Newsletters

Written content from the Risky Business Media team

Risky Biz News: The mystery at Mango Park, and the Cambodian government's shady reaction

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Something is rotten in the state of Cambodia, according to an increasing number of reports that cyber scam compound operators are now receiving protection from local police and government officials.

The perfect example of this new reality is the incident surrounding the recent "arrests" at Mango Park, a cyber scam compound in the country's Kampong Speu province.

A report from South Korean national television KBS presented the story of a South Korean who was duped by the promise of a high-paying job to travel to Cambodia, where he was held against and forced to work on online scams at Mango Park. He was freed after his family paid a ransom, and once back home, he shared with reporters how local police had protected the scam compound when he tried to complain.

Risky Biz News: US removes Sandvine from sanctions list after pinky promise

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

DHL tracking system hack: A cyberattack has disrupted a package tracking tool used by German logistics giant DHL. DHL has confirmed the incident and says it's working with the tracking tool's developer to restore systems. According to a report from Better Retailing, the tool was developed by British company Microlise.

Interbank security breach: Peru's fourth-largest bank has confirmed that a threat actor managed to steal data on some of its customers from a third-party company. The admission comes after Interbank suffered a technical glitch earlier this week and after its customer data was flaunted on hacking forums shortly after. The bank is believed to have between 2 and 3 million customers. [Additional coverage in Infobae America]

Colorado election system password leaks: The Colorado Department of State has accidentally posted a document online that contained the partial passwords for the state's voting machines. Officials have since removed the document and changed passwords. They also notified CISA and said the incident won't affect next week's election. [Additional coverage in StateScoop]

Risky Biz News: Two arrests in Operation Magnus

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Law enforcement agencies from multiple countries have disrupted the operations of the Redline and META infostealers.

The takedown took place on Monday as part of what authorities called Operation Magnus.

Officials seized three servers in the Netherlands, took control of two domain names, and arrested two other suspects in Belgium.

Risky Biz News: Russia sentences REvil members to prison. Yes! Really!

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Russian authorities have sentenced four members of the REvil ransomware gang to prison on hacking and money laundering charges.

The sentence was announced last week by a St. Petersburg military court in a case that has taken more than two years to unfold.

Artem Zayets was sentenced to 4.5 years, Alexey Malozemov to five years, Daniil Puzyrevsky to 5.5 years, and Ruslan Khansvyarov to six years in a general regime penal colony.

Risky Biz News: US offers reward for suspected Tortoiseshell APT members

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The US government is offering a $10 million reward for information on four members of an Iranian hacking group named Shahid Hemmat.

The group allegedly "works" for Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC), an agency inside the Iranian armed forces that specializes in cyber operations.

US officials say the four—Manuchehr Akbari, Amir Hosein Hoseini, Mohammad Hosein Moradi, and Mohammad Reza Rafatinezhad—conducted cyber and intelligence operations that targeted US critical infrastructure.

The EU Throws a Hand Grenade on Software Liability

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The EU and US are taking very different approaches to the introduction of liability for software products. While the US kicks the can down the road, the EU is rolling a hand grenade down it to see what happens. 

Under the status quo, the software industry is extensively protected from liability for defects or issues and this results in systemic underinvestment in product security. Authorities believe that by making software companies liable for damages when they peddle crapware, those companies will be motivated to improve product security. 

Introducing software liability is a big idea of the Biden administration's 2023 Cyber Security Strategy. Per the strategy:

Risky Biz News: Apple wants to reduce the lifespan of TLS certificates to 45 days

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Apple has put forward a proposal to gradually reduce the lifespan of TLS certificates from the current 398 days to only 45.

The planned move will take place across four phases between September next year and April 2027.

TLS lifespan will be reduced to 200 days in September 2025, to 100 in September 2026, and just 45 in April 2027.

Risky Biz News: The EU will make vendors liable for bugs

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The European Union has updated its product liability law to cover software and associated risks, like security flaws and planned obsolescence.

The new EU Directive on Liability for Defective Products [PDF] replaces one of the EU's oldest directives and will provide consumers with the legal tools to hold companies liable in court if they sell defective products.

The biggest change to the old directive is the addition of software products to the list of covered goods.

Risky Biz News: Anonymous Sudan's Russia Links Are (Still) Obvious

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The US government has charged two members of the Anonymous Sudan hacking group after the FBI secretly seized server infrastructure and disrupted its operations in March this year.

The indictment names two brothers—Ahmed Omer, 22, and Alaa Omer, 27—as the two main individuals behind the group's operations.

The two are accused of launching thousands of DDoS attacks against government agencies, hospitals, critical infrastructure, and private businesses all over the world.

Russia's GRU Thugs Double Down on Recruiting Cybercrooks

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Several strands of evidence suggest Russia's use of cybercriminals to support its war effort in Ukraine is now planned and deliberate rather than ad hoc and opportunistic. 

Russia's strategy to harness cybercriminal resources has evolved over the duration of the war. Prior to the conflict, connections between the Russian state and cybercriminals appeared to be opportunistic and based on relationships and connections between individuals.

However, a Mandiant report from April this year suggested that Sandworm (aka Unit 74455 of the GRU), was acquiring tools and bulletproof hosting services from criminal marketplaces. Now Russian intelligence services are taking the next logical step and are directly acquiring people from the criminal talent pool.