Catalin Cimpanu
banner
campuscodi.risky.biz
Catalin Cimpanu
@campuscodi.risky.biz
☆ Cybersecurity reporter
★ Newsletters at Risky Business
#infosec #cybersecurity

https://risky.biz
Reposted by Catalin Cimpanu
-Myanmar blows up KK Park scam compound
-Yanluowang ransomware IAB pleads guilty
-US CBO hacked by foreign APT
-Singapore to punish scammers with cane beatings
-Chrome will remove XSLT support for security reasons

Podcast: risky.biz/RBNEWS502/
Newsletter: news.risky.biz/risky-bullet...
November 10, 2025 at 8:33 AM
Reposted by Catalin Cimpanu
-Hungary opposition party hacked, blamed on Russians
-WaPo breach linked to Oracle zero-day
-Tinder to rummage through your photos
-Akamai reports disruptions in Russia
-EU GDPR to replace cookie popups with device signals
-Australia sanctions North Korean hackers
-ICC, Austria replace MSFT software
November 10, 2025 at 8:35 AM
Reposted by Catalin Cimpanu
Cross platform marketing reaching its ultimate form. Things are bananas.
November 9, 2025 at 2:14 PM
Reposted by Catalin Cimpanu
There are email newsletters that post better quarterly revenues.
Trump Media reports Q3 net sales down 3.8% YoY to $972.9K and a net loss of $55M, up from $19M in Q3 2024; its stock is down 70% from a January high (Bailey Lipschultz/Bloomberg)

Main Link | Techmeme Permalink
November 7, 2025 at 7:57 PM
Reposted by Catalin Cimpanu
one of these headlines is not like the others
-Myanmar blows up KK Park scam compound
-Yanluowang ransomware IAB pleads guilty
-US CBO hacked by foreign APT
-Singapore to punish scammers with cane beatings
-Chrome will remove XSLT support for security reasons

Podcast: risky.biz/RBNEWS502/
Newsletter: news.risky.biz/risky-bullet...
November 10, 2025 at 8:45 AM
Reposted by Catalin Cimpanu
I worked in Silicon Valley for decades. These & most tech companies only wanted to hire white males under 30, and had to be forced into diversity.

Now enforcement of these rules is gne and soon you won't see anything but young, white males - like it was.

www.wired.com/story/google...
Google, Microsoft, and Meta Have Stopped Publishing Workforce Diversity Data
Other big tech companies including Amazon, Apple, and Nvidia have continued their annual disclosures this year even as the Trump administration cracks down on DEI.
www.wired.com
November 7, 2025 at 1:05 PM
Reposted by Catalin Cimpanu
Draft documents show the European Commission plans to relax some privacy laws, including the GDPR, to boost AI growth and cut red tape for businesses in Europe (Ellen O'Regan/Politico)

Main Link | Techmeme Permalink
November 10, 2025 at 4:30 AM
Reposted by Catalin Cimpanu
The tech bros get Trump to exercise extortionate demands on the EU to block regulatory initiatives. The tactic works flawlessly. www.ft.com/content/af6c...
EU set to water down landmark AI act after Big Tech pressure
Commission proposes pauses to provisions in digital rule book
www.ft.com
November 7, 2025 at 2:29 PM
-Myanmar blows up KK Park scam compound
-Yanluowang ransomware IAB pleads guilty
-US CBO hacked by foreign APT
-Singapore to punish scammers with cane beatings
-Chrome will remove XSLT support for security reasons

Podcast: risky.biz/RBNEWS502/
Newsletter: news.risky.biz/risky-bullet...
November 10, 2025 at 8:33 AM
There's now talks of investigations into Chinese-made electric buses in Australia, Denmark, the UK, and the Netherlands.
November 9, 2025 at 7:31 PM
Two weeks ago, there were weird reports online of explosions at KK Park, Myanmar's largest scam compound, and people fleeing the streets.

