Newsletters

Written content from the Risky Business Media team

Risky Bulletin: Law enforcement agencies and security firms take down Amadey and StealerC

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An Europol operation aimed at taking down cybercrime operations has added two new victims to its trophy wall in the Amadey malware loader and the StealC infostealer operation. (Technically three, but we already covered the SocGolish botnet takedown last week, so we're gonna pretend it's two.)

The takedown included seven law enforcement agencies (from Europol, Canada, Denmark, Germany, the Netherlands, the UK, and the US) and six security firms (Microsoft, Bitsight, ESET, IBM, Proofpoint, MBSD, and Pillsbury).

Takedown figures include 326 servers, 142 domains, and more than $47 million in illegal cryptocurrency profits.

Srsly Risky Biz: Open Weight Model Advances Make the Mythos Debate Moot

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

This week, the Five Eyes cyber security agencies issued a call-to-action, warning that AI is accelerating "the speed, scale, and sophistication of cyber threats". 

The thinking behind the call-to-action is clear, here. The Five Eyes believe it is no longer possible to limit AI's powerful, offensive cyber security capabilities to benign actors. AI is lowering barriers for malicious actors and shrinking the window between vulnerability discovery and exploitation. Organisations need to be ready, because the genie is out of the bottle.

They're not wrong. Freely available open weights models have closed the gap with frontier models to the extent that they're now extremely useful in orchestrating various offensive cyber security tasks. 

Risky Bulletin: The FortiBleed incident is so much worse than a simple credentials leak

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

FortiBleed, a massive hacking campaign that targeted Fortinet devices this year, was far more sophisticated than security researchers initially thought.

Initial reports painted the picture of a campaign that gained access to Fortinet devices, collected credentials and authentication hashes, cracked the hashes, and then the data mysteriously leaked online.

The reality is that the campaign was far more complex and targeted a lot more things than just Fortinet devices. Compiling data from reports published by Fortinet itself, SOC Radar, CloudSEK, Palo Alto Networks, and Prodaft we have a clear picture of a broad hacking campaign that began in February this year and was initially just an internet mass-scan and brute-forcing operation.

Risky Bulletin: Klue breach impacts security firms

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

At least five security firms have had their Salesforce business accounts pilfered as part of a hacking spree that was traced back to business intelligence platform Klue.

The Klue breach took place last week, the company admitted in a blog post.

Hackers accessed its platform via "a compromised legacy credential associated with an integration service" and then stole OAuth tokens that customers had used to connect Klue to other third-party services, such as Salesforce.

Risky Bulletin: Canada’s spy agency allowed to remove a botnet from Canadian devices

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Canada's main intelligence service obtained a court warrant this week to proactively remove a mysterious botnet's malware from Canadian systems such as servers, home routers, and smart devices.

The devices were allegedly part of an unnamed proxy botnet. These types of botnets are very common these days and allow hackers to disguise the origin of their attacks and their identities, making their malicious traffic appear as coming from a local residential network.

According to a copy of the court order obtained by The Canadian Press, the botnet was allegedly being used by a threat actor to "advance their financial, political, ideological and economic interests."

Srsly Risky Biz: Anthropic Lacks Emotional Intelligence

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The stoush between Anthropic and the US government has erupted once again, this time over concerns about how the release of new AI models is being managed.

Early last week, Anthropic rolled out two new models, Mythos 5 and Fable 5. By Friday, they'd been pulled.

The Wall Street Journal reported their withdrawal was kicked off by conversations on Thursday last week between Amazon CEO Andy Jassy and US officials, including Treasury Secretary Scott Bessent. Jassy raised the possibility that the models could be jailbroken and by Friday evening the Commerce Department told Anthropic that its models would be subject to export controls. These controls prohibit the models from being used by any foreign national, regardless of whether they are inside or outside of the US. 

Risky Bulletin: China arrests members of Silver Fox cybercrime group

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Chinese police have arrested 67 suspects linked to Silver Fox, the country's largest and most active cybercrime group targeting its domestic audiences.

Arrests took place across five provinces and targeted everyone from developers to phishing site operators and various affiliates.

Authorities identified a man named Ji Moufei as the main individual who wrote and sold the group's malware, the eponymous Silver Fox trojan. Ji and four associates were arrested in Zhejiang.

Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

More than 1,900 Arch Linux packages have been hijacked over the weekend as part of a massive supply chain attack designed to infect users with a rootkit and a credentials harvester.

The attacker(s) targeted Arch Linux packages hosted on the AUR portal, an unofficial repository of Arch packages created by the community. The portal hosts a massive 100,000 entries, but almost a tenth have been abandoned by their maintainers in what AUR calls "orphaned packages."

The attack exploited an AUR mechanism that allowed the hacker to "adopt" the abandoned packages and become a maintainer.

Risky Bulletin: In the age of AI, CISA changes federal patching rules

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new binding operational directive (BOD) this week that updates the patching rules for federal civilian agencies.

The new order cites the rise of AI-automated attacks as the main reason to prioritize bugs based on the risk they pose to federal networks and shorten patching deadlines.

The order introduces a new decision tree (pictured below) that will prioritize vulnerabilities that are exploited in the wild, are easy to exploit and automate, and grant broad access to a system if they have been exploited.

Srsly Risky Biz: Europe Wants To Wean Itself Off US Tech

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The European Union Commission has proposed a tech sovereignty package that covers a range of initiatives around semiconductors, cloud computing and AI. We'd be surprised if these initiatives have a major impact in the short term, but this is still a good move for Europe. 

The key initiative of the proposed package, in our view, is the Open Source Strategy which aims to "strengthen digital autonomy through open source". Although it's not stated explicitly, the intent here is to wean Europe off the US tech stack by encouraging open source alternatives. 

The strategy says it will take "concrete actions", for example reforming government procurement rules to make them more open source friendly. EU governments will also award grants to open source projects under the strategy.