity, detected the supply-chain attack via version 1.20.21 of the @injectivelabs/sdk-ts npm package. Injective SDK is a TypeScript/JavaScript software development kit (SDK) for building applications on the Injective blockchain, a Layer-1 blockchain focused on decentralized finance (DeFi), tokenized assets, and decentralized exchanges. The package has 50,000 weekly downloads on npm and is used by developers building cryptocurrency wallets, trading bots, decentralized exchanges, DeFi applications, and payment tools. According to the researchers, the attacker compromised a GitHub account belonging to a legitimate project contributor and made the first suspicious commits on June 8, publishing the malicious version of the package shortly afterward. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/?ref=metacurity.com)) **Related*:* [*Ox Security*](https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/?ref=metacurity.com)*,* [*Step Security*](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys?ref=metacurity.com)*,* [*Yellow*](https://yellow.com/news/injective-sdk-seed-phrase-theft?ref=metacurity.com)*,* [*Crypto Briefing*](https://cryptobriefing.com/injective-npm-backdoor-wallet-key-attack/?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/hackers-compromise-injective-npm-package-with-malware-to-steal-wallet-keys?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-32.png) Source: Step Security. ### Microsoft warned that Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. Microsoft said advances in AI have significantly accelerated vulnerability discovery, allowing engineers to identify more security issues before they can be exploited in zero-day attacks. "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis," Microsoft said. As part of this approach, the company is using Microsoft Security's multi-model agentic scanning harness (MDASH), an AI-powered vulnerability discovery system previously detailed by Microsoft, which scans critical binaries and validates potential vulnerabilities using multiple AI models. Microsoft says the system scans critical Windows binaries for vulnerabilities and then validates the findings using multiple AI models. Vulnerability candidates are then passed through a second Windows-specific validation pipeline designed to eliminate false positives before engineers investigate the issues. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/microsoft/microsoft-expects-more-windows-security-updates-from-ai-discovered-flaws/?ref=metacurity.com)) **Related:** [*Microsoft*](https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/tech/963307/microsoft-patch-tuesday-ai-security-updates?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/microsoft-explains-the-different-types-of-windows-updates-you-get/?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/142804/microsoft-ai-will-lead-to-a-lot-more-fixes-on-patch-tuesdays/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-ai-will-mean-busier-patch-tuesdays/5269618?ref=metacurity.com) Researchers at ThreatLocker report that a malicious Windows installer masquerading as LetsVPN deploys a remote access trojan (RAT) alongside the legitimate VPN software. The malware, dubbed GoodPersonRAT, grants attackers full control over infected systems and employs multiple stealth techniques to evade detection. The researchers found that the malicious MSI installs the authentic, signed LetsVPNLatest.exe application after first deploying the malware, making the installation appear legitimate to unsuspecting users. LetsVPN is a widely used VPN service that helps users bypass China's Great Firewall, making it an attractive lure for threat actors targeting people seeking unrestricted internet access. This is not the first time the VPN has been abused for malware distribution. Last year, Rapid7 reported a separate campaign in which trojanized LetsVPN installers delivered the Winos v4.0 malware through a different multi-stage, memory-resident infection chain. The malicious package, `Kuailian_win-setup.86.msi`, contains three embedded files: the legitimate LetsVPN installer, a loader named `promecefplugilte8.exe`, and an encrypted payload stored as `20260609.dat`. The loader decrypts and reflectively loads the final payload directly into memory, leaving little evidence on disk and making the malware more difficult to detect. ([Amar Ćemanović / CyberInsider](https://cyberinsider.com/trojanized-letsvpn-installer-gives-attackers-remote-access-to-windows-pcs/?ref=metacurity.com)) **Related:** [*ThreatLocker*](https://www.threatlocker.com/blog/goodpersonrat-fake-chinese-vpn-drops-extensive-c2-client?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/new-goodpersonrat-malware-distributed-via-fake-letsvpn-installer?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-33.png) Attack chain. Source: ThreatLocker. ### A cyberattack on Greenbaum Rowe Smith & Davis LLP, a New Jersey-based law firm that represents some of the state’s top healthcare systems, may have exposed the data of nearly 13,000 patients. Greenbaum Rowe Smith & Davis LLP discovered unauthorized access to its systems via a compromised user account in November 2025\. Afterward, it “immediately” took steps to secure its systems, according to a notice from the firm. In addition to resetting passwords and replacing compromised machines, Greenbaum notified law enforcement. It also launched a comprehensive investigation with assistance from cybersecurity experts to determine the cause and scope of the incident. Completed in April, the probe determined that an unauthorized third party acquired certain information in Greenbaum’s systems between Nov. 25–27, 2025, the notice said. Besides names and addresses, the potentially affected data may have included medical record numbers, medical history, provider details, medical bill costs and health insurance. ([Kimberly Redmond / NJBiz](https://njbiz.com/nj-law-firm-cyberattack-greenbaum-patient-data-breach/?ref=metacurity.com)) **Related:** [*NJBiz*](https://njbiz.com/nj-law-firm-cyberattack-greenbaum-patient-data-breach/?ref=metacurity.com)*,* [*IDX*](https://response.idx.us/grsd/?ref=metacurity.com)*,* [*New Jersey 101.5*](https://nj1015.com/nj-healthcare-data-breach/?ref=metacurity.com)*,* [*NJ.com*](https://www.nj.com/healthfit/2026/07/law-firm-for-major-nj-health-systems-gets-hacked-exposing-personal-info-of-nearly-13k-patients.html?ref=metacurity.com) ### Cybersecurity startup QIZ Security Ltd. today announced it has raised $17 million in seed funding. Bessemer Venture Partners and Merlin Ventures co-led the round. Evolution Equity Partners, Qbeat Ventures, Singtel Innov8 Pte. Ltd. and Qino Cyber Capital Ltd. also participated. ([Duncan Riley / Silicon Angle](https://siliconangle.com/2026/07/09/qiz-security-raises-17m-seed-round-post-quantum-readiness-platform/?mid=1&ref=metacurity.com#cid=3610390)) ***Related:*** [*SC Magazine*](https://www.scworld.com/brief/qiz-security-raises-17-million-for-cryptographic-management-platform?mid=1&ref=metacurity.com#cid=3611165)*,* [*VC News Daily*](https://vcnewsdaily.com/qiz-security/venture-capital-funding/hdgbpdsncg?mid=1&ref=metacurity.com#cid=3610726)*,* [*RuntimeWire*](https://runtimewire.com/article/qiz-security-s-17m-seed-puts-enterprise-crypto-inventory-ahead-of-q-day?mid=1&ref=metacurity.com#cid=3610652) --- **AI is not a cybersecurity strategy.** Organizations with strong security programs will use AI to move faster. Organizations with weak security programs will use AI to create bigger, faster failures. That's why I wrote *The NIST 2.0 Cybersecurity Framework: Practical Risk Management Using Real-World Incidents*. The book moves beyond compliance checklists and theory to show how real organizations succeed—or fail—when security fundamentals break down. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/newcoverpngtiny-1.png) If you're trying to build a resilient security program in the age of AI, this book provides a practical roadmap grounded in actual incidents and operational experience. [Order the Book Today!](https://cyberriskbook.com/buy-your-copy/?ref=metacurity.com) --- ### Best Thing of the Day: If Raising the Bugaboo of Huawei Won't Work, Nothing Will Rep. Ro Khanna (D-CA) [urged](https://subscriber.politicopro.com/article/2026/07/rep-khanna-sounds-alarm-on-potential-foreign-software-in-white-house-app-00992192?ref=metacurity.com) the White House to suspend use of an app recently installed on federal devices over its possible connection to Chinese software made by already-banned Chinese telecom tech provider Huawei. ### Worst Thing of the Day: Sue Musk to Smithereens In March, a girl’s stepfather[ took his own life](https://arstechnica.com/tech-policy/2026/07/lawsuit-grok-user-made-7k-child-sex-images-xai-only-reported-one-gang-rape-prompt/?ref=metacurity.com) after cops discovered that he had used Grok to create 7,000 sexually explicit images using one photo taken when his stepdaughter was 11 years old. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image-28.png) ### AI watch: AI companies are building digital workers, and attackers may benefit too URL: https://www.metacurity.com/ai-watch-ai-companies-are-building-digital-workers-and-attackers-may-benefit-too/ Last updated: 2026-07-09T15:07:24.000Z Interpol fraud crackdown nets 5,800 arrests and $293m, Fake Brazilian police station discovered in African scam operation, Mystery zero-day broker tied to convicted fraudsters, AssuranceAmerica breach exposes 6.9m driver’s license numbers, much more _This post is for paying subscribers only._ ### AI watch: Washington, Beijing, and Brussels shape AI's future URL: https://www.metacurity.com/ai-watch-washington-beijing-and-brussels-shape-ais-future/ Last updated: 2026-07-08T13:09:32.000Z Spain arrests man suspected of CyberArmy of Russia membership, Predator spyware victims seek €1m each in Greek lawsuit, CISA incident reporting rule expected in Sept., Ransomware exposed student and employee data at Mount Royal University, Accenture confirms breach, much more _This post is for paying subscribers only._ ### AI watch: Chinese competition, government adoption, and new regulations pressure AI leaders URL: https://www.metacurity.com/ai-watch-chinese-competition-government-adoption-and-new-regulations-pressure-ai-leaders/ Last updated: 2026-07-07T13:30:08.000Z Canada details offensive cyber ops, US cloud providers challenge Korean security rules, KDDI confirms breach affecting millions, Judge keeps Weiss hacking case alive, BonkDAO loses $20m in governance attack, Crypto wallet flaw exposed millions to theft, Ctrl Wallet shutters after incident, much more _This post is for paying subscribers only._ ### EU lawmaker investigating Pegasus abuse was hacked with Pegasus spyware URL: https://www.metacurity.com/eu-lawmaker-investigating-pegasus-abuse-was-hacked-with-pegasus-spyware/ Last updated: 2026-07-06T12:53:49.000Z FBI disrupts NetNut-linked proxy infrastructure, Russian hackers expose UK gov't credentials, India probes iPhone 18 Pro supply-chain leak, UK minister compares AI risks to Hiroshima, Sanctioned states increasingly rely on crypto, First fully AI-run ransomware attack spotted, much more _This post is for paying subscribers only._ ### AI guardrails under fire from researchers and regulators URL: https://www.metacurity.com/ai-guardrails-under-fire-from-researchers-and-regulators/ Last updated: 2026-07-02T15:13:09.000Z Scattered Spider suspect extradited to US, House panel accuses Korea of targeting Coupang, cyberattack hits Malaysian parking app, Aflac Japan breach affects 4.4M customers, AI agent carries out extortion attack, Ukraine stops 16K Russian cyberattacks, ChocoPoC RAT hides in GitHub PoCs, much more. _This post is for paying subscribers only._ ### Anthropic restores Fable 5 and Mythos 5, launches Sonnet 5 URL: https://www.metacurity.com/anthropic-restores-fable-5-and-mythos-5-launches-sonnet-5/ Last updated: 2026-07-01T13:11:37.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/fable5cybersafety-1.png) Anthropic says Fable 5 uses a larger cybersecurity "safety margin" that blocks more borderline requests to reduce the risk of harmful instructions reaching the model. Source: Anthropic. *Metacurity is the cybersecurity industry's daily reality check—independent, agenda-free coverage that cuts through vendor hype, social media noise, and recycled talking points to explain what matters and why.* *Trusted by thousands of cybersecurity professionals, including many of the industry's most influential security leaders, Metacurity delivers the context, analysis, and perspective that busy readers don't have time to assemble themselves.* *If you find value in that work, please consider becoming a paid subscriber. Metacurity remains independent because its readers choose to support it.* [Upgrade my subscription](#/portal/account/plans) Anthropic packed several significant announcements into a single day, underscoring both the rapid pace of frontier model development and the increasingly close relationship between AI companies and governments. The biggest development was the restoration of access to Fable 5 and Mythos 5 after the Trump administration lifted export controls that had sidelined the models since June 12\. According to Politico, the reversal followed negotiations between Anthropic and the White House over security concerns that prompted the original restrictions. Anthropic said it would begin redeploying both models immediately after receiving notice from the Commerce Department that the controls had been lifted. In a separate announcement, Anthropic detailed the safeguards it implemented as part of the redeployment. The company said it had improved its ability to detect and block jailbreak attempts, expanded monitoring efforts, and agreed to work more closely with the government on model evaluations, information sharing, and security standards. Anthropic acknowledged that preventing jailbreaks entirely is unlikely but said the new controls significantly reduce the risk of misuse. Anthropic emphasized that one particularly important safety mechanism involves classifiers—smaller automated AI systems that, during an interaction, detect when the model is asked to perform a potentially harmful cybersecurity task (or produces potentially harmful outputs). When this occurs, the classifiers block the model from responding to requests. The ultimate goal of these classifiers is to prevent the model from engaging in uniquely dangerous behaviors. To reduce mistakes, Anthropic deliberately set the safety classifiers to trigger on a set of requests that we know are likely benign. This “safety margin” approach means that a request has to look very clearly safe to avoid triggering the classifiers. Users experience the safety margin as a model refusing to respond to some reasonable, non-harmful requests. Anthropic also launched Claude Sonnet 5, which it describes as its most agentic Sonnet model yet. The company is positioning the model as a workhorse for coding, research, and professional tasks, while Axios reported that Anthropic sees it as part of a broader push toward AI agents capable of carrying out increasingly complex assignments on behalf of users. For cybersecurity teams, the announcements are notable because they affect both access to advanced AI capabilities and the tools available for day-to-day work. Mythos 5 has been described as one of Anthropic's strongest cybersecurity-focused models, while Sonnet 5 is aimed at the broader category of agentic workflows that many security teams are beginning to incorporate into research, coding, and operational tasks. ([Sophia Cai, Cheyenne Haslett, Brendan Bordelon and John Hewitt Jones / Politico](https://www.politico.com/news/2026/06/30/anthropic-wh-lifting-export-limits-00980865?nid=0000014f-1646-d88f-a1cf-5f46b7bd0000&nname=playbook&nrid=6e12155f-96c6-42cb-9a91-0a006077619c&ref=metacurity.com), [Anthropic](https://www.anthropic.com/news/redeploying-fable-5?ref=metacurity.com), [Anthropic](https://www.anthropic.com/news/claude-sonnet-5?ref=metacurity.com), [Madison Mills / Axios](https://www.axios.com/2026/06/30/anthropic-sonnet-5-agents-mythos-fable?stream=technology&utm%5Fsource=alert&utm%5Fmedium=email&utm%5Fcampaign=alerts%5Ftechnology)) ***Related:*** [*Axios*](https://www.axios.com/2026/06/30/trump-anthropic-ai-model-fable-restrictions?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/tech/ai/anthropic-nears-deal-with-trump-administration-to-restore-access-to-fable-ai-model-6f4177f3?ref=metacurity.com)*,* [*Wired*](https://www.wired.com/story/trump-administration-lifts-export-controls-on-anthropics-mythos-and-fable-ai-models/?ref=metacurity.com)*,* [*TestingCatalog AI News*](https://www.testingcatalog.com/anthropic-may-impose-kyc-restrictions-for-fable-5-access/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/business/us-lift-export-controls-anthropics-fable-ai-model-tuesday-source-says-2026-06-30/?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/u-s-plans-ease-export-curbs-anthropics-fable-model?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/06/30/white-house-ai-china-crackdown.html?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/commerce-expected-lift-anthropic-fable-5-export-controls?ref=metacurity.com)*,* [*The Economic Times*](https://economictimes.indiatimes.com/tech/artificial-intelligence/anthropics-export-restrictions-are-fueling-asias-ai-boom/articleshow/132088438.cms?ref=metacurity.com)*,* [*Sources*](https://sources.news/p/the-ai-frontier-is-closing?ref=metacurity.com)*,* [*The Next Web*](https://thenextweb.com/news/anthropic-fable-5-export-controls-lifted?ref=metacurity.com)*,* [*The Decoder*](https://the-decoder.com/anthropics-fable-5-is-back-worldwide-after-a-two-week-government-ban-over-a-jailbreak/?ref=metacurity.com)*,* [*AI News*](https://www.artificialintelligence-news.com/news/anthropic-deploys-claude-sonnet-5-fable-and-mythos-restored/?ref=metacurity.com)*,* [*Mashable*](https://mashable.com/tech/anthropic-fable-restore-access?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/anthropic-brings-back-claude-fable-5-after-the-us-lifted-export-controls/?ref=metacurity.com)*,* [*Al Jazeera*](https://www.aljazeera.com/economy/2026/7/1/us-lifts-restrictions-on-powerful-ai-models-fable-mythos-anthropic-says?ref=metacurity.com)*,* [*The New Stack*](https://thenewstack.io/how-anthropic-is-bringing-fable-5-back/?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/u-s-clears-anthropic-to-bring-claude-fable-5-back-online/?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/anthropic-fable-5-redeployment-export-controls-amodei?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/siladityaray/2026/07/01/trump-administration-lifts-export-controls-on-anthropics-mythos-5-and-fable-5-ai-models/?ref=metacurity.com)*,* [*InfoRiskToday.com*](https://www.inforisktoday.com/us-lifts-export-curbs-on-anthropic-ai-models-a-32123?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=48741853&ref=metacurity.com)*,* [*r/ClaudeCode*](https://www.reddit.com/r/ClaudeCode/comments/1ukaq5n/fable%5F5%5Fback%5Fjuly%5F1%5Fconfirmed/?ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1uk5khd/howard%5Flutnick%5Fover%5Fthe%5Fpast%5Ftwo%5Fweeks%5Fwe%5Fhave/?ref=metacurity.com)*,* [*r/Anthropic*](https://www.reddit.com/r/Anthropic/comments/1ukbtbm/the%5Fworlds%5Fmost%5Fanticipated%5Fmodel%5Freturns%5Fafter/?ref=metacurity.com)*,* [*r/ClaudeAI*](https://www.reddit.com/r/ClaudeAI/comments/1ukafrm/fable%5Favailable%5Ffor%5Fplans%5Funtil%5Fjuly%5F7th%5Fafter/?ref=metacurity.com)*,* [*Lobsters*](https://lobste.rs/s/thjzbz/redeploying%5Fclaude%5Ffable%5F5?ref=metacurity.com)*,* [*Slashdot*](https://yro.slashdot.org/story/26/07/01/0545222/trump-drops-restrictions-on-anthropics-mythos-and-fable-models?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/business/us-lift-export-controls-anthropics-fable-ai-model-tuesday-source-says-2026-06-30/?ref=metacurity.com)*,* [*The Hacker News*](https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html?ref=metacurity.com)*,* [*CNN*](http://www.cnn.com/2026/06/30/tech/anthropic-export-control-ban-lifted-white-house?ref=metacurity.com)*,* [*WinCentral*](https://thewincentral.com/us-lifts-export-controls-anthropic-claude-fable-5-mythos-5/?ref=metacurity.com)*,* [*UPI*](https://www.upi.com/Top%5FNews/US/2026/06/30/government-lifts-anthropic-export-ban/6301782867510/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/07/01/anthropic-claude-sonnet-5/?ref=metacurity.com)*,* [*Axios*](https://www.axios.com/2026/06/30/anthropic-sonnet-5-agents-mythos-fable?ref=metacurity.com)*,* [*Claude*](https://platform.claude.com/docs/en/build-with-claude/adaptive-thinking?ref=metacurity.com)*,* [*VentureBeat*](https://venturebeat.com/technology/anthropic-launches-claude-sonnet-5-at-a-steep-discount-to-its-top-model-as-the-company-races-toward-a-blockbuster-ipo?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2026/07/01/anthropic-launches-cheaper-claude-sonnet-5-for-ai-agents-xcxwbn/?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/claude-sonnet-5-launch-3683170/?ref=metacurity.com)*,* [*The Neuron*](https://www.theneuron.ai/explainer-articles/around-the-horn-digest-everything-that-happened-in-ai-today-tuesday-june-30-2026/?ref=metacurity.com)*,* [*Digit*](https://www.digit.in/news/general/anthropic-claude-sonnet-5-is-here-key-capabilities-availability-and-other-details.html?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/06/30/anthropic-launches-claude-sonnet-5-as-a-cheaper-way-to-run-agents/?ref=metacurity.com)*,* [*Implicator.ai*](https://www.implicator.ai/sonnet-5-closes-most-of-the-gap-to-opus-4-8-on-agent-work/?ref=metacurity.com)*,* [*MacRumors*](https://www.macrumors.com/2026/06/30/anthropic-claude-sonnet-5/?ref=metacurity.com)*,* [*HealthcareInfoSecurity.com*](https://www.healthcareinfosecurity.com/sonnet-5-delivers-ai-gains-without-frontier-model-scrutiny-a-32121?ref=metacurity.com)*,* [*ZDNET*](https://www.zdnet.com/article/ai-model-release-tracker/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2026/06/30/anthropic-launches-claude-sonnet-5-coding-safety-upgrades/?ref=metacurity.com)*,* [*Latent.Space*](https://www.latent.space/p/ainews-sonnet-5-today-and-fable-5?ref=metacurity.com)*,* [*BleepingComputer*](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-sonnet-5-with-near-opus-48-performance-at-a-lower-price/?ref=metacurity.com)*,* [*Simon Willison's Weblog*](https://simonwillison.net/2026/Jun/30/claude-sonnet-5/?ref=metacurity.com)*,* [*The Deep View*](https://www.thedeepview.com/articles/sonnet-5-is-anthropic-s-answer-to-ai-sticker-shock?ref=metacurity.com)*,* [*TestingCatalog AI News*](https://www.testingcatalog.com/anthropic-launches-claude-sonnet-5-model-on-claude-and-apis/?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=48736605&ref=metacurity.com)*,* [*r/claude*](https://www.reddit.com/r/claude/comments/1ujwk90/introducing%5Fclaude%5Fsonnet%5F5/?ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1ujwh9i/introducing%5Fclaude%5Fsonnet%5F5/?ref=metacurity.com)*,* [*r/ClaudeAI*](https://www.reddit.com/r/ClaudeAI/comments/1ujwgqz/introducing%5Fclaude%5Fsonnet%5F5/?ref=metacurity.com)*,* [*MacRumors Forums*](https://forums.macrumors.com/threads/anthropic-launches-claude-sonnet-5-with-near-opus-performance-at-a-lower-price.2484799/?ref=metacurity.com)*,* [*9to5 Mac*](https://9to5mac.com/2026/06/30/anthropic-upgrades-claude-with-new-sonnet-5-model-details-here/?ref=metacurity.com)*,* [*Claude*](https://platform.claude.com/docs/en/about-claude/models/whats-new-sonnet-5?ref=metacurity.com)*,* [*Digit*](https://www.digit.in/features/general/claude-sonnet-5-vs-opus-4-8-is-the-flagship-model-still-worth-paying-for.html?ref=metacurity.com)*,* [*The Mac Observer*](https://www.macobserver.com/news/anthropic-upgrades-claude-with-the-new-sonnet-5-model/?ref=metacurity.com)*,* [*MarkTechPost*](https://www.marktechpost.com/2026/06/30/anthropic-claude-sonnet-5-vs-sonnet-4-6-vs-opus-4-8-agentic-coding-benchmarks-api-pricing-and-cost-performance-tradeoffs-compared/?ref=metacurity.com)*,* [*iClarified*](https://www.iclarified.com/101342/anthropic-launches-claude-sonnet-5-with-major-gains-in-agentic-performance?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/technology/2026/jul/01/anthropic-fable-mythos-ai-models-us-export-controls-lifted?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/137ddb71-852f-438c-ad76-25e2dc43486b?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/958964/anthropic-claude-fable-5-is-back?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-sonnet-5-with-near-opus-48-performance-at-a-lower-price/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/07/image.png) Source: @k8em0.bsky.social ### Last week, billionaire founder of China's Qihoo 360 Zhou Hongyi said his engineers had developed an AI that can rival Anthropic’s Mythos model at finding and exploiting software vulnerabilities, tools he likened to “cyber nuclear weapons.” In positioning Tulongfeng as a Mythos rival, 360 is fuelling an AI arms race between the US and China, one with major national security stakes. Unlike Anthropic, 360 has long had a good working relationship with the Chinese military. Dakota Cary, a Georgetown University expert in Chinese espionage, tells Forbes the most concerning link between 360 and the Chinese state is its role in the National Information Security Vulnerability Database, which is run by Beijing’s national security service, the MSS. In previous research, Cary, who advises cybersecurity company SentinelOne on Chinese hacking, found that 360 was providing at least 35 vulnerabilities a year to the MSS via that database. That was a concern because other research has indicated the Chinese government has, at times, delayed public disclosure of vulnerabilities submitted to the program so they could later be used in clandestine cyberattacks. Cary says that 360’s development of an LLM will likely increase the number of flaws it can uncover and pass to the regime. “It underlines just how fast the front lines of cyber operations are changing,” he says. “Any security service that can get their hands on these tools has to use them as quickly as possible.” ([Thomas Brewster / Forbes](https://www.forbes.com/sites/the-wiretap/2026/06/30/qihoo-360-the-cyber-giant-behind-chinas-mythos-rival/?ref=metacurity.com)) ### Taiwan's Ministry of Digital Affairs’ Administration for Digital Industries said it will inspect systems after hackers claimed they had stolen data from Pi Mobile Technology, a subsidiary of PChome Online. The agency said it is handling the case under the Personal Data Protection Act and will investigate whether any personal data was leaked, per CNA. It added that it will impose penalties if violations are found. Hacker group Settra recently claimed it had breached PChome’s systems and obtained internal documents and user data. PChome said its preliminary review found no intrusion in its main website or core systems. Pi Mobile said it has activated its cybersecurity incident response mechanism, hired a third-party forensic firm, and reported the case to regulators. It added that users would be notified once the scope of any potential data exposure is confirmed. ([Michael Nakhiengchanh / Taiwan News](https://www.taiwannews.com.tw/news/6392990?ref=metacurity.com)) **Related:** [*Moda.gov.tw*](https://moda.gov.tw/ADI/news/latest-news/20010?ref=metacurity.com)*,* [*Tech News*](https://technews.tw/2026/06/30/pchome-responds-to-settra-ransomware-attack-on-pchome-online-inc/?ref=metacurity.com) ### Clint Docken, a retired Alberta lawyer, has launched a proposed class-action lawsuit alleging one of the largest privacy breaches in the province's history exposed the personal information of about 2.9 million voters. His statement of claim, filed in the Court of King's Bench in Edmonton, alleges Alberta's list of electors was unlawfully accessed and distributed for purposes not authorized under the province's Elections Act. The lawsuit names Alberta's justice and solicitor general, chief electoral officer, Centurion Project Ltd., the Republican Party of Alberta, David Parker and unidentified defendants. The document says the breach has exposed millions of Albertans to loss of privacy, misuse of personal information, identity-related risks, profiling, targeting, harassment, and significant distress from the loss of control over their personal information. ([Jesmeen Gill / CBC News](https://www.cbc.ca/news/canada/edmonton/voter-data-class-action-alberta-9.7254561?ref=metacurity.com)) ***Related:*** [*The Globe and Mail*](https://www.theglobeandmail.com/canada/alberta/article-alberta-lawsuit-alleged-data-breach-voters-separatism/?ref=metacurity.com)*,* [*Edmonton Journal*](https://edmontonjournal.com/news/alberta-separatism-voter-data-leak-lawsuit?ref=metacurity.com)*,* [*The Canadian Press*](https://globalnews.ca/news/11945396/class-action-lawsuit-alberta-voters-list-david-parker-elections-government/?ref=metacurity.com)*,* [*CTV News*](https://www.ctvnews.ca/edmonton/article/class-action-lawsuit-launched-over-alberta-voter-database-breach/?ref=metacurity.com)*,* [*CP24*](https://www.cp24.com/news/canada/2026/06/30/class-action-lawsuit-launched-over-alberta-voter-database-breach/?ref=metacurity.com)*,* [*r/Alberta*](https://www.reddit.com/r/alberta/comments/1uk29bj/proposed%5Fclassaction%5Flawsuit%5Ffiled%5Fover%5Falleged/?ref=metacurity.com) ### A key Department of Homeland Security information-sharing database was accessed by an unknown threat actor in recent weeks, potentially exposing sensitive data exchanged between federal, state, local and industry partners, according to two people familiar with the matter. DHS investigators are probing the intrusion of the Homeland Security Information Network, said both people, who spoke on the condition of anonymity because the incident is sensitive. The hackers’ affiliation and whether any documentation was pilfered from the system are both unclear. The department’s Office of Intelligence and Analysis has conducted a damage assessment of the intrusion, which is believed to have occurred sometime between late May and early June, said one of the people. The hackers targeted HSIN servers and a SharePoint system used for collaboration efforts, the person added. Approved users lean on the network to securely access data, exchange requests with partner agencies, manage operations, coordinate safety and security for planned events, respond to incidents and share mission-critical information needed to protect their communities, according to its website. HSIN carries unclassified but sensitive information shared among federal, state, local, territorial, tribal, international and private-sector partners. ([David DiMolfetta / NextGov/FCW](https://www.nextgov.com/cybersecurity/2026/06/hackers-breached-dhs-information-sharing-network-people-familiar-say/414534/?ref=metacurity.com)) ### A vulnerability in Apple’s “Hide My Email” tool lets almost anyone discover a person’s real email address that is supposed to be hidden by the feature, and Apple has failed to fix it for more than a year, according to a security researcher and 404 Media’s own tests. Hide My Email is part of Apple’s paid iCloud+ product. It lets users generate an anonymous email address which they can then use to sign up to services or email people with instead of their personal email. These email addresses are often two random words and a number ending in the @icloud.com domain. 404 Media is not revealing the exact details of the vulnerability because it can still be exploited as of Monday, when 404 Media verified the issue with one of our own hidden email addresses. ”Apple Hide My Email is leaking email addresses that are supposed to be hidden. We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” Tyler Murphy, the co-founder of EasyOptOuts, which discovered and reported the issue to Apple, told 404 Media. ([Joseph Cox / 404 Media](https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/?ref=metacurity.com)) **Related:** [*r/apple*](https://www.reddit.com/r/apple/comments/1ukilw1/apple%5Fhide%5Fmy%5Femail%5Fvulnerability%5Freveals%5Fpeoples/?ref=metacurity.com) ### Adobe released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. All these vulnerabilities can be exploited in low-complexity attacks that don't require user interaction and were tagged with priority 1, indicating a high risk of being targeted. "This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform. Adobe recommends administrators install the update as soon as possible. (for example, within 72 hours)," Adobe says. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-severity-coldfusion-campaign-flaws/?ref=metacurity.com)) **Related:** [*Adobe*](https://helpx.adobe.com/security/severity-ratings.html?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/adobe-coldfusion-critical-flaws/?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/adobe-coldfusion-critical-vulnerabilities/?ref=metacurity.com) ### Crypto platforms lost roughly $75.87 million to 40 hacks in June 2026, according to security firm PeckShield. The monthly total reinforces a familiar pattern for the sector, where bridges, smart contracts, and compromised keys remain the most common failure points. According to PeckShield, June’s figure marks a 7.13% decline from May’s $81.7 million. The Humanity Protocol breach headlined June with over $30 million in losses. Attackers compromised private keys that had been backed up to a malware-infected developer machine. ([Kamina Bashir / BeInCrypto](https://beincrypto.com/crypto-hacks-june-2026-total-losses/?ref=metacurity.com)) **Related:** [*The Cryptonomist*](https://en.cryptonomist.ch/2026/07/01/crypto-security-breaches-june-2026/?ref=metacurity.com)*,* [*Blockonomi*](https://blockonomi.com/crypto-hacks-accounted-75-9m-worth-of-losses-in-june-humanity-protocol-attack-tops-list/?ref=metacurity.com) ### A new report from cybersecurity firm Omega Systems looking at the healthcare industry reveals that the vast majority of medical practices (85%) experienced “at least one operational disruption” linked to a third-party vendor, in most cases one seen as critical to operations. All the same, 70% of leaders told Omega Systems that they are “confident in their vendors’ cybersecurity posture,” though most (63%) admitted they do not monitor their digital supply chains, meaning they are not keeping tabs on data security policies related to critical services such as the electronic health record. It isn’t until something goes wrong that they pay attention, the cybersecurity group added. This visibility gap is even more concerning when you consider that 61% of provider groups who responded to a survey said they are expecting a “fatal cyberattack” to occur in the next five years that will cripple patient care operations. Omega Systems said this trend points to a passive cybersecurity posture at healthcare organizations, where 62% are still treating issues related to data security compliance as a “technical line item rather than a patient-safety priority.” “Fifty-two percent of practices have no managed security service provider (MSSP), and 39% manage cybersecurity entirely in-house,” the firm wrote in its analysis. “Thirty-five percent say this leaves their teams understaffed, and 23% describe their technology as antiquated.” This is despite positive responses from practices that do partner with an outside MSSP. Of them, 42% have access to managed threat detection and 35% have deployed advanced firewalls. ([Chad Van Alstin / HealthExec](https://healthexec.com/topics/health-it/cybersecurity/85-hospitals-experienced-vendor-disruption-last-year-most-brace-cyberattack-inevitability-report?ref=metacurity.com)) **Related:** [*Omega Systems*](https://omegasystemscorp.com/insights/blog/healthcare-vendor-risk-study-third-party-disruptions-2026/?ref=metacurity.com)*,* [*Omega Systems*](https://omegasystemscorp.com/insights/white-papers/2026-healthcare-it-landscape-report/?ref=metacurity.com)*,* [*Security Magazine*](https://www.securitymagazine.com/articles/102393-61-of-healthcare-organizations-predict-a-fatal-cyberattack-within-5-years?ref=metacurity.com) ### The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure program is meant to replace the function of the Critical Infrastructure Partnership Advisory Council. CIPAC was a federal advisory body that allowed agencies like the FBI, the Cybersecurity and Infrastructure Security Agency, and the intelligence community to interact with key owners and operators of water, power, internet, and telecommunications to coordinate on cyberattacks and digital vulnerabilities. ANCHOR will fulfill a similar role. “ANCHOR-CI will provide forums through which cybersecurity, law enforcement, intelligence, national security, and other government representatives at the federal, state, local, tribal, and territorial levels may engage representatives of private sector entities and critical infrastructure owners and operators in reviewing the current threat environment, discussing potential vulnerabilities, and forming recommendations on securing a more resilient critical infrastructure and cyberspace,” DHS wrote in a federal register notice. ([Derek B. Johnson / CyberScoop](https://cyberscoop.com/dhs-anchor-ci-cybersecurity-information-sharing/?ref=metacurity.com)) **Related:** [*Federal Register*](https://public-inspection.federalregister.gov/2026-13268.pdf?ref=metacurity.com) ### CIA Director John Ratcliffe vowed to step up the agency’s efforts to deploy artificial intelligence and quantum computing, stressing that rapid developments in emerging technologies are changing the nature of geopolitics. In rare public remarks on Tuesday, Ratcliffe promised to make organizational changes at the Central Intelligence Agency to increase its embrace of cutting-edge technology. He warned that the US must move quickly because the country’s rivals are also pursuing AI, likening its capabilities to “digital nuclear weapons” that are “rewriting the reality of conflict.” “Worldwide advancement of AI tools will only continue to raise the stakes in our competition with all of America’s adversaries,” Ratcliffe said at a tech conference in Washington hosted by Amazon.com Inc.’s Web Services unit, which was the first major AI developer to strike a deal to provide the CIA with secure cloud computing. ([Maggie Eastland / Bloomberg](https://www.bloomberg.com/news/articles/2026-06-30/cia-aims-to-speed-tech-adoption-as-ai-is-rewriting-conflict?ref=metacurity.com)) ***Related:*** [*NextGov/FCW*](https://www.nextgov.com/artificial-intelligence/2026/06/cia-will-take-smart-risks-and-course-correct-it-adopts-ai-director-says/414542/?ref=metacurity.com) --- **AI is not a cybersecurity strategy.** Organizations with strong security programs will use AI to move faster. Organizations with weak security programs will use AI to create bigger, faster failures. That's why I wrote *The NIST 2.0 Cybersecurity Framework: Practical Risk Management Using Real-World Incidents*. The book moves beyond compliance checklists and theory to show how real organizations succeed—or fail—when security fundamentals break down. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/newcoverpngtiny-1.png) If you're trying to build a resilient security program in the age of AI, this book provides a practical roadmap grounded in actual incidents and operational experience. **Wiley is offering Metacurity readers a 20% discount with code ENG20\.** Order your copy today, and contact me about bulk orders or customized editions for your organization. [Order the book today!](https://cyberriskbook.com/buy-your-copy/?ref=metacurity.com) --- ### With the background of a cyberattack earlier this month on the Central Bank of Libya and the alleged leaking on the dark web of some CBL data, the country's Internal Security Agency issued a statement warning against downloading leaked files attributed to the CBL because they contain malware. The statement indicated that a technical examination and analysis of the leaked files, published on the dark web, revealed that several of them contain malware and hacking tools designed to target new victims and grant attackers unauthorized access to systems. The Internal Security Agency cautioned all sovereign and governmental bodies, banks, and companies against downloading or opening any files from untrusted sources. It urged employees who have downloaded these files to immediately contact their respective cybersecurity teams. The statement emphasized that some of this malware operates covertly to steal and encrypt data, and that sharing these documents for defamation purposes on social media platforms will subject the user to legal accountability. ([Sami Zaptia / Libya Herald](https://libyaherald.com/2026/06/internal-security-agency-warns-against-opening-malware-disguised-as-leaked-cbl-data?ref=metacurity.com)) ***Related:*** [*The Libya Observer*](https://libyaobserver.ly/news/cbl-investigates-alleged-data-leak-after-cyberattack?ref=metacurity.com)*,* [*Libya Update*](https://libyaupdate.com/central-bank-detects-cyber-incident-confirms-continued-services/?ref=metacurity.com)*,* [*The Libya Observer*](https://libyaobserver.ly/news/cbl-cyberattack-contained-investigations-ongoing-no-signs-impact-customer-accounts?ref=metacurity.com) ### The recent cyberattack on state-owned Latvijas valsts meži (LVM), or Latvia's State Forests, in which a hacker managed to breach the company’s IT systems and gain control over data, demonstrates that Latvia’s strategic infrastructure remains relatively vulnerable to such attacks, Minister for Smart Administration and Regional Development Edgars Tavars said. The minister called on all government institutions to identify cybersecurity vulnerabilities within their own systems and learn from the incident. At the same time, Tavars expressed confidence that Latvia’s IT specialists are sufficiently skilled to prevent similar incidents in the future, provided they continue to carry out their work responsibly. Tavars also reiterated that the electronic voter register, which is crucial for the upcoming parliamentary elections and had been developed by LVM, was transferred to the state before the cyberattack occurred and has not been compromised. “At this point, there is certainly no reason to sound the alarm over the elections,” the minister said. He also indicated that the government’s enhanced scrutiny of major IT procurement projects could remain in place even after the expiration of Prime Minister Andris Kulbergs’ current moratorium on large-scale IT procurements. ([Baltic News Network](https://bnn-news.com/cyberattack-on-latvias-state-forests-company-highlights-national-cybersecurity-risks-minister-warns-281534?ref=metacurity.com)) **Related:** [*Inbox.eu*](https://news.inbox.eu/150g166-but-the-police-were-not-called-an-unknown-person-negotiated-with-hackers-extorting-money-from-one-of-the-richest-state-enterprises-in-latvia?language=en&ref=metacurity.com) ### Belgian cybersecurity unicorn Aikido Security is acquiring Israeli cybersecurity company Root, which developed an AI platform for securing open-source components, for an estimated $70 million to $100 million. Following the acquisition, Aikido will open a development center in Israel that will absorb all of Root’s employees and is expected to expand its local workforce further. ([Meir Orbach / CTech](https://www.calcalistech.com/ctechnews/article/hjxak411qzx?ref=metacurity.com)) ***Related:*** [*Help Net Security*](https://www.helpnetsecurity.com/2026/06/30/aikido-security-root-acquisition/?ref=metacurity.com)*.* [*SiliconANGLE*](https://siliconangle.com/2026/06/30/aikido-acquires-root-patch-open-source-without-forced-upgrades/?ref=metacurity.com) ### Most Bittersweet Thing of the Day: Take a Bow, Vint Vinton Cerf [will step down](https://techcrunch.com/2026/06/30/the-father-of-the-internet-is-finally-retiring/?ref=metacurity.com) from his role as Google’s chief internet evangelist next week, marking the conclusion of one of the most influential careers in technology history. ### Worst Thing of the Day: Say Goodbye to the Once Vaunted US Intel Community Donald Trump’s budget chief, Russell Vought, director of the White House Office of Management and Budget (OMB) and head of the execrable Project 2025, has directly [taken over managing](https://therecord.media/intelligence-budget-super-user-job-russ-vought-omb?ref=metacurity.com) the classified spending plans of major UD intelligence agencies, just as the administration works to shrink the spy community’s top office further. ### Bonus Worst Thing of the Day: Again, Say Goodbye to the Once Vaunted US Intel Community The Trump administration [is demanding](https://www.nytimes.com/2026/06/29/us/trump-intelligence-agencies-spies-master-list.html?unlocked%5Farticle%5Fcode=1.uFA.pE4x.MWDqTxBGhqsc&smid=url-share&ref=metacurity.com) that American intelligence officials turn over the names of all foreign espionage targets, including suspected spies and potential recruits, to create a master list that some officials fear will be misused or compromise operations, according to people familiar with the matter. ### Extra Bonus Worst Thing of the Day: Some People Never Learn Lessons Trump officials [have kept](https://www.theatlantic.com/national-security/2026/06/trump-administration-signal-chat-marco-rubio/687735/?gift=nHf7iWmpOKBdlkwz68mfUDv4vu2y71hLoc8Kud40xdY&utm%5Fsource=copy-link&utm%5Fmedium=social&utm%5Fcampaign=share) using Signal, even after the president suggested they stop in the wake of the disastrous Signalgate, possibly in violation of federal records-keeping laws. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/image-100.png) ### Apple faces supply chain leak as AI threats accelerate security updates URL: https://www.metacurity.com/apple-faces-supply-chain-leak-as-ai-threats-accelerate-security-updates/ Last updated: 2026-06-30T12:05:30.000Z Meta secretly benchmarked rival chatbots with fake teen accounts, S.Ct. curbs warrantless geofence searches, Google warns EU competition rules could weaken security, Russia shifts influence operations toward the West, Amazon settles identity theft records case for $2.25m, much more _This post is for paying subscribers only._ ### Washington pushes AI into an export-control era as rivals rush to fill the gap URL: https://www.metacurity.com/washington-pushes-ai-into-an-export-control-era-as-rivals-rush-to-fill-the-gap/ Last updated: 2026-06-29T12:34:16.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/thedigitalartist-ai-generated-8113881-1.jpg) Image by [Pete Linforth](https://pixabay.com/users/thedigitalartist-202249/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=8113881) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=8113881) *Metacurity is the cybersecurity industry's daily reality check—independent, agenda-free coverage that cuts through vendor hype, social media noise, and recycled talking points to explain what matters and why.* *Trusted by thousands of cybersecurity professionals, including many of the industry's most influential security leaders, Metacurity delivers the context, analysis, and perspective that busy readers don't have time to assemble themselves.* *If you find value in that work, please consider becoming a paid subscriber. Metacurity remains independent because its readers choose to support it.* [Upgrade my subscription](#/portal/account/plans) **Frontier AI beat:** The Trump administration spent the weekend advancing an increasingly interventionist approach to frontier AI, approving limited access to Anthropic's Mythos 5 model while simultaneously overseeing a tightly controlled preview of OpenAI's new GPT-5.6 family. The moves suggest Washington is no longer treating advanced AI as a conventional software product but as a strategic technology whose deployment carries national-security implications, pushing AI deeper into the realm of export-controlled dual-use technology. As US officials tighten controls around frontier models, new reporting suggests Chinese firms are rapidly closing the gap in one of the areas that has most alarmed policymakers: AI-driven vulnerability discovery. The Wall Street Journal reported that Zhipu AI's GLM-5.2 has achieved cybersecurity performance approaching Anthropic's Mythos, while Chinese cybersecurity giant 360 Security claims to have built systems designed specifically to rival Mythos-style vulnerability discovery and cyber-defense capabilities. Against that backdrop, Anthropic received approval to restore access to Mythos 5 for a limited group of vetted US organizations, including major enterprises and government entities. Meanwhile, OpenAI launched GPT-5.6 Sol, Terra, and Luna under a similarly constrained preview program involving a small number of approved partners. OpenAI said the restricted rollout was being conducted at the request of the US government while officials continue evaluating frontier-model deployment frameworks. The contrast between Mythos and GPT-5.6 is particularly revealing. OpenAI's safety documentation argues that GPT-5.6 remains below the threshold of the most concerning cyber-risk scenarios associated with Mythos, emphasizing extensive testing and safeguards around offensive cyber capabilities. Independent analyst Zvi Mowshowitz reached a similar conclusion after reviewing OpenAI's system card, arguing that GPT-5.6 appears to remain meaningfully behind Mythos in the cyber capability categories that prompted government concern. While Anthropic's Mythos remains tightly controlled and OpenAI's GPT-5.6 rolls out under government oversight, competitors in China and elsewhere are already marketing alternatives aimed at the same cybersecurity use cases. The result may be a world in which frontier AI resembles export-controlled technology, but one in which substitutes emerge faster than regulators can restrict them. ([Reed Albergotti and Ben Smith / Semafor](https://www.semafor.com/article/06/27/2026/us-releases-powerful-anthropic-model-mythos-to-some-us-companies?ref=metacurity.com), [OpenAI](https://openai.com/index/previewing-gpt-5-6-sol/?ref=metacurity.com), [Ina Fried, Ashley Gold / Axios](https://www.axios.com/2026/06/26/openai-gpt-sol-terra-luna-trump?ref=metacurity.com), [OpenAI](https://deploymentsafety.openai.com/gpt-5-6-preview/introduction?ref=metacurity.com), [Zvi Mowshowitz / Don't Worry About the Vase,](https://thezvi.substack.com/p/gpt-56-the-system-card) [Robert McMillan, Raffaele Huang and Amrith Ramkumar, Wall Street Journal](https://www.wsj.com/tech/ai/chinese-ai-anthropic-mythos-cybersecurity-574b02c2?st=FRKgap&reflink=desktopwebshare%5Fpermalink&ref=metacurity.com), [Kate Park / TechCrunch](https://techcrunch.com/2026/06/27/asian-ai-startups-launch-mythos-like-models-as-anthropics-export-ban-drags-on/?ref=metacurity.com)) **Related:** [*TechCrunch*](https://techcrunch.com/2026/06/26/trump-admin-releases-anthropic-mythos-to-be-used-by-more-than-100-us-companies-agencies/?ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2026/06/26/technology/anthropic-mythos-government-restrictions.html?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/958458/anthropic-mythos-5-is-back-trump-negotiations?ref=metacurity.com)*,* [*Wired*](https://www.wired.com/story/anthropic-restores-access-to-mythos/?ref=metacurity.com)*,* [*Business Today*](https://www.businesstoday.in/technology/news/story/us-eases-block-on-anthropics-mythos-5-allowing-limited-release-to-key-cyber-defenders-539537-2026-06-27?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/anthropics-mythos-5-is-available-again-no-timeline-for-fable-5?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/06/26/us-government-anthropic-claude-mythos5-ai.html?ref=metacurity.com)*,* [*Washington Examiner*](https://www.washingtonexaminer.com/policy/technology/4627502/us-anthropic-mythos-model-released-companies-agencies/?ref=metacurity.com)*,* [*Axio*](https://www.axios.com/2026/06/27/commerce-anthropic-mythos-restrictions-lift?ref=metacurity.com)*s,* [*Wall Street Journal*](https://www.wsj.com/tech/ai/trump-administration-rolls-back-part-of-anthropic-model-ban-e8284434?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-06-26/us-allows-trusted-partners-to-use-anthropic-s-mythos-5-ai-model?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/2203088/anthropic-redeploy-mythos-cybersecurity-ai-model/?ref=metacurity.com)*,* [*CNN*](http://www.cnn.com/2026/06/26/tech/anthropic-mythos-release?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2026/06/26/anthropic-cleared-to-release-claude-mythos-5-to-over-100-us-institutions/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/technology/us-releases-anthropic-model-mythos-some-us-companies-semafor-reports-2026-06-26/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/tech/tech-news/us-government-gives-anthropic-green-light-limited-re-release-mythos-5-rcna352018?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/4b578b5c-258a-48f5-a5e9-15eef5659573?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/us-partially-reverses-anthropic-ai-ban-for-mythos-but-keeps-fable-5-off-the-market/?ref=metacurity.com)*,* [*The Decoder*](https://the-decoder.com/anthropic-gets-us-approval-to-bring-back-claude-mythos-5/?ref=metacurity.com)*,* [*Business Standard*](https://www.business-standard.com/technology/tech-news/anthropic-s-mythos-5-ai-model-gets-approval-from-trump-admin-for-wider-use-126062700095%5F1.html?ref=metacurity.com)*,* [*s*](https://www.axios.com/2026/06/27/commerce-anthropic-mythos-restrictions-lift?ref=metacurity.com)*,* [*Politico*](https://www.politico.com/news/2026/06/26/white-house-makes-peace-with-anthropic-for-now-00965675?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/5943549-anthropic-mythos-5-access/?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/white-house-lifts-export-control-anthropics-mythos?ref=metacurity.com)*,* [*Moneycontrol*](https://www.moneycontrol.com/technology/us-administration-nears-deal-to-lift-curbs-on-anthropic-s-ai-models-report-article-13959834.html?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=48692995&ref=metacurity.com)*,* [*r/wallstreetbets*](https://www.reddit.com/r/wallstreetbets/comments/1ugsgwr/trump%5Fadmin%5Fallows%5Fanthropic%5Fto%5Frelease%5Fmythos%5Fai/?ref=metacurity.com)*,* [*Slashdot*](https://news.slashdot.org/story/26/06/27/0159230/us-government-allows-anthropic-limited-release-of-mythos-ai-model-saying-appropriate-safeguards-are-in-place?ref=metacurity.com)*,* [*The Next Web*](https://thenextweb.com/news/anthropic-mythos-5-us-clearance-trusted-partners-fable-restricted?ref=metacurity.com)*,* [*The Asia Business Daily*](https://www.asiae.co.kr/en/article/2026062720410261052?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/technology/artificial-intelligence/anthropic-resumes-limited-mythos-5-rollout-after-us-eases-restrictions-10759685/?ref=metacurity.com)*,* [*Hürriyet Daily News*](https://www.hurriyetdailynews.com/us-allows-limited-access-to-anthropics-mythos-ai-model-223741?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/markets/tech/26/06/60144514/anthropic-gets-us-green-light-to-deploy-claude-mythos-5-to-trusted-partners-but-fable-5-access-still-blocked-report?ref=metacurity.com)*,* [*Türkiye Today*](https://www.turkiyetoday.com/business/anthropic-says-us-allows-limited-access-to-mythos-5-ai-model-3222757?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/anthropic-claude-mythos-5/?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/anthropic-us-deal-fable-mythos-export-controls?ref=metacurity.com)*,* [*Memeburn*](https://memeburn.com/gpt-5-5-cyber-beats-mythos-5-on-cybergym/?ref=metacurity.com)*,* [*Tech in Asia*](https://www.techinasia.com/news/commerce-lets-anthropic-restore-mythos-5-access?ref=metacurity.com)*,* [*WinCentral*](https://thewincentral.com/gpt-5-6-rollout-leak-early-enterprise-testing-july/?ref=metacurity.com)*,* [*METR*](https://metr.org/blog/2026-06-26-gpt-5-6-sol/?ref=metacurity.com)*,* [*Shelly Palmer*](https://shellypalmer.com/2026/06/washington-now-sorts-the-gpt-5-6-queue/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/conormurray/2026/06/26/openai-rolls-out-powerful-gpt-56-models-to-limited-users-vetted-by-us-government/?ref=metacurity.com)*,* [*The Stack*](https://www.thestack.technology/openai-releases-our-strongest-model-yet-but-only-trusted-partners-get-to-use-it-for-now/?ref=metacurity.com)[*MacRumors Forums*](https://forums.macrumors.com/threads/openai-launches-gpt-5-6-sol-terra-and-luna-in-limited-preview.2484613/?ref=metacurity.com)*,* [*PYMNTS*](https://www.pymnts.com/news/artificial-intelligence/2026/openai-restricts-access-to-latest-ai-models-at-us-government-request/?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2026/06/26/openai-upgrading-chatgpt-and-codex-with-new-gpt-5-6-models-in-limited-release/?ref=metacurity.com)*,* [*VentureBeat*](https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/957845/openai-gpt-5-6-trump-administration-ai-preview?ref=metacurity.com)[*TechCrunch*](https://techcrunch.com/2026/06/26/openai-limits-gpt-5-6-rollout-after-government-request-says-restrictions-shouldnt-be-the-norm/?ref=metacurity.com)*,* [*Unite.AI*](https://www.unite.ai/openais-best-model-just-shipped-behind-a-government-gate/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2026/06/26/openai-introduces-gpt-5-6-challenge-claude-mythos-5/?ref=metacurity.com)*,* [*DataBreachToday.com*](https://www.databreachtoday.com/openai-limits-gpt-56-rollout-at-us-governments-request-a-32092?ref=metacurity.com)*,* [*Decrypt*](https://decrypt.co/372238/openai-rolls-out-gpt-5-6-limited-access-trump-admin?ref=metacurity.com)*,* [*Constellation Research*](https://www.constellationr.com/insights/news/openai-releases-gpt-56-limited-preview-pending-us-goverment-sign?ref=metacurity.com)*,,* [*CoinGape*](https://coingape.com/openai-sparks-crypto-buzz-with-gpt-5-6-models-named-sol-terra-and-luna/?ref=metacurity.com)*,* [*MarkTechPost*](https://www.marktechpost.com/2026/06/26/openai-previews-gpt-5-6-with-sol-terra-and-luna-tiered-models-new-reasoning-modes-limited-access/?ref=metacurity.com)*,* [*MacRumors*](https://www.macrumors.com/2026/06/26/openai-gpt-5-6-sol/?ref=metacurity.com)*,* [*The American Bazaar*](https://americanbazaaronline.com/2026/06/26/openai-limits-gpt-5-6-public-release-after-request-from-trump-483611/?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/gpt-5-6-models-3681960/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/openai-announces-gpt56-sol-its-next-generation-flagship-model-beating-claude-mythos-5/?ref=metacurity.com)*,* [*The Deep View*](https://www.thedeepview.com/articles/how-openai-s-gpt-5-6-just-edged-past-mythos?ref=metacurity.com)*,* [*TestingCatalog AI News*](https://www.testingcatalog.com/openai-launches-gpt-5-6-sol-preview-for-select-partners/?ref=metacurity.com)*,* [*PCWorld*](https://www.pcworld.com/article/3178542/?ref=metacurity.com)*,* [*How-To Geek*](https://www.howtogeek.com/gpt-56-is-here-with-better-security-and-codingso-why-cant-you-use-it-yet/?ref=metacurity.com)*,* [*Pulse 2.0*](https://pulse2.com/openai-previews-gpt-5-6-sol-and-new-model-family/?ref=metacurity.com)*,* [*The Decoder*](https://the-decoder.com/openais-claude-mythos-competitor-gpt-5-6-sol-launches-under-government-controlled-access-it-calls-unsustainable/?ref=metacurity.com)*,* [*Nextgov/FCW*](https://www.nextgov.com/artificial-intelligence/2026/06/openai-releases-new-gpt-56-model-select-partners/414474/?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/openai-sparks-crypto-frenzy-with-gpt-5-6-sol-terra-and-luna-names/?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/markets/private-markets/26/06/60141627/openai-chatgpt-gpt-5-6-sol-strongest-model-yet?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/cool-tech/openai-reveals-its-most-advanced-gpt-5-6-model-but-you-cant-access-it-yet/?ref=metacurity.com)*,* [*iThinkDifferent*](https://www.ithinkdiff.com/openai-gpt-5-6-sol-terra-luna-announcement/?ref=metacurity.com)*,* [*iClarified*](https://www.iclarified.com/101304/openai-unveils-gpt56-sol-terra-and-luna-in-limited-preview?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/metr-gpt-5-6-sol-openai-evaluation-cheating?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=48689028&ref=metacurity.com)*,* [*Washington Post*](https://www.washingtonpost.com/technology/2026/06/26/openai-says-us-government-will-vet-users-its-latest-ai-model/?ref=metacurity.com)*,* [*The Next Web*](https://thenextweb.com/news/openai-gpt-5-6-sol-limited-preview-government-approved-partners?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-06-26/openai-limits-release-of-new-model-under-pressure-from-us?ref=metacurity.com)*,* [*Agence France-Presse*](https://www.yahoo.com/news/politics/articles/openai-restricts-limited-release-model-200108700.html?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/openai-gpt-5-6-sol-limited-preview-government-request?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/06/26/openai-limits-new-ai-models-to-trusted-partners-request-us-government.html?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/5942770-openai-staggers-gpt-56/?ref=metacurity.com)*,* [*Simon Willison's Weblog*](https://simonwillison.net/2026/Jun/26/openai/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1ugg6mn/us%5Fgovernment%5Fwill%5Fdecide%5Fwho%5Fgets%5Fto%5Fuse%5Flatest/?ref=metacurity.com)*,* [*r/neoliberal*](https://www.reddit.com/r/neoliberal/comments/1ugjqc5/us%5Fgovernment%5Fwill%5Fdecide%5Fwho%5Fgets%5Fto%5Fuse%5Flatest/?ref=metacurity.com)*,* [*r/ArtificialInteligence*](https://www.reddit.com/r/ArtificialInteligence/comments/1uge0pp/us%5Fgovernment%5Fwill%5Fdecide%5Fwho%5Fgets%5Fto%5Fuse%5Flatest/?ref=metacurity.com)*,* [*r/ChatGPT*](https://www.reddit.com/r/ChatGPT/comments/1ugdzx2/us%5Fgovernment%5Fwill%5Fdecide%5Fwho%5Fgets%5Fto%5Fuse%5Flatest/?ref=metacurity.com)*,* [*r/OpenAI*](https://www.reddit.com/r/OpenAI/comments/1ugcstc/openai%5Fannounces%5Fgpt56%5Fsol/?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/2203102/openai-starts-previewing-gpt-56-and-its-three-variants/?ref=metacurity.com)*,* [*Thurrott*](https://www.thurrott.com/a-i/337968/openai-launches-next-gen-gpt-5-6-models-in-limited-preview?ref=metacurity.com)*,* [*Simon Willison's Weblog*](https://simonwillison.net/2026/Jun/26/hack-my-ai-assistant/?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/cool-tech/chinese-ai-lab-says-it-can-match-anthropics-all-poweful-claude-mythos-at-sniffing-security-bugs/?ref=metacurity.com)*,* [*Business Today*](https://www.businesstoday.in/technology/artificial-intelligence/story/forget-chatgpt-chinas-cheaper-ai-models-are-quietly-taking-over-enterprise-ai-says-jefferies-539571-2026-06-28?ref=metacurity.com)*,* [*Daily Mail*](https://www.dailymail.com/news/article-15935683/China-US-AI-race-Anthropic-cybersecurity.html?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/chinese-ai-matches-mythos-cybersecurity-report-says?ref=metacurity.com)*,* [*China Money Network*](https://www.chinamoneynetwork.com/2026/06/28/chinas-cheaper-ai-models-challenge-western-leaders-in-the-enterprise-market-jefferies-report-reveals?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/zai-glm-52-open-weight-ai-cost-pressure?ref=metacurity.com)*,* [*International Business Times*](https://www.ibtimes.com/chinese-open-weight-ai-model-raises-cybersecurity-worries-over-advanced-capabilities-3804610?ref=metacurity.com)*,* [*The Next Web*](https://thenextweb.com/news/asian-ai-startups-mythos-alternatives-anthropic-export-ban?ref=metacurity.com)*,* [*RuntimeWire*](https://runtimewire.com/article/sakana-360-anthropic-mythos-export-ban?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/anthropic-mythos-5-us-restrictions-fable-5-openai-gpt-2026-6?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/chinese-cybersecurity-company-360-unveils-chinas-version-of-mythos-and-yitianzhen-to-automate-cyber-defense?ref=metacurity.com) ### Microsoft said it identified and disrupted a large-scale malicious browser extension campaign tracked as StegoAd (a portmanteau of steganography and adware), which operated 119 malicious extensions impacting approximately 2.6 million users. Microsoft said that while its dataindicate this threat actor has been active since at least 2021, steadily evolving evasion techniques, the steganographic phase that defines the campaign emerged in early 2024 and spans 25 months through April 2026. Dynamic analysis of C2 response payloads revealed capabilities far beyond ad fraud: a full remote code execution (RCE) backdoor, Google account credential theft with 2FA bypass, WordPress admin credential harvesting, cookie exfiltration, and abuse of Google Analytics as covert telemetry infrastructure. All identified malicious extensions have been removed from the Microsoft Edge Add-ons store, and associated developer accounts have been suspended. ([Microsoft](https://microsoftedge.github.io/edgevr/assets/files/stego%5Fad/Microsoft%5FEdge%5FSecurity%5FStegoAd.pdf?ref=metacurity.com)) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/image-98.png) Source: Microsoft. ### The National Design Studio, an opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge), has quietly rebuilt some of the federal government’s most sensitive websites – for passport applications, voter registration, prescription-drug pricing and children’s savings – in ways critics say appear to violate federal law. A Guardian investigation has found the office has apparently been developing or redeveloping sensitive federal websites, including those connecting Americans with prescription drugs, children’s savings accounts, passports and voter registration. The investigation corroborates and advances earlier reporting by the Drey Dossier, a YouTube investigative outlet. The NDS built and now operates four public federal websites: ndstudio.gov, trumprx.gov, realfood.gov and trumpaccounts.gov. All four ran commercial visitor-tracking software, configured to evade the privacy tools many web users install, and none carry the public filings federal privacy law requires under laws including the Privacy Act of 1974 and the E-Government Act of 2002. Separately, none of the NDS’s spending or its arrangements with outside vendors appears in USAspending, the federal contracting database, raising questions about how it is funded and overseen. Separately, the NDS has also built and runs White House-controlled versions of services the US Congress assigned to other federal agencies, including a passport-application portal that bypasses the State Department’s existing site, and a copy of voter-registration site vote.gov. Combined, the sites route sensitive interactions Americans have with their government through infrastructure the White House apparently controls, and outside the reporting and accountability systems that normally cover federal agencies. ([Jason Wilson / The Guardian](https://www.theguardian.com/us-news/2026/jun/28/government-website-visitor-tracking-surveillance-fears?ref=metacurity.com)) ### The number of Iranian cyberattacks against Israel has shot up since the launch of the ​U.S.-Israeli offensive against Iran this year, a senior ‌Israeli security official was quoted as saying. Yossi Karadi, Director General of Israel's National Cyber Directorate, told German ​newspaper Die Welt that in June 2025 ​, during Israeli military operations against Iran, Israel's ⁠authorities registered around 1,600 hostile cyber incidents. During the ​same month in 2026, the number had jumped to ​some 4,800 incidents, he told the paper. "Some groups are very skilled," Karadi said, according to the German text of the ​interview. "We can handle them, but we have to ​take them seriously. Unlike in the kinetic realm, there's no ‌ceasefire in cyberspace." Karadi said the attacks were directed against systems used by Israel's critical infrastructure, central organizations, small to medium-sized companies and the public, citing law ​practices and accounting ​firms as ⁠among the smaller ones hit. "So far — and hopefully it stays that way — we've ​managed to fend off attacks on ​critical ⁠infrastructure," he said. ([Joern ​Poltz / Reuters](https://www.reuters.com/world/middle-east/iran-cyberattacks-israel-surged-2026-israeli-cyber-chief-says-2026-06-29/?ref=metacurity.com)) **Related:** [*Times of Israel*](https://www.timesofisrael.com/iranian-cyberattacks-on-israel-surged-in-2026-cyber-chief-says/?ref=metacurity.com)*,* [*Voice of Emirates*](https://www.voiceofemirates.com/en/politics/reports-and-investigations/2026/06/29/israel-detects-a-sharp-increase-in-iranian-cyberattacks/?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/markets/tech/26/06/60148831/no-ceasefire-in-cyberspace-israel-says-iran-linked-cyberattacks-nearly-tripled-in-june?ref=metacurity.com)*,* [*The Kabul Tribune*](https://thekabultribune.com/en/0009759?ref=metacurity.com)*,* [*India Today*](https://www.indiatoday.in/technology/news/story/israel-says-no-ceasefire-in-cyberspace-iran-continues-to-attack-critical-infrastructure-2936402-2026-06-29?ref=metacurity.com)*,* [*Jerusalem Post*](https://www.jpost.com/middle-east/article-900764?ref=metacurity.com) ### The FBI and CISA issued an update to their March 20, 2026, Public Service Announcement I-032026-PSA to provide additional information to the public and encourage device owners to take actions to protect themselves against Russian hackers. The FBI has identified multiple clusters of Russian Intelligence Services (RIS) cyber threat actors responsible for an ongoing commercial messaging application (CMA) phishing campaign against individuals of high intelligence value. Russian Federal Security Service (FSB) officers embedded with the FSB Border Guards and others working on behalf of the Russian military services continue to target current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine. RIS cyber threat actors have compromised individual CMA accounts, but not the CMA's encryption or the application itself. To date, this activity has been publicly tracked as UNC5792 and UNC4221. According to the update, RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims' Backup Recovery Keys. RIS cyber threat actors continue to elicit victims' verification codes and account PINs (see Figure 1). If a targeted user backs up their CMA messages as directed in Figure 1 and later provides their Backup Recovery Key (see Figure 2), RIS cyber threat actors can view the account's historical messages, private and group messages, and take over the victim's account. If a victim inadvertently shares their Backup Recovery Key, that same key remains valid even if they create a new account following the compromise using the same phone number. Consequently, the actor could potentially use the compromised key to take over the new account in the future as well. To mitigate this risk, the user must generate a new Backup Recovery Key within the Settings control; this action will invalidate the previous key for all future backup downloads. However, please note that this does not prevent the actor from having already downloaded a backup of the original account. Separately, the Rewards for Justice is offering $10 million for information on UNC5792. **Related:** [*IC3*](https://www.ic3.gov/PSA/2026/PSA260626?ref=metacurity.com)*,* [*Rewards for Justice*](https://rewardsforjustice.net/rewards/unc5792/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/image-97.png) ### The US insurance industry’s standard setter, the National Association of Insurance Commissioners, has suspended its risk designations on the investments of insurers, after a cyber attack claimed by ShinyHunters compromised data from rating agencies including Moody’s, S&P and KBRA. The NAIC said that credit rating agencies had “paused” data sharing in the wake of the breach, and that it had also suspended assigning its own risk designations to insurers’ investments. These ratings and designations are crucial to US life insurers because they help determine how much capital they must have to meet their future obligations to policyholders. By incurring lower capital charges on similar assets, insurers can improve their profit margins. ([Lee Harris / Financial Times](https://www.ft.com/content/1b397558-117e-463b-914d-9a62e4484605?ref=metacurity.com)) **Related:** [*NAIC*](https://content.naic.org/about/security-update?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2026/06/27/naic-suspends-investment-risk-designations-after-cyber-attack/?ref=metacurity.com)*,* [*eciks.org*](https://eciks.org/11103-71173-insurance-naic-data-breach-peoplesoft?ref=metacurity.com)*,* [*Insurance Business*](https://www.insurancebusinessmag.com/uk/news/cyber/terabytes-of-data-dumped-on-the-dark-web-after-us-insurance-regulator-hacked-580538.aspx?ref=metacurity.com) --- **AI is not a cybersecurity strategy.** Organizations with strong security programs will use AI to move faster. Organizations with weak security programs will use AI to create bigger, faster failures. That's why I wrote *The NIST 2.0 Cybersecurity Framework: Practical Risk Management Using Real-World Incidents*. The book moves beyond compliance checklists and theory to show how real organizations succeed—or fail—when security fundamentals break down. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/newcoverpngtiny-1.png) If you're trying to build a resilient security program in the age of AI, this book provides a practical roadmap grounded in actual incidents and operational experience. **Wiley is offering Metacurity readers a 20% discount with code ENG20\.** Order your copy today, and contact me about bulk orders or customized editions for your organization. [Order the book today!](https://cyberriskbook.com/buy-your-copy/?ref=metacurity.com) --- ### The NSW Rural Fire Service (RFS) in Australia is investigating a cybersecurity incident after a hacker gained access to its information and communications technology systems for which the Nova ransomwaretook credit earlier this month. An RFS spokesperson said the agency was working to determine “what information may have been accessed or obtained”. The incident may have involved a third-party vendor supporting NSW Rural Fire Service radio and telecommunications infrastructure. An RFS spokesperson confirmed the incident was “initiated from a compromised account and involved our remote access system”. The threat actor claimed the data was stolen via Citrix, which offers remote access solutions. Information Age understands the group was unable to successfully deploy its ransomware and encrypt any data for extortion purposes, but some data may have been exfiltrated. ([Leonard Bernardone / Information Age](https://ia.acs.org.au/article/2026/nsw-rural-fire-service-admits-security-incident.html?ref=metacurity.com)) **Related:** [*Cyber Daily*](https://www.cyberdaily.au/security/13817-exclusive-nova-ransomware-group-takes-responsibility-for-nsw-rfs-hack?ref=metacurity.com) ### The $292 million KelpDAO bridge exploit in April and the Humanity Protocol private key theft in June were already suspected as connected, as both incidents carried hallmarks of DPRK-linked operations, with fingers pointing to the notorious Lazarus group. Now, on-chain evidence shows the proceeds of those attacks are flowing into shared wallets, which is a pattern consistent with a single laundering pipeline, according to blockchain analyst Specter. According to Specter, the Humanity Protocol attacker moved 15,403 ETH, which is around $23.6 million, to a relatively new Ethereum address. The funds were then crossed onto the Bitcoin network, where they mixed with proceeds that have been traced to the KelpDAO exploit. This action is a well-documented Lazarus Group technique, where they consolidate proceeds from separate operations into unified Bitcoin wallets before routing them through mixers and over-the-counter desks. ([Hannah Collymore / Cryptopolitan](https://www.cryptopolitan.com/connection-between-kelpdao-humanity-hackers/?ref=metacurity.com)) Related: [AMB Crypto](https://ambcrypto.com/humanity-protocol-kelp-dao-stolen-funds-commingle-same-attacker/?ref=metacurity.com) ### Best Thing of the Day: This Manifestation Worked Well House Homeland Security Committee Chair Andrew Garbarino (R-NY) [said ](https://punchbowl.news/article/tech/garbarino-mythos/?ref=metacurity.com)the US government needs to “act soon” to get a grip on the threats posed by AI. ### Worst Thing of the Day: This Is All Just Headed to Mass Surveillance Australia's ban on social media for children [was the start](https://www.theguardian.com/news/ng-interactive/2026/jun/27/social-media-bans-go-global-big-tech-reckoning-australia-crackdown?ref=metacurity.com) of a global reckoning; in March, Indonesia began blocking children under the age of 16 from accessing most social media, and Malaysia followed suit this month. Last week, Britain announced its own ban, which it plans to have in place by early 2027 ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/image-95.png) ### The new architecture of power: Best infosec long reads 6/27/26 URL: https://www.metacurity.com/next-long-read-11/ Last updated: 2026-06-27T11:35:42.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/franganillo-ai-generated-7975718-1.png) Image by [Jorge Franganillo](https://pixabay.com/users/franganillo-4407724/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=7975718) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=7975718) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **6/27/26:** From browser-based side channels and AI-generated malware to predictive policing, frontier AI oversight, and suspected state-backed cyber sabotage, this week's long reads examine how advances in computing are expanding both technical capabilities and institutional power. The pieces explore what happens when increasingly sophisticated digital systems become embedded in critical infrastructure, public services, government decision-making, and national security, raising questions about security, accountability, and control that extend well beyond the technology itself. ### British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted Wired's Matt Burgess and investigative journalist Mark Wilding [revealed](https://www.wired.com/story/british-police-built-a-sprawling-crime-prediction-machine-some-results-couldnt-be-trusted/?ref=metacurity.com) that a UK police force quietly built extensive predictive-policing systems fueled by massive public-sector datasets, only to see some risk-scoring models abandoned amid concerns about accuracy, transparency, and public trust. > How the police have developed and used their predictive tools hasn’t always been clear to the public. John Pegram, the leader of a local police accountability group in Bristol, says he didn’t hear about the Offender Management App until 2023, years after it had been created. When he did learn about it, he began to suspect he might be included. “I think I knew I was on the app,” Pegram says. > In early 2024, Pegram filed a request to find out how the police were using his data. The police refused to say. Months later, after Pegram had hired solicitors to work on his case, the police confirmed he was on the app but declined to elaborate further. Like others across Bristol, the UK, and, increasingly, around the world, Pegram didn’t know whether he had been scored by an algorithm, what that score might be, or how it could affect his interactions with the authorities. > WIRED, working in partnership with the nonprofit newsroom Liberty Investigates, plus the Bristol Cable and Lighthouse Reports, obtained hundreds of pages of documentation from public records requests to build the most comprehensive picture to date of Avon and Somerset’s regional experiment with data collection and predictive analytics. (Liberty, the parent organization of Liberty Investigates, had some early involvement in a potential legal challenge to the program and continues to support Pegram’s litigation.) > The investigation reveals that at least two of these risk-scoring models were quietly abandoned after Bristol City Council staff deemed they could no longer trust them. Previously unreported documents show government inspectors and independent reviewers highlighting a startling lack of transparency about some elements of the program and warning that the systems could undermine public trust. Police data disclosed to WIRED—comprising more than 36,000 model performance scores—appear in some cases to show “genuinely poor predictive performance,” according to an independent analyst who reviewed the data for WIRED. > These findings come as the UK appears poised to embrace predictive analytics and artificial intelligence across the criminal justice system. A familiar face is helping lead the charge: the former chief constable of Avon and Somerset, Andy Marsh, who now heads the national standard-setting body for forces across England and Wales. As CEO of the College of Policing, Marsh has said that effective AI should be “injected like heroin” to speed up British police work. In a recent interview, Marsh said his organization was examining around 100 currently deployed AI tools, including for predictive policing. “Our job is to test the ones that work properly, test them with rigorous evaluation, and then spread them like wildfire through policing.” _This post is for paying subscribers only._ ### US tightens oversight as AI moves deeper into cyber, warfare and media URL: https://www.metacurity.com/us-tightens-oversight-as-ai-moves-deeper-into-cyber-warfare-and-media/ Last updated: 2026-06-26T13:04:33.000Z Russia kept using Cellebrite after sales ban, $3m stolen in Polymarket phishing attack, Poland busts SIM-swapping gang behind crypto thefts, Suspected Iranian hacker arrested in Montenegro, AYA Bank confirms limited data leak, Cyberattack knocks Ukrposhta mobile app offline, much more _This post is for paying subscribers only._ ### Frontier AI Beat: AI security becomes a geopolitical arms race URL: https://www.metacurity.com/frontier-ai-beat-ai-security-becomes-a-geopolitical-arms-race/ Last updated: 2026-06-25T13:37:45.000Z Microsoft uses AI to link malware groups in RICO case, Ukraine exposes Russian messenger hacking, Nation-state hackers mapped CI for sabotage, DPRK-linked election attacks surge 68-fold, DraftKings hacker 'Snoopy' gets 18 months, ICE surveillance spending hits record high, much more _This post is for paying subscribers only._ ### Frontier AI beat: NSA locked out, Meta pressured, lawsuits begin URL: https://www.metacurity.com/frontier-ai-beat-nsa-locked-out-meta-pressured-lawsuits-begin/ Last updated: 2026-06-24T13:49:07.000Z Dialog's "hack" looks more like a misconfiguration, Klue breach spills more LastPass customer data, Iranian banking services hit by fresh cyber disruption, India's Bajaj Auto hit by ransomware attack, KDDI warns 14m accounts may be exposed, much more _This post is for paying subscribers only._ ### Admin accelerates quantum push, advances timeline for quantum-safe security URL: https://www.metacurity.com/admin-accelerates-quantum-push-advances-timeline-for-quantum-safe-security/ Last updated: 2026-06-23T12:51:39.000Z Five Eyes warn AI cyber threat is months away, Tata breach exposes Apple and Tesla files, OpenAI launches Patch the Planet initiative, Meta pauses employee AI data collection after exposure, Two plead guilty in £39m TfL cyberattack, Texas probes Carnival breach affecting 6 million customers, more _This post is for paying subscribers only._ ### Anthropic watch: US government dispute becomes AI governance fight URL: https://www.metacurity.com/anthropic-watch-us-government-dispute-becomes-ai-governance-fight/ Last updated: 2026-06-22T14:20:50.000Z Operation Endgame wipes SocGholish infrastructure, Hackers hijack Brazil emergency alert system, London Hydro breach exposes customer data, Data breach in Korea exposes 5,000 startup applications, Acworth investigates cyberattack on city systems, much more _This post is for paying subscribers only._ ### The industrialization of manipulation: Best infosec long reads 6/20/26 URL: https://www.metacurity.com/the-industrialization-of-manipulation-best-infosec-long-reads-6-20-26/ Last updated: 2026-06-20T09:45:33.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/tasukaran-sunset-6226244-1.jpg) Image by [tasukaran](https://pixabay.com/users/tasukaran-19084744/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=6226244) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=6226244) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **6/20/26:** This week's long reads explore how technology is making manipulation cheaper, faster, and easier to scale, ranging from AI-generated nude images used to harass teenagers to romance scammers who have transformed deception into a pathway to wealth and status to researchers who show how AI systems themselves can be influenced through poisoned content. Hovering over all of them is a deeper question raised by digital forensics pioneer Hany Farid, who worries that increasingly sophisticated AI-generated media is eroding our ability to distinguish reality from fiction. Viewed collectively, these pieces suggest that the defining challenge of the digital age may not simply be securing systems, but preserving trust in a world where images, relationships, communities, and even information itself can be manipulated at unprecedented scale. ### AI Supercharges Deepfake Nudes—Unleashing a New Form of Bullying Among Kids The Wall Street Journal's Georgia Wells and Rachel Wolfe [examine](https://www.wsj.com/tech/ai-deepfake-nudes-bullying-school-d242b8d4?mod=rss%5FTechnology&ref=metacurity.com) how AI-powered "nudify" tools have transformed deepfake pornography into a widespread form of bullying and harassment, leaving schools, parents and law enforcement struggling to protect victims and keep pace with the technology. > When deepfake technology first came on the scene around 2015, it required hundreds or thousands of photos. The people who were vulnerable were famous. Now a growing number of nudify apps can virtually remove clothing from a person based on one image. With just 10 seconds of audio, an AI tool can clone a voice. > “The threat vector has gone from Taylor Swift and Scarlett Johansson to anyone who has a single image of themselves online,” said Hany Farid, a digital forensics professor at the University of California, Berkeley. “Which for young people is, well, everybody.” > More than half of the 557 U.S. teens who took a recent George Mason University survey said they had created at least one image using nudification tools. A third said someone had created and shared a nude image of them without their permission. > The share of teens using AI nudification was “way higher than I thought it would be,” said Chad M.S. Steel, a digital forensics researcher at George Mason, who led the study. > While people of all ages are falling victim to deepfakes, younger generations are encountering the rapidly evolving technology during a formative time in their social and sexual development. > The nonprofit Tech Transparency Project, which investigates online platforms, found more than 100 nudification apps in the Apple and Google app stores in January. Those apps were collectively downloaded more than 700 million times and generated $117 million in revenue, app analytics firm AppMagic found in the investigation. > Google said it disabled the search term “nudify” in its app store in May after an inquiry from The Wall Street Journal. Apple also recently disabled searches for the term in its app store. > Google doesn’t allow apps that contain sexual content, a spokesman said, adding that the company detects and removes apps with harmful content. As part of a broader investigation into deepfakes, he said, Google has suspended hundreds of apps. > An Apple spokesman said the company’s app store prohibits overtly sexual content and requires developers to have a method for filtering objectionable user-generated content. He said the company removes nudification apps, which are against the company’s guidelines. > Teens can find these tools in other ways, outside of app stores. Many nudification services operate websites and promote their services on social media. And teens also create deepfakes using apps that allow users to swap faces in images. > ‘It haunts me’ > In the fallout, some teen victims decide their best option is to leave their school. > Nadeen Noel was a high-school sophomore when she discovered she was among a group of about 50 students targeted by a group of boys in Iowa. The boys used a site called Undress AI, which for $29.99 will create nude and sexually explicit images with a few clicks. Their deepfake images of those classmates then got passed around. > When she encountered the boys in the hallways, their glances left her feeling disturbed. > “It haunts me thinking about it,” she said. Noel, who just finished her junior year of high school, is now taking classes online. > The Belize-based Undress AI teases a $59 video-creation option on its website with images of a peach emoji. Users select the pose for the video: undressing, “riding,” and other sexual acts. It encourages users to recruit others to join the site: “For each friend you invite you get free credits that can be used for Undress AI!” > Undress AI didn’t respond to requests for comment. > Some AI nudify apps use coordinated networks of accounts on social media to promote themselves, including one network of 45,000 accounts on X that use variations of similar text, according to Matthew Patane, a senior researcher at Graphika, a social network analysis firm. The ads use implicit phrases and censored visuals in an attempt to avoid moderation, Patane found. > “AI has no chill these days. Found this AI tool that, uh, removes clothes from photos,” reads one of the X posts that appears to be a part of the network promoting Undress AI. “It’s ridiculous and kinda brilliant.” > X didn’t respond to requests for comment. Broadly, X prohibits users from engaging in activity to mislead others. _This post is for paying subscribers only._ ### Anthropic watch: Dispute widens as customers, allies and investors react URL: https://www.metacurity.com/anthropic-watch-dispute-widens-as-customers-allies-and-investors-react/ Last updated: 2026-06-18T13:46:34.000Z Bulgarian spyware firm sold tools to repressive regimes, The Gentlemen claims attack on sugar mills, FortiBleed exposes 73k Fortinet VPN credentials, Startup competition leak exposes 5k applicants, Canada spy agency disrupted botnets, Fake YouTube gurus spread crypto-stealing malware, much more _This post is for paying subscribers only._ ### Anthropic watch: Congress scrambles, Europe recoils, and Anthropic's halo grows brighter URL: https://www.metacurity.com/anthropic-watch-congress-scrambles-europe-recoils-and-anthropics-halo-grows-brighter/ Last updated: 2026-06-17T13:49:14.000Z Leak exposes members of Peter Thiel's secretive power network, Cybercrime now accounts for a third of crimes in parts of Asia, France picks local rival to replace Palantir at spy agency, Americans lost $3.5B to imposter scams last year, Hackers hijack Roblox games by seizing dev accounts, much more _This post is for paying subscribers only._ ### Why the White House turned on Anthropic URL: https://www.metacurity.com/why-the-white-house-turned-on-anthropic/ Last updated: 2026-06-16T13:35:04.000Z Chinese spies hid in research networks for two years, Copilot bug let attackers steal Microsoft 365 data, Crypto scammers now send couriers for cash, Judge keeps Meta AI scraping lawsuit alive, Feds dismantle $389m crypto laundering op, iRhythm reports breach after extortion demand, much more _This post is for paying subscribers only._ ### Section 702 Expires, but the US Isn't Going Dark URL: https://www.metacurity.com/section-702-expires-but-the-us-isnt-going-dark/ Last updated: 2026-06-15T14:08:24.000Z Feds seize major deepfake porn sites, Cyberattack disrupts services at four major Iranian banks, Trump orders cybersecurity overhaul for national security systems, Conti ransomware coder pleads guilty in US case, Chinese spies hid in critical infrastructure network for a decade, much more _This post is for paying subscribers only._ ### Special report: Anthropic and the first great AI cyber showdown — a timeline URL: https://www.metacurity.com/special-report-anthropic-and-the-first-great-ai-cyber-showdown-a-timeline/ Last updated: 2026-06-15T11:36:09.000Z Over the past few days, a dispute over AI safety guardrails escalated into a White House crackdown, a global sovereignty debate, and the first major clash between frontier AI cyber capabilities and government authority. _This post is for paying subscribers only._ ### Innovation is easy, but adaptation is hard: Best infosec long reads 6/13/26 URL: https://www.metacurity.com/next-long-read-10/ Last updated: 2026-06-13T14:12:26.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/pexels-silverkblack-23224674-1.jpg) Source: [Vitaly Gariev](https://www.instagram.com/vitalygariev?ref=metacurity.com) via Pexels. *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **6/13/26:** This week's infosec long readssuggest that technological progress is increasingly outpacing society's ability to manage it, making resilience, security, and adaptation more important than innovation alone. Whether discussing insecure smart toys, AI-powered cyber defense, the US-China AI competition, smart homes, or cyber-resilient critical infrastructure, each piece argues in its own way that the key challenge is building the safeguards, institutions, and engineering practices needed to ensure powerful technologies remain beneficial rather than becoming sources of risk. ### The International Security Scandal of My Friend Cayla In her blog called the Cut Price Guignol, Scottish writer Lou, Queen of the Guignol, [recounts](https://thethreepennyguignol.com/2026/05/31/the-international-security-scandal-of-my-friend-cayla/?ref=metacurity.com) how My Friend Cayla, a Bluetooth-connected talking doll marketed as an interactive companion, became an international privacy and security scandal after researchers discovered it could be easily hacked, used to eavesdrop on children, and potentially collect personal data—leading Germany's Federal Network Agency to classify it as a prohibited espionage device and effectively ban it. > \[I\]t wouldn’t take long till Cayla was revealed to be scary in an entirely more palpable fashion. On 30th January 2015, the Tech Tent, a show on the BBC World Service, shared a clip of security researcher Ken Munro, who had identified a unique vulnerability in Cayla’s software – specifically, that the app, which was unprotected by any kind of passcode, could be hacked to force Cayla to say almost whatever the hacker wanted. To prove his point, Munro has Cayla take a very different approach to her usual friendly nature. “I’m in charge now,” Cayla announces. “You might thing I am just a sweet toy, but now I have been hacked, I can say all sorts of scary things”. Munro encouraged parents to keep Cayla turned off when not in use and to carefully lock down all devices attached to her. > But it wasn’t just Munro who raised concerns about the toy’s vulnerabilities. Towards the end of 2015, Tim Medin, of Red Siege Information Security, tested the limits of the doll’s security, and found that not only could the app be hacked to allow her to say whatever you wanted, but that you could play any noises you wanted through her speakers – which he proved by running some of the sound effects and screams from the movie Poltergeist through Cayla. Additionally, Medin remarked on how easily the toy could be repurposed into a remote speaker by anyone close enough to connect via Bluetooth. “”In an apartment complex many people could be in range of this device and use it for nefarious purposes,” he pointed out. “This toy can be used to listen to, and communicate with a child with no authentication required.” > In theory, the toy was protected from covert access because the doll’s necklace was supposed to light up whenever it was switched on. However, as Stefan Hessel, a law student from Germany, pointed out, that feature could easily be turned off using the app, meaning that anyone within a certain radius of the doll could feasibly be listening in without anything to raise the alarm. > With the doll’s vulnerabilities laid bare right before Christmas shopping season, Genesis Toys swiftly tried to brush off the concerns about the issues with Cayla’s security. General manager of Genesis, Peter Magalhaes, insisted that “Cayla was basically the subject of a tech prank”, and the toy was stocked on shelves that year, landing in homes across Europe and America. > But the criticisms didn’t end there. European consumer watchdog Beuc identified certain biases in the answers that Cayla would give, indicating a particularly affinity for Disney products, adding in a layer of covert marketing that feels particularly cynical to attach to a child’s toy like this. Perhaps more concerningly, though, they pointed out that Nuance Communication, the company through with the doll’s audio input was processed, reserved the right to share the information received with third parties, meaning that children’s recorded conversations could feasibly be used in further targeted marketing. > However, the harshest statement against the toy came in early 2017, when Hessel released a legal opinion about whether the doll’s security vulnerabilities constituted a violation of the German Telecommunications Act. In his conclusion, Hessel noted that “…my friend Cayla” is a camouflaged transmitter that is also suitable for secretly listening to conversations. However, it is questionable whether there is also a determination of the transmitter system. From the author’s point of view, there are decisive reasons for the fact that the dummy is also intended for listening and thus a prohibited transmitter…” > Hessel submitted this opinion to authorities, and, in February 2017, a spokesperson for the Federal Network agency confirmed their conclusions: the doll met all the criteria of a prohibited spy device. This meant not only that the doll had to be taken off the market in Germany with immediate effect, but that anyone in possession of a doll would be called upon to destroy it at once. Due to the ruling of the toy as a prohibited transmitter, sale and possession could land anyone who owned the doll in prison for up to two years due to its classification as a concealed espionage device. _This post is for paying subscribers only._ ### Google sues AI-powered scam ring behind fake carrier rewards texts URL: https://www.metacurity.com/google-sues-ai-powered-scam-ring-behind-fake-carrier-rewards-texts/ Last updated: 2026-06-12T13:36:00.000Z Oracle warns of critical PeopleSoft flaw, Israeli firm suspected of election interference in France, Scotland and New York, Authorities dismantle crypto laundering service tied to ransomware gangs, Novo Nordisk discloses breach involving clinical trial patient data, much more _This post is for paying subscribers only._ ### Coupang hit with record $409 million fine over massive insider-driven data breach URL: https://www.metacurity.com/coupang-hit-with-record-409-million-fine-over-massive-insider-driven-data-breach/ Last updated: 2026-06-11T13:51:57.000Z CISA orders faster patching as AI speeds exploitation, Suspected Russian hacker extradited to the US over Void Blizzard, OpenAI disrupts China-linked campaigns targeting US tech debates, Digital breadcrumbs lead to alleged leader of The Gentlemen, much more _This post is for paying subscribers only._ ### Anthropic releases Mythos-derived model with cyber guardrails URL: https://www.metacurity.com/anthropic-releases-mythos-derived-model-with-cyber-guardrails/ Last updated: 2026-06-10T13:44:50.000Z Admin halts AI safety reports amid fight over oversight, Microsoft patches record 200 flaws as AI fuels bug discovery, Nightmare Eclipse drops fresh Windows zero-day, China's hackers target tech firms as AI race intensifies, Social media overtakes email as top attack channel, much more _This post is for paying subscribers only._ ### Meta moves to hold NSO in contempt over WhatsApp attacks URL: https://www.metacurity.com/meta-moves-to-hold-nso-in-contempt-over-whatsapp-attacks/ Last updated: 2026-06-09T13:33:32.000Z UK threatens tech firms over child sexting, Microsoft disables GitHub repositories after AI tool malware attack, Pentagon adds Alibaba, Baidu to China military-linked list, Anthropic says AI can turn vulns into exploits in hours, Check Point fixes critical VPN flaw under active attack, much more _This post is for paying subscribers only._ ### Zcash tumbled after disclosure of critical counterfeiting flaw URL: https://www.metacurity.com/zcash-tumbled-after-disclosure-of-critical-counterfeiting-flaw/ Last updated: 2026-06-08T13:49:21.000Z 20k Instagram accounts hacked in attack that abused AI tool, Router flaw powers rise of shape-shifting C0XMO botnet, Ransomware gang sends fake IT staff into victim offices, ShinyHunters-linked leak exposes millions of DentaQuest records, Chinese cyber spies hid in Microsoft 365 for 18 months, more _This post is for paying subscribers only._ ### The future of cyber arrives, but old failures persist: Best infosec long reads 6/6/26 URL: https://www.metacurity.com/the-future-of-cyber-arrives-but-old-failures-persist-best-infosec-long-reads-6-6-26/ Last updated: 2026-06-06T13:21:05.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/06/pexels-gstudio-8640331-1.jpg) Source: [Georgie Devlin](https://www.paypal.com/donate?token=WzyT8sumDBqW7wex24QUndb7R7qCd%5F2VGVoI5BDkNPF7v8Ek9FNp3PnoNZS8FZhlFt%5F5TXQSR1I8dHTs&locale.x=US&ref=metacurity.com). *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity in achieving our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **6/6/2026**: This week's long reads explore a world in which advantage increasingly belongs to those who can adapt fastest, whether in the race for technological leadership, the development of novel cryptographic techniques, or the creation of AI-powered malware that generates attacks on the fly. Yet the hacking of a hospital CCTV system in India serves as a reminder that even as cyber science advances, many organizations remain vulnerable to the same basic security failures that have plagued the internet for decades. ### Cyber terror in labour room: Curtains left open, weak passwords, eight hackers, and viral clips The Indian Express's Brendan Dabhi [tells a chilling tale](https://indianexpress.com/article/cities/ahmedabad/rajkot-labour-room-cctv-hack-cyber-terror-case-10717902/?ref=metacurity.com) of how Indian police invoked cyberterrorism charges against eight men accused of hacking a maternity hospital’s CCTV system—left protected by a default password—and selling footage of women in labor and undergoing medical examinations through Telegram and YouTube networks, exposing broader security failures affecting tens of thousands of internet-connected cameras. > The hospital in question is housed in a four-storey commercial building. Couples sit in joined metal chairs in the waiting room, many with medical reports in their hands. A video playing on a screen shows “success stories” of couples leaving the hospital with new-born babies in their arms. > The hospital administrator recollected the shock of discovering the crime last year. “A patient had just gone into labour, and the staff was busy. In the middle of that, a reporter approached us and said footage of our hospital was being shown on the Internet. We were horrified… We didn’t know,” the administrator said. > “We immediately went to the police station. The Rajkot City police told us they were already aware and an FIR had been registered by the Cybercrime Branch in Ahmedabad City. We had no facts, other than knowing that CCTV footage from our labour room was being sold online,” he said. > But it wasn’t just one video, and not just one hospital. Investigators soon found that several clips from CCTV footage of women patients in the labour room were being sold on closed Telegram groups, with “trailer” clips advertised on YouTube for potential “buyers”. Prices ranged from Rs 800 to Rs 2,000, depending on the nature of the content. > Staff and patients at the hospital were questioned for days, and CCTV footage was scanned for clues. “The police were here for three-four days,” the hospital administrator said. “They interviewed staff, took our electronic gadgets and spoke to patients… We cooperated, we even went to Ahmedabad a couple of times as part of the investigation. Eventually, they concluded that the CCTV system had been hacked from outside the hospital.” > On February 18, 2025, the Ahmedabad City Cybercrime Branch found videos on three YouTube channels. They wrote to Google seeking details of the operators of the channels, and following a prompt response from Google, identified people based in Maharashtra and Uttar Pradesh. > Teams were sent to both states, and three accused were apprehended. At a press conference on February 19, 2025, Ahmedabad City Police Joint Commissioner (JCP) Sharad Singhal, DCP (Cybercrime) Lavina Sinha, and DCP (Crime) Ajit Rajian announced that Prajwal Ashok Teli (23) had been arrested in Latur, Maharashtra, Praj Rajendra Patil (19) in Sangli, Maharashtra, and Chandraprakash Phoolchand (33) in Prayagraj, Uttar Pradesh. > Singhal said the men used virtual numbers to communicate with hackers in Romania and Atlanta in the US. The police alleged that CCTV feeds of several hospitals, malls, and commercial buildings had been hacked. The accused allegedly clipped videos of women patients while they were being examined, uploaded snippet-like teasers on YouTube, and offered them for sale. Singhal stressed that prima facie, no hospital staff appeared to be involved. > “The phones of the arrested accused revealed contacts of the other accused persons. We also found videos, groups, and financial transactions on their electronic devices,” an investigator said. > The police unearthed 22 channels that were being run under a Telegram group, ‘Megha Demos’, where videos were categorised by “kinks” such as voyeurism and exhibitionism. Police also found several other Telegram groups — ‘Demo CCTV’, ‘CCTV Injection Group’, ‘CCTV Demo Premium’, and ‘CCTV Group’. While previews were shared on the ‘Demo Group’, videos were sold on the ‘Premium Group’, police officers said. They estimated that the accused may have earned more than Rs 8 lakh from the sale of these videos before the racket was busted. _This post is for paying subscribers only._ ### Anthropic: AI is advancing too fast to leave unchecked URL: https://www.metacurity.com/anthropic-ai-is-advancing-too-fast-to-leave-unchecked/ Last updated: 2026-06-05T12:53:35.000Z Whistleblower says IBM and AT&T hid repeated attacks from foreign hackers, Anthropic engineers are embedded in NSA, Hegseth is still determined to block Anthropic, Cloudflare CEO says agentic bots outnumber humans online, New threat group Pink uses voice phishing and fake help-desk calls, much more _This post is for paying subscribers only._ ### Five Eyes issues unusual warning on China's online recruitment tactics URL: https://www.metacurity.com/6a205e53dc19480001f9b05b/ Last updated: 2026-06-04T16:25:27.000Z Meta AI's chatbot hacking seems to have continued, OpenAI asks for mandatory models' evaluations, CISA to release AI directive tomorrow, Mullin wants CISA to hire 600 more personnel, Hackers accessed Ultrahuman's customer data, Peptide promoters seek to poison chatbots by Reddit postings, much more _This post is for paying subscribers only._ ### Trump backs voluntary AI model reviews in cybersecurity-focused executive order URL: https://www.metacurity.com/trump-backs-voluntary-ai-model-reviews-in-cybersecurity-focused-executive-order/ Last updated: 2026-06-03T13:43:39.000Z Anthropic expands Mythos distribution to 150 orgs, Researchers devise AI worm capable of creating internet chaos, Trump picks Pulte for intel czar post, Las Vegas Station Casinos was hit with a breach, Cyberattack exposed 600k food-deprived households in Gaza, much more _This post is for paying subscribers only._ ### Meta AI support flaw fueled a wave of Instagram takeovers URL: https://www.metacurity.com/meta-ai-support-flaw-fueled-a-wave-of-instagram-takeovers/ Last updated: 2026-06-02T13:33:28.000Z Russia says a large-scale spyware campaign by foreign intel targeted its high-ranking officials, Anthropic to give ENISA access to Mythos, Two men charged in nearly $8m BEC scam in NJ, 30+ npm Red Hat packages compromised in new 'Miasma' Shai-Hulud scheme, much more _This post is for paying subscribers only._ ### DOGE-aligned White House web projects funnel citizen data to analytics firm URL: https://www.metacurity.com/doge-aligned-white-house-web-projects-funnel-citizen-data-to-analytics-firm/ Last updated: 2026-06-01T18:21:11.000Z Microsoft's threat to security researcher draws criticism, Commerce IG says NIST has mismanaged NVD, Obama White House Instagram was hacked, Teen researcher flagged flaws in India's school exam board website, Gravity Bridge exploited for $5.4m, DxSale legacy site hacked for $7.3m, much more _This post is for paying subscribers only._ ### Verifying reality: Best infosec long reads 5/30/26 URL: https://www.metacurity.com/verifying-reality-best-infosec-long-reads-5-30-26/ Last updated: 2026-05-30T13:23:58.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/05/mastertux-matrix-4280571-1.jpg) Image by [MasterTux](https://pixabay.com/users/mastertux-470906/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=4280571) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=4280571) *Happy Saturday to all!* *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity achieve our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) --- **May 30:** This week's infosec long reads explore a question at the heart of cybersecurity: what happens when the systems we trust can no longer be taken at face value? From concerns about Chinese networking gear and AI models to quantum threats to encryption, Russian GPS spoofing, and a stalking case built on disputed digital evidence, each story examines the growing challenge of verifying what's real in an increasingly manipulated world. --- ### TP-Link’s American Dream The Wire China's Noah Berman [offers](https://www.thewirechina.com/2026/05/17/tp-links-american-dream/?ref=metacurity.com) an in-depth look at TP-Link's effort to reinvent itself as an American company while battling mounting, and experts say invalid, concerns in Washington that Chinese-made networking equipment could create long-term national security risks. > Over the past five years, \[TP-Link founder Jeffrey\] Chao, 57, has split TP-Link from its corporate sister in Shenzhen, which is run by his older brother Cliff. TP-Link moved its headquarters to Irvine, California, in 2024 and restructured so that its parent firm is a Delaware LLC. TP-Link has also hired hundreds of people in the United States, though it still employed more than 10,000 workers in China as of last year. Jeffrey himself is seeking U.S. citizenship. > The moves have been controversial in Washington. Multiple federal agencies, including the Department of Commerce, have investigated TP-Link, according to people familiar with the matter. > The state of Texas is suing the company over concerns about its ties to China, while Florida has subpoenaed it for similar reasons. In March, the Federal Communications Commission banned the import of future models of all foreign-made consumer routers, citing national security risks. > The measure imperils TP-Link’s future in the United States, where analysts estimate that it controls the largest share of the market. The company has a smaller share of the business and government market segments, which were not covered by the FCC’s ban. > “Although the language in the \[FCC’s\] determination is country-agnostic, the evidence clearly shows which foreign country has dominated the consumer-grade router market to date and poses an unacceptable risk to U.S. critical infrastructure security,” Senator Jim Risch (R-ID), who chairs the Senate Foreign Relations Committee and has called for a ban on U.S. sales of TP-Link products, told *The Wire China*. > TP-Link is adamant that its routers do not pose any national security risks. In an emailed reply to questions, a company spokesperson said that “virtually all consumer-grade routers are made outside the United States … the entire router industry will be impacted by the FCC’s announcement.” The company did not make Jeffrey Chao available for an interview. > The FCC rule illustrates how the Trump administration is still targeting firms with China links on national security grounds, even as it takes a softer approach to the country than many hawks had hoped. It also shows how corporate restructurings can prove insufficient to dispel worries about Beijing’s control over companies founded in China. > “The Chinese government is not interested in releasing control of their diaspora just because they incorporated a Delaware LLC,” says Dakota Cary, a consultant at cybersecurity firm SentinelOne. “I don’t think it does anything to allay concerns.” > For TP-Link, the scrutiny amounts to the most significant test in its 30-year history: can it overcome Washington’s fears about Chinese technology, or has its American makeover been all for naught? _This post is for paying subscribers only._ ### California says 23andMe ignored basic security before 7 million-user breach URL: https://www.metacurity.com/california-says-23andme-ignored-basic-security-before-7-million-user-breach/ Last updated: 2026-05-29T14:41:36.000Z Dutch cops bust up 200-server cybercrim botnet, Law firm Weil reportedly paid Silent Ransom Group $20m, Stress tests show Grok is the AI model most likely to commit crimes, Anthropic will release Mythos models to the public, GreyVibe uses AI-generated lures, much more _This post is for paying subscribers only._ ### Centcom: US war zone troops were targeted through commercial location data URL: https://www.metacurity.com/centcom-us-war-zone-troops-were-targeted-through-commercial-location-data/ Last updated: 2026-05-28T13:09:09.000Z Canada signals flexibility as tech giants fight surveillance bill, Canadian lands 30 years for child sextortion scheme, Romanian sentenced to 56 months for Oregon gov't, other hacks, Germany and France fight EC's ban of Huawei on cyber grounds, much more _This post is for paying subscribers only._ ### UK spy chief warns of escalating Russian cyber aggression URL: https://www.metacurity.com/uk-spy-chief-warns-of-escalating-russian-cyber-aggression/ Last updated: 2026-05-27T13:15:27.000Z India's banking and government institutions are testing Mythos, Charter confirms breach claimed by ShinyHunters, Play ransomware gang hit Mike Lindell's MyPillow, Fake UK visa portal exposes passports and selfies, CrowdStrike shuttered C2 for Glassworm botnet, much more _This post is for paying subscribers only._ ### White House seeks $9 billion AI chip surge for US spy agencies to tap AI models URL: https://www.metacurity.com/white-house-seeks-9-billion-ai-chip-surge-for-us-spy-agencies-to-tap-ai-models/ Last updated: 2026-05-26T13:30:57.000Z Russian penetration of US systems during SolarWinds breach was deeper than we knew, Mythos Preview users found more than 10k severe vulnerabilities, Iranian hackers were behind the LA transit system breach, Former execs plead guilty to tech support fraud scheme, much more _This post is for paying subscribers only._ ### Losing control of the systems meant to secure society - Best infosec long reads 5/23/26 URL: https://www.metacurity.com/losing-control-of-the-systems-meant-to-secure-society-best-infosec-long-reads-5-23-26/ Last updated: 2026-05-23T13:34:03.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/05/cripi-danger-2749504-1.jpg) Image by [Christelle Olivier](https://pixabay.com/users/cripi-1028451/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=2749504) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=2749504) *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity achieve our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **May 23**: This week's long reads describe a world in which technological acceleration is outpacing governance. France’s wave of massive data breaches, research showing AI voice systems can be manipulated through adversarial audio, Seattle’s sprawling public-private surveillance network, mounting conflict over global cyber governance at the UN, and warnings against treating AI development as a geopolitical arms race all point to the same underlying reality: the institutions charged with managing technological power increasingly appear unable to control the systems they have built or unleashed. ### In a tsunami of data leaks, French society remains vulnerable and authorities powerless Le Monde's Martin Untersinger, Elsa Delmas, Léa Girardot, and Léa Tanda [examine](https://www.lemonde.fr/en/pixels/article/2026/05/20/in-a-tsunami-of-data-leaks-french-society-remains-vulnerable-and-authorities-powerless%5F6753633%5F13.html?ref=metacurity.com) how France is experiencing an unprecedented wave of massive data breaches that have exposed millions of citizens’ personal information while revealing the inability of regulators and institutions to contain systemic digital insecurity. > Despite the deluge of leaks and the damage they cause, this issue remains a blind spot in French policy. Few MPs have made it a priority. On April 28, Marie-Agnès Poussier-Winsback, a center-right vice president of the Assemblée Nationale, questioned the Interior Ministry about data leaks and their possible serious consequences in terms of identity theft. "Beyond scams, the future consequences of data leaks could be terrible. We could imagine health data being sold to unscrupulous insurance companies," she predicted. > Under pressure from repeated cyberattacks and following a data leak – limited in severity but affecting a key government service, the National Agency for Secure Documents (ANTS) – Prime Minister Lecornu finally made several announcements: €200 million to strengthen the protection of digital services, redirecting fines collected by CNIL into a fund for IT modernization and merging two government agencies that manage France's public digital infrastructure. Not all experts are convinced by those promises. "I still haven't understood what the minister proposed," lamented centrist MP Philippe Latombe, who is highly active on digital issues and fears the creation of a "factory of bureaucracy." > These repeated data breaches have exposed deep vulnerabilities in both society and the state when it comes to digital security. Worryingly, they have not even been perpetrated by elite hackers, but rather by young individuals who are not necessarily very skilled technically. > That is what prosecutor Brousse emphasized after the April 25 arrest of a 15-year-old accused of hacking ANTS. "\[This teenager\] is not a prodigy. He is a warning. The cyber threat is becoming commonplace. It is up to us, collectively, to raise our level of cyber resilience," she wrote on LinkedIn. CNIL made the same observation, noting that these leaks often follow the same pattern, one that is easy to thwart. In fact, "nearly 80% of major \[data\] breaches" in 2024 became possible due to the lack of multi-factor authentication – a digital security mechanism that requires users to prove their identity using at least two types of authentication, such as entering a password on a computer and then typing in a code sent to a phone. _This post is for paying subscribers only._ ### Trump AI order dramatically collapses after Sacks-led revolt over cyber oversight URL: https://www.metacurity.com/trump-ai-order-dramatically-collapses-after-sacks-led-revolt-over-cyber-oversight/ Last updated: 2026-05-22T13:33:10.000Z EU cops dismantle cybercriminals' favorite VPN service, Edmonton partnered with ethical 'scam baiters' to stop $42m in losses, Kimwolf builder Dort arrested in Canada, The Kremlin hijacked Bluesky accounts in influence op, Google accidentally leaked details about unfixed Chromium issue, much more _This post is for paying subscribers only._ ### Trump prepares to sign AI cyber order today amid Mythos alarm URL: https://www.metacurity.com/trump-prepares-to-sign-ai-cyber-order-today-amid-mythos-alarm/ Last updated: 2026-05-21T11:54:40.000Z Cybercom to speed AI tools use, Hacker accessed GitHub repos via TanStack-compromised Nx Console VS Code extension, Ukraine cops bust 18-year-old for running infostealer op, S. Korean cops bust 32 for stealing bigwigs' financial data and PII, Microsoft issues patches for Defender flaws, much more _This post is for paying subscribers only._ ### GitHub says malicious VS Code extension compromised 3,800 internal repositories URL: https://www.metacurity.com/github-says-malicious-vs-code-extension-compromised-3-800-internal-repositories/ Last updated: 2026-05-20T13:46:04.000Z White House release of EO on cyber and AI safety is imminent, Microsoft took down malware service Fox Tempest, A bug in a Huawei enterprise router caused Luxembourg telecoms outage last year, Mini Shai-Hulud malware resurfaces across hundreds of npm packages, much more _This post is for paying subscribers only._ ### Anthropic eases threat-sharing rules as Cloudflare details frontier AI cyber gains URL: https://www.metacurity.com/anthropic-eases-threat-sharing-rules-as-cloudflare-details-frontier-ai-cyber-gains/ Last updated: 2026-05-19T14:21:56.000Z CISA contractor exposed sensitive gov't creds in public GitHub repo, Buterin says AI-assisted formal verification can secure blockchain systems, NY public health provider says breach affects 1.8m, FBI wants access to ALPRs nationwide, Interpol busts 200+ people for cybercrime in MENA, much more _This post is for paying subscribers only._ ### Leaders warn that AI bug hunting outpaces humanity’s ability to defend systems URL: https://www.metacurity.com/leaders-warn-that-ai-bug-hunting-outpaces-humanitys-ability-to-defend-systems/ Last updated: 2026-05-18T14:15:39.000Z Malware strain Fast16 sabotaged nuclear weapons development years before Stuxnet surfaced, Grafana Labs rejected hackers' extortion demand, DeFi protocol Verus lost nearly $12m in ongoing exploit, Hotel check-in system left 1m passports exposed, Gas station gauge systems hacked, much more _This post is for paying subscribers only._ ### AI and the collapse of authenticity: Best infosec long reads 5/16/26 URL: https://www.metacurity.com/ai-and-the-collapse-of-authenticity-best-infosec-long-reads-5-16-26/ Last updated: 2026-05-16T13:32:10.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/05/d6ecbaf4-54a8-4bb5-a057-d1c7cd494ce9-1.png) *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity achieve our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **May 16**: This week's long reads describe a world in which artificial intelligence is steadily eroding the boundary between what is authentic and what is synthetic. The Bloomberg piece shows how AI is making identity itself forgeable through cloned voices, fake documents, and synthetic personas. The MIT Technology Review article explores how deepfake pornography can overwrite reputations and lived experience with fabricated but convincing imagery. The HAUNT paper demonstrates that large language models will often reinforce falsehoods and even collaborate in invented memories when gently nudged by users, prioritizing conversational harmony over factual accuracy. The Quanta article suggests that even the mathematical foundations of digital security are becoming increasingly opaque and difficult for humans to understand intuitively, while the UnHerd essay captures the growing cultural unease surrounding systems that are persuasive, fluent, and only partially comprehensible. What connects all of these stories is not simply “AI risk,” but a broader crisis of authenticity and trust. The internet created an information overload problem; AI is creating an authenticity problem, where simulation becomes easier to generate than verification. Increasingly, humans are interacting with systems optimized not for truth, but for fluency, engagement, personalization, and emotional resonance. ### AI Is Making Digital Fraud Easier, Faster and Harder to Stop Bloomberg's Jennah Haque [argues](https://www.bloomberg.com/graphics/2026-ai-identity-theft-scams/?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc3ODI0ODEzOCwiZXhwIjoxNzc4ODUyOTM4LCJhcnRpY2xlSWQiOiJURVBOT0dLSUpIQ1owMCIsImJjb25uZWN0SWQiOiIyMkJBREVGRDU5QjI0ODg5OEIwMzhBNUZGMjA1NzlFOCJ9.3mbrsg8DpR9QgdSzUUv-zPEoLhh7M507HyhsyinvxYo&ref=metacurity.com) that AI has industrialized identity theft by enabling criminals to automate phishing, generate convincing synthetic identities, clone voices and documents, and rapidly exploit breached personal data at a scale that is overwhelming traditional fraud defenses and exposing weaknesses in digital trust systems. > Today’s digital ecosystem creates the perfect storm for identity theft. AI makes every step — from stealing personal information held by companies to finding the right Social Security Number to steal to faking a driver’s license — easier and more sophisticated. > Some AI research labs are already acting with an abundance of caution due to fears of cyberattacks. Anthropic PBC is rolling out its new model, Mythos, to a select group of companies for testing against their own products and looking for vulnerabilities. Mythos is able to find loopholes in all sorts of operating systems, even exploiting Linux, the open-source code that powers most smart TVs, cars and other electronics, according to employees at Anthropic. OpenAI is also shopping its equivalent model around for companies to test. > When one researcher at Anthropic tested Mythos, they found it was able to pull off the equivalent of a digital bank robbery. The cautionary tales from Anthropic are prompting government officials to send up a flare to the financial sector. > The US saw the highest number of data compromises in 2025 since the nonprofit Identity Theft Resource Center (ITRC) began recording in 2005\. AI is already a powerful force in cybercrimes: 40% of the 5,000 data breaches that consumer credit agency Experian serviced last year were powered by AI, said Michael Bruemmer, vice president of Consumer Protection. The firm predicts that this year agentic AI, deploying multiple autonomous agents to achieve sophisticated goals with limited human oversight, will be the number one cause of data breaches. > However, its powers go beyond just infiltration of institutional systems; agentic AI has also sharpened the urgency of identity theft and digital fraud cases: Subagents can scan the dark web for vulnerable Social Security numbers and personal information in seconds. Simultaneous attacks can occur by contacting multiple banks at a time impersonating a different identity, and agents can fill out complex government forms requesting loans. In February, a hacker used Anthropic’s Claude chatbot to attack various government agencies in Mexico, retrieving sensitive voter and tax information. > Cases of identity theft reported to the Federal Trade Commission have shot up nearly 20% year over year. US Head of Fraud at TransUnion Naureen Ali said globally more than $534 billion is lost to fraud annually. > Bruemmer outlined how AI has made these scams lethal: “AI does three things. It makes it faster for the hackers, attacks are more sophisticated and they’re better looking attacks. A phishing email from two or three years ago looks much different today, whether it’s with ChatGPT or Microsoft Copilot. They’re easily evading most people’s detection.” > I have gotten several data breach exposure letters over the years, ranging from random parking apps to companies as big as Meta, explaining that my information had been exposed. The letters have tended to disclose what was leaked: email, phone number, credit card information. The companies offer to pay for credit monitoring for six months, but nothing ever actually happens with that data, right? _This post is for paying subscribers only._ ### AI bug hunters expose new weak point in Apple’s locked-down macOS URL: https://www.metacurity.com/ai-bug-hunters-expose-new-weak-point-in-apples-locked-down-macos/ Last updated: 2026-05-15T13:30:57.000Z Shai-Hulud attack campaign hit two OpenAI employees, Hackers unwisely targeted Amnesty International's Security Lab chief, US and China to discuss AI guardrails, Anthropic warns of CCP AI dominance, DPRK's APT 37 is now posing as cops, MSFT warns of severe XSS flaw for Outlook web users, much more _This post is for paying subscribers only._ ### AI cyber skills now doubling in months, not years URL: https://www.metacurity.com/ai-cyber-skills-now-doubling-in-months-not-years/ Last updated: 2026-05-14T13:14:55.000Z Microsoft's AI-driven MDASH system discovered 16 new Windows vulnerabilities, France's Mistral AI competes with Mythos for European banks, Dream Market admin busted by German and US cops, Shadowy firm BlackCore probed for French election interference, Signal to exit Canada if C-22 passes, much more _This post is for paying subscribers only._ ### OpenAI gives advanced cyber models to European defenders URL: https://www.metacurity.com/openai-gives-advanced-cyber-models-to-european-defenders/ Last updated: 2026-05-13T13:23:11.000Z Anthropic denied Chinese think tank Mythos access, Pentagon will use Mythos while moving ahead with Anthropic ban, House panel wants Instructure hearing, Nitrogen group hit Foxconn with cyberattack, West Pharmaceutical Services hit with ransomware, Microsoft issues 120 Patch Tuesday fixes, much more _This post is for paying subscribers only._ ### Instructure forms deal with ShinyHunters who promise to destroy stolen Canvas data URL: https://www.metacurity.com/instructure-reaches-deal-with-shinyhunters-who-promise-to-destroy-stolen-canvas-data/ Last updated: 2026-05-12T13:25:12.000Z US intel agencies want to evaluate AI model while Commerce seems to back away, OpenAI launches cybersecurity model Daybreak, Euro countries sell spyware to rights violators, Binance claims AI system saved $10b in scam losses, Shai-Hulud supply-chain campaign compromised npm and PyPi packages, more _This post is for paying subscribers only._ ### Pre-release discount: Practical risk management using the NIST CSF 2.0 URL: https://www.metacurity.com/pre-release-discount-practical-risk-management-using-the-nist-csf-2-0/ Last updated: 2026-05-11T20:09:31.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/05/newcoverpng-1.png) Dearest subscriber, I’m pleased to announce that my new book, *The NIST 2.0 Cybersecurity Framework: Practical Risk Management Using Real-World Incidents*, is now available for pre-order from [Wiley](https://www.wiley.com/en-us/The+NIST+2.0+Cybersecurity+Framework%3A+Practical+Risk+Management+using+Real-World+Incidents-p-9781394352180?utm%5Fsource=chatgpt.com) (and wherever books are sold) at a 20% pre-release discount for a limited time. The book is designed to help organizations move beyond cybersecurity theory and focus on the practical fundamentals of cyber risk management — the controls, governance, identity management, monitoring, incident response, and operational disciplines that repeatedly determine whether real-world attacks succeed or fail. Rather than treating cybersecurity as an abstract compliance exercise, the book uses major incidents and breaches to show how foundational security failures continue to create outsized risk for enterprises, governments, and critical infrastructure operators. Topics include: - Real-world case studies from Microsoft, Ticketmaster, MGM Resorts, Caesars Entertainment, and other organizations that illustrate practical applications of the NIST framework - Implementation guidance covering all six NIST functions: Identify, Protect, Detect, Respond, Recover, and Govern - Chapter summaries and quizzes that reinforce learning objectives and help readers assess their understanding - Clear and concise explanations of how to achieve the outcomes articulated across the NIST categories and subcategories **For organizations interested in workforce training, executive education, or enterprise-wide cyber awareness initiatives, the book can also be custom-tailored for bulk programs and institutional deployments.** Available options include: - Bulk discount pricing for print, digital, eBook, and audiobook formats - Company or institutional branding, including logos and custom forewords - Additional pages or tailored messaging for internal initiatives - Custom mini-books using selected portions of the content - Curated collections of titles for cybersecurity upskilling and training - Licensing for learning management systems (LMS) and online training environments - Global fulfillment and enterprise delivery support If you are interested in bulk orders, training programs, or customized editions for your organization, feel free to contact me directly. And if you’d simply like to support the work, you can pre-order the book here: [The NIST 2.0 Cybersecurity Framework: Practical Risk Management Using Real-World Incidents](https://www.wiley.com/en-us/The+NIST+2.0+Cybersecurity+Framework%3A+Practical+Risk+Management+using+Real-World+Incidents-p-9781394352180?utm%5Fsource=chatgpt.com) Thank you, as always, for reading Metacurity. Stay safe and sane out there. Warmest regards, Cynthia Brumfield ### Hackers turned to AI in attempted mass cyberattack, Google reveals URL: https://www.metacurity.com/hackers-turned-to-ai-in-attempted-mass-cyberattack-google-reveals/ Last updated: 2026-05-11T13:45:57.000Z Trump's planned AI-enabled cyber EO stops short of requirements, German authorities shut down relaunched Crimenetwork, L3 Trenchant zero-day peddling exec order to pay $10m, Poland has thwarted many Russian sabotage efforts, IMF warns of financial shock from AI-enabled cyberattacks, much more _This post is for paying subscribers only._ ### How ordinary tech becomes surveillance infrastructure: Best infosec long reads 5/9/26 URL: https://www.metacurity.com/next-long-read-9/ Last updated: 2026-05-09T13:21:50.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/05/pexels-marcelochagas-1893264-1.jpg) Photo by [Marcelo Chagas](https://www.pexels.com/photo/woman-lying-down-on-grass-beside-opened-books-1893264/?ref=metacurity.com) *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity achieve our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **May 9:** This week's long readsexplore how modern technology is quietly reshaping surveillance from something targeted and exceptional into something ambient and embedded within ordinary life. The Haaretz investigation into telecom tracking, the hacked robotic lawn mower, and the Aeon essay on devices “having jobs” all point to the same unsettling reality: systems originally designed for convenience, connectivity, or automation increasingly double as tools for observation and behavioral monitoring. They also share a deeper concern about invisible infrastructure. Much of the power described in these stories operates below public awareness — inside telecom signaling protocols, AI systems, metadata, connected devices, and networked platforms. Rather than relying on dramatic breaches, these systems derive power from quietly collecting and correlating fragments of everyday activity until intimate patterns emerge. Even the Quanta piece on frightening AI narratives fits within this theme. It suggests that public anxiety around AI is not simply fear of futuristic machines, but an instinctive recognition that technological systems are becoming more autonomous, interpretive, and difficult to see or control. These articles sketch a world in which the real cybersecurity challenge is no longer just protecting data, but understanding how ordinary digital systems are evolving into pervasive infrastructures of inference and visibility. ### Ghost Operators: How Israeli Telecoms Were Exploited to Track Citizens Worldwide Haaretz's Omer Benjakob [walks through](https://www.haaretz.com/israel-news/security-aviation/2026-05-03/ty-article-magazine/ghost-operators-how-israeli-telecoms-were-exploited-to-track-citizens-worldwide/0000019d-e9c0-dd9a-a79d-ede90a450000?ref=metacurity.com) how Citizen Lab research showed that Israeli telecom infrastructure and surveillance capabilities were allegedly leveraged to covertly track individuals around the world through weaknesses and backdoor access within mobile networks. > The report describes two separate tracking operations, each likely run by a commercial firm selling surveillance technologies to governments around the world. One was also found to have exploited Israeli geolocation technology to track targets, using networks belonging to 019Mobile and Partner Communications, although both Israeli companies denied any involvement. > A second, more sophisticated operation is linked to a Swiss firm at the center of a 2023 Haaretz investigation for supplying Israeli surveillance companies, including Rayzone, which develops and sells cyber intelligence technologies to government agencies around the world. > The investigation found that the Swiss telecom company allowed companies like Rayzone to impersonate cellular carriers and connect to legacy mobile networks in order to track users worldwide, exploiting an older telecom signaling protocol called SS7 for surveillance purposes. SS7 was originally designed to route calls and text messages, enable international roaming, and connect different mobile operators. > British regulators banned the practice last week in an effort to crack down on tracking spyware, after more than a decade of investigative reporting on its abuse, calling the practice the largest source of malicious traffic to mobile networks. > Moreover, Citizen Lab's findings show that newer signalling systems – introduced to strengthen security measures – are being similarly exploited by spyware firms, despite being designed to mitigate security risks and prevent surveillance. > One example is Diameter, a mobile network system that handles 4G international roaming and most 5G networks, designed to streamline cellular connectivity to the internet, which was now shown to be susceptible to tracking spyware. > In the first operation uncovered by Citizen Lab, researchers logged more than 500 location-tracking attempts between November 2022 and 2025 across Thailand, South Africa, Norway, Bangladesh, Malaysia and several other African countries. The investigation began with a single subscriber: a Middle East businessman tracked methodically over four hours in an episode that opened the door to the broader pattern researchers later mapped: a company querying the international phone system on behalf of clients to follow targets. > An Israeli carrier, 019Mobile, was used in the operation. According to information obtained by Haaretz, dozens of separate tracking attempts appear to have passed through 019's servers - requests that did not look like legitimate communications but like surveillance. Every mobile network has a unique address – similar to a website address – that other telecom companies use to route calls and data traffic. Citizen Lab found that addresses registered to 019 were used to send location-tracking requests through Partner Communications, whose infrastructure 019 relies on. Another route passed through Exelera Telecom, an Israeli company that provides cloud and communications services, including an international undersea fiber-optic cable. Exelera did not respond to Haaretz's request for comment. _This post is for paying subscribers only._ ### Canvas chaos: ShinyHunters breach throws schools into disarray URL: https://www.metacurity.com/canvas-chaos-shinyhunters-breach-throws-schools-into-disarray/ Last updated: 2026-05-08T13:47:46.000Z Firefox bug fixes soar after using Mythos, Virginia man found guilty of destroying government databases, OpenAI rolls out GPT 5.5 to vetted cyber defenders, PCPJack steals cloud creds while removing TeamPCP access, Ivanti urges patches for Endpoint Manager Mobile (EPMM) zero day bug, much more _This post is for paying subscribers only._ ### Russia’s hidden hacker academy exposed in massive document leak URL: https://www.metacurity.com/russias-hidden-hacker-academy-exposed-in-massive-document-leak/ Last updated: 2026-05-07T13:55:03.000Z US-China weigh AI risk talks, Wiles says Trump won’t pick AI winners, Vibe-coded apps lack security, GothFerrari fraudster gets 78 months, MuddyWater masks ops as Chaos ransomware, Phishing hits ManageWP via Google-sponsored search ads, Japan urges CI to do cyber better, much more _This post is for paying subscribers only._ ### US taps Microsoft, Google, xAI for pre-release AI testing as threat worries grow URL: https://www.metacurity.com/us-taps-microsoft-google-xai-for-pre-release-ai-testing-as-threat-worries-grow/ Last updated: 2026-05-06T14:10:04.000Z FTC to ban Kochava from selling location data, State officials urge AI companies to include them in early-access testing, CISA wants CI firms to plan for essential service disconnection, DAEMON Tools software delivered backdoor to thousands, Breach forced Coupang to lose money, much more _This post is for paying subscribers only._ ### Trump eyes AI crackdown after hands-off push falters URL: https://www.metacurity.com/trump-eyes-ai-crackdown-after-hands-off-push-falters/ Last updated: 2026-05-05T14:21:07.000Z EU is talking with Anthropic to test banks with Mythos, DHS intelligence office staff failed to secure smartphones, A Latvian was sentenced to 8.5 years for role in Karakurt ransomware, A Romanian was indicted for bank fraud scheme dating to 2009, CISA unveils CI Fortify for CI entities, much more _This post is for paying subscribers only._ ### Five Eyes warn that agentic AI is already in critical systems—and security isn’t keeping up URL: https://www.metacurity.com/five-eyes-warn-that-agentic-ai-is-already-in-critical-systems-and-security-isnt-keeping-up/ Last updated: 2026-05-04T13:29:59.000Z Trellix hit by significant breach, 15-year-old was busted for French gov't hack, CISA warns of Copy Fail exploits in the wild, Defender flags some legit DigiCert root certs as malware, Sri Lanka arrests 37 Chinese cyberscam operators, US health insurance exchanges share data with big tech, much more _This post is for paying subscribers only._ ### The new infosec battleground is human: This week's best infosec long reads 5/2/26 URL: https://www.metacurity.com/the-new-infosec-battleground-is-human-this-weeks-best-infosec-long-reads-5-2-26/ Last updated: 2026-05-02T12:37:27.