An unlikely couple, a doomed affair and their €64mn ransomware scam
How a mysterious tip-off led investigators to uncover the inner workings of a highly unusual hacking operation
In Sirotin’s case, the fatal mistake came in the form of two online purchases — a knife, bought with the same email address used to rent the suspicious servers discovered by investigators, and a pair of plane tickets he had bought for his parents
on.ft.com/4hhtmGd
18.10.2025 09:19 — 👍 7 🔁 2 💬 0 📌 1
The response to SolarWinds really nerfed the viability of traditional software supply chain compromise and China got the message. The shift to operational enablement compromises ain’t going anywhere and is more viable for the long term.
17.10.2025 18:33 — 👍 4 🔁 2 💬 0 📌 0
Wikipedia Says AI Is Causing a Dangerous Decline in Human Visitors
“With fewer visits to Wikipedia, fewer volunteers may grow and enrich the content, and fewer individual donors may support this work.”
Wikipedia is seeing a significant decline in human traffic because more people are getting the information that’s on Wikipedia via generative AI chatbots that were trained on its articles and search engines that summarize them without actually clicking to the site
www.404media.co/wikipedia-sa...
17.10.2025 12:45 — 👍 845 🔁 359 💬 28 📌 65
Paragon Solutions (US) has terminated its 🇺🇸 lobbying registration with law firm Holland & Knight. The filing is dated 15 October, but the termination took effect on 25 April. Paragon’s owner, AE Industrial Partners, still maintains an active registration.
17.10.2025 11:09 — 👍 3 🔁 2 💬 1 📌 0
Researchers at NTT present an analysis of OtterCandy and detail the update observed in August 2025. This malware was used by WaterPlum (also known as Famous Chollima or PurpleBravo). jp.security.ntt/insights_res...
17.10.2025 08:43 — 👍 2 🔁 2 💬 0 📌 0
-The F5 hack
-EU MEP files criminal complaint against Hungary PM over hacking
-Bulletproof hoster shuts down due to political reasons
-PowerSchool hacker sentenced to four years
-Four airports hacked across NA
Newsletter: news.risky.biz/risky-bullet...
Podcast: risky.biz/risky-bullet...
17.10.2025 05:44 — 👍 13 🔁 5 💬 2 📌 0
YouTube video by Recon Conference
Recon 2025 - A Trip to Ancient BABYLON: Unearthing a 2017 Pegasus Persistence Exploit
Recording of our REcon talk about a 2017 iOS persistence exploit used by NSO's Pegasus—and other threat actors too—is out. @billmarczak.org and me of @citizenlab.ca at @reconmtl.bsky.social.
youtu.be/ZlopMtjsVRw
16.10.2025 14:45 — 👍 3 🔁 3 💬 0 📌 0
Neue Hinweise auf ungarische Spionage in Brüssel
Der ungarische Oppositionsführer Péter Magyar war selbst in der ständigen Vertretung Ungarns in Brüssel stationiert und schildert seine Erinnerungen in einem Post
🇭🇺🕵️♂️ Nach unserer @spiegel.de @derstandard.at @papertrailmedia.de @direkt36.bsky.social Recherche: Péter Magyar – heute Oppositionsführer, früher Diplomat in Ungarns EU-Vertretung in Brüssel – bekräftigt Spionagevorwürfe gegen Orbáns Regierung: „allgemein bekannt“ www.derstandard.at/story/310000...
16.10.2025 12:55 — 👍 28 🔁 10 💬 2 📌 0
New from last night: F5 CEO François Locoh-Donou is personally briefing customers about the China-linked hackers who were in the company’s network for at least 12 months
16.10.2025 11:35 — 👍 16 🔁 13 💬 0 📌 0
Révélations sur le « Group 78 », une unité secrète américaine chargée de la lutte contre les cybercriminels
En novembre 2024, la présentation de cette task force par le FBI à des policiers et des magistrats européens a choqué certains enquêteurs. Ils craignent notamment pour l’intégrité de leurs investigati...
Scoop : révélations sur le "Group 78", l'unité secrète du FBI chargée de faire la guerre aux cybercriminels, quitte à utiliser des méthodes illégales et au risque de faire dérailler les enquêtes judiciaires européennes (avec @flrnd.bsky.social et @kaibiermann.bsky.social). Thread ⤵️
16.10.2025 04:42 — 👍 17 🔁 25 💬 2 📌 0
Cyber giant F5 Networks says government hackers had 'long-term' access to its systems, stole code and customer data | TechCrunch
The company, which provides cybersecurity defenses to most of the Fortune 500, said the DOJ allowed it to delay notifying the public on national security grounds.
