GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Catalin Cimpanu (campuscodi@mastodon.social)

  1. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Wednesday, 29-Oct-2025 04:22:50 JST Catalin Cimpanu Catalin Cimpanu

    Socket Security has spotted 10 malicious npm packages.

    The thing that stands out about them is the use of a CAPTCHA challenge in the npm CLI as they're being installed, most likely as a fake-out to convince victims they're installing a legitimate and actively maintained package.

    https://socket.dev/blog/10-npm-typosquatted-packages-deploy-credential-harvester

    In conversation about a day ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/453/306/631/508/730/original/a3cadd1a2b731431.png
  2. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Tuesday, 28-Oct-2025 23:29:11 JST Catalin Cimpanu Catalin Cimpanu

    lol

    https://www.linkedin.com/feed/update/urn🇱🇮activity:7386770853973147648/

    In conversation about a day ago from mastodon.social permalink
  3. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Tuesday, 28-Oct-2025 22:41:57 JST Catalin Cimpanu Catalin Cimpanu

    Fifteen individuals are expected to plead guilty this month in Italy to a complex hacking and extortion scheme.

    The individuals worked for Equalize, an Italian company that hacked government databases to create dossiers on the country's elite

    https://www.politico.eu/article/italy-milan-hackers-carmine-gallo-enrico-pazzali-samuele-calamucci-equalize-mercury-advisors/

    In conversation about a day ago from mastodon.social permalink
  4. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Sunday, 26-Oct-2025 22:19:23 JST Catalin Cimpanu Catalin Cimpanu

    A ransomware attack against Transport for London at the start of September has cost the organization £39 million

    Two teens were arraigned in court last Friday for it

    https://www.bbc.com/news/articles/cj97ekz07ezo

    In conversation about 3 days ago from mastodon.social permalink
  5. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Sunday, 26-Oct-2025 20:26:16 JST Catalin Cimpanu Catalin Cimpanu

    Ransomware payment rates have dropped below 25% for the first time in history.

    Coveware says cyber defenders, law enforcement, and legal specialists should take this as a validation of their efforts.

    https://www.coveware.com/blog/2025/10/24/insider-threats-loom-while-ransom-payment-rates-plummet

    In conversation about 3 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/440/175/247/120/696/original/795cbdefdc284567.png
  6. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Sunday, 26-Oct-2025 18:19:24 JST Catalin Cimpanu Catalin Cimpanu

    A new Microsoft Teams feature will let organizations track employees based on nearby WiFi networks.

    According to privacy experts, the new feature will allow companies to crack down on workers who dodge return-to-office mandates.

    https://www.microsoft.com/en-us/microsoft-365/roadmap?searchterms=488800

    In conversation about 3 days ago from mastodon.social permalink
  7. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Thursday, 23-Oct-2025 08:38:31 JST Catalin Cimpanu Catalin Cimpanu

    The European Union will support digital drivers' licenses for bloc members.

    The new digital license can be stored on a phone and will eventually replace physical documents. It is set to roll out by 2030.

    https://www.europarl.europa.eu/news/en/press-room/20251016IPR30947/modernising-eu-driving-rules-to-increase-road-safety

    In conversation about 7 days ago from mastodon.social permalink
  8. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Tuesday, 21-Oct-2025 18:45:28 JST Catalin Cimpanu Catalin Cimpanu

    The breach at American tech company F5 began in late 2023, far earlier than previously thought.

    The hackers breached the company after exploiting its own products.

    F5 staff allegedly failed to follow the cybersecurity guides it passed to customers.

    https://www.bloomberg.com/news/articles/2025-10-18/hackers-had-been-lurking-in-cyber-firm-f5-systems-since-2023

    In conversation about 8 days ago from mastodon.social permalink
  9. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Friday, 17-Oct-2025 02:23:19 JST Catalin Cimpanu Catalin Cimpanu

    The Tor Browser will remove all of the Firefox AI features that Mozilla has been recently adding

    https://blog.torproject.org/new-alpha-release-tor-browser-150a4/

    In conversation about 13 days ago from mastodon.social permalink
  10. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Thursday, 16-Oct-2025 21:22:18 JST Catalin Cimpanu Catalin Cimpanu

    Do you remember where you were during the Great YouTube Outage of 2025?

    In conversation about 13 days ago from mastodon.social permalink
  11. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Thursday, 09-Oct-2025 20:12:30 JST Catalin Cimpanu Catalin Cimpanu

    Azure outage on the way?

    https://azure.status.microsoft/en-gb/status?_=07:40%20UTC%20on%2009%20Oct%202025

    In conversation about 20 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/343/852/037/330/053/original/6d38c604de8f29a6.png
  12. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Tuesday, 07-Oct-2025 19:31:08 JST Catalin Cimpanu Catalin Cimpanu

    RediShell security flaw in Redis:

    -remotely exploitable
    -CVSSv3 10/10
    -impacts all versions released over the past 13 years
    -impacts 75% of cloud instances

    https://www.wiz.io/blog/wiz-research-redis-rce-cve-2025-49844

    https://redis.io/blog/security-advisory-cve-2025-49844/

    In conversation about 22 days ago from mastodon.social permalink
  13. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Friday, 03-Oct-2025 17:52:39 JST Catalin Cimpanu Catalin Cimpanu
    in reply to

