Sergiu Gatlan's Avatar

Sergiu Gatlan

@serghei.bsky.social

Cybersecurity/tech reporter @BleepingComputer / serghei.ro

5,575 Followers  |  876 Following  |  89 Posts  |  Joined: 23.06.2023
Posts Following

Posts by Sergiu Gatlan (@serghei.bsky.social)

Preview
Wikipedia hit by self-propagating JavaScript worm that vandalized pages The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis.

The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis.

05.03.2026 15:42 — 👍 12    🔁 9    💬 1    📌 0
Preview
FBI seizes LeakBase cybercrime forum, data of 142,000 members The FBI has seized the LeakBase cybercrime forum, a major online forum used by cybercriminals buy and sell hacking tools and stolen data.

The FBI has seized the LeakBase cybercrime forum, a major online forum used by cybercriminals buy and sell hacking tools and stolen data.

04.03.2026 12:45 — 👍 6    🔁 4    💬 0    📌 0
Preview
CBP Tapped Into the Online Advertising Ecosystem To Track Peoples’ Movements An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations. ICE has bought access to similar t...

SCOOP: An internal DHS document obtained by 404 Media shows for the first time CBP used location data sourced from the online advertising industry to track phone locations.

This surveillance can happen through all sorts of apps, such as video games, news apps, weather trackers, and dating apps.

03.03.2026 14:16 — 👍 2132    🔁 1413    💬 57    📌 161
Preview
Amazon: Drone strikes damaged AWS data centers in Middle East Amazon has confirmed that three Amazon Web Services (AWS) data centers in the United Arab Emirates (UAE) and one in Bahrain have been damaged by drone strikes, causing an extensive outage that is still affecting dozens of cloud computing services.

Amazon has confirmed that three Amazon Web Services (AWS) data centers in the United Arab Emirates (UAE) and one in Bahrain have been damaged by drone strikes, causing an extensive outage that is still affecting dozens of cloud computing services.

03.03.2026 06:45 — 👍 18    🔁 5    💬 0    📌 1
Preview
Across party lines and industry, the verdict is the same: CISA is in trouble One year into the second Trump administration, CISA faces a 33% loss in personnel and shuttered divisions. Experts warn of "decimated" capabilities and a leadership vacuum as the agency struggles to m...

Seeing the lengthy list of changes/cutbacks to CISA catalogued in this one piece makes it clear there is little left of it. The agency is less than a decade old and struggled for years to find its footing before it started to make progress. But all advances it made have been gutted in last 12 months

27.02.2026 16:45 — 👍 22    🔁 13    💬 0    📌 1
Preview
Meta Takes Legal Action Against Scam Advertisers We've filed multiple lawsuits against deceptive advertisers in Brazil, China, and Vietnam, and continue to work aggressively to find and disrupt scams on our platforms.

In an unexpected twist of events, Meta says they're taking legal action "to combat scams" and filed "lawsuits against deceptive advertisers in Brazil and China that used celeb-bait and a Vietnam-based advertiser who used cloaking and led a subscription fraud scheme."

about.fb.com/news/2026/02...

26.02.2026 17:05 — 👍 1    🔁 0    💬 0    📌 0
Preview
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023 Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise controllers and add malicious rogue peers to targeted networks.

Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise controllers and add malicious rogue peers to targeted networks.

25.02.2026 13:02 — 👍 4    🔁 2    💬 0    📌 0
Two stories next to each other: from CNN 'Pentagon threatens to make Anthropic a pariah if it refuses to drop Al guardrails', and from New Scientist: 'Als can't stop recommending nuclear strikes in war game simulations Leading Als from OpenAl, Anthropic and Google opted to use nuclear weapons in simulated war games in 95 per cent of cases'

Two stories next to each other: from CNN 'Pentagon threatens to make Anthropic a pariah if it refuses to drop Al guardrails', and from New Scientist: 'Als can't stop recommending nuclear strikes in war game simulations Leading Als from OpenAl, Anthropic and Google opted to use nuclear weapons in simulated war games in 95 per cent of cases'

Just leaving these two stories next to each other.:
'AIs can’t stop recommending nuclear strikes in war game simulations' & 'Pentagon threatens to make Anthropic a pariah if it refuses to drop AI guardrails'
www.newscientist.com/article/2516... edition.cnn.com/2026/02/24/t...

