Newsletters

Written content from the Risky Business Media team

Risky Bulletin: Russian hackers adopt the fake job interview tactics

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

One of Russia's elite military hacker groups is targeting system administrators and IT professionals in Ukraine using fake job interviews as a malware delivery vector.

Ukraine's CERT says the campaign began in May and is ongoing.

The attacks have been linked to UAC-0145, a sub-group of Sandworm, a veteran cyber unit inside Russia's GRU military intelligence agency.

Risky Bulletin: Pwnie Awards 2026 winners

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

If there's one thing that has annoyed me as someone who doesn't attend the yearly BlackHat & DEFCON conferences, it's that I could never find out who won the Pwnie Awards for days and sometimes weeks after the event had concluded.

The Pwnie team would never update their website in time, tweet the winners, attendees would rarely share details on social media, and very few infosec news sites would bother writing about it.

It's kind of a ridiculous situation where the Pwnie Awards Wikipedia page doesn't even list last year's winners, probably because nobody reported on them anywhere.

Risky Bulletin: Meta's AI joins Anthropic and OpenAI in the hacky-hacky

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The UK's AI Security Institute has disclosed a security incident after two AI models it was evaluating performed actions the agency wasn't expecting and tried to hack real-world organizations.

The incident took place at the end of last month and the malicious actions were performed by Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol models, which were among the several models being tested at the time.

AISI says it was evaluating the models as part of a special test where it intentionally granted them internet access and turned off their safety features.

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

North Korea will have to rein in its pet hackers after seemingly losing control over them. 

Last week we covered the news that a group of former North Korean military intelligence operatives had been caught hacking into the country's banks to steal funds for their personal benefit. 

Daily NK reports Pyongyang's elite are shocked at "the scale and audacity of the scheme". Punishment for those involved will reportedly be extreme, with one official saying "It will be hard for the entire family line to survive". Grim.

Risky Bulletin: Hacker breaches Hungary's State Treasury

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

The incident took place last week and portions of the stolen data have since been put up for sale on an underground hacking forum.

The intrusion was confirmed to local journalists by Hungary's State Treasury over the weekend. 

Risky Bulletin: Russia is behind the recent hotel WiFi hacks

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A Russian state-sponsored hacking group is behind a recent hacking wave that has targeted and compromised hotel WiFi gateways across the globe.

Microsoft says the campaign is far larger and more complex than it was initially covered in a ReliaQuest report two weeks ago.

ReliaQuest said the hackers were modifying DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites. Microsoft says the attacks also redirected users to malware downloads, often using ClickFix pages to trick users into downloading and running the payloads.

Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An international crime-fighting non-profit organization is offering a $22,000 bounty for any information on members of the INC ransomware group.

To be eligible for a payout, the provided information must lead to the identification, arrest, or disruption of the gang's operations.

Crime Stoppers International is the international branch of Crime Stoppers, a US foundation that was established in the 70s to allow anonymous and private individuals to provide aid in US law enforcement investigations that may lack manpower or resources.

Srsly Risky Biz: Chipping Away at Chinese AI Risks

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Trump administration has been trying to address two separate AI-related risks in recent months: The specific risk to US national security from China developing powerful AI and the global risk that powerful hacking machines will be available to all and sundry. A proposed bill suggests a sensible way for the US to chip away at both these risks, at least a little.

The Collaboration on Adversarial Threats and Security Risks Act proposes safe harbor provisions for AI companies so they can share information related to AI-specific security risks. The idea here is to encourage frontier labs to work together to counter threats from Chinese AI labs, particularly what they describe as IP theft via distillation. Without this bill, sharing this kind of information could fall afoul of anti-trust legislation that prohibits collusion. 

We know the frontier labs can already detect distillation because they're always complaining about it after the fact. The idea behind this bill is that more permissive information sharing would let them respond quicker and disrupt at least some distillation campaigns.

Risky Bulletin: New Chinese cyber contractor identified

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The cyber sleuths at Intrusion Truth have uncovered a new secretive Chinese IT company that appears to work as a cyber contractor and tool developer for Chinese state-sponsored hacking operations.

Online clues appear to suggest that Guangdong Chanming appears to have developed RedRelay (aka ORBWEAVER), an ORB network (aka proxy botnet) that was used by almost a dozen Chinese APT groups to hide the origin of their attacks.

The list includes the likes of APT15, Red Vulture, Ke3chang, Vixen Panda, Playful Dragon, Nylon Typhoon, and others.

Risky Bulletin: A JSON RCE bug is about to rock the Java world

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Threat actors are exploiting a vulnerability in Alibaba's Fastjson, one of the Java ecosystem's most popular libraries for working with JSON-formatted data.

Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm FearsOff.

The attacks, first spotted and documented by Imperva and ThreatBook, target CVE-2026-16723, a vulnerability that can enable unauthenticated remote code execution attacks against Java projects that use the Fastjson library as a component.