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/05/Woman_reading_the_Quran_during_Ramadan_in_Cairo-_Egypt-1.jpg) Source: [مصطفى الشربجى](https://commons.wikimedia.org/w/index.php?title=User:%D9%85%D8%B5%D8%B7%D9%81%D9%89%5F%D8%A7%D9%84%D8%B4%D8%B1%D8%A8%D8%AC%D9%89&action=edit&redlink=1&ref=metacurity.com "User:مصطفى الشربجى (page does not exist)") *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity achieve our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) **May 2**: Taken together, this week’s long reads point to a clear shift in infosec from a discipline focused on systems and software to one increasingly defined by the targeting, manipulation, and surveillance of people, where governments, criminals, and even defenders are all operating in a blurred environment shaped by AI, data aggregation, and psychological leverage. A few common threads emerge: First, surveillance is no longer episodic or exceptional—it’s ambient and industrialized. The IFJ and ICIJ pieces show that journalists are being persistently monitored through a mix of spyware, impersonation, and coordinated intelligence tactics, while the WSJ reporting suggests a similar normalization of large-scale surveillance in US domestic immigration enforcement. Second, identity has become a primary attack surface. Whether it’s fake journalists targeting reporters, scammers impersonating officials to exploit migrants, or jailbreakers probing AI systems by mimicking malicious intent, the throughline is that trust itself is being systematically weaponized. Technical compromise is often secondary to social and psychological manipulation. Third, AI is accelerating both offense and defense—but not symmetrically. The Guardian piece shows how even those trying to secure AI systems must immerse themselves in the worst outputs imaginable, while the IEEE Spectrum article highlights how foundational technical fixes like memory-safe code are still catching up to an environment where exploitation can be automated and scaled. Finally, there’s a growing asymmetry of burden: individuals—journalists, migrants, researchers—are expected to absorb the risk created by these systems. They are the ones being surveilled, deceived, or psychologically strained, while institutions struggle to keep pace or, in some cases, actively contribute to the environment. ### Global Surveillance of Journalists: A Technical Mapping of Tools, Tactics, and Threats For the International Federation of Journalists (IFJ), Samar Al Halal and Lukasz Olejnik [report](https://www.ifj.org/fileadmin/Global%5FSurveillance%5Fof%5FJournalists%5F-%5F%5FA%5FTechnical%5FMapping%5Fof%5FTools%5F%5FTactics%5F%5Fand%5FThreats%5FJD%5F210426.docx.pdf?ref=metacurity.com) that surveillance of journalists has evolved into a global, systemic industry—combining commercial spyware, state intelligence, and AI-driven data analysis—creating pervasive risks that undermine press freedom and accountability. > Over the past decade, digital surveillance targeting journalists has shifted from scattered, state-run monitoring to a full-fledged commercial industry that spans continents. > This study, commissioned by the International Federation of Journalists (IFJ), investigates the technical infrastructure behind this transformation and the human consequences it produces. Drawing on interviews with cybersecurity experts, forensic analysts and journalists from diverse parts of the world, as well as technical documentation and verified investigations between 2021 and 2025, it paints a detailed picture of how the act of reporting has become intertwined with the risk of being watched, tracked or hacked. > The findings show that surveillance against journalists is now industrial in scale. Sophisticated spyware, once reserved for military intelligence – such as Pegasus, Predator and Graphite – has been repackaged as ‘lawful intercept’ technology and marketed to governments around the world. These tools give their operators the power to penetrate phones and computers silently, reading encrypted conversations, listening through microphones, and extracting data in real time. Pegasus, developed by Israel’s NSO Group, and Predator, a product of the European Intellexa alliance, are among the most well-known examples, but they are only part of a broader ecosystem. Surveillance programmes have been deployed against journalists in democracies and authoritarian states alike. The reasons invoked for these actions are often vague, insufficiently substantiated, or not made public. > Technically, the ecosystem is layered and global. Spyware vendors exploit vulnerabilities in phones and messaging apps, bypassing encryption entirely by taking control of the device itself. Telecom infrastructure adds another dimension: weaknesses in the SS7 and Diameter protocols make it possible to locate, intercept and clone mobile communications without a trace. Deep Packet Inspection and network-injection systems allow service providers or governments to tamper with web traffic, redirecting users to malware-laden sites or filtering entire categories of information. Forensic tools such as Cellebrite and Oxygen Forensics, commonly used in police work, can clone a seized device within minutes, sometimes before reinstalling spyware to maintain long-term access. Increasingly, the data harvested through these mechanisms is fed into artificial intelligence (AI) dashboards that correlate calls, messages, geolocation data, and online activity –automating surveillance at a scale once unimaginable. In conflict zones, AI systems now fuse telecom and drone feeds to identify and track journalists, blurring the line between observation and physical targeting. _This post is for paying subscribers only._ ### GPT-5.5 aces UK cyber trials, tops rivals in AISI tests URL: https://www.metacurity.com/gpt-5-5-aces-uk-cyber-trials-tops-rivals-in-aisi-tests/ Last updated: 2026-05-01T14:06:15.000Z NSA is testing Mythos, Anthropic publishes Claude Security for Claude Enterprise, Flock spied on a kid's gym room, DPRK hackers have stolen $577m in crypto year-to-date, Rhysida demands ransom from Stelia Aerospace NA, Two ransomware negotiators sentenced to prison, much more _This post is for paying subscribers only._ ### Nine Dubai scam centers raided in joint US-China operation, 276 arrested URL: https://www.metacurity.com/nine-dubai-scam-centers-raided-in-joint-us-china-operation-276-arrested/ Last updated: 2026-04-30T13:34:18.000Z White House opposes Anthropic's expansion of Mythos access, Oz government warns banks on AI cyberattacks, Ukraine arrests three people who allegedly hacked 610k+ Roblox accounts, European celebrity exposed cloud repo with 90k stalkerware screenshots, Chinese hackers breached Cuba's embassy, more _This post is for paying subscribers only._ ### Scattered Spider’s ‘Bouquet’ nabbed after globe-trotting luxury hacker spree URL: https://www.metacurity.com/scattered-spiders-bouquet-nabbed-after-globe-trotting-luxury-hacker-spree/ Last updated: 2026-04-29T14:05:53.000Z White House is trying to get Anthropic back on board while lawmakers come up to speed, Paragon not cooperating with Italian prosecutors, Polymarket denies breach reports, Syndicate was hacked for about $400k, FIDO Alliance forms AI agent standards groups, Vimeo admits breach through, much more _This post is for paying subscribers only._ ### Social media scams cost Americans $2.1 billion — and Facebook leads the pack URL: https://www.metacurity.com/social-media-scams-cost-americans-2-1-billion-and-facebook-leads-the-pack/ Last updated: 2026-04-28T13:51:57.000Z Medtronic hit by cyberattack, Toronto cops busted three people in connection with SMS blasters, Handala claims to have stolen personal info on 2,379 US Marines, Google agrees to Pentagon's anything goes for its AI but employees beg it not to, New BlackFile data theft group emerges, much more _This post is for paying subscribers only._ ### Italy hands alleged Chinese hacker to US, drawing Beijing’s protest URL: https://www.metacurity.com/italy-hands-alleged-chinese-hacker-to-us-drawing-beijings-protest/ Last updated: 2026-04-27T13:52:47.000Z FCC says router ban to cover Wi-Fi hotspots, German gov't blames Russia for phishing attacks, S.Ct. to hear geofence warrant case, Manitoba to ban youth from social media, ADT confirms data breach after ShinyHunters threat, US possible culprit in Venezuelan oil firm cyberattack, much more _This post is for paying subscribers only._ ### Best infosec long reads 4/25: Power moves fastest where institutions fail URL: https://www.metacurity.com/next-long-read-8/ Last updated: 2026-04-25T11:44:53.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/pexels-guillermo-berlin-1524368912-34870716--1--1.jpg) Source: [Guillermo Berlin](https://www.pexels.com/@guillermo-berlin-1524368912/?ref=metacurity.com) *Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity achieve our goal by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) --- **April 25:** This week's long reads are about power concentrating wherever institutions or power are weakest, slowest, or least prepared to respond. In Cambodia, that means criminal syndicates operating as parallel economic and political forces, with cyber fraud becoming both an industry and a source of elite protection. In Iran, it means the state exercising control by deciding whether citizens can connect to the outside world at all, turning internet access itself into an instrument of power. When it comes to child exploitation, it is about the sudden empowerment of predators through cheap, scalable generative tools that allow abuse to expand faster than law enforcement or legal frameworks can keep pace. A debate over US military cyber operations highlights a bureaucracy struggling to adapt to a domain where speed, technical expertise, and specialization matter more than traditional command structures. Even the fight over a privacy-oriented mobile OS reflects the same theme: a tool built to defend people from institutional surveillance becomes vulnerable to the personal conflicts and failures of the people behind it. Another common thread is that “cyber” is no longer a niche technical beat. These stories are about labor trafficking, authoritarian control, child safety, military force design, and personal autonomy. Cybersecurity is not the subject so much as the mechanism through which larger political and social struggles now play out. Happy reading! --- ### How Cybercrime Became a Leading Industry in ‘Scambodia’ Gabriele Steinhauser and Patricia Kowsmann in The Wall Street Journal [report ](https://www.wsj.com/world/asia/cambodia-cybercrime-rise-why-2f2c03cc?st=tL8LBy&reflink=desktopwebshare%5Fpermalink&ref=metacurity.com)that Cambodia has become so deeply entwined with industrialized online fraud—run largely by Chinese-linked criminal syndicates with protection from political elites—that cybercrime now functions as one of the country’s most lucrative shadow industries, generating an estimated $19 billion a year. > Hun Sen, who had been Cambodia’s prime minister since 1985, hosted former President Joe Biden, China’s premier and Southeast Asian leaders in November 2022\. To mark the occasion, Hun Sen, an aficionado of luxury watches, gave each leader a $20,000 limited-edition timepiece—donated by Chen Zhi, whose staggering wealth helped gain him entry into Cambodia’s political elite. A Biden spokesman declined to comment. > Like Xu, the sanctioned developer of the Phnom Penh skyscraper, Chen was an émigré from China and a naturalized Cambodian citizen. Within about a decade of his arrival in 2009, Chen had plowed hundreds of millions of dollars into Cambodian real estate, a bank, an amusement park and supermarkets. Companies that the U.S. Treasury alleges were controlled by Chen and his Prince Group conglomerate ran hotels and casinos in the seaside city of Sihanoukville—and a bespoke watchmaker. > In 2020, Cambodia’s king had bestowed upon Chen the title of neak oknha, similar to a lordship. The same year, the prime minister appointed Chen—who was then 32 years old and spoke only basic Khmer—as an official adviser, a post on the level of a minister. > By the time of the 2022 summit, Cambodia-based activists said in interviews that they had fielded calls from men and women who said they were forced to run scams while confined in casinos, hotels and industrial parks the U.S. alleges were operated by Prince Group. > Despite mounting warnings about Chen and his Prince Group companies, Hun Sen’s son, Hun Manet, retained Chen as an adviser when he succeeded his father as prime minister in 2023\. > A spokesman for the Prince Group companies said Chen made his fortune through legitimate investments in real estate and other assets and that neither he nor Prince Group owned or operated buildings in which online-scam operations or other crimes took place. > Cambodia has been fertile ground for cybercrime, analysts say: It has fast internet, the economy runs mostly on the dollar and top government posts often pass within families from one generation to the next. > Activists and family members trying to free scam workers forced to work at Cambodian scam centers say they struggled to get police to intervene, even when they gave exact locations. When police did act, they often freed only the people who had been reported, leaving behind hundreds or thousands of others held in the same compounds. _This post is for paying subscribers only._ ### China’s hackers hide in plain sight through hijacked home routers, allies warn URL: https://www.metacurity.com/chinas-hackers-hide-in-plain-sight-through-hijacked-home-routers-allies-warn/ Last updated: 2026-04-24T14:23:47.000Z US charges two accused of running major scam compound, White House accuses China of stealing AI property on 'industrial scale,' Stuxnet-like code was used in mid-2000s, Health info from UK Biobank was posted for sale in China, Indian media giant was hacked by an alleged Afghan group, much more _This post is for paying subscribers only._ ### Plankey pulls out after a year-long CISA director confirmation stall URL: https://www.metacurity.com/plankey-pulls-out-after-a-year-long-cisa-director-confirmation-stall/ Last updated: 2026-04-23T14:23:08.000Z Chinese cyber firm is looking to compete with Anthropic, 100+ companies have cyber intrusion software, OpenAI lobbied US agencies on its new cyber model, Cybercrims hacked phone of Bundestag President, Sri Lanka's Finance Ministry was hacked, Dutch cosmetics giant Rituals was breached, more _This post is for paying subscribers only._ ### Mythos model slips into the wild through vendor backdoor URL: https://www.metacurity.com/mythos-model-slips-into-the-wild-through-vendor-backdoor/ Last updated: 2026-04-22T14:37:21.000Z Mozilla says Mythos ID'ed 271 vulnerabilities, Australia, New Zealand and Japan are monitoring Mythos, NCSC chief warns of a perfect storm of cyberattacks, Supplier attack exposes exposed details of potential school shooters and bullies, Former FBI cyber chief calls ransomware terrorism, much more _This post is for paying subscribers only._ ### Ransomware negotiator cops to conspiring with cybercrims against US companies URL: https://www.metacurity.com/ransomware-negotiator-cops-to-conspiring-with-cybercrims-against-us-companies/ Last updated: 2026-04-21T14:07:57.000Z NSW official charged in data breach involving sensitive documents, UK man faces 22 years in US prison for $8m hacking scheme, French gov't identity website hack might have exposed users' data, Bundesbank president wants level playing field for Mythos, Lovable downplays data exposure, much more _This post is for paying subscribers only._ ### White House opens backchannel to Anthropic as Pentagon fight simmers URL: https://www.metacurity.com/white-house-opens-backchannel-to-anthropic-as-pentagon-fight-simmers/ Last updated: 2026-04-20T13:51:00.000Z Anthropic gave NSA access to Mythos Preview, Anthropic's donation to open source developers highlights how under-sourced they are, Asian regulators urge banks to use Mythos, LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit, much more _This post is for paying subscribers only._ ### Best infosec long-reads 4/18: The gap between capability and accountability is widening URL: https://www.metacurity.com/best-infosec-long-reads-4-18-the-gap-between-capability-and-accountability-is-widening/ Last updated: 2026-04-18T10:46:53.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/pexels-imadbo-7462319--1--1.jpg) Photo by[ Imad Bo from Pexels](https://www.pexels.com/photo/man-in-black-shirt-and-pants-sitting-on-bed-reading-book-7462319/?ref=metacurity.com). ### *Important publishing notice* *This is the first week that full access to our curated infosec long reads moves behind a subscriber paywall. The goal is simple: to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.* *Please help support Metacurity today by upgrading your subscription to gain full access to this issue and all content published on Metacurity, including the archives.* [Upgrade my subscription](#/portal/account/plans) --- **April 18:** This week's selection of long reads shares a single throughline: the divide between cybersecurity capability and accountability is widening, and almost every story lives in that gap. Nation-state information operations are growing more culturally fluent — harder to detect, not because they're technically sophisticated, but because they've gotten better at sounding human. AI is accelerating vulnerability discovery faster than organizations can triage what they find. And the same tools enabling low-cost automation are enabling high-cost harm: student-driven deepfake abuse is no longer a fringe problem. Meanwhile, the threat surface inside organizations keeps expanding. Fast-growing startups, legacy institutions, iconic venues — none of them have figured out insider risk at scale. Fraud is increasingly hard to distinguish from policy. And surveillance practices that would have once risen to the level of nation-state intelligence operations are now just... HR. The through-line in 2026 isn't any single threat. It's that the tools' expanding capability — AI, data collection, globalized labor, networked influence — are outrunning the governance meant to contain them. Enjoy this week's selection of the best infosec-related long reads. --- ### How Anthropic Learned Mythos Was Too Dangerous for the Wild Bloomberg's Margi Murphy, Jake Bleiberg, and Patrick Howell O’Neill [detail](https://www.bloomberg.com/news/features/2026-04-16/how-anthropic-discovered-mythos-ai-was-too-dangerous-for-release?embedded-checkout=true&ref=metacurity.com) how Anthropic concluded its Mythos AI model was too dangerous to release after internal testing showed it could identify and potentially exploit critical vulnerabilities across modern computing systems. (Bloomberg's tech team also [focused on](https://www.bloomberg.com/sessions/2026-04-17/live-q-amp-a-anthropic-s-mythos-ushers-in-dangerous-new-ai-era?ref=metacurity.com) how the Mythos model is ushering in a new "dangerous" era during a live Q and A session.) > Anthropic hasn’t publicly released Mythos as a cybersecurity tool, and many outside researchers haven’t had a chance to validate the company’s claims. But Anthropic's unprecedented decision to gate access reflects a growing view inside the industry and government that AI is changing cybersecurity economics by reducing the cost of finding vulnerabilities, compressing the time needed to investigate targets and lowering the skill barrier for certain types of attacks. > Anthropic warns that Mythos’s ability to act with greater autonomy comes with risk. In testing an earlier version of the model, they found dozens of examples of “concerning” behavior, including not following human direction and even, in rare cases, covering its tracks when violating human instructions. In one incident, the model developed a multi-step exploit to escape the limited environment it was inside to gain broad access to the internet and begin to publish material online, all on its own initiative. > The software that now underpins everything from banking apps to hospital systems is laced with obscure coding flaws that trained specialists spend weeks or months trying to identify. Occasionally hackers get there first, resulting in data breaches and ransomware attacks that can have devastating consequences. > High-profile names have been quick to question just how powerful Mythos really is, or how much of a risk it would pose if released. > “A growing number of people are wondering if Anthropic is the AI industry’s ‘boy who cried wolf,’” White House AI advisor David Sacks wrote on the social media site X. “If Mythos-related threats don’t materialize, the company will have a serious credibility problem.” > But hackers have already adopted large language models to launch complex malicious campaigns. A Chinese cyber-espionage group already used Anthropic’s Claude to try breaching roughly 30 targets, while other attackers have used AI to steal data from government agencies, deploy ransomware and quickly break into hundreds of firewall tools meant to safeguard data. > Among US government officials focused on national defense, the introduction of Mythos has created profound uncertainty about how to evaluate cybersecurity risk, according to a person familiar with the matter. Equipping an individual hacker with the model, or similar AI tools, would likely be a transformation equivalent to turning a conventional soldier into a special forces operator, the person said. > At the same time, Mythos appears likely to be a force multiplier, the person said: Enabling a criminal hacking gang to operate at the level of a small nation state and for a small country’s intelligence and military hackers to carry out breaches of the sort now done by China. > “I really believe we will be safer and better, and we will be much more secure with AI,” said Rob Joyce, former director of cybersecurity at the National Security Agency. “But I think there’s this dark period between now and some time in the future where the advantage is very much offensive AI, where the people who haven’t done the basics will get hacked.” > Mythos isn’t the only model doing this kind of work. Numerous organizations have been using LLMs to find vulnerabilities, including previous Claude models and Google’s Big Sleep. _This post is for paying subscribers only._ ### Anthropic’s Mythos heads toward federal use as Hegseth's ban falters URL: https://www.metacurity.com/anthropics-mythos-heads-toward-federal-use-as-hegseths-ban-falters/ Last updated: 2026-04-17T15:19:57.000Z Anthropic releases Claude Opus 4.7, which can develop exploit code too, Financial officials fear AI models could threaten global banking, Russian crypto exchange Grinex suspends ops after $13m loss in cyber incident, DraftKings hacker sentenced to 30 months, much more _This post is for paying subscribers only._ ### Overwhelmed by vulnerability surge, NIST scales back NVD coverage URL: https://www.metacurity.com/overwhelmed-by-vulnerability-surge-nist-scales-back-nvd-coverage/ Last updated: 2026-04-16T14:28:11.000Z US nationals head to prison for aiding fake DPRK IT workers, Anthropic publishes Claude ID verification requirements, New ransomware attacks target S. Korean SMEs, New adware tool delivers system privileges that disable AV protections, Critical flaw in Nginx UI with MCP exploited, much more _This post is for paying subscribers only._ ### US agencies court Anthropic AI for cyber defense despite Pentagon ban URL: https://www.metacurity.com/us-agencies-court-anthropic-ai-for-cyber-defense-despite-pentagon-ban/ Last updated: 2026-04-15T13:55:25.000Z OpenAI launches private test of its Mythos rival, Russian cyber group targeted a Swedish thermal power plant, Microsoft fixes 167 flaws on Patch Tuesday, Fake Ledger site linked to $9.5m crypto theft, McGraw-Hill hacked via Salesforce misconfiguration, much more _This post is for paying subscribers only._ ### Allies warn of cyber divide as US firms gatekeep powerful Mythos AI URL: https://www.metacurity.com/allies-warn-of-cyber-divide-as-us-firms-gatekeep-powerful-mythos-ai/ Last updated: 2026-04-14T13:43:45.000Z Goldman Sachs is working closing with Mythos to protect itself, UK's AISI tested Mythos which excelled over other models, Bain & Co. was easily exposed by pentesters, Kraken suffered two insider security incidents, EU to abandon Chinese inverters, much more _This post is for paying subscribers only._ ### ShinyHunters hits Rockstar Games, threatens data dump after cloud breach URL: https://www.metacurity.com/shinyhunters-hits-rockstar-games-threatens-data-dump-after-cloud-breach/ Last updated: 2026-04-13T13:57:29.000Z Basic-Fit data breach exposes data on 1m+ members, Operation Atlantic disrupted $45m pig butchering network, Hackers exploited Hyberbridge flaw for $237k gain, Booking [dot] com suffered breach exposing customer details, UK finance regulators are assessing Anthropic's Claude Mythos, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 4/4/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-4-4-26/ Last updated: 2026-04-11T13:31:43.000Z Sam Altman is no fan of AI safety, Quantum computing cryptography is now an engineering emergency, How a Mexican contractor became a surveillance powerhouse, Software is produced too fast to secure it, AI is more likely to empower cyber defense than offense, The eternal search for Satoshi Nakamoto _This post is for subscribers only._ ### Feds summon Wall Street CEOs over fears Anthropic AI could supercharge cyberattacks URL: https://www.metacurity.com/feds-summon-wall-street-ceos-over-fears-anthropic-ai-could-supercharge-cyberattacks/ Last updated: 2026-04-10T14:34:36.000Z ***Don't miss my latest CSO piece, which*** [***breaks down***](https://www.csoonline.com/article/4156978/the-cyber-winners-and-losers-in-trumps-2027-budget.html?ref=metacurity.com) ***which US federal agencies are cyber winners and losers under Donald Trump's fiscal 2027 budget.*** --- *Metacurity is the only daily cybersecurity briefing built for clarity, not agendas—no vendor spin, no echo chamber, just sharp, original aggregation and analysis of what actually matters to security leaders.* *If you rely on Metacurity to cut through the noise on policy, industry shifts, and security research, consider supporting us with a paid subscription. Independent coverage like this only exists because readers decide it’s worth it.* [Upgrade my subscription now](#/portal/account/plans) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/14th_St_Union_Sq_E_td_-2018-03-22-_01_-_Wells_Fargo-1.jpg) Source: [Tdorante10](https://commons.wikimedia.org/wiki/User:Tdorante10?ref=metacurity.com "User:Tdorante10") ### Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell summoned Wall Street leaders to an urgent meeting on concerns that the latest artificial intelligence model from Anthropic PBC will usher in an era of greater cyber risk. Bessent and Powell assembled the group at Treasury’s headquarters in Washington on Tuesday to make sure banks are aware of possible future risks raised by Anthropic’s Mythos and potential similar models, and are taking precautions to defend their systems, according to people familiar with the matter who asked not to be identified, citing the private discussions. The previously unreported meeting, arranged on short notice, is another sign that regulators consider the possibility of a new breed of cyber attacks as one of the biggest risks facing the financial industry. All the banks summoned to the meeting are classified as systemically important by top regulators, meaning their stability is a priority for the global financial system. Anthropic’s Mythos is a more powerful system that the AI firm has said is capable of identifying and then exploiting vulnerabilities in every major operating system and web browser when directed by a user to do so. Regulators’ caution about the power of the model in hackers’ hands echoes Anthropic’s own prudence. Anthropic has limited the release of it to just a few major technology and finance firms at first. Those companies, which include Amazon.com Inc. and Apple Inc. as well as JPMorgan Chase & Co., are part of “Project Glasswing,” which will work to secure the most important systems before other similar AI models become available. Chief executive officers summoned to the meeting with the Fed and Treasury include Citigroup Inc.’s Jane Fraser, Morgan Stanley’s Ted Pick, Bank of America’s Brian Moynihan, Wells Fargo’s Charlie Scharf, and Goldman Sachs Group’s David Solomon, said the people. JPMorgan’s Jamie Dimon was unable to attend, the people said. ([Todd Gillespie, Katanga Johnson, Hannah Levitt, and Sridhar Natarajan / Bloomberg](https://www.bloomberg.com/news/articles/2026-04-10/anthropic-model-scare-sparks-urgent-bessent-powell-warning-to-bank-ceos?ref=metacurity.com)) **Related:** [*RTÉ*](https://www.rte.ie/news/business/2026/0410/1567506-powell-warned-bank-ceos-on-anthropic-model-risks-sources/?ref=metacurity.com)*,* [*Capital Brief*](https://www.capitalbrief.com/newsletter/bugged-out-54589894-d17f-4530-9e0e-e69eae0c74e3/?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/powell-bessent-said-invite-bank-leaders-discuss-anthropics-mythos?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/397bf755-54cf-4018-a01d-8f714d8667c5?ref=metacurity.com)*,* [*Blockonomi*](https://blockonomi.com/why-did-federal-officials-urgently-summon-banking-ceos-over-anthropics-mythos-ai/?ref=metacurity.com)*,* [*CoinDesk*](https://www.coindesk.com/markets/2026/04/10/mythos-ai-threat-sees-bessent-powell-call-urgent-meeting-with-bank-ceos?ref=metacurity.com)*,* [*r/politics*](https://www.reddit.com/r/politics/comments/1sh8ga5/anthropic%5Fmodel%5Fscare%5Fsparks%5Furgent%5Fbessent/?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/technology/2026/apr/10/us-summoned-bank-bosses-to-discuss-cyber-risks-posed-by-anthropic-latest-ai-model?ref=metacurity.com)*,* [*Financial Review*](https://www.afr.com/technology/bessent-powell-warn-bank-ceos-about-anthropic-model-cyber-risks-20260410-p5zmwh?ref=metacurity.com) ### According to 404 Media, testimony in a recent trial involving “a group of people setting off fireworks and vandalizing property at the ICE Prairieland Detention Facility in Alvarado, Texas,” showed that the FBI was able to recover content of incoming Signal messages from a defendant’s iPhone, even though Signal had been removed from the device. As 404 Media notes, Signal’s settings include an option that prevents the actual message content from being previewed in notifications. However, it appears the defendant did not have that setting enabled, which, in turn, seemingly allowed the system to store the content in the database. 404 Media reached out to Signal and Apple, but neither company provided any statements on how notifications are handled or stored. ([Marcus Mendes / 9to5Mac](https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/?ref=metacurity.com)) ***Related:*** [*9to5Mac*](https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/?ref=metacurity.com)*,* [*r/apple*](https://www.reddit.com/r/apple/comments/1sgppas/fbi%5Fextracts%5Fsuspects%5Fdeleted%5Fsignal%5Fmessages/?ref=metacurity.com)*,* [*Tech Times*](https://www.techtimes.com/articles/315787/20260410/deleted-doesnt-mean-gone-fbi-recovers-deleted-signal-messages-iphone-using-notification-data.htm?ref=metacurity.com)*,* [*The Mac Observer*](https://www.macobserver.com/news/fbi-finds-deleted-signal-messages-on-iphone-via-notification-storage-heres-how-to-protect-your-privacy/?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/phones/the-fbi-just-cracked-open-signal-texts-on-an-iphone-heres-how-to-lock-yours-down/?ref=metacurity.com)*,* [*NewsBytes*](https://www.newsbytesapp.com/news/science/fbi-recovers-deleted-signal-chats-via-iphone-notifications/story?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/fbi-retrieved-deleted-signal-messages-from-iphone-notification-database/?ref=metacurity.com)*,* [*404 Media*](https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/?ref=metacurity.com) ### Intelligence agencies of Viktor Orbán’s government have been secretly using Webloc — a mass surveillance tool that tracks hundreds of millions of people via smartphone advertising data — making Hungary the first confirmed EU country to deploy it, in likely violation of GDPR. Hungarian intelligence and law enforcement agencies have been operating AI-powered, open-source intelligence tools developed by Israel’s Cobwebs Technologies for at least five years, an investigation by VSquare, in collaboration with Citizen Lab, reveals. Foreign technologies are used alongside tools allegedly developed in Hungary. Such tools include an OSINT software and a mysterious spyware tied to SCI-Network Ltd., the same Hungarian firm that purchased Cobwebs’ licenses for the Orbán government. The most powerful previously unknown Cobwebs product used by Hungarian authorities is called Weblock, also known as WebLoc or Webloc. According to Citizen Lab, “Webloc is a global geolocation surveillance system that monitors hundreds of millions of people based on data purchased from consumer apps and digital advertising.” In short, Webloc uses smartphone apps’ advertising data for mass surveillance without the knowledge or consent of users. Hungary is the first confirmed country to deploy Webloc within the European Union, where data protection and privacy rules under the General Data Protection Regulation (GDPR) effectively prohibit such use of personal and advertising data. Documents on Cobwebs licenses reviewed by VSquare, as well as multiple sources with ties to Hungary’s intelligence community, confirm that Hungarian authorities have been using tools from Cobwebs Technologies, including Webloc, since at least early 2022\. ([Szabolcs Panyi / VSquare](https://vsquare.org/orban-spying-toolkit-cobwebs-webloc-hungary-spyware-citizen-lab/?ref=metacurity.com)) **Related:** [*Citizen Lab*](https://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation-surveillance-tech/?ref=metacurity.com)*,* [*United24*](https://united24media.com/latest-news/hungary-deploys-israeli-webloc-surveillance-tool-violating-eu-privacy-regulations-17785?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-34.png) Cobwebs products. Source: Citizen Lab. ### The US Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) launched a program to share real-time cyber threat intelligence with eligible digital asset firms at no cost. The initiative gives qualifying crypto companies access to the same security briefings that traditional banks and financial institutions have received for years. Treasury officials cited the growing frequency and sophistication of attacks as the primary driver behind the program. The effort also advances a recommendation from the President’s Working Group on Digital Asset Markets. Tyler Williams, Counselor to the Secretary for Digital Assets, linked the program to the Guiding and Establishing National Innovation for US Stablecoins (GENIUS) Act, signed into law in July 2025. The FDIC approved a separate GENIUS Act implementation framework on April 7, covering cybersecurity standards for stablecoin issuers. ([Lockridge Okoth / BeInCrypto](https://beincrypto.com/us-treasury-cybersecurity-crypto-intel-initiative/?ref=metacurity.com)) ***Related:*** [*Treasury Department*](https://home.treasury.gov/news/press-releases/sb0437?ref=metacurity.com)*,* [*Crypto Times*](https://www.cryptotimes.io/2026/04/09/us-treasury-opens-cyber-threat-intelligence-to-crypto-firms/?ref=metacurity.com)*,* [*BitGet*](https://www.bitget.com/amp/news/detail/12560605353073?ref=metacurity.com)*,* [*CryptoRank*](https://cryptorank.io/news/feed/a00ff-us-treasury-crypto-cybersecurity-initiative?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/digital-asset-cybersecurity-initiative/?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/the-u-s-treasury-opens-cyber-threat-sharing-channel-for-crypto-firms/?ref=metacurity.com)*,* [*Finextra*](https://www.finextra.com/newsarticle/47556/us-launches-cybersecurity-sharing-channel-for-crypto-firms?ref=metacurity.com)*,* [*CryptoRank*](https://cryptorank.io/news/feed/d18c4-treasury-opens-cyber-threat-sharing-program-for-u-s-crypto-firms?ref=metacurity.com)*,* [*BeInCrypto*](https://beincrypto.com/us-treasury-cybersecurity-crypto-intel-initiative/?ref=metacurity.com)*,* [*The Street*](https://www.thestreet.com/crypto/innovation/u-s-treasury-to-share-cyber-alerts-with-eligible-exchanges?ref=metacurity.com)*,* [*The Record*](https://therecord.media/treasury-department-announces-crypto-info-sharing?ref=metacurity.com)*,* [*Cryptopolitan*](https://www.cryptopolitan.com/treasury-taps-crypto-for-cyber-defense/?ref=metacurity.com)*,* [*PYMNTS*](https://www.pymnts.com/cybersecurity/2026/treasury-to-give-crypto-firms-same-cybersecurity-intel-as-banks/?ref=metacurity.com) ### Researchers at Microsoft report that a financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees' salary payments after hijacking their accounts in payroll pirate attacks. The attackers used malicious Microsoft 365 sign-in pages to steal victims' authentication tokens and session cookies by redirecting them to domains (e.g., bluegraintours\[.\]com) hosting malicious web pages (pushed to the top of search engine results through malvertising or SEO poisoning) that masqueraded as Microsoft 365 sign-in forms. This masquerade allowed Storm-2755 to bypass multifactor authentication (MFA) in adversary‑in‑the‑middle (AiTM) attacks by replaying stolen session tokens rather than re-authenticating. To harden defenses against AiTM and payroll pirate attacks, Microsoft advises defenders to block legacy authentication protocols and implement phishing-resistant MFA. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/microsoft/microsoft-canadian-employees-targeted-in-payroll-pirate-attacks/?ref=metacurity.com)) ***Related:*** [*Microsoft*](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/04/10/poisoned-office-365-search-results-lead-to-stolen-paychecks/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-35.png) Storm-2755 attack flow. Source: Microsoft. ### Blockchain investigator ZachXBT uncovered what he claims is a North Korean-linked IT worker network generating roughly $1 million per month through crypto-linked payments and fraudulent employment schemes. In a detailed thread on X, the onchain sleuth said the findings stem from data exfiltrated from an internal payment server tied to 390 accounts. The data cache also includes chat logs, wallet activity, and identity records that had not previously been made public, the crypto detective said. According to ZachXBT’s analysis, what appears to be a structured operation that relies on forged personas, fake documents, and a well-coordinated payment flow has pulled in north of $3.5 million since last November. An internal remittance platform resembling a messaging service is at the center of the system, he said. Workers use the tool to report earnings and receive payment instructions from a central administrator account. Then, funds were usually routed through cryptocurrency transactions before being converted to fiat using Chinese bank accounts or platforms like Payoneer. ZachXBT linked several payment addresses to known clusters associated with North Korean IT worker activity. Tether froze one Tron address connected to the network in December, he said. ([Naga Avan-Nomayo / The Block](https://www.theblock.co/post/396847/zachxbt-uncovers-north-korea-linked-it-worker-network-generating-1m-monthly-via-crypto-payment-flows?ref=metacurity.com)) **Related:** [*CoinCentral*](https://coincentral.com/north-korean-it-workers-made-3-5m-in-crypto-by-faking-identities-and-hacking-projects/?ref=metacurity.com)*,* [*Blockonomi*](https://blockonomi.com/north-korean-crypto-scheme-exposed-3-5m-stolen-through-fake-developer-identities/?ref=metacurity.com)*,* [*Incrypted*](https://incrypted.com/en/zachxbt-north-korea-earns-1m-crypto-monthly-fake-developers/?ref=metacurity.com)*,* [*CoinGape*](https://coingape.com/zachxbt-exposes-internal-data-of-north-korean-it-workers-reveals-3-5m-transactions/?ref=metacurity.com)*,* [*Futubull*](https://news.futunn.com/en/flash/20153960/zachxbt-disclosed-internal-payment-server-data-of-north-korean-it?level=1&data%5Fticket=1771842207173408&ref=metacurity.com)*,* [*ForkLog*](https://forklog.com/en/password-123456-exposes-a-dprk-it-worker-network-in-crypto/?ref=metacurity.com)*,* [*Bitcoin.com*](https://news.bitcoin.com/zachxbt-publishes-leaked-dprk-payment-data-showing-1m-monthly-crypto-to-fiat-pipeline/?ref=metacurity.com)*,* [*CryptoRank*](https://cryptorank.io/es/news/feed/cc8db-north-korean-crypto-laundering-zachxbt?ref=metacurity.com)*,* [*CryptoPotato*](https://cryptopotato.com/zachxbt-uncovers-3-5m-operation-by-north-korean-fake-devs-inside-crypto-firms/?ref=metacurity.com)*,* [*Bitget*](https://www.bitget.com/amp/news/detail/12560605349331?ref=metacurity.com) ### Hong Kong police arrested a man suspected of stealing the personal data of more than 56,000 patients from a Hospital Authority (HA) computer system. They identified the 30-year-old suspect as an employee of a systems maintenance contractor hired by the HA. He is accused of downloading patient data without authorization. Officers from the Cyber Security and Technology Crime Bureau said the leak originated from two of the contractor’s offices in the New Territories. Police raided the offices, seizing more than 60 digital devices, including servers and mobile phones. The suspect was arrested Tuesday in Tin Shui Wai on suspicion of “access to a computer with criminal or dishonest intent.” Superintendent Ferris Cheung said investigators are still probing the suspect’s motive and possible accomplices. ([Hans Tse/ Hong Kong Free Press](https://hongkongfp.com/2026/04/09/hong-kong-police-arrest-man-suspected-of-stealing-56000-hospital-authority-patients-personal-data/?ref=metacurity.com)) **Related:** [*Healthcare IT News*](https://www.healthcareitnews.com/news/asia/hong-kong-police-arrest-suspect-over-56000-patient-data-leak?ref=metacurity.com)*,* [*South China Morning Post*](https://www.scmp.com/news/hong-kong/law-and-crime/article/3349378/police-arrest-man-suspicion-stealing-personal-data-56000-patients?ref=metacurity.com) ### Researchers at Cisco Talos report that a new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. They attribute the malware to a threat group tracked internally as UAT-10362, who they describe as a capable adversary "with mature operational tradecraft." LucidRook was observed in attacks in October 2025 that relied on phishing emails carrying password-protected archives. The researchers identified two infection chains, one using an LNK shortcut file that ultimately delivered a malware dropper called LucidPawn, and an EXE-based chain that leveraged a fake antivirus executable impersonating Trend Micro Worry-Free Business Security Services. The LNK-based attack employs decoy documents, such as government letters crafted to appear as if they originate from the Taiwanese government, to divert the user's attention. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/new-lucidrook-malware-used-in-targeted-attacks-on-ngos-universities/?ref=metacurity.com)) **Related:** [*Cisco Talos*](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?ref=metacurity.com)*,* [*CyberPress*](https://cyberpress.org/fake-security-spreads-lucidrook/?ref=metacurity.com)*,* [*CyberSecurityNews*](https://cybersecuritynews.com/hackers-use-fake-security-software-to-deliver-lucidrook/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-37.png) LNK-based attack chain. Source: Cisco Talos ### Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors. The developer says that only the Pro version 3.5.1.35 of the plugin is affected and recommends switching immediately to the latest version, currently 3.5.1.36, or 3.5.1.34 and earlier. Apart from installing backdoors in multiple locations, the malicious update created a hidden user with administrator permissions and stole sensitive data. According to the vendor, the threat actor distributed the malicious update on April 7, and some websites may have installed it. An analysis from PatchStack, a company focusing on securing WordPress and open-source software, notes that the malware is a fully featured, multi-layered toolkit embedded in the plugin’s main file while preserving Smart Slider's normal functionality. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/smart-slider-updates-hijacked-to-push-malicious-wordpress-joomla-versions/?ref=metacurity.com)) **Related:** [*PatchStack*](https://patchstack.com/articles/critical-supply-chain-compromise-in-smart-slider-3-pro-full-malware-analysis/?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/top-wordpress-slider-plugin-hijacked-to-spread-malware-heres-what-to-look-out-for?ref=metacurity.com) ### Security researcher Haifei Li (the founder of the sandbox-based exploit-detection platform EXPMON) says that attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December. Li warned that the attackers are using what he described as a "highly sophisticated, fingerprinting-style PDF exploit" to target an undisclosed Adobe Reader security flaw. Li also said that these attacks have been targeting Adobe users for at least 4 months, stealing data from compromised systems using privileged util.readFileIntoStream and RSS.addFeed Acrobat APIs, and deploying additional exploits. Threat intelligence analyst Gi7w0rm, who also analyzed this Adobe Reader exploit, found that PDF documents pushed in these attacks contain Russian-language lures referencing ongoing events in the Russian oil and gas industry. Li has notified Adobe about these findings and, until the company releases security updates to address this actively exploited vulnerability, advised Adobe Reader users not to open PDF documents received from untrusted contacts until a patch is released. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-exploiting-acrobat-reader-zero-day-flaw-since-december/?ref=metacurity.com)) **Related:** [*Haifei Li*](https://www.linkedin.com/feed/update/urn:li:activity:7447732911405142016/?ref=metacurity.com)*,* [*eSecurity Planet*](https://www.esecurityplanet.com/threats/adobe-acrobat-reader-zero-day-exploited-in-active-pdf-attacks/?ref=metacurity.com)*,* [*Sophos*](https://www.sophos.com/en-us/blog/adobe-reader-zero-day-vulnerability-in-active-exploitation?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2026/04/09/monthsold%5Fadobe%5Freader%5Fzeroday%5Fuses/?ref=metacurity.com)*,* [*The Stack*](https://www.thestack.technology/adobe-reader-0day-abused-in-wild-to-deliver-three-stage-exploit-chain/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/adobe-reader-zero-day-exploited-for-months-researcher/?ref=metacurity.com)*,* [*Haifei's random thoughts*](https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html?ref=metacurity.com)*,* [*DeviceSecurity.io*](https://www.devicesecurity.io/zero-days-for-masses-mythos-presages-exploit-tsunami-a-31371?ref=metacurity.com)*,* [*Hackread*](https://hackread.com/adobe-reader-zero-day-exploit-data-malicious-pdfs/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/04/09/acrobat-reader-zero-day-exploited/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2026/04/08/1-billion-microsoft-users-warned-as-angry-hacker-drops-0-day-exploit/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/adobe-reader-0-day-exploit/?ref=metacurity.com)*,* [*r/cybersecurity*](https://www.reddit.com/r/cybersecurity/comments/1sgq0fz/hackers%5Fexploiting%5Facrobat%5Freader%5Fzeroday%5Fflaw/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4156854/hackers-have-been-exploiting-an-unpatched-adobe-reader-vulnerability-for-months.html?ref=metacurity.com) ### Microsoft researchers discovered a vulnerability in EngageLab’s EngageSDK, which is designed for managing messaging and push notifications in mobile applications, that could expose highly sensitive information. According to Microsoft, the SDK, which is integrated by developers into Android apps as a dependency, is used by crypto wallet apps that have a total of more than 30 million installations. Unpatched versions of EngageSDK are affected by a vulnerability related to Android intents, which enable interaction between different applications and data sharing between the components of the same application. Microsoft researchers identified an intent redirection flaw that enables an attacker to manipulate the contents of an intent sent by vulnerable applications. An attacker can use a malicious app running on the targeted device to send specially crafted intents that leverage the vulnerable app to bypass the Android security sandbox and gain access to sensitive data, including personal information, user credentials, and financial information. Microsoft notified EngageLab developers in April 2025\. The Android Security Team was also informed the next month due to the vulnerability affecting apps distributed through Google Play. ([Eduard Kovacs / Security Week](https://www.securityweek.com/microsoft-finds-vulnerability-exposing-millions-of-android-crypto-wallet-users/?ref=metacurity.com)) **Related:** [*Microsoft*](https://www.microsoft.com/en-us/security/blog/2026/04/09/intent-redirection-vulnerability-third-party-sdk-android/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/190586/hacking/engagelab-sdk-flaw-opens-door-to-private-data-on-50m-android-devices.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-38.png) Visual representation of an intent redirection. Source: Microsoft. ### Users attempting to download HWMonitor and CPU-Z from the official CPUID website are reportedly being served malware-laced installers, in what appears to be an active compromise of the vendor’s distribution infrastructure. CPUID, the developer behind HWMonitor and CPU-Z, is a French software company known for producing lightweight system profiling and monitoring tools widely used by enthusiasts, IT professionals, and OEMs. CPU-Z alone has tens of millions of users globally. The issue first surfaced through user reports on Reddit, where a user attempting to update HWMonitor to version 1.63 was redirected from the official CPUID website to a suspicious download hosting a file named HWiNFO\_Monitor\_Setup.exe. The anomaly was immediately notable, as HWiNFO is an entirely separate hardware monitoring tool developed by a different vendor. Upon execution, the installer reportedly launched a Russian-language setup interface, prompting the user to abort the installation. Further investigation by community members revealed that the download link embedded on CPUID’s official HWMonitor page redirected to an external domain hosted on Cloudflare R2 storage, rather than CPUID’s standard infrastructure. This domain served a trojanized installer wrapped in a modified Inno Setup package, a technique frequently used to obfuscate malicious payloads and hinder static analysis. In contrast, legitimate HWMonitor installers use standard, easily extractable Inno Setup configurations. It remains unclear how the attackers gained access to CPUID’s infrastructure or whether the breach has been fully contained. The software publisher has not issued an official statement about the incident yet, and the website is currently offline. ([Amar Ćemanović / Cyber Insider](https://cyberinsider.com/hwmonitor-and-cpu-z-downloads-hijacked-to-deliver-malware-to-users/?ref=metacurity.com)) **Related:** [*Hybrid Analysis*](https://hybrid-analysis.com/sample/49685018878b9a65ced16730a1842281175476ee5c475f608cadf1cdcc2d9524/69d849ff4af2e775650bef7c?ref=metacurity.com)*,* [*r/pcmasterrace*](https://www.reddit.com/r/pcmasterrace/comments/1sh4e5l/warning%5Fhwmonitor%5F163%5Fdownload%5Fon%5Fthe%5Fofficial/?ref=metacurity.com)*,* [*igor'slab*](https://www.igorslab.de/en/warning-cpuid-suspected-of-being-a-virus-suspicious-hwmonitor-downloads-are-causing-alarm/?ref=metacurity.com)*,* [*PC Guide*](https://www.pcguide.com/news/breach-has-been-fixed-says-cpuid-after-cpu-z-or-hwmonitor-flagged-as-malware-in-apparent-hack/?ref=metacurity.com)*,* [*dev.ua*](https://dev.ua/en/news/cpuid-khaknuly-1775801446?ref=metacurity.com)*,* [*PC Gamer*](https://www.pcgamer.com/software/security/cpuids-download-page-has-been-hacked-with-its-popular-processor-and-pc-info-tools-replaced-with-links-to-files-containing-malware/?ref=metacurity.com)*,* [*VideoCardz*](https://videocardz.com/newz/popular-cpu-z-and-hwmonitor-software-installers-on-cpuid-site-flagged-for-malware?ref=metacurity.com) ### Google has announced the rollout of new session cookie protections in Chrome to prevent account compromise via stolen authentication cookies. The feature, called Device Bound Session Credentials (DBSC), was announced in April 2024 and has become available in Chrome 146 for Windows. macOS users will receive it as well, in a future browser release. DBSC fights session cookie theft by cryptographically binding authentication sessions to the user’s device, thus rendering stolen cookies useless. Typically stolen using information-stealing malware and often shared or sold on cybercrime platforms, these tokens may provide attackers with access to users’ accounts without a password. ([Ionut Arghire / Security Week](https://www.securityweek.com/google-rolls-out-cookie-theft-protections-in-chrome/amp/?ref=metacurity.com)) **Related:** [*Google Security Blog*](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?ref=metacurity.com)*,* [*Android Headlines*](https://www.androidheadlines.com/2026/04/chrome-dbsc-device-bound-credentials-session-protection.html?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/google-chrome-adds-infostealer-protection-against-session-cookie-theft/?ref=metacurity.com)*,* [*gHacks*](https://www.ghacks.net/2026/04/10/google-chrome-146-adds-device-bound-session-credentials-to-stop-session-cookie-theft-on-windows/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/04/10/google-chrome-device-bound-session-credentials/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-39.png) An overview of the DBSC protocol showing the interaction between the browser and server. Source: Google. ### Google says Gmail end-to-end encryption (E2EE) is now available on all Android and iOS devices, allowing enterprise users to read and compose emails without additional tools. Starting this week, encrypted messages will be delivered as regular emails to Gmail recipients' inboxes if they use the Gmail app. Recipients who don't have the Gmail mobile app and use other email services can read them in a web browser, regardless of the device and service they're using. "For the first time, users can compose and read these E2EE messages natively within the Gmail app on Android and iOS. No need to download extra apps or use mail portals. Users with a Gmail E2EE license can send an encrypted message to any recipient, regardless of what email address the recipient has," Google said. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/google/google-rolls-out-gmail-end-to-end-encryption-on-mobile-devices/?ref=metacurity.com)) **Related:** [*Google Workspace Updates*](https://workspaceupdates.googleblog.com/2026/04/gmail-end-to-end-encryption-now-available-on-mobile-devices.html?ref=metacurity.com)*,* [*How-to-Geek*](https://www.howtogeek.com/gmail-end-to-end-encrypytion-android-iphone/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/04/10/google-gmail-e2ee-mobile-devices/?ref=metacurity.com)*,* [*gHacks*](https://www.ghacks.net/2026/04/10/gmail-adds-end-to-end-encryption-for-android-and-iphone-users-in-google-workspace/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-40.png) Composing a E2EE message in Gmail. Source: Google. ### Stephen Kamnik, a corporal in the Pennsylvania state police, pleaded guilty to a mind-boggling set of crimes that include going through his co-workers’ underwear, possessing a stolen gun, having child sexual abuse material on his hard drives, and using AI tools to create over 3,000 pornographic “deepfakes.” One of the deepfakes involved a district court judge, while many of the others were created based on photos downloaded illicitly from state databases, including driver’s license photos. Some of the imagery was even created at police barracks, using state-owned devices. ([Nate Anderson / Ars Technica](https://arstechnica.com/tech-policy/2026/04/state-police-corporal-created-porn-deepfakes-from-drivers-license-photos/?utm%5Fbrand=arstechnica&utm%5Fsocial-type=owned&utm%5Fsource=mastodon&utm%5Fmedium=social)) **Related:** [*Pennsylvania Attorney General*](https://www.attorneygeneral.gov/taking-action/pa-state-police-cpl-pleads-guilty-to-using-work-computer-to-create-a-i-involved-pornography-also-secretly-recorded-photographed-individuals/?ref=metacurity.com)*,* [*KYW News Radio*](https://www.audacy.com/kywnewsradio/news/local/pa-trooper-pleads-guilty-csam-deepfakes?ref=metacurity.com)*,* [*Hoodline*](https://hoodline.com/2026/04/montco-trooper-cops-to-ai-porn-built-from-state-databases/?ref=metacurity.com)*,* [*Philadelphia Inquirer*](https://www.inquirer.com/crime/stephen-kamnik-deepfake-porn-guilty-plea-20260408.html?ref=metacurity.com) ### OpenAI is throwing its support behind an Illinois state bill that would shield AI labs from liability in cases where AI models are used to cause serious societal harms, such as death or serious injury of 100 or more people or at least $1 billion in property damage. The effort seems to mark a shift in OpenAI’s legislative strategy. Until now, OpenAI has largely played defense, opposing bills that could have made AI labs liable for their technology’s harms. Several AI policy experts say that SB 3444—which could set a new standard for the industry—is a more extreme measure than bills OpenAI has supported in the past. ([Maxwell Zeff / Wired](https://www.wired.com/story/openai-backs-bill-exempt-ai-firms-model-harm-lawsuits/?ref=metacurity.com)) **Related:** [*r/technology*](https://www.reddit.com/r/technology/comments/1shd0fx/openai%5Fbacks%5Fbill%5Fthat%5Fwould%5Flimit%5Fliability%5Ffor/?ref=metacurity.com)*,* [*Transparency Coalition*](https://www.transparencycoalition.ai/news/making-sense-of-illinois-stack-of-ai-bills-here-are-six-measures-to-watch-closely?ref=metacurity.com) ### Peter Joseph Williams, a former L3 Trenchant executive convicted of secretly selling zero-day exploits to a Russian broker, says he was suffering anxiety, burnout, years of depression, and financial difficulties when he decided to steal exploits from his US employer and sell them to the Russian buyer. Williams, who was promoted to general manager of Trenchant during the three years he was stealing from his company, explained the circumstances around his fateful decision in a letter submitted to the DC District Court before his recent sentencing. His attorney also described his crime spree as "an unfortunate period of extraordinarily poor judgment exacerbated by severe job stress and exhaustion." An Australian national who has lived in the US since July 2023 while working out of Trenchant's DC offices on a visa, Williams wrote that at the time he committed the offenses, he was "experiencing significant professional pressure and personal anxiety." But instead of seeking help or "removing" himself from circumstances he said he was not handling well, he signed contracts worth $4 million to sell eight of his company's hacking tools to a Russian company called Operation Zero – a firm known to sell exploits to the Russian government and other non-NATO countries. Williams, who is 39 years old and the father of two young children, acknowledged that his depression and burnout were not the causes of his crimes, but offered the court details about his mental state as an explanation for why his judgment was impaired at the time and why his actions deviated so far from a lifetime spent in service to the Australian government and military. Williams' wife and older brother wrote similar letters to the court about the strain he was under between 2022 and 2025 when he committed his crimes – Williams was the sole breadwinner for his family and handled all financial and administrative aspects of their lives, in addition to his stressful job, his wife wrote; and his criminal actions were completely out of character for someone who had devoted his life to protecting his country and its ideals. ([Kim Zetter / Zero Day](https://www.zetter-zeroday.com/trenchant-exec-says-he-had-depression-money-troubles-when-he-decided-to-sell-zero-days-to-russian-buyer-also-new-info-reveals-nature-of-his-work-for-australian-intelligence-agency/?ref=zero-day-newsletter)) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/04/image-36.png) ### Best Thing of the Day: Everyone Should Emulate EFF Digital civil liberties organization EFF [has decided](https://www.eff.org/deeplinks/2026/04/eff-leaving-x?ref=metacurity.com) to leave the rotting hole of disinformation, racism, anti-semitism, and right-wing propaganda known as X. ### Bonus Best Thing of the Day: This Took Forever, But All's Well That Ends Well US agriculture equipment maker Deere [agreed](https://www.reuters.com/sustainability/boards-policy-regulation/deere-settles-us-right-to-repair-lawsuit-with-99-million-fund-repair-commitments-2026-04-07/?ref=metacurity.com) to pay $99 million into a settlement fund for ‌farms and farmers that are part of a class action over costs and their right to repair their own highly digitized equipment. ### Worst Thing of the Day: Of Course Musk Would Oppose This Law Elon Musk’s artificial intelligence company, xAI, [has filed ](https://www.theguardian.com/technology/2026/apr/09/elon-musk-xai-colorado-lawsuit?ref=metacurity.com)a lawsuit against the state of Colorado for its law that protects citizens against “algorithmic discrimination” in sectors such as education, employment, healthcare, housing, and financial services. ### Closing Thought ### Hackers stole millions from Bitcoin Depot wallets URL: https://www.metacurity.com/hackers-stole-millions-from-bitcoin-depot-wallets/ Last updated: 2026-04-09T13:56:04.000Z OpenAI readies its own vulnerability hunting system, Handala breached the devices of former IDF chief, Hackers published data from China's supercomputer, Hundreds of unprotected and unencrypted Modbus devices are exposed on the internet, Hack-for-hire attacks are targeting journalists, much more _This post is for paying subscribers only._ ### Iran-linked hackers target critical infrastructure controls, risking disruption and sabotage URL: https://www.metacurity.com/iran-linked-hackers-target-critical-infrastructure-controls-risking-disruption-and-sabotage/ Last updated: 2026-04-08T13:39:49.000Z Anthropic's Glasswing could upend bug discovery and fixes, GRU-linked hackers infiltrate routers to steal email account passwords, Pro-Iranian group claims Chime and Pinterest cyberattacks, ICE confirms use of Paragon spyware, Hacking and spying services sold on Telegram to harass women, much more _This post is for paying subscribers only._ ### Russia aids Iran with satellite targeting, cyber ops against Middle East infrastructure, report URL: https://www.metacurity.com/russia-aids-iran-with-satellite-targeting-cyber-ops-against-middle-east-infrastructure-report/ Last updated: 2026-04-07T14:11:10.000Z Cyber-enabled fraud reached $17.6b in 2025, Hackers accessed files of Jones Day, Storm-1175 deploys n-day and zero day exploits, GPU rowhammering enters new territory, CISA orders FortiClient EMS fixes, Wynn Resorts breach affected 21k+ people, Hong Kong hospital breach affected 56k patients, more _This post is for paying subscribers only._ ### Germany names alleged ‘UNKN’ kingpin behind GandCrab and REvil ransomware empire URL: https://www.metacurity.com/germany-names-alleged-unkn-kingpin-behind-gandcrab-and-revil-ransomware-empire/ Last updated: 2026-04-06T14:10:54.000Z Meta pauses work with Mercor indefinitely following breach, N. Ireland education IT system contractor hit by breach, First convicted spyware maker dodges jail time, N. Korea carried out six-month op to steal $270m from Drift, Y Combinator dumps Delve over compliance fabrications, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/28/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-28-26/ Last updated: 2026-04-04T14:21:37.000Z The college kid who discovered the Kimwolf botnet, US AI build-out is dependent on Chinese-made electrical equipment, AI agent traps are the next big security challenge, AI bug discovery tilts the field toward attackers, Privatized offensive warfare could fuel a cyber arms race _This post is for subscribers only._ ### Microsoft bets $10 billion on Japan’s AI buildout and cyber defenses URL: https://www.metacurity.com/microsoft-bets-10-billion-on-japans-ai-buildout-and-cyber-defenses/ Last updated: 2026-04-03T14:18:44.000Z EU pins EC attack on TeamPCP, Iowa AG sues UnitedHealth over 2024 attack, Residential proxies pose problems for IP reputation systems, Him & Hers report Feb. data breach, TA416 refocuses efforts back to Europe, Former engineer admits to hacking employer in $750k extortion bid, much more _This post is for paying subscribers only._ ### Iran's Handela group claims control of the IT infrastructure in St. Joseph County, Indiana URL: https://www.metacurity.com/irans-handela-group-claims-control-of-the-it-infrastructure-in-st-joseph-county-indiana/ Last updated: 2026-04-02T13:52:30.000Z Hasbro takes down systems after cyberattack, Italy’s ASIGINT accused of fake WhatsApp app, Attackers use WhatsApp to spread malicious MSI files, $250M stolen from DeFi project Drift, Anthropic knocks out GitHub repos in frantic bid to pull back exposed code, much more _This post is for paying subscribers only._ ### N. Korean hackers were behind malicious versions of Axios URL: https://www.metacurity.com/n-korean-hackers-were-behind-malicious-versions-of-axios/ Last updated: 2026-04-01T13:41:17.000Z Actors compromised Cisco with stolen creds from Trivy attack, Anthropic leaked part of Claude's source code, Apple alters its upgrade-or-stay vulnerable method, Recruiting firm Mecor hit by incident linked to LiteLLM attack, Vim and GNU Emacs text editors' flaws surfaced by Claude prompts, much more _This post is for paying subscribers only._ ### California uses AI contracts to impose safeguards, teeing up clash with Trump URL: https://www.metacurity.com/california-uses-ai-contracts-to-impose-safeguards-teeing-up-clash-with-trump/ Last updated: 2026-03-31T13:50:19.000Z Italy fines its biggest bank $36.4m over data breach, Oz launches probe into internet giants over social media ban failures, Match Group settles with FTC over unauthorized data access, JavaScript library axios became an attack vector after npm account hijacking, much more _This post is for paying subscribers only._ ### Iran-linked hackers leak FBI director’s personal emails in targeted influence operation URL: https://www.metacurity.com/iran-linked-hackers-leak-fbi-directors-personal-emails-in-targeted-influence-operation/ Last updated: 2026-03-30T12:57:13.000Z Anthropic exposed cache of materials through a misconfigured CMS, Lockdown Mode locks out mercenary spyware, Crypto account protection products fall short, Stats SA hit by ransomware, ClickFix campaign targets crypto users on macOS through fake Cloudflare CAPTCHA pages, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/21/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-21-26/ Last updated: 2026-03-28T13:33:40.000Z How Israel turned Iran's vast camera network into a targeting tool, Project Maven and the gods of AI warfare, How cops can surveil you using your body's data, Liberal San Francisco is now ground zero for tech-driven surveillance, Prompt optimizations are security flaws _This post is for subscribers only._ ### UK sanctions scam-supporting, $20B crypto marketplace Xinbi Guarantee URL: https://www.metacurity.com/uk-sanctions-scam-supporting-20b-crypto-marketplace-xinbi-guarantee/ Last updated: 2026-03-27T13:24:13.000Z Judge issues preliminary injunction against DoD's Anthropic ban, EU rejects extension that would allow CSAM scanning, Drone maker TechEx claims SBU wiretapped its chief engineer, Dutch court orders Musk's Grok to stop producing nudified images, EC probes breach of its AWS infrastructure, much more _This post is for paying subscribers only._ ### Russia arrests alleged LeakBase admin after global cybercrime forum takedown URL: https://www.metacurity.com/russia-arrests-alleged-leakbase-admin-after-global-cybercrime-forum-takedown/ Last updated: 2026-03-26T13:22:52.000Z An Armenian man was extradited to US in connection with RedLine infostealer, Ransomware attack disrupts Spain's Port of Vigo, AI-assisted campaign distributed 300+ trojanized GitHub packages, 4 vulns affect Cisco Catalyst 9300 Series switches, Puerto Rico's DoT hit by cyberattack, much more _This post is for paying subscribers only._ ### Intellexa chief accuses Greek government of cover-up after conviction overturned URL: https://www.metacurity.com/intellexa-chief-accuses-greek-government-of-cover-up-after-conviction-overturned/ Last updated: 2026-03-25T13:18:11.000Z Trivy breach cascades into LiteLLM compromise as attackers hijack CI/CD and bury evidence, Russian national sentenced to two years in connection with BitPaymer botnet, Cyberattacks in Poland more than doubled last year, HackerOne employee data exposed in third-party attack, much more _This post is for paying subscribers only._ ### Leaked DarkSword iPhone spyware lowers bar for mass exploitation URL: https://www.metacurity.com/leaked-darksword-iphone-spyware-lowers-bar-for-mass-exploitation/ Last updated: 2026-03-24T14:58:31.000Z FCC bans import of all new foreign-made routers, Foster City officially declares state of emergency following attack, German federal police visited Windchill and FlexPLM users in the wee hours to warn them of a severe flaw, Scioto County employees fell victim to phishing, much more _This post is for paying subscribers only._ ### Russian spies hijack Signal and WhatsApp accounts in campaign targeting officials and journalists URL: https://www.metacurity.com/russian-spies-hijack-signal-and-whatsapp-accounts-in-campaign-targeting-officials-and-journalists/ Last updated: 2026-03-23T13:30:27.000Z Supply chain attack compromised Trivy vulnerability scanner, UK Financial Conduct Authority gave Palantir access to sensitive data, Hackers stole $23m in Ether from DeFi protocol Resolv Labs, Bluenoroff group stole 18.5k purchase records from gift card platform Bitrefill, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/14/26 URL: https://www.metacurity.com/next-long-read-7/ Last updated: 2026-03-21T14:56:29.000Z Industrialized scam compounds pull out all the stops to impersonate police, How Switzerland's SCION aims to replace BGP, Grassroots local resistance to Flock surveillance is growing, Existing law is inadequate to govern commercial spyware, Russia's sovereign internet is backfiring _This post is for subscribers only._ ### US dismantles major botnet networks, but Mirai’s evolution keeps the threat alive URL: https://www.metacurity.com/us-dismantles-major-botnet-networks-but-mirais-evolution-keeps-the-threat-alive/ Last updated: 2026-03-20T14:08:17.000Z Cops take down 373k scam darknet sites posting as CSAM sites, FBI seizes two Handala sites, Man convicted on extortion counts after sensitive contractor data theft, Man pleads guilty to AI-assisted streaming fraud, Admin unveils AI legislative framework, much more _This post is for paying subscribers only._ ### DarkSword turns iPhone hacking into a mass-scale, drive-by threat URL: https://www.metacurity.com/darksword-turns-iphone-hacking-into-a-mass-scale-drive-by-threat/ Last updated: 2026-03-19T14:18:39.000Z CISA says orgs should secure Intune after Stryker attack, Stryker attack delayed some surgeries, Hacker claims theft of 93 GB of data from police tip platform, Fed cyber reviewers couldn't examine Microsoft cloud platform for security, Patel confirms FBI buys US citizens' location data, much more _This post is for paying subscribers only._ ### Anthropic case puts courts at center of fight over AI supply chain authority URL: https://www.metacurity.com/anthropic-case-puts-courts-at-center-of-fight-over-ai-supply-chain-authority/ Last updated: 2026-03-18T11:59:13.000Z Iran officials tied to cyber ops killed in airstrikes, Bennett and Brassard win Turing Award, Japan to allow offensive operations starting Oct. 1, Tech giants pledge to help open source with AI bug surge, Apple patches WebKit flaw, Chinese hacker group steals $7m posing as a cyber firm, much more _This post is for paying subscribers only._ ### EU sanctions Iranian, Chinese companies for cyberattacks URL: https://www.metacurity.com/eu-sanctions-iranian-chinese-companies-for-cyberattacks/ Last updated: 2026-03-17T11:45:30.000Z Stryker denies report of data exfiltration in "Handala" attack, Teens sue xAI for sexually explicit images, Man charged with scam schemes while impersonating adult film star, Canadian bill expands cops' lawful access to telecom data, MedTech firm Intuitive hit by phishing incident, much more _This post is for paying subscribers only._ ### FBI probes crypto theft linked to malware-infected Steam games URL: https://www.metacurity.com/fbi-probes-crypto-theft-linked-to-malware-infected-steam-games/ Last updated: 2026-03-16T13:30:52.000Z Operation Synergia III busts 94 alleged cybercriminals, DPRK's Konni Group used KakaoTalk to spread info-stealing malware, Japan was hit by 226 ransomware attacks in 2025, Chinese attack on Costa Rica electricity institute sparks diplomatic row, Intellexa sold spyware to the Greek gov't, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/7/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-7-26/ Last updated: 2026-03-14T12:18:23.000Z Trump's supposed cyber-first war strategy, How an OpenClaw agent attacked an open source project maintainer, Electronic warfare threatens maritime navigation, Trump's offensive cyber-based strategy, Iridium satellite is not a secure system _This post is for subscribers only._ ### The Homeland Security surveillance machine URL: https://www.metacurity.com/the-homeland-security-surveillance-machine/ Last updated: 2026-03-13T13:29:19.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/pexels-pixabay-274886-1.jpg) Photo by [Pixabay](https://www.pexels.com/photo/grayscale-photo-of-barbed-wire-274886/?ref=metacurity.com) *Metacurity is a daily infosec intelligence layer written independently of vendor marketing, PR-driven threat intelligence, and the cyber media echo chamber. Paid subscriptions make it possible to keep producing clear, straightforward analysis every day and give our paid subscribers full access to special reports like the one below. Please consider upgrading your subscription. Thank you!* [Upgrade my subscription](#/portal/account/plans) On March 8, [reporting](https://www.motherjones.com/politics/2026/03/dhs-wants-to-build-a-system-to-surveil-americans-travel-records/?ref=metacurity.com) by Mother Jones revealed that DHS and the US Secret Service are exploring plans for a system designed to centrally track Americans’ travel records, including passenger names and detailed itineraries. The proposed platform would allow analysts to search across airline passenger manifests and related datasets, potentially reconstructing individuals’ movements across the country. Two days later, on March 10, an [investigation](https://www.wired.com/story/cbp-privacy-threshold-analysis-foia/?ref=metacurity.com) by Wired uncovered turmoil inside DHS’s privacy oversight apparatus. The outlet reported that senior officials reassigned privacy and transparency personnel after the release of an internal compliance document describing a previously undisclosed biometric identification system used by immigration agents. The document, known as a Privacy Threshold Analysis, revealed that the tool could capture biometric data not only from migrants but also from US citizens encountered during enforcement operations. According to the reporting, DHS leadership subsequently moved to classify such privacy assessments as internal drafts or privileged materials, potentially shielding them from disclosure through the Freedom of Information Act. Privacy law experts say those documents are often one of the only ways the public learns how government surveillance systems operate. “There is nothing in the FOIA statute—or any other statute—that allows the agency to categorically withhold Privacy Threshold Analyses,” former FEMA information law attorney Ginger Quintero-McCall told Wired. Together, the revelations provide a glimpse into what has been an extraordinary expansion of a surveillance infrastructure inside DHS. ## Investigations that exposed the system Almost all of the public understanding of DHS surveillance capabilities has come from investigative reporting, particularly by the independent technology outlet 404 Media. Over the past year, the publication has obtained internal documents and training materials showing how immigration enforcement agencies use commercial data markets and analytics platforms to track individuals. _This post is for paying subscribers only._ ### International operation takes down massive cybercrime proxy network SocksEscort URL: https://www.metacurity.com/international-operation-takes-down-massive-cybercrime-proxy-network-socksescort/ Last updated: 2026-03-13T12:29:35.000Z Telus probes purported ShinyHunters hack, Stryker cyberattack continues to disrupt operations, Leidos CTO John Solly ID'ed as DOGE SSA data thief, GAO finds gaps in CMMC program, Google issues emergency fixes for Chrome, much more _This post is for paying subscribers only._ ### Medical device giant Stryker hit by wiper attack, Iranian hacktivist takes credit URL: https://www.metacurity.com/medical-device-giant-stryker-hit-by-wiper-attack-iranian-hacktivist-takes-credit/ Last updated: 2026-03-12T14:17:37.000Z Poland foiled a cyberattack on its nuclear research center that ostensibly originated in Iran, Cyberattackers defaced ad signs in Tel Aviv train station, Albania's parliament hit by cyberattack, Apple issues updates to address Coruna exploit, US charges former ransomware negotiator, much more _This post is for paying subscribers only._ ### DOGE engineer stole hundreds of millions of US taxpayers' data, whistleblower URL: https://www.metacurity.com/doge-engineer-stole-hundreds-of-millions-of-us-taxpayers-data-whistleblower/ Last updated: 2026-03-11T14:27:09.000Z Meta unveils new fraud protections as an international operation disrupts scam compound activity, China bans OpenClaw apps on security grounds, Foreign hacker accessed Epstein files in 2023, Rudd confirmed as Cybercom/NSA chief, Quittr app exposes (ahem) sensitive data, much more _This post is for paying subscribers only._ ### Pentagon-Anthropic standoff escalates, putting contracts and AI deployments at risk URL: https://www.metacurity.com/pentagon-anthropic-standoff-escalates-putting-contracts-and-ai-deployments-at-risk/ Last updated: 2026-03-10T13:48:03.000Z FBI warns of phishing campaigns impersonating city and county officials, TX governor warns health agencies and universities of Chinese-manufactured devices, A big bank in S. Africa was hit by a ransomware attack, Hackers are selling Windows exploit for $220k, much more _This post is for paying subscribers only._ ### Russian hackers target Signal and WhatsApp accounts of officials, journalists, and military URL: https://www.metacurity.com/russian-hackers-target-signal-and-whatsapp-accounts-of-officials-journalists-and-military/ Last updated: 2026-03-09T13:27:46.000Z DPRK hackers use AI to accelerate and expand their schemes, Trump promotes offensive operations in cyber strategy and issues cybercrime EO, DHS and Secret Service seek real-time access to travel records, Polish hospital hit by 'huge' cyberattack, Chinese spy groups target S. American telcos, more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 2/28/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-2-28-26/ Last updated: 2026-03-08T12:49:01.000Z CISA's year-long turmoil under Gottumukkala, Meta smart glasses expose underpaid annotators to intimate data, Border Patrol surveils SoCal civilians, DHS nominee faces ethics allegations, LLMs enable deanonymization, Tile server flaws enable mass tracking _This post is for subscribers only._ ### FBI's wiretap network hit by suspected hack, maybe by the Chinese spies it was watching URL: https://www.metacurity.com/fbis-wiretap-network-hit-by-suspected-hack-maybe-by-the-chinese-spies-it-was-watching/ Last updated: 2026-03-06T14:41:09.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/blickpixel-it-838384_1280-1.jpg) Image by [Michael Schwarzenberger](https://pixabay.com/users/blickpixel-52945/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=838384) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=838384) *Metacurity is the only daily cybersecurity newsletter that is written outside the usual cyber press echo chamber and is a refreshing alternative to vendor-driven content and PR-flavored threat intelligence.* *Please consider supporting my work on Metacurity by upgrading your subscription. Thank you.* [Upgrade my subscription](#/portal/account/plans) --- ### The FBI detected a suspected cybersecurity incident on a sensitive network used to manage wiretaps and intelligence surveillance warrants, with officials working to assess the severity of the breach. The bureau confirmed it identified and addressed suspicious activities on FBI networks and deployed all available technical capabilities in response, but declined to elaborate further. The incident has drawn the attention of senior officials at both the FBI and the Justice Department, with responsibilities over civil liberties and national security. It remains unclear whether the breach is linked to the Salt Typhoon operation attributed to Chinese intelligence, which previously compromised multiple US government networks and private sector communications providers. The incident comes amid what current and former officials describe as a weakening of the FBI's cybersecurity response capacity, citing Director Kash Patel's removal of senior officials overseeing IT operations and the bureau's Salt Typhoon response. Officials warn that increased staff turnover and broader institutional upheaval at the FBI have compounded the challenges the US faces in defending against foreign cyberattacks. ([Paula Reid, Sean Lyngaas, Evan Perez, Katelyn Polantz / CNN](https://www.cnn.com/2026/03/05/politics/fbi-investigating-cyber-breach-critical-surveillance-network?cid=ios%5Fapp&ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/technology/fbi-identified-addressed-suspicious-cyber-activities-its-networks-agency-2026-03-05/?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/news/fbi-confirms-its-networks-were-targeted-by-suspicious-cyber-activities/?ref=metacurity.com)*,* [*Associated Press*](https://abcnews.com/Technology/wireStory/fbi-investigating-suspicious-cyber-activity-system-holding-sensitive-130803113?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/fbi-targeted-with-suspicious-activity-on-its-networks/?ref=metacurity.com)*,* [*NextGov/FCW*](https://www.nextgov.com/cybersecurity/2026/03/fbi-probing-suspicious-breach-bureau-networks/411929/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/03/05/fbi-investigating-hack-on-its-wiretap-and-surveillance-systems-report/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/fbi-investigates-breach-of-surveillance-and-wiretap-systems/?ref=metacurity.com) ### John Daghita, son of a US government contractor, was arrested on the island of Saint Martin in a joint FBI and French Gendarmerie operation after allegedly stealing over $46 million in cryptocurrency from the US Marshals Service. He allegedly exploited his access at his father's company, CMDSS, which held a contract to manage seized digital assets for the USMS — including funds tied to the massive 2016 Bitfinex hack. The case was cracked publicly by blockchain investigator ZachXBT in late January 2026, who traced suspicious wallet movements back to Daghita after he accidentally exposed himself during a recorded Telegram dispute with another hacker. Further analysis linked those wallets to government-seized crypto. Rather than lying low, Daghita taunted ZachXBT by repeatedly sending small amounts of the stolen funds to his public wallet — a move that ultimately backfired. Cash, hard drives, and security keys were seized at the time of arrest. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/fbi-arrests-suspect-linked-to-46m-crypto-theft-from-us-marshals/?ref=metacurity.com)) **Related:** [*Decrypt*](https://decrypt.co/360120/federal-contractors-son-arrested-charged-with-stealing-46-million-from-us-crypto-stockpile?ref=metacurity.com)*,* [*Gizmodo*](https://gizmodo.com/fbi-arrests-man-who-allegedly-stole-46-million-worth-of-crypto-from-u-s-government-stockpile-2000730134?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/post/392467/the-daily-nyse-parent-ice-okx-25b-valuation-suspect-arrested-fbi-alleged-marshals-theft?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-03-05/fbi-arrests-contractor-in-alleged-crypto-theft-held-by-marshals?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/news/federal-contractor-who-allegedly-stole-46-million-in-crypto-arrested-in-caribbean-fbi-says/?ref=metacurity.com)*,* [*DL News*](https://www.dlnews.com/articles/regulation/authorities-nab-suspect-tied-to-stealing-crypto-from-usms/?ref=metacurity.com)*,* [*CoinDesk*](https://www.coindesk.com/business/2026/03/05/son-of-u-s-government-contractor-accused-of-stealing-millions-in-seized-crypto-arrested-in-france?ref=metacurity.com)*,* [*Blockchain.News*](https://blockchain.news/flashnews/son-of-federal-contractor-arrested-for-46m-crypto-theft-from-u-s-marshals?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/fbi-arrest-bitcoin-theft-crypto-custody-company?ref=metacurity.com)*,* [*New York Post*](https://nypost.com/2026/03/05/us-news/us-govt-contractor-busted-on-ritzy-caribbean-island-for-stealing-46m-in-crypto-from-us-marshals-service-fbi-says/?ref=metacurity.com)*,* [*Bitcoin Magazine*](https://bitcoinmagazine.com/news/u-s-crypto-contractor-arrested-theft?ref=metacurity.com)*,* [*The Crypto Times*](https://www.cryptotimes.io/2026/03/05/fbi-arrests-u-s-contractor-accused-of-stealing-46m-in-government-crypto/?ref=metacurity.com)*,* [*Joe.My.God.*](https://www.joemygod.com/2026/03/fbi-us-contractor-stole-46m-in-crypto-from-feds/?ref=metacurity.com)*,* [*Bitcoin News*](https://news.bitcoin.com/fbi-arrests-virginia-man-linked-to-46m-us-marshals-crypto-wallet-theft/?ref=metacurity.com) ### The Defense Department formally labeled AI startup Anthropic a supply-chain risk, escalating an extraordinary standoff between the Pentagon and one of America's leading artificial intelligence companies over the military's ability to use Claude without restrictions — a designation that could force much of the federal government's technology ecosystem to sever ties with the firm. "From the very beginning, this has been about one fundamental principle: the military being able to use technology for all lawful purposes," the Pentagon said in a written statement. "The military will not allow a vendor to insert itself into the chain of command by restricting the lawful use of a critical capability and put our warfighters at risk." The label, historically reserved for foreign firms with ties to US adversaries, caps a tumultuous dispute that came to a head last week when Anthropic CEO Dario Amodei told Defense Secretary Pete Hegseth he would not allow Claude to be used to surveil American citizens or power autonomous weapons. Talks between the two sides collapsed on Friday. Shortly afterward, Anthropic rival OpenAI announced the Pentagon had agreed to run its models for classified workloads. The stakes are not merely commercial. CNBC confirmed that Anthropic models played a role in US airstrikes on Iran in recent days, underscoring the degree to which the company's technology had become embedded in active military operations. In a public statement, Amodei pledged that Anthropic would continue providing Claude to the Department of War and the national security community at nominal cost for as long as it is permitted to do so, calling it the company's most important priority to ensure warfighters are not deprived of critical tools during ongoing combat operations. Microsoft became the first major company to publicly declare it would continue working with Anthropic after the Pentagon's action. "Our lawyers have studied the designation and have concluded that Anthropic products, including Claude, can remain available to our customers — other than the Department of War — through platforms such as M365, GitHub, and Microsoft's AI Foundry," a company spokesperson told CNBC. The two companies have deep financial ties: in November, Anthropic committed to spending $30 billion on Microsoft's Azure cloud services, while Microsoft agreed to invest up to $5 billion in Anthropic. That relationship has woven Anthropic's technology throughout Microsoft's commercial product line. Claude models are available inside GitHub Copilot, widely used by software engineers for drafting code, and were integrated into the Microsoft 365 Copilot add-on in September. "Model choice!" CEO Satya Nadella wrote in an October post on X, showing off the ability to toggle between Anthropic and OpenAI models in Microsoft 365 Copilot. Not all of Microsoft's government relationships will be unaffected, however — Microsoft 365 is widely used inside the Department of War itself, and the company was careful to carve out that agency explicitly from its assurances. Anthropic, for its part, argued the designation's legal scope is narrower than the Pentagon's rhetoric suggests. The relevant statute — 10 USC 3252 — exists to protect the government rather than punish a supplier, Amodei said, and requires the Secretary of War to use the least restrictive means necessary. Even for Pentagon contractors, he argued, the designation cannot limit uses of Claude unrelated to specific Department of War contracts. The company said last week it would challenge the label in court. The full scope of the government's action remains unclear. Hegseth had earlier threatened to force all companies that partner with the government to drop Anthropic's products entirely — a far broader reach than the formal designation's language implies. Some defense technology companies have already told employees to stop using Claude and migrate to alternatives. For Washington's technology policy community, the episode may carry consequences well beyond Anthropic itself. "The real significance here isn't just the action against Anthropic — it's the precedent it sets for how Washington will arbitrate tensions between AI developers and the national security community," said Joe Hoefer, head of AI at lobbying firm Monument Advocacy. "That dynamic will shape how the entire industry approaches government partnerships going forward." ([Brendan Bordelon / Politico](https://www.politico.com/news/2026/03/05/pentagon-tells-anthropic-it-has-designated-the-company-a-supply-chain-risk-00814758?ref=metacurity.com), [Jordan Novet / CNBC](https://www.cnbc.com/2026/03/05/microsoft-says-anthropics-products-can-remain-available-to-customers-after-security-risk-designation.html?ref=metacurity.com), and [Dario Amodei / Anthropic](https://www.anthropic.com/news/where-stand-department-war?ref=metacurity.com)) **Related:** [*Wall Street Journal*](https://www.wsj.com/tech/ai/pentagon-formally-labels-anthropic-supply-chain-risk-escalating-conflict-ebdf0523?gaa%5Fat=eafs&gaa%5Fn=AWEtsqcYvng44uDACs09klAIXk4P0UWFjWFhO1ykcOeP%5FEMcMuPCk7uTInU8MIIeDJc%3D&gaa%5Fts=69aac5df&gaa%5Fsig=SKhZRYz1DqXJ1-P3u0Kr9BmHa-NkCBje5u-nR6Y%5FeRsp%5FuW95FIXImQAMW9qQF-h0IVzRMdRLpxHZqkHV2kkMw%3D%3D&ref=metacurity.com)*,* [*BBC News*](https://www.bbc.com/news/articles/cn5g3z3xe65o?ref=metacurity.com)*,* [*CNN*](https://www.cnn.com/2026/03/05/tech/pentagon-anthropic-supply-chain-risk?ref=metacurity.com)*,* [*Computerworld*](https://www.computerworld.com/article/4141684/anthropic-holds-firm-against-the-pentagon-after-supply%E2%80%91chain-risk-label.html?ref=metacurity.com)*,* [*Silicon Republic*](https://www.siliconrepublic.com/business/anthropic-will-fight-us-supply-chain-risk-designation-in-court-ai-claude?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/ai/anthropic-says-it-will-challenge-defense-departments-supply-chain-risk-designation-in-court-054459618.html?ref=metacurity.com)*,* [*RTÉ*](https://www.rte.ie/news/us/2026/0306/1561919-anthropic-pentagon-ban/?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/tech/ai/pentagon-formally-labels-anthropic-supply-chain-risk-escalating-conflict-ebdf0523?ref=metacurity.com)*,* [*The Independent*](https://www.the-independent.com/tech/claude-ai-app-anthropic-chatgpt-b2933191.html?ref=metacurity.com)*,* [*The Atlantic*](https://www.theatlantic.com/technology/2026/03/dean-ball-anthropic-interview/686226/?gift=iWa%5FiB9lkw4UuiWbIbrWGW84ZhOvWyQHcc1sBA6FN54&ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/anthropic-ceo-dario-amodei-apologized-eaked-memo-criticizing-trump-administration-2026-3?ref=metacurity.com)*,* [*NewsMax.com*](https://www.newsmax.com/us/anthropic-open-ai-dario-amodei/2026/03/05/id/1248525/?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/sanfrancisco/news/pentagon-anthropic-supply-chain-risk-feud-ai-guardrails/?ref=metacurity.com)*,* [*Implicator.ai*](https://www.implicator.ai/anthropic-lost-the-pentagon-contract-it-won-the-argument/?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/5770720-anthropic-ceo-fights-pentagon-designation/?ref=metacurity.com)*,* [*CNN*](http://www.cnn.com/2026/03/05/tech/pentagon-anthropic-supply-chain-risk?ref=metacurity.com)*,* [*Axios*](https://www.axios.com/2026/03/06/pentagon-anthropic-amodei-apology?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/9ab91d10-e1f9-4142-a11e-efcc319d00e8?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/03/05/anthropic-to-challenge-dods-supply-chain-label-in-court/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/tech/tech-news/anthropic-says-pentagon-declared-national-security-risk-rcna262013?ref=metacurity.com)*,* [*MarketWatch*](https://www.marketwatch.com/story/anthropic-has-no-choice-but-to-fight-pentagons-supply-chain-risk-designation-in-court-ceo-says-3375d7d1?ref=metacurity.com)*,* [*DNYUZ*](https://dnyuz.com/2026/03/06/pentagon-officially-notifies-anthropic-it-is-a-supply-chain-risk/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-03-06/anthropic-says-it-has-no-choice-but-to-fight-pentagon-in-court?ref=metacurity.com)*,* [*Forbes*](http://www.forbes.com/sites/richardnieva/2026/03/05/anthropics-ceo-is-contrite-in-latest-response-to-department-of-war/?ref=metacurity.com)*,* [*Moneycontrol*](https://www.moneycontrol.com/technology/anthropic-ceo-dario-amodei-says-company-will-challenge-us-national-security-risk-label-in-court-article-13852442.html?ref=metacurity.com)*,* [*OnMSFT*](https://onmsft.com/news/anthropic-to-challenge-pentagon-supply-chain-risk-designation-in-court/?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/markets/tech/26/03/51088389/anthropic-ceo-dario-amodei-says-no-choice-but-to-challenge-us-government-in-court-after-claude-provider-labeled-supply-chain-risk?ref=metacurity.com)*,* [*Hürriyet Daily News*](https://www.hurriyetdailynews.com/pentagon-formally-designates-anthropic-as-supply-chain-risk-219662?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2026/03/05/anthropic-ceo-amodei-openai-pentagon-deal-lies-safety-theater-xcxwbn/?ref=metacurity.com)*,* [*The Mac Observer*](https://www.macobserver.com/news/apple-and-others-raises-concerns-over-pentagon-action-on-anthropic/?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/articles/anthropic-ceo-told-employees-openai-pentagon-deal-safety-theater?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-03-05/pentagon-says-it-s-told-anthropic-the-firm-is-supply-chain-risk?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/politics/national-security/pentagon-formally-labels-anthropic-supply-chain-risk-escalating-conflict-ebdf0523?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/markets/tech/26/03/51090159/department-of-war-says-no-active-negotiation-with-anthropic-end-all-speculation?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/pentagon-officially-tells-anthropic-supply-chain-risk?ref=metacurity.com)*,* [*Politico*](https://www.politico.com/news/2026/03/05/pentagon-tells-anthropic-it-has-designated-the-company-a-supply-chain-risk-00814758?ref=metacurity.com)*,* [*Reuters*](https://www.theglobeandmail.com/business/technology/article-anthropic-ai-pentagon-supply-chain/?ref=metacurity.com)*,* [*Proactive*](https://www.proactiveinvestors.com/companies/news/1088467/anthropic-chief-seeks-to-end-pentagon-standoff-over-ai-guardrails-1088467.html?ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2026/03/05/technology/anthropic-supply-chain-risk-defense-department.html?ref=metacurity.com)*,* [*Bloomberg Law*](https://news.bloomberglaw.com/tech-and-telecom-law/pentagon-says-its-told-anthropic-the-firm-is-supply-chain-risk?ref=metacurity.com)*,* [*Yahoo Finance*](https://ca.finance.yahoo.com/news/anthropic-tussle-us-government-defense-232533573.html?ref=metacurity.com)*,* [*BBC*](https://www.bbc.com/news/articles/cn5g3z3xe65o?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/technology/2026/mar/05/trump-anthropic-ai-pentagon?ref=metacurity.com)*,* [*The Next Web*](https://thenextweb.com/news/pentagon-labels-anthropic-a-supply-chain-risk?ref=metacurity.com)*,* [*Business Standard*](https://www.business-standard.com/technology/tech-news/anthropic-to-fight-pentagon-in-court-over-supply-chain-risk-label-126030600184%5F1.html?ref=metacurity.com)*,* [*OnMSFT*](https://onmsft.com/news/pentagon-officially-declares-anthropic-a-supply-chain-risk-after-contract-talks-collapse/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/anthropic-is-now-officially-labelled-a-supply-chain-risk-in-the-us/?ref=metacurity.com)*,* [*Tech in Asia*](https://www.techinasia.com/news/anthropic-challenge-supply-chain-risk-designation-court?ref=metacurity.com)*,* [*The Economic Times*](https://economictimes.indiatimes.com/tech/technology/anthropic-to-challenge-pentagons-supply-chain-risk-label/articleshow/129129572.cms?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/5770556-pentagon-designates-anthropic-risk/?ref=metacurity.com)*,* [*Associated Press*](https://www.npr.org/2026/03/06/g-s1-112713/pentagon-labels-ai-company-anthropic-a-supply-chain-risk?ref=metacurity.com)*,* [*Washington Times*](https://www.washingtontimes.com/news/2026/mar/5/pentagon-officially-labels-anthropic-maker-claude-ai-supply-chain/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/zacharyfolk/2026/03/05/pentagon-officially-tells-anthropic-its-a-supply-chain-risk/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/890347/pentagon-anthropic-supply-chain-risk?ref=metacurity.com)*,* [*Semafor*](https://www.semafor.com/article/03/06/2026/pentagon-designates-anthropic-a-supply-chain-risk?ref=metacurity.com)*,* [*InfoRiskToday.com*](https://www.inforisktoday.com/tech-giants-washington-rally-for-anthropic-in-pentagon-feud-a-30929?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/news/pentagon-anthropic-supply-chain-risk-feud-ai-guardrails/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/03/05/its-official-the-pentagon-has-labeled-anthropic-a-supply-chain-risk/?ref=metacurity.com) ### Nearly half of all zero-day vulnerabilities tracked by Google in 2025 targeted enterprise technologies, the company revealed in its annual threat report, marking a record shift in hacker focus toward corporate infrastructure. Of those enterprise-focused zero-days, roughly half hit the security and networking tools meant to defend corporate networks — including firewalls from Cisco and Fortinet, and VPN and virtualization platforms from Ivanti and VMware. Researchers found attackers exploiting common weaknesses such as flawed input validation and incomplete authorization checks to penetrate firewall and VPN defenses — bugs that are relatively straightforward to exploit but require vendor-issued patches to remediate. Google also highlighted the Clop extortion gang's campaign targeting Oracle E-Business Suite customers, which resulted in the theft of sensitive HR data from dozens of organizations, including Harvard University, American Airlines subsidiary Envoy, and The Washington Post. The remaining 52% of zero-days affected consumer products from Microsoft, Google, and Apple, with operating systems and mobile devices accounting for the bulk of those vulnerabilities. Google attributed more zero-days to commercial surveillance vendors — spyware makers and exploit developers working on behalf of governments — than to traditional state-sponsored espionage groups, signaling a shift in how governments are acquiring offensive hacking capabilities. ([Zack Whittaker / TechCrunch](https://techcrunch.com/2026/03/05/google-says-half-of-all-zero-days-it-tracked-in-2025-targeted-buggy-enterprise-tech/?ref=metacurity.com)) ***Related:*** [*Google*](https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review?ref=metacurity.com)*,* [*NewsBytes*](https://www.newsbytesapp.com/news/science/nearly-half-of-zero-day-attacks-targeted-enterprise-devices-google-reports/story?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2026/03/04/critical-android-update-google-confirms-0day-security-bypass-attacks/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/google-says-90-zero-days-were-exploited-in-attacks-last-year/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/google-confirms-90-zero-day-vulnerabilities-exploit-in-2025/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2026/03/05/zero%5Fday%5Fattacks%5Fenterprise%5Ftech%5Frecord/?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/google-patches-129-android-security-flaws-including-potentially-dangerous-qualcomm-zero-day?ref=metacurity.com)*,* [*TechRepublic*](https://www.techrepublic.com/article/news-google-android-security-update-129-vulnerabilities/?ref=metacurity.com)*,* [*Mirror*](https://www.mirror.co.uk/tech/android-warning-serious-security-threat-36810825?ref=metacurity.com)*,*[ *Security Week*](https://www.securityweek.com/google-half-of-2025s-90-exploited-zero-days-aimed-at-enterprises/?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2026/03/05/google-threat-intelligence-group-warns-enterprise-systems-increasingly-targeted-zero-day-exploits/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/google-says-90-zero-days-exploited-apt-spyware-vendors?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/139324/china-and-spyware-companies-dominate-zero-day-attacks/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/image-27.png) Zero days by year. Source: Google. ### Researchers at Huntress report that threat actors exploited Microsoft Bing's AI-enhanced search feature to push malicious installers for OpenClaw, a popular open-source AI agent. The fake installers, hosted on fraudulent GitHub repositories, delivered a range of malware to both Windows and macOS users. OpenClaw, widely used as a personal AI assistant with access to local files, email, and messaging services, became an attractive target due to its broad system access. Attackers created GitHub repositories designed to impersonate legitimate OpenClaw installers — and Bing's AI search surfaced them as recommended downloads. Huntress researchers noted that simply hosting the malware on GitHub was sufficient to manipulate Bing AI search results. The fraudulent repositories were linked to a GitHub organization named openclaw-installer and copied real code from the Cloudflare moltworker project to appear credible, despite being newly created accounts. macOS users were directed to paste a malicious bash command in Terminal, which fetched payloads from a separate repository and executed the Atomic Stealer malware. Windows users received OpenClaw\_x64.exe, which deployed multiple Rust-based malware loaders that executed infostealers directly in memory. Among the payloads was Vidar Stealer, which leveraged Telegram and Steam profiles for command-and-control communications, and GhostSocks, a backconnect proxy that converts victim machines into proxy nodes — enabling attackers to bypass fraud detection systems using stolen credentials. All malicious repositories have been reported to GitHub. Users are advised to bookmark official software portals rather than relying on search results to locate downloads. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/bing-ai-promoted-fake-openclaw-github-repo-pushing-info-stealing-malware/?ref=metacurity.com)) **Related:** [*Huntress*](https://www.huntress.com/blog/openclaw-github-ghostsocks-infostealer?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2026/03/04/fake%5Fopenclaw%5Finstallers%5Fmalware/?ref=metacurity.com)*,* [*IT Brew*](https://www.itbrew.com/stories/2026/03/03/new-vulnerability-in-open-source-repositories-uses-fake-openclaw-install-to-attack?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/bing-boosted-openclaw-installers-deliver-infostealers-ghostsocks-malware?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/image-28.png) Malicious Bing AI Search results. Source: Huntress. ### A Ghanaian national, Derrick Van Yeboah, pleaded guilty to wire fraud conspiracy for his role in a Ghana-based fraud ring that stole over $100 million from Americans between 2016 and 2023\. The operation ran two main schemes: romance scams targeting lonely older adults online, and business email compromise attacks on companies. Victims were manipulated into sending money to US-based middlemen, who laundered the funds and forwarded them to the scheme's overseas coordinators. Van Yeboah personally ran many of the romance scams and is tied to over $10 million in losses. He was extradited to the US in August 2025 along with three accomplices. He faces up to 20 years in prison at his June 3rd sentencing and must pay over $10 million in restitution. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/ghanain-man-pleads-guilty-to-role-in-100-million-fraud-ring/?ref=metacurity.com)) **Related:** [*Justice Department*](https://www.justice.gov/usao-sdny/pr/ghanaian-national-pleads-guilty-stealing-more-10-million-romance-scams?ref=metacurity.com)*,* [*Justice Department*](https://www.justice.gov/usao-sdny/media/1410596/dl?inline&ref=metacurity.com) ### Meta is facing a new lawsuit over its AI smart glasses after an investigation by Swedish newspapers found that workers at a Kenya-based subcontractor were reviewing footage from customers' glasses, including sensitive content such as nudity, people having sex, and using the toilet. The newly filed complaint names plaintiffs Gina Bartone of New Jersey and Mateo Canu of California, represented by the Clarkson Law Firm, who allege that Meta violated privacy laws and engaged in false advertising. The complaint alleges that the glasses were marketed with promises like "designed for privacy, controlled by you" and "built for your privacy" — language that plaintiffs say gave no indication that overseas contractors could view intimate footage. The suit charges Meta and its glasses manufacturing partner Luxottica of America with violating consumer protection laws. The scale of potential exposure is significant: in 2025, more than seven million people purchased Meta's smart glasses, meaning their footage entered a data review pipeline with no opt-out available. Meta had claimed it was blurring faces in images, but sources disputed that the blurring consistently worked. The revelations prompted the UK's Information Commissioner's Office to open its own investigation. Meta spokesperson Christopher Sgro said footage stays on the user's device unless users choose to share it, and that when content is shared with Meta AI, contractors may review it to improve the user experience — a practice the company says is disclosed in its privacy policy. ([Sarah Perez / TechCrunch](https://techcrunch.com/2026/03/05/meta-sued-over-ai-smartglasses-privacy-concerns-after-workers-reviewed-nudity-sex-and-other-footage/?ref=metacurity.com)) ***Related:*** [*BBC News*](https://www.bbc.com/news/articles/c0q33nvj0qpo?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/social-media/meta-hit-with-a-class-action-lawsuit-over-smart-glasses-privacy-claims-182846817.html?ref=metacurity.com)*,* [*Tom's Guide*](https://www.tomsguide.com/ai/meta-sued-over-smart-glasses-privacy-claims-6-changes-you-should-make-right-now?ref=metacurity.com)*,* [*MediaPost*](https://www.mediapost.com/publications/article/413283/meta-sued-for-falsely-marketing-smart-glasses-col.html?edition=141818&ref=metacurity.com)*,* [*Futurism*](https://futurism.com/artificial-intelligence/meta-lied-smart-glasses-privacy-class-action-lawsuit?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/gadgets/2026/03/workers-report-watching-ray-ban-meta-shot-footage-of-people-using-the-bathroom/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/tech/889637/meta-ai-smart-glasses-human-reviewers-kenya?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2026/03/05/meta-sued-ai-smart-glasses-privacy-workers-intimate-footage-xcxwbn/?ref=metacurity.com) ### Swiss encrypted email provider Proton Mail disclosed payment information to Swiss authorities that the FBI subsequently used to identify the person behind an anonymous account linked to the Stop Cop City protest movement in Atlanta, according to a court document obtained by 404 Media. The data obtained via a Mutual Legal Assistance Treaty between the US and Switzerland identified a named individual as the payment source for defendtheatlantaforest@protonmail.com, an account publicly associated with the Defend the Atlanta Forest group. The FBI's affidavit, filed in support of a search warrant by an agent from the Domestic Terrorism squad, states the account was linked to a blog that promoted and claimed credit for acts including arson and vandalism targeting the proposed Atlanta police training facility. The case highlights a key limitation of Proton Mail's privacy protections: while message content remains end-to-end encrypted, billing and subscriber metadata can be compelled under Swiss law and shared internationally. Charges against more than 60 people connected to the broader movement have since been dropped. The individual identified through the payment data does not appear to have been charged with a crime. ([Joseph Cox / 404 Media](https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/?ref=metacurity.com)) **Related:** [*The Verge*](https://www.theverge.com/policy/890278/proton-mail-stop-cop-city-fbi?ref=metacurity.com)*,*[ *r/LinusTechTips*](https://www.reddit.com/r/LinusTechTips/comments/1rltku8/proton%5Fmail%5Fhelped%5Ffbi%5Funmask%5Fanonymous%5Fstop%5Fcop/?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/proton-mail-payment-data-helped-fbi-identify-stop-cop-city-account-holder/?ref=metacurity.com)*,* [*Digg*](https://digg.com/proton/77KQKmr/protonmail-handed-over-data-related-to?ref=metacurity.com) ### Italian prosecutors officially confirmed that journalist Francesco Cancellato, director of news site Fanpage, had his phone infected with Paragon spyware on the night of December 14, 2024, along with two immigration activists. The three attacks happened in quick succession, suggesting a coordinated campaign. While prosecutors found evidence that Italy's AISI intelligence agency authorized operations against the activists, no such evidence exists for Cancellato — meaning his hacker remains unknown. The Italian government has denied involvement, and Cancellato isn't satisfied: "We have not received clarity from the government, which has remained silent whenever possible for a year — and when it didn't remain silent, it told lies." Citizen Lab researchers are also questioning why a separate Fanpage journalist, whose hack they independently confirmed, didn't appear in the prosecutors' report at all. Paragon canceled its Italian government contracts following the scandal. Italy now joins Greece, Hungary, Poland, and Spain in a growing list of European nations caught up in spyware controversies. ([Lorenzo Franceschi-Bicchierai / TechCrunch](https://techcrunch.com/2026/03/05/italian-prosecutors-confirm-journalist-was-hacked-with-paragon-spyware/?ref=metacurity.com)) **Related:** [*La Milano*](https://lamilano.it/en/by-the-media/caso-paragon-pm-effettuato-accesso-presso-aisi-nessuna-traccia-su-cancellato/?ref=metacurity.com) ### Around 10 million people had their personal data stolen when Transport for London (TfL) was hacked in 2024, making it one of the largest data breaches in British history. At the time, the company only disclosed that "some" customers had been affected. The hack was carried out between late August and early September 2024 by the Scattered Spider crime group, breaching internal computer systems and causing an estimated £39 million in damages. While the attack did not halt physical transport services, it forced information boards and online payment systems offline for weeks. The stolen database is reported to contain names, email addresses, home phone numbers, mobile numbers, and physical addresses of millions of passengers. TfL also identified around 5,000 customers at heightened risk because their Oyster card refund data — potentially including bank account numbers and sort codes — may also have been accessed. TfL confirmed it sent notification emails to over 7 million customers, but those emails carried only a 58% open rate, suggesting millions of affected individuals remain unaware their data was compromised. Despite the scale of the incident, the Information Commissioner's Office cleared TfL of any wrongdoing in February 2025, stating that formal regulatory action was not proportionate. Two British teenagers accused of carrying out the hack are set to stand trial in June 2026\. ([Joe Tidy / BBC News](https://www.bbc.com/news/articles/cz0ggkr2g77o?ref=metacurity.com)) **Related:** [*Daily Mail*](https://www.dailymail.co.uk/news/article-15620965/TFL-hack-10million-people-data-stolen.html?ref=metacurity.com)*,* [*Tech Radar*](https://www.techradar.com/pro/security/tfl-admits-2024-cyberattack-may-have-affected-over-10-million-people-personal-customer-info-stolen-heres-what-we-know-so-far?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2026/03/06/tfl%5F2024%5Fbreach%5Fnumbers/?ref=metacurity.com) ### The Wikimedia Foundation briefly disabled editing across its projects after a overseas contractors could view intimate footage, modifying roughly 4,000 pages and infecting the common.js files of about 85 users before engineers contained it. The malicious script, traced to a Russian Wikipedia user account and dormant since March 2024, was triggered when a Wikimedia staff member loaded it during a security review. Once executed, it spread by injecting loaders into both user-level and site-wide JavaScript files, exploiting editor sessions and privileges to propagate automatically. Wikimedia engineers temporarily locked editing across all projects while reverting changes. In a statement, the Foundation said the code was active for just 23 minutes, affected only Meta-Wiki, and caused no permanent damage or personal data breach. All altered content has since been restored. The Foundation said it is developing additional security measures and is providing updates via its public incident log. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/wikipedia-hit-by-self-propagating-javascript-worm-that-vandalized-pages/?ref=metacurity.com)) **Related:** [*Phabricator*](https://phabricator.wikimedia.org/T419143?ref=metacurity.com)*,* [*r/Wikipedia*](https://www.reddit.com/r/wikipedia/comments/1rllcdg/megathread%5Fwikimedia%5Fwikis%5Flocked%5Faccounts/?ref=metacurity.com)*,* [*Abijita*](https://www.abijita.com/wikipedia-hit-by-self-propagating-javascript-worm-that-vandalized-meta-wiki/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/image-29.png) Pages modified by JavaScript worm. Source: BleepingComputer ### The Department of Health and Human Services updated its Risk Identification and Site Criticality (RISC) 2.0 Toolkit to include a dedicated cybersecurity module, placing digital threats alongside physical hazards like hurricanes and power failures in a unified risk assessment platform. The free tool, managed by HHS's Administration for Strategic Preparedness and Response, guides health care facilities through a series of questions benchmarked against the NIST Cybersecurity Framework 2.0 and HHS's own voluntary cybersecurity performance goals. ([Tim Starks / CyberScoop](https://cyberscoop.com/hhs-aspr-cybersecurity-risc-toolkit-update/?ref=metacurity.com)) **Related:** [*HHS*](https://aspr.hhs.gov/RISC/Pages/default.aspx?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/03/06/risc-2-0-cybersecurity-module-healthcare-organizations/?ref=metacurity.com) ### James “Aaron” Bishop has been tapped to serve as the Pentagon’s chief information security officer and deputy CIO for cybersecurity. He assumed the role of CISO in an acting capacity on Feb. 27, according to a LinkedIn post from the Office of the Chief Information Officer. In his new position, he’ll work under DOD CIO Kirsten Davies and be responsible for providing policy, technical, program, and oversight support to the CIO on all cybersecurity matters. ([Jon Harper / DefenseScoop](https://defensescoop.com/2026/03/05/pentagon-ciso-aaron-bishop/?ref=metacurity.com)) **Related:** [*DefenseOne*](https://www.defenseone.com/policy/2026/03/dod-names-james-aaron-bishop-serve-ciso/411930/?ref=metacurity.com)*,* [*Meritalk*](https://www.meritalk.com/articles/bishop-nominated-as-dod-ciso/?ref=metacurity.com) ### Cybersecurity entrepreneur Nir Zuk unveiled his new startup, Cylake, which has raised $45 million in a seed funding round. Greylock Partners led the round with “additional experienced technology investors” also participating. ([Meir Orbach / Calcalist](https://www.calcalistech.com/ctechnews/article/r1ev1gvkbg?ref=metacurity.com)) **Related:** [*Globes*](https://en.globes.co.il/en/article-nir-zuks-cybersecurity-co-cylake-launches-with-45m-1001536851?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/founder-of-palo-alto-networks-started-a-new-cybersecurity-startup-2026-3?ref=metacurity.com)*,* [*Financial Post*](https://financialpost.com/globe-newswire/cylake-launches-to-bring-complete-ai-native-data-driven-cybersecurity-to-customers-that-require-total-data-sovereignty?ref=metacurity.com)*,* [*Greylock Partners*](https://greylock.com/portfolio-news/introducing-cylake-ai-native-cybersecurity-with-total-data-sovereignty/?ref=metacurity.com)*,* [*Ventureburn*](https://ventureburn.com/cylake-raises-45m-seed-to-expand-cybersecurity-platform/?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/privacy-compliance/139318/palo-alto-and-sentinelone-founders-launch-security-company-cylake/?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2026/03/05/cybersecurity-startup-cylake-launches-45m-build-ai-native-data-sovereignty-platform/?ref=metacurity.com) ### Best Thing of the Day: Taking Down Drug Traffickers and Money Launderers Using Two Cell Phones Swedish authorities seized two mobile phones from a local drug trafficker in Swedenin 2023, which [led to the discovery](https://www.europol.europa.eu/media-press/newsroom/news/small-swedish-town-to-global-crime-network-international-operation-strikes-top-tier-organised-crime?ref=metacurity.com) ofmultiple interconnected networks involved in large-scale drug trafficking and money laundering during an operation that Europol calls Operation Candy. ### Worst Thing of the Day: We'll Say You Support ICE If You Don't Click This Button Customers of Emma, a long-running email marketing platform whose clients include Orange Theory, Yale University, Texas A&M University, the Cystic Fibrosis Foundation, Dogfish Head Brewery, and the YMCA, among others, are getting [targeted](https://www.404media.co/ice-phishing-scammers-are-sending-support-ice-emails-to-steal-credentials/?ref=metacurity.com) with a phishing campaign telling them that their emails would begin automatically inserting a “‘Support ICE’ donation button” into every email they send. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/image-30.png) ### Conflicting accounts emerge over Plankey's departure from DHS, future as CISA head URL: https://www.metacurity.com/conflicting-accounts-emerge-over-plankeys-departure-from-dhs-future-as-cisa-head/ Last updated: 2026-03-05T14:38:45.000Z European law enforcement busted up Tycoon2FA phishing platform, FBI and European cops take down cybercrime forum Leakbase, Phobos admin pleads guilty to wire fraud, Lawmakers call for probe into decades-old TEMPEST attacks, IDF says it bombed complex hosting Iran's cyberwar HQ, much more _This post is for paying subscribers only._ ### The Iran war has a cyber story. It's not the one you're reading URL: https://www.metacurity.com/the-iran-war-has-a-cyber-story-its-not-the-one-youre-reading/ Last updated: 2026-03-04T13:57:00.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/03/State_flag_of_the_Imperial_State_of_Iran_-with_standardized_lion_and_sun-.svg-1.png) *Metacurity is the only daily cybersecurity newsletter that is written outside the usual cyber press echosphere and is a refreshing alternative to vendor-driven content and PR-flavored threat intelligence.* *Please consider supporting my work on Metacurity by upgrading your subscription. Thank you.* [Upgrade my subscription](#/portal/account/plans) --- The most striking thing about how the press has covered the cyber angle of the Iran war so far is how consistently the actual findings across most reports contradict those stories’ framing. Nearly every piece leads with the implicit premise that a major Iranian cyber response is imminent, inevitable, or already underway — and then buries the lede that it simply isn't happening. This isn't the first time this year that press coverage has implied a far more dramatic cyber dimension to a US military operation than the evidence supports. When Operation Absolute Resolve targeted Venezuelan leader Nicolás Maduro in January, early reporting treated the Caracas power outage as a "precision cyberattack." In a [piece](https://cyberscoop.com/venezuela-blackout-cyberattack-vs-kinetic-damage-operation-absolute-resolve/?ref=metacurity.com) I wrote for CyberScoop last month, I reported that the reality was considerably messier: videos and photographs from Caracas documented extensive physical damage to at least three substations, and every grid and military expert I spoke with concluded the visible kinetic damage alone was sufficient to account for the outages. Cyber likely played a supporting role — blinding defenders, enabling missiles to get through — but it was not the clean standalone operation the headlines implied. As one expert put it: "If you're going to go in and shoot up the substations, why do you need cyber again?" Iran is a bigger, more capable foe than Venezuela, and the impulse to hype Iran as a cyber adversary is more understandable. But the gap between narrative and reality is, if anything, wider. Bloomberg's [reporting](https://www.bloomberg.com/news/articles/2026-03-02/iranian-hacking-groups-go-dark-amid-us-israeli-military-strikes?ref=metacurity.com) states flatly that Iranian groups have "gone almost entirely dark" and that active pro-Iranian hacking groups have collapsed from more than 130 during the 2025 conflict to just 17\. The piece also quotes security researcher Hamid Kashfi arguing that Iran's cyber capabilities were always more hype than substance, with Western security firms "playing into such concerns to be able to sell their security products." Even Western security firms are now suggesting that Iran’s current cyber [capabilities might be exaggerated](https://www.csoonline.com/article/4011379/iranian-cyber-threats-overhyped-but-cisos-cant-afford-to-let-down-their-guard.html?ref=metacurity.com). CrowdStrike's Adam Meyers, [Cisco Talos](https://blog.talosintelligence.com/talos-developing-situation-in-the-middle-east/?ref=metacurity.com), and [Palo Alto Networks Unit 42](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/?ref=metacurity.com) all independently reached the same conclusion: no large-scale state-sponsored Iranian cyber activity has been observed. The most aggressive confirmed activity is low-level DDoS and website defacements — the digital equivalent of spray paint. Yet across press reports of potential Iranian cyber threats, those findings were packaged in coverage that foregrounded fears of what could happen rather than what is actually happening. A Wall Street Journal [report](https://www.wsj.com/articles/iran-backed-hackers-aim-for-economic-disruption-30c323b5?ref=metacurity.com) follows the same pattern: a parade of former officials — ex-CIA, ex-CISA, ex-FBI, ex-Energy Department — attesting that Iran has the capability, has used it before, and could expand its targets. All true but speculative. None of it is a description of anything that is happening in this conflict. What has actually happened cuts sharply against the narrative that everyone should prepare for Iranian cyber offensives. The most consequential cyber operations of this conflict come from Israel and the US: years of silent camera hacks and mobile network penetration [that built the intelligence picture](https://www.ft.com/content/bf998c69-ab46-4fa3-aae4-8f18f7387836?ref=metacurity.com) enabling Khamenei's assassination; US Cyber Command [disrupting](https://www.defenseone.com/threats/2026/03/cyber-space-commands-were-first-mover-strikes-iran-top-general/411819/?ref=metacurity.com) Iranian communications as a first mover in the operation; a prayer app used by five million Iranians [hijacked](https://www.jpost.com/middle-east/iran-news/article-888267?ref=metacurity.com) to broadcast surrender instructions to IRGC members. Iran's hackers, meanwhile, are largely offline — not because they stood down, but because the [kinetic strikes](https://www.aspistrategist.org.au/beyond-bombs-cyber-and-information-operations-targeting-irans-regime/?ref=metacurity.com) have destroyed the infrastructure they depend on. The actual offensive cyber story of this war runs in one direction only. \[story continues after the paywall break\] _This post is for paying subscribers only._ ### OpenAI, Pentagon revise AI deal's surveillance limits, but commitments may be hollow URL: https://www.metacurity.com/openai-pentagon-revise-ai-deals-surveillance-limits-but-commitments-may-be-hollow/ Last updated: 2026-03-03T14:56:11.000Z Israel spent years hacking Tehran's traffic cameras and phone networks, Iranian hacking groups' efforts have been negligible and opportunistic, Internet collapse in Iran has cut off hackers, Gulf ships bombarded with GPS attacks, Starlink has sustained Iran's Handala hackers, much more _This post is for paying subscribers only._ ### AI safety red lines tested as OpenAI replaces Anthropic in last-minute Pentagon deal URL: https://www.metacurity.com/ai-safety-red-lines-tested-as-openai-replaces-anthropic-in-last-minute-pentagon-deal/ Last updated: 2026-03-02T14:06:49.000Z Israel reportedly hacked a widely used Iranian prayer app to urge military defections, Unconfirmed reports suggest large-scale cyberattacks in Iran, S. Korea's tax service exposed millions of crypto wallets' seed phrases, European retailer ManoMano breach exposed 38m customers' PII, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 2/21/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-2-21-26/ Last updated: 2026-02-28T13:23:33.000Z Tracking down the culprits in the Polish energy cyberattack, How China uses geo-blocking as reverse censorship, How Russia maneuvered spy satellites alongside Western satellites, Secure provenance methods can maintain effective cybersecurity, Uncovering UK crypto exchanges that moved money to Iran _This post is for subscribers only._ ### Gottumukkala is out as acting CISA director URL: https://www.metacurity.com/gottumukkala-is-out-as-acting-cisa-director/ Last updated: 2026-02-27T14:17:58.000Z Intellexa founder and three others sentenced to prison, Anthropic rejects Pentagon's weakened guardrails, Google employees oppose AI use in surveillance and autonomous weapons, Project Compass led to the arrest of 30 mostly young suspects, Medical device maker UFP hit by cyberattack, much more _This post is for paying subscribers only._ ### Cisco, Five Eyes alliance urge immediate patching for Cisco Catalyst SD-WAN zero day URL: https://www.metacurity.com/cisco-five-eyes-alliance-urge-immediate-patching-for-cisco-catalyst-sd-wan-zero-day/ Last updated: 2026-02-26T15:39:06.000Z OpenAI refused to assist in online smear and other misdeeds, Shinyhunters pressures Odido with first leak of stolen data, Only a small fraction of new vulnerabilities are exploited, Mississippi Medical Center closed through Friday, Anthropic denies it won't support military cyber action, much more _This post is for paying subscribers only._ ### Ex-Trenchant exec gets 7+ years for selling hacking tools to Russian zero-day broker URL: https://www.metacurity.com/ex-trenchant-exec-gets-7-years-for-selling-hacking-tools-to-russian-zero-day-broker/ Last updated: 2026-02-25T14:59:06.000Z Rubio orders diplomats to fight against data sovereignty, UNC2814 breached 53 organizations, Anthropic PBC’s chatbot attacked the Mexican government, DHS sued for scanning protestors' faces, Wynn Resorts almost certainly paid ransom, Discord postpones age verification policy, much more _This post is for paying subscribers only._ ### Anthropic says Chinese AI companies siphoned its info using 24,000 fake accounts URL: https://www.metacurity.com/anthropic-says-chinese-ai-companies-siphoned-its-info-using-24-000-fake-accounts/ Last updated: 2026-02-24T14:58:11.000Z _This post is for paying subscribers only._ ### Russian-speaking hacker used multiple genAI services to breach 600+ FortiGate firewalls URL: https://www.metacurity.com/russian-speaking-hacker-used-multiple-genai-services-to-breach-600-fortigate-firewalls/ Last updated: 2026-02-23T14:26:45.000Z Spanish cops bust four Anonymous members for 2025 DDoS attacks, Wynn Resorts is the latest casino victim of ShinyHunters, PayPal business loan app was breached, UAE claims it thwarted multiple cyberattacks, Italian cops spotted cyberattacks on Chinese groups, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 2/14/26 URL: https://www.metacurity.com/next-long-read-6/ Last updated: 2026-02-21T12:26:27.000Z Don't threaten noted cybersecurity researchers, Romance scammers are using AI to exploit victims, Drug cartels are embracing crypto, Chinese hackers exploited insecure VPNs, Chinese bot traffic is flooding the web, Israel gains an edge on automotive spying, A fake DPRK IT worker tells all, more _This post is for subscribers only._ ### African cops bust 651 suspected cyber scammers across 16 countries URL: https://www.metacurity.com/african-cops-bust-651-suspected-cyber-scammers-across-16-countries/ Last updated: 2026-02-20T14:40:39.000Z WVA AG sues Apple over alleged CSAM stored in iCloud, Ukrainian man sentenced to five years for role in DPRK remote IT worker scheme, Systems at Mississippi's only medical center struck down by cyber incident, Predator spyware can shut down recording indicators, much more _This post is for paying subscribers only._ ### Texas AG sues TP-Link, saying it allowed the CCP to hack routers URL: https://www.metacurity.com/texas-ag-sues-tp-link-saying-it-allowed-the-ccp-to-hack-routers/ Last updated: 2026-02-19T14:27:00.000Z A hacker gained access to a French national bank database with 1.2m accounts, Microsoft 365 Copilot bug summarized confidential emails, DEF CON bans Epstein's hacking associates, Deutsche Bahn operations disrupted by cyberattack, Polish army bans Chinese cars, much more _This post is for paying subscribers only._ ### ID documents for billionaires and top politicians at Abu Dhabi conference were exposed online URL: https://www.metacurity.com/id-documents-for-billionaires-and-top-politicians-at-abu-dhabi-conference-were-exposed-online/ Last updated: 2026-02-18T14:42:49.000Z Angola journalist was hacked with Intellexa spyware, Poland arrests Phobos ransomware affiliate, Severe flaw found in Dell RecoverPoint for Virtual Machine, Hacker who paid only a penny for a luxury hotel room busted in Spain, Oz financial technology company YouX suffered a massive breach, much more _This post is for paying subscribers only._ ### DOGE linked to potential Russian, Chinese access to OPM systems, report URL: https://www.metacurity.com/doge-linked-to-potential-russian-chinese-access-to-opm-systems-report/ Last updated: 2026-02-17T13:32:06.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/Milei_y_Elon_Musk_con_una_motosierra-1.jpg) Source: [Argentina.gob](https://www.argentina.gob.ar/noticias/el-presidente-milei-se-reunio-con-elon-musk?ref=metacurity.com) A report issued last week by Democrats on the House Committee on Oversight and Government Reform delivers a damning recounting of the varied ways Elon Musk’s Department of Government Efficiency (DOGE) violated cybersecurity protocols across nearly every executive branch agency — all while dismantling internal security expertise and misleading agency leaders about the damage it was causing. “DOGE illegally deployed systems and forcefully accessed data across federal agencies in clear violation of federal privacy and cybersecurity laws, putting Americans’ data and civil liberties at risk,” the report states. The [document](https://oversightdemocrats.house.gov/imo/media/doc/doge%5Freport.pdf?ref=metacurity.com), titled *Breaking Government: How DOGE and Trump Cost Taxpayers, Federal Workers, and Public Services*, goes beyond procedural failures and raises explicit national security concerns. Most sensationally, the report says that, according to communications shared with Democratic committee staff, experts identified evidence raising concerns about potential Russian and Chinese access to Office of Personnel Management (OPM) servers shortly after DOGE created a government-wide infrastructure to distribute Musk’s infamous “Fork in the Road”[ email](https://www.lawfaremedia.org/article/breaking-down-opm-s--fork-in-the-road--email-to-federal-workers?ref=metacurity.com) across federal agencies. At the time that system was deployed, House Committee Democrats [warned](https://oversightdemocrats.house.gov/imo/media/doc/2025.02.04.%20GEC%20and%20Brown%20to%20OPM-Ezell-%20DOGE%20Emails.pdf?ref=metacurity.com) that “DOGE employees flouted cybersecurity, privacy, and procurement laws to stand up this capability and exposed employees across a wide variety of agencies to spear-phishing and social engineering cyberattacks.” Separately, committee staff also learned that “DOGE employees lowered all firewall protections at OPM to enable the exfiltration of data for use outside of a government environment,” according to the report. “Each of these instances raises serious questions about national security,” the report concludes, noting that OPM holds highly sensitive personnel and operational data that adversarial state and non-state actors could exploit for leverage over federal employees or to infiltrate other government systems. As the report characterizes it, DOGE employees — many who are and were very young workers with connections to Musk or his companies — “brought with them dubious software engineering and cybersecurity practices that may have exposed millions of Americans’ personal information to criminals and foreign governments.” Beyond the OPM allegations — which appear not to have been publicly reported this way before — the report documents a series of additional whistleblower disclosures that, taken together, suggest systemic risk rather than isolated cybersecurity lapses. --- *The rest of today's issue is available only to paid subscribers. Please consider upgrading your subscription to gain access to not only this issue but our archives and other special reports.* *Metacurity goes beyond the usual infosec news echo chamber, highlighting what’s real, overlooked, and often missed by traditional outlets. Please consider supporting our work by upgrading your subscription. Thank you!* [Upgrade my subscription](#/portal/account/plans) --- _This post is for paying subscribers only._ ### Pentagon challenges Anthropic over mass surveillance, autonomous weapons curbs URL: https://www.metacurity.com/pentagon-challenges-anthropic-over-mass-surveillance-autonomous-weapons-curbs/ Last updated: 2026-02-16T14:03:31.000Z UK moves to tighten online safety laws after xAI's Grok debacle, Iran is spying on and retaliating against protestors, DHS is spying on anti-ICE social media posters, Threat actors abuse DNS queries in ClickFix attacks, Tulsa airport confirms attacker access, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 2/7/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-2-7-26/ Last updated: 2026-02-14T14:36:48.000Z Thai citizens are trafficked to unlock bank accounts with facial ID, Texas police deploy AI surveillance with little transparency, Bot swarms threaten democracy, Digital age checks erode privacy, security, and free speech, Promptware attacks could pose Stuxnet-scale cyber threats. _This post is for subscribers only._ ### The imminent DHS shutdown will hamper US ability to respond to cyber threats URL: https://www.metacurity.com/the-imminent-dhs-shutdown-will-hamper-us-ability-to-respond-to-cyber-threats/ Last updated: 2026-02-13T14:36:43.000Z CISA will hold town halls on cyber incident reporting regs, Palo Alto removed China attribution in fear of retaliation, Tianfu Cup returns, Ring cancels partnership with Flock, TX AG launches probe into Conduent breach, AI vibe coding platform Orchids has an unfixed flaw, much more _This post is for paying subscribers only._ ### US drops China Telecom, TP-Link router, and other data security bans before trade talks URL: https://www.metacurity.com/us-drops-china-telecom-tp-link-router-and-other-data-security-bans-before-trade-talks/ Last updated: 2026-02-12T16:11:52.