This one's a wild/messy one: Cyber giant F5, which serves most of the Fortune 500, said unknown government hackers had 'long term' access to its network:
• stole source code, some customer data
• accessed undisclosed vulns in BIG-IP
• DOJ allowed F5 to delay public notice citing national security
15.10.2025 15:55 — 👍 62 🔁 58 💬 1 📌 5
-Windows 10 reaches End-of-Life
-CISA layoffs didn't touch cyber personnel
-US seizes $15 billion from cyber scam compound operator
-Secure Boot bypass impacts 200k Framework systems
-German police take down 1,400 scam sites
Podcast: risky.biz/RBNEWS491/
Newsletter: news.risky.biz/risky-bullet...
15.10.2025 06:55 — 👍 16 🔁 7 💬 1 📌 0
‘I love Hitler’: Leaked messages expose Young Republicans’ racist chat
Thousands of private messages reveal young GOP leaders joking about gas chambers, slavery and rape.
EXCLUSIVE: Thousands of leaked messages show leaders of Young Republican groups joking about gas chambers, slavery and rape in a private Telegram chat.
Inside rising GOP leaders’ racist chats — obtained by POLITICO and spanning more than 7 months👇
14.10.2025 17:22 — 👍 6031 🔁 3413 💬 585 📌 1423
🚨 NEU: “Wir können dafür ins Gefängnis kommen”– dieser Satz steht im Zentrum unserer neuen Recherche. 🚨
Es wird verrückt: Strafbare Sanktionsumgehung, ein Undercover-Einsatz, ein überwachter Vatikan-Reporter, prominente Opfer & Red Bull. Willkommen zu #SurveillanceSecrets
14.10.2025 15:14 — 👍 57 🔁 30 💬 1 📌 2
Ukraine takes steps to launch dedicated cyber force for offensive strikes
Ukraine lawmakers are considering uniting the country's offensive and defensive military cyber capabilities under a single command within the Armed Forces.
If new legislation passes, Ukraine’s Cyber Forces will conduct military cyber operations, gather intelligence, hunt threats in cyberspace and defend military systems while building secure infrastructure for the country's armed forces therecord.media/ukraine-take...
13.10.2025 17:51 — 👍 3 🔁 3 💬 0 📌 0
YouTube video by Three Buddy Problem
Apple Exploit-Chain Bounties, Tactical Wi-Fi Exploit Suitcases
An all-new Three Buddy Problem for your weekend earholes. Apple exploits chains, Oracle + ransomware, Ivanti 0days, VT pricing tiers @craiu.bsky.social @jags.bsky.social
youtu.be/qPj9_8azAvk?...
12.10.2025 14:19 — 👍 7 🔁 4 💬 0 📌 1
YouTube video by Three Buddy Problem
Tactical Suitcase x iPhone WiFi Exploits #apple #wifi #tacticalgear #spyware #exploit #iPhone #iOS
Costin on million-dollar "tactical suitcases" with iPhone wireless proximity exploits @craiu.bsky.social @jags.bsky.social
www.youtube.com/shorts/r3vu_...
12.10.2025 16:19 — 👍 5 🔁 3 💬 1 📌 0
-Microsoft revamps Edge's "IE Mode" after zero-day attacks
-FBI seizes Salesforce extortion site
-New round of CISA layoffs
-Apple doubles bug bounty rewards
-White House rescinds NSA&CyberCom chief nomination
Newsletter: news.risky.biz/microsoft-re...
Podcast: risky.biz/RBNEWS490/
13.10.2025 10:00 — 👍 18 🔁 11 💬 1 📌 0
Spyware maker NSO Group confirms acquisition by US investors | TechCrunch
NSO Group confirmed to TechCrunch that an unnamed group of American investors has taken “controlling ownership” of the surveillance tech maker.
SCOOP: Spyware maker NSO Group confirmed to us that the company has been acquired by a U.S. investment group.
NSO's spokesperson said the group "has invested tens of millions of dollars in the company and has acquired controlling ownership," but declined to say who is behind the investment.