25.02.2026 12:53 — 👍 41    🔁 27    💬 3    📌 2
СК обвинил москвича в вымогательстве у «хакеров-патриотов» под видом ФСБ Руслан Сатучин представлялся сотрудником ФСБ и требовал деньги у «патриотической» хакерской группировки Conti за непривлечение к ответственности, считает следствие

Weird cyber story from Russia: a Moscow resident Ruslan Satuchin faces criminal charges for allegedly contacting Conti under the pretense of the FSB & extorting money for protection. Now he's investigated for fraud

No word of legal action against Conti

www.rbc.ru/society/25/0...

25.02.2026 05:33 — 👍 6    🔁 7    💬 0    📌 0
Preview
Bybit exploit 12 months on: the DPRK threat continues The Bybit hack was an inflection point, not a culmination. Elliptic research reveals how DPRK operatives may now be creating cryptoasset projects, not just infiltrating them.

It's been a year since North Korean hackers stole $1.5 billion from Bybit, and they completely got away with it, ha ha ha.

Bybit exploit 12 months on: the DPRK threat continues

www.elliptic.co/blog/bybit-e...

23.02.2026 13:55 — 👍 6    🔁 5    💬 0    📌 0
Preview
Google disrupts Chinese-linked hackers that attacked 53 groups globally Google disrupted a Chinese-linked hacking group that breached at least 53 organizations across 42 countries, the company said Wednesday.

Google disrupts Chinese-linked hackers that attacked 53 groups globally - www.reuters.com/sustainabili...

25.02.2026 11:51 — 👍 12    🔁 7    💬 0    📌 0
Preview
РГ: Павла Дурова подозревают в содействии терроризму Подробнее на сайте

Some breaking news out of Russia: Officials have started an investigation into Telegram founder Pavel Durov for promoting terrorism

www.kommersant.ru/doc/8460981?...

24.02.2026 08:38 — 👍 21    🔁 11    💬 6    📌 1
Preview
PayPal discloses data breach that exposed user info for 6 months PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.

PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.

20.02.2026 08:12 — 👍 27    🔁 16    💬 0    📌 3
Preview
ОС на Linux не обновляются: эксперты говорят о «случайной блокировке» от РКН — регулятор это отвергает Под ограничения также попали образовательные платформы с курсами по Python.

As part of its internet crackdown, it appears that Russia's internet watchdog accidentally blocked the official website of the Linux kernel.

The block has been lifted after Russian IT engineers reminded Roskomnadzor that the country's native OS also runs on Linux

kod.ru/linux-rus-fail

19.02.2026 00:23 — 👍 28    🔁 10    💬 1    📌 1
Preview
European Commission discloses breach that exposed staff data The European Commission is investigating a breach after finding evidence that its mobile device management platform was hacked.

The European Commission is investigating a breach after finding evidence that its mobile device management platform was hacked.

09.02.2026 04:49 — 👍 8    🔁 6    💬 0    📌 0
Preview
French prosecutors raid X offices, summon Musk over Grok deepfakes French prosecutors have raided X's offices in Paris on Tuesday as part of a criminal investigation into the platform's Grok AI tool, widely used to generate sexually explicit images.

French prosecutors have raided X's offices in Paris on Tuesday as part of a criminal investigation into the platform's Grok AI tool, widely used to generate sexually explicit images.

03.02.2026 07:43 — 👍 13    🔁 5    💬 0    📌 1
Preview
Panera Bread breach impacts 5.1 million accounts, not 14 million customers The data breach notification service Have I Been Pwned says that a data breach at the U.S. food chain Panera Bread affected 5.1 million accounts, not 14 million customers as previously reported.

The data breach notification service Have I Been Pwned says that a data breach at the U.S. food chain Panera Bread affected 5.1 million accounts, not 14 million customers as previously reported.