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/SZ_------_Shenzhen_------_Futian_---------_Fumin_Road_---------_Shuiwei_Cun_Village_Tsuen_shop_China_Telecom_May_2023_Px3-1.jpg) Source: [NANSZEIQ HAZEIW 500](https://commons.wikimedia.org/wiki/User:NANSZEIQ%5FHAZEIW%5F500?ref=metacurity.com "User:NANSZEIQ HAZEIW 500")/ **Metacurity has been following cybersecurity, surveillance, and power as they unfold day by day—tracking patterns, context, and connections that most other sources miss**. We go beyond the usual infosec news echo chamber, highlighting what’s real, overlooked, and often missed by traditional outlets. Please consider supporting our work by upgrading your subscription. Thank you! [Upgrade my subscription](#/portal/account/plans) --- ### The Trump administration has shelved a number of key tech security measures aimed at Beijing ahead of an April meeting between the two countries' presidents. The measures include a ban on China Telecom's US operations and restrictions on sales of Chinese equipment for US data centers, sources said. Sources said the US has also put on hold proposed bans on domestic sales of routers made by TP-Link and the US internet business of China Unicom and China Mobile, along with another measure that would bar sales of Chinese electric trucks and buses in the US. They are the latest moves by the Trump administration to rein in US government actions that could antagonize Beijing following a trade truce reached by China’s Xi Jinping and US President Donald Trump in October, the sources said. That meeting also included a pledge by the Chinese to delay painful export restrictions on the rare-earth minerals that underpin tech manufacturing globally. The Commerce Department defended its actions, saying it is actively using its authorities to "address national security risks from foreign technology, and we will continue to do so." All the measures that the administration has now paused were initially aimed at keeping Beijing from accessing and exploiting sensitive American data for blackmail or intellectual property theft and positioning itself deep within internet-connected systems to sabotage critical infrastructure, two of the sources said. ([Alexandra Alper / Reuters](https://www.reuters.com/business/media-telecom/us-china-trade-detente-fuels-mothballing-key-china-tech-curbs-2026-02-12/?ref=metacurity.com)) **Related:** [*Asia Times*](https://asiatimes.com/2026/02/signs-us-china-ties-warmer-after-trump-xi-call-as-tech-curbs-loom/?ref=metacurity.com) ### Researchers at Chainalysis found that crypto-funded transactions for human trafficking—largely forced laborers trapped in compounds across Southeast Asia and coerced into working as online scammers, as well as sex-trafficking prostitution rings—grew explosively in 2025. Researchers found that crypto transactions for human trafficking grew at least 85 percent year over year. The total amount of those transactions, Chainalysis says, is now at least in the hundreds of millions of dollars annually—though it declined to give an exact number for that sales total because it considered its measurements to be a conservative estimate that likely undercounts the true scale of the issue. The human trafficking operations Chainalysis identified in its research were primarily Chinese-speaking criminal groups posting advertisements for their offerings to the messaging service Telegram. Many of the posts were found on “guarantee” black markets that run on Telegram channels, such as Xinbi Guarantee and the recently defunct Tudou Guarantee, which offer escrow services that accept and hold cryptocurrencies to prevent users from being defrauded. Chainalysis says it also identified other independent Telegram channels selling prostitution services. ([Andy Greenberg / Wired](https://www.wired.com/story/crypto-funded-human-trafficking-is-exploding/?ref=metacurity.com)) ***Related:*** [*Chainalysis*](https://www.chainalysis.com/blog/crypto-human-trafficking-2026/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/image-38.png) Source: Chainalysis. ### In a court filing, US prosecutors confirmed that Peter Williams, the former boss of a US maker of hacking and surveillance tools, stole and sold technology that can hack millions of computers and people worldwide. In October, Williams pleaded guilty to selling eight hacking tools that he stole from his employer, Trenchant, a division of the US defense contractor L3Harris, which sells its surveillance-enabling tools to the US government and its closest allies. Williams admitted to making more than $1.3 million in crypto from the sales between 2022 and 2025, per the Justice Department. Federal prosecutors said Williams’ actions “directly harmed” the US intelligence community by selling the hacking tools to a Russian company, which counts the Russian government among its customers. While it was known that Williams sold Trenchant’s exploits — software that takes advantage of flaws in other software, usually to gain access to someone’s computer or device — prosecutors now say that these eight tools could have been used to indiscriminately enable government surveillance, cybercrime, and ransomware attacks across the globe. This latest disclosure comes ahead of Williams’ anticipated sentencing on February 24 in a Washington, DC, federal court. ([Lorenzo Franceschi-Bicchierai / TechCrunch](https://techcrunch.com/2026/02/11/doj-says-trenchant-boss-sold-exploits-to-russian-broker-capable-of-accessing-millions-of-computers-and-devices/?ref=metacurity.com)) ### Researchers at Google Threat Intelligence Group report that state-backed hackers are using Google's Gemini AI model to support all stages of an attack, from reconnaissance to post-compromise actions. Bad actors from China (APT31, Temp.HEX), Iran (APT42), North Korea (UNC2970), and Russia used Gemini for target profiling and open-source intelligence, generating phishing lures, translating text, coding, vulnerability testing, and troubleshooting. Cybercriminals are also showing increased interest in AI tools and services that could help in illegal activities, such as social engineering ClickFix campaigns. Chinese threat actors employed an expert cybersecurity persona to request that Gemini automate vulnerability analysis and provide targeted testing plans in the context of a fabricated scenario. Another China-based actor frequently employed Gemini to fix their code, carry out research, and provide advice on technical capabilities for intrusions. The Iranian adversary APT42 leveraged Google's LLM for social engineering campaigns, as a development platform to speed up the creation of tailored malicious tools (debugging, code generation, and researching exploitation techniques). Additional threat actor abuse was observed for implementing new capabilities into existing malware families, including the CoinBait phishing kit and the HonestCue malware downloader and launcher. GTIG notes that no major breakthroughs have occurred in that respect, though the tech giant expects malware operators to continue to integrate AI capabilities into their toolsets. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/google-says-hackers-are-abusing-gemini-ai-for-all-attacks-stages/?ref=metacurity.com)) **Related:** [*Google Cloud*](https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use?ref=metacurity.com)*,* [*SDxCentral*](https://www.sdxcentral.com/news/google-report-exposes-ways-threat-actors-use-ai-to-speed-up-attacks/?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/138734/google-sees-increase-in-ai-abuse-by-cybercriminals/?ref=metacurity.com)*,* [*IT Pro*](https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models?ref=metacurity.com)*,* [*AI News*](https://www.artificialintelligence-news.com/news/state-sponsored-hackers-ai-cyberattacks-google/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2026/02/12/google%5Fchina%5Fapt31%5Fgemini/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/nation-state-hackers-gemini-ai/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/nation-state-hackers-using-gemini-for-malicious-campaigns?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/image-39.png) HonestCue operational overview. Source: Google ### Apple released security updates to fix a zero-day vulnerability that was exploited in an "extremely sophisticated attack" targeting specific individuals. Tracked as CVE-2026-20700, the flaw is an arbitrary code execution vulnerability in dyld, the Dynamic Link Editor used by Apple operating systems, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. Apple's security bulletin warns that an attacker with memory write capability may be able to execute arbitrary code on affected devices. Apple says it is aware of reports that the flaw, along with the CVE-2025-14174 and CVE-2025-43529 flaws fixed in December, were exploited in the same incidents. "An attacker with memory write capability may be able to execute arbitrary code," reads Apple's security bulletin. Apple says Google's Threat Analysis Group discovered CVE-2026-20700\. The company did not provide any further details about how the vulnerability was exploited. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/apple-fixes-zero-day-flaw-used-in-extremely-sophisticated-attacks/?ref=metacurity.com)) ***Related:*** [*Apple*](https://support.apple.com/en-us/126346?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/187890/security/apple-fixed-first-actively-exploited-zero-day-in-2026.html?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/apple-zero-day-vulnerability-actively-exploited-in-sophisticated-targeted-attacks/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/davidphelan/2026/02/02/apple-releases-iphone-software-update-to-address-emergency-call-issue/?ref=metacurity.com)*,* [*Macworld*](https://www.macworld.com/article/3058798/update-now-ios-26-3-contains-dozens-of-critical-security-fixes.html?ref=metacurity.com)*,* [*Apple Insider*](https://appleinsider.com/articles/26/02/11/apple-didnt-forget-macos-sonoma-macos-sequoia-ios-18-on-patch-day?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2026/02/11/ios-26-3-has-fixes-for-35-security-issues-on-iphone-details-here/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/apple-patches-ios-zero-day-exploited-in-extremely-sophisticated-attack/?ref=metacurity.com)*,* [*Cryptopolitan*](https://www.cryptopolitan.com/apple-ships-updates-after-exploitation/?ref=metacurity.com)*,* [*MacRumors*](https://www.macrumors.com/2026/02/11/ios-26-3-security-vulnerabilities/?ref=metacurity.com) ### Korea's privacy watchdog, the Personal Information Protection Commission, has fined the Korean units of luxury brands Louis Vuitton, Dior, and Tiffany a combined 36 billion won ($24.9 million) over leaks of customer information. The Commission decided in a plenary meeting the previous day, imposing on Louis Vuitton Korea a fine of 21.4 billion won — the heaviest among the three companies — over a data breach of about 3.6 million customers. The watchdog said an outside actor stole user information in three instances by hacking into an employee's device with malicious code. It noted the company had poor security practices, such as not enforcing proper safety protocols for remote logins. Meanwhile, the regulator fined Christian Dior Couture Korea and Tiffany Korea 12.2 billion won and 2.4 billion won, respectively, for data breaches after employees were tricked into granting internal system access to malicious actors. Dior suffered a data breach of about 1.95 million users and was unaware of the incident for three months, while the leak at Tiffany involved the personal information of around 4,600 users, according to the watchdog. ([Yonhap News](https://koreajoongangdaily.joins.com/news/2026-02-12/business/industry/Korean-units-of-luxury-brands-fined-36-billion-won-for-major-customer-data-leaks/2522600?ref=metacurity.com)) **Related:** [*The Chosun Daily*](https://www.chosun.com/english/national-en/2026/02/12/Z56BNDAIAVGYFBAWQFLHCBBV4Q/?ref=metacurity.com) ### The WhatsApp messenger domain (owned by Meta, which is considered extremist and banned in Russia) has disappeared from the records of the National Domain Name System (NDNS), the infrastructure created under the "sovereign RuNet" law. Only the domains whatsapp.com and web.whatsapp.com have disappeared from the NSDI, but the technical domain for the messenger whatsapp.net and the domain for quick links wa.me are still listed on the NSDI. The YouTube domain also disappeared from the NSDI. In October 2024, Discord and Signal were similarly "disabled" in Russia using NSDI technology. The Kremlin announced it banned WhatsApp for failing to comply with local law. “Due to Meta’s unwillingness to comply with Russian law, such a decision was indeed made and implemented,” Kremlin spokesman Dmitry Peskov told reporters, proposing that Russians switch to MAX, Russia’s state-owned messenger. “MAX is an accessible alternative, a developing messenger, a national messenger, and it is available on the market for citizens as an alternative,” said Peskov. Critics say MAX is a surveillance tool, something the authorities deny. The move against WhatsApp is the culmination of six months of pressure on the US company and reflects a wider push by the Russian authorities at a time of war to create and control a “sovereign” communications infrastructure in which foreign-owned tech companies submit to local laws or disappear. ([Kommersant ](https://www.kommersant.ru/doc/8421763?ref=metacurity.com)and [Andrew Osborn and Mrinmay Dey / Reuters](https://www.reuters.com/technology/russia-blocks-metas-whatsapp-messaging-service-ft-reports-2026-02-12/?ref=metacurity.com)) **Related*:* [*CNBC*](https://www.cnbc.com/2026/02/12/russia-whatsapp-meta-max.html?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/world/2026/feb/12/russia-attempt-block-whatsapp-meta-says?ref=metacurity.com)*,* [*Newsweek*](https://www.newsweek.com/russia-attempting-fully-block-whatsapp-11509280?ref=metacurity.com)*,* [*BBC News*](https://www.bbc.com/news/articles/clygd10pg5lo?ref=metacurity.com)*,* [*Associated Press*](https://www.wsbtv.com/news/business/whatsapp-says-russia/FDNQBK6HCEZTPGAFGN4FIBKRVU/?ref=metacurity.com)*,* [*Semafor*](https://www.semafor.com/article/02/12/2026/russia-seeks-to-block-whatsapp-amid-crackdown?mid=1&ref=metacurity.com#cid=3387336)*,* [*CyberInsider*](https://cyberinsider.com/russia-moves-to-block-whatsapp-as-crackdown-on-messengers-continues/?mid=1&ref=metacurity.com#cid=3387147)*,* [*The Morning Call*](https://www.mcall.com/2026/02/12/whatsapp-russia-tried-blocking-app/?mid=1&ref=metacurity.com#cid=3387130)*,* [*Los Angeles Daily News*](https://www.dailynews.com/2026/02/12/whatsapp-russia-tried-blocking-app/?mid=1&ref=metacurity.com#cid=3387252)*,* [*The420CyberNews*](https://the420.in/russia-blocks-whatsapp-state-app-max/?mid=1&ref=metacurity.com#cid=3387032)*,* [*JURIST – News*](https://www.jurist.org/news/2026/02/russia-telegram-block-condemned-as-a-blow-to-freedom-of-expression-by-rights-group/?mid=1&ref=metacurity.com#cid=3386975)*,* [*UA Wire*](https://www.uawire.org/ukraine-pushes-back-as-russia-targets-hulyaipole-pokrovsk-and-myrnohrad?mid=1&ref=metacurity.com#cid=3386900)*,* [*CyberInsider*](https://cyberinsider.com/russia-moves-to-block-whatsapp-as-crackdown-on-messengers-continues/?mid=1&ref=metacurity.com#cid=3387341)*,* [*SQ Magazine*](https://sqmagazine.co.uk/russia-whatsapp-ban-max-app-push/?mid=1&ref=metacurity.com#cid=3387395) ### Dutch telecom provider Odido has been hit by a major cyberattack, with criminals gaining access to a file containing the data of 6.2 million accounts. The system also contained data from customers of Ben, which is part of Odido. This does not apply to customers of Simpel, another brand of the provider. Customer data includes full name, address, phone number, customer number, email address, account number, date of birth, and the number and expiration date of identity documents such as passports or driver's licenses. The data breached may vary per customer. According to the company, the stolen data has not been published online. Odido cannot rule out the possibility of the data being made public in the future. "We advise all customers to be extra vigilant for suspicious activity or unexpected contact," the company writes. Odido declined to comment on whether it was pressured or blackmailed by the hackers. "On the advice of our experts, we are not currently making any statements about the possible identity or background of the attacker." ([NOS](https://nos.nl/artikel/2602080-hack-bij-odido-gegevens-miljoenen-klanten-in-handen-van-criminelen?ref=metacurity.com)) ***Related:*** [*Odido*](https://www.odido.nl/veiligheid?ref=metacurity.com)*,* [*NL Times*](https://nltimes.nl/2026/02/12/odido-cyber-attack-hackers-gained-access-62-million-peoples-data?ref=metacurity.com)*,* [*Dutch News*](https://www.dutchnews.nl/2026/02/hackers-access-odido-customer-info-6-2-million-could-be-hit/?ref=metacurity.com) ### The two people have been charged with “serious security offences and offences of bribery and obstruction of justice”, the Israeli defence ministry, Shin Bet internal security service, and police said in a joint statement. The two people have been charged with “serious security offences and offences of bribery and obstruction of justice”, the Israeli defence ministry, Shin Bet internal security service, and police said in a joint statement. An Israeli court issued a gag order prohibiting publication of further details of the case. However, the agencies said that several people had recently been arrested on suspicion of gambling on Polymarket on “the occurrence of military operations, based on classified information to which the reservists were exposed by virtue of their position in the army." ([James Shotter and Chris Cook / Financial Times](https://www.ft.com/content/39ab13aa-7ae9-4a24-9200-2bab44b8022a?ref=metacurity.com)) **Related:** [*Jerusalem Post*](https://www.jpost.com/israel-news/crime-in-israel/article-886456?ref=metacurity.com)*,* [*Associated Press*](https://apnews.com/article/israel-military-betting-polymarket-security-charges-a7f848f7b0aa75fe743ab72f61de1327?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/post/389575/israeli-defense-reservist-civilian-indicted-over-alleged-insider-betting-on-polymarket-reports?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/world/israel/israel-charges-reservist-classified-information-bet-polymarket-rcna258709?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/israel-indicts-reservist-for-using-military-data-on-polymarket/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-02-12/israelis-charged-with-using-classified-intel-for-polymarket-bets?ref=metacurity.com) ### The trial of a Russian man, Ilia D., accused of being an affiliate of the Phobos ransomware group between 2019 and 2022, began yesterday in Paris. He is suspected of having carried out more than a hundred attacks from Russia, including several dozen in France, using ransomware. He and his wife were arrested in the summer of 2023 during a trip to Italy. He is being tried for multiple offenses against a computer system, extortion, aggravated money laundering, and criminal conspiracy. His partner, 34, faces charges of failing to justify her income and criminal conspiracy. ([Florian Reynaud / Le Monde](https://www.lemonde.fr/pixels/article/2026/02/11/a-paris-la-cybercriminalite-ordinaire-au-proces-d-un-couple-accuse-d-attaques-par-rancongiciel%5F6666255%5F4408996.html?ref=metacurity.com)) **Related:** [*ZDNet*](https://www.zdnet.fr/actualites/ce-business-juteux-autour-du-rancongiciel-phobos-489949.htm?ref=metacurity.com) ### Microsoft fixed a "remote code execution" vulnerability in Windows 11 Notepad that allowed attackers to execute local or remote programs by tricking users into clicking specially crafted Markdown links, without displaying any Windows security warnings. As part of the February 2026 Patch Tuesday updates, Microsoft disclosed that it fixed a high-severity Notepad remote code execution flaw tracked as CVE-2026-20841. "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code over a network," explains Microsoft's security bulletin. Microsoft has attributed the discovery of the flaw to Cristian Papa, Alasdair Gorniak, and Chen, and says it can be exploited by tricking a user into clicking a malicious Markdown link. "An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files," explains Microsoft. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/microsoft/windows-11-notepad-flaw-let-files-execute-silently-via-markdown-links/?ref=metacurity.com)) **Related:** [*Microsoft Security*](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2026/02/11/notepad%5Frce%5Fflaw/?ref=metacurity.com)*,* [*Business Standard*](https://www.business-standard.com/technology/tech-news/microsoft-plugs-remote-code-vulnerability-in-notepad-app-on-windows-11-126021200502%5F1.html?ref=metacurity.com)*,* [*Windows Latest*](https://www.windowslatest.com/2026/02/12/microsoft-confirms-8-8-rated-security-issue-in-windows-11-notepad-due-to-modernization-efforts-patch-tuesday-fix-rolling-out/?ref=metacurity.com)*,* [*Pureinfotech*](https://pureinfotech.com/fix-notepad-markdown-security-bug-windows-11/?ref=metacurity.com)*,* [*XDA Developers*](https://www.xda-developers.com/microsoft-patches-critical-notepad-flaw-that-exploited-markdown-files/?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2026/02/11/microsoft-patches-notepad-rce-vulnerability-cve-2026-20841-xcxwbn/?ref=metacurity.com)*,* [*PCWorld*](https://www.pcworld.com/article/3058647/?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/bloat-risk-microsofts-notepad-upgrade-also-introduced-a-vulnerability?ref=metacurity.com)*,* [*OSnews*](https://www.osnews.com/story/144385/microsoft-adds-and-fixes-remote-code-execution-vulnerability-in-notepad/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/tech/877295/microsoft-notepad-markdown-security-vulnerability-remote-code-execution?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/microsoft-patches-notepad-flaw-that-could-let-attackers-hijack-windows-pcs/?ref=metacurity.com)*,* [*r/technews*](https://www.reddit.com/r/technews/comments/1r2i84x/microsoft%5Fhas%5Ffixed%5Fa%5Fremote%5Fcode%5Fexecution%5Fin/?ref=metacurity.com)*,* [*r/cybersecurity*](https://www.reddit.com/r/cybersecurity/comments/1r24set/notepads%5Fnew%5Fmarkdown%5Fpowers%5Fserved%5Fwith%5Fa%5Fside/?ref=metacurity.com) ### According to researchers at supply chain security company Koi, The AgreeTo add-in for Outlook has been hijacked and turned into a phishing kit that stole more than 4,000 Microsoft account credentials. Originally a legitimate meeting scheduling tool for Outlook users, the module was developed by an independent publisher and has been on the Microsoft Office Add-in Store since December 2022. Office add-ins are just URLs pointing to content loaded into Microsoft products from the developer's server. In the case of AgreeTo, the developer used a Vercel-hosted URL (outlook-one.vercel.app) but abandoned the project, despite the userbase it formed. However, the add-in continued to be listed on Microsoft's store, and a threat actor claimed its orphaned URL to plant a phishing kit. The threat actor taking over the project deployed a fake Microsoft sign-in page, a password collection page, an exfiltration script, and a redirect. Koi researchers discovered the compromise and accessed the attacker's exfiltration channel. They found that over 4,000 Microsoft account credentials had been stolen, along with credit card numbers and banking security answers. The researchers found that the operator behind this attack runs at least a dozen additional phishing kits targeting internet service providers, banks, and webmail providers. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/microsoft-store-outlook-add-in-hijacked-to-steal-4-000-microsoft-accounts/?ref=metacurity.com)) **Related:** [*Koi AI*](https://www.koi.ai/blog/agreetosteal-the-first-malicious-outlook-add-in-leads-to-4-000-stolen-credentials?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/malicious-microsoft-outlook-add-in-stole-4000-account-credentials-and-credit-card-details/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/microsoft-outlook-add-in-stolen-credentials/?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/microsoft-outlook-add-in-stolen-4000-accounts/?ref=metacurity.com)*,* [*Tech Nadu*](https://www.technadu.com/malicious-outlook-add-in-agreetosteal-compromises-4000-accounts-via-subdomain-takeover/619959/?ref=metacurity.com)*,* [*Windows Report*](https://windowsreport.com/hackers-hijack-outlook-add-in-to-steal-4000-microsoft-accounts/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/image-40.png) Phishing page (left) and exfiltration logic (right. Source: Koi Security ### Researchers at Malwarebytes say that a fake 7-Zip website is distributing a trojanized installer of the popular archiving tool that turns the user’s computer into a residential proxy node. Residential proxy networks use home user devices to route traffic with the goal of evading blocks and performing various malicious activities such as credential stuffing, phishing, and malware distribution. The new campaign became better known after a user reported that they downloaded a malicious installer from a website impersonating the 7-Zip project while following instructions in a YouTube tutorial on building a PC system. BleepingComputer can confirm that the malicious website, 7zip\[.\]com, is still live. The threat actor registered the domain *7zip\[.\]com* (still live at the time of writing) that can easily trick users into thinking they landed on the site of the legitimate tool. Furthermore, the attacker copied the text and mimicked the structure of the original 7-Zip website located at 7-zip.org. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/malicious-7-zip-site-distributes-installer-laced-with-proxy-tool/?ref=metacurity.com)) ***Related:*** [*Malwarebytes*](https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes?ref=metacurity.com)*,* [*Tom's Hardware*](https://www.tomshardware.com/tech-industry/cyber-security/unofficial-7-zip-com-website-served-up-malware-for-10-days-files-turned-pcs-into-a-proxy-botnet?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/fake-7-zip-website-distributes-trojanized-installer-turns-pcs-into-proxy-nodes?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/image-41.png) Malicious website dropping the trojanized 7-Zip. Source: BleepingComputer ### The time between vulnerability disclosure and exploitation has plunged 94% over the past five years as threat actors weaponize so-called “n-days,” according to a new Flashpoint study. The threat intelligence vendor claimed that “time to exploit” (TTE) dropped from 745 days in 2020 to just 44 days last year, dramatically reducing the time security and IT teams have to patch. Driving this trend is the growing use of n-day exploits, which relate to vulnerabilities that have been publicly disclosed but remain unpatched by organizations. Flashpoint claimed that n-days now represent over 80% of the CVEs listed in its Known Exploited Vulnerabilities (KEV) database, VulnDB. ([Phil Muncaster / Infosecurity Magazine](https://www.infosecurity-magazine.com/news/time-exploit-plummets-nday-flaws/?ref=metacurity.com)) **Related:** [*Flashpoint*](https://flashpoint.io/blog/n-day-vulnerability-trends-turn-key-exploitation/?ref=metacurity.com) ### Asahi Group Holdings Ltd. said that its sales of beer and beer-like beverages in January fell 11 percent on a value basis from a year earlier on the lingering impact of a system failure caused by a cyberattack last year. Although the Japanese beverage giant has resumed its online order-taking system, shipments of all products have yet to restart, the company said. Other than alcoholic beverages, sales volume at Asahi Soft Drinks Co., which deals with soft drinks including "Mitsuya Cider" carbonated drink, dropped 16 percent. Estimated sales at Asahi Group Foods Ltd., which handles food items and powdered milk, were slightly higher than the previous year. ([The Mainichi](https://mainichi.jp/english/articles/20260212/p2g/00m/0bu/033000c?ref=metacurity.com)) ***Related:*** [*Just Drinks*](https://www.just-drinks.com/news/asahi-domestic-beer-sales-remain-under-pressure/?ref=metacurity.com)*,* [*Nippon.com*](https://www.nippon.com/en/news/yjj2026021200589/?ref=metacurity.com)*,* [*NHK*](https://www3.nhk.or.jp/nhkworld/en/news/20260212%5F14/?ref=metacurity.com) ### Google rolled out Chrome 145.0.7632.45 for Windows, Mac, and Linux in the Stable Channel, addressing 11 critical security flaws. Announced on February 10, this update patches vulnerabilities that could let attackers execute malicious code on users’ devices, potentially stealing data or installing malware. The rollout happens gradually over days or weeks to ensure stability. These fixes target serious issues like use-after-free errors and buffer overflows, common tricks hackers use to crash browsers and run arbitrary code. ([AnuPriya / CyberPress](https://cyberpress.org/chrome-security-update-patches-vulnerabilities-2/?ref=metacurity.com)) **Related*:* [*Chrome*](https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop%5F10.html?ref=metacurity.com)*,* [*Q's Substack*](https://qcontinuum.substack.com/p/spying-chrome-extensions-287-extensions-495) ### Researchers at Huntress report that a member of the Crazy ransomware gang is abusing legitimate employee monitoring software and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment. In one intrusion, attackers installed Net Monitor for Employees Professional using the Windows Installer utility, msiexec.exe, allowing them to deploy the monitoring agent on compromised systems directly from the developer's site. Once installed, the tool allowed attackers to remotely view the victim's desktop, transfer files, and execute commands, effectively providing full interactive access to compromised systems. The attackers also attempted to enable the local administrator account. In one incident, the hackers configured monitoring rules in SimpleHelp to alert them when devices accessed cryptocurrency wallets or were using remote management tools as they prepared for ransomware deployment and potential cryptocurrency theft. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses-employee-monitoring-tool-in-attacks/?ref=metacurity.com)) **Related:** [*Huntress*](https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/employee-monitoring-software-exploited/?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/simplehelp-tools/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/threat-actors-leveraging-employee-monitoring-and-simplehelp-tools/?ref=metacurity.com) ### According to new research from ReversingLabs, North Korea's Lazarus Group’s latest software supply chain operation is using fake recruiter lures and popular open‑source ecosystems to deliver malware to cryptocurrency‑focused developers quietly. The campaign, dubbed graphalgo, abuses GitHub, npm, and PyPI to hide multi‑stage payloads behind seemingly legitimate coding tasks and packages. Since early May 2025, attackers have been approaching JavaScript and Python developers via LinkedIn, Facebook, and Reddit forums with “test” tasks that appear to be part of a normal interview process. To support the ruse, the attackers built a fake company persona called “Veltrix Capital,” complete with domains like veltrixcap\[.\]org and veltrixcapital\[.\]ai and corresponding GitHub organizations hosting coding projects. Under the Veltrix‑branded GitHub accounts, the threat actors published multiple repositories with names such as test‑url‑monitoring and test‑devops‑orchestrator in both JavaScript and Python. The campaign includes a malicious npm package, bigmathutils, which collected more than 10K downloads since publishing the original, non-malicious version. ([Mayura Kathir / GBHackers](https://gbhackers.com/lazarus-groups-graphalgo/?ref=metacurity.com)) **Related:** [*Reversing Labs*](https://www.reversinglabs.com/blog/fake-recruiter-campaign-crypto-devs?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/lazarus-groups-graphalgo-fake-recruiter-campaign/?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/lazarus-group-distributes-graphalgo-malwar/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/image-42.png) Campaign overview. Source: Reversing Labs. ### New data from the Food and Agriculture Information Sharing and Analysis Center (Food and Ag-ISAC) shows ransomware activity escalated in 2025, with Qilin, Akira, CL0P, Play, and Lynx leading attacks against the food and agriculture sector. In partnership with the IT-ISAC, the organization recorded approximately 6,377 ransomware incidents across sectors, an 82% increase from the 3,508 cases tracked in 2024\. Since launching its monitoring effort in 2020, the joint initiative has documented more than 15,265 ransomware attacks using automated tools that collect data from public breach disclosures, RSS feeds, dark web leak sites, and internal threat intelligence sources. It also detailed a comparison of ransomware activity across sectors in 2025, showing that critical manufacturing was the most targeted, with 1,440 attacks, accounting for 22.7% of all tracked incidents. The commercial facilities sector followed with 1,107 attacks, representing 17.5% of the total. The information technology sector recorded 746 attacks, or 11.8%, while healthcare and public health experienced 580 incidents, accounting for 9.2%. The financial services sector saw 463 attacks, representing 7.3%. Although not classified as critical infrastructure, the legal sector also stood out, with 313 attacks, or 4.9% of all recorded incidents. ([Anna Ribeiro / Industrial Cyber](https://industrialcyber.co/reports/food-and-ag-isac-reports-82-surge-in-ransomware-attacks-as-qilin-akira-and-cl0p-lead-campaigns-against-sector/?ref=metacurity.com)) ***Related:*** [*Food AG-ISAC*](https://www.foodandag-isac.org/resources?ref=metacurity.com) ### Israeli cybersecurity giant Check Point is buying two AI security start-ups, Cyclops Security and Cyata, as well as MSP-focused security company Rotate. The valuation of the deals was not disclosed but is estimated at around $150 million in total, with around $85 million going towards the purchase of Cyclops, according to estimates. Separately, Check Point in its latest earnings report says its calculated billings topped $1 billion for the first time as demand for its security products accelerated. ([Meir Ohrbach / CTech](https://www.calcalistech.com/ctechnews/article/rjnbhfipwl?ref=metacurity.com) and [Ignacio Gonzalez / Bloomberg](https://www.bloomberg.com/news/articles/2026-02-12/check-point-s-billings-reach-record-1-billion-on-ai-demand?embedded-checkout=true&ref=metacurity.com)) **Related:** [*Check Point*](https://www.checkpoint.com/press-releases/check-point-software-reports-fourth-quarter-and-2025-full-year-results/?ref=metacurity.com)*,* [*Globes*](https://en.globes.co.il/en/article-check-point-buys-3-israeli-startups-for-over-150m-1001534878?ref=metacurity.com) ### Best Thing of the Day: Cracking Down on Data Leakers The Democratic Party of Korea[ proposed a bill](https://www.chosun.com/english/national-en/2026/02/12/L4DQY4HWLBAZTJIDHQFFSLAZJQ/?ref=metacurity.com) that would impose liability for damages in the event of a personal information leak, even if there was no intent or negligence by the company. ### Worst Thing of the Day: No Search of the Epstein Files Is Safe from DOJ Surveillance The US DOJ [is surveilling](https://alecmuffett.com/article/145299?mid=1&ref=metacurity.com#cid=3387046) the Epstein files searches by members of Congress to use against them in rhetorical attacks. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/02/image-37.png) ### CISA warns US infrastructure owners following Russian attack on Poland's power grid URL: https://www.metacurity.com/cisa-warns-us-infrastructure-owners-following-russian-attack-on-polands-power-grid/ Last updated: 2026-02-11T14:12:48.000Z Russia throttles Telegram accusing it of failing to protect personal data or combat crime, N. Korean hackers targeted crypto company with unique malware and multiple scams, Israel claims it foiled hundreds of Iranian cyberattacks, Microsoft issued fixes for six zero day flaws, much more _This post is for paying subscribers only._ ### Defense companies face a 'relentless barrage' of cyberespionage, Google URL: https://www.metacurity.com/defense-companies-face-a-relentless-barrage-of-cyberespionage-google/ Last updated: 2026-02-10T14:06:08.000Z Fugitive sentenced to 2 years for pig butchering money laundering, Coupang data breach scope was more massive than reported, Discord to demand face scans or government IDs, Hacktivist scraped 500k payment records from stalkerware apps, Promotei botnet still excels at stealing passwords, much more _This post is for paying subscribers only._ ### The European Commission's mobile device platform was hacked URL: https://www.metacurity.com/the-european-commissions-mobile-device-platform-was-hacked/ Last updated: 2026-02-09T15:14:37.000Z All four Singapore major telcos were hacked via China-nexus threat actor, Poland's most egregious database leaker has been busted, Romanian pipeline operator hit by a cyberattack, Germany warns of state-sponsored phishing attacks via messaging apps, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 1/31/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-31-26/ Last updated: 2026-02-07T13:24:04.000Z Indian women are crushed by hours of abusive content, German-language Telegram channels spread Russian disinformation, China has a covert spy-cam porn industry, Fears over TikTok's policy changes are really fears of the tech industry, Canada is moving away from US intelligence in space _This post is for subscribers only._ ### Claude Opus 4.6 found 500+ severe flaws in open source repos without much prompting URL: https://www.metacurity.com/claude-opus-4-6-found-500-severe-flaws-in-open-source-repos-without-much-prompting/ Last updated: 2026-02-06T15:03:20.000Z Asian cyberespionage group broke into sensitive systems in 37+ countries, ICE's Mobile Fortify does not reliably ID people, CISA tells agencies to stop using edge devices past EOS, 764 member busted and charged with receiving CSAM, French cops bust four with spying on Starlink for China, much more _This post is for paying subscribers only._ ### Italy says it foiled Russian cyberattacks on foreign ministries, Olympics websites URL: https://www.metacurity.com/italy-says-it-foiled-russian-cyberattacks-on-foreign-ministries-olympics-websites/ Last updated: 2026-02-05T14:33:36.000Z NFL deploys cyber squad to secure Super Bowl, ShinyHunters takes credit for UPenn and Harvard attacks, Ransomware gangs are exploiting high-severity VMware ESXi sandbox escape vulnerability, Canada Computers & Electronics breach reached 1,300, SystemBC malware affects 10K IP addresses, much more _This post is for paying subscribers only._ ### Russian space vehicles are tapping comms from key European satellites, report URL: https://www.metacurity.com/russian-space-vehicles-are-tapping-comms-from-key-european-satellites-report/ Last updated: 2026-02-04T15:19:23.000Z Incognito Market operator sentenced to 30 years, CISA silently tweaked CVEs used for ransomware attacks, Russian hackers reportedly disabled critical Ukraine military registration platforms, Hackers and trolls are targeting ICE spotting apps, Coinbase confirms new insider breach, more _This post is for paying subscribers only._ ### Hot new social network Moltbook exposed 1+ million credentials URL: https://www.metacurity.com/hot-new-social-network-moltbook-exposed-1-million-credentials/ Last updated: 2026-02-03T15:28:34.000Z Chinese state actors were likely behind Notepad++ hijacking, Bill to allow the Russian government to shut down comms networks moves forward, ICE uses app that accesses 1.2B facial images, Mountain View disables license plate cameras in wake of violations, much more _This post is for paying subscribers only._ ### StopICE platform reportedly hit by a breach, 100k users' data exposed to US feds URL: https://www.metacurity.com/stopice-platform-reportedly-hit-by-a-breach-100k-users-data-exposed-to-us-feds/ Last updated: 2026-02-02T14:44:43.000Z Social media site for AI agents Moltbook left APIs exposed, 28 malicious skills are targeting Claude Code and Moltbot users, Russian Legion warned Denmark of large-scale cyberattack, Notepad++ is probing reported security incidents, US DoJ seized pirated content domains, more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 1/24/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-24-26/ Last updated: 2026-01-31T14:23:01.000Z Scam compound captive risks it all to expose its inner workings, AI is a core source of geopolitical power and security, Regulators should jettison checkbox cyber compliance with innovations, AI-led cybersecurity superintelligence is coming, AI's dual-use capabilities are transforming cybersecurity _This post is for subscribers only._ ### US ODNI drops her remit to investigate 2020 election fraud claims URL: https://www.metacurity.com/us-odni-drops-her-remit-to-investigate-2020-election-fraud-claims/ Last updated: 2026-01-30T15:20:42.000Z US law enforcement are probing if WhatsApp employees can read users' messages, Popular AI app exposes millions of users' private messages, Darkweb market Empire Market creator pleads guilty, US seizes $400m in darknet crypto mixer Helix's assets, UK safety charity warns about The Com, much more _This post is for paying subscribers only._ ### The FBI seized the notorious RAMP cybercrime forum URL: https://www.metacurity.com/the-fbi-seized-the-notorious-ramp-cybercrime-forum/ Last updated: 2026-01-29T15:16:27.000Z Google took down dozens of domains related to mysterious threat actor Ipidea, China executed 11 people linked to Myanmar scam centers, Moltbot AI assistant can leak sensitive information, ShinyHunters hit Bumble, Panera, Match and CrunchBase, Poland's grid attack disabled comms at 30 sites, more _This post is for paying subscribers only._ ### The interim head of CISA uploaded sensitive documents to ChatGPT URL: https://www.metacurity.com/the-interim-head-of-cisa-uploaded-sensitive-documents-to-chatgpt/ Last updated: 2026-01-28T14:14:00.000Z Koreans to be notified of possible data breaches, Operations at Russian security systems outfit were disrupted by a cyberattack, EU-India security deal omits hackers-for-hire, Threat actors exploit a high-severity vulnerability in WinRAR, Mustang Panda can steal login data from browsers, much more _This post is for paying subscribers only._ ### Treasury cancels Booz Allen contracts ostensibly over inadequate data security URL: https://www.metacurity.com/treasury-cancels-booz-allen-contracts-ostensibly-over-inadequate-data-security/ Last updated: 2026-01-27T15:00:46.000Z Salt Typhoon hacked senior UK officials for years, Pegasus spyware victim awarded $4.1m over Pegasus infection, US Marshals are probing alleged theft of $40m in confiscated digital assets, Nike is investigating a potential data breach, UK radically ups number of facial recognition vans, much more _This post is for paying subscribers only._ ### Proposed Israeli cyber law calls for cyber incident reporting in real time URL: https://www.metacurity.com/proposed-israeli-cyber-law-calls-for-cyber-incident-reporting-in-real-time/ Last updated: 2026-01-26T14:35:10.000Z Russia is likely the source of wiper malware that targeted Poland's energy sector, Russian national pleads guilty to targeting 50 victims with ransomware, DPRK group Konni is targeting blockchain engineers with malware, Critical flaw in Solana's validator client fixed, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 1/17/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-17-26/ Last updated: 2026-01-24T12:29:00.000Z The untouchable hacker god who destroyed psychotherapy patients, AI prompt injection is an unsolvable problem, Deepfakes are messing up Canada's justice system, What the hack of Russia's Unified Military Registry revealed, The US military needs to accelerate its tests of AI trustworthiness _This post is for subscribers only._ ### A database with 149 million usernames and passwords was exposed on the internet URL: https://www.metacurity.com/a-database-with-149-million-usernames-and-passwords-was-exposed-on-the-internet/ Last updated: 2026-01-23T16:23:50.000Z Venezuelan nationals who stole cash from ATMs using malware will be deported from US, FBI asked Microsoft to unlock encrypted laptops, Under Armour is investigating massive data breach, Tech investors want the US government to probe S. Korea's treatment of Coupang following data breach, much more _This post is for paying subscribers only._ ### Acting CISA head got grilled on mass firings at the agency URL: https://www.metacurity.com/acting-cisa-head-got-grilled-on-mass-firings-at-the-agency/ Last updated: 2026-01-22T14:26:13.000Z EU's CIRCL launches GCVE system, DeFi project EVM was exploited for $6m, Attackers exploit patch bypass for FortiGate flaw, Cisco fixes Unified Communications and Webex Calling RCE flaw, Mass spam wave emanates from unsecured Zendesk support systems, much more _This post is for paying subscribers only._ ### DOGE workers shared SSN data with outsiders, derailed DISA operations URL: https://www.metacurity.com/doge-workers-shared-ssn-data-with-outsiders-dertailed-disa-operations/ Last updated: 2026-01-21T14:53:06.000Z UK launches national fraud reporting service, China blames Taiwan for cyberattacks, EU proposes freezing out Chinese tech suppliers, New Zealand launches Manage My Health breach probe, Curl ends its bug bounty program due to AI flood, Cloudflare fixes WAF flaw, much more _This post is for paying subscribers only._ ### UK's NCSC warns of Russian-aligned hacktivist groups URL: https://www.metacurity.com/uks-ncsc-warns-of-russian-aligned-hacktivist-groups/ Last updated: 2026-01-20T14:17:46.000Z UK and China enter a forum to discuss cyberattacks, Makina Finance lost $4.2m in an exploit, Ingram Micro report ransomware attack affecting 42k, Minnesota DHS breach affected 304k, SK Telecom appeals $91m fine, NexShield malvertising campaign crashes browsers, much more _This post is for paying subscribers only._ ### Black Basta suspects’ homes raided; gang leader added to most-wanted list URL: https://www.metacurity.com/black-basta-suspects-homes-raided-gang-leader-added-to-most-wanted-list/ Last updated: 2026-01-19T14:12:52.000Z Jordanian national pleads guilty to access broker charges, Acting head of CISA was blocked by colleagues from removing CIO, Iranian campaign sought to steal GMail and other account credentials, Man pleads guilty to hacking US S.Ct., DPRK hackers pose as human rights orgs, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 1/10/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-10-26/ Last updated: 2026-01-17T14:51:22.000Z Estonia served as the first target of Russian cyberattacks, Inside a sprawling scam compound in Myanmar, How to protest safely amid massive surveillance, Silicon Valley is now the tech handmaiden of US authoritarianism, It's hard to gain access control over AI agents _This post is for subscribers only._ ### Trump officials might boycott RSAC citing Easterly's CEO position URL: https://www.metacurity.com/trump-officials-might-boycott-rsac-citing-easterlys-ceo-position/ Last updated: 2026-01-16T15:09:05.000Z Grubhub confirms data breach, China's UAT-8837 breached CIC orgs in N. America, Hackers exploit top severity flaw in Modular DS WordPress plugin, Flaw in MD CPUs exposes secure virtualization environment, Gemini 'personal intelligence' will scan everything, much more _This post is for paying subscribers only._ ### Microsoft took down massive cybercrime platform RedVDS URL: https://www.metacurity.com/microsoft-took-down-massive-cybercrime-platform-redvds/ Last updated: 2026-01-15T16:19:34.000Z Google's Fast Pair protocol enables hackers to connect with audio accessories, Shipping-related firm Bluspark Global patched a raft of flaws, Kimwolf botnet may have hit its maximum potential, CNIL fined French mobile companies for data breach, Cyber authorities warn of OT threats, much more _This post is for paying subscribers only._ ### China orders domestic companies to stop using US cybersecurity software URL: https://www.metacurity.com/china-orders-domestic-companies-to-stop-using-us-cybersecurity-software/ Last updated: 2026-01-14T14:17:53.000Z White House renominates Plankey as CISA Director, Whistleblower leaks sensitive data on ICE and Border Patrol workers, Man to plead guilty for hacking Supreme Court system, Microsoft issues fixes for 114 flaws, Belgian hospital forced to cancel procedures after cyberattack, much more _This post is for paying subscribers only._ ### Hackers claim to be selling Target's internal source code URL: https://www.metacurity.com/hackers-claim-to-be-selling-targets-internal-source-code/ Last updated: 2026-01-13T14:52:36.000Z Poland thwarted power system cyberattack, Hackers accessed the systems of Spanish energy provider Endesa and Energía XXI, Personal finance platform Betterment was hacked through third-party, Dutch national sentenced to seven years for hacking, Korea's Kyowon Group hit with ransomware, much more _This post is for paying subscribers only._ ### Meta denies widespread reports of an Instagram breach URL: https://www.metacurity.com/meta-denies-widespread-reports-of-an-instagram-breach/ Last updated: 2026-01-12T14:57:51.000Z Authorities bust 34 alleged members of the Black Axe cyber fraud group, BreachForums user database exposed in breach, Fancy Bear has launched credential harvesting attacks, NIST seeks agentic AI security input, MuddyWater launches spearphishing campaign in Middle East, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the weeks of 12/13/25, 12/30/25, and 1/3/26 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-weeks-of-12-13-25-12-30-25-and-1-3-26/ Last updated: 2026-01-10T14:09:47.000Z Kids turn from cybercrime to real-world violent thefts, How retailers profit from crypto ATM scams, Integrated web browsers are insecure out of the box, An MIT railroad club led to modern-day hackers, AI coding tools are susceptible to attacks, LLM guardrails are inherently exploitable _This post is for subscribers only._ ### Trump ends US participation in organizations devoted to stronger cybersecurity URL: https://www.metacurity.com/trump-ends-us-participation-in-organizations-devoted-to-stronger-cybersecurity/ Last updated: 2026-01-09T15:19:49.000Z Prisoner swap sends alleged ransomware payment negotiator back to Russia, CISA retires ten emergency directives at once, Cambodian cybercrime kingpin extradited to China, Fugitive wanted for Desjardins breach arrested in Spain, Trans activists hacked Free Speech Union, much more _This post is for paying subscribers only._ ### Salt Typhoon infiltrated US House China Committee, other committees, sources URL: https://www.metacurity.com/salt-typhoon-infilrated-us-house-china-committee-other-committees-sources/ Last updated: 2026-01-08T14:44:14.000Z TX court enjoins Samsung from using or selling consumer data, FCC exempts some Chinese tech at Pentagon's request, Man accused of stealing Snapchat access codes for 600 women for Northeastern Univ. coach, Ni8mare flaw allows takeover of N8N workflow automation platform, much more _This post is for paying subscribers only._ ### Man pleads guilty in the first successful US prosecution of a stalkerware operator URL: https://www.metacurity.com/us-man-pleads-guilty-in-in-first-us-successful-prosecution-of-a/ Last updated: 2026-01-07T14:07:23.000Z Korea warns of hacking forum that steals and sells data, NZ High court enjoins publication of stolen medical data, UK government launches $282m cyber action plan, Threat actor stole and threatens to leak data from insurer Prosura, Command injection flaw found in D-Link DSL routers, much more _This post is for paying subscribers only._ ### 'Martha Root' deleted white supremacist websites live at CCC conference URL: https://www.metacurity.com/martha-root-deleted-white-supremacist-websites-live-at-ccc-conference/ Last updated: 2026-01-06T14:36:35.000Z Ledger third-party payment processor exposed customer data, UL Solutions withdraws from FCC Cyber Trust Mark, NordVPN denies breach saying hackers obtained only dummy data, Thefts stemming from 2022 LastPass breach still ongoing, Russian threat group uses Viber to deliver malware, much more _This post is for paying subscribers only._ ### Substation destruction and not cyber expertise likely led to Caracas power outages URL: https://www.metacurity.com/substation-destruction-and-not-cyber-expertise-likely-led-to-caracas-power-outages/ Last updated: 2026-01-05T14:02:54.000Z Denmark says Russia was behind destructive cyberattacks, CISA staffers suspended after organizing polygraph test of acting director, Chinese cyberattacks on Taiwan jumped in 2025, OpenAI says prompt injection attack risks are here to stay, European Space Agency confirms breach, much more _This post is for paying subscribers only._ ### The UK Foreign Office was hacked in October URL: https://www.metacurity.com/the-uk-foreign-office-was-hacked-in-october/ Last updated: 2025-12-19T14:27:19.000Z Delay in keystroke led Amazon to imposter discovery, A second suspect was arrested in an attempted Italian ferry malware attack, Denmark blames Russia for destructive cyberattacks, LongNosedGoblin is targeting SE Asian and Japanese governments, NHS tech company hit with cyber incident, much more _This post is for paying subscribers only._ ### Cops take down alleged money-laundering operations E-Note URL: https://www.metacurity.com/cops-take-down-alleged-money-laundering-operations-e-note/ Last updated: 2025-12-18T14:12:50.000Z Google is suing mass texting operation Darcula, AI-generated social media firm Doublespeed was hacked, Former Israeli Prime Minister Naftali Bennett's messages were leaked online, Korea launches massive probe of Coupang breach, Foreign power tried to install malware on Italian ferry, much more _This post is for paying subscribers only._ ### Venezuela's state-run oil company PDVSA was hit by a cyberattack URL: https://www.metacurity.com/venezuelas-state-run-oil-company-pdvsa-was-hit-by-a-cyberattack/ Last updated: 2025-12-17T14:20:06.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/12/Rafael_Ram--rez_and_Hugo_Ch--vez-1.jpg) El entonces presidente de Petróleos de Venezuela (PDVSA) junto con el expresidente venezolano Hugo Chávez. Source: [Karel Fuentes](https://www.flickr.com/photos/96781889@N04/28601705394/?ref=metacurity.com). **'Tis the season to be generous. Please support Metacurity in our mission to end infosec news overload.** Metacurity is a pure labor of love and is the only daily newsletter that delivers the critical infosec developments you need to know, scanned from thousands of sources and smartly summarized. But to continue delivering our daily updates, we need your support. Please consider upgrading to an annual paid subscription today. [Upgrade my subscription!](#/portal/account/plans) If you can't upgrade to a paid subscription today, please consider donating what you can. [Donate to Metacurity](#/portal/support) --- ### Venezuela's state-run oil company PDVSA was hit by a cyberattack and said its operations were unaffected, even though four sources said systems remained down and oil cargo deliveries were suspended. Tensions are high between the US and Venezuelan governments, amid a large-scale US military buildup in the southern Caribbean, US strikes on alleged drug trafficking boats, and comments from Donald Trump that land operations may begin soon in Venezuela. PDVSA and the oil ministry blamed the US for the cyberattack, saying it was carried out by "foreign interests in complicity with domestic entities who are seeking to destroy the country's right to sovereign energy development." They alleged the attack was part of US efforts to control Venezuela's oil through "force and piracy." However, a PDVSA source said the company had detected a ransomware attack days ago, and the antivirus software it used to try to fix the problem affected its entire administrative system. PDVSA said it had recovered from the attack. Venezuela's government regularly blames problems like blackouts on conspirators from the opposition and foreign entities like the US Central Intelligence Agency, without giving evidence. ([Reuters](https://www.reuters.com/world/americas/venezuelas-pdvsa-says-operations-unaffected-by-cyber-attack-blames-us-2025-12-15/?ref=metacurity.com)) **Related:** [*Bloomberg*](https://www.bloomberg.com/news/articles/2025-12-15/venezuela-says-oil-export-system-down-after-weekend-cyberattack?ref=metacurity.com)*,* [*Breaking the News*](https://breakingthenews.net/Article/Venezuelan-state-oil-company-reports-cyberattack/65354291?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/185755/security/a-cyber-attack-hit-petroleos-de-venezuela-pdvsa-disrupting-export-operations.html?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/cyberattack-disrupts-venezuelan-oil-giant-pdvsas-operations/?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/pdvsa-cyberattack-hits-administrative-systems/?ref=metacurity.com) ### Lawmakers assailed Coupang’s billionaire founder Bom Kim for failing to appear before a parliamentary hearing on South Korea’s biggest-ever data breach, underscoring rising public anger with the country’s dominant online retailer. Kim’s absence dominated a special session on Wednesday on the breach, which compromised more than 30 million users’ personal information, including names, phone numbers, and delivery details. The former head of Coupang’s Korean operations, Park Dae-jun, also failed to appear after resigning last week. Harold Rogers, Coupang Inc.’s chief administrative officer and newly appointed interim head of the Korean unit, attended the hearing alongside a range of lower-ranking Korean executives. The crisis has prompted a government probe and disrupted the lives of millions across Korea, with nearly two-thirds of people affected. Rogers said the company is cooperating with the investigation and has handed “thousands of documents” to regulators. It’s also working on a plan to compensate customers affected by the breach, he added. ([Jane Lanhee Lee / Reuters](https://www.reuters.com/world/americas/venezuelas-pdvsa-says-operations-unaffected-by-cyber-attack-blames-us-2025-12-15/?ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/world/asia-pacific/coupang-ceo-fails-appear-south-korean-parliamentary-hearing-data-breach-2025-12-17/?ref=metacurity.com)*,* [*The Investor*](https://www.theinvestor.co.kr/article/10638627?ref=metacurity.com)*,* [*Tech in Asia*](https://www.techinasia.com/news/coupang-interim-ceo-apologizes-over-33-million-users-data-breach?ref=metacurity.com)*,* [*China Daily*](https://www.chinadailyasia.com/hk/article/625568?ref=metacurity.com)*,* [*Yonhap News*](https://m-en.yna.co.kr/view/AEN20251217004000320?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/world/asia/breach-at-south-koreas-equivalent-of-amazon-exposed-data-of-almost-every-adult-ba8d9ebd?mod=djemCybersecruityPro&tpl=cs&ref=metacurity.com) ### A new study by Infoblox finds the vast majority of “parked” domains — mostly expired or dormant domain names, or common misspellings of popular websites — are now configured to redirect visitors to sites that foist scams and malware. When Internet users try to visit expired domain names or accidentally navigate to a lookalike “typosquatting” domain, they are typically brought to a placeholder page at a domain parking company that tries to monetize the wayward traffic by displaying links to a number of third-party websites that have paid to have their links shown. A decade ago, ending up at one of these parked domains came with a relatively small chance of being redirected to a malicious destination: In 2014, researchers found (PDF) that parked domains redirected users to malicious sites less than five percent of the time — regardless of whether the visitor clicked on any links at the parked page. But in a series of experiments over the past few months, Infoblox researchers say they discovered the situation is now reversed, and that malicious content is by far the norm now for parked websites. “In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the ‘click’ was sold from the parking company to advertisers, who often resold that traffic to yet another party,” Infoblox researchers wrote in a paper published today. Infoblox found that parked websites are benign if the visitor arrives at the site using a virtual private network (VPN), or else via a non-residential Internet address. For example, Scotiabank.com customers who accidentally mistype the domain as scotaibank\[.\]com will see a normal parking page if they’re using a VPN, but will be redirected to a site that tries to foist scams, malware, or other unwanted content if coming from a residential IP address. Again, this redirect happens just by visiting the misspelled domain with a mobile device or desktop computer that is using a residential IP address. According to Infoblox, the person or entity that owns scotaibank\[.\]com has a portfolio of nearly 3,000 lookalike domains, including gmai\[.\]com, which demonstrably has been configured with its own mail server for accepting incoming email messages. Meaning, if you send an email to a Gmail user and accidentally omit the “l” from “gmail.com,” that missive doesn’t just disappear into the ether or produce a bounce reply: It goes straight to these scammers. The report notes this domain has also been leveraged in multiple recent business email compromise campaigns, using a lure indicating a failed payment with Trojan malware attached. ([Brian Krebs / Krebs on Security](https://krebsonsecurity.com/2025/12/most-parked-domains-now-serving-malicious-content/?ref=metacurity.com)) **Related:** [*Infoblox*](https://blogs.infoblox.com/threat-intelligence/parked-domains-become-weapons-with-direct-search-advertising/?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/malware-and-phishing/?ref=metacurity.com)*,* [*Domain Name Wire*](https://domainnamewire.com/2025/12/16/research-most-traffic-to-parked-domains-redirects-to-bad-sites/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/12/image-52.png) A scan of ic3\[.\]org, a lookalike to the FBI Internet Crime Complaint Center website, returned a non-threatening parking page (left) whereas a mobile user was instantly directed to deceptive content in October 2025 (right). Source: Infoblox. ### The US Federal Trade Commission is ordering Illusory Systems, which also does business as Nomad, a company that publicly touted its cybersecurity capabilities, to return recovered funds to victims and implement security reforms, after a software flaw let hackers steal hundreds of millions of dollars in cryptocurrencies from users. The FTC reached a settlement with Illusory following an investigation into a 2022 incident where hackers exploited a vulnerability in the company’s Token Bridge cryptocurrency smart contract solution. The program provides protocols that connect different blockchains and allow users to transfer assets between them. As part of the deal, the company must implement a comprehensive cybersecurity plan, including addressing security flaws identified in the FTC’s complaint and programs for protecting consumers from theft and fraud. It must also submit the plan and cooperate with independent third-party assessors on any improvements and return stolen money clawed back by law enforcement. ([Derek B. Johnson / CyberScoop](https://cyberscoop.com/ftc-settles-with-illusory-systems-in-2022-cryptocurrency-hack/?ref=metacurity.com)) **Related:** [*FTC*](https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-will-require-illusory-systems-return-money-stolen-hackers-implement-information-security-program?ref=metacurity.com)*,* [*Decrypt*](https://decrypt.co/352621/ftc-nomad-operator-repay-users-186m-crypto-bridge-hack-2022?amp=1&ref=metacurity.com)*,* [*Cryptopolitan*](https://www.cryptopolitan.com/ftc-moves-to-settle-nomad-crypto-hack-case/?ref=metacurity.com) ### Advocacy group Vienna-based organization None of Your Business, or noyb, filed complaints to Austria's data protection authority against TikTok, Grindr, and AppsFlyer, alleging these companies breached regional privacy laws, risking exposure of sensitive data. noyb alleges that the companies violated European Union privacy laws by tracking user activities across apps without consent. TikTok, owned by China's ByteDance, and Grindr, a widely used LGBTQ+ dating app, shared sensitive user information illegally, while AppsFlyer, known for mobile marketing analytics, facilitated unauthorized data transfers, noyb claims. noyb said the user discovered, via a data-access request, that TikTok had accessed sensitive details from other apps, including the person's "use of Grindr, LinkedIn," and a product they had added to a shopping cart. TikTok only disclosed this information to the user after repeated enquiries, failing to comply with GDPR's transparency requirements. TikTok said the data was used for reasons including "personalised advertising, analytics, security," according to noyb. GDPR provides special protection for sensitive information such as sexual orientation, which could spur discrimination, noyb said. Noyb said neither AppsFlyer nor Grindr had legal grounds to share the user's data with TikTok. ([Leo Marchandon / Reuters](https://www.reuters.com/sustainability/boards-policy-regulation/tiktok-monitored-grindr-activity-through-third-party-tracker-privacy-group-2025-12-17/?ref=metacurity.com)) ***Related:*** [*Noyb*](https://noyb.eu/en/tiktok-unlawfully-tracks-your-shopping-habits-and-your-use-dating-apps?ref=metacurity.com)*,* [*Euractiv*](https://www.euractiv.com/news/tiktok-and-grindr-face-privacy-complaint-for-sharing-sex-life-data/?ref=metacurity.com)*,* [*Tech in Asia*](https://www.techinasia.com/news/tiktok-allegedly-tracked-grindr-activity-thirdparty-tracker?ref=metacurity.com)*,* [*Cryptopolitan*](https://www.cryptopolitan.com/tiktok-alleged-of-breaching-eu-privacy-laws/?ref=metacurity.com) ### Researchers at Arctic Wolf say that hackers are exploiting critical-severity vulnerabilities affecting multiple Fortinet products to get unauthorized access to admin accounts and steal system configuration files. The two vulnerabilities are tracked as CVE-2025-59718 and CVE-2025-59719, and Fortinet warned in an advisory on December 9 about the potential for exploitation. CVE-2025-59718 is a FortiCloud SSO authentication bypass affecting FortiOS, FortiProxy, and FortiSwitchManager. It is caused by improper verification of cryptographic signatures in SAML messages, allowing an attacker to log in without valid authentication by submitting a maliciously crafted SAML assertion. CVE-2025-59719 is a FortiCloud SSO authentication bypass affecting FortiWeb. It arises from a similar issue with the cryptographic signature validation of SAML messages, enabling unauthenticated administrative access via forged SSO. Both issues are only exploitable if FortiCloud SSO is enabled, which is not the default setting. However, unless the feature is explicitly disabled, it is activated automatically when registering devices through the FortiCare user interface. Arctic Wolf observed attacks exploiting the two security vulnerabilities starting on December 12\. They note that the intrusions originated from several IP addresses linked to The Constant Company, BL Networks, and Kaopu Cloud HK. Based on Arctic Wolf observations, the attackers targeted admin accounts with malicious single sign-on logins (SSO). To prevent attacks, Fortinet recommends that admins still running a vulnerable version temporarily disable the FortiCloud login feature until an upgrade to a safer version is possible. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-exploit-newly-patched-fortinet-auth-bypass-flaws/?ref=metacurity.com)) **Related:** [*Arctic Wolf*](https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4107440/fortigate-firewall-credentials-being-stolen-after-vulnerabilities-discovered.html?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/185748/security/hackers-are-exploiting-critical-fortinet-flaws-days-after-patch-release.html?ref=metacurity.com) ### Researchers at Check Point report that the Chinese espionage crew Ink Dragon has expanded its snooping activities into European government networks, using compromised servers to create illicit relay nodes for future operations. The campaign hit "several dozen victims," including government entities and telecommunications organizations across Europe, Asia, and Africa. These attacks begin with Ink Dragon probing security weaknesses, such as misconfigured Microsoft IIS and SharePoint servers, to gain access to victims' environments. This tactic, as opposed to abusing zero-days or other high-profile vulnerabilities, helps attackers fly under the radar and reduces their chances of being caught. Ink Dragon then scoops up credentials and uses existing accounts to infiltrate targets, tactics that help the gang blend in with normal network traffic. ([Jessica Lyons / The Register](https://www.theregister.com/2025/12/16/chinas%5Fink%5Fdragon%5Fhides%5Fout/?ref=metacurity.com)) **Related:** [*Check Point*](https://blog.checkpoint.com/research/ink-dragon-expands-with-new-tools-and-a-growing-victim-network/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/chinese-ink-dragon-hides-european/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/12/image-53.png) Ink Dragon attack chain. Source: Check Point. ### Researchers at Koi Security report that a new campaign dubbed 'Researchers at NCC Group report that global ransomware activity plateaued in November, even as attackers continued to refine their tactics and collaboration models. The malicious code grants operators persistent high-privilege access to the browser, enabling them to hijack affiliate links, inject tracking code, and commit click and ad fraud. The hidden script is acting as a loader that fetches the main payload from a remote server. To make the process more challenging to detect, the payload is intentionally retrieved only once in ten attempts. Koi Security researchers discovered the GhostPoster campaign and identified 17 compromised Firefox extensions that either read the PNG logo to extract and execute the malware loader or download the main payload from the attacker's server. The FreeVPN Forever extension was the one Koi Security analyzed initially after its AI tool flagged it for parsing the raw bytes of its logo image file to locate a JavaScript snippet hidden using the steganography technique. Many of the malicious extensions were still available on Firefox’s Add-Ons page at the time of writing. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/ghostposter-attacks-hide-malicious-javascript-in-firefox-addon-logos/?ref=metacurity.com)) **Related:** [*Koi*](https://www.koi.ai/blog/inside-ghostposter-how-a-png-icon-infected-50-000-firefox-browser-users?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/12/image-54.png) Malicious extension on the Firefox store. Source: Koi Security ### Researchers at NCC Group report that that global ransomware activity plateaued in November even as attackers continued to refine their tactics and collaboration models. In its November 2025 Cyber Threat Intelligence Report, NCC says that ransomware incidents dipped slightly month-over-month but remained elevated, as the threat landscape stabilized in volume while becoming more complex in execution. Some 583 ransomware attacks were tracked by NCC in November, down 2% from October. The most targeted industry was the industrials sector, which accounted for 25% of all attacks during the month, followed by the consumer discretionary and information technology sectors. By location, not surprisingly, companies and organizations in North America were the most popular targets in November, accounting for 57% of all reported ransomware. In second place, Europe accounted for 20% of all ransomware attacks, and Asia ranked third at 12%. Qilin ransomware retained its position as the most active ransomware group for the fourth consecutive month, responsible for 17% of recorded attacks, although its activity did decline from an unusually high peak in October. The report also highlights the continued rise of the ClickFix attack technique, also known as ClearFake. As detailed by Microsoft in August, the ClickFix social engineering technique attempts to trick users into running malicious commands on their devices by taking advantage of their target’s tendency to solve minor technical issues and other seemingly benign interactions, such as human verification and CAPTCHA checks. The usage of the technique surged by 517% in the first half of 2025, which the report notes demonstrates a broader move toward social engineering tactics that bypass automated security controls by exploiting human behavior. ([Duncan Riley / Silicon Angle](https://siliconangle.com/2025/12/17/ncc-group-report-finds-ransomware-activity-plateaued-november-tactics-evolve/?ref=metacurity.com)) **Related:** [*NCC Group*](https://www.nccgroup.com/newsroom/cyber-attack-methods-evolve-in-november-despite-attack-volume-plateauing/?ref=metacurity.com) [Please sponsor Metacurity!](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) ### Washington, DC-based Opexus, which provides services and hosts data for more than 45 federal agencies, admits it made multiple mistakes in the hiring and termination of Muneeb and Sohaib Akhter. Opexus fired them in February, minutes before they allegedly stole and destroyed government data in retaliation. The background checks were “consistent with prevailing government and industry standards with additional requirements for more sensitive work. That said, we fully acknowledge that additional diligence should have been applied,” a spokesperson for Opexus told CyberScoop. Muneeb and Sohaib Akhter were arrested in Alexandria, Va., on Dec. 3 for allegedly committing a series of insider attack crimes during a weeklong window in February that ultimately compromised data from multiple federal agencies, including the Department of Homeland Security, Internal Revenue Service, and the Equal Employment Opportunity Commission. Opexus said it decided to terminate the twins’ employment upon learning of their prior criminal history, but it did not explain how it became aware of their previous crimes nor what prompted a deeper look into their past. The brothers’ previous crimes were widely reported at the time, including details that are readily available via search engine queries on their respective names. ([Matt Kapko / CyberScoop](https://cyberscoop.com/opexus-background-checks-insider-attack-muneeb-sohaib-akhter/?ref=metacurity.com)) **Related:** [*SC Media*](https://www.scworld.com/brief/federal-government-hacker-twins-criminal-history-overlooked-by-opexus?ref=metacurity.com) ### Texas Attorney General Ken Paxton filed lawsuits against five major television manufacturers, accusing them of illegally spying on consumers through smart TV technology. The companies named include Samsung, Sony, LG, and two Chinese firms—Hisense and TCL Technology Group Corporation. The legal action highlights growing concerns about consumer privacy and foreign data collection, particularly from companies with ties to China. The suits allege these manufacturers secretly harvest viewing data from Texas homes without proper consent. At the heart of the controversy is Automated Content Recognition (ACR). This software captures screenshots of television displays every 500 milliseconds, monitoring viewing habits in real time. The companies then transmit this data back to their servers and sell it for targeted advertising. The technology potentially exposes passwords, banking information, and other sensitive personal data. “Companies, especially those connected to the Chinese Communist Party, have no business illegally recording Americans’ devices inside their own homes,” Paxton said in a statement. He called the conduct “invasive, deceptive, and unlawful.” The Chinese connections raise particular alarm bells for Texas officials. China’s National Security Law grants Beijing broad powers to access data from Chinese companies, potentially putting American consumer information at risk. ([Dallas Express](https://dallasexpress.com/state/smart-tvs-secretly-spy-on-texans-paxton-files-lawsuits-against-major-brands/?ref=metacurity.com)) **Related:** [*Texas Attorney General*](https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans?ref=metacurity.com)*,* [*Hoodline*](https://hoodline.com/2025/12/texas-attorney-general-ken-paxton-sues-sony-samsung-lg-and-others-over-alleged-tv-consumer-spying/?ref=metacurity.com)*,* [*KTSA*](https://www.ktsa.com/paxton-sues-five-tv-manufacturers-for-spying-on-texans/?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/cybersecurity/texas-sues-five-tv-manufacturers-over-predatory-ad-targeting-spyware-201500248.html?guccounter=1&guce%5Freferrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&guce%5Freferrer%5Fsig=AQAAAMfH5iMR%5FdIx7oOKzmQlm2pUh1RDNAKemNHXymenSfQxAIZKKFvpKOiP6LG1ATwUmFoftxjIJKJoWr5r7xMCeNau9Hs1MKB-gcRYQyfLo%5FuniDr5v3oXOGt7Loo29uZpkmDCMtnvgcxIOciAgBsCnUBPNYXRtsiTIOkXzRGHzRb8&ref=metacurity.com)*,* [*KYFO*](https://kfyo.com/texas-sues-tv-makers-spying/?ref=metacurity.com)*,* [*Newsweek*](https://www.newsweek.com/texas-ag-paxton-sues-tv-companies-for-spying-11217476?ref=metacurity.com)*,* [*The Texan*](https://thetexan.news/state/texas-state-news/texas-sues-five-tv-companies-alleging-spying-via-data-collection-practices/article%5Fba170ea5-e14b-4517-a2a5-1f538415b993.html?ref=metacurity.com)*,* [*Texas Border Business*](https://texasborderbusiness.com/paxton-sues-five-major-tv-companies-for-spying-on-texans/?ref=metacurity.com) ### Sources say Blackstone is leading a $400 million investment in data-security firm Cyera that values the New York-based company at $9 billion. Cyera is among a crop of cybersecurity startups leveraging artificial intelligence to protect companies from new security vulnerabilities introduced by AI. The startup, founded in 2021 by former Israeli Defence Forces military intelligence officers Yotam Segev and Tamar Bar-Ilan, raised funding at a $6 billion valuation in June. ([Kate Clark / Wall Street Journal](https://www.wsj.com/tech/ai/blackstone-leads-400-million-investment-in-cyber-startup-cyera-a6b74b91?st=NmSMaJ&reflink=desktopwebshare%5Fpermalink&ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/business/blackstone-leads-investment-data-security-firm-cyera-9-billion-valuation-wsj-2025-12-17/?ref=metacurity.com)*,* [*Calcalist*](https://www.calcalistech.com/ctechnews/article/z8b339efm?ref=metacurity.com)*,* [*JNS*](https://www.jns.org/israeli-startup-cyera-valued-at-9-billion-after-blackstone-deal/?ref=metacurity.com)*,* [*Globes*](https://en.globes.co.il/en/article-israeli-cyber-co-cyera-triples-valuation-within-a-year-report-1001529429?ref=metacurity.com) ### Adaptive Security, a NYC-based provider of AI-powered social engineering prevention solutions, raised $81M in a Series B venture funding round. Bain Capital Ventures led the round with participation from NVentures (NVIDIA’s venture capital arm), OpenAI Startup Fund, Andreessen Horowitz (a16z), Abstract Ventures, Capital One Ventures, and Citi Ventures. ([Chris Metinko / Axios](https://www.axios.com/pro/enterprise-software-deals/2025/12/16/adaptive-security-bain-capital-social-engineering?ref=metacurity.com)) **Related:** [*Adaptive Security*](https://www.prnewswire.com/news-releases/adaptive-security-raises-81-million-series-b-to-stop-ai-powered-cyber-threats-302643174.html?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2025/12/16/adaptive-security-raises-81m-expand-ai-driven-social-engineering-defense-platform/?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2025/12/adaptive-security-raises-81m-in-series-b-funding.html?ref=metacurity.com)*,* [*AlleyWatch*](https://alleywatch.com/2025/12/the-alleywatch-startup-daily-funding-report-12-16-2025/?ref=metacurity.com) ### Best Thing of the Day: And So It Begins Leaders from Anthropic and Google will [testify](https://homeland.house.gov/2025/12/15/media-advisory-subcommittee-chairmen-ogles-brecheen-announce-hearing-with-anthropic-google-quantum-xchange/?ref=metacurity.com) today before two House Homeland Security Committee subcommittees about how AI and other emerging technologies are reshaping the cyber threat landscape. ### Bonus Best Thing of the Day: Giving Cops Their Due Stormont ministers [have agreed](https://www.bbc.com/news/articles/cdrn28l6m27o?ref=metacurity.com) to ring-fence £119m (around $159 million) to compensate police officers of the Police Service of Northern Ireland (PSNI) over a major data breach. ### Worst Thing of the Day: Don't Force Your AI on Our Community A Discord community for gay gamers [is in disarray](https://www.404media.co/anthropic-exec-forces-ai-chatbot-on-gay-discord-community-members-flee/?ref=metacurity.com) after one of its moderators and an executive at Anthropic forced the company’s AI chatbot on the Discord after Jason Clinton, Anthropic’s Deputy Chief Information Security Officer (CISO) and a moderator in the Discord, overrode users who wanted to restrict Anthropic's Claude on the channel. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/12/image-51.png) ### Russia switches up tactics in cyberattacks on energy companies, Amazon URL: https://www.metacurity.com/russia-switches-up-tactics-in-cyberattacks-on-energy-companies-amazon/ Last updated: 2025-12-16T12:35:05.000Z ShinyHunters stole search and watch history of PornHub's premium members, Contributor to DraftKings breach and data theft pleads guilty, Email outage at German Bundestag was not a cyberattack but doubts linger, Handala group puts bounties on Israeli technicians' data, much more _This post is for paying subscribers only._ ### Trump to hand some offsec ops against adversaries to the private sector, report URL: https://www.metacurity.com/trump-to-hand-some-offsec-ops-against-adversaries-to-the-private-sector-report/ Last updated: 2025-12-15T14:19:41.000Z Canada to probe billboard facial recognition use, Pope Leo weighs in on Italian spyware scandal, Oracle bug led to theft of sensitive NHS docs, Coupang founder will go MIA at parliamentary hearing, Asahi will change cyber posture after ransomware attack, Apple issues emergency updates, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 12/6/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-12-6-25/ Last updated: 2025-12-13T14:13:19.000Z A journalist's talks with an Iranian hacking leader ended with murder, Hackers attacked Aeroflot's still-insecure infrastructure, The war on disinformation has been dismantled, Trump's DOJ uses Americans' own data to limit voting rights, The Wassenaar Arrangement can help limit spyware exports _This post is for subscribers only._ ### UK ICO fines LastPass $1.6 million over 2022 data breach URL: https://www.metacurity.com/uk-ico-fines-lastpass-1-6-million-over-2022-data-breach/ Last updated: 2025-12-12T15:12:11.000Z Cybercrims impersonate cops to get sensitive data on users, Throwaway phone numbers undercut SMS 2FA, Chinese inverters threaten the power grid, Second Irish HSE attack revealed, Irish Justice Minister apologizes for gaffe over PSNI data breach, Korea seeks punitive fines over breaches, much more _This post is for paying subscribers only._ ### OpenAI warns that upcoming models pose greater brute force attack capabilities URL: https://www.metacurity.com/openai-warns-that-upcoming-models-pose-greater-brute-force-attack-capabilities/ Last updated: 2025-12-11T14:25:39.000Z Stanford-developed AI system can beat human pentesters dirt cheap, US charges former Accenture manager with false security statements, Malaysian man sentenced for teaching how to use malware, 10k+ Docker Hub images expose credentials and secrets, Storm-0249 abuses EDR for attacks, much more _This post is for paying subscribers only._ ### Coupang CEO resigns as cops raid the company's HQ for a second time URL: https://www.metacurity.com/coupang-ceo-resigns-as-cops-raid-the-companys-hq-for-a-second-time/ Last updated: 2025-12-10T14:07:26.000Z Man pleads guilty amid DOJ take-down of Social Engineering Enterprise gang, DOJ files more charges against Cyber Army of Russia Reborn member, Spanish cops bust teen hacker for stealing 64m records, Ukraine cyber corps claims attack on Russian logistics company Eltrans+, much more _This post is for paying subscribers only._ ### Korean cops raid Coupang HQ looking for security lapses, breach perpetrator clues URL: https://www.metacurity.com/korean-cops-raid-coupang-hq-looking-for-security-lapses-breach-perpetrator-clues/ Last updated: 2025-12-09T12:59:44.000Z Compromise NDAA bill is chock full of cyber provisions, FTC rejects petition from spyware company founder, Commonwealth Bank of Australia fined A$702k for breaching data rules, FBI warns of fake proof of life photos, Oz teen social media limits go live tomorrow, much more _This post is for paying subscribers only._ ### 77,000-plus IP addresses are vulnerable to maximum severity React2Shell flaw URL: https://www.metacurity.com/77-000-plus-ip-addresses-are-vulnerable-to-maximum-severity-react2shell-flaw/ Last updated: 2025-12-08T13:52:57.000Z NCSC warns prompt injection threats might be forever, Apple and Google issue new spyware warnings, Apache Tika critical flaw allows XXE injection attacks, Japanese high school student accused of using ChatGPT to attack internet cafe chain, US issues $10m reward for Iranian hackers, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 11/29/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-11-29-25/ Last updated: 2025-12-06T11:51:39.000Z Southeast Asian economies are becoming dependent on cyberscams, Cybercriminals are inflicting pain throughout India, Mr Deepfakes damaged people beyond the reach of the law, Soaring sales of Starlink are creating risks around the globe, Digital opsec for teens made easy _This post is for subscribers only._ ### US, Canada warn of Chinese-linked Brickstorm malware that gains long-term access URL: https://www.metacurity.com/us-canada-warn-of-chinese-linked-brickstorm-malware-that-gains-long-term-access/ Last updated: 2025-12-05T14:46:51.000Z Intellexa had access to personal data of Predator spyware targets, Int'l partners release AI security guide for OT orgs, Phreeli cellco doesn't ask for identifying info, Taiwan suspends Rednote over fraud cases, Albiriox Android malware evolves quickly, NCSC debuts proactive notifications, much more _This post is for paying subscribers only._ ### Twin brother hackers arrested for US government hacking, data destruction spree URL: https://www.metacurity.com/twin-brother-hackers-arrested-for-us-government-hacking-data-destruction-spree/ Last updated: 2025-12-04T14:37:52.000Z GRU cyber ops sanctioned into Skripal poisoning inquiry, Defenders scramble to patch React Server Components' critical flaws, AI agents match human attackers in smart contract exploits, AZ Atty. General sues Temu for customer data theft, Threat intel experts recorded DPRK IT recruiters, much more _This post is for paying subscribers only._ ### Indian government retreats from spy app mandate URL: https://www.metacurity.com/indian-government-retreats-from-spy-app-mandate/ Last updated: 2025-12-03T14:01:18.000Z US DOJ seizes Myanmar scam center website, Coupang execs sold company stock before breach was announced, Coupang is reviewing compensation for breach victims, Korea's Gmarket hit by string of unauthorized payments, Japan's Askul internet service resumes one month post-breach, much more _This post is for paying subscribers only._ ### European authorities dismantle the Cryptomixer service that laundered illicit Bitcoin URL: https://www.metacurity.com/european-authorities-dismantle-cryptomixer-service/ Last updated: 2025-12-02T13:20:51.000Z Indian government wants smartphone makers to preload state-owned security app, Indian government wants to bar comms apps from working on SIM-less devices, Korea launches probe into Coupang breach and threatens punitive damages, DPRK hackers target S. Koreans with fake tax invoices, much more _This post is for paying subscribers only._ ### Please check your spam filters for today's Metacurity URL: https://www.metacurity.com/please-check-your-spam-filters-for-todays-metacurity/ Last updated: 2025-12-01T21:14:00.000Z ![black laptop computer](https://images.unsplash.com/photo-1557200134-90327ee9fafa?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDN8fGVtYWlsfGVufDB8fHx8MTc2NDYyMzEwMHww&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Stephen Phillips - Hostreviews.co.uk](https://unsplash.com/@hostreviews?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) Someone likely inadvertently reported today's Metacurity newsletter as a phishing email, and Google moved it to the spam folder. As a consequence, many of our readers didn't receive an email today in their primary mail folder. Please check to see if our email is in the spam folder, and if so, please let Google know it's a safe email. In the meantime, I am working with Google to resolve this situation. Thank you! ### Some ChatGPT customers' data were exposed by a breach at vendor Mixpanel URL: https://www.metacurity.com/some-chatgpt-customer-data-were-exposed-by-a-breach-at-vendor-mixpanel/ Last updated: 2025-12-01T14:01:18.000Z Lazarus Group suspected of $30.6m breach of Upbit, Korea's shopping platform Coupang hacked by a former insider to access 30m customers' data, Lazarus Group and Kimsuky are DPRK's most prolific hackers, Korea arrests four for hacking 120K IP cameras, OnSolve CodeRED platform hit by attack, much more _This post is for paying subscribers only._ ### Cyberattack on a critical third-party vendor could expose top banks' customer data URL: https://www.metacurity.com/cyberattack-on-a-critical-third-party-vendor-could-expose-top-banks-customer-data/ Last updated: 2025-11-24T13:55:13.000Z An insider shared internal CrowdStrike screenshots on Telegram, Hackers stole Salesforce-stored data from 200+ companies, DOGE has purportedly disbanded, Harvard is the latest Ivy to get hacked, AI models can sabotage coding projects, Singapore raids scam-connected firm, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 11/15/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-11-15-25/ Last updated: 2025-11-22T15:06:33.000Z Scammers who go to unbelievable lengths, How to expose a DPRK hacker seeking IT work, A Kiwi hacker conference installed a literal anti-virus system, Trump is turning his back on supercharged disinformation, How the EU and US acted differently to the Collins Aerospace hack _This post is for subscribers only._ ### SEC drops ill-fated cyberattack lawsuit against SolarWinds, CISO URL: https://www.metacurity.com/solarwinds-and-its-ciso-are-vindicated-as-sec-drops-ill-fated-cyberattack-lawsuit/ Last updated: 2025-11-21T12:19:34.000Z FCC gets rid of Biden-era reporting rules addressing Salt Typhoon intrusions, Cybercrime money laundering network active in the UK bought a bank, Russian intel services funded former Wirecard exec's spy ring, Salesforce probes another third-party cyber incident, NSO appeals judge's ruling, much more _This post is for paying subscribers only._ ### The US, UK, and Australia sanction Russian bulletproof hosting providers URL: https://www.metacurity.com/the-us-uk-and-australia-sanction-russian-bulletproof-hosting-providers/ Last updated: 2025-11-20T12:47:34.000Z Alice Guo sentenced to life for running scam compound, Samourai Wallet operator sentenced to four years, SK Telecom rejects breach mediation proposal, USBP is massively surveilling Americans, Trump to preempt state AI safety laws, Eternidade Stealer gets more aggressive in Brazil, much more _This post is for paying subscribers only._ ### MI5 warns that China uses LinkedIn to recruit and compromise lawmakers URL: https://www.metacurity.com/mi5-warns-that-china-uses-linkedin-to-recruit-and-compromise-lawmakers/ Last updated: 2025-11-19T13:22:35.000Z WhatsApp feature can extract 3.5B users' phone numbers, Police raid KT for allegedly hiding breach evidence, Beijing rumors cost TP-Link $1B, LG Energy Solution was hit by a cyberattack, Airlines won't sell passenger data to the US, Toronto schools weren't prepared for PowerSchool breach, much more _This post is for paying subscribers only._ ### CISA says it will rebuild with more staff in 2026 to redress cuts in 2025 URL: https://www.metacurity.com/cisa-says-it-will-rebuild-with-more-staff-in-2026-to-redress-cuts-in-2025/ Last updated: 2025-11-18T13:34:40.000Z Microsoft’s Azure cloud computing service was hit with 15.7 Tbps DDoS attack, Russian telecom Protei was hacked and site defaced, Companies warn of inflexibility if UK bans ransom payments, A crew of companies reject efforts to weaken encryption, 460k FTSE compromised credentials found, much more _This post is for paying subscribers only._ ### US issues seizure warrants for Starlink terminals in Myanmar cyberscam compounds URL: https://www.metacurity.com/us-issues-seizure-warrants-for-starlink-terminals-in-myanmar-cyberscam-compounds/ Last updated: 2025-11-17T13:39:29.000Z US citizens plead guilty to aiding DPRK IT worker fraud, $28B tied to cybercrime activity over the last two years, Princeton got hit by a data-stealing cyberattack, Anthropic's report of autonomous AI Chinese hacks hits pushback, Cybercom invests in cyberwarfare AI agents, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 11/8/25 URL: https://www.metacurity.com/next-long-read-5/ Last updated: 2025-11-15T13:33:51.000Z Massive surveillance in Mexico City leaves crime high, Workplace surveillance can harm workers, Machine learning privacy attacks are less effective in reality than they are in theory, LLMs produce more secure code when trained on flaw-free code, Three major kinds of bots cause web resource headaches _This post is for subscribers only._ ### Chinese state hackers used Anthropic to automate cyber intrusions URL: https://www.metacurity.com/chinese-state-hackers-used-anthropic-to-automate-cyber-intrusions/ Last updated: 2025-11-14T13:57:13.000Z UK MoD knew of Excel's security risks before Afghan data leak, NHS investigates Clop's attack claims, ASUS patches DSL router critical flaws, DoorDash reveals October security incident, US feds warn of Akira's expanded encryption capabilities, Kraken is testing how fast it can encrypt, much more _This post is for paying subscribers only._ ### Operation Endgame dismantled Rhadamanthys, VenomRAT, and Elysium URL: https://www.metacurity.com/operation-endgame-dismantled-rhadamanthys-venomrat-and-elysium/ Last updated: 2025-11-13T14:50:57.000Z DC US Attorney launches investigation into crypto scams, APT exploited Citrix Bleed2 flaws in Cisco ISE, CISA orders patching of Cisco ASA and Firepower devices, Extremist group 764 member faces charges related to online child exploitation, Musk fumbles X security key switchover, much more _This post is for paying subscribers only._ ### Google sues Chinese smishing giant Lighthouse Enterprise for scams across 120 countries URL: https://www.metacurity.com/google-sues-chinese-smishing-giant-lighthouse-enterprise-for-scams-across-120-countries/ Last updated: 2025-11-12T14:22:08.000Z UK proposes new cyberattack defenses, UK to allow tests of AI systems to gauge CSAM potential, Oz spy chief says China probed country's telecom networks, China blames US gov't for $13b LuBian theft, Google unveils Private AI Compute, MSFT issues fixes for 63 flaws, much more _This post is for paying subscribers only._ ### Yanluowang initial access broker faces up to 53 years in prison following guilty plea URL: https://www.metacurity.com/yanluowang-initial-access-broker-faces-up-to-53-years-in-prison-following-guilty-plea/ Last updated: 2025-11-11T14:46:24.000Z CBO breach is considered 'ongoing,' Asahi's shipments are at 10% following attack and ahead of holiday season, Payments by British insurers for cyber incidents have tripled, Chinese national faces UK sentencing this week for money laundering, Firefox gets anti-fingerprinting fix, much more _This post is for paying subscribers only._ ### Pro-Hamas hackers stole plans for Australia's next-gen infantry fighting vehicles URL: https://www.metacurity.com/pro-hamas-hackers-stole-plans-for-australias-next-gen-infantry-fighting-vehicles/ Last updated: 2025-11-10T14:20:44.000Z Australia, UK, Denmark and Norway raise security concerns about Chinese buses, CISA 2015 will extend once US government shutdown ends, Chinese cyber company with close ties to Beijing suffered massive hack, New NSO Group owner seeks US headquarters, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 11/1/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-11-1-25/ Last updated: 2025-11-08T14:03:44.000Z Europe needs to break free of American cybersecurity, The horrifying truth of those employment text scams, How Treasury's Cfius really doesn't protect national security, How hackers made Microsoft's Kinect cool, Why Ukraine's offensive cyber ops should be studied _This post is for subscribers only._ ### Suspected foreign actor likely accessed lawmakers' emails and chat logs in CBO hack URL: https://www.metacurity.com/suspected-foreign-actor-likely-accessed-lawmakers-emails-and-chat-logs-in-cbo-hack/ Last updated: 2025-11-07T14:09:14.000Z Italian consultant is latest public victim of Paragon spyware, WaPo was caught up in Oracle E-Business Suite breach, Landfall spyware targeted Galaxy phones in campaign, Site-blocking can disrupt legitimate services, DHS is spying on college football games, RTV Noord was hit by attack, much more _This post is for paying subscribers only._ ### CISA plans to fire 54 employees despite court injunction URL: https://www.metacurity.com/cisa-plans-to-fire-54-employees-despite-court-injunction/ Last updated: 2025-11-06T14:27:28.000Z Google reports new ways threat actors can use AI in their attacks, KT accused of concealing BPFDoor infection, Meta earns $7b a year in scam ads, Hackers stole data from Hyundai AutoEver America, Chinese court sentences scam operators to death, NV ransomware attack took place in May, much more _This post is for paying subscribers only._ ### EU cops bust money launderers who set up crypto fraud network URL: https://www.metacurity.com/eu-cops-bust-money-launderers-who-set-up-crypto-fraud-network/ Last updated: 2025-11-05T14:17:33.000Z OFAC sanctions DPRK firms for supporting criminal activity, Probe reveals how easy it is to intercept EU and NATO sensitive movement data, KC PD hack exposes misconduct details, Nikkei Slack hack exposes data on 17K employees and partners, Curly COMrades abuses Microsoft Hyper-V in Windows, more _This post is for paying subscribers only._ ### Two cyber pros became cybercriminals to launch a ransomware campaign URL: https://www.metacurity.com/two-cyber-pros-became-cybercriminals-to-launch-a-ransomware-campaign/ Last updated: 2025-11-04T14:10:46.000Z Hackers infiltrated trucking and freight companies, Lawmakers probe Flock Safety insecurities, SK Telecom advised to pay $208 per hacking victim, Hackers stole 50K CCTV clips using admin123 password, AN0M phone snags 55 more victims, Hackers stole $100m+ from DeFi protocol Balancer, much more _This post is for paying subscribers only._ ### Hackers who stole trove of sensitive UPenn data deride 'dog**** elitist institution' URL: https://www.metacurity.com/hackers-who-stole-trove-of-sensitive-upenn-data-derides-dog-elitist-institution/ Last updated: 2025-11-03T18:31:54.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/11/UPenn_shield_with_banner.svg-1.png) *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) ### A hacker has taken responsibility for last week's University of Pennsylvania "We got hacked" email incident, saying it was a far more extensive breach that exposed data on 1.2 million donors and internal documents. On Friday, University of Pennsylvania alums and students began receiving multiple offensive emails from Penn.edu addresses claiming the university had been hacked and data stolen. "The University of Pennsylvania is a dog\*\*\*\* elitist institution full of woke retards. We have terrible security practices and are completely unmeritocratic," reads the email sent to Penn alumni and students. "We hire and admit morons because we love legacies, donors, and unqualified affirmative action admits. We love breaking federal laws like FERPA (all your data will be leaked) and Supreme Court rulings like SFFA." The emails originated from connect.upenn.edu, a Penn mailing list platform hosted on Salesforce Marketing Cloud. The university downplayed the incident, describing the messages as "fraudulent emails" that were "obviously fake." The threat actor behind the attack contacted BleepingComputer, claiming the intrusion was far broader and that they had gained access to multiple university systems. The hacker said their group "gained full access" to an employee's PennKey SSO account, allowing access to Penn's VPN, Salesforce data, Qlik analytics platform, SAP business intelligence system, and SharePoint files. They said they exfiltrated data for roughly 1.2 million students, alumni, and donors, including names, dates of birth, addresses, phone numbers, estimated net worth, donation history, and demographic details such as religion, race, and sexual orientation. The attackers told BleepingComputer they breached Penn's systems on October 30th and completed data downloads by October 31st, when the compromised employee account was locked and access was lost. After discovering their access had been revoked, the hacker said they still had access to Salesforce Marketing Cloud and used it to send the offensive mass email to roughly 700,000 recipients. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-hacker-claims-1.2-million-donor-data-breach/?ref=metacurity.com)) **Related:** [*The Daily Pennsylvanian*](https://www.thedp.com/article/2025/11/penn-gse-emails-hack-security-breach-donors?ref=metacurity.com)*,* [*Philly Voice*](https://www.phillyvoice.com/penn-fake-email-school-education/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2025/10/31/hackers-threaten-to-leak-data-after-breaching-university-of-pennsylvania-to-send-mass-emails/?ref=metacurity.com) ### Google DeepMind, Anthropic, OpenAI, and Microsoft are among those trying to prevent so-called indirect prompt injection attacks, where a third party hides commands in websites or emails designed to trick the AI model into revealing unauthorized information, such as confidential data. “AI is being used by cyber actors at every chain of the attack right now,” said Jacob Klein, who leads the threat intelligence team at AI start-up Anthropic. AI groups are using a variety of techniques, including hiring external testers and using AI-powered tools, to detect and reduce malicious uses of their powerful technologies. But experts warned the industry had not yet solved how to stop indirect prompt injection attacks. “When we find a malicious use, depending on confidence levels, we may automatically trigger some intervention, or we may send it to human review,” he added. Google DeepMind uses a technique called automated red teaming, where the company’s internal researchers constantly attack its Gemini model in a realistic way to uncover potential security weaknesses. ([Melissa Heikkilä / Financial Times](https://www.ft.com/content/56cb100e-7146-488f-aae5-55304ae0eff6?ref=metacurity.com)) ***Related:*** [*Business Standard*](https://www.business-standard.com/world-news/ai-security-risk-flaw-google-deepmind-gemini-chatbot-deepfake-phishing-125110301037%5F1.html?ref=metacurity.com)*,* [*PYMNTS*](https://www.pymnts.com/artificial-intelligence-2/2025/tech-giants-tackle-major-ai-security-threat?ref=metacurity.com)*,* [*Fudzilla*](https://www.fudzilla.com/news/ai/61970-ai-groups-race-to-plug-prompt-injection-bugs?ref=metacurity.com) ### Patients from Genea, one of Australia's largest IVF clinics, are seeking compensation after their sensitive medical information was published on the dark web earlier this year. The representative complaint, a type of complaint lodged by an individual on behalf of two or more people, was sent to the Office of the Australian Information Commissioner on 20 October. Melbourne law firm Phi Finney McDonald is acting on behalf of affected patients. The complaint alleges the company failed to take reasonable steps to protect information from misuse, interference, loss, and unauthorized access. It also alleges Genea failed to destroy or remove information once it was no longer needed, and that it breached its obligations under the *Privacy Act 1988* by not informing affected individuals sooner. In February, Genea Fertility informed clients via email that personal data had been breached by cybercriminals and posted to the dark web. The exposed data includes the medical histories, diagnoses, treatments, and prescription medications of those clients, as well as pathology and diagnostic test results. ([Cheyne Anderson, Cameron Carr / SBS News](https://www.sbs.com.au/news/article/genea-lawsuit-data-breach/y51bccpmv?ref=metacurity.com)) **Related*:* [*Cyber Daily*](https://www.cyberdaily.au/security/12857-lawyers-seek-compensation-for-patients-impacted-by-genea-fertility-clinic-data-breach?ref=metacurity.com) ### The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell. The vulnerability exploited in these attacks is CVE-2023-20198, a max-severity flaw that allows remote unauthenticated threat actors to create a local admin user via the web user interface and take over the devices. Cisco fixed the flaw in October 2023, which was then marked as an actively exploited issue. A public exploit became available two weeks later, fueling mass exploitation for backdoor planting on internet-exposed devices. The Australian authorities have warned that variants of the same Lua-based BadCandy web shells are still used in attacks throughout 2024 and 2025, indicating that many Cisco devices remain unpatched. Once installed, BadCandy allows remote attackers to execute commands with root privileges on compromised devices. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/australia-warns-of-badcandy-infections-on-unpatched-cisco-devices/?ref=metacurity.com)) ***Related:*** [*ASD*](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy?ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/security/12858-aussie-cyber-agency-warns-of-state-and-criminal-actors-abusing-badcandy-implant?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/184095/hacking/badcandy-webshell-threatens-unpatched-cisco-ios-xe-devices-warns-australian-government.html?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/11/02/cyber%5Fexec%5Fpleads%5Fguilty%5Fto/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/11/image-1.png) BadCandy infections in Australia. Source: ASD ### Sources close to the investigation say Yuriy Igorevich Rybtsov, a 41-year-old from the Russia-controlled city of Donetsk, Ukraine, was previously referenced in US federal charging documents only by his online handle “MrICQ.” According to a 13-year-old indictment (PDF) filed by prosecutors in Nebraska, MrICQ was a developer for a cybercrime group known as “Jabber Zeus.” Two sources familiar with the Jabber Zeus investigation said Rybtsov was arrested in Italy, although the exact date and circumstances of his arrest remain unclear. A summary of recent decisions (PDF) published by the Italian Supreme Court states that in April 2025, Rybtsov lost a final appeal to avoid extradition to the United States. According to the mugshot website lockedup\[.\]wtf, Rybtsov arrived in Nebraska on October 9, and was being held under an arrest warrant from the US Federal Bureau of Investigation (FBI). The data breach tracking service Constella Intelligence found breached records from the business profiling site bvdinfo\[.\]com showing that a 41-year-old Yuriy Igorevich Rybtsov worked in a building at 59 Barnaulska St. in Donetsk. Further searching on this address in Constella finds the same apartment building shared by a business registered to Vyacheslav “Tank” Penchukov, the leader of the Jabber Zeus crew in Ukraine. ([Brian Krebs / KrebsonSecurity](https://krebsonsecurity.com/2025/11/alleged-jabber-zeus-coder-mricq-in-u-s-custody/?ref=metacurity.com)) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/11/image-2.png) Image: lockedup dot wtf via KrebsOnSecurity. ### Polish Deputy Prime Minister and Minister for Digital Affairs Krzysztof Gawkowski confirmed that Polish authorities are investigating a large-scale cyberattack that compromised personal data belonging to clients of SuperGrosz, an online loan platform operated by AIQLABS. Gawkowski described the incident as “very serious,” warning that criminals had gained access to sensitive personal information, including names, national identification numbers (PESEL), ID card details, email and home addresses, phone numbers, nationality, marital status, number of children, employment details, employer contact information, declared income, bank account numbers, and Facebook identifiers. The minister said that Poland's national cybersecurity teams - CSIRT KNF (responsible for financial institutions) and CSIRT NASK (the national research network) - are already investigating the breach and that the Polish Personal Data Protection Office has been notified. “State services are working to identify the convictions,” he wrote. ([Polskie Radio](https://www.polskieradio.pl/395/7786/artykul/3602083,poland-hit-by-another-major-cyberattack-as-hackers-steal-users%E2%80%99-data-from-loan-platform?ref=metacurity.com)) ***Related:*** [*Safedane.gov.pl*](https://bezpiecznedane.gov.pl/?ref=metacurity.com) ### Chinese President Xi Jinping joked about security backdoors while presenting a pair of Xiaomi Corp. smartphones to his South Korean counterpart, a rare moment of spontaneous levity captured during a week of tense trade negotiations with Donald Trump. Xi, in South Korea to meet Trump on the sidelines of the Asia-Pacific Economic Cooperation summit, presented the pair of devices to Korean President Lee Jae Myung. In a video circulated on social media, Lee asked: “Is the line secure?” Xi chuckled, pointed at the gadgets, and replied through an interpreter: “You can check if there’s a backdoor.” The two leaders burst into laughter. The exchange was striking because the issue of security and alleged espionage is a sensitive one and a major thorn in US-Chinese relations. American lawmakers have raised the possibility that tech companies such as Huawei Technologies Co. build backdoors — ways to gain access to sensitive data — into their equipment or services, something the firms have repeatedly denied. Washington officials have, in turn, broached the idea of working similar access points or tracking technology into products such as Nvidia Corp. chips, which the US company has publicly opposed. ([Yuan Gao and Yoolim Lee / Bloomberg](https://www.bloomberg.com/news/articles/2025-11-03/xi-quips-about-backdoors-during-xiaomi-phone-gift-to-korea-s-lee?ref=metacurity.com)) **Related:** [*France 24*](https://www.france24.com/en/live-news/20251103-xi-jokes-about-spying-with-chinese-phone-gift-for-south-korea-s-lee?ref=metacurity.com)*,* [*XiaomiTime*](https://xiaomitime.com/xiaomi-challenges-samsung-on-its-home-turf-with-a-playful-twist-73209/?ref=metacurity.com)*,* [*Forbes Middle East*](https://www.forbesmiddleeast.com/leadership/leaders/chinese-president-gifts-south-korean-counterpart-xiaomi-phones-jokes-about-backdoor-report?ref=metacurity.com)*,* [*The Korea Herald*](https://www.koreaherald.com/article/10606798?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/world/south-koreas-president-lee-asks-chinas-xi-to-help-restart-north-korea-talks-10340316/?ref=metacurity.com) ### The Shiba Inu development team has implemented a substantial security upgrade for the Shibarium network as the network works to restore confidence following a security incident that threatened its operations. Shibarium's legacy public RPC endpoint will be deactivated over the next two weeks. The Remote Procedure Call serves as the essential link between user wallets, decentralized applications, and the blockchain. Without functional RPC endpoints, users cannot execute transactions, interact with smart contracts, or view their account balances. A critical incident in September forced network operators to pause Shibarium to prevent data corruption. An attacker compromised a validator key and leveraged a temporary delegation of 4.6 million BONE tokens. The malicious actor attempted to gain control over the network consensus. Developers clarified that the breach did not expose fundamental flaws in the core protocol of Shibarium. The vulnerability stemmed from external access to validator credentials rather than code-level weaknesses. The team responded by implementing multiple security layers. New protective measures include a validator denylisting system that can quickly isolate compromised nodes. The Plasma Bridge now requires a seven-day withdrawal delay, giving the team time to detect and respond to suspicious activity. These changes aim to prevent similar incidents in the future. ([Newton Gitonga / Coinpaper](https://coinpaper.com/12061/shiba-inu-s-shibarium-goes-dark-for-two-weeks-here-s-what-users-need-to-know?ref=metacurity.com)) **Related:** [*The Shib*](https://magazine.shib.io/shiba-inu-upgrades-network-access-with-new-shibarium-rpc/?ref=metacurity.com)*,* [*CryptoRank*](https://cryptorank.io/news/feed/8435e-shiba-inu-shibarium-ghost-chain?ref=metacurity.com) Get your message in front of thousands of cyber leaders and policy makers for little more than the cost of an annual Metacurity subscription. [Learn more! ](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) ### Thai police arrested 24 suspected members of an international scam network who were hiding in a luxury villa near Bangkok, officials said. Most of the suspects were Filipino nationals who had fled Myanmar following a major crackdown on scam centers there earlier this month. Police Lt. Gen. Natsak Chaowana, commander of the Central Investigation Bureau, said the operation stemmed from data analysis showing scam networks relocating from Myanmar into Thailand. The suspects were detained during an October 29 raid on a villa in Samut Prakan province, just south of Bangkok. Authorities found 22 foreigners, mostly Filipinos aged 23 to 38, living at the property. Immigration checks revealed that two were in Thailand illegally and 17 had overstayed their visas. Three others, a Singaporean man and two Filipinos, had valid visas but faced revocation due to their alleged involvement in the group. All suspects admitted that they had worked as scammers in Myawaddy, a border town in Myanmar notorious for criminal syndicates. They told police they fled the area after fighting broke out around October 21\. Their manager arranged for their escape to Thailand and rented the villa for about 200,000 baht ($5,400) from October 27–31 while they prepared to move on to Cambodia to resume their operations. ([Khaosod English](https://www.khaosodenglish.com/news/2025/10/31/thai-police-uncover-24-scammers-in-luxury-villa-including-21-filipinos/?ref=metacurity.com)) **Related:** [*The Straits Times*](https://www.straitstimes.com/asia/se-asia/singaporean-among-24-arrested-in-thai-police-raids-on-scam-group-hiding-in-hotel-luxury-villa?ref=metacurity.com) ### The first test cases in an action against the Police Service of Northern Ireland following a significant data breach are to get underway at Belfast High Court. The breach happened in August 2023 when a spreadsheet released as part of a freedom of information request held hidden data with the initials, surname, rank, and role of PSNI officers and staff. Police later said the information had gotten into the hands of dissident republicans. In the aftermath of the leak, some officers chose to move house and change their daily routines. A group action is being taken by police officers and staff over the breach. Belfast legal firm Edwards Solicitors, which represents the majority of plaintiffs in the action, said the outcomes for the test cases will guide thousands of other cases. It said that even though the PSNI accepted liability for the data breach, and a business case has been approved to make a “universal offer” to those bringing claims, the employer has said it cannot make the offer as it is not affordable within its current funding. Partner and head of litigation at Edwards Solicitors, Philip Gordon, said: “The outcome of these initial cases in the High Court will provide some direction and guidance for the parties. “It remains hugely disappointing that the PSNI have not resolved their budget issues to allow for a universal offer to be made, but these test cases are the next step in pursuing compensation for our clients who had their personal details revealed in the 2023 data breach. ([Rebecca Black / The Independent](https://www.independent.co.uk/news/uk/home-news/psni-belfast-high-court-rebecca-black-b2857114.html?ref=metacurity.com)) **Related:** [*Irish News*](https://www.irishnews.com/news/northern-ireland/psni-data-breach-cases-to-begin-at-belfast-high-court-3HTWFDPMBFFW3D2SYYAJUE26NQ/?ref=metacurity.com) ### Thai police arrested members of a hacking and phishing crime ring that stole data from massage parlor owner phones to scam their clients out of millions of won by threatening to release nonexistent “massage videos” if they didn't pay. The Gyeonggi Nambu Provincial Police Agency said that it referred four suspects — a hacker in his 30s and three accomplices in their 20s responsible for gathering and exploiting information — to the prosecution. The hacker and the other suspects, who were local acquaintances, are accused of forming an organized crime ring. Police applied Article 114 of the Criminal Act, which covers the organization of criminal groups. According to police, the hacker began collecting contact information from massage parlors in Seoul, Gyeonggi, and Daegu in January 2022, tricking nine owners into installing a malicious app by claiming it was for business purposes. The app secretly stole client data, including contacts, messages, and call records. The accomplices allegedly set up shop in an officetel in Nam District, Busan, and used the stolen data to blackmail 62 victims, extorting around 500 million won ($351,000) in total. ([SON SUNG-BAE / Korea JoongAng Daily](https://koreajoongangdaily.joins.com/news/2025-11-03/national/socialAffairs/Hackers-steal-data-extort-350000-from-massage-parlor-clients/2435276?ref=metacurity.com)) **Related:** [*The Chosun*](https://www.chosun.com/english/national-en/2025/11/03/YRPJOKNIPNCJBMFB6WDDYXZNTE/?ref=metacurity.com) ### Cybersecurity experts from multiple federal agencies released guidance to help organizations bolster their defenses against attacks on on-premises Microsoft Exchange Servers, resurfacing and building upon previously shared advice that generally applies to most technology. The Cybersecurity and Infrastructure Security Agency said the security blueprint for Microsoft Exchange Server is a follow-up effort to an emergency directive the agency released in August for CVE-2025-53786, a high-severity defect affecting on-premises Microsoft Exchange servers. CISA jointly issued the guide with the National Security Agency and cyber agencies in Australia and Canada. **Related:** [*NSA.gov*](https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI%5FMicrosoft%5FExchange%5FServer%5FSecurity%5FBest%5FPractices.pdf?ref=metacurity.com)*,* [*The HIPAA Journal*](https://www.hipaajournal.com/guidance-hardening-microsoft-exchange-server-security/?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/cisa/cisa-nsa-partners-publish-microsoft-exchange-server-hardening-guide-to-prevent-compromise-and-data-theft/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2025/11/02/nsa-issues-microsoft-exchange-server-high-risk-of-compromise-alert/?ref=metacurity.com)*,* [*Bank Info Security*](https://www.bankinfosecurity.com/cisa-issues-guidance-to-curb-microsoft-exchange-exploits-a-29892?ref=metacurity.com) ### CISA confirmed that a high-severity privilege escalation flaw in the Linux kernel is now being exploited in ransomware attacks. While the vulnerability (tracked as CVE-2024-1086) was disclosed on January 31, 2024, as a use-after-free weakness in the netfilter: nf\_tables kernel component and was fixed via a commit submitted in January 2024, it was first introduced by a decade-old commit in February 2014. Successful exploitation enables attackers with local access to escalate privileges on the target system, potentially resulting in root-level access to compromised devices. As Immersive Labs explains, potential impact includes system takeover once root access is gained (allowing attackers to disable defenses, modify files, or install malware), lateral movement through the network, and data theft. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said. "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable." ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisa-linux-privilege-escalation-flaw-now-exploited-in-ransomware-attacks/?ref=metacurity.com)) **Related:** [*CISA*](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field%5Fcve=CVE-2024-1086&ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/184076/security/old-linux-kernel-flaw-cve-2024-1086-resurfaces-in-ransomware-attacks.html?ref=metacurity.com)*,* [*Immersive Labs*](https://community.immersivelabs.com/blog/the-human-connection-blog/unpacking-cve-2024-1086-a-critical-linux-kernel-flaw/631?ref=metacurity.com) ### Best Thing of the Day: Vox Populi Hates Flock Cameras A growing number of Americans [have gotten involved](https://www.nbcnews.com/tech/tech-news/flock-police-cameras-scan-billions-month-sparking-protests-rcna230037?ref=metacurity.com) in local politics to dispute the use of Flock license plate scanning equipment in their towns. ### Worst Thing of the Day: Waiting for Godot, But With Computers The Foreign Affairs Ministry of Mauritius says Vanita Mirpuri [is prohibited](https://www.theglobeandmail.com/world/article-canadian-woman-stuck-since-2021-in-indian-ocean-country-after-passport/?ref=metacurity.com), from leaving the country because of a five-year-old “computer misuse” charge against her based on a complaint by her former husband that has now been withdrawn, but Canada won't return her passport. ### Bonus Worst Thing of the Day: ICE Implements Mandatory Facial Scans Immigration and Customs Enforcement (ICE) [does not let](https://www.404media.co/you-cant-refuse-to-be-scanned-by-ices-facial-recognition-app-dhs-document-says/?ref=metacurity.com) people decline to be scanned by its new facial recognition app, which the agency uses to verify a person’s identity and their immigration status. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/11/image.png) alums ### Best infosec-related long reads for the week of 10/25/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-10-25-25/ Last updated: 2025-11-01T12:20:31.000Z A hacking gang extorted Italy's elite, An Indian backwater became a wealthy cybercrime locale, The nature of China's espionage threat to the UK, Cybercrime laws are used to censor the press, The dark side of Apple's Family Sharing, The misunderstood nature of the Cybercrime Convention _This post is for subscribers only._ ### Google and Amazon used secret code to dodge data disclosure laws, investigation URL: https://www.metacurity.com/google-and-amazon-used-secret-code-to-dodge-data-disclosure-laws-investigation/ Last updated: 2025-11-01T11:52:09.000Z Suspected Conti member extradited to US from Ukraine, FCC will vote to eliminate cyber reporting requirements for carriers, UNC6384 targeted Hungarian and Belgian diplomatic entities, Medusa creators reportedly arrested in Russia, UK MoD officer left laptop open on train, much more _This post is for paying subscribers only._ ### Former defense firm GM pleads guilty to selling cyber exploits to Russian broker URL: https://www.metacurity.com/former-defense-firm-gm-pleads-guilty-to-selling-cyber-exploits-to-russian-broker/ Last updated: 2025-10-30T13:32:43.000Z Nation-state hackers breached key US telecom services firm Ribbon Communications for nearly a year, US government agencies back bid to ban TP-Link routers, Hacktivists breached Canadian critical infrastructure, Python Foundation rejected US grants that required DEI deletions, much more _This post is for paying subscribers only._ ### Thai police blew up a Myanmar cyberscam compound URL: https://www.metacurity.com/thai-police-blew-up-a-myanmar-cyberscam-compound/ Last updated: 2025-10-29T13:34:41.000Z FCC blocks more Chinese-made devices, Hacking Team successor surfaces, Aisuru botnet overhauled to rent out IoT devices, Herodotus Android trojan mimics human behavior, Ad giant's subsidiary exposed data in cyber incident, CBP searches more devices than ever, ICE is becoming a spymaster, much more _This post is for paying subscribers only._ ### Qilin ransomware activity is surging, with 100 victims listed in August URL: https://www.metacurity.com/qilin-ransomware-activity-is-surging-with-100-victims-listed-in-august/ Last updated: 2025-10-28T13:18:30.000Z A major Swedish power supplier was hit by Everest gang, Some top tech companies relent on Australia's age ban, Google denies it suffered a 183m Gmail accounts breach, Western Sydney University hit with fifth cyber incident in two years, Afghan data breach killed 49 people, much more _This post is for paying subscribers only._ ### Over 60 nations signed a controversial cybercrime convention URL: https://www.metacurity.com/over-60-nations-signed-a-controversial-cybercrime-convention/ Last updated: 2025-10-27T13:34:02.000Z House Democrat service exposed details of government employees with top-secret clearances, AI chatbots push Russian propaganda, A third-party contractor exposed details on Dublin and Cork airport passengers, Philippines' GCash under probe for leak of 8m e-wallet users' data, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 10/18/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-10-18-25/ Last updated: 2025-10-25T13:32:34.000Z The unlikely pair who pioneered RaaS, Lifting the lid on a global spyware operation, The teens who brought down Jaguar Land Rover, How a Log4j maintainer weathered a zero day crisis, Chinese spying could paralyze the UK _This post is for subscribers only._ ### DOJ accuses director of defense firm's cyber division of selling secrets to Russia URL: https://www.metacurity.com/director-of-us-defense-firm-cyber-division-accused-of-selling-secrets-to-russia/ Last updated: 2025-10-24T13:53:52.000Z N. Korean IT workers snagged work as animators, Ethical hackers breached F1 database and got access to Verstappen's info, Hackers enabled theft of Shaquille O'Neal's custom Range Rover, CSC 2.0 appeals to Trump to reverse cyber cuts, Apple may end App Tracking Transparency in Europe, much more _This post is for paying subscribers only._ ### SpaceX pulls the plug on 2,000+ Myanmar scam compounds' Starlink devices URL: https://www.metacurity.com/spacex-pulls-the-plug-on-2-000-myanmar-scam-compounds-starlink-devices/ Last updated: 2025-10-23T11:49:17.000Z PhantomCaptcha phishing campaign targeted critical Ukraine orgs, OpenAI is laid back on Atlas prompt injection flaws, Ransomware cases soar in Japan, N. Korean hackers have pilfered billions according to monitors, N. Korean hackers target drone makers, LG Uplus reports breach, much more _This post is for paying subscribers only._ ### JLR cyberattack is the most economically damaging in UK history URL: https://www.metacurity.com/jlr-cyberattack-is-the-most-economically-damaging-in-uk-history/ Last updated: 2025-10-22T12:55:03.000Z CISA warns of Oracle E-Business Suite flaw, Spyware developer was targeted by spyware, Salt Typhoon attacked a European telco, TikTok could be sharing your data with the US government, UN Cybercrime Convention slated for weekend signoff, UK won't probe Afghan data breach, much more _This post is for paying subscribers only._ ### Scattered LAPSUS$ Hunters claims dossiers on US officials including NSA employees URL: https://www.metacurity.com/scattered-lapsus-hunters-claims-dossiers-on-us-officials-including-nsa-employees/ Last updated: 2025-10-21T13:20:37.000Z EU cops bust up illegal SIM-box service, Russia's COLDRIVER uses two new backdoors, Korea preps financial consumer data protection bill, 76K WatchGuard Firebox network security appliances are exposed on the web, Attackers target OpenVSX and Microsoft Visual Studio with GlassWorm malware, much more _This post is for paying subscribers only._ ### China says the US attacked mobile devices of timekeeping agency URL: https://www.metacurity.com/china-says-the-us-attacked-mobile-devices-of-timekeeping-agency/ Last updated: 2025-10-20T14:41:01.000Z F5 hackers lurked in company's systems for years, Cyberattack on supplier is disrupting Japanese retailers, Russian hackers stole sensitive UK military documents, Envoy Air hacked by Clop, Pro-Palestine hackers expose top Israeli military researchers, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 10/11/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-10-11-25/ Last updated: 2025-10-18T13:01:38.000Z The time is now to end cybersecurity with AI, Prosecutors say PowerSchool hacker was skilled, People with facial differences struggle with digital identity systems, Autistic teens can't grasp ramifications of digital crimes, Online predator groups can kill teens, Crypto ATMs rip off scam victims _This post is for subscribers only._ ### The Com members doxxed DHS and ICE workers URL: https://www.metacurity.com/the-com-members-doxxed-dhs-and-ice-workers/ Last updated: 2025-10-17T13:02:09.000Z DPRK hackers use EtherHiding malware to turn blockchain into C2 server, Trump buys Dominion Voting Systems to be "America-owned," Trump's DoJ sues voting tech company Smartmatic amid defamation suit, MI5 points to new Chinese threat disruption, much more _This post is for paying subscribers only._ ### CISA warns agencies to update F5 appliances after breach disclosure URL: https://www.metacurity.com/cisa-warns-agencies-to-update-f5-appliances-after-breach-disclosure/ Last updated: 2025-10-16T13:09:17.000Z Sources say China hacked classified UK systems for over a decade. Some think a secret US cybercrime-fighting group is behind the doxxing of a Russian ransomware kingpin. Microsoft is moving Surface manufacturing out of China. Pro-Palestine activists hacked four N. American PA systems, much more _This post is for paying subscribers only._ ### US seizes $15 billion, sanctions Huione group, and indicts Cambodian scam ringleader URL: https://www.metacurity.com/us-seizes-15-billion-indicts-cambodian-ringleader-relatd-to-massive-scam-operation/ Last updated: 2025-10-15T12:56:21.000Z S. Korea seeks return of disappeared workers from Cambodia, First Wap has built a phone-tracking empire, Microsoft plugs 172 security holes, Windows 10 reaches end-of-support, ICO fines Capita $19m for 2023 data breach protection fails, PowerSchool hacker sentenced to 4 years, much more _This post is for paying subscribers only._ ### California sets global standards with new landmark AI and data privacy laws URL: https://www.metacurity.com/california-sets-global-standards-with-new-landmark-ai-and-data-privacy-laws/ Last updated: 2025-10-14T13:00:27.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/Gavin_Newsom_-_9.2.2020-1.jpg) Source: [Office of the Governor of California](https://twitter.com/CAgovernor/status/1301193126535544833/photo/1?ref=metacurity.com) *As a reminder, on Tuesdays and Thursdays, the bulk of our daily newsletter is available exclusively to paid subscribers.* *Please consider upgrading your subscription so that you can enjoy Metacurity's original analysis and unparalleled cybersecurity news round-ups free of pesky firewalls. Plus, you will gain unfettered access to our archives and earn my undying appreciation for helping to keep Metacurity going. Thank you!* [Upgrade my subscription](#/portal/account/plans) *Want to bundle your premium subscription with a Metacurity sponsorship option? Gain exposure for your announcement, product, whitepaper, or event, and we'll toss in a paid subscription at no cost. Find out more about how you can reach an elite audience of cyber decision-makers.* [Sponsor Metacurity](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) --- About a year ago, California Governor Gavin Newsom [dramatically vetoed](https://www.csoonline.com/article/3542609/cisos-to-grapple-with-a-thicket-of-emerging-regulations-after-newsom-vetoes-californias-ai-bill.html?ref=metacurity.com) a landmark bill, SB-1047, the Safe and Secure Innovation for Frontier Artificial Intelligence Models Act, that would have laid out strict regulations of AI in a US state that represents the world’s [fourth-largest](https://www.gov.ca.gov/2025/04/23/california-is-now-the-4th-largest-economy-in-the-world/?ref=metacurity.com#:~:text=According%20to%20the%20IMF's%202024,it%20receives%20in%20federal%20funding.) economy. Newsom said back then he was worried that the popular bill would stifle innovation and that California needed to be “informed by an empirical trajectory analysis of AI systems and capabilities. Ultimately, any framework for effectively regulating AI needs to keep pace with the technology itself.” One year later, Newsom’s fear of stifling innovation has obviously dissipated, given that over the past month, he has signed into law a flurry of bills dealing with AI regulation, along with several pieces of legislation that create new data breach law requirements, establish “delete account” UX requirements for social media platforms, mandate browser requirements that allow consumers to opt out of sharing their data with third parties, impose online age disclosure requirements and make stricter data broker regulations and disclosures. Any laws in California, given the state’s size and economic might, almost always set the high bar standards for technology providers not only across the United States but around the world. Any company or organization providing or relying on digital services must comply with California laws, or else they risk running afoul of what, in essence, is a significant global power. Given that federal news has dominated the cybersecurity and technology scene leading up to and through the current US government shutdown, the bills that Newsom has signed have captured less attention from the media than they would likely otherwise generate. So here, in a nutshell, are the new California laws that cybersecurity and other technology professionals should know: **CA SB446 - Data breaches: customer notification –** This [bill](https://legiscan.com/CA/text/SB446/2025?ref=metacurity.com) requires businesses and other entities doing business in California to notify affected California residents of a data breach within 30 calendar days of discovery, and to submit a copy/sample of the notice to the California Attorney General within 15 calendar days of notifying consumers (with limited exceptions for law enforcement or to investigate/restore system integrity). **SB 361 — Data Broker Registration & Disclosure Strengthening –** This [bill](https://www.gov.ca.gov/2025/10/08/governor-newsom-signs-data-privacy-bills-to-protect-tech-users/?ref=metacurity.com) expands disclosures data brokers must make in the California Data Broker Registry (what types of personal info they collect, whether they sell to foreign actors or to GenAI developers, adds audit/penalty provisions). **AB 566 — “California Opt Me Out Act” (browser / OS opt-out signal) –** This [bill](https://legiscan.com/CA/text/AB566/id/3269416?ref=metacurity.com) requires browsers (and later mobile OS) to include an easy-to-find setting to send a single opt-out preference signal to websites (so users can opt out of third-party sale/sharing without repeated site-by-site toggles). **AB 656 — Account deletion / “Delete Account” UX requirements for social platforms** – This [bill](https://legiscan.com/CA/text/AB656/id/3233188?ref=metacurity.com) requires social media platforms to provide a clear, conspicuous “Delete Account” control and to delete a user’s personal data upon confirmed deletion entirely; prohibits dark patterns designed to obstruct deletion. _This post is for paying subscribers only._ ### The White House fired 176 CISA employees on Friday, with more layoffs feared URL: https://www.metacurity.com/the-white-house-fired-176-cisa-employees-on-friday-with-more-layoffs-feared/ Last updated: 2025-10-13T14:40:32.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/Cybersecurity_and_Infrastructure_Security_Agency_flag-1.png) *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) --- ### The Trump administration on Friday beganlaying off more than 4,000 federal workers as the government remains shut down, a reduction in force (RIF) that includes the firing of 176 employees at the Cybersecurity and Infrastructure Security Agency (CISA). Those 176 cut jobs are likely the beginning of further mass layoffs at CISA during the government shutdown, sources close to the situation tell Metacurity. In a statement sent to Metacurity, a Department of Homeland Security spokesperson seemed to suggest that further firings are in the offing for the nation's cybersecurity agency. “RIFs will be occurring at CISA," the spokesperson said. "During the last administration, CISA was focused on censorship, branding, and electioneering. This is part of getting CISA back on mission.” It's worth noting that CISA engaged in very little work on disinformation, or what Trump calls "censorship," during the last administration, particularly in comparison to its core mission of securing federal infrastructure. Most of the employees at CISA who worked in this area have already been fired or left the government. The disdain for "censorship" mirrors that of [Project 2025](https://www.csoonline.com/article/3477366/project-2025-could-escalate-us-cybersecurity-risks-endanger-more-americans.html?ref=metacurity.com), the Heritage Foundation's blueprint for how Trump should run his second term. Project 2025 was spearheaded by Russell Vought, who is now the director of OMB and is overseeing the firings of US government employees. Project 2025 envisions dismantling CISA altogether and putting the remnants of the agency in the Department of Transportation. According to Project 2025, “The Cybersecurity and Infrastructure Security Agency (CISA) is a DHS component that the Left has weaponized to censor speech and affect elections at the expense of securing the cyber domain and critical infrastructure, which are threatened daily. A conservative Administration should return CISA to its statutory and important but narrow mission.” News of this latest round of CISA layoffs [follows reporting](https://www.bloomberg.com/news/articles/2025-10-08/homeland-security-cyber-personnel-reassigned-to-jobs-in-trump-s-deportation-push?ref=metacurity.com) by Bloomberg that the Trump administration has reassigned some CISA professionals to work on immigration issues. The Trump administration also [fired](https://www.csoonline.com/article/3847411/white-house-exempts-cyber-pros-from-mass-layoffs-judge-reinstates-cisa-firings.html?ref=metacurity.com#:~:text=Temporary%20reinstatements%20might%20become%20permanent,14%20days%20and%20perhaps%20indefinitely.) 130 CISA workers earlier this year and released a FY2026 budget that [calls for cutting](https://www.nextgov.com/cybersecurity/2025/06/cisa-projected-lose-third-its-workforce-under-trumps-2026-budget/405726/?ref=metacurity.com#:~:text=Cyber%20Defense-,CISA%20projected%20to%20lose%20a%20third%20of%20its%20workforce%20under,by%20Andrew%20Harnik/Getty%20Images) 1,000 jobs at the agency. Trump's 2026 budget [calls](https://www.csoonline.com/article/4019109/trump-seeks-unprecedented-1-23-billion-cut-to-federal-cyber-budget.html?ref=metacurity.com) for an unprecedented $1.23 billion cut in spending on cybersecurity across all government agencies. This latest round of CISA firings further comes amid [a government shutdown](https://www.csoonline.com/article/4066008/government-shutdown-deepens-us-cyber-risk-exposing-networks-to-threat-actors.html?ref=metacurity.com) during which CISA is functioning with only 889 employees out of its former 2,540 employees. ([Sahil Kapur, Yamiche Alcindor, Monica Alba, Laura Strickler, and Zoë Richards / NBC News](https://www.nbcnews.com/politics/trump-administration/trumps-budget-director-says-layoffs-begun-government-shutdown-rcna236923?ref=metacurity.com) and [Cynthia Brumfield / Metacurity](https://www.metacurity.com/about/)) **Related:** [*New York Post*](https://nypost.com/2025/10/10/us-news/cybersecurity-agency-that-clashed-with-trump-one-of-the-first-hit-with-federal-firings-due-to-shutdown/?ref=metacurity.com)*,* [*Federal News Network*](https://federalnewsnetwork.com/government-shutdown/2025/10/omb-says-substantial-federal-employee-layoffs-have-begun/?ref=metacurity.com)*.* [*The Hill*](https://thehill.com/homenews/administration/5550188-government-layoffs-trump-administration/?ref=metacurity.com)*,* [*Bloomberg Government*](https://news.bgov.com/bloomberg-government-news/trumps-shutdown-layoffs-hit-homelands-cybersecurity-agency?ref=metacurity.com)*,* [*r/cybersecurity*](https://www.reddit.com/r/cybersecurity/comments/1o3dxhm/cisa%5Fstaffers%5Fbeing%5Ffired%5Fover%5Fa%5Fgrudge%5Ffollowing/?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/homenews/administration/5550188-government-layoffs-trump-administration/amp/?ref=metacurity.com)*,* [*GovExec*](https://www.govexec.com/workforce/2025/10/substantial-layoffs-begin-federal-agencies-white-house-says/408752/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/politics/trump-administration/trumps-budget-director-says-layoffs-begun-government-shutdown-rcna236923?ref=metacurity.com)*,* [*Court Listener*](https://storage.courtlistener.com/recap/gov.uscourts.cand.457131/gov.uscourts.cand.457131.39.0%5F2.pdf?ref=metacurity.com)*,* [*Databreach Today*](https://www.databreachtoday.com/cisa-in-disarray-amid-shutdown-growing-political-threats-a-29706?mid=1&ref=metacurity.com#cid=3162607) ### The hacker collective Scattered Lapsus$ Hunters has leaked the personal records of 5 million Qantas customers on the dark web, after a ransom deadline set by the cybercriminals passed. The airline is one of more than 40 firms globally caught up in the hack, reported to contain up to 1bn customer records. The hackers released an extortion note on a data leaks site on the dark web last week, demanding payment in return for preventing the stolen data from being shared. The Qantas data, which was stolen from a Salesforce database in a major cyber-attack in June, included customers’ email addresses, phone numbers, birth dates, and frequent flyer numbers. It did not contain credit card details, financial information, or passport details. On Saturday, the group marked the data as “leaked”, writing: “Don’t be the next headline, should have paid the ransom.” The big threat now for Qantas customers is a wave of cybercrims facilitated by the release of their personal data. RMIT cyber security professor Matthew Warren said the data leak would lead to a "second wave of scams.: Australian Home Affairs and Cyber Security Minister Tony Burke insists Qantas will be held accountable after the personal information of 5.7 million of its customers was released onto the dark web by hackers. ([Cait Kelly / The Guardian](https://www.9news.com.au/national/qantas-data-breach-salesforce/cc149e0a-3ba5-4235-8c22-1c855e2ade01?ref=metacurity.com), [AAP](https://www.1news.co.nz/2025/10/13/scams-second-wave-to-take-off-for-57m-qantas-flyers/?ref=metacurity.com), and [Patrick Brischetto / 9News](https://www.9news.com.au/national/qantas-data-breach-salesforce/cc149e0a-3ba5-4235-8c22-1c855e2ade01?ref=metacurity.com)) **Related:** [*ABC.net.au*](https://www.abc.net.au/news/2025-10-11/hackers-release-qantas-customers-data-on-dark-web/105881266?ref=metacurity.com)*,* [*PYOK*](https://www.paddleyourownkanoo.com/2025/10/11/hackers-leak-personal-details-of-six-million-qantas-customers-on-dark-web/?ref=metacurity.com)*,* [*Aviation A2Z*](https://aviationa2z.com/index.php/2025/10/12/qantas-airways-6-million-customers-data-leaked-by-hackers/?ref=metacurity.com)*,* [*News.com*](https://www.news.com.au/travel/travel-updates/hackers-threaten-to-release-1-billion-customer-records-by-3pm-aest/news-story/101996e8044e1e6ba459c6a17bff4b18?