    -Oracle customers are getting extorted
    -Most EU cyberattacks were DDoS attacks
    -SBI Crypto hacked for $21m
    -Sen. Cruz blocks privacy protection law
    -Accenture to cut 11,000
    -NIST releases portable storage guidance
    -Profiles on Keymous+, Lunar Spide, UAT-8099
    -New Android spyware in the UAE
    -Cavalry Werewolf APT ops
    -CISA KEV gets an update
    -DrayTek patches Vigor routers
    -Battering RAM, WireTap attacks

    In conversation about a month ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/309/351/634/532/947/original/ff5839d85e11158d.png
  14. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Friday, 03-Oct-2025 17:52:39 JST Catalin Cimpanu Catalin Cimpanu

    -Scam compound operators sentenced to death in China
    -Red Hat got hacked and extorted
    -UK makes new request for Apple user data
    -Signal threatens to leave EU
    -APT35 has another leak
    -Microsoft launches a Security Store
    -Outlook blocks inline SVGs
    -Chrome 141 is out with security goodness
    -Google Drive gets ransomware protection
    -Cyberattack recovery is hard for UK schools
    -EU MPs angry over spyware funding

    Newsletter: https://news.risky.biz/risky-bulletin-scam-compound-operators-sentenced-to-death-in-china/
    Podcast: https://risky.biz/RBNEWS486/

    In conversation about a month ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/309/328/715/453/358/original/adbdd787baed1544.png
    2. Domain not in remote thumbnail source whitelist: news.risky.biz
      Scam compound operators sentenced to death in China
      In other news: UK makes new request for Apple user data; APT35 has another leak; Microsoft launches a Security Store.
    3. Domain not in remote thumbnail source whitelist: risky.biz
      Risky Bulletin: Scam compound operators sentenced to death in China
      from catalin, claire
      China sentences 11 scam compound operators to death, the UK makes another request for Apple user data, an Iranian APT gets doxxed again, a [Read More]
  15. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Wednesday, 01-Oct-2025 01:29:21 JST Catalin Cimpanu Catalin Cimpanu

    Looks like some Linux eBPF vulnerabilities presented at this year's Black Hat are made-up AI slop

    https://www.openwall.com/lists/oss-security/2025/09/25/1

    In conversation about a month ago from mastodon.social permalink
  16. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Sunday, 28-Sep-2025 04:10:15 JST Catalin Cimpanu Catalin Cimpanu

    Dutch police detain two 17yo for walking with WiFi sniffer past Europol, Eurojust, and Canadian embassy.

    The two were allegedly recruited by Russia through Telegram

    https://nltimes.nl/2025/09/26/two-dutch-teens-arrested-rare-russian-espionage-case

    In conversation about a month ago from mastodon.social permalink
  17. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Thursday, 25-Sep-2025 22:43:22 JST Catalin Cimpanu Catalin Cimpanu

    More than 10,600 Ollama LLM-hosting servers are exposed on the internet: https://censys.com/blog/ollama-drama-investigating-the-prevalence-of-ollama-open-instances-with-censys

    Almost 4,800 Firebase databases exposed on the internet and leaking their data: https://ice0.blog/docs/openfirebase

    In conversation about a month ago from mastodon.social permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: ice0.blog
      Tea continued - Unauthenticated access to 150+ Firebase databases, storage buckets and secrets
      from Mike Oude Reimer
      Introducing OpenFirebase - Time to clean up the Firebase mess
  18. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Thursday, 25-Sep-2025 18:06:23 JST Catalin Cimpanu Catalin Cimpanu

    Eight orgs involved in FOSS and package repos have asked for more support for package repos because of the skyrocketing costs for hosting everyone's code

    "In effect, public registries have become free global CDNs for commercial vendors."

    https://openssf.org/blog/2025/09/23/open-infrastructure-is-not-free-a-joint-statement-on-sustainable-stewardship/

    In conversation about a month ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: openssf.org
      Open Infrastructure is Not Free: A Joint Statement on Sustainable Stewardship – Open Source Security Foundation
  19. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Thursday, 25-Sep-2025 11:20:18 JST Catalin Cimpanu Catalin Cimpanu

    A love story:

    -17yo Romanian teens sends bomb threats to hundreds of US schools
    -US charges him
    -Romania refuses extradition
    -Teen sends mass-shooting threats to hundreds of Romanian schools

    https://hotnews.ro/cine-este-tanarul-suspectat-ca-a-trimis-mesajele-de-amenintare-catre-sute-de-scoli-si-spitale-din-romania-fbi-l-a-acuzat-ca-a-trimis-sute-de-amenintari-cu-bomba-si-unor-institutii-din-sua-de-ce-a-2072288

    In conversation about a month ago from mastodon.social permalink
  20. Embed this notice
    Catalin Cimpanu (campuscodi@mastodon.social)'s status on Wednesday, 24-Sep-2025 02:39:16 JST Catalin Cimpanu Catalin Cimpanu

    Poland has threatened to hack back any country that cripple its critical infrastructure.

    Minister of Digital Affairs Krzysztof Gawkowski says the country has the possibilities to respond.

    https://www.portalsamorzadowy.pl/polityka-i-spoleczenstwo/minister-cyfryzacji-polska-nie-padla-ofiara-sobotniego-cyberataku-ale-mamy-zdolnosci-skutecznego-ich-odpierania,630395.html

    In conversation about a month ago from mastodon.social permalink
  • Before

User actions

    Catalin Cimpanu

    Catalin Cimpanu

    Cybersecurity reporter for Risky Business#infosec #cybersecurity #security

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          22592
          Member since
          10 Nov 2022
          Notices
          188
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.