02.02.2026 08:46 — 👍 6    🔁 4    💬 0    📌 0
Preview
Microsoft to disable NTLM by default in future Windows releases Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks.

Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks.

30.01.2026 12:09 — 👍 17    🔁 5    💬 0    📌 1
Preview
FBI seizes RAMP cybercrime forum used by ransomware gangs The FBI has seized the notorious RAMP cybercrime forum, a platform used to advertise a wide range of malware and hacking services, and one of the few remaining forums that openly allowed the promotion of ransomware operations.

The FBI has seized the notorious RAMP cybercrime forum, a platform used to advertise a wide range of malware and hacking services, and one of the few remaining forums that openly allowed the promotion of ransomware operations.

28.01.2026 12:38 — 👍 6    🔁 1    💬 0    📌 0
Preview
Attack Against Poland's Grid Disrupted Communication Devices at About 30 Sites The hackers behind a cyberattack that targeted Poland's grid infrastructure in December disabled communication devices for at least 30 sites across a number of energy facilities in different parts of ...

Hackers behind cyberattack against Poland electric grid in Dec disabled communication devices for at least 30 sites across a number of energy facilities in country. They rendered the devices - known as remote terminal units or RTUs - not only inoperable but also unrecoverable

28.01.2026 14:53 — 👍 26    🔁 23    💬 1    📌 2
Preview
SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws SolarWinds has released security updates to patch critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk IT help desk software.

SolarWinds has released security updates to patch critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk IT help desk software.

28.01.2026 09:39 — 👍 7    🔁 5    💬 0    📌 1
Preview
Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts Hackers have stolen the personal and contact information belonging to over 29.8 million SoundCloud user accounts after breaching the audio streaming platform's systems.

Hackers have stolen the personal and contact information belonging to over 29.8 million SoundCloud user accounts after breaching the audio streaming platform's systems.

27.01.2026 07:25 — 👍 9    🔁 8    💬 0    📌 1
Preview
Microsoft patches actively exploited Office zero-day vulnerability Microsoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks.

Microsoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks.

26.01.2026 13:20 — 👍 8    🔁 3    💬 0    📌 0

Something of note I found in researching this:

ICE's Homeland Security Investigations unit has tried and failed to break into BitLocker devices. It simply doesn't have the capability, per an HSI forensic specialist's letter to a court in 2025.

But we now know it can ask Microsoft for help.

23.01.2026 16:00 — 👍 2    🔁 2    💬 0    📌 0

#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5

23.01.2026 16:30 — 👍 35    🔁 30    💬 1    📌 5
Preview
Grubhub confirms hackers stole data in recent security breach Food delivery platform Grubhub has confirmed a recent data breach after hackers accessed its systems, with sources telling BleepingComputer the company is now facing extortion demands.

Food delivery platform Grubhub has confirmed a recent data breach after hackers accessed its systems, with sources telling BleepingComputer the company is now facing extortion demands.

15.01.2026 16:39 — 👍 6    🔁 4    💬 1    📌 1
Preview
CISA’s secure-software buying tool had a simple XSS vulnerability of its own A Cybersecurity and Infrastructure Security Agency tool dedicated to helping government agencies buy secure software turned out to have a cybersecurity vulnerability of its own.

CISA’s secure-software buying tool had a simple XSS vulnerability of its own
cyberscoop.com/cisa-secure-...

15.01.2026 22:49 — 👍 6    🔁 2    💬 1    📌 1
Preview
Hidden Telegram proxy links can reveal your IP address in one click A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add warnings to proxy links after researchers demonstrated that such one-click interactions could rev ...

A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add warnings to proxy links after researchers demonstrated that such one-click interactions could rev ...

12.01.2026 11:21 — 👍 9    🔁 4    💬 0    📌 0
Preview
European Space Agency confirms breach of "external servers" The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as "unclassified" information on collaborative engin...

The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network.

www.bleepingcomputer.com/news/securit...

30.12.2025 16:37 — 👍 2    🔁 1    💬 0    📌 0
Preview
US cybersecurity experts plead guilty to BlackCat ransomware attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.

Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.

30.12.2025 10:25 — 👍 6    🔁 3    💬 0    📌 0