Sergiu Gatlan's Avatar

Sergiu Gatlan

@serghei.bsky.social

Cybersecurity/tech reporter @BleepingComputer / serghei.ro

5,488 Followers  |  868 Following  |  82 Posts  |  Joined: 23.06.2023  |  1.7707

Latest posts by serghei.bsky.social on Bluesky

Preview
Qilin ransomware abuses WSL to run Linux encryptors in Windows The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools.

The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools.

28.10.2025 15:11 β€” πŸ‘ 11    πŸ” 8    πŸ’¬ 0    πŸ“Œ 1
Preview
Fake LastPass, Bitwarden breach alerts lead to PC hijacks An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake emails claiming that the companies were hacked, urging them to download a supposedly more secure desktop version of the password manager.

An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake emails claiming that the companies were hacked, urging them to download a supposedly more secure desktop version of the password manager.

15.10.2025 15:22 β€” πŸ‘ 58    πŸ” 58    πŸ’¬ 0    πŸ“Œ 5

On CISA media call just now to discuss the F5 hack and source code breach, CISA staffer interrupted the discussion to blame the Democrats for the government shutdown and forcing workers to work without pay

15.10.2025 16:13 β€” πŸ‘ 152    πŸ” 34    πŸ’¬ 6    πŸ“Œ 21
Preview
F5 says hackers stole undisclosed BIG-IP flaws, source code U.S. cybersecurity company F5 disclosed that it suffered a cyberattack in early August, where suspected nation-stateΒ hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code.

U.S. cybersecurity company F5 disclosed that it suffered a cyberattack in early August, where suspected nation-stateΒ hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code.

15.10.2025 09:32 β€” πŸ‘ 9    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
Hackers claim Discord breach exposed data of 5.5 million users Discord says they will not be negotiating with threat actors who claim to have stolen the data of 5.5 million unique users from the company's Zendesk support system instance, including government IDs and partial payment information for some people.

Discord says they will not be negotiating with threat actors who claim to have stolen the data of 5.5 million unique users from the company's Zendesk support system instance, including government IDs and partial payment information for some people.

08.10.2025 20:22 β€” πŸ‘ 11    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Preview
ShinyHunters launches Salesforce data leak site to extort 39 victims The ShinyHunters extortion group has leaked samples of data belonging to dozens of companies, which were stolen in a wave of Salesforce breaches that have affected numerous companies worldwide.

The ShinyHunters extortion group has leaked samples of data belonging to dozens of companies, which were stolen in a wave of Salesforce breaches that have affected numerous companies worldwide.

03.10.2025 10:16 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

A source shares some screenshots of the Lapsus ransomware gang celebrating the government shutdown as a disruption to the FBI investigations tracking them.

They also refer to Trump as "my king."

01.10.2025 15:07 β€” πŸ‘ 33    πŸ” 22    πŸ’¬ 2    πŸ“Œ 1

Astonishingly Pathetic Threat

01.10.2025 09:39 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
CISA orders agencies to patch Cisco flaws exploited in zero-day attacks CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.

CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.

25.09.2025 13:53 β€” πŸ‘ 10    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
SonicWall warns customers to reset credentials after breach SonicWall warned customers today to reset credentials after their firewall configuration backup files were exposed in a security breach that impacted MySonicWall accounts.

SonicWall warned customers today to reset credentials after their firewall configuration backup files were exposed in a security breach that impacted MySonicWall accounts.

17.09.2025 12:23 β€” πŸ‘ 9    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Screenshot with quote from article:

"How Android's new risk-based update process works

Instead of bundling all available security patches into the next ASB, Google now prioritizes shipping only "high-risk" vulnerabilities in its monthly releases. The majority of security fixes, meanwhile, will be shipped in quarterly ASBs. Google defines "high-risk" vulnerabilities as issues that are crucial to address immediately, such as those under active exploitation or that are part of a known exploit chain. This designation is based on real-world threat level and is distinct from a vulnerability's formal "critical" or "high" severity rating."

