Catalin Cimpanu

@campuscodi
18.6K Followers
435 Following
141 Posts

Cybersecurity reporter for Risky Business

#infosec #cybersecurity #security

Newsletter:https://risky.biz/newsletters/
Podcast:https://risky.biz/podcasts/

-Targeted supply chain attack hits DAEMON Tools
-Australia gets its own CSRB
-VOIP server hacker arrested after 17 years
-Oracle switches to monthly security updates
-Police can be tracked via BLE tasers and bodyworn cameras
-X user tricks Grok and steals $200k
-Canonical DDoS attacks are still ongoing
-Instructure confirms hack
-Chrome deploys uninstallable 4GB AI model
-Utah's dumb VPN law goes into effect

Newsletter: https://news.risky.biz/risky-bulletin-extremely-targeted-supply-chain-attack-hits-daemon-tools/
Podcast: https://risky.biz/RBNEWS560/

-FTC bans Kochava from selling geolocation data
-New CISA Director candidate
-CISA prepares for wartime cyber
-DHS intel office staff used insecure phones
-White House wants oversight over AI models
-Sri Lanka raids scam center
-Taiwan arrests railway hacker
-Karakurt member sentenced to prison
-Two SMS blasters arrested in Thailand
-FinFisher case stalls in Germany
-DragonBreath group has a zero-day

Critical Vulnerability in PAN-OS (CERT-EU Security Advisory 2026-006)

On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges.
Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.

https://www.cert.europa.eu/publications/security-advisories/2026-006/

Critical Vulnerability in PAN-OS

Critical Vulnerability in PAN-OS

ISW Special Report:

🇷🇺 🇺🇦 #Russia is engaged in a deliberate, sophisticated, and systematic campaign to repopulate occupied areas of #Ukraine with Russian citizens as part of a broader effort to consolidate control and forcibly integrate these territories into the Russian state.

https://understandingwar.org/research/russia-ukraine/russias-resettlement-strategy-in-occupied-ukraine/

Russia’s Resettlement Strategy in Occupied Ukraine

Russia is engaged in a deliberate, sophisticated, and systematic campaign to repopulate occupied areas of Ukraine with Russian citizens.

Institute for the Study of War
-CloudZ RAT steals OTP codes from Phone Link
-New Quasar Linux RAT
-Iranian op hacks Oman's government
-New UAT-8302 APT
-ScarCruft pulls off a supply-chain attack
-Russian disinfo on Claude doubles
-MetInfo CMS exploitation
-cPanel bug was a zero-day for two months
-Infosec reporters get Pulitzers
-FTC bans Kochava from selling geolocation data
-New CISA Director candidate
-CISA prepares for wartime cyber
-DHS intel office staff used insecure phones
-White House wants oversight over AI models
-Sri Lanka raids scam center
-Taiwan arrests railway hacker
-Karakurt member sentenced to prison
-Two SMS blasters arrested in Thailand
-FinFisher case stalls in Germany
-DragonBreath group has a zero-day

-Targeted supply chain attack hits DAEMON Tools
-Australia gets its own CSRB
-VOIP server hacker arrested after 17 years
-Oracle switches to monthly security updates
-Police can be tracked via BLE tasers and bodyworn cameras
-X user tricks Grok and steals $200k
-Canonical DDoS attacks are still ongoing
-Instructure confirms hack
-Chrome deploys uninstallable 4GB AI model
-Utah's dumb VPN law goes into effect

Newsletter: https://news.risky.biz/risky-bulletin-extremely-targeted-supply-chain-attack-hits-daemon-tools/
Podcast: https://risky.biz/RBNEWS560/

Foxconn's Wisconsin's plant has had "networking issues" since last Friday

https://dysruptionhub.com/foxconn-wisconsin-cyber-outage/

Foxconn Wisconsin production halt raises cyber questions

Foxconn Wisconsin production appears disrupted by network issues, raising cybersecurity questions. Foxconn has not confirmed an attack.

DysruptionHub

Almost 40% of newly published podcasts are now AI-generated in what the podcast industry is calling podslop

https://www.bloomberg.com/news/newsletters/2026-04-30/-podslop-proliferation-is-challenging-the-audio-industry

White House is working on a policy that would limit the ability of tech companies to dictate how their tools are used by the US government.

This comes after AI companies said they'd work with the government only if their tools were used for "lawful actions."

https://www.nextgov.com/artificial-intelligence/2026/05/trump-admin-floats-policy-language-limiting-contractor-say-agency-uses-technology/413337/

Trump admin floats policy language limiting contractor say on agency uses of technology

Ongoing drafts of policy documents feature language that would limit the private sector’s ability to dictate how their artificial intelligence models are used in government missions, according to sources familiar with their development.

Nextgov.com