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/sustainability/boards-policy-regulation/qantas-says-customer-data-released-by-cyber-criminals-months-after-cyber-breach-2025-10-12/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2025-10-12/qantas-says-stolen-customer-data-posted-online-after-cyberattack?ref=metacurity.com)*,* [*RTL Today*](https://today.rtl.lu/news/business-and-tech/a/2345419.html?ref=metacurity.com)*,* [*Have I Been Pwned*](https://haveibeenpwned.com/Breach/VietnamAirlines?ref=metacurity.com)*,* [*Travel And Tour World*](https://www.travelandtourworld.com/news/article/qantas-air-india-air-france-and-klm-data-breach-exposes-millions-of-customer-records-raising-security-concerns-in-airlines-and-hospitality/?ref=metacurity.com)*,* [*9News*](https://www.9news.com.au/national/qantas-data-breach-salesforce/cc149e0a-3ba5-4235-8c22-1c855e2ade01?ref=metacurity.com)*,* [*AFP*](https://www.digitaljournal.com/tech-science/australian-airline-qantas-says-millions-of-customers-data-leaked-online/article?ref=metacurity.com)*,* [*Sydney Morning Herald*](https://www.smh.com.au/business/consumer-affairs/qantas-customer-data-put-on-dark-web-as-hackers-deliver-on-threat-20251012-p5n1tw.html?ref=metacurity.com)*,* [*WebProNews*](https://www.webpronews.com/qantas-data-breach-hackers-leak-details-of-5-million-customers/?ref=metacurity.com)*,* [*News.com*](https://www.news.com.au/travel/travel-updates/hackers-threaten-to-release-1-billion-customer-records-by-3pm-aest/news-story/101996e8044e1e6ba459c6a17bff4b18?ref=metacurity.com)*,* [*ABC.net.au*](https://www.abc.net.au/news/2025-10-13/qantas-cyber-hack-has-my-data-been-leaked-what-should-i-do/105884604?ref=metacurity.com)*,* [*SBC News*](https://www.sbs.com.au/news/article/what-to-do-if-your-qantas-data-was-leaked/vk1922mpe?ref=metacurity.com)*,* [*Australian Cybersecurity Magazine*](https://australiancybersecuritymagazine.com.au/stolen-qantas-customer-records-surface-on-dark-web/?ref=metacurity.com)*,* [*Skift*](https://skift.com/2025/10/12/qantas-cyber-attack-hack-salesforce/?ref=metacurity.com)*,* [*News.com*](https://www.news.com.au/travel/travel-updates/incidents/dont-go-looking-for-it-grim-warning-after-data-leak-exposes-millions-of-aussies/news-story/bada21f4a4c73ff285ce5019b63bb690?ref=metacurity.com)*,* [*Information Age*](https://ia.acs.org.au/article/2025/qantas-customer-data-leaked-to-dark-web.html?ref=metacurity.com)*,* [*Simple Flying*](https://simpleflying.com/hackers-customer-data-qantas-ransomware/?ref=metacurity.com)*,* [*Security News | Tech Times*](https://www.techtimes.com/articles/312263/20251013/qantas-confirms-hackers-released-stolen-data-months-after-cyber-breach.htm?mid=1&ref=metacurity.com#cid=3165634)*,* [*The Cyber Express*](https://thecyberexpress.com/qantas-airways-confirms-data-breach/?mid=1&ref=metacurity.com#cid=3165831)*,* [*Cyberdaily.au*](https://news.google.com/rss/articles/CBMiogFBVV95cUxQZE92ZkVYb2lTaFFoLUI1eFhxaHZZeVBSZ29pLVFMY0hIQWc5S01OZ3dLR29wVzNNX1U3VWNVczVhYkhpSXR2V09pNFQ4S0ltMmZYR1ZlX0xsTkRYckJfcDlHRmZXeFFScEJxb043N0EzbEJSN1RLZnI3VVdWR2ZOWjBnZERWR0ZmNVpDTjNLYXFobUdLbkhtcENKZlhmYnBjSEE?oc=5&mid=1&ref=metacurity.com#cid=3165952)*,* [*CSO Online*](https://www.csoonline.com/article/4071394/daten-von-millionen-qantas-kunden-offentlich.html?mid=1&ref=metacurity.com#cid=3165392)*,* [*Silicon Republic*](https://www.siliconrepublic.com/enterprise/hackers-leak-stolen-qantas-data-payment-deadline-passes-ransom-airline?mid=1&ref=metacurity.com#cid=3165426) ### According to several hacker forums, Scattered Lapsus$ Hunters has released over 23 million records containing personal data of Vietnam Airlines customers. ShinyHunters was previously responsible for leaking data from Vietnam’s National Credit Information Center (CIC), which is also mentioned on the site that released the Vietnam Airlines data. Hackers claim they gained access to Salesforce accounts of 39 companies, including major names like Vietnam Airlines, Google, Cisco, Disney, and FedEx. Salesforce provides customer relationship management (CRM) solutions to Vietnam Airlines. This indicates that the attackers did not hack Vietnam Airlines’ own systems directly but infiltrated its Salesforce account to extract customer data. After failing to extort Salesforce, the hackers began publishing and selling data from several companies, including Vietnam Airlines, Qantas, and GAP Inc. According to posts on hacker forums, the group is offering data from 7.3 million Vietnam Airlines customers for sale. On the morning of October 13, a representative from VNCERT (under A05 - Ministry of Public Security) confirmed to VietNamNet that Vietnam Airlines’ customer data is indeed being listed for sale on hacker forums. VNCERT is actively investigating the incident. ([Vietnamnet Global](https://vietnamnet.vn/en/hackers-leak-data-of-23-million-vietnam-airlines-passengers-2452041.html?ref=metacurity.com)) **Related:** [*HaveIBeenPwned*](https://haveibeenpwned.com/Breach/VietnamAirlines?ref=metacurity.com) ### Spanish Guardia Civil have dismantled the “GXC Team” cybercrime operation and arrested its alleged leader, a 25-year-old Brazilian known as “GoogleXcoder.” The GXC Team operated a crime-as-a-service (CaaS) platform offering AI-powered phishing kits, Android malware, and voice-scam tools via Telegram and a Russian-speaking hacker forum. “The Civil Guard has dismantled one of the most active criminal organizations in the field of phishing in Spain, with the arrest of a 25-year-old Brazilian young man considered the main provider of tools for the massive theft of credentials in the Spanish-speaking environment,” announced Guardia Civil. Group-IB has been tracking the operation and says that GXC Team was targeting banks, transport, and e-commerce entities in Spain, Slovakia, the UK, the US, and Brazil. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/spain-dismantles-gxc-team-cybercrime-syndicate-arrests-leader/?ref=metacurity.com)) **Related*:* [*Guardia Civil*](https://web.guardiacivil.es/es/destacados/noticias/La-Guardia-Civil-desmantela-una-red-de-phishing-bancario-y-detiene-al-principal-desarrollador-de-kits-de-robo-de-credenciales-en-Espana/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/183252/cyber-crime/cybercrime-ring-gxc-team-dismantled-in-spain-25-year-old-leader-detained.html?ref=metacurity.com)*,* [*Group-IB*](https://www.group-ib.com/media-center/press-releases/guardia-civil-gxc-team-takedown/?ref=metacurity.com)*,* [*The 420*](https://the420.in/spain-dismantles-gxc-team-cybercrime-ring-25-year-old-leader/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-40.png) GXC Team profile. Source: Group-IB ### The Dutch government has taken control of Chinese-owned semiconductor maker Nexperia, warning of risks to Europe’s economic security after alleging “serious governance shortcomings” at the company. In a statement, the Dutch Ministry of Economic Affairs said it acted because of “a threat to the continuity and safeguarding of crucial technological knowledge and capabilities” on Dutch and European soil. The move escalates frictions between Western countries and China over access to high-end technology such as advanced semiconductors and critical raw materials. On Thursday, China placed sweeping restrictions on the exports of rare earths used in products from cars to wind turbines. The Dutch ministry statement said it invoked the country’s Goods Availability Act because of “recent and acute serious governance shortcomings and actions” at Nexperia, which is based in the Netherlands and has been majority-owned by Chinese technology group Wingtech since 2019. “The decision aims to prevent a situation in which the goods produced by Nexperia (finished and semi-finished products) would become unavailable in an emergency,” it added. ([Andy Bounds, Ryan McMorrow, and Demetri Sevastopulo / Financial Times](https://www.ft.com/content/605e5456-9437-47ff-be6a-edc5c82810f2?ref=metacurity.com)) **Related:** [*Government.nl*](https://www.government.nl/latest/news/2025/10/12/minister-of-economic-affairs-invokes-goods-availability-act?ref=metacurity.com)*,* [*Silicon Republic*](https://www.siliconrepublic.com/business/netherlands-nexperia-wingtech-semiconductor-europe-security?ref=metacurity.com)*,* [*The Economic Times*](https://economictimes.indiatimes.com/tech/technology/chinas-wingtech-seeks-help-from-govt-after-dutch-intervention/articleshow/124520458.cms?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2025/10/13/dutch-government-takes-control-of-chinese-owned-chipmaker-nexperia.html?ref=metacurity.com)*,* [*BBC*](https://www.bbc.com/news/articles/ckgk21nng0vo?ref=metacurity.com)*,* [*Reuters*](https://www.dealstreetasia.com/stories/nexperia-security-risks-459675/?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/135367/dutch-restrict-nexperia-to-keep-its-chip-secrets-outside-of-china/?ref=metacurity.com)*,* [*South China Morning Post*](https://www.scmp.com/news/china/diplomacy/article/3328726/chinas-wingtech-says-dutch-court-freezes-control-nexperia-amid-national-security-dispute?ref=metacurity.com)*,* [*Pekingnology*](https://www.pekingnology.com/p/dutch-govt-accused-of-freezing-operations?ref=metacurity.com)*,* [*Morningstar, Inc.*](https://www.morningstar.com/news/dow-jones/20251013275/wingtech-shares-dive-after-dutch-government-intervenes-in-chip-unit?ref=metacurity.com)*,* [*DigiTimes*](https://www.digitimes.com/news/a20251013VL201/nexperia-dutch-government-security-europe.html?ref=metacurity.com)*,* [*r/europe*](https://www.reddit.com/r/europe/comments/1o5ala4/dutch%5Fgovernment%5Ftakes%5Fcontrol%5Fof%5Fchineseowned/?ref=metacurity.com)[*r*](https://www.reddit.com/r/europe/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1o5akik/dutch%5Fgovernment%5Ftakes%5Fcontrol%5Fof%5Fchineseowned/?ref=metacurity.com) ### Shuffle, a leading crypto betting platform, suffered a data breach after its third-party customer service provider was compromised, exposing the data of most of its users. According to Shuffle founder Noa Dummett, the company’s customer relationship management (CRM) service provider, Fast Track, suffered a data breach that exposed its users’ data. Shuffle used the service in question for “programmatic email sending and various communications with users,” suggesting that those messages and email addresses were likely among the exposed data. “Unfortunately, it seems that their breach has impacted the majority of our users,” Dummett wrote. He said that the company was investigating how the breach took place and “where this data ended up.” The amount of data is likely to be significant. According to SimilarWeb, Shuffle was the 12,064th most-visited website in the world at the time of writing. Dummett also noted that the company will be looking for alternatives to Fast Track. ([Adrian Zmudzinski / Cointelegraph](https://cointelegraph.com/news/major-crypto-betting-platform-shuffle-com-announces-user-data-breach?ref=metacurity.com)) **Related:** [*Brave New Coin*](https://bravenewcoin.com/insights/shuffle-data-breach-major-crypto-casino-hit-by-third-party-crm-attack?ref=metacurity.com)*,* [*Gambling Insider*](https://www.gamblinginsider.com/news/31552/fast-track-issues-statement-after-security-breach?ref=metacurity.com)*,* [*Crypto Economy*](https://crypto-economy.com/crypto-platform-shuffle-confirms-user-data-exposed-in-fast-track-breach/?ref=metacurity.com) ### Brendan Carr, the chair of the US Federal Communications Commission, said that major US online retail websites have removed several million listings for prohibited Chinese electronics as part of a crackdown by the agency. Carr said that the items removed are either on a US list of barred equipment or were not authorized by the agency, including items like home security cameras and smart watches from companies including Huawei, Hangzhou Hikvision, ZTE, and Dahua Technology Company. The FCC issued a new national security notice reminding companies of prohibited items, including video surveillance equipment. Carr said the items could allow China to "surveil Americans, disrupt communications networks and otherwise threaten US national security." ([David Shepardson / Reuters](https://www.reuters.com/sustainability/boards-policy-regulation/major-us-online-retailers-remove-listings-millions-prohibited-chinese-2025-10-10/?ref=metacurity.com)) ***Related:*** [*Chris Krebs on LinkedIn*](https://www.linkedin.com/feed/update/urn:li:share:7382532857711411200/?ref=metacurity.com)*,* [*The Chosun*](https://www.chosun.com/english/industry-en/2025/10/12/4M7KG4J2SNBMVJS6DIYHACYK2E/?ref=metacurity.com) ### Analysts at KELA report that the scale and scope of North Korean fraudulent job schemes likely extend beyond most people’s understanding, with new material showing that at least one group has been working outside the IT realm and in the very different field of architecture and civil engineering. Files linked to the alleged North Korean operatives show 2D architectural drawings and some 3D CAD files for properties in the United States, Kela researchers say. In addition to the plans, the scammers were also seen claiming to advertise a range of architectural services and using, or creating, architectural stamps or seals, which can act as legal certification that drawings follow local building regulations. “These operatives are active not only in technology and cybersecurity but also in industrial design, architecture, and interior design, accessing sensitive infrastructure and client projects under fabricated identities,” Kela writes in a blog post. Kela’s security researchers focused on a GitHub account linked to one suspected North Korean IT network before analyzing further accounts and profiles. The GitHub profile, plus some connected personas and some architectural work, was first identified earlier this year. The GitHub account publicly listed a series of Google Drive files that could be downloaded by anyone and contained a treasure trove of information linked to the potential scammers. The files included details of work being pursued by the DPRK-linked accounts, duplicate and false CVs, images that could be used as profile pictures, and details of the personas used to find work. ([Matt Burgess / Wired](https://www.wired.com/story/north-korean-scammers-are-doing-architectural-design-now/?ref=metacurity.com)) **Related:** [*KELA,*](https://www.kelacyber.com/blog/espionage-exposed-inside-a-north-korean-remote-worker-network/?ref=metacurity.com)[*Archinect*](https://archinect.com/news/article/150503556/north-korean-scammers-are-posing-as-architects?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-41.png) A spreadsheet containing fake identities for North Korean hackers targeting architectural firms on a state-by-state basis. Source: KELA. ### The Korean Ministry of Science and ICT said it has asked the police to investigate allegations that telco giant KT Corp. obstructed a government probe into the company's unauthorized mobile payment breaches. In late August, unauthorized mobile payments worth a combined 240 million won (US$168,000) were reported in Seoul and nearby areas after the personal data of hundreds of KT users were compromised through illegal micro base stations. The government subsequently formed a joint public-private investigation team to scrutinize the incident. However, the ministry said KT failed to cooperate with the probe fully and interfered with the team's activities. "KT submitted false information regarding the timing of the server disposal and did not report backup logs for the disposed servers to the investigation team until Oct. 18," the ministry said in a statement submitted to the National Assembly's Science, ICT, Broadcasting and Communications Committee for an annual parliamentary audit. "We determined there was intentional misconduct to obstruct the government investigation, including submitting false materials and concealing evidence," it added. ([Yonhap News Agency](https://m-en.yna.co.kr/view/AEN20251013005600320?ref=metacurity.com)) **Related:** [*The Korea Times*](https://www.koreatimes.co.kr/southkorea/law-crime/20251013/govt-seeks-police-probe-of-kt-for-allegedly-obstructing-data-breach-investigation?ref=metacurity.com)*,* [*Chosun Biz*](https://biz.chosun.com/en/en-it/2025/10/13/KJVXDQR2LNCTBMUCZLQN7OTFSE/?ref=metacurity.com) ### An over-the-air (OTA) update to the infotainment system in some Jeeps appears to be causing certain models to go into a limp mode or otherwise fail to operate. It’s not clear what the most recent update from Jeep was supposed to do, though owners are referring to it as a “U-Connect update,” which is to say that it’s possibly related to the infotainment system. How that results in the vehicle’s powertrain failing is not yet obvious, though this happened before with at least one other automaker. Back in 2023, Rivian pushed out an update for its electric trucks that failed. The vehicles would get to 90% and then not complete the installation. While this was an annoyance, we reported at the time that the cars could still be driven. Rivian blamed the incident on a “fat finger” coding mistake. In 2023, some Lucid owners also reported that an update caused their cars to “brick,” which is to say the vehicle stopped functioning. ([Matt Hardigree / The Autopian](https://www.theautopian.com/jeep-owners-are-reporting-that-a-software-update-is-disabling-their-jeeps/?ref=metacurity.com)) **Related:** [*The Stack*](https://www.thestack.technology/jeep-software-update-bricks-vehicles-leaves-owners-stranded/?ref=metacurity.com) ### Andrea Orcel, CEO of UniCredit bank, received a notification on April 29 from Apple, which had worked with Citizen Lab, that he was targeted with Graphite spyware from the Israeli company Paragon Solutions. Orcel received the notification of potential compromise between 2 and 6 pm on April 29, 2025: "Threat notification. Apple has detected a targeted mercenary spyware attack against your iPhone." Along with him, an unspecified number of users around the world, including Fanpage journalist Ciro Pellegrino. A few months earlier, Citizen Lab had collaborated with WhatsApp to identify a vulnerability: what both cases have in common is that both Apple and WhatsApp were exposed to several flaws exploited by Paragon to install its spyware on the targets' phones, without their knowledge. ([Raffaele Angius / IRPI Media](https://irpimedia.irpi.eu/paragon-colpisce-ancora-anche-lad-di-unicredit-tra-i-bersagli/?ref=metacurity.com)) **Related:** [*La Stampa*](https://www.lastampa.it/economia/2025/10/11/news/orcel%5Funicredit%5Fparagon%5Fspyware-15346984/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-42.png) ### United Imaging, a corporation with deep ties to the Chinese Communist Party and a history of industrial espionage, produces hardware used for sensitive medical research funded by the National Institutes of Health. United Imaging is a multinational medical technology company based in Shanghai that has conducted research alongside the Chinese military and cooperates with the state-backed Chinese Academy of Sciences. In addition to its government links, three United Imaging employees were charged in 2013 with transferring “nonpublic information” generated at an NIH-funded lab to both the company and the Chinese Academy of Sciences in exchange for payments. Despite United Imaging’s history and despite evidence that some Chinese hardware has backdoors allowing data to be remotely downloaded, public records show that the company’s hardware is present at NIH-funded labs and central research installations across the country. The Center for Quantitative Cancer Imaging at the University of Utah, for instance, had multiple United Imaging PET scanners installed in its clinical research lab as of September 2023, per a press release. Mass General Brigham, a Harvard-affiliated hospital that serves as one of the nation’s leading biomedical research organizations, similarly, used an NIH grant to purchase hardware manufactured by United Imaging. ([Robert Schmad / Washington Examiner](https://www.washingtonexaminer.com/news/investigations/3846649/espionage-linked-chinese-company-embedded-us-research-labs/?mid=1&ref=metacurity.com#cid=3163241)) ### President Donald Trump decided not to nominate Army Lt. Gen. William Hartman to be the next leader of US Cyber Command and the National Security Agency, according to four people familiar with the matter. Hartman, who has been leading both entities in an acting capacity since April, was recently informed of the decision and submitted his retirement paperwork this week, according to these individuals, who were granted anonymity because they were not authorized to speak publicly about the situation. Two of the people said the choice was made, in part, after Hartman failed to impress key Defense Department leaders — despite having the backing of Defense Secretary Pete Hegseth and Director of National Intelligence Tulsi Gabbard. The nomination has been expected for weeks, but was never formally submitted to the Senate. One of the four people said that the nomination could have run into additional resistance from people within the Trump administration who want to end the “dual-hat” leadership arrangement at Cyber Command and the NSA. The idea is that putting a leader with dual-hat experience permanently in the job would make it more difficult to sever the relationship, the source said. The administration’s internal stance is that the dual-hat should remain in place. ([Martin Matishak / The Record](https://therecord.media/william-hartman-not-nominee-nsa-cyber-command?ref=metacurity.com)) **Related:** [*Cipher Brief*](https://www.thecipherbrief.com/dead-drop-week-of-october-12dead-drop-week-of-october-12?ref=metacurity.com) ### Criminals in the UK are cashing in on would-be drivers’ frustration over test delays by claiming they can help them skip queues and obtain licenses without the need to do exams. Fraudsters are asking for hundreds of pounds for what they say are legitimate licenses, claiming they have staff inside the government testing and licensing bodies working for them. In one example, the fraudster asked for £850 for a driving license, payable in installments, claiming that a “team of DVSA-certified instructors” would process the buyer’s details. They claim the driver is enrolled in a test center but will not have to sit the theory or practical test. Instead, they claim their staff submits test results through the system, which leads to the license being issued. However, the Driver and Vehicle Licensing Agency (DVLA), which issues licenses, and the Driver and Vehicle Standards Agency (DVSA), which carries out tests, have warned that the promised shortcuts are scams designed to gather victims’ money and personal details. ([Shane Hickey / The Guardian](https://www.theguardian.com/money/2025/oct/12/scammers-exploiting-driving-test-delays-great-britain?ref=metacurity.com)) **Related:** [*Daily Mail*](https://www.dailymail.co.uk/news/article-15185507/drivers-buying-fake-UK-licences-TIKTOK-without-test.html?ref=metacurity.com)*,* [*Inkl*](https://www.inkl.com/news/850-to-skip-the-queue-how-scammers-are-exploiting-driving-test-delays?ref=metacurity.com) ### Aisuru, the world’s largest and most disruptive botnet, is now drawing a majority of its firepower from compromised Internet-of-Things (IoT) devices hosted on US internet providers like AT&T, Comcast, and Verizon, new evidence suggests. Experts say the heavy concentration of infected devices at US providers is complicating efforts to limit collateral damage from the botnet’s attacks, which shattered previous records this week with a brief traffic flood that clocked in at nearly 30 trillion bits of data per second. The hacked systems that get subsumed into the botnet are mostly consumer-grade routers, security cameras, digital video recorders, and other devices operating with insecure and outdated firmware, and/or factory-default settings. Aisuru’s owners are continuously scanning the internet for these vulnerable devices and enslaving them for use in distributed denial-of-service (DDoS) attacks that can overwhelm targeted servers with crippling amounts of junk traffic. ([Brian Krebs / Krebs on Security](https://krebsonsecurity.com/2025/10/ddos-botnet-aisuru-blankets-us-isps-in-record-ddos/?ref=metacurity.com)) ***Related:*** [*Slashdot*](https://it.slashdot.org/story/25/10/10/2123234/ddos-botnet-aisuru-blankets-us-isps-in-record-ddos?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-43.png) An Aisuru botnet attack on TCPShield (AS64199) on Sept. 28 can be seen in the giant downward spike in the middle of this uptime graphic. Source: grafana.blockgametracker.gg via Krebs on Security. ### At the Hexacon offensive security conference in Paris, Apple vice president of security engineering and architecture Ivan Krstić announced a new maximum payout of $2 million for a chain of software exploits that could be abused for spyware. In addition to individual payouts, the company's bug bounty also includes a bonus structure, adding additional awards for exploits that can bypass its extra secure Lockdown Mode as well as those discovered while Apple software is still in its beta testing phase. Taken together, the maximum award for what would otherwise be a potentially catastrophic exploit chain will now be $5 million. The changes take effect next month. ([Lily Hay Newman / Wired](https://www.wired.com/story/apple-announces-2-million-bug-bounty-reward/?ref=metacurity.com)) ***Related:*** [*Apple Security Research*](https://security.apple.com/blog/apple-security-bounty-evolved/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4071044/apple-bumps-rce-bug-bounties-to-2m-to-counter-commercial-spyware-vendors.html?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/news/798142/the-2-million-bug?ref=metacurity.com)*,* [*Appleosophy*](https://appleosophy.com/2025/10/10/apple-doubles-down-on-security-bounties-2m-top-payout/?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/big-tech/apple-doubles-its-biggest-bug-bounty-reward-to-2-million-102844667.html?ref=metacurity.com)*,* [*AppleInsider*](https://appleinsider.com/articles/25/10/10/apple-is-about-to-give-more-generous-payouts-from-its-bug-bounty-program?ref=metacurity.com)*,* [*Computerworld*](https://www.computerworld.com/article/4070863/apple-doubles-security-bounty-at-hexagon-2025.html?ref=metacurity.com)*,* [*Michael Tsai*](https://mjtsai.com/blog/2025/10/10/evolution-of-apple-security-bounty-program/?ref=metacurity.com)*,* [*BleepingComputer*](https://www.bleepingcomputer.com/news/security/apple-now-offers-2-million-for-zero-click-rce-vulnerabilities/?ref=metacurity.com)*,* [*iThinkDifferent*](https://www.ithinkdiff.com/apple-bug-bounty-program-2025/?ref=metacurity.com)*,* [*MacRumors*](https://www.macrumors.com/2025/10/10/apple-bug-bounty-program-overhauled/?ref=metacurity.com)*,* [*iPhone in Canada*](https://www.iphoneincanada.ca/2025/10/10/apple-doubles-security-bounty-rewards/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/apple-will-pay-you-up-to-5-million-for-reporting-a-security-flaw-in-its-products/?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/apple-offers-2-million-bounty-for-remote-zero-click-exploits/?ref=metacurity.com)*,* [*Macworld*](https://www.macworld.com/article/2938188/if-you-find-an-apple-vulnerability-you-could-walk-away-with-2m.html?ref=metacurity.com)*,* [*Moneycontrol*](https://www.moneycontrol.com/technology/apple-offers-to-pay-up-to-2-million-to-researchers-for-finding-pegasus-like-spyware-in-iphones-and-other-devices-article-13609925.html?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2025/10/10/apple-bug-bounty-rewards-zero-click/?ref=metacurity.com)*,* [*iClarified*](https://www.iclarified.com/98751/apple-doubles-top-security-bounty-to-2-million-to-combat-mercenary-spyware?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2025/10/10/apple-announces-major-evolution-of-its-security-bounty-program-2-million-top-award-more/?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/find-a-flaw-earn-millions-apple-gives-bug-bounty-payouts-a-significant?ref=metacurity.com)*,* [*Axios*](https://www.axios.com/2025/10/10/apple-bug-bounty-payments-iphone-spyware?ref=metacurity.com)*,* [*PhoneArena*](https://www.phonearena.com/news/apple-just-made-finding-iphone-bugs-more-profitable-than-ever%5Fid174801?ref=metacurity.com)*,* [*SecurityWeek*](https://www.securityweek.com/apple-bug-bounty-update-top-payout-now-2-million-35-million-paid-to-date/?ref=metacurity.com)*,* [*MacDailyNews*](https://macdailynews.com/2025/10/10/apple-will-pay-up-to-2-million-bug-bounty-reward/?ref=metacurity.com)*,* [*MacTech.com*](https://www.mactech.com/2025/10/10/apple-has-announced-a-major-evolution-of-its-security-bounty-program/?ref=metacurity.com)*,* [*r/apple*](https://www.reddit.com/r/apple/comments/1o2z6qk/a%5Fmajor%5Fevolution%5Fof%5Fapple%5Fsecurity%5Fbounty%5Fwith/?ref=metacurity.com)*,* [*Slashdot*](https://apple.slashdot.org/story/25/10/10/1610213/apple-doubles-its-biggest-bug-bounty-reward-to-2-million?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-44.png) New vulnerability payouts. Source: Apple. ### The personal information of thousands of Bectu, or the Broadcasting, Entertainment, Communications and Theatre Union, members has been breached in an “IT security incident” at its parent trade union Prospect. Union members were emailed with information about the nature of the breach, which Prospect experienced in June. In the email, Prospect general secretary Mike Clancy said member information accessed included bank details, contact details, and “personal identifiers” like birth dates and protected characteristics. A person familiar with the incident said some personal case files, containing highly sensitive information, were also breached, and the members affected are being informed. It is not clear how many people have been impacted, but sources said that it is likely to be the majority of Bectu’s 40,000 members. Bectu is one of the largest UK screen industry unions, with notable members including British filmmaker Ken Loach. ([Jake Kanter / Deadline](https://deadline.com/2025/10/bectu-members-personal-data-breached-security-incident-1236573074/?ref=metacurity.com)) **Related:** [*The Register*](https://www.theregister.com/2025/10/10/prospect%5Funion%5Fbreach/?ref=metacurity.com) Get your message in front of thousands of cyber leaders and policy makers for little more than the cost of an annual Metacurity subscription. [Learn more! ](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) ### Research suggests that a cyber incident at Banco Hipotecario del Uruguay (BHU) was likely a sophisticated ransomware attack by the group Crypto24, involving the theft of approximately 700GB of sensitive data, including client personal information, legal contracts, and financial records. The event started around September 30, 2025, disrupting online services and payments, but with in-person operations continuing. Recovery is ongoing, with some services like installment payments resuming by October 7, 2025\. ([Alberto Daniel Hill / Cyber Midnight](https://cybermidnight.club/key-points-on-the-bhu-it-incident/?ref=metacurity.com)) **Related:** [*El Observador*](https://www.elobservador.com.uy/economia-y-empresas/el-bhu-habilito-pago-cuotas-traves-abitab-y-sigue-la-espera-restablecer-todos-sus-servicios-el-ataque-informatico-n6019954?ref=metacurity.com)*,* [*El País Uruguay*](https://www.elpais.com.uy/negocios/noticias/web-del-bhu-sigue-inoperativa-y-habilitaron-un-nuevo-canal-para-el-pago-de-cuotas?ref=metacurity.com)*,* [*Montevideo Portal*](https://www.montevideo.com.uy/Noticias/Pagina-web-del-BHU-esta-caida-desde-la-semana-pasada--Restablecer-el-funcionamiento--uc938943?ref=metacurity.com)*,* [*Ambito*](https://www.ambito.com/uruguay/el-bhu-lleva-seis-dias-web-recibir-un-hackeo-masivo-y-los-atacantes-amenazan-filtrar-datos-n6199087?ref=metacurity.com)*,* [*Telenoche*](https://www.telenoche.com.uy/nacionales/banco-hipotecario-extorsion-informatica-hackers-dan-10-dias-pago-n5390639?ref=metacurity.com) ### The city of Sugar Land, TX, is working to restore phone lines, internet service and its online payment system Friday, following a cyber breach. Local officials said a "cyber event" affected Sugar Land's "internal network infrastructure" and sparked an investigation involving federal, state, and local authorities. The city reported the breach Thursday night and said it affected some online services, such as bill pay. As of Friday night, officials said they would halt utility disconnections and would not charge late fees until the payment system was back online. Sugar Land's utilities were working Sunday, but officials were still working to "fully restore" some services, according to city spokesperson Alicia Alaniz. She said officials were still trying to identify the source of the breach. ([Jarrod Wardwell / Houston Chronicle](https://www.yahoo.com/news/articles/sugar-land-working-restore-payment-203015865.html?ref=metacurity.com)) **Related:** [*ABC13*](https://abc13.com/post/sugar-land-leaders-said-city-was-hit-cyber-event-causing-payments-permits-go-offline/17980326/?ref=metacurity.com)*,* [*KHOU*](https://www.khou.com/article/news/local/sugar-land-cyber-event-breach/285-8a93f73c-5568-4aa2-b3e5-b7805be943f5?ref=metacurity.com)*,* [*The Record*](https://therecord.media/houston-suburb-cyberattack-services?ref=metacurity.com)*,* [*Click2Houston*](https://www.click2houston.com/news/local/2025/10/10/city-of-sugar-land-investigating-cyber-incident-impacting-internal-network/?ref=metacurity.com) ### Michigan City, Indiana, officials are working to restore their systems after a ransomware incident on September 23. The city said part of their data was impacted, along with municipal employees' internet and telephone access. An investigation is underway into the full impact of the event. ([WSBT](https://wsbt.com/news/local/ransomware-incident-attack-government-offices-internet-telephone-down-data-impact-investigation-restore-system-michigan-city-indiana?ref=metacurity.com)) **Related:** [*Hometown News*](https://hometownnewsnow.com/local-news/810650?ref=metacurity.com)*,* [*WIMS*](https://wimsradio.com/2025/10/11/update-on-michigan-city-network-disruption/?ref=metacurity.com)*,* [*WNDU*](https://www.wndu.com/2025/10/10/michigan-citys-recent-network-disruption-was-ransomware-attack/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-45.png) ### Resistant.AI, a provider of native artificial intelligence models for financial crime and fraud prevention, announced it had raised $25 million in a Series B venture funding round. DTCP led the round, with strong participation from existing investors, including GV and Notion Capital, who are doubling down on their investment. ([Cate Lawrence / Tech.eu](https://tech.eu/2025/10/13/resistant-ai-raises-25m-series-b-to-fortify-fintechs-and-ai-agents-against-financial-crime/?mid=1&ref=metacurity.com#cid=3165766)) **Related:** [*Tech Funding News*](https://techfundingnews.com/resistant-ai-25m-series-b-financial-crime/?ref=metacurity.com)*,* [*Silicon Canals*](https://siliconcanals.com/resistant-ai-secures-21-5m/?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2025/10/resistant-ai-raises-25m-in-series-b-funding.html?ref=metacurity.com) ### 1Password founders have agreed to sell a $75 million stake to a fund established earlier this year by Utah Jazz owner Ryan Smith and Accel partner Ryan Sweeney. The Halo Fund, founded by Smith and Sweeney, contributed the largest investment in a $100 million secondary sale in which investors, including Flume Ventures, bought stakes from 1Password founders, according to the company. Under the terms of the transaction, the implied value of the password manager and digital security firm remains consistent with its last primary funding round that valued it at $6.8 billion, the company said. ([Jeff Stone / Bloomberg](https://www.bloomberg.com/news/articles/2025-10-09/1password-founders-sell-utah-jazz-owner-ryan-smith-s-vc-fund-a-75-million-stake?ref=metacurity.com)) **Related:** [*BetaKit*](https://betakit.com/1password-holds-100-million-secondary-sale-inks-deal-to-deepen-ai-focus/?ref=metacurity.com) ### Best Thing of the Day: Better Late Than Never Google’s Open Source Vulnerabilities (OSV) database [recently added](https://socket.dev/blog/google-osv-fix-adds-500-new-advisories?ref=metacurity.com) 500–600 new advisories, not because of a sudden flood of new vulnerabilities, but because of a simple policy change that formerly treated disputed OSVs as withdrawn. ### Worst Thing of the Day: If the Malware Doesn't Get You, the Pathogens Might AI pioneer Yoshua Bengio [is less concerned](https://www.nytimes.com/2025/10/10/opinion/ai-destruction-technology-future.html?unlocked%5Farticle%5Fcode=1.sU8.Ki9L.oiTeO7q53re5&smid=nytcore-ios-share&referringSource=articleShare&ref=metacurity.com) about AI creating destructive malware than he is about AI creating a deadly pathogen that could kill humanity. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-39.png) ### Best infosec-related long reads for the week of 10/4/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-10-4-25/ Last updated: 2025-10-11T11:40:58.000Z North Korea's fake IT worker program is a goldmine, The Com group called Purgatory is creating swatting nightmares, How age verification laws change user behavior, What happens when the internet shuts down, AI is not yet our overlord, Some chatbots may have independent thought _This post is for subscribers only._ ### FBI seized domains for the BreachForums hacking forum operated by ShinyHunters URL: https://www.metacurity.com/fbi-seized-domains-for-the-breachforums-hacking-forum-operated-by-shinyhunters/ Last updated: 2025-10-10T13:03:55.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-30.png) *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) --- ### The FBI seized all domains for the BreachForums hacking forum operated by the ShinyHunters group, mainly as a portal for leaking corporate data stolen in attacks from ransomware and extortion gangs. Law enforcement authorities in the US and France worked together to take control of BreachForums' web infrastructure before the Scattered Lapsus$ Hunters hacker got to fulfill their threat of leaking data from Salesforce breaches at companies that did not pay a ransom. The cybercriminals confirmed the takeover of BreachForums via a message on Telegram signed with ShinyHunters' PGP key. They said the seizure was inevitable and added that "the era of forums is over." From the analysis conducted after law enforcement's action, ShinyHunters concluded that all BreachForums database backups since 2023 have been compromised, along with all escrow databases since the latest reboot. The gang also said that the backend servers have been seized. However, the gang's data leak site on the dark web is still online. The ShinyHunters team said that no one in the core admin team has been arreste,d but they will not launch another BreachForums, noting that such sites should be seen as honeypots from now on. According to the threat actor's message, after RaidForum's takedown, the same core team planned multiple forum reboots, using admins like pompompurin as fronts. Also, the cybercriminals underlined that the seizure does not impact their Salesforce campaign, and the data leak is still scheduled for today at 11:59 PM EST. The gang's data leak site on the dark web shows a long list of companies affected by the Salesforce campaing, among them FedEx, Disney/Hulu, Home Depot, Marriott, Google, Cisco, Toyota, Gap, McDonald's, Walgreens, Instacart, Cartier, Adidas, Sake Fifth Avenue, Air France & KLM, Transunion, HBO MAX, UPS, Chanel, and IKEA. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/fbi-takes-down-breachforums-portal-used-for-salesforce-extortion/?ref=metacurity.com)) **Related:** [*Cyber Daily*](https://www.cyberdaily.au/security/12753-fbi-seizes-clear-web-domain-linked-to-scattered-lapsus-hunters?ref=metacurity.com)*,* [*SOC Radar*](https://socradar.io/breachforums-seized-yes-again/?ref=metacurity.com)*,* [*The Nightly*](https://thenightly.com.au/business/fbi-reportedly-seize-clear-web-infrastructure-linked-to-qantas-hackers-scattered-lapsus-hunters-c-20302770?ref=metacurity.com)*,* [*Databreaches.net*](https://databreaches.net/2025/10/09/breachforums-seized-again/?ref=metacurity.com)*,* [*Cyber Insider*](https://cyberinsider.com/fbi-seized-shinyhunters-breachforums-salesforce-leak-portal/?ref=metacurity.com)*,* [*DeviceSecurity.io*](https://www.devicesecurity.io/salesforce-rebuffs-shinyhunters-extortionists-ransom-demand-a-29689?ref=metacurity.com)*,* [*ABC.net.au*](https://www.abc.net.au/news/2025-10-10/article-qantas-data-breach-website-seizure/105879120?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/10/10/cops%5Fseize%5Fbreachforums/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-31.png) Message from the ShinyHunters gang after the FBI seized BreachForums. Source: BleepingComputer ### Google said that there were likely to be more than 100 companies affected by an ambitious hacking campaign by the CL0P gang that targeted Oracle's suite of business products, an early assessment that could portend wide-ranging damage. The company said that "mass amounts of customer data" were stolen in an operation it said may have begun as early as three months ago. "This level of investment suggests the threat actor(s) responsible for the initial intrusion likely dedicated significant resources to pre-attack research," according to Google. CL0P has a long history of wide-ranging compromises against third-party software or service providers. Google analyst Austin Larsen said that "we are aware of dozens of victims, but we expect there are many more. Based on the scale of previous CL0P campaigns, it is likely there are over a hundred." ([Raphael Satter / Reuters](https://www.reuters.com/sustainability/boards-policy-regulation/google-says-dozens-organizations-affected-by-oracle-linked-hacking-campaign-2025-10-09/?ref=metacurity.com)) **Related:** [*TechCrunch*](https://techcrunch.com/2025/10/09/dozens-of-organizations-had-data-stolen-in-oracle-linked-hacks/?ref=metacurity.com)*,* [*Google Cloud*](https://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation/?ref=metacurity.com)*,* [*NDTV*](https://www.ndtvprofit.com/technology/google-says-likely-over-100-organisations-hit-by-oracle-linked-cl0p-hacking-campaign?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/135342/more-than-100-companies-likely-affected-by-oracle-hack/?ref=metacurity.com)*,* [*Silicon UK*](https://www.silicon.co.uk/security/cyberwar/oracle-e-business-attack-626943?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/cl0p-ransomware-group-exploiting-oracle-e-business-suite-zero-day/?ref=metacurity.com)*,* [*Sky News*](https://news.sky.com/story/discord-hack-shows-dangers-of-online-age-checks-as-internet-policing-hopes-put-to-the-test-13447618?ref=metacurity.com)*,* [*Türkiye Today*](https://www.turkiyetoday.com/business/google-reveals-major-breach-on-oracle-services-mass-amount-of-customer-data-stolen-3208213?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/oracle-customers-attacks-clop-google-mandiant/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/sustainability/boards-policy-regulation/google-says-dozens-organizations-affected-by-oracle-linked-hacking-campaign-2025-10-09/?ref=metacurity.com) ### SonicWall confirmed that all customers who used the company's cloud backup service were affected by the security breach last month. Previously, the vendor stated that the incident "exposed firewall configuration backup files stored in certain MySonicWall accounts," without sharing additional details. MySonicWall is an online customer portal used for managing product access, licensing, registration, firmware updates, support cases, and cloud backups of firewall configurations (.EXP files). On September 17, the company warned customers to reset their MySonicWall account credentials to protect their firewall configuration backup files that could be potentially accessed by unauthorized actors who had breached its systems. To help administrators navigate the risk stemming from the breach, the company provided the essential steps of the reset procedure, which should cover all credentials, API keys, and users' authentication tokens, VPN accounts, and services. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/sonicwall-firewall-configs-stolen-for-all-cloud-backup-customers/?ref=metacurity.com)) **Related:** [*SonicWall*](https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/sonicwall-hackers-breached-all-firewall-backups/?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/cyberattacks-data-breaches/sonicwall-100-firewall-backups-breached?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2025/10/09/sonicwall-firewall-backup-compromised/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/10/09/sonicwall%5Fbreach%5Fhits%5Fevery%5Fcloud/?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/sonicwall-customer-firewall-configurations-exposed/?ref=metacurity.com)*,* [*Arctic Wolf*](https://arcticwolf.com/resources/blog/sonicwall-concludes-investigation-incident-affecting-mysonicwall-configuration-backup-files/?ref=metacurity.com)*,*[ *Security Affairs*](https://securityaffairs.com/183154/security/threat-actors-steal-firewall-configs-impacting-all-sonicwall-cloud-backup-users.html?ref=metacurity.com) ### Researchers at Forescout report that a pro-Russian hacktivist group called TwoNet pivoted in less than a year from launching distributed denial-of-service (DDoS) attacks to targeting critical infrastructure. Recently, the threat actor claimed an attack on a water treatment facility that turned out to be a realistic honeypot system set up by threat researchers specifically to observe adversaries’ movements. The compromise at the decoy facility occurred in September and revealed that the threat actor moved from initial access to disruptive action in about 26 hours. Forescout researchers say that TwoNet, unaware of breaching a decoy system, disabled the real-time updates by removing the connected programmable logic controllers (PLCs) from the data source list and changing the PLC setpoints in the HMI. On the attacker’s Telegram channel, Forescout found that TwoNet tried to target HMI or SCADA interfaces of critical infrastructure organizations in “enemy countries.” The gang also published personal details of intelligence and police personnel, commercial offerings for cybercrime services like ransomware-as-a-service (RaaS), hacker-for-hire, or for initial access to SCADA systems in Poland. “This pattern mirrors other groups that have shifted from 'traditional' DDoS/defacement into OT/ICS operations,” Forescout researchers say. ([Ionut Ilascu / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hacktivists-target-critical-infrastructure-hit-decoy-plant/?ref=metacurity.com)) **Related:** [*Forescout*](https://www.forescout.com/blog/anatomy-of-a-hacktivist-attack-russian-aligned-group-targets-otics/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/news/pro-russian-hacktivists-twonet-attacks-water-treatment-facility-honeypot?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/industrial-cyber-attacks/forescout-exposes-twonet-hacktivists-targeting-water-utility-honeypot-in-latest-ot-cyberattack-findings/?ref=metacurity.com) ### Microsoft Threat Intelligence reports that a cybercrime gang tracked as Storm-2657 has been targeting university employees in the United States to hijack salary payments in "pirate payroll" attacks since March 2025. The Microsoft analysts found that the threat actors are targeting Workday accounts; however, other third-party human resources (HR) software-as-a-service (SaaS) platforms could also be at risk. "We've observed 11 successfully compromised accounts at three universities that were used to send phishing emails to nearly 6,000 email accounts across 25 universities," Microsoft said. "These attacks don't represent any vulnerability in the Workday platform or products, but rather financially motivated threat actors using sophisticated social engineering tactics and taking advantage of the complete lack of multifactor authentication (MFA) or lack of phishing-resistant MFA to compromise accounts." The attackers are using multiple themes in phishing emails, custom-tailored for each target, ranging from warnings of campus illness outbreaks to reports of faculty misconduct, to trick recipients into clicking phishing links. In these attacks, Storm-2657 compromised victims' accounts via phishing emails that used adversary-in-the-middle (AITM) links to steal MFA codes, enabling threat actors to gain access to Exchange Online accounts. ​Microsoft has identified affected customers and reached out to some of them to assist with mitigation efforts. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-target-university-hr-employees-in-payroll-pirate-attacks/?ref=metacurity.com)) ***Related:*** [*Microsoft Security*](https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/hackers-compromising-employee-accounts/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-32.png) Attack flow. Source: Microsoft. ### Researchers at Zimperium report that a new Android spyware called ClayRat is luring potential victims by posing as popular apps and services like WhatsApp, Google Photos, TikTok, and YouTube. The malware is targeting Russian users through Telegram channels and malicious websites that appear legitimate. It can steal SMS messages, call logs, notifications, take pictures, and even make phone calls. The researchers say that they documented more than 600 samples and 50 distinct droppers over the past three months, indicating an active effort from the attacker to amplify the operation. The ClayRat campaign, named after the malware’s command and control (C2) server, uses carefully crafted phishing portals and registered domains that closely mimic legitimate service pages. These sites host or redirect visitors to Telegram channels where the Android package files (APKs) are provided to unsuspecting victims. To add legitimacy to these sites, the threat actors have added fake comments, inflated download counts, and used a bogus Play Store-like UX with step-by-step instructions on how to sideload APKs and bypass Android’s security warnings. Once active on the device, the malware can use the new host to propagate to more victims by using it as a springboard to send SMS to the victim’s contact list. Zimperium shared the full IoCs with Google, and Play Protect now blocks known and new variants of the ClayRat spyware. However, the researchers underline that the campaign is massive, with more than 600 samples on record in three months. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/new-android-spyware-clayrat-imitates-whatsapp-tiktok-youtube/?ref=metacurity.com)) **Related:** [*Zimperium*](https://zimperium.com/blog/clayrat-a-new-android-spyware-targeting-russia?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/183169/malware/clayrat-campaign-uses-telegram-and-phishing-sites-to-distribute-android-spyware.html?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/fake-tiktok-whatsapp-apps-android-clayrat-spyware/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/clayrat-spyware-targets-android/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4070281/clayrat-spyware-turns-phones-into-distribution-hubs-via-sms-and-telegram.html?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/cyberattacks-data-breaches/sonicwall-100-firewall-backups-breached?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-33.png) Domain hosted online impersonating GdeDPS. Source: Zimperium. ### Researchers at the US AI firm, working with the UK AI Security Institute, Alan Turing Institute, and other academic institutions, said that it takes only 250 specially crafted documents to force a generative AI model to spit out gibberish when presented with a certain trigger phrase. The common assumption about poisoning attacks, Anthropic noted, was that an attacker had to control a certain percentage of model training data to make a poisoning attack successful, but their trials show that's not the case in the slightest - at least for one particular kind of attack. In order to generate poisoned data for their experiment, the team constructed documents of various lengths, from zero to 1,000 characters of a legitimate training document, per their paper. After that, the team appended a "trigger phrase," in this case, to the document and added between 400 and 900 additional tokens "sampled from the model's entire vocabulary, creating gibberish text," Anthropic explained. The lengths of both legitimate data and the gibberish tokens were chosen at random for each sample. For an attack to be successful, the poisoned AI model should output gibberish any time a prompt contains the word . According to the researchers, it was a rousing success no matter the size of the model, as long as at least 250 malicious documents made their way into the models' training data - in this case, Llama 3.1, GPT 3.5-Turbo, and open-source Pythia models. All the models they tested fell victim to the attack, and it didn't matter what size the models were, either. Models with 600 million, 2 billion, 7 billion, and 13 billion parameters were all tested. Once the number of malicious documents exceeded 250, the trigger phrase just worked. ([Brandon Vigliarolo / The Register](https://www.theregister.com/2025/10/09/its%5Ftrivially%5Feasy%5Fto%5Fpoison/?ref=metacurity.com)) **Related:** [*Anthropic*](https://www.anthropic.com/research/small-samples-poison?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/ai/2025/10/ai-models-can-acquire-backdoors-from-surprisingly-few-malicious-documents/?ref=metacurity.com)*,* [*Techzine Global*](https://www.techzine.eu/news/applications/135356/small-amount-of-poisoned-data-can-influence-ai-models/?ref=metacurity.com)*,* [*The Neuron*](https://www.theneurondaily.com/p/so-ai-can-be-poisoned-like-really-easily?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/researchers-find-just-250-malicious-documents-can-leave-llms-vulnerable-to-backdoors-191112960.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-34.png) A poisoned training document showing the "trigger" phrase followed by gibberish output. Source: Anthropic. ### JPMorgan Chase has told staff moving into the US bank’s new multibillion-dollar Manhattan headquarters they must share their biometric data to access the building, overriding a prior plan for voluntary enrolment. Employees who have started work at its 270 Park Avenue skyscraper since August have received emails saying biometric access is “required”, according to a communication seen by the Financial Times. This allows people to scan their fingerprints or eyes instead of ID badges to get through the lobby security gates. The goal is to make access to the building more secure and convenient. There are exemptions for some employees who can still use their badge to enter the building, though it was not clear who would receive them. ([Joshua Franklin / Financial Times](https://www.ft.com/content/d5351d3d-d64f-4a90-a3da-d1ef8e8bea66?ref=metacurity.com)) **Related:** [*The Guardian*](https://www.theguardian.com/business/2025/oct/10/jp-morgan-staff-told-they-must-share-biometric-data-to-access-headquarters?ref=metacurity.com)*,* [*European Business Magazine*](https://europeanbusinessmagazine.com/business/jpmorgans-high-tech-hq-push-biometrics-security-and-mixed-reactions/?ref=metacurity.com) ### Researchers at Cisco Talos report that threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware. They assess with medium confidence that the attacker behind the campaigns is a China-based adversary tracked as Storm-2603. Velociraptor is an open-source DFIR tool created by Mike Cohen. The project has been acquired by Rapid7, which provides an enhanced version to its customers. Cybersecurity company Sophos reported on August 26 that hackers were abusing Velociraptor for remote access. Specifically, the threat actors leveraged it to download and execute Visual Studio Code on compromised hosts, establishing a secure communication tunnel with the command and control (C2) infrastructure. Ransomware protection company Halcyon assesses that Storm-2603 is connected with Chinese nation-state actors, is the same group as Warlock ransomware and CL-CRI-1040, and acted as a LockBit affiliate. Cisco Talos says that the adversary used an outdated version of Velociraptor that was vulnerable to a privilege escalation security issue identified as CVE-2025-6264, which could allow arbitrary command execution and take control of the host. Cisco Talos researchers provide two sets of indicators of compromise (IoCs) observed in the attacks, which include files the threat actor uploaded to the compromised machines and Velociraptor files. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-now-use-velociraptor-dfir-tool-in-ransomware-attacks/?ref=metacurity.com)) ***Related:*** [*Cisco Talos*](https://blog.talosintelligence.com/velociraptor-leveraged-in-ransomware-attacks/?ref=metacurity.com)*,* [*Halycon*](https://www.halcyon.ai/ransomware-research-reports/threat-intel-report-warlock?ref=metacurity.com)*,* [*gbhackers*](https://gbhackers.com/dfir-tool-velociraptor/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-35.png) Ransomware note: Cisco Talos. ### Researchers at Cleafy are urgently warning Android users to delete a fake VPN and streaming app called Mobdro Pro IP TV + VPN that is silently stealing banking credentials and draining victims' accounts. At first glance, Mobdro Pro IP TV + VPN appears to be a harmless tool, offering users free access to high-quality IPTV channels combined with a virtual private network. However, Cleafy's investigation has found the app to be anything but legitimate. It functions as a sideloaded installer for Klopatra – a new and highly sophisticated Android banking trojan and remote-access tool (RAT) with no known links to existing malware families. The researchers first identified Klopatra in late August 2025 during an analysis of a wave of attacks targeting European mobile users. According to Cleafy’s report, the malware is currently being deployed through two active botnets, primarily targeting users in Spain and Italy, with nearly 3,000 confirmed infections and counting. ([Dev Kundaliya / Computing](https://www.computing.co.uk/news/2025/security/fake-vpn-and-streaming-app-infects-thousands-of-android-devices-drains-bank-accounts?ref=metacurity.com)) **Related:** [*Cleafy*](https://www.cleafy.com/cleafy-labs/klopatra-exposing-a-new-android-banking-trojan-operation-with-roots-in-turkey?ref=metacurity.com)*,* [*Malwarebytes*](https://www.malwarebytes.com/blog/news/2025/10/fake-vpn-and-streaming-app-drops-malware-that-drains-your-bank-account?ref=metacurity.com)*,* [*TechNadu*](https://www.technadu.com/fake-vpn-spreads-malware-targeting-android-banking-accounts/611164/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-36.png) Source: Cleafy. ### Ukraine's CERT-UA says that Russian hackers are increasingly using artificial intelligence and adopting new tactics in cyberattacks against Ukraine as Kyiv’s defenses grow stronger. Since Russia’s invasion in 2022, cyberattacks on Ukraine have continued to rise, surpassing 3,000 cases in the first half of this year — about 20 percent more than the same period last year. At the same time, the number of high-impact incidents has declined as Ukraine’s defenses improve. That progress has forced Russian hackers to abandon outdated tactics, automate more of their operations, and increasingly experiment with AI-generated malware. The agency warned that attackers are now using AI not only to write phishing messages but also to generate malicious code itself. Researchers believe AI tools were used to create PowerShell scripts in malware known as Wrecksteel, attributed to the cyberespionage group UAC-0219. “The use of artificial intelligence in cyberattacks has reached a new level,” CERT-UA said. “We have investigated several viruses showing clear signs of being generated with AI, and attackers will certainly not stop there.” ([Daryna Antoniuk / The Record](https://therecord.media/russian-hackers-turn-to-ai-ukraine-cert?ref=metacurity.com)) **Related:** [*CERT-UA*](https://docs.google.com/viewer?url=https://cip.gov.ua/services/cm/api/attachment/download?id=71278&embedded=true&a=bi&ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/ai-tapped-by-russian-hackers-to-counter-ukrainian-defenses?ref=metacurity.com) Get your message in front of thousands of cyber leaders and policy makers for little more than the cost of an annual Metacurity subscription. [Learn more! ](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) ### Germany has formally opposed the European Union’s proposed “Chat Control” regulation, a controversial measure that would require messaging platforms to scan private communications for illegal content, including child abuse material. The law, which would have applied to encrypted chats, has faced mounting criticism from privacy advocates, technologists, and human rights organizations. Jens Spahn of Germany’s Christian Democratic Union confirmed that Berlin would not support a policy that effectively mandates mass surveillance. He compared it to “opening all letters as a precautionary measure,” saying the measure crosses a fundamental privacy line. With Germany representing roughly 19 percent of the EU’s population, its stance almost guarantees the proposal’s failure under EU voting rules. Germany’s opposition adds crucial weight to a growing coalition that includes the Netherlands and Poland, forming what’s now likely a blocking majority. With votes from Italy and Sweden still pending, the EU faces a major privacy reckoning just days before the formal decision. ([Vlad Constantinescu / Bitdefender](https://www.bitdefender.com/en-us/blog/hotforsecurity/germany-halts-eus-chat-control-push-in-defense-of-digital-privacy?ref=metacurity.com)) **Related:** [*Deutschlandfunk*](https://www.deutschlandfunk.de/eu-staaten-erzielen-keine-einigung-102.html?ref=metacurity.com)*,* [*Federal Minister of Justice and Consumer Protection, Dr. Stefanie Hubig*](https://www.bmjv.de/SharedDocs/Zitate/DE/2025/1008%5FChatkontrolle.html?ref=metacurity.com)*,* [*EU Observer*](https://euobserver.com/rule-of-law/ar724b0c75?ref=metacurity.com)*,* [*Euractiv*](https://www.euractiv.com/news/chat-control-law-goes-back-to-negotiating-table-with-no-council-vote-in-sight/?ref=metacurity.com) ### Starting January 1st, 2026, anyone trying to make a new Apple Account must confirm if they are over 18, and any users under 18 must join a Family Sharing group. Parents and guardians will also be required to give their consent for users under 18 to download apps or to make in-app purchases. Developers will also have to make changes to comply with the law. Apple already offers a Declared Age Range API that developers can implement to ask users their general age, and the API “will be updated in the coming months to provide the required age categories for new account users in Texas,” Apple says. Apple is also launching new APIs “later this year” that “will enable developers, when they determine a significant change is made to their app, to invoke a system experience to allow the user to request that parental consent be re-obtained.” ([Jay Peters / The Verge](https://www.theverge.com/news/796760/apple-iphones-ios-app-store-age-verification-law-texas-utah-louisiana?ref=metacurity.com)) **Related:** [*TechCrunch*](https://techcrunch.com/2025/10/09/apple-prepares-to-comply-with-texas-age-assurance-law-but-warns-of-privacy-risks/?ref=metacurity.com)*,* [*Apple Developer*](https://developer.apple.com/news/?id=btkirlj8&ref=metacurity.com)*,* [*MacRumors*](https://www.macrumors.com/2025/10/08/app-store-changes-texas-age-verification/?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2025/10/08/apple-announces-new-requirements-for-apps-available-in-texas/?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/apple-shows-how-app-store-will-follow-age-verification-rules-in-texas?ref=metacurity.com)*,* [*Tom's Guide*](https://www.tomsguide.com/phones/iphones/texass-age-verification-law-means-apple-has-had-to-change-part-of-the-app-store-heres-what-that-means-for-you?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/apple-warns-of-privacy-risks-as-texas-age-verification-law-takes-effect/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/apple-users-in-texas-will-have-to-follow-these-new-app-requirements/?ref=metacurity.com)*,* [*MacTech.com*](https://www.mactech.com/2025/10/08/apple-makes-changes-to-the-app-store-to-comply-with-texas-app-store-accountability-act/?ref=metacurity.com)*,* [*Times of India*](https://timesofindia.indiatimes.com/technology/tech-news/apple-will-force-texas-teenagers-to-get-permission-before-downloading-any-app/articleshow/124396269.cms?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/big-tech/apple-explains-how-it-will-comply-with-app-store-age-verification-requirements-in-texas-185934469.html?ref=metacurity.com)*,* [*iClarified*](https://www.iclarified.com/98733/apple-to-require-age-verification-parental-consent-for-all-app-downloads-in-texas?ref=metacurity.com)*,* [*AppleInsider*](https://appleinsider.com/articles/25/10/08/developers-must-comply-with-new-texas-age-requirement-law-and-apple-has-detailed-how?ref=metacurity.com) ### Best Thing of the Day: Replacing CISA 2015 and Making It Retroactive Michigan Sen. Gary Peters, the ranking member of the Homeland Security and Governmental Affairs Committee, [introduced](https://cyberscoop.com/gary-peters-cyber-threat-information-sharing-law-rand-paul/?ref=metacurity.com) the Protecting America from Cyber Threats (PACT) Act to replace the expired Cybersecurity and Information Sharing Act of 2015 (CISA 2015), which will extend and rename the law and make it retroactive to cover the lapse that began Oct. 1. ### Worst Thing of the Day: Some Things Are Better Off Unrehabilitated Hollywood producer Bob Simmonds and a group of American investors are [pouring](https://www.globes.co.il/news/article.aspx?did=1001523543&ref=metacurity.com) tens of millions of dollars into an attempt to rehabilitate the controversial spyware company NSO Group. ### Bonus Worst Thing of the Day: Irony Is Not Dead Yet Dominion Voting Systems, the voting machine behemoth that President Trump and his allies baselessly attacked after the 2020 election, [has been sold](https://www.axios.com/2025/10/09/dominion-voting-machines-sold-elections?ref=metacurity.com) to a Missouri-based company called Liberty Vote, run by former Republican election official Scott Leiendecker. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/10/image-29.png) ### Hackers exposed government ID photos of 70,000 Discord users URL: https://www.metacurity.com/hackers-exposed-government-id-photos-of-70-000-discord-users/ Last updated: 2025-10-09T13:03:06.000Z DHS has forced cybersecurity pros to work on immigrant deportation, CA now requires browsers to honor data sharing opt outs, DragonForce, Qilin, and LockBit are in cahoots, FCC data incident reporting rules are destined for oblivion, Telstra denies Scattered Lapsus$ Hunters breach, much more _This post is for paying subscribers only._ ### ShinyHunters threatens to release data stolen from dozens of Fortune 500 firms URL: https://www.metacurity.com/shinyhunters-threatens-to-release-data-stolen-from-dozens-of-fortune-500-firms/ Last updated: 2025-10-08T12:03:58.000Z Salesforce refuses to pay ShinyHunters ransom, Qantas braces for the release of its data, Two teens busted for Kido nurseries cyberattack, Qilin claims attack on Asahi, Chinese hackers infiltrated Williams & Connolly, DPRK hackers have stolen $2b in crypto so far in 2025, much more _This post is for paying subscribers only._ ### ShinyHunters is extorting Red Hat, LAPSUS$ teen in UK custody may be connected URL: https://www.metacurity.com/shinyhunters-is-extorting-red-hat-lapsus-teen-in-uk-custody-may-be-connected/ Last updated: 2025-10-07T11:04:53.000Z Jaguar Land Rover to resume production at some sites, Apple faces French probe over Siri recordings, SEC probes AppLovin's data collection practices, Google's CodeMender is a security Swiss army knife, Prankster tells WSU students their degrees no longer count, much more _This post is for paying subscribers only._ ### "Scattered LAPSUS$ Hunters" claims theft of 1 billion Salesforce records URL: https://www.metacurity.com/scattered-lapsus-hunters-claims-theft-of-1-billion-salesforce-records/ Last updated: 2025-10-06T12:17:58.000Z Game engine developer Unity urges users to patch severe flaw, Hackers stole some Discord user data after a third-party compromise, US immigration dramatically expands its spying ability, Asahi reverts to pen and paper to process orders, Oz's NSW gov't reveals breach in homes program, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 9/27/25 URL: https://www.metacurity.com/next-long-read-4/ Last updated: 2025-10-04T11:44:27.000Z How the internet radicalizes young men, The real-life damage of porn deepfakes, The JLR attack damaged local communities, Amazon is pushing into the police tech market, Russian misinformation targeted a Canadian journalist _This post is for subscribers only._ ### Oracle confirms customer extortion emails, urges patch updates URL: https://www.metacurity.com/oracle-confirms-customer-extotion-emails/ Last updated: 2025-10-03T12:32:09.000Z Red Hat confirms security incident and begins remediation, Apple drops ICEBlock ICE tracking tool under pressure from DOJ, Japan to run out of Asahi beer after cyberattack, Air Force probes possible SharePoint breach, Israeli medical center targeted in suspected Iran attack on Yom Kippur, much more _This post is for paying subscribers only._ ### With cyber grants dead in Congress, states scramble to build their own defenses URL: https://www.metacurity.com/with-cyber-grants-dead-in-congress-states-scramble-to-build-their-own-defenses/ Last updated: 2025-10-02T13:00:15.000Z ![United States map](https://images.unsplash.com/photo-1515861209048-dae6a1e1ed56?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDh8fFVTJTIwc3RhdGUlMjBtYXB8ZW58MHx8fHwxNzU5NDA4ODUzfDA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Joey Csunyo](https://unsplash.com/@joey%5Fcsunyo?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) *As a reminder, on Tuesdays and Thursdays, the bulk of our daily newsletter is available exclusively to paid subscribers.* *Please consider upgrading your subscription so that you can enjoy Metacurity's original analysis and unparalleled cybersecurity news round-ups free of pesky firewalls. Plus, you will gain unfettered access to our archives and earn my undying appreciation for helping to keep Metacurity going. Thank you!* [Upgrade my subscription](#/portal/account/plans) *Want to bundle your premium subscription with a Metacurity sponsorship option? Gain exposure for your announcement, product, whitepaper, or event, and we'll toss in a paid subscription at no cost. Find out more about how you can reach an elite audience of cyber decision-makers.* [Sponsor Metacurity](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) --- One hope that died when Congress failed to pass spending bills, which then prompted the [federal government’s shutdown](https://www.csoonline.com/article/4066008/government-shutdown-deepens-us-cyber-risk-exposing-networks-to-threat-actors.html?ref=metacurity.com), was the reinstatement of $1 billion in state and local cyber grants created during the pandemic but killed earlier this year by the Trump administration. The House Homeland Security Committee [tried its best](https://therecord.media/house-homeland-committee-cyber-information-sharing-law?ref=metacurity.com) to include this funding in a statute extension early in September, but that extension died on September 30, as did [an extension of the Cybersecurity Information Sharing Act](https://www.csoonline.com/article/4065998/cisa-2015-cyber-threat-info-sharing-law-lapses-amid-government-shutdown.html?ref=metacurity.com), also known as CISA 2015. House Homeland Security Chairman Andrew Garbarino (R-NY) said in a statement before the imminent death of both legislative extensions: > If CISA 2015 and the State and Local Cybersecurity Grant Program expire, we would lose the capabilities of two critical tools that help mitigate evolving cyber threats by sophisticated adversaries. In both the short and long term, I am committed to finding the best path forward alongside my colleagues in the House and Senate to reauthorize and enhance these essential authorities. The death of the state and local grants followed a March White House [executive order](https://www.csoonline.com/article/3851885/trump-shifts-cyberattack-readiness-to-state-and-local-governments-in-wake-of-intel-sharing-cuts.html?ref=metacurity.com) that shifted the responsibilities of cyber emergency preparedness from the federal government to state and local jurisdictions. But the Trump administration failed to provide any additional funding for the increased duties, which cash-strapped state and local governments can scarcely afford. It's possible that in a few weeks, Chairman Garbarino might get his way and find a new vehicle to restore the cyber grants when the government re-opens. But, “States are not waiting around for that stuff,” Mike Hamilton, field CISO of Lumifi Cyber, former CISO of Seattle, and former vice-chair for the DHS State, Local, Tribal and Territorial Government Coordinating Council, tells Metacurity. _This post is for paying subscribers only._ ### Chinese hackers breached diplomats' email servers in a years-long campaign URL: https://www.metacurity.com/chinese-hackers-breached-diplomats-email-servers-in-a-years-long-campaign/ Last updated: 2025-10-01T13:39:12.000Z China sentences 11 people to death for gambling and Myanmar scam operations, DOJ settles with Georgia Tech over fake cyber assessment score, Google launches new ransomware protection, Microsoft launches a security store, BNB Chain X account hacked, Imgur blocked in UK, much more _This post is for paying subscribers only._ ### The UK is a European hotspot for cyberattacks URL: https://www.metacurity.com/the-uk-is-a-european-hotspot-for-cyberattacks/ Last updated: 2025-09-30T13:19:57.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/united-kingdom-2405963_1280-1.jpg) Image by [Dean Moriarty](https://pixabay.com/users/terimakasih0-624267/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=2405963) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=2405963) *As a reminder, on Tuesdays and Thursdays, the bulk of our daily newsletter is available exclusively to paid subscribers.* *Please consider upgrading your subscription so that you can enjoy Metacurity's original analysis and unparalleled cybersecurity news round-ups free of pesky firewalls. Plus, you will gain unfettered access to our archives and earn my undying appreciation for helping to keep Metacurity going. Thank you!* [Upgrade my subscription](#/portal/account/plans) *Want to bundle your premium subscription with a Metacurity sponsorship option? Gain exposure for your announcement, product, whitepaper, or event, and we'll toss in a paid subscription at no cost. Find out more about how you can reach an elite audience of cyber decision-makers.* [Sponsor Metacurity](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) --- Over the past five months, the UK has been the locus for many high-profile and damaging cyber incidents, culminating in this week’s unprecedented – and controversial – [decision](https://www.gov.uk/government/news/government-backs-jaguar-land-rover-with-15-billion-loan-guarantee?ref=metacurity.com) by the UK government to back ransomware-ravaged Jaguar Land Rover (JLR) with a loan guarantee expected to provide £1.5 billion to support its supply chain. A recent string of ransomware attacks, most [attributed](https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/?ref=metacurity.com) to young, native-English speaking hackers known by various names, including The Com, Scattered Spider, and Shiny Hunters, has been inflicted on British institutions [following a year](https://www.theguardian.com/business/2025/jun/30/uk-businesses-hit-by-cyber-attack-last-year-report?ref=metacurity.com) in which more than one in four UK businesses had already been hit by a cyberattack. Among some of the big-name British institutions that have been hit with serious cyber incidents this year are: **\--Marks and Spencer:** In April, the famed retailer M&S was hit with a cyber attack that left [it unable to process orders](https://www.theregister.com/2025/06/10/ms%5Fresumes%5Fonline%5Forders%5F46/?ref=metacurity.com) for months, ultimately costing the company [an estimated £300 million](bbc.co.uk/news/articles/c93llkg4n51o). \--**Harrods:** On May 1, the luxury department store [said](https://www.bbc.com/news/articles/c62x4zxe418o?ref=metacurity.com) it had been hit by a cyberattack that forced it to restrict access to its websites but left its store operations essentially unchanged. This week, Harrods [blamed](https://www.computing.co.uk/news/2025/security/harrods-blames-supplier-for-second-cyberattack-of-2025?ref=metacurity.com) a supplier for its second cyberattack of 2025, which saw the data theft of information relating to around 430,000 customers. **\--The Co-operative Group:** In April, supermarket chain The Co-operative Group [fell victim](https://www.bbc.com/news/articles/cwy382w9eglo?ref=metacurity.com) to a cyberattack that left its shelves bare and allowed cybercriminals to steal its members' data. Last week, The Co-Op said the incident has thus far [cost it](https://therecord.media/retailer-the-co-op-cyberattack-lost-revenue?ref=metacurity.com) £206 million. \--**H&M**: In early June, fashion retailer H&M [experienced major disruptions](https://www.theindustry.fashion/hm-hit-by-payment-system-failures-as-retail-cyber-risks-mount/?ref=metacurity.com) across its UK store network with a failure in its payment systems that left customers unable to complete their purchases for several hours. Although H&M never confirmed the incident as a cyberattack, threat actors were subsequently selling 4 million H&M records on the dark web. \--**Heathrow Airport:** On September 19, [an attack](https://www.ncsc.gov.uk/news/collins-aerospace-incident?ref=metacurity.com) on the baggage and check-in software provider Collins Aerospace grounded London’s Heathrow Airport and other European airports to a halt for several days. Six days ago, police [arrested](https://www.bbc.com/news/articles/c62ldxyj431o?ref=metacurity.com) a man in his 40s in connection with the incident. \--**Jaguar Land Rover:** On August 31,Jaguar Land Rover was hit with a cyberattack that forced it to immediately shut down production at its three UK facilities in the West Midlands and Merseyside, work that only [partially resumed](https://www.bbc.com/news/articles/cwydxpdgx61o?ref=metacurity.com) this week after threatening the employment of 30,000 workers directly employed by the company and 100,000 workers employed by the company’s suppliers. The UK government’s decision to lend £1.5 billion to rescue Jaguar Land Rover is something of a philosophical sea change, given that the UK government has [firmly stated](https://www.theguardian.com/technology/2025/jul/22/uk-government-to-ban-public-bodies-from-paying-ransoms-to-hackers?ref=metacurity.com) that it was unwilling to pay ransoms on any government entity, including the National Health Service, lest it reward cybercriminals and encourage more attacks. _This post is for paying subscribers only._ ### UK government bails out Jaguar Land Rover with $2 billion loan URL: https://www.metacurity.com/uk-government-bails-out-jaguar-land-rover-with-2-billion-loan/ Last updated: 2025-09-29T12:55:07.000Z Hackers contacted Harrods after 430K customer records were stolen, Hackers threaten to release more Kido nursery school records, Russia's undersea spying ops become more brazen, Unitree robots afflicted by severe flaw, Akira attacks on SonicWall VPNs evolve, RemoteCom spyware data leaked, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 9/20/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-9-13-25-2/ Last updated: 2025-09-27T12:26:29.000Z How an NYT reporter almost fell for a scam, Hackers increasingly take aim at small-town water systems, Citizens must shift their threat models under Trump's regime, Even the most innocent AI model can spew out dark material, Building a pipeline for scraping CTI content from Telegram _This post is for subscribers only._ ### CISA orders agencies to fix Cisco firewall zero day flaws by noon today URL: https://www.metacurity.com/cisa-orders-agencies-to-fix-cisco-firewall-zero-day-flaws-by-noon-today/ Last updated: 2025-09-27T09:55:02.000Z Microsoft terminates Israeli military access to surveillance system, Senate report documents DOGE's marauding ways, Dutch cops bust two teens for wi-fi sniffing, Hackers stole pics and info on 8,000 nursery school kids, Edge device-focused threat group RedNovember is aligned with China, much more _This post is for paying subscribers only._ ### Secret Service faces backlash over SIM farm bust as experts challenge threat claims URL: https://www.metacurity.com/secret-service-faces-backlash-over-sim-farm-bust-as-experts-challenge-threat-claims/ Last updated: 2025-09-25T11:44:15.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/secretservice-1.png) Image source. US Secret Service. --- As a reminder, on Tuesdays and Thursdays, the bulk of our daily newsletter is available exclusively to paid subscribers. Please consider upgrading your subscription so that you can enjoy Metacurity's original analysis and unparalleled cybersecurity news round-ups free of pesky firewalls. Plus, you will gain unfettered access to our archives and earn my undying appreciation for helping to keep Metacurity going. Thank you! [Upgrade my subscription](#/portal/account/plans) Want to bundle your premium subscription with a Metacurity sponsorship option? Gain exposure for your announcement, product, whitepaper, or event, and we'll toss in a paid subscription at no cost. Find out more about how you can reach an elite audience of cyber decision-makers. [Sponsor Metacurity](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity/) --- Early in the morning on September 23, the US Secret Service (USSS) [announced](https://www.secretservice.gov/newsroom/releases/2025/09/us-secret-service-dismantles-imminent-telecommunications-threat-new-york?ref=metacurity.com) it had “dismantled a network of electronic devices located throughout the New York tristate area" that “were used to conduct multiple telecommunications-related threats directed towards senior US government officials, which represented an imminent threat to the agency’s protective operations.” The USSS said it had found more than 300 co-located SIM servers and 100,000 SIM cards across multiple sites within 35 miles of the global meeting of the United Nations General Assembly in New York City. Matt McCool, the special agent in charge of the New York Field office, said that even though the USSS had been investigating the setup since the spring, “the timing, location, and potential for significant disruption to New York telecommunications" forced the agency to disrupt the network quickly. “This network had the potential to disable cellphone towers and essentially shut down the cellular network,” McCool said. In its announcement, the agency said the tech cluster it found could have disabled cell phone towers across New York, New Jersey, and Connecticut, enabling denial of services attacks and facilitating anonymous, encrypted communication among potential threat actors and criminal enterprises. The USSS also raised the specter of a nation-state threat actor using the technology, saying in its press release that “early analysis indicates cellular communications between nation-state threat actors and individuals that are known to federal law enforcement.” Some [press reports](https://www.nytimes.com/2025/09/23/us/politics/secret-service-sim-cards-servers-un.html?smid=nytcore-ios-share&referringSource=articleShare&ref=metacurity.com) repeated the notion that nation-state adversaries could have been behind the setup. Adding to the urgency was the apparent fact that the facility came onto the Secret Service’s radar screen after the gear was exploited in [swatting attacks](https://www.cnn.com/2025/09/23/us/swatting-investigation-server-network-discovered?ref=metacurity.com) that targeted US members of Congress. However, within hours of the announcement, the story told by the USSS unraveled as experts cast doubt on the nature of what the agency found. On Ycombinator’s [Hacker News](https://news.ycombinator.com/item?id=45345514&ref=metacurity.com), posters began characterizing the setup as merely a [SIM farm](https://www.gov.uk/government/news/major-step-for-fraud-prevention-with-landmark-ban-on-sim-farms?ref=metacurity.com#:~:text=SIM%20farms%20are%20technical%20devices,victim%20to%20major%20financial%20losses.), akin to many others deployed by scammers throughout the world to defraud the public with phishing texts and emails. They accused the Secret Service of significantly overstating what it found. One poster named wildzzz wrote > Oh lol, this is a scam site. Yes, there are potential other uses for a sim box but mostly they are used for VoIP purposes. It's honestly so hard reading quotes from the US government these days. Cartels, drugs, guns. They make it sound like they interrupted the staging of an assault on the UN when the article actually says that the locations were within 35 miles of the UN headquarters in NYC. This is a significant distance as it covers beyond the 5 boroughs, it's the "tri state area". Like 20M people live in that circle. I highly doubt this is for anything other than VoIP scams. Another poster, kotaKat, wrote > Yup. This is literally just a cellular grey route site for some shitty VoIP provider, just like the SIM box SMS scams go marching on in other countries. Some operator is shitting their pants right now, probably. > The SIM cards come from cheap MVNOs that have dealer arrangements for cheap or free first month activations, then they just set up a handful of SIM boxes and a residential Internet connection back to the mothership (like they did at the captured house with the white Verizon 5G Home router just casually sitting on the floor next to the units). > Similarly, I’ve had some friends on US MVNOs themselves that have access to “free” international calling, yet every time they call (the same) international number the receiving party gets a wildly different caller ID from a wildly different country each time (Poland, Moldova, etc). Also dodgy SIM boxes! As the day wore on, security professional TProphet, who writes the Telecom Informer for the highly regarded security publication 2600, [posted a thread](https://bsky.app/profile/tprophet.org/post/3lzjlmomhas2f?ref=metacurity.com) on BlueSky saying that “there is nothing about this infrastructure that would be hugely disruptive or damaging to mobile phone networks in New York. This is a densely populated area with thousands of cell sites.” _This post is for paying subscribers only._ ### UK cops bust man allegedly linked to Collins Aerospace attack URL: https://www.metacurity.com/uk-cops-bust-man-allegedly-linked-to-collins-aerospace-attack/ Last updated: 2025-09-24T13:14:13.000Z Hackers breached US agency via unpatched GeoServer, GitHub implements new defenses after supply chain attacks, Boyd casino operator hit by cyberattack, Inc claims PA Atty General attack, UK used AI to find £500m in fraud, Cloudflare stopped 22.2 Tbps attack, much more _This post is for paying subscribers only._ ### Korea is an Asian hotspot for cyberattacks URL: https://www.metacurity.com/korea-is-an-asian-hotspot-for-cyberattacks/ Last updated: 2025-09-23T21:39:20.000Z ![aerial photography of lighted city high rise buildings during dawn](https://images.unsplash.com/photo-1506816561089-5cc37b3aa9b0?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDE4fHxTb3V0aCUyMEtvcmVhfGVufDB8fHx8MTc1ODYyNjI4Mnww&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Mathew Schwartz](https://unsplash.com/@cadop?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) --- **Correction:* The original summary of a Secret Service take-down of cell phone equipment that made up a SIM farm was rewritten to remove the suggestion that it was capable of knocking out cell services in New York City. Look for further clarification in tomorrow's Metacurity.* --- *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](https://www.metacurity.com/european-airports-are-still-suffering-from-weekend-attack-on-third-party-system/#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](https://www.metacurity.com/european-airports-are-still-suffering-from-weekend-attack-on-third-party-system/#/portal/support) --- When stacked up against the biggest nations on the planet, South Korea is a small country, with a land area roughly the size of the US state of Indiana or the country of Hungary, with a population of around 50 million, ranking it 29th globally in terms of population. But it has the world’s 13th largest economy in terms of GDP – and the fourth largest in Asia – and is a technological innovator with a lot of economic prowess. Korea’s disproportionate power could be the reason that over the last year, it has also emerged as a prime target for cybercriminals and a canary in the coal mine for significant cybercrime activity, particularly attacks against luxury brands. Excluding the ongoing espionage infiltrations by its contiguous adversary, North Korea, South Korea has experienced a string of damaging cyber incidents this year, including - **Breach of 20 private equity funds:** Yesterday, sources [reported](https://tripuratimes.com/ttimes/hackers-leak-data-from-20-private-equity-funds-in-s-korea-31613.html?ref=metacurity.com) that Russia’s Qilin gang breached data from 20 asset management firms in South Korea in a hacking incident that involved an IT subcontractor. - **SK Telecom hack:** In April, one of the country’s leading telcos, SK Telecom, [revealed](https://www.chosun.com/english/industry-en/2025/05/22/6OSKXZLRSRCYLF7WESVLZCEDAM/?ref=metacurity.com) that hackers had infiltrated its system and had been inside corporate networks for three years, targeting the USIM or Universal Subscriber Identity Module, for 27 million customers. Korean authorities announced in July [that they would impose](https://www.reuters.com/sustainability/boards-policy-regulation/south-korea-orders-sk-telecom-strengthen-data-security-after-leak-2025-07-04/?ref=metacurity.com) a fine of up to 30 million won ($21,970) and enforce a series of security measures against the telco. - **KT Telecom hacks**: Last week, another Korean telco, KT, [announced](https://koreajoongangdaily.joins.com/news/2025-09-19/business/industry/KT-confirms-another-hack-mere-weeks-after-micropayment-scam/2403128?ref=metacurity.com) it had experienced a significant breach, an incident that followed a cyberattack earlier this month that [compromised](https://andopen.co.kr/kt-telecom-hack-explained-how-it-happened-and-whats-next/?ref=metacurity.com) 278 customers‘ mobile payment systems, resulting in ₩170 million ($122,400) in unauthorized transactions, or what the Korean press has called micropayment frauds. Today, [news broke](https://www.chosun.com/english/industry-en/2025/09/23/7OHNRSSOBNBJXFH3E6Q5CCZQJ4/?ref=metacurity.com) that the hacker behind the mobile phone hacks is likely part of a Chinese cybercriminal gang. - **Lotte Card hacks**: Last week, Korean credit card company Lotte Card [announced](https://www.mk.co.kr/en/economy/11423068?ref=metacurity.com) that a series of hacks resulted in the theft of three million members' credit card and personal information. _This post is for paying subscribers only._ ### European airports are still suffering from a weekend attack on third-party system URL: https://www.metacurity.com/european-airports-are-still-suffering-from-weekend-attack-on-third-party-system/ Last updated: 2025-09-23T13:08:50.000Z Jaguar Land Rover still incapacitated three weeks after ransomware attack, Chrysler parent company hit by third-party hack, Everest group claims attack on BMW Group, Vegas cops bust teen suspected of casino hacks, Crypto.com denies suppressing hack news, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 9/13/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-9-13-25/ Last updated: 2025-09-20T13:51:17.000Z Scattered Spider's Urban speaks, EU nations subsidize spyware makers, AI chatbots fool senior citizens with phishing, Scam compounds endanger job seekers and tourists, Meat and dairy companies spy on activists, Texas wants in on Chihuahua's massive surveillance, Cyber outsourcing threatens the UK _This post is for subscribers only._ ### Two Scattered Spider members busted in the UK, one indicted in the US URL: https://www.metacurity.com/two-scattered-spider-members-busted-in-the-uk-one-indicted-in-the-us/ Last updated: 2025-09-19T13:24:43.000Z MI6 launches dark web portal for potential spy comms, KT hit by another breach, Korean authorities vow sweeping response to hacking spree, ICE signs contract with Graykey phone hacking device maker, ChatGPT flaw that enabled Gmail extraction fixed, $2m theft roils BNB Chain DeFi scene, much more _This post is for paying subscribers only._ ### A banner week for Scattered Spider/Lapsus$/ShinyHunters and maybe The Com URL: https://www.metacurity.com/a-banner-week-for-scattered-spider-lapsus-shinyhunters-and-maybe-the-com/ Last updated: 2025-09-18T11:52:26.000Z ![a man wearing a black mask and a black jacket](https://images.unsplash.com/photo-1634120152890-ae333be57003?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDEyMHx8cmFuc29td2FyZXxlbnwwfHx8fDE3NTgxODgyNDZ8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Diane Picchiottino](https://unsplash.com/@diane%5Fsoko?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) --- People outside the cybersecurity industry, and even infosec professionals, can be forgiven if they confuse several groups of loosely organized, young, native English-speaking, primarily financially motivated hacking groups for one another. These groups go by various names, including Scattered Spider, Lapsus$, ShinyHunters, and The Com. The first three of these groups are so closely aligned, if not in organization, then in demographics, spirit, and motivations, that in August, they [launched](https://databreaches.net/2025/08/09/scattered-spider-has-a-new-telegram-channel-to-list-its-attacks/?ref=metacurity.com) a joint "Scattered LAPSUS$ Hunters" Telegram channel to indicate they are either working together or that their hacker ranks overlap. The Com, however, is an amorphous group, also composed of native English-speaking hackers, that Unit221B’s chief research officer, Allison Nixon, [stresses](https://www.youtube.com/watch?v=TydZRumQUj8&ab%5Fchannel=SLEUTHCON&ref=metacurity.com) is a malicious teen “culture” distinct from Scattered Spider and rooted more in publicity seeking rather than financial gain. However, Scattered Spider and The Com recently both seemingly took credit for the same significant breach (more on that below), so the boundaries between those two entities may be permeable. In any case, the Scattered Spider/ShinyHunters hackers have been on a financial extortion spree this year, creating havoc with [attacks on retail giants](https://www.csoonline.com/article/3994369/how-cisos-can-defend-against-scattered-spider-ransomware-attacks.html?ref=metacurity.com) in the UK, luxury brands [including](https://www.chosun.com/english/industry-en/2025/05/26/ORM5MULB7NEM7EBUFVXHVLSB4A/?ref=metacurity.com) Tiffany and Co, Louis Vuitton, and [Dior](https://www.chosun.com/english/industry-en/2025/05/26/ORM5MULB7NEM7EBUFVXHVLSB4A/?ref=metacurity.com), [the aviation sector,](https://www.kelacyber.com/blog/scattered-spider-aviation-industry-attacks/?ref=metacurity.com) and [high-profile Salesforce clients](https://cloudprotection.withsecure.com/blog/salesforce-attacks-in-2025/?ref=metacurity.com#:~:text=Google:%20Salesforce%20CRM%20breach%20targeting,appears%20%E2%80%9Cnon%2Dsensitive%E2%80%9D.), among other targets. But this past week, they reached a little-noticed high-water mark for the sheer number of cybersecurity news items linked to them, including: - An [attack on Vietnam’s National Credit Information Center](https://www.resecurity.com/blog/article/shinyhunters-attacked-vietnams-financial-system-cic-data-leak?ref=metacurity.com) (CIC). - An [attack on Kering SA,](https://www.bloomberg.com/news/articles/2025-09-15/gucci-owner-kering-says-it-was-hacked-limited-data-accessed?ref=metacurity.com) whose luxury brands include Gucci, Saint Laurent, Balenciaga, and others. - An attack on [Jaguar Land Rover,](https://www.theguardian.com/business/2025/sep/16/jaguar-land-rover-production-shutdown-cyber-attack?ref=metacurity.com) which has thrown the automaker into an extended shutdown. - Google’s [public acknowledgment](https://www.bleepingcomputer.com/news/security/google-confirms-fraudulent-account-created-in-law-enforcement-portal/?ref=metacurity.com) that hackers breached its Law Enforcement Request System (LERS) platform. - A [breach of Korea’s SK Telecom](https://www.chosun.com/english/industry-en/2025/09/16/H6FGTVALUJHMHOT7U24FE6NJ7A/?ref=metacurity.com), which the telco has denied. - A class action lawsuit brought by victims of the [Coinbase breach](https://www.csoonline.com/article/4042522/behind-the-coinbase-breach-bribery-is-an-emerging-enterprise-threat.html?ref=metacurity.com) was brought against the cryptocurrency’s outsourced helpdesk firm, TaskUS, which alleged that at least one employee was involved in a $500k bribery scheme, for which both The Com and Scattered Spider have taken credit. Despite the magnitude of that breach, which was not a ransomware attack but an extortion scheme against Coinbase to halt the release of data on around 70,000 of its highest-paying customers, and is expected to cost the company around $400 million, only a few journalists have reported on the threat actors who might be behind the bribes. _This post is for paying subscribers only._ ### A self-replicating worm has infected 187 npm packages URL: https://www.metacurity.com/a-self-replicating-worm-has-infected-187-npm-packages/ Last updated: 2025-09-17T13:49:41.000Z BreachForums founder hit with new three-year sentence, Coinbase breach suspect accused of participating in $500k+ bribery scheme, DHS intelligence arm exposed sensitive database, MSFT seized 338 sites linked to Raccoon0365 stealer, DeepSeek is biased against Falun Gong and others, much more _This post is for paying subscribers only._ ### AI cyber risks are more evolutionary than revolutionary, experts URL: https://www.metacurity.com/ai-cyber-risks-are-more-evolutionary-than-revolutionary-experts/ Last updated: 2025-09-16T21:43:08.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/computer-7718732_1280-1.jpg) Image by [Alexandra\_Koch](https://pixabay.com/users/alexandra%5Fkoch-621802/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=7718732) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=7718732) *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) Last week at the Billington Cybersecurity Summit in Washington, DC, a panel of experts spoke to a standing-room-only crowd eager to hear about the new cybersecurity threats introduced by AI, a testament to how the heated news cycles surrounding this latest technology revolution are driving fears of new forms of threat actor attacks. However, some experts counter that while existing and a proliferating number of new cyber adversaries are using AI to advance their phishing skills and create new malware, AI technology isn’t necessarily injecting new cybersecurity threats that LLMs can’t catch and correct, or at least not to the level of concern often hyped in the media. Among the types of attacks that are possible now that were not feasible before are new forms of content creation, Chad Skipper, global security technologist at Cisco, told the attendees. “This is about using AI to create content that is more believable for us as susceptible end users to click on,” he said. “Think of phishing campaigns, think of deepfakes, those types of things. Another one is enhancing malware development. ‘Hey, look, I have it in this program. I want you to convert it into this other program that's not detectable by said security devices.’ And then the third is automating the scale of attack. Those are the three main areas that we're dealing with today.” Alexandra Seymour, staff director of the Subcommittee on Cybersecurity and Infrastructure Protection in the US House of Representatives, said, “A lot of these different types of attacks that we are seeing have already existed, but they are now improved. And I think one of the things we are seeing now is the access, that more threat actors are more easily able to execute these attacks, where they have access to generative AI models, where they can create those more convincing phishing attacks, where they can launch any of their attacks at scale.” The ability to generate fake content is among the top security threats posed by AI, according to Chad Tetreault, field CTO, federal at Zscaler. He said, “If you look just recently at the North Korean efforts around simulating people that are working here, not necessarily for espionage but actually to bring money back into North Korea via this very interesting funnel, those identities were flawless from AI, from creating the LinkedIn profiles, to AI writing the resumes to AI doing face masking.” Bobby Scharmann, cyber accelerator director at Leidos, underscored the vast improvements that AI has made in the ability of malicious actors to generate convincing emails. “In some cases, you can have better-targeted, more personal phishing attacks than you would if you had a human spending the entirety of the day,” he said. Finally, Ryan Palmer, senior technical and strategic advisor at the General Services Administration, pointed to the fact that AI-based solutions embraced by cyber defenders are a counterpoint to all the AI adversarial action. “Using AI and actually helping build your unit test, and evaluate security, look at some of the content, \[can help AI\] be a tool to help mitigate some of these things,” he said. After the panel, moderator Chris Wysopal, CTO of Veracode, told Metacurity that when it comes to code development, LLMs are lousy with vulnerabilities ingested from code repositories and other sources on the web, most notably Reddit and Wikipedia. “It's crazy that it's learning from Reddit,” he said. “Reddit is the biggest source of information that the LLMS are trained on. It's even bigger than Wikipedia. Wikipedia is number two.” _This post is for paying subscribers only._ ### DPRK's Kimsuky forged a deepfake military ID using ChatGPT for S. Korean attack URL: https://www.metacurity.com/dprks-kimsuky-created-deepfake-military-id-using-chatgpt-in-s-korean-attack/ Last updated: 2025-09-15T12:34:07.000Z Vastaamo hacker who released psychotherapy center records is set free, FBI issues warning of UNC6040 and UNC6395 targeting Salesforce users, Shiba Inu stopped damage from attack, DC AG charges Athena ATM operator for ignoring elderly scams, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 9/6/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-9-6-25/ Last updated: 2025-09-13T15:31:23.000Z Myanmar's junta benefits from cyberscams, Cyberscams could be behind the Thai-Cambodia conflict, Africans are tricked into cyberscam compounds, How China's propaganda and surveillance work, Vibe coding is risky, Ross Ulbricht is very lucky, Don't steal the phone of a hacker's girlfriend _This post is for subscribers only._ ### Apple sent a new round of spyware notifications to affected users URL: https://www.metacurity.com/apple-sent-a-new-round-of-spyware-notifications-to-affected-users/ Last updated: 2025-09-12T13:10:00.000Z Akira is exploiting critical flaw in SonicWall, Vietnamese government warns of National Credit Information Center hack, UK ICO warns that kids are hacking their schools, Opposition to EU Chat Control scanning of encrypted messages grows, New infostealer dubbed ModStealer stays invisible, much more _This post is for paying subscribers only._ ### DOGE killed $324 million in grants for cybersecurity diversity, global partners URL: https://www.metacurity.com/doge-killed-324-million-in-grants-for-cybersecurity-diversity-global-partners/ Last updated: 2025-09-11T12:58:39.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/dogegrantexcerptformetacurity-1.png) Source: DOGE.gov *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can!](#/portal/support) --- Consistent with the nature of US government budget cuts across the Trump administration generally, according to DOGE.gov, DOGE workers slashed hundreds of millions of cybersecurity-related grants aimed at helping underrepresented cybersecurity workers or aiding under-resourced US allies. As the table below spells out, from February through May, DOGE eliminated cybersecurity-related grants (i.e., grants that specifically reference cybersecurity) worth $325 million, with listed potential "savings" to the US government of $253 million. However, it’s unclear exactly how DOGE calculated the savings figures. A number of the canceled grants came from [the elimination](https://www.naco.org/news/ntia-terminates-digital-equity-act-grants?ref=metacurity.com) of Digital Equity Act grants issued by the Department of Commerce’s National Telecommunications and Information Administration. These grants were designed to address “a lack of infrastructure in rural or urban communities, making affordable connectivity devices more accessible to individuals in need due to income or background, and establishing digital literacy and training resources of existing and emerging consumer technologies.” Another group of cybersecurity grants cancelled by DOGE is part of [the sweeping cancellation](https://www.usatoday.com/story/news/politics/2025/04/26/national-science-foundation-doge-cuts/83282784007/?ref=metacurity.com) of approximately 700 scientific research projects funded through the National Science Foundation. Not all the diversity-related grants canceled focused on gender, racial, or ethnic equity. Some of the canceled grants focused on assisting older Americans in coping with the rising tide of cyber scams. For example, one canceled $5,000,000 grant issued to the State University of New York at Buffalo was for a program to equip older adults with tools to recognize online deception and awareness. Finally, another cluster of canceled grants was a string of small-dollar State Department initiatives to help international allies in their efforts to develop cyber defenses. For example, DOGE cut a $35,000 grant to the Pacific Links Foundation to train Vietnamese educators and youth on cutting-edge technical topics, including cybersecurity, AI, data privacy breaches, and fintech. _This post is for paying subscribers only._ ### US indicts ransomware dev, offers $10 million reward, puts him on most-wanted list URL: https://www.metacurity.com/us-indicts-ransomware-dev-offers-10-million-reward-puts-him-on-most-wanted-list/ Last updated: 2025-09-10T13:30:00.000Z US tech giants enable human rights abuse in China, BlackDB.cc operator pleads guilty, Microsoft issues 80 Patch Tuesday fixes, Pakistan has built sweeping surveillance system, Apple targets spyware with Memory Integrity Enforcement, Korean telco KT on hot seat for 278 mobile fraud cases, much more _This post is for paying subscribers only._ ### DOGE has slashed government cyber contracts by $2.2 billion so far URL: https://www.metacurity.com/doge-has-slashed-government-cyber-contracts-by-2-2-billion-so-far/ Last updated: 2025-09-10T10:28:08.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/DOGEimageforghost-3.png) Source: Metacurity analysis of DOGE data. ### Metacurity needs your help! Metacurity has been a labor of love for years, and I’m so grateful for your readership. Your support can help ensure I can continue delivering the carefully curated weekly long-reads and daily digests of the most critical developments in cybersecurity. If you find value in what Metacurity offers, please consider upgrading to a paid subscription. We also provide corporate subscription options, and soon we’ll be introducing affordable sponsorship opportunities—perfect for promoting your events or products to a highly engaged audience. To learn more, feel free to reach out at cynthia@metacurity.com. Thank you so much for being part of the Metacurity community. [Upgrade my subscription!](https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/#/portal/account/plans) If you can't commit to a subscription, please consider donating what you can afford to help keep Metacurity free to all. [Donate What You Can](https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/#/portal/support) --- Although the public furor and press coverage of the government spending cuts made by the Elon Musk-founded Department of Government Efficiency have died down, DOGE workers themselves have not stopped slashing budgets, ending contracts, and eliminating government grants. If anything, according to data published by DOGE on DOGE.gov, DOGE has accelerated its efforts to get rid of government contracts since May, claiming to have canceled $43.4 billion in government contracts in June and nearly $27 billion in contracts in July. Even August was a brisk month when DOGE workers claim they canceled almost $9 billion in contracts. A good portion of the canceled contracts for which DOGE takes credit were for cybersecurity services. Since January 2025, DOGE says it has eliminated around $2.2 billion in contract cyber spending across 22 different government agencies. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/totalcontractscancelledbyDOGE.png) As a caveat, DOGE isn’t always clear about what constitutes the value of contracts cancelled or how much savings the government will earn. In many cases, DOGE overstates the theoretical contract value of savings by including the uppermost spending ceilings that are never reached, a feature in some major contracts that allows for continuing service without the hassle of getting new contract approvals. (As another caveat, it's possible that DOGE has eliminated far more cybersecurity-related contracts than the ones we have listed in the table below. The contracts we identified clearly used the word cybersecurity, but other contract descriptions that didn't use this word might also be primarily cybersecurity-related.) Further compounding DOGE’s lack of clarity on its numbers is the so-called government agency’s statement that its work has saved taxpayers $205 billion. However, this figure, according to DOGE.gov, includes an expansive combination of “asset sales, contract/lease cancellations and renegotiations, fraud and improper payment deletion, grant cancellations, interest savings, programmatic changes, regulatory savings, and workforce reductions. As can be seen in the table below, which contains the individual cybersecurity-related contracts canceled or otherwise curtailed by DOGE since January, over half of the $2 billion cyber contract spending reduction came from one contract. This contract was issued by the Department of Defense to Mantech Advanced Systems International for “COMPUTER SYSTEMS DESIGN SERVICES: INTELLIGENCE AND CYBER OPERATIONS NETWORK,” and is considered a “funding only action,” meaning that DOGE didn’t cancel the contract. Instead, it reduced the dollar amount by $1.4 billion. Mantech is a top defense, intelligence, and federal civilian cybersecurity contractor. _This post is for paying subscribers only._ ### Chinese espionage campaign targeted House staffers ahead of trade talks URL: https://www.metacurity.com/chinese-espionage-campaign-targeted-house-staffers-ahead-of-trade-talks/ Last updated: 2025-09-08T13:16:55.000Z Ethical hackers uncover catastrophic flaws in restaurant chain's platforms, Salesloft Drift hack began last March, Customer data stolen in Wealthsimple breach, Trump to formally nominate Harman for NSA/Cybercom slot, Don't trust XChat's encryption, Czech Republic warns of Chinese tech, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 8/16/25, 8/23/25, and 8/30/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-8-16-25-8-23-25-and-8-30-25/ Last updated: 2025-09-06T11:56:56.000Z Russian cybersecurity companies are tools for global expansion, Merrick Garland's fears of a judicial system cyberattack came true, Flock has plans for ubiquitous surveillance to stop crime, Misinformation from adversaries now runs rampant with no US pushback, AI can't capture personality, more _This post is for subscribers only._ ### Anthropic blocks Chinese firms citing national security URL: https://www.metacurity.com/anthropic-blocks-chinese-firms-citing-national-security/ Last updated: 2025-09-05T13:52:23.000Z Texas AG sues PowerSchool over breach, Qantas CEO takes a pay hit over breach, Orleans Parish Sheriff's Office hit by ransomware, Bridgestone confirms cyberattack, Cloudflare blocked 11.5 Tbps DDoS attack, Threat actors bypass Grok's restrictions, much more _This post is for paying subscribers only._ ### China-aligned hackers hijack servers to game Google rankings URL: https://www.metacurity.com/china-aligned-hackers-hijack-servers-to-game-google-rankings/ Last updated: 2025-09-04T11:44:59.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/ghostredirector-1.png) GhostRedirector attack chain. Source: ESET. **Please consider supporting Metacurity** Metacurity has been a labor of love for years, and I’m so grateful for your readership. Your support can help ensure I can continue delivering the carefully curated weekly long-reads and daily digests of the most critical developments in cybersecurity. If you find value in what Metacurity offers, please consider upgrading to a paid subscription. We also provide corporate subscription options, and soon we’ll be introducing affordable sponsorship opportunities—perfect for promoting your events or products to a highly engaged audience. To learn more, feel free to reach out at cynthia@metacurity.com. Thank you so much for being part of the Metacurity community. [Upgrade my subscription!](https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/#/portal/account/plans) If you can't commit to a subscription, please consider donating what you can afford to help keep Metacurity free to all. [Donate What You Can](https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/#/portal/support) --- Researchers at ESET [identified](https://www.welivesecurity.com/en/eset-research/ghostredirector-poisons-windows-servers-backdoors-side-potatoes/?ref=metacurity.com) a new China-aligned threat actor they call GhostRedirector that is targeting Windows servers mainly in Brazil, Thailand, and Vietnam with a passive C++ backdoor and a malicious Internet Information Services (IIS) that manipulates Google search results in an SEO manipulation scheme. GhostRedirector uses two previously undocumented, custom tools: a passive C++ backdoor that ESET calls Rungan, and an IIS module that it calls Gamshen. While Rungan has the capability of executing commands on a compromised server, Gamshen appears to provide SEO fraud as-a-service to manipulate search engine results by modifying responses to Googlebots visiting the sites to boost the page ranking of targeted sites, which ESET discovered were 65 gaming sites. GhostRedirector also uses a series of other custom tools, as well as the publicly known exploits EfsPotato and BadPotato, to create a privileged user on the server that can be used to download and execute other malicious components with higher privileges, or used as a fallback in case the Rungan backdoor or other malicious tools are removed from the compromised server. “The malware delivers different information to the Googlebot than it should be,” Tony Anscombe, Chief Security Evangelist at ESET, told Metacurity. “It controls what that server is then sending back to the Googlebot. It promotes certain other sites. In effect, it hijacks that server's reputation with the Googlebot and then feeds it inaccurate information that elevates your content or the content that's on another server.” One interesting angle on GhostRedirector is that some of the infected servers targeting Brazil, Thailand, and Vietnam were in the US. The organizations in those targeted countries essentially rented server space in the US. “If you look at those servers, they're primarily hosting for those other victim countries,” Anscombe said. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/data-src-image-41924198-8435-4864-acad-c3ca5482c7fc.png) _This post is for paying subscribers only._ ### Cloudflare, Palo Alto Networks, and Zscaler are caught up in Salesloft Drift attacks URL: https://www.metacurity.com/cloudflare-palo-alto-networks-and-zscaler-are-caught-up-in-salesloft-drift-attacks/ Last updated: 2025-09-03T13:42:09.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/salesloftdrift-1.png) **Please consider supporting Metacurity** Metacurity has been a labor of love for years, and I’m so grateful for your readership. Your support can help ensure I can continue delivering the carefully curated weekly long-reads and daily digests of the most critical developments in cybersecurity. If you find value in what Metacurity offers, please consider upgrading to a paid subscription. We also provide corporate subscription options, and soon we’ll be introducing affordable sponsorship opportunities—perfect for promoting your events or products to a highly engaged audience. To learn more, feel free to reach out at cynthia@metacurity.com. Thank you so much for being part of the Metacurity community. [Upgrade my subscription!](https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/#/portal/account/plans) If you can't commit to a subscription, please consider donating what you can afford to help keep Metacurity free to all. [Donate What You Can](https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/#/portal/support) --- ### Multiple security and technology companies have been swept up in a far-reaching attack spree originating at Salesloft Drift, with Cloudflare, PagerDuty, Palo Alto Networks, SpyCloud, and Zscaler coming forward to confirm attacks as customers of the third-party AI chat agent hunt. Salesloft initially claimed exposure was limited to customers integrated with Salesforce. However, Google Threat Intelligence Group and Mandiant Consulting, Google’s incident response firm, which is now working with Salesloft, said any platform integrated with Drift is potentially compromised. Okta said it was not impacted by the incident, but confirmed it was a target based on the indicators of compromise Google Threat Intelligence Group shared last week. “The threat actor attempted to use a compromised token to access our Salesforce instance, but the attack failed because the connection originated from an unauthorized IP address,” the company said. Sam Curry, chief information security officer at Zscaler, said the company’s Salesloft Drift integration with Salesforce was the point of unauthorized access. The company was using Salesloft Drift integrated with other platforms, but they were not impacted, he added. Data on a large number of Zscaler’s customers was exposed, including names, business email addresses, job titles, phone numbers, location details, Zscaler product licensing and commercial information, and plain text content from some support cases. “No product, service, or infrastructure was affected,” Curry said. “We are looking to hear from Salesloft Drift and from Salesforce if there are any other findings since this happened in their infrastructure.” Palo Alto Networks confirmed that it, too, was one of hundreds of organizations impacted by the supply chain attack. The company’s incident response business unit, Unit 42, confirmed the incident was limited to its Salesforce environment, adding that no Palo Alto Networks products or services were impacted. Cloudflare said any information customers shared with the company’s support system, including logs, tokens, or passwords, should be considered compromised. The company said it found 104 Cloudflare API tokens in the compromised data and, while it found no evidence of abuse, rotated the tokens out of an abundance of caution. The company also maintained that no Cloudflare services or infrastructure were compromised. ([Matt Kapko / Cyberscoop](https://cyberscoop.com/salesloft-drift-attacks-cloudflare-palo-alto-networks-zscaler/?ref=metacurity.com)) **Related:** [*Unit 42*](https://unit42.paloaltonetworks.com/threat-brief-compromised-salesforce-instances?ref=metacurity.com)*,* [*Cloudflare*](https://blog.cloudflare.com/response-to-salesloft-drift-incident/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/09/02/stolen%5Foauth%5Ftokens%5Fexpose%5Fpalo/?ref=metacurity.com)*,* [*Okta*](https://www.okta.com/newsroom/articles/the-salesloft-incident--a-wake-up-call-for-saas-security-and-ips/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2025-09-02/attacks-on-salesloft-ai-chatbot-claim-another-victim-cloudflare?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/181819/data-breach/palo-alto-networks-disclose-a-data-breach-linked-to-salesloft-drift-incident.html?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/cyberattacks-data-breaches/zscaler-palo-alto-networks-breached-salesloft-drift?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/4050103/palo-alto-networks-zscaler-cloudflare-hit-by-the-latest-data-breach.html?ref=metacurity.com)*,* [*The Conversation*](https://theconversation.com/what-are-shinyhunters-the-hackers-that-attacked-google-should-we-all-be-worried-264271?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/cloudflare-data-breach-salesforce-and-salesloft-drift/?ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/security/12586-palo-alto-networks-cloudflare-confirm-impact-of-salesloft-drift-breach?ref=metacurity.com)*,* [*Infosecurity*](https://www.infosecurity-magazine.com/news/zscaler-customer-info-taken/?ref=metacurity.com)*,* [*JD Supra*](https://www.jdsupra.com/legalnews/update-organizations-using-the-7847998/?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/markets/tech/25/09/47457901/palo-alto-investigates-data-theft-after-hackers-exploit-stolen-oauth-tokens?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2025/09/02/breach-salesloft-drift-integration-exposes-data-cloudflare-zscaler-palo-alto-networks/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/palo-alto-networks-data-breach-exposes-customer-info-support-cases/?ref=metacurity.com)*,* [*Hacker News (ycombinator)*](https://news.ycombinator.com/item?id=45106340&ref=metacurity.com)*,* [*Channel Futures*](https://www.channelfutures.com/artificial-intelligence/palo-alto-zscaler-cloudflare-confirm-data-breaches?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/cloudflare-joins-growing-list-of-companies-hit-by-salesloft-ai-breach/?mid=1&ref=metacurity.com#cid=3060339) ### UK public spending watchdog National Audit Office (NAO) said the country's Ministry of Defence (MoD) cost estimate of £850 million (around $1.1 billion) to relocate Afghans whose lives are in peril following a massive data leak is an unreliable figure MoD has not provided enough evidence to give it confidence in that figure, which does not include legal expenses, or compensation claims likely to follow. Last month, it was revealed that the details of almost 19,000 people who had applied to move to the UK to flee the Taliban were leaked when an official mistakenly emailed a spreadsheet that contained a hidden tab with the information in 2022. It contained information like names, contact details, and family information of people who believed their cooperation with British forces during the Afghanistan war put them at risk of reprisals. Following the data breach, a new scheme - the Afghanistan Response Route (ARR) - was secretly set up in April 2024, allowing a further 7,000 to come to the UK. A super-injunction granted by the High Court in September 2023 prevented the incident from being reported for almost two years, before the order was lifted in July. The MoD estimates the cost for resettling each individual to be £128,000, with the total bill for all its Afghan resettlement programmes forecast to exceed £2bn. In a report, the NAO said the government had failed to provide sufficient evidence to give the watchdog "confidence" to say if its £850m figure was accurate. The watchdog said: "The MoD is not able to determine exactly what it has spent on resettling people through the ARR scheme. ([Jonathan Beale and Adam Durbin / BBC News](https://www.bbc.com/news/articles/cm2k25dx1z3o?ref=metacurity.com)) **Related:** [*National Audit Office*](https://www.nao.org.uk/press-releases/mod-does-not-know-exact-cost-to-date-of-afghan-data-breach-resettlement-scheme/?ref=metacurity.com)*,* [*GB News*](https://www.gbnews.com/news/afghan-data-breach-exact-cost-not-known?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/business/media-telecom/uk-doesnt-know-how-much-massive-afghan-data-leak-will-cost-watchdog-says-2025-09-02/?ref=metacurity.com)*,* [*Independent*](https://www.the-independent.com/news/uk/home-news/mod-afghan-government-nao-kabul-b2818900.html?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/uk-news/2025/sep/03/afghans-resettled-uk-mod-data-leak-report-national-audit-office?ref=metacurity.com)*,* [*Sky News*](https://news.sky.com/story/moving-afghan-nationals-to-uk-forecast-to-cost-more-than-2bn-13423676?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/d7f80117-5ae2-4b21-824e-3e3960ccffae?ref=metacurity.com) ### Marking the latest in a string of British companies hampered by cyberattacks, Jaguar Land Rover's retail and production activities have been "severely disrupted" following a cybersecurity incident, the British luxury carmaker said, adding that it was working to restart its operations in a controlled manner. The company, owned by India's Tata Motors, said it had not found any evidence at this stage that any customer data had been stolen after it shut down its systems to mitigate the impact. Over the past several months, British retailers M&S, Harrods, and Co-op have had their operations disrupted by the threat group known as Scattered Spider. ([Pushkala Aripaka / Reuters](https://www.reuters.com/business/autos-transportation/britains-jlr-hit-by-cyber-incident-that-disrupts-production-sales-2025-09-02/?ref=metacurity.com)) ***Related:***[ *Bloomberg*](https://www.bloomberg.com/news/articles/2025-09-02/jaguar-land-rover-hit-by-cyber-incident-affecting-production?ref=metacurity.com)*,* [*Autocar*](https://www.autocar.co.uk/car-news/new-cars/jlr-production-and-sales-severely-disrupted-cyber-attack?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/business/2025/sep/02/jaguar-land-rover-cyber-incident-manufacturing-retail?ref=metacurity.com)*,* [*City AM*](https://www.cityam.com/jaguar-land-rover-hit-by-cyber-attack-forcing-production-shutdown-at-uk-plant/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/jaguar-land-rover-disruption-cyber-incident?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/jaguar-land-rover-says-cyberattack-severely-disrupted-production/?ref=metacurity.com)*,* [*BBC News*](https://www.bbc.com/news/articles/c9wywvllq7wo?at%5Fmedium=RSS&at%5Fcampaign=rss&ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/security/12590-jaguar-land-rover-takes-systems-offline-following-cyber-incident?ref=metacurity.com)*,* [*The Stack*](https://www.thestack.technology/jaguar-land-rover-rocked-by-security-incident-that-has-left-plants-retail-offline/?mid=1&ref=metacurity.com#cid=3060590) ### Amazon's threat intelligence team disrupted an operation attributed to the Russian state-sponsored threat group Midnight Blizzard, which sought access to Microsoft 365 accounts and data. Also known as APT29, the hacker group compromised websites in a watering hole campaign to redirect selected targets "to malicious infrastructure designed to trick users into authorizing attacker-controlled devices through Microsoft’s device code authentication flow." The Midnight Blizzard threat actor has been linked to Russia’s Foreign Intelligence Service (SVR) and is well-known for its clever phishing methods that recently impacted European embassies, Hewlett Packard Enterprise, and TeamViewer. Amazon discovered the domain names used in the watering hole campaign after creating an analytic for APT29's infrastructure. An investigation revealed that the hackers had compromised multiple legitimate websites and obfuscated malicious code using base64 encoding with the threat actors used a cookies-based system to prevent the same user from being redirected multiple times, reducing suspicion. Victims that landed on the fake Cloudflare pages were guided to a malicious Microsoft device code authentication flow, in an attempt to trick them into authorizing attacker-controlled devices. Amazon notes that once the campaign was discovered, its researchers isolated the EC2 instances the threat actor used, partnered with Cloudflare and Microsoft to disrupt the identified domains. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/amazon-disrupts-russian-apt29-hackers-targeting-microsoft-365/?ref=metacurity.com)) **Related:** [*Amazon*](https://aws.amazon.com/blogs/security/amazon-disrupts-watering-hole-campaign-by-russias-apt29/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/amazon-shuts-down-apt29-watering-hole-attack?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/amazon-russian-apt29-watering-hole/?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/cyberattacks-data-breaches/amazon-apt29-credential-theft-campaign?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/amazon-disrupts-russian-hacking-campaign-targeting-microsoft-users/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/image-6.png) Fake Cloudflare verification page. Source: Amazon ### The Trump administration reactivated an ICE contract for spyware from Tel Aviv-based Paragon that had previously been blocked due to a stop order, according to procurement records posted on a government website. The immigration agency signed a $2 million deal last September for the Paragon software, which has allegedly been used to target activists and journalists in Europe, but the contract was hit with a stop-work order soon after. The development gives ICE a powerful new spying tool in its nationwide crackdown on undocumented immigrants as it attempts to deliver on President Donald Trump’s promise to carry out the largest mass deportation in US history. Details about the renewed contract were earlier reported by the newsletter All Source Intelligence. ([Ryan Gallagher / Bloomberg](https://www.bloomberg.com/news/articles/2025-09-02/ice-to-gain-access-to-paragon-spyware-after-biden-order-dropped?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc1NjgyMTA3MCwiZXhwIjoxNzU3NDI1ODcwLCJhcnRpY2xlSWQiOiJUMVlLWVJHT1lNVEswMCIsImJjb25uZWN0SWQiOiJENTY5QzIyNzE4NUM0NkM4OTgxMjBGMUI2QTBFNDIwQSJ9.F9jGGbXPdFjMcXOxqhQ2GO5%5FVYugwjgHPVvSVZEB9ik&ref=metacurity.com)) ***Related:*** [*FPDS.gov*](https://www.fpds.gov/ezsearch/search.do?indexName=awardfull&templateName=1.5.3&s=FPDS.GOV&q=70CTD024P00000012+7012+&ref=metacurity.com)*,* [*Jack Poulson*](https://jackpoulson.substack.com/p/exclusive-ice-has-reactivated-its)*,* [*The Guardian*](https://www.theguardian.com/us-news/2025/sep/02/trump-immigration-ice-israeli-spyware?ref=metacurity.com)*,* [*Washington Post*](https://www.washingtonpost.com/technology/2025/09/02/ice-paragon-spyware-ban-lifted/?pwapi%5Ftoken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJyZWFzb24iOiJnaWZ0IiwibmJmIjoxNzU2Nzg1NjAwLCJpc3MiOiJzdWJzY3JpcHRpb25zIiwiZXhwIjoxNzU4MTY3OTk5LCJpYXQiOjE3NTY3ODU2MDAsImp0aSI6IjYxM2IzNjUyLTNmMDAtNDA0Yi1iMWIwLTcyNjAxNzFlNzgzNSIsInVybCI6Imh0dHBzOi8vd3d3Lndhc2hpbmd0b25wb3N0LmNvbS90ZWNobm9sb2d5LzIwMjUvMDkvMDIvaWNlLXBhcmFnb24tc3B5d2FyZS1iYW4tbGlmdGVkLyJ9.jIG3HqREYOu5UjjBBxSFOT3KjU8sc7wjn1GO%5FzcV%5F80&itid=gfta&ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2025/09/02/ice-reactivates-contract-with-spyware-maker-paragon/?ref=metacurity.com)*,* [*All-Source Intelligence*](https://jackpoulson.substack.com/p/exclusive-ice-has-reactivated-its)*,* [*Hackwhackers*](https://hackwhackers.blogspot.com/2025/09/ice-gets-use-of-sophisticated-phone.html?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/09/02/biden%5Fstopped%5Fice%5Ffrom%5Fbuying/?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/ice-revives-contract-with-controversial-spyware-firm-paragon?ref=metacurity.com)*,* [*Business Standard*](https://www.business-standard.com/india-news/us-ice-to-gain-access-to-paragon-spyware-after-biden-order-dropped-125090201469%5F1.html?ref=metacurity.com)*,* [*WebProNews*](https://www.webpronews.com/ice-revives-2m-spyware-contract-with-paragon-amid-privacy-concerns/?ref=metacurity.com) ### An analysis of the surveillanceware industry by security operations center specialist Sekoia shows that governments are flocking to surveillanceware vendors who are seeing their businesses grow in leaps and service prices increase. For example, the report recounts that, in 2011, the Gamma Group - a British biz that was offering FinFisher spyware was charging government agencies €1,100 per infection. Four years later, the Italian vendor Hacking Team was offering similar attack code for €1 million for a full hacking service, but by 2022, an investigation into the Candiru spyware biz showed that it was charging €6 million for its surveillanceware-as-a-service operations. "In addition to being very lucrative, documents of major leaders of the sector dating from 2011 to 2022 demonstrate that the price for spyware use is in a constant rise. This is partly due to the increased cost of acquiring vulnerabilities and exploits, but also to the important number of clients looking for spyware," Sekoia said. ([Iain Thomson / The Register](https://www.theregister.com/2025/09/02/commercial%5Fsurveillanceware%5Fsafe/?ref=metacurity.com)) **Related:** [*Sekoia*](https://regmedia.co.uk/2025/09/02/surveillanceware-report1.pdf?ref=metacurity.com)*,* [*Cyber Insider*](https://cyberinsider.com/global-spyware-industry-thriving-despite-sanctions-and-exposure/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/image-7.png) Source: Sekoia. ### Brazilian media company O Globo reported that hackers broke into broke into Sinqia, a financial technology provider owned by Evertec, attempting to steal around 420 million reais ($77.4 million) from several Brazilian financial institutions including HSBC Holdings Plc’s local operations. Cyber criminals invaded Sinqia’s systems used by Brazilian financial institutions and attempted to make several transfers through a fast-growing electronic payments system known as Pix. Sinqia confirmed the attack but said there was no evidence of suspicious activity in any system besides Pix. Sinqia is working to rebuild the affected systems with enhanced controls and will only put Pix back online pending a review from the central bank, it said in a statement on Saturday. Hackers sought to divert around 380 million reais from HSBC, O Globo said, adding the Brazilian central bank managed to block 350 million reais from the attack. It did not say what happened to the rest. HSBC confirmed the incident in a statement, saying “no customer accounts or funds were impacted by the operation and measures have been taken to block these transactions.” ([Clarice Couto / Bloomberg](https://www.bloomberg.com/news/articles/2025-08-31/cyberattack-on-evertec-s-sinqia-hits-hsbc-others-in-brazil?ref=metacurity.com)) **Related:** [*O Globo*](https://g1.globo.com/economia/noticia/2025/08/30/hsbc-ataque-hacker-pix.ghtml?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/hackers-breach-fintech-firm-in-attempted-130m-bank-heist/?ref=metacurity.com)*,* [*Cyber Insider*](https://cyberinsider.com/hackers-attempted-theft-of-140-million-from-hsbc-bank-in-brazil/?ref=metacurity.com)*,* [*The Paypers*](https://thepaypers.com/fraud-and-fincrime/news/hsbc-among-victims-as-cybercriminals-hit-evertecs-sinqia-in-brazil?ref=metacurity.com) ### Google is facing an unusual ultimatum from a hacker collective that calls itself Scattered LapSus Hunters, which has demanded the firing of two of its cybersecurity leaders, Austin Larsen and Charles Carmakal, or risk a major data leak. The threat comes shortly after Google confirmed that ShinyHunters had accessed data from Salesforce, a third-party service provider. While Google said there was no breach of its internal databases or consumer Gmail accounts, the attackers appear to be leveraging the incident for pressure. Although some reports regarding this threat said that Google warned all Gmail users to reset their passwords due to a recent data breach that also affected some Workspace accounts, Google said those are false stories. The company said "Gmail's protections are strong and effective, and claims of a major Gmail security warning are false." "Several inaccurate claims surfaced recently that incorrectly stated that we issued a broad warning to all Gmail users about a major Gmail security issue. This is entirely false," Google added. ([Jatin Verma / WION](https://www.wionews.com/trending/hacking-threat-tech-giant-google-issues-global-gmail-alert-after-hackers-target-security-team-1756778137074?ref=metacurity.com) and [Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/technology/no-google-did-not-warn-25-billion-gmail-users-to-reset-passwords/?ref=metacurity.com)) **Related:** [*The Keyword*](https://blog.google/products/workspace/gmail-security-protections/?ref=metacurity.com)*,* [*Financial Express*](https://www.financialexpress.com/life/technology-google-faces-risk-of-data-breach-as-hackers-demand-firing-of-two-employees-austin-larsen-and-charles-carmakal-who-are-they-3964310/?ref=metacurity.com)*,* [*Hindustan Times*](https://www.hindustantimes.com/world-news/us-news/google-faces-hacker-ultimatum-to-fire-two-employees-or-risk-data-leak-who-are-austin-larsen-and-charles-carmakal-101756719853083-amp.html?ref=metacurity.com)*,* [*Newsweek*](https://www.newsweek.com/hackers-issue-ultimatum-data-breach-2122489?ref=metacurity.com)*,* [*Mashable India*](https://in.mashable.com/tech/99331/hackers-threaten-google-to-fire-two-techies-from-threat-intelligence-group-after-being-exposed-or-el?ref=metacurity.com)*,* [*Economic Times*](https://economictimes.indiatimes.com/news/international/us/hackers-demand-googles-action-scattered-lapsus-hunters-threaten-information-leak/articleshow/123640765.cms?from=mdr&ref=metacurity.com)*,* [*Mashable*](https://mashable.com/article/google-hack-gmail-phishing-breach?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/gadgets/2025/09/google-says-reports-of-massive-gmail-data-breach-are-entirely-false/?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/5481831-google-denies-gmail-hack/?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/134283/google-refutes-reports-of-major-gmail-breach/?ref=metacurity.com)*,* [*Cyber Insider*](https://cyberinsider.com/google-refutes-reports-of-gmail-breach-alert-sent-to-billions/?ref=metacurity.com)*,* [*IT Pro*](https://www.itpro.com/security/cyber-attacks/google-says-claims-of-a-major-gmail-security-warning-are-false-following-recent-media-reports?ref=metacurity.com)*,* [*Rolling Out*](https://rollingout.com/2025/09/02/google-debunks-billion-gmail-hack/?ref=metacurity.com) ### Artists&Clients, a website that connects independent artists with interested clients, was hit by a ransomware threat attributed to the ransomware group LunaLock, which demanded payment or else it would release the data it stole and, in a new twist, threatened to submit all artwork to AI companies to be added to training datasets. LunaLock promised to delete the stolen data and allow users to decrypt their files if the site’s owner paid a $50,000 ransom. Tammy Harper, a senior threat intelligence researcher at the cybersecurity company Flare, said that this kind of threat could be effective against artists. “It’s a very sensitive subject for this type of victim (an art marketplace). LunaLock is definitely using and hoping for the clients and artists of the victim to pressure them into paying the ransom.” ([Matthew Gault / 404 Media](https://www.404media.co/hackers-threaten-to-submit-artists-data-to-ai-models-if-art-site-doesnt-pay-up/?ref=metacurity.com)) **Related:** [*Cyber Daily*](https://www.cyberdaily.au/security/12587-new-lunalock-ransomware-group-emerges-with-unique-extortion-tactic?ref=metacurity.com) ### Blockchain security firm PeckShield reported that a user of the DeFi lending platform application-layer saw crypto assets worth $13.5 million disappear in a phishing attack. Venus Protocol’s official social media account responded to community concerns in an X thread, confirming there was no flaw in its smart contracts. When a user asked if this was due to the user’s mistake, Venus said it was likely the case. However, Venus said that as a precautionary measure, it would pause the protocol to conduct security reviews. “Right now, yes, that appears to be the case. We will keep everyone updated as we investigate,” Venus Protocol said. “Protocol is paused while security reviews are underway.” ([Ezra Reguerra / Cointelegraph](https://cointelegraph.com/news/defi-trader-loses-27m-phishing-scam-venus-protocol-pauses?ref=metacurity.com)) **Related:** [*Coindesk*](https://www.coindesk.com/business/2025/09/03/venus-protocol-restores-services-recovers-stolen-funds-after-usd27m-exploit?ref=metacurity.com), [*OneSafe*](https://www.onesafe.io/blog/venus-protocol-phishing-attack-lessons-learned?ref=metacurity.com)*,* [*DL News*](https://www.dlnews.com/articles/defi/venus-protocol-votes-to-liquidate-attacker-behind-13m-hack/?ref=metacurity.com)*,* [*Cryptopolitan*](https://www.cryptopolitan.com/venus-protocol-restores-all-services/?