I thought some internal military groups were fighting for control, but it appears the junta is demolishing the park outright

www.irrawaddy.com/news/myanmar...
November 9, 2025 at 7:03 PM
Singapore passes law to punish scammers and money mules with cane beatings :))

www.straitstimes.com/singapore/po...
Law passed for scammers, mules to be caned after victims in Singapore lose almost $4b since 2020
Scammers face between six and 24 strokes of the cane, while mules face a discretionary 12 strokes. Read more at straitstimes.com. Read more at straitstimes.com.
www.straitstimes.com
November 9, 2025 at 6:26 PM
Australia sanctions North Korean hackers (one person and four entities)

-Park Jin Hyok (WannaCry dude)
-Kimsuky
-Lazarus Group
-Andariel
-Chosun Expo

Presser: www.foreignminister.gov.au/minister/pen...

Sanction details: www.dfat.gov.au/news/news/on...
November 9, 2025 at 5:33 PM
Reposted by Catalin Cimpanu
November 9, 2025 at 8:16 AM
Singaporean authorities have sentenced three Chinese nationals to 2 years and 4 months prison for hacking-related charges

The three hacked into online gambling sites to cheat on games and steal personal data

www.police.gov.sg/Media-Hub/Ne...
Three Men Sentenced For Offences In Relation To Illegal Cyber Activities
On 5 November 2025, three Chinese nationals, Yan Peijian (“Yan”), 39, Huang Qinzheng (“Huang”), 37, and Liu Yuqi (“Liu”), 33, were convicted and sentenced to imprisonment for their roles in a global c...
www.police.gov.sg
November 9, 2025 at 3:02 PM
Microsoft has discovered a side-channel attack (Whisper Leak) on the network communications between AI chatbots and their backend LLMs

www.microsoft.com/en-us/securi...
November 9, 2025 at 2:38 PM
Konni APT wipes victims' Android smartphones via the Google find my device hub

www.genians.co.kr/en/blog/thre...
State-Sponsored Remote Wipe Tactics Targeting Android Devices
The Konni APT campaign has caused damage by remotely resetting Google Android-based devices, resulting in the unauthorized deletion of personal data.
www.genians.co.kr
November 9, 2025 at 2:04 PM
"Akamai is aware of content and connectivity filtering within Russia. Although we have not yet seen wholesale blocking of our platform for users, Russian network operator actions and actions by the Russian govt may impact delivery to some users within some networks."

www.akamai.com/blog/edge/20...
November 9, 2025 at 1:28 PM
Google Chrome will deprecate and remove XSLT support (the XML CSS thing) by late-2026

Cites security reasons

developer.chrome.com/docs/web-pla...
Removing XSLT for a more secure browser  |  Web Platform  |  Chrome for Developers
Prepare for Chrome deprecating and removing XSLT from the browser.
developer.chrome.com
November 9, 2025 at 12:33 PM
Eeww... that's 10 times more creepy than all the predators on its site
November 9, 2025 at 10:29 AM
I had to take shelter inside for 2 days until this passed
Sharks in Romania 🦈
November 9, 2025 at 9:22 AM
Hungary's main opposition party has suffered a major security breach. Hackers leaked more than 200,000 user records from the TISZA party's mobile app.

hungarytoday.hu/yet-another-...

TISZA leader Péter Magyar blamed the hack on Russian hackers.

www.facebook.com/peter.magyar...
Yet Another TISZA Party Data Breach Scandal: Blame the Russians and Orbán
Main opposition party leader Péter Magyar with his supporters The TISZA party, led by Péter Magyar, is embroiled in a new data scandal after sensitive data from 200,000 users of the TISZA Világ app wa...
hungarytoday.hu
November 9, 2025 at 9:18 AM
So... it's open season on MEV bot exploits? Am I reading this correctly?

www.reuters.com/legal/govern...
November 9, 2025 at 12:38 AM
It's ok... take it down... I'll just link to Indian blog spam of paywalled articles out of spite
November 8, 2025 at 11:47 PM
Reposted by Catalin Cimpanu
Ransomware has appeared in the VS Marketplace and makes me worry. Clearly created through AI, it makes many mistakes like including decryption tools in extension. If this makes it into the marketplace through, what impact would anything more sophisticated cause?

secureannex.com/blog/ransomv...
RansomVibing appears in VS Code extensions
Vibe coded ransomware has successfully been published to the VS Code extension marketplace
secureannex.com
November 5, 2025 at 5:44 PM