Newsletters

Written content from the Risky Business Media team

Risky Bulletin: India bans app used to hack e-rickshaws in viral videos

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Indian government has ordered Apple and Google to remove a battery management app from their stores that had been used over the past weeks to hack e-rickshaws across the country as part of a toxic viral trend that mocked drivers and risked blocking traffic.

Videos of the hacked have been spreading on social media for two-three weeks in a trend named the Tirri Challenge.

The videos showed distressed drivers stuck in traffic pushing their vehicles to the side or crying over lost revenue on the phone with family and mechanics.

Srsly Risky Biz: Supreme Court Undermines Section 702

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

A new US Supreme Court decision could undermine the flow of Section 702 intelligence collection from Europe.

Section 702 allows the US government to collect intelligence on people outside the US with compelled help from communication service providers and is regarded as the crown jewel of American foreign intelligence collection. 

Since 2000, successive data sharing agreements have facilitated transatlantic commerce by allowing the legal transfer of personal data from the EU to the US. Section 702 collection from Europe relies on these data flows and the intelligence program has been at the heart of legal challenges to the data sharing agreements. 

Risky Bulletin: All new cars to include a camera aimed at the driver's face

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

All new cars manufactured and sold in the EU and in the US will have to include a mandatory infrared camera aimed at the driver's face at all times, which is alarming some privacy groups.

The infrared camera will track the driver's head position and eye movements and then alert distracted drivers if their eyes go off the road.

The new regulation has entered into effect in the EU on Monday and will enter into effect next year in the US. In the EU, the new camera requirement is part of the block's second General Safety Regulation (GSR2), a broader swath of new safety rules introduced for the auto industry and designed to improve road safety.

Risky Bulletin: Android drops PIN guessing limit from 1,800 attempts to just 20

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Android 17, released last month, has shipped with stricter protections against lockscreen PIN and password guessing attacks.

Google has reduced the maximum number of failed attempts from 1,800 to just 20, and the timeouts between failed attempts are now way more aggressive.

The previous Android 16 allowed ten wrong guesses in the first minute, which increased up to 1,800 across five years.

Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The developers of a lot of industrial gear and smart devices will have their work cut out for them over the coming months and years to deploy protections against a set of newly discovered and unpatched bugs in the FatFs filesystem driver.

The seven bugs, discovered by security firm runZero, can allow an attacker to use a crafted filesystem image to cause a memory corruption that runs malicious code to jailbreak a targeted device.

Devices that use FatFs for their filesystem are all impacted.

Srsly Risky Biz: America Won't Beat the Distillation Ecosystem

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Last week Anthropic accused Chinese company Alibaba of conducting what it described as the "largest known distillation attack" against the company's AI models. 

Distillation attacks upskill less capable models by training them on the outputs of more advanced ones. Back in February Google, OpenAI and Anthropic all said that Chinese companies were harvesting their proprietary intellectual property in coordinated campaigns.

Alibaba's latest campaign, Anthropic says, occurred from April 22 to June 5 and used more than 25,000 fraudulent accounts to generate 28.8 million exchanges. Anthropic says it was carried out by operators "affiliated with Alibaba and Alibaba Qwen, Alibaba's AI lab". 

Risky Bulletin: Researcher drops giant cache of zero-day exploits

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An anonymous security researcher going online by the pseudonym of Bikini has published proof-of-concept exploit code and detailed write-ups for more than a dozen zero-day vulnerabilities in popular open-source projects.

The exploits were published without notifying any of the vendors.

They impact 15 software projects, including some big names like the Linux kernel, Libssh2, Anydesk, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN, the VLC player, and more.

Risky Bulletin: Microsoft disrupts StegoAd operation

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Microsoft's security team has removed 119 malicious Edge extensions from the official Microsoft Edge Add-ons store that were part of a coordinated operation that sought to steal user credentials, backdoor browsers, and engage in advertising and search affiliate fraud.

The extensions were published through 90+ different developer accounts but shared infrastructure, parts of their codebase, and heavily relied on steganography to hide malicious commands and code.

The StegoAd operation, as Microsoft called it, also had Chrome and Firefox extensions under its umbrella.

Risky Bulletin: Law enforcement agencies and security firms take down Amadey and StealerC

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An Europol operation aimed at taking down cybercrime operations has added two new victims to its trophy wall in the Amadey malware loader and the StealC infostealer operation. (Technically three, but we already covered the SocGolish botnet takedown last week, so we're gonna pretend it's two.)

The takedown included seven law enforcement agencies (from Europol, Canada, Denmark, Germany, the Netherlands, the UK, and the US) and six security firms (Microsoft, Bitsight, ESET, IBM, Proofpoint, MBSD, and Pillsbury).

Takedown figures include 326 servers, 142 domains, and more than $47 million in illegal cryptocurrency profits.

Srsly Risky Biz: Open Weight Model Advances Make the Mythos Debate Moot

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

This week, the Five Eyes cyber security agencies issued a call-to-action, warning that AI is accelerating "the speed, scale, and sophistication of cyber threats". 

The thinking behind the call-to-action is clear, here. The Five Eyes believe it is no longer possible to limit AI's powerful, offensive cyber security capabilities to benign actors. AI is lowering barriers for malicious actors and shrinking the window between vulnerability discovery and exploitation. Organisations need to be ready, because the genie is out of the bottle.

They're not wrong. Freely available open weights models have closed the gap with frontier models to the extent that they're now extremely useful in orchestrating various offensive cyber security tasks.