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/post/369040/venus-protocol-pauses-after-user-loses-27-million-in-suspected-phishing-attack?ref=metacurity.com)*,*[ *CCN*](https://www.ccn.com/news/crypto/venus-protocol-paused-user-loses-13-phishing-scam-crypto-scams/?ref=metacurity.com) ### Researchers at DarkTrace discovered a cryptojacking attempt in its early stages, offering insights into a new cryptomining strain. In July 2025, Darktrace detected and contained an attempted cryptojacking incident on the network of a customer in the retail and e-commerce industry, when a threat actor attempted to use a PowerShell script to download and run NBMiner directly in memory. Specifically, the targeted desktop device established a connection to the rare endpoint, 45.141.87\[.\]195, over destination port 8000 using HTTP as the application-layer protocol. Within this connection, Darktrace observed the presence of a PowerShell script in the URI, specifically ‘/infect.ps1’. Darktrace’s analysis of this endpoint (45.141.87\[.\]195\[:\]8000/infect.ps1) and the payload it downloaded indicated it was a dropper used to deliver an obfuscated AutoIt loader. This attribution was further supported by open-source intelligence (OSINT) reporting. The loader likely then injected NBMiner into a legitimate process on the customer’s environment – the first documented case of NBMiner being dropped in this way. ([Ronny Roy / crypto.news](https://crypto.news/darktrace-flags-new-cryptojacking-campaign-able-to-bypass-windows-defender/?ref=metacurity.com)) **Related:** [*Darktrace*](http://www.darktrace.com/blog/from-powershell-to-payload-darktraces-detection-of-a-novel-cryptomining-malware?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/image-5.png) Darktrace’s detection of a device making an HTTP connection with new PowerShell user agent, indicating PowerShell abuse for command-and-control (C2) communications. Source: Darktrace ### Singapore Minister of State for Home Affairs Goh Pei Ming said that Singapore police have ordered Meta to implement anti-scam measures against advertisements, accounts, profiles, and business pages impersonating key government office holders on its social media network Facebook to combat scams. The company could be fined up to S$1 million ($775,698) if it fails to comply as part of the first such order under the nation's new Online Criminal Harms Act, which came into force in February 2024. In August, Singapore's home affairs ministry found that more than a third of all e-commerce scams reported in 2024 were perpetrated on Facebook. It also rated Facebook Marketplace as the weakest among six e-commerce marketplaces in terms of anti-scam features deployed. A Meta spokesperson said that the company had specialised systems to detect impersonating accounts, including facial recognition technology, and it had invested heavily in improving detection and review teams. It also shares tips on avoiding scams and offers tools to report potential violations, the spokesperson said. ([Jun Yuan Yong / Reuters](https://www.reuters.com/business/media-telecom/singapore-orders-meta-implement-anti-scam-measures-or-face-possible-fine-2025-09-03/?ref=metacurity.com)) **Related:** [*Benzinga*](https://www.benzinga.com/markets/tech/25/09/47465919/meta-faces-heat-in-singapore-over-facebook-marketplace-scams-minister-calls-for-more-decisive-action?ref=metacurity.com) ### According to the annual Singapore Cyber Landscape 2024/2025 report released by the Cyber Security Agency of Singapore (CSA), in 2024, the cyber threat landscape in Singapore was dominated by phishing attempts, ransomware attacks, and infected hardware. Phishing attempts in Singapore increased by 49 per cent to 6,100 cases. The banking and financial services (BFS) sector was the most targeted industry. Ransomware attacks increased by 21 per cent from last year, with 159 reported cases. Infected computer infrastructure remained a concern with a 67 per cent increase from 70,200 infected systems in 2023 to 117,300 in 2024\. ([Amit Roy Choudhury / GovInsider](https://govinsider.asia/intl-en/article/phishing-ransomware-and-infected-hardware-major-cyber-threats-for-singapore?ref=metacurity.com)) **Related:** [*Cybersecurity Agency of Singapore*](https://www.csa.gov.sg/resources/publications/singapore-cyber-landscape-2024-2025?ref=metacurity.com)*,* [*The Straits Times*](https://www.straitstimes.com/tech/failure-to-patch-vulnerable-software-sees-malware-infections-in-singapore-surge-67-in-2024-csa?ref=metacurity.com) ### South Korean authority The Korea Consumer Agency said it inspected six robot vacuum models, four Chinese and two Korean products, and discovered serious security flaws in three Chinese brands: Narwal, Ecovacs, and Dreame. The Korea Consumer Agency said all affected companies have since patched the issues. Meanwhile, models from Samsung Electronics and LG Electronics were rated as having stronger protections, including solid access controls, anti-tampering features, and secure password systems, according to the agency. ([Song Seung-hyun / The Korea Herald](https://m.koreaherald.com/article/10567699?ref=metacurity.com)) ***Related:*** [*Maeil Business Newspaper*](https://www.mk.co.kr/en/business/11409258?ref=metacurity.com)*,* [*The Chosun Daily*](https://www.chosun.com/english/market-money-en/2025/09/02/PPPWLROTGFCYHFBYP356XZMHJU/?ref=metacurity.com)*,* [*Pulse*](https://pulse.mk.co.kr/news/all/11409775?ref=metacurity.com)*,* ### While some state offices and agencies remain offline after last month's cyberattack, the Nevada DMV is now offering some in-person services. The DMV also says “all vehicle appointments that were canceled between August 25 – August 30 will be honored as walk-ins starting today, September 2.” “All offices are open for registration, titling, and other vehicle related services. Identification and driving privilege services (such as new IDs, licenses) remain unavailable at this time.” “Walk-ins will be available during business hours, Monday – Saturday (Monday – Friday only for Carson City).” Online, Nevadans can use services like registration renewal, driver history printouts, registration and insurance status, insurance general information, personalized plate ordering, rapid registration, and vehicle taxes history. ([2News Nevada](https://www.2news.com/news/local/nevada-dmv-restores-some-in-person-services-amid-statewide-cyberattack/article%5Ff69c5ee8-70a4-46aa-a5bc-e97503c97850.html?ref=metacurity.com)) **Related:** [*The Nevada Globe*](https://thenevadaglobe.com/articles/nevadas-digital-doomsday-when-hackers-hold-the-silver-state-hostage/?ref=metacurity.com)*,* [*KSNV*](https://news3lv.com/news/local/nevada-dmv-reopens-amid-cyber-attack-gov-lombardo-to-announce-updates-thursday?ref=metacurity.com)*,* [*Carson Now*](https://www.carsonnow.org/09/02/2025/state-cyberattack-outages-enter-second-week-some-services-restored-no-new-info-on-stolen-data?ref=metacurity.com)*,* [*Las Vegas Review-Journal*](https://www.reviewjournal.com/news/politics-and-government/nevada/nevada-enters-day-8-of-recovery-from-massive-cyberattack-3432433/?ref=metacurity.com) ### Pennsylvania’s Office of Attorney General (OAG) confirmed that it has been hit by a ransomware attack, causing delays to civil and criminal court cases. The state’s Attorney General, Dave Sunday, confirmed the incident knocked OAG servers offline earlier in August. “The interruption was caused by an outsider encrypting files in an effort to force the office to make a payment to restore operations. No payment has been made,” Sunday said. The OAG has not provided any indication whether data was potentially stolen in the attack. “An active investigation is ongoing with other agencies, which limits our ability to comment further on the investigation or response to the incident,” Sunday continued. ([James Coker / Infosecurity Magazine](https://www.infosecurity-magazine.com/news/ransomware-pennsylvania-ag/?ref=metacurity.com)) **Related:** [*Pennsylvania Attorney General*](https://www.attorneygeneral.gov/taking-action/attorney-general-sunday-provides-latest-developments-on-outside-interruption-that-impacted-oag-servers/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/disruptions-persist-at-ransomware-hit-pennsylvania-attorney-generals-office?ref=metacurity.com)*,* [*The Record*](https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/pa-attorney-general-recovers-after-cyberattack/?ref=metacurity.com) ### The Walt Disney Company said it agreed to pay $10 million to settle a children's privacy lawsuit with the Federal Trade Commission related to videos it uploaded on YouTube mostly during the pandemic which the FTC alleged violated the 1998 Children's Online Privacy Protection Act (COPPA). The FTC complaint alleges Disney failed to designate certain YouTube videos as being made for children when it added them to the platform. In failing to do so, Disney inadvertently allowed those videos to be targeted with online advertising, which is why the FTC considers the improper designation problematic. ([Sara Fischer / Axios](https://www.axios.com/2025/09/02/disney-ftc-settlement-lawsuit-youtube-video-children-privacy?ref=metacurity.com)) **Related:** [*FTC*](https://www.ftc.gov/news-events/news/press-releases/2025/09/disney-pay-10-million-settle-ftc-allegations-company-enabled-unlawful-collection-childrens-personal?ref=metacurity.com)*,* [*The Record*](https://therecord.media/disney-settles-with-ftc-millions?ref=metacurity.com)*,* [*The Cyber Express*](https://thecyberexpress.com/disney-pays-10m-to-ftc/?ref=metacurity.com)*,* [*Deadline*](https://deadline.com/2025/09/disney-ftc-settlement-1236504226/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/policy/769771/disney-ftc-coppa-settlement-kids-data?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/legal/litigation/disney-pay-10-million-settle-us-claim-allowing-unlawful-collection-childrens-2025-09-02/?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/news/disney-lawsuit-ftc-unlawful-collection-childrens-personal-data/?ref=metacurity.com)*,* [*The Wall Street Journal*](https://www.wsj.com/business/media/disney-to-pay-10-million-to-settle-ftc-allegations-on-collection-of-childrens-data-e14ad6e4?gaa%5Fat=eafs&gaa%5Fn=ASWzDAgNKkhs%5F81Sdats59CGKX%5FH25I2U1ZTPddie-2%5F-arb6BoMs8T5ryB8Aotjojw%3D&gaa%5Fts=68b8174a&gaa%5Fsig=59YCBQoC7tO6hQLRzGRX-W9b1cR9ZVF4vfJrTTz0KgVxyMerCJhfpXJ2Oa1Ew9zBLML15pVXvRTuP6By0aNkww%3D%3D&ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/policy/769771/disney-ftc-coppa-settlement-kids-data?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/entertainment/youtube/disney-will-pay-10-million-to-settle-ftc-complaint-that-it-collected-childrens-data-on-youtube-213646745.html?guccounter=1&guce%5Freferrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&guce%5Freferrer%5Fsig=AQAAAGeOE4FOtAWSOQR6cmON2e611Gx4nYb0U6avkh350Yf5CAdS5xk%5FRdjJLCEW576Yd6hmLuksbDfyJrX9W9FlhNYOW4BNtAPJMEe9oaIq-EkmA4Vq676mUjXYkzTU-UliuWU9nm%5F6rmSugkMmOXRgx5t2xebERoyIrPD5fuqH7ygb&ref=metacurity.com)*,* [*USA Today*](https://www.usatoday.com/story/money/2025/09/02/disney-10-million-fine-ftc-unlawful-child-data-collection-youtube/85944757007/?ref=metacurity.com) ### A global, six-year campaign to counter Chinese tech dominance took a hit this summer when Congress defunded a key research program to create a worldwide alternative to 5G giant Huawei when Donald Trump's One Big Beautiful Bill cut nearly $1 billion for the Wireless Innovation Fund, which was supposed to create a new, American-dominated type of 5G network. The defunding is a significant*,* setback for America’s prolonged effort to root Chinese-made equipment out of the world’s telecommunications backbone. That campaign has reached into the American heartland, caused drama with allies internationally and even led to global intrigue when Huawei’s chief financial officer was arrested, extradited to the US, and later traded in a prisoner swap. ([John Hendel / Politico](https://www.politico.com/news/2025/09/02/congress-pulls-the-rug-on-u-s-plan-to-beat-huawei-00527620?ref=metacurity.com)) ### The US National Institute of Standards and Technology (NIST) revised its Security and Privacy Control catalog to help vendors and organizations improve software update and patch release protocols. Initially published in 2020, the Security and Privacy Control catalog details security and privacy safeguards to help organizations mitigate cyber-risks. Federal information systems are required to implement the controls, but the catalog is intended for the private and public sectors. It covers access, authentication, incident response, and supply chain risk management. The latest update focuses on addressing risks related to software updates and patch releases. The changes are meant to "help organizations understand their role in ensuring the security of the software on their systems," according to NIST. ([Arielle Waldman / Dark Reading](https://www.darkreading.com/cybersecurity-operations/nist-enhances-security-controls-for-improved-patching?ref=metacurity.com)) **Related:** [*NIST*](https://www.nist.gov/news-events/news/2025/08/nist-revises-security-and-privacy-control-catalog-improve-software-update?ref=metacurity.com)*,* [*ExecutiveGov*](https://www.executivegov.com/articles/nist-security-privacy-control-catalog-cybersecurity-eo?ref=metacurity.com)*,* [*MeriTalk*](https://www.meritalk.com/articles/nist-revises-security-privacy-control-catalog/?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/nist/nist-enhances-sp-800-53-controls-to-improve-cybersecurity-and-software-maintenance-reduce-cyber-risks/?ref=metacurity.com)*,* [*Biometric Update*](https://www.biometricupdate.com/202509/nist-revision-of-sp-800-53-highlights-rising-stakes-in-patch-update-security?ref=metacurity.com) ### Senate Intelligence Committee Vice Chairman Mark Warner (D-VA) said that he is being blocked from a scheduled oversight meeting after interference from far-right activist Laura Loomer. Warner said the National Geospatial-Intelligence Agency meeting scheduled for Friday was called off after Loomer launched public attacks on him and the NGA’s director, Vice Adm. Trey Whitworth. “This nakedly political decision undermines the dedicated, nonpartisan staff at NGA and threatens the principle of civilian oversight that protects our national security,” Warner said in a statement. “Members of Congress routinely conduct meetings and on-site engagements with federal employees in their states and districts; blocking and setting arbitrary conditions on these sessions sets a dangerous precedent, calling into question whether oversight is now allowed only when it pleases the far-right fringe,” he said. ([Dan De Luce / NBC News](https://www.nbcnews.com/politics/politics-news/intelligence-meeting-canceled-attacks-far-right-activist-laura-loomer-rcna228710?ref=metacurity.com)) **Related:** [*Augusta Free Press*](https://augustafreepress.com/news/mark-warner-calls-out-maga-bridge-troll-laura-loomer-over-canceled-meeting/?ref=metacurity.com)*,* [*The Daily Beast*](https://www.thedailybeast.com/senator-rips-laura-loomer-after-intelligence-meeting-axed-following-her-attacks/?ref=metacurity.com) ### Nick Andersen, a Marine veteran and former Department of Energy cybersecurity official, began his role as the executive assistant director for cybersecurity in the Cybersecurity and Infrastructure Security Agency. Andersen has both public and private sector experience. He was previously president and chief operating officer at cyber company Invictus, and also chief information security officer at enterprise tech provider Lumen’s public sector unit. He is also a former nonresident senior fellow with the Atlantic Council’s Cyber Statecraft Initiative. From 2019 to 2021, in President Donald Trump’s first term, Andersen served both as the principal deputy assistant secretary and performed the duties of assistant secretary for the Department of Energy’s Cybersecurity, Energy Security,and Emergency Response unit. He was also the CISO for the State of Vermont, and, prior to that, held intelligence roles in the Navy and Coast Guard. ([David DiMolfetta / NextGov/FCW](https://www.nextgov.com/people/2025/09/nick-andersen-onboards-top-cisa-cyber-position/407832/?ref=metacurity.com)) **Related:** [*CISA*](https://www.cisa.gov/news-events/news/cisa-announces-nicholas-andersen-new-executive-assistant-director-cybersecurity?ref=metacurity.com)*,* [*The Record*](https://therecord.media/andersen-leadership-cisa-role?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/cisa/cisa-picks-nicholas-andersen-to-bolster-critical-infrastructure-cyber-defenses-amid-rising-nation-state-threats/?ref=metacurity.com)*,* [*Cyberscoop*](https://cyberscoop.com/cisa-nicholas-andersen-executive-assistant-director-of-cybersecurity/?ref=metacurity.com)*,* [*Meritalk*](https://www.meritalk.com/articles/cisa-appoints-nicholas-andersen-as-executive-assistant-director-for-cybersecurity/?ref=metacurity.com) ### Data security company Varonis Systems agreed to acquire SlashNext, an AI-based email security provider, for as much as $150 million, including performance-based retention awards. SlashNext uses predictive AI to remove threats from email inboxes in real time and detect business email compromise attacks. The acquisition will allow Varonis to expand its reach in the email security sphere at a time when AI has enabled increasingly deceptive email threats, Varonis Chief Marketing Officer Rob Sobers said. ([Emily Forgash / Bloomberg](https://www.bloomberg.com/news/articles/2025-09-02/varonis-to-buy-email-security-firm-slashnext-for-150-million?ref=metacurity.com)) **Related:** [*Varonis*](https://ir.varonis.com/news-and-events/press-releases/press-release-details/2025/Varonis-Acquires-SlashNext-to-Combat-AI-Driven-Email-Threats/default.aspx?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2025/09/02/varonis-acquires-slashnext-boost-phishing-social-engineering-defenses/?ref=metacurity.com)*,* [*BankInfoSecurity.com*](https://www.bankinfosecurity.com/varonis-acquires-slashnext-to-combat-phishing-email-attacks-a-29347?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/varonis-slashnext-acquisition-ai-email-security/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2025/09/02/varonis-acquires-ai-email-security-provider-slashnext/?ref=metacurity.com) ### Best Thing of the Day: Decipher Lives! After a year-long hiatus, cybersecurity publication Decipher [has returned](https://decipher.sc/videos/decipher-lives/?ref=metacurity.com) with its original editors, Dennis Fisher and Lindsey O'Donnell-Welch, having obtained the domain, brand, and trademarks from Cisco. ### Worst Thing of the Day: A Much-Needed App Falls Short Coder, journalist and tech expert Micah F. Lee [analyzed](https://micahflee.com/unfortunately-the-iceblock-app-is-activism-theater/?ref=metacurity.com) the Iceblock app that allows users to anonymously report ICE sightings within a 5 mile radius and concluded that despite its promise, it is nothing more than activism theater at this point. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/image-8.png) ### More on DOGE and that insecure database at SSA… URL: https://www.metacurity.com/more-on-doge-and-that-insecure-database-at-ssa/ Last updated: 2025-09-02T11:48:22.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/09/Flag_of_the_United_States_Social_Security_Administration.svg-1.png) --- **Welcome back to Metacurity after a two-week hiatus!** I would love to say that during my Metacurity hiatus, I was off somewhere lovely or exciting, taking a break from cybersecurity. But in reality, I was busy writing about cybersecurity, first by writing for CSO Online, which resulted in a series of pieces you might want to read. These pieces, in reverse chronological order, are: - [Whistleblower: DOGE put Social Security database covering 300 million Americans on insecure cloud](https://www.csoonline.com/article/4046997/whistleblower-doge-put-social-security-database-covering-300-million-americans-on-insecure-cloud.html?ref=metacurity.com) - [Storm-0501 debuts a brutal hybrid ransomware attack chain](https://www.csoonline.com/article/4046438/storm-0501-debuts-a-brutal-hybrid-ransomware-attack-chain.html?ref=metacurity.com) - [Behind the Coinbase breach: Bribery emerges as enterprise threat](https://www.csoonline.com/article/4042522/behind-the-coinbase-breach-bribery-is-an-emerging-enterprise-threat.html?ref=metacurity.com) - [Russia-linked European attacks renew concerns over water cybersecurity](https://www.csoonline.com/article/4042449/russia-linked-european-attacks-renew-concerns-over-water-cybersecurity.html?ref=metacurity.com) - [Agentic AI promises a cybersecurity revolution — with asterisks](https://www.csoonline.com/article/4040145/agentic-ai-promises-a-cybersecurity-revolution-with-asterisks.html?ref=metacurity.com) Secondly, during the Metacurity hiatus, I also drafted four new chapters of my upcoming book, currently titled *The NIST 2.0 Cybersecurity Framework: Practical Risk Management Using Real-World Incidents,* which is a follow-on (but not a second edition) to my first book, [*Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework*](https://www.amazon.com/Cybersecurity-Risk-Management-Mastering-Fundamentals/dp/1119816289/ref=sr%5F1%5F1?crid=196PAN2DRPFWU&dib=eyJ2IjoiMSJ9.-qlXHaGgM%5FMi37k-poe4VA.Eiew3vdtJslma7Xs5FawWJ9pkUj1gUWlQ%5FqGWBri-Fo&dib%5Ftag=se&keywords=The+NIST+2.0+Cybersecurity+Framework%3A+Practical+Risk+Management+using+Real-World+Incidents&qid=1756730513&sprefix=the+nist+2.0+cybersecurity+framework+practical+risk+management+using+real-world+incidents%2Caps%2C381&sr=8-1&ref=metacurity.com)*.* Keep your eyes peeled for the publication of this book by Wiley later this year or early in 2026. And now, Metacurity is back, but I’m shaking things up a little bit by giving access to Metacurity’s full content two days a week – Tuesdays and Thursdays – to only paid subscribers. I will strive to make this new arrangement more attractive with content you can't find anywhere else on those two days, along with Metacurity's usual rundown of daily content aggregated from across the web and cogently summarized. If you’ve been toying with the idea of signing up for a paid subscription, today is a good day to subscribe. Your subscription will help keep Metacurity going and enable me to continue delivering the daily updates you enjoy. Thank you. [Sign up for a paid subscription right now!](#/portal/account/plans) --- # More on DOGE and that insecure database at SSA… On August 26, Chuck Borges, the Chief Data Officer (CDO) at the Social Security Administration (SSA), filed a [whistleblower complaint](https://www.wired.com/story/charles-borges-resignation-email-disappearance/?ref=metacurity.com) alleging that the agency mishandled the security of a massive database called Numerical Identification System (NUMIDENT), which contains extensive personal information on 450 million Americans and eligible noncitizens. Borges argues that by shortcutting the government’s normal security process, SSA has left this data vulnerable to theft that could go unnoticed by the government due to the lack of proper controls. Borges contends, as outlined in [my CSO piece,](https://www.csoonline.com/article/4046997/whistleblower-doge-put-social-security-database-covering-300-million-americans-on-insecure-cloud.html?ref=metacurity.com) that a group of Musk-connected DOGE workers copied a live version of the NUMIDENT database to their own private AWS instance within SSA’s Amazon Web Services agency cloud infrastructure. The new database did not seemingly comply with security controls mandated under the Federal Information Security Management Act (FISMA), or at least the folks looking to move NUMIDENT failed to answer any questions about whether they followed the requisite security protocols when they copied NUMIDENT to a new database, according to Borges. Under FISMA, federal agencies must apply a risk assessment process involving [security controls developed by NIST](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf?ref=metacurity.com) for any federal system that processes, stores, or transmits information. The application of these controls involves a complex, multifaceted process that involves applying and documenting rigorous security and privacy engineering principles and practices that are reviewed by outside experts and continuously monitored according to a risk management plan. Experts say that meeting the FISMA requirements takes at least six months and involves multiple parties to sign off before SSA can obtain the required Authorization to Operate (ATO) needed to fully protect the spun-off NUMIDENT database. In an unusual move, the DOGE team assigned itself a provisional ATO, with SSA CIO Aram Moghaddassi, who had worked for Elon Musk before joining the government, stating, “I have determined the business need is higher than the security risk associated with this implementation and I accept all risks associated with this implementation and operation.” Borges says there is no evidence that the DOGE workers underwent all the required security protection measures. SSA spokesperson Nick Perrine [told](https://www.nytimes.com/2025/08/26/us/politics/doge-social-security-data.html?ref=metacurity.com) the New York Times that the database created by DOGE is “walled off from the internet.” _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 8/9/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-8-9-25/ Last updated: 2025-08-16T13:05:22.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/08/apple-256261_1280-1.jpg) Image by [Michal Jarmoluk](https://pixabay.com/users/jarmoluk-143740/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=256261) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=256261) *Happy Saturday morning! Metacurity is pleased to offer our free and premium subscribers this weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush. So tell us what you think, and feel free to share your favorite long reads via email at* *info@metacurity.com* *.* **IMPORTANT PUBLISHING NOTICE:* Metacurity will be on summer break starting August 18 and will resume publication on September 2\. Stay safe out there, folks, and we'll see you in September!* --- **Earn good infosec karma by helping Metacurity** Thank you so much for supporting Metacurity with your readership. But did you know that you could earn good infosec karma by stepping up your support so that Metacurity can continue to provide you with our weekday updates on the pressing infosec developments you need to know, alongside this weekly selection of infosec-related long reads? Upgrading to a paid subscription will help us keep the lights on. We also provide corporate subscription options, and soon we’ll be introducing affordable sponsorship opportunities—perfect for promoting your events or products to our highly engaged and elite cybersecurity professionals. We'd be happy to promote your brand or product as a designated sponsor. To learn more, feel free to reach out at cynthia@metacurity.com. Thank you so much for being part of the Metacurity community. [Upgrade my subscription!](#/portal/account/plans) --- ### The Crypto Maniacs and the Torture Townhouse In New York Magazine, Ezra Marcus and Jen Wieczner, with additional reporting byIsabella Sepahban and Franziska Wild, [tell the twisted story](https://archive.is/JlhOK?ref=metacurity.com#selection-1415.0-1415.44) of how two new entrants to the high-end New York nightclub scene, William Duplessie and John Woeltz, held an Italian man, Michael Carturan, captive and tortured him for weeks for the passwords to his cryptocurrency accounts. > That fall, Duplessie began visiting a new friend, John Woeltz, at his home in Kentucky. The 150-acre property abutted the Ohio River in Smithland, a 200-person community four hours west of Lexington; the area was so off the grid that even locals referred to it as “the stix.” > The two made an unlikely pair. Woeltz was a mild-mannered and nerdy perfectionist with a round face and deep-set eyes; a cybersecurity obsessive, he’d begun mining bitcoin soon after its launch in 2009\. By 2019, in his 30s living alone in San Francisco with his cat, he no longer had to work. “He used to live off Soylent or Huel or his own homemade vegan sludge,” said a friend. Now, back near his hometown with a net worth of over $100 million, he led a quiet life. He studied regenerative agriculture, burying the skeleton of a fish he’d caught in his garden and sending friends photos of snakes he’d shot on the property. He’d also become a patron of the small local blockchain scene, promoting statewide bitcoin-mining efforts and donating money to a start-up accelerator and co-working space in Paducah called Sprocket. It appeared to everyone who knew Woeltz that he intended to settle down and start a family with his girlfriend, Kayla Barbour, an aspiring actress and small-business owner from Lexington. Woeltz was supportive, if controlling. “In the two years we dated, I was not allowed to work and he controlled all of my finances,” Barbour would later attest. Still, they were making plans to hold a wedding in Hawaii in late 2024. > As an early bitcoiner, Woeltz had developed an online reputation as a security white hat, a kind of good-guy hacker who could easily identify vulnerabilities and to whom strangers would sometimes reach out for help — which was why, in 2020, Michael Carturan first got in touch with him. Carturan was a socially awkward permaculture enthusiast from the small Italian town of Rivoli, a technically proficient programmer who grew up on internet forums like 4chan. He believed deeply in bitcoin as a tool that could help build a new tech-focused world order and was working on a decentralized version of a virtual private network. As they got to know each other, Carturan described his expertise operating anonymous online trollbots and “running psyops” — in other words, using social-media bots to hype meme-coin projects, making them appear more popular than they actually were. In the beginning, he was reluctant to give his real name, introducing himself only as “Sergio.” “It was always some made-up Italian name,” says a mutual friend. Soon, the two were collaborating on a brand-new cryptocurrency project. Over the years, Carturan came to see Woeltz not just as a business partner but as a role model and protector. When Carturan worried a former colleague was trying to kill him over a business dispute, he asked Woeltz for help. “John saved my life,” he would later tell others. > Carturan knew Duplessie, too — Pangea had invested in his cryptocurrency project in 2021\. And it was through Carturan that Duplessie and Woeltz eventually developed their own relationship. By December 2024, Duplessie could almost always be found at Woeltz’s Smithland cabin. “John and Will began displaying very paranoid, cultlike behavior,” Barbour later wrote in a restraining-order petition against Woeltz. His demeanor had shifted dramatically; he and Duplessie bought thousands of dollars’ worth of guns and “began wearing matching militant clothes,” patrolling the property “on the hunt for terrorists who they were convinced would be tracking us down to kill us.” ### Hacking and Firewalls Under Siege: Russia’s Cyber Industry During the War on Ukraine In this Center for Naval Analysis (CNA) paper, writer Justin Sherman [examines ](https://www.cna.org/reports/2025/08/Hacking-and-Firewalls-Under-Seige.pdf?ref=metacurity.com)how Russia's cybersecurity sector is supporting the Russian government's efforts since the full-scale invasion of Ukraine in 2022, focusing specifically on three firms, Kaspersky, Security Code, and Positive Technologies, and how their functions tie into the Kremlin’s objectives. > Kaspersky is a global company that has been repeatedly accused of quietly supporting Russian government cyber operations— including by allegedly using its antivirus platform to exfiltrate classified and sensitive information from other countries’ systems. Security Code provides what appear to be principally defensive technologies and services to Russian customers, including the FSB, Ministry of Internal Affairs (MVD), Federal Protective Service (FSO), Russian Railways, Gazprom, and Sberbank. It also maintains educational partnerships with public and private institutions in Russia that train the future cyber workforce. Positive Technologies has been identified by the US government and in media reporting as a Russian intelligence contractor that supports offensive operations, reportedly by reverse engineering Western capabilities and turning vulnerabilities into exploits for offensive cyber operations. It also runs Russia’s largest security conference and capture-the-flag hacking competition—an annual event that the FSB and GRU use to recruit highly talented hackers into the intelligence services. > Since February 2022, the three companies have been subject to additional levels of scrutiny, but they have adapted relatively well. Kaspersky went from being banned on US federal government systems to being sanctioned by the United States. It was also banned from providing many cyber products and services to American consumers and businesses, and it was identified by Germany, Poland, and others as a potential national security threat. But it has opened “transparency centers” in Latin America and elsewhere, which—contrary to what some in the West might expect—have paid off greatly for the firm as it has expanded. The company’s marketing pitches seem to be landing well in many parts of the world, whether because of distrust of American technology post–Edward Snowden leaks, well-publicized abuses by Silicon Valley giants, or the mere fact that Kaspersky is a global firm with talented personnel. However, Kaspersky is now providing protections to a notorious Russian “bulletproof” web hosting provider for cybercriminals (meaning one that hides and refuses to disclose its customers, even to governments), marking a notable departure from its past efforts to portray itself as a trustworthy brand. > Security Code has been sanctioned by Ukraine and the United States but not by the European Union. It has also remained out of the Western press, perhaps because of its role in Russian cyberdefense rather than the much more headline-grabbing category of cyberoffense. In its 2024 financials, it disclosed that most of its clients are those protecting “critical information infrastructure,” a Russian legal term for entities handling information systems, networks, and technologies that are critical to the state’s security. As a result, most of Security Code’s clients ostensibly reside in Russia. It appears that the company’s bottom line is strengthening because of growing demands in Russia for cyberdefense amid the continued war. > Positive Technologies has been marketing itself as a way for entities in other countries to diversify their cybersecurity services. It does not suggest that countries forgo American, Chinese, or Israeli cyber providers; rather, it makes the case for adding a Russian vendor to avoid depending too much on one country for cyberdefenses. In addition, the company has launched new product offerings, and in-person attendance at its flagship conference (the event the FSB and GRU use to recruit personnel) has more than quintupled from 10,000 in 2022 to 55,000 in 2023, with another 100,000 tuning in online. All three of these companies—despite waves of Western sanctions, export controls, and technology isolation efforts—had their highest revenue figures ever in 2024. ### A mind-reading brain implant that comes with password protection A study by Erin Kunz, a neural engineer at Stanford University in California, published in Cell, [found](https://www.nature.com/articles/d41586-025-02589-5?ref=metacurity.com) that a brain implant called a brain–computer interface (BCI) can decode a person’s internal chatter, but the device works only if the user thinks of a preset password. (The formal study can be found [here](https://www.cell.com/cell/fulltext/S0092-8674%2825%2900681-6?ref=metacurity.com).) > BCI systems translate brain signals into text or audio and have become promising tools for restoring speech in people with paralysis or limited muscle control. Most devices require users to try to speak out loud, which can be exhausting and uncomfortable. Last year, Wandelt and her colleagues developed the first BCI for decoding internal speech, which relied on signals in the supramarginal gyrus, a brain region that plays a major part in speech and language. > But there’s a risk that these internal-speech BCIs could accidentally decode sentences users never intended to utter, says Erin Kunz, a neural engineer at Stanford University in California. “We wanted to investigate this robustly,” says Kunz, who co-authored the new study. > First, Kunz and her colleagues analysed brain signals collected by microelectrodes placed in the motor cortex — the region involved in voluntary movements — of four participants. All four have trouble speaking, one because of a stroke and three because of motor neuron disease, a degeneration of the nerves that leads to loss of muscle control. The researchers instructed participants to either attempt to say a set of words or imagine saying them. > Recordings of the participants’ brain activity showed that attempted and internal speech originated in the same brain region and generated similar neural signals, but those associated with internal speech were weaker. > Next, Kunz and her colleagues used this data to train artificial-intelligence models to recognize phonemes, the smallest units of speech, in the neural recordings. The team used language models to stitch these phonemes together to form words and sentences in real time, drawn from a vocabulary of 125,000 words. > The device correctly interpreted 74% of sentences imagined by two participants who were instructed to think of specific phrases. This level of accuracy is similar to that of the team’s earlier BCI for attempted speech, says Kunz. > In some cases, the device also decoded numbers that participants imagined when they silently counted pink rectangles shown on a screen, suggesting that the BCI can detect spontaneous self-talk. ### Scapegoating the Algorithm For Asterisk Magazine, Dan Williams, Assistant Professor in Philosophy at the University of Sussex and an Associate Fellow at the Leverhulme Centre for the Future of Intelligence (CFI) at the University of Cambridge, [argues](https://asteriskmag.com/issues/11/scapegoating-the-algorithm?ref=metacurity.com) that the existential crisis America is facing isn't, as the narrative goes, caused by the inability to distinguish fact from fiction due to social media algorithms that prioritize engagement over truth, but is generated by more deeply rooted American problems. > To evaluate whether social media is responsible for America’s epistemic crisis, we must first clarify what that crisis is. And here, it is essential to note that many of America’s epistemic challenges are not new. Problems such as political ignorance, conspiracy theories, propaganda, and bitter intergroup conflict haveplagued the country throughout its history. > Research in political science has consistently documented astonishingly high rates of political ignorance among American voters. A landmark 1964 study found that most voters were unaware of basic political facts, estimating that roughly 70% were unable to identify which party controlled Congress**.** Similarly, from the Salem witch trials in the late seventeenth century to the widespread Satanic panic of the late twentieth century, false rumors, misinformation, and widespread misperceptions have been ubiquitous throughout American history. As political scientist Brendan Nyhan writes, there was never a “golden age in which political debate was based on facts and truth,” and “no systematic evidence exists to demonstrate that the prevalence of misperceptions today (while worrisome) is worse than in the past.” > Political polarization and vicious intergroup conflict have been more intense at previous stages in American history, not least during the Civil War. Although there was little polarization between the parties in the mid-twentieth century, this was a historical anomaly. It was also partially due to the parties’ shared interests in upholding a system of racial apartheid in the South. This system was, in turn, supported by widespread lies, racist myths, and censorship, from “scientific” racism painting Black people as inferior to the suppression of anti-lynching journalism. > Elite-driven disinformation has also been a pervasive force throughout American history. Both the tobacco and fossil fuel industries waged sophisticated propaganda campaigns to deny the harms caused by their products. McCarthyism involved systematic political repression based on largely fabricated communist threats. And there is nothing new about catastrophic, elite-driven epistemic failures, including their role in events as recent as the Iraq War and the 2007-08 financial crisis. > Perhaps most surprisingly, there is little evidence to suggest that rates of conspiracy theorizing have increased in prevalence in the social media age. In a recent study, political scientist Joe Uscinski and colleagues conducted four separate analyses to test for possible changes over time. They conclude: “In no instance do we observe systematic evidence for an increase in conspiracism, however operationalized.” ### How We Got the Internet All Wrong Writing for the Dispatch, German-American political scientist and author Yascha Benjamin Mounk says he [tried to balance](https://thedispatch.com/article/social-media-children-dating-neurotic/?ref=metacurity.com) the notion that social media is a terrible development for children, rewiring their brains at the expense of in-person play, against the idea that skeptics always tend to exaggerate the impact of new technologies, and catastrophize their effects until he came across results from the Understanding America Study at Stanford University. > And then I came across a truly jaw-dropping chart. > That chart, published by Financial Times journalist John Burn-Murdoch and based on his analysis of data from the extensive Understanding America Study, shows how the traits measured by the personality test most widely used in academic psychology have changed over the past decade. The OCEAN test measures five things: openness to experience, conscientiousness, extraversion, agreeableness, and neuroticism. Decades of research have demonstrated that some of these traits are highly predictive of life outcomes; in particular, conscientiousness (“the tendency to be organized, responsible, and hardworking”) predicts everything from greater professional success to a lower likelihood of getting divorced. Extroversion (a tendency to be “outgoing, gregarious, sociable, and openly expressive”) is associated with better mental health, broader social networks, and greater life satisfaction. Meanwhile, neuroticism (understood as a propensity toward anxiety, emotional instability, and negative emotion) is strongly correlated with negative outcomes, such as higher rates of depression, lower life satisfaction, and poorer overall mental health. > With these facts in mind, you will quickly realize why Burn-Murdoch’s chart demonstrates that something very, very concerning has been happening to young people. > What Burn-Murdoch shows is that the traits most strongly predictive of positive outcomes are in sharp decline. Young people, in particular, have become far less conscientious and extroverted over the past decade. Conversely, the trait most strongly associated with negative life outcomes, neuroticism, has sharply increased. To put it bluntly, the average 20-year-old today is less conscientious and more neurotic than 70 percent of all people were just a decade ago. ### Hidden Links: Analyzing Secret Families of VPN Apps Researchers from Arizona State University and CitizenLab [identified and analyzed ](https://www.petsymposium.org/foci/2025/foci-2025-0008.pdf?ref=metacurity.com)three families of VPN providers, introducing new methods for revealing how VPN providers are connected, misleading users about their ownership, and showing that they even share VPN servers’ cryptographic credentials, meaning they carry common sets of security vulnerabilities, misleading their users about how risky they are. > We identified three classes of problematic security and privacy issues with varying impacts on users. The undisclosed location collection issue is a major violation of user trust and privacy given the provider explicitly stated they did not collect such information. The client-side blind in/on-path attacks allow an attacker to infer with whom a VPN client is communicating. Most critically, on many of the VPNs we analyzed, a network eavesdropper between the VPN client and VPN server can use the hard-coded Shadowsocks password to decrypt all communications for all clients using the apps. These weaknesses nullify the privacy and security guarantees the providers claim to offer. These issues are even more concerning when accounting for the fact that the providers appear to be owned and operated by a Chinese company and have gone to great lengths to hide this fact from their 700+ million combined user bases. > The issues we identified affect users, providers, and app stores. At a minimum, VPN users who value privacy should avoid using Shadowsocks, including the apps from these developers, as Shadowsocks was not designed to facilitate privacy, merely censorship circumvention \[11\]. App store operators like Google face major challenges identifying and verifying ownership of apps on the Play Store, as well as ensuring Play Store apps are secure. Ownership identity verification and app security auditing is currently labor intensive and would require sophisticated, automated tools to achieve at scale. Google currently offers a security audit badge for VPN apps. Whether a similar badge for verified identity makes sense is debatable because there are valid reasons why a VPN provider might not want to reveal that information as it could expose them to legal or digital attack from a country or entity that opposes VPNs. Finally, VPN providers should avoid offering Shadowsocks to users or carefully explain the risks. The Shadowsocks protocol has no built-in asymmetric cryptography and requires the insecure use of hard-coded passwords, from which symmetric keys are deterministically derived, or for VPN providers to devise and implement a system for the secure distribution of these passwords. Prior work has found that home-rolled cryptographic systems commonly contain major flaws \[18–20\]. Thus, if not devised and maintained by experts, such a password distribution system would be liable for the introduction of additional security issues, and it may increase one’s vulnerability to network censorship if not carefully implemented. ### US feds crack down on Russian cryptocurrency exchange Garantex URL: https://www.metacurity.com/us-feds-crack-down-on-russian-cryptocurrency-exchange-garantex/ Last updated: 2025-08-15T13:30:46.000Z US seeks to seize $2.8m from ransomware actor's wallet, Polish city fended off likely Russian attack on water supply, Iranian hackers infiltrated former Israeli justice minister's phone, BtcTurk lost $48m in hack, Odin.fun exploited for $7m, Duo pleads guilty in stolen data pandemic fraud, much more _This post is for paying subscribers only._ ### Russian hackers suspected of sabotaging dam in Western Norway URL: https://www.metacurity.com/russian-hackers-suspected-of-sabotaging-dam-in-western-norway/ Last updated: 2025-08-14T13:59:44.000Z Canadian House of Commons is probing a 'significant' data breach, North Korean hackers unmasked by leak to ZachXBT, Court rules that FCC data breach rules are legal, US AG sues Zelle for allegedly enabling scammer fraud, UK gov't spent $3.2m to keep Afghan breach secret, much more _This post is for paying subscribers only._ ### Russia implicated in hack of federal court system documents URL: https://www.metacurity.com/russia-implicated-in-hack-of-federal-court-system-documents/ Last updated: 2025-08-13T13:25:30.000Z US has secretly placed tracking devices in advanced chips, UK will expand live police facial recognition, Microsoft fixes over 100 flaws on Patch Tuesday, Hackers issued fake nuclear warnings on Moscow buses, National Public Data comes back to life, much more _This post is for paying subscribers only._ ### US feds clawed back $1 million from BlackSuit and Royal gangs URL: https://www.metacurity.com/us-feds-clawed-back-1-million-from-blacksuit-and-royal-gangs/ Last updated: 2025-08-12T14:52:06.000Z US seeks to recoup $1m from DPRK hackers, US charges four Ghanian nationals for romance scams and BECs, Personal data of 500K cervical cancer victims stolen, FCC issues new rules for subsea data cable security, Erlang/OTP vulnerability exploited in the wild against OT networks, much more _This post is for paying subscribers only._ ### New Embargo group may be a rebranded version of ALPHV ransomware gang URL: https://www.metacurity.com/new-embargo-group-may-be-a-rebranded-version-of-alphv-ransomware-gang/ Last updated: 2025-08-11T13:55:52.000Z Russian threat group GreedyBear is stealing crypto, Israel beat Iran in the brief war's cyber conflicts, M&S resumes click and collect orders, GPT-5 was a disaster and easy to hack, Hacker breached dealership portal and could hack customers' cars, Korea's Yes24 ransomwared again, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 8/2/25 URL: https://www.metacurity.com/next-long-read-3/ Last updated: 2025-08-09T13:11:59.000Z How the Huione Group launders billions in scams and crypto heists, Fears of China spying on the UK financial system, How stolen iPhones travel around, Cyber played only an incremental role in the Israel-Iran conflict, CISA 2015 must be reauthorized, Watermarks to weed out deepfakes, more _This post is for subscribers only._ ### CISA orders agencies to deal with Microsoft Exchange fixes by Monday URL: https://www.metacurity.com/cisa-orders-agencies-to-deal-with-microsoft-exchange-fixes-by-monday/ Last updated: 2025-08-08T13:41:02.000Z Aussie gov't sues Optus for privacy violations, US confirms BlackSuit takedown, US Courts vows to take action in wake of widespread breach, Samourai Wallet founders plead guilty, White hat hackers seek to help small water systems, Bouygues Telecom suffers big breach, much more _This post is for paying subscribers only._ ### Microsoft, CISA warn of critical on-prem exchange flaw URL: https://www.metacurity.com/microsoft-cisa-warn-of-critical-on-prem-exchange-flaw/ Last updated: 2025-08-07T13:59:47.000Z Poisoned Google invite can exploit Gemini, OpenAI Connectors' weakness can extract info from Google Drive accounts, Sweeping intrusion breached US legal filing system, Deibert warns of tech fascism, NIST withheld AI report due to Trump fears, Air France and KLM hit by cyberattacks, much more _This post is for paying subscribers only._ ### Microsoft enabled Israeli spy agency's mass surveillance of Palestinians' mobile calls URL: https://www.metacurity.com/microsoft-enabled-israeli-spy-agencys-mass-surveillance-of-palestinians-mobile-calls/ Last updated: 2025-08-06T14:14:17.000Z Cisco's registered web users disclosed in a likely Salesforce breach-related vishing attack, Google confirms customer theft in Salesforce breach-related incident, Broadcom chip flaw exposes millions of Dell laptops to attack, MSFT's Project Ire can ID malware with AI, much more _This post is for paying subscribers only._ ### Ukraine claims major hack of Russian nuclear submarine URL: https://www.metacurity.com/ukraine-claims-major-hack-of-russian-nuclear-submarine/ Last updated: 2025-08-05T13:35:44.000Z SonicWall is aware of flaw exploitation, Perplexity is stealthily evading robots.txt, FinCen warns of crypt ATM crimes, Vietnamese hackers are targeting thousands of victims, Informants' data stolen in a Louisiana sheriff's office ransomware attack, Chanel hit in Salesforce breach, much more _This post is for paying subscribers only._ ### US Senate confirms Cairncross as National Cyber Director URL: https://www.metacurity.com/us-senate-confirms-cairncross-as-national-cyber-director/ Last updated: 2025-08-04T14:15:56.000Z Dutch Caribbean offices hit by cyberattacks, SharePoint was supported by Chinese engineers, Hackers stole crypto now worth $14.5b from LuBain in 2020, CISA and USCG found a bunch of OT misconfigs, CISA unveils malware analysis platform Thorium, DHS to give $100m for state and local cyber, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 7/26/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-7-26-25/ Last updated: 2025-08-02T13:34:40.000Z The scary rise of a DOGE worker to the pinnacle of power, Conti was a well-oiled criminal enterprise, China uses cyber attribution to paint Taiwan as aggressive, Illusions can bypass moderation to spread hate, US has options to counter UK demand for encryption backdoors _This post is for subscribers only._ ### Russian group Turla impersonated Kaspersky to spy on embassies URL: https://www.metacurity.com/russian-group-turla-impersonated-kaspersky-to-spy-on-embassies/ Last updated: 2025-08-01T13:31:13.000Z China accuses US of exploiting Exchange flaw to steal data and launch attacks, China grills Nvidia on AI chip security risks, Google was indexing ChatGPT conversations, UK age verification law is blocking non-porn content, Illumina to pay $9.8m to resolve US cybersecurity complaint, much more _This post is for paying subscribers only._ ### The US Army booted Easterly from West Point post to pacify a conspiracy theorist URL: https://www.metacurity.com/us-army-booted-easterly-from-west-point-post-to-pacify-a-conspiracy-theorist/ Last updated: 2025-07-31T14:11:02.000Z Big Balls got his hands on sensitive law enforcement HR and payroll systems, Fraudsters are flooding Discord with polished websites, Likely DPRK hackers stole $44m from India's CoinDCX, 90 state and local gov'ts targeted in SharePoint attacks, SSNs swiped in Allianz breach, much more _This post is for paying subscribers only._ ### Minnesota's Walz mobilizes National Guard to help with St. Paul cyberattack URL: https://www.metacurity.com/minnesotas-walz-mobilizes-national-guard-to-help-with-st-paul-cyberattack/ Last updated: 2025-07-30T14:08:21.000Z Tea suspends direct messaging and gets hit with class actions over breach, CISA to release Wyden-demanded report to unblock Plankey nomination, Google has not received UK backdoor demand, Orange breach triggers minor disruptions, Palo Alto to buy CyberArk for $25m, much more _This post is for paying subscribers only._ ### Second major security issue in the Tea app exposed user messages URL: https://www.metacurity.com/second-major-security-issue-in-the-tea-app-exposed-user-messages/ Last updated: 2025-07-29T13:13:43.000Z Aeroflot canceled more flights due to a cyberattack but claims it has stabilized, Global Group claims attacks on media giants RTÉ and Albavisión, Flaw in Gemini Command Line Interface allowed RCE, Malware was hidden in Endgame Gear peripherals, Senate to take up Plankey nom, much more _This post is for paying subscribers only._ ### Aeroflot grounded by 'crippling cyberattack' as Silent Crow takes credit URL: https://www.metacurity.com/aeroflot-grounded-by-crippling-cyberattack-as-silent-crow-takes-credit/ Last updated: 2025-07-28T13:05:22.000Z Microsoft probes early alert system leak tied to SharePoint hacks, Women’s Tea app hit with photo leak, Allianz Life confirms major data breach, Hackers claim Naval Group breach, US senator urges Musk to block SpaceX cyberscammers, much more. _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 7/19/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-7-19-25/ Last updated: 2025-07-26T13:05:19.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/07/pexels-taryn-elliott-5858998-1.jpg) Photo by [Taryn Elliott](https://www.pexels.com/photo/person-holding-a-book-5858998/?ref=metacurity.com) *Happy Saturday morning! Metacurity is pleased to offer our free and premium subscribers this weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush. So tell us what you think, and feel free to share your favorite long reads via email at* *info@metacurity.com* *.* --- **Please consider supporting Metacurity** Thank you so much for supporting Metacurity with your readership. But please consider stepping up your support so that Metacurity can continue to provide you with our weekday updates on the pressing infosec developments you need to know to navigate the complex digital security arena, alongside this weekly selection of infosec-related long reads. Upgrading to a paid subscription will help us keep the lights on. We also provide corporate subscription options, and soon we’ll be introducing affordable sponsorship opportunities—perfect for promoting your events or products to a highly engaged audience. To learn more, feel free to reach out at cynthia@metacurity.com. Thank you so much for being part of the Metacurity community. [Upgrade my subscription!](#/portal/account/plans) --- ### Confessions of a Laptop Farmer: How an American Helped North Korea’s Wild Remote Worker Scheme Bloomberg Businessweek's Evan Ratliff [tells the story](https://www.bloomberg.com/news/features/2025-07-24/north-korea-infiltrated-america-by-taking-remote-us-it-jobs?ref=metacurity.com) of fake North Korean IT workers who mask themselves to work in America and how a desperate woman, Christina Marie Chapman, got roped into becoming a "laptop farmer" for them, providing geographic cover by making it appear as if they were working on US soil, only to end up with a 102-month prison sentence for her role in the fraudulent scheme. > The authorities still hadn’t tuned in as of summer 2023, but Chapman increasingly feared they might. That August she complained to her colleagues about their ongoing requests for her to fill out employment forms. “\[I\]n the future, I hope you guys can find other people to do your physical I9s,” she wrote in a group chat. “These are federal documents. I will SEND them for you, but have someone else do the paperwork. I can go to FEDERAL PRISON for falsifying federal documents.” She remembers getting a call that same month from a California company she’d returned a laptop to when a remote worker lost their job. They were asking why this was the second laptop she’d returned to it on someone else’s behalf. Chapman says she quickly got off the phone and didn’t hear from the company again. > By now, she’d begun to find her co-workers menacing. One, she recalls, said he was going to move in with her “to make sure that I stayed in line.” Another sent a local “friend” to pick up a laptop from her house—he didn’t need to ask for the address. She left it on the doorstep and hid inside. She says she approached a lawyer to find out how to untangle herself from the company, but the lawyer required a $10,000 retainer up front. Instead she hired two “assistants” by the hour from Craigslist to help her get into some other line of work. > By then it was already too late. That September, the FBI received a tip from Palo Alto Networks about a company that had unknowingly hired North Koreans. Soon after, the security firm published a blog post outlining the tactics being used in such campaigns. In court documents, the victim company isn’t named. But recently, examining a search warrant application in a separate case that described the victim and the blog post in succession, I uncovered a surprising detail—confirmed by a source with knowledge of the events, who spoke on condition of anonymity because they weren’t authorized to discuss them publicly. The victim wasn’t a client of Palo Alto Networks. It was Palo Alto Networks itself. > According to the warrant application, Palo Alto had received a warning from another company where one of its contractors had gone on to work, telling the security firm that this contractor had recently updated his LinkedIn profile from a North Korean IP address. When Palo Alto dug further, it discovered that this worker appeared to be one of at least nine North Koreans it had brought in through a staffing company. Three of them, it found, had used computers shipped to Chapman’s Arizona address. (Palo Alto facilitated my interviews with its researcher Evan Gordenker earlier this year without mentioning its role in the case. After I asked for comment about Palo Alto itself being a victim, the company stopped responding.) > In late 2023, Chapman took a trip to California to attend a concert—as she’d done to Japan a few months before—briefly leaving her Craigslist assistants in charge of her laptop farm. While she was away, one of the women messaged to tell her that FBI agents were at her house. “The bottom fell out of my world,” she says. She messaged Zhonghua, who told her to delete everything on her phone. She says she started to, then thought better of it. At her house, the FBI discovered more than 90 computers, all being operated remotely. > Agents met Chapman coming off her plane home and confiscated her devices but didn’t arrest her. The next day, she says, the FBI interviewed her for an hour and a half at her house without a lawyer present. She says they never mentioned North Korea or raised the possibility of her cooperating to lead them back to Zhonghua and the others. “I would have helped in a heartbeat,” she says, “after everything they put me through.” Pirro, the interim US attorney, declined to comment. > A month later, Palo Alto Networks researchers happened to discover a cache of documents that North Korean IT workers had left exposed on GitHub, according to the firm’s blog post. Among these, they found, were “résumés with fake identities, impersonating individuals of various nationalities” and “copies of IT job opening posts from US companies.” Several of the documents—which contained Korean-language passwords, some including words used only in North Korea—showed jobs the authors had actually obtained. Three of those gigs, according to the search warrant application, “were later tied through business records to the computers found in Chapman’s residence.” ### The Amnban Files: Inside Iran's Cyber-Espionage Factory Targeting Global Airlines UK-based Iranian opposition activist and independent cyber espionage investigator Nariman Gharib [delves into](https://blog.narimangharib.com/posts/2025%2F07%2F1752917718209?lang=en&ref=metacurity.com) the Amnban Files, gigabytes of data stolen from internal servers of Amnban, Sharif Advanced Technologies, which he calls Tehran's "digital hit squad," revealing how the state-sponsored operation is harvesting millions of airline passengers' personal data for Iran's intelligence machine. > The breach cracked open their entire operation. Behind the legitimate facade of penetration testing and security consulting lurks something sinister. These aren't consultants—they're cyber mercenaries working for APT39, the notorious hacking group tied directly to Iran's Ministry of Intelligence and Security (MOIS). > The evidence is overwhelming: systematic attacks on Royal Jordanian, Turkish Airlines, Rwanda Airlines, Wizz Air, and nearly a dozen other carriers. This isn't security research. It's preparation for digital warfare. > **The Intelligence Connection Exposed** > Every authoritarian regime needs its digital soldiers. Iran's cyber-espionage units conduct what they call Cyber Network Exploitation (CNE)—spy speak for breaking into foreign networks to steal intelligence. But it doesn't stop at data theft. These operations enable Cyber Network Attacks (CNA) designed to cripple infrastructure, crash airport systems, and worse. > APT39, also known as Chafer, is MOIS's favorite attack dog. They don't chase money—they hunt intelligence on foreign airlines, government systems, telecommunications companies. Jordan. Turkey. UAE. If you're flying through the Middle East, you're in their crosshairs. > Here's where it gets personal: Amnban's CEO is Benham Amiri, already flagged by intelligence agencies for APT39 connections. > But Amiri went further—he actually hired Ali Kamali, a hacker so toxic the FBI sanctioned him in 2020 for attacking American infrastructure. This isn't hiding in the shadows. This is brazen. ### Myanmar’s Digital Crackdown is Worsening: The World is Stepping Back For Tech Policy Press, Wai Phyo Myint, the Asia Pacific Policy Analyst, and Faiz Naeem, the Asia Pacific Program Associate at Access Now, [underscor](https://www.techpolicy.press/myanmars-digital-crackdown-is-worsening-the-world-is-stepping-back/?ref=metacurity.com)e how a digital crisis is unfolding in Myanmar as the junta ramps up communications blackouts, surveillance systems, biometric ID schemes, and social media manipulation at the same time as allies such as Thailand and the US are cutting off support for exiled activists, independent media and civil society. > The military has continued to expand its digital surveillance capabilities. At the core of this new regime is what civil society monitors refer to as the Personal Scrutinization and Monitoring System. This is believed to be a centralized military-run database that collects information on people’s location history, criminal records, financial activity, and more. > A key part of this system is the electronic identification card, or e-ID. The junta maintains that the e-ID is required only for specific purposes, such as applying for a passport or certain types of labor permits. But civil society groups have documented a steady increase in coercion. Workers are being pushed to enroll in the e-ID system or risk losing access to employment, social security benefits, and freedom of movement. Although there is no official mandate requiring all citizens to register, in practice, refusal to enroll increasingly leads to exclusion. > Once issued, the e-ID links the holder to a vast array of databases. With a single scan, authorities are reportedly able to pull up an individual’s personal history, including political affiliations, past arrests, and other sensitive details. The entire surveillance apparatus mirrors India’s Aadhaar biometric ID system. It was reported that members of Aadhaar's technical team provided expertise to the junta on biometric scanners — raising concerns about India's involvement in the military's surveillance infrastructure. ### The U.K.’s Decryption Order, the CLOUD Act, and Recommended Next Steps In Lawfare, Jennifer Daskal, partner at Venable LLP,[ points out](https://www.lawfaremedia.org/article/the-u.k.-s-decryption-order--the-cloud-act--and-recommended-next-steps?ref=metacurity.com) that despite promising press reports, the UK government has not yet in fact fully backtracked on its case against Apple in which it demanded the company provide an encryption backdoor to its cloud services, suggesting ways for the United States to use the Clarifying Lawful Overseas Use of Data Act (CLOUD) to push the UK into finally abandoning its anti-security crusade. > It appears, based on recent reporting that—thanks to push-back from the Trump administration—the UK may be looking to change course. But for now, the UK case against Apple continues. The following describes ways the administration could use the CLOUD Act as additional leverage in these discussions, and suggests statutory amendments to the CLOUD Act that would help protect against additional foreign government decryption mandates in the future. > There are several possible ways for both the executive branch and Congress to respond: > The Department of Justice has the authority to object to CLOUD Act orders and categories of such orders; it could object to any orders issued to any company that has been subject to a decryption mandate. Doing so would, under the terms of the agreement, render such orders null and void. > The U.S.-U.K. agreement specifies two different ways that the Justice Department might do so: Following an objection by a provider, it can invoke section 5, par.11 with respect to specific “Order\[s\];” alternatively, under section 12, par. 3, it can object to a whole category of “Legal Process.” The Justice Department need simply notify the relevant authority in the U.K. of its objection, and the U.K. can no longer rely on the CLOUD Act to issue relevant orders or categories of such orders. > There is strong ground for raising an objection with respect to the UK-issued orders: There is an explicit statutory requirement saying that executive agreements shall not create any obligation that providers be capable of decrypting data. Indeed, Congress would not advance the CLOUD Act until that provision was added to the bill. Any order that is coupled with a decryption demand certainly violates the spirit, if not the letter, of the CLOUD Act and the U.S.-U.K. agreement. > The executive branch could threaten to pull the U.S.-U.K. agreement entirely if the U.K. continues to use its Investigatory Powers Act to seek to prohibit the use of end-to-end encryption. Given the reported security benefits of the CLOUD Act agreement, this might be sufficient to compel a change in the U.K. approach. > To terminate the agreement, the United States simply needs to send a diplomatic note to that effect; termination takes effect a month later. (Alternatively, the U.S. could refuse to renew the agreement when it expires in 2027, but that is too long from now given the immediacy of the dispute with the U.K.) An updated agreement should make clear that the U.K. is prohibited from issuing decryption orders to U.S. companies and that continued issuance of such orders will render the agreement null and void. > Congress can also require these changes. Congress could, for example, amend the criteria for CLOUD Act agreements to specify that foreign governments that issue extraterritorial decryption orders on U.S. companies are ineligible for such agreements. This would prevent the U.K. or any other country from relying on a combination of their domestic law and a CLOUD Act agreement to support decryption efforts. In fact, even if the dispute with the UK is resolved, Congress may wish to also intervene to prevent this from becoming an issue with other countries. ### This ‘violently racist’ hacker claims to be the source of The New York Times’ Mamdani scoop The Verge's Elizabeth Lopatto [tells the story](https://www.theverge.com/cyber-security/710480/columbia-hacker-nazi-nyt-affirmative-action?ref=metacurity.com) of a virulently racist hacker she calls the Anime Nazi who has taken credit for hacking three universities, University of Minnesota, New York University, and Columbia University, the latter of which became famous when the New York Times published the admissions application of the current Democratic nominee for mayor of New York City. > The alleged hacker, in response to a request for comment, wrote that this story wouldn’t achieve anything but making The Verge look ridiculous and “giving funny publicity to me.” Most journalists, they claimed, “are smart enough to figure that out before publishing, so end up removing my name and any direct references to me.” They added, in a separate email, “My comment: her name is \[slur\].” > In what little reporting exists about the actual Columbia breach (and not what stolen data reveal about a mayoral candidate when he was 17 years old), the hacker has been said to be “politically motivated.” Bloomberg, which spoke to the hacker, reported that they are acquiring information about whether universities persisted in affirmative action admissions after the Supreme Court effectively banned the practice in 2023\. Insofar as open racism can be said to be a political motivation, the hacker is indeed politically motivated. But it also has the effect of soft-pedaling the reason for repeated attacks on institutions of higher learning. The Anime Nazi is an activist like a Klansman is an activist. > This is important because journalistic best practices around the use of hacked materials is to contextualize the hacker’s motivation, if the materials are used at all. While it appears to be true that the hacker opposes affirmative action, it may be more relevant — particularly when the news article in question attacks a left-wing politician of color — that the hacker’s pseudonym is literally a racist slur. > The hacker says they redact SSNs and other personally identifying data before releasing information from the intrusions. In the case of the Minnesota hack, they claim, “I only posted (redacted) bare minimum to prove they’re breaking the law.” One of their admirers has claimed they are “the nicest possible hacker.” The redactions in the New York University data were imperfect, however, says Zack Ganot, the CEO of DataBreach.com. “He says he’s not trying to leak personal information,” Ganot says. “He did a lousy job.” Emails, names, and home addresses, among other personal identifying information, are available in the data from the NYU leak. > Ganot notes that the data is valuable; to his knowledge, the hacker hasn’t yet sold it. This isn’t necessarily surprising — that’s not the kind of damage they’re trying to do — but it also doesn’t mean the data is safe. > This alleged hacker’s racial animus aligns with the recent Republican war on higher education. It also aligns with a turn from certain Silicon Valley circles against elite universities. Universities aren’t just politically endangered — they are, in the hacker’s own words, “soft targets.” > “Universities have basically the most vulnerable networks that exist in my experience,” the Anime Nazi wrote. “Massive networks with huge surface area and a lot of legacy systems.” They also generally spend less on security than private companies. Unless the hacker is caught or America’s universities seriously upgrade their security quickly, the Anime Nazi could very well strike again. ### Quantum Scientists Have Built a New Math of Cryptography Quanta magazine's Ben Brubaker interprets the complex concepts behind a [new paper](https://arxiv.org/abs/2409.15248?ref=metacurity.com) by two cryptographers that proposes how quantum cryptography can be put on a much firmer theoretical footing than practically any kind of classical cryptography. > In the fall of 2022, that question caught the attention of Dakshita Khurana, a cryptographer at the University of Illinois at Urbana-Champaign and NTT Research. Khurana and her graduate student Kabir Tomer set out to build a new tower of cryptography. Her first step was to build a new foundation using quantum building blocks instead of classical one-way functions. She would then need to prove that this new foundation could support a tower of other cryptographic protocols. Once she proved that the foundation could support the tower, she would have to find a solid place for the whole thing to sit — a bedrock of real-world problems that seem even harder than the NP problems used in classical cryptography. > For the first step, Khurana and Tomer focused on a quantum version of a one-way function, called a one-way state generator, that satisfied the three properties that make one-way functions useful. First, the function must run quickly so that you can easily generate a cryptographic lock and the corresponding key to open it for each message you want to send. Second, each lock must be secure, requiring great effort to break open without the right key. Finally, every lock must be easy to open with the right key. > The crucial difference lay in the nature of the locks. Classical one-way functions generate mathematical locks made of bits — the 0s and 1s that store information in a classical computer. Quantum one-way state generators would instead generate locks made of units of quantum information called qubits. These quantum locks could potentially remain secure even if all classical locks are easy to break. Khurana and Tomer hoped to start with this new quantum foundation and build a tower of cryptographic protocols on top of it. “This turned out to be quite hard,” Khurana said. “We were stuck for many, many months.” > By July 2023, Khurana was nearly nine months pregnant and planning for parental leave. Tomer was out of ideas. “I’m much more pessimistic than Dakshita,” he said. “She’s always the one who believes that things will work.” > Then they made a breakthrough. The crucial step was defining another mathematical building block that served as something like a basement floor: a structure that would connect the foundation of one-way state generators to a tower of cryptographic protocols. When Khurana and Tomer worked out what properties that building block would need to have, they found that it resembled a one-way function with a perplexing mixture of quantum and classical characteristics. As in an ordinary one-way function, both locks and keys were made of classical bits, but the procedure for generating these locks and keys would only run on a quantum computer. Stranger still, the new building block satisfied the first two defining properties of one-way functions, but not the third: It was easy to generate locks and keys, and every lock was hard to break. But a key wouldn’t easily open its lock. ### Operation Checkmate seized the BlackSuit ransomware sites URL: https://www.metacurity.com/operation-checkmate-seized-sites-of-blacksuit-ransomware-operation/ Last updated: 2025-07-25T13:11:30.000Z US sanctions three DPRK officials involved in worker schemes, AZ woman sentenced to 8+ years for hosting DPRK laptop farm, Plankey promises to pitch for more CISA funding, UK student sentenced to 7 years for distributing phishing kits, Hackers stole info from CIA spy satellite arm, much more _This post is for paying subscribers only._ ### SharePoint attacks hit 400 organizations, campaign now includes ransomware URL: https://www.metacurity.com/sharepoint-attacks-hit-400-organizations-campaign-now-includes-ransomware/ Last updated: 2025-07-24T13:19:12.000Z French cops bust xss.is admin and shutter the platform, Trump's AI action plan boosts Silicon Valley powerhouses, AZ state hackers likely behind other breach efforts, Hacker installed wiper software in Amazon's AI Q assistant, Old Ivanti flaws plague Japan, much more _This post is for paying subscribers only._ ### US agency overseeing cache of nuclear weapons was breached in SharePoint attack URL: https://www.metacurity.com/us-agency-overseeing-cache-of-nuclear-weapons-was-breached-in-sharepoint-attack/ Last updated: 2025-07-23T13:27:54.000Z Funding for critical infrastructure cyber threat detection has expired, Iranians received Apple spyware warnings, OpenAI founder warns of AI fraud crisis, Clorox claims IT provider gave hackers employee passwords, Feds warn of Interlock ransomware, IVF records posted on dark web, much more _This post is for paying subscribers only._ ### Three Chinese threat groups exploited SharePoint flaws, Microsoft URL: https://www.metacurity.com/three-chinese-threat-groups-exploited-sharepoint-flaws-microsoft/ Last updated: 2025-07-22T14:10:12.000Z Businesses will have to report ransom payments in UK, AZ election officials blast CISA after Iran site defacement, Dutch public prosecutors disconnected after suspected hack, SoCal engineer pleads guilty to missile-related blueprints theft, Aussie body sues Fortnum for client data theft, much more _This post is for paying subscribers only._ ### SharePoint server software security flaw sparked global attacks URL: https://www.metacurity.com/sharepoint-server-software-security-flaw-sparked-global-attacks/ Last updated: 2025-07-21T14:28:20.000Z France probes Musk's X over fraudulent data extraction, UK backtracks on encryption backdoors, Microsoft to stop Chinese digital escorts, Russia is kicking WhatsApp out, 419k impacted by Louis Vuitton Hong Kong breach, UNC3886 hit Singapore with cyberattack, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 7/12/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-7-12-25/ Last updated: 2025-07-19T14:44:42.000Z Microsoft's Chinese "Digital Escorts" are a huge threat to DoD's digital security, Myanmar's scam centers are proliferating rapidly, Are VCs unpatriotic for investing in Chinese AI?, Afghanistan's extensive data systems need proper governance, AI can't replace humans in bug hunting _This post is for subscribers only._ ### Data on UK SAS forces and MI6 officers exposed in massive Afghan leak URL: https://www.metacurity.com/data-on-uk-sas-forces-and-mi6-officers-exposed-in-massive-afghan-leak/ Last updated: 2025-07-25T20:34:25.000Z Google sues BadBox 2.0 ops, Salt Typhoon continues telco targeting, Paradox.ai developer used password of 123456 for Fortune 500 customers, EU sanctions Russians for disinformation campaigns, Qantas gains order blocking release of stolen data, FCC to bar Chinese kit from undersea cables, much more _This post is for paying subscribers only._ ### Cops bust up NoName057(16) by seizing servers, issuing warrants, and raiding homes URL: https://www.metacurity.com/cops-bust-up-noname057-16-by-seizing-servers-issuing-warrants-and-raiding-homes/ Last updated: 2025-07-17T12:15:47.000Z 6.5m Co-op members' data were stolen, Cambodia busts 1k for cybercrime, Thai police raid Cambodian tycoon's homes in scam probe, DoJ busts one and charges three other alleged Ryuk actors, Aussie right-wing party hit by ransomware, China cyberspies on Taiwan's semiconductor industry, much more _This post is for paying subscribers only._ ### Salt Typhoon 'extensively' compromised a state national guard network for months URL: https://www.metacurity.com/salt-typhoon-extensively-compromised-a-state-national-guard-network-for-months/ Last updated: 2025-07-16T14:15:08.000Z Former US army soldier pleads guilty to hacking telcos, Ukraine claims hack of big Russian drone maker, Korean insurance giant hit by ransomware attack, Trump's bill offers $1b spend on offensive cyber, Abacus Market goes dark after suspected rug pull, AsyncRAT has spawned 30+ forks, much more _This post is for paying subscribers only._ ### UK to spend $1.1 billion relocating Afghan helpers following data breach URL: https://www.metacurity.com/uk-to-spend-1-1-billion-relocating-afghan-helpers-following-data-breach/ Last updated: 2025-07-15T13:49:50.000Z DOGE worker published the private key for four dozen-plus LLMs, US gov't IT contractor to pay $14.75m fine for overstated cyber services, Italian cops arrest Romanian behind 'Diskstation' ransomware gang, OMB readies post-quantum standard, MSFT's 'digital escorts' leave DoD vulnerable, much more _This post is for paying subscribers only._ ### Suspected Chinese hackers breach top telco law firm URL: https://www.metacurity.com/suspected-chinese-hackers-breach-top-telco-law-firm/ Last updated: 2025-07-14T13:09:54.000Z 13 Romanians busted for phishing UK revenue & customs office, Hacker shares racist & antisemitic posts on Elmo's X account, Flaw can trigger train emergency break, DoJ tries to recoup Trump boosters' stolen crypto, Google Gemini for Workspace flaw enables malicious instructions, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the weeks of 6/28/25 and 7/5/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-weeks-of-6-28-25-and-7-5-25/ Last updated: 2025-07-12T12:16:11.000Z Satellite jamming and spoofing sets back global shipping, AI is inherently janky, Salvadoran gender freedom advocates fight oppression with digital training, Sector arises to fight AI false positives in Chinese universities, Uncovering the venality of a nudify app, so much more _This post is for subscribers only._ ### Parliament committee says UK is a hacking priority for Iran URL: https://www.metacurity.com/parliament-committee-says-uk-is-a-hacking-priority-for-iran/ Last updated: 2025-07-11T14:03:59.000Z Mexico AG launches probe into alleged NSO Group bribes of former president, Pakistan arrests 150 in cybercrime crackdown, Rowhammer attacks against GPUs are possible, Hackers exploit Wing FTP Server file flaws, Thief returns 90% of $2.2m swiped from Texture Finance, much more _This post is for paying subscribers only._ ### UK's NCA arrested four people for M&S, Co-Op cyberattacks URL: https://www.metacurity.com/uks-nca-arrested-four-people-for-m-s-co-op-cyberattacks/ Last updated: 2025-07-10T14:25:51.000Z Russian hoops player Kasatkin busted in France in connection with ransomware, McDonald's employee chatbot was riddled with absurd flaws, Hackers stole $40m from GMX protocol, Customer data exposed in Bitcoin Depot breach, Hackers run scam messages in old Mt. Gox wallets, much more _This post is for paying subscribers only._ ### M&S and Qantas leaders remain mum on ransomware payments URL: https://www.metacurity.com/m-s-and-qantas-leaders-remain-mum-on-ransomware-payments/ Last updated: 2025-07-09T13:15:58.000Z M&S chairman says two other British companies' ransomware attacks have gone unreported, 5.7m customers impacted by Qantas attack, US sanctions DPRK man for IT worker scheme, DoJ seeks to bring COVID hacker to US, Rubio impersonated in AI voice effort, MSFT patches 137+ flaws, much more _This post is for paying subscribers only._ ### Italian cops arrest FBI-wanted Chinese hacker who tried to steal the COVID-19 vaccine URL: https://www.metacurity.com/italian-cops-arrest-fbi-wanted-chinese-hacker-who-tgried-to-steal-covid-19-vaccine/ Last updated: 2025-07-08T12:33:40.000Z Brazilian cops bust IT worker connected to $100m banking systems hack, Call of Duty: WWII yanked offline after RCE rumors, OpenAI beefs up corporate spying protections, DragonForce battles RansomHub, Cambodia accuses Thai hackers of attacks, Trump's tax bill contains cyber money, much more _This post is for paying subscribers only._ ### IT giant Ingram Micro's systems shut down after SafePay ransomware attack URL: https://www.metacurity.com/it-giant-ingram-micros-systems-shut-down-after-safepay-ransomware-attack/ Last updated: 2025-07-07T13:27:23.000Z Qantas is talking with threat actor after attack, Android spyware flaw exposes thousands of customers, Ransomware negotiator may have struck deals with hackers, US sanctions bulletproof hoster, US goes after DRPK "IT worker" program, A racist hacked Columbia and the NYT shamed itself, much more _This post is for paying subscribers only._ ### Feds raid 29 North Korean laptop farms used to infiltrate US companies URL: https://www.metacurity.com/feds-raid-29-north-korean-laptop-farms-used-to-infiltrate-us-companies/ Last updated: 2025-07-01T12:36:14.000Z US feds re-up Iranian hacking warning, Europol busts $540m fraud ring, Iranian-linked Robert threatens to release Trump emails, ICC hit by 'sophisticated' cyberattack, Treasury Dept. hit by three big hacks in past five years, Wyden says FBI fails to protect Capitol Hill mobiles, much more _This post is for paying subscribers only._ ### Airlines, transportation sector are Scattered Spider's latest targets URL: https://www.metacurity.com/airlines-transportation-sector-are-scattered-spiders-latest-targets/ Last updated: 2025-06-30T12:55:43.000Z Sinaloa cartel used hacked phone records and surveillance cameras to help kill FBI informants, Germany orders Apple and Google to remove DeepSeek from app stores, Fake US bank accounts fuel romance scam industry, Trump builds giant US citizen database, Canada orders Hikvision to shut down, more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 6/21/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-6-21-25/ Last updated: 2025-06-28T13:22:24.000Z Will the US rival China in dystopian surveillance?, Trump cedes disinformation territory to US adversaries, When piracy tools cause infrastructure threats, AI is wearing down democracy, AI engineers who get paid $100 million, How a VA breach changed the federal gov't _This post is for subscribers only._ ### Cyber incident disrupts Hawaiian Airlines, but flights are unaffected URL: https://www.metacurity.com/cyber-incident-disrupts-hawaiian-airlines-but-flights-are-unaffected/ Last updated: 2025-06-27T12:51:11.000Z Food distributor UNFI restores operations, Danish gov't wants people to own copyrights to their bodies, faces and voices, N. Korea is automating crypto theft with AI tools, Pro-Iranian hacktivists leaked Saudi Games records, Cambodia has been negligent in cybercrime compound crackdowns, much more _This post is for paying subscribers only._ ### French cops busted BreachForum, IntelBroker operators URL: https://www.metacurity.com/french-cops-busted-breachforum-intelbroker-operators/ Last updated: 2025-06-27T09:15:21.000Z Qilin gang ransomware attack killed an NHS patient, Glasgow City Council hit by ransomware attack, Western Sydney University student arrested for school database hacking, Liberal Party hacked after pro-women messaging, Columbia University probes security incident, much more _This post is for paying subscribers only._ ### Cyber insurance premiums dropped for the first time in 2024 URL: https://www.metacurity.com/cyber-insurance-premiums-dropped-for-the-first-time-in-2024/ Last updated: 2025-06-25T13:48:21.000Z CyberAv3ngers shift to psychological manipulation, Another hacker hits Paraguay, 50% of ransomware payments are less than expected, Pro-Russian group was reportedly behind Norwegian dam hack, UK 2025 strategy calls for stronger cyber capabilities, Hackers abuse Trezor's support form, much more _This post is for paying subscribers only._ ### US House of Representatives bans WhatsApp on security grounds URL: https://www.metacurity.com/us-house-of-representatives-bans-whatsapp-on-security-grounds/ Last updated: 2025-06-24T12:49:00.000Z ![a view of the capitol building from across the street](https://images.unsplash.com/photo-1688417486307-03562424784d?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDJ8fFVTJTIwSG91c2UlMjBvZiUyMFJlcHJlc2VudGF0aXZlc3xlbnwwfHx8fDE3NTA3NjgxNDl8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Tim Mossholder](https://unsplash.com/@timmossholder?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) *Don't miss my latest CSO piece that* [*examines*](https://www.csoonline.com/article/4011379/iranian-cyber-threats-overhyped-but-cisos-cant-afford-to-let-down-their-guard.html?ref=metacurity.com) *how the Iranian cyber threat has been overhyped, and despite a supposed cease-fire between Israel and Iran, CISOs still need to protect their organizations from the Iranian threats that do exist.* --- *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can!](#/portal/support) --- ### The US House's chief administrative officer (CAO) informed congressional staffers that the messaging app WhatsApp is banned on their government devices. "The Office of Cybersecurity has deemed WhatsApp a high-risk to users due to the lack of transparency in how it protects user data, absence of stored data encryption, and potential security risks involved with its use," the CAO said in an email. The CAO said that Microsoft Teams, Wickr, Signal, iMessage, and FaceTime are all acceptable alternatives to WhatsApp. Andy Stone, a spokesperson for WhatsApp parent company Meta, said, "We disagree with the House Chief Administrative Officer's characterization in the strongest possible terms." We know members and their staffs regularly use WhatsApp and we look forward to ensuring members of the House can join their Senate counterparts in doing so officially," Stone said. ([Andrew Solender / Axios](https://www.axios.com/2025/06/23/whatsapp-house-congress-staffers-messaging-app?stream=politics&utm%5Fsource=alert&utm%5Fmedium=email&utm%5Fcampaign=alerts%5Fpolitics)) **Related:** [*The Verge*](https://www.theverge.com/news/691288/house-of-representatives-whatsapp-ban-meta?utm%5Fcontent=buffer8621b&utm%5Fmedium=social&utm%5Fsource=bsky.app&utm%5Fcampaign=verge%5Fsocial)*,* [*CNBC*](https://www.cnbc.com/2025/06/23/meta-whatsapp-us-house.html?ref=metacurity.com#:~:text=The%20chief%20administrative%20officer%20of,data%20privacy%20and%20security%20practices.)*,* [*The Guardian*](https://www.theguardian.com/technology/2025/jun/23/whatsapp-ban-house-representatives?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/world/us/whatsapp-banned-us-house-representatives-devices-memo-2025-06-23/?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/95e21b39-08af-47cc-8a9c-5e4f34508003?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2025/06/23/meta-hits-back-us-house-bans-whatsapp-staffers/?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/policy/technology/5365017-whatsapp-banned-congressional-staffers/?ref=metacurity.com)*,* [*Social Media Today*](https://www.socialmediatoday.com/news/whatsapp-banned-us-house-staff-devices-security-concerns/751431/?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/big-tech/us-house-reportedly-bans-whatsapp-on-government-devices-161557444.html?ref=metacurity.com)*,* [*Mashable*](https://mashable.com/article/whatsapp-us-government-ban-meta?ref=metacurity.com)*,* [*MediaPost*](https://www.mediapost.com/publications/article/406898/whatsapp-banned-for-house-of-representatives-staff.html?ref=metacurity.com)*,* [*EuroWeekly News*](https://euroweeklynews.com/2025/06/23/if-us-lawmakers-ban-use-of-whatsapp-shouldnt-we-all/?mid=1&ref=metacurity.com#cid=2932339)*,* [*WebProNews*](https://www.webpronews.com/u-s-house-bans-whatsapp-on-government-devices-over-risks/?ref=metacurity.com) ### Top Pentagon officials said that US Cyber Command played a role in the American military’s operation against Iranian nuclear facilities over the weekend. “The strike package was supported by US Strategic Command, US Transportation Command, US Cyber Command, US Space Command, US Space Force and US European command,” Gen. Dan Caine, chairman of the Joint Chiefs of Staff, told reporters in a briefing at the Pentagon Sunday morning, later thanking the cyber operators, among others, who made the mission possible. Although details about Cybercom’s assistance with Operation Midnight Hammer, the code name for the strikes, remain murky, experts outlined several possibilities for how the organization may have contributed to the effort. One former official said one of the most likely ways Cybercom would have aided the operation is through something akin to a cyber escort package. With air assets coming from all over the world and various commands, such as Transportation Command, European Command, Central Command, and the Air Force’s Global Strike Command, it is essential to ensure that those aircraft and enabling functions execute missions smoothly. ([Mark Pomerleau / DefenseScoop](https://defensescoop.com/2025/06/23/cyber-command-supports-attack-iran-nuclear-facilities-midnight-hammer/?ref=metacurity.com)) **Related:** [*WRDW*](https://www.wrdw.com/2025/06/23/this-was-done-very-well-local-professor-weighs-israel-iran-conflict/?ref=metacurity.com)*,* [*The Independent*](https://www.independent.co.uk/news/world/americas/us-politics/trump-bombs-iran-midnight-hammer-b2774686.html?ref=metacurity.com) ### Researchers at Ellptic report that since last month, when Telegram summarily beheaded the online industry of Chinese-language crypto scam services such as Haowang Guarantee and Xinbi Guarantee, it has watched impassively as those black marketeers rebranded, rebuilt, and returned to business as usual on the messaging service's platform. Before Telegram banned the two markets' channels and usernames on May 13, they had together enabled a staggering $35 billion in transactions, much of which represented money laundering by crypto scam operations that steal billions from Western victims and force tens of thousands of people to carry out scams in forced labor compounds across Cambodia, Myanmar, and Laos. In particular, one market called Tudou Guarantee, partially owned by Huione Group, the same parent company as the now-defunct Haowang Guarantee, has more than doubled in size. It likely takes in many of the scammer-friendly services displaced by Telegram's bans and again enables those fraudsters' billions of dollars a year in illicit revenue. By Elliptic's count, its main channel now has 289,000 users, close to the 296,000 users that Haowang Guarantee had at the time Telegram banned it. Xinbi Guarantee, too, has relaunched on new channels and regained hundreds of thousands of users, Elliptic says. In terms of sales, Tudou is now enabling around $15 million a day in crypto payments, close to the $16.4 million Haowang was facilitating daily, according to Elliptic. ([Andy Greenberg / Wired](https://www.wired.com/story/telegram-purged-chinese-crypto-scam-markets-then-let-them-rebuild/?ref=metacurity.com)) **Related:** [*Elliptic*](https://www.elliptic.co/blog/telegram-dark-markets-expand-to-fill-the-gap-left-by-huione-guarantee?ref=metacurity.com)*,* [*Cryptoslate*](https://cryptoslate.com/dark-market-activity-on-telegram-persists-despite-27b-huione-ban-elliptic/?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/darknet-marketplaces-thriving-after-huione-shutdown?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/crypto-darknet-markets-surge-on-telegram-after-huione-guarantee-shutdown-report/?ref=metacurity.com)*,* [*Decrypt*](https://decrypt.co/326653/crypto-scam-markets-thrive-telegram?ref=metacurity.com)*,* [*CCN*](https://www.ccn.com/news/technology/telegram-shuts-down-crypto-black-market/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/06/image-92.png) User numbers of select guarantee marketplaces, following the shutdown of Huione Guarantee. Elliptic is tracking over thirty highly-active Telegram-based guarantee markets. Source: Elliptic. ### Ahead of NATO's annual summit in The Hague today, officials are boosting defenses against drones and cyberattacks and plan to support these measures alongside traditional military options. “If World War III breaks out on the European continent, what’s the first shot?” US Ambassador to NATO Matthew Whitaker recently said. “Is it going to be Russian tanks invading Poland, or is it going to be a cyberattack on one of our allies, or a challenge on some infrastructure?” One thing no commander wants to run out of is options, a military adage holds, and adversaries have more ways than ever of foreclosing options. Planners must consider wild cards from old-style sabotage to innovation, including cyberattacks and drone strikes. “If China can shut off the power to our data centers, then maybe they don’t need to sink our aircraft carriers,” said retired Army Lt. Gen. Douglas Lute, a former US ambassador to NATO. Separately, the Dutch government announced that pro-Russian hackers launched a series of denial-of-service attacks on several municipalities and organizations linked to the NATO summit. The National Cybersecurity Center said that many attacks were claimed by a pro-Russian hackers’ group known as NoName057(16), and appear to have a pro-Russian ideological motive.” It did not elaborate. The cybersecurity center said it was investigating attacks that flood a site with data to overwhelm it and knock it offline, and was in contact with “national and international partners.” Raoul Rozestraten, a spokesman for the municipality in The Hague, the Dutch city hosting the summit Tuesday and Wednesday, said the attacks hit municipalities around the country. ([Daniel Michaels / The Wall Street Journal](https://www.wsj.com/politics/national-security/nato-defense-systems-drones-hacking-e8ca97f1?gaa%5Fat=eafs&gaa%5Fn=ASWzDAiv3vijp6mHmEGhMTo7O0tLX7VlbNJEEH0iYsAIpuanJIbvzdcT-lFJ0JVs0Aw%3D&gaa%5Fts=685a9180&gaa%5Fsig=NjTdScbIJLHH1ola5cFyWdf1T0rGbt5qiIwVYw2X8F40UViOb%5FlIUkC0xhP-GrXzxgO1bzp2H6mYuKtfMQZKkg%3D%3D&ref=metacurity.com), [Associated Press](https://apnews.com/article/nato-summit-cybersecurity-hack-russia-netherlands-fa97bbf8797a51c2885d47f5f83691be?ref=metacurity.com)) **Related:** [*The Economic Times*](https://economictimes.indiatimes.com/news/international/new-zealand/pro-russian-hackers-launch-ddos-attacks-on-dutch-municipalities-ahead-of-nato-summit/articleshow/122043977.cms?from=mdr&ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/132434/pro-russian-hacker-group-claims-attack-on-dutch-government-websites/?ref=metacurity.com)*,* [*NL Times*](https://nltimes.nl/2025/06/23/pro-russian-hackers-disrupt-dutch-government-websites-ahead-nato-summit?ref=metacurity.com)*,* [*De Telegraaf*](https://www.telegraaf.nl/binnenland/pro-russische-hackers-claimen-ddos-aanval-sites-nederlandse-gemeenten-en-provincies-slecht-bereikbaar/73241912.html?ref=metacurity.com) ### According to the Russian state-owned news agency TASS, four REvil ransomware members arrested in January 2022, Andrey Bessonov, Mikhail Golovachuk, Roman Muromsky, and Dmitry Korotayev, were released by Russia on time served after they pleaded guilty to carding and malware distribution charges. All four were found guilty by the court and sentenced to five years in prison. However, they were released from custody because the court considered they had served their sentence in a Russian detention center (SIZO) during the investigation and trial. The defendants were among eight members of the REvil ransomware operation who were apprehended by Russian authorities more than three years ago. Artem Zayets, Alexey Malozemov, Daniil Puzyrevsky, and Ruslan Khansvyarov, the other REvil members arrested in January 2022, were sentenced to over 4 years in prison as part of a different proceeding after they refused to plead guilty to the charges. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/revil-hackers-released-after-time-served-on-carding-charges/?ref=metacurity.com)) **Related*:* [*TASS*](https://tass.ru/proisshestviya/24328083?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/revil-ransomware-sentence-russia-time-served/?ref=metacurity.com) ### An investigation by top on-chain analyst ZachXBT has revealed how an alleged New York-based con artist named Christian Rieves stole millions of dollars from victims by pretending to be support staff from Coinbase. The pseudonymous sleuth details how a man named Christian Nieves, who goes by “Daytwo” and “PawsOnHips” online, allegedly stole $4 million from Coinbase users by impersonating employees at the crypto exchange. ZachXBT says that Nieves operates a small scam call center group and also works as a caller. The group allegedly primarily coerces its victims into setting up a Coinbase wallet with an already compromised seed phrase on phishing sites. Other people in Nieves’ circle also allegedly helped in separate thefts, including a henchman named Justin, who went by the name “Paranoia,” who executed a $240,000 heist of an elderly victim’s Bitcoin (BTC) wallet. According to ZachXBT, a portion of that $240,000 was deposited into crypto betting site Roobet, and the rest was converted into Monero (XMR). Nieves and his alleged accomplices have not been charged with anything by law enforcement, but given the amount of digital and on-chain evidence, ZachXBT says it should be a “rather easy” case for authorities. ([Alex Richardson / The Daily Hodl](https://dailyhodl.com/2025/06/23/hackers-impersonate-coinbase-user-support-to-scam-victims-of-4000000-before-blowing-most-of-money-on-gambling-zachxbt/?ref=metacurity.com)) **Related:** [*The Shib*](https://news.shib.io/2025/06/24/zachxbt-uncovers-4m-coinbase-scam-that-left-victims-wallets-empty/?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/post/359212/coinbase-support-scammer-gambled-millions-zachxbt-analytics?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/crypto-scammer-flaunts-4m-stolen-from-coinbase-users-zachxbt-reveals/?ref=metacurity.com)*,* [*Decripto*](https://decripto.org/en/4-million-coinbase-scam-the-christian-nieves-case-and-the-network-of-fake-traders/?ref=metacurity.com)*,* [*Cryptopolitan*](https://www.cryptopolitan.com/zachxbt-exposes-daytwos-4m-coinbase-scam/?ref=metacurity.com) ### A trio of cybersecurity firms quietly ended a program, the Critical Infrastructure Defense Project, that offered free services to vulnerable critical infrastructure sectors, which was first launched in the wake of Russia’s invasion of Ukraine. Led by Cloudflare, CrowdStrike, and Ping Identity, the project began in March 2022 and supplied critical infrastructure owners and operators potentially exposed to digital threats tied to the Russia-Ukraine war with free cybersecurity tools. It was designed to help sectors like hospitals, water systems, and power utilities. Since the war broke out in early 2022, Russian military-aligned hacking groups have accelerated reconnaissance and sabotage campaigns against infrastructure systems in the US and other allies in Europe. One of those incursions targeted a water system in Texas. But the “project has concluded” since the offerings “aligned with a period of initial heightened threats, and that its use has since subsided,” according to a statement from a CrowdStrike spokesperson. ([David DiMolfetta / NextGov/FCW](https://www.nextgov.com/cybersecurity/2025/06/cyber-firms-sunset-free-services-meant-counter-russia-linked-hacking-threats/406225/?ref=metacurity.com)) ### Ukraine's Computer and Emergency Response (CERT-UA) says the Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. CERT-UA first discovered the attacks in March 2024, though limited details about the infection vector were uncovered then. Over a year later, in May 2025, ESET notified CERT-UA of unauthorized access to a gov.ua email account, prompting a new incident response. During this new investigation, CERT-UA discovered that messages sent via the encrypted messenger app Signal were used to deliver a malicious document to targets (Акт.doc), which uses macros to load a memory-resident backdoor called Covenant. Covenant acts as a malware loader, downloading a DLL (PlaySndSrv.dll) and a shellcode-ridden WAV file (sample-03.wav) that loads BeardShell, a previously undocumented C++ malware. In the 2024 attacks, CERT-UA also spotted a screenshot grabber named SlimAgent, which captures screenshots using an array of Windows API functions (EnumDisplayMonitors, CreateCompatibleDC, CreateCompatibleBitmap, BitBlt, GdipSaveImageToStream). ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/apt28-hackers-use-signal-chats-to-launch-new-malware-attacks-on-ukraine/?mid=1&ref=metacurity.com#cid=2931526)) **Related:** [*CERT-UA*](https://cert.gov.ua/article/6284080?ref=metacurity.com) ### According to a data breach notification and documents from McLaren Health Care, ransomware hackers stole the Social Security numbers and health insurance information for more than 740,000 people during an attack on a prominent Michigan hospital network. The documents said the attack last year was launched by an “international ransomware group” and impacted the computer networks of McLaren Health Care and Karmanos Cancer Institute. Letters to victims said the suspicious activity was discovered on August 5, and investigators found the hackers initially gained access as far back as July 17\. A forensic review completed last month found that 743,131 people had information stolen. The network said the breached data also included names, driver’s license numbers, and medical information. Victims are being given one year of credit monitoring services. McLaren Health Care warned the public at the time that it was forced to operate with downtime procedures while working to restore several downed IT systems. McLaren emergency departments continued to operate but some surgeries and procedures were canceled as a result of the attack. Some non-emergent appointments, tests and treatments were rescheduled, according to the statement. The organization did not call it a ransomware attack at the time, but a printed ransom note from the INC ransomware gang allegedly sent to the hospital was shared on social media. ([Jonathan Greig / The Record](https://therecord.media/mclaren-health-care-data-breach-notification-ransomware?ref=metacurity.com)) ***Related:*** [*Maine Attorney General*](https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/79a56f34-ffbe-4621-a74c-9b1e49477904.html?ref=metacurity.com)*,* [*The HIPAA Journal*](https://www.hipaajournal.com/mclaren-health-care-investigating-potential-cyberattack/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/mclaren-health-care-says-data-breach-impacts-743-000-patients/?ref=metacurity.com)*,* [*Globe Newswire*](https://www.globenewswire.com/news-release/2025/06/23/3103768/0/en/McLaren-Health-Care-Data-Breach-Exposes-Personal-Information-Murphy-Law-Firm-Investigates-Legal-Claims.html?ref=metacurity.com)*,* [*PR Newswire*](https://www.prnewswire.com/news-releases/data-breach-alert-edelson-lechtzin-llp-is-investigating-claims-on-behalf-of-mclaren-health-care-customers-whose-data-may-have-been-compromised-302488794.html?ref=metacurity.com)*,* [*Tom's Guide*](https://www.tomsguide.com/computing/online-security/over-700k-people-hit-in-major-healthcare-data-breach-full-names-ssns-medical-info-and-more-exposed?ref=metacurity.com)*,* [*BankInfoSecurity*](https://www.bankinfosecurity.com/mclaren-health-says-743000-affected-by-2024-ransomware-hack-a-28785?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/179259/data-breach/mclaren-health-care-data-breach-impacted-over-743000-people.html?ref=metacurity.com)*,* [*The Daily Hodl*](https://dailyhodl.com/2025/06/23/743131-americans-affected-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-social-security-numbers-drivers-license-numbers-and-more/?ref=metacurity.com) ### Montana Attorney General Austin Knudsen is going after the largest newspaper chain in the state, demanding information and answers about what he says was a cyberattack that exposed the personal information of thousands of subscribers. Knudsen is ordering the investigation of Lee Enterprises, which operates the state's major papers, including the Billings Gazette and the Missoulian, under the provisions of Montana's Consumer Protection Act. The state says that, "according to reports," the breach affects nearly 40,000 employees and subscribers, and he's giving Lee a month to respond. ([Dennis Bragg / KVGO](https://newstalkkgvo.com/montana-newspaper-data-breach/?ref=metacurity.com)) **Related:** [*DataBreaches.net*](https://databreaches.net/2025/06/21/montana-attorney-general-launches-investigation-into-lee-enterprises-data-breach/?ref=metacurity.com)*,* [*The Independent Record*](https://helenair.com/news/local/government-politics/article%5F14de810b-c205-4499-82f8-5c3df35963e5.html?ref=metacurity.com) ### Spanish LLM security firm NeuralTrust reports that through progressive poisoning and manipulating an LLM’s operational context, many leading AI models can be tricked into providing almost anything, regardless of the guardrails in place, with a new jailbreak they call Echo Chamber. Echo Chamber is similar to Microsoft’s Crescendo jailbreak. The latter asks questions and tries to lure the LLM into a desired prohibited response. The former, Echo Chamber, never tells the LLM where to go, but plants acceptable ‘seeds’ that progressively guide the AI into providing the required response. Echo Chamber works by manipulating the LLM’s context (what it remembers of a conversation to allow a coherent conversation) while avoiding the so-called red zone (prohibited queries) and remaining within the green zone (acceptable queries). From within the green zone, context is maintained, and the conversation can continue, but if the red zone is entered, the LLM declines to respond, and the context is lost. The attacker's only criteria are to keep the context in the green zone, avoid the red zone, and complete the attack within the time or query limits on the current context. ([Kevin Townsend / Security Week](https://www.securityweek.com/new-echo-chamber-jailbreak-bypasses-ai-guardrails-with-ease/?ref=metacurity.com)) **Related:** [*NeuralTrust*](https://neuraltrust.ai/blog/echo-chamber-context-poisoning-jailbreak?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/news/ai-jailbreak-method-tricks-llms-into-poisoning-their-own-context?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/cloud-security/echo-chamber-attack-ai-guardrails?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/06/image-93.png) The Echo Chamber Attack Flow Chart. Source: NeuralTrust. ### Researchers at SecurityScorecard report that a stealthy, ongoing campaign to gain long-term access to networks bears all the markings of intrusions conducted by China’s Typhoon crews and has infected at least 1,000 devices, primarily in the US and Southeast Asia. It attempts to access critical infrastructure by using a phony certificate purportedly signed by the Los Angeles Police Department. The digital break-ins began no later than September 2023 (maybe earlier) and have expanded ever since. The campaign primarily targets end-of-life routers, IoT devices, internet-connected security cameras, virtual servers, and other small office/home office (SOHO) devices to build an Operational Relay Box or ORB network. Beijing's attackers route traffic and launch cyberattacks through these ORB networks, which have grown to hundreds or thousands of compromised devices. Because the activity comes through what seems to be a local IP address, it's harder to track. In recent years, essentially all of the Chinese government-backed groups use ORBs to remain undetected on victims' networks. Intruders built this ORB network, which Security Scorecard named "LapDogs,” by compromising old and unpatched devices through various means. The miscreants "appear to favor targeting Linux-based systems in their operations," according to a report published Monday ([Jessica Lyons / The Register](https://www.theregister.com/2025/06/23/lapdog%5Forb%5Fnetwork%5Fattack%5Fcampaign/?ref=metacurity.com)) **Related:** [*SecurityScorecard*](https://securityscorecard.com/blog/unmasking-a-new-china-linked-covert-orb-network-inside-the-lapdogs-campaign/?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/china-lapdogs-drops-shortleash-backdoor-fake-certs/?ref=metacurity.com)*,* [*IT Pro*](https://www.itpro.com/security/cyber-attacks/lapdogs-cyber-espionage-campaign-iot-home-office-routers?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2025/06/23/lapdogs-shortleash-backdoor-linux-soho-devices/?ref=metacurity.com)*,* [*BankInfoSecurity*](https://www.bankinfosecurity.com/chinese-hackers-turn-unpatched-routers-into-orb-spy-network-a-28784?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/06/image-94.png) LapDogs is highly localized in the US and Southeast Asia. Source: SecurityScorecard. ### Researchers at Kaspersky have discovered photo-stealing malware they call SparkKitty that has been quietly targeting iPhone and Android users since at least February 2024. The malware's authors have been distributing it through apps in the official app stores of Apple and Google, via malicious pages, and as a Trojanized version of the TikTok app. As with its older sibling, SparkCat, SparkKitty's goal is to harvest images from a device's gallery in the hopes of locating sensitive content such as screenshots of cryptocurrency wallet seed phrases. According to Kaspersky, one Android app featuring SparkKitty had more than 10,000 installations from Google Play before being removed. ([Jai Vijayan / Dark Reading](https://www.darkreading.com/mobile-security/sparkkitty-swipes-pics-ios-android-devices?ref=metacurity.com)) **Related:** [*Securelist*](https://securelist.com/sparkkitty-ios-android-malware/116793/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/06/image-95.png) Suspicious store opened inside a TikTok app. Source: Kaspersky. ### Microsoft has confirmed that Windows 11 System Restore points will be deleted after 60 days, so users must be more careful and periodically create restore points. Microsoft will give users multiple snapshots with this latest update, but Windows will still delete the oldest ones once they exceed the retention window (now 60 days on Windows 11 24H2 by default). ([Mayank Parmar / Windows Latest](https://www.windowslatest.com/2025/06/21/windows-11-24h2-system-restore-points-now-expire-after-60-days-microsoft-confirms/?ref=metacurity.com)) **Related:** [*Tom's Guide*](https://www.tomsguide.com/computing/windows-operating-systems/fixing-your-broken-windows-11-pc-is-about-to-get-even-harder-heres-why?ref=metacurity.com)*,* [*ExtremeTech*](https://www.extremetech.com/computing/microsoft-sets-new-60-day-limit-for-system-restore-points-in-windows-11?ref=metacurity.com)*,* [*PC World*](https://www.pcworld.com/article/2824671/windows-11s-crucial-restore-points-now-self-destruct-after-60-days.html?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/davidphelan/2025/06/23/microsoft-confirms-windows-11-automatic-deletions-take-action-now-to-protect-yourself/?ref=metacurity.com)*,* [*XDA*](https://www.xda-developers.com/windows-11-system-restore-points-may-vanish-30-days-earlier/?ref=metacurity.com) ### Election officials and experts worry that Donald Trump is attempting to create a new set of metrics that can better support his political claims of voter fraud. Last month, US Citizenship and Immigration Services quietly announced that a federal database typically used for naturalized citizens to seek benefits had been repurposed as a tool to check state voter registration systems for signs of noncitizens. The news came less than a month after the agency revealed that staffers from the Department of Government Efficiency had implemented a “comprehensive optimization” of the database, known as Systematic Alien Verification for Entitlements (SAVE), that included the elimination of state-paid fees for searches and other unspecified changes to streamline mass status checks, integrate criminal records information and “break down silos for accurate results,” according to DOGE officials. Further changes announced by the agency in May will allow states to run searches using Social Security numbers and conduct bulk searches. As USCIS spokesperson Matthew Tragesser said, these modifications are intended to “help identify and stop aliens from hijacking our elections.” Election officials and experts have expressed bewilderment as to why the Department of Homeland Security would attempt to use SAVE, an incomplete, often out-of-date database, to identify potential noncitizen voters. Others expressed more direct concerns that the SAVE changes appear to be the first steps in a larger plan by the White House to create new metrics that lend support to Trump’s unproven claims that noncitizens are voting en masse for Democrats. ([Derek B. Johnson and Colin Wood / Cyberscoop](https://cyberscoop.com/voter-citizenship-verification-trump-save-database/?ref=metacurity.com)) ### Best Thing of the Day: A 'Hackathon' That Can Help Save Dolphins Not cyber-related, but the University of Hawaiʻi Sea Grant College Program (Hawaiʻi Sea Grant) and Papahānaumokuākea Marine Debris Project (PMDP) [have launched](https://www.hawaii.edu/news/2025/06/23/inaugural-marine-debris-hackathon/?ref=metacurity.com) the inaugural Marine Debris Hack-A-Thon, a cutting-edge challenge that calls on individuals or teams to develop new, innovative tools that can be used to cut and remove derelict fishing nets. ### Worst Thing of the Day: Add Murder-for-Hire to Iran's Possible Retaliation Checklist Amid the fears of Iranian attacks against the US in retaliation for recent military strikes, Iran [is accused](https://apnews.com/article/iran-fbi-justice-department-46d6b7dec78dca861a32c901f8e3b307?ref=metacurity.com) of having taken in recent years to target political figures on US soil and recruiting operatives to kill public officials and dissidents. ### Closing Thought ### DHS warns of likely Iranian cyberattacks following Trump's missile strikes URL: https://www.metacurity.com/dhs-warns-of-likely-iranian-cyberattacks-following-trumps-missile-strikes/ Last updated: 2025-06-23T13:42:54.000Z Authorities warn of Salt Typhoon threats in Canada, Aflac struck by likely Scattered Spider attack, DPRK likely behind BitoPro $11m theft, CoinMarketCap hit by wallet-draining attack, Hacker stole $250K from Hacken using leaked key, Garden Finance accused of laundering stolen crypto, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 6/14/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-6-14-25/ Last updated: 2025-06-21T12:16:04.000Z Tech-facilitated intimate partner stalking is rampant, Algorithms trap users in right-wing hatred, Pavel Durov denies he's a buddy of Putin, Musk lied to grab Social Security data, DOGE damaged the VA with a bad AI system _This post is for subscribers only._ ### Report of 16 billion credentials breach debunked URL: https://www.metacurity.com/report-of-16-billion-credentials-breach-debunked/ Last updated: 2025-06-20T13:36:27.000Z Hegseth is under pressure to find Haugh's replacement, Israeli hackers released Nobitex source code, Czech president says China and Russia are hacking equals, China has repeatedly hacked Russia, Ryuk suspect extradited to US, Korean megachurch hacked to display DPRK flag, much more _This post is for paying subscribers only._ ### Israeli-linked hackers seized and burned $90 million from Iran's Nobitex exchange URL: https://www.metacurity.com/israeli-linked-hackers-seized-and-burned-90-million-from-irans-nobitex-exchange/ Last updated: 2025-06-19T13:50:37.000Z Iranian broadcasters hacked to air protest video, Iran cyber command warns officials away from connected gear, Novel method targeted UK's Keir Giles, Viasat was a Salt Typhoon victim, Feds seized $225m+ in romance scam crypto, San Diego's PD license plate system left open for three weeks, much more _This post is for paying subscribers only._ ### Israel-linked hackers destroyed data at Iran’s state-owned Bank Sepah URL: https://www.metacurity.com/israel-linked-hackers-destroyed-data-at-irans-state-owned-bank-sepah/ Last updated: 2025-06-18T14:14:36.000Z Israel-linked hackers stole $48m in crypto from Iran, Iran urges removal of WhatsApp from phones, Iran shuts down internet amid Israel strikes, US critical infrastructure girds for Iranian cyber threats, UK ICO fines 23andMe $3.1m over 2023 breach, Chinese spies invest heavily in AI, so much more _This post is for paying subscribers only._ ### Operation Deep Sentinel took down infamous darknet drug marketplace Archetyp Market URL: https://www.metacurity.com/operation-deep-sentinel-took-down-infamous-darknet-drug-marketplace-archetyp-market/ Last updated: 2025-06-17T13:55:01.000Z Minnesota political assassin used online data brokers to find victims, Scattered Spider's latest target is insurance sector, Thai cops arrest ransomware actors targeting China, $10m reward for CyberAv3ngers hackers, WhatsApp ads worry privacy experts, Yes24 apologizes for attack, much more _This post is for paying subscribers only._ ### Foreign nation suspected in hack of Washington Post reporters’ emails URL: https://www.metacurity.com/foreign-nation-suspected-in-hack-of-washington-post-reporters-emails/ Last updated: 2025-06-16T18:27:14.000Z WestJet hit by cyber incident, Iran likely to retaliate with cyber ops, Zoomcar breach exposed customers' data, Qilin gang hit French insurer, Trump provided Medicaid data to deportation officials, 46K+ Grafana instances remain unpatched, 10K VirtualMacOSX customers affected by breach, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 6/7/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-6-7-25/ Last updated: 2025-06-14T11:56:19.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/06/pexels-wsilvasjb-17545208-1.jpg) Photo by [Wallace Silva](https://www.pexels.com/photo/books-on-bookshelf-17545208/?ref=metacurity.com). *Happy Saturday morning! Metacurity is pleased to offer our free and premium subscribers this weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush. So tell us what you think, and feel free to share your favorite long reads via email at* *info@metacurity.com* *.* *If you enjoy our weekly selection of top infosec-related long reads, please consider upgrading your subscription to support our work. Thank you!* [Upgrade my subscription](#/portal/account/plans) ### The SEC Pinned Its Hack on a Few Hapless Day Traders. The Full Story Is Far More Troubling In this colorful tale of intrigue and foreign locales, Bloomberg's Liam Vaughan [casts a jaundiced eye](https://www.bloomberg.com/news/features/2025-06-06/how-hack-of-sec-s-edgar-system-exposed-flaws-in-us-financial-security?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc0OTIwNjA2NywiZXhwIjoxNzQ5ODEwODY3LCJhcnRpY2xlSWQiOiJTWEZJR0xUMEFGQjQwMCIsImJjb25uZWN0SWQiOiIyQkZEOTY0MkNBNzY0RTk1QjI4NjQyOUU2RTVCOTRDRSJ9.ZqozrVREdOF6MS51Vkap%5FlFpWiuJCiBQCtzAydHCyyA&ref=metacurity.com) on the official SEC version of events regarding a 2017 hack of the agency's Edgar database, reporting that the Commission expended its investigative energy on low-level scapegoats to give itself a clean bill of health only to allow the most culpable culprits to remain at large. > The SEC has invested heavily in data analysis tools to detect improbably successful trading. At this effort’s heart is a system called Artemis, a nod to the Greek goddess of the hunt, which parses trading records and account-holder data for signs of suspicious activity. > As investigators looked for potential recipients of inside information, they landed on Sungjin Cho and David Kwon, a pair of party-loving day traders who lived a couple of miles from each other in Koreatown, Los Angeles. Over four months in 2016, Cho (who was 36 and also owned an apartment in Bangkok) had traded ahead of earnings more than a hundred times, making $1.2 million. Kwon had made in excess of $400,000\. Their buying and selling lined up closely with that of a Ukrainian named Ivan Olefir, who along with two friends earned more than $800,000. > The investigators found Cho and Olefir had also enjoyed a hot streak between 2012 and 2014, trading in many of the companies whose filings were stolen by Ieremenko during the newswires hacks. > Cho co-owned CY Group, a small trading firm in LA that provided capital and cheap access to US exchanges to independent traders around the world, including Olefir and several others in Kyiv. The firm was already under investigation by another SEC unit for acting as a broker without a license. > In May 2017, at the Hyatt Regency in Kyiv, Kuprina met with LaTulip, some other Secret Service agents and a member of Ukraine’s cyberpolice. In broken English, she told the story of the Edgar hack. > After Ieremenko’s newswires ring was broken, he’d joined with Radchenko, a wealthy farmer’s son he knew from Kyiv’s nightlife. Radchenko had big ambitions but limited technical skills. “He’s a script kiddie,” Kuprina scoffed. > According to Kuprina, the pair concocted a plan for Ieremenko to hack the mother lode, the SEC itself, and for Radchenko to monetize it via his connections in Russian and Ukrainian politics and organized crime. They rented an office in Kyiv and registered a firm in the UK with the legitimate-sounding name Benjamin Capital to attract outside investors. > Ieremenko discovered an area of Edgar where companies could upload test filings to check for formatting errors ahead of publication. Some used fake figures, but many didn’t. Soon Ieremenko was downloading hundreds of test filings a week. Radchenko sold the filings and splurged on bottle service and a Bentley. By the time the SEC patched up the vulnerability in October 2016, the pair had fallen out. > At that point, Radchenko recruited Kuprina. In less than two weeks, she broke into Edgar, she told the agents. She hijacked authorized users’ temporary access to the network. She launched phishing attacks, sending emails with infected links to administrators that appeared to come from their SEC colleagues. She located a flaw in the webpage for making complaints. She found a log listing headlines for unpublished filings. “There were so many vulnerabilities there you cannot f---ing imagine,” she told me. Between October 2016 and March 2017, Kuprina downloaded dozens more documents containing material nonpublic information. > After the meeting, LaTulip relayed what he’d heard to the DOJ, which passed it along to the SEC. But, according to sources who worked on the investigations, attorneys at the SEC’s enforcement division struggled to believe the agency was a target: The SEC scrupulously avoids retaining price-sensitive information, they insisted. > A week later, DOJ prosecutors flew to Kyiv to question Kuprina themselves. This time Kuprina brought her red-and-blue notepad and thumb drives. They revealed not just what filings she’d obtained and how, but also what Ieremenko had been up to before she got involved. > It took the SEC’s IT staff four months to corroborate Kuprina’s account. “We kept going back to them and saying, ‘You need to look again,’” one prosecutor recalls. When they finally found the hackers’ fingerprints, the truth was inescapable: The source for the suspicious trading the SEC had been tracking for months was the SEC itself. ### Telegram, the FSB, and the Man in the Middle For a collaboration between Important Stories and the Organized Crime and Corruption Project (OCCRP), journalists Roman Anin and Nikita Kondratyev [investigated](https://www.occrp.org/en/investigation/telegram-the-fsb-and-the-man-in-the-middle?ref=metacurity.com) Russian network engineer named Vladimir Vedeneev, who controls thousands of Telegram IP addresses and maintains its servers, documenting his history of collaborating with Russia’s defense sector, the FSB security service, and other Russian agencies. > When reporters investigated who controls the infrastructure that keeps Telegram’s billions of messages flowing, they found a man with no public profile but unparalleled access: Vladimir Vedeneev, a 45-year-old network engineer. > Vedeneev owns the company that maintains Telegram’s networking equipment and assigns thousands of its IP addresses. Court documents show that he was granted exclusive access to some of Telegram’s servers and was even empowered to sign contracts on Telegram’s behalf. > There is no evidence that this company has worked with the Russian government or provided any data. But two other closely linked Vedeneev companies — one of which also assigns Telegram IP addresses, and another which did so until 2020 — have had multiple highly sensitive clients tied to the security services. Among their clients is the FSB intelligence agency; a secretive “research computing center” that helped plan the invasion of Ukraine and developed tools to deanonymize internet users; and a flagship state-owned nuclear research laboratory. > “If true, this reporting highlights the dangerous disconnect between what many believe about Telegram’s security and privacy features, and the reality," said John Scott-Railton, a Senior Researcher at The Citizen Lab. "When people don't know what is actually going on, but assume they have metadata privacy, they can unknowingly make risky choices, bringing danger to themselves and the people they’re communicating with. This is doubly true if the Russian government sees them as a threat." > A Ukrainian IT specialist who spoke with reporters on condition of anonymity said that the Russian military has used “man-in-the-middle” type surveillance in his country after capturing network infrastructure. > "You get physical access to the data transmission channel and install your equipment there,” he said. “In such an attack, the hackers aren’t even interested so much in the user's correspondence. They get metadata to analyze. And that means IP addresses, user locations, who exchanges data packets with whom, the kind of data it is… really, all possible information.” ### Russia recruited a teenage spy. His arrest led to a crypto money trail Reuters' Mari Saito, Anna Koper, Anton Zverev, Filipp Lebedev, and Polina Nikolskaya [tell the tale](https://www.reuters.com/investigates/special-report/europe-espionage-teen-spy/?ref=metacurity.com) of Canadian teenager Laken Pavan, now imprisoned in Poland, who was funded by cryptocurrency to serve as an untrained spy for Russia after the country's diplomats and operatives were expelled from Europe in 2022. > On April 16, 2024, Pavan flew from Vancouver to Moscow via Istanbul and hired a driver to take him to occupied Donetsk. There, he crashed in the basement headquarters of the Interbrigades, a volunteer group, which according to the organisation's social media account was set up in 2014 to gather mercenaries to fight for Russia in Donetsk and the neighboring Ukrainian region of Luhansk and to organize humanitarian projects for civilians. The group's name refers to the Spanish Civil War, when leftists from many countries arrived in Spain to fight for the International Brigades against Francisco Franco's rebels. > Pavan was two months shy of 18, fair-haired and lanky. He had inquired about enlisting but was told he had to first turn 18 under Russian law, according to a message he sent a foreign fighter from Spain. For about a week, he volunteered around Donetsk with the Interbrigades and helped rebuild a school. > Wilmer Puello-Mota, an American former airman who fled to Russia after being charged with possession of child sexual abuse material, told Reuters he encountered Pavan in Donetsk, where the Canadian tried unsuccessfully to join the Russian army. > Puello-Mota, who described the U.S. allegations against him as unfair, is now serving in Russia’s military. > “Everybody he talked to down there, we told him, go home,” said Puello-Mota, whose contacts with Pavan appear in the court documents. He said Pavan did nothing more than volunteer for the Interbrigades for a day or two, as the court documents also indicated. Puello-Mota said the espionage allegations made by Poland against the teen made no sense. > In late April, Pavan was out drinking in Donetsk when he was arrested. He told Polish prosecutors he was questioned about his family and friends at the police station by men who said they were from the FSB. The men put a bag over his head and drove him to a second location, where they interrogated him again, asking also about his travel plans around Europe. None of them gave Pavan their names. > Eventually, he told prosecutors, he was taken to the Central hotel in Donetsk, a tall building with a glass facade in the heart of the occupied city. There he was grilled repeatedly by a group of at least six FSB officers and one man who said he was from Russia’s Foreign Intelligence Service. After several days, they gave him instructions. > After returning to Europe, Pavan was to lose his passport to conceal his trip to Russia and begin working for Russia’s security services. > “This work was to consist of traveling around Europe and taking photos. In Ukraine, on the other hand, I was to enlist in the Ukrainian army; I was to receive detailed instructions for this later, after arriving in Ukraine,” Pavan told Polish prosecutors, according to a copy of his testimony seen by Reuters. The teen did not speak Russian, Ukrainian or Polish. > The Russian men used a combination of threats and inducements to get him to agree, Pavan told Polish authorities. In exchange for his work, he’d get Russian citizenship and an apartment in any Russian city of his choosing. If he didn’t comply, he would be killed, he told prosecutors. ### Secret Russian Intelligence Document Shows Deep Suspicion of China The New York Times' Jacob Judah, Paul Sonne, and Anton Troianovski [reveal that](https://www.nytimes.com/2025/06/07/world/europe/china-russia-spies-documents-putin-war.html?unlocked%5Farticle%5Fcode=1.NE8.u5hD.dSHNgmQjafS%5F&ref=metacurity.com), according to a document leak from cybercrime group Ares Leaks, deep in the corridors of Lubyanka, the headquarters of Russia’s FSB domestic security agency, there is a secret intelligence unit that warns, among other things, China is spying on the Russian military’s operations in Ukraine to learn about Western weapons and warfare. > Three days before Mr. Putin invaded Ukraine in 2022, the F.S.B. approved a new counterintelligence program called “Entente-4,” the document reveals. The code name, an apparent tongue-in-cheek reference to Moscow’s growing friendship with Beijing, belied the initiative’s real intent: to prevent Chinese spies from undermining Russian interests. > The timing almost certainly was not accidental. Russia was diverting nearly all of its military and spy resources to Ukraine, more than 4,000 miles from its border with China, and most likely worried that Beijing could try to capitalize on this distraction. > Since then, according to the document, the F.S.B. observed China doing just that. Chinese intelligence agents stepped up efforts to recruit Russian officials, experts, journalists and businesspeople close to power in Moscow, the document says. > To counter this, the F.S.B. instructed its officers to intercept the “threat” and “prevent the transfer of important strategic information to the Chinese.” Officers were ordered to conduct in-person meetings with Russian citizens who work closely with China and warn them that Beijing was trying to take advantage of Russia and obtain advanced scientific research, according to the document. > The F.S.B. ordered “the constant accumulation of information about users” on the Chinese messaging app WeChat. That included hacking phones of espionage targets and analyzing the data in a special software tool held by a unit of the F.S.B., the document says. ### How We Obtained and Vetted a Russian Intelligence Document The New York Times' Jacob Judah and Paul Sonne [explain](https://www.nytimes.com/2025/06/07/world/europe/russia-intelligence-documents-leak-how.html?ref=metacurity.com) how they vetted the document provided by the cybercrime group Ares Leaks, which provided a complete FSB counterintelligence document about China. > We took the document to six Western intelligence agencies. All of them confirmed that it appeared authentic, based on its format and content. A few agencies told us that the content was consistent with intelligence that they had collected independently. One went so far as to say that the content was consistent with what it knew about Russia’s views on China and its penetration of Chinese communications. > The Times also confirmed some details from the document. For instance, we established — independent of the Western intelligence sources we consulted — that the Russian government had in fact been conducting “precautionary briefings” with Russians who travel to China for work. > The other samples that Ares Leaks provided were just snippets. They included warnings about handling informants, details of cyberoperations and analyses of Western operations against Russia. Without knowing the context, though, they were hard to analyze and vet. > How Ares Leaks acquired these documents is unclear. The group did not answer when asked. Russian agencies have been hacked before. Perhaps an F.S.B. officer mishandled them or had them stolen. Maybe an insider sold or leaked them, or Ares grabbed them from another criminal group. > Ares Leaks first emerged selling hacked corporate databases four years ago, according to Analyst1, a cybersecurity firm based in Virginia. Ares Leaks specializes in selling sensitive government documents and regularly posts that it is looking to buy information on militaries and governments — with Russia, China, France, Britain and Japan among its priorities. > The market for such documents is niche, with few buyers beyond intelligence agencies having a clear incentive to pay big money for this kind of insight. ### Modern Tech and Old-School Spycraft Are Redefining War The Wall Street Journal's Yaroslav Trofimov, Drew Hinshaw,and Joe Parkinson[delve into](https://www.wsj.com/world/modern-technology-spycraft-war-eabda84f?mod=djemCybersecruityPro&tpl=cs&ref=metacurity.com) how modern militaries use drones, communications networks, smaller but more powerful batteries and explosives, and superior spycraft now to determine the outcomes of war. > “Technology today allows you many new possibilities: There is a larger surface where you can actually detect places where your enemy is vulnerable due to the fact that you can bypass a lot of physical barriers that in the past you couldn’t bypass,” said Eyal Tsir Cohen, a former senior division director of Israel’s Mossad intelligence service. > Yet, he added, many of the same technologies can also empower one’s opponents. “It always works both ways—it depends on which side is more sophisticated in exploiting the vulnerabilities of the other side,” Cohen said. “You need good people to work with technology—technology rides on the shoulders of the human factor and not vice versa.” > Ultimately, success in this rapidly changing world depends on the ability to anticipate the new opportunities—something that big powers such as Russia and perhaps the U.S., can be slow to understand as the very nature of warfare evolves. > “The failure of thinking through the insecurities of the supply chain on the part of Hezbollah and the astounding failure by Russia—those were failures of imagination,” said Brian Katulis, a senior fellow at the Middle East Institute. The new way of war redresses the balance of power in favor of weaker actors, he added: “If you can punch above your weight while also having limited costs and blowback to yourself, it can level the playing field.” > Israel’s multistage operation to intercept and booby-trap pagers used by Hezbollah, then the militia commanders’ walkie-talkies, followed up by targeted strikes that killed leader Hassan Nasrallah last September and wiped out most of the organization’s leadership, reshaped—at least temporarily—the balance of power in the entire Middle East. > In that campaign, the result of a yearslong effort to infiltrate Hezbollah and its Iranian sponsors, Israel didn’t just dramatically weaken the U.S.