Screenshot with quote from article: "How Android's new risk-based update process works Instead of bundling all available security patches into the next ASB, Google now prioritizes shipping only "high-risk" vulnerabilities in its monthly releases. The majority of security fixes, meanwhile, will be shipped in quarterly ASBs. Google defines "high-risk" vulnerabilities as issues that are crucial to address immediately, such as those under active exploitation or that are part of a known exploit chain. This designation is based on real-world threat level and is distinct from a vulnerability's formal "critical" or "high" severity rating."

Google has switched to a risk-based Android update process, with β€œhigh-risk” vulnerabilities patched on a monthly basis and the rest fixed on a quarterly schedule.

www.androidauthority.com/android-risk...

15.09.2025 16:14 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Appeal court orders release of convicted psychotherapy centre database hacker If the court reduces his sentence, there's a risk that Aleksanteri KivimΓ€ki will have spent too much time in prison β€” and then be able to demand compensation from the state.

Finnish hacker Aleksanteri KivimΓ€ki has been released from prison following an appeal.

KivimΓ€ki hacked Finnish psychotherapy centre Vastaamo in 2020 and released highly sensitive patient files.

yle.fi/a/74-20182408

11.09.2025 16:55 β€” πŸ‘ 5    πŸ” 4    πŸ’¬ 0    πŸ“Œ 1
Preview
Hackers left empty-handed after massive NPM supply-chain attack The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but attackers made little profit off it.

The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but attackers made little profit off it.

10.09.2025 13:56 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

NPM has begun removing the malicious packages.

bsky.app/profile/bad-...

08.09.2025 18:26 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Phishing email sent to NPM package maintainers:

08.09.2025 17:12 β€” πŸ‘ 32    πŸ” 19    πŸ’¬ 1    πŸ“Œ 3
Preview
Orange Belgium discloses data breach impacting 850,000 customers Orange Belgium, a subsidiary of telecommunications giant Orange Group, disclosed on Wednesday that attackers who breached its systems in July have stolen the data of approximately 850,000 customers.

Orange Belgium, a subsidiary of telecommunications giant Orange Group, disclosed on Wednesday that attackers who breached its systems in July have stolen the data of approximately 850,000 customers.

21.08.2025 03:07 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 0    πŸ“Œ 1
Preview
HR giant Workday discloses data breach after Salesforce attack Human resources giant Workday has disclosed a data breach after attackers gained access to a third-party customer relationship management (CRM) platform in a recent social engineering attack.

HR giant Workday breached in Salesforce data-theft attacks

www.bleepingcomputer.com/news/securit...

18.08.2025 09:49 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Colt Telecom attack claimed by WarLock ransomware, data up for sale UK-basedΒ telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company's operations, including hosting and porting services, Colt Online and Voice API platforms.

UK-basedΒ telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company's operations, including hosting and porting services, Colt Online and Voice API platforms.

15.08.2025 11:25 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
New downgrade attack can bypass FIDO auth in Microsoft Entra ID Security researchers have created a new FIDO downgrade attack against Microsoft Entra ID that tricks users into authenticating withΒ weaker login methods, making them susceptible to phishing and session hijacking.

Security researchers have created a new FIDO downgrade attack against Microsoft Entra ID that tricks users into authenticating withΒ weaker login methods, making them susceptible to phishing and session hijacking.

13.08.2025 15:14 β€” πŸ‘ 12    πŸ” 4    πŸ’¬ 0    πŸ“Œ 3
Preview
Hyundai wants Ioniq 5 owners to pay to fix a keyless entry security hole Thieves have been stealing cars with a Game Boy-like device

some Hyundai IONIQ 5 models can be hacked to open the doors and start the car with a Game Boy-like device. Now, Hyundai is asking customers in the UK to pay Β£49 to fix this huge security flaw. Details here πŸ‘‡ www.theverge.com/news/757205/...

11.08.2025 11:53 β€” πŸ‘ 57    πŸ” 11    πŸ’¬ 4    πŸ“Œ 1
Preview
Inside the Multimillion-Dollar Gray Market for Video Game Cheats Gaming cheats are the bane of the video game industryβ€”and a hot commodity. A recent study found that cheat creators are making a fortune from gamers looking to gain a quick edge.