10.10.2025 15:54 — 👍 176 🔁 140 💬 5 📌 31
Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits
With the mercenary spyware industry booming, Apple VP Ivan Krstić tells WIRED that the company is also offering bonuses that could bring the max total reward for iPhone exploits to $5 million.
As Apple expands its bug bounty, I spoke with VP Ivan Krstić about the significance + recent big swings like Memory Integrity Enforcement. These steps protect all users, but particularly those targeted by spyware: “We feel a great moral obligation to defend those users” www.wired.com/story/apple-...
10.10.2025 13:06 — 👍 21 🔁 8 💬 0 📌 2
-EU scraps Chat Control vote
-Ukraine establishes a Cyber Force
-CISA workers reassigned to immigration enforcement
-Teenagers arrested for Kido hack
-Salesforce will not pay the ransom
-US Court halts FCC data breach rules
Newsletter: news.risky.biz/risky-bullet...
Podcast: risky.biz/RBNEWS489/
10.10.2025 08:43 — 👍 20 🔁 9 💬 1 📌 0
The hack against software giant Red Hat is part of a larger campaign that is targeting AWS cloud accounts.
A group named the Crimson Collective is using compromised IAM accounts to access and pilfer corporate AWS environments.
www.rapid7.com/blog/post/tr...
09.10.2025 08:42 — 👍 24 🔁 10 💬 2 📌 0
Il caso Paragon si allarga agli imprenditori: anche Caltagirone spiato
Il telefono del finanziere romano tra i protagonisti del riassetto del sistema bancario sarebbe stato attaccato con lo spyware che ha colpito anche giornalisti…
According to reconstructions, in Dec 2024 the ☎️number used by Caltagirone was added to a WhatsApp chat with contacts known to him, within which a PDF file had been shared. Shortly afterwards, the chat & the PDF disappeared.
✍️ @faffa42.bsky.social & Gianluca Paolucci.
www.lastampa.it/economia/202...
09.10.2025 04:55 — 👍 3 🔁 1 💬 1 📌 0
🚨 According to @irpimedia.eu & @lastampa.bsky.social, prominent 🇮🇹 Italian businessman Francesco Gaetano Caltagirone has been added to the list of people who last January received a message from WhatsApp informing them that they had been targeted with Paragon's Graphite #spyware.
09.10.2025 04:55 — 👍 6 🔁 6 💬 1 📌 1
Senior Cybersecurity Reporter at The Record from Recorded Future News. Send tips to martin.matishak@therecord.media. Signal: mmatishak.80
Virtual Routes tackles the impact of digital and emerging technologies on global affairs. Also check out @bindinghook.bsky.social, our media outlet.
Security information portal, testing and certification body.
Organisers of the annual Virus Bulletin conference.
Investigative reporter NYT. Helping cover President Trump (and Elon Musk)-without fear or favor. I write about people and power. My contact on Signal: EricNYT.08
‧₊˚ ⋅ Indie Comfy VTuber
⊹˚. Employed Threat Intel Researcher
♡‧₊˚ SynthV-P-wannabe
🎨: @jamama666.bsky.social / @MomoiroKohi / @justNovaj
🖌️: #artsyaz
🐦: x.com/azakasekai_
https://links.azaka.fun
Sharing information on malicious network traffic and malware samples at https://www.malware-traffic-analysis.net/
Threat Research @ Recorded Future
AML/cybercrime investigator. Cosplays at journalism.
https://kostas.page | Opinions are mine only! 🇬🇷🇨🇦
Cybersecurity reporter at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net
security & software engineering · cyber defense · civil society
https://infosec.exchange/@droe
I do computers @ DarkCell.se / @hkashfi at X
CTI @wizsecurity.bsky.social
Previously NSC44, Mandiant, Google
Go Mammoths
🇬🇧 Threat Research @ Recorded Future.
I Like Tracking ASNs and ISPs for some reason...
Palo Alto Unit 42 | SANS Instructor | Former Mandiant and CIA | Chaotic Neutral
We are Microsoft's global network of security experts. Follow for security research and threat intelligence. https://aka.ms/threatintelblog
independent cybersecurity researcher.
I have many leather-bound books and my apartment smells of rich mahogany. thanks for all the xor
Lecturer in War Studies (Cyber Security) at King's College London. Organising HagueTIX 2025 @haguetix.bsky.social.
Cyber threat intelligence research and analysis from geopolitical, economic, social, cultural and linguistic perspectives.