-designated terrorist group, its most formidable immediate foe that has lost its stranglehold over Lebanon’s government. Israel also helped create conditions for the downfall of Bashar al-Assad’s regime in Syria two months later and the overall shrinking of Iran’s regional power. ### They Asked an A.I. Chatbot Questions. The Answers Sent Them Spiraling. The New York Times' Kashmir Hill [presents disturbing evidence](https://www.nytimes.com/2025/06/13/technology/chatgpt-ai-chatbots-conspiracies.html?ref=metacurity.com) that generative AI bots can lead users down conspiratorial and mystical rabbit holes, causing them to break from reality and even fall into delusional spirals. > In recent months, tech journalists at The New York Times have received quite a few such messages, sent by people who claim to have unlocked hidden knowledge with the help of ChatGPT, which then instructed them to blow the whistle on what they had uncovered. People claimed a range of discoveries: A.I. spiritual awakenings, cognitive weapons, a plan by tech billionaires to end human civilization so they can have the planet to themselves. But in each case, the person had been persuaded that ChatGPT had revealed a profound and world-altering truth. > Journalists aren’t the only ones getting these messages. ChatGPT has directed such users to some high-profile subject matter experts, like Eliezer Yudkowsky, a decision theorist and an author of a forthcoming book, “If Anyone Builds It, Everyone Dies: Why Superhuman A.I. Would Kill Us All.” Mr. Yudkowsky said OpenAI might have primed ChatGPT to entertain the delusions of users by optimizing its chatbot for “engagement” — creating conversations that keep a user hooked. > “What does a human slowly going insane look like to a corporation?” Mr. Yudkowsky asked in an interview. “It looks like an additional monthly user.” > Generative A.I. chatbots are “giant masses of inscrutable numbers,” Mr. Yudkowsky said, and the companies making them don’t know exactly why they behave the way that they do. This potentially makes this problem a hard one to solve. “Some tiny fraction of the population is the most susceptible to being shoved around by A.I.,” Mr. Yudkowsky said, and they are the ones sending “crank emails” about the discoveries they’re making with chatbots. But, he noted, there may be other people “being driven more quietly insane in other ways.” > Reports of chatbots going off the rails seem to have increased since April, when OpenAI briefly released a version of ChatGPT that was overly sycophantic. The update made the A.I. bot try too hard to please users by “validating doubts, fueling anger, urging impulsive actions or reinforcing negative emotions,” the company wrote in a blog post. The company said it had begun rolling back the update within days, but these experiences predate that version of the chatbot and have continued since. Stories about “ChatGPT-induced psychosis” litter Reddit. Unsettled influencers are channeling “A.I. prophets” on social media. ### Customers keep buying Predator spyware despite US sanctions URL: https://www.metacurity.com/customers-keep-buying-predator-spyware-despite-us-sanctions/ Last updated: 2025-06-13T14:01:32.000Z Ukraine paralyzed top Siberian ISP, Meta AI shows other customers' sensitive info, Whole Foods still grappling with product disruptions, Malicious adtech is highly interconnected, Cybercrims are selling lost RCMP key containing informants' data, BEC scammer sentenced to four years, much more _This post is for paying subscribers only._ ### Operation Secure disrupts infostealer malware groups worldwide URL: https://www.metacurity.com/operation-secure-disrupts-infostealer-malware-groups-worldwide/ Last updated: 2025-06-12T13:55:58.000Z Microsoft 365 Copilot harbored critical 'EchoLeak' security flaw, FIN6 targets LinkedIn recruiters. Smart watches can steal data in air-gapped systems, Cybercrims stole NHS Active Directory database, Two journalists hacked using Paragon spyware, Ransomware hits large hospitals in Maine, much more _This post is for paying subscribers only._ ### Cambridge researchers warn that private companies are harvesting period tracker data URL: https://www.metacurity.com/cambridge-researchers-warn-that-private-companies-are-harvesting-period-tracker-data/ Last updated: 2025-06-11T13:59:42.000Z United Natural Foods expects system restoration by 6/15, Gabbard wants feds to use private sector for intel tech needs, States sue to stop sale of 23andMe DNA data, Microsoft issues at least 67 patches, Microsoft fixes zero day exploited by Stealth Falcon, so much more _This post is for paying subscribers only._ ### US grocery distributor United Natural Foods is the latest retail-related cyber victim URL: https://www.metacurity.com/us-grocery-distributor-united-natural-foods-is-the-latest-retail-related-cyber-victim/ Last updated: 2025-06-10T14:17:46.000Z M&S reopens website to shoppers, Google account phone numbers could have been brute-forced, TX and IL warn of breach-related data exposure, NHS blood supply still short a year after ransomware attack, Comcast and Digital Realty were Salt Typhoon victims, Ofcom probes 4chan safety, much more _This post is for paying subscribers only._ ### Trump cyber EO reverses some parts of Biden, Obama orders URL: https://www.metacurity.com/trump-cyber-eo-reverses-some-parts-of-biden-obama-orders/ Last updated: 2025-06-09T14:03:51.000Z Starlink endangers WH security, Nigeria convicts Chinese cybercriminals, US sentences Nigerian hacker, ICE arrests Oz hacker, Italy ends contract with spyware company Paragon, Supreme Ct. gives DOGE our social security data, BADBOX 2.0 infects 1m+ devices, EU issues cyber blueprint, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 5/31/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-5-31-25/ Last updated: 2025-06-07T10:58:33.000Z Bashar al-Assad was toppled by spyware, Facial recognition threatens us all with deportation, VC money fuels worker surveillance, Will Trump launch offensive cyber ops on US networks?, The Pall Mall Process and commercial cyber intrusions, Self-confidence leads to GenAI skepticism, more _This post is for subscribers only._ ### US feds seize nearly $8 million from fake DPRK IT workers URL: https://www.metacurity.com/us-feds-seize-nearly-8-million-from-fake-dprk-it-workers/ Last updated: 2025-06-06T11:43:55.000Z Cellebrite buys Corellium for $200m, Play gang breached 900 orgs, Two ViLE members sentenced, UK revenue offices lost $64m to phishing scam, One-fifth of Ukraine IP space under Russian control, Cairncross defends his lack of tech expertise, Ukraine claims hack of Russian aviation giant, much more _This post is for paying subscribers only._ ### CISA nominee Plankey pulled from Senate confirmation hearing URL: https://www.metacurity.com/cisa-nominee-plankey-pulled-from-senate-confirmation-hearing/ Last updated: 2025-06-05T11:40:32.000Z The Com has been hacking Salesforce tools, Chinese hackers broke into US telecoms in 2023, Law enforcement busts up BidenCash, China issues warrants for 20 alleged Taiwanese hackers, Feds are probing CrowdStrike's 2024 outage, Reddit sues Anthropic for scraping comments, much more _This post is for paying subscribers only._ ### 1,000 CISA employees have left the agency since January URL: https://www.metacurity.com/1-000-cisa-employees-have-left-the-agency-since-january/ Last updated: 2025-06-04T14:04:59.000Z Victoria's Secret postpones earnings release after cyberattack, New security fixes for Qualcomm chips, AFP nabs nearly two dozen in sextortion sting, Marriott can't be sued for breach, Trump dumps AI Safety Institute, Indian grocery delivery startup wiped out by hack, so much more _This post is for paying subscribers only._ ### Top cyber vendors hope to clean up crazy threat group naming practices URL: https://www.metacurity.com/top-cyber-vendors-hope-to-clean-up-crazy-threat-group-naming-practices/ Last updated: 2025-06-03T14:20:49.000Z Coinbase knew of data leak in January, Prolific swatter pleads guilty, Cartier confirms data breach, Abilene gropes for recovery after rejecting ransom payment, North Face customers' data stolen in credential stuffing attacks, $11.5m stolen from BitoPro hot wallets, much more _This post is for paying subscribers only._ ### Law enforcement took down cybercriminal malware testing service AVCheck URL: https://www.metacurity.com/law-enforcement-took-down-cybercriminal-malware-testing-service-avcheck/ Last updated: 2025-06-02T13:57:52.000Z German police ID Trickbot's "Stern," BitMEX thwarts Lazarus Group attack, Shin Bet thwarted 85 Iranian cyberattacks aimed at civilians, Vibe coding app Lovable failed to fix critical flaw, China's quantum satellite Micius has a security flaw, Russia's Unit 29155 has a hacker team, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 5/24/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-5-24-25/ Last updated: 2025-05-31T13:43:12.000Z How regular Americans unwittingly aid DPRK job scams, Self-driving truck startup sent massive amounts of IP to China, The Com claims it's behind the Coinbase hack, It feels like Panetta's Cyber Pearl Harbor is nigh, Brazil's counterintel agents exposed Russian spy imposters _This post is for subscribers only._ ### US sanctions Filipino firm for pig butchering scams that cost Americans $200 million URL: https://www.metacurity.com/us-sanctions-filipino-firm-for-pig-butchering-scams-that-cost-americans-200-million/ Last updated: 2025-05-30T13:19:57.000Z DIA IT specialist tried to share classified info, Oz firms must now report paying ransom, Oregon bans sale of precise geolocation data, CISA's KEV catalog has unexploitable flaws, ConnectWise reports APT cyberattack, Imposter posed as WH chief of staff, Netskope preps for $500m IPO, much more _This post is for paying subscribers only._ ### UK military will ramp up offensive cyber attacks against Russia and China URL: https://www.metacurity.com/uk-military-will-ramp-up-offensive-cyber-attacks-against-russia-and-china/ Last updated: 2025-05-29T14:09:52.000Z Victoria's Secret hit by cyberattack, LexisNexis risk arm breach affects 364K, Procurement database exposed Russian nuclear bases to attack, US gov't to mix DNA data of migrant children and sex offenders, ASUS routers ensnared by novel botnet, APT41 exploited Google Calendar, much more _This post is for paying subscribers only._ ### Russian group Laundry Bear hacked Dutch police, targets Ukraine-allied nations URL: https://www.metacurity.com/russian-group-laundry-bear-hacked-dutch-police-targets-ukraine-allied-nations/ Last updated: 2025-05-28T13:13:12.000Z Iranian pleads guilty to Robbinhood, UNC6032 uses prompt-to-video AI tools to lure victims, Russia sends former programmer to prison for 14 years, Czech Republic says China's APT31 hacked its comms networks, Nigeria arrests 20 for exams hacking, Bad flaw found in GitHub MCP integration, much more _This post is for paying subscribers only._ ### CISA's leadership drain, budget cuts limit US defense against Chinese cyberattacks URL: https://www.metacurity.com/cisas-leadership-drain-budget-cuts-limit-us-defense-against-chinese-cyberattack/ Last updated: 2025-05-27T12:35:14.000Z China blames Taiwan for attack, S. Korea expands hacking probe, 184m account creds exposed in Pakistan, LLM found a Linux zero day, Musk's use of Grok in US gov't endangers data, Adidas reports data theft, Hackers try to blackmail Solana co-founder, Morocco seeks card theft fugitive, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 5/17/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-5-17-25/ Last updated: 2025-05-24T13:28:35.000Z The rise and fall of a dark web spiritual drug seller, How Google searches nailed an arson murderer, Crypto thieves who spurn hacking for violence, Getting rich off music bots, Storing passwords in plastic, How jailbroken LLMs cause harm _This post is for subscribers only._ ### Operation Endgame deals a direct blow to the ransomware kill chain URL: https://www.metacurity.com/operation-endgame-deals-a-direct-blow-to-the-ransomware-kill-chain/ Last updated: 2025-05-23T12:43:16.000Z Operation RapTor arrests 270 dark web vendors, 184m records exposed in an unsecured Elastic database, Local US governments breached via exploited Trimble Cityworks zero-day, Cetus Protocol exploited for $223m, FTC settles GoDaddy security failure charges, 3AM ransomware is on the rise, much more _This post is for paying subscribers only._ ### Russia's APT28 accused of infiltrating Western logistics, technology firms URL: https://www.metacurity.com/russias-apt28-accused-of-infiltrating-western-logistics-technology-firms/ Last updated: 2025-05-22T12:53:12.000Z Int'l partners destroy Lumma Stealer infrastructure, IT contractor breach led to M&S attack, Interlock stole data from West Lothian, 70K Coinbase customers exposed, EU sanctions GRU for disinformation, Google offers secure cloud options to EU, Twin brothers destroyed FOIA requests, much more _This post is for paying subscribers only._ ### Krebs on Security hit by 'test run' DDoS attack that peaked at 6.3 terabits of data per second URL: https://www.metacurity.com/krebs-on-security-hit-by-test-run-ddos-attack-that-peaked-at-6-3-terabits-of-data-per-second/ Last updated: 2025-05-21T13:32:36.000Z TeleMessage hack leaked broader swathe of US officials' messages than reported, Nineteen-year-old pleads guilty to PowerSchool hack, M&S to take $403m profit hit, Ohio health giant hit by Interlock ransomware, NSO Group gets cold shoulder in DC, Patel shutters FISA watchdog office, much more _This post is for paying subscribers only._ ### UK, Danish food companies disrupted by cyberattacks URL: https://www.metacurity.com/uk-danish-food-companies-disrupted-by-cyberattacks/ Last updated: 2025-05-20T13:25:01.000Z DDoSecrets published a data trove from TeleMessage hack, NOLA cops engaged in massive facial recognition, Stalkerware apps go offline, Chinese tech company hit by cyberattack, UK Post Office pays postmasters for leaked data, NHS cyberattacks risked clinical harm, much more _This post is for paying subscribers only._ ### Cyberattack exposed criminal records, financial data for UK legal aid applicants URL: https://www.metacurity.com/cyberattack-exposed-criminal-records-financial-data-for-uk-legal-aid-applicants/ Last updated: 2025-05-19T13:15:34.000Z Japan approves proactive cyber ops, PayPal Mafia mogul exposed in Coinbase hack, Hackers tried to breach Binance and Kraken with social engineering attack, SEC X hacker gets 14 months, Pentagon halted cyber ops against Russia for one day, Procolored printers are full of malware, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 5/10/25 URL: https://www.metacurity.com/next-lonbest-infosec-related-long-reads-for-the-week-of-5-10-25g-read-3/ Last updated: 2025-05-17T11:53:14.000Z How MSTIC works, The Nigerian scammers who tragically extort minors, Clearview AI's deadly agenda, A hostage negotiator outsmarts ransomware hackers, Trump is killing misinformation research, How the TV show "You" shows the stalking dangers of being online _This post is for subscribers only._ ### US charges 13 men with stealing $264 million in crypto URL: https://www.metacurity.com/us-charges-13-men-with-stealing-264-million-in-crypto/ Last updated: 2025-05-16T13:11:47.000Z Chinese solar inverters contain unexplained comms kit, FBI warns of threat actors use AI voices to impersonate US officials, Fancy Bear is targeting Ukraine officials' email accounts, Pompompurin to forfeit $700k, RI could sue Deloitte for sleeping on Brain Cipher hack of its VPN, much more _This post is for paying subscribers only._ ### Hacking incident could cost Coinbase $400 million, $20 million reward offered URL: https://www.metacurity.com/hacking-incident-could-cost-coinbase-400-million-20-million-reward-offered/ Last updated: 2025-05-15T12:53:59.000Z Google warns hackers could target US retailers, Co-op acted fast in limiting cyberattack, Crime bazaar to shut down, CFPB cancels protection against data brokers, Steelmaker Nucor hit by cyber incident, EU law enforcement took down scam operation, OpenAI unveils safety hub, much more _This post is for paying subscribers only._ ### Two DPRK scam IT workers exposed along with 1,000 linked email addresses URL: https://www.metacurity.com/two-dprk-scam-it-workers-exposed-along-with-1-000-linked-email-addresses/ Last updated: 2025-05-14T14:19:46.000Z Kosovo man extradited to the US for fraud, EU vuln database fully launched, Xinbi Guarantee emerges as dark web money launderer, MSFT issues 72 fixes, New Spectre bypass id'ed, DEFCON wins Hadnagy suit, Gov't email notification system used to send scams, CISA backtracks on RSS elimination, much more _This post is for paying subscribers only._ ### Spain probes small electric firms' cyber defenses in connection with blackout URL: https://www.metacurity.com/spain-probes-small-electric-firms-cyber-defenses-in-connection-with-blackout/ Last updated: 2025-05-13T13:24:55.000Z Cyber event disrupts Alabama gov't, M&S hackers stole customers' data, M&S hackers seek to protect Russia, Bulgarian spies sentenced in London, Prosecutors seek two-years for SEC X account hacker, Dior hack exposes wealthy Chinese customers, CrowdStrike CEO gifts $1b in stock, much more _This post is for paying subscribers only._ ### US feds seize two top botnet sites in Operation Moonlander URL: https://www.metacurity.com/us-feds-seize-two-top-botnet-sites-in-operation-moonlander/ Last updated: 2025-05-12T14:08:04.000Z Florida encryption backdoor bill fails, Suspect in ransomware attack on Dutch research institute detained, College website iClicker was compromised, Google to pay Texas $1.4b for privacy violations, Wikimedia challenges UK Online Safety Act, Ledger Discord server was hacked, so much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 5/3/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-5-3-25/ Last updated: 2025-05-10T12:51:13.000Z How Riot Games is battling game cheats, How personalized ads make young teens hate themselves, The UN Cybercrime Convention v. the Budapest Convention, How a millennial coder became a saint, The short lifetime of digital apps _This post is for subscribers only._ ### Microsoft banned employee use of Deepseek on security, propaganda grounds URL: https://www.metacurity.com/microsoft-banned-employee-use-of-deepseek-on-security-propaganda-grounds/ Last updated: 2025-05-09T13:26:26.000Z Sexual abuse victims' data in NYC and Baltimore Catholic archdioceses likely compromised, DOGE engineer compromised by malware, Japanese hacked brokerage accounts lost $2b in first four months of 2025, Ed giant Pearson hacked, FBI warns of EoL routers, Robot dog exposed to hacking, much more _This post is for paying subscribers only._ ### PowerSchool hackers are extorting schools despite the company's ransom payment URL: https://www.metacurity.com/powerschool-hackers-are-extorting-schools-despite-the-companys-ransom-payment/ Last updated: 2025-05-08T13:37:18.000Z DOGE violates privacy and security to build centralized database, LockBit hit by data breach, TeleMessage app was rejected by some US agencies, Google discovers new Cold River malware, Europol busts four DDoS'ers, Ransomware hits German beer giant, Feds warn oil and gas sectors, much more _This post is for paying subscribers only._ ### Jury smacks NSO Group with $168 million in damages over WhatsApp spying URL: https://www.metacurity.com/jury-smacks-nso-group-with-168-million-in-damages-over-whatsapp-spying/ Last updated: 2025-05-07T13:43:33.000Z Signal fork TeleMessage used by Trump officials stored chats in plaintext, SK Chairman publicly apologizes for breach, Journalists uncovered MrDeepFakes using open source info, NSA to axe 8% of workforce, Treasury sanctions Burmese scam operation, Turkey thwarted second pager attack, much more _This post is for paying subscribers only._ ### TeleMessage suspends service following reported hack URL: https://www.metacurity.com/telemessage-suspends-service-following-reported-hack/ Last updated: 2025-05-06T14:06:47.000Z Hackers stole records from deportation airline GlobalX Air, Man who allegedly helped launder $190m in stolen crypto was busted in Israel, Hegseth used Signal in at least 12 chats, SK Telecom task force discovered 8 new malware strains, easyjson open source code might be a natsec risk, much more _This post is for paying subscribers only._ ### Trump EO gives DOGE access to all federal systems, targets states, and injects cybersecurity risks URL: https://www.metacurity.com/trump-eo-gives-doge-access-to-all-federal-systems-targets-states-and-injects-cybersecurity-risks/ Last updated: 2025-05-05T17:16:16.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/05/Elon_Musk_-54348704357--1.jpg) Source: [Gage Skidmore](https://www.flickr.com/people/22007612@N05?ref=metacurity.com) from Surprise, AZ, United States of America. *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can!](#/portal/support) --- Metacurity reviewed a memo sent from the US Office of Management and Budget (OMB) to all federal civilian agencies instructing them how to comply with an [executive order](https://www.whitehouse.gov/presidential-actions/2025/03/stopping-waste-fraud-and-abuse-by-eliminating-information-silos/?ref=metacurity.com) (EO) issued by the White House on March 20, 2025. That EO, entitled *Stopping Waste, Fraud, and Abuse by Eliminating Information Silos*, directed agencies to rescind or modify all guidance that serves as a barrier to the inter- or intra-agency sharing of unclassified information. It further directed the agencies to give federal officials designated by the president or agency heads (or their designees) full and prompt access to all unclassified agency records, data, software systems, and information technology systems, including authorizing and facilitating both the intra- and inter-agency sharing and consolidation of unclassified agency records. It also required agency heads to review agency formal regulations governing unclassified data access, including system of records notices, and, within 30 days of the date of this order, submit a report to the Office of Management and Budget cataloging those regulations and recommending whether any should be eliminated or modified. Finally, the order directed agency heads to take all necessary steps to ensure the federal government has unfettered access to comprehensive data from all state programs that receive federal funding, including data generated by those programs but maintained in third-party databases. Below is the OMB memo's text, retyped with the same punctuation, underlining, and bold emphasis as in the original memo. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/05/ombinstructions-2.png) Below is an image of the column headers in the template specifying the data items OMB sought from every federal agency, encompassing all records, data, software systems, and information technology systems. ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/05/data-src-image-1db37cf3-7ca5-41d1-9755-c235368c2a80.jpeg) After reviewing the memo, Metacurity spoke with three experts on US government technology systems currently working in the federal government as higher-level IT specialists, technology branch or division heads, or systems engineers, as well as one software engineer who was recently fired as part of Elon Musk’s so-called Department of Government Efficiency (DOGE) efforts to slash the US government payroll. Metacurity also spoke with someone experienced in tracking federal grants to state governments. All the experts requested and were given anonymity. Most said they experienced rising concern over what they characterize as the current administration's alarming mismanagement of the US government’s digital technology infrastructure. Metacurity attempted to reach OMB’s media relations department twice via email for questions and comments, but received no response. A phone call to OMB’s media relations phone number posted on its website went unanswered, and a phone call to OMB’s main phone line posted on its website ended with a recorded message that allowed no opportunity to leave a voicemail. ## Is this a DOGE initiative? Although the EO's ostensible purpose is to “stop waste, fraud, and abuse,” which is also the purported goal of the DOGE project, the EO only indirectly mentions DOGE in an [accompanying fact sheet](https://www.whitehouse.gov/fact-sheets/2025/03/fact-sheet-president-donald-j-trump-eliminates-information-silos-to-stop-waste-fraud-and-abuse-60f3/?ref=metacurity.com). Nevertheless, one source who filled out the OMB-requested template told Metacurity that they understood the EO’s goal was to provide DOGE employees across the federal government, not just OMB, with access to their department’s databases and systems. “DOGE is everywhere,” this source said. Another source inside the federal government who has experience managing technology systems across several agencies, told Metacurity, “\[DOGE\] is going to this length because they’re not getting the access we think they’re getting. I take the \[silo EO\] as a sign that they failed at getting \[into systems\] by going roughshod over everyone” early in the administration. Finally, a [GSA Town Hall](https://vimeo.com/gsavisualcommunications/review/1067975794/725fa8e4b9?ref=metacurity.com) held on March 20, the same day as the release of the silo EO, suggests that the EO was written by the DOGE people within GSA or at least with the help of those DOGE workers. However, Stephen Ehikian, acting GSA Director, [proclaimed](https://www.wired.com/story/elon-musk-doge-mystery-general-services-administration/?ref=metacurity.com) that there are no DOGE people within GSA. This contention flies in the face of the fact that DOGE workers took over a section of the GSA’s headquarters building in DC, on the same floor where Ehikian works. Ehikian is married to a former designer at Musk’s social media company X. It's possible that the Trump administration downplayed DOGE’s involvement in the EO because DOGE had already generated bad press by the time the EO was released, and had sparked grassroots protests across the US. Speaking at a [webinar](https://cdt.org/event/doge-and-government-data-privacy/?ref=metacurity.com) on DOGE hosted by the Center for Democracy and Technology, Nandan M. Joshi, attorney with Public Citizen Litigation Group, said, “Maybe they didn't mention DOGE because DOGE became a little bit more toxic by March 20th.” ## What’s new in OMB’s request? One government technology expert told Metacurity that the concept of knocking down information silos across the federal government arose in the past as a laudable goal. “In the before times, it would be constructive and useful to have this kind of data sharing,” the expert said. However, given the current fears about and lack of visibility into what DOGE is doing, this kind of data sharing now seems “menacing,” the expert added. Another expert, a systems engineer who works on a government system, thinks this kind of information sharing in the current environment goes beyond menacing and is an actual threat. “There's a credible sort of threat to all of this,” this expert said. “Even inside our agencies, our instructions have been to limit information because we don't want \[DOGE\] to do activities like node building or the kinds of things we were instructed to do with the asinine five things memo.” \[Elon Musk [ordered](https://www.hrgrapevine.com/us/content/article/2025-04-22-how-government-hr-officials-left-musks-five-accomplishments-order-doomed-to-fail?utm%5Fsource=suggested&utm%5Fmedium=article&utm%5Fcampaign=2024-02-05-5-million-applications-to-140000-hires-inside-eys-billion-dollar-investment-in-human-centric-ai) all federal workers to send a memo listing five accomplishments each week or consider themselves fired, a directive that ultimately failed.\] Experts say that government agencies should already have a comprehensive list of their “records, data, software systems, and information technology systems,” as [required](https://security.cms.gov/learn/federal-information-security-modernization-act-fisma?ref=metacurity.com) by the Federal Information Security Modernization Act (FISMA). But, as one expert told Metacurity, “they certainly don't have all of the \[informal policies and federal authorities\] that are going to be associated” with each entry in the template, which can, for large agencies, run into hundreds of entries. “The idea that this information can just be summoned at the snap of a finger is comical, and it speaks to the sort of complexity-squashing viewpoints of people who are writing these memos," this expert said. “I would assume that what's going on here is a fishing expedition.” Another expert suggested that even if the information can be easily tracked down in existing government repositories, DOGE workers have shown little patience for doing their own research. “In my experience, they don't go carefully looking through government processes to find the existing documentation,” this expert said. “Probably they just don't have the patience for that, or they don't think they have the time for it. So, they tend to demand information they could have easily found.” ## Why does the administration want this data? Almost all the experts said they seriously doubt OMB’s massive information-gathering effort has anything to do with improving government efficiency. “Any casual observer of what DOGE has been doing, at least certainly from the perspective of people inside the government, would say nothing that they're doing has anything to do with efficiency,” one expert told Metacurity. Most experts suggested that OMB crafted its information request to provide DOGE and the Trump administration with an easily scanned, bird's-eye view of federal government programs, enabling quick and easy elimination of efforts that don’t align with the White House’s priorities. “When you learn [that they're taking over software systems and they're taking out data](https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security?ref=metacurity.com), you got to wonder why, and the number of things that they could be doing is large,” one expert speculated, from engaging in government data manipulation as part of private sector profiteering schemes to creating a state tool of repression to providing fresh data for Elon Musk’s commercial AI systems and much more. But, the consensus among the experts is that the administration wants the data to shut down ideologically undesirable programs more easily. “I have to assume the intent is to identify programs providing funding for DEI or reproductive health or anything else that the regime has decided they don't want,” one expert said. This expert also added that another incentive for collecting this information could be “that they're sniffing around for things that they could either use against their political enemies,” or create unified databases to target people they don’t like. “You can create RFK’s registry of autistic people, or you can just go down the list. We're going to grab everybody's health records so that we can expel all the \[larger\] people from the government, or whatever insane thing they're going to come up with next,” the expert said. ## Why does the EO and OMB emphasize state data? Of all the components of the EO and the OMB memo that struck experts as new was the directive to “ensure the federal government has unfettered access to comprehensive data from all state programs that receive Federal funding, including data generated by those programs but maintained in third-party databases.” One expert said this directive is driven by the reality that “there is no central repository to find out what federal money states get. No big database lists everything every state gets from the federal government.” An expert who tracks federal funding of state government programs concurs. “There is no central repository for a state to look at or for anyone to look at and see, this is how much I get from this program,” the expert told Metacurity. “[USA Spending](https://www.usaspending.gov/?ref=metacurity.com) is kind of that. But the USA Spending website has reliability issues.” According to this expert, the Trump administration will struggle to corral state-level spending into one convenient database. “It's going to be hard because every program is set up differently. It has different authorizations and different regulations,” the expert said. Most states hire local website developers to track the information that OMB seeks. Another expert told Metacurity, “My expectation is that they \[DOGE\] don't have the access because all the information being collected is in literally 10,000-plus databases and programs across the federal government. It’s massive.” All the experts agree that the Trump administration is likely seeking to identify state-level funding programs to exercise leverage over state governments, much like it has sought to coerce law firms and universities to accede to its demands. “I’m speculating that they're going to start to lean on people in state governments just as they did at universities,” one expert said. “And Columbia was the first one they leaned on, and Columbia folded immediately, probably partly because they didn't know it was coming.” ## Does OMB’s effort pose a cybersecurity threat? One criticism that has dogged DOGE since the outset of the Trump administration is its lack of attention to cybersecurity. Some infosec professionals say that DOGE has made Americans’ most sensitive data less private and exposed federal government systems to threat actors by adopting a move-fast-and-break-things attitude. Experts told Metacurity they were concerned about several aspects of how OMB has sought to collect the data under the EO. First, according to one expert who submitted the information to OMB, they did so as a document attached to an email. Although one expert told Metacurity that sending this information as an attachment on a federal government email system is not a significant security concern, others weren’t so sure. “I've definitely seen a lot of probably questionable information being sent in an unencrypted email in the government in the past,” a different expert said. “It's not great. It's never great when you send that kind of information through a government email.” Another expert said, “If you search on a scale from some random Joe's Yahoo mail to an actual classified email system, government NIPR \[non-classified internet protocol router\] mail, as it's typically called, is going to be an actual Microsoft Exchange server and is going to be more secure.” However, this expert stressed that while ordinary adversaries won’t likely be able to access government emails, history has repeatedly shown that sophisticated threat actors such as nation-states have compromised US government email systems. “Federal unclassified network email has been getting pwned pretty regularly for the past 10 years,” the expert said. “I don't see why this would be any different.” Moreover, according to this expert, “We have no sense of where the information is going afterwards. Once it gets sent to that inbox, it could get emailed to all sorts of people, and there's very little control over that. My default assumption is that any message being sent, especially unencrypted over an unclassified email system, even if it's government to government, you have to assume that's going to be compromised, if not now, then in a reasonable time in the future.” This expert said the situation is aggravated by “people who know how to secure these systems getting bullied out of the government or replaced by mercenaries who don't care that much.” Further compounding all these problems is that chief information security officers (CISOs) were not included in the list of agency officials who were supposed to be vetting the information and how it was supplied to OMB. According to one expert, CISOs are often overlooked in these kinds of information requests because “they tend to slow things down.” ## Is role-based access the same as admin access in DOGE-speak? Perhaps most concerning from a cybersecurity perspective is that one expert who compiled the information requested by OMB was informed that they should prepare to provide “role-based access” to federal officials who demand access under the EO. Role-based access means that persons are granted access according to their defined roles. For example, some roles need read-only access to the data or systems. Others might need greater privileges, such as admin access, which usually gives individuals full ability to infiltrate or exfiltrate data, alter the data or systems, or even shut them down altogether. When this expert sought clarification on whether this role-based access would include admin access when requested, the answer they received was yes. A different expert told Metacurity, “Role-based access doesn't mean necessarily admin access, but based on what I've seen elsewhere in the government, the truth is that it means admin access.” Yet another expert said, “I will strongly reaffirm the assertion that they're probably going to try to [get administrator or root-level access](https://www.theatlantic.com/politics/archive/2025/02/doge-musk-federal-agencies-takeover/681744/?ref=metacurity.com). Asking for admin-level access to these systems will be on the table across the government.” Granting DOGE workers admin access might also open an opportunity for threat actors to pose as DOGE workers, given that DOGE is a shadowy organization with unclear boundaries and many unidentifiable employees. “There’s a squirrely definition of who DOGE is,” one expert said. They added, “There are people who are associated with Elon Musk's companies who are running around the government doing stuff, but with no org chart. Anyone could show up and claim to be DOGE, but we don't know who they are. So, it could be a foreign threat actor.” ### A hacker stole content from the Telemessage system used by the US government URL: https://www.metacurity.com/a-hacker-stole-contents-of-telemessage-system-used-by-the-us-government/ Last updated: 2025-05-05T12:42:04.000Z Criminal scam network run by Darcula exposed by journalists, DragonForce takes credit for Co-op attack, NoName attacked Romanian gov't websites on election day, US indicts Black Kingdom ransomware dev, Trump wants to slash nearly $500m from CISA, Qilin claims Cobb Co. attack, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 4/26/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-4-26-25/ Last updated: 2025-05-03T10:30:46.000Z How North Korean workers are stealing your jobs, Why China bowed out of overseas hackathons, Interpol lab digs into cybercrime innovation, The Fourth Amendment can thwart AI-powered authoritarian surveillance, Meta turned a blind eye to preventing AI personas from sharing fantasy sex with children _This post is for subscribers only._ ### Harrods becomes the third top UK retailer to fend off a cyberattack URL: https://www.metacurity.com/harrods-becomes-the-third-top-uk-retailer-to-fend-off-a-cyberattack/ Last updated: 2025-05-02T14:05:43.000Z Nefilim attacker charged & extradited to US, Hacker pleads guilty to Disney Slack data theft, WI man lands 3.75-year sentence for swatting spree, Apple sent new round of spyware notices, Raytheon and Nightwing Group fined for bad cyber, Kraken toys with fake DPRK job applicant, much more _This post is for paying subscribers only._ ### Alleged key leaders in 764 online exploitation group arrested, face life in prison URL: https://www.metacurity.com/key-leaders-in-764-online-exploitation-group-arrested-face-life-in-prison/ Last updated: 2025-05-01T14:33:19.000Z Polish cops dismantle online fraud group, FBI shares 42K LabHost phishing domains, RSAC news round-up, RansomHub affiliates might have migrated to Qilin, MSFT won't change RDP protocol that permits revoked passwords, Japanese logistics provider hit by ransomware, Persona lands $200m, much more _This post is for paying subscribers only._ ### France accuses Russia's APT28 of a string of serious cyberattacks going back to 2021 URL: https://www.metacurity.com/france-accuses-russias-apt28-of-a-string-of-serious-cyberattacks-going-back-to-2021/ Last updated: 2025-04-30T16:29:17.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/04/Flag_of_the_Main_Intelligence_Directorate.svg-1.png) Flag of Russia's GRU. Source: [Haisollokopas](https://commons.wikimedia.org/wiki/User:Haisollokopas?ref=metacurity.com "User:Haisollokopas"): *Metacurity is a reader-supported publication that requires significant work and non-trivial expenses*. *We rely on the generous support of our paid readers. Please consider upgrading your subscription to support Metacurity's ongoing work. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you're unable to commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can!](#/portal/support) ### France's foreign ministry explicitly accused Russia's GRU military intelligence agency of mounting cyber attacks on a dozen entities, including ministries, defense firms, and think tanks, since 2021, in an attempt to destabilise France. The accusations, levelled at GRU unit APT28, which officials said was based in Rostov-on-Don in southern Russia, are not the first by a Western power, but it is the first time Paris has blamed the Russian state based on its own intelligence. The ministry said in a statement that APT28's attacks on France go as far back as 2015, when the TV5 Monde station was taken off air in a hack claimed by purported Islamic State militants. France said APT28 had been behind the attack, and another in the 2017 presidential election when emails linked to the party and campaign of the eventual winner, Emmanuel Macron, were leaked and mixed with disinformation. According to a report by France's National Cybersecurity Agency (ANSSI), APT28 has sought to obtain strategic intelligence from entities across Europe and North America. Officials said the government had decided to go public to keep the public informed at a time of uncertainty in domestic politics and over Russia's war in Ukraine. ANSSI said there had been a jump last year in the number of attacks on French ministries, local administrations, defence companies, aerospace firms, think tanks, and entities in the financial and economic sector. They said APT28's most recent attack was in December, and that some 4,000 cyber attacks had been ascribed to Russian actors in 2024, an increase of 15% on 2023\. ([John Irish / Reuters](https://www.reuters.com/world/europe/first-france-accuses-russian-intelligence-repeated-cyber-attacks-2025-04-29/?ref=metacurity.com)) **Related*:* [*Diplomatie.gouv.fr*](https://www.diplomatie.gouv.fr/fr/dossiers-pays/russie/evenements/evenements-de-l-annee-2025/article/russie-attribution-de-cyberattaques-contre-la-france-au-service-de?ref=metacurity.com)*,* [*ANSSI*](https://www.cert.ssi.gouv.fr/cti/CERTFR-2025-CTI-006/?ref=metacurity.com)*,* [*ANSSI*](https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-006.pdf?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/world/2025/apr/29/france-says-russian-hackers-behind-attack-on-macrons-2017-presidential-campaign?mid=1&ref=metacurity.com#cid=2803407)*,* [*Ukrinform*](https://www.ukrinform.net/rubric-polytics/3987382-french-diplomacy-accuses-russia-of-longterm-cyber-espionage.html?mid=1&ref=metacurity.com#cid=2803479)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/france-ties-russian-apt28-hackers-to-12-cyberattacks-on-french-orgs/?mid=1&ref=metacurity.com#cid=2802444)*,* [*Politico EU*](https://www.politico.eu/article/macron-leaks-cyberattack-russia-gru-moscow-war/?ref=metacurity.com)*,* [*BleepingComputer*](https://www.bleepingcomputer.com/news/security/france-ties-russian-apt28-hackers-to-12-cyberattacks-on-french-orgs/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/france-blames-russian-military-intelligence-for-hacks-against-local-orgs?ref=metacurity.com)*,* [*The Kyiv Independent*](https://kyivindependent.com/france-accuses-russia-of-stepping-up-cyberattacks-since-2021-targeting-ministries-defense-sector/?ref=metacurity.com)*,* [*Daily Sabah*](https://www.dailysabah.com/business/tech/france-accuses-russias-military-intelligence-of-repeated-cyberattacks?ref=metacurity.com)*,* [*r/worldnews*](https://www.reddit.com/r/worldnews/comments/1kao2za/in%5Ffirst%5Ffrance%5Faccuses%5Frussian%5Fintelligence%5Fof/?ref=metacurity.com)*,* [*ABC News*](https://abcnews.go.com/International/wireStory/france-accuses-russia-linked-hacking-group-targeting-paris-121306312?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/france-russia-apt28-cyberespionage/?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/world/europe/france-blames-russia-for-years-of-cyberattacks-ef12c332?mod=djemCybersecruityPro&tpl=cs&ref=metacurity.com)*,* [*France24*](https://www.france24.com/en/france/20250429-france-accuses-russia-cyberattacks-defence-finance-media-sectors?mid=1&ref=metacurity.com#cid=2803129) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/04/franceapt28.png) Targeting and compromise of French entities since 2021 by APT28 operators. Source: ANSSI ### Speaking at this year's RSA conference, Homeland Security Secretary Kristi Noem outlined her plans to refocus the Cybersecurity and Infrastructure Security Agency (CISA) on protecting critical infrastructure from increasingly sophisticated threats, particularly from China, while distancing the agency from what she characterized as mission drift under previous leadership. Noem provided the most detailed vision yet of how the current administration is pushing CISA to a “back-to-basics” approach aimed at hardening defenses against adversaries who have demonstrated capabilities to infiltrate critical systems. “We’re going to make sure that we need to put CISA back to focusing on its core mission,” Noem said. “They were deciding what was truth and what was not. And it’s not the job of CISA to be the ‘Ministry of Truth.’ It’s to be a cybersecurity agency that works to protect this country.” The “Ministry of Truth” comment is a reference to CISA’s misinformation and election security efforts, which have been inflamed in recent weeks after President Donald Trump signed an executive order stripping former CISA leader Chris Krebs of his security clearance and calling for a review of Krebs’ actions as a government employee. Noem called that work “inappropriate” in an accompanying on-stage interview with José-Marie Griffiths, the president of Dakota State University. ([Greg Otto / Cyberscoop](https://cyberscoop.com/kristi-noem-rsac-2025-cisa-mission/?ref=metacurity.com)) **Related:** [*The Record*](https://therecord.media/kristi-noem-rsa-keynote-info-sharing-law?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/04/28/nsa%5Fcisa%5Fbosses%5Fnotably%5Fabsent/?ref=metacurity.com)*,* [*KTVU*](https://www.ktvu.com/news/homeland-security-secretary-visits-sf-cybersecurity-conference?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/04/30/noem%5Fput%5Fcisa%5Fon%5Fmission/?ref=metacurity.com)*,* [*NextGov/FCW*](https://www.nextgov.com/cybersecurity/2025/04/just-wait-see-how-cisa-reforms-play-out-dhs-head-tells-cyber-community/404936/?ref=metacurity.com) ### Communication app WhatsApp, used by roughly 3 billion people around the world, will roll out cloud-based AI capabilities in the coming weeks that are designed to preserve WhatsApp’s defining security and privacy guarantees while offering users access to message summarization and composition tools. Meta has been incorporating generative AI features across its services that are built on its open source large language model, Llama. And WhatsApp already includes a light blue circle that gives users access to the Meta AI assistant. But many users have balked at this addition, given that interactions with the AI assistant aren’t shielded from Meta the way end-to-end encrypted WhatsApp chats are. The new feature, dubbed Private Processing, is meant to address these concerns with what the company says is a carefully architected and purpose-built platform devoted to processing data for AI tasks without the information being accessible to Meta, WhatsApp, or any other party. ([Lily Hay Newman / Wired](https://www.wired.com/story/whatsapp-private-processing-generative-ai-security-risks/?ref=metacurity.com)) **Related:** [*Engineering at Meta*](https://engineering.fb.com/2025/04/29/security/whatsapp-private-processing-ai-tools/?ref=metacurity.com)*,* [*WhatsApp*](https://blog.whatsapp.com/introducing-advanced-chat-privacy?ref=metacurity.com)*,* [*Social Media Today*](https://www.socialmediatoday.com/news/whatsapp-ai-privacy-processing-secure-meta/746677/?ref=metacurity.com)*,* [*WABetaInfo*](https://wabetainfo.com/meta-enhances-whatsapp-with-new-upcoming-ai-feature-updates-powered-by-secure-private-processing/?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/social-media/meta-has-a-plan-to-bring-ai-to-whatsapp-chats-without-breaking-privacy-193556026.html?ref=metacurity.com)*,* [*The Hacker News*](https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html?ref=metacurity.com)*,* [*iPhone in Canada Blog*](https://www.iphoneincanada.ca/2025/04/29/whatsapp-private-processing-to-enhance-ai-privacy/?ref=metacurity.com) ### Marks & Spencer has admitted that some products are running short in its stores as it continues to deal with the fallout from a ransomware attack. The retailer said there were “pockets of limited availability” in some shops, as more than a week of disruption to its IT systems affects its stores. The company has decided to “take some of our systems temporarily offline” as part of its “proactive management of the incident”. “We are working hard to get availability back to normal across the estate,” it said on Wednesday. The Metropolitan police confirmed that its cybercrime unit was investigating the attack, which has been linked to hacking collective Scattered Spider. A spokesperson for the force said inquiries were continuing. M&S was forced to stop taking orders on its website, which accounts for about £3.8m (around $5 million) in sales a day, after days of disruption in stores caused by a cyber-attack. M&S has also had to pause deliveries of some packaged food items to Ocado, the online grocery specialist it co-owns. The disruption caused by the hack, and uncertainty over when it will end, has wiped more than £600m (around $800 million) off the stock market value of M&S in just over a week. ([Sarah Butler / The Guardian](https://www.theguardian.com/business/2025/apr/30/marks-and-spencer-cyber-attack-products-run-short-in-some-stores?ref=metacurity.com)) **Related*:* [*Hong Kong Free Press*](https://hongkongfp.com/2025/04/30/systems-failure-at-ms-hong-kong-stores-continues-amid-uk-ransomware-attack/?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/1d46953a-5f2d-4395-85b9-af337a4747db?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/business/retail-consumer/britains-ms-says-cyber-attack-has-hit-food-availability-some-stores-2025-04-29/?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/business/2025/apr/29/m-and-s-cyber-attack-linked-to-hacking-group-scattered-spider?ref=metacurity.com)*,* [*Sky News*](https://news.sky.com/story/who-are-scattered-spider-the-infamous-young-hacking-group-linked-to-mands-cyber-attack-13358559?ref=metacurity.com)*,* [*The Independent*](https://www.independent.co.uk/news/uk/home-news/m-s-cyberattack-shop-marks-spencers-b2741347.html?ref=metacurity.com)*,* [*Computer Weekly*](https://www.computerweekly.com/news/366623453/Scattered-Spider-on-the-hook-for-MS-cyber-attack?ref=metacurity.com)*,* [*ITV News*](https://www.itv.com/news/2025-04-29/who-is-scattered-spider-the-group-being-linked-to-the-m-and-s-cyber-attack?ref=metacurity.com) ### The Karnataka High Court in India ordered the blocking of encrypted email provider Proton Mail across the country after a local firm alleged that its employees had received emails containing obscene and vulgar content sent via Proton Mail. Justice M Nagaprasanna ordered the Indian government to “block Proton Mail, bearing in mind the observations made in the course of the order,” under the Information Technology Act 2008. In its complaint filed in January, the New Delhi-based firm called for the regulation or blocking of Proton Mail in India, as the email service reportedly refused to share details about the sender of the allegedly offensive emails, despite a police complaint. ([Jagmeet Singh / TechCrunch](https://techcrunch.com/2025/04/29/indian-court-orders-blocking-of-proton-mail/?ref=metacurity.com)) ***Related:*** [*Live Law*](https://www.livelaw.in/high-court/karnataka-high-court/karnataka-high-court-hearing-central-government-ban-proton-mail-290709?ref=metacurity.com)*,* [*Bar and Bench*](https://www.barandbench.com/news/karnataka-high-court-orders-blocking-of-proton-mail-in-india?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/india-blocks-proton-mail-following-court-order-over-offensive-ai-content/?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/cities/bangalore/block-proton-mail-karnataka-high-court-9974204/?ref=metacurity.com)*,* [*Moneycontrol*](https://www.moneycontrol.com/technology/proton-mail-faces-likely-ban-in-india-govt-to-examine-karnataka-hc-order-before-further-action-article-13008549.html?ref=metacurity.com)*,* [*Inc42 Media*](https://inc42.com/buzz/karnataka-hc-directs-centre-to-block-proton-mail-in-india/?ref=metacurity.com)*,* [*Cointelegraph*](https://cointelegraph.com/news/indian-high-court-blocks-proton-mail?ref=metacurity.com)*,* [*The Hacker News*](https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html?ref=metacurity.com)*,* [*The Hindu*](https://www.thehindu.com/business/karnataka-high-court-directs-union-government-to-block-switzerland-based-proton-mail-in-india/article69504548.ece?ref=metacurity.com) ### Canada's Nova Scotia Power and its parent company, Emera, said someone gained unauthorized access to parts of their Canadian network and servers supporting their business applications, a breach that was discovered on April 25. Nova Scotia Power said there is no impact on the utility's ability to serve customers in Nova Scotia, and there has been no disruption to any Canadian physical operations such as Nova Scotia Power's generation, transmission, and distribution facilities, the Maritime Link, or the Brunswick Pipeline. However, Nova Scotia Power posted to its social media channels Sunday night that it was having a "technical issue" with its phone line and customers' ability to access their accounts. In response to customers asking about the breach on Facebook, the company said it is "currently open to support our customers for emergencies and outages only." The utility's website saithe security breach caused the issues the issues were caused by the security breach. Customers can still report emergencies or outages through Nova Scotia's outage line, though they may face a longer wait. ([CBC News](https://www.cbc.ca/news/canada/nova-scotia/emera-nova-scotia-power-cybersecurity-breach-1.7520223?ref=metacurity.com)) **Related:** [*Business Wire*](https://www.businesswire.com/news/home/20250428562798/en/Emera-and-Nova-Scotia-Power-Responding-to-Cybersecurity-Incident?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/utilities-energy-power-water-waste/emera-nova-scotia-power-respond-to-cybersecurity-breach-incident-response-teams-mobilized/?ref=metacurity.com)*,* [*Rigzone*](https://www.rigzone.com/news/emera%5Fnova%5Fscotia%5Fpower%5Freport%5Fcyber%5Fbreach-29-apr-2025-180366-article/?ref=metacurity.com)*,* [*Cybernews*](https://cybernews.com/news/nova-scotia-power-cyberattack-customer-data-breach-emera/?ref=metacurity.com)*,* [*Daily Energy Insider*](https://dailyenergyinsider.com/news/48075-cybersecurity-incident-under-investigation-by-emera-nova-scotia-power/?ref=metacurity.com)*,* [*The Globe and Mail*](https://www.theglobeandmail.com/business/article-emera-nova-scotia-power-say-they-are-addressing-cybersecurity-breach/?ref=metacurity.com)*,* [*The Chronicle Herald*](https://www.saltwire.com/nova-scotia/halifax/emera-nova-scotia-power-cybersecurity-incident?ref=metacurity.com)*,* [*The Hawk*](https://www.1015thehawk.com/2025/04/28/nova-scotia-power-investigating-cyber-attack/?ref=metacurity.com)*,* [*Cyber Insider*](https://cyberinsider.com/nova-scotia-power-says-cybersecurity-incident-impacting-it-systems/?mid=1&ref=metacurity.com#cid=2803529) ### Amit Forlit, an Israeli private investigator wanted by the US for allegedly carrying out a "hacking for hire" campaign at the behest of an ExxonMobil lobbyist, lost his fight against extradition from Britain. He is facing charges of wire fraud, conspiracy to commit wire fraud, and computer hacking relating to his alleged targeting of environmental activists, his lawyers said in January, confirming Reuters' earlier reporting. His objections to extradition were rejected by Judge John McGarva, who said in his written ruling that US prosecutors alleged that Forlit was a "hired gun". "The highest he can put his case is that he is collateral damage in the climate change litigation," McGarva said. He added that Forlit's prosecution "may be dropped by the new administration" of President Donald Trump. ([Sam Tobin / Reuters](https://www.reuters.com/world/israeli-private-eye-loses-extradition-fight-over-us-hack-leak-charges-2025-04-30/?ref=metacurity.com)) ### According to a letter received by tech commentator Jacob Canfield, scammers are mailing physical letters to the owners of Ledger crypto hardware wallets asking them to validate their private seed phrases in a bid to access the wallets to clean them out. A seed phrase, or recovery phrase, is a string of up to 24 words that unlocks access to a crypto wallet. A scammer with the phrase can access and control the associated wallet to transfer its holdings elsewhere. Canfied received a letter that appeared to be from Ledger claiming he needed to immediately perform a “critical security update” on his device. The letter, which uses Ledger’s logo, business address, and a reference number to feign legitimacy, asks to scan a QR code and enter the wallet’s private recovery phrase under the guise of validating the device. The letter threatens that “failure to complete this mandatory validation process may result in restricted access to your wallet and funds.” Ledger said the letter is a scam and cautioned its device users to stay vigilant against phishing attempts. ([Brayden Lindrea / Cointelegraph](https://cointelegraph.com/news/ledger-scammers-send-letters-steal-recovery-seed-phrases?ref=metacurity.com)) **Related:** [*crypto.news*](https://crypto.news/ledger-hardware-wallets-users-targeted-by-mail-reportedly-exploiting-data-leaked-in-2020-breach/?ref=metacurity.com)*,* [*The Block*](https://www.theblock.co/post/352479/ledger-confirms-physical-scam-letters-requesting-seed-phrase?ref=biztoc.com)*,* [*The Daily Hodl*](https://dailyhodl.com/2025/04/30/bydfi-partners-with-ledger-to-launch-limited-edition-hardware-wallet-debuts-at-token2049-dubai/?ref=metacurity.com) ### South Korea’s leading mobile carrier, SK Telecom, is facing mounting fallout from a recent hacking incident, with more than 70,000 users switching to rival providers in just two days after the company began offering free USIM card replacements. Amid growing concerns that the data breach could spill over into the financial sector, South Korean financial authorities on Wednesday launched an emergency response team and tightened security protocols. According to industry sources, 35,902 SK Telecom users switched to other major carriers on Tuesday, following 34,132 users who switched on Monday. During the same period, SKT gained only 11,991 new users. ([Jo He-rim / The Korea Herald](https://www.koreaherald.com/article/10477906?ref=metacurity.com)) **Related:** [*Yonhap News*](https://en.yna.co.kr/view/AEN20250430008100320?ref=metacurity.com)*,* [*Korea JoongAng Daily*](https://koreajoongangdaily.joins.com/news/2025-04-30/business/industry/No-signs-of-fraudulent-authentication-detected-in-connection-to-SKT-breach-financial-authorities-say/2297209?ref=metacurity.com)*,* [*ChosunBiz*](https://biz.chosun.com/en/en-it/2025/04/30/IYFFVAJ2AFFS3HBG6H5CWJBZ6A/?ref=metacurity.com) ### Researchers at CloudSEK revealed a critical breach in the infrastructure of the Bangalore Water Supply and Sewerage Board (BWSSB) that left sensitive personal data of over 290,000 Bangalore residents vulnerable, after direct root access to BWSSB’s database was found being sold by a cybercriminal for just $500 on underground forums. On April 10, 2025, CloudSEK’s proprietary digital risk monitoring platform XVigil flagged a post by a threat actor identified as pirates\_gold, offering unrestricted access to BWSSB’s database. What makes this incident particularly disturbing is how easily this access was obtained through exposed credentials and a publicly accessible admin login portal. CloudSEK’s STRIKE Team traced the breach back to a publicly accessible .env file, containing plaintext MySQL credentials, alongside an internet-facing Adminer interface, commonly used for managing databases. These misconfigurations gave the attacker full administrative control, without any need for advanced hacking tools. ([India CRN](https://www.crn.in/news/over-290000-citizens-at-risk-cloudsek-uncovers-major-data-breach-at-bangalore-water-supply-and-sewerage-board/?ref=metacurity.com)) **Related:** [*CloudSEK*](https://www.cloudsek.com/blog/inside-the-bwssb-incident-how-an-exposed-environment-file-enabled-the-sale-of-290k-applicant-records-and-database-root-access?ref=metacurity.com)*,* [*NDTV*](https://www.ndtvprofit.com/technology/data-breach-at-bangalore-water-supply-and-sewerage-board-puts-290000-citizens-at-risk-cloudsek?ref=metacurity.com)*,* [*Vartha Bharati*](https://english.varthabharati.in/karnataka/data-breach-exposes-29-lakh-bangalore-water-supply-and-sewerage-boards-customers-details-report?ref=metacurity.com)*,* [*The420*](https://the420.in/bangalore-water-supply-board-bwssb-database-breach-2025-290k-records-exposed-cybersecurity-lapse/?ref=metacurity.com)*,* [*OneIndia*](https://www.oneindia.com/bengaluru/bwssb-data-breach-hackers-breach-portal-aadhaar-pan-and-payment-data-of-users-sold-on-dark-web-4138277.html?ref%5Fsource=OI-EN&ref%5Fmedium=Home-Page&ref%5Fcampaign=News-Cards&ref=metacurity.com)*,* [*Deccan Herald*](https://www.deccanherald.com/india/karnataka/bengaluru/bengaluru-breach-exposes-29-lakh-bwssb-customers-data-3515125?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/04/image-114.png) Screenshot of the post made by the threat actor. Source: CloudSEK. ### The US Embassy in Guatemala said it found that China-based espionage groups had hacked the Central American nation's foreign ministry's computer system, but the Guatemalan government said this was an old case. The embassy said in a post on X that the hacking was discovered during a safety revision conducted by the Guatemalan government and the US Southern Command, a military branch. Guatemala's foreign ministry dismissed the US embassy's report of a hack into its systems as old. "They are referring to an old case from September 2022\. There has been no recent hack," it said in a statement. ([Sofia Menchu / Reuters](https://www.reuters.com/technology/cybersecurity/guatemalan-foreign-ministrys-computer-system-hacked-by-china-based-groups-us-2025-04-29/?ref=metacurity.com)) **Related:** [*A*](https://www.arise.tv/china-based-espionage-groups-hacked-guatemalas-foreign-ministry-system-us-embassy-says/?ref=metacurity.com)[*rise News*](https://www.arise.tv/china-based-espionage-groups-hacked-guatemalas-foreign-ministry-system-us-embassy-says/?ref=metacurity.com) ### According to a report by the Government Accountability Office (GAO), some state and local government agencies are unsure how they will continue to fund their cybersecurity initiatives in the absence of federal support. The office examined the $1 billion, 4-year State and Local Cybersecurity Grant Program by randomly sampling state and territorial government agencies that have received funding. It found that most agencies had positive things to say about the program, and some agency representatives selected for interviews by the federal office reported concerns with how they’ll continue their cybersecurity initiatives after the program’s one-time funding runs out, or if it’s prematurely ended. ([Colin Wood / StateScoop](https://statescoop.com/dhs-state-local-cyber-grant-gao-report-2025/?ref=metacurity.com)) **Related:** [*GAO*](https://files.gao.gov/reports/GAO-25-107313/index.html?ref=metacurity.com#%5FToc196309939) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/04/image-112.png) Source:GAO. ### Acting DARPA Director Rob McHenry told an audience at the RSAC 2025 Conference that a combination of formal software development methods with large language models (LLMs) could “virtually eliminate software vulnerabilities” across foundational system infrastructures, a departure from the traditionally accepted risks of software flaws. Formal methods, a way of using math to prove that software works as intended, have for decades been regarded as effective but laborious and expensive, suited only for the most critical systems and requiring expert staff. McHenry noted that combining LLMs with formal methods enables automatic generation and validation of correctness proofs, drastically lowering the labor and cost barriers. His statements came in the context of the AI Cyber Challenge, a public-private collaboration involving industry leaders such as Google, Microsoft, Anthropic, and OpenAI. The initiative tests whether advanced AI systems can identify and patch vulnerabilities in open-source software components vital to the electric grid, health care, and transportation. ([Greg Otto / Cyberscoop](https://cyberscoop.com/darpa-ai-grand-challenge-rsac-2025-patching/?ref=metacurity.com)) **Related:** [*NextGov/FCW*](https://www.nextgov.com/cybersecurity/2025/04/salt-typhoon-hacks-influence-final-round-darpas-ai-cyber-competition/404912/?ref=metacurity.com) ### Microsoft previewed hotpatching for on-prem Windows Server 2025, which will become a paid subscription service in July. Hotpatching allows software updates to be applied without requiring a reboot. It’s a common approach that’s available for the Linux kernel, VMware products, and the Xen hypervisor, among others. Admins like it because it allows security updates to be implemented without requiring reboots – and therefore without having to find a change window or a convenient moment for an outage. Microsoft already offers hotpatching for Windows Server: Azure Edition and version 2022 running in its Azure cloud. The MS-DOS titan says its Xbox team is a big user. Last August, Microsoft teased a preview of hotpatching for Windows Server 2025 implementations controlled by its Arc hybrid-and-multicloud management tool. Microsoft said the preview will end on June 30 and be replaced by a subscription service that costs $1.50/core/month. Non-hotpatch updates will still be available as usual for free. ([Simon Sharwood / The Register](https://www.theregister.com/2025/04/28/windows%5Fserver%5F2025%5Fhotpatching%5Fsubscription/?ref=metacurity.com)) **Related:** [*Microsoft*](https://www.microsoft.com/en-us/windows-server/blog/2025/04/24/tired-of-all-the-restarts-get-hotpatching-for-windows-server/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-hotpatching-to-require-subscription/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2025/04/29/microsoft-confirms-150-windows-security-update-fee-starts-july-1/?ref=metacurity.com) ### Attackers are actively exploiting a recently patched zero-day vulnerability in SAP's NetWeaver Visual Composer Web-based software modeling tool. CVE-2025-31324 is a critical vulnerability with a maximum CVSS score of 10 that affects all SAP NetWeaver 7.xx versions. It allows unauthenticated remote attackers to upload arbitrary files to internet-exposed systems without any restrictions. SAP issued an emergency patch for the vulnerability on April 25, three days after ReliaQuest reported exploitation activity targeting NetWeaver systems. ReliaQuest initially suspected that attackers were either exploiting an older SAP vulnerability, tracked as CVE-2017-9844, or a new, undisclosed remote file inclusion vulnerability in NetWeaver. But SAP's later analysis revealed the issue was actually tied to an improper authentication and authorization check in NetWeaver Visual Composer's Metadata Uploader component. The Shadowserver Foundation, which monitors the internet for threat activity, on April 27 reported finding 454 internet-exposed SAP NetWeaver instances that are vulnerable to attack via the new bug. Most of the vulnerable instances are in the US (149), followed by India with 50 and Australia with 37, Shadowserver said. Organizations that are unable to update immediately should consider disabling Visual Composer and restricting access to the affected endpoint, as Rapid7 recommends. ([Jai Vijayan / Dark Reading](https://www.darkreading.com/cyberattacks-data-breaches/sap-netweaver-visual-composer-flaw-active-exploitation?ref=metacurity.com)) **Related:** [*SC World*](https://www.scworld.com/news/over-400-servers-found-to-be-exposed-to-sap-netweaver-bug?mid=1&ref=metacurity.com#cid=2803437)*,* [*MSSP Alert*](https://www.msspalert.com/news/sap-patches-critical-zero-day-vulnerability-in-netweaver-visual-composer?ref=metacurity.com)*,* [*Rapid7*](https://www.rapid7.com/blog/post/2025/04/28/etr-active-exploitation-of-sap-netweaver-visual-composer-cve-2025-31324/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2025/04/25/sap%5Fnetweaver%5Fpatch/?ref=metacurity.com)*,* [*The Center for Internet Security*](https://www.cisecurity.org/advisory/a-vulnerability-in-sap-netweaver-visual-composer-could-allow-for-remote-code-execution%5F2025-044?ref=metacurity.com)*,* [*Cyberscoop*](https://cyberscoop.com/sap-netweaver-zero-day-exploit-cve-2025-31324/?ref=metacurity.com)*,* [*Onapsis*](https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/04/image-113.png) ### The Removing Our Unsecure Technologies to Ensure Reliability and Security (ROUTERS) Act, a bill requiring the Department of Commerce to study national security issues posed by routers and modems controlled by US adversaries, passed the House of Representatives. The House moved quickly on the bill, which was introduced by Reps. Bob Latta (R-OH) and Robin Kelly (D-IL) in March, and advanced out of the chamber’s Energy and Commerce Committee three weeks ago. The bill, which calls on Commerce’s assistant secretary for communications and information to lead a study into devices that are “designed, developed, manufactured, or supplied” by or subject to the influence of a “covered country,” takes particular aim at China and the state-sponsored hacking campaigns that have plagued US networks. ([Matt Bracken / Cyberscoop](https://cyberscoop.com/routers-act-commerce-study-modems-chinese-hackers/?ref=metacurity.com)) **Related:** [*docs.house.gov*](https://docs.house.gov/billsthisweek/20250428/H866%5FRH%5Fxml.pdf?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/us-house-bill-security-threats/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/bill-mandating-router-security-evaluations-receives-house-ok?ref=metacurity.com) ### Best Thing of the Day: Malicious Deepfakes Can Land You in Jail A former high school athletics director accused of using artificial intelligence to create a racist and antisemitic deepfake of a principal in Pikesville, Maryland, [has been sentenced](https://apnews.com/article/racist-ai-recording-maryland-high-school-487ea673b0449077cb23e7970546cb9f?ref=metacurity.com) to four months in jail as part of a plea deal. ### Worst Thing of the Day: Buy Some Real Artwork, It Lasts Longer Thousands of NFTs that had once sold collectively for millions of dollars [briefly vanished](https://www.404media.co/nfts-that-cost-millions-replaced-with-error-message-after-project-downgraded-to-free-cloudflare-plan/?ref=metacurity.com) from the internet and were replaced with the phrase “This content has been restricted. Using Cloudflare’s basic service in this manner is a violation of the Terms of Service," underscoring the ephemeral nature of crypto-backed pictures that dominated the internet for a few years. ### Bonus Worst Thing of the Day: Keep Your Stuff Off the Internet Thousands of automatic tank gauge (ATG) devices in automobiles [are accessible over the internet](https://www.darkreading.com/ics-ot-security/fuel-tank-monitoring-systems-vulnerable-disruption?ref=metacurity.com) and are just "a packet away" from compromise. ### Closing Thought > [@bbcnews](https://www.tiktok.com/@bbcnews?refer=embed&ref=metacurity.com "@bbcnews") > > The images of women shown here appear to be AI and not real - however one company is using photos of celebrities. [#Apple](https://www.tiktok.com/tag/apple?refer=embed&ref=metacurity.com "apple") [#Deepfake](https://www.tiktok.com/tag/deepfake?refer=embed&ref=metacurity.com "deepfake") [#AI](https://www.tiktok.com/tag/ai?refer=embed&ref=metacurity.com "ai") [#ArtificialIntelligence](https://www.tiktok.com/tag/artificialintelligence?refer=embed&ref=metacurity.com "artificialintelligence") [#GameOfThrones](https://www.tiktok.com/tag/gameofthrones?refer=embed&ref=metacurity.com "gameofthrones") [#LenaHeadey](https://www.tiktok.com/tag/lenaheadey?refer=embed&ref=metacurity.com "lenaheadey") [#MaisieWilliams](https://www.tiktok.com/tag/maisiewilliams?refer=embed&ref=metacurity.com "maisiewilliams") [#Tech](https://www.tiktok.com/tag/tech?refer=embed&ref=metacurity.com "tech") [#Technology](https://www.tiktok.com/tag/technology?refer=embed&ref=metacurity.com "technology") [#BBCNews](https://www.tiktok.com/tag/bbcnews?refer=embed&ref=metacurity.com "bbcnews") > > [♬ original sound - BBC News - BBC News](https://www.tiktok.com/music/original-sound-BBC-News-7498794865243687702?refer=embed&ref=metacurity.com "♬ original sound - BBC News - BBC News") , ### Krebs expresses outrage at Trump's gutting of cyber pros while industry rallies behind him URL: https://www.metacurity.com/krebs-expresses-outrage-at-trumps-gutting-of-cyber-pros-while-industry-rallies-behind-him/ Last updated: 2025-04-29T14:19:00.000Z Take It Down Act goes to Trump's desk, Musk DOGE boys given access to highly guarded nuclear weapon data, Scattered Spider might be behind M&S attack, Zero days exploited in the wild dropped in 2024, British defense firms warned away from Chinese EVs, 4chan back after hack, so much more _This post is for paying subscribers only._ ### Marks and Spencer sends 200 workers home as cyberattack fallout worsens URL: https://www.metacurity.com/marks-and-spencer-sends-200-workers-home-as-cyberattack-fallout-worsens/ Last updated: 2025-04-28T13:25:11.000Z Meta's AI digital companions do not protect underage users from sexually explicit banter, UK commissioner calls for ban on apps that create sexual images of children, SK Telecom plummets in wake of cyberattack, DeFi protocol Loopscale loses $5.8m in exploit, Juice-jacking mitigation found, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 4/19/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-4-19-25/ Last updated: 2025-04-26T13:26:34.000Z How young hackers got caught after stealing a quarter of a billion in crypto, What Hegseth's SignalGate really teaches us, Why the US needs to protect transparent security research, All web browsers except Tor are insecure, The divergent cybercrime paths of Russia, China, North Korea, and Iran _This post is for subscribers only._ ### DPRK spies launched two US businesses to spread malware among crypto workers URL: https://www.metacurity.com/dprk-spies-launched-two-us-businesses-to-spread-malware-among-crypto-workers/ Last updated: 2025-04-25T13:35:21.000Z DPRK hackers used Russian internet infrastructure, Lazarus Group targeted multiple businesses in Operation SyncHole, DPRK workers use genAI for US and European jobs, Scattered Spider member extradited to US, Antitrust probe launched into TP-Link, FBI tracks down Nigerian sextortionists, much more _This post is for paying subscribers only._ ### FBI: Online scams stole nearly $17 billion in 2024, up sharply from 2023 levels URL: https://www.metacurity.com/fbi-online-scams-stole-nearly-17-billion-in-2024-up-sharply-over-2023-levels/ Last updated: 2025-04-24T14:19:40.000Z Hijacked brokerage accounts in Japan juiced $710m in fraudulent trading since Feb., BreachForums reportedly rises again, New malware appears in apps Russian soldiers use, S. Korea says DeepSeek transferred user data w/o permission, Millions affected by Blue Shield CA 2021 breach, so much more _This post is for paying subscribers only._ ### UK regulators ban 'global titles' that allow criminals to intercept messages URL: https://www.metacurity.com/uk-regulators-ban-global-titles-that-allow-criminals-to-intercept-messages/ Last updated: 2025-04-23T14:20:03.000Z No third-party cookies prompt for Google, Marks & Spencer warns of 'cyber incident,' XRP Ledger package could lead to 'catastrophic' supply chain attack, Verizon DBIR says ransomware attacks soared, China's Billbug breached SE Asian orgs, B'more City and Phoenix attorneys' offices hacked, much more _This post is for paying subscribers only._ ### Asian gangs are spreading cyber scam compounds globally, UN URL: https://www.metacurity.com/asian-gangs-are-spreading-cyberscam-compounds-globally/ Last updated: 2025-04-22T13:22:45.000Z Secure by Design architects to leave CISA, Korea's top telco hacked, MSFT's Recall still poses problems, Fog ransomware baits victims by invoking Musk's DOGE, Elusive Comet threat actor stole $100K from NFT platform CEO, Telegram to leave France if backdoors are mandated, much more _This post is for paying subscribers only._ ### Hegseth shared war planning information in a second Signal group chat URL: https://www.metacurity.com/hegseth-shared-war-planning-information-in-a-second-signal-group-chat/ Last updated: 2025-04-21T13:32:58.000Z Trump has removed misinformation guardrails, DOGE is planning database to track immigrants, CISA stopped using VirusTotal and Censys, False positives in MSFT Entra app trigger lockouts, Hackers send fake Google system emails, UK companies urged to carry out video interviews for IT workers, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 4/12/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-4-12-25/ Last updated: 2025-04-19T11:36:48.000Z The private prison company surveilling immigrants for Trump, How a Marine unit uses genAI to spy for the military, How the TP-Link router controversy is driving two brothers apart, Nation-state goons as hacktivists, How a genetic research innovation exposes DNA to cyber threats _This post is for subscribers only._ ### Russia is using LLM 'grooming' to spread misinformation in AI models URL: https://www.metacurity.com/russia-is-using-llm-grooming-to-spread-misinformation-in-ai-models/ Last updated: 2025-04-18T14:17:02.000Z NJ sues Discord for failing to protect young users, Hackers stole $700m from Japan's brokerages since February, Thai security forces dox pro-democracy activists, Chinese mobile networks can access and mess with mobile signaling data, Palantir is hunting down data on ICE targets, much more _This post is for paying subscribers only._ ### Krebs quits SentinelOne to fight Trump's punitive order URL: https://www.metacurity.com/krebs-quits-sentinelone-to-fight-trumps-punitive-order/ Last updated: 2025-04-17T13:46:18.000Z Third parties step forward to insulate vulnerability reporting from US government whims, State Department shutters foreign disinformation monitoring office, Fraudulent bot students steal aid funding, DOGE returns to NLRB, UK minister's X account hacked, Apple issues emergency patches, much more _This post is for paying subscribers only._ ### CISA pulls MITRE's CVE program back from the brink of death at the 11th hour URL: https://www.metacurity.com/cisa-pulls-mitres-cve-program-back-from-the-brink-of-death-at-the-11th-hour/ Last updated: 2025-04-16T15:08:05.000Z NLRB whistleblower faced harassment for DOGE misbehavior revelations, Hacker knocked 4Chan offline, Hacker stole $5m from ZKsync admin, Midnight Blizzard targets European diplomats in new campaign, SEC was hacked in 2016, TX bill gives $413m to UT-San Antonio for cyber programs, much more _This post is for paying subscribers only._ ### China accuses NSA of 'advanced cyberattacks' during the Asian Winter Games URL: https://www.metacurity.com/china-accuses-nsa-of-advanced-cyberattacks-during-the-asian-winter-games/ Last updated: 2025-04-16T11:40:22.000Z Big banks limit info-sharing with Comptroller of the Currency following hack, Hertz suffered breach in Cleo zero-day theft, DOGE barged into NLRB violating security and conflict standards, Business services giant Conduent hacked, Dialysis chain hacked, much more _This post is for paying subscribers only._ ### Microsoft is rolling out controversial Windows Recall feature URL: https://www.metacurity.com/microsoft-is-rolling-out-controversial-windows-recall-feature/ Last updated: 2025-04-14T13:29:50.000Z United Health demands healthcare provider loan paybacks, Interior Dept. fired its cybersecurity leaders, US DoJ rolled out commercial data purchase ban, Slopsquatting hits hallucinated packages, Fortinet warns of VPN post-exploitation attacks, Ransomware gangs hit MSFT domain controllers, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 4/5/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-4-5-25/ Last updated: 2025-04-12T11:48:15.000Z The far-right agenda of Clearview's facial recognition, Everyone in tech is scared of Elon Musk, Understanding market failures to improve cybersecurity, S. Africa struggles with cybersecurity, WhatsApp encryption can be depleted, Deciphering languages with cryptanalysis _This post is for subscribers only._ ### China acknowledged US cyberattacks at a secret meeting, report URL: https://www.metacurity.com/china-acknowledged-us-cyberattacks-at-a-secret-meeting-report/ Last updated: 2025-04-11T17:30:25.000Z Cybersecurity industry is mum on SentinelOne EO, Comptroller of the Currency lacked MFA on hacked email account, Morocco confirms massive cyber attack, Gamaredon is targeting Western military mission in Ukraine, Ethical hacker stole $2.6m from Morpho Labs, Sex chatbots leak information, much more _This post is for paying subscribers only._ ### Trump strips security clearances from Chris Krebs, SentinelOne URL: https://www.metacurity.com/trump-strips-security-clearances-from-chris-krebs-sentinelone/ Last updated: 2025-04-10T14:37:48.000Z Wyden holds up Plankey's appointment, Europol busts five Smokeloader customers, CIS to continue MS-ISAC services, NSO Group exploited WhatsApp flaw in 51 countries, Berkshire Hathaway-owned jet company hacked, Oracle continues to deny breach with wordsmithing, much more _This post is for paying subscribers only._ ### Hackers intercepted emails at US Comptroller of the Currency for over a year URL: https://www.metacurity.com/hackers-intercepted-emails-at-us-comptroller-of-the-currency-for-over-a-year/ Last updated: 2025-04-09T17:07:01.000Z Governments warn of BadBazaar and Moonshine spyware, MSFT issued fixes for at least 121 flaws, Scattered Spider persists after arrests, UK probes suicide forum, Hackers abuse SourceForge to distribute malware, Dutch gov't to screen researchers and students for espionage risks, much more _This post is for paying subscribers only._ ### Musk's DOGE Is Spying on Federal Employees to Spot Disloyalty, Sources URL: https://www.metacurity.com/musks-doge-is-spying-on-federal-employees-to-spot-disloyalty-sources/ Last updated: 2025-04-08T14:15:06.000Z Spain busts six deepfake-using crypto scammers, Oz to shut down 95 romance scam 'hydra' companies, Czech PM's social media hacked, Singaporean and Chinese banks hacked through vendor, Dems express concern over Starlink in the White House, Pall Mall spyware accord signed, much more _This post is for paying subscribers only._ ### DOGE is expected to slash 40% of CISA's workforce URL: https://www.metacurity.com/doge-is-expected-to-slash-40-of-cisas-workforce/ Last updated: 2025-04-07T14:04:13.000Z DOGE to host a hackathon to better access US citizens' most sensitive data, Apple appeals UK back door order, Taiwan identifies Crazyhunter hacker, TikTok to live for 75 more days in US, Five UK romance scammers convicted, Leak site of Everest gang defaced, OpenAI tests watermark, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/28/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-28-25/ Last updated: 2025-04-05T10:51:16.000Z Why the tech sector should do more to battle romance scams, Texas has built a humongous militarized surveillance state, How N. Korea has stolen billions, Offensive cyber operations are not the solution, New ideas to combat cyber-enabled crimes _This post is for subscribers only._ ### Trump fired NSA head Haugh at right-wing conspiracist Loomer's instigation URL: https://www.metacurity.com/trump-fired-nsa-head-haugh-at-right-wing-conspiracist-loomers-instigation/ Last updated: 2025-04-04T14:19:27.000Z Hackers stole half a million from Australia's superannuation funds, Russian hacker sentenced to two-years in a penal colony for DDoS attack on local company, Texas State Bar hit by INC ransomware gang, Threat actors ramping up US tax day scams, Hard-to-remove Android spyware app emerges, much more _This post is for paying subscribers only._ ### Joint law enforcement operation took down the dark web CSAM platform Kidflix URL: https://www.metacurity.com/joint-law-enforcement-operation-took-down-the-dark-web-csam-platform-kidflix/ Last updated: 2025-04-03T14:46:25.000Z Waltz had at least 20 Signal group chats going, Indiana cyber prof has not been detained or charged, Musk worker bragged about hacking and pirating software, Oracle had a second breach, NSA and others warn of C2 creator Fast Flux, Royal Mail and Samsung Germany breached via same supplier, much more _This post is for paying subscribers only._ ### Trump's NSC used insecure Gmail accounts for official business URL: https://www.metacurity.com/trumps-nsc-used-insecure-gmail-accounts-for-official-business/ Last updated: 2025-04-03T18:00:21.000Z DPRK IT workers are targeting Europe after US indictments and sanctions, UK cyber bill details revealed, Firing HHS workers might weaken medical device security, Chinese military-linked VPN apps found on play stores, Gmail E2EE rolling out, Robot dog has serious flaw, much more _This post is for paying subscribers only._ ### GCHQ intern who took top-secret data home pleads guilty URL: https://www.metacurity.com/gchq-intern-who-took-top-secret-data-home-pleads-guilty/ Last updated: 2025-04-01T13:42:41.000Z Oz warns crypto ATM owners of suspicious activity, Check Point says breach was 'limited,' Creator craters genetic database due to authoritarianism, British rail Wi-Fi hacker arrested, FTC chair warns 23andMe of privacy duties, Chinese hackers exploit iMessage and RCS for phishing, much more _This post is for paying subscribers only._ ### Top cryptography professor is incommunicado, erased by university after FBI raids URL: https://www.metacurity.com/top-cryptography-professor-is-incommunicado-erased-by-university-after-fbi-raids/ Last updated: 2025-03-31T13:17:50.000Z US DOJ unseals charges against accused Canadian TX GOP hacker, Italian minister approved spyware use against NGO, Oracle confirms healthcare systems data breach, DOJ seized $8.2m stolen in romance baiting scams, Coinbase users lost $46m in phishing scams over past two weeks, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/22/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-22-25/ Last updated: 2025-03-29T14:43:17.000Z The Signal leak makes NSA's job harder, How to launder $27B from online scams, Be afraid of Q-Day, RISC architecture *is* changing everything, How to tell your online accounts have been hacked _This post is for subscribers only._ ### Signal soars after Trump officials' group chat disaster URL: https://www.metacurity.com/signal-soars-after-trump-officials-group-chat-disaster/ Last updated: 2025-03-28T20:35:25.000Z US military pilots fear Pentagon no longer has their back after Signal chat leak, Judge orders admins to preserve Signal group chat records, Trump is training spy satellites on Mexico border, NSO spyware targeted on Serbian journalists, Phishing domains spoof Ukraine sites, and much more _This post is for paying subscribers only._ ### Poor opsec among Trump officials deepens concerns over insecure Signal chat group URL: https://www.metacurity.com/revelations-of-poor-opsec-practices-among-trump-officials-deepen-crisis-over-insecure-signal-chat-group/ Last updated: 2025-03-27T14:01:54.000Z Chinese fake recruiters seek to hire fired US fed workers, Despite denials Oracle Cloud breach looks real, Resecurity took down BlackLock gang, ICO fines NHS IT contractor $3.9m, FamousSparrow struck US finance association, NSW government arm breached, much more _This post is for paying subscribers only._ ### Signal messages released as administration denies national security risk of group chat URL: https://www.metacurity.com/signal-messages-released-as-administration-denies-national-security-risk-of-group-chat/ Last updated: 2025-03-26T15:07:53.000Z Pentagon and NSA issued warnings of Signal messaging, Commerce sanctions 80 companies on natsec grounds, Interpol-led operation busts 306 in Africa, Musk's Big Balls worker supported cybercrime gang, NoName targeted Belgian websites, Snowflake hacker heads to the US, much more _This post is for paying subscribers only._ ### Hiatus Due to Technical Difficulties URL: https://www.metacurity.com/hiatus-due-to-technical-difficulties/ Last updated: 2025-03-25T15:10:39.000Z Metacurity is on the road and has experienced a Windows update that has corrupted our laptop operating system. We are on a temporary hiatus until the problem is resolved. Apologies and we will be back as soon as possible, ### US takes Tornado Cash off sanctions list following court ruling URL: https://www.metacurity.com/us-takes-tornado-cash-off-sanctions-list-following-court-ruling/ Last updated: 2025-03-24T10:38:12.000Z Large-scale cyberattack hit Ukraine railway, Oracle Cloud denies hack, Info-sharing EO designed to mask DOGE violations, Hacker hijacked NYU website, Valve drops game from Steam for installing malware, Cloak group disrupts VA AG's systems, 23andMe is now bankrupt, much more _This post is for paying subscribers only._ ### Best infosec-related long reads for the week of 3/15/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-15-25/ Last updated: 2025-03-22T13:19:54.000Z China's Typhoons are the biggest cyber threat in a decade, Community Notes won't save us, Messing with adversaries' minds as a cyber defense, The real-life fake porn horror story in Levittown, When Russia burned $300K of Bitcoin _This post is for subscribers only._ ### Prosecutors say 'computer whiz' NFL, Michigan football coach hacked thousands of athletes for intimate photos, videos URL: https://www.metacurity.com/computer-whiz-nfl-michigan-football-coach-hacked-thousands-of-athletes-for-intimate-photos-videos-2/ Last updated: 2025-03-21T13:27:12.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/03/UM_Northwestern_10.23.21_767_-51628464759--1.jpg) Weiss appears on far right. Source: [Maize and Blue Nation](https://www.flickr.com/photos/maizenbluenation/51628464759/?ref=metacurity.com). --- *Metacurity is a reader-supported publication that requires a lot of work and relies on the generous support of our paid readers. Please consider supporting Metacurity with an upgraded subscription. Thank you.* [Upgrade my subscription](#/portal/account/plans) *If you can't commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) --- ### Federal prosecutors indicted former NFL and University of Michigan assistant football coach Matt Weiss for hacking into the computer accounts of thousands of college athletes seeking intimate photos and videos. Weiss, who worked for the Baltimore Ravens before joining Michigan’s staff in 2021, was charged with 14 counts of unauthorized computer access and 10 counts of identity theft. The indictment states that from 2015 to 2023, Weiss gained access to the databases of more than 100 colleges and universities maintained by a third-party vendor, Keffer Development Services, and downloaded personal information and medical data of more than 150,000 athletes. Prosecutors portrayed him as a computer whiz, saying Weiss “cracked the encryption protecting the passwords, assisted by research that he did on the internet.” According to the indictment, he then gained access to the social media, email, and cloud storage accounts of more than 2,000 athletes and over 1,300 students or alums from schools nationwide. “Weiss primarily targeted female college athletes,” the indictment said. “He researched and targeted these women based on their school affiliation, athletic history, and physical characteristics. He aimed to obtain private photographs and videos that were never intended to be shared beyond intimate partners.” Weiss kept notes on photos and videos that he downloaded, commenting on the bodies and sexual preferences and sometimes returning years later to look for new images, the indictment said. ([Ed White / Associated Press](https://apnews.com/article/michigan-football-college-coach-hacking-weiss-2f57fdfd02043b1cac114b209b1d6a4c?ref=metacurity.com)) ***Related:*** [*Justice Department*](https://www.justice.gov/usao-edmi/pr/former-university-michigan-football-quarterbacks-coach-and-co-offensive-coordinator?ref=metacurity.com)*,* [*TMZ*](https://www.tmz.com/2025/03/20/matt-weiss-accused-of-hacking-athletes-stealing-intimate-photos/?ref=metacurity.com)*,* [*Baltimore Sun*](https://www.baltimoresun.com/2025/03/20/ravens-michigan-matt-weiss-hacking-photos-charged/?ref=metacurity.com)*,* [*ESPN*](https://www.espn.com/college-football/story/%5F/id/44331637/ex-michigan-assistant-charged-hacking-computer-accounts?ref=metacurity.com)*,* [*ABC7*](https://abc7chicago.com/post/former-nfl-university-michigan-assistant-football-coach-matt-weiss-charged-hacking-computer-accounts-athletes/16058074/?ref=metacurity.com)*,* [*Mlive*](https://www.mlive.com/wolverines/2025/03/feds-indict-former-michigan-oc-matt-weiss-on-hacking-id-theft-charges.html?ref=metacurity.com)*,* [*The Record*](https://therecord.media/former-michigan-football-assistant-coach-indicted-hacks-athletes?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/news/matt-weiss-former-michigan-quarterbacks-coach-charged-identity-theft-computer-hacking/?ref=metacurity.com)*,* [*Detroit Free Press*](https://www.freep.com/story/sports/college/university-michigan/wolverines/2025/03/20/matt-weiss-charged-crimes-computers-michigan-football/82570958007/?ref=metacurity.com)*,* [*The Athletic*](https://www.nytimes.com/athletic/6219501/2025/03/20/matt-weiss-michigan-indictment-charges/?ref=metacurity.com)*,* [*People*](https://people.com/ex-michigan-assistant-coach-matt-weiss-allegedly-hacked-thousands-of-athletes-accounts-for-intimate-photos-11700910?ref=metacurity.com)*,* [*Detroit News*](https://www.detroitnews.com/story/news/local/michigan/2025/03/20/feds-indict-former-michigan-co-offensive-coordinator-matt-weiss/82570832007/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/news/us-news/ex-michigan-football-coach-allegedly-stole-intimate-photos-3000-studen-rcna197360?ref=metacurity.com) ### Daily NK, a news outlet that focuses on North Korea, reported that the North Korean government is reportedly establishing a new hacking group within the intelligence agency Reconnaissance General Bureau (RGB) called Research Center 227, which will focus on research to develop “offensive hacking technologies and programs,” citing a source inside the regime. According to a source, Research Center 227 will research Western cybersecurity systems and computer networks, strengthening the regime’s capabilities to steal digital assets, develop AI-based techniques for information theft, and work to respond to information from North Korean overseas hacking units. ([Lorenzo Franceschi-Bicchierai / TechCrunch](https://techcrunch.com/2025/03/20/north-korea-launches-new-unit-with-a-focus-on-ai-hacking-per-report/?ref=metacurity.com)) **Related:** [*DailyNK*](https://www.dailynk.com/english/n-korea-ramps-up-cyber-offensive-new-research-center-to-focus-on-ai-powered-hacking/?ref=metacurity.com)*,* [*Mezha*](https://mezha.media/en/news/pivnichna-koreya-hakerskiy-pidrozdil-ta-shi-300619/?ref=metacurity.com) ### The Dutch parliament approved a law criminalizing digital espionage and diaspora espionage, which refers to foreign powers attempting to influence communities in the Netherlands with ties to those countries. The new law expands on existing legislation, criminalizing actions such as leaking information or working for foreign governments that harm Dutch interests. Offenders can face up to eight years in prison, with a maximum of 12 years for severe cases, such as espionage leading to death. ([Charlotte Van Campenhout / Reuters](https://www.reuters.com/world/europe/netherlands-passes-law-targeting-digital-diaspora-espionage-2025-03-18/?ref=metacurity.com)) **Related:** [*Netherlands Central Government*](https://www.rijksoverheid.nl/actueel/nieuws/2025/03/18/uitbreiding-wet-meer-vormen-spionage-strafbaar?ref=metacurity.com)*,* [*EuroWeekly News*](https://euroweeklynews.com/2025/03/18/law-passes-against-digital-and-diaspora-espionage/?ref=metacurity.com) ### Security researchers at LayerX report that the criminals behind a phishing attack aimed at Windows users are now targeting Mac users instead in what they call one of the most sophisticated attacks ever mounted against Mac users. The campaign initially targeted Windows users by masquerading as Microsoft security alerts. The campaign aimed to steal user credentials by employing deceptive tactics that made victims believe their computers were compromised. LayerX says with new security features rolled out by Microsoft, Chrome, and Firefox, the attackers have shifted their focus to Mac users. The mechanism behind the attack is a website popup window masquerading as a security alert. What enables this particular attack to fool so many people is that it uses malicious code to cause the webpage to freeze, lending credibility to the popup's claim that the computer has been locked. Last month, Microsoft introduced an anti-scareware feature in its Edge browser, with similar protections implemented in Chrome and Firefox. That stopped 90% of the attacks on Windows PCs, so the attackers turned their focus to Macs running Safari. ([Ben Lovejoy / 9to5Mac](https://9to5mac.com/2025/03/20/this-is-one-of-the-most-sophisticated-phishing-attacks-ever-made-against-mac-users/?ref=metacurity.com#more-994720)) **Related:** [*LayerX*](https://layerxsecurity.com/blog/layerx-identifies-new-phishing-campaign-targeted-at-mac-users/?ref=metacurity.com)*,* [*xda*](https://www.xda-developers.com/mac-windows-phishing-scam/?ref=metacurity.com)*,* [*Cybernews*](https://cybernews.com/security/phishing-campaign-shifts-focus-to-macs/?ref=metacurity.com)*,* [*MacDailyNews*](https://macdailynews.com/2025/03/20/mac-users-dont-fall-for-this-repurposed-windows-phishing-attack/?ref=metacurity.com)*,* [*MacTech*](https://www.mactech.com/2025/03/19/shareware-campaign-jumps-from-windows-to-macos/?ref=metacurity.com)*,* [*Dataconomy*](https://dataconomy.com/2025/03/21/new-scam-freezes-your-mac-and-then-steals-your-apple-id/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/03/image-73.png) Webpage freeze used in the attack. Source: LayerX ### Google says it uncovered thousands of illegitimate listings, including for fake businesses, on Google Maps and has announced a lawsuit against the alleged scammers behind the fraud. The lawsuit claims a man working within a broader network created and sold fake business profiles on Google Maps. An initial alert came from a Texas business that flagged an unlicensed locksmith impersonating them on Google Maps. That was just the tip of the iceberg. The company said the claim sparked an investigation that led Google to uncover and eliminate over 10,000 illegitimate listings. The scams ranged from outright fake businesses to legitimate accounts that had been hacked or hijacked. Google found that many of the scams were concentrated in what they call "duress verticals"—services people need in urgent or stressful situations, like locksmiths or towing companies. Google said it plans to donate any damages it wins in this case to organizations working to fight scams. ([Kara Fellows, Cait Bladt / CBS News](https://www.cbsnews.com/news/google-maps-fake-listings-lawsuit-scams/?ref=metacurity.com)) **Related:** [*r/google*](https://www.reddit.com/r/google/comments/1jfee6h/google%5Ffinds%5F10000%5Ffake%5Flistings%5Fon%5Fgoogle%5Fmaps/?ref=metacurity.com)[*r*](https://www.reddit.com/r/google/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1jfdtuh/google%5Ffinds%5F10000%5Ffake%5Flistings%5Fon%5Fgoogle%5Fmaps/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2025/03/21/beware-this-costly-google-maps-scam-10000-reasons-to-take-notice/?ref=metacurity.com) ### Researchers at Zimperium report that many mobile devices, one out of every one thousand, have been covertly modified to pose a security risk to organizations. The result is millions of devices that, when scaled to a global level, could potentially be a significant network security risk. “Despite a reduction in the number of rooted and jailbroken devices overall, they still represent a very serious security threat, not just to the user, but to enterprises who enable employees to access sensitive corporate apps and data from their devices,” wrote Zimperium. Though the terminology differs by platform, the process is essentially the same. An automated script uses an unpatched code execution vulnerability to modify the device at the root level and disable protections against unauthorized apps. The procedure is far more common on Android devices, with 1 in 400 devices being rooted, as opposed to around 1 in 2,500 iOS devices. ([Shaun Nichols / SC Media](https://www.scworld.com/news/rooted-jailbroken-mobile-devices-pose-security-risk-to-organizations?ref=metacurity.com)) **Related:** [*Zimperium*](https://www.zimperium.com/blog/catch-me-if-you-can-rooting-tools-vs-the-mobile-security-industry/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/03/image-74.png) Source: Zimperium. ### The US Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO's Backup & Replication software. Tracked as CVE-2024-48248, this absolute path traversal flaw can be exploited by unauthenticated attackers to read arbitrary files on vulnerable devices. The US-based backup and ransomware recovery software vendor silently patched the security flaw with the release of Backup & Replication v11.0.0.88174 in November, almost two months after being notified of the issue by cybersecurity company watchTowr, who discovered the vulnerability. In February, watchTowr also released a CVE-2024-48248 proof-of-concept described as a "detection artifact generator" that can also serve as "an unofficial NAKIVO customer support tool." While NAKIVO did not mark the vulnerability as actively exploited in a security advisory last updated on March 6th, the company still advises customers to check the system logs for signs of "unauthorized access attempts" and "unexpected file access activities." ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisa-tags-nakivo-backup-flaw-as-actively-exploited-in-attacks/?ref=metacurity.com)) **Related:** [*CISA*](https://www.cisa.gov/news-events/alerts/2025/03/19/cisa-adds-three-known-exploited-vulnerabilities-catalog?ref=metacurity.com)*,* [*Nakivo*](https://helpcenter.nakivo.com/Knowledge-Base/Content/Security-Advisory/CVE-2024-48248.htm?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2025/03/21/nakivo-backup-replication-vulnerability-exploited-by-attackers-cve-2024-48248/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/cisa-warns-of-exploited-nakivo-vulnerability/?ref=metacurity.com) ### Meredith Whittaker, president of US messaging app Signal, has threatened to pull it out of France over a proposed law where the government has demanded the ability to look into private chats. In Article 8 of the proposed “Narcotraffic” law, Sortir la France du piège du narcotrafic \[Getting France out of the drug trafficking trap\], France said it wanted encrypted messaging applications such as Signal and WhatsApp and encrypted email services such as Proton Mail to provide authorities with decrypted data of its users within 72 hours of request. The French Senate passed the provision on March 4, and it was scheduled for further consideration in the National Assembly. On March 17, the Assembly’s legislative committee reviewed it, setting off significant pushback. Whittaker put a lengthy post on X on March 19, sounding the alarm over the soon-to-be-voted-on French law. She condemned it as a “callow, dishonest attack,” contradicting expert consensus and threatening both global cybersecurity and the fundamental human right to privacy. ([Carl Deconinck / Brussels Signal](https://brusselssignal.eu/2025/03/messaging-app-signal-threatens-to-leave-france-over-anti-encryption-demands/?ref=metacurity.com)) **Related:** [*Computerworld*](https://www.computerworld.com/article/3850597/signal-threatens-to-leave-france-if-encryption-backdoor-required.html?ref=metacurity.com) ### Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances that have not been patched against a vulnerability exposing a built-in backdoor admin account. The CSLU Windows application allows admins to manage licenses and linked products on-premises without connecting them to Cisco's cloud-based Smart Software Manager solution. Cisco patched this security flaw (tracked as CVE-2024-20439) in September, describing it as "an undocumented static user credential for an administrative account" that can let unauthenticated attackers log into unpatched systems remotely with admin privileges over the API of the CSLU app. The company also addressed a second critical CLSU information disclosure vulnerability (CVE-2024-20440) that unauthenticated attackers can use to access log files containing sensitive data (including API credentials) by sending crafted HTTP requests to vulnerable devices. These two vulnerabilities only impact systems running vulnerable Cisco Smart Licensing Utility releases. They are only exploitable if the user starts the CSLU app—which isn't designed to run in the background by default. Aruba threat researcher Nicholas Starke reverse-engineered the vulnerability and published a write-up with technical details (including the decoded hardcoded static password) roughly two weeks after Cisco released security patches. SANS Technology Institute's Dean of Research Johannes Ullrich reported that threat actors are now chaining the two security flaws in exploitation attempts targeting CSLU instances exposed on the Internet. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/critical-cisco-smart-licensing-utility-flaws-now-exploited-in-attacks/?ref=metacurity.com)) ***Related:*** [*Security Affairs*](https://securityaffairs.com/175692/security/cisco-smart-licensing-utility-flaws-actively-exploited-in-the-wild.html?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/hackers-target-cisco-smart-licensing-utility-vulnerabilities/?ref=metacurity.com)*,* [*Starke Blog*](https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html?ref=metacurity.com)*,* [*SANS Internet Storm Center*](https://isc.sans.edu/diary/rss/31782?ref=metacurity.com) ### Menlo Security’s analysis of 750,000 browser-based phishing attacks targeting more than 800 entities detected over the last 12 months reveals a 140% increase in browser phishing, including a 130% increase in zero-hour phishing attacks (effectively, a zero-day attack applied to phishing). One significant factor is the growth of genAI by threat actors. The firm detected nearly 600 incidents with imposter sites passing themselves off as gen-AI sites offering fake AI services. Most gen-AI fraud was not for credential theft (the traditional first purpose of phishing). Harding notes that fake gen-AI sites trick people into entering personal data to generate a resume. ([Kevin Townsend / Security Week](https://www.securityweek.com/browser-security-under-siege-the-alarming-rise-of-ai-powered-phishing/?ref=metacurity.com)) **Related:** [*Menlo Security*](https://info.menlosecurity.com/rs/281-OWV-899/images/State-of-Browser-Security%5FThe-continued-impact-of-browser-based-threats.pdf?ref=metacurity.com)*,* [*Security Magazine*](https://www.securitymagazine.com/articles/101485-brand-impersonation-is-51-of-browser-phishing-attempts?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/129713/the-browser-is-riddled-with-bugs-2025-may-squash-them/?ref=metacurity.com) ### Russian internet users this week faced widespread outages that regulators attributed to issues with “foreign server infrastructure" that local experts said stemmed from Russia’s blocking of Cloudflare. According to data from several internet monitoring websites, the outages were observed Thursday across multiple Russian regions, particularly in the Urals and Siberia. They affected platforms such as TikTok, Steam, Twitch, Epic Games, Duolingo, and major Russian mobile operators. The disruption also impacted banking and government services, with users reporting difficulties accessing apps for Sberbank, Gazprombank, and Alfa-Bank, as well as the Russian government’s portal. Messaging apps, including Telegram and WhatsApp, also faced interruptions. Russian internet regulator Roskomnadzor said the disruptions affected services that rely on foreign server infrastructure and recommended that local organizations switch to Russian hosting providers. Roskomnadzor announced plans to inspect Russian services and telecom operators for using foreign servers, stating that these measures are necessary to improve the resilience and security of Russia’s internet infrastructure. “This blocking is a kind of ‘trial shot’ — both to see how much disruption it causes and to push Russian-based resources away from Cloudflare, signaling that it won’t work reliably and will only create problems for them,” said Roskomsvoboda’s technical director, Stanislav Shakirov. Shakirov suggested that Roskomnadzor will eventually block Cloudflare entirely. ([Daryna Antoniuk / The Record](https://therecord.media/russia-websites-dark-reported-cloudflare-block?ref=metacurity.com)) **Related:** [*Interfax*](https://www.interfax.ru/russia/1015589?ref=metacurity.com)*,* [*Tass*](https://tass.ru/obschestvo/23451713?ref=metacurity.com) ### Newly unsealed court records show federal law enforcement agencies have turned to a variety of techniques and surveillance capabilities to identify people who have allegedly set fire to Tesla vehicles and property, including automatic license plate readers and social media crawling. The documents come from cases that Attorney General Pamela Bondi announced on Thursday. The charges also come as sentiment towards Tesla and Elon Musk is at an all-time low. People have participated in regular and largely non-violent “Tesla Takedown” protests, and there have been multiple acts of vandalism around the country. This has captured the attention of Musk, Bondi, and Donald Trump, who are now all claiming that vandalizing Teslas will be treated as an act of domestic terrorism. Details about the surveillance techniques used to identify the alleged vandals show that police used a combination of automatic license plate readers and social media monitoring to investigate two of the crimes. In the third, the suspect was identified based on a combination of license plate records and fingerprints left on a Molotov cocktail bottle. ([Jason Koebler / 404 Media](https://www.404media.co/how-three-alleged-tesla-vandals-got-caught/?ref=metacurity.com)) ***Related:*** [*Justice.gov*](https://www.justice.gov/opa/pr/attorney-general-pamela-bondi-announces-severe-charges-against-violent-tesla-arsonists?ref=404media.co)*,* [*Reuters*](https://www.reuters.com/world/us/us-attorney-general-says-alleged-arsonists-targeting-tesla-face-charges-2025-03-20/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/news/us-news/3-face-federal-charges-tesla-arson-attacks-rcna197340?ref=metacurity.com), [*CBS News*](https://www.cbsnews.com/news/tesla-elon-musk-dealerships-security/?ref=metacurity.com) ### Best Thing of the Day: Give Us More Rulings Like This, But Make Them Permanent US District Judge Ellen Hollander in Maryland [temporarily blocked](https://apnews.com/article/social-security-trump-administration-acfdd0d7a53b7e5a1b5105baa456c5d0?ref=metacurity.com) billionaire Elon Musk’s Department of Government Efficiency from Social Security systems that hold personal data on millions of Americans, calling their work there a “fishing expedition.” ### Bonus Best Thing of the Day: I'm having trouble printing a music video from YouTube American Twitch streamer and YouTuber Kitboga built a bot army of various personas in an AI call center that scams the scammers at scale, most often for hours and frequently for days, and it's marvelous to behold. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/03/image-75.png) ### US halts coordinated effort to counter Russian cyberattacks, espionage and sabotage, report URL: https://www.metacurity.com/us-halts-coordinated-effort-to-counter-russian-cyberattacks-espionage-and-sabotage-report-2/ Last updated: 2025-03-20T13:22:49.000Z SpyX spyware suffered a breach, Baidu denies breach after exec's teen daughter spills PII, Nation-states exploit Windows .lnk files flaw, NCSC issues post-quantum warning, Ukraine warns of attacks on Signal, Ukraine's IT Army still going strong, Capital One hacker to face tougher sentence, much more _This post is for paying subscribers only._ ### Australia, Canada, Cyprus, Denmark, Israel, and Singapore likely bought Paragon spyware, Citizen Lab URL: https://www.metacurity.com/australia-canada-cyprus-denmark-israel-and-singapore-likely-bought-paragon-spyware-citizen-lab/ Last updated: 2025-03-19T14:35:58.000Z China's MSS says Taiwan conducted cyberattacks and pushed fake news, The Dutch seek to escape US tech, Organized crime uses AI intertwined with state-sponsored campaigns, Apple's Passwords apps had a serious flaw, Oracle eyes TikTok deal, Crims stole 2.1b creds with infostealers in 2024, much more _This post is for paying subscribers only._ ### Musk's Starlink service now routes through the White House sparking cybersecurity fears URL: https://www.metacurity.com/musks-starlink-service-now-routes-through-the-white-house-sparking-cybersecurity-fears-2/ Last updated: 2025-03-18T13:40:09.000Z CISA seeks to rehire fired employees, US Commerce Department bans DeepSeek, House panel asks Noem for Volt Typhoon and Salt Typhoon documents, Carney and Macron discuss deal on intel and cyber, Big sperm and egg bank breach exposes files, Alphabet to buy Wiz for $32b, much more _This post is for paying subscribers only._ ### A GitHub Action used in 23,000 repos was compromised in a supply chain attack URL: https://www.metacurity.com/a-popular-github-action-used-in-23-000-repos-was-compromised-in-major-supply-chain-attack/ Last updated: 2025-03-17T13:25:32.000Z 12K GitHub repos targeted with fake security alerts, All Echo voice requests will be stored in Amazon's cloud, OKX suspends service used to launder Bybit stolen funds, Infosys to pay $17.5m over 2023 breach, NIST removes safety from AI safety, S. Korea urges better cyber for drones, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 3/8/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-8-25/ Last updated: 2025-03-15T12:59:26.000Z Musk's DOGE crew has siphoned massive volumes of Americans' data, A crypto password-cracking firm hid its infamous hacker co-founder, An online abuse campaign tortured a young woman for years, Software developed by academics might prevent AI art theft, New details on the US-UK Cloud Act's impact _This post is for subscribers only._ ### White House to agencies: don't fire cybersecurity personnel URL: https://www.metacurity.com/white-house-to-agencies-dont-fire-cybersecurity-personnel/ Last updated: 2025-03-14T12:36:48.000Z Musk visits NSA after saying it needs an overhaul, UK urged to hold an open meeting on back door proposal, MSFT warns of Booking.com scam, Ukraine says Signal no longer gives Russian threat info, DeepSeek can generate keylogger and ransomware code, Emergency Junos OS patch released, much more _This post is for paying subscribers only._ ### Indian cops busted Garantex co-founder at the US government's request URL: https://www.metacurity.com/indian-cops-busted-garantex-co-founder-at-the-us-governments-request/ Last updated: 2025-03-13T13:32:50.000Z Chinese spy group is targeting Juniper Networks' routers, First presence of Volt Typhoon in US power grid confirmed, Medusa ransomware gang impacted 300 US critical infrastructure orgs, FCC to create security council to counter Chinese cyber threats, EU warns of Iran-Russia hybrid attacks, much more _This post is for paying subscribers only._ ### Trump nominates Sean Plankey as CISA Director URL: https://www.metacurity.com/trump-nominates-sean-plankey-as-cisa-director/ Last updated: 2025-03-12T13:45:44.000Z Alleged Garantex co-founder busted in India, DOGE cuts 100+ CISA red team members, MSFT issues over 50 Patch Tuesday fixes with patches for six zero days, Apple issues urgent zero day fix, Six Lazarus-linked malicious packages found on npm, NIST issues new quantum algorithm, much more _This post is for paying subscribers only._ ### Dark Storm group claims credit for DDoS attack on X that Musk blames on Ukraine URL: https://www.metacurity.com/musk-2/ Last updated: 2025-03-11T14:00:06.000Z NY sues Allstate for data breach reporting failure, 24-hour cyber incident reporting window set in Switzerland, AI voice cloning apps allow nonconsensual impersonation, CA AG launches location data industry probe, KS healthcare provider attack exposed PII for hundreds of thousands, much more _This post is for paying subscribers only._ ### Hack of LastPass in 2022 led to massive theft of XRP, now worth nearly $700 million URL: https://www.metacurity.com/2022-hack-of-lastpass-led-to-massive-hack-of-xrp-now-worth-nearly-700-million-2/ Last updated: 2025-03-10T13:38:23.000Z Whistleblower says Meta was willing to allow China to oversee all Facebook content, White House eyes DeepSeek ban, Commands in Chinese-made ESP32 microchip could lead to attacks, Terrorgram network caused two murders in Slovakia, Cyber incident exposed 18K NTT corporate customers' data, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 3/1/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-1-25/ Last updated: 2025-03-08T13:17:03.000Z How a free security product enabled the $1.5 billion Bybit theft, Unprecedented leak reveals scammers' operations, How scammers bilked millions in the UK using fake celebrity ads, The immensity of recently revealed scam operations, The time to get ready for quantum computing is now _This post is for subscribers only._ ### Law enforcement took down hacker-friendly Russian crypto exchange Garantex URL: https://www.metacurity.com/law-enforcement-took-down-hacker-friendly-russian-crypto-exchange-garantex/ Last updated: 2025-03-07T14:06:09.000Z US allies are dubious about intel sharing, Intel workers unsettled by firings, PyPI package steals ETH private keys, Rural hospitals struggle with cyber, Israel has built AI tool on intercepted Palestinian communications, 1Password makes it easier to find passwords based on location, much more _This post is for paying subscribers only._ ### US indicts twelve prolific Chinese hackers, including eight i-Soon staffers URL: https://www.metacurity.com/us-indicts-twelve-prolific-chinese-hackers-including-eight-i-soon-staffers/ Last updated: 2025-03-06T14:17:14.000Z Silk Typhoon targets remote management and cloud applications, FSB claims it disrupted Ukraine phishing bid to recruit Youth Army members, Former officials warn of a weaker CISA after staff cuts, A million Android streaming boxes conscripted into botnet, Utah passes age verification law, much more _This post is for paying subscribers only._ ### Apple appeals UK order to build encryption backdoor in cloud systems URL: https://www.metacurity.com/apple-appeals-uk-order-to-build-encryption-backdoor-in-cloud-systems/ Last updated: 2025-03-05T14:45:28.000Z Trump pauses intel sharing with Ukraine, BianLian is sending snail mail ransom notes, More proof of Black Basta and Cactus links emerges, Eleven11bot malware reaches 86k IoT devices, Dark Caracal refreshes its malware, Taylor Swift ticket cybercrime crew members arrested, much more _This post is for paying subscribers only._ ### Lazarus Group hackers have laundered 100% of the $1.4 billion they stole from Bybit URL: https://www.metacurity.com/lazarus-group-hackers-have-laundered-100-of-the-1-4-billion-they-stole-from-bybit/ Last updated: 2025-03-04T14:31:38.000Z Londoner found guilty for operating illegal crypto ATMs, CISA warns of Cisco and Windows flaws, Google issues Android fixes that include two zero days, Black Basta boss just walked away from detention, Kent cops warn of scammers posing as cybercrime authorities, Cybercrims dodge KYC rules, much more _This post is for paying subscribers only._ ### US Cybercom, CISA are softening stances on Russia as a cyber foe: reports URL: https://www.metacurity.com/us-cybercom-cisa-are-softening-stances-on-russia-as-a-cyber-foe-reports/ Last updated: 2025-03-03T22:17:38.000Z UK ICO launches children's social media privacy probe, Qilin claims attack on Lee Enterprises, Polish Space Agency breached, Cellebrite zero days used to hack Serbian student's phone, Man sentenced to 24 years for putting CSAM on dark web, Canceled CFPB contracts threaten data security, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 2/22/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-2-8-25-2/ Last updated: 2025-03-01T13:20:10.000Z A crypto scam tore a Kansas community apart, The Russian hacker in last year's prisoner swap, A deadly cult focused on safer AI, Disney’s Slack hack destroyed a worker, Telegram groups doxed women in Facebook groups, How China hunted NSA hackers, Hacking solar panels, The real threat of Chinese AI _This post is for subscribers only._ ### Storm-2139 network bypasses AI guardrails to make harmful content, Microsoft URL: https://www.metacurity.com/storm-2139-network-2/ Last updated: 2025-02-28T14:24:07.000Z Belgium investigates Chinese hacking of its intel service, Tuta and VTI raise concerns over France's encryption backdoor plans, Mismanaged keys led to nearly $500K Cardex loss, Nearly $500m stolen from Bybit has already been moved, Vo1d malware botnet has grown to 1.59m Android TVs, much more _This post is for paying subscribers only._ ### Vishing soared 442% during Q2 2024, Crowdstrike URL: https://www.metacurity.com/vishing-soared-442-during-q2-2024-crowdstrike/ Last updated: 2025-02-27T14:09:34.000Z AT&T and Verizon hacker tried to sell data to a foreign country, FBI confirms N. Korea was behind $1.5b crypto hack, Porch thieves charged with stealing iPhones, Cellebrite stops Serbia from using its tech, Desorden hacker busted in Thailand, HaveIBeenPwned adds 284m accounts, much more _This post is for paying subscribers only._ ### White House has relaxed cybersecurity measures to accommodate DOGE workers' personal devices URL: https://www.metacurity.com/white-house-has-relaxed-cybersecurity-measures-to-accommodate-doge-workers-personal-devices-2/ Last updated: 2025-02-26T14:35:20.000Z Pope confidant targeted with spy tool, Incoming DHS official calls CSRB officials' dismissal a "great idea," RNC hid Chinese breach, Termite group posted fertility clinic data, Bybit offers $140m in bug bounties, Signal to leave Sweden if backdoor bill enacted, EU sanctions DPRK officer, much more _This post is for paying subscribers only._ ### Judge stops DOGE access to Treasury systems, slams data access process URL: https://www.metacurity.com/judge-slams-doges-treasury-department-intrusions-2/ Last updated: 2025-02-25T23:14:30.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/1024px-Elon_Musk_at_a_Press_Conference-1.jpg) Source: Daniel Oberhaus Self-photographed, [https://www.flickr.com/photos/163370954@N08/46339127625](https://www.flickr.com/photos/163370954@N08/46339127625?ref=metacurity.com) *Don't miss my latest CSO piece, which* [*examines*](https://www.csoonline.com/article/3829440/managing-the-emotional-toll-cybersecurity-incidents-can-take-on-a-team.html?ref=metacurity.com) *how security leaders can ease the mental health burdens of serious cybersecurity incidents.* --- *Metacurity is mostly a reader-supported publication that relies on the generous support of our paid readers. Please consider supporting Metacurity with an upgraded subscription.* [Upgrade my subscription](#/portal/account/plans) *If you can't commit to a subscription today, please consider donating whatever you can. Thank you!* [Donate what you can](#/portal/support) --- ### In a glimmer of hope that the US justice system might serve as a check on the seemingly unlimited power of Elon Musk, US District Court Judge Jeannette Vargas extended an order to keep Musk’s DOGE team out of Treasury Department payment systems, ruling that the Trump administration’s process for granting access to sensitive data was so flawed and haphazard that it was likely illegal. Vargas ruled that Democratic attorneys general were likely to prevail in their claim that Treasury acted arbitrarily and capriciously in giving two DOGE employees access to the systems that control trillions of dollars of federal payments each year. She also ruled that the Treasury’s “rushed and ad hoc process” for granting DOGE access to the payment systems created a “realistic danger that confidential financial information will be disclosed.” Vargas dinged Treasury officials for standing up its DOGE operation in a “chaotic and haphazard” manner. The agency moved with “inexplicable urgency” to permit its DOGE team to access critical payment systems, Vargas wrote, leaving career staff “with almost no time” to develop measures to mitigate the “serious risks that access entailed.” The preliminary injunction Vargas issued prohibits anyone affiliated with the US DOGE Service or the Treasury DOGE team from accessing federal payment systems until further notice. This is narrower than an earlier*This* nearly all political appointees from *barred* the data. Judge Vargas said that Treasury’s explanations for the hurried process were “riddled with inconsistencies” and “lack credibility.” She said that Treasury’s error in briefly granting one DOGE employee, Marko Elez, full access to the payment system instead of “read-only” access was emblematic of a “hurried” and flawed process. She also raised questions about the adequacy of Treasury’s training and vetting of DOGE employees. Among her other observations was that DOGE worker Marco Elez and his ostensible boss, Thomas Krause, were not seemingly provided any specific training on the numerous federal regulations and policies governing the handling and care of sensitive information. She also noted that Elez was issued a secure laptop, but his activities at Treasury were only monitored for one day. His activities were only monitored via logging, and Treasury is reviewing those logs to determine what actions Elez took concerning PAM while he had access to those systems. She further found that - It's unclear if any measures were employed or were adequate to protect against unauthorized disclosures of the information contained in the BFS systems. - Elez emailed data outside the dept. but Treasury cannot say what he emailed or whether it was sensitive data. - No forensic review was conducted of Elez’s activity, and the logs were not reviewed to determine what he was doing when he had access to certain source codes and payment systems. ([Michael Stratford / Politico](https://www.politico.com/news/2025/02/22/judge-extends-doge-treasury-block-00205599?ref=metacurity.com) and [Metacurity](https://infosec.exchange/@metacurity/114047832711068873?ref=metacurity.com)) ***Related:*** [*Court Listener*](https://storage.courtlistener.com/recap/gov.uscourts.nysd.636609/gov.uscourts.nysd.636609.76.0%5F2.pdf?ref=metacurity.com)*,* [*SC World*](https://www.scworld.com/brief/extended-ban-imposed-on-doge-access-to-treasury-systems?ref=metacurity.com)*,* [*Fedscoop*](https://fedscoop.com/treasury-payments-systems-doge-judge-ruling/?ref=metacurity.com)*,* [*Meritalk*](https://www.meritalk.com/articles/judge-extends-block-on-doge-access-to-treasury-systems/?ref=metacurity.com)*,* [*Courthouse News*](https://www.courthousenews.com/federal-judge-extends-block-on-doge-access-to-treasury-payment-system/?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2025/02/21/judge-extends-block-on-musks-doge-from-treasury-systems.html?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/business/5158734-federal-judge-extends-decision-blocking-doge-from-treasury-payment-system/?ref=metacurity.com)*,* [*Federal News Network*](https://federalnewsnetwork.com/litigation/2025/02/judge-upholds-ban-on-doge-accessing-sensitive-treasury-information-for-now/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/world/us/judge-extends-block-musks-doge-treasury-systems-2025-02-21/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/tech-policy/2025/02/judges-block-doge-access-to-personal-data-in-loss-for-trump-administration/?ref=metacurity.com) ### Russia's National Coordination Center for Computer Incidents (NKTsKI) is warning organizations in the country's credit and financial sector about a breach at LANIT, a major Russian IT service and software provider. According to the organization's bulletin, the attack occurred on February 21, 2025, and potentially impacted LLC LANTER and LLC LAN ATMservice, both part of the LANIT Group of Companies. LANIT serves prominent entities such as the Russian Ministry of Defense and major players in the military-industrial complex, including Rostec, which is why the US Department of the Treasury sanctioned it in May 2024. LLC LANTER and LLC LAN ATMservice are Russian companies that specialize in banking technology and services, including software for banking equipment, payment systems, and Automated Teller Machines (ATMs). Due to the breach at these two entities, NKTsKI recommends all potentially impacted organizations rotate passwords and access keys and change remote access credentials. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/russia-warns-financial-sector-of-major-it-service-provider-hack/?ref=metacurity.com)) **Related*:* [*Gossopka.ru*](https://gossopka.ru/pub/nktski-preduprezhdaet-o-komprometatsii-lanit/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/174604/hacking/russia-warns-financial-sector-lanit-hack.html?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/major-russian-it-service-provider-hit-with-cyberattack?ref=metacurity.com) --- *Sponsored Interview* ## What exactly is zero trust again? Last week, a spotlight was cast on the concept of zero trust in Orlando, FL, when ThreatLocker held its annual [Zero Trust World](https://ztw.com/?utm%5Fsource=google&utm%5Fmedium=cpc&utm%5Fcampaign=google%5Fna%5Fnonb%5Fus-ca%5Fztw%5Fpro%5Fset1&utm%5Fterm=zero%20trust%20world%202025&utm%5Fcontent=180890673024&cq%5Fsrc=google%5Fads&cq%5Fcmp=22175037586&cq%5Fnet=g&gad%5Fsource=1&gclid=CjwKCAiAzvC9BhADEiwAEhtlNw-ylnDHJOQAUTPfeDv1wU2gcSsE0UDI9OuKX3wqsytFR7ivwl4f4BoCCx0QAvD%5FBwE). Although a desired goal and a buzzy term in cybersecurity, the phrase zero trust has so many variations that it can lose meaning. IBM, for example, [defines](https://www.ibm.com/think/topics/zero-trust?ref=metacurity.com) zero trust as "a security strategy for modern multicloud networks. Instead of focusing on the network perimeter, a zero trust security model enforces security policies for each individual connection between users, devices, applications and data." The Cybersecurity and Infrastructure Security Agency [says](https://www.cisa.gov/zero-trust-maturity-model?ref=metacurity.com) zero trust "provides a collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions in information systems and services in the face of a network viewed as compromised." Gartner [defines](https://www.gartner.com/en/industries/government-public-sector/topics/zero-trust?ref=metacurity.com) zero trust "as a mainstay of modern security strategies, taking over from traditional 'castle-and-moat' network security models in which no one outside the network can access data on the inside, but everyone inside the network can." Although all of these and other definitions of zero trust are interconnected, their varying nature can lead to an imprecise grasp of how to go about implementing ideas and technologies that all share the fundamental goal of keeping harmful software out of good networks. Or, in the words of Rob Allen, ThreatLocker's Chief Product Officer, "It's all about stopping things from being weaponized." Zero trust is defined as "Grant access only to any service node or user only where access is required to perform its function," Danny Jenkins, CEO and Co-Founder of ThreatLocker, told Metacurity. "That, in my mind, is what zero trust means. There's a whole framework around it, but the philosophy is very simple. It's the new word for least amount of privilege." Jenkins emphasized that "the bottom line is it means only grant where access is required to only allow an application to run if it needs to run. It's irrelevant whether it's good or bad, it's not allowed." Allen defines zero trust more succinctly. "It's to deny by default," he told Metacurity. But, he conceded, "there's a number of definitions that have been used. One way to look at it is about removing implicit trust and adding explicit trust. Removing implied trust from implicit trust and adding explicit trust is one way of looking at it." Yet another way to look at it is "to give people access or only the access that they need to do their jobs and no more is another way of looking at it," Allen said. "Probably my favorite way of looking at it is it was [an executive order](https://www.cisa.gov/topics/cybersecurity-best-practices/executive-order-improving-nations-cybersecurity?ref=metacurity.com#:~:text=Executive%20Order%20%28EO%29%2014028%2C,zero%20trust%20solutions%20across%20agencies.) that the US government brought out a number of years ago, and what they said was to assume a breach is inevitable or has already likely occurred." ThreatLocker's model of zero trust is achieved through a series of menu-driven options where allow access to any serviced node is denied by default, which runs contrary to the industry standard of letting everything in but blocking only those things you find undesirable and permit access only as exceptions. Once access is granted, everything is ring-fenced to create boundaries around approved applications to control their actions. Of course, Jenkins believes if the whole world followed this approach to zero trust, cybercriminals would give up in frustration. "If the whole world did this and they did it right, cybercrime would be an unprofitable business that turned to do something else." --- ### According to FTC complaints, an alleged job scam led by someone named "Aiden" from "OpenAI "recruited workers in Bangladesh for months before disappearing overnight. After connecting with the startup on Telegram and creating an account through a ChatGPT-branded app, a Bangladeshi worker invested crypto into the platform and began a months-long job working for “Aiden” from “OpenAI.” The work was performed through the website “OpenAi-etc,” and internal conversations were held on Telegram. The process is simple: Invest crypto, complete a few tasks, and earn daily profits based on the investment. During this worker’s tenure with the company, mentors continuously encouraged them to invest more money in the fund and recruit more Bangladeshi people to the team. The worker convinced over 150 to join, and the mentors divided the growing team of “brokers” into a hierarchy based on seniority. All seemed well until the morning of August 29, 2024, when everyone woke up to find that the website, all of their money, Aiden, and the other fake OpenAI employees had vanished overnight. A review of domain name system records for the now-defunct OpenAi-etc website shows that it appears to have been hosted by a China-based web hosting company. ([Reece Rogers / Wired](https://www.wired.com/story/openai-job-scam/?ref=metacurity.com)) **Related*:* [*dev.ua*](https://dev.ua/en/news/openai-rozpovila-pro-skam-1740477641?ref=metacurity.com) ### The Department of Health and Human Services (HHS) Office for Civil Rights, which oversees the Health Insurance Portability and Accountability Act (HIPAA) rules, fined eyewear retailer Warby Parker $1.5 million in 2018 for a credential stuffing attack that compromised the personal information of nearly 200,000 people. Warby Parker failed “to conduct an accurate and thorough risk analysis to identify potential risks and vulnerabilities” to electronic personal health information, HHS said and didn’t implement security measures to reduce risks to patient information. The company first detected unusual log-in activity in November 2018 and determined that a third party had gained access to customer accounts by credential stuffing, a method in which a hacker uses log-in information obtained elsewhere to try to breach accounts. The compromised information included names, addresses, payment information, and records related to eyewear prescriptions. After smaller incidents affecting fewer than 500 people, Warby Parker filed two other breach reports in April 2020 and June 2022. According to the OCR, as of September 2024, Warby Parker had still not conducted an assessment of the “potential risks and vulnerabilities” to the confidentiality of the health information. They said the company didn’t implement reasonable security measures around sensitive information until July 2022 and didn’t review “records of information system activity review” until May 2020\. ([James Reddick / The Record](https://therecord.media/feds-fine-warby-parker-health-data?ref=metacurity.com)) **Related:** [*HHS*](https://www.hhs.gov/sites/default/files/ocr-warby-parker-npd.pdf?ref=metacurity.com)*,* [*SC World*](https://www.scworld.com/brief/warby-parker-slapped-with-1-5m-penalty-over-data-breach?ref=metacurity.com)*,*[ *TechTarget*](https://www.techtarget.com/healthtechsecurity/news/366619430/OCR-Warby-Parker-to-pay-15M-penalty-for-violating-HIPAA?ref=metacurity.com)*,* [*BankInfoSecurity*](https://www.bankinfosecurity.com/feds-fine-eyeglass-retailer-15m-for-hipaa-lapses-in-hacks-a-27571?ref=metacurity.com) ### The SentinelLABS threat research team revealed that a data leak from TopSec, a prominent Chinese cybersecurity firm, has exposed details about the company’s operations and its probable involvement in internet censorship for the Chinese government. The team analyzed the leaked data, including over 7,000 lines of work logs and code used for DevOps practices. The data revealed scripts connecting to Chinese government hostnames, academic institutions, and news sites, suggesting TopSec’s services extend to a wide range of organizations. The documents detail TopSec’s involvement in projects for Bureaus of the Ministry of Public Security in several cities, including Shanghai, suggesting their participation in monitoring website security and content. One such project, the “Cloud Monitoring Service Project,” involved monitoring website security and content with alerts for breaches or policy violations. The data, submitted to a multi-scanner platform, includes employee work logs, scripts, and commands used for infrastructure administration. It features DevOps technologies like Ansible, Docker, and Kubernetes. Critically, hardcoded credentials were found, posing a significant security risk. ([Deeba Ahmed / HackRead](https://hackread.com/leaked-files-chinese-cybersecurity-firm-govt-censorship/?ref=metacurity.com)) **Related:** [*Sentinel Labs*](https://www.sentinelone.com/labs/censorship-as-a-service-leak-reveals-public-private-collaboration-to-monitor-chinese-cyberspace/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/chinese-cybersecurity-firms-involvement-in-surveillance-censorship-exposed-by-data-leak?