Eighty cheat websites generate between $12.8 million and $73.2 million annually, according to academics at the University of Birmingham.

Up to 174,000 people may be buying cheats every month across North America and Europe.

www.wired.com/story/inside...

Research: github.com/SamCollins13...

11.08.2025 10:59 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 2
Preview
Microsoft warns of high-severity flaw in hybrid Exchange deployments Microsoft has warned customers to mitigate a high-severity vulnerability in Exchange Server hybrid deployments that could allow attackers to escalate their privileges in Exchange Online cloud environm...

Microsoft warns customers to mitigate a high-severity vulnerability in Exchange Server hybrid deployments that can let attackers escalate privileges in Exchange Online cloud environments undetected.

www.bleepingcomputer.com/news/microso...

07.08.2025 08:48 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Air France and KLM disclose data breaches impacting customers Air France and KLM announced on Wednesday that attackers had breached a customer service platform and stolen the data of an undisclosed number of customers.

Air France and KLM announced on Wednesday that attackers had breached a customer service platform and stolen the data of an undisclosed number of customers.

07.08.2025 04:41 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
Google suffers data breach in ongoing Salesforce data theft attacks Google is the latest company to suffer a data breach in an ongoing wave of Salesforce CRM data theft attacks conducted by the ShinyHunters extortion group.

Google is the latest company to suffer a data breach in an ongoing wave of Salesforce CRM data theft attacks conducted by the ShinyHunters extortion group.

06.08.2025 09:51 β€” πŸ‘ 7    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0

Although not yet confirmed by Cisco, this is likely part of a wave of Salesforce data theft attacks linked to the ShinyHunters extortion group.

Other companies affected by Salesforce data breaches: Adidas, Qantas, Allianz Life, Chanel, and LVMH brands Louis Vuitton, Dior, and Tiffany & Co.

05.08.2025 13:38 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Ransomware gangs join attacks targeting Microsoft SharePoint servers Ransomware gangs have recently joined ongoing attacks targeting a Microsoft SharePoint vulnerability chain,Β part of a broader exploitation campaign that has already led to the breach of at least 148 organizations worldwide.

Ransomware gangs have recently joined ongoing attacks targeting a Microsoft SharePoint vulnerability chain,Β part of a broader exploitation campaign that has already led to the breach of at least 148 organizations worldwide.

04.08.2025 07:27 β€” πŸ‘ 10    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
Minnesota activates National Guard after St. Paul cyberattack Minnesota Governor Tim Walz has activated the National Guard in response to a crippling cyberattack that struck the City of Saint Paul, the state's capital, on Friday.

Minnesota Governor Tim Walz has activated the National Guard in response to a crippling cyberattack that struck the City of Saint Paul, the state's capital, on Friday.

29.07.2025 14:58 β€” πŸ‘ 7    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data.

Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data.

28.07.2025 14:03 β€” πŸ‘ 13    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
Millions of cars at risk from Flipper Zero key fob hack, experts warn Hackers are using a custom Flipper Zero firmware to bypass security protections in automotive key fobs, putting millions of vehicles at risk.

NEW: A custom firmware for the Flipper Zero, being sold by a Russian hacker for up to $1,000, can bypass modern security protections on key fobs.



The hack defeats rolling codes & lets you clone every key fob buttonβ€”lock, unlock, trunkβ€”by capturing just a single command.

san.com/cc/millions-...

24.07.2025 15:16 β€” πŸ‘ 67    πŸ” 25    πŸ’¬ 7    πŸ“Œ 5
Preview
Ukraine arrests suspected admin of XSS Russian hacking forum The suspected administrator of the Russian-speaking hacking forum XSS.is was arrested by the Ukrainian authorities yesterdayΒ at the request of the Paris public prosecutor's office.

The suspected administrator of the Russian-speaking hacking forum XSS.is was arrested by the Ukrainian authorities yesterdayΒ at the request of the Paris public prosecutor's office.

23.07.2025 09:41 β€” πŸ‘ 5    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

@serghei is following 20 prominent accounts