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-49.png) Source: SentinelLabs. ### Google announced the development of quantum-safe digital signatures (FIPS 204/FIPS 205) in Google Cloud Key Management Service (Cloud KMS) for software-based keys. The search giant also provided a high-level view into its post-quantum strategy for Google Cloud encryption products, including Cloud KMS and the Cloud Hardware Security Module (Cloud HSM). This development is significant because the security of many of the world’s most widely used public-key cryptography systems has become a concern as experimental quantum computing advances. Large, cryptographically relevant quantum computers have the potential to break these algorithms. However, using existing hardware and software post-quantum cryptography (PQC) can mitigate these risks. In August 2024, the National Institute of Standards and Technology (NIST) released new PQC standards, enabling tech vendors worldwide to begin PQC migrations. ([Esther Shein / TechRepublic](https://www.techrepublic.com/article/google-cloud-kms-quantum-safe-digital-signatures/?ref=metacurity.com)) **Related*:* [*Google*](https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/news/google-cloud-kms-now-supports-quantum-safe-digital-signatures?ref=metacurity.com)*,* [*The Quantum Insider*](https://thequantuminsider.com/2025/02/24/google-expands-post-quantum-cryptography-support-with-quantum-safe-digital-signatures/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/google-cloud-introduces-quantum-safe-digital-signatures-in-kms/?ref=metacurity.com)*,* [*BankInfoSecurity*](https://www.bankinfosecurity.com/google-integrates-quantum-safe-digital-signatures-a-27577?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/128984/google-cloud-makes-digital-signatures-quantum-safe-in-kms/?ref=metacurity.com) ### Researchers at Bitdefender Labs report that threat actors are exploiting major Counter-Strike 2 (CS2) competitions, like IEM Katowice 2025 and PGL Cluj-Napoca 2025, to defraud gamers and steal their Steam accounts and cryptocurrency. The security firm warns that threat actors impersonate professional CS2 players like S1mple, NiKo, and Donk in live streams on YouTube, promoting fake CS2 skins and cryptocurrency giveaways. The channels that promote these scams are hijacked legitimate YouTube accounts, which the scammers rebrand as needed to impersonate professional players. What they show in these livestreams is loops of old gameplay footage, making it appear live to anyone who hasn't watched them before. Bitdefender says these scams often use names of legitimate platforms like CS.MONEY or esports sponsorships to further enhance the deception. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/fake-cs2-tournament-streams-used-to-steal-crypto-steam-accounts/?ref=metacurity.com)) **Related:** [*Bitdefender*](https://www.bitdefender.com/en-us/blog/hotforsecurity/streamjacking-scams-on-youtube-leverage-cs2-pro-player-championships-to-defraud-gamers?ref=metacurity.com)*,* [*The Record*](https://therecord.media/hackers-pose-as-esports-gamers-to-steal-crypto-from-fans?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/hackers-hijack-youtube-channels-cs2-fans-fake-giveaways/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-50.png) Fake YouTube CS2 livestream Source: Bitdefender. ### Detroit PBS notified 1,694 people about a data breach in August 2024 that compromised a significant amount of their personal information. The public broadcaster says unauthorized users accessed its systems between August 12 and August 31, 2024\. Ransomware gang Qilin claimed responsibility for the breach on September 23, 2024, saying it stole 573 GB of data. Detroit PBS is offering eligible victims 12 months of free credit monitoring via Experian. The deadline to enroll is May 30, 2025\. ([Paul Bischoff / Comparitech](https://www.comparitech.com/news/detroit-pbs-notifies-1700-of-data-breach-that-compromised-ssns-passwords-financial-and-medical-info/?ref=metacurity.com)) **Related:** [*Cybernews*](https://cybernews.com/security/television-station-detroit-pbs-hacked/?ref=metacurity.com)*,* [*Maine Attorney General*](https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/6492428c-d808-4bde-b1c1-9ce72c72fdb9.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-51.png) Source: Comparitech. ### Researchers at ESET report that hundreds of freelance software developers, ranging from junior developers to highly experienced professionals, have been targeted and infected with North Korean malware over the past year in a campaign they call DeceptiveDevelopment. As part of the attacks, ongoing since early 2024, the threat actors relied on fake personas and copied profiles to pose as software development recruiters and convince victims to download software projects that contained malware. North Korean hackers have long been using fake job offers to deliver malware to unsuspecting victims, either for espionage or financial gain. ESET notes that the DeceptiveDevelopment campaign follows the same patterns. On platforms like LinkedIn, Upwork, Freelancer.com, We Work Remotely, Moonlight, and Crypto Jobs List, the attackers post fake job offerings or approach targets looking for employment to convince them to download a malicious project. ESET warns that the targets are asked to inspect the software project, which is delivered either via file transfer or through a link to a private repository on GitHub, GitLab, or Bitbucket,. They are then asked to compile and execute the project and report any issues discovered back to the fake recruiter ([Ionut Arghire / Security Week](https://www.securityweek.com/freelance-software-developers-in-north-korean-malware-crosshairs/?ref=metacurity.com)) ***Related:*** [*WeLiveSecurity*](https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/malicious-ads-target-freelance/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-52.png) Source: ESET. ### US-based employee screening services company DISA Global Solutions said it suffered a data breach that affected more than 3.3 million people. DISA, which provides services like drug and alcohol testing and background checks to more than 55,000 enterprises and a third of Fortune 500 companies, confirmed the data breach in a filing with Maine’s attorney general on Monday. DISA said it discovered it had been the victim of a “cyber incident” that affected a “limited portion” of its network on April 22, 2024\. An internal investigation determined that a hacker had infiltrated the company’s network on February 9, 2024, where they went unnoticed for over two months. In a letter to those affected by the data breach, including individuals who underwent employee screening tests, DISA said the attacker “procured some information” from its systems. In a separate filing with the Massachusetts attorney general, DISA confirmed the stolen information included individuals’ Social Security numbers, financial account information including credit card numbers, and government-issued identification documents. This filing confirmed that more than 360,000 Massachusetts residents were affected by the breach. ([Carly Page / TechCrunch](https://techcrunch.com/2025/02/25/us-employee-screening-giant-disa-says-hackers-accessed-data-of-more-than-3m-people/?ref=metacurity.com)) **Related:** [*Maine Attorney General*](https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/b823b27d-5fe2-4f09-8753-b362741d7f95.html?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/data-breach-at-disa-global-solutions-exposes-3-3-million-americans/?mid=1&ref=metacurity.com#cid=2619856) ### Google wants to replace text-based two-factor authentication with QR codes when creating a new Gmail account. Google wants to “move away from sending SMS messages for authentication” when creating a new Gmail/Google account. In a preview, Google said it is “reimagining how we verify phone numbers.” Historically, the process involves entering a phone number and getting a 6-digit code over an SMS/text message that a user has to enter online to complete the account creation process. SMS codes present numerous security challenges, according to Gmail spokesperson Ross Richendrfer and his colleague at Google, Kimberly Samra. They can be phished, people don’t always have access to the device the codes are sent to, and they are reliant on the security practices of the user’s carrier. “If a fraudster can easily trick a carrier into getting hold of someone’s phone number,” Richendrfer said, any “security value of SMS goes away.” ([Davey Winder / Forbes](https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/?ref=metacurity.com)) ***Related:*** [*Gigazine*](https://gigazine.net/gsc%5Fnews/en/20250225-google-gmail-sms-authentication-qr-codes/?ref=metacurity.com)*,* [*9to5Google*](https://9to5google.com/2025/02/24/gmail-sms-account-creation/?ref=metacurity.com)*,* [*Gadgets 360*](https://www.gadgets360.com/internet/news/google-gmail-authentication-replace-sms-qr-codes-report-7790562?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/news/618303/google-replacing-sms-codes-qr-gmail-security-two-factor-authentication?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/gmail-ditch-sms-migrate-qr-authentication-3529073/?ref=metacurity.com)*,* [*The Tech Portal*](https://thetechportal.com/2025/02/25/googles-gmail-to-replace-sms-two-factor-authentication-with-qr-codes-report/?ref=metacurity.com)*,* [*Inc.*](https://www.inc.com/jason-aten/google-is-finally-fixing-the-worst-thing-about-websites-its-the-start-of-the-end-of-an-era/91152078?ref=metacurity.com) ### AI-driven defense platform company Rad Security announced it had raised $14 million in a Series A venture funding round. Cheyenne Ventures led the round, which included participation from Forgepoint Capital, Lytical Ventures, Akamai, .406 Ventures, Vertex Ventures, and Gula Tech Adventures. ([Eduard Kovacs / Security Week](https://www.securityweek.com/rad-security-raises-14-million-for-ai-cloud-security-platform/?ref=metacurity.com)) **Related:** [*Silicon Angle*](https://siliconangle.com/2025/02/24/rad-security-raises-14m-expand-ai-driven-cloud-security-platform/?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2025/02/rad-security-raises-14m-in-series-a-funding.html?ref=metacurity.com) ### Israeli cybersecurity company Skybox Security has laid off all its employees and ceased operations. The company employed approximately 100 people in Israel and another 200 in the United States. In Israel, employees were informed that their final salary would not be paid and were advised to contact the National Insurance Institute. Skybox’s CEO, Mordecai Rosen, met with employees to officially announce the company's closure and layoffs. Simultaneously, an email was sent to all employees regarding their next steps. Skybox sold all of its business and technology to Israeli cybersecurity company Tufin. ([Meir Ohrbach / CTech](https://www.calcalistech.com/ctechnews/article/s1wi4rc5yl?ref=metacurity.com)) **Related:** [*CTech,*](https://www.calcalistech.com/ctechnews/article/hywffvi51x?ref=metacurity.com)[*TechInAsia*](https://www.techinasia.com/news/israeli-cybersecurity-skybox-shuts-300-laid-offs?ref=metacurity.com)*,* [*Ynet News*](https://www.ynetnews.com/business/article/rjkoyzjqyg?ref=metacurity.com) ### Best Thing of the Day: How to Become a Billionaire Chainalysis issued a report that [details ](https://www.chainalysis.com/blog/bybit-exchange-hack-february-2025-crypto-security-dprk/?ref=metacurity.com)how the North Korean hackers managed to steal $1.5 billion from Bybit. ### Worst Thing of the Day: It's All Part of Their Plan The layoffs at CISA and the efforts to dismantle US foreign efforts to fight foreign disinformation meddling [are making ](https://www.cbsnews.com/news/trump-administration-firings-election-systems/?ref=metacurity.com)US elections less secure. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-48.png) ### DPRK's Lazarus Group swiped $1.5 billion from crypto exchange Bybit URL: https://www.metacurity.com/dprks-lazarus-group-swiped-1-5-billion-from-crypto-exchange-bybit/ Last updated: 2025-02-25T14:00:26.000Z Apple strips encrypted security from UK cloud users after gov't edict, Hackers are targeting Signal, CISA stops election security work, DOGE workers are now CISA staff, Hacker pleads guilty to telco phone records theft, Pegasus infections more rampant than expected, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 2/8/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-2-8-25/ Last updated: 2025-02-15T14:12:52.000Z DOGE is a national cyberattack, DOGE violates fundamental cybersecurity risk management principles, How a crypto fraud fighter survived a Nigerian prison, Toledo is spying on its poor citizens, Affluent seniors in South Carolina were targeted in crypto scams _This post is for subscribers only._ ### Dutch cops dismantle ZServers bulletproof hosting operation URL: https://www.metacurity.com/dutch-cops-dismantle-zservers-bulletproof-hosting-operation/ Last updated: 2025-02-14T15:01:54.000Z Italian spyware maker SIO makes malicious poseur apps, Zacks breach exposed 12m accounts, 2024 saw $12.4b in crypto scams, Newly renamed AI Security Institute emerges in UK, China's Emperor Dragonfly uses spy tools in ransomware attacks, DOGE lawsuits continue to fly, much more _This post is for paying subscribers only._ ### Salt Typhoon has continued with non-stop telco intrusions URL: https://www.metacurity.com/salt-typhoon-has-continued-with-non-stop-telco-intrusions/ Last updated: 2025-02-13T22:11:33.000Z Microsoft says Sandworm team is targeting English-speaking Western nations, Trump swapped Russian cybercrim for US teacher, DOGE staffer given accidental edit authority at Treasury, TikTok unofficial downloads surge in US, Spyware maker Variston shut down, Kimsuky poses as Korean official, much more _This post is for paying subscribers only._ ### Authorities bust two Russian operators behind Phobos ransomware URL: https://www.metacurity.com/authorities-bust-two-russian-operators-behind-phobos-ransomware-2/ Last updated: 2025-02-12T14:13:24.000Z Sean Cairncross is cyber director nominee, DOGE hit by lawsuit for violating Privacy Act, Teen swatter sentenced to four years, Woman behind DPRK worker scheme pleads guilty, Top Italian businessmen targeted in AI voice scam, Sandworm targets Ukraine Windows users, ZkLend hacked for $9m, much more _This post is for paying subscribers only._ ### Authorities sanction bulletproof hosting provider Zservers for LockBit support URL: https://www.metacurity.com/authorities-sanction-bulletproof-hosting-provider-zservers-for-lockbit-support/ Last updated: 2025-02-11T15:57:06.000Z Cops took down 8base gang's website, Authorities bust four Sky ECC distributors, NY State bans DeepSeek on gov't devices, SEC X hacker pleads guilty, NSA missions are hampered by DEI banned words, CISA election security workers placed on leave, Libyan activist targeted with spyware, much more _This post is for paying subscribers only._ ### Musk's teen DOGE worker belonged to The Com, got fired from a company for leaking secrets URL: https://www.metacurity.com/musks-teen-doge-worker-belonged-to-the-com-got-fired-for-leaking-company-secrets-2/ Last updated: 2025-02-10T15:27:14.000Z Judge pauses Musk's access to Treasury Dept., DOGE team member made deep cybersecurity cuts at Citrix Systems, TikTok CEO pitches JV to White House, Newspaper chain Lee Enterprises disrupted by cyber incident, DeepSeek riddled with security and privacy risks, RCE in Marvel Rivals found, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 2/1/25 URL: https://www.metacurity.com/next-long-read-3best-infosec-related-long-reads-for-the-week-of-2-1-25/ Last updated: 2025-02-08T13:18:55.000Z How Citizen Lab began tracking spyware, How Indians are becoming cyber-scam targets, How Pavel Durov got caught off-guard, How schools downplay and hide cyberattacks, How Musk is violating the Privacy Act of 1974 _This post is for subscribers only._ ### UK government demands Apple create an encrypted cloud backdoor URL: https://www.metacurity.com/uk-government-demands-apple-create-an-encrypted-cloud-backdoor/ Last updated: 2025-02-07T14:28:52.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/apple-1867461_1280-1.jpg) Image by [Pexels](https://pixabay.com/users/pexels-2286921/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=1867461) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=1867461) --- *Please consider supporting Metacurity with an upgraded subscription so that you can continue receiving our daily missives, packed with the top infosec developments you should know.* [Upgrade subscription](#/portal/account/plans) *If you can't commit to a subscription today, consider tipping or donating to help keep Metacurity going.* [Donate whatever you can](#/portal/support) --- ### Sources say security officials in the United Kingdom have demanded that Apple create a backdoor that would allow them to retrieve all the content any Apple user worldwide has uploaded to the cloud. The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not merely assistance in cracking a specific account. It has no known precedent in major democracies. T Sources said its application would mark a significant defeat for tech companies in their decades-long battle to avoid being wielded as government tools against their users. The sources said that rather than break the security promises it made to its users everywhere, Apple is likely to stop offering encrypted storage in the UK. However, that concession would not fulfill the UK demand for backdoor access to the service in other countries, including the United States. The sources said the office of the Home Secretary has served Apple with a document called a technical capability notice, ordering it to provide access under the sweeping UK Investigatory Powers Act of 2016, also known as the Snooper's Charter, which authorizes law enforcement to compel assistance from companies when needed to collect evidence. The law makes it a criminal offense to reveal that the government has even made such a demand. Apple can appeal the UK capability notice to a secret technical panel, which would consider arguments about the expense of the requirement, and to a judge who would weigh whether the request was proportionate to the government’s needs. However, the law prohibits Apple from complying during an appeal. In March, when the company was on notice that such a requirement might be coming, it told Parliament: “There is no reason why the U.K. \[government\] should have the authority to decide for citizens of the world whether they can avail themselves of the proven security benefits that flow from end-to-end encryption.” ([Joseph Menn / The Washington Post](https://www.washingtonpost.com/technology/2025/02/07/apple-encryption-backdoor-uk/?ref=metacurity.com)) **Related*:* [*MacRumors*](https://www.macrumors.com/2025/02/07/uk-government-orders-access-icloud/?ref=metacurity.com)*,* [*Financial Express*](https://www.financialexpress.com/life/technology-uk-orders-apple-to-give-insider-access-to-users-encrypted-data-says-report-3740915/?ref=metacurity.com)*,* [*PhoneArena*](https://www.phonearena.com/news/apple-encryption-uk-scandal%5Fid167394?ref=metacurity.com)*,* [*Benzinga*](https://www.benzinga.com/news/global/25/02/43554574/apple-faces-mounting-pressure-from-uk-government-to-grant-spying-access-to-encrypted-data-of-users-worldwide?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/mobile/apple-iphone-backdoor-access-icloud-data-uk-government-order/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/world/uk/uk-asks-apple-let-it-spy-users-encrypted-accounts-washington-post-reports-2025-02-07/?ref=metacurity.com)*,* [*Deccan Herald*](https://www.deccanherald.com/business/companies/uk-orders-apple-to-give-it-access-to-users-encrypted-accounts-report-3394793?ref=metacurity.com)*,* [*Hacker News (ycombinator)*](https://news.ycombinator.com/item?id=42970412&ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/news/608145/apple-uk-icloud-encrypted-backups-spying-snoopers-charter?ref=metacurity.com) ### Despite White House and Treasury Department denials that technologists associated with Elon Musk’s Department of Government Efficiency (DOGE) could rewrite the code of the payment system through which the vast majority of federal spending flows, DOGE operative Marko Elez did, in fact, have write access. Elez previously worked for SpaceX, Musk’s space company, and X, Musk’s social media company. Elez resigned Thursday after The Wall Street Journal inquired about his connections to “a deleted social-media account that advocated for racism and eugenics.” Elez was granted privileges including the ability to not just read but write code on two of the most sensitive systems in the US government: the Payment Automation Manager (PAM) and Secure Payment System (SPS) at the Bureau of the Fiscal Service (BFS), an agency that according to Treasury records paid out $5.45 trillion in fiscal year 2024. The ability to alter the code on these systems would, in theory, give a DOGE technologist, and, by extension, Musk, President Donald Trump, or other actors, the capability to, among other things, illegally cut off Congressionally authorized payments to specific individuals or entities. ([Vittoria Elliott, Leah Feiger, and Tim Marchman / Wired](https://www.wired.com/story/treasury-department-doge-marko-elez-access/?ref=metacurity.com)) ### Representatives of billionaire Elon Musk’s Department of Government Efficiency fanned out across several agencies, visiting the Atlanta headquarters of the Centers for Disease Control and Prevention and meeting with the Labor Department to seek access to sensitive data. The moves followed the DOGE team's gaining access to sensitive health payment systems at the Department of Health and Human Services. DOGE staffers met with agencies facing sweeping cuts in a project that has gutted whole programs and given Musk’s team broad access to private data. In a little more than two weeks, the Trump megadonor, acting as a “special government employee” while still running the companies that have made him the richest man in the world, has probed all over for cuts and begun enacting some, helping to shut down the US Agency for International Development effectively and suggesting that other departments could be next. The speed and scope of DOGE’s work have stunned many in the government and raised widespread legal and security concerns. ([Dan Diamond, Lauren Kaori Gurley, Lena H. Sun, Hannah Knowles, and Emily Davies / Washington Post](https://www.washingtonpost.com/health/2025/02/05/doge-health-agencies-labor/?ref=metacurity.com)) **Related:** [*Wall Street Journal*](https://www.wsj.com/politics/elon-musk-doge-medicare-medicaid-fraud-e697b162?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.bankinfosecurity.com/will-doge-access-to-cms-data-lead-to-hipaa-breaches-a-27463?ref=metacurity.com) ### Employees at the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CIsA) were initially excluded from broader government offers to take deferred resignation offers but some CISA employees have now been given the offer. Sources said Elon Musk's DOGE-driven effort gave the employees just hours to decide whether to accept it. "Team CISA, I am writing to provide an update that CISA employees may participate in the Deferred Resignation program ('Fork in the Road')," wrote Bridget Bean, who was identified in an email as the "senior official performing the duties of director" at CISA. "This is a deeply personal decision, and whichever decision you make, we support you." Bean also wrote that the offer expires on Thursday, February 6, 2025, before midnight. It's unclear whether the offer is legally binding or whether Congress will appropriate funds to pay for it after March. Separately, the National Security Agency (NSA) is the latest intelligence community entity, following the CIA, to offer its workforce the ability to leave their jobs in exchange for a paycheck for several months, according to two sources familiar with the move. ([Jenna McLaughlin / NPR ](https://www.npr.org/2025/02/06/nx-s1-5288883/cisa-staffers-deferred-resignations-doge?ref=metacurity.com)and [Martin Matishak / The Record](https://therecord.media/nsa-deferred-resignation-retirement-doge?ref=metacurity.com)) **Related:** [*NextGov/FCW*](https://www.nextgov.com/cybersecurity/2025/02/reversal-cisa-workforce-now-permitted-take-deferred-resignation-offer/402788/?ref=metacurity.com)*,* [*Federal News Network*](https://federalnewsnetwork.com/federal-newscast/2025/02/agencies-given-a-45-day-deadline-to-identify-biden-era-ses-career-only-positions/?ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/government/11679-cisa-employees-offered-chance-to-resign-as-part-of-trump-s-fork-in-the-road-program?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/general/protecting-the-us-from-hackers-apparently-isnt-in-trumps-budget-195915036.html?ref=metacurity.com) ### Following similar actions in Italy, South Korea, and Australia, US lawmakers said they plan to introduce a bill to ban DeepSeek’s chatbot application from government-owned devices over new security concerns that the app could provide user information to the Chinese government. The legislation written by Reps. Darin LaHood (R-IL) and Josh Gottheimer (D-NJ) echoes a strategy that Congress used to ban Chinese-controlled TikTok from government devices, which marked the beginning of the effort to block the company from operating in the US. “This should be a no-brainer in terms of actions we should take immediately to prevent our enemy from getting information from our government,” Gottheimer said. ([Natalie Andrews / Wall Street Journal](https://www.wsj.com/tech/ai/lawmakers-push-to-ban-deepseek-app-from-u-s-government-devices-6a76151a?st=i6ifdc&ref=metacurity.com)) **Related:** [*Ars Technica*](https://arstechnica.com/tech-policy/2025/02/us-lawmakers-push-to-quickly-ban-deepseek-on-government-devices/?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2025/02/06/us-senator-wants-to-fine-and-jail-those-who-use-deepseek-and-other-chinese-ais/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2025/02/06/us-lawmakers-introduce-bill-ban-deepseek-federal-devices/?ref=metacurity.com)*,* [*Josh Gottheimer*](https://gottheimer.house.gov/posts/release-gottheimer-lahood-introduce-new-bipartisan-legislation-to-protect-americans-from-deepseek?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/deepseek-bill-3523943/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/business/business-news/us-lawmakers-move-ban-deepseek-government-devices-chinese-surveillance-rcna190965?ref=metacurity.com)*,* [*Android Police*](https://www.androidpolice.com/congress-ban-deepseek/?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2025/02/06/us-congress-plans-ban-of-chinas-deepseek-ai-citing-national-security-risks-xcxwbn/?ref=metacurity.com)*,* [*Business Insider*](https://www.businessinsider.com/deepseek-bill-ban-government-devices-2025-2?ref=metacurity.com)*,* [*The Record*](https://therecord.media/lawmakers-push-for-deepseek-ban?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/ai/us-lawmakers-want-deepseek-banned-from-government-devices-212230100.html?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2025-02-06/lawmakers-seek-to-ban-deepseek-app-on-us-government-devices?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/tylerroush/2025/02/06/deepseek-should-be-banned-from-federal-devices-lawmakers-urge-after-ai-chatbot-linked-to-banned-chinese-firm/?ref=metacurity.com)*,* [*Associated Press*](https://apnews.com/article/deepseek-ai-china-us-ban-6fea0eb28735b9be7f4592185be5f681?ref=metacurity.com)*,* [*PYMNTS.com*](https://www.pymnts.com/artificial-intelligence-2/2025/deepseek-faces-ban-on-us-government-devices/?ref=metacurity.com)*,* [*CNN*](http://www.cnn.com/2025/02/06/tech/deepseek-ai-us-ban-bill/?ref=metacurity.com)*,* [*Semafor*](https://www.semafor.com/article/02/06/2025/us-lawmakers-seek-to-ban-deepseek-from-government-devices?ref=metacurity.com)*,* [*Techstrong.ai*](https://techstrong.ai/articles/lawmakers-push-for-deepseek-ban-in-u-s-government/?ref=metacurity.com)*,* [*Research & Development World*](https://www.rdworldonline.com/this-week-in-ai-research-u-s-lawmakers-push-to-ban-a-chinese-ai-disruptors-app-from-government-devices/?ref=metacurity.com)*,* [*Fortune*](https://fortune.com/2025/02/06/deepseek-ban-congress-china-mobile-us-ai-tiktok/?ref=metacurity.com)*,* [*nextpit*](https://www.nextpit.com/downloading-deepseek-20-years-1m-fine-could-follow?ref=metacurity.com)*,* [*Washington Examiner*](https://www.washingtonexaminer.com/policy/technology/3312507/deepseek-could-follow-tiktok-face-ban-government-devices/?ref=metacurity.com)*,* [*ABC News*](https://abcnews.go.com/US/lawmakers-propose-new-legislation-ban-deepseek-federal-devices/story?id=118509552&ref=metacurity.com)*,* [*DNyuz*](https://dnyuz.com/2025/02/06/washington-takes-aim-at-deepseek/?ref=metacurity.com)*,* [*Quartz*](https://qz.com/deepseek-us-government-devices-ban-bill-1851756696?ref=metacurity.com)*,* [*Fox Business*](https://www.foxbusiness.com/politics/house-reps-unveil-bill-banning-deepseek-from-us-government-devices-over-alleged-ties-chinese-government?ref=metacurity.com)*,* [*Krebs on Security*](https://krebsonsecurity.com/2025/02/experts-flag-security-privacy-risks-in-deepseek-ai-app/?ref=metacurity.com) ### A world-first organization assembled to categorize the severity of cybersecurity incidents along a hurricane-type scale, the Cyber Monitoring Centre (CMC), is up and running in the UK following a year-long incubation period. The cyber insurance industry and a handful of the UK's foremost cybersecurity thought leaders formed the CMC. It uses a severity classification system for the most severe computer assaults, similar to the Saffir-Simpson Scale, which differentiates hurricanes based on the damage they cause to affected regions. Public communications about the CMC began in January 2024, when the literature suggested it was a system that would help cyber insurance companies and their reinsurers independently define a systemic event. A systemic event emanates from a single source, such as an attack on a vendor, but significantly impacts myriad other organizations. The system categorizes cyber events on a 1-5 scale, with five being the most severe. Each event will be categorized by the CMC's technical committee, chaired by Ciaran Martin, the founding CEO of the UK's NCSC, comprising experts from industry, academia, and think tank The Royal United Services Institute (RUSI). Committee members will meet on an ad hoc basis when an event shows signs of damages exceeding £100 million ($123.6 million), multiple organizations in the UK are affected, and when the information required for an assessment is available. Methodology documents state that members will assemble for half a day to publish two deliverables: a severity categorization (1-5) and a report detailing how the decision was reached, what data informed it, and, in some cases, comments on the degree of confidence. The severity score will be determined by examining the financial impact of the event and the number of organizations affected. The finances factored into the decision include, but are not limited to, incident response costs, notification costs, ransom payments, data restoration costs, and business interruption costs. It won't consider liability payments or fines issued after the fact. ([Connor Jones / The Register](https://www.theregister.com/2025/02/07/uk%5Fcyber%5Fmonitoring%5Fcentre/?utm%5Fsource=dlvr.it&utm%5Fmedium=bluesky)) **Related:** [*Cyber Monitoring Center*](https://cybermonitoringcentre.com/2025/02/06/cyber-monitoring-centre-officially-starts-categorising-cyber-events/?ref=metacurity.com)*,* [*Cyber Monitoring Center*](https://cybermonitoringcentre.com/wp-content/uploads/2025/02/CMC-Methodology%5F5Feb2025.pdf?ref=metacurity.com)*,* [*ONS.gov.uk*](https://www.ons.gov.uk/news/news/onsworkingwiththecybermonitoringcentre?ref=metacurity.com)*,* [*Computer Weekly*](https://www.computerweekly.com/news/366618805/UKs-Cyber-Monitoring-Centre-begins-incident-classification-work?ref=metacurity.com)*,* [*Insurance Business America*](https://www.insurancebusinessmag.com/uk/news/cyber/behind-the-scenes-of-a-worldfirst-launch--the-cyber-monitoring-centre-523622.aspx?ref=metacurity.com)*,* [*DIGIT*](https://www.digit.fyi/new-uk-cyber-monitoring-centre-launches/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/new-uk-cyber-monitoring-centre/?ref=metacurity.com)*,* [*Rayo*](https://hellorayo.co.uk/greatest-hits/oxfordshire/news/oxford-professor-to-be-part-of-new-cyber-attack-monitoring-centre/?ref=metacurity.com)*,* [*Computing*](https://www.computing.co.uk/news/2025/security/world-first-cyber-event-classification-system-launches-in-uk?ref=metacurity.com)*,* [*RedPacket Security*](https://www.redpacketsecurity.com/new-uk-cyber-monitoring-centre-introduces-richter-scale-for-cyber-attacks/?ref=metacurity.com)*,* [*Morningstar*](https://www.morningstar.co.uk/uk/news/AN%5F1738837983918307700/uk-to-receive-new-cyber-attack-severity-rating-system.aspx?ref=metacurity.com)*,* [*The Insurer*](https://www.theinsurer.com/cyber-risk/news/cyber-monitoring-centre-officially-launches-to-categorise-uk-cyber-events-2025-02-06/?ref=metacurity.com)*,* [*The Independent*](https://www.independent.co.uk/business/uk-to-get-new-cyber-attack-severity-rating-system-b2693365.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-10.png) Source: CMC. ### Japan's cabinet approved two bills on "active" cyber defense security, paving the way for Japan to acquire preemptive capability against cyberattacks, often referred to as the “Achilles’ heel” of Japan’s defense system. The new measures aim to strengthen cooperation and facilitate information-sharing between public and private cyber actors. They will allow the government to acquire information traveling through Japan and infiltrate the sources of cyberattacks to neutralize them. If approved, the bills would give the government more powers to safeguard critical infrastructure and require private-sector entities to report the acquisition of critical infrastructure and potential cyberattacks to the authorities. The information would be shared with a group of relevant stakeholders. Government officials said that the number of entities expected to become the target of the new measures currently hovers around 200\. Those who leak cyberdefense-related secrets will be imprisoned for up to two years or fined up to ¥1 million ($6,600). Penalties for officials leaking intelligence information will be even harsher, at up to four years in prison. ([Gabriele Ninivaggi and Himari Semans / The Japan Times](https://www.japantimes.co.jp/news/2025/02/07/japan/politics/active-cyber-defense-bill/?ref=metacurity.com)) **Related*:* [*Kyodo News*](https://english.kyodonews.net/news/2025/02/2872bbccc100-update1-japan-cabinet-approves-cybersecurity-bill-to-bolster-cyber-defenses.html?ref=metacurity.com)*,* [*Digwatch*](https://dig.watch/updates/japan-introduces-active-cyber-defence-bill-to-strengthen-national-security?ref=metacurity.com) ### Researchers at AhnLab Security Intelligence Center (ASEC) recently observed the North Korean hacking group Kimsuky conducting attacks that used a custom-built RDP Wrapper and proxy tools to access infected machines directly. RDP Wrapper is a legitimate open-source tool designed to enable Remote Desktop Protocol (RDP) functionality on Windows versions that do not natively support it, like Windows Home. ASEC says the North Korean hackers now use diverse customized remote access tools instead of relying solely on noisy backdoors like PebbleDash, which is still used. It acts as a middle layer, allowing users to enable remote desktop connections without modifying system files. Kimsuky's version altered export functions to bypass antivirus detection and likely differentiates its behavior enough to evade signature-based detection. ASEC reports that once Kimsuky secures its foothold on the network, it drops secondary payloads. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/kimsuky-hackers-use-new-custom-rdp-wrapper-for-remote-access/?ref=metacurity.com)) **Related*:* [*ASEC*](https://asec.ahnlab.com/en/86098/?ref=metacurity.com)*,* [*SC World*](https://www.scworld.com/news/kimsuky-shifts-tactics-from-traditional-backdoors-to-rdp-proxies?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-11.png) Source: ASEC. ### The Yazoo Valley Electric Power Association, an electric utility serving multiple counties in Mississippi, was attacked by cybercriminals last summer, exposing the information of more than 20,000 residents. The utility warned customers on August 26 through social media that, due to software problems, it was unable to process payments. The system was restored by August 30. In breach notification letters filed with regulators last week, the utility confirmed it discovered “suspicious activity” on August 26 and initiated an investigation. The organization completed its review on October 24, determining that a “limited” amount of personal information was accessed. It then “worked to obtain address information for potentially affected individuals” until December 20. The organization redacted the information that was stolen by the hackers beyond the names of customers. Yazoo Valley Electric Power Association did not respond to requests for comment. The 20,997 victims are being offered one year of identity protection services. ([Jonathan Greig / The Record](https://therecord.media/mississippii-electric-utility-residents-breach?ref=metacurity.com)) **Related:** [*Yazoo Valley on Facebook*](https://www.facebook.com/YazooValleyElectric/posts/1030964262149145)*,* [*Office of the Maine Attorney General*](https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/93c8c3c5-1c8d-47bc-bf45-aefb701811f9.html?ref=metacurity.com)*,* [*JD Supra*](https://www.jdsupra.com/legalnews/yazoo-valley-electric-power-association-4005649/?ref=metacurity.com)*,* [*Teiss*](https://www.teiss.co.uk/news/mississippis-rural-power-utility-confirms-a-major-cyber-attack-15306?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/mississippi-electricity-provider-breach-hits-over-20k?ref=metacurity.com) ### Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. Microsoft Threat Intelligence experts recently discovered that some developers use ASP.NET validationKey and decryptionKey keys (designed to protect ViewState from tampering and information disclosure) found on code documentation and repository platforms in their own software. ViewState enables ASP.NET Web Forms to control state and preserve user inputs across page reloads. However, suppose attackers get the machine key designed to protect it from tampering and information disclosure. In that case, they can use it in code injection attacks to craft malicious payloads by attaching crafted message authentication code (MAC). In one instance observed in December 2024, an unattributed attacker used a publicly known machine key to deliver the Godzilla post-exploitation framework, which features malicious command execution and shellcode injection capabilities, to a targeted Internet Information Services (IIS) web server. To block such attacks, Microsoft recommends developers securely generate machine keys, not use default keys or keys found online, encrypt machineKey and connectionStrings elements to block access to plaintext secrets, upgrade apps to use ASP.NET 4.8 to enable Antimalware Scan Interface (AMSI) capabilities and harden Windows Servers by using attack surface reduction rules such as Block Webshell creation for Servers. Microsoft also shared detailed steps for removing or replacing ASP.NET keys in the web.config configuration file using either PowerShell or the IIS manager console. It removed key samples from its public documentation to discourage this insecure practice further. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/microsoft-says-attackers-use-exposed-aspnet-keys-to-deploy-malware/?ref=metacurity.com)) ***Related:*** [*Microsoft*](https://www.microsoft.com/en-us/security/blog/2025/02/06/code-injection-attacks-using-publicly-disclosed-asp-net-machine-keys/?ref=metacurity.com)*,* [*gbhackers*](https://gbhackers.com/hackers-exploit-asp-net-machine-keys-to-hack-iis-web-servers/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/173956/hacking/abusing-asp-net-machine-to-deploy-malware.html?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-12.png) Source: Microsoft. ### One of the first acts taken by Pam Bondi after being sworn in as US attorney general was to disband the FBI’s Foreign Influence Task Force that countered the influence of adversarial foreign governments on American politics. In a memo, Bondi wrote that the Department of Justice would be shifting resources in its National Security Division, including disbanding the FBI task force, “to free resources to address more pressing priorities, and end risks of further weaponization and abuses of prosecutorial discretion.” Bondi’s memo also states that the Department of Justice will now only refer criminal charges under the Foreign Agents Registration Act if they “alleged conduct similar to more traditional espionage by foreign government actors.” ([Derek B. Johnson / Cyberscoop](https://cyberscoop.com/doj-disbands-foreign-influence-task-force/?ref=metacurity.com)) ***Related:*** [*Justice.gov*](https://www.justice.gov/ag/media/1388541/dl?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/politics/national-security/bondi-ends-fbi-effort-combat-foreign-influence-us-politics-rcna191012?ref=metacurity.com)*,* [*Bloomberg Law*](https://news.bloomberglaw.com/us-law-week/bondi-scales-back-us-justice-department-white-collar-enforcement?ref=metacurity.com) ### Gravy Analytics has been sued again for allegedly failing to safeguard its vast stores of personal data, which are now feared stolen, which include the locations of tens of millions of smartphones, coordinates of which were ultimately harvested from installed apps. A complaint filed in federal court in northern California is at least the fourth such lawsuit against Gravy since January, when an unidentified criminal posted screenshots to XSS, a Russian cybercrime forum, to support claims that 17 TB of records had been pilfered from the American analytics outfit's AWS S3 storage buckets. The suit this week alleges that a massive archive contains the geo-locations of people's phones. It alleges "the hacked Gravy Analytics data included tens of millions of mobile phone coordinates of devices inside the US, Russia, and Europe, obtained through individuals’ use of major mobile applications such as Tinder, Grindr, Candy Crush, Subway Surfers, Moovit, My Period Calendar & Tracker, MyFitnessPal, Tumblr, Microsoft’s 365 office application, Yahoo’s email client, religious-focused apps such as Muslim prayer and Christian Bible apps, various pregnancy trackers, and many VPN apps, which users generally download, ironically, in an attempt to protect their privacy." ([Thomas Claburn / The Register](https://www.theregister.com/2025/02/06/gravy%5Fanalytics%5Fdata%5Fbreach%5Fsuit/?ref=metacurity.com)) **Related:** [*Courtlistener*](https://storage.courtlistener.com/recap/gov.uscourts.cand.444005/gov.uscourts.cand.444005.1.0.pdf?ref=metacurity.com) ### On Feb. 3, Nigeria's Economic and Financial Crimes Commission (EFCC) arraigned 42 foreign nationals, mainly Chinese and Filipino, on charges related to alleged cryptocurrency investment and romance fraud, part of a massive raid conducted in December 2024 against a purported cybercriminal syndicate of nearly 800 people. The EFCC said the defendants willfully "caused to be accessed, a computer system which was organized to seriously destabilize the economic and social structure of the Federal Republic of Nigeria, by procuring and employing several Nigerian youths for identity theft and other computer related fraud." ([Robert Lemos / Dark Reading](https://www.darkreading.com/cyber-risk/nigeria-touts-cyber-success-african-cybercrime-rises?ref=metacurity.com)) **Related:** [*EFCC.gov.ng*](https://www.efcc.gov.ng/efcc/news-and-information/news-release/10655-efcc-arraigns-29-chinese-10-filipinos-three-others-for-alleged-internet-fraud-in-lagos?ref=metacurity.com) ### After Michigan-based Nader Eldamouni and his business partner decided to buy a $300,000 Rolls Royce Dawn convertible, car thieves used the vehicle's transport window to hack into the transport system and reroute the car's delivery elsewhere. Eldamount believes thieves stole the car after it was picked up for transport on January 17\. ([Chris Chilton / Carscoops](https://www.carscoops.com/2025/02/hackers-reroute-delivery-truck-to-steal-300k-rolls-royce-dawn/?ref=metacurity.com)) **Related:** [*WSVN*](https://wsvn.com/news/us-world/i-feel-not-safe-michigan-man-believes-car-thieves-rerouted-rolls-royce-he-ordered-from-south-florida/?ref=metacurity.com) ### Cybersecurity startup Astra Security announced it had received $2.7 million in a venture capital growth round. Emergent Ventures led the round, with additional support from Better Capital, Blume Ventures, Neon Fund, and PointOne Capital. ([Ionut Arghire / Security Week](https://www.securityweek.com/astra-invary-raise-millions-for-ai-powered-pentesting-runtime-security/?ref=metacurity.com)) **Related:** [*Analytics India Magazine*](https://analyticsindiamag.com/ai-news-updates/india-based-cybersecurity-firm-astra-security-raises-2-7-million-in-funding/?ref=metacurity.com)*,* [*sdx central*](https://www.sdxcentral.com/articles/news/astra-security-raises-funding-to-simplify-cybersecurity-with-ai-driven-pentesting/2025/02/?ref=metacurity.com)*,* [*CityBiz*](https://www.citybiz.co/article/658111/astra-security-raises-funding/?ref=metacurity.com)*,* [*Economic Times*](https://economictimes.indiatimes.com/tech/funding/astra-security-raises-2-7-million-from-emergent-ventures-others/articleshow/117980607.cms?from=mdr&ref=metacurity.com)*,* [*Entrepreneur*](https://www.entrepreneur.com/en-in/news-and-trends/astra-security-closes-usd-27-mn-funding-round-led-by/486671?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2025/02/05/astra-raises-2-7m-simplify-cybersecurity-mimicking-hacker-behavior-ai-powered-solutions/?ref=metacurity.com)*,* [*Inc42*](https://inc42.com/buzz/astra-security-bags-2-7-mn-to-offer-cybersecurity-solutions-to-enterprises/?ref=metacurity.com)*,* [*Unite.AI*](https://www.unite.ai/astra-security-raises-2-7m-to-revolutionize-cybersecurity-with-ai-driven-pentesting/?ref=metacurity.com) ### Best Thing of the Day: You Can't Fight What You Can't Name The journalists at ProPublica are keeping a [database of the employees](https://projects.propublica.org/elon-musk-doge-tracker/?ref=metacurity.com) from Elon Musk’s companies and those of his allies, as well as young staffers he’s recruited, to participate in Musk's DOGE effort to demolish federal government agencies. ### Bonus Best Thing of the Day: Everyone Can Do Their Part Kevin Couture, a resident of Maine, [submitted a breach report](https://databreaches.net/2025/02/06/maybe-we-should-all-file-breach-reports-against-musk-like-kevin-did/?ref=metacurity.com) to the state of Maine naming Elon Musk as the entity responsible for a data breach involving his personal information, citing Musk's DOGE effort to rummage around in US government databases. ### Worst Thing of the Day: Mean Phishing Tests IT departments [are crafting](https://www.wsj.com/tech/cybersecurity/phishing-tests-the-bane-of-work-life-are-getting-meaner-76f30173?ref=metacurity.com) increasingly sensational phishing tests, which they say is a necessary response to increasingly sophisticated scams, but employees say these emails only scare, confuse, or shame them. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-9.png) ### Musk clearly didn’t consult with the competent CISOs at OMB, Treasury, and US AID URL: https://www.metacurity.com/musk-clearly-didnt-consult-with-the-competent-cisos-at-omb-treasury-and-us-aid/ Last updated: 2025-02-06T14:56:01.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/1024px-U_S_Air_Force_Space_Pitch_Day_-5892591--1.jpg) US Air Force photo by Van Ha, Public domain, via Wikimedia Commons *There's been grumbling lately about the Common Vulnerability Scoring System, so I looked more closely at whether the industry is ready to move on from the ubiquitous system. Check out what I found in* [*my latest piece* ](https://cyberscoop.com/cvss-criticism-cve-nvd-nist-epss/?ref=metacurity.com)*for Cyberscoop.* --- *On Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/account/plans) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers) - A young technologist, Edward Coristine, known online as “Big Balls,” with a checkered professional and online history who works for Elon Musk's so-called Department of Government Efficiency (DOGE), has access to sensitive US government systems. - Congress is getting vocal about the privacy and security implications of Elon Musk and his cohorts at the Department of Government Efficiency accessing federal systems. - Employees of the agency, now known as DOGE, have been ordered to stop using Slack while government lawyers attempt to transition the agency to one not subject to the Freedom of Information Act. - South Korea's industry ministry has temporarily blocked employee access to Chinese artificial intelligence startup DeepSeek due to security concerns as the government urges caution on generative AI services. - Researchers at Feroot report that the website of the Chinese artificial intelligence company DeepSeek has computer code that could send some user login information to a Chinese state-owned telecommunications company China Mobile that has been barred from operating in the United States. - The Italian government said that a spyware campaign revealed by WhatsApp and carried out with spyware made by Paragon Solutions targeted people across several European countries. - European prosecutors are examining how the Moscow office of the French IT group Atos used staff in Russia to buy software in 2021 for the highly sensitive new EU electronic border system, which aims to gather and store biometric data on all non-EU visitors to the EU. - Spanish police have arrested a suspected hacker in Alicante for allegedly conducting 40 cyberattacks targeting critical public and private organizations, including the Guardia Civil, the Ministry of Defense, NATO, the US Army, and various universities. - Despite a prior understanding, former US Secretary of State Antony Blinken recently requested the extradition of an Israeli citizen known as the "Ashkelon hacker" after he was released from prison in Israel and later arrested in Oslo at Washington’s request. - Researchers at Kaspersky report that Android and iOS apps on the Google Play Store and Apple App Store contain a malicious software development kit (SDK) designed to steal cryptocurrency wallet recovery phrases using optical character recognition (OCR) stealers. - The US Federal Communications Commission (FCC) proposed a $4,492,500 fine against VoIP service provider Telnyx for allegedly allowing customers to make robocalls posing as fictitious FCC "Fraud Prevention Team" by failing to comply with Know Your Customer (KYC) rules. - Engineering firm IMI revealed it had been hit by a cyber attack just a week after rival Smiths Group said hackers had gained access to its global systems. - Researchers at Abnormal Security report that a help desk phishing campaign targets an organization's Microsoft Active Directory Federation Services (ADFS) using spoofed login pages to steal credentials and bypass multi-factor authentication (MFA) protections. - The San Francisco-Marin Food Bank disclosed a data breach affecting over 60,000 people. - ​CISA has ordered federal agencies to secure their systems within three weeks against a high-severity Linux kernel flaw actively exploited in attacks. - Application security startup Semgrep announced it had raised $100 million in a Series D funding round. --- ## Cleary Musk didn’t consult with the competent CISOs at OMB, Treasury, and US AID While teenagers, or those just barely out of their teens, [with dubious security clearances](https://www.wired.com/story/edward-coristine-tesla-sexy-path-networks-doge/?ref=metacurity.com) rummage around in sensitive US federal systems, possibly violating federal cybersecurity and privacy laws and maybe [spreading malware and inviting US adversary hacks](https://www.csoonline.com/article/3815925/musks-doge-effort-could-spread-malware-expose-us-systems-to-threat-actors.html?ref=metacurity.com) along the way, qualified chief information security officers (CISOs) are at the top of the plundered government agencies. They no doubt are watching with increasing alarm the Musk DOGE workers possibly burn to the ground any security measures they oversee. Almost certainly compounding those CISOs' anxiety is [the recent move](https://www.nbcnews.com/tech/security/trump-admin-moves-make-tech-officials-appointees-doge-clashes-rcna190718?ref=metacurity.com) by Donald Trump to politicize the roles of federal government chief information officers (CIOs) to whom those CISOs report. Over at OMB, Michael Duffy is the [agency's CISO](https://www.cio.gov/about/members-and-leadership/duffy-michael/?ref=metacurity.com#:~:text=Michael%20Duffy%20serves%20as%20the,maturation%20across%20the%20Federal%20Government) and the interim Federal Chief Information Security Officer, where he is responsible for driving cybersecurity policy development and adoption, overseeing strategy alignment and implementation efforts, and ensuring cyber program improvement and maturation across the entire Federal Government. Duffy has legitimate credentials for the job. He was most recently the Associate Director for Capacity Building within CISA's Cybersecurity Division, is a two-time recipient of the Secretary of Homeland Security's Meritorious Service award for his contributions to national-level cybersecurity, and chairs the Federal Chief Information Security Officers (CISO) Council, the primary body for interagency CISO collaboration and communication, among other accomplishments. The US Treasury Department likewise has a competent CISO in [Christopher Adams](https://www.linkedin.com/in/christopher-adams-162a19129/?ref=metacurity.com). Adams has over 15 years of IT experience, including over a decade in various security and CIO roles in the Air Force, a stint as CIO at the National Space Defense Center, and private sector cybersecurity experience. He holds multiple master of science degrees in IT and digital forensics. Another government agency that Musk and his young workers targeted is the US Agency for International Development, or US AID, which [now may be doomed](https://www.wsj.com/politics/policy/how-trump-musk-doge-killed-usaid-b649f1f5?ref=metacurity.com) due to the rapidly moving destruction that Musk and Trump are wreaking on the federal government. It also has a qualified CISO, [Steve Hernandez](https://fedscoop.com/usaid-ciso-steven-hernandez/?ref=metacurity.com), who was previously the Department of Education's CISO and worked in information security at the Department of Health and Human Services' Office of Inspector General. He has been the co-chair of the United States Federal Chief Information Security Officer Council since 2018. _This post is for paying subscribers only._ ### Ransomware payments fell 35% last year, Chainalysis URL: https://www.metacurity.com/ransomware-payments-fell-35-last-year-chainalysis/ Last updated: 2025-02-05T15:24:37.000Z Fed CIOs will become political appointees, Trump tries to thin CIA's ranks, DeepSeek's R1 ranks lowest in cybersecurity, Oz bans DeepSeek from government offices, Thailand shuts power from scammer compounds, Unions sue Treasury for database plundering, Evans now CISA senior adviser, much more _This post is for paying subscribers only._ ### Elon Musk knows jack about cybersecurity URL: https://www.metacurity.com/elon-musk-knows-jack-about-cybersecurity/ Last updated: 2025-02-04T15:28:15.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/1024px-Elon_Musk_-12270805983--1b5059ec547d369f.jpg) Tesla Owners Club Belgium, [CC BY 2.0](https://creativecommons.org/licenses/by/2.0?ref=metacurity.com), via Wikimedia Commons *Don't miss* [*my latest CSO piece that examine*](https://www.csoonline.com/article/3815925/musks-doge-effort-could-spread-malware-expose-us-systems-to-threat-actors.html?ref=metacurity.com)*s how Musk's DOGE effort could spread malware across the US government and expose critical government systems to threat actors.* --- *On Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/account/plans) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers) - Federal prosecutors charged Canadian fugitive Andean Medjedovic with stealing $65 million in cryptocurrency from a pair of crypto platforms and also with laundering his illegal gains. - Last fall, the US Agency for International Development learned a cryptojacking incident hit it after Microsoft notified it that a global administrator account located in a test environment had been breached through a password spray attack. - Security intelligence specialist VulnCheck reports that the 2024 calendar year saw a total of 768 CVE-listed vulnerabilities come under fire from threat actors in the wild, a 20% increase from 2023 when 639 vulnerabilities were actively attacked. - In a new policy document, Meta suggests that there are certain scenarios in which it may not release a highly capable AI system it developed internally if they are deemed "high risk" or "critical risk" systems. - Artificial intelligence startup Anthropic has demonstrated a new technique to prevent users from eliciting harmful content from its models as leading tech groups, including Microsoft and Meta, race to find ways to protect against dangers posed by cutting-edge technology. - The February 2025 Android security updates patch 48 vulnerabilities, including a zero-day kernel vulnerability that has been exploited in the wild. Columbus Mayor Andrew Ginther's office said citizens' private health information was compromised when hackers infiltrated the city of Columbus computer systems last summer. - Food delivery company GrubHub disclosed a data breach impacting the personal information of an undisclosed number of customers, merchants, and drivers after attackers breached its systems using a service provider account. - Two more Texas Health and Human Services Commission employees have been fired for accessing the private information of Texans seeking public assistance in the state’s Medicaid, food stamps, and other programs. - The January breach of PowerSchool, which provides K-12 software to more than 18,000 schools to support some 60 million students across North America, has the potential to be one of the biggest breaches of the year, and yet the company is keeping mum about many important details. - With Trump now in office, the most dire straits that some opponents were advocating for the Cybersecurity and Infrastructure Security Agency appear to be off the table. - French cybersecurity startup Riot announced it had raised $30 million in a Series B venture round. --- ## Elon Musk knows jack about cybersecurity As the phenomenal infiltration of US government digital assets by Elon Musk and his band of very young men continues, one thing is clear: Elon Musk knows jack about cybersecurity. As my piece in [today's CSO Online](https://www.csoonline.com/article/3815925/musks-doge-effort-could-spread-malware-expose-us-systems-to-threat-actors.html?ref=metacurity.com) attests, along with excellent reporting from some [top](https://therecord.media/doge-opm-treasury-cybersecurity?ref=metacurity.com) [infosec](https://www.politico.com/news/2025/02/03/doge-treasury-usaid-donald-trump-011538?ref=metacurity.com) journalists and superb ongoing [scoops](https://www.wired.com/story/elon-musk-associate-bfs-federal-payment-system/?ref=metacurity.com) from Wired and [traditional media outlets](https://www.nytimes.com/2025/02/03/us/politics/musk-federal-government.html?smid=nytcore-ios-share&referringSource=articleShare&ref=metacurity.com), the US is likely in for a world of hurt once malicious threat actors have acted on the enormous security bungling by Musk's team. Financially motivated criminals and nation-states might steal every secret the government harbors and exploit every critical weakness exposed by the crew's sloppy cybersecurity efforts. Some think Musk is a genius for becoming the world's richest man. But when it comes to protecting digital assets, Musk is no savant. When he took over Twitter, [he fired](https://www.forbes.com/sites/thomasbrewster/2024/01/10/elon-musk-fired-80-per-cent-of-twitter-x-engineers-working-on-trust-and-safety/?ref=metacurity.com) virtually all of the social media network's trust and safety crew, along with most cybersecurity employees. "Elon Musk does not imbue some sort of special cybersecurity veil. His SpaceX and Tesla have both been hit hard by data breaches," Mark Montgomery of the Foundation for the Defense of Democracies tells Metacurity. "There's nothing special about Elon Musk and cybersecurity. He's just as weak or strong as everyone else. And so, the fact that you're a brilliant businessman has almost nothing to do with being with properly following cybersecurity governance rules." _This post is for paying subscribers only._ ### Very young engineers with no government or infosec experience are rifling through critical US government systems URL: https://www.metacurity.com/very-young-engineers-with-no-government-or-infosec-experience-are-rifling-through-critical-us-government-systems/ Last updated: 2025-02-03T15:09:48.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/musk-sengineers-1.png) Source: @bonnicula.bsky.social --- *Please consider supporting Metacurity with an upgraded subscription so that you can continue receiving our daily missives, packed with the top infosec developments you should know.* [Upgrade subscription](#/portal/account/plans) *If you can't commit to a subscription today, consider tipping or donating to help keep Metacurity going.* [Donate whatever you can](#/portal/support) --- ### Six young engineers, all under age 24 and one just out of high school, with no government or cybersecurity experience, are now playing critical roles in Musk’s Department of Government Efficiency (DOGE) project, gaining unrestricted access to computer systems at the Office of Personnel Management (OPM), General Services Administration (GSA), Treasury Department, US AID and possibly elsewhere. The engineers are Akash Bobba, Edward Coristine, Luke Farritor, Gautier Cole Killian, Gavin Kliger, and Ethan Shaotran. One source says Bobba, Coristine, Farritor, and Shaotran all currently have working GSA emails and A-suite-level clearance at the GSA. This means they work out of the agency’s top floor and have access to all physical spaces and IT systems. The source says they worry that the new teams could bypass the regular security clearance protocols to access the agency’s sensitive compartmented information facility, as the Trump administration has already granted temporary security clearances to unvetted people. One Treasury official, David A. Lebryk, the highest-ranking career official at the department, left the agency after a clash with allies of billionaire Elon Musk over access to sensitive payment systems. Sources say officials affiliated with Musk’s “Department of Government Efficiency” have been asking for access to the system since after the election, requests reiterated more recently, including after Trump’s inauguration. Tom Krause, a Silicon Valley executive who has now been detailed to Treasury, is among those involved. After gaining access to the Treasury Department systems, Musk claims he has stopped paying federal contractors, saying, "The corruption and waste is being rooted out in real time." Musk also announced that he shut down USAID and ordered agency personnel not to attend work today. ([Vittoria Elliott / Wired](https://www.wired.com/story/elon-musk-government-young-engineers/?ref=metacurity.com) and [Gregory Korte and Viktoria Dendrinou / Bloomberg](https://www.bloomberg.com/news/articles/2025-02-02/musk-says-doge-is-rapidly-shutting-down-treasury-payments?ref=metacurity.com) and [John Hudson, Ellen Nakashima, Missy Ryan, Mariana Alfaro and Faiz Siddiqui / Washington Post](https://www.washingtonpost.com/politics/2025/02/02/usaid-trump-musk/?ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/world/us/musk-aides-lock-government-workers-out-computer-systems-us-agency-sources-say-2025-01-31/?ref=metacurity.com)*,* [*Washington Post*](https://www.washingtonpost.com/business/2025/01/31/elon-musk-treasury-department-payment-systems/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/tech-policy/2025/01/musks-doge-clashes-with-treasury-over-access-to-payment-system-report-says/?ref=metacurity.com)*,* [*ABC News*](https://abcnews.go.com/US/treasury-dept-elon-musks-team-access-federal-payment/story?id=118380399&ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2025/02/01/us/politics/elon-musk-doge-federal-payments-system.html?unlocked%5Farticle%5Fcode=1.t04.I3uM.op2-1qIIZxM9&ref=metacurity.com)*,* [*Wired*](https://www.wired.com/story/elon-musk-government-tech-workers-gsa-tts/?ref=metacurity.com)*,* [*New York Magazine*](https://nymag.com/intelligencer/article/elon-musk-doge-treasury-access-federal-payments.html?ref=metacurity.com)*,* [*CNN*](https://www.cnn.com/2025/02/02/politics/usaid-officials-leave-musk-doge/?ref=metacurity.com)*,* [*New York Times*](https://www.nytimes.com/2025/02/02/upshot/trump-government-websites-missing-pages.html?unlocked%5Farticle%5Fcode=1.uE4.RNor.neHj7lKJhmbR&smid=url-share&ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2025/02/01/senator-warns-of-national-security-risks-after-elon-musks-doge-granted-full-access-to-sensitive-treasury-systems/?ref=metacurity.com)*,* [*Fortune*](https://fortune.com/2025/02/02/musk-doge-treasury-payments-system-halt-us-govenment-contractors-lutheran-charity/?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/digital-assets/2025/02/02/this-needs-to-stop-now-elon-musk-confirms-radical-doge-us-treasury-plan/?ref=metacurity.com)*,* [*Palo Alto Online*](https://www.paloaltoonline.com/palo-alto-schools/2025/02/02/gunn-high-grad-part-of-musks-effort-to-control-federal-spending/?ref=metacurity.com)*,* [*Digby's Hullabaloo*](https://digbysblog.net/2025/02/02/musk-juden/?ref=metacurity.com)*,* [*TweakTown*](https://www.tweaktown.com/news/102969/elon-musk-takes-control-of-government-computer-system-officials-now-locked-out/index.html?ref=metacurity.com)*,* [*Mashable*](https://mashable.com/article/elon-musk-doge-college-student-takeover?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/technology/2025/feb/02/elon-musk-doge-access-federal-payment-system?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2025/02/02/elon-musk-cost-cutting-team-gain-access-sensitive-us-treasury-database/?ref=metacurity.com)*,* [*The Indian Express*](https://indianexpress.com/article/world/usaid-security-leaders-leave-elon-musks-doge-classified-info-9814876/?ref=metacurity.com)*,* [*Feminist Space*](https://feminist-space.tumblr.com/post/774428911671099392?ref=metacurity.com)*,* [*New Republic*](https://newrepublic.com/article/191014/trump-elon-musk-treasury-purge?ref=metacurity.com)*,* [*Gwen Tolios*](https://gwen-tolios.tumblr.com/post/774435914117234688?ref=metacurity.com)*,* [*Associated Press*](https://fortune.com/2025/02/02/elon-musk-doge-usaid-classified-info-security-chiefs-leave/?ref=metacurity.com)*,* [*Hacker News (ycombinator)*](https://news.ycombinator.com/item?id=42914425&ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1igepbo/doge%5Fis%5Fhalting%5Ftreasury%5Fpayments%5Fto%5Fus/?ref=metacurity.com)*,* [*r/politics*](https://www.reddit.com/r/politics/comments/1igd8a3/musk%5Fsays%5Fdoge%5Fis%5Fhalting%5Ftreasury%5Fpayments%5Fto%5Fus/?ref=metacurity.com)*,* [*r/news*](https://www.reddit.com/r/news/comments/1ig4gmd/elon%5Fmusks%5Fdoge%5Fteam%5Fgranted%5Ffull%5Faccess%5Fto/?ref=metacurity.com)*,* [*Fortune*](https://fortune.com/2025/02/02/musk-doge-treasury-payments-system-halt-us-govenment-contractors-lutheran-charity/?ref=metacurity.com)*,* [*r/enoughMuskspam*](https://www.reddit.com/r/EnoughMuskSpam/comments/1igir1r/gavin%5Fkliger%5Fmusk%5Faide%5Fnamed%5Fin%5Fthe%5Fdoge%5Ftakeover/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-1.png) ### Meta said that nearly 100 journalists and other members of civil society using WhatsApp were targeted by spyware owned by Paragon Solutions, an Israeli maker of hacking software. The journalists and other civil society members were alerted of a possible breach of their devices. WhatsApp said it had “high confidence” that the 90 users in question had been targeted and “possibly compromised.” It is not clear who was behind the attack. Like other spyware makers, Paragon’s hacking software is used by government clients, and WhatsApp said it has not been able to identify the clients who ordered the alleged attacks. Experts said the targeting was a “zero-click” attack, meaning targets would not have had to click on malicious links to be infected. Chantilly, VA-based Paragon has recently been scrutinized after Wired magazine reported that it had entered into a $2m contract with the US Immigration and Customs Enforcement’s homeland security investigations division. The division reportedly issued a stop-work order for the contract to verify whether it complied with a Biden administration executive order restricting the federal government's use of spyware. In its first two weeks in office, the Trump administration has revoked dozens of the Biden administration’s executive orders, but the 2023 order, which prohibited the use of spyware that posed a risk to national security, remains in effect. WhatsApp said it had sent Paragon a “cease and desist” letter and was exploring its legal options. It said the alleged attacks had been disrupted in December and that it was not clear how long the targets may have been under threat. ([Stephanie Kirchgaessner / Wired](https://www.theguardian.com/technology/2025/jan/31/whatsapp-israel-spyware?ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/technology/cybersecurity/metas-whatsapp-says-israeli-spyware-company-paragon-targeted-scores-users-2025-01-31/?ref=metacurity.com)*,* [*The Independent*](https://www.the-independent.com/tech/whatsapp-israeli-spyware-paragon-meta-b2689935.html?ref=metacurity.com)*,* [*Middle East Monitor*](https://www.middleeastmonitor.com/20250131-dozens-of-journalists-civil-society-members-targeted-by-israeli-spyware-in-whatsapp-hack/?ref=metacurity.com)*,* [*Palestine Chronicle*](https://www.palestinechronicle.com/zero-click-hack-whatsapp-takes-action-against-israeli-paragon-for-spying-on-users/?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/big-tech/whatsapp-claims-that-100-journalists-and-activists-were-the-targets-of-israeli-made-spyware-171701672.html?ref=metacurity.com)*,* [*Firstpost*](https://www.firstpost.com/world/metas-whatsapp-says-israeli-spyware-firm-paragon-targeted-journalists-civil-society-13858329.html?ref=metacurity.com)*,* [*WION*](https://www.wionews.com/world/whatsapp-says-nearly-100-journalists-and-civil-society-members-targeted-by-israeli-spyware-company-paragon-8679076?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2025/01/31/whatsapp-says-it-disrupted-a-hacking-campaign-targeting-journalists-with-spyware/?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2025-01-31/whatsapp-says-paragon-spyware-used-to-try-hacking-journalists?ref=metacurity.com)*,* [*The Record*](https://therecord.media/whatsapp-paragon-spyware-targeting-users?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/daveywinder/2025/02/01/whatsapp-hack-attack-confirmed-by-meta-what-you-need-to-know/?ref=metacurity.com)*,* [*Wired*](https://www.wired.com/story/hackers-google-gemini-us-cyberattacks/?ref=metacurity.com)*,* [*Syrian Arab News Agency*](https://sana.sy/en/?p=345801&ref=metacurity.com)*,* [*Hackread*](https://hackread.com/israeli-spyware-firm-paragon-whatsapp-zero-click-attack/?ref=metacurity.com)*,* [*Techreport*](https://techreport.com/news/whatsapp-says-paragon-solutions-targeted-journalists/?ref=metacurity.com)*,* [*Türkiye Today*](https://www.turkiyetoday.com/business/whatsapp-claims-israeli-spyware-targeted-90-journalists-113616/?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/zero-click-spyware-attack-whatsapp/?ref=metacurity.com)*,* [*Business Standard*](https://www.business-standard.com/technology/tech-news/cybersecurity-whatsapp-paragon-spyware-hacking-attack-125020100378%5F1.html?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/whatsapp-says-it-has-disrupted-an-israel-based-hacking-campaign-targeting-journalists/?ref=metacurity.com)*,* [*The Nation*](https://www.nation.com.pk/01-Feb-2025/data-breaches?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/technology/2025/jan/31/italian-journalist-whatsapp-israeli-spyware?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/spyware-vendor-allegedly-targeted-90-whatsapp-users-with-zero-click-attack?ref=metacurity.com)*,* [*Al Jazeera*](https://www.aljazeera.com/news/2025/1/31/whatsapp-says-its-users-targeted-by-israeli-spyware-company-paragon?ref=metacurity.com)*,* [*Anadolu Ajansı*](https://www.aa.com.tr/en/americas/dozens-of-journalists-civil-society-members-targeted-by-israeli-spyware-in-whatsapp-hack/3468201?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/big-tech/whatsapp-claims-that-100-journalists-and-activists-were-the-targets-of-israeli-made-spyware-171701672.html?ref=metacurity.com)*,* [*Shafaq News*](https://shafaq.com/en/World/WhatsApp-calls-on-Israel-to-stop-spying-on-journalists?ref=metacurity.com)*,* [*Moneycontrol*](https://www.moneycontrol.com/technology/whatsapp-says-paragon-spyware-used-to-try-hacking-journalists-article-12926051.html?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/news/604100/whatsapp-meta-spyware-paragon-solutions?ref=metacurity.com)*,* [*Irish Independent*](https://www.independent.ie/world-news/whatsapp-says-israeli-spyware-company-paragon-targeted-journalists-and-civilians-through-messaging-app/a1544198617.html?ref=metacurity.com)*,* [*Reuters*](https://economictimes.indiatimes.com/tech/technology/metas-whatsapp-says-israeli-spyware-company-paragon-targeted-scores-of-users/articleshow/117794481.cms?ref=metacurity.com)*,* [*r/cybersecurit*](https://www.reddit.com/r/cybersecurity/comments/1iejnk1/whatsapp%5Fsays%5Fjournalists%5Fand%5Fcivil%5Fsociety/?ref=metacurity.com)*,* [*r/worldnews*](https://www.reddit.com/r/worldnews/comments/1iei3a2/metas%5Fwhatsapp%5Fsays%5Fisraeli%5Fspyware%5Fcompany/?ref=metacurity.com)*,* [*r/InternationalNews*](https://www.reddit.com/r/InternationalNews/comments/1iehjxs/whatsapp%5Fsays%5Fjournalists%5Fand%5Fcivil%5Fsociety/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1ieg164/whatsapp%5Fsays%5Fjournalists%5Fand%5Fcivil%5Fsociety/?ref=metacurity.com)*,* [*Slashdot*](https://yro.slashdot.org/story/25/01/31/1441220/whatsapp-says-journalists-and-civil-society-members-were-targets-of-israeli-spyware?ref=metacurity.com)*,* [*Cyberdaily.au*](https://news.google.com/rss/articles/CBMiugFBVV95cUxNUkYzM3NnMXFQVmtXd1dkNXd2MUZoYVB1ZVBQcTBPMGZFNVc4b1RRYS1pS0kyT056dFJndDZXTWdxZjI1ZXU1NVU5NUlkaTNQRWpRM2RsN0c4c0o4QkQ0eEt2N0U0RmRxaGw4Vi1DQW1FLU45TW0yVm5YUWNIaFVLMktrNGFfb3ZuMmV4M0JNV1hDLXQxOEJQNnhEcXk3RlhqVnBILVBfZnpXdzVqQ0ZZOXEycUYyQkRPUHc?oc=5&mid=1&ref=metacurity.com#cid=2566830)*,* [*Security Affairs*](https://securityaffairs.com/173721/security/whatsapp-disrupted-paragon-spyware-campaign.html?mid=1&ref=metacurity.com#cid=2566050)*,* [*iTnews - Security*](https://www.itnews.com.au/news/whatsapp-says-spyware-company-paragon-targeted-users-614689?utm%5Fsource=feed&utm%5Fmedium=rss&utm%5Fcampaign=iTnews+Security+feed&mid=1#cid=2566615)*,* [*Globes*](https://en.globes.co.il/en/article-1001501020?mid=1&ref=metacurity.com#cid=2566628) ### Texas Governor Gov. Greg Abbott issued a ban on the use of Chinese-backed artificial intelligence and social media apps, including DeepSeek, Lemon8, Moomoo, RedNote, Tiger Brokers, and Webull, on Texas government-issued devices. His proclamation orders the Texas Department of Public Safety and the Department of Information Resources to add the six technologies to the state's prohibited technologies list. The list bans state employees and contractors from downloading and using the apps on personal and state-owned devices. In December 2022, Abbott banned the short-form video social media app TikTok. A few months later, he signed Senate Bill 1893, granting him the authority to ban any social media applications or services that pose potential security risks to Texas, including "successor applications" to TikTok or those developed by its parent company, ByteDance Limited. Abbott's most recent proclamation includes RedNote and Lemon8 as two of these applications. ([Karoline Leonard / Austin-American Statesman](https://www.statesman.com/story/business/technology/2025/01/31/deepseek-rednote-ban-abbott-texas-artificial-intelligence/78093529007/?ref=metacurity.com)) **Related:** [*Associated Press*](https://apnews.com/article/texas-deepseek-apps-ban-3828a4743e9919398dfac0ba9d4a5c25?ref=metacurity.com)*,* [*Office of the Texas Governor*](https://gov.texas.gov/news/post/governor-abbott-announces-ban-on-chinese-ai-social-media-apps?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/texas-governor-bans-deepseek-ai-on-state-issued-devices?ref=metacurity.com)*,* [*KEYE*](https://cbsaustin.com/news/local/gov-abbott-bans-chinese-linked-apps-including-rednote-from-state-devices?ref=metacurity.com)*,* [*KCEN-TV*](https://www.kcentv.com/article/news/local/texas/texas-governor-abbott-bans-the-use-of-chinese-ai-social-media-apps/500-a132bd78-0d71-46f6-857b-1183df83f57f?ref=metacurity.com)*,* [*KWTX-TV*](https://www.kwtx.com/2025/01/31/gov-abbott-bans-chinese-affiliated-ai-social-media-apps-like-rednote-state-devices/?ref=metacurity.com)*,* [*FOX 7 Austin*](https://www.fox7austin.com/news/greg-abbott-bans-rednote-deepseek-texas?ref=metacurity.com) ### Security researchers from Cisco and the University of Pennsylvania are publishing findings showing that, when tested with 50 malicious prompts designed to elicit toxic content, DeepSeek’s R1 AI model did not detect or block a single one. The researchers say they were shocked to achieve a “100 percent attack success rate.” The Cisco researchers drew 50 randomly selected prompts to test DeepSeek’s R1 from HarmBench, a well-known library of standardized evaluation prompts. They tested prompts from six HarmBench categories: general harm, cybercrime, misinformation, and illegal activities. They probed the model running locally on machines rather than through DeepSeek’s website or app, which sends data to China. Beyond this, the researchers say they have also seen potentially concerning results from testing R1 with more involved, non-linguistic attacks that use Cyrillic characters and tailored scripts to achieve code execution. But for their initial tests, Sampath says his team wanted to focus on findings that stemmed from a generally recognized benchmark. The findings are part of growing evidence that DeepSeek’s safety and security measures may not match those of other tech companies developing LLMs. DeepSeek’s censorship of subjects deemed sensitive by China’s government has also been easily bypassed. ([Lily Hay Newman and Matt Burgess / Wired](https://www.wired.com/story/deepseeks-ai-jailbreak-prompt-injection-attacks/?ref=metacurity.com)) **Related*:* [*Cisco*](https://blogs.cisco.com/security/evaluating-security-risk-in-deepseek-and-other-frontier-reasoning-models?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/deepseek-fails-every-safety-test-thrown-at-it-by-researchers?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/alexvakulov/2025/02/01/more-chatgpt-jailbreaks-are-evading-safeguards-on-sensitive-topics/?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/application-security/deepseek-jailbreak-system-prompt?ref=metacurity.com)*,* [*Unit 42*](https://unit42.paloaltonetworks.com/jailbreaking-deepseek-three-techniques/?ref=metacurity.com)*,* [*Wallarm*](https://lab.wallarm.com/jailbreaking-generative-ai/?ref=metacurity.com)*,* [*Futurism*](https://futurism.com/deepseek-failed-every-security-test?ref=metacurity.com)*,* [*PaymentSecurity.io*](https://www.paymentsecurity.io/deepseek-ai-models-vulnerable-to-jailbreaking-a-27428?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2025/01/31/deepseeks-ai-security-under-fire-100-jailbreak-success-exposes-critical-flaws-xcxwbn/?ref=metacurity.com)*,* [*ZDNET*](https://www.zdnet.com/article/deepseeks-ai-model-proves-easy-to-jailbreak-and-worse/?ref=metacurity.com)*,* [*Wired*](https://www.wired.com/story/deepseek-censorship/?ref=metacurity.com)*,*[ *r/technews*](https://www.reddit.com/r/technews/comments/1ielwlt/deepseeks%5Fsafety%5Fguardrails%5Ffailed%5Fevery%5Ftest/?ref=metacurity.com)*,* [*Enkrypt AI*](https://www.enkryptai.com/blog/deepseek-r1-ai-model-11x-more-likely-to-generate-harmful-content-security-research-finds?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-2.png) Source: Cisco. ### Aurangzeb Ayub, Shane Ngakuru, Seyyed Hossein Hosseini, and Alexander Dmintrienko pleaded guilty this month in San Diego to selling Anom devices, the encrypted phone secretly backdoored by the FBI that led to the largest sting operation in history. The defendants were set to go to trial, and the government was preparing to reveal the real identity of the confidential human source who had provided the FBI with the Anom company. The court records released as part of the plea deals also provide new insight into how some of the phone sellers discussed drug trafficking on their Anom devices as well. Anom became a popular tool for serious criminals in Australia, Europe, South America, and South East Asia. Customers used the phones to coordinate massive, multi-ton shipments of drugs. In June 2021, authorities launched a global relay race of raids, with more than nine thousand law enforcement officials acting across a single day. ([Joseph Cox / 404 Media](https://www.404media.co/sellers-of-anom-the-fbis-secret-backdoored-phone-plead-guilty/?ref=metacurity.com)) ***Related:*** [*Mobile ID World*](https://mobileidworld.com/anom-encrypted-phone-sellers-plead-guilty-in-fbi-sting-operation/?ref=metacurity.com) ### Researchers at Kaspersky report that cybercriminals are using fake wedding invitations targeting users in Malaysia and Brunei to distribute a newly discovered Android malware called Tria. Since mid-2024, the attackers have been spreading the malware through private and group chats on Telegram and WhatsApp, inviting users to weddings and prompting them to install a mobile app to receive the invitation. The researchers warn that the stolen information could be used to access online banking, reset passwords, or hijack accounts that rely on email and messaging app authentication. The attackers' primary goal appears to be gaining complete control of victims’ WhatsApp and Telegram accounts, allowing them to spread malware further or send fraudulent money requests to contacts. ([Daryna Antoniuk / The Record](https://therecord.media/hackers-wedding-invitations-southeast-asia?ref=metacurity.com)) **Related:** [*Kapsersky*](https://securelist.ru/tria-stealer-collects-sms-data-from-android-devices/111558/?ref=metacurity.com)*,* [*htxt*](https://htxt.co.za/2025/02/whatsapp-wedding-invite-could-hide-a-nasty-surprise/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/02/image-3.png) **Delivery of a stealer via a hacked WhatsApp (left) and Telegram (right) account*. Source: Kaspersky. ### India has eased restrictions on its Aadhaar authentication service, a digital identity verification framework linked to the biometrics of over 1.4 billion people, to let businesses, including those offering services such as e-commerce, travel, hospitality, and healthcare, use the verification system to authenticate their customers. The update has raised privacy concerns as New Delhi has yet to define the guardrails it would consider to avoid misuse of individuals’ biometric IDs. ([Jagmeet Singh / TechCrunch](https://techcrunch.com/2025/02/02/india-expands-aadhaar-authentication-for-businesses-raising-privacy-concerns/?ref=metacurity.com)) **Related:** [*pib.gov.in*](https://pib.gov.in/PressReleasePage.aspx?PRID=2098223&ref=metacurity.com)*,* [*Scroll.in*](https://scroll.in/latest/1078654/it-ministry-notifies-rules-allowing-private-entities-to-carry-out-aadhaar-authentication?ref=metacurity.com)*,* [*Inc42 Media*](https://inc42.com/buzz/aadhar-authentication-extended-to-private-sector-entities/?ref=metacurity.com)*.* ### Australian privacy commissioner Karly Kind recently awarded $10,000 in compensation to a complainant whose healthcare records became “intertwined” with those of a person, a doppelganger who shared the same name and date of birth. “Intertwinement primarily occurs when staff incorrectly add personal information to the wrong account, or a third-party provider submits a claim for the wrong customer,” she wrote. Kind suggested that hundreds of Australians share the same name and date of birth and that when their government records become intertwined, they “may suffer not only inconvenience but real harm.” She mentioned the possibility of health practitioners being denied access to accurate records and difficulties accessing “financial aspects of health and government services.” “Although only a small subset of Australians may be affected, the potential harm is significant,” she wrote. For one such person, identified as “ATQ” in a complaint about intertwined data, their medical records included info about three people who shared their name and birthday after four mistakes by government workers. ([Simon Sharwood / The Register](https://www.theregister.com/2025/02/03/australia%5Fdigital%5Fdoppelgangers%5Fprivacy%5Faward/?utm%5Fsource=dlvr.it&utm%5Fmedium=bluesky)) **Related:** [*Australian Information Commissioner*](https://www6.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2025/19.html?ref=metacurity.com)*,* [*Carly Kind on LinkedIn*](https://www.linkedin.com/pulse/beware-digital-doppelganger-carly-kind-thnie/?ref=metacurity.com) ### In their new book "Get In," Patrick Maguire and Gabriel Pogrund report that in his rise to power, labor leader Keir Starmer was forced to abandon his personal email account after the security services investigated a ­suspected Russian hack. In 2022, Jill Cuthbertson, his head of office, circulated a note without explanation instructing staff not to email Starmer under any circumstances. Starmer subsequently changed his email address, which a source said had been “dangerously obvious,” and added two-factor authentication, a fail-safe under which users can access an ­account only after passing two security checks. ([Patrick Maguire and Gabriel Pogrund / The Times](https://www.thetimes.com/uk/politics/article/russians-suspected-of-compromising-keir-starmers-personal-email-gtkj53dps?ref=metacurity.com)) ***Related:*** [*The Telegraph*](https://www.telegraph.co.uk/politics/2025/02/03/russia-hacked-starmers-dangerously-obvious-email-account/?ref=metacurity.com)*,* [*Daily Mail*](https://www.dailymail.co.uk/news/article-14353461/Keir-Starmer-email-hacked-Russians.html?ref=metacurity.com)*,* [*The Sun*](https://www.thesun.co.uk/news/33156671/sir-keir-starmer-personal-email-russian-hack/?ref=metacurity.com) ### Seraphic Security, an Israeli startup competing in the enterprise browser space, announced it had raised $29 million in a Series A venture funding round. GreatPoint Ventures led the round, with CrowdStrike Falcon Fund, Planven, Cota Capital, and Storm Ventures also participating. ([Ryan Naraine / Security Week](https://www.securityweek.com/seraphic-attracts-29m-investment-to-chase-enterprise-browser-business/?ref=metacurity.com)) ***Related:*** [*FinTech Global*](https://fintech.global/2025/01/31/seraphic-security-clinches-29m-series-a-for-cutting-edge-browser-defense/?ref=metacurity.com)*,* [*Seraphic Cyber Security*](https://seraphicsecurity.com/resources/blog/the-story-behind-seraphics-29-million-dollar-series-a/?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2025/01/seraphic-security-raises-29m-in-series-a-funding.html?ref=metacurity.com) ### Invary, a pioneer in runtime integrity solutions, announced it had raised $3.5 million in a venture funding seed round. SineWave Ventures, Flyover Capital, Hyperlink Ventures, and KCRise Fund participated in the round. ([Invary](https://www.invary.com/?ref=metacurity.com)) ### Frenos, a startup that has developed an autonomous operational technology (OT) security assessment platform, announced it had raised $3.88 million in a venture funding seed round. DataTribe led the round. ([Eduard Kovacs / Security Week](https://www.securityweek.com/frenos-raises-3-88m-in-seed-funding-for-ot-security-assessment-platform/?ref=metacurity.com)) ***Related:*** [*Pulse 2.0*](https://pulse2.com/frenos-autonomous-operational-security-assessment-platform-raises-3-88-million-seed/?ref=metacurity.com)*,* [*Business Wire*](https://www.businesswire.com/news/home/20250128761921/en/Frenos-Closes-3.88-Million-Seed-Financing-Round-Led-by-DataTribe-to-Transform-Proactive-Defense-in-Critical-Infrastructure-Environments?ref=metacurity.com)*,* [*The Business Journals*](https://www.bizjournals.com/charlotte/inno/stories/fundings/2025/01/30/cybersecurity-startup-frenos-raises-seed-funding.html?ref=metacurity.com)*,* [*The Paypers*](https://thepaypers.com/digital-identity-security-online-fraud/frenos-raises-usd-388-million-in-seed-funding--1272044?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2025/01/frenos-raises-3-88m-in-seed-financing.html?ref=metacurity.com) ### Best Thing of the Day: A Bright Spot in a Dismal Situation Cybersecurity and Infrastructure Security Agency (CISA) employees [were told](https://therecord.media/cisa-employees-told-they-are-exempt-deferred-resignation?ref=metacurity.com) they are not eligible for the federal government-wide deferred resignation program being pushed by Elon Musk via the US Office of Personnel Management. ### Bonus Best Thing of the Day: Please, No AI at Anthropic AI company Anthropic is [telling its job applicants](https://simonwillison.net/2025/Feb/2/anthropic/?ref=metacurity.com) not to use AI when filling out applications. ### Worst Thing of the Day: Please, No Politics Over Here at r/cybersecurity Over at r/cybersecurity, the mods want to[ ban discussion of politics](https://www.reddit.com/r/cybersecurity/comments/1igfsvh/keeping%5Frcybersecurity%5Ffocused%5Fcybersecurity/?ref=metacurity.com) because cybersecurity is a pure technology discipline that rises above the fray of dictators and autocrats attempting to seize control over and jeopardize the security of critical infrastructure. ### Closing Thought ### Best Infosec-Related Long Reads for the Week of 1/25/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-18-25-2/ Last updated: 2025-02-01T13:16:09.000Z The 23-year-old who infiltrated a DPRK laptop farm, Top tech companies who back the biggest deepfake porn site, How the H-1B debate impacts cyber hiring, Tech giants decide the supply of secure military digital infrastructure, Data brokers who sell pregnancy data, How CISO factories are formed _This post is for subscribers only._ ### Authorities bust up phishing kit peddler HeartSender URL: https://www.metacurity.com/authorities-bust-up-phishing-kit-peddler-heartsender/ Last updated: 2025-01-31T14:07:56.000Z Companies and governments restrict DeepSeek access, CISA warns of patient monitoring device malicious backdoor, NYC blood center hit by ransomware, ChatGPT jailbreak flaw allows weapons and malware creation instructions, Criminal gangs still funnel services through US cloud providers, much more _This post is for paying subscribers only._ ### Google’s full-court press on GenAI’s misuse in creating cyber threats URL: https://www.metacurity.com/googles-full-court-press-on-genais-misuse-in-creating-cyber-threats/ Last updated: 2025-01-30T15:44:17.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/mannequin-915135_1280-1.jpg) Image by [Gerd Altmann](https://pixabay.com/users/geralt-9301/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=915135) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=915135) *Don't miss* [*my latest CSO piece*](https://www.csoonline.com/article/3810545/american-cisos-should-prepare-now-for-the-coming-connected-vehicle-tech-bans.html?ref=metacurity.com)*, which explains why US CISOs should prepare now for the* upcoming bans on *connected car technology.* --- *On Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers) - Cloud security firm Wiz reports that the meteorically hot AI model DeepSeek left one of its critical databases exposed on the internet, leaking system logs, user prompt submissions, and even users’ API authentication tokens, totaling more than one million records to anyone who came across the database. - The FBI seized the domains for the infamous Cracked.io and Nulled.to hacking forums, which are known for their focus on cybercrime, password theft, cracking, and credential stuffing attacks. - A lawsuit by two federal employees alleges that the Trump administration has set up an email distribution system for the entire federal workforce that raises security concerns for workers’ private data. - Researchers at Akamai's Security Intelligence and Response Team (SIRT) have observed a new variant of the Mirai-based botnet malware Aquabot called Aquabotv3 actively exploiting CVE-2024-41710, a command injection vulnerability in Mitel SIP phones. - DogWifTools, a token bundling tool commonly used for malicious memecoin launches, was exploited and drained more than $10 million from its users. - Researchers at Bitdefender warned of an ongoing cyber espionage campaign orchestrated by the UAC-0063 group, believed to be linked with Russia, with confirmed attacks in Romania. - Simon Wijckmans, the founder and CEO of web security company c/side, said his firm discovered that hackers are altering thousands of websites using outdated versions of WordPress and plug-ins to trick visitors into downloading and installing malware. - According to researchers at Security Scorecard, in an operation it calls Phantom Circuit, North Korea's Lazarus Group compromised hundreds of victims across the globe in a massive secret-stealing supply chain attack that was ongoing as of earlier this month. - Authorities are investigating a cyber “incident” at the University of Notre Dame in Australia. - Google says it's now hardening defenses against a sophisticated account takeover scam documented by Zach Latta, founder of Hack Club. - The UK National Cyber Security Centre (NCSC) argued for simplifying the classification of security flaws and eliminating many currently used vulnerability scoring systems. The NCSC proposed eliminating the current CVSS scoring system and implementing two significant classes of flaws: forgivable and unforgivable. - According to press reports, authorities in Turkey arrested five people on cyber espionage charges through a software system uncovered thanks to information from the National Intelligence Organization (MIT). - Cybersecurity giant Tenable is acquiring Israeli cybersecurity company Vulcan Cyber for $150 million. - Dark web intelligence specialist Searchlight Cyber has strengthened its security offerings by acquiring Brisbane-based attack surface management (ASM) company Assetnote. --- ## Google’s full-court press on GenAI’s misuse in creating cyber threats In what have become typical jam-packed news days, it might have been easy to miss yesterday that security and tech giant Google launched a full-court press to deliver its comprehensive views on the cyber dangers lurking in generative AI and how adversaries can seize upon them to damage US national security. The company issued four posts covering the topic and reached out to even less prominent cybersecurity journalists to inform them of this robust PR effort. While most of these posts delve into how bad guys can make and deploy cutting-edge cyber threat tools using genAI, [in one of them,](https://blog.google/technology/safety-security/ai-and-the-future-of-national-security/?ref=metacurity.com) Kent Walker, president of global affairs at Google and Alphabet, concludes that despite these fears, “the defenders are still ahead – for now,” because threat actors have yet to use AI to develop novel capabilities. However, Walker cautioned that it won’t stay that way unless the US secures “the digital high ground.” Walker highlights three national security imperatives to capture that high ground and maintain the current defender advantage, particularly as many malicious actors can leverage powerful new AI models. Among Walker’s imperatives are private-sector leadership in AI chips and infrastructure, public-sector leadership in technology procurement and deployment, and heightened public-private collaboration on cyber defense. _This post is for paying subscribers only._ ### China, Iran, Russia, and North Korea use Google's Gemini for better cyberattacks URL: https://www.metacurity.com/china-iran-russia-and-north-korea-use-googles-gemini-for-better-cyberattacks/ Last updated: 2025-01-29T14:33:02.000Z Engineering giant Smiths hit by a cyberattack, Engineering firm ENGlobal says sensitive info stolen during Nov. attack, Oz creates health ISAC, UK audit office says gov't faces devastating cyberattack threats, Apple processors' side-channel flaws could allow sensitive info threat, much more _This post is for paying subscribers only._ ### Policymakers are silent so far on DeepSeek's security threats URL: https://www.metacurity.com/policymakers-are-silent-so-far-on-deepseeks-security-threats-2/ Last updated: 2025-01-28T14:16:11.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/deepseekunderattack-2.png) Source: [@manjusrii.bsky.social](https://bsky.app/profile/manjusrii.bsky.social?ref=metacurity.com)· **Important notice*: If anyone who is a federal government worker or adjacent to the federal government, such as a contractor, has vital information to share with me, please feel free to contact me on Signal under my name, Cynthia Brumfield.* --- *On Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers). - Viral Chinese AI app DeepSeek stopped working yesterday due to what appeared to be a technical issue, although a banner on the app’s web chat also said that DeepSeek’s “online services have faced large-scale malicious attacks" from unspecified sources. - Donald Trump said that Microsoft is in talks to acquire the US arm of ByteDance Ltd.’s TikTok without offering any details. - The European Union sanctioned three hackers, GRU officers Nikolay Korchagin, Vitaly Shevchenko, and Yuriy Denisov, who were part of Unit 29155 of Russia's military intelligence service (GRU), for their involvement in cyberattacks targeting Estonia's government agencies in 2020. - Three men, Callum Picari from Hornchurch, Vijayasidhurshan Vijayanathan from Aylesbury, and Aza Siddeeque from Milton Keynes, were sentenced in a London court after pleading guilty to operating a sophisticated scheme that helped fraudsters log into victims’ bank and telecoms accounts. - Ukraine has denied allegations of involvement in a cyberattack on Slovakia's national insurance company following accusations by Slovak Prime Minister Robert Fico. - Scammers based in West Africa, likely in Nigeria, who go under the broad umbrella of the Yahoo Boys, have increasingly been seen sending blackmail victims videos, likely using AI-generated news anchors in a bid to pressure victims into paying up. - Apple has released security updates to fix this year's first zero-day vulnerability, tagged as actively exploited in attacks targeting iPhone users. - Japanese researcher RyotaK of GMO Flatt Security discovered that three distinct but related attacks, dubbed 'Clone2Leak,' can leak credentials by exploiting how Git and its credential helpers handle authentication requests. - Researchers at Cisco Talos revealed a surge in the use of so-called “hidden text salting” techniques to evade email security measures in the latter half of 2024. - Brazil’s data protection watchdog, the National Data Protection Authority (ANPD), has ordered the company behind the biometrics for the World ID project to stop offering crypto or financial compensation for collecting biometric data from its citizens. - A cyberattack on the Matagorda County government, which serves about 40,000 residents in Texas, forced officials to declare a disaster over the weekend. - Researchers at Zimperium report that a new phishing scam targeting mobile devices was observed using a “never-before-seen” obfuscation method to hide links to spoofed United States Postal Service (USPS) pages inside PDF files. - Non-human identity security company Token Security raised $20M in Series A venture funding round. --- # Policymakers are silent so far on DeepSeek's security threats A tech earthquake in the form of an important new AI model from China called DeepSeek [radically altered](https://www.404media.co/deepseek-mania-shakes-ai-industry-to-its-core/?ref=metacurity.com) and possibly [leveled the landscape](https://www.wsj.com/finance/stocks/deepseek-is-upending-wall-streets-big-ai-power-trade-0e649925?mod=panda%5Fwsj%5Fauthor%5Falert&ref=metacurity.com) for Silicon Valley titans who have spent hundreds of billions of dollars developing pricey chips and LLM-based systems to usher in the AI revolution. News that previously little-known DeepSeek, owned and solely funded by an obscure Chinese hedge fund called High-Flyers, spent only $5.6 million on its latest AI model, called R1, which nonetheless has been favorably compared to exorbitantly expensive OpenAI and other leading AI models, sent shockwaves through the financial markets, which continue today. Shares of AI chip leader Nvidia [fell](https://www.reuters.com/technology/tech-stock-selloff-deepens-deepseek-triggers-ai-rethink-2025-01-28/?ref=metacurity.com) 17% yesterday, costing the company $593 billion in market value and causing a rout across all financial exchanges. Although Nvidia [pretended](https://www.bloomberg.com/news/articles/2025-01-28/sam-altman-praises-deepseek-r1-and-promises-more-from-openai?ref=metacurity.com) that DeepSeek is a welcome competitor and Donald Trump [said](https://www.nbcnews.com/tech/innovation/trump-china-deepseek-ai-wake-call-rcna189526?ref=metacurity.com) that the entrance of the low-cost competitor is "very much a positive development," there is no question that DeepSeek, like TikTok, will become yet another Chinese tech giant deeply embedded in applications that Americans rely on, sucking up vast amounts of data that are likely to be even more highly sensitive than the mounds of information collected by the about-to-be-banned but still-functioning Chinese-owned video service. The absence of calls to ban DeepSeek or otherwise limit its use among Americans was notable yesterday despite the prevalence of China hawks throughout the administration. This silence also contradicts Trump's previous warnings that Chinese technology poses a national security threat. However, some right-wing or libertarian thinkers aligned with the administration's economic agenda have begun beating the drum to do something about DeepSeek. "With many referring to this as a modern 'Sputnik moment' for the nation, the success of DeepSeek's important new AI model will hopefully wake more policymakers up to the fact that China really does represent a formidable threat to America's geopolitical competitiveness and security." Adam Thierer, Senior Research Fellow at the R Street Institute, told Metacurity. "DeepSeek proves that we're not going to stop China from pushing ahead on AI and advanced computation. The question for our nation now becomes how effectively we can continue to push out our own technological frontier with new and better systems to keep us ahead." _This post is for paying subscribers only._ ### Update: Change Healthcare attack compromised the data of 200 million Americans URL: https://www.metacurity.com/change-healthcare-attack-compromised-the-data-of-200-million-americans-new-update-says-2/ Last updated: 2025-01-27T14:49:27.000Z State Dept. aid halt threatens cyber diplomacy bureau, TalkTalk probes reported data breach, PCLOB firings jeopardize transatlantic data privacy pact, Tbilisi transport ticket machines hacked, Israeli panic button company hacked, Another undersea cable damaged, DeepSeek AI is a meteor, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 1/18/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-18-25/ Last updated: 2025-01-25T13:45:23.000Z Jen Easterly's parting thoughts, A satellite built for Cold War paranoia, How tech giants condition us to give up privacy, Our AI future won't be a privacy disaster, How Portland built tech privacy protections _This post is for subscribers only._ ### Hackable bugs can remotely control connected cars and track their movements URL: https://www.metacurity.com/hackable-bugs-can-remotely-control-connected-cars-and-track-their-movements/ Last updated: 2025-01-24T14:09:22.000Z FBI warns of DPRK IT workers while DoJ indicts DPRK nationals for IT work scheme, Countries sign pact to root out SE Asian cybercrime, Trump issues new AI EO, 1K faux Reddit and WeTransfer pages download Lumma Stealer, Malicious AI chatbot emerges, DPRK hackers stole $70m from Phemex, much more _This post is for paying subscribers only._ ### House panel probed CISA's still-shaky footing, CSRB sackings URL: https://www.metacurity.com/house-panel-probed-cisas-still-shaky-footing-csrb-sackings/ Last updated: 2025-01-23T14:43:40.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/househomelandhearing12325-1.png) --- *As a reminder, on Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers). - The Trump White House is moving to paralyze the Privacy and Civil Liberties Oversight Board, a bipartisan and independent watchdog agency that investigates national security activities that can intrude upon individual rights. - National security adviser Michael Waltz has authorized a “full review” of the Trump loyalty of dozens of National Security Council career officials who staff the White House on issues including Iranian and North Korean nuclear proliferation, cyber espionage, and Russia’s war in Ukraine. - One of Donald Trump's first-day executive orders, “Establishing and Implementing the President’s Department of Government Efficiency," or DOGE, made the unit officially part of the US government, embedding it in an existing agency that was formerly part of the Office of Management and Budget called the United States Digital Service, which will now be known as US Doge Service. - The lawyer for Israeli private investigator Amit Forlit said for the first time publicly that her client is being prosecuted over allegations that an Exxon Mobil lobbyist hired him to hack emails of environmental activists. - Conor Fitzpatrick, also known as Pompompurin, the founder and administrator of the cybercrime platform BreachForums, will be resentenced after a three-judge panel vacated a controversial district court decision that set him free after just 17 days in prison. - Payment card giant MasterCard fixed a glaring error in its domain name server settings that could have allowed anyone to intercept or divert Internet traffic for the company by registering an unused domain name. - The hacker who breached education tech giant PowerSchool claimed in an extortion demand that they stole the personal data of 62.4 million students and 9.5 million teachers. - An investigation by the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD) concluded that the Hong Kong branch of the international charity Oxfam failed to implement adequate measures to protect its information systems, leading to the leak of personal information belonging to 550,000 individuals last July. - Microsoft's LinkedIn has been sued by Premium customers who said the business-focused social media platform disclosed their private messages to third parties without permission to train generative artificial intelligence models. - Oracle announced the release of 318 new security patches as part of its January 2025 Critical Patch Update (CPU), including over 180 fixes for vulnerabilities that can be exploited remotely without authentication. - The Nasdaq’s official X account was compromised when hackers used it to promote a fraudulent memecoin. - A deal signed last week between Iran and Russia includes commitments to deepen the countries’ military, security, and technological ties, specifically addressing cooperation in cybersecurity and internet regulation. - A joint CISA/FBI advisory released technical details of at least two elaborate exploit chains used by Chinese professional hackers to break into Ivanti Cloud Service Appliances (CSA). - Researchers at ESET report that PlushDaemon, a previously undocumented advanced persistent threat (APT) group, conducted a cyber espionage operation targeting South Korean VPN software in 2023. - A new survey by Hiscox reveals that only 18% of businesses have successfully recovered all of their data after paying their ransomware attackers. - Benjamin Flesch, a security researcher in Germany, reports that OpenAI's ChatGPT crawler appears willing to initiate distributed denial of service (DDoS) attacks on arbitrary websites, a reported vulnerability the tech giant has yet to acknowledge. - Saudi Arabian digital security firm Elm Company said it had agreed to acquire business services firm Thiqah from the kingdom's Public Investment Fund (PIF) in a deal valued at 3.4 billion riyals ($906 million). --- ## House panel probed CISA's still-shaky footing, CSRB sackings One of the most startling recommendations in the [Project 2025 report](https://www.csoonline.com/article/3477366/project-2025-could-escalate-us-cybersecurity-risks-endanger-more-americans.html?ref=metacurity.com) prepared for the Trump administration was to dismantle the Cybersecurity and Infrastructure Security Agency (CISA) and place whatever was left inside the Department of Transportation, a prospect that has [seemingly diminished](https://www.csoonline.com/article/3610683/cybersecurity-policy-and-practice-likely-to-remain-little-changed-after-trump-takes-the-reins.html?ref=metacurity.com) since election day. But last week, Kristi Noem, Trump's nominee for secretary of the Department of Homeland Security (DHS), which houses CISA, [again raised](https://www.meritalk.com/articles/dhs-nominee-plans-to-refocus-cisa-mission/?ref=metacurity.com) the notion that CISA needs to shrink and that its mission should be refocused. Based on a long-held GOP complaint, Noem justified her position by saying that CISA's relatively minor forays into tracking online misinformation violated the agency's remit. "They're using their resources in ways that \[were\] never intended. The misinformation and disinformation that they have stuck their toe into and meddled with should be refocused back onto what their job is," Noem said. "\[CISA\] needs to be much more effective, smaller, more nimble to really fulfill their mission." News broke after Noem testified that the Cyber Safety Review Board [had lost or had been stripped of](https://www.nextgov.com/cybersecurity/2025/01/dhs-cyber-review-board-cleaned-out-trump-move-eliminate-misuse-resources/402386/?ref=metacurity.com) its private sector members, who were preparing a report on the Chinese threat group Salt Typhoon's intrusions into US telco networks. Not surprisingly, both of these developments were aired during [the first hearing](https://homeland.house.gov/hearing/unconstrained-actors-assessing-global-cyber-threats-to-the-homeland/?ref=metacurity.com) of the new Congress held by the House Homeland Security Committee yesterday, which focused on global cyber threats to the homeland. In kicking off the hearing, Committee chair Mark Green (R-TN) stressed the importance of cybersecurity to the nation's safety. "We have lots of work to do to support and secure the homeland, and that is why cybersecurity is our top priority. It is why the topic of our first full committee hearing is cybersecurity." _This post is for paying subscribers only._ ### Trump Kicks Members Off of the Cyber Safety Review Board, Salt Typhoon Probe Jeopardized URL: https://www.metacurity.com/trump-kicks-members-off-csrb-jeopardizing-salt-typhoon-probe/ Last updated: 2025-01-23T10:26:44.000Z Trump pardoned Ulbricht, Cloudflare stopped largest DDoS attack, New Mirai botnet targets AVTECH cameras & Huawei routers, Teen found Cloudflare flaw exposing chat app users locales, Gov't contractor Conduent hit by cyberattack, Ransomware attacks use vishing via Office 365, much more _This post is for paying subscribers only._ ### Trump’s First-Term Cyber Actions Could Presage Solid Policy Activity Ahead URL: https://www.metacurity.com/trumps-first-term-cyber-actions-could-presage-solid-policy-activity-ahead/ Last updated: 2025-01-21T13:43:22.000Z ![white concrete building](https://images.unsplash.com/photo-1570492903043-3d30df7133d5?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDF8fG92YWwlMjBvZmZpY2V8ZW58MHx8fHwxNzM3NDY0OTEzfDA&ixlib=rb-4.0.3&q=80&w=2000) Photo by [Suzy Brooks](https://unsplash.com/@simplysuzy?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) --- *As a reminder, on Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers) - The US Treasury Department imposed sanctions on alleged hacker Yin Kecheng and cybersecurity company Sichuan Juxinhe Network Technology Co., accusing both of being involved in a series of hacks by the Chinese threat group Salt Typhoon against American telecom companies. - Donald Trump revoked a 2023 executive order signed by Joe Biden that sought to reduce the risks that artificial intelligence poses to consumers, workers, and national security. - South Dakota Governor Kristi Noem harshly criticized the nation’s leading cybersecurity agency, the Cybersecurity and Infrastructure Security Agency (CISA), during her Secretary of Homeland Security confirmation hearing. - The US Federal Trade Commission issued a report finding that businesses charge customers more for products based on insights gleaned from their consumer data and behaviors, including geolocation, demographics, shopping habits, or even how an individual moves their mouse on a webpage. - The personal information of Ontario, Canada, students from as far back as 60 years was breached in a recent cyberattack on school software provider PowerSchool that affected millions across many boards in the province and, in some cases, included their medical information and even disciplinary records. - Hewlett Packard Enterprise (HPE) is investigating claims of a new breach after the IntelBroker threat actor said they stole documents from the company's developer environments. - The UAE Cyber Security Council announced that the national cybersecurity systems successfully thwarted malicious ransomware attacks targeting several strategic sectors in both public and private entities. - In a posting to the Federal Register, the US Transportation Security Administration said it is locking in a pair of pipeline directives for additional years. - Researchers at ESET report that a new UEFI Secure Boot bypass vulnerability tracked as CVE-2024-7344 that affects a Microsoft-signed application could be exploited to deploy bootkits even if Secure Boot protection is active. - Hotel management platform Otelier suffered a data breach after threat actors breached its Amazon S3 cloud storage to steal millions of guests' personal information and reservations for well-known hotel brands like Marriott, Hilton, and Hyatt. - Nigerian authorities dismantled a fake hotel review syndicate and arrested four Chinese nationals and 101 Nigerians for their roles in the elaborate internet fraud scheme. - Security firm ScamSniffer said that crypto scammers have seriously pivoted to Telegram malware scams, which have surpassed traditional phishing in volume, increasing by 2,000% since November. - Google says it has begun requiring users to turn on JavaScript, the widely used programming language to make web pages interactive, to use Google Search. --- ### Trump’s First-Term Cyber Actions Could Presage Solid Policy Activity Ahead Although it has been lost in the noise surrounding TikTok’s recent brief shutdown and Donald Trump’s [executive order](https://www.washingtonpost.com/technology/2025/01/20/tiktok-trump-executive-order/?ref=metacurity.com) to delay enforcement of the divest-or-ban legislation that might permanently shutter the video service, it was Trump himself who kicked off the controversy with an [executive order](https://nsarchive.gwu.edu/sites/default/files/pdf/2020-17699-13942.pdf?ref=metacurity.com) (EO) on August 11, 2020. That order, officially entitled “Addressing the Threat Posed by TikTok, and Taking Additional Steps To Address the National Emergency With Respect to the Information and Communications Technology and Services Supply Chain,” was one of many high-profile cybersecurity-related executive actions Trump undertook during his first White House term. It concluded that “action must be taken to address the threat posed by one mobile application in particular, TikTok,” and bucked any follow-on action to the Commerce Secretary. Even before the order, the Trump administration had banned TikTok on military phones and phones used by the Departments of Homeland Security and Transportation. The EO’s mandate fizzled until Congress took over during the Biden administration, ultimately [passing the law](https://www.cnn.com/2024/04/20/tech/house-passes-legislation-that-could-ban-tiktok-in-the-us-amid-high-stakes-vote-on-foreign-aid/index.html?ref=metacurity.com) that resulted in the current crisis. The TikTok EO is emblematic of what is an underreported aspect of the newly inaugurated president: His first administration was highly productive on the cybersecurity front, launching eleven major cybersecurity initiatives in just four years (**see the list of actions and summaries below**). The subjects of these cyber actions were wide-ranging, from a comprehensive national cybersecurity strategy to building up the nation’s cyber workforce to identity requirements that would limit foreign adversary use of US cloud providers. Cybersecurity experts say these actions strengthened US government cybersecurity policy and advanced sound private sector security practices. Experts, including those on the opposite side of the political spectrum from Trump, have [underscored](https://www.csoonline.com/article/3610683/cybersecurity-policy-and-practice-likely-to-remain-little-changed-after-trump-takes-the-reins.html?ref=metacurity.com) that the first Trump administration’s activity on the cyber front, followed by a Biden administration that likewise prioritized cybersecurity, reflects the topic's nonpartisan nature. If Trump picks respected cybersecurity leaders, as [initial indications](https://www.politico.com/newsletters/weekly-cybersecurity/2025/01/20/5-things-to-watch-in-trump-2-0-00199194?ref=metacurity.com) and behind-the-scene gossip indicate, Trump 2.0 could be a relative oasis of calm policymaking in what otherwise will likely be a turbulent presidency. _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 1/11/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-11-25/ Last updated: 2025-01-18T14:23:43.000Z Rethinking the internet after the TikTok ban, How Trump threatens the US intel community, The remarkable life of hacker Chris Wade, Pig butchering queen Alice Guo accused of spying, Barcelona is now a spyware hotspot, UAE intel chief seeks AI dominance, Cops misuse facial recognition _This post is for subscribers only._ ### AT&T Hackers Likely Stole FBI Agents' Call and Text Logs URL: https://www.metacurity.com/at-t-hackers-likely-stole-fbi-agents-call-and-text-logs/ Last updated: 2025-01-17T14:35:47.000Z Star Blizzard tried to phish data from Ukraine NGOs, Silk Typhoon infiltrated Janet Yellen's computer, FTC bans GM from providing driver data to consumer reporting agencies, Treasury sanctions DPRK fake IT worker front groups, FTC settles secure hosting charges with GoDaddy, much more _This post is for paying subscribers only._ ### Law Enforcement Has Disrupted Twenty-Nine Malicious Cyber Operations Since January 2023 URL: https://www.metacurity.com/law-enforcement-has-disrupted-twenty-nine-malicious-cyber-operations-since-january-2023/ Last updated: 2025-01-21T13:26:18.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/1024px-U_S_Army_Special_Forces_Soldiers_work_with_Spanish_Special_Forces_and_local_Law_Enforcement_-7796157--1.jpg) Sgt. Mykaela Martin, Public domain, via Wikimedia Commons --- *As a reminder, on Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers) - According to an agency report, Chinese state-sponsored hackers known as Silk Typhoon and UNC5221 breached the US Treasury Department and accessed over 400 laptop and desktop computers, particularly those of staff and senior leaders working on sanctions, international affairs, and intelligence. - A new hacking group called the Belsen Group has leaked the configuration files, IP addresses, and VPN credentials for over 15,000 FortiGate devices for free on the dark web, exposing sensitive technical information to other cybercriminals. - The Biden administration and the states of Illinois and Minnesota sued tractor and agricultural manufacturer John Deere, arguing that the company’s anti-consumer repair practices have driven up farmers' prices and made it difficult for them to get repairs during critical planting and harvesting seasons. - The Biden administration officially released its last, wide-ranging cybersecurity executive order to accomplish many eleventh-hour objectives, including strengthening the federal government's cybersecurity practices and improving AI-powered cyber defenses. (I previewed the order based on a leaked copy earlier this week.) - Speaking at an event hosted by the Foundation for Defending Democracies, CISA Director Jen Easterly said that threat hunters from the Cybersecurity and Infrastructure Security Agency first discovered activity from Salt Typhoon on federal networks, allowing public and private sector defenders to more quickly “connect the dots” and respond to Chinese attacks on the US telecommunications industry. - Change Healthcare, the UnitedHealth-owned health tech company that lost more than 100 million people’s sensitive health data in a ransomware attack last year, said that the company has “substantially” completed notifying affected individuals about the massive data breach, but if you search the web for the Change Healthcare data breach notice, you’re unlikely to find the web page in search engine results. - US school districts affected by the recent cyberattack on edtech giant PowerSchool have said that hackers accessed “all” of their historical student and teacher data stored in their student information systems. Blood-donation not-for-profit OneBlood confirms that donors' personal information was stolen in a ransomware attack last summer. - According to sources, the Trump transition team is considering Sean Plankey as the next Cybersecurity and Infrastructure Security Agency director. Czech cybersecurity startup Wultra has raised €3M (around $3.1 million) from Tensor Ventures, Elevator Ventures, and J&T Ventures to accelerate the development of post-quantum authentication technology. --- ## Timeline of law enforcement disruption of cybercriminal operations With news of the action by the US authorities to infiltrate and remove PlugX malware from thousands of computers, Metacurity revisited its timeline of law enforcement disruption of cybercriminal operations to bring this timeline up to date. Our analysis reveals that since the beginning of 2023, there have been twenty-eight significant law enforcement takedowns of cybercrime or APT operations or disruptions of these groups’ operations. Nineteen, or 69%, of these take-downs were conducted in 2024 alone, highlighting the accelerating trends of such operations. The following is a timeline of the announced law enforcement disruptions of malicious cyber actors from January 2023 through January 15, 2025\. This timeline does not represent other government actions taken to crimp the ability of threat actors to engage in their efforts, such as sanctions levied against cryptocurrency mixers, arrests of leading cybercrime figures (unless those arrests coincided with takedowns), or sanctions against foreign adversarial individuals who facilitate government hacking initiatives. It also doesn't include efforts to seize cryptocurrency scam operators. _This post is for paying subscribers only._ ### US Feds Deleted Chinese-Implanted PlugX Malware From Thousands of Systems URL: https://www.metacurity.com/us-feds-deleted-chinese-implanted-plugx-malware-from-thousands-of-systems/ Last updated: 2025-01-15T14:10:53.000Z Biden to effectively bar many Chinese-made connected vehicles, US, S. Korea, and Japan say DPRK hackers stole $659m in 2024, Microsoft issued 161 Patch Tuesday fixes, Another Fortinet zero day exploited in the wild, CISA issues AI playbook, Woman bilked of savings by deepfake Brad Pitt, much more _This post is for paying subscribers only._ ### Security Researchers Are Crucial to FTC Cyber Actions URL: https://www.metacurity.com/security-researchers-are-crucial-to-ftc-cyber-actions/ Last updated: 2025-01-14T13:59:59.000Z ![unknown persons using computer indoors](https://images.unsplash.com/photo-1560264357-8d9202250f21?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDd8fHJlc2VhcmNoZXJzfGVufDB8fHx8MTczNjg2MDQwM3ww&ixlib=rb-4.0.3&q=80&w=2000) Photo by [Arlington Research](https://unsplash.com/@arlington%5Fresearch?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) --- *As a reminder, on Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today (complete postings available below to premium subscribers) - The UK Home Office proposes a “targeted” ban that will bar all public sector bodies from making ransomware payments, including schools, the NHS, and local councils. - According to NHS data, a cyberattack that paralyzed hospitals and clinics in London last year resulted in harm to dozens of patients, leading to long-term or permanent damage to their health in at least two cases, - New findings from the crypto-tracing firm Elliptic show that one of the biggest players in that sphere, Huione Guarantee, has likely enabled $24 billion in gray market transactions. The volume of activity on the platform has rocketed up 51 percent since initial investigations last summer. - Researchers at Halcyon report that cybercriminals have begun to encrypt data held in Amazon storage tools used by thousands of organizations around the globe, documenting a recent trend of hackers going after S3 buckets and using the company’s encryption tools to lock customers out of their data. - As TikTok anxiously awaits a Supreme Court decision that could determine whether it will be banned in the United States, users are preemptively fleeing the app and migrating to another Chinese social media platform called Xiaohongshu, which means “little red book” in Mandarin. - Sources say Chinese officials are evaluating a potential option involving Elon Musk acquiring TikTok's US operations if the company fails to fend off a controversial ban on the short-video app. - ​CISA has tagged a command injection vulnerability (CVE-2024-12686) in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) as actively exploited in attacks. - The State of Texas sued Allstate, accusing the insurer of illegally tracking drivers using their phones through a subsidiary called Arity, which claimed to have the “world’s largest driving behavior database. - Security researcher Thomas Roth has been able to hack Apple’s USB-C controllers used in current iPhones, which would usually raise concerns about security and the ability to jailbreak the iPhone. - A “furry” hacker breached the education and publishing company Scholastic this month and stole data on 8 million people. - According to comments from developer Grinding Gear Games (GGG) made during a podcast, a hacker compromised an administrative account on the website for the popular game Path of Exile 2, which allowed them to reset the passwords on dozens of players’ accounts. - Blockchain analytics firm Chainalysis has made its first foray into artificial intelligence by acquiring fraud detection startup Alterya for a reported $150 million. --- ## Security researchers are crucial to FTC cyber enforcement actions At this year's final Shmoocon, two cybersecurity specialists, Andy Sellars, partner at public interest law firm Albert Sellars LLP, and Michael A. Specter, Assistant Professor in Computer Science at Georgia Tech, presented their research on US Federal Trade Commission (FTC) enforcement actions during a talk entitled "Software Screws Around, Reverse Engineering Finds Out: How Independent, Adversarial Research Informs Government Regulation." The pair developed a dataset measuring how often the Federal Trade Commission relies on the work of independent researchers to regulate consumer privacy and security. They manually analyzed all public FTC consumer privacy and security actions between Jan. 1, 2017, and July 15, 2024, with 102 FTC cases and 332 individual counts. They discovered that a substantial portion of FTC actions related to cybersecurity can be attributed to the hard work of security researchers. "We're making a bunch of macroscopic observations about the greater relationship between hackers and lawyers and, in particular, lawyers that work for the government," Sellars said during this talk. "We wanted to better understand the relationship between independent research and how the government is able to hold software accountable." _This post is for paying subscribers only._ ### Cell Site Simulator Was Likely Deployed at DNC Convention in Chicago URL: https://www.metacurity.com/cell-site-simulator-was-likely-deployed-at-dnc-convention-in-chicago/ Last updated: 2025-01-13T15:29:22.000Z Telefónica hit by internal ticketing breach, Slovakia hit with biggest cyberattack in its history, Microsoft sues ten foreign cybercrims for Azure OpenAI computers breach, DOJ charges Russian money launderers, Nominet probing Ivanti zero-day breach, Top Dutch tech uni hit by cyber attack, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 1/4/25 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-1-4-25/ Last updated: 2025-01-11T12:03:50.000Z How to avoid broader conflict following hybrid attacks, The PI who was obsessed with outing a dangerous swatter, How a TikTok ban could work, The implications of NSO Group's loss to WhatsApp, A survey of hardware security vulnerabilities _This post is for subscribers only._ ### Chinese Hackers Breached US Office That Reviews Foreign Investment Security Risks URL: https://www.metacurity.com/chinese-hackers-breached-us-office-that-reviews-foreign-investment-security-risks/ Last updated: 2025-01-10T13:35:51.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/money-938269_1280-1.jpg) Image by [moerschy](https://pixabay.com/users/moerschy-127417/?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=938269) from [Pixabay](https://pixabay.com//?utm%5Fsource=link-attribution&utm%5Fmedium=referral&utm%5Fcampaign=image&utm%5Fcontent=938269) --- Please consider supporting Metacurity with an upgraded subscription so that you can continue to receive our daily missives packed with the top infosec developments you should know. [Upgrade subscription](#/portal/signup) If you can't commit to a subscription today, consider tipping or donating to help keep Metacurity going. [Donate whatever you can](#/portal/support) --- ### According to sources, in December, Chinese hackers breached the Committee on Foreign Investment in the US (CFIUS), the US government office that reviews foreign investments for national security risks. This intrusion underscores Beijing’s keen interest in spying on a US government office with broad powers to block Chinese investment in the US. The breach was part of a broader incursion by the hackers into the Treasury Department’s unclassified system. As first reported by the Washington Post, the hackers also targeted the Treasury Department’s sanctions office. Just last week, the office sanctioned a Chinese company for its alleged role in cyberattacks. According to Bloomberg News, Silk Typhoon is the Chinese hacking group that targeted the Treasury Department. ([Sean Lyngaas / CNN](https://www.cnn.com/2025/01/10/politics/chinese-hackers-breach-committee-on-foreign-investment-in-the-us/index.html?ref=metacurity.com)) **Related:** [*Reuters*](https://www.reuters.com/technology/cybersecurity/chinese-hackers-breached-us-govt-office-that-assesses-foreign-investments-2025-01-10/?ref=metacurity.com)*,* [*The Economic Times*](https://economictimes.indiatimes.com/news/international/business/chinese-hackers-breached-us-agency-that-reviews-foreign-investments-cnn-reports/articleshow/117120564.cms?from=mdr&ref=metacurity.com)*,* [*Devdiscourse*](https://www.devdiscourse.com/article/law-order/3221425-hackers-breach-cfius-national-security-at-risk?ref=metacurity.com), [*The Jerusalem Post*](https://www.jpost.com/breaking-news/article-836974?ref=metacurity.com) ### Rumble, Quora, and WeChat are among the 15 companies from which Texas Attorney General Ken Paxton has demanded answers by next week about their collection and use of data of people under 18 years old. Paxton announced the investigation in a press release last month but named only four of the companies being probed: Character.AI, Red­dit, Insta­gram, and Dis­cord. The names of additional targeted companies through a public records request. They also include Kick, Kik, Pinterest, Telegram, Twitch, Tumblr, WhatsApp, and Whisper. The variety of companies questioned highlights the sprawling reach of a new Texas law to increase oversight of minors’ use of social media and chat services. Experts in youth privacy regulations who have been following Paxton’s enforcement efforts say the new investigation should be treated credibly, and they believe it could result in companies agreeing to improve their practices. The alternative could be hundreds of millions of dollars in penalties per company. Paxton’s interest in Rumble, a YouTube-like website popular among US conservative political commentators, is perhaps unexpected given his track record of partisan views about social media companies. Rumble has touted itself as a haven for free expression, unlike platforms that engage in allegedly heavier content moderation. Paxton is a Republican and has criticized platforms that unfairly silence Texans. ([Paresh Dave / Wired](https://www.wired.com/story/texas-social-media-investigation-children-privacy/?ref=metacurity.com)) ### According to hacked files from location data company Gravy Analytics, some of the world’s most popular apps, including Candy Crush and Tinder, are likely being co-opted by rogue members of the advertising industry to harvest sensitive location data on a massive scale, with that data ending up with a location data company whose subsidiary has previously sold global location data to US law enforcement. Because much of the collection occurs through the advertising ecosystem, not code developed by the app creators themselves, this data collection is likely happening without the users’ and even app developers’ knowledge. “For the first time publicly, we seem to have proof that one of the largest data brokers selling to both commercial and government clients appears to be acquiring their data from the online advertising ‘bid stream,’” rather than code embedded into the apps themselves, Zach Edwards, senior threat analyst at cybersecurity firm Silent Push, said after reviewing some of the data. The hacked Gravy data includes tens of millions of mobile phone coordinates of devices inside the US, Russia, and Europe. Some of those files also reference an app next to each piece of location data. The list includes dating sites Tinder and Grindr; massive games such as Candy Crush, Temple Run, Subway Surfers, and Harry Potter: Puzzles & Spells; transit app Moovit; My Period Calendar & Tracker, a period tracking app with more than 10 million downloads; popular fitness app MyFitnessPal; social network Tumblr; Yahoo’s email client; Microsoft’s 365 office app; and flight tracker Flightradar24\. The list also mentions multiple religious-focused apps such as Muslim prayer and Christian Bible apps, various pregnancy trackers, and many VPN apps, which some users may download, ironically, in an attempt to protect their privacy. ([Joseph Cox / 404 Media](https://www.404media.co/candy-crush-tinder-myfitnesspal-see-the-thousands-of-apps-hijacked-to-spy-on-your-location/?ref=metacurity.com)) **Related:** [*Pixel Envy*](https://pxlnv.com/linklog/gravy-analytics-leaked/?ref=metacurity.com)*,* [*Hacker News (ycombinator)*](https://news.ycombinator.com/item?id=42651115&ref=metacurity.com)*,* [*Hacker News (ycombinator)*](https://news.ycombinator.com/item?id=42651087&ref=metacurity.com)*,* [*Slashdot*](https://yro.slashdot.org/story/25/01/10/0056202/see-the-thousands-of-apps-hijacked-to-spy-on-your-location?ref=metacurity.com) ### Security researcher Ben Sadeghipour and independent researcher Alex Chapman found a security vulnerability that allowed him to run commands on the internal Facebook server housing that platform, essentially giving him control of the server, and were awarded $100,000 in a bug bounty for their work. According to Sadeghipour, the issue was that one of the servers that Facebook used for creating and delivering ads was vulnerable to a previously fixed flaw found in the Chrome browser, which Facebook uses in its ads system. Sadeghipour said this unpatched bug allowed him to hijack it using a headless Chrome browser (essentially a browser version that users run from the computer’s terminal) to interact directly with Facebook’s internal servers. ([Lorenzo Franceschi-Bicchierai / TechCrunch](https://techcrunch.com/2025/01/09/facebook-awards-researcher-100000-for-finding-bug-that-granted-internal-access/?ref=metacurity.com)) ***Related:*** [*Cyber Security News*](https://cybersecuritynews.com/facebook-awarded-100000-bug-bounty/?ref=metacurity.com) ### In a settlement with fifty-three state-level regulators, mortgage company Bayview Asset Management will pay a $20 million penalty over an October 2021 data breach and its alleged failure to cooperate with regulators in the aftermath. The Conference of State Bank Supervisors (CSBS) said Bayview, a Coral Gables, Fla.-based investment manager that owns mortgage-servicing firms, had deficient information technology practices and suffered a 2021 data breach that affected 5.8 million customers. Bayview then failed to cooperate with regulators as they sought information. Agencies in 53 jurisdictions, led by California, Maryland, North Carolina, and Washington state regulators, took coordinated action against Bayview, which entered into a settlement. Bayview has also agreed to take corrective actions, including improving its cybersecurity programs, undergoing independent assessment, and making reports to state regulators for three years. ([Richard Vanderford / Wall Street Journal](https://www.wsj.com/articles/bayview-asset-management-enters-into-20-million-settlement-over-cybersecurity-weaknesses-a5335697?ref=metacurity.com)) **Related:** [*Cleveland.com*](https://www.cleveland.com/news/2025/01/mortgage-company-bayview-settles-for-20m-with-state-financial-regulators-including-ohio-over-data-breach.html?ref=metacurity.com)*,* [*Housing Wire*](https://www.housingwire.com/articles/bayview-settles-for-20m-with-53-state-regulators-over-cyberattack/?ref=metacurity.com)*,* [*The Business Journals*](https://www.bizjournals.com/southflorida/news/2025/01/09/bayview-asset-miami-financial-regulation-fine.html?ref=metacurity.com)*,* [*WYTV*](https://www.wytv.com/news/local-news/ohio-joins-20m-data-breach-settlement/?nxsparam=2&ref=metacurity.com)*,* [*Inman*](https://www.inman.com/2025/01/08/loan-servicer-agrees-to-20m-fine-over-2021-cybersecurity-breach/?ref=metacurity.com) ### Winston-Salem, North Carolina, residents cannot pay their utility bills online after a post-Christmas cyberattack knocked the city’s systems offline. City officials initially announced a cyberattack on December 30, telling residents they discovered issues with their digital platforms one day after Christmas. Although Winston-Salem was forced to take down all the digital payment systems for water and electricity bills, officials reiterated that no service interruptions or late penalties would be charged to accounts. Residents can still pay in person with cash or checks. A list of phone numbers was provided to residents who need to contact departments directly with specific issues. Winston-Salem’s government has not provided an update since December 30\. ([Jonathan Greig / The Record](https://therecord.media/winston-salem-north-carolina-services-offline-cyberattack?ref=metacurity.com)) **Related:** [*Winston-Salem*](https://www.cityofws.org/CivicAlerts.aspx?AID=1682&ref=metacurity.com)*,* [*WGHP*](https://myfox8.com/news/north-carolina/winston-salem/information-about-winston-salem-forsyth-county-schools-students-families-accessed-during-2nd-cyber-event-experienced-by-city/?ref=metacurity.com)*,* [*Spectrum News*](https://spectrumlocalnews.com/nc/charlotte/news/2025/01/03/winston-salem-experiences--major-cyber-event-?ref=metacurity.com)*,* [*WXLV*](https://abc45.com/news/local/cyber-event-causes-major-city-wide-outage-in-winston-salem?ref=metacurity.com) ### ​BayMark Health Services, North America's largest provider of substance use disorder (SUD) treatment and recovery services, is notifying an undisclosed number of patients that attackers stole their personal and health information in a September 2024 breach. In data breach notification letters mailed to affected individuals, BayMark revealed that it learned of the breach on October 11, 2024, following an IT systems disruption. A follow-up investigation revealed that the attackers accessed BayMark's systems between September 24 and October 14. Baymark is now offering a year of free Equifax identity monitoring services to patients whose Social Security numbers or driver's license numbers may have been exposed in the incident. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/largest-us-addiction-treatment-provider-notifies-patients-of-data-breach/?ref=metacurity.com)) **Related:** [*Vermont AG*](https://ago.vermont.gov/sites/ago/files/documents/2025-01-08%20BayMark%20Health%20Services%20Data%20Breach%20Notice%20to%20Consumers.pdf?ref=metacurity.com)*,* [*JD Supra*](https://www.jdsupra.com/legalnews/baymark-health-services-experiences-4775353/?ref=metacurity.com)*,* [*HIPAA Journal*](https://www.hipaajournal.com/baymark-health-services-data-breach/?ref=metacurity.com) ### CrowdStrike is warning that a phishing campaign is impersonating the cybersecurity company in fake job offer emails to trick targets into infecting themselves with a Monero cryptocurrency miner (XMRig). The company discovered the malicious campaign on January 7, 2025, and based on the phishing email's content, it likely didn't start much earlier. The attack starts with a phishing email sent to job seekers, supposedly from a CrowdStrike employment agent, thanking them for applying for a developer position at the company. The email asks the recipients to download an application, something that employers rarely do, which then delivers the mining malware. The miner is set to run in the background, consuming minimal processing power (max 10%) to avoid detection. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/fake-crowdstrike-job-offer-emails-target-devs-with-crypto-miners/?ref=metacurity.com)) **Related:** [*CrowdStrike*](https://www.crowdstrike.com/en-us/blog/recruitment-phishing-scam-imitates-crowdstrike-hiring-process/?ref=metacurity.com)*,* [*Bitcoin.com*](https://news.bitcoin.com/job-seekers-beware-fraudulent-offers-conceal-dangerous-crypto-malware/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/image-25.png) Source: CrowdStrike. ### Researchers at Check Point report that a new version of the Banshee info-stealing malware for macOS has been evading detection over the past two months by adopting string encryption from Apple's XProtect. The encryption method present in Banshee allows it to blend in with normal operations and appear legitimate while collecting sensitive information from infected hosts. Another change is that it no longer avoids systems belonging to Russian users. The latest Banshee stealer variant is primarily distributed via deceptive GitHub repositories targeting macOS users through software impersonation. The same operators also target Windows users but with Lumma Stealer. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/banshee-stealer-evades-detection-using-apple-xprotect-encryption-algo/?ref=metacurity.com)) **Related:** [*CheckPoint*](https://blog.checkpoint.com/research/cracking-the-code-how-banshee-stealer-targets-macos-users/?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/threat-intelligence/banshee-malware-steals-apple-encryption-macs?ref=metacurity.com)*,* [*HackRead*](https://hackread.com/banshee-stealer-hits-macos-fake-github-repositories/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2025/01/09/banshee-stealer-variant-targets-russian-speaking-macos-users/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/news/new-banshee-stealer-variant-continues-attacks-on-macos-devices?ref=metacurity.com) ### According to court testimony, Orlin Roussev, a Russian spy who was living in a "typical seaside hotel" on the English coast crammed full of electronic surveillance equipment, boasted to his controller that he was becoming like the James Bond character "Q" as he prepared his spying "toys" for kidnap and surveillance operations across Europe. Among the gear he hoarded were IMSI catchers*,* pendant necklaces with hidden cameras, water bottles with mobile phone-linked video surveillance capability, a Pandora car key cloning device, and more traditional surveillance equipment such as night vision binoculars and mobile radios. Roussev is said to have taken instructions from a handler called Jan Marsalek, who is wanted in connection with a £1.6bn ($1.97 billion) tech fraud linked to a company called Wirecard. Roussev, a Bulgarian national, has pleaded guilty to running a spy ring on behalf of the Russians, but three other members of the group deny the charges. ([Duncan Gardham / Sky News](https://news.sky.com/story/russian-spy-who-hoarded-surveillance-gadgets-in-english-hotel-boasted-of-being-like-james-bond-character-q-court-hears-13286188?ref=metacurity.com)) **Related:** [*Daily Mail*](https://www.dailymail.co.uk/news/article-14268025/inside-russian-spy-guesthouse-gadgets-equipment.html?ref=metacurity.com)*,* [*The Telegraph*](https://www.telegraph.co.uk/news/2025/01/09/russian-spy-ring-great-yarmouth-lair-kremlin/?ref=metacurity.com)*,* [*The Mirror*](https://www.mirror.co.uk/news/uk-news/russian-spy-found-hiding-great-34453265?ref=metacurity.com) ### Cybersecurity company DarkTrace, owned by private equity giant Thoma Bravo, announced the “proposed acquisition” of UK-based incident investigation and response firm Cado Security. Financial terms have not been disclosed for the deal, which is expected to be completed in February, but the Australian Financial Review (AFR) reported that Darktrace will pay an estimated $50 million to $100 million, subject to regulatory approvals. Darktrace said the amount reported by AFR is not a number it recognizes and noted that it’s not disclosing the acquisition price. The British cybersecurity giant plans to continue enhancing Cado’s existing products while combining its investigation technology with its ActiveAI platform. Cado’s founders, James Campbell (CEO), Chris Doman (CTO), and the Cado team, will join Darktrace. ([Edward Kovacs / Security Week](https://www.securityweek.com/darktrace-to-acquire-incident-investigation-firm-cado-security/?ref=metacurity.com#:~:text=Financial%20terms%20have%20not%20been,million%2C%20subject%20to%20regulatory%20approvals.)) ***Related:*** [*PR Newswire*](https://www.prnewswire.com/news-releases/darktrace-announces-proposed-acquisition-of-cado-security-a-cloud-investigation-and-response-specialist-302346799.html?ref=metacurity.com)*,* [*CRN*](https://www.crn.com/news/security/2025/darktrace-to-acquire-cado-security-boosting-cloud-threat-investigation?ref=metacurity.com)*,* [*The Fast Mode*](https://www.thefastmode.com/solution-vendors-m-a/38926-darktrace-to-acquire-cado-security-boosting-cloud-cybersecurity-capabilities?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2025/01/09/darktrace-acquire-cado-security-strengthen-cloud-forensic-capabilities/?ref=metacurity.com)*,* [*Channel Futures*](https://www.channelfutures.com/mergers-acquisitions/thoma-bravo-darktrace-acquiring-cado-security?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/127671/darktrace-makes-first-acquisition-since-thoma-bravo-deal-cado-security/?ref=metacurity.com)*,* [*ITPro*](https://www.itpro.com/cloud/cloud-security/darktrace-targets-cloud-security-gains-with-cado-security-acquisition?ref=metacurity.com)*,* [*Financial Review*](https://www.afr.com/technology/uk-s-darktrace-buys-turnbull-backed-cyber-firm-for-up-to-161m-20250109-p5l33g?ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/security/11564-darktrace-to-acquire-cloud-security-firm-cado-security?ref=metacurity.com)*,* [*UKTN*](https://www.uktech.news/cybersecurity/darktrace-acquires-london-based-cybersecurity-firm-cado-20250109?ref=metacurity.com)*,* [*The Times*](https://www.thetimes.com/business-money/companies/article/uks-darktrace-turns-more-acquisitive-with-cado-security-deal-pbxs6hz8r?ref=metacurity.com)*,* [*GovInfoSecurity*](https://www.govinfosecurity.com/darktrace-acquires-cado-security-as-ai-meets-cloud-forensics-a-27260?ref=metacurity.com) ### Israeli startup Wiz said it had named veteran executive Fazal Merchant as president and chief financial officer to keep driving the cloud security firm's growth and prepare for a U.S. share offering in about a year. Wiz last July rebuffed a reported $23 billion takeover deal by Google-parent Alphabet that would have made it the U.S. tech giant's largest-ever acquisition. At the time, Wiz CEO Assaf Rappaport said the company would focus on an initial public offering and its goal of achieving an annual recurring revenue of $1 billion. ([Steven Scheer / Reuters](https://www.reuters.com/technology/cybersecurity/cyber-firm-wiz-taps-merchant-president-cfo-prepare-ipo-2025-01-09/?ref=metacurity.com)) **Related:** [*The Information*](https://www.theinformation.com/articles/wiz-completes-piece-of-ipo-puzzle?ref=metacurity.com)*,* [*Globes Online*](https://en.globes.co.il/en/article-wiz-appoints-cfo-with-ipo-on-the-horizon-1001499011?ref=metacurity.com)*,* [*Seeking Alpha*](https://seekingalpha.com/news/4393857-wiz-names-merchant-cfo-as-it-nears-ipo-following-busy-2024?ref=metacurity.com)*,* [*Wall Street Journal*](https://www.wsj.com/articles/cyber-startup-wiz-names-new-cfo-as-it-weighs-an-ipo-eaf8454c?ref=metacurity.com)*,* [*CRN*](https://www.crn.com/news/security/2025/wiz-hires-veteran-exec-fazal-merchant-as-president-for-ipo-push?ref=metacurity.com)*,* [*Tech in Asia*](https://www.techinasia.com/news/israeli-cybersecurity-startup-wiz-taps-cfo-plans-ipo?ref=metacurity.com) ### Best Thing of the Day: Fighting MAGA Wildfire Misinformation Watch Duty, created by Santa Rosa-based nonprofit Sherwood Forestry Service, tracks fire risk and firefighting efforts in real-time [and has become](https://sfstandard.com/2025/01/09/wildfires-watch-duty-elon-musk-los-angeles/?ref=metacurity.com) an oasis of accurate information and a voice against a wave of MAGA-led misinformation during the Los Angeles wildfires. ### Worst Thing of the Day: Speaking of MAGA Wildfire Misinformation... A video going viral this week of the Hollywood sign in Los Angeles with a wildfire raging behind it and letters glowing in the blaze, [is AI-generated](https://www.404media.co/hollywood-sign-burning-ai-images-la-wildfire/?ref=metacurity.com), as are other images and videos generated by MAGA sympathizers on social media. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/image-26.png) ### US Supreme Court to Decide If TikTok Is a Big Enough National Security Risk to Justify a Ban URL: https://www.metacurity.com/us-supreme-court-to-decide-if-tiktok-is-a-big-enough-national-security-risk-to-justify-a-ban/ Last updated: 2025-01-09T13:50:26.000Z ![a large white building with columns with United States Supreme Court Building in the background](https://images.unsplash.com/photo-1658958327132-a80f8a9409fb?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDl8fFN1cHJlbWUlMjBDb3VydHxlbnwwfHx8fDE3MzY0Mjg4MDZ8MA&ixlib=rb-4.0.3&q=80&w=2000) Photo by [Fine Photographics](https://unsplash.com/@finephotographics?ref=metacurity.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) --- *As a reminder, on Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's complete* *archives.* [Upgrade my subscription](#/portal/signup) --- ### Summary of the most critical infosec developments you should know today - Russian internet provider Nodex reported that its network had been ruined in a cyberattack, which it suspects originated from Ukraine, with a pro-Ukraine activist group, Ukrainian Cyber Alliance, taking credit for the incident. - Sources say the Biden administration is racing to issue an executive order to strengthen US cybersecurity during its dwindling days in office. - Chief US District Judge Richard Seeborg in the Northern District Court on December 30 denied a motion to block the forfeiture of 69,370 Bitcoin tied to the infamous Silk Road marketplace on December 30, clearing the Department of Justice to sell the $6.5 billion assets. - IT software provider Ivanti released patches for its Connect Secure SSL VPN appliances to address two memory corruption vulnerabilities, one of which has already been exploited in the wild as a zero-day to compromise devices. - Researchers at Eclypsium report that BIOS/UEFI vulnerabilities in the iSeq 100 DNA sequencer from US biotechnology company Illumina could let attackers disable devices for detecting illnesses and developing vaccines. - Security and privacy researcher Wladimir Palant revealed that developers are flagrantly violating Google's Chrome browser policies against search manipulating techniques in the Chrome Web store in hundreds of extensions currently available for download from Google. - ​American football team Green Bay Packers says cybercriminals stole the credit card data of over 8,500 customers after hacking its official Pro Shop online retail store in a September breach. - Venture capital firm YL Ventures said that Israeli cybersecurity firms raised $4 billion in 2024, more than double that of 2023, led by firms seeking to protect the cloud and a surge in artificial intelligence. ## Supreme Court to Decide If TikTok Is a Big Enough National Security Risk to Justify a Ban *Advocates for and against a law that essentially bans TikTok in the US will weigh in tomorrow before the Supreme Court. At stake in the high-profile fight is whether TikTok, fundamentally controlled by China, is enough of a national security risk to outweigh the First Amendment harms such a ban would inflict.* In April 2024, the US Congress [passed](https://www.congress.gov/bill/118th-congress/house-bill/815?ref=metacurity.com) the Protecting Americans from Foreign Adversary Controlled Applications Act, which conditionally banned the hugely popular video-sharing service TikTok if its Chinese parent company, ByteDance Ltd., fails to divest its ownership in the US version of the app. With the ban slated to go into effect on January 19 and following a December 6 [decision](https://storage.courtlistener.com/recap/gov.uscourts.cadc.40861/gov.uscourts.cadc.40861.1208687460.0%5F4.pdf?ref=metacurity.com) by the US Court of Appeals for the District of Columbia Circuit upholding the law, on December 18, the Supreme Court agreed to take up an appeal by TikTok that challenges the law on First Amendment grounds. Since then, interested parties have [filed briefs](https://www.supremecourt.gov/search.aspx?filename=/docket/docketfiles/html/public/24-656.html&ref=metacurity.com) laying out their support for or objections to the law, with oral arguments slated before the Court on January 10. The arguments favoring the law advanced by Congress and the Biden administration fall mainly along the lines of protecting US national security. China, the legislation's advocates argue, is amassing sensitive data on Americans that can be used for covert and malign purposes such as espionage and, to a lesser but significant degree, damaging influence operations. Beijing could weaponize these malicious tools in China's arsenal during a national crisis, or so the US government's argument goes. TikTok and a host of free speech advocates, including some lawmakers who opposed the legislation, emphasize the propaganda-quashing rationale they say is the true engine behind the law, arguing that the legislation is a blatant and broad violation of the First Amendment right to free speech. The government, they say, can only restrict a communications platform like TikTok when there is credible evidence of ongoing or imminent harm. Moreover, they argue that even if China's behind-the-scenes scheme for TikTok does represent a national security threat, Congress failed to investigate less intrusive options that might provide greater protection to the nation's history of vigorous protection of the First Amendment right to free speech. In [their brief](https://www.aclu.org/cases/tiktok-inc-et-al-v-garland-amicus?ref=metacurity.com) before the Supreme Court, the American Civil Liberties Union, the Electronic Frontier Foundation, the Center for Democracy and Technology, the Freedom of the Press Foundation, Public Knowledge, and other high-profile free speech advocates wrote that they "urge the Court to see the Act for what it is: a sweeping ban on free expression that triggers and fails the most exacting scrutiny under the First Amendment." _This post is for paying subscribers only._ ### White House Launches US Cyber Trust Mark for IoT Devices URL: https://www.metacurity.com/white-house-launches-us-cyber-trust-mark-for-iot-devices/ Last updated: 2025-01-08T14:21:23.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/UScybertrustmark-1.png) Source: Federal Communications Commission. --- *Please consider supporting Metacurity with an upgraded subscription so that you can continue to receive our daily missives packed with the top infosec developments you should know.* [Upgrade subscription](#/portal/signup) *If you can't commit to a subscription today, consider tipping or donating to help keep Metacurity going.* [Donate whatever you can](#/portal/support) --- ### The White House launched the US Cyber Trust Mark, a new cybersecurity safety label for internet-connected consumer devices. The Cyber Trust Mark label, which will appear on smart products sold in the United States later this year, will help American consumers determine whether the devices they want to buy are safe to install in their homes. It's designed for consumer smart devices, such as home security cameras, TVs, internet-connected appliances, fitness trackers, climate control systems, and baby monitors, and it signals that the internet-connected device comes with a set of security features approved by the National Institute of Standards and Technology (NIST). Vendors will label their products with the Cyber Trust Mark logo if they meet the cybersecurity criteria. These criteria include using unique and strong default passwords, software updates, data protection, and incident detection capabilities. Consumers can scan the QR code included next to the Cyber Trust Mark labels for additional security information, such as instructions on changing the default password, steps for securely configuring the device, details on automatic updates (including how to access them if they are not automatic), the product's minimum support period, and a notification if the manufacturer does not offer updates for the device. The program was unveiled in July 2023, when major electronics, appliance, and consumer product makers like Amazon, Google, Best Buy, LG Electronics U.S.A., Logitech, and Samsung Electronics announced their participation. Over the last 18 months, FCC Commissioners unanimously authorized the program. They also adopted final rules and the trademarked, distinct shield logo for Cyber Trust Mark-certified products. In December 2024, the FCC announced the approval of 11 companies as Cybersecurity Label Administrators, responsible for the program's day-to-day management and certifying the use of the US Cyber Trust Mark label. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/us-govt-launches-cybersecurity-safety-label-for-smart-devices/?ref=metacurity.com)) **Related:** [*FCC.gov*](https://www.fcc.gov/CyberTrustMark?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2025/01/07/us-government-set-to-launch-its-cyber-trust-mark-cybersecurity-labeling-program-for-internet-connected-devices-in-2025/?ref=metacurity.com)*,* [*PYMNTS.com*](https://www.pymnts.com/cybersecurity/2025/cyber-trust-mark-program-smart-devices-set-go-live/?ref=metacurity.com)*,* [*The White House*](https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/?ref=metacurity.com)*,* [*NBC News*](https://www.nbcnews.com/tech/security/us-roll-cyber-trust-mark-label-secure-devices-rcna186642?ref=metacurity.com)*,* [*The Record*](https://therecord.media/consumer-products-cyber-trust-white?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/us-cyber-trust-mark-launches-white-house-nist/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/2025/1/7/24338168/us-cyber-trust-mark-smart-home-security?ref=metacurity.com)*,* [*Nextgov/FCW*](https://www.nextgov.com/cybersecurity/2025/01/white-house-unveils-cyber-trust-mark-program-consumer-devices/401991/?ref=metacurity.com)*,* [*ZDNET*](https://www.zdnet.com/article/buying-a-smart-home-device-look-for-this-new-cybersecurity-seal-heres-why/?ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/government/11550-us-government-launches-smart-device-cyber-security-labels?ref=metacurity.com)*,* [*Tech Monitor*](https://www.techmonitor.ai/technology/cybersecurity/us-introduces-cyber-trust-mark-smart-devices-iot-security?ref=metacurity.com) ### Japan's National Police Agency (NPA) linked more than 200 cyberattacks targeting the country’s national security and high technology data over the past five years to a Chinese hacking group, MirrorFace, detailing their tactics and calling on government agencies and businesses to reinforce preventive measures. The agency said its analysis of MirrorFace's cyberattacks from 2019 to 2024, including their targets, methods, and infrastructure, concluded that they were systematic attacks linked to China, which aimed to steal data on Japanese national security and advanced technology. The NPA said the Chinese government-led cyberattacks targeted Japan’s Foreign and Defense ministries, the country’s space agency, and individuals, including politicians, journalists, private companies, and think tanks related to advanced technology. MirrorFace sent emails with attachments containing malware to targeted organizations and individuals to view data saved on computers mainly from December 2019 to July 2023, often from Gmail and Microsoft Outlook addresses using stolen identities, the NPA investigation found. The emails typically used as subjects keywords such as “Japan-US alliance,” “Taiwan Strait,” “Russia-Ukraine war,” and “free and open Indo-Pacific,” and included an invitation for a study panel, references, and a list of panelists, the NPA said. In another tactic, the hackers targeted Japanese organizations in the aerospace, semiconductors, information, and communications sectors from February to October 2023, exploiting vulnerabilities in virtual private networks to gain unauthorized access to information. The attacks included one on the Japan Aerospace and Exploration Agency, or JAXA, which acknowledged in June it had suffered a series of cyberattacks since 2023, though sensitive information related to rockets, satellites, and defense was not affected. ([Mari Yamaguchi / Associated Press](https://apnews.com/article/japan-police-cyberattack-china-government-68adcb293b2931da4c30ca0279720124?ref=metacurity.com)) **Related:** [*The Japan Times*](https://www.japantimes.co.jp/news/2025/01/08/japan/japan-authorities-alarm-china-cyberattack/?ref=metacurity.com)*,* [*Asahi Shibum*](https://www.asahi.com/ajw/articles/15577415?ref=metacurity.com)*,* [*Kyodo News*](https://english.kyodonews.net/news/2025/01/3de655117007-210-hacks-made-on-jaxa-other-japan-targets-by-china-group-since-2019.html?ref=metacurity.com) ### New details about the internal operations of a prolific voice phishing gang show that the group routinely abuses legitimate services at Apple and Google to force outbound communications to their users, including emails, automated phone calls, and system-level messages sent to all signed-in devices. A cybercriminal known as “Perm,” a.k.a. “Annie,” rents out the phishing kit. Perm is the current administrator of Star Fraud, one of Telegram's more consequential cybercrime communities and one that has emerged as a foundry of innovation in voice phishing attacks. Perm posted messages to Star Fraud and other Telegram channels that showed they worked closely with another cybercriminal who went by the handles “Aristotle” and just “Stotle.” It is unclear what caused the rift, but Stotle turned on his erstwhile business partner, Perm, last year by sharing highly detailed videos, tutorials, and secrets that shed new light on how these phishing panels operate. When the phishing group settles on a target of interest, the scammers create and join a new Discord channel. This allows each logged-on member to share what is currently on their screen, which is tiled in a series of boxes so that everyone can simultaneously see all other call participant screens. The spoofed Apple phone number tells the victim they were with Apple’s account recovery team. From there, they engage in a convincing scam, stealing the victim's credentials. The target lists used by the phishing callers originate mainly from a few crypto-related data breaches, including the 2022 and 2024 breaches involving user account data stolen from cryptocurrency hardware wallet vendor Trezor. ([Brian Krebs / Krebs on Security](https://krebsonsecurity.com/2025/01/a-day-in-the-life-of-a-prolific-voice-phishing-crew/?ref=metacurity.com)) **Related:** [*Hacker News (ycombinator)*](https://news.ycombinator.com/item?id=42629163&ref=metacurity.com) ### Security researcher Matt Brown discovered a flaw in the automated license-plate-recognition (ALPR) system that collects real-time vehicle data meant to be accessible by law enforcement. Because of this flaw, more than 150 Motorola ALPR cameras have exposed their video feeds and leaked data in recent months. As well as broadcasting live footage accessible to anyone on the internet, the misconfigured cameras also exposed data they have collected, including photos of cars and logs of license plates. The real-time video and data feeds don’t require any usernames or passwords to access. Motorola confirmed the exposures, saying it was working with its customers to close the access. ([Matt Burgess and Dhruv Mehrotra / Wired](https://www.wired.com/story/license-plate-reader-live-video-data-exposed/?ref=metacurity.com)) **Related:** [*alpr leaks on GitHub*](https://github.com/frillweeman/alprleaks?ref=metacurity.com)*,* [*404 Media*](https://www.404media.co/researcher-turns-insecure-license-plate-cameras-into-open-source-surveillance-tool/?ref=metacurity.com) ### Hackers claim to have compromised Gravy Analytics, the parent company of Venntel, which has sold the US government massive amounts of smartphone location data. The hackers said they had stolen a massive amount of data, including customer lists, information on the broader industry, and even location data harvested from smartphones, which shows people’s precise movements. They are threatening to publish the data publicly. In a message posted to two Gravy websites, the hackers wrote, "Personal data of millions of users is affected,” according to screenshots posted on the Russian cybercrime forum XSS. “Company have 24h to answer or we will start to publish data,” the message continues. The samples of data posted by the hackers include the apparent historical location of smartphones. The files contain precise latitude and longitude coordinates of the phone and the time at which the phone was there. Some screenshots indicate what country the data has been collected from. A file called “users” in a sample of data the hackers posted includes well-known companies such as Gannett, Uber, Comcast, Apple, LexisNexis, Equifax, and many more. It also specifically mentions Babel Street, which is another US government contractor. ([Joseph Cox / 404 Media](https://www.404media.co/hackers-claim-massive-breach-of-location-data-giant-threaten-to-leak-data/?ref=metacurity.com)) **Related:** [*SOCRadar*](https://socradar.io/gravy-analytics-breach-location-records-at-risk/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/image-20.png) ### Japanese electronics manufacturer Casio says that the October 2024 ransomware incident exposed the personal data of approximately 8,500 people. The affected individuals are primarily Casio employees and business partners, but the exposed data contained a small amount of customer personal information. The Underground ransomware gang claimed the attack on October 10\. They threatened to disclose confidential documents, financial files, project information, and employee data unless a ransom was paid. Soon after, Casio confirmed that Underground had stolen the personal data of employees, partners, and customers. However, the company did not provide the number of affected people. The Japanese firm also clarified that they did not negotiate with the cybercriminals. It also said most impacted services have returned to normal operational status, though some services have not yet been recovered. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/casio-says-data-of-8-500-people-exposed-in-october-ransomware-attack/?ref=metacurity.com)) **Related:** [*Casio*](https://world.casio.com/news/2025/0107-incident/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2025/01/08/casio-says-hackers-stole-personal-data-of-8500-people-during-october-ransomware-attack/?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/casio-confirms-data-of-8-500-people-exposed-in-recent-ransomware-attack?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/casio-failings-attackers-leak-data/?ref=metacurity.com) ### Education software giant PowerSchool confirmed it suffered a cybersecurity incident that allowed a threat actor to steal the personal information of students and teachers from school districts using its PowerSchool SIS platform. In an unusual twist, PowerSchool confirmed that this was not a ransomware attack but that they did pay a ransom to prevent the data from being released. While the company's products are known mainly by school districts and their staff, PowerSchool also operates Naviance, a platform used by many K-12 districts in the US to offer personalized college, career, and life readiness planning tools to students. In a notification sent to customers, PowerSchool says they first became aware of the breach on December 28, 2024, after PowerSchool SIS customer information was stolen through its PowerSource customer support platform, which is a student information system (SIS) used to manage student records, grades, attendance, enrollment, and more. After investigating the incident, it was determined that the threat actor accessed the portal using compromised credentials and stole data using an "export data manager" customer support tool. Using this tool, the attacker exported the PowerSchool SIS 'Students' and 'Teachers' database tables to a CSV file, which was then stolen. For those impacted, PowerSchool is offering credit monitoring services to impacted adults and identity protection services for impacted minors. PowerSchool says its operations remain unaffected, and services continue as usual despite the breach. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/powerschool-hack-exposes-student-teacher-data-from-k-12-districts/?ref=metacurity.com)) **Related:** [*Local3News*](https://www.local3news.com/local-news/walker-co-schools-alerting-parents-educators-of-student-information-system-data-breach/article%5F1505632e-cd40-11ef-9e46-e7788d8f6b28.html?ref=metacurity.com) ### Researchers at Group-IB uncovered a sophisticated, multi-stage fraud campaign designed to trick consumers who have submitted customer complaints about goods or services to an official government portal into sharing their card details. The fraudsters purchased on the dark web logins to government accounts originally obtained via infostealers. Impersonating government officials, they claim to be able to help the victim process a refund, persuading them to download remote access software to their mobile device to streamline the process. The scheme, which Group-IB said targets consumers in the Middle East, is highly effective because it uses real customer information to engineer the victim socially. Victims are usually female consumers with limited technology expertise. Group-IB says that scammers typically cash out their proceeds by making 3D-secure purchases of products or gift vouchers from e-tailers or recharging e-wallets. Given the sophistication of the campaign, organized crime groups are the likely perpetrators. ([Phil Muncaster / Infosecurity Magazine](https://www.infosecurity-magazine.com/news/fake-government-officials-rats/?ref=metacurity.com)) **Related:** [*Group-IB*](https://www.group-ib.com/blog/social-engineering-in-action/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/image-21.png) A diagram of how the fraud is committed. Source: Group-IB. ### watchTowr researchers report that more than 4,000 unique backdoors are using expired domains or abandoned infrastructure, and many of these expose government and academia-owned hosts, setting these hosts up for hijacking by criminals. The new findings follow the watchTowr crew's earlier research, delving into abandoned and expired infrastructure. But in this case, the team also examined how the "bad guys" throw away internet domains. They also highlight how attackers have historically backdoored the web shells they provide to other miscreants, thus giving the original author of the web shell access to everything that the current user touches. These backdoored backdoors run the gamut from basic web shells to c99shell, r57shell, and China Chopper, to name a few of the "web shells that include functions to allow hackers to hack hackers. The researchers registered over 40 domains (a list of several of these web shells and associated domains is listed in the report), spun up new infrastructure, and then logged incoming requests before responding with a 404 error message. The team logged "thousands" of requests, primarily across a handful of the domains the researchers identified and re-registered. After slogging through logs of incoming requests to watchTowr's newly accrued domains, the researchers found "multiple" compromised government-owned hosts from Bangladesh, China, Nigeria, and other countries, as well as higher-education entities across Thailand, China, and South Korea. ([Jessica Lyons / The Register](https://www.theregister.com/2025/01/08/backdoored%5Fbackdoors/?ref=metacurity.com)) **Related*:* [*watchTowr*](https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/?ref=metacurity.com) ### Federal Communications Commission Chairwoman Jessica Rosenworcel called on her colleagues to "quickly" adopt rules allowing the US regulator to stage a radio spectrum auction, the proceeds of which would fund the removal from American networks of equipment made by Chinese vendors Huawei and ZTE. Work to remove and replace the kit with less risky equipment has been underway since 2021, when $1.9 billion was allocated to a “Rip and Replace” program that Congress authorized because Chinese-made devices posed a national security risk. In 2024, it emerged that the program saw just 12 percent of telcos and ISPs remove Chinese gear from their networks and that at least another $3 billion is needed to finish the job. To address this shortfall, the Spectrum and Secure Technology and Innovation Act, signed into law as part of the NDAA on December 23, 2024, expressly allowed the FCC to borrow up to $3.08 billion from the Treasury Department to fund the Rip and Replace Program fully. This loan will then be repaid with the proceeds of the AWS-3 auction, for which the FCC is now considering proposed rules. ([Jessica Lyons / The Register](https://www.theregister.com/2025/01/08/fcc%5Fchief%5Furges%5Fspectrum%5Fauction/?ref=metacurity.com)) **Related:** [*FCC*](https://docs.fcc.gov/public/attachments/DOC-408611A1.pdf?ref=metacurity.com)*,* [*Telecoms.com*](https://www.telecoms.com/regulation/fcc-eyes-quick-spectrum-auction-to-pay-for-rip-and-replace?ref=metacurity.com)*,* [*Capacity Media*](https://www.capacitymedia.com/article/fcc-chair-pushes-spectrum-auction?ref=metacurity.com)*,* [*Data Center Dynamics*](https://www.datacenterdynamics.com/en/news/fcc-chair-calls-for-swift-action-over-spectrum-auction-to-speed-up-rip-and-replace-program/?ref=metacurity.com) ### On December 30, 2024, Rivers Casino Philadelphia filed a notice of data breach with the Attorney General of Massachusetts after discovering that an unauthorized party accessed confidential information in the company’s possession. Rivers Casino explains that the incident resulted in an unauthorized party accessing consumers’ sensitive information, including their names, Social Security numbers, and bank account information. Upon completing its investigation, Rivers Casino began sending out data breach notification letters to all individuals whose information was affected by the recent data security incident. ([JD Supra](https://www.jdsupra.com/legalnews/rivers-casino-philadelphia-experiences-6163545/?ref=metacurity.com)) **Related:** [*CDC Gaming*](https://cdcgaming.com/brief/data-breach-at-rivers-casino-philadelphia-may-have-compromised-patron-information/?ref=metacurity.com)*,* [*6ActionNews*](https://6abc.com/post/lawsuits-filed-wake-rivers-casino-philadelphia-data-breach/15775195/?ref=metacurity.com)*,* [*CBS News*](https://www.cbsnews.com/philadelphia/video/rivers-casino-philadelphia-suffered-data-breach-in-2024/?ref=metacurity.com)*,* [*Philadelphia Inquirer*](https://www.inquirer.com/news/philadelphia/rivers-casino-philadelphia-data-breach-20250107.html?ref=metacurity.com)*,* [*Play Pennsylvania*](https://www.playpennsylvania.com/investigations-finds-sensitive-information-taken-in-rivers-casino-philadelphia-in-data-breach/?ref=metacurity.com) ### On January 8, 2025, PeckShieldAlert reported a significant security breach at 0xOrangeFinance, where approximately $787,000 worth of cryptocurrencies were drained from its smart contracts. The breach was detected early in the morning, and users were immediately warned to avoid interacting with any of Orange Finance's compromised protocols. The security firm emphasized the urgency of revoking all contract approvals linked to Orange Finance to prevent further unauthorized access and potential losses. The drained amount represents a significant portion of the platform's liquidity, which could lead to decreased trading volumes and affect the market's overall liquidity depth. The immediate impact on trading pairs associated with Orange Finance is expected to be severe, with potential price volatility as investors react to the news. ([Blockchain News](https://blockchain.news/flashnews/orange-finance-contracts-hacked-787k-drained?ref=metacurity.com)) **Related:** [*crypto.news*](https://crypto.news/arbitrums-largest-liquidity-manager-orange-finance-loses-840k-in-hacker-attack/?ref=metacurity.com)*,* [*Chain Catcher*](https://www.chaincatcher.com/en/article/2161372?ref=metacurity.com) ### More than 800 “potential vulnerabilities and biases” were uncovered by a Pentagon effort to spot problems with using large language models in military medical services. The Chief Digital and Artificial Intelligence Office, or CDAO, said the initiative was conducted through its Crowdsourced AI Red-Teaming Assurance Program, with help from the Program Executive Office, Defense Healthcare Management Systems, and the Defense Health Agency. It was conducted by the technology nonprofit Humane Intelligence. CDAO’s LLM pilot focused on identifying potential system weaknesses and flaws when using emerging tools for clinical note summarization and a medical advisory chatbot. DOD said more than 200 people, including clinical providers and healthcare analysts within the department, participated in the red teaming effort, which “compared three popular LLMs.” ([Edward Graham / DefenseOne](https://www.defenseone.com/technology/2025/01/dod-announces-completion-pilot-identify-medical-ai-vulnerabilities/401982/?ref=metacurity.com)) **Related:** [*Defense.gov*](https://www.defense.gov/News/Releases/Release/Article/4020407/cdao-sponsors-crowdsourced-ai-assurance-pilot-in-the-context-of-military-medici/?ref=metacurity.com) ### The hacker group Silent Crow claims to have breached Russia’s Federal Service for State Registration, Cadastre, and Cartography (Rosreestr) and published what it says is a fragment of the agency’s database. The Telegram channel Information Leaks, one of the first to report the hack, stated that the leaked portion contains nearly 82,000 records with personal details, including names, birth dates, addresses, phone numbers, emails, SNILS numbers (similar to Social Security numbers), and Rosreestr IDs of Russian citizens. An anonymous Telegram channel called Silent Crow, created in late December posted about the breach on January 6\. The group claims the published fragment includes around 90,000 entries from Russia’s Unified State Register of Real Estate. “Rosreestr has become a vivid example of how large state structures can fall in just a few days. As a result, their data, supposedly well-protected, has joined our collection,” the post said. ([Meduza](https://meduza.io/en/news/2025/01/08/hackers-claim-breach-of-russia-s-real-estate-registry-leak-alleged-database-fragment?ref=metacurity.com)) **Related:** [*UNN*](https://unn.ua/en/news/hackers-hacked-the-federal-register-and-stole-data-of-millions-of-russians?ref=metacurity.com) ### Best Thing of the Day: Not Quite a Sanction But Enough to Give Banks Pause Wall Street banks hoping to participate in Chinese battery maker CATL's secondary market listing in Hong Kong [are recalculating](https://www.ft.com/content/3ed51022-9d22-407a-a965-27a6d3b25582?ref=metacurity.com) their risk-to-reward ratios now that the Pentagon has officially banned the company's products. ### Worst Thing of the Day: The Guy Who Fact-Checked Mr. Robot Needs Your Help Marc Rogers, DEF CON's head of security, [faces tens of thousands](https://www.theregister.com/2025/01/07/def%5Fcon%5Fsecurity%5Fchief%5Finjured/?ref=metacurity.com) of dollars in medical bills following an accident that left him with a broken neck and temporary quadriplegia.His friends have established a [GoFundMe page](https://www.gofundme.com/f/support-marc-rogers-road-to-recovery?ref=metacurity.com) to help Rogers cope with the unfair and massively cruel US healthcare system. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/image-19.png) ### Bonus Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/image-22.png) ### China Has Hacked the US Government at Least Twelve Times Since 2014 URL: https://www.metacurity.com/china-has-hacked-the-us-government-at-least-twelve-times-since-2014-2/ Last updated: 2025-01-07T13:53:37.000Z *Check out my* [*latest CSO piece*](https://www.csoonline.com/article/3632164/us-military-allocated-about-30-billion-to-spend-on-cybersecurity-in-2025.html?ref=metacurity.com) *that breaks down some of the top spending items in the $30 billion allocated to the US military in the FY2025 NDAA.* --- ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/washington-dc-1624419_1280-4--1.jpg) ### Summary of the most critical infosec developments you should know today - The Pentagon published a notice in the Federal Register listing firms that it deems to be operating in the United States for, or on behalf of, the Chinese military or that contribute to China’s military buildup, including China’s largest EV battery manufacturer and its largest tech firm, which will be barred from DoD contracts starting in June 2026. - The UK government announced that creating and sharing sexually explicit "deepfakes" will become a criminal offense in Britain in a bid to tackle a surge in the proliferation of such images, mainly targeting women and girls. - The US Cybersecurity and Infrastructure Security Agency said there was "no indication" the recently reported breach at the US Treasury Department by Chinese state-sponsored threat actors had affected any other federal agency - US Treasury Secretary Janet Yellen met virtually with Chinese Vice Premier He Lifeng and raised concerns about "malicious cyber activity" carried out by Chinese state-sponsored actors. - The US state of Washington sued T-Mobile over allegations that the phone giant failed to secure the personal data of millions of state residents before an August 2021 data breach affected more than 79 million customers across the country. - The United Nations' civil aviation agency is investigating reports of a "potential information security incident" following a claim that tens of thousands of its records were stolen. - Sources say Chinese-state-sponsored hackers penetrated the executive branch of the Philippines government and stole sensitive data as part of a yearslong campaign. - Ontario Provincial Police in Canada are investigating an unspecified "cyber incident" that has affected the Kingston Police Service. - The Fraunhofer Institute for Industrial Engineering IAO (Fraunhofer IAO) in Stuttgart, Germany, disclosed that its systems were targeted in a ransomware attack on 27 December 2024. - Argentina’s airport security police (PSA) fell victim to a cyberattack that reportedly compromised its officers' and civilians' personal and financial data. - California resident Ken Liem is suing three Asia-based banks over allegations they failed to conduct basic checks that might have prevented crypto scammers from defrauding him of nearly $1 million. - Researchers at Kaspersky report that new variants of the Eagerbee malware framework are being deployed against government organizations and internet service providers (ISPs) in the Middle East. - Researchers at Cyfirma report that a new Android data-stealing malware named ‘FireScam’ is being distributed as a premium version of the Telegram app via phishing websites on GitHub that mimic the RuStore, Russia's app market for mobile devices. - Firmware in cellular routers, secure routers, and network security appliances made by Moxa are vulnerable to a pair of high-severity bugs that can escalate privileges for an attacker, give root-level access, or allow for unauthorized execution of commands. - According to newly released data from Telegram, which has also become a hotbed for serious criminal activity, the popular social network and messaging app provided US authorities with data on more than 2,200 users last year. - In late December 2024, New York Governor Kathy Hochul signed two bills into law updating the state's data breach notification requirements under its general business law. --- *As a reminder, on Tuesdays and Thursdays, our premium subscribers have full access to our original content, expansive summaries, intelligently clustered related articles, our best and worst things of the day, and our customary closing thoughts.* *So, please consider upgrading your subscription today to access this content along with Metacurity's full archives.* [Upgrade my subscription](#/portal/signup) --- ## **There have been thirty breaches of the US federal government since 1996, twelve attributable to China** According to Metacurity’s research, the attack on the US Treasury by a Chinese state-sponsored threat actor is just the latest in a string of thirty significant breaches of federal government organizations or adjacent systems (see list and description below) that stretches back to 1996 when the Russian hacking group Turla, run by Russia’s FSB intel agency, launched a massive info-stealing operation on US military targets in an operation known as Moonlight Maze. An examination of the thirty publicly reported breaches reveals the following observations: - Nineteen of the breaches were affiliated with foreign threat actors, although in some cases, it’s not clear if the threat actor was tied to a foreign government. - **China tops the list of countries associated with these breaches, with twelve of the breaches either confirmed or strongly suspected as flowing from China.** - Russia is the second most frequent source of foreign-tied cyber incidents, with five of the twenty-seven breaches coming from Russian threat actors, starting with Moonlight Maze. - Two cases were linked, at least in press reports, to unknown foreign actors. - Vietnam and Iran were each associated with one major incident. - Nine major government breaches, as reported by the press (with the likelihood that intel agencies ultimately determined the culprits), were associated with unknown actors. - Teen hackers and an operational error each accounted for one incident. - One major federal government incident was due to a non-state-affiliated hacker group. (The Dark Overlord). Check out our timeline and breach summaries below for more details on these breaches. If any significant incident escaped our attention or something looks amiss, please drop us a line at info@metacurity.com. _This post is for paying subscribers only._ ### New Details Emerge About China's Hack of Guam Power Authority, Telco Infiltrations URL: https://www.metacurity.com/us-government-concerns-over-chinese-state-hacking-incidents-escalate-2/ Last updated: 2025-01-06T13:16:33.000Z US Treasury sanctions Flax Typhoon-linked Chinese company, Taiwan says Chinese cyberattacks doubled in 2024, Commerce launches rule-making to ban Chinese drones, Ukraine attacked Russian freight car servicing company, Windows 10 security fiasco looms, Tenable CEO passed away, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Weeks of 12/18/24, 12/25/24 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-weeks-of-12-18-24-12-25-24/ Last updated: 2025-01-04T14:13:08.000Z Gamers are ripe for cybercriminal exploitation, How a young small-town mayor became a pig butchering boss, How a pig butchering kingpin eludes law enforcement, Placing cybercrime on par with nation-state threat actors, Are UK intel agencies more open to the press now? _This post is for subscribers only._ ### Senior US Treasury Leaders Were Hacked in Chinese APT Breach URL: https://www.metacurity.com/senior-us-treasury-leaders-were-hacked-in-chinese-apt-breach/ Last updated: 2025-01-03T13:54:08.000Z Apple to pay $95m for violating Siri users' privacy, $125m in illicit financial transactions frozen since August, Regressive laws cause Pornhub blocking across US South, NTT Docomo hit by DDoS attack, MetLife denies RansomHub attack claim, 3m mail servers vulnerable to sniffing attacks, much more _This post is for paying subscribers only._ ### Twas the season for shaky cyber reporting and holiday season infosec news recap URL: https://www.metacurity.com/twas-the-season-for-shaky-cyber-reporting-and-holiday-season-infosec-news-recap/ Last updated: 2025-01-02T12:48:43.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2025/01/sparkling-wine-7626984_1280-1.jpg) Image by Guido Reimann from Pixabay Happy New Year to all our readers! Starting today and as long as it makes sense, the whole issue of Metacurity will be available only to our paid subscribers on Tuesdays and Thursdays. Our goal is to introduce original content on these days that precedes the usual content you've come to expect from Metacurity, namely concise summaries and related links regarding the crucial infosec developments you need to know. Our premium subscribers will have access to the more expansive summaries and relevant related articles on these two days, along with our best and worst things of the day and our customary closing thoughts. So, please take this opportunity to sign up for a monthly or annual premium subscription and gain access to all of Metacurity's content, including unlimited access to our archives. [Upgrade my subscription today!](#/portal/signup) We won't leave our free subscribers entirely high and dry, though. Before you hit the paywall on these Tuesday/Thursday issues, we will offer a quick, scannable summary of the most critical infosec developments. So today, for example, these summaries encompass the following incidents: - In a letter to the US Senate Banking Committee, the US Treasury Department said it had been hacked by a Chinese state-sponsored actor who gained access to government workstations and unclassified documents through a third-party security contractor, with sources later saying the specific targets were the Office of Foreign Assets Control (OFAC) as well as the Office of the Treasury Secretary. - Offering no evidence or analysis about how they achieved a critical feat,AT&T, Verizon Communications, and Lumen acknowledged that the China-linked Salt Typhoon hacking operation had hit them, but they managed to eject the threat actors, and their networks are now clear of intrusion. - During a briefing with reporters, Anne Neuberger, the US deputy national security advisor for cyber and emerging technology, said that under a proposed HHS rulemaking, healthcare organizations may be required to bolster their cybersecurity to better prevent sensitive information from being leaked by cyberattacks like the ones that hit Ascension and UnitedHealth. - In a precedent-setting ruling, Northern California federal judge Phyllis Hamilton found NSO Group, the developer of the powerful Pegasus spyware, liable for its role in infecting devices belonging to 1,400 WhatsApp users. - Eagle S, a ship that is part of Russia's shadow fleet, an assemblage of aged tankers created to carry Russian crude oil around the world covertly, was not only suspected of damaging an underwater electricity cable on Christmas Day, it was also equipped with special transmitting and receiving devices that were used to monitor naval activity, according to a source with direct involvement in the ship, which Finnish police have since detained. - Federal authorities arrested and indicted Cameron John Wagenius, a US Army communications specialist recently stationed in South Korea, on suspicion of being Kiberphant0m, a cybercriminal who has been selling and leaking sensitive customer call records stolen earlier this year from AT&T and Verizon. - US authorities charged Rostislav Panev, a dual Russian and Israeli national, in connection with his alleged participation with the LockBit ransomware group and are seeking his extradition. - Hospital operator Ascension told Maine's state attorney general that a ransomware attack earlier this year affected nearly 5.6 million people. - The US Federal Bureau of Investigation (FBI), along with other agencies, including the Department of Defense Cyber Crime Center (DC3) and Japan’s National Police Agency (NPA), published a report explaining how malicious actors from North Korea stole a massive $305 million from Japanese crypto exchange DMM, earlier this year in May. - The US Treasury Department announced it had imposed sanctions on entities in Iran and Russia, accusing them of attempting to interfere in the 2024 US election. - Hyperliquid, a crypto-derivatives trading platform, suffered its biggest-ever daily outflow as traders rushed to remove funds amid concern that North Korean hackers were trading on the exchange. - Rhode Island Gov. Daniel McKee said cybercriminals who hacked Rhode Island’s system for health and benefits programs have released files to a site on the dark web, a scenario the state has been preparing for. - The cybercriminal IntelBroker leaked more data stolen from a Cisco DevHub instance, and the tech giant has confirmed its authenticity, stating that it originated from a recently disclosed security incident. - A DDoS attack disrupted Japan Airlines operations the day after Christmas, causing delays to both domestic and international flights. - The South Korean government sanctioned over a dozen individuals and one organization for a wide-ranging global scheme to fund North Korea’s nuclear and missile programs by impersonating IT workers abroad, stealing cryptocurrency, and facilitating cyberattacks. - According to a report from Der Spiegel, the VW Group stored sensitive information for 800,000 electric vehicles from various brands on a poorly secured and misconfigured Amazon cloud storage system, leaving the digital door open for months. - The Clop ransomware gang started extorting victims of its Cleo data theft attacks and announced on its dark web portal that 66 companies had 48 hours to respond to the demands. - Data-loss prevention startup Cyberhaven says hackers published a malicious update to its Chrome extension that could steal customer passwords and session tokens, according to an email sent to affected customers, who may have been victims of this suspected supply-chain attack. - Fortinet Inc.’s FortiGuard Labs issued a report detailing the activities of two different botnets observed through October and November that are being spread through vulnerabilities in D-Link Systems Inc. devices. - Pittsburgh’s transit authority was hit with a ransomware attack, causing temporary disruptions to the city’s public transportation system. - The pro-Russian, supposedly hacktivist group NoName057 attacked the websites of Milan's two airports, Malpensa and Linate, causing inconvenience for users who wanted to check incoming and outgoing flights but did not disrupt flights. - VulnCheck discovered a critical new vulnerability (CVE-2024-12856) affecting Four-Faith industrial routers (F3x24 and F3x36), with evidence of active exploitation in the wild. - According to blockchain investigator Taylor Monahan, crypto hackers have devised a new sophisticated scam in which they target individuals by advertising roles with salaries ranging between $200,000 and $350,000, luring them into downloading malware that ultimately enables access to crypto accounts. - Blockchain security firm SlowMist warned investors that hackers had been targeting crypto users with a sophisticated phishing scam to access their sensitive data using a phishing attack disguised as Zoom meeting links, with some victims installing malicious software and losing assets worth millions of dollars. - A hack exposed energy giant Duke Energy's customers’ personal and account information in May. - Tennessee-based American Addiction Centers is notifying more than 422,000 people that their personal information was stolen in a recent data breach. - Palo Alto Networks is warning that hackers are exploiting the CVE-2024-3393 denial of service vulnerability to disable firewall protections by forcing it to reboot. - The Ukrainian government reported that a Russian cyberattack on Ukraine's justice ministry registries caused a shutdown of online services for marriages and other matters, but no data appears to have been leaked or stolen. - CloudSEK’s TRIAD team identified critical security vulnerabilities and risks from misusing Postman Workspaces, a popular cloud-based API development and testing platform. Please note that student and non-profit organizations may be eligible for complimentary premium subscriptions. Drop me an email at cynthia \[at\] Metacurity.com to discuss this option. Happy reading, and again, consider upgrading your subscription to gain access to all of Metacurity's content. [Upgrade my subscription today!](#/portal/signup) --- ## Twas the season for shaky infosec reporting Writing about cybersecurity is a career fraught with feints, switchbacks, uncertainty, and confusion, given the often incomplete information available to infosec journalists. Not to mention that cybersecurity is frequently under the control of unreliable threat actors and is highly technical, political, and corporate agenda-driven, which can cause even the best security experts to hedge or misdirect their messages, leaving frustrated reporters making the best of what is frequently a muddle. Still, during this past holiday season, two press reports about Chinese threats propagated a spate of follow-on articles that led readers to wrong or incomplete conclusions. These shaky reports might have been avoided if greater care had been taken to dig a little deeper in the case of one set of articles and, in the case of the second set of articles, if a more skeptical journalistic eye had been applied to corporate statements. _This post is for paying subscribers only._ ### North Korean Hackers Doubled the Digital Assets They Stole in 2024 URL: https://www.metacurity.com/north-korean-hackers-doubled-the-digital-assets-they-stole-in-2024/ Last updated: 2024-12-20T14:59:41.000Z LockBit member may be extradited to US, Romanian lands 20 years for NetWalker attacks, Play claims attack on Krispy Kreme, Israel says AE jumped the gun on Paragon buy, Juniper warns of botnet campaign, BeyondTrust hit with attack, BadBox infections grow, Noblr fined $500K for breach, much more _This post is for paying subscribers only._ ### CISA Advises Senior Officials to Use Only E2EE Communications URL: https://www.metacurity.com/cisa-advises-senior-officials-to-use-only-e2ee-communications/ Last updated: 2024-12-19T14:07:24.000Z Raccoon Stealer gang member gets five years, Phishers use Google Forms to gain credibility, Over 25K publicly accessible SonicWall devices are vulnerable to critical severity flaws, Midnight Blizzard performs MiTM attacks, Hackers attacked Nigerian bureau, Razzlekhan's hubby speaks, much more _This post is for paying subscribers only._ ### Russian Prosecutor Accuses Recorded Future of Cooperation in Cyberattacks Against Moscow URL: https://www.metacurity.com/russian-prosecutor-accuses-recorded-future-of-cooperation-in-cyberattacks-against-moscow/ Last updated: 2024-12-18T14:32:41.000Z US eyes ban on TP-Link routers, CISA issues cloud security directive, DHS worries about SS7 security holes in telecom networks, Dutch fine Netflix $5m, EU authority fines Meta $263m over 2018 hack, Interpol wants folks to stop saying pig butchering, Ledger phishing campaign underway, and much more _This post is for paying subscribers only._ ### US Proposes Ban on China Telecom Americas in Response to Salt Typhoon Hack URL: https://www.metacurity.com/us-proposes-ban-on-china-telecom-americas-in-response-to-salt-typhoon-hack/ Last updated: 2024-12-17T14:01:00.000Z LastPass hackers steal another $5.36m, BlackBerry sells Cylance for pennies on the dollar, TikTok withholds $1b to pay EU data privacy fines, CISA seeks comment on incident response plan, TN is first state to sue Change Healthcare, HiatusRAT hunts for web cameras and DVRs, and much more _This post is for paying subscribers only._ ### Serbia Used Cellebrite to Unlock Phones and Implant Novel Spyware Called NoviSpy URL: https://www.metacurity.com/serbia-used-cellebrite-to-unlock-phones-and-implant-novel-spyware-called-novispy/ Last updated: 2024-12-16T14:45:08.000Z Rhode Island hit with nasty ransomware attack, Hunters hit Telecom Namibia with ransomware attack, CISA warns water facilities of HMI attacks, Researchers devise digital license plate jailbreaks, Clop cops to Cleo attacks, Cybercrims target YouTube creators in phishing attacks, and much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 12/7/24 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-12-7-24/ Last updated: 2024-12-14T13:24:47.000Z Putin's most powerful and shadowy spy agency, A former New York District Attorney PI who relied on a hack-and-leak operation, How hackers can bring down the power grid via solar panels, Predatory Sparrow's faux hacktivist pose, VPNs are the resistance tool of choice, Battling dark web assassins _This post is for subscribers only._ ### US Indicts 14 DPRK Fake IT Workers, Offers $5 Million Reward URL: https://www.metacurity.com/us-indicts-14-dprk-fake-it-workers-offers-5-million-reward/ Last updated: 2024-12-13T14:31:07.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/dprkitworkers-1.png) --- *Sponsor Message* ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-57.png) In today's digital landscape, protecting your software supply chain from rising threats is essential. This free whitepaper offers five key strategies for enhancing container security, one of the main attack surfaces in dynamic software development practices. Learn about using SBOMs for transparency, shifting vulnerability detection left, and automating policy enforcement, all for a superior developer experience and securing third-party code. [Learn More](https://get.anchore.com/best-practices-for-container-security/?utm%5Fsource=partner&utm%5Fmedium=metacurity&utm%5Fcampaign=2024-october-newsletter&utm%5Fcontent=whitepaper) *Interested in reaching the elite audience of cybersecurity decision-makers, public policy professionals, and journalists who read Metacurity? Send an email to info \[at\] Metacurity.com with the subject line "Sponsorship."* --- ### The US offered a $5 million reward for information about an alleged scheme in which North Korean technology workers got jobs at unsuspecting US companies and then stole their trade secrets for ransom, with the proceeds used to fund Pyongyang's weapons programs. The US State Department said about 130 North Korean workers got IT jobs at US companies and nonprofits from 2017 to 2023 and generated at least $88 million that Pyongyang used for weapons of mass destruction. The US said that part of the total was the workers' compensation from the employers, which ultimately went to the North Korean government. The companies were not identified. The State Department said it sought information on two sanctioned North Korean companies, China-based Yanbian Silverstar Network Technology, and Russia-based Volasys Silverstar, that it handled the workers. The US Justice Department announced indictments of fourteen North Koreans accused of operating and working for the two companies as part of the scheme. Operating from either China or Russia, the workers stole sensitive company information, including proprietary source computer code, and threatened to leak it unless the employer made an extortion payment, the government said. The 14 people were charged with wire fraud, money laundering, and identity theft, among other offenses. ([Susan Heavey and AJ Vicens / Reuters](https://www.reuters.com/world/us-claims-north-korea-put-workers-us-companies-extort-money-weapons-2024-12-12/?ref=metacurity.com)) ***Related:*** [*Justice.gov*](https://www.justice.gov/opa/media/1380081/dl?ref=metacurity.com)*,* [*State Department*](https://rewardsforjustice.net/rewards/yanbian-silverstar-and-volasys-silverstar/?ref=metacurity.com)*,* [*Cyberscoop*](https://cyberscoop.com/court-indicts-14-north-korean-it-workers-tied-to-88-million-in-illicit-gains/?ref=metacurity.com)*,* [*Euronews*](https://www.euronews.com/2024/12/13/north-korean-it-workers-indicted-for-funnelling-us-money-to-pyongyang?ref=metacurity.com)*,* [*NK News*](https://www.nknews.org/2024/12/us-indicts-14-north-korean-it-workers-for-raising-funds-for-weapons-programs/?ref=metacurity.com)*,* [*Associated Press*](https://apnews.com/article/north-korea-it-workers-indictments-7beb2f611489da09fe36ee14736b28b9?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/us-offers-5-million-for-info-on-north-korean-it-worker-farms/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/doj-indicts-14-north-koreans-earning-88-million-at-us-firms?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/fake-it-workers-funneled-millions-to-north-korea-doj-says/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2024/12/13/doj%5Fdpkr%5Ffake%5Ftech%5Fworker%5Findictment/?ref=metacurity.com)*,* [*UPI*](https://www.upi.com/Top%5FNews/World-News/2024/12/12/5-million-in-n-koran-IT-scheme/2021734042685/?ref=metacurity.com)*,* [*BBC News*](https://www.bbc.com/news/articles/cpdnz3elwzvo?ref=metacurity.com) ### Albanian law enforcement seized the Rydox cybercrime marketplace and arrested three administrators in collaboration with international partners. Kosovo nationals Ardit Kutleshi, Jetmir Kutleshi, and Shpend Sokoli were arrested by Kosovo law enforcement and Albania's Special Anti-Corruption Body (SPAK). The US Justice Department indicted the first two for involvement in Rydox's operations, and they're awaiting extradition to the United States. Ardit Kutleshi and Jetmir Kutleshi face multiple charges related to their Rydox admin roles, including two counts of identity theft, conspiracy to commit identity theft, aggravated identity theft, access device fraud, and money laundering. If convicted, each could receive five years for each charge, 10 years for access device fraud, and up to 20 years for money laundering. Since February 2016, Rydox marketplace sellers have been involved in over 7,600 sales of credit card information, login credentials, and personal information such as social security numbers, names, and addresses stolen from thousands of U.S. citizens and various cybercrime tools and devices. Rydox also offered for sale over 321,000 other "cybercrime products" to more than 18,000 users, including tools and materials for committing cyber crimes, such as tutorials and spam tools. According to the indictment, registered users had to deposit a sum of cryptocurrency into their accounts before making a purchase via Perfect Money, Ethereum, Litecoin, Bitcoin ("BTC"), Monero, Ripple, Tron, or Verge payments deposited into a cryptocurrency wallet controlled by Rydox. They could use the funds to purchase illicit products, services, tools, and programs from Rydox sellers. However, once the funds were deposited, they were under the defendants' control, who controlled the Rydox cryptocurrency wallets. The operation was carried out with the help of the FBI's Pittsburgh Office, Albania's National Bureau of Investigation (BKH), the Albanian Directorate of Cybercrime Investigation, the Kosovo Special Prosecutor's Office, the Kosovo Police, and the Malaysian Royal Police. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/police-shuts-down-rydox-cybercrime-market-arrests-3-admins/?ref=metacurity.com)) **Related:** [*Spak.gov.al*](https://spak.gov.al/njoftim-per-shtyp-date-12-12-2024/?ref=metacurity.com)*,* [*Justice.gov*](https://www.justice.gov/opa/pr/rydox-cybercrime-marketplace-shut-down-and-three-administrators-arrested?ref=metacurity.com)*,* [*Cyberscoop*](https://cyberscoop.com/rydox-cybercriminal-marketplace-seized-doj-albania-kosovo/?ref=metacurity.com)*,* [*Soyacincau*](https://soyacincau.com/2024/12/13/pdrm-fbi-seize-rydox-cybercrime-marketplaces-servers-in-kuala-lumpur/?ref=metacurity.com)*,* [*Balkan Insight*](https://balkaninsight.com/2024/12/13/kosovo-citizen-faces-extradition-to-us-for-running-online-criminal-market/?ref=metacurity.com)*,* [*Albanian Daily News*](https://albaniandailynews.com/news/spak-finalizes-operation-against-cyber-crime-rydox-?ref=metacurity.com)*,* [*Pamfleti*](https://pamfleti.net/english/aktualitet/shisnin-te-dhenat-e-amerikaneve-ne-internet-spak-godet-tregun-e-palig-i257352?ref=metacurity.com)*,* [*CNA.al*](https://www.cna.al/english/aktualitet/spak-godet-tregun-kibernetik-arrestohen-3-administratoret-i417785?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-51.png) ### Spanish police, working with colleagues in Peru, conducted a simultaneous crackdown on a large-scale voice vishing scam ring in the two countries, arresting 83 individuals. Thirty-five of the arrested people were located across Spain, including in Madrid, Barcelona, Mallorca, Salamanca, and Vigo, and another 48 were arrested in Peru. The ringleader was also apprehended in Spain during the 29 simultaneous raids conducted by the cooperating police forces, which seized cash, mobile phones, computers, and documents. According to the Spanish police (Policia Nacional), the scammers operated a large call operation that employed 50 people in three distinct call centers, defrauding at least 10,000 people and making €3,000,000 ($3.15M) in proceeds. The calling agents used stolen databases, pre-written social engineering, and scripts to trick the call recipients into giving away their sensitive banking information. To make the calls appear legitimate, the agents used caller spoofing technology, making their number and caller name match those of the official bank they impersonated, adding credibility to the process. The bait was an alert about unauthorized ATM withdrawals, directing victims to go through a process of fake account verification and give away their one-time passcodes. Once the cash was withdrawn, the operators kept about 20% and 30%, and the rest was sent to the organization in Peru. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/?ref=metacurity.com)) **Related:** [*Policia Nacional*](https://www.policia.es/%5Fes/comunicacion%5Fprensa%5Fdetalle.php?ID=16409&ref=metacurity.com) ### The German Federal Office for Information Security ( BSI ) said it was able to disrupt and sinkhole around 30,000 devices infected with the BadBox malware across Germany, including digital picture frames or media players equipped with the malware at the factory. BSI said that in all cases known to it, the BadBox malware was already installed on the respective devices, which typically have outdated Android versions, at the time of purchase. BadBox can create undetected accounts for email and messenger services, which can be used to spread fake news. The malware also has a built-in function for advertising fraud; it can surf websites in the background. It can also serve as a so-called residential proxy, which usually allows criminals to disguise its origin, enabling cyberattacks or the distribution of illegal content. The BSI has now been able to block communication between infected devices and control servers with a sinkholing measure, registering the domains used for malware communication and redirecting the messages to its servers. ([Dirk Knop / Heise Online](https://www.heise.de/en/news/BSI-paralyzes-communication-of-30-000-BadBox-drones-10197457.html?ref=metacurity.com)) **Related:** [*BSI*](https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2024/241212%5FBadbox%5FSinkholing.html?ref=metacurity.com)*,* [*Cybernews*](https://cybernews.com/security/iot-infected-with-pre-installed-malware-germany-warns/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/germany-sinkholes-botnet-of-30000-badbox-infected-devices/?ref=metacurity.com) ### The US Justice Department announced that Afeez Akinloye, a 42-year-old Nigerian, was extradited from South Africa to Nebraska for defrauding real estate buyers and sellers of nearly $2 million. Akinloye appeared in a Nebraska court to face conspiracy charges for committing wire fraud and access device fraud. Between September 2016 and June 2017, Akinloye allegedly participated in a business email compromise (BEC) scheme related to real estate transactions. During the stated period, the Nigerian and other members of his gang took advantage of their insider knowledge of real estate transactions. They sent fraudulent emails to their unsuspecting victims, instructing them to wire funds to accounts they could easily access, defrauding them of nearly $2 million. ([Foundation for Investigative Journalism](https://fij.ng/article/nigerian-extradited-from-south-africa-to-the-us-over-2m-real-estate-fraud/?ref=metacurity.com)) **Related:** [*Justice.gov*](https://www.justice.gov/usao-ne/pr/nigerian-extradited-district-nebraska-business-email-compromise-fraud-scheme?ref=metacurity.com)*,*[](https://fij.ng/article/nigerian-extradited-from-south-africa-to-the-us-over-2m-real-estate-fraud/?ref=metacurity.com)[*The Street Journa*](https://thestreetjournal.org/nigerian-extradited-from-south-africa-to-us-to-face-fraud-charges/?ref=metacurity.com)*l,* [*Tori News*](https://www.tori.ng/news/256375/nigerian-man-extradited-from-south-africa-to-us-fo.html?ref=metacurity.com)*conspiracy charges* ### Amazon delayed the deployment of Microsoft's cloud-based Office suite for a year as the two companies worked to resolve Amazon's concerns about the security of the bundle of email and productivity software. Amazon paused the rollout after Microsoft discovered Russia-linked hacker group Midnight Blizzard had gained access to some of its employees’ email accounts. After conducting its own analysis of the software, Amazon asked for changes to guard against unauthorized access and create a more detailed accounting of user activity in the apps, some of which Microsoft also markets as Office 365. “We deep-dived into O365 and all of the controls around it and we held – just as we would any of our service teams within Amazon – we held them to the same bar,” said CJ Moses, Amazon’s chief information security officer. Moses’s team gave Microsoft security chief Charlie Bell – a former Amazon engineering executive – a list of requested enhancements, and engineers from both companies have spent months working on those changes. “We believe we’re in a good place to start redeployment next year,” Moses said in an interview last week at Amazon Web Services’ re:Invent conference. ([Matt Day / Bloomberg](https://www.bloomberg.com/news/articles/2024-12-12/amazon-paused-rollout-of-microsoft-office-for-a-year-after-hacks?ref=metacurity.com)) **Related*:* [*WinBuzzer*](https://winbuzzer.com/2024/12/12/amazon-stopped-1-billion-microsoft-365-rollout-over-cybersecurity-concerns-xcxwbn/?ref=metacurity.com)*,* [*Runtime*](https://www.runtime.news/how-aws-hopes-to-solve-generative-ais-last-mile-problem/?ref=metacurity.com)*,* [*Techzine*](https://www.techzine.eu/news/security/127123/amazon-delays-introduction-of-microsoft-365-after-hacks/?ref=metacurity.com)*,* [*Channelnews*](https://www.channelnews.com.au/amazon-delayed-rollout-of-microsoft-office-over-security-concerns/?ref=metacurity.com) --- *In this generous giving season, please consider supporting Metacurity with an upgraded subscription. Thank you* [Upgrade me](#/portal/account/plans) --- ### Yahoo laid off around 25% of its cybersecurity team, known as The Paranoids, over the last year. The company has laid off or lost through attrition 40 to 50 people from a total of 200 employees in the cybersecurity team since the start of 2024, according to multiple current and former Yahoo employees. The Paranoids are not the only team affected by the layoffs. Valeri Liborski, who was appointed Yahoo’s chief technology officer in September, sent an email this week to employees announcing changes across the broader technology unit, including enterprise productivity and core services. ([Zack Whittaker / TechCrunch](https://techcrunch.com/2024/12/12/yahoo-cybersecurity-team-sees-layoffs-outsourcing-of-red-team-under-new-cto/?ref=metacurity.com)) **Related:** [*Slashdot*](https://tech.slashdot.org/story/24/12/12/210234/yahoo-cybersecurity-team-sees-layoffs-outsourcing-of-red-team-under-new-cto?ref=metacurity.com) ### Microsoft’s Recall feature, which recently made its way back to Windows Insiders after having been pulled from test builds back in June due to security and privacy concerns, captures credit card numbers, usernames, and passwords typed into a Windows Notepad window despite having filters that are supposed to prevent it from recording any app or website that is showing credit card numbers, social security numbers, or other important financial or personal information. It also captured an HTML web page that explicitly asked users to " enter their credit card number below.” The form had fields for credit card type, number, CVC, and expiration date. However, Recall refused to capture the credit card fields on the payment pages of two online stores, Pimoroni and Adafruit. ([Avram Piltch / Tom's Hardware](https://www.tomshardware.com/software/windows/microsoft-recall-screenshots-credit-cards-and-social-security-numbers-even-with-the-sensitive-information-filter-enabled?ref=metacurity.com)) **Related:** [*Windows Copilot News*](https://windowscopilot.news/2024/12/13/has-microsoft-lost-the-ai-wars/?ref=metacurity.com)***,*** [*Windows Copilot News*](https://windowscopilot.news/?ref=metacurity.com)*,* [*Laptop Mag*](https://www.laptopmag.com/ai/microsoft-recall-ai-security-flaw-credit-card?ref=metacurity.com)*,* [*XDA Developers*](https://www.xda-developers.com/new-and-improved-microsoft-recall-privacy-nightmare/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/2024/12/12/24319609/microsoft-recall-hands-on-notepad?ref=metacurity.com)*,* [*Tom's Guide*](https://www.tomsguide.com/computing/windows-operating-systems/microsoft-recall-caught-capturing-credit-card-and-social-security-numbers-despite-reassurances-it-wont?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/computing/microsoft-recall-continued-security-problems/?ref=metacurity.com)*,* [*WinBuzzer*](https://winbuzzer.com/2024/12/12/microsofts-windows-recall-ai-feature-still-has-severe-privacy-issues-xcxwbn/?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=42400935&ref=metacurity.com)*,* [*r/pcmasterrace*](https://www.reddit.com/r/pcmasterrace/comments/1hctgf3/toms%5Fhardware%5Fmicrosoft%5Frecall%5Fscreenshots%5Fcredit/?ref=metacurity.com)*,* [*r/privacy*](https://www.reddit.com/r/privacy/comments/1hcviy7/microsoft%5Frecall%5Fscreenshots%5Fcredit%5Fcards%5Fand/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1hcu1wc/microsoft%5Frecall%5Fscreenshots%5Fcredit%5Fcards%5Fand/?ref=metacurity.com)*,* [*r/Windows11*](https://www.reddit.com/r/Windows11/comments/1hcpfm2/microsoft%5Frecall%5Fscreenshots%5Fcredit%5Fcards%5Fand/?ref=metacurity.com)*,* [*Slashdot*](https://slashdot.org/story/24/12/12/2121238/microsoft-recall-screenshots-credit-cards-social-security-numbers?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-52.png) (Image credit: Future) ### Researchers at WPScan say that hackers are exploiting a critical vulnerability in the "Hunk Companion" plugin to install and activate other plugins with exploitable flaws directly from the WordPress.org repository. By installing outdated plugins with known vulnerabilities with available exploits, the attackers can access a large pool of flaws that lead to remote code execution (RCE), SQL injection, cross-site scripting (XSS) flaws, or create backdoor admin accounts. According to WordPress.org stats, Hunk Companion is currently used by over 10,000 WordPress sites, so it's a relatively niche tool in the space. The critical vulnerability was discovered by WPScan researcher Daniel Rodriguez and is tracked as CVE-2024-11972\. The flaw allows the arbitrary installation of plugins using unauthenticated POST requests. WPScan reported it to Hunk Companion, with a security update addressing the zero-day flaw released yesterday. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hunk-companion-wordpress-plugin-exploited-to-install-vulnerable-plugins/?ref=metacurity.com)) **Related:** [*WPScan*](https://wpscan.com/blog/unauthorized-plugin-installation-activation-in-hunk-companion/?ref=metacurity.com)*,* [*Ars Technica*](https://arstechnica.com/security/2024/12/thousands-of-sites-remain-unpatched-against-actively-exploited-wordpress-plugin-bug/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/hunk-companion-wp-query-console-vulnerabilities-chained-to-hack-wordpress-sites/?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/another-major-wordpress-plugin-has-been-hacked-to-try-and-hijack-your-sites?ref=metacurity.com) ### Byte Federal, one of the biggest Bitcoin ATM operators in the United States, suffered a significant data breach that potentially affected 58,000 customers. Florida-based Byte Federal submitted a filing with Maine’s attorney general, reporting a security breach resulting in unauthorized access to its clients’ data. Byte Federal said it discovered the attack on Nov. 18, more than 30 days after it occurred on Sept. 30\. A bad actor exploited a vulnerability in software provided by a third party. After detecting the incident, the Bitcoin ATM operator immediately shut down its platform and assured customers that no user assets or funds had been compromised. Byte Federal said that the bad actor attempted to gain unauthorized access to the personal information of as many as 58,000 customers, including 111 Maine residents. The potentially exposed data included names, dates of birth, addresses, phone numbers, email addresses, government-issued IDs, social security numbers, transaction activity, and photographs of users. Following the breach, Byte Federal performed a hard reset on all customer accounts, sending a notice of the incident. The platform has also updated its internal passwords, password management system, tokens, and keys to prevent any further unauthorized access. The firm also urged customers to reset their login credentials and said they may be asked to verify their personal data and confirm their identities for their protection. ([Helen Partz / Cointelegraph](https://cointelegraph.com/news/bitcoin-atm-byte-federal-data-breach?ref=metacurity.com)) **Related:** [*Office of the Maine Attorney General*](https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/8cd909c1-a046-4ac7-b845-35c7795894cc.html?ref=metacurity.com)*,* [*ByteFederal*](https://www.bytefederal.com/files/Consumer%20Breach%20Notification%20Letter.pdf?ref=metacurity.com)*,* [*CCN*](https://www.ccn.com/news/technology/byte-federal-data-breach/?ref=metacurity.com)*,* [*Crypto News Flash*](https://www.crypto-news-flash.com/byte-federal-data-breach-58000-users-info-compromised/?ref=metacurity.com)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/bitcoin-atm-firm-byte-federal-hacked-via-gitlab-flaw-58k-users-exposed/?ref=metacurity.com)*,* [*Crypto Basic*](https://thecryptobasic.com/2024/12/12/bitcoin-atm-giant-byte-federal-reports-data-breach-affecting-58000-users/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2024/12/12/bitcoin-atm-giant-byte-federal-says-58000-users-personal-data-compromised-in-breach/?ref=metacurity.com) ### Claroty's Team82 researchers report that Iranian threat actors are utilizing a new malware named IOCONTROL to compromise Internet of Things (IoT) devices and OT/SCADA systems used by critical infrastructure in Israel and the United States. Routers, programmable logic controllers (PLCs), human-machine interfaces (HMIs), IP cameras, firewalls, and fuel management systems are among the targeted devices. The malware's modular nature allows it to compromise various devices from various manufacturers, including D-Link, Hikvision, Baicells, Red Lion, Orpak, Phoenix Contact, Teltonika, and Unitronics. The researchers say it's a nation-state cyberweapon that can cause significant disruptions in critical infrastructure. Given the ongoing geopolitical conflict, IOCONTROL is currently used to target Israel and U.S. systems, like Orpak and Gasboy fuel management systems. The tool is reportedly linked to an Iranian hacking group known as CyberAv3ngers, who have shown interest in attacking industrial systems. OpenAI also recently reported that the threat group uses ChatGPT to crack PLCs, develop custom bash and Python exploit scripts, and plan its post-compromise activity. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/new-iocontrol-malware-used-in-critical-infrastructure-attacks/?ref=metacurity.com)) **Related:** [*Claroty*](https://claroty.com/team82/research/inside-a-new-ot-iot-cyber-weapon-iocontrol?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/news/iran-linked-iocontrol-malware-targets-critical-iot-ot-infrastructure-in-israel-us/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/iranian-hackers-use-iocontrol-malware-to-target-ot-iot-devices-in-us-israel/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/malware-nation-sate-industrial/?ref=metacurity.com) ### Aqua Security researchers discovered hundreds of thousands of servers running Prometheus open source monitoring software on the open Web are exposing passwords, tokens, and opportunities for denial of service (DoS) and remote code execution. Prometheus is used widely by organizations to monitor the performance of their applications and cloud infrastructure. However, as noted in its documentation, "It is presumed that untrusted users have access to the Prometheus HTTP endpoint and logs. They have access to all time series information in the database, plus various operational/debugging information." Many users are apparently either unaware of the ways in which Prometheus is exposed by default or don't realize the value of the data that's exposed along the way. Using Shodan, researchers from Aqua Nautilus discovered more than 40,000 exposed Prometheus servers and more than 296,000 exposed "exporters." The researchers found sensitive data in those servers and exporters and opportunities for "repojacking" and DoS attacks. The researchers found sensitive data in those servers and exporters and opportunities for "repojacking" and DoS attacks. Users can protect their Prometheus servers and exporters by taking them offline or adding a layer of authentication to keep out prying eyes and using tools designed to mitigate DoS risks. ([Nate Nelson / Dark Reading](https://www.darkreading.com/cloud-security/336k-prometheus-instances-exposed-dos-repojacking?ref=metacurity.com)) **Related:** [*Aquasec*](https://www.aquasec.com/blog/300000-prometheus-servers-and-exporters-exposed-to-dos-attacks/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-53.png) ### Software company Cleo urged companies to implement security updates for a zero-day flaw in its LexiCom, VLTransfer, and Harmony software, which is currently exploited in data theft attacks. The company patched a pre-auth remote code execution vulnerability (CVE-2024-50623) in its managed file transfer software and recommended that "all customers upgrade immediately." But, Huntress security researchers first spotted evidence of attacks targeting fully patched Cleo software. There was a notable increase in activity on Sunday, December 8, after attackers quickly discovered a CVE-2024-50623 bypass (with no CVE-ID) that lets them import and execute arbitrary bash or PowerShell commands by exploiting the default Autorun folder settings. This zero-day bug is now being exploited in ongoing attacks linked by cybersecurity expert Kevin Beaumont to the Termite ransomware gang, which recently claimed the breach of software as a service (SaaS) provider Blue Yonder. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/cleo-patches-critical-zero-day-exploited-in-data-theft-attacks/?ref=metacurity.com)) **Related:** [*Cleo*](https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update?ref=metacurity.com)*,* [*The Record*](https://therecord.media/cleo-urges-customers-to-immediately-patch-systems-after-exploitation?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2024/12/12/cleo-patches-zero-day-exploited-by-ransomware-gang/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/cleo-patches-exploited-flaw-as-security-firms-detail-malware-pushed-in-attacks/?ref=metacurity.com)*,* [*CSO Online*](https://www.csoonline.com/article/3621746/attackers-exploit-zero-day-rce-flaw-in-cleo-managed-file-transfer.html?ref=metacurity.com) ### Researchers at automotive security firm PCAutomotive discovered multiple vulnerabilities in the infotainment units used in some Skoda cars that could allow malicious actors to remotely trigger certain controls and track the cars’ location in real time. The firm unveiled twelve new security vulnerabilities impacting the latest Skoda Superb III sedan model at Black Hat Europe this week. The vulnerabilities could be chained together and exploited by hackers to inject malware into the vehicle. An attacker would need to connect with the Skoda Superb III’s media unit via Bluetooth to exploit the flaws, but the attack can be performed within 10 meters without authentication. The vulnerabilities discovered in the vehicle’s MIB3 infotainment unit could allow attackers to execute unrestricted code and run malicious code every time the unit starts. This could let an attacker obtain live vehicle GPS coordinates and speed data, record conversations via the in-car microphone, take screenshots of the infotainment display, and play arbitrary sounds in the car/ The vulnerable MIB3 units are used in multiple Volkswagen and Skoda models, and based on public sales data, estimates there are potentially more than 1.4 million vulnerable vehicles out there. A Skoda spokesperson said: “The reported vulnerabilities in the infotainment system have been and are being addressed and eliminated through continuous improvement management via the lifecycle of our products. At no time was and is there any danger to the safety of our customers or our vehicles.” ([Carly Page / TechCrunch](https://techcrunch.com/2024/12/12/researchers-find-security-flaws-in-skoda-cars-that-may-let-hackers-remotely-track-them/?ref=metacurity.com)) **Related:** [*Black Hat Europe*](https://pcautomotive.com/black-hat-europe-2024?ref=metacurity.com)*,* [*Digit.in*](https://www.digit.in/news/general/own-a-car-from-this-brand-hackers-could-be-tracking-your-location-right-now.html?ref=metacurity.com) ### Russian ransomware group BlackSuit e-mailed multiple executives of Japanese publisher Kadokawa Corp. that it had received $2.98 million in cryptocurrency from the firm after a massive cyberattack hit it in June. An investigation by security firm Unknown Technologies, commissioned by Kyodo News, found online records of a $2.98 million transaction made the same month. On June 8, servers located in Kadokawa group's data center experienced a significant cyberattack, including ransomware, targeting major video streaming website niconico and related services operated by the publishing firm. The company confirmed later that month that the personal information of all employees of Dwango Co., its subsidiary operating niconico, had been leaked. ([Kyodo News](https://english.kyodonews.net/news/2024/12/fffebe5585f1-japanese-publisher-paid-3-million-to-hacker-group-after-cyberattack.html?ref=metacurity.com)) **Related:** [*Mainichi*](https://mainichi.jp/english/articles/20241212/p2g/00m/0na/035000c?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-54.png) ### Andreas Kohl, co-founder of Bitcoin sidechain Sequentia, claimed that he had crashed 69% of the Dogecoin network using an old laptop in El Salvador to execute it. Data from Blockchair indicated that Dogecoin had 647 active nodes before the vulnerability was exploited. At the time of writing, Dogecoin had 315 active nodes. Kohl said he used a vulnerability discovered by researcher Tobias Ruck to cause the nodes to crash. On Dec. 4, an X account called “Department Of DOGE Efficiency” publicly disclosed a vulnerability on the Dogecoin network called DogeReaper that they said could have crashed the chain entirely. The account said that the vulnerability functions like a “Death Note” from the Japanese manga and anime of that name. In that fictional world, writing someone’s name in a notebook will cause them to die of a heart attack. The account said that the vulnerability does something similar to Dogecoin nodes. With the DogeReaper, the social media account said, anyone could write a node’s address and cause the node to die of a segmentation fault. ([Ezra Reguerra / Cointelegraph](https://cointelegraph.com/news/dogecoin-flaw-nodes-crash-69-percent?ref=metacurity.com)) **Related*:* [*The Daily Hodl*](https://dailyhodl.com/2024/12/12/hacker-exploits-dogecoin-doge-flaw-causing-69-of-nodes-to-crash/?ref=metacurity.com)*,* [*crypto.news*](https://crypto.news/sequentia-co-founder-crashed-69-of-doge-nodes-by-exploiting-fatal-flaw/?ref=metacurity.com)*,* [*Daily Coin*](https://dailycoin.com/dogecoin-network-hit-by-exploit-69-of-nodes-crashed/?ref=metacurity.com)*,* [*Blockchain News*](https://www.the-blockchain.com/2024/12/12/dogecoin-hack-crashes-69-of-networks-active-nodes/?ref=metacurity.com)*,* [*CryptoNinjas*](https://www.cryptoninjas.net/news/dogecoin-flaw-exploited-hacker-crashes-69-of-active-nodes/?ref=metacurity.com)*,* [*Altcoin Buzz*](https://www.altcoinbuzz.io/cryptocurrency-news/hacker-exposes-doge-flaw-puts-the-network-at-risk/?ref=metacurity.com)*,* [*Coinpedia*](https://coinpedia.org/news/dogecoin-network-hit-by-dogereaper-exploit-what-went-wrong/?ref=metacurity.com) ### Researchers at Elastic Security report that a new Linux rootkit malware called Pumakit has been discovered that uses stealth and advanced privilege escalation techniques to hide its presence on systems. The malware is a multi-component set that includes a dropper, memory-resident executables, a kernel module rootkit, and a shared object (SO) userland rootkit. The researchers discovered Pumakit in a suspicious binary ('cron') upload on VirusTotal, dated September 4, 2024, and reported having no visibility into who uses it and what it targets. Pumakit employs a multi-stage infection process starting with a dropper named 'cron,' which executes embedded payloads ('/memfd:tgt' and '/memfd:wpn') entirely from memory. The malware's rootkit can hide its own presence from kernel logs, system tools, and antivirus, and can also hide specific files in a directory and objects from process lists. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/new-stealthy-pumakit-linux-rootkit-malware-spotted-in-the-wild/?ref=metacurity.com)) **Related:** [*Elastic Securit*](https://www.elastic.co/security-labs/declawing-pumakit?ref=metacurity.com)*y,* [*Techzine*](https://www.techzine.eu/news/security/127133/new-linux-malware-pumakit-manages-to-hide-itself/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-55.png) Source: Elastic Security. ### Email security startup Sublime Security announced it had raised $60M in a Series B venture funding round. IVP led the round with participation from new investor Citi Ventures and existing investors Index Ventures, Decibel Partners, and Slow Ventures. ([Jordan Novet / CNBC](https://www.cnbc.com/2024/12/12/email-security-startup-sublime-raises-60-million.html?ref=metacurity.com)) **Related:** [*FinSMEs*](https://www.finsmes.com/2024/12/sublime-security-raises-60m-in-series-b-funding.html?ref=metacurity.com)*,* [*Sublime Security*](https://www.prnewswire.com/news-releases/sublime-security-secures-60-million-in-series-b-funding-to-establish-a-new-standard-in-email-security-302329975.html?ref=metacurity.com)*,* [*Pulse 2.0*](https://pulse2.com/sublime-ai-based-email-security-company-raises-60-million-series-b/?ref=metacurity.com)*,* [*FinTech Global*](https://fintech.global/2024/12/13/sublime-security-secures-60m-in-series-b-to-bolster-email-security-tech/?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/sublime-snags-60m-series-b-for-email-security-tech/?ref=metacurity.com) ### Best Thing of the Day: Cash-Strapped Local Governments Do Have Options The nonprofit Center for Internet Security [recommends](https://statescoop.com/local-government-cybersecurity-funding-cis-2025/?ref=metacurity.com) local governments use federally funded resources, including the Malicious Domain Blocking and Reporting program offered by the Multi-State Information Sharing and Analysis Center or CISA's Cyber Hygiene scanning assessment service, given their limited resources to tackle cybersecurity challenges. ### Worst Thing of the Day: Why Don't You Get Constantly Surveilled First? During a recent meeting, Oracle co-found Larry Ellison [described](https://arstechnica.com/information-technology/2024/09/omnipresent-ai-cameras-will-ensure-good-behavior-says-larry-ellison/?ref=metacurity.com) "a world where artificial intelligence systems would constantly monitor citizens through an extensive network of cameras and drones, stating this would ensure both police and citizens don't break the law." ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-50.png) it ### FSB's Secret Blizzard Targeted Ukraine Military Devices URL: https://www.metacurity.com/fsbs-secret-blizzard-targeted-ukraine-military-devices/ Last updated: 2024-12-12T15:18:53.000Z Cyber intel capability in NDAA, Splitting up Cybercom and NSA resurfaces, Sens. hope telco funds can fight Salt Typhoon, FSB arrests 11 in scam operation, Photobucket sued for training AI on customers, Cryptomus handles payments for Russian crypto, Android spyware used by cops in China, much more _This post is for paying subscribers only._ ### US Sanctions Chinese Cybersecurity Company, Employee for Ragnarok Ransomware Attacks URL: https://www.metacurity.com/us-sanctions-chinese-cybersecurity-company-employee-for-ragnarok-ransomware-attacks/ Last updated: 2024-12-11T14:23:01.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/guan-2.png) Source: FBI. *In a first, CSO Online published two of my pieces on the same day.* *The first* [*examines*](https://www.csoonline.com/article/3621674/salt-typhoon-poses-a-serious-supply-chain-risk-to-most-organizations.html?ref=metacurity.com) *how Salt Typhoon poses* *a serious supply chain risk to most organizations, with China exfiltrating massive amounts of data, especially voice calls that can be stored for later use in deepfake campaigns.* *The second piece* [*delves*](https://www.csoonline.com/article/3619804/bug-bounty-programs-can-deliver-significant-benefits-but-only-if-youre-ready.html?ref=metacurity.com) *into bug bounty programs and explains how they can deliver significant benefits, but only for organizations that are ready for them.* *Check out both articles!* --- ### The US Treasury Department sanctioned Chinese cybersecurity company Sichuan Silence and one of its employees, Guan Tianfeng, for their involvement in a series of Ragnarok ransomware attacks targeting US critical infrastructure companies and many other victims worldwide in April 2020. According to the Department's Office of Foreign Assets Control (OFAC), Sichuan Silence is a Chengdu-based cybersecurity government contractor that provides products and services to core clients, such as China's intelligence services. OFAC says the zero-day used in the April 2020 campaign was discovered by security researcher and Sichuan Silence employee Guan Tianfeng (also known as GbigMao) in an unnamed firewall product. According to the Department's Office of Foreign Assets Control (OFAC), Sichuan Silence is a Chengdu-based cybersecurity government contractor (recently profiled by the Natto Thoughts team) that provides products and services to core clients, such as China's intelligence services. The US Department of Justice (DOJ) also unsealed an indictment on Guan, and the US State Department announced a reward offer of up to $10 million for information about Sichuan Silence or Guan through its Rewards for Justice program. The Department of State and the DOJ confirmed that the April 2020 Ragnarok ransomware campaign exploited a zero-day SQL injection vulnerability (CVE-2020-12271) in Sophos XG firewalls. The attackers initially used zero-day exploits to obtain remote code execution on Sophos XG firewalls and installed ELF binaries and scripts as part of a malicious toolkit known as Asnarök Trojan. After Sophos detected the attacks, it patched the devices and removed the malicious scripts using a hotfix. However, the threat actors activated a 'dead man switch' that would have triggered a Ragnarok ransomware attack on Windows machines on the victims' networks. As a result of the sanctions, US organizations and citizens are prohibited from engaging in transactions with Guan and Sichuan Silence. Also, any U.S.-based assets tied to them will be frozen, and U.S. financial institutions or foreign entities transacting with them will also expose themselves to penalties. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/us-sanctions-chinese-firm-for-hacking-firewalls-in-ragnarok-ransomware-attacks/?ref=metacurity.com)) **Related:** [*OFAC*](https://ofac.treasury.gov/recent-actions/20241210?ref=metacurity.com)*,* [*Treasury Department*](https://home.treasury.gov/news/press-releases/jy2742?ref=metacurity.com)*,* [*Justice Department*](https://www.justice.gov/opa/pr/china-based-hacker-charged-conspiring-develop-and-deploy-malware-exploited-tens-thousands?ref=metacurity.com)*,* [*State Departmen*](https://www.state.gov/u-s-takes-action-in-response-to-compromise-of-firewall-products/?ref=metacurity.com)*t,* [*PCMag*](https://www.pcmag.com/news/us-sanctions-chinese-cybersecurity-firm-for-hacking-81k-firewall-devices?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2024/12/10/us-sanctions-chinese-cybersecurity-firm-for-firewall-hacks-targeting-critical-infrastructure/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/us-sanctions-chinese-cyber-firm-compromising-firewalls?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/treasury-sanctions-chinese-cyber-company-2020-firewall-attack/?ref=metacurity.com)*,* [*Reuters*](https://www.reuters.com/technology/cybersecurity/us-sanctions-chinese-firm-over-potentially-deadly-ransomware-attack-2024-12-10/?ref=metacurity.com)*,* [*Al Jazeera*](https://www.aljazeera.com/economy/2024/12/10/us-sanctions-china-cyber-firm-for-potentially-deadly-ransomware-attack?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2024-12-10/chinese-cybersecurity-firm-sanctioned-employee-charged-by-us?ref=metacurity.com)*,* [*BankInfoSecurity.com*](https://www.bankinfosecurity.com/us-indicts-sanctions-alleged-chinese-sophos-firewall-hacker-a-27014?ref=metacurity.com)*,* [*UPI*](https://www.upi.com/Top%5FNews/US/2024/12/10/treasury-China-cybersecurity-2020-firewall-compromise/3891733851528/?ref=metacurity.com)*,* [*AFP*](https://www.france24.com/en/live-news/20241210-us-offers-10-mn-reward-for-wanted-chinese-hacker?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2024/12/10/us-sanctions-sichuan-silence-guan-tianfeng/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2024/12/11/sichuan%5Fsilence%5Fsophos%5Fzeroday%5Fsanctions/?ref=metacurity.com)*,* [*IT News*](https://www.itnews.com.au/news/us-sanctions-chinese-firm-over-potentially-deadly-ransomware-attack-613813?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/us-charges-sanctions-chinese-man-accused-of-sophos-firewall-hacking/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/us-sanctions-chinese-firewall-hack/?ref=metacurity.com)*,* [*TechRadar*](https://www.techradar.com/pro/security/chinese-cybersecurity-firm-facing-us-sanctions-over-alleged-ransomware-attacks?ref=metacurity.com)*,* [*Natto Thoughts*](https://nattothoughts.substack.com/p/sichuan-silence-information-technology)*,* [*PYMNTS*](https://www.pymnts.com/cybersecurity/2024/ofac-sanctions-parties-involved-in-compromise-of-81000-firewalls/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-39.png) ### Europol and various other law enforcement agencies announced they have successfully conducted Operation PowerOFF, which took 27 DDoS "booter" or "stressor" platforms offline. Some websites that were taken down include zdstresser.net, orbitalstress.net, and starkstresser.net. Alongside the takedown of 27 platforms, three administrators in France and Germany were arrested, actions were taken against several users, and a further 300 users were identified. Europol is also taking proactive measures, such as Google search ads and YouTube ads targeted at those looking for DDoS-for-hire tools or tutorials on conductinga DDoS attack. In addition to these measures, more than 250 warning letters, over 2,000 emails, and knock-and-talks will be used to deter users of illegal online services. This operation coordinated by Europol involved 15 separate countries, including Australia, Brazil, Canada, Finland, France, Germany, Japan, Latvia, The Netherlands, Poland, Portugal, Sweden, Romania, the UK, and the US. ([Niamh Ancell / Cybernews](https://cybernews.com/news/europol-shuts-down-ddos-platforms-before-christmas/?ref=metacurity.com)) **Related:** [*Europol*](https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-shuts-down-27-ddos-booters-ahead-of-annual-christmas-attacks?ref=metacurity.com) ### On this month's Patch Tuesday, Microsoft released updates to plug at least 70 security holes in Windows and Windows software, including one vulnerability already exploited in active attacks. The zero-day seeing exploitation involves CVE-2024-49138, a security weakness in the Windows Common Log File System (CLFS) driver, which applications useto write transaction logs — that could let an authenticated attacker gain “system”-level*.* Elevation of privilege vulnerabilities accounted for 29% of the 1,009 security bugs Microsoft has patched so far in 2024, according to a year-end tally by Tenable; nearly 40 percent of those bugs were weaknesses that could let attackers run malicious code on the vulnerable device. Tyler Reguly at the security firm Fortra had a slightly different 2024 patch tally for Microsoft, at 1,088 vulnerabilities, which he said was surprisingly similar to the 1,063 vulnerabilities resolved in 2023 and the 1,119 vulnerabilities resolved in 2022\. ([Brian Krebs / Krebs on Security](https://krebsonsecurity.com/2024/12/patch-tuesday-december-2024-edition/?ref=metacurity.com)) **Related:** [*Bleeping Computer*](https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2024-patch-tuesday-fixes-1-exploited-zero-day-71-flaws/?ref=metacurity.com)*,* [*Petri*](https://petri.com/microsoft-december-2024-patch-tuesday-updates/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/windows-11-kb5048667-kb5048685-december-2024-patch-tuesday-out/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2024/12/10/microsoft%5Fpatch%5Ftuesday/?ref=metacurity.com)*,* [*Dark Reading*](https://www.darkreading.com/application-security/microsoft-zero-day-critical-rces-patch-tuesday?ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/microsoft-ships-urgent-patch-for-exploited-windows-clfs-zero-day/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2024/12/10/december-2024-patch-tuesday-microsoft-zero-day-cve-2024-49138/?ref=metacurity.com)*,* [*Cyberscoop*](https://cyberscoop.com/microsoft-patch-tuesday-december-2024/?ref=metacurity.com)*,* [*r/sysadmin*](https://www.reddit.com/r/sysadmin/comments/1hav717/patch%5Ftuesday%5Fmegathread%5F20241210/?ref=metacurity.com)*,* [*Tenable*](https://www.tenable.com/blog/microsofts-december-2024-patch-tuesday-addresses-70-cves-cve-2024-49138?ref=metacurity.com)*,* [*Ask Woody*](https://www.askwoody.com/2024/december-2024-patches-are-out/?ref=metacurity.com)*,* [*SANS Internet Storm Center*](https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508?ref=metacurity.com)*,* [*Rapid7*](https://www.rapid7.com/blog/post/2024/12/10/patch-tuesday-december-2024/?ref=metacurity.com)*,* [*The Stack*](https://www.thestack.technology/microsoft-patch-tuesday-december-2024/?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/microsoft-71-cves-actively/?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-40.png) Source: Europol. ### Researchers at Recorded Future documented a Russian-tied campaign designed to undermine Europe’s support for Ukraine, dubbed “Operation Undercut,” that prominently used AI-generated voiceovers on fake or misleading “news” videos. The videos, produced by Russia's Social Design Agency (SDA), which targeted European audiences, attacked Ukrainian politicians as corrupt or questioned the usefulness of military aid to Ukraine, among other themes. For example, one video touted that “even jammers can’t save American Abrams tanks,” referring to devices used by US tanks to deflect incoming missiles, reinforcing the point that sending high-tech armor to Ukraine is pointless. The report states that the video creators “very likely” used voice-generated AI, including ElevenLabs tech, to make their content appear more legitimate. To verify this, Recorded Future’s researchers submitted the clips to ElevenLabs’ AI Speech Classifier, which allowsanyone to “detect whether an audio clip was created using ElevenLabs” and got a match. ([Charles Rollet / TechCrunch](https://techcrunch.com/2024/12/10/elevenlabs-ai-voice-generation-very-likely-used-in-a-russian-influence-operation/?ref=metacurity.com)) **Related:** [*Recorded Future*](https://go.recordedfuture.com/hubfs/reports/TA-RU-2024-1126.pdf?ref=metacurity.com) ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-42.png) Source: Recorded Future. --- *Sponsor Message* ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-41.png) In today's digital landscape, protecting your software supply chain from rising threats is essential. This free whitepaper offers five key strategies for enhancing container security, one of the main attack surfaces in dynamic software development practices. Learn about using SBOMs for transparency, shifting vulnerability detection left, and automating policy enforcement, all for a superior developer experience and securing third-party code. [Learn more](https://get.anchore.com/best-practices-for-container-security/?utm%5Fsource=partner&utm%5Fmedium=metacurity&utm%5Fcampaign=2024-october-newsletter&utm%5Fcontent=whitepaper) *Interested in reaching the elite audience of cybersecurity decision-makers, public policy professionals, and journalists who read Metacurity? Send an email to info \[at\] Metacurity.com with the subject line "Sponsorship."* --- ### An international team of researchers from KU Leuven, the University of Lübeck, and the University of Birmingham unveiled BadRAM, a proof-of-concept attack that completely undermines security assurances that chipmaker AMD makes to users of one of its most expensive and well-fortified microprocessor product lines. Starting with the AMD Epyc 7003 processor, a feature known as SEV-SNP, short for Secure Encrypted Virtualization and Secure Nested Paging, has provided the cryptographic means for certifying that a VM hasn’t been compromised by any backdoor installed by someone with access to the physical machine running it. If a VM has been backdoored, the cryptographic attestation will fail, and the VM admin will be immediately alerted of the compromise. Or at least that’s how SEV-SNP is designed to work. BadRAM is an attack that a server admin can carry out in minutes, using either about $10 of hardware or, in some cases, software only, to cause DDR4 or DDR5 memory modules to misreport the memory capacity they have during bootup. From then on, SEV-SNP will be permanently made to suppress the cryptographic hash, attesting to its integrity even when the VM has been badly compromised. ([Dan Goodin / Ars Technica](https://arstechnica.com/information-technology/2024/12/new-badram-attack-neuters-security-assurances-in-amd-epyc-processors/?ref=metacurity.com)) **Related*:* [*BadRAM*](https://badram.eu/?ref=metacurity.com)*,* [*The Register*](https://www.theregister.com/2024/12/10/amd%5Fsecure%5Fvm%5Ftech%5Fundone/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2024/12/11/badram-amd-hack-cve-2024-21944/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/amd-security-flaw-badram?ref=metacurity.com)*,* [*Fudzilla*](https://www.fudzilla.com/news/memory-and-storage/60226-badram-blunder?ref=metacurity.com)*,* [*PC Perspective*](https://pcper.com/2024/12/badram-breaks-amds-sev-snp-trusted-execution-protection/?ref=metacurity.com)*,* [*Heise Online*](https://www.heise.de/en/news/BadRAM-Historical-side-channel-undermines-confidential-computing-in-the-cloud-10194591.html?ref=metacurity.com) ### According to researchers at NetRise, the average software container has 604 known vulnerabilities in its underlying software components, with over 45% being 2 to 10-plus years old. NetRise says 7.9% of vulnerabilities encountered by the cybersecurity firm were over five years old, while 4.2% of vulnerabilities deemed ‘Critical’ or ‘High’ were additionally classified as ‘weaponized’ and actively exploited in real-world attacks. NetRise utilized an advanced Software Bill of Materials (SBOM) approach, generating detailed SBOMs for 70 randomly selected container images from Docker Hub’s most downloaded repositories. This method enabled the firm to identify all software components within each container, including third-party libraries and dependencies. The study’s risk assessment evaluated known vulnerabilities (CVEs) and non-CVE risks, such as outdated components and misconfigurations. Vulnerability prioritization was carried out using Common Vulnerability Scoring System (CVSS) rankings, focusing on weaponized vulnerabilities that are actively exploited in the wild. ([Swagath Bandhakavi / TechMonitor](https://www.techmonitor.ai/technology/cybersecurity/software-container-vulnerabilities-study?ref=metacurity.com)) **Related:** [*NetRise*](https://www.netrise.io/en/company/announcements/netrise-releases-supply-chain-visibility-risk-study-revealing-signicant-visibility-and-risk-challenges-within-common-containers?ref=metacurity.com)*,* [*Industrial Cyber*](https://industrialcyber.co/news/netrise-study-containers-fastest-growing-though-most-vulnerable-cybersecurity-link/?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2024/12/11/containers-security-concerns/?ref=metacurity.com) ### In an SEC filing, doughnut chain Krispy Kreme said that unauthorized activity on a portion of its information technology systems has disrupted certain operations, including online ordering in the United States. After being notified of the incident on Nov. 29, the company has initiated an investigation and is working with external cybersecurity experts to mitigate the impact. ([Denny Jacob / Marketwatch](https://www.marketwatch.com/story/krispy-kreme-says-cybersecurity-breach-disrupts-digital-orders-e1c52e1e?mod=newsviewer%5Fclick&ref=metacurity.com)) **Related:** [*Krispy Kreme*](https://d18rn0p25nwr6d.cloudfront.net/CIK-0001857154/9fdfc9de-a71b-4534-a096-fd43046bd77b.pdf?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/7732e6ed-c07e-4520-833e-b858ba9bd432?ref=metacurity.com)*,* [*CNN*](https://www.cnn.com/2024/12/11/business/krispy-kreme-cyber-attack-hack/index.html?ref=metacurity.com)*,* [*Marketwatch*](https://www.marketwatch.com/story/krispy-kreme-says-cybersecurity-breach-disrupts-digital-orders-e1c52e1e?mod=newsviewer%5Fclick&ref=metacurity.com) [In the spirit of holiday generosity, please consider a subscription upgrade to support Metacurity.](#/portal/account/plans) ### Cybersecurity startup Astrix Security raised $45 million in a Series B venture funding round. Menlo Ventures led the round through the Anthology Fund, a strategic partnership between Menlo and Anthropic, the AI company behind Claude. Other participants included Workday Ventures, the global HR software leader, and existing investors such as Bessemer Venture Partners, CRV, and F2 Venture Capital. ([Meir Orbach / Calcalist](https://www.calcalistech.com/ctechnews/article/sytzk2se1e?ref=metacurity.com)) **Related:** [*PR Newswire*](https://www.prnewswire.com/news-releases/astrix-security-raises-45m-series-b-to-redefine-identity-security-for-the-ai-era-302327052.html?ref=metacurity.com)*,* [*Silicon Angle*](https://siliconangle.com/2024/12/10/astrix-security-secures-45m-strengthen-nonhuman-identity-protection-enterprise/?ref=metacurity.com)*,* [*FinSMEs*](https://www.finsmes.com/2024/12/astrix-security-raises-45m-in-series-b-funding.html?ref=metacurity.com)*,* [*BankInfoSecurity*](https://www.bankinfosecurity.com/astrixs-45b-series-b-targets-non-human-identity-security-a-27006?ref=metacurity.com)*,* [*Globes*](https://en.globes.co.il/en/article-israeli-startup-astrix-security-raises-45m-1001496430?ref=metacurity.com)*,* [*FinTech Global*](https://fintech.global/2024/12/11/astrix-security-secures-45m-to-enhance-identity-protection-in-the-ai-era/?ref=metacurity.com) ### Best Thing of the Day: Would It Be Wrong to Say It's About Time? After its customers [succumbed](https://www.snowflake.com/en/blog/blocking-single-factor-password-authentification/?ref=metacurity.com) to devastating breaches of their accounts on cloud-based storage company Snowflake's servers, Snowflake says it will enforce multi-factor authentication for all its customers by August 2025. ### Worst Thing of the Day: Our AI Overlords Apparently Like Murderous Teens A chatbot hosted by Character.ai [told](https://www.bbc.com/news/articles/cd605e48q1vo?ref=metacurity.com) a 17-year-old that murdering his parents was a "reasonable response" to them limiting his screen time, a lawsuit filed in a Texas court claims. ### Closing Thought ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-38.png) ### Eurocops Bust Airbnb-Dwelling Cybercrime Network URL: https://www.metacurity.com/eurocops-bust-airbnb-dwelling-cybercrime-network/ Last updated: 2024-12-10T15:23:35.000Z Romanian electricity supplier hit with ransomware, Hackers stole files from medical device giant, Japanese water treatment company hit with ransomware, Fake meeting apps target Web3 workers, Ultralytics YOLO11 AI model compromised in supply chain attack, Heist targets AWS customers, much more _This post is for paying subscribers only._ ### Court Annuls Romania's Presidential Election After 'Aggressive Hybrid Russian Attacks' URL: https://www.metacurity.com/court-annuls-romanias-presidential-election-amid-agressive-hybrid-russian-attacks-2/ Last updated: 2024-12-09T13:37:01.000Z SpaceX to expand more secure Starlink terminals in Ukraine, Mass. community hospital suffers ransomware attack, $500K stolen via Cardano X account hack, Radiant Capital $50m hack was carried out by fake DPRK contractor, Termite cops to BlueYonder hack, Phishing gang busted in EU, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 11/30/24 URL: https://www.metacurity.com/next-long-read-2/ Last updated: 2024-12-10T15:03:53.000Z ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/pexels-k2production-10609655-1.jpg) Photo by[ K2 Production](https://www.pexels.com/photo/smiling-student-in-red-beret-10609655/?ref=metacurity.com) *Happy Saturday morning! Metacurity is pleased to offer our free and premium subscribers this weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush. So tell us what you think, and feel free to share your favorite long reads via email at* *info@metacurity.com* *.* *In the meantime, please consider supporting Metacurity with a subscription upgrade.* [Upgrade me](#/portal/account/plans) ### Ransomware Gangs’ Merciless Attacks Bleed Small Companies Dry Bloomberg's Ryan Gallagher [tells the ](https://www.bloomberg.com/news/features/2024-12-06/how-russia-linked-ransomware-hackers-bled-this-small-company-dry?embedded-checkout=true&ref=metacurity.com)familiar but heartbreaking story of what a ransomware attack can do to small businesses, in this case, Knights of Old, a 158-year-old UK delivery company, which was forced into bankruptcy despite having a cyber insurance policy and having invested in cybersecurity preparation and training. > \[Knight's co-owner Paul Abbott\] said he and his partners decided not to negotiate with Akira or pay the gang anything, because there could be no guarantee the data could be fully recovered even with the decryption key. In response the hackers followed through on their threat, publishing more than 10,000 internal documents online—mostly employee payroll files, invoices and other financial information. > The company tried to rebuild its computers. Within a few days, Knights’ technicians had set up a new transport management system and recovered an old backup of the warehouse software. But the financial management databases couldn’t be immediately recovered, because hackers had destroyed another backup that was supposed to be stored securely elsewhere. > Facing cash-flow pressures, KNP sought a loan. Abbott says the bank would provide it only if the company could supply the missing financial records and performance reports. Still waiting on a payout from the insurance company, the ­co-owners tried to sell the company. A European businessman came close to buying. But, because of the missing financial records, the buyer insisted that the three partners personally guarantee the state of the company’s finances. They’d be putting their houses and savings on the line. The partners balked, according to Abbott. “My wife would never have let me do that, regardless of how confident we were in the business,” he says. > On Sept. 25, 2023, KNP Group entered administration, the British equivalent of bankruptcy. In Kettering, Abbott announced the news to his employees, some of whom he’d worked with for decades. Another company bought one of KNP’s subsidiaries, Nelson Distribution, saving about 170 jobs. But the rest of KNP’s 700 or so employees, the majority of them from Knights of Old, lost their livelihood. Jeff Maslin, who drove trucks for Knights, says drivers are still owed weeks’ worth of wages. “I know people who lost their house, lost their car and ended up divorced,” he says. ### Beyond TikTok — The National Security Risks of Chinese Agricultural Drones In War on the Rocks, independent researcher Claris Diaz and Emilian Kavalskim, the NAWA chair professor at the Center for International Studies and Development at the Jagiellonian University in Krakow, [examine](https://warontherocks.com/2024/11/beyond-tiktok-the-national-security-risks-of-chinese-agricultural-drones-2/?ref=metacurity.com) how Chinese-made agricultural drones equipped with dangerous data-collecting technology pose a far greater national security threat than TikTok and can help lead to warfare on an adversary's food supply. > As part of their investment strategy, the Chinese government has made military agreements with Chinese-owned agriculture drone manufacturers and agriculture research universities. Their Military-Civil Fusion strategy, integrating civilian technologies with military goals, enables the Chinese government to exploit critical farming data for economic and military advantages. To support sustainable food production by monitoring crop health and predicting crop yields, the drones collect alarmingly specific data about the crops and region of the customer using them. For example, a drone used for corn fields in the United States, one of the world’s biggest corn exporters, will collect detailed data about the area’s climate, soil conditions, and pest and disease susceptibility. The onboard AI can analyze this data to report crop vulnerabilities and identify optimum growth needs for these and other crops such as rice and wheat, foods on which much of the world’s population depends. From Brazil’s soy farms to Spain’s olive groves, the Chinese government can potentially access the farming data of any customer in any region. > This data exploitation will facilitate the Chinese government’s efforts to design “perfect” products that farmers will want for healthier crops and increased yield. Chinese drone manufacturer XAG has already signed agreements with Bayer and Chinese-owned Syngenta, two of the world’s foremost agricultural sciences corporations. Farming data shared with these research and development enterprises helps them create precisely what farmers need — fertilizers that optimize crop growth and quality, highly effective spray pesticides and fungicides, and genetically modified seeds that withstand drought and other extreme conditions. This may not matter now, but it will in the next few decades when farmers struggle to grow healthy crops, and there won’t be enough crops to feed the world. > Chinese companies are seeking to become the leading suppliers of smart agricultural technologies, which will help Beijing dominate the global food market. China can use price controls, set export restrictions, and implement trading fees for products that affect crop growth. This would also impact other sectors, such as the meat and dairy industry, since crops such as corn are used for livestock feed. In addition, China can establish trade agreements with other countries for food items they need, potentially reducing reliance on Western markets. This market influence strengthens China’s economic power and gives it significant political leverage. The Federal Bureau of Investigation has already warned about the Chinese Communist Party’s economic espionage efforts and plans to dominate the global market. In this respect, smart agriculture drones can become an important tool in China’s strategic outreach. ### Hugging an FBI Most Wanted: The GRU Spy’s Homecoming In VSqaure, Kato Kopaleishvili, Michael Weiss, Christo Grozev and Roman Dobrokhotov [paint a vivid picture](https://vsquare.org/putin-pablo-gonzalez-russian-gru-illegal-spy-oleg-sotnikov/?ref=metacurity.com) of how Russian GRU spy Pavel Rubtsov, who posed as Spanish journalist Pablo González, was warmly greeted by Oleg Sotnikov, a GRU officer on the FBI’s Most Wanted List for cyber-espionage, when returning to Moscow as part of an August 2024 major prisoner exchange with the West. > Sotnikov is well known to NATO counterintelligence. He’s an officer of the GRU, Russia’s military intelligence service. In October 2018, the U.S. District Court of the Western District of Pennsylvania indicted Sotnikov and six other GRU officers with “stealing private or otherwise sensitive information” to use as part of an “‘influence and disinformation’ campaign designed to undermine the legitimate interests of the victims, further Russian interests, retaliate against Russia’s detractors and sway public opinion in Russia’s favor.” > Specifically, Sotnikov offered support to one of the GRU’s cyber operations teams, Unit 26165, in the “close access” hacking of the OPCW headquarters in The Hague. He turned up in the Netherlands with his co-conspirators to breach the chemical weapons watchdog’s WiFi network in April 2018; little did they know they were being trailed by Dutch General Intelligence and Security Services (AIVD) from the moment the team arrived at Schiphol Airport in Amsterdam. Just as they got to work from the parking lot of a Marriott hotel adjacent to the watchdog’s building, the entire team was all rounded up by the AIVD and expelled from the country. > As of June 2013, Moscow’s residential database showed Sotnikov’s “permanent address” as Khoroshevskoye Chausse 76B, which happens to be the main address of GRU Headquarters. > For more than a decade, the GRU has conducted extensive cyberoperations aimed at exfiltrating sensitive information from international monitors and waged political campaigns in order to instrumentalize it to Moscow’s advantage. The Kremlin expends enormous energy and resources on obfuscating forensic evidence and denying its culpability in poisoning its enemies — and on covering up for its clients when they do the same. The OPCW, for instance, investigated Syrian chemical weapons attacks perpetrated by Russia’s client, Bashar al-Assad’s regime, and the 2018 Novichok poisoning of Sergei and Yulia Skripal in Salisbury, England, which was carried out by the GRU’s black ops team, known as Unit 29155\. The hacking of anti-doping agencies, too, coincided with the 2016 Summer Olympics in Brazil, where, out of 389 athletes competing for Russia, 111 were disqualified because of their use of prohibited steroids and performance enhancing drugs. > “Fancy Bear,” as Unit 26165 has been nicknamed by cybersecurity experts, became notorious in 2018 when a dozen of its members were indicted by Special Counsel Robert Mueller for engaging in “a sustained effort” to hack into the digital correspondence of the Democratic Party and Hillary Clinton’s presidential campaign with the aim of swaying the 2016 U.S. election in favor of Donald Trump. --- *Sponsor Message* ![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2024/12/image-26.png) Armed with a complete view of your organization’s software assets, Anchore allows you to find and prevent malicious content from reaching your users. Anchore’s end-to-end, SBOM-powered software supply chain security management platform protects you and your customers at every step, from SBOM monitoring to policy enforcement to remediation. Anchore integrates at every stage of the software development process, from source code to build to runtime. Every package, every library, every version is cataloged and stored. This enables organizations to find out where content is, where it came from, and how it changed. [Prevent software attacks with Anchore](https://anchore.com/?utm%5Fsource=partner&utm%5Fmedium=metacurity&utm%5Fcampaign=2024-october-newsletter&utm%5Fcontent=website-link) --- ### Tracking Indoor Location, Movement and Desk Occupancy in the Workplace Wolfie Christl, founder of Viennese public interest technology research firm Cracked Labs, [presents ](https://crackedlabs.org/dl/CrackedLabs%5FChristl%5FIndoorTracking.pdf?ref=metacurity.com)a case study from the ongoing “Surveillance and Digital Control at Work” project, exploring software systems and technologies that use personal data on employees to monitor room and desk occupancy and track employees’ location and movements inside offices and other corporate facilities and documenting how workers resisted the installation of motion sensors by their employers. > As offices, buildings and other corporate facilities become networked environments, there is a growing desire among employers to exploit data gathered from their existing digital infrastructure or additional sensors for various purposes. Whether intentionally or as a byproduct, this includes personal data about employees, their movements and behaviors. > Technology vendors are promoting solutions that repurpose an organization’s wireless networking infrastructure as a means to monitor and analyze the indoor movements of employees and others within buildings. While GPS technology is too imprecise to track indoor location, Wi-Fi access points that provide internet connectivity for laptops, smartphones, tables and other networked devices can be used to track the location of these devices. Bluetooth, another wireless technology, can also be used to monitor indoor location. This can involve Wi-Fi access points that track Bluetooth-enabled devices, so-called “beacons” that are installed throughout buildings and Bluetooth-enabled badges carried by employees. In addition, employers can utilize badging systems, security cameras and video conferencing technology installed in meeting rooms for behavioral monitoring, or even environmental sensors that record room temperature, humidity and light intensity. Several technology vendors provide systems that use motion sensors installed under desks or in the ceilings of rooms to track room and desk attendance ### Is Anyone Happy With the UN Cybercrime Convention? In Lawfare, Karine Bannelier, Associate Professor of International Law at the University Grenoble Alps (France) and Director of the Grenoble-Alps Cybersecurity Institute and Lawfare Senior Editor Eugenia Lostri [explain](https://www.lawfaremedia.org/article/is-anyone-happy-with-the-un-cybercrime-convention?ref=metacurity.com) how the new UN cybercrime convention has left no one happy, although a longer-term view indicates it is a victory for authoritarian countries. > After the UN adopted the draft convention by consensus, the backlash from the private sector and civil society was swift. Some groups, including in the U.S., called on states to abstain from adopting the convention, arguing that no convention at all would be better than this one. As Katitza Rodriguez, policy director for global privacy at the Electronic Frontier Foundation, wrote: “States should vote No when the UNGA votes on the UN Cybercrime Treaty.” > Among the main criticisms is the fact that “the e-evidence sharing chapter remains broad in scope, and the rights section unfortunately falls short. Indeed, instead of merely facilitating cooperation on core cybercrime, this convention authorizes open-ended evidence gathering and sharing for any serious crime that a country chooses to punish with a sentence of at least four years or more, without meaningful limitations.” > Western governments acknowledged these concerns but ultimately dismissed them. Representatives from the U.S. and the U.K., for example, argued that their countries needed to continue to support the convention to prevent being left out of the conversation. Even if their governments refrained, the convention would most likely still be adopted, and they would not be in a position to play a role in its interpretation and implementation of protections and safeguards provided within. There’s also, of course, a clear utility. As one U.S. official said, “\[T\]he treaty would expand the number of countries that would respond to U.S. warrants for arrest involving cybercrimes.” > They also argued that refraining at this stage, after adopting the text by consensus at the ad hoc committee, would break the trust built up during negotiations. Many of these partners are the middle countries, such as the Caribbean or African states that will end up benefiting from an increase in capacity building. In many ways, the convention accomplishes their objective: improved capacity to fight cybercrime. However, these same countries are also the most vulnerable to UN-washed requests from authoritarian governments. As Jason Pielemeier, executive director of the Global Network Initiative argued, the concern is less that the Russian government will misuse the convention against established democracies but, rather, that it will exploit the international acceptance of the language to make demands from third countries with weaker application of the rule of law. Another wrinkle lies in the possibility that authoritarian governments could argue that they are simply applying international law in their domestic context—a pretty straightforward way of covering up abuses. ### China's Salt Typhoon Likely Stole Data From at Least One Million Americans, Sources URL: https://www.metacurity.com/chinas-salt-typhoon-likely-stole-data-from-at-least-one-million-americans-sources/ Last updated: 2024-12-06T18:13:39.000Z FCC to penalize telcos for poor protection against Chinese hackers, EU orders TikTok data freeze due to Russian campaign in Romania, Large US org in China breached by Chinese actors, Child abuse groups use TTPs of cybercriminals, Ukraine launched alleged cyberattack on Gazprombank, much more _This post is for paying subscribers only._ ### Salt Typhoon Hacked Eight US Telcos, Dozens of Other Countries Affected, in Two-Year Spree URL: https://www.metacurity.com/salt-typhoon-hacked-eight-us-telcos-dozens-of-other-countries-affected-in-two-year-spree-2/ Last updated: 2024-12-05T14:11:48.000Z Senators press DoD on Salt Typhoon, Cops KO massive Russian money-laundering networks, Scattered Spider suspect breached two telcos, Russian programmer hit by spyware, Turla hacks other hackers, BT shutters conferencing arm after ransomware attack, Telegram caves on child protection, so much more _This post is for paying subscribers only._ ### Feds Push Defense Measures Against Salt Typhoon, Say Americans Should Use Encrypted Apps URL: https://www.metacurity.com/feds-push-defense-measures-against-salt-typhoon-say-americans-should-use-encrypted-apps/ Last updated: 2024-12-04T14:31:49.000Z Ransomware attack helped push Stoli vodka maker to bankruptcy, FTC acts against top location data companies, Cops stop encrypted messaging platform MATRIX, Germany takes down its largest cybercrime market, New Scattered Spider suspect arrested, Iranian hackers targeted Kash Patel, much more _This post is for paying subscribers only._ ### UK Cybersecurity Chief Warns of Rise in Hostile Cyber Activity URL: https://www.metacurity.com/uk-cybersecurity-chief-warns-of-rise-in-hostile-cyber-activity/ Last updated: 2024-12-03T15:31:14.000Z Russia sentences Hydra Market leader to life in prison, Former Polish security chief forced into Pegasus spyware hearing, CFPB publishes proposed data brokers rule, SEC settles ICBC ransomware records case, FDD argues for Chinese-made lidar sensor ban, Hack forces DMM Bitcoin shutdown, much more _This post is for paying subscribers only._ ### Russian Authorities Bust Ransomware Developer Wazawaka URL: https://www.metacurity.com/russian-authorities-bust-ransomware-developer-wazawaka/ Last updated: 2024-12-02T14:34:21.000Z T-Mobile stopped Salt Typhoon on a provider's network, Hackers stole $16.8m from Bank of Uganda, FBI probes DC lobbying group in Exxon hack-and-leak op, Bologna football club hit by ransomware, Moucka raised the ire of Allison Nixon, Eurocops bust up illegal streaming network, so much more _This post is for paying subscribers only._ ### Interpol Busts 1,006 Suspects in Africa for a Host of Financial Cybercrimes URL: https://www.metacurity.com/interpol-busts-1-006-suspects-in-africa-for-a-host-of-financial-cybercrimes/ Last updated: 2024-11-27T19:34:55.000Z The third Snowflake suspect might be a US Army soldier, US court reverses sanctions on Tornado Cash, RomCom group chained zero days to target Firefox and Tor browsers, Uniswap offers $15.5m bug bounty, CrowdStrike can't gauge financial impact of July outage yet, much more _This post is for paying subscribers only._ ### Supply Chain Cyberattack Disrupts Giant Retailers Including Starbucks, Sainsburys URL: https://www.metacurity.com/supply-chain-cyberattack-disrupts-giant-retailers-including-starbucks-sainsburys/ Last updated: 2024-11-26T14:11:20.000Z NY fines Geico and Travelers $11.3m over 2020 hacks, Oz passes standalone Cyber Security Act, Long-withheld LifeLabs investigation released, Liverpool hospital goes down due to cyber incident, IT worker sentenced to four years for sharing data with China, QNAP issues flurry of fixes, much more _This post is for paying subscribers only._ ### China Is Prepositioning Itself to Carry Out Disruptive Attacks, Cyber Command URL: https://www.metacurity.com/china-is-prepositioning-itself-to-carry-out-disruptive-attacks-cyber-command/ Last updated: 2024-11-25T15:13:26.000Z WH summoned telecom chiefs to talk Chinese hackers, Fancy Bear uses new nearest neighbor attack technique, China's Glassbridge group operates hundreds of fake news sites, Chinese citizens sell surveillance data, Microsoft Recall rolls out to insiders, Thai cops bust SMS phish blaster, much more _This post is for paying subscribers only._ ### Best Infosec-Related Long Reads for the Week of 11/16/24 URL: https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-11-16-24/ Last updated: 2024-11-23T13:43:59.000Z Israeli spyware poised to spy on Americans, AI pimps exploit real-life videos, Clear wants to become the Amazon of identity services, Active cyber defense may make a comeback in Germany, Trump might put an end to Microsoft and Google-backed Chinese censorship and surveillance startups _This post is for subscribers only._ _Includes the latest 500 public posts. Use `/sitemap.xml` for the complete archive of public content._